TL;DR: 83% of enterprises already use AI, but only 13% have strong visibility into how it touches their data, while 76% say autonomous AI agents are the hardest to secure, according to Cyera’s 2025 State of AI Data Security Report. The gap is no longer about model adoption, but about governance that can see and constrain data access in real time.
Editorial analysis by NHI Mgmt Group, based on content published by Cyera: “AI Security Best Practices: Why a Data-Centric Approach Is the Foundation for Secure AI Innovation”.
By the numbers:
- 83% of enterprises already use AI, but only 13% report strong visibility into how it touches their data.
Key questions
Q: What breaks when AI agents are given access without identity governance?
A: What breaks is accountability.
Q: When do autonomous systems create more governance risk than ordinary automation?
A: They create more risk when they can decide the action sequence, choose tools at runtime, and execute without human approval.
Q: How can security teams tell whether AI posture management is actually working?
A: It is working when teams can answer four questions quickly and consistently: who owns the agent, what it can access, which guardrails apply, and when access changed.
Practitioner guidance
- Discover and classify AI-fed sensitive data Map the datasets that train, prompt, augment, or inform AI systems, then tag regulated records, intellectual property, and other high-risk data so access can be governed by sensitivity rather than system name.
- Create AI-specific identity policies Assign each model or agent a defined identity scope, tie permissions to business purpose and data classification, and remove access automatically when the AI use case changes.
- Deploy continuous AI security posture monitoring Track configuration drift, data movement, and policy compliance in real time so new connectors, new datasets, or new entitlements are detected before they become exposure paths.
Bottom line: AI security failures are increasingly about uncontrolled data access, not just model behaviour or adoption speed.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Data visibility, not model sophistication, is now the primary AI governance failure mode: organisations are deploying AI faster than they can see where it touches sensitive information. That means the most important control is not a model blacklist or a dashboard, but a reliable data control plane that can explain access in context. Practitioners should treat visibility into AI data movement as a governance prerequisite, not a reporting feature.
A few things that frame the scale:
- 13% of organisations suffered breaches of their AI models, according to IBM's Cost of a Data Breach 2025 report.
A question worth separating out:
Q: What steps should security teams take to prevent Shadow AI risks?
A: Security teams should assess their governance frameworks, implement real-time monitoring tools, and ensure proper training on the risks associated with Shadow AI. These steps will help identify unauthorized agents and mitigate risks effectively.
👉 Read our full editorial: AI security best practices show why data-centric controls matter