Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI adoption gaps and data exposure: what security teams need to know


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Fragmented enterprise AI adoption is concentrating risk where GenAI usage is highest, with frontier organisations using more than 300 tools and 71.4% employee adoption in some cases, according to Cyberhaven. The governance problem is not tool count but uncontrolled data flow into and out of AI systems, which makes visibility and policy consistency the decisive control.

NHIMG editorial — based on content published by Cyberhaven: Why Fragmented AI Adoption Poses a Major Data Risk

By the numbers:

Questions worth separating out

Q: How should security teams govern AI use cases across multiple business units?

A: Security teams should require a single inventory of AI use cases, models, and agents with consistent ownership, lifecycle stage, and risk metadata.

Q: Why does fragmented AI infrastructure create security risk?

A: Fragmented AI infrastructure creates risk because each provider handoff can split responsibility for credentials, permissions, and logging.

Q: What do organisations get wrong about approval for AI actions?

A: They often assume a single approval step is enough for a whole conversation.

Practitioner guidance

  • Measure real AI usage by team and workflow Map which GenAI tools are actually in use, which teams use them most, and which business processes move sensitive data through them.
  • Apply data controls at prompt and output points Use DLP, content classification, and logging where data enters and exits AI systems.
  • Govern developer assistants as SDLC controls Treat coding assistants as part of source control, pipeline, and repository governance.

What's in the full article

Cyberhaven's full article covers the operational detail this post intentionally leaves for the source:

  • The reported adoption splits by percentile and department, useful if you need the original data for internal benchmarking.
  • The article's breakdown of where AI usage is most concentrated across engineering and regulated business functions.
  • The framing of how prompts and outputs behave as a data-in-motion channel in day-to-day work.
  • The source article's guidance on using DSPM and related controls to reduce exposure without blocking adoption.

👉 Read Cyberhaven's analysis of fragmented AI adoption and data risk →

AI adoption gaps and data exposure: what security teams need to know?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Fragmented AI adoption is a data governance problem before it is an AI tooling problem. The article shows that risk concentrates where adoption is fastest, not where policy is most complete. That means security teams need to treat GenAI usage as a distributed data plane with inconsistent controls. For programmes that already struggle with shadow IT, the lesson is familiar: visibility and control must follow actual use, not approved intent.

A question worth separating out:

Q: How can teams reduce AI leakage risk without slowing adoption?

A: By designing for containment and recovery instead of relying on perfect prevention. That means isolating sensitive data sources, tightening access to retrieval layers, and preparing purge or restore workflows for accidental disclosure. This approach keeps AI usable while reducing the blast radius when content escapes its intended context.

👉 Read our full editorial: Fragmented AI adoption creates hidden data risk across enterprises



   
ReplyQuote
Share: