TL;DR: AI is changing how sensitive data moves through prompts, agents, summarisation tools, and third-party models, creating structural gaps in legacy DLP and DSPM programs, according to Cyberhaven. Security teams now have to treat AI risk as a design input, because point-in-time controls cannot keep pace with data that is copied, transformed, and re-entered through AI sessions.
NHIMG editorial — based on content published by Cyberhaven: How to Make AI Security Foundational to Your Data Security Stack
By the numbers:
- Frontier organizations now use approximately 300 generative AI tools.
- Enterprise adoption of endpoint-based AI agents has grown 276% in a single year.
- 82% of the top 100 most-used generative AI SaaS applications carry medium, high, or critical risk ratings.
Questions worth separating out
Q: How should security teams govern sensitive data used by AI systems?
A: Security teams should treat AI as a data consumer that needs policy boundaries, not just authentication.
Q: Why do legacy DLP tools struggle with AI workflows?
A: Legacy DLP was built for files, email, and pattern matching, not for free-form prompts, embedded copilots, or agentic connections.
Q: What breaks when organisations add AI security after DLP and DSPM are already deployed?
A: The stack ends up with isolated visibility.
Practitioner guidance
- Implement AI-aware data lineage Track where sensitive data originates, how it moves, and where it enters prompts or agentic workflows so policy can follow the data instead of the app.
- Extend DLP to the endpoint and browser Move enforcement closer to the point of interaction, because the critical exposure moment often happens when users copy, paste, or compose content into AI tools.
- Inventory the full AI tool surface continuously Maintain an automatically updated inventory of sanctioned and unsanctioned AI tools so governance reflects real usage rather than approved lists.
What's in the full article
Cyberhaven's full post covers the operational detail this post intentionally leaves for the source:
- How its AI-native endpoint DLP approach handles copy, paste, and browser-based AI sessions in practice
- How its data lineage model is used to connect discovery, classification, and enforcement across the stack
- How the vendor frames the relationship between DSPM, IRM, and AI security in a unified operating model
- How organisations can translate policy decisions into technical controls for AI workflows
👉 Read Cyberhaven's analysis of making AI security foundational to the data stack →
AI security in the data stack: what changes for DLP and DSPM?
Explore further
AI security has moved from a category decision to an architectural decision. The article’s core point is correct: organisations that bolt AI controls on after DLP and DSPM are already deployed will inherit blind spots. That matters because AI changes the data path, not just the tooling. For practitioners, the lesson is to design governance around AI-mediated data movement from the start.
A question worth separating out:
Q: Should organisations prioritise AI data governance before scaling AI adoption?
A: Yes. Organisations that scale AI before establishing discovery, classification, monitoring, and policy enforcement are effectively expanding the attack surface faster than they can govern it. AI adoption should be matched with controls that follow the data lifecycle, otherwise compliance, exposure, and misuse risks compound as usage grows.
👉 Read our full editorial: AI security as a foundation for modern data security stacks