Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

AI security in the data stack: what changes for DLP and DSPM?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: AI is changing how sensitive data moves through prompts, agents, summarisation tools, and third-party models, creating structural gaps in legacy DLP and DSPM programs, according to Cyberhaven. Security teams now have to treat AI risk as a design input, because point-in-time controls cannot keep pace with data that is copied, transformed, and re-entered through AI sessions.

NHIMG editorial — based on content published by Cyberhaven: How to Make AI Security Foundational to Your Data Security Stack

By the numbers:

Questions worth separating out

Q: How should security teams govern sensitive data used by AI systems?

A: Security teams should treat AI as a data consumer that needs policy boundaries, not just authentication.

Q: Why do legacy DLP tools struggle with AI workflows?

A: Legacy DLP was built for files, email, and pattern matching, not for free-form prompts, embedded copilots, or agentic connections.

Q: What breaks when organisations add AI security after DLP and DSPM are already deployed?

A: The stack ends up with isolated visibility.

Practitioner guidance

  • Implement AI-aware data lineage Track where sensitive data originates, how it moves, and where it enters prompts or agentic workflows so policy can follow the data instead of the app.
  • Extend DLP to the endpoint and browser Move enforcement closer to the point of interaction, because the critical exposure moment often happens when users copy, paste, or compose content into AI tools.
  • Inventory the full AI tool surface continuously Maintain an automatically updated inventory of sanctioned and unsanctioned AI tools so governance reflects real usage rather than approved lists.

What's in the full article

Cyberhaven's full post covers the operational detail this post intentionally leaves for the source:

  • How its AI-native endpoint DLP approach handles copy, paste, and browser-based AI sessions in practice
  • How its data lineage model is used to connect discovery, classification, and enforcement across the stack
  • How the vendor frames the relationship between DSPM, IRM, and AI security in a unified operating model
  • How organisations can translate policy decisions into technical controls for AI workflows

👉 Read Cyberhaven's analysis of making AI security foundational to the data stack →

AI security in the data stack: what changes for DLP and DSPM?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

AI security has moved from a category decision to an architectural decision. The article’s core point is correct: organisations that bolt AI controls on after DLP and DSPM are already deployed will inherit blind spots. That matters because AI changes the data path, not just the tooling. For practitioners, the lesson is to design governance around AI-mediated data movement from the start.

A question worth separating out:

Q: Should organisations prioritise AI data governance before scaling AI adoption?

A: Yes. Organisations that scale AI before establishing discovery, classification, monitoring, and policy enforcement are effectively expanding the attack surface faster than they can govern it. AI adoption should be matched with controls that follow the data lifecycle, otherwise compliance, exposure, and misuse risks compound as usage grows.

👉 Read our full editorial: AI security as a foundation for modern data security stacks



   
ReplyQuote
Share: