TL;DR: The old split between data in motion and data at rest breaks down when files move from storage into GenAI tools without a traditional network event, leaving legacy DLP and posture tools blind to the full path, according to Cyberhaven. Data lineage, not state, becomes the more durable security model for AI-era data governance.
NHIMG editorial — based on content published by Cyberhaven: Data in Motion vs. Data at Rest: Why the Model Breaks
Questions worth separating out
Q: How should security teams prepare data access governance before enabling GenAI tools?
A: Start by reducing permission debt.
Q: Why do traditional data in motion and data at rest models fail for AI risk?
A: They assume data moves through a visible boundary that tools can inspect.
Q: What do security teams get wrong about AI and data classification?
A: They often treat classification as a labelling exercise instead of an access-control input.
Practitioner guidance
- Map sensitive-data paths into AI tools Trace how contracts, source code, customer records, and regulated data move from storage systems into GenAI applications, including copy-paste, uploads, and connected integrations.
- Add lineage-aware monitoring to DSPM Extend DSPM workflows so they record origin, movement, and downstream reuse of sensitive files across SaaS, endpoints, and AI tools.
- Review identity permissions that enable AI data redistribution Check which users, groups, and service integrations can move sensitive content from controlled repositories into external AI tools.
What's in the full article
Cyberhaven's full article covers the operational detail this post intentionally leaves for the source:
- How the vendor's data lineage approach traces movement across endpoints, cloud apps, and AI tools
- The specific ways browser uploads, copy-paste, and connected integrations evade legacy boundary-based DLP
- Why the vendor argues point-in-time posture scanning cannot reconstruct the path of sensitive data
- The example workflow for following a file back to its source system after it enters an AI assistant
👉 Read Cyberhaven's analysis of why the data in motion vs. data at rest model breaks →
Data state vs. data lineage: are your controls keeping up?
Explore further
Data lineage is becoming the governance layer that state-based controls were never designed to provide. The article shows why current storage-versus-transit thinking collapses once AI tools can ingest, transform, and redistribute sensitive content without a clean edge event. That creates a broader accountability problem for security and identity programmes because access decisions now influence downstream data movement. Practitioners should treat lineage as a governance requirement, not a reporting enhancement.
A question worth separating out:
Q: How do organisations reduce AI exposure without blocking useful access?
A: Organisations should reduce exposure by removing stale data, tightening access around high-risk combinations, and restricting AI to verified datasets instead of broad repositories. That approach lowers blast radius while preserving use cases. The goal is not to stop AI access, but to make access intentional, visible, and defensible.
👉 Read our full editorial: Data in motion and data at rest no longer explain AI data risk