TL;DR: Sensitive data can be found by DSPM, but visibility alone does not reduce risk unless teams can correlate data with identity, access, and activity, especially as AI systems amplify misuse pathways, according to BigID. The real security gap is contextual understanding, because inventory without access intelligence turns into false confidence and missed exposure.
NHIMG editorial — based on content published by BigID: Data Security Posture Management (DSPM) needs data context to reduce risk
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should security teams reduce risk when DSPM only shows data location?
A: They should connect discovery to identity, access, and activity data so sensitivity is evaluated in context.
Q: Why does AI make DSPM weaker if data is already classified?
A: AI weakens discovery-only DSPM because it consumes data dynamically through prompts, retrieval, and agent workflows.
Q: What breaks when DSPM lacks identity correlation?
A: You get false confidence, because the tool can prove data exists without proving it is safely reachable.
Practitioner guidance
- Correlate data discovery with entitlement data Join classification results to identity, role, and access records so every sensitive dataset has a clear exposure path, not just a location tag.
- Add usage telemetry to high-risk datasets Track query activity, export events, and downstream references so security teams can see whether sensitive data is being actively consumed or redistributed.
- Extend coverage into AI pipelines Map sensitive datasets into copilots, retrieval layers, and agent workflows so runtime data use is governed alongside storage controls.
What's in the full article
BigID's full article covers the operational detail this post intentionally leaves for the source:
- Data-context examples showing how access, activity, and sensitivity are correlated across environments
- Operational DSPM questions for evaluating whether a programme is measuring risk or only cataloguing data
- AI workflow scenarios that show how prompts, retrieval, and agent usage change the exposure model
- Implementation framing for moving from static classification to continuous contextual governance
👉 Read BigID's analysis of why DSPM needs identity and activity context →
DSPM visibility gaps: why identity context changes the picture?
Explore further
Discovery without identity context is not data security, it is data inventory. DSPM only reduces risk when it can tie sensitivity to effective access and usage. If a programme can classify data but cannot explain who can reach it or how it is consumed, it has visibility without control. That is why identity correlation belongs at the centre of data governance, not as an optional enrichment layer. Practitioners should treat identity-aware DSPM as the minimum viable model for meaningful risk reduction.
A question worth separating out:
Q: Who is accountable when an AI-assisted workflow leaks sensitive data?
A: Accountability sits with the organisation that allowed the workflow to operate outside governed controls. Security, IAM, and business owners all share responsibility for ensuring approval, logging, and lifecycle management exist before data moves through the path. If no one can block or revoke it, no one is governing it.
👉 Read our full editorial: DSPM fails without identity and activity context for data risk