Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Perplexity security and Comet risk: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15984
Topic starter  

TL;DR: Perplexity security is a shared-responsibility problem in which enterprise controls, consumer-tier usage, and Comet’s agentic browsing create different governance boundaries, according to WitnessAI. The gap is no longer model security alone, but visibility and enforcement at the interaction layer where prompts, account type, and authenticated actions determine exposure.

NHIMG editorial — based on content published by WitnessAI: Perplexity security and the shared-responsibility gap for enterprise AI

Questions worth separating out

Q: How should security teams govern AI agents that can access enterprise systems?

A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.

Q: Why do agentic AI systems create more security risk than standard chatbots?

A: Agentic systems can turn model output into action, which means a bad instruction can affect code flow, tool use, and downstream state.

Q: What breaks when AI governance does not include interaction-level visibility?

A: Teams lose the ability to prove which account was used, what was prompted, and what action followed.

Practitioner guidance

  • Separate enterprise and personal AI access paths Require identity-based tier assignment for approved AI tools and block corporate data from personal accounts through policy, monitoring, and user education.
  • Instrument AI activity at the interaction layer Capture prompts, responses, account type, and downstream actions in a single audit trail so reviewers can reconstruct what happened inside each session.
  • Treat agentic browsing as privileged automation Limit what Comet-style sessions can reach, require scoped permissions, and log actions performed inside authenticated tabs or connected services.

What's in the full article

WitnessAI's full article covers the operational detail this post intentionally leaves for the source:

  • Plan-by-plan differences in enterprise controls, retention terms, and admin settings for Perplexity use.
  • Detailed examples of Comet prompt-injection behaviour and how those tests translated into session-level risk.
  • WitnessAI's network-level discovery approach for finding AI activity routed through the platform without endpoint tooling.
  • Runtime policy actions and guardrail behaviour for blocking or routing risky AI interactions.

👉 Read WitnessAI's analysis of Perplexity security and Comet risk →

Perplexity security and Comet risk: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15569
 

Interaction-layer governance is now the decisive control plane for enterprise AI. The article shows that provider-side assurances are insufficient once users can move between enterprise and personal accounts. Security leaders need policy enforcement where prompts, account type, and session actions meet, because that is where actual exposure occurs. This is a NIST CSF and NIST SP 800-53 concern as much as an AI governance one, since auditability and access control have to extend into the interaction layer. The practitioner conclusion is clear: identity policy must govern AI usage at runtime, not only at procurement.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% reporting no or low visibility and 47% saying visibility is only partial, according to The State of Non-Human Identity Security.
  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to the same research.

A question worth separating out:

Q: Who is accountable when sensitive data is retained in a third-party AI tool?

A: Accountability sits with the organisation that allowed the data into the tool, even if the provider stores or processes it. Teams need clear ownership for prompt retention, deletion requests, and vendor data processing terms. If the provider cannot prove erasure or lineage, the organisation still carries the compliance and privacy risk.

👉 Read our full editorial: Perplexity security depends on tier controls and interaction-layer governance



   
ReplyQuote
Share: