They should do both, but start with the controls that reveal where AI is used and how data moves. Without discovery and monitoring, prevention rules have no reliable context. Once the estate is visible, preventive controls can focus on high-risk tools, workflows, and agent actions rather than every AI interaction.
Why visibility comes before preventive AI controls
Organisations usually get better results by starting with discovery and monitoring, then tightening prevention around what is actually in use. AI environments are often fragmented across approved tools, embedded features, plugins, model endpoints and agent workflows, so prevention rules written without visibility tend to be too broad, too narrow, or both. Monitoring gives the context needed to decide where restrictions matter most.
That sequencing matters because the same control can behave very differently depending on data flow, user role, and the action an AI system is allowed to take. A blanket prevention policy may block benign use while still missing high-risk paths such as sensitive data export, external tool calls, or agentic actions that can change systems. Visibility is what turns security policy from theory into a workable control set.
For AI use cases that overlap with identity and access decisions, discovery also helps teams understand which interactions are only informational and which involve authorisation, delegation, or privilege. That distinction is central to deciding whether a preventive control should focus on the model, the application, the workflow, or the access path itself. For a broader identity and lifecycle lens, NHI Lifecycle Management Guide is useful because it frames visibility, ownership, and control placement together.
How to balance prevention with monitoring in practice
The practical rule is to use monitoring to find the highest-risk interactions, then apply prevention where the blast radius is real and the workflow is understood. Start with controls that reveal where AI is used, what data enters and leaves the system, and which tools or actions the system can invoke. Only then can teams decide whether to block, allow with alerting, step-up review, or constrain by policy.
This is especially important when AI touches secrets, customer data, regulated information, or production systems. In those cases, prevention without context often overcorrects, while monitoring without follow-through becomes passive observability. The most effective posture combines both, but it prioritises visibility first so preventive controls can be targeted rather than symbolic. NHIMG’s Ultimate Guide to NHIs is a relevant reference point here because it connects visibility gaps, sprawl, and unmanaged credentials to practical control design.
Once the estate is visible, prevention should concentrate on the few places where AI can create irreversible impact, such as data exfiltration, tool misuse, or autonomous actions against downstream systems. That is a better investment than trying to prevent every prompt, every query, or every model output. If the organisation cannot yet answer where the AI is, what it can reach, and what data it can expose, hard prevention will usually be miscalibrated.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | DE.CM — Continuous Monitoring | AI security needs visibility into active use and data movement. |
| PR.AC — Identity Management, Authentication, and Access Control | AI prevention depends on controlling who and what can invoke high-risk actions. | |
| PR.DS — Data Security | The question turns on seeing how data moves through AI systems before blocking it. | |
| Recommendation — Monitor AI usage and data flows continuously to guide targeted control decisions. Apply access controls to restrict sensitive AI workflows and actions. Protect data paths in AI systems based on observed usage and exposure. | ||
| CIS Controls v8 | 8 — Audit Log Management | Monitoring is central to understanding AI behaviour and risky data movement. |
| 6 — Access Control Management | Prevention becomes effective only after high-risk AI access paths are known. | |
| Recommendation — Centralise and review AI-related logs to detect risky use and data exposure. Restrict AI access to sensitive systems and data based on observed need. | ||
| NIST AI RMF | MAP — Map | AI security prioritisation starts with understanding where AI is used and what it touches. |
| MEASURE — Measure | Monitoring provides the evidence needed to judge AI risk and control effectiveness. | |
| Recommendation — Inventory AI use cases and data flows before selecting preventive controls. Measure AI behaviour and exposure to target controls where risk is highest. | ||
Practitioner Guidance
What to prioritise: Build a minimum viable inventory of AI usage, data paths, and action paths before writing strict deny rules. The goal is to locate the controls that matter most, not to freeze all AI activity on day one.
Decision rule: If you cannot reliably trace the data entering and leaving the AI flow, prioritise monitoring and classification first. If the workflow is already visible and the AI can touch sensitive data or production actions, add preventive controls around those specific paths.
What good looks like: Security teams can tell which AI systems are in use, which data types they handle, which tools they can invoke, and which actions require escalation or restriction. Prevention then becomes targeted, reviewable, and easier to defend operationally.
Practitioner takeaway: Treat visibility as the prerequisite for effective prevention, because controls are only as precise as the environment they can see.
Related resources from NHI Mgmt Group
- How do organisations decide whether to prioritise AI tooling for offense or defense in security programs?
- How should organisations decide whether to prioritise browser security for unmanaged identities, shadow SaaS, or AI app usage?
- How do organisations decide whether AI monitoring should sit with security, engineering, or IAM teams?
- How should organisations decide whether to buy AI security tools through procurement channels?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 22, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org