The Dark Side of AI: How CASB and DLP Fall Short in Protecting Against Cyber Risks
As organizations increasingly rely on artificial intelligence (AI) to automate complex workflows, a new wave of cybersecurity threats is emerging. Traditional security measures, such as cloud access security brokers (CASB) and data loss prevention (DLP), are struggling to keep pace with the dynamic nature of AI-powered interactions. It’s time to rethink our approach to securing these systems.
The problem lies in the limitations of CASB and DLP controls, which are designed to govern user access to specific applications or data fields. However, when it comes to AI, the risk is not just about accessing a particular tool or data set, but also about the meaning behind the conversation itself. A prompt may appear harmless at first glance, but its wording, context, and purpose can make all the difference in determining whether it’s safe or malicious.
The scenario is particularly challenging because exposure won’t always come from obvious sources such as pasting account numbers or API keys into a conversation. Instead, sensitive information can be shared indirectly through a series of prompts, making it difficult for traditional CASB controls to detect and prevent data leakage. This means that security teams are caught in a bind: tightening CASB controls could push users towards unmanaged apps that nobody can see, while being too permissive with DLP rules leaves the gates open for sensitive data leakage.
So what’s the solution? Security must inspect the interaction itself, not just the access to AI services. This means looking closely at what’s being asked, what the model generates in response, and whether its resulting actions are permitted. For instance, using an AI tool to develop go-to-market copy referencing an unannounced product is a high-risk scenario, while using it to come up with a blog outline for publication is relatively low-risk.
In agentic workflows, retrieving approved knowledge bases may not be risky, but forwarding restricted internal documentation externally certainly is. Treating retrieved content as data is expected behavior, but when instructions are embedded cleverly enough that the agent ingests and follows them, prompt injection becomes a serious risk because the model cannot reliably distinguish data from instructions.
To mitigate these risks, security teams will need to extend their governance beyond just authenticating agents or sessions. This requires AI anomaly detection capabilities to decide what should be allowed, taking into account the cumulative context of an AI conversation. By doing so, organizations can ensure that they’re protecting against not only malicious prompts but also those with unintended consequences.
Ultimately, securing AI-powered systems is a complex challenge that demands a more nuanced approach than traditional CASB and DLP controls can provide. It’s time for security teams to rethink their playbook and invest in the right tools and techniques to detect and prevent AI-related cyber threats before they happen.
Source: SecurityWeek — 2026-08-04