As organizations increasingly rely on artificial intelligence (AI) to automate and optimize complex workflows, a new challenge has emerged for cybersecurity teams. Despite their best efforts to mitigate risks through cloud access security brokers (CASB) and data loss prevention (DLP) tools, AI poses a unique set of threats that these traditional controls are ill-equipped to handle.
The problem lies in the fact that AI risk is not confined to a single app or file, but rather manifests itself in the interactions between humans and AI models. A malicious prompt can lead to unintended consequences, such as sensitive data leakage or even autonomous agents taking actions that compromise an organization’s security. However, traditional CASB controls are limited in their ability to evaluate the semantic and cumulative context of an AI conversation, making it difficult to detect potential risks.
One of the key limitations of CASB is its focus on user access rather than the substance of the conversation. A prompt may look harmless at first glance, but upon closer inspection, its wording, context, and purpose can reveal underlying risks. For instance, a user might unknowingly share sensitive details across prompts, which could be enough for an AI model to make sense of them.
Imagine a scenario where a vendor contract is being closed in the next few days, and information about it is shared through AI-powered conversations. Or picture a summary of an outage incident report being generated by an AI tool. In both cases, there is real business risk associated with this information sharing, even if it doesn’t match a DLP rule.
Security teams are caught between a rock and a hard place when trying to mitigate these risks. If they squeeze CASB controls too tightly, users may shift to unmanaged apps that nobody can see. On the other hand, if DLP rules are too permissive, sensitive data leakage becomes a significant concern.
The solution lies in inspecting the interaction between humans and AI models, rather than just focusing on user access or data flow. This requires controls that operate at the point of exposure, where the risk is highest. Security teams need to look closely at what’s being asked, what the model generates in response, what tools the agent invokes, what data it retrieves or transmits, and whether its resulting actions are permitted.
For instance, using AI to develop go-to-market copy referencing an unannounced product puts sensitive information at risk. Similarly, a software developer using an AI tool to answer a generic question is low-risk, but requesting proprietary logic or linking it to a real customer problem can escalate the risk significantly.
Treating retrieved content as data is expected behavior, but when instructions are embedded cleverly enough that the agent ingests and follows them, prompt injection becomes a serious risk. Authenticating an agent or session is a baseline control, but it’s not enough when a low-risk request can suddenly turn into a high-risk action.
To mitigate these risks effectively, organizations need to extend their governance beyond traditional CASB and DLP controls. This means implementing AI anomaly detection capabilities that can decide what should be allowed based on the context of the conversation. By doing so, security teams can ensure that AI is used responsibly and minimize the risk of sensitive data leakage or other unintended consequences.
In conclusion, as organizations increasingly rely on AI to drive their workflows, it’s essential for cybersecurity teams to rethink their approach to security. Traditional CASB and DLP controls are not sufficient to mitigate the unique risks associated with AI. By inspecting the interaction between humans and AI models, extending governance beyond traditional controls, and implementing AI anomaly detection capabilities, organizations can ensure that AI is used responsibly and minimize the risk of sensitive data leakage or other unintended consequences.
Source: SecurityWeek — 2026-08-04