The biggest cybersecurity challenges when it comes to integrating AI platforms like Microsoft Copilot, ChatGPT Enterprise or any other AI agents for enterprises may seem to be pertinent to governance, acceptable use policies and employee training in AI. However, that is not always the case. Ultimately, it comes down to a challenge with the data.
In the recent episode of The Security Strategist podcast, host Shubhangi Dua, Podcast Producer and B2B Tech Journalist, is joined by Itay Maor, Head of Product at Orion Security. They address the foundational issue with deploying agentic AI to enterprise workflows, which comes down to Data Loss Prevention (DLP).
Maor begins the conversation with the statement: “Data loss is preventable. It's not just observable.”
He adds that only by dropping assumptions built over 20 years of ineffective DLP can teams successfully make Data Loss Prevention work.
What Is Hindering Enterprise Security's Adaptation to an AI-First World?
For enterprises to become a core part of an AI-first world, data must be protected from an early start. As soon as tools like Copilot or ChatGPT Enterprise enter the picture, sensitive data begins flowing into prompts. The issue is that security teams often lack visibility into what employees are inputting, such as customer records, deal terms, or source code.
Firstly, blocking the AI is not going to work in this scenario because AI is here to stay. The issue that needs addressing is that security teams need to be able to see where the enterprise data is flowing.
Maor believes AI hasn't created an entirely new security problem; it has exposed one that has existed for years.
“Customer records, source code, deal terms- legacy DLP doesn’t help much because they were built to match patterns, credit card numbers, keywords. Pasting a Q3 revenue forecast into a chatbot won't trigger standard security alerts,” he says, putting it into context.
“You approve ChatGPT Enterprise, but what if your employee just logged in using their personal account? Same URL, same interface, same browser, and your network controls say chatgpt.com and waves it through,” Maor adds.
Security teams need to know which identity the data is flowing to. Right now, it's difficult for them to differentiate.
The third layer, however, is where the market is heading because it depicts where the AI is connected to the data. For instance, Microsoft Copilot is wired into SharePoint and ChatGPT. Cloud connects to Google Drive, to Slack, and to email through native connectors. Meanwhile, the agents query internal systems on their own autonomously.
“There is no upload, no paste, no human action to inspect at all,” the Head of Product at Orion tells Dua.
AI agents end up inheriting 10 years of over-permisioning, he says; “it happily surfaces an M&A document to anyone with access that was never cleaned up, making it searchable in plain English.”
Each of these three layers widens the gap that all controls can cover. So, the first challenge isn't blocking AI; it's that you can no longer answer where your data is going, and everything else in AI security starts with that question.
Security Teams Must Move From Detection to Data Loss Prevention
Maor proposes that enterprises need to shift their mindset from detection to prevention, asserting that "Prevention is the goal, not just detection with good reporting.
“Lead with the mindset before the tactics,” he advises enterprises, “data loss is preventable, and that should be the mindset, not just observable.”
From DLP Rules to AI Control
Why boards are backing AI-driven DLP over static policies to cut false positives and align data protection with real business context.
This means security teams must stop enumerating every risk as a policy up front, unlike before. Policies are essential for deterministic rules, and they’re not going away. If a rule says ‘PCI data never leaves production’, but the era of managing hundreds of policies is over.
Another mindset shift is needed around false positives. Teams need to stop treating high false-positive rates as simply the cost of doing business. They're not some unavoidable force of nature. “They don't have to live with them. The problem is that when false positives become the norm, you train your team to ignore alerts—including the ones that actually matter,” he says to Dua.
And finally, enterprises need to stop staffing around the problem instead of solving it. Adding more analysts to a queue that's growing faster than your headcount isn't a scalable strategy. It's better to reduce the noise than to keep expanding the team that's trying to manage it.
As enterprises continue embracing AI, Orion's view is that the future of data security won't be defined by more dashboards or more point solutions. It will be defined by knowing where data is moving, understanding why it's moving and preventing loss before it happens.
Takeaways
- DLP tools are overwhelmed with false positives.
- AI can provide real-time contextual understanding.
- Traditional DLP systems are not equipped for modern data challenges.
- The future of data security relies on AI-driven solutions.
- Guardrails are essential for safe AI usage in enterprises.
- Real-time monitoring is crucial for effective data protection.
- Policies should be limited and focused on specific use cases.
- AI can recognise sensitive data patterns that traditional methods cannot.
- Data security must adapt to the rapid evolution of AI technologies.
- Education on new risks is vital for enterprises.
Chapters
00:00 The Evolution of Data Loss Prevention (DLP)
02:54 AI's Role in Redefining Data Security
06:12 Challenges of Traditional DLP Systems
09:02 The Need for Contextual Understanding in DLP
12:07 Guardrails for AI in Data Security
15:04 Transitioning from Policies to AI-Driven Solutions
17:54 Real-World Examples of Data Protection
20:49 The Future of DLP and Data Security
Watch the full episode of The Security Strategist podcast to hear Itay Maor, Head of Product at Orion, discuss how AI is reshaping enterprise DLP and what security leaders should act on next. Visit orionsec.io.
Comments ( 0 )