惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Security Affairs
S
Secure Thoughts
P
Proofpoint News Feed
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
S
Schneier on Security
V
Vulnerabilities – Threatpost
Security Archives - TechRepublic
Security Archives - TechRepublic
T
The Exploit Database - CXSecurity.com
A
Arctic Wolf
Latest news
Latest news
Hacker News - Newest:
Hacker News - Newest: "LLM"
AI
AI
T
Troy Hunt's Blog
H
Heimdal Security Blog
美团技术团队
Webroot Blog
Webroot Blog
P
Proofpoint News Feed
Hacker News: Ask HN
Hacker News: Ask HN
Google DeepMind News
Google DeepMind News
P
Privacy & Cybersecurity Law Blog
U
Unit 42
Google DeepMind News
Google DeepMind News
V2EX - 技术
V2EX - 技术
G
Google Developers Blog
N
News and Events Feed by Topic
Project Zero
Project Zero
The Register - Security
The Register - Security
N
Netflix TechBlog - Medium
IT之家
IT之家
月光博客
月光博客
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
N
News and Events Feed by Topic
Simon Willison's Weblog
Simon Willison's Weblog
L
Lohrmann on Cybersecurity
Schneier on Security
Schneier on Security
博客园_首页
Help Net Security
Help Net Security
AWS News Blog
AWS News Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
S
Security @ Cisco Blogs
PCI Perspectives
PCI Perspectives
Cisco Talos Blog
Cisco Talos Blog
C
Cybersecurity and Infrastructure Security Agency CISA
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Docker
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
阮一峰的网络日志
阮一峰的网络日志
Spread Privacy
Spread Privacy
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Hacker News
The Hacker News

informationweek

2026 tech company layoffs How Sedgwick scaled AI in legacy claims workflows InformationWeek Podcast: CTOs on using AI in regulated spaces How top CIOs are measuring the real ROI of IT automation What AI must learn from Roosevelt, conservation and 1929 Experian's chief innovation officer gleans AI gains with startup collab ETS CIO on competing with AI startups 'running with scissors' Before the next VMware: How CIOs prepare for vendor shocks The strategic alignment powering cyber-resilient organizations The AI infrastructure bottleneck is becoming a CIO problem InformationWeek Podcast: CTOs on reining in rogue AI agents Workplace equity in the age of AI Why and how to implement an AI asset rationalization strategy Why companies are shifting toward private AI models AI agents in automation: When to build, when to buy Navan CTO AI on trial: The Workday case that CIOs can The AI infrastructure boom is coming for enterprise budgets How CIOs can manage LLM costs: A practical guide What CIOs miss when buying vertical SaaS software InformationWeek Podcast: How CTOs balance AI and their teams Whirlpool, Duke Energy, Cleveland Clinic CIOs on scaling AI Where CIOs get stuck rebuilding the enterprise: What 'Rewired' reveals As AI makes projects harder to track, will CIOs need new controls? Why disaster recovery plans fail in geopolitical crises A silent erosion of enterprise AI by data poisoning Priceline CTO prioritizes engineers able to 'hold a room and a roadmap' InformationWeek Podcast: When CTOs need to restart IT projects Wayfair CTO maps agentic path across digital and brick-and-mortar commerce The AI contract gaps the Google-Pentagon deal just made visible Non-human identity sprawl is agentic AI's real risk Anthropic's Mythos forces a rethink of vulnerability management Outsourcing contracts weren't built for AI. CIOs are renegotiating now The AI spend hangover companies didn't plan for The power of CIO networking in the competitive AI world Why CIOs see AI projects stall: Speed without structure kills scale IT leaders should never let a good crisis go to waste SFO's digital twin maps airport operations from the curb to takeoff CIOs caught in the middle as AI startups disrupt vertical Saas Submit an IT Leadership column to InformationWeek Podcast: Rightsizing AI frameworks to avoid failure modes The invisible labor crisis inside IT: AI work the org chart can't see Why AI teams treat training data like capital Ask the Experts: How CIOs can identify and overcome cultural barriers to innovation Nobody told legal about your RAG pipeline -- why that's a problem Meta's new 'AI Zuckerberg' is a mirror for every C-suite Will the music stop for AI's funding dance? Rethink tech talent: Local is the smartest play for IT InformationWeek Podcast: Catching errors in AI-powered code CIOs can combat talent scarcity with AI-augmented leadership -- Gartner How Bellevue, Wash., is applying AI to streamline a broken permitting process Ignore the hype: Smarter tech bets at speed of change Who controls the fix? Colorado's repair fight tests CIO power Ask the Experts: The red flags that signal an AI project isn't worth pursuing The hidden high cost of training AI on AI Red Hat's Marco Bill: Resource control is key for AI sovereignty InformationWeek Podcast: New IT architecture, cloud, edge and AI Enterprises need Tier 1 provider relationships to deliver on AI How CIOs run and rebuild the business at the same time in the AI era It's not your tech stack, it's your structure -- fix it Confidential computing resurfaces as security priority for CIOs FinOps: Helpful tool, or a cloud control placebo for CIOs? Cleveland's open data overhaul: From sticky notes to public dashboards Why build vs. buy doesn't fit modern IT systems InformationWeek Podcast: Is quantum computing slumbering? Your AI vendor is now a single point of failure Vibe coding: Speed without security is a liability A practical guide to controlling AI agent costs before they spiral AI fuels a new wave of technical debt The sunsetting of Sora: A hard lesson in AI portfolio resilience HP pushes broad internal AI use after early productivity gains Why value-based pricing is inevitable InformationWeek Podcast: Safeguarding ecosystems from outsiders Why AI scaling is so hard -- and what CIOs say works Humans are the North Star for AI-native workplaces -- Gartner How IT leaders build a culture for what comes next Compliance costs risk widening the AI gap AI-driven layoffs add new demands on CIOs to prove value AI transformation: Early wins are not enough for CIOs Why CIOs can't let users wait on IT Memory shortage doesn't have to spell disaster for IT budgets Accelerate AI adoption: 3 reasons for adopting MCP How techno-nationalism is complicating IT resilience and supply chains for CIOs InformationWeek Podcast: Compliance crackdown on AI and BYOD Workday’s AI reset: Agents and the race to remake SaaS Why enterprise AI initiatives keep dying before production Metrics of meaning: What do we really measure in AI? Techno-nationalism is reshaping CIO infrastructure strategy Using AI to pick team leaders -- without crossing legal or ethical lines What Oracle's layoffs reveal about running IT with fewer people Chief AI Officer on course-correcting when AI moves too fast Large enterprises need high-performing networks to scale AI InformationWeek Podcast: When do smaller AI models make sense? The future belongs to AI-driven IT Ways AI supercharges risk awareness and data insights for CIOs How automation prepares you for agentic NetOps Should the CIO, CFO or CEO hold the kill switch on AI? The CIO's new mandate: Redesign work itself Ask the Experts: CIOs say they wouldn’t pull workloads back from the cloud How AI is Reshaping the Enterprise
As Microsoft expands Copilot, CIOs face a new AI security gap
2026-04-02 · via informationweek

Earlier this week, Microsoft expanded its Copilot capabilities with new features designed to provide a persistent AI co-worker across enterprise workflows. These features combine multiple AI models and operate continuously inside the tools that employees already use. At the same time, Google has continued rolling out AI functionality inside its Chrome product that can interpret and act across multiple tabs -- effectively turning the browser into an execution layer rather than a passive interface.

Individually, these announcements look like incremental product updates. Taken together, they signal a more meaningful shift. Today's AI is not confined to discrete tools that users open and close. It is becoming embedded in the environments where work happens -- observing, interpreting and increasingly acting on information in real time.

For CIOs, this shift introduces a new kind of security problem -- not because AI creates entirely new risks, but because it now operates in a place that most enterprise security programs have not been designed to govern -- the interaction layer.

Related:Will the music stop for AI's funding dance?

A model built around data movement

Modern enterprise security is built on the assumption that risk can be controlled by managing access and tracking data movement. Identity systems determine who can access what. Data loss prevention (DLP) tools monitor where information goes. Endpoint and network controls enforce boundaries around both.

That model still holds, but it is no longer complete.

The most immediate concern is also the most familiar. As explained by Dan Lohrmann, field CISO for public sector at Presidio, users are already feeding sensitive information into AI systems as part of everyday work: "Users paste sensitive content -- source code, customer records, incident details, internal strategy documents -- into chat prompts because it feels fast and informal." 

In many cases, those interactions happen outside approved workflows, when users access personal accounts on company devices; this creates what Lohrmann described as a persistent shadow AI problem.

But focusing on what users input into AI systems captures only part of the risk. The more consequential change is what happens next.

Shape-shifting data

AI does not simply move data: It reshapes it. Edward Liebig, CEO of OT SOC Options -- a consortium of operational technology cybersecurity professionals -- explained that this distinction is often overlooked. Enterprises have spent years building controls around data movement, but AI introduces risk through the transformation of that data; it summarizes, recombines and reinterprets information in ways that are difficult to track.

Related:The hidden high cost of training AI on AI

"What is changing with AI embedded into browsers, email and workflow tools is not just how data moves, but how context is constructed, and how decisions are influenced," Liebig said.

That shift creates scenarios that fall outside traditional detection models, he warned. A sensitive report summarized into bullet points may no longer match classification rules. Multiple low-risk data sources, when combined, may produce a high-risk conclusion. Outputs may reflect internal strategy or operational logic, even without containing any original data.

"AI doesn't need to exfiltrate data to create exposure," Liebig said. "It can infer it."

Cameron Brown, head of cyber threat and risk analytics at insurance company Ariel Re, is also concerned about this new security gap. Traditional controls are built to detect clear signals: files leaving a system, data being copied or transferred. But AI-generated exposure is subtler.

"AI doesn't always leak data in obvious ways," Brown said. "It summarizes, reshapes, hints, infers. Suddenly that 'leak' doesn't look like a leak at all."

Authorized access, but unintended outcomes

Related:Red Hat CIO Marco Bill: Resource control is key for AI sovereignty

If data transformation were the only issue, existing DLP controls could evolve to address it. But AI introduces a second, more complex problem: risk emerging from activity that is fully authorized.

"At the interaction layer, the primary risk is not unauthorized access," Liebig said. "It is authorized use producing unintended outcomes."

Identity and access management (IAM) systems can determine whether a user is allowed to access a data set. They cannot determine how an AI system will interpret that data once accessed, or how it will be combined with other inputs.

"IAM solves for access," Liebig said. "It does not solve for outcome."

That gap becomes even more significant as AI systems are integrated into enterprise environments. Lohrmann pointed out that linking AI tools to systems such as CRM platforms, ticketing tools or code repositories effectively creates a new operator with the user's permissions -- one capable of querying and synthesizing information across multiple systems.

"The AI is a force multiplier for access," Lohrmann said.

The implication is not just broader access, but also more powerful and less predictable use of that access. In other words, a security nightmare.

The browser as the control gap

Where these interactions take place is just as relevant as how they happen. AI is increasingly embedded in the browser and productivity layer; the same environment where users authenticate into systems, access sensitive data, and interact with external content. That makes the browser a central point of exposure, yet one that has historically been overlooked from a security perspective.

"The browser didn't become the weakest link," Liebig said. "It simply exposed a layer we never governed." 

Enterprises have spent years instrumenting networks, endpoints and identity systems. Far fewer have invested in governing the interaction layer where users and AI systems now converge. Brown is blunt about the implications. 

"It's where most AI interactions happen, yet it's treated like the least interesting part of the stack," he said. "That's backward. It should be ground zero."

Lohrmann agreed, noting that embedded assistants and extensions often operate with weaker controls and less visibility than traditional enterprise applications.

The problem is compounded when users operate outside of enterprise-managed environments. Employees introduce security risks by using personal accounts on corporate devices, where data shared with AI tools may be stored outside corporate systems and beyond the reach of audit and response processes, Lohrmann said.

A visibility challenge then emerges: "Model histories pile up, business intel gets tangled in them and good luck to any forensic team trying to unwind that overcooked spaghetti," Brown said.

Extending control beyond access

None of these developments make existing security controls irrelevant. Identity management, endpoint security and DLP remain essential. But they are not sufficient to address the risks introduced by AI.

Traditional monitoring approaches are limited by what they are designed to detect, Brown explained. "Traditional DLP still does its job catching the obvious stuff," he said. But AI-driven exposure often falls outside those patterns, requiring a shift toward monitoring behavior and intent, rather than just data movement.

Enterprises need a new layer of control, one that extends beyond access into how AI systems use and transform data, Lohrmann said. "IAM generally answers 'who are you?' and 'what can you access?'" he said. "AI adds 'how is data used and transformed?'"

That shift implies new requirements: visibility into prompts and outputs, tighter control over how AI tools connect to enterprise systems, and more granular oversight of how AI-generated outputs are used in decision-making.

Taken together, these changes point to a broader evolution in enterprise security, one that does not replace traditional controls but extends them into a layer that has, until now, been largely ungoverned. Monitoring where data goes is no longer enough if its meaning can change without visibility. Controlling access is insufficient if the outcomes of that access cannot be validated.

"We are moving from a world of data protection to a world of decision assurance," Liebig said.

About the Author

Madeleine Streets

Senior Editor, InformationWeek

Madeleine Streets is a senior editor at InformationWeek, where she shapes stories and contributes news analysis through a CIO lens. 

She comes to InformationWeek from TechTarget’s Learning Content team, in which she authored explainers and features on a range of enterprise IT topics. Before moving to the field of enterprise technology, Madeleine spent several years covering retail, consumer finance, and ecommerce technology for fashion trade publication Footwear News. She has also been published in Women’s Wear Daily, TIME, Associated Press, SELF, and Observer, among others. The thread that ties her coverage together is a commitment to honest, impactful storytelling -- and insatiable curiosity.

Outside of writing, Madeleine can be found studying wine, singing in her local choir, and working her way towards her annual reading goal of 100 books. She is based in New York City, US.