惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Blog — PlanetScale
Blog — PlanetScale
博客园 - 司徒正美
Vercel News
Vercel News
F
Fortinet All Blogs
月光博客
月光博客
G
Google Developers Blog
博客园 - Franky
GbyAI
GbyAI
The Cloudflare Blog
I
InfoQ
雷峰网
雷峰网
WordPress大学
WordPress大学
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
T
The Blog of Author Tim Ferriss
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 聂微东
小众软件
小众软件
腾讯CDC
B
Blog
量子位
V
V2EX
S
SegmentFault 最新的问题
Google DeepMind News
Google DeepMind News

Cyera Research

PostGREShell: The database powering much of the internet had an open door for 12 years Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning Sandcastles, Not Sandboxes: How One Architectural Flaw Exposed Seven Products Breaking Local AI Runtimes: 10 vulnerabilities in the Engine Behind Your Open-Source Models The Hidden Attack Surface of Agentic AI: Securing AI Agent Integration Platforms The Helpful Agent Problem: When AI Good Intentions Become Security Incidents Agent-Inflicted Damage: Inside the Real-World Failures of Enterprise AI Systems Proto6: The Schema Was Not Supposed to Run Four New OpenClaw Vulnerabilities: When AI Agents Become the Attacker's Execution Layer The End of Volume-Based Severity: Rebuilding Risk Assessment with AI That File in Teams? Your Entire Organization Might Be Able to Access It The Long-Lived Risk of Malicious OAuth Applications: A Practical Threat Hunting Guide for M365 Escaping the Guest: How Custom LLM Workflows Uncovered Critical VMSVGA Vulnerabilities From Prompt to Exploit: Cyera Research Discloses Command & Prompt Injection Vulnerabilities in Gemini CLI The New Data Breach Playbook: How ShinyHunters Exploit Access The Data Taxonomy Illusion: Why Security Teams Are Solving the Wrong Problem Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama SplitSSHell - When a Comma Becomes Root How a Single Character Broke OpenSSH Certificate Authentication Compromise Once, Breach Everywhere. ‍The Age of Mega-Supply Chain Attacks Top 10 Notable Data Security Risks in AWS Environments Top 10 Data Security Risks on Microsoft 365 Environments One Megabyte to Root: How a Size Check Broke Docker’s Last Line of Defense LangDrained: 3 Paths to Your Data Through LangChain, the World’s Most Popular AI Framework Ni8mare  -  Unauthenticated Remote Code Execution in n8n (CVE-2026-21858) 96% of Enterprise Permissions Go Unused. AI Agents Won't Leave Them That Way. When Language Becomes the Attack Vector: The Lethal Trifecta of AI Agents DESTRUCTURED - Critical Vulnerability in Unstructured.io (CVE-2025–64712) Assessing the Top Data Security Risks in AWS Environments Detection Is Fast. Understanding Is Not. Why File-Access Incidents Stall - and How Impact Clarity Changes the Outcome The OpenClaw Security Saga: How AI Adoption Outpaced Security Boundaries
83% Use AI; Only 13% Have Visibility - Cyera’s 2025 State...
Cyera · 2026-02-02 · via Cyera Research

CyberSecurity Insiders in partnership with Cyera Research Labs - Cyera’s Data & AI Security research arm, surveyed 900+ IT leaders to provide the evidence customers kept asking for.

Key Takeaways: 

  • 83% of enterprises already use AI- yet only 13% report strong visibility into how it touches their data.
  • 76% say autonomous AI agents are the hardest to secure, and only 9% monitor AI activity in real time.
  • Controls lag incidents: 66% have caught AI over-accessing sensitive data, while just 11% can automatically block risky activity.

The first alert didn’t come from a SIEM. It came from a sales manager asking why an AI copilot could “magically” find a pricing deck it shouldn’t know. No exploit. No zero-day. Just default access, missing guardrails, and no one watching the prompt layer.

That story showed up again and again in the 2025 State of AI Data Security Report : AI is already threaded through daily work, but the controls that keep data safe haven’t caught up. The result is a readiness gap-use is high, oversight is low-and it’s widening at the exact edges attackers and accidents love.

From Questions to Evidence: Why (and How) We Conducted the Survey

Customers kept asking the same questions-Where do we stand vs. peers? Which guardrails are actually standard? How do we measure readiness? There was no neutral, cross-industry baseline. So, in partnership with CyberSecurity Insiders, we fielded a structured, multiple-choice survey of 921 IT and security practitioners across industries and sizes (CISOs, security leaders, architects, SOC heads, data-governance roles). Results are statistically robust (±3.2% at 95% CI). We focused on adoption and maturity, visibility and monitoring, controls at the prompt/agent edge, identity & access for AI, and governance/readiness-aligned to the OWASP Top 10 for LLM Applications

What we asked (and why)

We wanted to know if AI is being governed with the same rigor we apply to users, systems, and data. So we asked about:

  • Where AI lives (tools, models, and workflows)
  • What visibility exists (logs, real-time signals, auditability)
  • Which controls are active (prompt filters, output redaction, auto-blocking)
  • How access is granted (AI as first-class identity or “just another user”)
  • Who owns governance (and whether policy maps to proof)

Here’s What the Data Says

Adoption outpaces control. AI is mainstream-83% use it in daily work-yet only 13% say they have strong visibility into how it touches enterprise data. Most teams are still in pilots or “emerging” maturity, but usage already spans content/knowledge work and collaboration. That’s how blind spots scale.

Risk concentrates at the edges. Confidence is highest when AI is buried inside familiar SaaS. It collapses when autonomy or public prompts enter the picture. 76% say autonomous agents are the hardest to secure; 70% flag external prompts to public LLMs. Nearly a quarter (23%) have no prompt or output controls at all. That’s not a model failure; that’s a policy failure at the interface.

AI is a new identity-treated like an old one. Only 16% treat AI as its own identity class with dedicated policies. 21% grant broad data access by default. 66% have already caught AI over-accessing information (often, not rarely). And while least-privilege should be tied to data classification in real time, only 9% say their data-security and identity controls are truly integrated for AI.

AI Governance lags reality. Just 7% have a dedicated AI governance committee, and only 11% feel fully prepared for emerging AI regulation. Logs are too often post-incident artifacts; auto-blocking exists in only 11% of programs. In other words: we’re observing after the fact and enforcing by hand.

Takeaways for CISOs, Architects and Data Leaders

If you treat AI like an app, you’ll miss the real risk. If you treat it like a human, you’ll over-permission it. If you ignore the prompt/output layer, you’ll never see the leak.

Here’s the pragmatic path forward:

  1. Instrument from the first pilot
    Turn on discovery of AI tools/models, central prompt/output logging, and real-time anomaly signals (exfil attempts, jailbreaks, over-consumption). Don’t create governance debt you’ll pay for later.
  2. Harden the interface
    Default to input filtering and output redaction at gateways. Keep agent scopes narrow, require approvals for autonomy, and enforce rate limits and kill switches. Aim for auto-blocking where risk patterns are clear.
  3. Make AI a first-class identity
    Provision AI with its own identity type and lifecycle. Enforce least-privilege tied to data classification and context, continuously-not quarterly. Review and expire scopes like you would production tokens.
  4. Anchor governance to evidence
    Put a named owner on AI governance. Map policy to logs, decisions, and outcomes you can actually show (DPIAs/TRAs where applicable). Track board-level metrics: coverage, auto-block rate, over-access rate, and time to detect/contain prompt-layer incidents.

Introducing Cyera Research Labs (and what’s next)

This post inaugurates Cyera Research Labs-our research arm dedicated to clear, data-driven guidance at the intersection of AI and data security. Expect concise briefs, rapid-response analyses when the landscape shifts, and practical playbooks you can put into production. If you want the next report, tell us and we’ll share benchmarks and guardrail patterns you can use on Monday.

Final word: AI is not waiting for governance to catch up. The leaders who win won’t be the loudest-they’ll be the ones who can prove visibility, containment, and least-privilege for non-human actors, starting now.

Read the 2025 State of AI Data Security Report.