惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
CERT Recently Published Vulnerability Notes
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
V
Visual Studio Blog
Stack Overflow Blog
Stack Overflow Blog
aimingoo的专栏
aimingoo的专栏
C
Check Point Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
T
Tor Project blog
P
Proofpoint News Feed
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Latest news
Latest news
L
LINUX DO - 热门话题
罗磊的独立博客
T
Tenable Blog
The Hacker News
The Hacker News
美团技术团队
N
Netflix TechBlog - Medium
V
Vulnerabilities – Threatpost
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
博客园 - 司徒正美
Jina AI
Jina AI
Cyberwarzone
Cyberwarzone
云风的 BLOG
云风的 BLOG
S
Secure Thoughts
Cloudbric
Cloudbric
S
Security @ Cisco Blogs
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Security Blog
Microsoft Security Blog
Spread Privacy
Spread Privacy
U
Unit 42
雷峰网
雷峰网
C
CXSECURITY Database RSS Feed - CXSecurity.com
Webroot Blog
Webroot Blog
爱范儿
爱范儿
博客园 - 【当耐特】
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
P
Palo Alto Networks Blog
Google Online Security Blog
Google Online Security Blog
The Last Watchdog
The Last Watchdog
博客园 - 聂微东
Help Net Security
Help Net Security
Hacker News: Ask HN
Hacker News: Ask HN
F
Full Disclosure
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
S
Security Affairs
Project Zero
Project Zero

Blog

CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike CrowdStrike Why AI Projects Stall and How CIOs Can Respond | CrowdStrike CrowdStrike Leads 2026 Frost Radar for Cloud Runtime Security CrowdStrike Expands Identity Leadership with OpenID and IDPro CrowdStrike 2026 Report: China Fuels Attacks on Tech June 2026 Patch Tuesday: Updates and Analysis | CrowdStrike CrowdStrike and Zscaler Bring Continuous Identity Security to Zero Trust Access 3 Principles to Safely Scale Agentic AI | CrowdStrike ISO 42001:2023 and the New Reality of Cloud AI Data Risk How to Stop AI-Driven Data Loss | CrowdStrike CrowdStrike and NVIDIA Bring Enterprise-Grade Security to AI Factory CrowdStrike and NVIDIA Collaboration Scales AI-Native Agents Secure Shadow AI at the Control Plane with Falcon for IT CrowdStrike Named Leader in 2026 Gartner Magic Quadrant for Endpoint Protection Shadow AI: The Hidden Risk Expanding Across the Enterprise CrowdStrike Named a Leader in Identity Threat Detection and Response Inside CrowdStrike’s Takedown of a Developer-Targeting Botnet Measuring AI-Enabled Success: 3 Trackable KPIs New Claude Integration Brings Audit Data to Falcon Platform How to Protect Identities and Sessions from Infostealers Now Live: CrowdStrike 2026 Financial Services Threat Landscape Report Falcon AIDR Detects Threats at Prompt Layer in Kubernetes AI Apps May 2026 Patch Tuesday: Updates and Analysis | CrowdStrike AI Threat Detection with Automated Leads | CrowdStrike CrowdStrike Named a Leader in Gartner Magic Quadrant for Cyberthreat Intelligence CrowdStrike Launches Falcon OverWatch for Defender CrowdStrike Technical Risk Assessments Reveal Common Exposure Patterns Tune In: The Future of AI-Powered Vulnerability Discovery Defending Against CORDIAL SPIDER and SNARKY SPIDER CrowdStrike Expands ChatGPT Enterprise Integration CrowdStrike Named a Leader in 2026 Frost & Sullivan Radar for CNAPP CrowdStrike Expands Real-Time CDR to Google Cloud CrowdStrike Falcon Cloud Security Delivers 264% ROI CrowdStrike Falcon Platform Achieves 441% ROI in Three Years CrowdStrike Introduces Shadow AI Visibility Service How Defenders Must Respond to Frontier AI | CrowdStrike Frontier AI for Defenders: CrowdStrike and OpenAI TAC April 2026 Patch Tuesday: Updates and Analysis | CrowdStrike How CrowdStrike Accelerates Exposure Evaluation Against Threats | Blog STARDUST CHOLLIMA Likely Compromises Axios npm Package Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Detecting CVE-2026-20929: Kerberos Relay Attack via DNS CNAME Abuse How Charlotte AI Agentworks Fuels Security's Agentic Ecosystem CrowdStrike Flex for Services Expands Access to Elite Security Expertise Falcon Data Security Secures Data Wherever It Lives and Moves CrowdStrike Advances CNAPP with Adversary-Informed Risk Prioritization CrowdStrike Services and Agentic MDR Put Agentic SOC in Reach
CrowdStrike
CrowdStrike · 2026-07-09 · via Blog

AI governance is a key enterprise concern. Organizations are assembling councils, publishing principles, rolling out “approved AI tools” lists, and asking employees to opt in to acceptable use policies. In most enterprises, however, the reality is that AI is already widely embedded in employees' daily work, often outside sanctioned channels and oversight. The visibility and control mechanisms needed to govern AI use are immature or nonexistent.

The result is a widening gap between what leadership desires for AI governance and what’s happening inside their organizations. CIOs must turn to technology guardrails capable of transporting AI governance intent from the realm of policy principles to the world of production environments, with scalable visibility and enforcement.  

Shadow AI Is the Default

Visibility is among the biggest challenges in AI governance: A recent survey found 45% of employees have used AI tools for work without informing their manager.1 Shadow AI can take many forms, including AI-enabled web apps, browser extensions, desktop apps, and SaaS platforms. 

Shadow AI isn’t just a compliance problem — it’s a serious security and data exposure problem. Employees may paste sensitive data into chatbots, connect critical business accounts to AI-enabled workflows, grant AI applications excessive permissions, or expose proprietary corporate files to AI agents. Every AI connection creates a new identity relationship that organizations must understand and govern. A study published earlier this year found more than half of employees admit to connecting third-party AI tools with other work systems without IT department approval or oversight.2

Traditional governance and security controls weren’t built to observe and interrogate the new AI prompt and agentic interaction layer, nor were they designed to continuously evaluate the identities and permissions behind those interactions.

AI Policy Demands a Collaborative Approach

Legal and privacy teams are essential to the development of AI policy, but they can’t be the only authors. AI governance isn’t only about what’s allowed. It’s about what’s possible in the architecture, what’s safe in the threat model, and what’s useful to the business. Effective AI governance requires these stakeholders at the table:

  • Business and product owners to align governance to outcomes, so controls don’t simply block innovation but shape it toward trusted, compliant, high-value use cases
  • IT and security leaders to define threat scenarios (e.g., prompt injection, model supply chain risk, agent autonomy), establish controls, and ensure detection and response can extend to AI workflows
  • Engineering leaders to weigh in on architectural possibilities and limitations and commit to implementing guardrails where they matter: strong identity controls, continuous authorization, logging, segmentation, safe tool use, and secure-by-default patterns in apps that call models

Determining AI governance policy is still a work in progress for many organizations. With multiple stakeholders and rapidly changing technology, it can be tricky to achieve alignment. An IBM study conducted last year found nearly two-thirds (63%) of organizations lacked AI governance policies.3 Even among organizations that reported having AI governance policies, more than half reported they lacked both approval processes for AI deployments and the technologies needed to enforce governance policy. 

The success of AI governance depends on operationalization. Few organizations today have the means to assess adherence at scale, detect violations, and continuously prove their guardrails are working. A policy that can’t be enforced becomes an artifact — useful for signaling intent but unreliable as a risk management mechanism. AI governance must become measurable: What AI tools are being used? Where is data going? Which models are connected to which business processes? Which human and non-human identities can invoke those models, access sensitive data, or delegate actions to downstream systems? What’s the rate of policy exceptions, and are those exceptions becoming the norm?

AI Agents Raise the Governance Stakes 

As AI technology rapidly changes, AI governance becomes harder. We’re moving from users asking questions of chatbots to the deployment of full-fledged AI agents that can plan, take actions, call tools, and chain tasks together.  

These agents multiply both impact and risk. They can touch more systems, execute more steps, and make more decisions faster than traditional oversight loops. Risks can go beyond bad answers to unintended actions: sending data externally, changing records, triggering financial transactions, or interacting with third parties in ways no one anticipated.

Each AI agent operates as an identity, and they rarely operate alone. They increasingly function as part of an identity chain — a sequence of humans, agents, applications, APIs, and data stores connected through delegated trust. This creates implications for identity governance. Identity can no longer be treated as a point-in-time decision. As AI agents operate continuously, inherit permissions, invoke APIs, and interact with multiple systems, identity must become a continuously evaluated security signal based on real-time context.  

The AI agent ecosystem evolves on a nearly daily basis. In the latest wave of open-source momentum, projects like OpenClaw have gained attention as developers experiment with increasingly capable agentic frameworks. Whether a given framework becomes businesses’ standard or not, the broader trend is clear: Capabilities are diffusing rapidly, and governance must account for AI tools that employees can adopt in an afternoon.

A Strategic Opening for CIOs and CISOs

Organizations that govern AI with discipline can scale it with confidence and move faster with fewer do-overs, fewer operational and security incidents, and greater credibility with customers, auditors, and regulators. CIOs, in close partnership with CISOs, are uniquely positioned to lead. Governance without security is hollow, and security without business and operational alignment fails to deliver durable outcomes.

Leaders can focus on three practical moves:

  1. Enforce technical guardrails. Define what must be technically enforced (data classification rules, approved model endpoints, least-privilege access, authentication, logging, token controls, prompt and output handling) and what can be guidance. Then invest in the controls that make enforcement real.

  2. Treat AI governance like an operational program. If AI governance is reviewed annually, or even quarterly, it’s already stale. Set and lead a weekly or monthly cadence with security, engineering, and business stakeholders to review adoption, incidents, exceptions, and new capabilities.

  3. Define metrics and automate measurement. Governance should be provable. Track the number of AI tools in use, sanctioned vs. unsanctioned usage, sensitive data interaction rates, policy exception volume, agent deployments, and mean time to detect/respond to AI-related events. Automate collection wherever possible.

AI is moving too fast for more static, document-driven governance approaches of the past. Organizations that treat AI governance as theater will be surprised by shadow AI, agent sprawl, and incidents that were preventable. The enterprises that build guardrails grounded in visibility, identity, and continuous enforcement will earn something far more valuable than compliance: the ability to scale AI with confidence.

Additional Resources

1. Gusto, Is AI Coming for My Job? A Look Inside America’s Workplace Anxiety and What Employers Need to Know, July 14, 2025

2. BlackFog, BlackFog Research Reveals Rising Shadow AI Risks, Jan. 27, 2026

3. IBM Cost of a Data Breach Report 2025: The AI Oversight Gap