惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
C
CXSECURITY Database RSS Feed - CXSecurity.com
S
Schneier on Security
博客园 - 叶小钗
博客园 - 三生石上(FineUI控件)
C
Cybersecurity and Infrastructure Security Agency CISA
Engineering at Meta
Engineering at Meta
Google DeepMind News
Google DeepMind News
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园_首页
T
Threat Research - Cisco Blogs
C
Cisco Blogs
Recent Announcements
Recent Announcements
S
Securelist
N
Netflix TechBlog - Medium
The Register - Security
The Register - Security
P
Privacy & Cybersecurity Law Blog
宝玉的分享
宝玉的分享
D
Darknet – Hacking Tools, Hacker News & Cyber Security
L
LINUX DO - 热门话题
T
Tor Project blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
月光博客
月光博客
AWS News Blog
AWS News Blog
P
Proofpoint News Feed
博客园 - 司徒正美
L
LINUX DO - 最新话题
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
H
Help Net Security
Spread Privacy
Spread Privacy
PCI Perspectives
PCI Perspectives
Project Zero
Project Zero
I
Intezer
T
The Blog of Author Tim Ferriss
有赞技术团队
有赞技术团队
The Last Watchdog
The Last Watchdog
C
Check Point Blog
Blog — PlanetScale
Blog — PlanetScale
B
Blog RSS Feed
MyScale Blog
MyScale Blog
V
Vulnerabilities – Threatpost
Recorded Future
Recorded Future
T
Tenable Blog
Jina AI
Jina AI
D
DataBreaches.Net
阮一峰的网络日志
阮一峰的网络日志

SECURITY.COM

Cyber Legends: The Connector 4 Application Control Updates That Help Teams Move Faster 3 Ways to Defend Against LOTL Attacks Now Spirals: New Stealthy Ransomware Deployed Against Asian IT Company Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor The Detection Gap: MITRE ATT&CK T1140 and T1105 Humble Brag: Symantec® Data Center Security Achieves Common Criteria Certification GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses Tips to Harden Your Air Gapped Environments The Visibility Challenge Nobody Asked For AV-TEST Gives Symantec® Endpoint Security Complete a Perfect Score The BYOVD Epidemic: How Attackers Are Weaponizing Trusted Windows Drivers to Kill Security 🎙️SECURITY.COM The Podcast: The Parasite in the Machine: Unmasking the Speagle Infostealer Your DLP Incident Backlog Owes You Closure Backdoor.Mistic: New Backdoor May be Linked to Ransomware Access Broker 5 Reasons Symantec® CBX Delivers Total Endpoint Visibility 8 XDR Questions From the Show Floor Another Year, Another Win: SE Labs® Recognizes Symantec® Endpoint Security Hidden in Teams: DragonForce Attackers Weaponize Microsoft Teams Relays to Stay Hidden Locking Down the Server 🎙️SECURITY.COM The Podcast: The Death of SIEM Threats Rise on a Tide of Global Unrest When Nation-States Stop Caring About Size Espionage Campaign Targeted Stock Exchange Executive for Five Months Data Security Is Having A Moment 5 Ways XDR Helps SOCs Act Faster 🎙️SECURITY.COM The Podcast: The Evolution of Cybersecurity PR with W2 Communications The Maximalism Trap: When More Becomes Too Much Symantec DLP Cloud and DPSM are the Power Couple Security Strategists Need Symantec DLP Cloud and DSPM are the Power Couple Security Strategists Need The Future of the Partnership: AI, Automation, and Ecosystems Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations 🎙️SECURITY.COM The Podcast: Iran’s Cyber Warfare Playbook: What Defenders Need to Know Right Now Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign Doing More with Less: How Government Agencies are Rethinking Cybersecurity Navigating Compliance and Insurance as a Competitive Edge Is SIEM Trying to Do Too Much? Every Defender Deserves Frontier AI The New Partner-Vendor Relationship DLP Made Easier on the Teams Running It The EU Digital Wallet: Why Waiting is Not an Option Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft Stopping Data Leaks at the Speed of AI Harvester: APT Group Expands Toolset With New GoGra Linux Backdoor How AI Increases the Load on Security Teams Web Traffic Visibility is the New Non-Negotiable The Agentic AI Tsunami is Here: Is Your Legacy IAM Sinking or Swimming? Technical Enablement vs. Marketing Noise Enterprise-Grade Security for All in 2026 Architecting for Margin Beyond the Initial Sale 🎙️SECURITY.COM The Podcast: A Brief History of Data Loss Prevention Symantec CBX Through the Paparazzi Lens The U.S. Navy’s Playbook for Cost-Controlled, Reliable Cybersecurity The Modern Threat Landscape and The Partner’s New Burden Symantec CBX Rocked RSAC 2026 Conference For Financial Services, a Wake-Up Call for Reclaiming IAM Control The Next Identity Shift Cyber Legends: Behind the Scenes of CBX Built for This Moment (and All Those to Come)
5 Ways To Keep AI in Check
About the Author · 2026-05-12 · via SECURITY.COM

2023 was the year 

AI went mainstream

. A few years into the boom and AI tools are already deeply embedded into how we work. 

9 in 10 companies report their employees use personal AI tools regularly

. From simple tasks like writing emails to powering agentic systems that execute multi-step tasks autonomously, AI has not-so-subtly become the productivity engine behind the scenes of most organizations.

But there’s no such thing as a free lunch. With its use come growing gaps in security. While personal AI use in the workplace has become nearly universal, 

only 4 in 10 companies actually have official LLM subscriptions

. Shadow AI—unsanctioned AI tool use—forces a familiar tension I often hear from security leaders, sometimes every week: either block AI and lose productivity, or allow it freely and accept risk. 

Neither extreme is ideal. Unapproved AI use slips in risks we can’t see, but outright blocking it all can take away useful productivity gains from your business. 

So how do we actually solve this paradox, especially at scale?

Enable AI—with the right guardrails in place

There it is. AI is already part of the workday, so the real challenge is giving employees room to use it without opening the door to data exposure (not to mention compliance gaps). Here are four key areas to keep usage in check:

Visibility 

Everything starts here. If you want to manage AI risk, you need a clean inventory of what’s being used across your environment. That means being able to scroll through a live list of AI applications and quickly find:

  • Which apps are in use.
  • Which users are accessing them.
  • Where they’re being accessed from.
  • What security and compliance attributes each app has.

This is where many teams get their first surprise—a long trail of unknown or sanctioned apps. Seeing which of these applications are gaining traction can also help better assess risk and prioritize the right gaps. 

Analysis   

Once you know what’s in play, the next step is understanding the surfaced risk in context. Not every AI deployment is the same. Some models may be running in approved environments, while others could’ve spawned in places they shouldn’t—like a personal device. 

Your analysis should answer:

  • Is the app enterprise-ready?
  • Does it meet compliance requirements?
  • What is the organization's readiness posture for this tool?
    Context is the difference between awareness and informed risk management. 

Real-time monitoring

Organizations need the ability to inspect activity inside AI tools like ChatGPT in real time. That includes monitoring prompts, uploads, and responses to detect when sensitive information may be exposed. 

For example, a beginning prompt flows normally, but a prompt containing sensitive data is flagged and blocked before it can even leave the enterprise, meaning it never reaches ChatGPT. Bingo.

Classification 

Some copilots and AI assistants use internal company data during inference, but without proper classification of that information there’s a risk that employees’ prompts could trigger AI to offer up information they shouldn’t have access to. 

By classifying sensitive data and applying labels through integrations such as Microsoft Purview Information Protection, organizations can make sure data is consistently identified and protected. Teams can prevent data from being used in AI inference, avoid accidental exposure through AI chat prompts, and even sanitize said data before it’s used to train models.

Often overlooked, this step is perhaps the most critical, especially as enterprises scale AI usage. 

Control 

Finally, organizations need the ability to enforce policies. Of course, this doesn’t mean blunt-force blocking. Effective teams actually rely on granular controls such as:

  • Allowing prompts but preventing file uploads.
  • Blocking high-risk applications entirely.
  • Restricting personal accounts from being used.
  • Preventing sensitive data from leaving the environment. 

Control is what makes safe AI adoption possible and sustainable. Organizations get to apply consistent rules that protect their data, while employees get to use the AI tools that make them more productive. Everybody wins.

AI and data protection don’t have to be at odds

The 

Symantec CloudSOC console 

brings all these capabilities together into one unified workflow: discovery, analysis, monitoring, classification, and control. With built-in support for two of the most used enterprise AI assistants—Microsoft Copilot and Google Gemini—organizations who deploy Symantec DLP Cloud gain real-time visibility, inspection, and enforcement across the AI tools employees actually use. 

The outcome? What every security and business leader is ultimately aiming for: employees stay productive and innovative, while sensitive data remains secure across its lifecycle. 

Watch these capabilities in action in my on-demand webinar: Securing the Proliferation of AI Applications