惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
J
Java Code Geeks
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Jina AI
Jina AI
博客园 - 司徒正美
Stack Overflow Blog
Stack Overflow Blog
美团技术团队
L
LangChain Blog
WordPress大学
WordPress大学
A
About on SuperTechFans
Martin Fowler
Martin Fowler
月光博客
月光博客
Y
Y Combinator Blog
U
Unit 42
D
Docker
Recent Announcements
Recent Announcements
Hugging Face - Blog
Hugging Face - Blog
B
Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
G
Google Developers Blog
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog Ransomware Didn't Slow Down in Q2 2026. It Just Spread Out. - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog Your AI Governance Policy Should Survive Your Next Model Change - Check Point Blog The Branding and Attribution Behind Cybercrime - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog
AI Has Moved From Assistance to Action. Is Your Security ...
lizwu@checkpoint.com · 2026-06-24 · via Check Point Blog

There is a quiet shift happening inside enterprise AI adoption. 

AI is no longer just something employees ask for help. It is becoming something the business asks to do work. Employees use public AI tools. Developers build with model providers. Business units adopt copilots. Internal teams embed AI into customer-facing applications. Agents retrieve data, call APIs, invoke tools, and take steps across workflows. 

That is a very different security problem. 

For a while, AI security could be treated mostly as a data governance conversation. What can employees paste into a prompt? Which tools are approved? Which models are allowed? All sensible questions. All still relevant. 

But they are not enough anymore. 

The harder question is no longer just who has access. It is what AI is doing with that access. 

And that is where things get interesting, in the same way discovering a door has no hinges is interesting. 

Adoption Is Ahead of Control 

The gap is already visible. According to the Check Point 2026 Cloud Security Report, 77% of organizations have changed their security strategy in response to AI, but only 26% say they have the architecture to enforce it. 

That 51-point gap is the story. 

AI is not staying inside one team, one platform, or one nicely labeled governance initiative. It is spreading across workforce tools, AI-powered applications, SaaS services, cloud environments, model APIs, and autonomous agents. 

Security leaders are being asked to govern something that is moving across the enterprise like water finding the lowest point. It flows through the approved channels first. Then it finds the gaps. 

This does not mean AI adoption should slow down. It means the security model has to catch up with how AI is actually being used. 

Visibility Helps. It Is Not Control. 

Most security teams know they need visibility into AI usage. Without it, governance becomes a politely formatted guess. 

But visibility is only the starting point. 

The same Check Point report found that only 5% of organizations have full visibility into AI tool usage across the organization. That means many teams are trying to govern AI without a complete picture of tools, agents, data flows, and runtime behavior. 

Even when visibility improves, the next questions are harder: 

  • What data can AI reach? 
  • What systems can it touch? 
  • What actions can it take? 
  • Which behaviors are acceptable? 
  • Where does enforcement need to happen before impact? 

Those questions matter because AI risk is no longer one surface. 

It spans employees using AI tools, applications powered by models and prompts, and agents that can act across connected systems. Each surface changes the security problem. Together, they create a governance challenge that traditional access control was not designed to solve on its own. 

Access can define what a system is allowed to reach. It does not fully define what the system is intended to do. 

That distinction matters. 

An agent can take a series of technically valid steps and still produce an outcome the business never intended. Each action may look reasonable in isolation. The result may not be. 

This is where AI governance has to move from policy to enforceable control. 

The Question for Security Leaders 

The question is not whether the business will use AI. It already is. 

The question is whether security teams can give the business confidence to use AI safely across the places where it is being adopted: workforce tools, AI applications, and autonomous agents. 

That requires a different operating model. One that starts with discovery, turns governance into enforceable policy, validates AI systems continuously, and protects behavior at runtime. 

The full AI Security Governance Framework goes deeper into that model. It explains how to think about AI risk surfaces, what governance has to cover, and which evaluation questions security leaders should ask before AI activity becomes too distributed to manage cleanly. 

AI is now part of how enterprises work. Increasingly, it is part of how enterprises act. 

Security needs to meet it there. 

Download the full AI Security Governance Framework to learn how to govern AI behavior across platforms, workforce tools, AI applications, and autonomous agents.