惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

A
Arctic Wolf
T
The Blog of Author Tim Ferriss
月光博客
月光博客
Recent Announcements
Recent Announcements
V
V2EX
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 三生石上(FineUI控件)
P
Proofpoint News Feed
The Register - Security
The Register - Security
博客园 - 叶小钗
博客园 - Franky
The Cloudflare Blog
雷峰网
雷峰网
罗磊的独立博客
M
MIT News - Artificial intelligence
I
InfoQ
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 【当耐特】
Engineering at Meta
Engineering at Meta
N
Netflix TechBlog - Medium
爱范儿
爱范儿
博客园 - 司徒正美
Recorded Future
Recorded Future
酷 壳 – CoolShell
酷 壳 – CoolShell
Google DeepMind News
Google DeepMind News
Martin Fowler
Martin Fowler
Microsoft Security Blog
Microsoft Security Blog
F
Full Disclosure
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
B
Blog
大猫的无限游戏
大猫的无限游戏
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
腾讯CDC
WordPress大学
WordPress大学
小众软件
小众软件
K
Kaspersky official blog
Attack and Defense Labs
Attack and Defense Labs
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Forbes - Security
Forbes - Security
aimingoo的专栏
aimingoo的专栏
IT之家
IT之家
The Last Watchdog
The Last Watchdog
N
News and Events Feed by Topic
B
Blog RSS Feed
S
Security @ Cisco Blogs
美团技术团队
量子位
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Cloudbric
Cloudbric
Hacker News - Newest:
Hacker News - Newest: "LLM"

BankInfoSecurity.com RSS Syndication

OnDemand | Why Cloud Intrusions Still Evade Detection Bank information security news, training, education Bank information security news, training, education Bank information security news, training, education Bank information security news, training, education Startup Geordie AI Lands $30M to Secure Enterprise AI Agents AI Exploit Risks Pushing Healthcare Security Shift Miasma Worm Hits Microsoft's AI Coding Ecosystem Senate Committee Leader Seeks Answers on NYC Health Hack Webinar | Securing the Agentic Enterprise: An Integrated Policy Framework for Enterprise AI Security Webinar | Securing the Agentic Enterprise: An Integrated Policy Framework for Enterprise AI Security AI Generated Code Is Expanding the Attack Surface What DORA, AI Oversight, and Cloud Dependency Mean for Business and Risk Leaders Why Hospitals Must Rethink Cyber Resilience Why The Privacy Risks of Embedded, Shadow AI in Healthcare The End of Static Security: Why AI Demands Real-Time Microsegmentation Anthropic Submits Pre-IPO SEC Filing, Leads Market Cap Fight AI Agents Are the New Insiders Demystifying Claude: Signal vs. Speculation Integrity or Innovation? Mixed Signals in Trump's Exec Orders Health Cyberthreat Sharing Is Advancing But Gaps Persist AI Is Reshaping Cybersecurity Training Priorities Claude Mythos 5 Can Build Exploits But Can't Power Campaigns Are Small Models Closing the Gap on Frontier AI Cyber Tools? Securing AI in Financial Services with Zero Trust Beyond the Inbox: Defending Against AI-Enabled Social Engineering Webinar | 6 Layers Standing Between Your Enterprise and AI Risk Webinar | 6 Layers Standing Between Your Enterprise and AI Risk How AI Governance Protects Patient Care and Sensitive Data Election Systems Are Now a Persistent Cyber Target DOJ, FBI Seize 13 Domains in Chinese Recruitment Op A Security Gets $37M to Thwart Weaponized AI With Automation Breach Roundup: CISA Says Agencies Should 'Patch Smarter' Joint Commission Certification Targets Healthcare AI Risks German Court: Google Liable for AI Summaries Google Sues Chinese Phishing Service Over Gemini Abuse Policy as Code: From Documents to Machine Intelligence Ozempic Drug Maker Loses Clinical Trial Data in Hack ISMG Editors: Anthropic Unleashes Claude Mythos 5 ISACA Survey: AI Adoption Is Rising, Visibility Is Not Anthropic Limits on OT Access to Mythos Draw Criticism Webinar | Frontier AI and Identity Security in Financial Services US Pulls the Plug on Anthropic 1Password Buys Apono to Expand AI Access Governance US Anthropic Export Controls Sparks Sharp EU Reaction GovSec Summit USA 2026: Cyber Resilience Amid Fiscal Reality Why AI Defenses Fail Without Data and Identity Fundamentals Geopolitics Is Now a Cybersecurity Problem Mythos Shutdown Contains a Message: Don ShinyHunters Hits Universities Via Oracle Zero-Day Labcorp Agrees to Pay $35M to Settle AMCA Data Breach US FCC Eases Router Ban for Cable ISPs How FDA Chinese Hacking Firm Upgrades With New Windows Backdoor South Korea Fines Coupang $409M Over Massive Data Breach Cyber Resilience Summit Dallas Prioritizes Risk Management Hacker: Restore Fable and Mythos Access, Cybersecurity Leaders Urge Live Webinar | Behind Dell’s AI Infrastructure Performance Rokarolla Android Banking Trojan Enables Device Takeover Ent Raises $100M to Reinvent Endpoint Security for AI Era The AI Accountability Gap CIOs Can Chinese Espionage Actor Abuses Email Rules to Steal Research Data AWS Unveils Continuum to Fight Vulnerability Backlog SpaceX Bets Big on AI Coding With $60B Cursor Deal Quantum-Safe Cryptography Isn Heart Monitoring Firm Tells SEC Hackers Stole Sensitive Data Mastra AI Framework Poisoned in npm Supply-Chain Attack Cyberspace Locked in a Nation-State Contest, Says NCSC CEO Webinar | The Future of SASE: Top 5 Predictions and Trends The Gentlemen Ransomware Gang Standardizes EDR Killing CISA Urges OT Resilience in Dark Remarks About Cyberattacks Attackers Steal Salesforce Data From Klue Battlecards Users Crime Gang Sells Access to 74,000 Fortinet Firewall Devices JPMorgan Pulls Anthropic Claude Access in Hong Kong Webinar | From SBOM to Submission: Operationalizing CRA Vulnerability Handling 6 Ways to Contain Enterprise Risk in Model Context Protocol Breach Roundup: ShinyHunters Leaks 26M MSG Records Accenture Buys Majority Stake in Dragos in $4.2B Deal Multimillion-Dollar Settlement Reached in MCNA Dental Hack Addressing Quantum Readiness in Healthcare Security Klue Confirms OAuth Token Theft Led to Salesforce Data Heist Cybercrime Initial Access Service SocGholish Disrupted Experts Warn of From Reflection to Shadow: AI, Us and the Space in Between ISMG Editors: Cyber Backlash Over the US Ban on Anthropic AI France and Germany Boost Digital Sovereignty Push North Korean IT Workers Try, Try, Try Again HIPAA Europe Seeks to Advance 6G Security, Privacy No Zero-Day Tied to 80,000 Harvested Fortinet Credentials Is It Time to Put Some Teeth in Post-Quantum Guidelines? New AI Model Aims to Transform Behavioral Health Lawsuits Already Getting Filed in Drug Maker Sakana AI Bets on Agent Orchestration Over Frontier Models OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses AryStinger Botnet Converts Legacy Routers to Global Proxies Trump Executive Order Accelerates Post-Quantum Security Push North Korean Hackers Poison Mastra AI Framework
AI Inherits People
Samuel Hill · 2026-06-19 · via BankInfoSecurity.com RSS Syndication

Agentic AI , Data Governance , Data Security

Your Controls Assume a Human Is Acting on the Data Being Accessed. But AI Isn't Human June 15, 2026    
AI Inherits People's Permissions but Not Judgment
Image: Shutterstock

Most enterprise security programs carry a quiet assumption: Whoever sits on the other side of a control is a person. Someone who can be trained, who pauses before acting and who, even with wide-ranging access, brings instinct to bear about what's worth opening, what's safe to share and what to leave untouched.

See Also: AI Impersonation Is the New Arms Race-Is Your Workforce Ready?

Across new CISO research on artificial intelligence and data security, leaders kept circling back to the same issue from different starting points. The person their controls were designed to govern is not who is now moving through their data. AI doesn't slow down. It doesn't screen. It doesn't quietly conclude that something is irrelevant before pulling it into memory.

What matters: AI takes on broad permissions with none of the human restraint that used to sit behind them. Every gap in a data control is now exposed to something that never hesitates.

Why Enterprise Security Controls Don't Work on AI

Every control, policy and enforcement mechanism inside the enterprise was drawn up with people in mind. People operate at human speed. They can be trained, reviewed and held to account. Even those with sweeping permissions tend to apply some innate sense of what to touch and when. A finance leader with full visibility into compensation data still won't crack open every file in the folder.

An AI agent picks up those same permissions and acts on them differently. It doesn't pause. It doesn't screen. It applies no judgment to what it pulls forward or puts to use. Point an agent at a data source and it reaches everything in range, not only the parts that matter.

The frameworks we built around human behavior simply have no vocabulary for what AI is now doing.

How Widespread Is the Non-Human Actor Problem

In a study of 124 security leaders, 90% of organizations had handed broad data access to enterprise generative AI tools, 68% couldn't say what data their agents were actually touching and 32% had unidentified agents running inside their environment.

That last figure is where most CISOs got stuck. Nearly one-third of organizations host agents that no one on the security team has ever catalogued. Those agents are reading, summarizing and acting on data using credentials that were inherited from people and written for people.

None of this is hypothetical. It's live right now.

What Does This Look Like Inside a Real Organization?

One example a CISO offered in the research captured it cleanly. An employee fed a batch of internal documents into a consumer AI tool to get them analyzed. By default, that tool allowed submitted content to be used for model training. The data was gone and nobody could say where.

There's nothing to trace here. No alert to match. No bad actor to chase down. Just an employee using a tool that did precisely what it was built to do, measured against a policy framework that assumed a person would be the one choosing what to share. The judgment layer was absent because the framework was never built to expect its absence.

Data estates that were never fully classified turn into wholesale, instant exposure the moment an agent is aimed at them. AI doesn't create that exposure. It was sitting there. AI just renders it visible at machine speed, to systems that bring no human sense of what should and shouldn't surface.

What Does Data Security at AI Speed Actually Require?

The actor inside your data estate isn't always a person anymore. Sometimes it's an inherited credential with a large language model behind the wheel. Sometimes it's an agent your IT team signed off on last quarter. Sometimes it's a sanctioned generative AI querying a SharePoint that was never classified to begin with.

The teams closing this gap tend to look alike. They've stretched their governance frameworks past human actors to cover non-human identities, too. They classify what AI tools are able to reach before any connection is made. And they make agent activity visible inside their environment, so they can respond to what counts instead of reconstructing it later.

What's left to do is build a data foundation that can actually be governed at the speed AI moves.

Where Do CISOs Go From Here?

The non-human actor problem is just one thread in a larger pattern. This research surfaced seven core insights into how data trust decides whether AI projects land or fall apart. The full report, The Impact of Data Trust on AI Success, works through all seven, with direct quotes from security leaders and a clear set of recommendations for governing AI without putting the brakes on the business.