AI Is Changing Cybersecurity: Why Organisations Must Protect Their Data Now
August 3, 2026

Introduction
Artificial intelligence is rapidly moving from experimentation into everyday business operations. Employees use generative AI to summarise documents, analyse information, write software, prepare proposals and support customer interactions. Meanwhile, organisations are embedding AI into applications, cloud platforms, development pipelines and automated workflows.
The opportunity is significant. AI can improve productivity, accelerate decision-making and help organisations deliver better products and services. However, its value depends on data. AI systems need access to information to generate useful outputs, and that creates an urgent cybersecurity challenge: how can organisations use AI without losing control of their most valuable data?
This is not simply a question of protecting an AI model. Organisations must secure the entire chain of interaction surrounding it: the users submitting prompts, the applications connecting to the model, the data sources supplying context, the identities authorising access and the outputs being generated or shared.
The scale of concern is already clear. The 2026 Thales Data Threat Report found that 70% of organisations ranked the speed of change within the AI ecosystem among their leading AI-related risks. It also found that 61% reported attacks targeting their AI applications, with sensitive data emerging as the leading target. These findings reflect a broader reality: AI is not replacing established cyber risks, but it is increasing their speed, reach and potential impact. Thales 2026 Data Threat Report
Organisations therefore need to act now. Secure AI adoption begins with understanding where sensitive data exists, determining who and what can access it, and applying protection that remains effective wherever that data moves.
The Growing AI Data Exposure Problem
One of the most immediate AI security risks comes from ordinary employee behaviour.
An employee may paste a contract into a public AI assistant to produce a summary. A developer may submit proprietary source code while troubleshooting an error. A salesperson might upload customer records to help identify opportunities, while a finance employee could ask an AI tool to interpret a spreadsheet containing commercially sensitive information.
In many cases, the employee is not acting maliciously. They are trying to work faster. Yet the information may be submitted without understanding how the AI service processes it, where it is stored, whether it will be retained or which third parties could gain access.
This creates a difficult security problem. Traditional controls may monitor files moving through email, managed applications or company networks, but AI interaction can happen through web interfaces, browser extensions, embedded assistants, application programming interfaces and unsanctioned tools. Without adequate visibility, the organisation may not know that sensitive information has left a controlled environment.
Prohibiting AI outright is rarely a sustainable answer. Employees who find AI useful may turn to personal accounts or unapproved applications, creating shadow AI that is even more difficult to monitor. A more effective approach is to give people approved tools, establish clear usage policies and apply technical controls that prevent sensitive data from being exposed.
Unstructured data makes the challenge harder
The AI exposure problem is intensified by the growth of unstructured data.
Organisations hold enormous quantities of documents, emails, presentations, source code, chat histories, recordings and collaboration content. This information is spread across cloud services, software-as-a-service applications, databases, shared drives, endpoints and hybrid infrastructure.
Unlike data stored in a structured database, unstructured information can be difficult to identify and classify consistently. A presentation may contain product plans. A chat transcript may include customer details. A document with an unremarkable filename could contain commercially sensitive intellectual property.
AI makes this information easier to search, summarise and combine. That creates business value, but it also means that data which was once difficult to locate can become instantly discoverable. An AI agent with overly broad access may retrieve information from multiple systems and expose it to a user who would never have discovered those sources manually.
This is why access to an AI application cannot automatically be treated as permission to access everything connected to it. The underlying data permissions must be understood and enforced at every stage.
Governance is struggling to keep pace
Many organisations began adopting AI through small pilots led by individual teams. Governance often followed later.
The result can be a fragmented environment containing multiple models, assistants, integrations and data connections, each operating under different rules. Security teams may not have a complete inventory of the AI services in use. Legal and compliance teams may not know what information is being processed. Employees may receive broad instructions to “use AI responsibly” without practical guidance about which data is permitted.
Effective AI governance needs to answer specific questions:
• Which AI tools and use cases are approved?
• What categories of data may be submitted?
• Where are prompts, outputs and interaction logs stored?
• Can the provider use submitted information to improve its models?
• Which applications, agents and machine identities have access to enterprise data?
• How are access rights reviewed and revoked?
• Who is responsible when an AI-generated action causes harm?
• How will risky or non-compliant activity be detected?
Policies are important, but they are not enough by themselves. Governance must be supported by controls that classify sensitive information, restrict inappropriate access and create an auditable record of how data is used.
Why AI Changes the Threat Landscape
AI gives defenders new ways to analyse threats and automate security work. It also gives attackers tools for operating more quickly and at greater scale.
Cybercriminals can use AI to research potential targets, generate persuasive phishing messages, translate scams, develop social-engineering scenarios and adapt malicious content. These capabilities reduce the time and effort required to conduct attacks.
AI-generated voice, video and written content also make impersonation more convincing. An attacker may imitate a senior executive, supplier or colleague to request a payment, obtain credentials or pressure an employee into disclosing information. According to Thales, 59% of respondents to its 2026 research had encountered deepfake attacks, while 48% had experienced reputational damage associated with AI-generated misinformation. Thales: AI as the New Insider Threat
The fundamental attack methods are often familiar. Phishing, credential theft, malware and exploitation have existed for years. AI changes the economics by making these activities faster, cheaper and easier to personalise.
AI creates a new form of insider risk
Insider risk has traditionally focused on employees, contractors and partners who misuse legitimate access, either accidentally or deliberately. AI introduces another type of trusted participant: the autonomous or semi-autonomous system.
An AI agent may be authorised to read documents, update records, send messages, call external services or take actions across business applications. If the agent is given excessive permissions, manipulated through a malicious prompt or connected to poorly protected data, it can amplify a security failure across several systems.
A human user might access records one at a time. An automated agent can process thousands. A human error may affect one document, whereas an incorrectly configured workflow could expose an entire repository.
This does not mean every AI system should be treated as hostile. It means machine identities and autonomous agents require the same disciplined identity governance expected for human users—and, in some cases, stronger controls because of the speed at which they operate.
Each agent should have a clearly defined identity, a legitimate purpose and the minimum access required to perform its task. High-risk actions should require additional approval, and permissions should be reviewed as applications and business requirements change.
Data can leak through multiple routes
Information can be exposed through an employee’s prompt, an excessive data connection, an insecure application or an AI-generated response. It may also be leaked if attackers manipulate the system into ignoring its intended instructions or retrieving restricted content.
The risks extend beyond direct disclosure. AI outputs can unintentionally reveal patterns or details derived from sensitive source information. Retrieval systems can return documents to the wrong user if authorisation is not enforced correctly. Prompts and responses may also enter logs, monitoring tools or debugging environments that have different security controls from the original data source.
Organisations must therefore protect data before it enters an AI workflow, while it is being processed and after the system produces an output.
What Organisations Need to Protect
AI security programmes should begin by identifying the information that would cause the greatest harm if it were disclosed, modified, destroyed or used without authorisation.
Intellectual property
Intellectual property includes source code, designs, formulas, product roadmaps, research, pricing models and strategic plans. It is often the information that differentiates an organisation from its competitors.
Employees may upload this material because it produces more relevant AI results.
Developers, for example, can receive better coding assistance when they provide real code and system context. However, that convenience can create substantial risk if the information enters an unapproved service or is retained beyond its intended use.
Organisations should classify intellectual property, define approved AI use cases and apply protection that follows the data across cloud, SaaS and on-premises environments.
Customer and employee data
AI systems can process names, addresses, payment information, account histories, health details and other personal data. The organisation remains responsible for protecting this information and meeting applicable privacy obligations.
Before personal data is used with AI, organisations should understand the lawful purpose, minimise the information involved and assess where it will be processed. Where possible, identifying elements should be removed, masked or replaced with tokens so the AI system can perform its function without receiving the original sensitive values.
The same care should apply to employee data, including performance information, salaries, identification documents and internal communications.
Financial information
Budgets, forecasts, transaction records, payroll information, bank details and merger or acquisition plans are attractive targets for attackers. They can support fraud, extortion, market abuse and highly convincing impersonation attempts.
Financial AI use cases should have strict access boundaries and reliable audit trails. Encryption and tokenisation can reduce the exposure of sensitive values, while strong authentication can help ensure that only authorised people and systems gain access.
Operational data
Operational data includes supply-chain information, production schedules, system configurations, security logs, infrastructure diagrams and data relating to critical services.
The sensitivity of this information is sometimes underestimated because it does not always contain personal or financial records. Yet an attacker could use it to identify dependencies, locate weaknesses or disrupt operations.
As AI becomes connected to operational processes, organisations should distinguish between systems that provide advice and those permitted to take action. Autonomous changes to high-impact environments need strong safeguards, tightly scoped permissions and appropriate human oversight.
How Thales Supports Secure AI Adoption
Secure AI adoption requires more than a single security product. Organisations need coordinated controls for data, identity, applications and activity across a complex technology environment.
Through its partnership with Thales, Cybergen helps organisations protect sensitive information, strengthen access controls and improve visibility across cloud, SaaS, hybrid infrastructure and modern applications. Cybergen has joined the Thales Accelerate Partner Network, combining its intelligence-led cybersecurity expertise with Thales’ enterprise data, application and identity security capabilities.
Data discovery and classification
An organisation cannot protect information it cannot find.
Data discovery helps locate sensitive information across repositories and environments. Classification then provides context by identifying the data’s type, sensitivity and business importance. This creates the foundation for consistent policy enforcement.
Discovery should not be treated as a one-off project. Data is constantly being created, copied and moved. AI applications add further movement as they retrieve information, generate outputs and create interaction records.
Continuous discovery and classification can help organisations identify unknown repositories, find excessive exposure and determine whether sensitive data is appearing in locations or AI workflows where it does not belong.
The visibility gap remains substantial. Thales’ 2026 research found that only 34% of organisations knew where all their data resided, while just 39% could classify it fully. These figures demonstrate why data security must begin with a reliable understanding of the organisation’s information estate. Thales 2026 Data Threat Report announcement
Encryption and tokenisation
Encryption protects information by making it unreadable without the appropriate cryptographic key. It can safeguard data at rest and in transit across databases, applications, cloud services and storage environments.
The quality of key management is critical. If keys are stored alongside the information they protect or are accessible to too many users, the value of encryption is reduced. Centralised key management and clear separation of duties give organisations stronger control over who can decrypt sensitive information.
Tokenisation takes a different approach by replacing a sensitive value with a non-sensitive substitute. The original information is held separately in a protected system. An application or AI workflow may therefore use the token without receiving the underlying customer, payment or identity data.
Encryption and tokenisation can help organisations minimise the sensitive information exposed to AI. The aim is not only to defend the model itself, but to ensure that data remains protected even if an application, integration or storage environment is compromised.
Thales describes data encryption, key management, application security and identity security as the foundation of its wider AI security approach, which is designed to address risks including data leakage, prompt injection, model manipulation and insecure retrieval pipelines. Thales AI Security Fabric
Access management controls
AI makes identity central to data security.
Organisations need to verify employees, administrators, applications, service accounts and AI agents. They also need to determine what each identity may access, from which context and for how long.
Strong identity and access management can include multi-factor authentication, single sign-on, conditional access, privileged access controls and risk-based authentication. The principle of least privilege should apply to both people and machines.
An AI assistant that only needs access to approved marketing documents should not be able to search HR records. An agent preparing a financial report may need read access to selected datasets but should not automatically be able to modify transactions. Temporary workflows should receive temporary permissions rather than permanent credentials.
Controls should also recognise risk. A request from an unusual device, location or automated process may justify additional verification or a restricted response.
Compliance and governance support
Regulators and customers expect organisations to understand how sensitive data is collected, accessed, protected and retained. AI does not remove these responsibilities.
Data discovery, classification, encryption, tokenisation and access controls help establish evidence that appropriate safeguards are in place. Centralised policy management and audit records can also simplify reporting, investigations and compliance assessments.
Technology alone cannot determine whether every AI use case is legally or ethically appropriate. However, it can provide the visibility and control needed to enforce governance decisions consistently.
Why Visibility Matters More Than Ever
Security teams need to understand how data moves through AI-enabled environments.
That includes identifying where data originates, which systems retrieve it, which identity requested it, whether it was transformed and where the output was sent. Without this context, an isolated event may appear harmless even when it is part of a larger pattern of risky behaviour.
Monitoring can help identify activity such as:
• Large volumes of sensitive information being submitted to an AI service
• An AI agent accessing systems outside its normal role
• Repeated attempts to retrieve restricted data
• A user suddenly adopting multiple unapproved AI tools
• Sensitive outputs being copied into public or personal applications
• Service accounts operating from unexpected locations
• Privilege changes that give an AI workflow unnecessary access
Visibility should lead to proportionate action. Low-risk activity may simply require logging.
More concerning behaviour could trigger a warning, stronger authentication, a blocked transaction or investigation by the security team.
This approach gives organisations a better opportunity to intervene before an incident becomes a breach.
Balancing Innovation and Security
The objective is not to slow AI adoption. It is to create the conditions in which adoption can happen safely.
If controls are too restrictive or difficult to use, employees will search for workarounds. If there are no meaningful controls, the organisation may gain short-term speed while accumulating data exposure, compliance problems and operational risk.
A balanced programme gives employees approved AI services that are easy to access and appropriate for their work. It explains what information can be used, provides safe alternatives for sensitive use cases and builds security into normal workflows.
Practical steps include:
1. Discover current AI use. Identify approved and unapproved tools, integrations, agents and data connections.
2. Map and classify sensitive data. Establish where critical information resides and which AI use cases may access it.
3. Prioritise use cases by risk. A public-content writing assistant does not require the same controls as an agent connected to financial or operational systems.
4. Apply least-privilege access. Give users, applications and agents only the data and actions required for their defined purpose.
5. Protect sensitive values. Use encryption, tokenisation and masking to reduce exposure throughout the AI lifecycle.
6. Monitor activity continuously. Look for unusual access, unauthorised tools, sensitive prompts and risky data movement.
7. Create clear employee guidance. Policies should use practical examples and provide a simple route for requesting approved capabilities.
8. Review controls regularly. AI services, integrations and threats change quickly. Governance must evolve with them.
Security is most effective when it enables a trustworthy route to innovation. Employees should not have to choose between productivity and compliance.
Protect the Data That Makes AI Valuable
AI is becoming part of the way organisations operate, compete and serve their customers. That makes its security inseparable from data security.
The organisations best positioned to benefit from AI will be those that know where their sensitive information resides, understand how it moves and control every human and machine identity that can access it. They will protect data with encryption and tokenisation, monitor activity across environments and embed governance into the technologies employees use every day.
Waiting until after sensitive information has been exposed is not a viable strategy. AI can magnify existing weaknesses too quickly, and the volume of data involved continues to grow.
Cybergen and Thales help organisations build a practical, data-centric approach to secure AI adoption—combining specialist cybersecurity guidance with enterprise capabilities for data discovery, classification, protection, application security and identity control.
Learn how Cybergen and Thales can help your organisation adopt AI securely, protect sensitive data and maintain control as your AI strategy grows. Explore Cybergen and Thales security solutions.
Ready to strengthen your security posture? Contact us today for more information on protecting your business.
Let's get protecting your business
Thank you for contacting us.
We will get back to you as soon as possible.
By submitting this form, you acknowledge that the information you provide will be processed in accordance with our Privacy Policy.
Please try again later.
Cybergen News
Sign up to get industry insights, trends, and more in your inbox.
Contact Us
Thank you for subscribing. It's great to have you in our community.
Please try again later.
SHARE THIS









