NEWS
Companies Built AI Into Core Systems Before Figuring Out How to Govern It
Seventy percent of organizations are running generative AI in live environments. Sixty-four percent have AI agents in pilot or production deployments, some with privileged access to core systems. More than half have already experienced at least one AI-related security incident. The infrastructure built to govern those systems arrived late, if it arrived at all.
Check Point’s 2026 Cloud Security Report confirms what security teams have been signaling for months: AI adoption outpaced the architecture needed to control it. Firms rewrote acceptable-use policies, launched governance programs, and increased budgets for AI-specific controls. They still lack the visibility and enforcement mechanisms to make those policies work at scale.
Security Teams Cannot See What Employees Use
Only five percent of organizations report visibility into the AI tools and services employees actually use. Security teams often cannot identify which tools are in play, what data enters AI workflows, or where that data moves afterward. The gap extends across endpoint monitoring, SaaS traffic inspection, and browser-based AI tools.
Paul Barbosa, VP of Cloud Security and SASE at Check Point Software Technologies, said AI adoption has outpaced the architecture built to govern it. Agents are acting inside live systems, data is moving through external AI services, and most enterprises still lack the visibility and enforcement to keep pace. Visibility, control, and security need to be present at all layers in the stack AI workloads will operate in.
The most common incidents involve unauthorized or shadow AI use, AI-generated phishing and deepfake content, and sensitive data leaks tied to AI services. Firms can detect AI-related risks more easily than they can stop them in real time. Prevention capabilities remain limited across prompts, data flows, and AI-generated outputs.

AI Traffic Is Changing Enterprise Network Patterns
Companies report increases in API-driven traffic, connections to external AI services, and east-west traffic inside hybrid environments. Existing network security tools often struggle to inspect AI-related traffic without affecting application performance. Inspection gaps remain a problem across the board.
AI infrastructure is moving closer to internal systems and regulated data. Some firms are shifting AI training and inference workloads into private cloud and on-premises environments, placing more focus on datacenter perimeter security and internal traffic inspection. The shift creates new blind spots in environments that were not designed to handle autonomous agents with privileged access.
Access Control Models Vary Widely
Approaches to governing employee access to AI services vary widely. Some rely on endpoint security tools, some apply separate rules for on-network and off-network access, and others block external AI tools entirely. Only a small percentage enforce consistent AI access controls regardless of location.
Coverage Gaps Extend Into SaaS and Browser Tools
Many firms report partial visibility into AI SaaS traffic and limited ability to control unauthorized AI applications. Coverage gaps extend into browser-based AI tools, where traditional network controls have little reach. Application-layer protections are under pressure. WAF and WAAP tools struggle with AI-specific attacks such as prompt injection, and increased false positives are becoming a problem in AI environments.
Runtime Protection Inside AI Applications Remains Immature
Few firms have broadly deployed controls for LLM inputs, outputs, and tool authorization. Many still rely on ad hoc testing for GenAI applications. Runtime security and data controls remain limited across the board.
Data governance is another weak point. Some companies permit source code in GenAI tools, and many cannot trace the flow of sensitive data through AI processing environments. AI-specific DLP (Data Loss Prevention) deployment remains low. Organizations cannot reliably track what data enters AI workflows, where it goes, or what happens to it afterward.
| Control Type | Deployment Status | Primary Gap |
|---|---|---|
| LLM input/output filtering | Limited deployment | Real-time enforcement |
| AI-specific DLP | Low adoption | Data flow tracing |
| Runtime tool authorization | Ad hoc testing | Broad coverage |
| Prompt injection defense | Struggling | False positive rate |
Firms Built Policies They Cannot Enforce
Organizations are rewriting acceptable use policies, creating AI governance programs, and increasing investment in AI-specific controls. The infrastructure needed to enforce those policies consistently does not exist. Security teams often lack insight into which tools employees use, what data enters AI workflows, and where that data moves afterward.
Only a small share can reliably distinguish legitimate AI activity from suspicious or unauthorized usage. The gap between policy and enforcement is widening as AI adoption accelerates. Firms that moved AI into production before building the governance layer are now trying to retrofit controls into live environments.
Incident Response Lags Behind Detection
Most organizations detect AI-related risks more easily than they stop them in real time. Prevention capabilities remain limited across prompts, data flows, and AI-generated outputs. The detection-to-prevention gap is a structural problem, not a tooling problem. Existing security architectures were built around human users and predictable application behavior, not autonomous agents with API access and privileged credentials.
What Happens When Agents Have Privileged Access
Some AI agents in production deployments have privileged access to core systems. Those agents rely on APIs, automation, and autonomous actions. Security architectures built around human users and predictable application behavior are struggling to keep pace.
The attack surface expands when agents can act inside live systems without human approval. Traditional access controls assume a human is making the decision. AI agents bypass that assumption. The result is a growing number of incidents tied to unauthorized actions, data leaks, and shadow AI use.
- Unauthorized or shadow AI use – employees deploying AI tools outside approved channels
- AI-generated phishing and deepfake content – attackers using AI to craft convincing social engineering attacks
- Sensitive data leaks tied to AI services – regulated data entering external AI workflows without oversight
The Bill Arrives After Deployment
Companies built AI into core systems before figuring out how to govern it. The bill is arriving now. More than half of organizations have experienced at least one AI-related security incident. The most common incidents involve unauthorized AI use, AI-generated phishing, and sensitive data leaks.
Security teams lack the visibility and enforcement mechanisms to close the gap. Only five percent report visibility into AI tools and services used inside their environments. The infrastructure needed to enforce AI governance policies consistently does not exist. Firms that moved AI into production before building the governance layer are now trying to retrofit controls into live environments while incidents continue to accumulate.
Disclaimer: This article is for informational purposes only and does not constitute security, legal, or compliance advice. Organizations should consult qualified cybersecurity professionals and legal counsel before implementing AI governance controls. Figures cited are accurate as of publication and reflect data from Check Point’s 2026 Cloud Security Report.
-
AI3 weeks agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI2 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING1 month agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
APPS1 month agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
CRYPTO1 month agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
AI1 month agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
NEWS2 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
AI2 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
