Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Varonis: Why AI Adoption Exposes Sensitive Data and How to Fix It

Varonis
08/01/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


I'm very pleased to be joined by Matt Locke, Field CTO at Varonis. Really good to see you, Matt. Thank you for having me. So we're talking about securing sensitive data in the age of AI, and you've just released a report, The State of Data Security. It reveals some alarming figures. 99% of organizations have sensitive data exposed to AI tools. So what does that tell us about the state of AI security today? Yeah, it's an alarming stat, so nothing that comes as any surprise, really. I think, more than anything, it highlights the speed of which AI is being adopted, and the lack of progress with traditional IT security functions. A lot of companies are realizing now that to roll out AI, it's going to highlight issues and risks that perhaps they've been ignoring and not addressing for years, and AI is fundamentally bringing that to the forefront. I want to dig deeper for a bit. So why do so many organizations find themselves in this sort of vulnerable position? Yeah, well, it's because traditionally, organizations don't adopt a data-centric focus on security. I think too many organizations are still looking at perimeter-based security, maybe trusting internal employees, and unfortunately, AI will utilize all of the permissions that an employee has, and if they're not addressed, if they're open, if they're exposed, inevitably, AI will utilize all of that. Yeah. Well, we hear a lot about shadow IT, but what about shadow AI? It's becoming a growing concern, employees using apps without approval. What makes this such a big risk to manage, I suppose, a difficult risk, and what are the other risks that companies are taking on? Yes, of course. It's a massive blind spot for a lot of companies. I think AI, particularly Gen AI, the co-pilots, the GPTs, they are incredibly consumer-friendly. They're designed to be consumer-friendly. I think in our personal lives, we're using them more and more, and so it's inevitable, I think, that individuals are going to start realizing that they can be more productive, get things done using AI. Lack of investment or focus in organizations means that they run the risk of these tools being used. There's no software needed. There's no logon needed. You can open up a browser and start using AI, and the risks are potentially huge. There is no real visibility of what's going on. Employees don't really understand the risks of putting sensitive information into AI. We've seen it before where PII, source code, are being uploaded into these AI tools to be able to make them more effective, and that information is gone. It's lost. Unfortunately, once it's left, it's very hard to retrieve and get it back. It's inevitable that those models will start to use that sensitive information to train themselves and get better. As organizations really think about providing these tools to the employees, they will find a way, and they will start to use them. We've heard about shadow IT for a long time. Shadow AI really is a massive risk to a lot of companies, and so they need to think about making it available, thinking about sanctioned AI. At least they have some chance of having some visibility, some control, and some governance about how they're being used. I want to ask you about automating data controls because many organizations still hesitate in racing automation. Why do you think this is? What's in their way? Well, there's a number of reasons. I think if you speak to an IT security team, they would happily, readily admit that automation is going to make things like data security challenges that much easier, but there's the worry and the risk of having any adverse effects. IT typically don't want to be seen as the bad guys. If I remove access from a particular file, or a site, or a particular data set from an employee and they can't perform their job, they can't share it, they can't process, then IT really are going to face the wrath of that organization. Automation has somewhat been a bit of a terrifying aspect for a lot of companies. They'd like to have change control. Really it comes down to a lack of visibility, a lack of context. I think if organizations want to tackle, for example, AI security and data security, they need to have context of what's important, what's sensitive. They need to be able to get high levels of confidence that these automation policies are going to do what they need to do. They're not going to have an adverse impact. Maybe start by running it in order only mode. Maybe thinking about running some policies around low-risk environments, just removing superfluous access or stale accounts. IT can run low-level automation policies to gain confidence, but most importantly, they can then take that information and share it with the C-level, the board, to show them the gains that they've made in reducing risk. There has been no impact on the business. It's about building confidence. I think with the sprawl of data that we have nowadays and the amount of permissions that have been generated all the time, it's inevitable that we have to adopt a level of automation. I think we're getting there slowly, but it's about context, it's about visibility, and it's about confidence on anything. Who owns the data in the organizations that you work with? What are the patterns you're seeing there and who owns it currently, but also who should own the data? It really depends on who you ask. I think most organizations realize now that the business owns the data. Can provide the frameworks to make sure that it's procured and provisioned and managed and backed up and all that stuff, but I think they recognize that the business do own the data. The business understands the value of the data. They should ideally understand who should have access to it. There's a whole educational thing that we need to keep doing to explain the risks of making mistakes and oversharing, but fundamentally, it is the business that own the data. There are more risks introduced with that type of thing. The business really want to adopt an open model of a collaboration and sharing. If you ask the business to decide who gets access, they'll be very willing to make sure everybody can do their job. You speak to IT and they're very much from a compliance, a security, a risk perspective, they want to lock it down. It's a happy medium. How do you strike that balance? How do you strike that balance? A lot of it is education. It's really about implementing guardrails, fundamentally. I think with the move to collaboration platforms, for example, as we all went into lockdown, the adoption of collaboration made these businesses function during that time. In essence, what we did is we made the decision somewhat unknowingly to allow the business to make decisions on who get access to data. IT relinquished that control. We're not getting it back anytime soon, but the business want to implement guardrails. They want to say, you can share and you can collaborate and do the productivity gains that you're seeing, but we're going to put some policies in place just to protect you, us, the business, our customers, our clients. If somebody shares something really sensitive, financial information or credential information with the whole organization, we're going to take that away. We're going to lock that down. We're not going to come and step on your toes and take away all of that productivity that we've become used to. Yeah, there has to be an educational piece, there has to be some guardrails, but we also have to trust the business that they know who should have access to it. We've spoken a lot about the risks of AI, but I want to end on a positive note. Have you got examples of organizations actually getting AI adoption right? Yes, absolutely. There are examples. Thank God there are examples. I think what is common amongst the organizations that have done this is that they have adopted a data-centric view to applying security controls. They're looking at things like policy-based access, so making decisions to say, well, marketing can have access to collateral about proposals and things they want to put on, but they can't have access to the PII. It makes it a little bit easier to then adopt things like AI solutions. Companies that are readily adopting these technologies are doing it successfully in a way where they understand what information can be fed into these platforms, they're ensuring that LLMs or whatever models they're building aren't learning from data sets they shouldn't be learning from, there's a lot of visibility, there's governance in place, there are committees set up to ensure that it's being used properly. It's about safely adopting these new technologies. They are going to be part and parcel of what we do in the future. The companies that don't typically do so well are the ones that say, no, we're not using it, we're locking it down, and then shadow AI creeps in, and then before you know it, information is leaking before you even think about rounds of actually securing it. It's those organizations that take a data-centric, policy-based approach that are actually reaping the rewards of running AI. Well, Nat, this has been really insightful. Thank you so much for sharing your expertise today. No problem. Thank you very much. I've been speaking with Matt Lark of Varonis, and for ISMG, I'm Anna Delaney.

TL;DR

  • 99% of organizations have sensitive data exposed to AI tools, not because AI created new vulnerabilities but because it highlights existing permission and access control problems that were never addressed.
  • Shadow AI represents a massive blind spot—employees can use consumer-friendly AI tools without any software or credentials, potentially uploading PII and source code that becomes permanently lost to external systems.
  • Organizations hesitate to automate data controls due to fear of business disruption, but starting with low-risk automation like removing stale accounts can build confidence and demonstrate value to leadership.
  • Companies successfully adopting AI take a data-centric, policy-based approach with clear governance, while those that simply ban AI tools see shadow usage and data leakage anyway.

AI Adoption Reveals Long-Standing Data Security Gaps

This interview with Matt Locke, Field CTO at Varonis, examines findings from their State of Data Security report showing that 99% of organizations have sensitive data exposed to AI tools. Locke explains this alarming statistic reflects not a new problem but rather the rapid pace of AI adoption exposing security issues that organizations have ignored for years. The fundamental challenge is that most companies still rely on perimeter-based security rather than data-centric approaches, and AI tools will utilize every permission an employee has—including excessive or outdated access rights that were never properly addressed.

Shadow AI and the Automation Hesitation

The discussion highlights shadow AI as a massive blind spot for organizations. Consumer-friendly AI tools like co-pilots and GPTs require no software installation or special credentials—employees can simply open a browser and start uploading sensitive information including PII and source code. Once data enters these external AI systems, it's effectively lost and may be used to train models. Locke advocates for sanctioned AI programs that provide visibility and governance rather than outright bans that drive shadow usage. On automation, he notes that IT teams hesitate to implement automated data controls due to fear of business disruption, but argues that starting with low-risk automation policies—like removing stale accounts—can build confidence while demonstrating risk reduction to leadership.

Chapters

0:00 - Introduction and Report Findings
1:02 - Why Organizations Are Vulnerable
1:34 - Shadow AI Risks
3:39 - Automating Data Controls
5:45 - Data Ownership Challenges
8:06 - Successful AI Adoption Examples

Key Quotes

0:43 "A lot of companies are realizing now that to roll out AI, it's going to highlight issues and risks that perhaps they've been ignoring and not addressing for years, and AI is fundamentally bringing that to the forefront."
2:38 "There is no real visibility of what's going on. Employees don't really understand the risks of putting sensitive information into AI."
4:33 "Really it comes down to a lack of visibility, a lack of context. I think if organizations want to tackle, for example, AI security and data security, they need to have context of what's important, what's sensitive."
7:27 "They want to say, you can share and you can collaborate and do the productivity gains that you're seeing, but we're going to put some policies in place just to protect you, us, the business, our customers, our clients."

FAQ

Why does AI adoption expose so much sensitive data?

AI tools utilize all the permissions an employee has access to. Most organizations have accumulated years of excessive permissions, stale accounts, and overshared data that were never properly addressed. AI adoption doesn't create these vulnerabilities—it highlights and exploits existing access control problems that perimeter-based security approaches have failed to address.

How should organizations balance data security with business productivity?

The key is implementing guardrails rather than lockdowns. Allow business users to share and collaborate for productivity gains, but put policies in place that automatically detect and remediate high-risk sharing—such as when someone shares financial or credential information organization-wide. This approach maintains productivity while protecting sensitive data without requiring IT to manually approve every access decision.


Categories:
  • » Webinar Library » Varonis
  • » Data Protection » Backup & Recovery
  • » Cybersecurity » Data Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • AI & Machine Learning
  • Data Privacy
  • Data Protection
  • Compliance & Governance
  • Executive Briefing
  • AI data security
  • Shadow AI
  • Data-centric security
  • Access control management
  • Security automation
  • Data governance
  • Collaboration platform security
  • Data ownership
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Varonis: Why AI Adoption Exposes Sensitive Data and How to Fix It

              Industry Events (Sponsor Hosted)

              • Aug
                03

                Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.

                08/03/202611:00 AM ET
                • Aug
                  06

                  Safeguarding Sensitive Data in the Era of Public AI Platforms

                  08/06/202604:00 AM ET
                  • Aug
                    06

                    AI Agents Revolutionizing Identity Attacks: Same Tactics, Enhanced Speed

                    08/06/202602:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/03/2026
                      11:00 AM
                      08/03/2026
                      Discover DLP Memories: The ever-evolving triage agent enhancing efficiency each shift.
                      https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-ever-evolving-triage-agent-enhancing-efficiency-each-shift/
                    • 08/06/2026
                      04:00 AM
                      08/06/2026
                      Safeguarding Sensitive Data in the Era of Public AI Platforms
                      https://www.truthinit.com/index.php/channel/2058/safeguarding-sensitive-data-in-the-era-of-public-ai-platforms/
                    • 08/06/2026
                      02:00 PM
                      08/06/2026
                      AI Agents Revolutionizing Identity Attacks: Same Tactics, Enhanced Speed
                      https://www.truthinit.com/index.php/channel/2064/ai-agents-revolutionizing-identity-attacks-same-tactics-enhanced-speed/
                    • 08/13/2026
                      12:00 PM
                      08/13/2026
                      Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                      https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                    • 08/19/2026
                      12:00 PM
                      08/19/2026
                      Becoming Agent Ready: Insights and Strategies with Cyera
                      https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version