N

News

Half your team is using AI. Can you see what it can access?

How much access does AI already have to your environment?

Verizon’s 2026 Data Breach Investigations Report found that 45% of employees now use AI regularly on work devices, up from 15% a year earlier. Among those users, 67% access AI through personal accounts that their employer does not control.

Shadow AI is now the third most common non-malicious insider action in Verizon’s data loss prevention dataset, a fourfold increase in one year. Across 858,440 events, source code was the information most often submitted to external AI models. Australian intellectual property is part of that flow.

IBM’s 2026 Cost of a Data Breach Report found that breaches involving shadow AI more than doubled to affect 43% of breached organisations, up from 20%. The average cost reached USD 5.39 million.


AI Risk Now Extends Beyond the Chat Window

Staff still paste information into unapproved tools, but AI can now read repositories, connect to business systems and take actions through agents.

Three changes matter:

  • Personal accounts hide business use. Blocking an AI service does not remove demand. It can push staff towards personal accounts and unmanaged devices, leaving the organisation with less visibility.

  • Coding assistants process more than a prompt. They can read source code, configuration files and credentials across a repository. That access explains why source code leads Verizon’s list of data submitted to external models.

  • AI agents can act. Agents can query records, trigger workflows and use connected systems with persistent permissions. A risky prompt may expose data. An over-permissioned agent can expose systems.


You Can’t Protect AI Use You Can’t See

Most AI activity happens in a browser, coding tool or connected application. Traditional controls may not show which services are being used, what information they receive or what an agent can access.

A policy cannot answer those questions, and a blanket ban can drive activity onto personal accounts. Effective governance starts with visibility: which tools are in use, who uses them, what data they handle and what actions they can take. Controls can then match the user, data and risk instead of treating every use case the same.


Prompt Security Closes the Visibility Gap

Prompt Security is our core AI security offer, delivering central visibility and protection across workplace AI. Powered by SentinelOne, it discovers approved and unapproved tools, inspects prompts and responses, and enforces policies in real time. This helps protect sensitive information, govern AI use and reduce risk without slowing productive work.

  • AI tool discovery. Find approved and unapproved AI tools, coding assistants and services, and see who is using them.

  • Real-time data protection. Inspect prompts and responses, then block, redact or anonymise sensitive information before it leaves the environment.

  • Policy-based controls. Set rules by user, team, tool and data type so approved activity can continue while higher-risk use is restricted.

  • AI application security. Test custom applications for prompt injection, jailbreaks, data poisoning and unsafe outputs throughout development and production.

  • Agent and MCP security. Discover AI agents and Model Context Protocol servers, review what they can access and keep a searchable record of their activity.

  • Audit and compliance. Record AI interactions, policy decisions and security events for governance, investigations and reporting.


Everyone Is Using AI. It’s Time for Visibility and Protection.

Join us and SentinelOne for a free one-hour webinar on finding shadow AI, protecting sensitive information and applying practical controls without stopping responsible adoption.

The session will cover where shadow AI appears across staff, teams and developers; what information may be exposed; why blanket bans reduce visibility; and how risk changes when AI applications and agents can act on business systems. Register HERE.


Find Out What AI Can Access

Request a free AI Security Briefing and uncover which AI tools are being used across your organisation, what information they can access and where stronger controls are needed.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.