Table of contents
Highlights
- Enterprise AI security is a distinct discipline that traditional cybersecurity controls weren’t designed to address.
- Agentic AI systems introduce risks that generative AI doesn’t, including identity sprawl and autonomous cascading failures.
- Most organizations lack AI-specific governance policies, leaving predictable security gaps that attackers can exploit.
- CIOs should evaluate AI platforms on data isolation, permissioned integrations, and compliance certifications.
- Shadow AI adoption has created ungoverned data flows across most enterprise environments.
- Moveworks' AI Assistant is designed to support permissioned access through integrations with Okta, Azure AD, ServiceNow, and Workday, so the platform can surface data and take actions within each employee’s existing authorization boundaries.
AI is becoming part of more enterprise workflows, and security architecture needs to evolve with it. In fact, 77% of organizations have changed their cloud security strategy due to AI — yet only 26% report having the architecture needed to support those changes.
For CIOs, the challenge is enabling AI adoption while strengthening the security posture around it.
The business teams want to move quickly with AI, while IT is responsible for protecting sensitive data and managing new risks across workflows, tools, and systems.
Below, we’ll take a practical approach to enterprise AI security, focusing on the areas that matter most when you’re evaluating vendors. We’ll go over gaps that are easy to overlook and which capabilities to look for before selecting an AI platform.
What enterprise AI security actually means
Once AI connects enterprise data and workflows, security depends on how it’s governed, what it can access, and how its actions are reviewed. That pulls in data governance, model integrity, and identity management all at once.
It also helps to break it down into three different contexts:
- Keeping AI systems secure: Making sure models and the data behind them aren’t exposed or tampered with
- Using AI to strengthen security: Helping teams spot threats faster and respond with more context and speed
- Defending against AI-powered attacks: Dealing with more convincing, scalable threats that are getting harder to detect
They’re related, but each requires a distinct strategy. Each has its own owners and tools (and usually a different budget). When they’re treated as a single discipline, gaps can go unnoticed and investment can go to tools or priorities that only address part of the risk.
Why traditional security controls fall short for AI
Most security tools were built for environments where apps, data, and identity could be managed separately.
AI brings those domains together in a single interaction, and that’s where things become harder to manage, especially with how quickly AI trends in IT are evolving.
That’s also where risk shows up.
A recent finding shows that 97% of organizations experiencing AI-related breaches lacked appropriate access controls. That’s a clear signal that AI is often moving faster than the guardrails around it.
AI blurs the boundaries between applications, data, and decisions
AI doesn’t separate identity, data, and application logic the way traditional systems do. One prompt can pull all of these into the same flow without triggering an obvious security alert.
For example, an authorized user asks a routine question, like “Can you summarize recent customer account activity?” The AI could piece together churn risk, billing status, and support tickets from different systems, surfacing sensitive information the user may not have permission to see.
In that scenario, the issue is data exposure through an authorized workflow rather than a classic breach or stolen credential.
Agentic AI introduces risks that generative AI does not
Generative AI usually operates within a single session: answer a prompt, reset, repeat. Agentic AI can carry context across steps, move between systems, and take actions with OS-level access at machine speed.
That changes what “risk” looks like in practice. The risk shifts from output quality alone to actions that can move across tools and workflows. So it’s no surprise that 80% of organizations report risky behaviors from AI agents.
Five enterprise AI security gaps to evaluate
Most AI platforms look solid on paper. The gaps tend to show up when they’re connected to real data, users, and workflows. We’ll explore five areas you can stress-test how security holds up once AI connects to real enterprise data, users, and workflows.
1. Shadow AI and uncontrolled tool adoption
Shadow AI has already become part of how many employees get work done. Around 57% of employees use personal GenAI accounts for work, and 33% have already entered sensitive information into them.
In the most AI-heavy enterprises, that adds up fast. Teams might use 300+ GenAI tools, most of them outside IT’s visibility.
In many cases, employees are reaching for tools that help them move faster, making it harder to track what data is going where.
2. Identity and access management for AI agents
AI agents often need access to multiple applications to get work done. But that can spread permissions across systems, making it harder to track what access is active and where it’s being used.
Many of these tools still operate in a trust-by-default mode. So if an agent’s credentials are compromised, the exposure may extend across connected systems and quickly widen that blast radius.
3. Prompt injection and adversarial inputs
Prompt injection is already showing up in real-world LLM apps. Around 67% of deployed applications have at least one exploitable prompt injection issue.
That means someone can embed instructions the model wasn’t meant to follow, like text telling it to ignore prior rules and reveal restricted data.
With agentic AI, it can get more serious.
Injected instructions can trigger unintended actions across systems. So a malicious input in a support chat could prompt an agent to update a ticket automatically or compromise employee data.
4. AI supply chain and third-party model risks
Most AI systems are built from different components that carry their own risks:
- Pre-trained models: Backdoors or bias that carry into outputs
- Open-source libraries: Hidden vulnerabilities, like tampered dependencies
- Third-party APIs: Compromises that expose data or alter responses
They can make things faster, but it also means you’re relying on underlying components you didn’t build or control.
A compromised component can introduce vulnerabilities into your application.
AI-generated code also requires security review. While code generation is improving quickly, generated code can still introduce vulnerabilities that need human validation. It’s a reminder that “it works” and “it’s secure” aren’t always the same thing.
5. Compliance frameworks that haven’t caught up
Many teams are still figuring out governance while AI Tools are already in use. Around 63% of breached organizations either don’t have an AI governance policy yet or are still building one.
At the same time, companies are trying to map AI to a growing set of security frameworks, including:
- NIST AI RMF
- ISO 42001
- EU AI Act
- GDPR
- CCPA
- HIPAA
AI doesn’t sit neatly inside any one of them, which can create ownership gaps when teams need to review an AI-driven action, output, or decision.
How to evaluate AI security posture as a CIO
For CIOs, the real test is what happens after an AI platform moves from the demo environment to the enterprise stack. That’s where security architecture either holds up or starts to show gaps, especially with agentic AI that can take actions across environments.
The criteria below can help you evaluate AI solutions in practice and identify security issues early.
Data isolation and permissioned integrations
AI should only access what a user’s already allowed to see, helping protect customer and employee data. That starts with role-based access tied to your identity provider (such as Okta or Azure AD), so permissions don’t get recreated or drift inside the AI layer.
The same principle applies to integrations. When connections with tools like ServiceNow, Workday, Salesforce, and Slack or Teams are properly scoped, the AI platform is better positioned to operate within existing authorization boundaries and reduce the risk of exposing data outside the intended access model.
Governance controls and audit trails
Good governance gives teams visibility into what AI is doing across systems and workflows. The right platform gives you an ongoing view of AI activity, with monitoring, audit trails, and alerts when something looks out of the ordinary.
You can quickly see:
- What data the AI accessed
- What actions it took
- Who approved each workflow
When questions come up, this record helps teams understand what happened without having to reconstruct activity after the fact.
Compliance certifications to look for
Certifications are one way to compare security claims with documented security practices. When you’re evaluating AI platforms, check for industry-relevant certifications like:
- ISO 27001
- SOC 2 Type II
- HIPAA
- GDPR
- FedRAMP
Relevant certifications can signal that security and compliance were considered in the platform’s design and operating model. That can support enterprise risk management and help internal teams evaluate compliance obligations more efficiently.
How Moveworks approaches enterprise AI security
The more work AI can do, the more important it is that each action stays within the guardrails your business has in place. That’s why Moveworks was built with a secure-by-design, privacy-by-design architecture rather than treating security as something to add later.
At the center is the Reasoning Engine, which can act as the intelligence layer across enterprise systems. It integrates with tools like Workday, ServiceNow, Okta, Azure AD, Slack, and Teams while operating within each employee’s existing permissions.
With Search + Action, employees can do more than find information. They can complete approved tasks with defined governance boundaries.
Built-in security capabilities include:
- Encryption in transit and at rest
- Role-based access controls
- Logical tenant separation
- Multi-tenant microservices architecture designed for secure data isolation
- Audit logging and traceability
- AI safeguards, including content moderation and risk assessment frameworks
Beyond the core standards mentioned earlier, Moveworks also maintains additional certifications, including:
- ISO 27017
- ISO 27018
- ISO 27701
- CSA STAR Level 2
- GDPR alignment
- CCPA alignment
As AI takes on more enterprise work, the platform underneath it matters just as much as the AI itself. That means looking beyond features and seeing how the platform is designed to operate across real enterprise systems, permissions, and workflows.
Explore how Moveworks supports enterprise-grade AI security.
Frequently Asked Questions
The most significant risks include shadow AI adoption without IT oversight, AI agents operating with overly broad permissions, prompt injection attacks that can trigger autonomous actions, and AI supply chain vulnerabilities from third-party models and open-source dependencies. Each of these risks can compound if organizations lack governance frameworks designed specifically for AI systems.
Agentic AI operates autonomously at machine speed, executing tasks, calling APIs, and making decisions without human intervention for each action. This introduces risks that generative AI does not, including chained vulnerabilities across agent workflows, identity sprawl from broad cross-environment permissions, and untraceable data leakage from agent-to-agent communication. Traditional security controls built for human-speed interactions may not detect these issues in time.
Several frameworks now address AI-specific security requirements. The NIST AI Risk Management Framework provides voluntary but widely adopted guidance organized around four functions: Govern, Map, Measure, and Manage. ISO/IEC 42001 establishes AI management system requirements, and the EU AI Act has phased enforcement timelines. Existing regulations like GDPR, CCPA, and HIPAA also apply to AI training data and outputs.
Shadow AI refers to AI tools that employees adopt without IT oversight or security review. Research suggests that a majority of employees use personal GenAI accounts for work, and many input sensitive information into unapproved tools. This creates ungoverned data flows, unmanaged compliance exposure, and areas that security teams cannot monitor or protect.
CIOs should assess three areas: data isolation (whether the platform enforces role-based access aligned with existing identity providers), governance controls (automated audit trails, anomaly detection, and visibility into what data AI accesses), and compliance certifications (ISO 27001, SOC 2 Type II, HIPAA, GDPR, FedRAMP). Platforms where security is architecturally built in tend to reduce both risk and compliance burden over time.
Prompt injection is one of the most prevalent vulnerabilities in deployed LLM applications. Attackers craft inputs that override an AI model's instructions, potentially extracting sensitive information or triggering unintended actions. With agentic AI, this risk escalates because compromised agents can send emails, modify data, or pivot across connected enterprise systems autonomously.