
Most security leaders got the same request sometime in the last two years: get AI under control. The natural move was to reach for the posture model that had already worked for cloud, and there were good reasons to do it.
Security posture management earned its place, and cloud security posture management (CSPM) gave teams continuous visibility into misconfigured infrastructure. Data security posture management (DSPM) and SaaS security posture management (SSPM) extended the same discipline to sensitive data and SaaS settings. They were right for an era when most risk lived in what an organization configured.
AI security posture management (AI-SPM) usually carries that logic forward. In our view, most AI-SPM approaches start with models, training data, pipelines, and AI cloud services. That work matters for teams building their own models, but in our experience most enterprises consume far more AI than they build.
Independent research shows how much of that consumption happens outside sanctioned tools. The 2025 global study from the University of Melbourne and KPMG found most employees using AI at work rely on free public tools. About half of AI-using employees in the survey said they had uploaded sensitive company information to public AI tools at least once.
Those figures are self-reported, drawn from 47 countries, and collected between November 2024 and January 2025. The authors also observe AI governance has largely focused on integrating AI into products, services, and operations. They call for better governance of how employees use AI in their everyday work.
Security teams see the pattern from their side. A Gartner survey of 302 cybersecurity leaders, released November 19, 2025, found 69% suspect or have evidence employees use prohibited public generative AI (GenAI). Gartner also predicts more than 40% of enterprises will experience security or compliance incidents linked to unauthorized shadow AI by 2030.
The model inventory tells you what you built. It doesn't tell you what left the building in a prompt, pasted into a public assistant on a Tuesday afternoon.
None of this makes cloud posture work a mistake. The environment changed, and AI risk moved from the infrastructure to the workforce using it.
When the board asks how exposed the company is to AI, a count of models and AI services rarely settles the conversation. What leaders want is a description of behavior, including who's using AI, with what data, and under what safeguards.
A usage-first AI security posture is the live answer to four questions. Each one changes faster than a model inventory does, which is why they're worth tracking.
The first question carries more weight than it seems, because identity decides which contract applies. A finance analyst on the company's licensed assistant and the same analyst on a personal login look identical in a model inventory. One session sits inside your contracts and retention terms, and the other sits outside them.
The third question is where helpful shortcuts become standing access. Once granted access to a webmail site, an extension installed to summarize email can read and modify the page, including the messages on screen. That's rarely what anyone approved.
These answers move daily, which changes what posture reporting looks like. Instead of an annual assessment, you get a trend line showing new tools, new tenants, and new permissions rising or falling week over week.
A usage-first view also tells you where model-level controls deserve investment. If sensitive data rarely reaches a homegrown model but flows daily into a public assistant, the priority order writes itself.
Model and pipeline posture still matters for the AI your teams build. An AI bill of materials describes what's inside a system, while these four questions describe what people do with it. The inventory becomes one input to the program rather than the whole program.
Most teams start an AI posture program with a policy document and a tool shortlist. Both have their place, but starting with observed usage reaches a defensible posture faster, because the policy then describes reality instead of intentions.
Here's a sequence for building an AI security posture management program around the AI already running in your environment.
The second move is where programs tend to stall, and ownership is usually the reason. Security can't adjudicate each marketing, legal, and engineering use case, but it can define the data boundaries those owners work within. A short register listing each use case, its owner, its data classes, and its boundary gives auditors the same view security has.
The third move is the "say yes to AI" principle in practice. People keep the tools they find useful, and the organization keeps sight of the data flowing through them. Boundaries also produce better telemetry than blocks, since a redacted prompt leaves a record while a blocked one often reappears on a personal phone.
For EU operations, the European Commission's AI Omnibus update confirms Annex III high-risk rules apply from December 2, 2027. The Omnibus that set this timeline entered into force on July 27, 2026. The dates are the easy part; what they mean for a specific use case is a conversation for counsel.
A quarterly posture score is accurate for roughly the afternoon it's produced. A weekly trend, tied to named owners and mapped to familiar frameworks, gives leadership something they can act on.
Most teams are still mapping which employees use which AI tools, and now some of the users aren't people. Agents act with someone's permissions across apps, at a pace most review processes weren't designed to match.
The December 2025 OWASP Top 10 for Agentic Applications names Tool Misuse and Exploitation as ASI02 and Identity and Privilege Abuse as ASI03. In OWASP's words, an agent without a distinct, governed identity operates in an "attribution gap" that makes enforcing true least privilege impossible.
Manipulation is a live concern, and early lab evidence isn't reassuring. In a simulated test of one model, NIST's Center for AI Standards and Innovation found tailored attacks raised agent hijack success to 81%. The strongest baseline attack, by comparison, had succeeded 11% of the time.
Protocols haven't closed the gap on their own. The MCP authorization specification builds authorization for HTTP transports on OAuth 2.1, but the July 28, 2026 version of the spec makes it optional. Discovering and approving MCP servers therefore falls to the enterprise.
Local servers widen the gap further. For standard input/output (STDIO) connections, the spec says implementations should retrieve credentials from the environment instead. A server added to a coding assistant on a laptop can therefore sit outside central review.
The riskiest agent often isn't the one the platform team built. It's the one an employee started in a browser sidebar or a local tool in five minutes, with their full session behind it.
Inadequate risk controls are one of the reasons Gartner gives for agent project cancellations. Gartner predicts over 40% of agentic AI projects will be canceled by the end of 2027. Its June 25, 2025 release also cites escalating costs and unclear business value.
Posture controls for agents look a lot like the ones you'd apply to a contractor:
With those controls in place, agent posture becomes something you measure each week. Without them, it's something teams tend to discover after an incident review.
The weekly drift report from the program above is the natural home for agent changes. New permissions then show up next to new tools and tenants.
Most security stacks already carry a console for cloud posture, another for data, another for SaaS, and now one for AI. Each solved a real problem when it arrived. Together, they can recreate the visibility gaps they were bought to close, which is how the solutions became the problem.
The architectural question is where AI posture controls should live. Controls built into the enterprise browser and desktop environment see the full session, including identity, tenant, page context, data movement, and agent actions. Extensions added to existing browsers carry much of that context to browsers a company doesn't fully manage, and they complement the environment well.
Network and proxy controls see traffic and remain useful for it. They often lack the in-session context needed to tell a corporate tenant from a personal one, or a routine prompt from a sensitive one.
This is the approach behind Island Enterprise AI, which brings AI visibility, governance, and data protection into the environment where people and agents already work. Island pairs the Island Enterprise Browser with the Island Extension and Island Desktop, so coverage follows the user across browser, desktop, extensions, and network.
The four usage questions from earlier map onto this environment directly. AI Protect recognizes whether someone is working in a corporate or personal tenant, and it redacts sensitive data before a prompt reaches the provider.
On the agent side, Agentic Endpoint Posture inventories agents, MCP servers, skills, and extensions. Agentic Identity issues just-in-time credentials through the Island MCP Gateway, and people and agents run under one policy engine with one audit trail.
The goal is to say yes to AI with confidence, because the boundaries travel with the work. Island doesn't replace CSPM or DSPM for the cloud infrastructure you build and host. It reduces how many separate consoles your team needs to answer the usage questions, and it gives security one place to watch posture move.
If you want to pressure-test a usage-first AI posture program against your environment, we're happy to walk through what we've built. Request a demo.
Security posture management is the continuous practice of finding and closing gaps in how cloud, data, SaaS, and AI environments are configured and used. For AI, the gaps that matter most tend to appear in daily usage rather than in configuration files.
CSPM watches cloud configuration, and DSPM tracks where sensitive data lives. AI-SPM adds the AI layer, and a usage-first program concentrates on prompts, uploads, and agent actions neither tool was designed to observe.
Baseline the AI your people and agents already use across browsers, desktop apps, extensions, and MCP connections. The weekly changes against that baseline will tell you more than the starting list.
Usually not on its own, because surveys like Gartner's find employees using prohibited AI tools anyway. Tenant controls and redaction keep AI both usable and visible.
Treat each agent as an identity with scoped tools, short-lived credentials, and an audit trail tied to the person who delegated it. That way, an agent's actions can be reviewed with the same rigor as an employee's.