October 7, 2026

Build AI Security Posture Management Around Usage, Not Models

No items found.

Key Takeaways

  • AI security posture management works best when it measures how people and agents use AI, alongside the models and AI cloud services an organization runs.
  • In many enterprises, AI arrives through public tools, extensions, and agents, so the posture that matters is set by prompts, uploads, and delegated actions.
  • A practical AI-SPM program starts with observed usage, classifies risk by data and use case, and swaps block lists for boundaries.
  • AI agents belong in security posture management as identities, with scoped tools, short-lived credentials, and an audit record of each action.

AI security posture management inherited a cloud playbook, but AI risk moved to the workforce

Most security leaders got the same request sometime in the last two years: get AI under control. The natural move was to reach for the posture model that had already worked for cloud, and there were good reasons to do it.

Security posture management earned its place, and cloud security posture management (CSPM) gave teams continuous visibility into misconfigured infrastructure. Data security posture management (DSPM) and SaaS security posture management (SSPM) extended the same discipline to sensitive data and SaaS settings. They were right for an era when most risk lived in what an organization configured.

AI security posture management (AI-SPM) usually carries that logic forward. In our view, most AI-SPM approaches start with models, training data, pipelines, and AI cloud services. That work matters for teams building their own models, but in our experience most enterprises consume far more AI than they build.

Independent research shows how much of that consumption happens outside sanctioned tools. The 2025 global study from the University of Melbourne and KPMG found most employees using AI at work rely on free public tools. About half of AI-using employees in the survey said they had uploaded sensitive company information to public AI tools at least once.

Those figures are self-reported, drawn from 47 countries, and collected between November 2024 and January 2025. The authors also observe AI governance has largely focused on integrating AI into products, services, and operations. They call for better governance of how employees use AI in their everyday work.

Security teams see the pattern from their side. A Gartner survey of 302 cybersecurity leaders, released November 19, 2025, found 69% suspect or have evidence employees use prohibited public generative AI (GenAI). Gartner also predicts more than 40% of enterprises will experience security or compliance incidents linked to unauthorized shadow AI by 2030.

The model inventory tells you what you built. It doesn't tell you what left the building in a prompt, pasted into a public assistant on a Tuesday afternoon.

None of this makes cloud posture work a mistake. The environment changed, and AI risk moved from the infrastructure to the workforce using it.

A usage-first posture answers four questions a model inventory can't

When the board asks how exposed the company is to AI, a count of models and AI services rarely settles the conversation. What leaders want is a description of behavior, including who's using AI, with what data, and under what safeguards.

A usage-first AI security posture is the live answer to four questions. Each one changes faster than a model inventory does, which is why they're worth tracking.

  1. Who is using which AI, under which identity? Map sanctioned and unsanctioned tools, and separate corporate tenants from personal accounts of the same tool.
  2. What data is moving? Prompts, pasted text, file uploads, and AI responses that flow back into documents all count toward exposure.
  3. What can act on someone's behalf? AI extensions, agents, and Model Context Protocol (MCP) connections can act with permissions the people who install or authorize them have granted or delegated.
  4. Which policy applied, and is there a record? Know whether each interaction was allowed, redacted, or stopped, and whether you can reconstruct it later.

The first question carries more weight than it seems, because identity decides which contract applies. A finance analyst on the company's licensed assistant and the same analyst on a personal login look identical in a model inventory. One session sits inside your contracts and retention terms, and the other sits outside them.

The third question is where helpful shortcuts become standing access. Once granted access to a webmail site, an extension installed to summarize email can read and modify the page, including the messages on screen. That's rarely what anyone approved.

These answers move daily, which changes what posture reporting looks like. Instead of an annual assessment, you get a trend line showing new tools, new tenants, and new permissions rising or falling week over week.

A usage-first view also tells you where model-level controls deserve investment. If sensitive data rarely reaches a homegrown model but flows daily into a public assistant, the priority order writes itself.

Model and pipeline posture still matters for the AI your teams build. An AI bill of materials describes what's inside a system, while these four questions describe what people do with it. The inventory becomes one input to the program rather than the whole program.

Build the AI-SPM program in five moves, starting with the AI you can already see

Most teams start an AI posture program with a policy document and a tool shortlist. Both have their place, but starting with observed usage reaches a defensible posture faster, because the policy then describes reality instead of intentions.

Here's a sequence for building an AI security posture management program around the AI already running in your environment.

  1. Discover usage at the interaction layer. Look in browsers, desktop AI apps, extensions, network egress, and endpoint MCP configurations, not only cloud accounts. Treat the first inventory as a baseline you'll compare against weekly, because it'll be incomplete on day one and the drift is the signal. Gartner's November 2025 guidance points the same direction, recommending regular shadow AI audits and GenAI risk evaluation inside SaaS assessments.
  2. Classify by data and use case, not by tool. The same AI assistant is low risk drafting a job post and high risk summarizing an M&A data room. Give each high-value use case a business owner, and let security own the guardrails rather than each individual decision.
  3. Set boundaries instead of block lists. Allow the corporate tenant, guide or block the personal one, redact sensitive data before it reaches the provider, and inspect what comes back. In our experience, block lists can push usage onto personal devices and accounts where visibility disappears. The Gartner survey above shows prohibition alone doesn't stop use. The University of Melbourne and KPMG authors note outright bans may be ineffective, though their survey data is correlational.
  4. Map controls to the frameworks you'll be asked about. The NIST AI Risk Management Framework (AI RMF) 1.0 is voluntary, organized around Govern, Map, Measure, and Manage, and currently being revised. ISO/IEC 42001 adds the AI management system layer, while the OWASP Top 10 for LLM Applications (2026 edition) keeps Sensitive Information Disclosure at number two.
  5. Measure drift and report posture as a trend. Track new tools, tenants, extensions, and agent permissions week over week. Report the movement to leadership instead of a point-in-time score, because direction tells a board more than a single number.

The second move is where programs tend to stall, and ownership is usually the reason. Security can't adjudicate each marketing, legal, and engineering use case, but it can define the data boundaries those owners work within. A short register listing each use case, its owner, its data classes, and its boundary gives auditors the same view security has.

The third move is the "say yes to AI" principle in practice. People keep the tools they find useful, and the organization keeps sight of the data flowing through them. Boundaries also produce better telemetry than blocks, since a redacted prompt leaves a record while a blocked one often reappears on a personal phone.

For EU operations, the European Commission's AI Omnibus update confirms Annex III high-risk rules apply from December 2, 2027. The Omnibus that set this timeline entered into force on July 27, 2026. The dates are the easy part; what they mean for a specific use case is a conversation for counsel.

A quarterly posture score is accurate for roughly the afternoon it's produced. A weekly trend, tied to named owners and mapped to familiar frameworks, gives leadership something they can act on.

Agents turn security posture from a snapshot into a moving target

Most teams are still mapping which employees use which AI tools, and now some of the users aren't people. Agents act with someone's permissions across apps, at a pace most review processes weren't designed to match.

The December 2025 OWASP Top 10 for Agentic Applications names Tool Misuse and Exploitation as ASI02 and Identity and Privilege Abuse as ASI03. In OWASP's words, an agent without a distinct, governed identity operates in an "attribution gap" that makes enforcing true least privilege impossible.

Manipulation is a live concern, and early lab evidence isn't reassuring. In a simulated test of one model, NIST's Center for AI Standards and Innovation found tailored attacks raised agent hijack success to 81%. The strongest baseline attack, by comparison, had succeeded 11% of the time.

Protocols haven't closed the gap on their own. The MCP authorization specification builds authorization for HTTP transports on OAuth 2.1, but the July 28, 2026 version of the spec makes it optional. Discovering and approving MCP servers therefore falls to the enterprise.

Local servers widen the gap further. For standard input/output (STDIO) connections, the spec says implementations should retrieve credentials from the environment instead. A server added to a coding assistant on a laptop can therefore sit outside central review.

The riskiest agent often isn't the one the platform team built. It's the one an employee started in a browser sidebar or a local tool in five minutes, with their full session behind it.

Inadequate risk controls are one of the reasons Gartner gives for agent project cancellations. Gartner predicts over 40% of agentic AI projects will be canceled by the end of 2027. Its June 25, 2025 release also cites escalating costs and unclear business value.

Posture controls for agents look a lot like the ones you'd apply to a contractor:

  • Inventory agents, MCP servers, and extensions alongside the human users who rely on them.
  • Give each agent its own identity with short-lived, scoped credentials.
  • Limit each agent's tools and data access to the task it was approved for.
  • Require human approval before high-impact actions like payments or deletions run.
  • Log each action against the person who delegated it.

With those controls in place, agent posture becomes something you measure each week. Without them, it's something teams tend to discover after an incident review.

The weekly drift report from the program above is the natural home for agent changes. New permissions then show up next to new tools and tenants.

One policy engine for people and agents keeps AI posture from fragmenting again

Most security stacks already carry a console for cloud posture, another for data, another for SaaS, and now one for AI. Each solved a real problem when it arrived. Together, they can recreate the visibility gaps they were bought to close, which is how the solutions became the problem.

The architectural question is where AI posture controls should live. Controls built into the enterprise browser and desktop environment see the full session, including identity, tenant, page context, data movement, and agent actions. Extensions added to existing browsers carry much of that context to browsers a company doesn't fully manage, and they complement the environment well.

Network and proxy controls see traffic and remain useful for it. They often lack the in-session context needed to tell a corporate tenant from a personal one, or a routine prompt from a sensitive one.

This is the approach behind Island Enterprise AI, which brings AI visibility, governance, and data protection into the environment where people and agents already work. Island pairs the Island Enterprise Browser with the Island Extension and Island Desktop, so coverage follows the user across browser, desktop, extensions, and network.

The four usage questions from earlier map onto this environment directly. AI Protect recognizes whether someone is working in a corporate or personal tenant, and it redacts sensitive data before a prompt reaches the provider.

On the agent side, Agentic Endpoint Posture inventories agents, MCP servers, skills, and extensions. Agentic Identity issues just-in-time credentials through the Island MCP Gateway, and people and agents run under one policy engine with one audit trail.

The goal is to say yes to AI with confidence, because the boundaries travel with the work. Island doesn't replace CSPM or DSPM for the cloud infrastructure you build and host. It reduces how many separate consoles your team needs to answer the usage questions, and it gives security one place to watch posture move.

Your AI posture is already written in how people work

If you want to pressure-test a usage-first AI posture program against your environment, we're happy to walk through what we've built. Request a demo.

FAQs

What is security posture management?

Security posture management is the continuous practice of finding and closing gaps in how cloud, data, SaaS, and AI environments are configured and used. For AI, the gaps that matter most tend to appear in daily usage rather than in configuration files.

How is AI security posture management different from CSPM and DSPM?

CSPM watches cloud configuration, and DSPM tracks where sensitive data lives. AI-SPM adds the AI layer, and a usage-first program concentrates on prompts, uploads, and agent actions neither tool was designed to observe.

What's the first step in building an AI security posture management program?

Baseline the AI your people and agents already use across browsers, desktop apps, extensions, and MCP connections. The weekly changes against that baseline will tell you more than the starting list.

Does blocking public AI tools improve your security posture?

Usually not on its own, because surveys like Gartner's find employees using prohibited AI tools anyway. Tenant controls and redaction keep AI both usable and visible.

How should AI agents fit into security posture management?

Treat each agent as an identity with scoped tools, short-lived credentials, and an audit trail tied to the person who delegated it. That way, an agent's actions can be reviewed with the same rigor as an employee's.

Island Team

Island is defining the future of work for people and AI agents. Its enterprise agentic control plane helps organizations enable, govern, and audit agentic workforces alongside people. Island boosts productivity across devices, browsers, applications, networks, and data while protecting sensitive information, simplifying access, and helping enterprises scale AI safely.