WitnessAI

Ask a CISO who owns the service account running last night’s batch job, and you’ll often get a shrug. That gap is the story of non-human identity. A non-human identity (NHI) is a digital identity assigned to software, from the service account behind a batch job to the AI agent running a workflow on its ... Read more » The post What is non-human identity (NHI)? appeared first on WitnessAI .

A single prompt inside an IDE, CLI, or agentic session can push source code, credentials, and regulated data past the enterprise boundary before anyone reviews it. In healthcare and financial services, that traffic often touches code paths already covered by HIPAA, PCI DSS, and secure-development controls. The problem is that most browser-centric, packet-based, and legacy ... Read more » The post…

An AI acceptable use policy identifies the AI tools employees, contractors, and AI agents may use, defines acceptable use, governs the data shared with AI systems, and establishes accountability for AI interactions. It also assigns responsibility for incidents. Your employees aren’t waiting for that document. Many employees already use AI without approval. This limits your ... Read more » The pos…

MCP architecture allows AI agents to reach enterprise file systems and databases. It can also connect them to SaaS platforms using credentials that many identity programs may not have in their inventory. The Cloud Security Alliance reports that regulators are increasingly requesting agent control logs. The design choices that accelerated adoption also created activity many ... Read more » The pos…

Think of MCP as the shipping container of enterprise AI. Before standardized containers, every port improvised its own way of loading cargo, and every route carried its own risks. Once the container arrived, global trade moved faster, but customs, inspection, and chain of custody had to catch up. MCP is doing the same thing for ... Read more » The post What is the Model Context Protocol (MCP)? ap…

Physician use of AI and ambient documentation tools has moved from early experimentation and pilot programs to daily clinical workflow. Clinicians paste patient details into consumer chatbots that carry no business associate agreement, and autonomous agents query EHR data using privileges provisioned for human users. Healthcare AI security has not kept pace with that adoption ... Read more » The …

AI governance responsibilities in Global 2000 enterprises rarely rest with a single executive. Ask who owns them, and you may hear several confident answers: the CISO, the CIO, the Chief AI Officer, legal, or compliance. Those answers often diverge when ownership isn’t written down. That gap becomes visible when regulators ask for named authority and ... Read more » The post Who is responsible fo…

Untrusted content in an email can prompt an enterprise AI system to share data outside its intended scope. EchoLeak showed how that can happen. Microsoft assigned CVE-2025-32711 to EchoLeak, a zero-click attack triggered by a crafted email. Microsoft 365 Copilot pulled data from OneDrive, SharePoint, and Teams and sent it out through a trusted Microsoft ... Read more » The post Prompt injection e…

Your employees are pasting contracts, source code, and customer records into chatbots right now. Your existing security stack likely has significant blind spots into these AI interactions. That’s the gap AI DLP (AI data loss prevention) is built to close. It treats the prompt-and-response channel as a governed surface rather than a blind spot, reading ... Read more » The post What is AI DLP? Data…

WitnessAI
11d ago

DeepSeek’s R1 model drew immediate attention after its January 2025 release. Since then, “is DeepSeek safe?” has become a standing question for CISOs, risk officers, and compliance leaders at large enterprises. If you’re fielding that question every week, you know the answer shifts with each deployment path. DeepSeek’s own privacy policy states that user data ... Read more » The post Is DeepSeek …

Perplexity Enterprise secures its side of the platform. Learn where responsibility shifts to you, and how to close consumer-tier and Comet risk gaps. The post A guide to Perplexity security appeared first on WitnessAI .

AI runtime security is the inspection and enforcement of policy on AI activity as it happens. It covers AI conversations and agent tool calls, from the prompt an employee sends to the response a model returns. It operates during live AI use, after deployment reviews have finished, when written policies need an enforcement point. AI ... Read more » The post What is AI runtime security? appeared fi…

WitnessAI
18d ago

The Model Context Protocol (MCP) is the open standard that lets AI agents discover and call external tools and data sources, such as APIs. In enterprise governance, an MCP gateway serves as the control layer between agents and the MCP servers they connect to. It governs which tools each agent can reach and creates audit ... Read more » The post What is an MCP gateway? appeared first on WitnessAI .

Attackers split harmful prompts into benign fragments the model reassembles. See why keyword filters miss it and what session-level defense requires. The post What is payload splitting? appeared first on WitnessAI .

WitnessAI
19d ago

Shadow AI adds $670K to breach costs and complicates EU AI Act compliance. Learn a 5-step framework to discover, govern, and secure unauthorized AI use. The post How to prevent shadow AI appeared first on WitnessAI .

Picture the last AI incident review your team ran. Somewhere in the timeline, an agent called an API, a model summarized a document, or an employee pasted context into a chatbot, and no one could reconstruct exactly what was authorized, by whom, or against which policy. That reconstruction problem is now a board-level question. Zero-trust ... Read more » The post Executive guide to zero-trust AI …

Memory poisoning corrupts what AI agents store and retrieve across sessions, turning a single injected payload into a persistent, cross-user risk. The post How does memory poisoning in agentic AI work? appeared first on WitnessAI .

Enterprise AI adoption has outpaced the controls meant to govern it. Employees adopt tools ahead of formal approval, and autonomous agents or customer-facing chatbots can reach business areas before formal review. Many organizations struggle to answer a basic question from their board: how mature is our AI program, and which gaps need attention before AI ... Read more » The post Understanding the…

The most-used AI tool in your company probably isn’t the one you approved. It’s the one an employee opened in a personal browser tab this morning, pasted a customer list into, and closed before lunch. You’ll never see it in your SSO audit trails, and that’s the problem. Most workforces already use AI tools outside ... Read more » The post How to respond to unapproved AI tools usage appeared first…

research.ioresearch.io

Sign up to keep scrolling

Create your feed subscriptions, save articles, keep scrolling.

Already have an account?