Opens in a new tab
vmblog logo 2024 wht (updated)

Stop Governing the AI Tool, and Start Governing the Data

Share: 

start governing the data

By Jonathan Kreiner, Co-Founder and CTO, ORION Security

When it comes to company-wide AI use, most security leaders have already moved past the ban-or-allow debate. They’ve weighed in on AI enterprise tool decisions, reviewed the data processing agreements and confirmed the vendors won’t train on company data, and published usage guidelines. On paper, that closes the loop: employees have a sanctioned way to use AI, and security has a policy to point to.

If only that were enough to stop sensitive data from leaking.

The AI tool isn’t the variable that matters most. AI features are now in all sorts of apps, whether it be the note-taker inside the video conferencing platform, the summarization feature in the CRM, or the writing assistant in the document editor, and many arrive through things that don’t naturally flag a security review. They show up as product updates to software already inside the perimeter. A governance program built around a list of approved AI tools can’t catch what it never gets a chance to evaluate, making efforts to govern AI tool by tool a losing race.

The Data Doesn’t Care About the Tool

Flip the question. Instead of asking which AI tools are allowed, ask what happens to the data once it moves, no matter which tool, feature, or agent picks it up along the way.

A piece of source code, a customer record, or an unreleased financial figure carries the same risk whether it passes through the AI product security vetted last quarter or a summarization feature a vendor added last week. The data doesn’t know the difference, but many governance programs still act as if it does.

The starting point for a data loss prevention program in today’s world has to be knowing what your sensitive data actually is, where it lives, and where it goes once someone, or something, starts moving it. Data that originates in a source code repository or a regulated customer database carries risk everywhere it travels afterward, whether that’s  through a sanctioned AI tool, an unreviewed one, or five hops between.

Knowing the type of content alone won’t get you there either. A finance employee running numbers through an AI planning tool during a routine budgeting cycle is normal. The same figures, pulled during a securities blackout period and headed toward a tool with no clear data retention terms, is a very different event. The data hasn’t changed but the context around it has: who’s moving it, when, and where it’s headed. It’s that context that determines whether the data movement is routine activity or a real incident.

Supporting a Data-First AI Program

If you want to best support AI use within your organization while doing your job as a security leader, take these steps:

  • Classify data in motion, not as a prerequisite project. Source code, PHI and PII, unreleased financials, legal documents, and core IP can be recognized the moment someone tries to move them, without a sweeping initiative to locate and label everything at rest first. That’s a different bet than a classic data-discovery project: waiting for a full inventory to finish before governance starts is a bet that AI adoption will slow down and wait for you. It won’t.
  • Follow the data wherever it goes. Track lineage from the moment sensitive data is created through every system it passes, so a leak is visible no matter which AI feature, sanctioned or not, was the last hop before it left.
  • Judge activity by context, not category alone. The same dataset can be routine in one workflow and alarming in another. Who’s moving it, in what circumstance, and toward what destination should carry as much weight as what the data is.
  • Treat this as continuous, not a rollout project. New AI features arrive in existing software on the vendor’s schedule, not security’s. A data-first approach absorbs that churn automatically, because it was never counting tools in the first place.

This is about building a program resilient enough to absorb whatever AI feature shows up next, unannounced, because the attention stays on the data itself: classified and tracked as it moves, understood through the context of who’s moving it, when, and why.

That’s the kind of program that scales alongside AI adoption, catching the next unannounced feature as just another data movement to evaluate, not a new blind spot to discover.

##

ABOUT THE AUTHOR

jonathan kreiner

Jonathan Kreiner is Co-Founder and CTO at ORION Security, which stops data loss by analyzing data in motion with context-aware AI agents. Prior to ORION, he led application security at WalkMe, where he experienced firsthand how policy-dependent DLP tools generated too many false positives without ever reaching real prevention, a gap that shaped ORION’s approach. Before that, he served in Unit 8200, the Israeli military’s elite signals intelligence unit. Jonathan was named to the Forbes Israel 30 Under 30 in 2025.