AI slid into just about every layer of enterprise IT, largely unnoticed, from the productivity tools employees use day-to-day to the infrastructure that sits behind them. That embedding cuts both ways. The beef that security teams and researchers at CrowdStrike have with one another is that the technology those workers now use to identify threats […]
Collabnix Team Follow The Collabnix Team is a diverse collective of Docker, Kubernetes, and IoT experts united by a passion for cloud-native technologies. With backgrounds spanning across DevOps, platform engineering, cloud architecture, and container orchestration, our contributors bring together decades of combined experience from various industries and technical domains.
21st September 2026 3 min read
AI slid into just about every layer of enterprise IT, largely unnoticed, from the productivity tools employees use day-to-day to the infrastructure that sits behind them. That embedding cuts both ways. The beef that security teams and researchers at CrowdStrike have with one another is that the technology those workers now use to identify threats more quickly has also altered the nature of what it looks like, how fast it goes and how easy or hard it is to be detectable using tools built for a slower time in terms of attacks.
This duality is what makes the protection conversation for networks and endpoints much larger than just the detection of threats. Security teams now need to consider AI as both a defensive tool, and taking the position of yet another type of risk, which will require its own controls.
Correlating the Size of The IssueWhat is AI security in networks covers a broader territory than most people initially assume. It includes using AI-driven tools to detect and respond to threats faster than human analysts could manage alone, but it also includes securing the AI systems themselves, the data they’re trained on, and the growing number of AI tools employees adopt on their own without formal approval from IT.
That last piece, however, has become a glaring blind spot for many organizations. Employees increasingly use AI-powered applications and browser extensions as part of their daily workflow, often running in the background without giving security teams any visibility into what is running or which data those tools can access. These unmanaged tools each pose a potential new attack surface, distinct from the endpoints and applications that security programs were originally designed to monitor.
A New Layer Of Complexity: Machine IdentitiesAI systems are not just new software to track It also introduce a constantly increasing sea of identities that aren’t human service accounts, API tokens and machine credentials which AI tools utilize to authenticate and access data on behalf of an organization. In fact, these identities outnumber human user accounts inside an average enterprise, but they often receive considerably less oversight than a typical end-user login.
Recent industry reporting on this gap has been striking. Coverage of shadow AI security exposure found that a large majority of employees at surveyed organizations were already using AI tools at work, while only a small fraction of those organizations had a formal policy governing that usage. That gap between adoption and governance is exactly where attackers look for openings.
The AI Revolution: What Now? within our Own Upfront Threat Landscape…However, AI is not just a visibility issue it affects how the attacks themselves are constructed. Phishing content can now be automatically generated, the approach adjusted dynamically to how a target responds and multiple stages of an attack can now be chained together with far less manual work compared to older techniques. This will be a factor in increasing the tempo of an attack and decreasing the time a security team has to detect and respond before significant damage is done.
Static rules and known threat signatures cannot defend against this type of adaptive behavior, whether for network defenses, endpoint defenses, or both. If a system has been trained to identify what an attack would have looked like yesterday, it may miss a variant that has been automatically altered in some way to bypass that detection method.
Why AI Is Needed Even More So For DefenseThis continually evolving threat landscape is far from one of the top reasons why security vendors themselves have bet so heavily on AI-powered detection. Behavioral analysis models can recognize anomalies across endpoints, network traffic, and user activity that a static rule set would struggle to flag, connecting signals over larger volumes of data than human analysts could realistically review in real time.
Artificial intelligence-driven defense does not mean that human judgment is entirely eliminated. Security teams are still required to cull through treated activity, prune detection models to mitigate false positives and executive engagement on how best to respond to real incidents. An effective strategy often combines automated detection with experienced analysts who can interpret context that a model may miss on its own.
Governance as a Foundational RequirementWith AI adoption outpacing formal policy in most organizations, governance has become as important as any technical control. It begins with fundamental visibility: Which AI tools are in use across the organization, at what scale and by whom, and which data can those tools access?
Federal guidance has increasingly emphasized structured governance as a starting point for managing this category of risk. A widely referenced federal AI risk framework lays out a structured approach for organizations to identify, measure, and manage risks associated with AI systems throughout their lifecycle, offering a useful reference point for security teams building out their own AI governance program from scratch.
Practical Steps for Getting StartedYou do not need to have an AI security program fully mature before you can see real change in what your organization is doing. The basic visibility on what AI tools are in use is a decent baseline and to have identity governance practices that already exist expanded out to machine identities and service accounts instead of being treated as some lower-tier priority.
After that, deploying AI-aware detection within existing network and endpoint security tools seems to create more value than building an entirely separate AI security stack. Actors not only limit themselves to strictly AI-driven technologies rarely, and defenses that can correlate AI-driven signals in Ü903014501B02 signatureless with traditional network and endpoint telemetry broadly are wearing best-beating position of catching the totality of contemporary attacking patterns.
Frequently Asked QuestionsUsing AI for security isn’t the same thing as AI security?
Not entirely. Let’s talk about intelligent security, including AI-powered threat detection, securing the tools and machine identities themselves, and governing how employees draw on AI sites across the enterprise.
Should Small Companies Bother with AI Safety?
Yes. Any size organization can also see unmanaged AI tool usage if all employees are using these types of tools unguided, as smaller companies use AI tools as frequently as large enterprise clients and without a governing policy in place.
What is a machine identity, unlike that of a user account?
A machine identifies a service account, an API token, etc. authenticates on behalf of a system or automated process rather than identifying an individual person. These identities typically have long-standing access and undergo less frequent audits than personal user accounts, making them an ideal target if not appropriately governed.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | AI Cybersecurity Threats: Intelligence vs. Authority | 0 | 6.33 | 29-09-2026 |
| 2 | Why are employees reluctant to disclose AI use to their bosses? | 0 | 6.49 | 28-09-2026 |
| 3 | Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI | 0 | 9.05 | 28-09-2026 |
| 4 | Defending against AI-fueled social engineering | 0 | 12.07 | 01-09-2026 |
| 5 | Machine vs. machine: The new reality of cybersecurity in ANZ | 0 | 7.56 | 26-08-2026 |
| 6 | When AI agents swarm, can banks keep up? | 0 | 10.38 | 30-09-2026 |
| 7 | ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories | 0 | 8.94 | 24-09-2026 |
| 8 | What is an "AI swarm," and why is it giving tech experts nightmares? | 0 | 8.16 | 23-09-2026 |
| 9 | The SOC Doesn't Need to Start Over with Every Alert | 0 | 8.65 | 25-09-2026 |