AI Security Fundamentals: The Real Industry Shift Taking Place

Experts discuss how AI is reshaping cybersecurity, from exposing existing vulnerabilities to enabling proactive defense strategies.
3 min read
Last updated September 25, 2026
Using AI to enhance security measures is the new standard.

Key takeaways

  • "Security for AI" isn't a distinct discipline. AI systems need the same governance, access controls, and monitoring as everything else in the stack.
  • Adopting AI often functions as an unplanned pen test, exposing pre-existing weaknesses like excessive permissions, weak identity controls, and poor data classification.
  • AI's real advantage for defenders isn't securing AI itself — it's using AI to finally process, prioritize, and act on security data at a scale humans never could.

AI adoption is forcing organizations to confront problems they've ignored for years, especially around data governance, identity management, and access controls. The real story isn't how to secure AI as its own category — it's how AI is exposing those long-standing gaps, and how it's finally giving defenders a way to keep up.

Varonis recently sat down with cybersecurity leaders Mike Privette, the mind behind Return on Security, and Matt Lock, former Field CTO at Varonis, to unpack how AI is reshaping both sides of that equation. Here are the key takeaways from their conversation. 

Security for AI vs. AI for security

It boils down to this: Security for AI isn’t distinctive, it’s security. AI systems are simply another piece of an organization’s technology stack that require the same governance, access controls, monitoring, and protection as the rest.

When AI was first introduced, early security efforts took a narrow view: protecting chatbots and models, preventing leakage, securing system prompts. That didn't last. The industry quickly moved from protecting AI to using AI to supercharge cybersecurity.

It's the same trajectory cloud computing took. Companies once marketed themselves as cloud companies, but today, using the cloud is simply assumed. Matt expects AI to reach that same point, where the question isn't whether a product uses AI, but whether it delivers better security outcomes because of it.

Why AI exposes existing weaknesses

An organization adopting AI opens itself up to what Mike calls “unexpected pen tests," because they quickly face a reality check on the level of unintended access an agent could have. That's because deploying tools like Copilot or Claude reveal excessive permissions, weak identity controls, poor data classification, and other issues.   

Agents accessing systems autonomously may also discover pathways security teams would not have otherwise anticipated. And for agents to do so in split seconds means that a sole bad actor with access to an organization’s unsecured AI can do serious damage in a short amount of time. 

Enroll in our free AI Security Fundamentals course.
Sign up now
Blog_SecurityStrategy

AI vs. AI: The new security arms race

Thanks to AI, attackers are seeing increases in both speed and scale. Matt points out that cybercriminals don’t care about compliance, governance, or guardrails. They’ll do whatever it takes to get what they’re after. In many cases, that’s data.

For decades, cybersecurity has largely been reactive. AI may offer the first technology that allows defenders to be proactive. With things like automated detection, 24/7 monitoring, preemptive phishing takedowns and automated investigations, the playing field has certainly leveled.

Matt and Mike also propose an interesting tactic: making attacks too expensive for attackers. Strategies like AI honeypots and AI labyrinths can waste attacker time, burn through an attacker’s tokens, and force attackers through useless paths.

Using AI to supercharge security

AI’s biggest impact is enabling defenders to operate at machine speed. Security teams generate enormous amounts of data but struggle to sort through it manually. 

With AI, security teams can easily: 

  • Investigate alerts 

  • Correlate signals

  • Add context

  • Reduce false positives

  • Surface only meaningful threats

Rather than having SOC analysts review everything, AI can help ensure only prioritized incidents reach humans.

Vulnerability prioritization

Matt also argues that the hard part isn’t finding the vulnerabilities, it’s fixing and prioritizing them. Historically, cybersecurity has been constrained by human capacity. AI changes that by helping enterprise security teams process more data, analyze more signals, reduce response time, and scale expertise across the security team.

The future of cybersecurity, then, is about knowing which ones are important.

The backlog might be ten million vulnerabilities today and a hundred million tomorrow.

— Matt Lock on why there’s a growing need for AI in security.

Security fundamentals still win

Despite the excitement around AI security, the conversation repeatedly comes back to the same thing: organizations need to focus on the fundamentals. Every AI initiative relies on accurate permissions, clean identity models, and data governance.

Data and identity remain the core problems behind cybersecurity. An organization without control over their data, identity, and access opens themselves to immense risk. Matt has preached this to other cybersecurity professionals for over a decade, but he's only now hearing others say the same thing back to him.  

The real AI security shift

For all the discussion around agents, autonomous systems, vulnerability discovery, and AI-powered attacks, Matt and Mike repeatedly return to the same conclusion: AI is changing cybersecurity, but it's not changing what cybersecurity is trying to accomplish.

The industry’s first reaction to AI was to ask: How do we secure AI? The more important question turned out to be: How do we use AI to solve security problems we've struggled with for decades?

If their predictions hold true, the future of cybersecurity won't be defined by who adopts AI first. It'll be defined by who uses it to solve the problems that have been there all along.

Watch their full conversation: 

 

Ready to secure everything you build and run with AI?

Learn how Varonis can help your organization reduce risk and safely scale AI with confidence.
1
See how Varonis secures AI environments: Schedule a demo of Varonis Atlas to understand what AI agents can access — and how to control actions on sensitive data.
2
Discover your AI data exposure: Our free Data Risk Assessment shows what data agentic AI can reach and how to reduce risk before it’s exploited.
3
Learn how to secure AI at scale: Follow Varonis on LinkedIn, YouTube,and X for practical insights on AI security, agent risk, and protecting the data that powers your AI initiatives.

Try Varonis free.

Get a detailed data risk report based on your company’s data.
Deploys in minutes.

Keep reading

Varonis tackles hundreds of use cases, making it the ultimate platform to stop data breaches and ensure compliance.

varonis-named-a-pace-setter-in-the-september-2026-gartner®-emerging-market-quadrant-for-ai-application-security
Varonis Named a Pace Setter in the September 2026 Gartner® Emerging Market Quadrant for AI Application Security
Discover how Varonis Atlas leads AI application security with innovative solutions that protect sensitive data throughout the AI lifecycle. Learn more now.
cosnitch:-when-your-ai-assistant-becomes-its-own-whistleblower
CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower
See how meta-hacking got Microsoft Copilot to snitch on itself, exposing CoSnitch, a one-click flaw that silently exfiltrates data.
varonis-atlas-now-integrates-with-claude-inference-hooks-to-extend-real-time-ai-data-protection
Varonis Atlas Now Integrates with Claude Inference Hooks to Extend Real-Time AI Data Protection
Varonis Atlas enforces data protection policy inline before a prompt ever reaches the model and extends coverage to Claude Chat and Claude Design.