SaaS applications now support many of the enterprise’s most important business processes and thus hold large volumes of sensitive data. At the same time, embedded AI, standalone AI applications, copilots, AI agents, OAuth integrations, non-human identities, and SaaS-to-SaaS connections create a larger and more interconnected risk surface. Security teams must govern not only how applications are configured, but also who or what can access them, which data can be reached, how permissions are delegated, and what activity is occurring across the environment.
These changes are pushing SaaS security beyond the traditional boundaries of SSPM. Discovery and configuration monitoring remain foundational, but the market is evolving toward broader visibility and control across identity posture, OAuth and third-party integrations, data exposure, active threats, remediation workflows, compliance, cost governance, and AI agents. What is emerging is not simply a larger feature set, but a more unified control plane for SaaS and AI risk.
Drawing on the findings of the SaaS Security and AI Governance Leadership Compass, this webinar will examine where the market is heading, which requirements are moving from optional to essential, and where capabilities remain immature or fragmented. Attendees will gain a research-driven view of the market’s evolution and the implications for security architecture, governance, and program priorities.
Matthew Gardiner, Fellow Analysts at KuppingerCole Analysts will present the central findings from KuppingerCole’s SaaS Security and AI Governance Leadership Compass research. He will explain how AI is changing the scope and direction of SaaS security, identify the capabilities moving from optional to essential, and discuss what this evolution means for enterprise security architecture, governance, and investment priorities.
Who should attend
This webinar is designed for CISOs and security leaders; SaaS, cloud, and application security teams; IAM and identity security professionals; AI governance and GRC leaders; enterprise and security architects; IT operations teams; and technology strategy stakeholders responsible for the security and governance of SaaS, AI, and agentic systems.
Hello everyone, and welcome to this webinar. I'm Matthew Gardiner, an analyst here at KuppingerCole Analysts. The topic that I've put together for this session is about convergence, basically, and the need for the security risks that this convergence is causing, but also the security solutions that have evolved to address the risk. So basically, it's the convergence of SaaS, by SaaS, SaaS applications.
AI, I mean AI, generative AI, but also I mean AI agents, is probably the more intensive part of the challenge area. And then identity, and by identity, I mean human identity, as well as non-human identities, specifically AI agents, and the challenges that brings. But before I get into the actual content, a little bit of housekeeping. First of all, you don't need to worry about audio. You'll be muted centrally. This is not a call-in webinar. You can ask your questions, though, by just hitting the question box.
So as you think of them, please just drop them in, and I'll address them after I get through the basic content. There will be a couple polls, so I'll, you know, I'll prompt you and read the poll, give you a little bit of time to answer the poll. Then I will, when appropriate, talk about the results of the polls and what we've learned, you know, working on this together. And then finally, you don't need to snap pictures or anything of the slides that will be available along with the recording.
So if you want to share the recording with your colleagues, or, you know, get a look at the slides more carefully, you will be able to do that. Just give us a couple days to get that together and let you know. So moving on to the agenda, four basic areas. I'm going to talk about this converging risk surface of SaaS applications and AI and how identity plays a role in both of those. The problems that this is probably you're starting to face or have been facing for a while, depending on how, you know, how mature your AI deployments are and how deep you are into the SaaS application world.
Then I'm going to, at a very high level, I'm going to go into the solution space, which I've entitled in my reports, SaaS security and AI governance. And the and is underlined, meaning that both come together in these solutions. So I'll talk a little bit about how those work. And then give you some questions to ask vendors as you're starting to get into market and ask some takeaways. And then I will hit your questions basically in the discussion session. So strap in, we have about 30 minutes. I have about 30 minutes of prepared content.
So going into the next slide, I'm going to talk about essentially the risk surface that, you know, is in play here. And I'm going to use the term sprawl quite a bit. And I love the definition I found for sprawl because it obviously is not specifically related to security or IT, but it sounds like it is. So here it is. It's the uncontrolled disorganized expansion of something beyond a manageable scope, typically resulting in fragmentation, redundancy, and reduced oversight.
Now, if that doesn't sort of talk about the impact of sprawl on IT and security and governance, I don't, you know, it's such a great definition. So we've basically been dealing with two types of sprawl in this space.
First, the SaaS applications sprawl, which has been around for, you know, SaaS applications have been around for more than 10 years. And so the sprawl has had more time to create itself. But in the last couple of years, obviously the explosion of AI and AI agents and the use thereof across, you know, basically every application domain has also started to create sprawl. And one of the key takeaways here is that the sprawl of both has sort of the same source. On the SaaS application side, it's not uncommon for organizations to have more than 300 applications.
However, most of those are the, you know, unsanctioned or unknown, something that was signed up for by individual users or business units. The same kind of thing is happening on the AI side of the equation where AI agents are being created, they're being created inside of SaaS applications, they're being created in AI development tools. But is the security and IT teams involved? Are they? In many cases, you know, I have some data shows that they're not.
So, you know, why do these things happen? Business units evolve, either SaaS or AI, you know, on their own without involving IT or security. You also have sort of the management of those either AI or SaaS applications being often done not by IT and security, but by the business unit owners themselves or individual users themselves if they've spun up access to these applications or AI systems themselves.
And also, to make matters more challenging with sprawl, you also have sprawl and integration. So, both SaaS applications and AI systems do much of their work related by integrating to other systems.
Obviously, AI agents, you know, are not just LLMs running, they also need skills and they need access to data to be able to, you know, consume and produce their results. So, at the end of the day, you have massive amounts of sprawl, which creates problems, which I'll get into. But before I get into more of the content, this is poll number one. We want to hear from you. The question is, does your organization have an established program to discover and continuously monitor your SaaS applications?
So, please answer that question. And I will, you know, watch the results come in and comment a little bit.
So, if you look at some data, some hard data that this is both data sets are come from the Cloud Security Alliance, which is doing a lot of great work in the space of SaaS applications and AI. Specifically around sprawl, on the SaaS sprawl side, there was a survey done in last year, where not surprisingly, you know, in this case, 55% of employees have adopted applications, SaaS applications without securities involvement.
So, they just sign up individually or the business unit decides they have some sort of application that they want to use and they can just do it and the same organizations, you know, are reporting that fragmented administration that I talked about where, you know, a local business unit owner or an individual is doing it and these people are not necessarily aware or cognizant of the security implications of the different administrative functions they're doing, the different user privileges they're giving out or the given application features they're turning on or integrations they're making, you know, what are the security implications of those, that's not necessarily their sweet spot.
Similarly, in the agent side of things, obviously, much newer study done earlier this year, you know, 82% of organizations discovered when they looked unknown AI agents running in their environment. So, that, you know, that's classic sprawl where the agents are being built and deployed by various people inside the organization, but not known and not monitored as part of the security program and these things have led to incidents, doesn't really say what type of incidents, but I'm assuming things like data leakage and inappropriate access would be, you know, types of incidents you'd see.
Okay, so I'm just going to take a peek at the poll. Remember, the question was, does your organization have an established program to discover and continuously monitor your SaaS applications? 31% said yes, 31% said no, and 25% still changing a little bit, so keep answering it, but it looks like kind of a third, a third, a third we're heading towards, where yes, no, don't know is leading the way.
So, I'll check in on that again in a minute. So, what are the problems these face? Let's get into those.
The first problem that, you know, is racing up into the lead really on the identity side of the equation of this convergence is this non-human to human ratio, and this has been an emerging challenge pre-AI with, you know, service accounts and you can kind of think of APIs integrations as a kind of a non-human identity that, you know, gets set up to connect two systems, but of course now with AI agents, now this has the potential to start exploding on us, where, you know, historically we thought of identity management as a human phenomenon, where actually it looks like the human is going to be the special case and the non-human identity, specifically AI agents, will be the predominant use case.
Different ratios you see on screen, um, we generally at Coupanger Call Analyst, we use 50 to 1 as sort of a reasonable approximation at most organizations of non-human to human, but you can see other data sources, you know, run the gambit from 17 to 144. At the end of the day, the point is it's a lot more than your humans and there's every reason to believe that AI agents are going to, I mean, jack this ratio up perhaps to hundreds of ones or many orders of magnitude.
So, you know, your identity management security challenge is now shifting essentially right below, you know, right below you into a non-human phenomenon. So, if you go into whether the challenges that this actually drives that, you know, you're probably starting to grapple with, is that first, you know, the shadow IT challenge that, you know, that's been on the table for more than a decade is being accelerated. In some ways, the traditional shadow IT was hard to accomplish because if, you know, you needed servers and you needed software deployed, you know, obviously pre-SAS and AI.
Now, you know, all this can happen without the IT team or security team doing anything, unfortunately. So, this is the emergence of the shadow SAS and AI that I already talked about up front. You also have the identity sprawl. I talked about it previously as SAS and AI sprawl, but you can also think about the ratio of non-human identities to human as well as even the human problem that's existed for a while where you have, you know, dormant human users. You could have, you know, orphaned accounts, you know, accounts that were in use and are no longer in use but are still active.
You have human administrators that are normal users because now they're administrators of some of these applications that their business unit or themselves have rolled out. So, you have this sort of concept of ghost administrators. And then you have, you know, the explosion of agents and other forms of non-human identity that I mentioned earlier.
Third, this integration risk. So, if you don't know what your applications and AI systems are connected to, it's very hard to secure and govern it. With the rise of OAuth being a popular method to authorize one application to talk to on a persistent basis, you have a potential for data leakage to be happening.
So, if you combine shadow SAS with OAuth-based authorizations, now you have sort of two factors of security risk that are in play, both the application itself but also where it's sharing or from where it's consuming data. And, you know, threat actors are starting to take advantage, do take advantage of these connections. The fourth item is this concept of configuration drift. Because of the very positive nature of SAS applications and AI systems is the developers, in many cases, can deploy new features on a daily basis.
And so, what was administered correctly today may have exposure tomorrow. And so, this drift creates a little, another point of sprawl, if you will, or out of controlness because you have these non-IT and security administrators faced with new features, some of which are opt-out.
So, they may even be turned on by default or they may not really understand the implications of opting into them. So, moving on to the part two of the slide. All of the above essentially can cause data exposure.
So, if you don't know, you know, who's using what applications, where they're integrated to, and where data is moving, you know, you could be having data exposure. You have the sort of newish, unique threats of AI agents themselves. Because of their non-deterministic capabilities, you may have agents that you don't know about that are doing, that are perhaps are being authenticated using, you know, an end user's privileges, which is fairly common these days.
But, you know, these are not deterministic systems that, you know, the same inputs don't provide the same outputs. And so, and these, you know, agents can themselves become insider threats where they're, you know, leaking data in ways that you didn't expect and or can be the concept of prompt injection where a malicious user, whether inside or outside, can prompt the agent to, you know, do things that shouldn't or leak data that shouldn't. And all of these sort of roll off into the seventh one where it's hard to prove control if there isn't control.
And so, increasingly regulations, you know, traditional frameworks would still apply in this new world of AI and SAS. But even new regulations like the EU AI Act, which is specifically about, you know, proving, you know, improving organizations' ability to prove control of their AI in that case, but more broadly, both SAS and AI applications is becoming harder faster than it's becoming easier.
Alright, so moving on to the next one, we're going to actually have another poll. And I'll read it off as you want to think about your answer. It's kind of same, same idea as the first poll is, does your organization have an established program to discover and continuously monitor your AI and AI agents? So I put together either it's either yes or no, we're planning, we have a plan in place. So you're sort of between yes and no, or four, you're just not in the loop in this area. So you don't know. Please give that a little thought.
And I will move on while you're answering that question to a little bit on the solutions. So go to the next slide.
So, you know, at a high level, what are these solutions that I'm calling my reports, SAS security and AI governance. And I specifically combine those with the and underlined such that basically what happened is that this space from a vendor point of view has consolidated the solution space into visibility and observability for both SAS applications and AI applications. And why has it converged? One of the reasons it's converged is that if you think about SAS applications, having AI capabilities and AI systems being SAS space, there's a lot of commonality between those two domains.
So it makes a lot of sense for what most of the vendors in this space started in the SAS security side of the things, which was generally referred to as SAS security posture management, but quickly evolved to add AI level, AI specific visibility and observability to their solution because of this common problem space, common risks, common challenges, and common technology. They were very well positioned to extend the realm of AI visibility and observability.
Obviously, one of the goals is discovery with these solutions. So the classic, you can't secure what you don't know about, and you can't govern them either. The first thing that these solutions do is help discover. So if you've ever run one of them, perhaps in the world of SAS posture management, the first thing you did is you essentially set up various forms of sniffers, like in your browser or on endpoints or network or via various API connections to help find those SAS applications and now AI applications that were historically in the shadows.
So that helps you build a case for improved visibility and control by seeing what you don't know about. In addition, they're focused on operational basically the final two points is continuous operational visibility and observability. So because of these applications change on a daily basis, they could be added to your environment on a daily basis. The concept of a one-time check really doesn't hold any water. If you're doing it once a quarter, it doesn't play anymore.
So having continuous discovery combined with continuous inventory and combined with continuous observing and monitoring is really what these solutions about, and then applying a risk-based assessment to help guide you towards the riskiest exposures that you have, and then helping you operationalize the remediation of it through integrations and through some automation. So that's at a high level what these solutions do. Let me take a look at the poll and see if there's any results. I don't see any results yet. So let me just, I'll move on to a little bit more detail.
So if you think about, you know, what do these solutions do at a high level? We basically all of them in their own way, cover these, discover, normalize data, assess the risk, and obviously, you know, raise them to the users, the security administrators, help govern and act. And so again, at a very high level, they do all of these capabilities in sort of a continuous basis.
So instead of doing any one of them individually, you have now a solution that can cover SaaS applications, many, many SaaS applications directly, AI platforms, and agent development platforms, as well as seeing agents inside of SaaS applications, and then combining the identities of the human users and non-human users into what is referred to generally as an enterprise security graph, which is the normalized part of the solution. And once you have this continuously updated enterprise security graph, a lot of things can now happen.
You can record on the state of play, you know, in near real time, but you can also do analytics to help discover perhaps risky settings, orphaned users, agents doing things you didn't expect, those sorts of things. So now that sort of ability to help you prioritize the risks that have been discovered in the applications that you maybe originally didn't know about, and then helping you act.
So all these solutions in this space will either integrate into your ITSM, so tickets can be opened, but they can also ping users to help essentially nudge them into, you know, complying with policy, as well as, in other cases, automatically making changes, you know, based on policy. So the value proposition of these solutions is you take a pretty big bite out of your operational challenges across both your SaaS applications, AI, and then, you know, sucking in your identity information into this enterprise graph and then making good use of it.
So pushing forward, a little bit on the market, just to give you a sense for the state of play. Click forward one, there we go. The market is, whether you've heard about it or not, it's actually relatively mature, partly based on the fact that it existed five or six years ago. It's focused on the SaaS application security and governance challenges. So they had a sort of a headstart into this AI world.
And because of that, you know, if I look at the universe of applications, I estimate about eight to 9,000 customers across the universe of vendors that I looked at in this and I estimate this is a swag, about $700 million in revenue in this space. So it gives you a sense it's not, these are not, you know, version one products across the board. They are relatively mature, and perhaps many of you have been using some of them on your SaaS application side.
So it kind of sets up this nice sweet spot where you could either start on the SaaS application side extended to AI, or increasingly I've been hearing about more anecdotally that organizations are starting on the AI side because there's a lot of heat and challenge there. But the sort of SaaS application security and governance comes along for the ride. So you sort of have a two for one in a way in this vendor landscape. So actually look, give me a quick pick, peek into the vendor landscape.
This is pulled from the leadership compass of SaaS security and AI governance that I published last month. I guess the point I would make here is there, you know, if you have a platform vendor that you like, and that you're deeply embedded with in other ways, like maybe CrowdStrike or Microsoft or two that come to mind, you can certainly take a look at what they're doing in this space and potentially extend your platform usage. But there's also a good opportunity to look at specialist vendors that exclusively focus on the SaaS security and AI governance space.
So it provides optionality for you with relatively mature technologies applied to both a relatively well-established problem space, as well as a new problem space for many of you, SaaS and then AI security and governance. So you get sort of that two for one and you have a good ecosystem of vendors from which to consider.
Obviously, a lot more depth in the report. So I would encourage you, if you can, look at the leadership compass here. I go into deep into each of these vendors and talk about market trends and key findings in greater depth than I've been talking about here, but the report itself obviously goes into greater depth. So now I'm going to go into some of the questions to ask as you're talking to vendors and thinking about your program. Some of the questions will be on the next slide. I grouped them basically into three categories, coverage, control, and fit. This set is fairly basic.
There's a parallel research report I wrote called the Buyer's Compass for SaaS Security and AI Governance. And as the name implies, it's about helping a potential buyer sort through all the capabilities that they might want to consider, help prioritize them, and help essentially think about an RFP give you all some content for an RFP that you could apply to your platform vendors or your specialist vendors as you see fit. But coverage-wise, first of all, you have to sort of say, what can the platform see and the solution see?
How do they discover SaaS applications and the AI systems embedded in them and AI agents? There's no one way. There's no, just look here and you'll find them all. Sometimes browser plugins are very popular. So you have to actually see what the user is actually going to and then mapping it up against known systems to see what are unknown with both AI and SaaS applications. Then also you have to see, well, once you know those SaaS applications and AI platforms, what can you see in the APIs?
Those APIs are various levels of maturity and various levels of integration that the different vendors have. And so once you pick the SaaS applications you care about most or the AI platforms you care about most, and then you can sort of evaluate the API level of visibility that the solutions give you. And then the third thing we haven't really talked about is sort of this data visibility. Some solutions have essentially leverage like Microsoft Purview to find sensitive data that's moving around. Some other vendors provide their own data inspection to find sensitive data.
So you have to sort of figure out like where you are in your data leak protection kind of solution to find out what do you need from vendors in the space. Control, what can you do with what it finds? Does it help you prioritize the risks? Does it find potentially over-privileged OAuth permissions that are out there or even OAuth permissions you didn't know existed at all? Can the solutions find threats? So a classic SaaS application threat is account takeover. So if a user's account is taken over and you have an IDP, the threat actor can go to that IDP, get access to everything that user has.
So a classic case for that is if they're into Microsoft Office 365, everything that user has access to in Office 365, the threat actor has access to. So do these systems. Many of them do are looking for threats and I'll be trying to raise them for you. Remediation, what can it fix automatically via policy? What integrations into your IT infrastructure? Can remediations be pushed through?
How much user engagement directly can the application do for you to help perhaps have the user themselves use the right SaaS application or explain the business rationale for using a certain type of AI agent, for example. So to help facilitate essentially bringing the shadow SaaS and AI into the, out of the shadows. And then the final thing that makes sense, integration is a big deal across the board here. A big value proposition of these solutions is integration into your SaaS apps, into your AI platforms and into your IT and security infrastructure.
So obviously you need to map what you have to what they support. And the more overlap between those two worlds, the better it'll fit into your environment. So let me go to some takeaways before I take a peek at your questions. So the number one takeaway is there is a convergence between SaaS security and AI governance. It's one risk surface, the vendors have responded. I'd even throw visibility into this convergence. So if you want to kill a couple of birds with one stone, this market might be for you. The continuous discovery to combat the shadow SaaS and AI is hypercritical.
New SaaS apps are signed up to every day, whether you know it or not. Obviously the world of AI is probably less in control. There's new personal agents, came out last week, who knows? OpenClaw was so last month, Muse is so this week. So no doubt your users and your business units are running fast and furious into the world of AI. And we need to accelerate our ability to secure and govern what we're doing.
OAuth grants and the sort of general concept of integrations, we need to find these hidden third-party trust paths because they become points of data leakage, but also paths for threat actors and or malicious users of any kind to follow those paths into those third parties. AI agents are no different. They literally depend on integrations into your systems and third parties to be intelligent. So that's obviously a critical thing to at least get visibility and observability for. Agents require governance beyond authentication.
I think that's a topic that because these are non-deterministic sort of pseudo-intelligent systems that may be operating on a persistent basis, just because they're, quote, verified and not rogue themselves, that doesn't tell you exactly what they're doing or what they have done. So visibility into that is a key takeaway that these solutions help address. And then finally, this enterprise security graph is sort of the core of these solutions.
And so the better that discoveries get inventoried and the better that it enables better posture management and exposure discovery, where is the sensitive data, who are the users, all those things essentially should exist in this enterprise security graph that becomes sort of the core value proposition or the technical part of the solution. And so how good that system is and how quickly it's evolving is a key takeaway that you should consider as you're getting into these solutions. So let me now just go take a peek at the questions that have come in. Let's see.
So there's sort of a, well, one question I'll quickly summarize as where do you start? I think that'll answer maybe one or two of these. The two domains basically at play here are SaaS applications, shadow SaaS, and the posture of those and AI. So you need to sort of assess where are things on fire? A way historically it's been done with these solutions is that people started with SaaS applications because AI didn't really kind of exist two years ago and they've expanded into the AI domain.
However, in talking with these vendors that's starting to flip where the AI and AI agent use cases are driving the adoption and then SaaS coverage becomes a phase two of the project. So you sort of need to discover where the pain lies, but the beauty, one of the beauties of this space is that you sort of get a two for one, but you might want to start in either the SaaS side or the AI side. Let's see. So Yen said, asks, you mentioned convergence of SSPM and SaaS security identity data AI.
Is this currently a platform UI integration or the solutions truly achieving real-time cross-sectional telemetry correlation, stitching them together without heavy manual effort? Yeah.
I mean, that's the enterprise security graph that I talked about. My assessment is that they all understand that continuous visibility into that combination of all the things you listed is essentially the heartbeat of these solutions because everything else falls from that. So that is, you do get that. All right. In the solutions, AI maturity, but how do you define it?
Well, let's see. When I'm saying AI maturity, I'm talking about AI security maturity, not specifically like the AI applications. I guess one thing I would ask the typical, like if I was talking to you right now, I would say, do you have an AI governance committee? That's a sign that I've seen out there that it's not purely a security and IT governance. It's more holistically about the use of AI inside a company. But if I see that, then I'm like, okay, second question, does the CSO or a representative of CSO have a seat at that table?
If yes, now we're sort of walking up the maturity. Then my third question would be, what tools have you deployed for AI security and governance? If I hear like one of these tools and I'm like, okay, you're moving up the maturity life cycle. Okay. So Margaret asked what platforms or tooling is available to look at the SaaS AI ROI or even just the overlap of SaaS services? That's actually a great question. It isn't one that I talked about live. It is covered extensively in the reports.
Most of these solutions do have some visibility and some flagging of just unused user accounts that maybe you're crossing your money or SaaS applications are redundant with whatever your preferred version is. So there is a way where they can help you save money by not spending on those things that you already own or don't want own or you have users that accounts that you're paying for that you shouldn't be paying for anymore.
And that obviously, it's not the major feature of these solutions, but it is a way of sort of getting a little bit ROI and a little bit of cost savings can be fed into the rationale for purchasing these solutions. A couple more questions around the platform or specialist perspective, like should I use a platform or should I use this one of these specialist startup single product companies, the vendors that are out there? And that's like a philosophical question.
What I would do if I was running the show and I had a deep, productive, satisfactory relationship with a platform vendor, I would absolutely consider what they're doing because that's part of the rationale of having a platform is perhaps extending it. But to keep them honest in this space, I would also go through my report and get one or two vendors that are specialists and consider them because you always have the trade-off between putting more eggs into your single security basket and having a little bit of diversity in your security control environment.
So at least consider two or three vendors, at least on paper, and then perhaps go into a POC with one or two of them and make the best decision you can. All right, just looking at some of the other questions that have rolled in. So Louis asked, what tools are available to detect and alert on AI deployments not authorized by IT? So this is what I call the sniffers that these vendors provide. And so obviously, AI deployments can be inside a SaaS application that hopefully you know they're using, but regardless, it's inside.
So it's a chatbot or it's an agent that lives inside of the SaaS applications. You can have agents that are inside of AI development platforms, you know, developed there and deployed. And then third, you can have personal agents, like a muse agent that some user has deployed on their personal machine. And this is why you sort of need sniffers all over the place to find them. So generally, what vendors do is, obviously, once they have API level connection, they can generally see agents being deployed inside the context of that SaaS application.
But they could come online at any point in time, but they need to inventory them. On the endpoint, if someone's running a local agent, you either need a browser-based plugin, or you need an agent, or you need access to data from an agent, if you have an EDR, for example. And so you need to look at, on the identity side, you would have a plugin to your identity provider. So you would see, here are the known applications and identities that I have. Anyone who's not in the identity provider may be unknown.
And so you essentially are either sourcing from all these places and putting them against the enterprise security graph, flagging the things that are new or unknown, and then remediating them, and then either making them known, okay, or trying to remediate them out. All right. The final check, see if there's anything else. I guess the final recommendation I'd have is, okay, like, who should own, there's a question sort of around who should own SaaS and AI governance in an organization.
This is going to put the, sort of, the developer security gap under great pressure, specifically with the AI agent side of things. You really need a way of working between those two groups more than ever. And traditionally, that's been a challenge, because the developers are developing against a business problem, often from inside a business unit, and the centralized security team is trying to catch up. And so one of the things these tools help with, obviously, is that gives the centralized security team visibility into what's happening as it happens. So that helps.
But I guess I will go back to the AI governance strategy that I think most companies should be doing if they aren't already. Because, of course, AI has much more implications than just security and governance. It's critical to the business in many cases.
And so, whether you should do something, how you do it, whether the non-determinism of an agent is okay or not, whether you roll it out to your end users, or you roll it out internally, are a lot of questions there. And so there should be an AI governance committee, and that AI governance committee should have a seat in the security team. And so the security team can be in the loop. Maybe someday we'll be at the point where this happens more naturally, and we don't need a formal committee that's somewhat centralized for this stuff to be run through.
But in the early days of the deployment of AI, I would say you need a specialty team with experts, both technical, business, and basically senior management and security all together, trying to figure this stuff out together, because it's still early days on the AI side. So thank you very much for your attendance, and thanks for the thumbs up and the exploding whatever those are, pops. And I hope you'll attend future events. I hope you'll go look at my publications in this area of SaaS security and AI governance, and follow me, my blogs. And I look forward to working with you all down the road.
Thanks again.
See All Locations
See All Locations