At SecurityWeek’s AI Risk Summit in California this month, a speaker shared a governance framework that began with a simple rule: if it contains sensitive data, no.
I understand the instinct. What's stuck with me lately isn't a rulebook; it's how quickly two ideas we thought we understood are being redefined. "Least privilege" used to mean deciding who gets a login. Now, it means deciding, mid-workflow, exactly which fields an autonomous agent can touch. And zero trust, which used to be about network permissions, is becoming something that has to travel with the data itself, wherever an agent takes it. Most governance frameworks, including the one behind that "no," haven't caught up to either shift yet.
That's the real cost of a blanket no: the most valuable AI use cases are built on exactly the data it locks away, including customer data, financial records, and proprietary business knowledge. If the answer to sensitive data is always no, the answer to meaningful AI is usually no too.
We wanted real numbers behind what we hear from customers every week, so we commissioned independent research from Enterprise Management Associates (EMA): more than 150 IT and security leaders surveyed this spring. 82.9% said they had been delayed by security or compliance review. More than 80% who shipped anyway were running on whatever data cleared the review. The delay number is costly, maybe a project killer. And those that shipped in a diminished state is troubling. There is a better way.
As a leader in data-centric security, Protegrity does not think the fix is fewer rules. We think it is rules that travel with the data instead of sitting in front of it as a checkpoint.
The organisations that pull ahead won't be the ones that keep saying no. They'll be the ones that figure out how to make sensitive data safely usable, so the security review becomes a green light, not a gate.
We're calling it the AI friction tax. EMA's full research is available here: State of AI Friction 2026.
You can also read a blog post from our CEO, based on his comments at the AI Risk Summit: Human in the Loop, Out of Control by Michael Howard.
Sincerely,