PROTEGRITY
 
 
 

CMO's letter

 
 

Hi ala,

At SecurityWeek’s AI Risk Summit in California this month, a speaker shared a governance framework that began with a simple rule: if it contains sensitive data, no.

I understand the instinct. What's stuck with me lately isn't a rulebook; it's how quickly two ideas we thought we understood are being redefined. "Least privilege" used to mean deciding who gets a login. Now, it means deciding, mid-workflow, exactly which fields an autonomous agent can touch. And zero trust, which used to be about network permissions, is becoming something that has to travel with the data itself, wherever an agent takes it. Most governance frameworks, including the one behind that "no," haven't caught up to either shift yet.

That's the real cost of a blanket no: the most valuable AI use cases are built on exactly the data it locks away, including customer data, financial records, and proprietary business knowledge. If the answer to sensitive data is always no, the answer to meaningful AI is usually no too.

We wanted real numbers behind what we hear from customers every week, so we commissioned independent research from Enterprise Management Associates (EMA): more than 150 IT and security leaders surveyed this spring. 82.9% said they had been delayed by security or compliance review. More than 80% who shipped anyway were running on whatever data cleared the review. The delay number is costly, maybe a project killer. And those that shipped in a diminished state is troubling. There is a better way.

As a leader in data-centric security, Protegrity does not think the fix is fewer rules. We think it is rules that travel with the data instead of sitting in front of it as a checkpoint. 

The organisations that pull ahead won't be the ones that keep saying no. They'll be the ones that figure out how to make sensitive data safely usable, so the security review becomes a green light, not a gate.

We're calling it the AI friction tax. EMA's full research is available here: State of AI Friction 2026.

You can also read a blog post from our CEO, based on his comments at the AI Risk Summit: Human in the Loop, Out of Control by Michael Howard.


Sincerely,

 
 

Chris Gaebler

Chief Marketing Officer, Protegrity

 
 
 

Editor’s Recommendation 

The State of AI Friction 

Protegrity, along with the EMA, surveyed enterprise AI and data teams to map where deployment actually stalls. The findings are more specific than the usual "AI is hard" narrative. They point to exactly where the friction compounds and what the teams wanting to move faster should be doing differently at the data layer.

Worth reading before your next board conversation about why the timeline slipped.

Download the report
 
 

From the team

Sovereign AI and the data you can use

Your sovereign AI platform is running and your most valuable data still isn't in it. Explore why the data layer is where sovereign AI stalls and what it looks like at clearance. Read>

How Protegrity and Composio Secure Agentic AI Workflows

When agents act on data autonomously the perimeter question becomes irrelevant. The right question is whether the data itself is protected before the agent ever touches it. This is what that looks like in a real pipeline. Read>

WATCH EPISODE 1
 
 

Industry insights

Security Wants to Enable AI, But Keeps Saying No  

At the AI Risk Summit, one consultant's framework for AI governance started with a simple rule: "If it contains sensitive data, no." Yet sensitive data is exactly what makes AI valuable. That's the dilemma confronting enterprises today. Security teams are under pressure to accelerate AI adoption while relying on controls designed to stop it. The real challenge isn't securing AI. It's enabling AI without sacrificing control of the data that powers it. Take the AI data readiness assessment to see where sensitive data may be exposed.

 
 

On the calendar

Cloudera EVOLVE NYC | 27 October | Marriott Marquis

Cloudera and Protegrity help organizations unlock trusted data for AI, analytics, and regulated workloads. Meet with us at EVOLVE to discuss how other organizations are securely enabling AI with Cloudera and Protegrity. Register>