We scan new podcasts and send you the top 5 insights daily.
ENT's platform doesn't need months of complex learning to be useful. By starting with a simple corporate policy, like a list of approved software, it can immediately identify unsanctioned AI tool usage. This initial, concrete value provides a foothold for the platform to then build its more complex behavioral baselines over time.
Esper established a clear policy for employees to pilot new AI tools. They can experiment without ingesting proprietary data, then submit promising tools to an IT and security-led committee that promises a quick decision. This approach balances fostering innovation with maintaining security.
To perform AI data analysis safely: 1) Only use AI tools with enterprise-level security approved by your company. 2) Clearly define the problem you're solving to guide the AI effectively. 3) Thoroughly validate the AI's output by checking its logic and simple math before trusting the conclusions.
Address security concerns by granting AI tools access incrementally. Start with low-risk tasks like drafting content. As you build confidence, gradually allow it to read your emails, then your calendar, and eventually perform actions. This "trust spectrum" approach makes adoption more comfortable.
Employees often use personal AI accounts ("secret AI") because they're unsure of company policy. The most effective way to combat this is a central document detailing approved tools, data policies, and access instructions. This "golden path" removes ambiguity and empowers safe, rapid experimentation.
Organizations must urgently develop policies for AI agents, which take action on a user's behalf. This is not a future problem. Agents are already being integrated into common business tools like ChatGPT, Microsoft Copilot, and Salesforce, creating new risks that existing generative AI policies do not cover.
By observing all employee actions to prevent security breaches, ENT incidentally builds a detailed model of how a company operates. This "work model" can be used for productivity analysis, identifying process inefficiencies, and pinpointing opportunities for AI agent automation, creating value far beyond its initial security mandate.
For enterprises, the raw capability of foundation models is a security risk, not a selling point. The real product value lies in building "boundaries"—robust permissions, approvals, and audit logs that make powerful models safe to deploy company-wide.
To avoid disrupting workflows, ENT's software first runs in a baseline mode to observe behavior and surface policy violations. Only after this "burn-in period," where the customer identifies critical risks, does the system switch to actively preventing actions. This phased approach builds trust and ensures interventions are targeted and meaningful.
To balance security with agility, enterprises should run two AI tracks. Let the CIO's office develop secure, custom models for sensitive data while simultaneously empowering business units like marketing to use approved, low-risk SaaS AI tools to maintain momentum and drive immediate value.
When companies don't provide sanctioned AI tools, employees turn to unsecured public versions like ChatGPT. This exposes proprietary data like sales playbooks, creating a significant security vulnerability and expanding the company's digital "attack surface."