Tailored IT solutions for YOUR business — since 2005
The OST Blog

Notes and thoughts from the "fitting room"

July 28, 2026 · Shea Taylor

 "What We Learned About Securing AI — Between the Sharks and the Penguins."

On a Friday in July, we did something a little unusual for an IT security event: we held it at an aquarium. About 30 business and IT leaders joined us at the Living Planet Aquarium in Draper, UT for lunch and a working session on a question nearly every organization is quietly wrestling with: how do you let your team use AI without losing control of your data?

Security experts from Check Point and PlainID brought the answers — and a few uncomfortable statistics. Here's what stuck with us.

Most companies are flying blind — and don't know it

The number that hushed the room: by Check Point's assessment, only around 5% of organizations have real visibility into how AI is being used inside their business. The other 95% can't answer basic questions: Which AI tools are employees using? On personal accounts or corporate ones? What information is being pasted into them?

That's not a hypothetical risk. Every prompt an employee types into a free consumer chatbot is business information leaving the building — customer details, draft contracts, financial figures — with retention and training policies nobody read.

The sneakiest trap: personal vs. corporate accounts

One example from the Check Point session that everyone recognized: the AI assistant button sitting right on the desktop. Click it, and it happily starts answering — on a personal account — unless you deliberately sign in with your work identity first. Most employees never notice the difference. Same tool, same screen, completely different data protections.

The lesson: "we bought the business version" isn't a control. Knowing which account your people are actually using is.

AI agents are the next wave — and they multiply the question

Both presenters pointed to what's coming fast: AI agents — think of them as digital employees that run continuously in the background, using tools, calling other systems, even talking to other agents. (One might be summarizing your meetings right now.) Every agent is another identity touching your data, which raises the question PlainID's session drove home: who — or what — is authorized to access what? Identity and authorization aren't just about people anymore, and yesterday's access policies weren't written with software employees in mind.

Blocking AI doesn't work. Governing it does.

The consensus across both sessions matched what we tell our own customers: banning AI just drives it underground while your competitors get faster. The workable path is visibility first (discover what's actually in use), then policy (which tools, which accounts, what data), then enforcement that's smart enough to understand intent, not just keywords — the difference between an employee asking an AI about "merging two sports teams" and "merging two companies."

Our take

This event is exactly why we built our Secure Workplace AI practice: policy before pilots, sanctioned tools your team will actually prefer over the ones they're sneaking, and monitoring that treats AI like the rest of your managed environment. If your organization can't currently answer "who's using what AI, on which accounts, with what data" — that's the conversation to have before the next headline. Start with an AI readiness conversation →

And yes, there were penguins

Huge thanks to everyone who came, to our presenters from Check Point and PlainID, and to the Living Planet Aquarium for a venue that made "security event" and "bring the family" work in the same sentence. Congratulations to "our prize winners" who took home a couple Lego sets and a laptop — and if you missed this one, our lunch-and-learn series continues this fall. Get on the invite list →]

---

Open Source Tailors has delivered honest, vendor-neutral IT guidance to businesses across Utah since 2005 — including managed security, cloud, and governed workplace AI. If you'd rather have this handled than explained, we're one conversation away: talk to a real person

← All posts

Want this handled instead of just explained?

Twenty years of honest, vendor-neutral IT guidance — one conversation away.

Talk to a Real Person