<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Open Source Tailors blog</title>
    <link>https://ostailors.com/blog</link>
    <description />
    <language>en</language>
    <pubDate>Mon, 03 Aug 2026 21:41:49 GMT</pubDate>
    <dc:date>2026-08-03T21:41:49Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Notes and thoughts from the "fitting room"</title>
      <link>https://ostailors.com/blog/notes-and-thoughts-from-the-fitting-room</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://ostailors.com/blog/notes-and-thoughts-from-the-fitting-room" title="" class="hs-featured-image-link"&gt; &lt;img src="https://ostailors.com/hubfs/nights-under-lights_002-1-1024x683.jpg" alt="Notes and thoughts from the &amp;quot;fitting room&amp;quot;" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="text-align: center;"&gt;&amp;nbsp;&lt;em&gt;"What We Learned About Securing AI — Between the Sharks and the Penguins."&lt;/em&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;On a Friday in July, we did something a little unusual for an IT security event: we held it at an aquarium. About 30 business and IT leaders joined us at the Living Planet Aquarium in Draper, UT for lunch and a working session on a question nearly every organization is quietly wrestling with: &lt;span style="font-weight: bold;"&gt;how do you let your team use AI without losing control of your data?&lt;/span&gt;&lt;br&gt;&lt;br&gt;Security experts from &lt;span style="font-weight: bold;"&gt;Check Point&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;PlainID&lt;/span&gt;&amp;nbsp;brought the answers — and a few uncomfortable statistics. Here's what stuck with us.&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;Most companies are flying blind — and don't know it&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;The number that hushed the room: by Check Point's assessment, only around &lt;span style="font-weight: bold;"&gt;5% of organizations have real visibility&lt;/span&gt;&amp;nbsp;into how AI is being used inside their business. The other 95% can't answer basic questions: Which AI tools are employees using? On personal accounts or corporate ones? What information is being pasted into them?&lt;br&gt;&lt;br&gt;That's not a hypothetical risk. Every prompt an employee types into a free consumer chatbot is business information leaving the building — customer details, draft contracts, financial figures — with retention and training policies nobody read.&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;The sneakiest trap: personal vs. corporate accounts&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;One example from the Check Point session that everyone recognized: the AI assistant button sitting right on the desktop. Click it, and it happily starts answering — &lt;span style="font-weight: bold;"&gt;on a personal account&lt;/span&gt;&amp;nbsp;— unless you deliberately sign in with your work identity first. Most employees never notice the difference. Same tool, same screen, completely different data protections.&lt;br&gt;&lt;br&gt;The lesson: "we bought the business version" isn't a control. Knowing &lt;em&gt;which account&lt;/em&gt;&amp;nbsp;your people are actually using is.&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;AI agents are the next wave — and they multiply the question&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;Both presenters pointed to what's coming fast: &lt;span style="font-weight: bold;"&gt;AI agents&lt;/span&gt; — think of them as digital employees that run continuously in the background, using tools, calling other systems, even talking to other agents. (One might be summarizing your meetings right now.) Every agent is another identity touching your data, which raises the question PlainID's session drove home: &lt;span style="font-weight: bold;"&gt;who — or what — is authorized to access what?&lt;/span&gt;&amp;nbsp;Identity and authorization aren't just about people anymore, and yesterday's access policies weren't written with software employees in mind.&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;Blocking AI doesn't work. Governing it does.&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;The consensus across both sessions matched what we tell our own customers: banning AI just drives it underground while your competitors get faster. The workable path is visibility first (discover what's actually in use), then policy (which tools, which accounts, what data), then enforcement that's smart enough to understand &lt;span style="font-weight: bold;"&gt;intent, not just keywords&lt;/span&gt;&amp;nbsp;— the difference between an employee asking an AI about "merging two sports teams" and "merging two companies."&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;Our take&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;This event is exactly why we built our &lt;a href="https://ostailors.com/secure-workplace-ai"&gt;&lt;span style="font-weight: bold;"&gt;Secure Workplace AI&lt;/span&gt;&lt;/a&gt;&amp;nbsp;practice: policy before pilots, sanctioned tools your team will actually prefer over the ones they're sneaking, and monitoring that treats AI like the rest of your managed environment. If your organization can't currently answer "who's using what AI, on which accounts, with what data" — that's the conversation to have &lt;span style="font-style: italic;"&gt;before&lt;/span&gt; the next headline. &lt;a href="https://ostailors.com/secure-workplace-ai"&gt;&lt;span style="font-weight: bold; font-size: 18px;"&gt;Start with an AI readiness conversation →&lt;/span&gt;&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;And yes, there were penguins&lt;/span&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;Huge thanks to everyone who came, to our presenters from Check Point and PlainID, and to the Living Planet Aquarium for a venue that made "security event" and "bring the family" work in the same sentence. Congratulations to "our prize winners" who took home a couple Lego sets and a laptop&amp;nbsp;— and if you missed this one, our lunch-and-learn series continues this fall. &lt;a href="https://ostailors.com/it-events-lunch-and-learns-in-utah-open-source-tailors"&gt;&lt;span style="font-weight: bold; font-size: 18px;"&gt;Get on the invite list →&lt;/span&gt;&lt;/a&gt;]&lt;br&gt;&lt;br&gt;---&lt;br&gt;&lt;br&gt;&lt;span style="font-style: italic;"&gt;Open Source Tailors has delivered honest, vendor-neutral IT guidance to businesses across Utah since 2005 — including managed security, cloud, and governed workplace AI. If you'd rather have this handled than explained, we're one conversation away&lt;/span&gt;: &lt;a href="https://ostailors.com/contact-open-source-tailors-nationwide-it-solutions"&gt;&lt;span style="font-weight: bold; font-size: 18px;"&gt;talk to a real person&lt;/span&gt;&lt;/a&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;h2 style="text-align: center;"&gt;&amp;nbsp;&lt;em&gt;"What We Learned About Securing AI — Between the Sharks and the Penguins."&lt;/em&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;On a Friday in July, we did something a little unusual for an IT security event: we held it at an aquarium. About 30 business and IT leaders joined us at the Living Planet Aquarium in Draper, UT for lunch and a working session on a question nearly every organization is quietly wrestling with: &lt;span style="font-weight: bold;"&gt;how do you let your team use AI without losing control of your data?&lt;/span&gt;&lt;br&gt;&lt;br&gt;Security experts from &lt;span style="font-weight: bold;"&gt;Check Point&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;PlainID&lt;/span&gt;&amp;nbsp;brought the answers — and a few uncomfortable statistics. Here's what stuck with us.&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;Most companies are flying blind — and don't know it&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;The number that hushed the room: by Check Point's assessment, only around &lt;span style="font-weight: bold;"&gt;5% of organizations have real visibility&lt;/span&gt;&amp;nbsp;into how AI is being used inside their business. The other 95% can't answer basic questions: Which AI tools are employees using? On personal accounts or corporate ones? What information is being pasted into them?&lt;br&gt;&lt;br&gt;That's not a hypothetical risk. Every prompt an employee types into a free consumer chatbot is business information leaving the building — customer details, draft contracts, financial figures — with retention and training policies nobody read.&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;The sneakiest trap: personal vs. corporate accounts&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;One example from the Check Point session that everyone recognized: the AI assistant button sitting right on the desktop. Click it, and it happily starts answering — &lt;span style="font-weight: bold;"&gt;on a personal account&lt;/span&gt;&amp;nbsp;— unless you deliberately sign in with your work identity first. Most employees never notice the difference. Same tool, same screen, completely different data protections.&lt;br&gt;&lt;br&gt;The lesson: "we bought the business version" isn't a control. Knowing &lt;em&gt;which account&lt;/em&gt;&amp;nbsp;your people are actually using is.&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;AI agents are the next wave — and they multiply the question&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;Both presenters pointed to what's coming fast: &lt;span style="font-weight: bold;"&gt;AI agents&lt;/span&gt; — think of them as digital employees that run continuously in the background, using tools, calling other systems, even talking to other agents. (One might be summarizing your meetings right now.) Every agent is another identity touching your data, which raises the question PlainID's session drove home: &lt;span style="font-weight: bold;"&gt;who — or what — is authorized to access what?&lt;/span&gt;&amp;nbsp;Identity and authorization aren't just about people anymore, and yesterday's access policies weren't written with software employees in mind.&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;Blocking AI doesn't work. Governing it does.&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;The consensus across both sessions matched what we tell our own customers: banning AI just drives it underground while your competitors get faster. The workable path is visibility first (discover what's actually in use), then policy (which tools, which accounts, what data), then enforcement that's smart enough to understand &lt;span style="font-weight: bold;"&gt;intent, not just keywords&lt;/span&gt;&amp;nbsp;— the difference between an employee asking an AI about "merging two sports teams" and "merging two companies."&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;em&gt;&lt;span style="font-weight: bold;"&gt;Our take&lt;/span&gt;&lt;/em&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;This event is exactly why we built our &lt;a href="https://ostailors.com/secure-workplace-ai"&gt;&lt;span style="font-weight: bold;"&gt;Secure Workplace AI&lt;/span&gt;&lt;/a&gt;&amp;nbsp;practice: policy before pilots, sanctioned tools your team will actually prefer over the ones they're sneaking, and monitoring that treats AI like the rest of your managed environment. If your organization can't currently answer "who's using what AI, on which accounts, with what data" — that's the conversation to have &lt;span style="font-style: italic;"&gt;before&lt;/span&gt; the next headline. &lt;span style="font-weight: bold; font-size: 18px;"&gt;&lt;/span&gt;&lt;a href="https://ostailors.com/secure-workplace-ai"&gt;&lt;span style="font-weight: bold; font-size: 18px;"&gt;Start with an AI readiness conversation →&lt;/span&gt;&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;span style="text-decoration: underline; font-size: 20px;"&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;And yes, there were penguins&lt;/span&gt;&lt;/span&gt;&lt;br&gt;&lt;br&gt;Huge thanks to everyone who came, to our presenters from Check Point and PlainID, and to the Living Planet Aquarium for a venue that made "security event" and "bring the family" work in the same sentence. Congratulations to "our prize winners" who took home a couple Lego sets and a laptop&amp;nbsp;— and if you missed this one, our lunch-and-learn series continues this fall. &lt;a href="https://ostailors.com/it-events-lunch-and-learns-in-utah-open-source-tailors"&gt;&lt;span style="font-weight: bold; font-size: 18px;"&gt;Get on the invite list →&lt;/span&gt;&lt;/a&gt;]&lt;br&gt;&lt;br&gt;---&lt;br&gt;&lt;br&gt;&lt;span style="font-style: italic;"&gt;Open Source Tailors has delivered honest, vendor-neutral IT guidance to businesses across Utah since 2005 — including managed security, cloud, and governed workplace AI. If you'd rather have this handled than explained, we're one conversation away&lt;/span&gt;: &lt;a href="https://ostailors.com/contact-open-source-tailors-nationwide-it-solutions"&gt;&lt;span style="font-weight: bold; font-size: 18px;"&gt;talk to a real person&lt;/span&gt;&lt;/a&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=245446418&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fostailors.com%2Fblog%2Fnotes-and-thoughts-from-the-fitting-room&amp;amp;bu=https%253A%252F%252Fostailors.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 28 Jul 2026 21:50:59 GMT</pubDate>
      <author>shea.taylor@ostailors.com (Shea Taylor)</author>
      <guid>https://ostailors.com/blog/notes-and-thoughts-from-the-fitting-room</guid>
      <dc:date>2026-07-28T21:50:59Z</dc:date>
    </item>
  </channel>
</rss>
