How SASE Reduces AI-Related Risk and Accelerates Secure Adoption

September 24, 2026

Article
22 min

How SASE Reduces AI-Related Risk and Accelerates Secure Adoption

Secure access service edge (SASE) architectures can help organizations adopt AI securely by providing centralized visibility, access control and security policies that reduce data exposure, manage AI-driven actions and limit operational disruption.

Executive Summary

Organizations are rapidly adopting artificial intelligence (AI) technologies, including generative AI, copilots, and agentic systems, to improve efficiency, accelerate decision-making, and automate complex tasks. As these capabilities become embedded into core business processes, they introduce a new class of risks that traditional security architectures are not designed to address. These risks stem directly from how AI systems interact with sensitive data, enterprise applications, and external platforms.

At a foundational level, AI risk can be grouped into two primary domains. The first is the exposure of sensitive data, as AI systems require access to proprietary, regulated, or confidential information to deliver meaningful outcomes. This data may be transmitted to external platforms, processed in shared environments, stored for logging or debugging, or even incorporated into model training processes, often with limited visibility or control. The second domain is the risk of AI-driven actions, particularly as organizations adopt agentic AI systems capable of interacting with enterprise applications and executing tasks autonomously. These systems introduce the potential for unintended actions, inaccurate outputs, and operational disruption, especially when combined with broad access permissions and probabilistic decision-making.

These challenges are compounded by the distributed and dynamic nature of AI usage. Employees frequently access AI tools directly over the internet, often from unmanaged devices or outside traditional network boundaries, while agentic systems interact with APIs, plugins, and external services in ways that are difficult to monitor using legacy controls. As a result, traditional perimeter-based security models, built around centralized inspection and network location, are no longer sufficient to provide consistent visibility or enforce policy across AI interactions.

SASE addresses these challenges by fundamentally shifting how security is applied. It uses an identity-driven, cloud-delivered model to enforce security policies consistently across all users, devices, and applications. By converging networking and security services into a unified platform, SASE enables organizations to apply inline inspection, centralized policy enforcement, and continuous monitoring to all traffic, including interactions with AI systems.

SASE reduces AI-related risk in several critical ways. It provides control over data movement through capabilities such data loss prevention (DLP), enabling organizations to prevent sensitive information from being transmitted to unauthorized AI platforms. It enables application-level governance through secure web gateway (SWG) and cloud access security broker (CASB) controls, which restrict access to approved AI services and eliminate shadow AI usage. It enforces identity and device-aware access through zero trust network access (ZTNA), ensuring that only authorized users and compliant devices can interact with sensitive AI systems and data sources.

Equally important, SASE provides comprehensive visibility into AI usage, allowing organizations to monitor how AI tools are being accessed, what data is being shared, and how frequently interactions occur. This visibility is essential for governance, anomaly detection, and policy enforcement in environments where AI usage is decentralized and rapidly evolving. In addition, SASE supports controls over AI-generated outputs and behaviors, applying policy to reduce the risk of inappropriate content, data leakage, or unintended systems interactions.

As AI adoption matures, organizations must also account for emerging risks such as agentic AI overreach, ungoverned integrations (e.g., MCP servers), prompt injection, and uncontrolled token consumption, which can introduce both operational and financial impact. Addressing these risks requires new control layers, such as AI gateways and MCP proxies, that work in conjunction with SASE to broker, inspect, and govern AI interactions in real time.

Ultimately, SASE enables organizations to move from a reactive, perimeter-based security model to a proactive framework that aligns with how AI is actually being used. By embedding security into the flow of AI interactions, rather than attempting to contain them, organizations can reduce the risk of data exposure, limit the impact of AI-driven actions, and maintain the visibility and control required to adopt AI technologies with confidence.

Common AI Risks to SASE Controls Mapping:

  • AI models ingesting and generating sensitive data. Limit the type of data users can upload to AI models with data classifications and data loss prevention controls. Integrate DLP with AI guardrails to control the content inside of AI responses.
  • Unsanctioned “shadow” AI usage. Restrict access to only sanctioned AI applications using DNS, secure web gateway, and CASB controls.
  • Users accessing sensitive AI models from unmanaged devices. Limit access to internal AI environments based on identity context and device security posture using zero trust network access and privilege remote access.
  • AI models generating inappropriate or malicious content. Filter AI-generated content using AI guardrails and advanced threat prevention controls.
  • Lack of visibility into AI usage. Generate AI usage reports based on secure web gateway and Firewall as a Service (FWaaS) logs.
  • AI agents with too much access to internal systems and data. Use AI gateways and MCP proxies to control AI agent access.
  • AI actions utilizing too many tokens and amplifying cost. Apply usage monitoring and rate limiting controls, such as AI gateways, to govern AI resource consumption.
  • Attackers manipulating AI to perform unauthorized actions via prompt injection.

The Risk Landscape of AI Adoption

Businesses are rapidly adopting multiple forms of artificial intelligence to improve efficiency, accelerate decision-making, and reduce the manual effort required across day-to-day operations. This includes generative AI tools that assist users with creating content and summarizing information, copilots that enhance employee productivity within existing applications, and agentic AI systems that can take action on behalf of users to complete specific tasks. As these technologies become more embedded into business processes, they are no longer isolated tools; instead, they are integrated components of how work gets done across the enterprise.

The adoption of AI technology introduces a broad set of technical and business risks that organizations must carefully evaluate as they expand their use of these capabilities. While increased efficiency, automation and improved decision-making are well-understood benefits, these advantages come with new forms of exposure that traditional security architectures were not designed to address. Unlike legacy systems, AI introduces dynamic interactions between users, data, and external platforms, often outside of direct organization control.

These risks largely center on two key areas: the exposure of sensitive data, whether to or from AI systems, and the potential for AI-driven systems to take actions that negatively impact the business.

Exposure of Sensitive Data

To generate meaningful output, GenAI models must have access to data that is relevant to the user’s request. For general queries such as “what kind of trees should I plant in Las Vegas?,” the required data is typically derived from publicly available information, and no sensitive input is needed. However, for business use cases, such as developing customer strategies, analyzing internal performance metrics, or summarizing proprietary documents, the model often requires access to sensitive or confidential data that must be provided directly by the user.

This introduces a fundamental challenge: The value of AI is directly tied to the sensitivity and quality of the data it consumes. In many enterprise scenarios, meaningful outcomes cannot be achieved without incorporating internal business context. As a result, organizations are often required to expose data that would traditionally remain within controlled systems and environments.

Once submitted, that data may be processed, stored, or used to improve underlying models, depending on the architecture and policies of the AI platform. This introduces several distinct risk scenarios that organizations must consider, each with different implications for data security and control.

Data may be processed transiently but still exposed during execution. Even when platforms claim not to retain data long-term, the data must still be transmitted to and processed within external systems. During this process, organizations have limited visibility into how the data is handled in memory, what security controls are applied during processing, or whether it is exposed to shared infrastructure. This creates a risk that sensitive data is momentarily accessible outside of the organization’s control, even if it is not permanently stored.

Data may also be explicitly stored or logged by the AI platform. Many AI services log prompts and responses for debugging, auditing, or service improvement purposes. In these cases, sensitive information may persist within provider environments beyond the original interaction. This creates concerns around data retention policies, access controls within the provider, and the potential for that data to be accessed by internal personnel, third parties, or through compromise of the provider itself.

Additionally, data may be retained and reused to improve models. Depending on the service and configuration, user-provided data may be incorporated into training or fine-tuning processes. This introduces a more persistent form of risk, where sensitive information is no longer tied to a single transaction but becomes part of the model’s learned behavior. Over time, this increases the possibility that elements of that data could influence future outputs, potentially exposing sensitive information in indirect or unintended ways.

There is also risk associated with data aggregation and correlation. Even if individual prompts do not appear sensitive in isolation, AI platforms may process large volumes of interactions across users and organizations. This creates the potential for data to be aggregated, correlated, or inferred in ways that reveal sensitive patterns, business insights, or operational details that were not explicitly disclosed in a single interaction.

These risks are amplified by the lack of transparency and variability across AI providers. Organizations often have limited visibility into where data is processed, how it is isolated between tenants, and what security controls are consistently enforced. This lack of transparency makes it difficult to validate whether data is being handled in accordance with organizational policies or regulatory requirements.

For these reasons, organizations must establish strict controls over which AI applications are accessible to users and how data is transmitted to and from those platforms. Based on the risks outlined, priority should be placed on controls that govern data movement, application access, and visibility into AI interactions.

Data protection controls, such as data classification and data loss prevention (DLP), are critical to limiting the exposure of sensitive information during AI interactions, particularly in scenarios where data is transmitted externally or processed by third-party platforms. Equally important are application control mechanisms, including secure web gateway and CASB capabilities, which enable organizations to restrict access to approved AI services and reduce risk introduced by unsanctioned or shadow AI usage.

In addition, organizations must implement controls that provide visibility into how AI systems are being used. Monitoring, logging, and inspection of AI-related traffic allow security teams to understand what data is being shared, how frequently AI tools are accessed, and whether usage aligns with organizational policies. Without this level of visibility, many of the previously described risks can occur without detection.

Without these controls, AI adoption can unintentionally expand the organization’s attack surface, introducing persistent data exposure risks and limiting the ability to govern how sensitive information is used.

Unauthorized (Autonomous/Agentic) AI Actions

Beyond data exposure, AI adoption introduces a second and equally significant concern: the potential for operational disruption and reputational harm resulting from the actions and outputs of AI systems.

As organizations expand their use of agentic AI, they are increasingly relying on systems capable of performing tasks that were previously executed by humans. These tasks range from software development and customer engagement to research, analytics, and content generation. As these systems become more embedded into business workflows, their influence on operations continues to grow.

The effectiveness of these systems is directly tied to the level of access and autonomy granted to them. To deliver meaningful value, AI agents often require integration with enterprise applications, access to sensitive data and, in some cases, the ability to take action with production environments. This creates an inherent tradeoff between efficiency and control. Systems that are overly restricted provide limited value, while those granted broader access introduce increased risk.

In practice, this risk is often introduced through how AI agents are connected to external systems and services. Many modern agentic frameworks rely on extensibility models such as APIs, plugins, or Model Context Protocol (MCP) servers to retrieve data and execute actions. While these integrations enable powerful capabilities, they also introduce new attack surfaces. For example, the use of unvetted or shadow MCP servers deployed outside of IT governance can allow AI agents to interact with unauthorized data sources or execute actions in environments that lack appropriate security controls. This creates a scenario where sensitive data may be accessed or modified through pathways that are not visible to security teams.

Unlike traditional automation, AI-driven systems are probabilistic in nature. Their outputs are based on patterns and likelihoods rather than deterministic logic, which increases the potential for inaccuracies, unintended actions, or misinterpretations of context. When these probabilistic outputs are directly tied to system-level actions, the risk extends beyond incorrect responses to include real operational impact.

For example, an AI agent tasked with automating customer communications may generate and send incorrect or misleading information due to incomplete context or flawed reasoning. Similarly, an agent integrated with development or infrastructure systems may trigger unintended configuration changes, execute incorrect scripts, or interact with APIs in ways that produce unintended side effects. In more complex environments, chained actions across multiple systems can amplify these errors, causing cascading failures that are difficult to detect and remediate.

There is also risk associated with prompt injection and context manipulation, where external or untrusted inputs influence the behavior of an AI agent. In agentic systems that dynamically retrieve data or execute actions based on input, a malicious or malformed prompt can alter decision logic, bypass intended safeguards or cause the agent to interact with unauthorized systems. When combined with excessive permissions or insufficient validation, this can result in actions being taken outside of the intended scope of the system.

In addition to access-related concerns, agentic AI introduces risk tied to resource consumption and cost, particularly in environments where usage is based on tokenized billing models. AI systems, especially those that leverage large language models, consume tokens for both input and output, and these costs can scale rapidly as usage increases.

Resource consumption in AI systems can be unpredictable due to the unbounded and iterative nature of the interactions. For example, an AI agent performing research, generating code, or interacting with APIs may execute multiple chained prompts, expand context windows, or repeatedly refine outputs. Each of these interactions consumes additional tokens, often without clear visibility into how many iterations are occurring or why.

This creates a scenario where a single user request can result in significant downstream token consumption, particularly when agents are allowed to operate autonomously or across multiple systems. In poorly governed environments, this can lead to unexpected cost overruns, inefficient use of compute resources, and difficulty forecasting AI-related spend. Inefficient prompts, excessive context inclusion, or repeated tries due to low-confidence outputs can all drive increased token usage without delivering proportional business value.

The impact of these failures extends beyond technical consequences. Inaccurate outputs delivered to customers, misleading insights used in executive decision-making, or publicly visible errors in AI-generated content can erode trust and damage brand reputation, while inefficient consumption of resources tied to AI usage can drive up operational costs. These risks are amplified by the speed and scale at which AI operates, allowing issues to propagate more quickly than in traditional systems.

Securing AI adoption, therefore, is not solely about protecting data; it is equally about controlling how AI systems interact with users, systems, and external audiences. Organizations must implement guardrails that govern access, validate outputs where appropriate, and limit the potential impact of AI-driven actions.

This requires the introduction of control points between users, AI systems, and downstream services. For example, AI gateways or MCP proxies can be used to broker and inspect interactions between AI agents and external tools or data sources. These intermediaries allow organizations to enforce policies around which services an agent is permitted to access, while also providing a mechanism to log, audit, and restrict agent behavior in real time. These controls must also govern how AI systems consume and act on data. This includes validating inputs to reduce the risk of prompt injection or context manipulation, as well as applying output filtering and validation to ensure that responses or actions align with business policies.

How SASE Reduces AI Adoption Risk

Secure access service edge (SASE) is a cloud-delivered network security architecture that converges connectivity and security services into a single, unified platform. It is designed to replace traditional approaches such as perimeter-based security models that rely on physical appliances and exposed VPN gateways.

In a SASE architecture, capabilities that were historically delivered through separate point solutions are integrated into a single fabric with centralized policy management. Rather than routing traffic through a centralized data center for inspection, security controls are applied closer to the user through a distributed cloud infrastructure. This enables consistent enforcement regardless of user location, device type, or application being accessed.

A key differentiator for SASE is its reliance on identity as the primary control plane. Access decisions are no longer based solely on network location but instead incorporate identity, security posture, and contextual signals. This model aligns closely with zero-trust principles and is particularly well-suited for environments where users, applications, and data are highly distributed.

This represents a shift from traditional network security architectures, which were built around the concept of a defined perimeter. In legacy models, access decisions are often based on whether a user is inside or outside the network, typically enforced through VPNs and centralized security appliances. While this approach was effective when applications and users were largely confined to corporate networks, it becomes increasingly ineffective in modern environments where users are remote, applications are cloud-hosted, and AI services are accessed over the internet. Attempting to control these interactions using perimeter-based approaches introduces latency and gaps in visibility and enforcement, particularly when users are accessing resources directly from unmanaged devices or external networks. SASE eliminates this dependency by bringing security enforcement closer to the user.

One of the primary ways SASE reduces AI-related risk is through control over data movement. As outlined earlier, the value of AI is directly tied to the data it consumes, which often includes sensitive or proprietary information. SASE architectures incorporate data protection capabilities, such as data loss prevention (DLP) and inline traffic inspection, that allow organizations to monitor and restrict what data can be transmitted to AI applications. This enables policies such as preventing the upload of regulated data, blocking the sharing of intellectual property, or alerting on risky behavior. By enforcing these controls inline, organizations can reduce the likelihood that sensitive data is exposed to AI platforms in an uncontrolled manner.

SASE also addresses the risk of unsanctioned or “shadow” AI usage, which is a common challenge as employees adopt AI tools independently to improve productivity. Through secure web gateway and CASB capabilities, organizations can identify which AI applications are being accessed, categorize them based on risk, and enforce policies that restrict access to only approved platforms. This ensures that interactions with AI systems occur within environments that meet the organization’s security and compliance requirements, rather than through unvetted external services.

Another critical capability is identity- and device-aware access control, delivered through zero trust network access (ZTNA). AI systems, particularly those integrated into internal workflows or hosted in private environments, often require access to sensitive data and business-critical applications. SASE enables organizations to restrict access to these systems based on user identity, device posture, and other contextual signals. For example, access to internal AI models or data sources can be limited to managed devices that comply with security posture requirements and to specific user roles. This reduces the risk of sensitive AI interactions occurring from unmanaged or potentially compromised endpoints.

In addition to controlling access and data movement, SASE provides visibility into AI usage and behavior. Because all traffic is inspected and logged, organizations gain insight into how AI applications are being used across the enterprise. This includes visibility into which users are accessing AI tools, what types of data are being transmitted, and how frequently these interactions occur. This level of visibility is critical for governance, as it allows security teams to detect anomalies, identify risky patterns, and ensure that AI usage aligns with organizational policies.

SASE also helps mitigate the risks associated with AI-generated outputs. Through integrated security controls, organizations can apply filtering, inspection, and policy enforcement to the responses generated by AI systems. This may include blocking malicious content, inappropriate or offensive content, and the distribution of sensitive information. While SASE does not replace the need for application-level guardrails, it provides an additional layer of control at the network access level.

SASE Security Capabilities:

Secure Web Gateway (SWG). Controls access to internet sites and SaaS applications through advanced web security enforcement. In the context of AI adoption, SWG plays a critical role in controlling which AI applications users are allowed to access. As employees turn to external GenAI tools to improve productivity, many of these interactions occur using web browsers and web-based client applications. SWG enables organizations to identify and categorize AI applications, block access to unsanctioned or high-risk platforms, and enforce acceptable use policies. For example, an organization may allow access to an approved enterprise AI platform while blocking access to public or unvetted AI services where data handling practices are unknown or undesirable for business use cases.

Firewall as a Service (FWaaS). Enforces network access policies based on IP address, port, and protocol. FWaaS provides network-level control over how AI-related traffic flows between users, systems, and external services. While many AI interactions occur at the application layer, FWaaS can still be used to restrict communication paths. FWaaS can prevent AI-integrated applications from initiating outbound connections to unauthorized external endpoints.

DNS Security. Provides domain-level control and visibility into DNS requests and responses. DNS security is particularly effective in identifying and blocking access to newly created, suspicious, or unclassified AI-related domains. Shadow AI tools, unofficial MCP servers, and malicious AI services commonly rely on domains that may not yet be categorized or widely recognized. For example, access to newly registered domains can be proactively blocked before a connection to the server is ever established.

Cloud Access Security Broker (CASB). Provides granular control over SaaS and cloud application access, including tenant restrictions and user activity controls. CASB is one of the most critical controls for managing AI risk, particularly in SaaS-delivered AI platforms. It provides visibility into how AI applications are being used and which users are interacting with them. CASB can enforce policies such as restricting access to specific AI tenants, such as corporate versus personal accounts, blocking file uploads to unsanctioned but tolerated AI platforms, and preventing the copying and pasting of data into AI prompts.

Data Loss Prevention (DLP). Classifies and protects sensitive data by controlling how it can be shared and used. DLP is the foundational control for mitigating data exposure risks associated with AI. It enables organizations to inspect data in motion and enforce policies that prevent sensitive information from being transmitted to AI applications. This may include detecting and blocking financial data, PII, and intellectual property. If a user attempts to paste a customer dataset or financial report into an AI prompt, DLP can block the action or trigger an alert.

Advanced Threat Prevention (ATP). Detects and blocks malicious activity using sandboxing, behavioral analysis, and threat intelligence. ATP capabilities help identify and mitigate threats associated with malicious content or adversarial inputs. For example, if an AI agent retrieves data from an external source that contains embedded malicious payloads, threat prevention controls can detect and block that activity.

Zero Trust Network Access (ZTNA). Delivers secure remote access to internal applications without exposing traditional VPN infrastructure. ZTNA controls access to internal AI systems and data sources. As organizations deploy private AI models or integrate AI into internal workflows, it becomes essential to ensure that only authorized users and devices can access these environments. This reduces the risk of sensitive AI interactions occurring from unmanaged endpoints and ensures that AI systems are not exposed through traditional VPN-based access models.

Remote Browser Isolation (RBI). Executes web sessions in an isolated environment to prevent direct interaction with potentially risky content. RBI can be used to reduce risk when users interact with unknown or untrusted AI platforms. Instead of allowing direct interaction from the user’s device, sessions are executed in an isolated environment, preventing data leakage or malicious content from reaching the endpoint. For example, if a user must access an unapproved AI tool for research or testing, RBI can isolate that session, prevent any data exchange between the user’s local device and the AI platform, and limit exposure to potential threats.

AI Guardrails. Applies policy, validation, and control mechanisms specifically to AI interactions. AI guardrails represent an emerging set of controls designed to manage how AI systems are used and how they behave. These controls can be implemented through AI gateways and MCP proxies. Examples of AI guardrails include validating prompts to prevent injection or misuse, filtering AI-generated outputs for sensitive or inappropriate content, enforcing policies on which tools or APIs an agent can access, and applying rate limits or usage thresholds to control token consumption.

Use SASE as the Foundation for Secure AI Adoption

Taken together, these capabilities allow SASE to directly address the two primary risk domains associated with AI adoption. It reduces the likelihood of sensitive data exposure by controlling how data is accessed and transmitted, and it limits the potential impact of AI-driven actions by enforcing access controls, monitoring behavior, and applying policy to both inputs and outputs. By embedding these controls into the fabric of network connectivity, SASE enables organizations to adopt AI technologies more confidently without sacrificing visibility or control.

Appendix: Real-World AI Security Incidents

Samsung Sensitive Data Exposure via GenAI
In 2023, Samsung engineers unintentionally leaked confidential source code and internal meeting notes by inputting them into ChatGPT while trying to debug and summarize work. The data was transmitted to external servers and could not be retrieved, raising concerns about retention and reuse. This led to a ban on GenAI tools for internal employees due to the exposure of proprietary intellectual property, triggering enterprise-wide concern about data governance and AI usage.

Source: https://www.forbes.com/sites/siladityaray/2023/05/02/samsung-bans-chatgpt-and-other-chatbots-for-employees-after-sensitive-code-leak/

Google AI Hallucination
During a 2023 public demo, Google’s AI chatbot incorrectly stated that the James Webb Space Telescope captured the first image of an exoplanet, which is factually incorrect. This led to a reported loss of approximately $100 billion in market value following the incident. This highlighted the risks of AI-generated misinformation in high-visibility scenarios.

Source: https://www.cnn.com/2023/02/08/tech/google-ai-bard-demo-error

Air Canada Chatbot Hallucination Court Case
An AI chatbot provided incorrect refund policy information to a customer. A tribunal ruled that Air Canada was responsible for the chatbot’s output. This set the legal precedent that companies are liable for AI-generated responses from systems they manage and use.

Source: https://www.forbes.com/sites/marisagarcia/2024/02/19/what-air-canada-lost-in-remarkable-lying-ai-chatbot-case/

Microsoft 365 Copilot Prompt Injection (CVE-2025-32711)
EchoLeak research demonstrated how prompt injection techniques can be used against Microsoft 365 Copilot by embedding malicious instructions within content such as emails or documents. When Copilot processes this content, it can be manipulated into exposing sensitive data or altering its behavior by treating the injected instructions as valid context.

Source: https://www.varonis.com/blog/echoleak

Uber AI Cost Overrun
Uber exhausted its entire 2026 AI coding budget within the first four months after rapidly adopting AI coding tools such as Claude Code across its engineering organization. The cost overrun was driven by token-based consumption, where increased usage from agentic workflows and large-scale code generation led to significantly higher-than-expected spending. This highlighted challenges in managing token-based consumption at enterprise scale and triggered a reassessment of AI cost models and usage governance.

Source: https://fortune.com/2026/05/26/uber-coo-ai-spending-tokens-claude-code/

Learn more about how CDW security experts can help your organization implement SASE and successfully adopt AI technologies.

Charles Cartwright

Executive Technology Strategist

Max Reczek brings over 10 years of expertise in writing and strategic content creation, covering a wide array of topics for CDW as an editorial lead. His focus areas include security, operational technology, IoT, financial services, manufacturing and more.