News

How to Ensure Data Visibility and Control in AI Risk Management: A Practical Guide for CISOs

News | 15.09.2026

Many artificial intelligence risk management programs look flawless strictly on presentation slides. They correctly cite standards, assign responsible executives, and fill out risk registers. However, a simple question about which AI agents or employees accessed sensitive customer data this week and what exactly they did with it often goes unanswered. This gap between formally adopted policy and the actual lack of control is the key reason AI security initiatives stall.

The problem lies not in a lack of regulations, but in the technical inability to track real data flows. Softprom, an official distributor of Forcepoint solutions, breaks down why standard approaches to AI risk management fail and explains how to build end-to-end protection using the Forcepoint AI Data Security platform.

Where the NIST AI RMF framework breaks down

When evaluating AI risks, most security professionals rely on the popular NIST AI Risk Management Framework. It is built around four core functions: Govern, Map, Measure, and Manage. In practice, this chain breaks down right in the middle.

It is impossible to measure exposure in a system you cannot correctly map, and it is impossible to map what you do not track at the data layer.

Let’s look at how the NIST AI RMF functions work and where critical issues arise:

Govern

  • Objectives: Establishing acceptable use policies, defining accountability, and setting up evaluation procedures for third-party AI tools.
  • Reality: Most organizations successfully set up committees and publish rules. However, policies are often created before a clear picture of real-world AI usage within the company exists.

Map

  • Objectives: Defining the operational context of each AI system, analyzing processed data, and identifying potential threats.
  • Reality: A policy may prohibit entering sensitive data into third-party AI services, but Map requires knowing whether data has already entered them and through which channels. Without specialized tools, this is impossible to verify.

Measure

  • Objectives: Quantitative and qualitative risk assessment based on mapping outputs.
  • Reality: This function completely depends on the accuracy of the Map stage. If the system fails to capture Shadow AI or autonomous agents, the final risk scores become inaccurate.

Manage

  • Objectives: Implementing technical controls and taking action to mitigate risks based on measurement results.
  • Reality: Decisions made on incomplete inputs lead to hidden threats and distort the organization's true security posture.

Three main factors reducing AI security control

Studies show that over 50% of IT leaders and CISOs find mitigating AI risks extremely difficult. This stems from three primary scenarios:

  • Shadow AI: Employees actively adopt browser extensions, free web-chat accounts, and built-in AI features within corporate software. Audits based on approved vendor lists capture only a small fraction of actual AI usage.
  • Autonomous AI agents: Agents independently call APIs, read, and write data across enterprise systems without constant human involvement. Traditional monitoring cannot attribute an agent's action to a specific user or flag anomalies in real time.
  • Loss of classification context: Data correctly labeled inside file repositories often loses its classification tags once passed into AI prompts, agent working contexts, or training sets. Information remains sensitive, but control over it disappears.

The Forcepoint solution: protection at the data layer

Attempts to solve the issue by layering more internal administrative procedures yield no results. Instrumentation operating directly at the data layer is required.

The specialized Forcepoint AI Data Security suite delivers continuous visibility and control over corporate information across AI environments. Security policies and classifiers cover all interaction channels — from local Copilots to third-party cloud services.

Key capabilities of Forcepoint AI Data Security

  • Automated Shadow AI discovery: Continuous monitoring of sanctioned and unsanctioned AI applications across the corporate network.
  • Real-time prompt inspection: Preventing data leaks via text queries and files uploaded to AI models.
  • AI agent auditing and control: Full attribution of autonomous agent actions to user identities and processes to build a reliable audit trail.
  • End-to-end classification preservation: Data protection is retained regardless of where or in what form information is processed by AI systems.

The Softprom team helps enterprises implement Forcepoint solutions by providing full expert support across all stages of security system design and deployment.