
With this article, I’m kicking off a series on Prompt Security from SentinelOne—a solution that the ISCG recommends as a response to AI-related risks in business. The following installments will cover protection for developers, in-house applications, AI agents, and the entire platform.
AI has made its way into companies faster than the guidelines for its use
From the report „Cyber Portrait of Polish Business 2026” (ESET, DAGMA IT Security) shows that 62% of employees who work at a computer currently use AI in their daily tasks. One in three admits they would bypass the company’s restrictions, and nearly one in four would, in such a situation, send the results of their work from their personal device to their company email. Only 27% organizations have a written AI policy, and 38% have corporate licenses for AI tools.
The adoption of AI has outpaced risk management by years—a phenomenon the industry calls “shadow AI.” And what risks does this actually pose for companies?
⬩ Leaks of secrets and IP—code, API keys, and contract data—end up in public models, never to be recovered
⬩ Disclosure of confidential information—customer data and strategic plans beyond the company’s control
⬩ Excessive permissions for AI agents – agents with broader access than necessary are performing an increasing number of tasks
⬩ Prompt injection and jailbreak – malicious commands alter the model's behavior
⬩ Content harmful to the brand – unsecured AI applications generate responses that violate company policy.
None of these risks stem from bad faith, but rather from a lack of visibility into the threats.
≫ How does the Prompt Security platform address this?
Prompt Security, acquired by SentinelOne in 2025 and integrated into the Singularity platform, operates in four areas within the employee protection layer:
- Observability – Automatic detection of all AI tools in the organization, including shadow AI, regardless of whether they run in a browser or as a local process. Deployment via a browser extension (e.g., via Intune) provides a complete map of AI usage in just a few minutes, without any infrastructure changes.
- Data Privacy – Automatic anonymization and redaction of sensitive data (PII, financial data, source code) before it is fed into an external model.
- Risk Management and Compliance – Detailed guidelines for departments, roles, and users to help ensure compliance with regulatory requirements.
- Employee Awareness – education at the time of risky behavior, rather than relying solely on punishment after the fact.
≫ Why does this work better than a ban?
The statistics clearly show that bans don’t work, because employees will find a way around them anyway. Visibility, oversight, and education are more effective than trying to halt the adoption of AI. For organizations that process sensitive or regulated data—and ISCG serves such clients on a daily basis—this approach allows teams to reap real benefits from AI without losing control over their data.
What's next?
In the following articles, I will discuss other key security areas addressed by Prompt Security, such as: protecting developers who use Copilot and Cursor, securing their own AI applications, ensuring the security of agents and MCPs, and providing a comprehensive overview of the Prompt Security platform.
Would you like to assess the extent of the "shadow AI" phenomenon in your company right now?
Contact an ISCG consultant—we’ll help you map out your company’s AI usage and determine the scope of your Prompt Security implementation. Schedule a demo:


