Three software engineers, including two men and one woman, are gathered around a laptop discussing programming code in a modern, high-rise office with large windows. The team appears to be reviewing or debugging software together, highlighting teamwork, collaboration, and the creative process in a tech startup or IT company. The cityscape outside the windows suggests a professional urban environment. This image conveys concepts of software development, agile workflow, modern business, innovation, and corporate teamwork.

For years, security teams have asked whether sensitive data is leaving the organisation. AI has quietly shifted this focus.

AI has not created a new problem; it has changed an existing one.

Users can now input sensitive information into AI tools, request summaries or analyses, and receive outputs that may still contain confidential data. Traditional DLP was designed to detect data leaving via email, USB drives, or file uploads. It was not built to address data transformed through AI prompts.

This transformation step creates a gap. The original file may remain on the network, but its contents can appear in summaries, generated reports, or AI-written emails shared externally. AI-generated content also introduces risks, including inaccuracy, non-compliance, or exposure of unintended data. DLP policies focused solely on file movement will not address these issues.

AI guardrails must address a broader question: not only where data goes, but how AI accesses, transforms, and generates it, as well as what happens to the resulting output.

Guardrails are not a new security category

It may be tempting to treat AI security as a separate function with dedicated tools and teams, but this approach is misguided. AI guardrails should extend existing controls such as DLP, secure web gateways, CASB, Zero Trust, and identity management. The goal is not to replace these controls, but to make them AI-aware so they can interpret prompts, uploaded content, AI responses, and subsequent actions.

Why AI-powered SASE matters

As AI adoption accelerates, security teams face a growing challenge: maintaining visibility, governance and control over how users interact with cloud-based AI services and the data they share.

Traditional network architectures were designed for a more predictable perimeter. They struggle when AI usage happens across cloud applications, unmanaged tools and distributed users, where sensitive data can be entered into prompts, transformed into outputs and shared beyond its original context.

This is why SASE becomes the logical control plane. By bringing networking, identity, data protection and cloud security controls into a unified architecture, SASE gives organisations a consistent way to assess AI usage, apply policy and enforce controls wherever users, devices and applications connect.

SASE provides a unified architecture capable of:
• Identifying AI applications being used
• Applying policies based on users, data and context
• Enforcing controls across users, devices and locations
• Extending visibility and governance to prompts, uploads, generated outputs and user behaviour

This allows organisations to reduce AI-related data exposure risks, apply governance consistently across approved and unapproved AI tools, enforce compliance requirements at the point of interaction and support innovation without introducing unnecessary restrictions.

Extending current identity, access and data protection policies to include AI interactions is a logical progression, not a new platform or a replacement for existing solutions.

Visibility comes first

Employees are adopting generative AI more quickly than most organisations can monitor. Shadow AI, or tools used without security’s knowledge or approval, presents an immediate risk. Employees experimenting with new AI tools often do not consider where their data is stored, how it is used to train models, or whether the tool meets compliance requirements. Their primary focus is task completion.

Before implementing policy, organisations must identify which AI tools are in use, what information is shared with them, and whether these tools meet security, privacy, and regulatory standards. Without this visibility, subsequent policy decisions are speculative.

With visibility in place, policies can become more nuanced than simple allow or block decisions. Context such as user, device, location, application, and data sensitivity enables organisations to apply proportionate controls. For example, a finance employee handling customer data requires different restrictions than someone using AI to draft internal meeting notes. This distinction is possible only with SSE-level context integrated into the platform.

AI Governance Is an Ongoing Discipline

AI tools and their associated risks evolve rapidly. New services emerge frequently, existing ones update their terms and capabilities regularly, and user behaviour changes just as quickly. A one-time deployment cannot keep pace with these developments.

Identifying AI usage, classifying risk, setting policy, enforcing controls, and adapting to new tools is ongoing work. This requires continuous monitoring and adjustment, not a project with a fixed end date. AI guardrails require ongoing governance, monitoring and policy optimisation as AI technologies, risks and user behaviours evolve. Organisations may choose to manage these capabilities internally or through a managed service provider, depending on their operational maturity and available resources.

Evolving SASE for an AI-Driven Workforce

AI does not require organisations to rip and replace their existing network architecture. It does require them to rethink where visibility, policy enforcement and governance occur. Organisations that extend their SASE architecture with AI-aware controls can enable innovation while maintaining security, compliance and operational resilience in an increasingly AI-driven workplace. At Nexon, this process begins with an assessment of current AI usage and existing SSE controls, mapping where AI guardrails can extend current capabilities.

Nexon - Garth Sperring

Garth Sperring is General Manager – Network & Cyber at Nexon Asia Pacific. For more information about strengthening security, improving network performance and simplifying connectivity with a SASE approach contact us at nexon.com.au/sase-your-way.