AI security needs full, local access to enterprise data

A cybersecurity writer argues AI tools need unfiltered telemetry and access to proprietary files kept under organizational control to detect multi-system attacks.

A cybersecurity writer argues that AI-driven security will be effective only when tools can access complete, unfiltered telemetry and proprietary files that remain under an organization’s control. The commentary states that without full-fidelity data and local control, models will miss attack chains that cross systems and create investigative blind spots.

The piece notes that many security products pre-filter and normalize telemetry before forwarding it to central systems. The author cites an estimate that logs and alerts reaching a security information and event management system represent roughly 10–20% of the events originally generated in an environment. That reduction removes timing and contextual data used to link actions across systems.

The writer describes attacks that span endpoints, cloud services, SaaS applications, network devices, operational technology and IoT sensors. An example outlines a departing employee who opens a confidential document, downloads it, uploads it to personal cloud storage and emails it externally. A conventional SIEM may record a data-loss-prevention alert for the download and a cloud-access security broker alert for the upload but lack the file contents, full access history and precise timing relationships needed to reconstruct intent and lineage.

The commentary emphasizes identity context and behavior baselines. It argues that distinguishing human users from service accounts, API keys or tokens requires identity data tied to telemetry. The author says a single unusual login is ambiguous, while hundreds of logins and device signals correlated over months can indicate whether activity matches a user’s normal travel patterns or reflects credential compromise.

Proprietary data is described as both highly targeted and often excluded from detection. Business documents, source code, customer records and financial models are frequently left out of security analysis because organizations avoid sending them to third-party clouds. The writer contends that excluding such files creates gaps that can allow insiders or attackers to move without detection.

The commentary refers to regulatory and legal frameworks as reasons organizations limit where sensitive data is analyzed. It lists the EU General Data Protection Regulation, the U.S. CLOUD Act, the Digital Operational Resilience Act and HIPAA as factors that drive organizations to keep certain data on-premises. The author recommends running AI inside an organization’s own environment so models can access full datasets without ceding control over data or model outputs.

The piece links the data issue to security operations architecture, saying that Security Operations Centers have long struggled with fragmented telemetry and that adding AI on top of those architectures can magnify gaps. It calls for prioritizing data collection and in-house analysis capabilities so AI can operate on the full set of signals needed to reconstruct complex attacks.

“Completeness and sovereignty are similar requirements viewed from two angles,” the author wrote, adding that “AI-driven security won’t be defined by who has the most sophisticated models, but by who gives their AI the most complete data.”

Articles by this author