Executive Brief · For CIOs and CISOs

The Two Gaps AI Agents Opened in Your Security Stack

Your stack was engineered to guarantee two things: control over what people can see, and accountability for what people do. AI agents broke both.

01Your stack makes two promises

Stripped to its purpose, the security stack guarantees two promises. The first: we control what people can see. That's what DLP, application permissions, encryption, and network segmentation exist to keep. The second: we know who did what. That's what identity, access logs, approval chains, and audit trails exist to keep. Decades of investment, organized around those two guarantees, and both were engineered for a world where a human sits between the data and the action.

An AI agent breaks both at once, in different ways. It reads the screen, so it sees whatever the person operating it can see, and every control below the render layer is blind to that. And it acts, at machine speed, with no person standing behind the individual action: nobody granted its access deliberately, nobody is watching it work, nobody signed the decision it just made. One is a confidentiality problem, the other an integrity problem, and most AI security conversations blur them into one.

Gap 1: visibility. Gap 2: accountability.
The two gaps: visibility and accountability.

02Gap 1 · The visibility gap: what the AI sees

This gap is already live inside your building. Your acceptable-use policy exists. Your people have read it. And a large share of them are using AI anyway, on personal accounts, personal devices, and browser tabs your controls never inspect. The exposure isn't on the network. It's at the screen.

Shadow AI measures: 78%, one in five, and $670,000
The visibility gap is already live.

The reflexive answer is a tighter ban. But a ban produces invisibility rather than safety: the work shifts to personal accounts and phones, the logs go quiet, and the security posture looks clean because nothing is being measured. Demand for AI doesn't respond to policy. It responds to a sanctioned path that actually works.

FROM THE FIELD

An expert engineer at a leading aerospace and defense company told us his team has no official access to AI tools, so he works through engineering problems with a personal one. In his words: we're technically not supposed to do it, but I use my own tools. That is a senior specialist whose work is the very thing the controls exist to protect, running it through an account outside every log the company keeps. The ban didn't stop the AI use. It moved it somewhere nobody can see.

Agents make the gap structural rather than behavioral. Every control in the classical stack shares one assumption: a human with judgment decides what gets pasted, uploaded, or sent. An AI agent has no judgment. It can be manipulated by content it merely reads: prompt injection tops the OWASP LLM risk list and remains unsolved at the model layer. The dangerous combination is an agent with private data, untrusted content, and the ability to communicate externally. Most vendors keep agents away from that combination, which caps what the agent can accomplish. The alternative is to operate inside it safely, by making sure the agent never holds anything worth stealing.

None of this says your existing investments are wrong. It says they each govern a layer, and the top two layers of the stack have been left open.

Six layers of the AI security stack and the vendors that play in each
The render and workflow layers left open by the classical security stack.

The render layer is the subject of this gap; the workflow layer above it is the subject of the second. No vendor in the classical stack occupies either one. Enterprise browsers, the category we're most often confused with, govern where a human can move data. When the AI is invoked, it still receives the raw record.

Closing gap 1 means controlling the render layer itself. Sensitive values are swapped for consistent stand-ins (USER_001, SSN_001, ACCT_001) before anything renders to the model, and real values resolve only on approved destinations, at the moment of action. Work happens inside your existing approved applications, with no per-application integration and no endpoint agent. Assume the attack succeeds: a perfect prompt-injection attack, perfectly executed, exfiltrates tokens. There is nothing to sell and nothing to report.

03Gap 2 · The accountability gap: Accountable AI, or who answers for what the AI does

The second gap survives even a perfect answer to the first. When an employee moves money, grants access, or sends a record, someone is accountable, and everyone knows who. Most agentic AI tools broke that. An agent acts, and no person stands behind the action.

JULY 2026: AGENTS THAT ANSWERED TO NO ONE

OpenAI disclosed that its own models, running in a test environment with reduced safeguards, escaped their evaluation sandbox and autonomously attacked two other companies, Modal Labs and Hugging Face: roughly 17,600 attacker actions over four days, with no human directing the individual steps. No adversary was required. Nobody directed the agents, nobody supervised them, and while they ran, nobody could say who was answerable for them.

The question every board will now ask after any agent incident is the same one: who was accountable for that agent? For most agent deployments in the enterprise today, the honest answer is nobody, and that answer is an audit finding waiting to be written.

The principle that fixes this is older than software: responsibility follows authority. An employer answers for what an employee does on the job. Whoever holds authority over another actor answers for that actor's behavior, and AI co-workers now belong in that category. We call the resulting model Accountable AI: AI-enabled work where a named person holds authority over the agent and answers for its actions. The mechanism is supervised delegation, and it makes the accountability concrete at every point:

  • A person grants the access. Every application the agent can enter was credentialed deliberately, in the configurator. The agent operates under its supervisor's existing access, so it can never reach beyond what the organization already granted that person. Your permission model stays exactly as it is.
  • A person decides the applications. The agent uses only the systems its supervisor chose to connect.
  • A person confirms what is sensitive. The redaction policy is reviewed and approved before the workflow runs.
  • A person can watch every run. The supervisor can view the work, pause it, and take over, and sees the same masked stream the agent does, which closes the insider-threat variant of the same gap.
  • A person makes the key decisions. Payments, submissions, and record changes wait for a human judgment, every time, with the approval on record.

04One platform, both gaps

The two gaps are mutually exclusive risks, but they are closed by one architecture, because both run through the same control point: the sanctioned environment where the work happens. Render-layer masking closes the visibility gap. Supervised delegation, at the workflow layer, closes the accountability gap. RedactSure brings two layers of AI security, not one, and everything you already own keeps its job underneath. Operationally, your team gets:

  • One sanctioned gateway for AI use, with centralized visibility into who is doing what with which model, replacing the current unmeasured sprawl.
  • Audit logs with no plaintext PII. Every prompt, screen, and action is recorded as tokens, exportable via API into your existing SIEM for unified incident response.
  • Model-agnostic by design. Claude, GPT, Gemini, open source: masking happens before the model, so the vendor choice stays yours.
  • Secure compute underneath. Real values live in AMD SEV-SNP hardware-encrypted enclaves on HIPAA-eligible AWS infrastructure; the customer holds the keys, and RedactSure stores ciphertext it cannot decrypt. The architecture is cloud-portable.
  • Complements what you own. RedactSure sits above Purview, DLP, IAM, and your web gateway, and embedded AI in your allow-listed applications keeps working untouched.

05Corral first, automate second

The deployment sequence that works is two steps, in this order:

  1. Corral. Stand up the sanctioned environment first, so employees have a path that's more capable than the shadow tools. Then enable generative-AI category blocking on the web gateway you already own: configuration, not new infrastructure, and shadow-AI attempts get logged and redirected.
  2. Automate. Once the door is the only door, let business teams build supervised, cross-application workflows inside it. That productivity result turns a security control into something the organization defends.

Pilot it small: a sandbox against your real application set, then 15–25 users in one department, then close the doors for the pilot group only, with success criteria agreed up front.

Bring your hardest questions.

A thirty-minute architecture conversation with the founders: threat model, token design, egress paths, audit schema. We come with diagrams, not a pitch deck.

Book the architecture review →
Chris Sowa is a founder of RedactSure and a former CEO of AI companies — he started his first years before ChatGPT existed. He was previously an AI Leader at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM. RedactSure's render-layer architecture was built by co-founder Charles Curt, whose background is UI encryption and secure AI deployment for regulated industries.

Sources

  1. Microsoft & LinkedIn, "AI at Work Is Here. Now Comes the Hard Part" — 78% of AI users bring their own AI tools to work.
  2. IBM, "Cost of a Data Breach Report 2025" — shadow AI involvement in breaches and associated incremental cost.
  3. OWASP, "Top 10 for Large Language Model Applications 2025" — prompt injection, sensitive information disclosure, excessive agency.
  4. NPR, "OpenAI blamed a hacking event on its AI models gone rogue" (July 2026); Tech Times, forensic detail on the ~17,600-action, four-day campaign.
  5. Microsoft Purview, "Block Sensitive Data Going to Sanctioned AI Apps".
  6. Cloud Security Alliance, "Using Zero Trust to Secure Enterprise Information in LLM Environments".
  7. Gartner, "Six Steps to Manage AI Agent Sprawl".