
AI didn’t create the data oversharing problem. It just made it impossible to ignore. Most enterprises have years of accumulated permission drift across their data landscape. For most of that time, the risk was theoretical. Then generative AI started surfacing sensitive files to anyone who asked the right question, and a slow-burn hygiene issue became an urgent security problem.
In this 45-minute session, Ryan Wood, CISO at VGM & Associates, and Creed Krueger, Cybersecurity Manager at VGM, share what they found when they finally got measurable visibility into their Copilot environment, how they prioritized remediation when nearly everything looked critical, and what they wish they’d known before AI rollout outran their controls.
They’ll also touch on what’s coming next: the rise of employee-built agents, the identity and ownership questions that don’t have clean answers yet, and why agent sprawl is the next visibility gap CISOs need to close.
James Pham, CEO and co-founder of Opsin, shared the patterns Opsin is seeing across enterprise deployments and where AI data security is heading over the next 6 to 12 months.
A few key insights from the conversation:
Interested in seeing Opsin in action?
Agent sprawl is the rapid, often ungoverned proliferation of AI agents across an organization, created inside tools like Microsoft Copilot Studio, ChatGPT, or Claude, often by individual employees without security review. It's a risk because each agent can inherit its creator's data access and permissions, and the sheer volume makes manual review impossible without a system for discovery and prioritization.
Start at the broadest layer first. Triage critical and high-severity issues at the site level (SharePoint, OneDrive) before moving to folder-and file-level findings. Pairing that with a risk framework: what data an agent touches, what identity it uses, how autonomous it is, and whether it's auditable, helps separate what needs immediate action from what can wait.
Build the remediation plan before you broadcast the finding. Surfacing a risk (like PHI exposure) without a plan in place creates urgency without direction, which can stall AI adoption altogether. A grounded conversation with a fix already underway lands better with leadership than an unstructured alarm.
Yes. Agents commonly inherit the permissions of the person who built them, which can grant broad access if that creator has elevated privileges. Agents also increasingly communicate with other agents, passing data and context between them without human oversight. Treating agent identity as a distinct governance category, separate from standard employee access,. is becoming a core requirement for AI security programs.
AI didn’t create the data oversharing problem. It just made it impossible to ignore. Most enterprises have years of accumulated permission drift across their data landscape. For most of that time, the risk was theoretical. Then generative AI started surfacing sensitive files to anyone who asked the right question, and a slow-burn hygiene issue became an urgent security problem.
In this 45-minute session, Ryan Wood, CISO at VGM & Associates, and Creed Krueger, Cybersecurity Manager at VGM, share what they found when they finally got measurable visibility into their Copilot environment, how they prioritized remediation when nearly everything looked critical, and what they wish they’d known before AI rollout outran their controls.
They’ll also touch on what’s coming next: the rise of employee-built agents, the identity and ownership questions that don’t have clean answers yet, and why agent sprawl is the next visibility gap CISOs need to close.
James Pham, CEO and co-founder of Opsin, shared the patterns Opsin is seeing across enterprise deployments and where AI data security is heading over the next 6 to 12 months.
A few key insights from the conversation:
Interested in seeing Opsin in action?