Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Securely Enable AI

You can’t govern every agent. You can decide what they find.

AI tools and agents open company files every day, and nobody can name all of them. PK Protect, PKWARE’s data security platform, finds the sensitive data those tools can reach on laptops, file servers, Microsoft 365, databases and cloud storage. Then it protects that data, so whatever opens it finds nothing worth taking.

AI TOOLS AND AGENTSWHERE THE DATA LIVESLaptops and file serversENCRYPTMicrosoft 365ENCRYPTDatabases and warehousesREPLACE VALUESCloud storageREPLACE VALUES AI TOOLS AND AGENTSLaptops and file serversENCRYPTMicrosoft 365ENCRYPTDatabases and warehousesREPLACE VALUESCloud storageREPLACE VALUES

Trusted by leading organizations for over 40 years

JPMorgan ChaseTruistFiservWestern Union

The threat

There are more AI agents in your company than anyone can check.

For every employee, there are now about 109 machine accounts, and 79 of them are AI agents. A year ago it was 82. Forty percent of those agents can already reach company data, and they work around the clock.

AI reaches that data in two ways. The first is data people feed it, like customer records pasted into a chat window or a copy of production data used to build an assistant. The second is data an agent can already open, because it works with the same access as the account running it.

Most AI security advice covers the first way. The second is already happening in your file shares.

109

machine accounts for every employee

79

of them are AI agents

40%

of AI agents can reach company data

Source: Palo Alto Networks, 2026 Identity Security Landscape Report

Nobody can check that many accounts one by one. What you can control is what’s inside the file when an agent opens it.

What’s at risk

Every place your data lives has a different way in, and a different fix.

An agent on a laptop and an agent querying a database reach data in different ways, so the data in each place needs a different kind of protection. PK Protect matches the protection to where the data lives.

Where the data livesWhat can reach itWhat PK Protect doesWhat still works
Laptops and file serversAgents and assistants running with an employee’s accessEncrypts the file. PK Protect issues and manages the keys, and your company directory decides who’s allowed to use them, separate from file permissions.Everyone who’s supposed to open it
Microsoft 365 (SharePoint, OneDrive, Outlook, Exchange Online)AI assistants working inside your Microsoft appsEncrypts the file the same wayEveryone who’s supposed to open it
Databases and warehousesAgents, data pipelines, and AI tools built on production copiesReplaces sensitive values with realistic fake values, permanently. A real card number becomes a fake one in the same format.Applications, testing and reporting
Cloud storageAgents and AI tools with storage accessReplaces sensitive values with realistic fake values, permanently. A real card number becomes a fake one in the same format.Applications, testing and reporting

Key-based protection requires Microsoft Entra ID or Active Directory to decide who can use the keys. Realistic fake values keep the same type and length, and the same real value always becomes the same fake value, so records still match across systems. Models that have to learn from the real values need a different approach.

The method

Getting data ready for AI looks endless. It comes down to three moves.

Most teams stall because the job looks like the whole environment at once. It doesn’t have to be. Start with the place that would hurt most if it got out, and work outward from there.

01Find02Decide03FixReady for whatever AIcomes next 01Find02Decide03FixReady for whatever AIcomes next
01 Find

Find the sensitive data AI can reach

PK Protect scans laptops, file servers, SharePoint, OneDrive, Outlook, Exchange Online, databases, warehouses and cloud storage for names, account numbers, health details and other sensitive values. You pick the scope, from one repository to the whole environment, so you can start with the part that would actually hurt.

02 Decide

Know what each file is before you touch it

A marketing PDF and a spreadsheet of customer Social Security numbers can sit in the same folder. PK Protect works out what the data is first, so the fix fits.

It can encrypt a file that gets shared or copied, replace the values in a table your apps still need, or black out a few fields in a document people have to read.

ENCRYPTREPLACEBLACK OUT
03 Fix

Protect it in the same pass

Protection happens automatically, based on rules you set, instead of waiting for someone to work through a ticket. On laptops, file servers and Microsoft 365, it runs the moment a file matches.

In databases and cloud storage, it runs as a scheduled job on whatever schedule you set. Instead of a growing list of problems nobody has fixed, you get a list that’s shorter after every scan.

Why PKWARE

Most AI security tools try to watch the agents. PK Protect secures the data they reach.

The usual answer to too many agents is one more agent to watch the rest. That supervisor needs access to everything, which makes it the biggest target in the building. Protect the sensitive data first, and you don’t need to watch every agent that reaches it.

Agents get access, not keys

An agent inherits the permissions of whoever runs it. It doesn’t inherit their keys.

On laptops, file servers and Microsoft 365, PK Protect issues and manages the keys, and your company directory decides who’s allowed to use them. File permissions don’t grant a key, so giving an account more access doesn’t open the file.

The data still works

In databases and cloud storage, sensitive values become realistic fake values with the same type and length. Applications, test environments and reporting keep running, and records still match across systems.

Nothing leaves your environment

PK Protect runs where your data lives. By default it keeps only an index of what it found and where: file paths, table and column names, the type of sensitive data, and how many matches. Not the values themselves.

What PK Protect doesn’t do

PK Protect doesn’t watch AI tools, prompts or agents, and doesn’t keep a record of what a model read. It protects the data, so it matters a lot less what opened it.

PK ProtectLaptops and file serversENCRYPTMicrosoft 365ENCRYPTDatabases and warehousesREPLACECloud storageREPLACE PK ProtectLaptops and file serversENCRYPTMicrosoft 365ENCRYPTDatabases and warehousesREPLACECloud storageREPLACE
Two ways to protect, one result: whatever reaches the data finds nothing worth taking.

The payoff

Protect the data once, and you don’t start over with every new AI tool.

There’ll be a new assistant next quarter and more agents after that. If every one has to be approved before it touches your data, your team is always behind.

Once the sensitive data is protected, a new tool reaching it is a much smaller event. You get to say yes to AI without reopening the same question every time.

Proof

Trusted where the data is most regulated.

“

Data privacy is going to continue to be important. And given that we operate at a global scale, we have to stay on top of that. This is why we are making investments in technology and working with partners like PKWARE.

Harveer Singh
Author, When Data Moves
Founder, Rizz Wireless
Former Chief Data Officer, Fortune 500 banking and payments
★★★★★PK Protect

“PKWare is great to work with, support is very responsive and remediates issues in a timely manner.”

Director of IT – Banking

View on Gartner Peer Insights™

Gartner and Peer Insights™ are trademarks of Gartner, Inc. and/or its affiliates. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

Questions

Securing AI, answered

Shadow AI is any AI tool or agent people at your company use without IT’s approval, including personal accounts, browser tabs and assistants built into apps you already pay for. The real risk is the company data that ends up in those tools.

No. PK Protect doesn’t monitor AI tools, prompts or agents. It finds and protects the sensitive data those tools could reach, so it matters less which one shows up.

Protect it before anyone can paste it or point an agent at it. In databases and cloud storage, PK Protect replaces sensitive values with realistic fake values. On laptops, file servers and Microsoft 365, it encrypts sensitive files so they only open for people your company directory allows to use the key.

Not on laptops, file servers or Microsoft 365 unless it has the key. An agent inherits the permissions of whoever runs it, not their keys. PK Protect issues and manages the keys, and your company directory decides who’s allowed to use them.

In databases and cloud storage there’s no key at all. The values have already been replaced.

Yes, for anything that depends on the shape of the data or on records matching across systems. Realistic fake values keep the same type and length, and the same real value always becomes the same fake value.

It depends on what the model needs. If it learns from the structure of the data, protected data works. If it has to learn from the real values, replacing them changes what it learns, and that data needs a different approach.

No. PK Protect runs in your environment. By default it keeps only an index of what it found and where, not the sensitive values.

On laptops and file servers, in SharePoint, OneDrive, Outlook and Exchange Online, and in databases, warehouses and cloud storage including Oracle, SQL Server, PostgreSQL, Snowflake, Salesforce, Amazon S3, Azure Blob Storage and Google Cloud Storage.

On laptops, file servers and Microsoft 365, protection runs the moment a file matches your policy. In databases and cloud storage, it runs as a scheduled job on whatever schedule you set.

Find what AI can reach. Then protect it.

Talk to us about the one place you’d want protected first.