In this TechBullion Q&A, we speak with Tim Freestone, Chief Strategy Officer at Kiteworks, and Patrick Spencer, SVP of Americas Marketing & Industry Research, aboutIn this TechBullion Q&A, we speak with Tim Freestone, Chief Strategy Officer at Kiteworks, and Patrick Spencer, SVP of Americas Marketing & Industry Research, about

Visibility Isn’t Control: Kiteworks on Why 2026 Will Be the Year Data Security Gets Enforced

In this TechBullion Q&A, we speak with Tim Freestone, Chief Strategy Officer at Kiteworks, and Patrick Spencer, SVP of Americas Marketing & Industry Research, about Kiteworks’ newly released Data Security and Compliance Risk: 2026 Forecast Report and why many organizations are entering a critical inflection point. Based on a global survey of security, IT, compliance, and risk leaders, the report argues that enterprises are moving faster than their ability to control sensitive data—especially as AI-driven workflows become autonomous. Freestone and Spencer explain why visibility alone is no longer enough, how enforcement gaps are widening, and what leaders must do now to avoid costly failures in the year ahead.

Q: What’s the clearest signal that 2026 will feel different from “normal” cyber risk?

Tim Freestone: Agentic AI is the signal—not because it’s flashy, but because it fundamentally changes the pace of risk. We’re moving from tools that suggest actions to systems that actually take them. That compresses the time between a mistake and real-world impact, especially when those systems interact with sensitive data or downstream workflows. The risk isn’t just that AI might leak data. It’s that AI is being embedded into everyday business processes—routing, summarizing, extracting, and making decisions—where even small policy gaps can turn into large incidents. Many organizations are adopting these systems to gain speed and productivity, while governance is expected to catch up later. In 2026, teams that treat agentic AI like a standard SaaS rollout will learn quickly that autonomy doesn’t wait for quarterly control reviews.

Q: Your report suggests data security posture management (DSPM) is becoming table stakes. Why isn’t that enough?

Patrick Spencer: Because visibility is not the same as control, and too many organizations stop at visibility. DSPM can show you where sensitive data lives and how it moves, but if you can’t consistently enforce classification and tagging across channels, you’re still making decisions with incomplete authority. That’s how sensitive information drifts into unmanaged workflows, poorly governed shares, or partner exchanges that don’t apply the same controls. It’s also why incident response slows down—teams spend the first day or two debating what the data actually was and where it went instead of containing the problem. Some organizations buy monitoring to feel more confident, when what they really need is enforcement to be safer.

Q: Why does the report emphasize centralized AI data gateways so strongly?

Tim Freestone: Because AI control sprawl is already happening, and sprawl is where accountability breaks down. When each team deploys its own AI tools and point controls, you end up with inconsistent policies, uneven logging, and unclear responsibility when something goes wrong. A centralized AI data gateway provides a control plane—a single place to apply policies consistently across copilots, agents, APIs, and integrations as they scale. It also forces discipline around questions many organizations postpone: what data can be used, for what purpose, with what retention, and with what evidence trail. Centralization doesn’t remove risk, but it prevents hundreds of quiet exceptions from becoming the operating model. In 2026, patchwork AI governance won’t scale—it will fail precisely where leaders assume they’re covered.

Q: If you had to identify one missing control that will hurt teams first, what would it be?

Patrick Spencer: Containment. Containment is what protects you when the “unlikely scenario” becomes a routine incident. Monitoring and human review matter, but they’re upstream controls. Containment is what you rely on when something moves too fast or behaves unexpectedly. Many organizations talk about responsible AI while lacking practical safeguards like purpose limitation or the ability to immediately isolate or terminate a misbehaving agent. When sensitive data is involved, that’s not a theoretical gap—it’s an operational and financial one. If an agent pulls too much data or routes it incorrectly, you don’t want deliberation; you want a hard stop that works instantly. In 2026, the difference between observing risk and stopping it will define outcomes.

Q: You describe evidence-quality audit trails as a “keystone.” Why are they so critical?

Tim Freestone: Because governance without evidence is just an opinion—and auditors, regulators, and customers don’t accept opinions. Evidence-quality audit trails let organizations answer fundamental questions quickly and defensibly: who accessed the data, what happened to it, where it went, what controls applied, and what the result was. When sensitive data moves across multiple channels with uneven logging, you don’t have a coherent narrative—you have fragments. That’s why incident response drags on and communication breaks down. Strong audit trails also influence internal behavior because actions are provable, not just “logged somewhere.” In 2026, “show me the proof” will be the default expectation, which makes building for proof no longer optional.

Q: What’s the most underestimated aspect of third-party risk heading into 2026?

Patrick Spencer: The coordination gap. Many organizations still treat third-party risk as a documentation exercise—questionnaires and attestations—while real risk shows up during an incident that requires partners to act together under pressure. Without shared response playbooks and aligned controls, the first true collaboration often happens during a breach. AI complicates this further because data can be transformed, summarized, or retained in ways traditional controls weren’t designed to capture. If you don’t understand how partners handle your data inside AI systems, you’re accepting risk you can’t measure or explain later. You can outsource work, but you can’t outsource accountability.

Q: If you could mandate one board-level discussion in early 2026, what would it be?

Tim Freestone: Accountability for AI governance—who owns it, how it’s measured, and what “good” actually looks like in plain language. Boards don’t need to debate model architectures, but they should demand enforceable controls, defensible evidence, and clear escalation paths when AI-driven processes fail. The most important question isn’t “Are we using AI?” It’s “Can we prove we’re controlling it everywhere sensitive data moves?” When regulators, customers, or partners ask for proof, you either have it or you don’t—and that moment usually arrives under stress. Boards that treat AI governance as a strategic risk will drive investment in enforcement and evidence. Those that don’t will be surprised by outcomes they can’t explain. In 2026, ambiguity isn’t a strategy—it’s a liability.

For a deeper dive into these findings and what they mean for enterprise security leaders, explore Kiteworks’ Data Security and Compliance Risk: 2026 Forecast Report.

Comments
Market Opportunity
Threshold Logo
Threshold Price(T)
$0.009707
$0.009707$0.009707
-1.34%
USD
Threshold (T) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Solana Price Prediction: Mobile SKR Token Launch as DeepSnitch AI Passes $1.13 Million in 2026

Solana Price Prediction: Mobile SKR Token Launch as DeepSnitch AI Passes $1.13 Million in 2026

Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
Share
Blockchainreporter2026/01/11 00:40
BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus

BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus

The post BetFury is at SBC Summit Lisbon 2025: Affiliate Growth in Focus appeared on BitcoinEthereumNews.com. Press Releases are sponsored content and not a part of Finbold’s editorial content. For a full disclaimer, please . Crypto assets/products can be highly risky. Never invest unless you’re prepared to lose all the money you invest. Curacao, Curacao, September 17th, 2025, Chainwire BetFury steps onto the stage of SBC Summit Lisbon 2025 — one of the key gatherings in the iGaming calendar. From 16 to 18 September, the platform showcases its brand strength, deepens affiliate connections, and outlines its plans for global expansion. BetFury continues to play a role in the evolving crypto and iGaming partnership landscape. BetFury’s Participation at SBC Summit The SBC Summit gathers over 25,000 delegates, including 6,000+ affiliates — the largest concentration of affiliate professionals in iGaming. For BetFury, this isn’t just visibility, it’s a strategic chance to present its Affiliate Program to the right audience. Face-to-face meetings, dedicated networking zones, and affiliate-focused sessions make Lisbon the ideal ground to build new partnerships and strengthen existing ones. BetFury Meets Affiliate Leaders at its Massive Stand BetFury arrives at the summit with a massive stand placed right in the center of the Affiliate zone. Designed as a true meeting hub, the stand combines large LED screens, a sleek interior, and the best coffee at the event — but its core mission goes far beyond style. Here, BetFury’s team welcomes partners and affiliates to discuss tailored collaborations, explore growth opportunities across multiple GEOs, and expand its global Affiliate Program. To make the experience even more engaging, the stand also hosts: Affiliate Lottery — a branded drum filled with exclusive offers and personalized deals for affiliates. Merch Kits — premium giveaways to boost brand recognition and leave visitors with a lasting conference memory. Besides, at SBC Summit Lisbon, attendees have a chance to meet the BetFury team along…
Share
BitcoinEthereumNews2025/09/18 01:20
The Economics of Self-Isolation: A Game-Theoretic Analysis of Contagion in a Free Economy

The Economics of Self-Isolation: A Game-Theoretic Analysis of Contagion in a Free Economy

Exploring how the costs of a pandemic can lead to a self-enforcing lockdown in a networked economy, analyzing the resulting changes in network structure and the existence of stable equilibria.
Share
Hackernoon2025/09/17 23:00