Visibility, Mitigation and Governance for Your Exploding AI Attack Surface
Rajnish Gupta (Tenable)
Nullcon Goa 2026 · Day 1
Overview
In an era defined by rapid technological advancement, the integration of Artificial Intelligence (AI) into enterprise operations has become a cornerstone of modern business strategy. Rajnish Gupta's talk at Nullcon, "Visibility, Mitigation and Governance for Your Exploding AI Attack Surface," delves into the critical security implications arising from this widespread adoption. Gupta, representing Tenable, a leader in exposure management, highlights that while AI offers unprecedented business benefits, it simultaneously introduces a vast and often unmanaged attack surface that poses significant risks to organizational data and infrastructure.

Key moments
- 0:00 Introduction, Pepsi analogy, and Tenable's perception
- 2:00 Tenable's exposure management and AI as a new attack surface
- 3:30 Rapid adoption and business benefits of enterprise AI
- 4:30 Critical AI security risks: data access and auditing gaps
- 6:00 Understanding the AI exposure gap: shadow AI and hidden paths
- 8:30 Tenable's AI-aware scanner for discovering AI agents
Visibility, Mitigation and Governance for Your Exploding AI Attack Surface
Speakers: Rajnish Gupta, Tenable
Conference: Nullcon
YouTube: https://www.youtube.com/watch?v=_hIpJ7xCRaY
Overview
In an era defined by rapid technological advancement, the integration of Artificial Intelligence (AI) into enterprise operations has become a cornerstone of modern business strategy. Rajnish Gupta's talk at Nullcon, "Visibility, Mitigation and Governance for Your Exploding AI Attack Surface," delves into the critical security implications arising from this widespread adoption. Gupta, representing Tenable, a leader in exposure management, highlights that while AI offers unprecedented business benefits, it simultaneously introduces a vast and often unmanaged attack surface that poses significant risks to organizational data and infrastructure.
The presentation serves as a stark warning and a call to action for security professionals. Gupta argues that the proliferation of Generative AI (GenAI) and Large Language Models (LLMs), coupled with the emergence of AI agents and "shadow AI" usage, has created a substantial gap in enterprise security visibility. Traditional security paradigms and tools are proving inadequate against these novel threats. The core of the talk centers on understanding this evolving landscape, identifying the specific challenges it presents, and outlining a strategic framework for robust AI exposure management, with a particular focus on how Tenable's solutions address these pressing concerns.
Gupta's talk underscores that AI is not merely a separate security problem but rather an integral extension of an organization's existing attack surface. Consequently, securing AI requires a holistic approach that integrates AI-specific threat detection and mitigation into an overarching exposure management strategy. The objective is to empower enterprises with the necessary tools and methodologies to gain comprehensive visibility, implement effective governance, and continuously monitor their AI deployments to safeguard against potential breaches, data exfiltration, and other AI-driven vulnerabilities.
Background
▶ Watch: Introduction, Pepsi analogy, and Tenable's perception (0:00)
The rapid and aggressive adoption of AI, particularly Generative AI (GenAI), by enterprises is a defining trend of the current technological landscape. Gupta emphasizes that this adoption is not driven by mere technological novelty but by tangible business benefits, leading to an explosive growth trajectory. Statistics presented illustrate this acceleration: AI adoption grew 3.2 times from 2024 to 2025, with a staggering 55% to 70% of organizations now actively integrating AI into their operations. This widespread embrace, however, has outpaced the development and implementation of corresponding security measures, creating a critical vulnerability gap.
A significant contributing factor to this expanding AI attack surface is the reliance on third-party packages. Gupta points out that approximately 70% of all AI tools deployed within enterprises incorporate third-party components. While this accelerates development and deployment, it also introduces supply chain risks, making organizations susceptible to vulnerabilities inherited from external dependencies. More alarmingly, 20% of these AI services are granted full access to sensitive enterprise data and critical information, yet they are rarely subjected to rigorous security audits. This creates an enormous blind spot, where powerful AI agents operate with privileged access, often without adequate oversight or protection.
The problem is further compounded by the pervasive issue of shadow AI. Much like shadow IT, where employees utilize unsanctioned software or services, shadow AI refers to the use of AI tools—ranging from browser extensions to personal GenAI subscriptions—by employees for business purposes without official IT or security department approval and oversight. This uncontrolled usage often stems from business units driving adoption for specific functions, such as HR leveraging AI for salary analysis or marketing for campaign generation. Without proper guardrails, sensitive data processed by these unsanctioned tools can be unknowingly exposed to external entities or the public, leading to severe compliance and data breach risks.
Traditional security tools, such as Data Loss Prevention (DLP) and Cloud Access Security Brokers (CASB), which have long been staples in enterprise security, are proving insufficient to address the nuances of the AI attack surface. Gupta challenges the notion that these existing solutions can adequately protect against AI-specific threats. He argues that DLP and CASB primarily rely on "fixed pattern rejects based identification," meaning they detect known patterns, keywords, or predefined data types. This approach lacks the contextual understanding necessary to identify subtle but dangerous interactions inherent in AI systems, such as sophisticated prompt injection attacks or the exfiltration of data through novel, context-dependent AI agent behaviors. The dynamic and evolving nature of AI interactions demands a more sophisticated, context-aware security paradigm that can perceive and respond to risks that fall outside of rigid, definition-based rules.
Key Findings
▶ Watch: Rapid adoption and business benefits of enterprise AI (3:30)
The central "key finding" of Gupta's presentation is the stark revelation of a significant and rapidly expanding AI exposure gap within enterprises. This gap is characterized by a fundamental lack of visibility and control over the AI assets and interactions occurring across an organization's network, leading to critical security vulnerabilities.
Firstly, enterprises struggle with a basic inventory problem. Many organizations cannot accurately answer fundamental questions such as "How many Co-pilot Studio enterprise or ChatGPT or Google agents are you running in your environment?" This absence of a clear inventory extends to the myriad of AI tools employees are using, including browser extensions and various GenAI applications, many of which fall under the umbrella of shadow AI. Without knowing what AI is present, let alone how it's being used, it's impossible to implement effective security measures. Gupta reiterates the long-standing security principle: "If we can't see something, we can't protect it."
Secondly, the talk highlights the severe risk of data exfiltration and the emergence of "hidden attack paths" created by AI agents. These agents, often connecting to vast amounts of enterprise data, can inadvertently or maliciously expose sensitive information. The lack of visibility into what data these agents access and how they process or transmit it constitutes a major concern. For instance, an HR department using AI to analyze salary data without proper guardrails could inadvertently expose confidential employee compensation details. Similarly, marketing teams generating campaigns with AI might expose proprietary strategies or customer data if the AI tool is not securely configured and monitored.
Thirdly, the presentation underscores the inadequacy of conventional security tools against AI-specific threats. While DLP and CASB solutions offer protection against certain data loss scenarios, their reliance on "fixed pattern rejects based identification" renders them ineffective against the contextual nuances of AI attacks. They struggle to identify sophisticated jailbreak attacks, prompt injection attempts, or subtle forms of data poisoning attacks that manipulate AI models to achieve malicious outcomes. These attacks require an understanding of the interaction's context, not just keyword matching or predefined rules.
Finally, the talk implicitly identifies the critical need for a continuous monitoring strategy tailored to AI applications. The dynamic nature of AI usage, with agents constantly connecting to data and users interacting in novel ways, necessitates ongoing vigilance. This continuous monitoring must extend beyond mere inventory to observe application behavior, identify anomalous connections, and detect deviations from established policies, thereby building a strong, adaptive security program for the evolving AI attack surface.
Technical Deep Dive
▶ Watch: Critical AI security risks: data access and auditing gaps (4:30)
Addressing the burgeoning AI attack surface requires a specialized and integrated approach, which Tenable aims to provide through a three-pronged strategy designed to enhance visibility, manage posture, and monitor interactions. This strategy leverages existing exposure management capabilities while introducing AI-specific functionalities.
The foundational element of Tenable's approach is AI-aware scanning. Gupta explains that this functionality is seamlessly integrated into their existing vulnerability management scanners (such as Nessus, a product synonymous with Tenable's scanning capabilities). The core purpose of AI-aware scanning is to provide a comprehensive inventory of all AI agents and applications active within an enterprise network. This includes identifying officially sanctioned AI deployments (e.g., specific GenAI platforms like Co-pilot Studio, ChatGPT, or Google agents) as well as the pervasive shadow AI instances. The scanner works by detecting various forms of AI usage, including applications running on endpoints, browser extensions that interact with AI services, and other unmanaged AI tools. By systematically discovering these assets, organizations can overcome the initial hurdle of "not knowing what they have," which is critical for establishing a baseline for security. This allows security teams to identify not only the presence of AI but also potential misconfigurations or unauthorized access points that could lead to vulnerabilities.
Beyond mere discovery, Tenable offers an AI SPM (AI Security Posture Management) solution. This is particularly relevant for organizations that are not just using off-the-shelf AI but are actively building or customizing their own Large Language Models (LLMs). Developing internal LLMs introduces unique security challenges, as the model's training data, architecture, and deployment environment can all become sources of exposure. AI SPM provides a consolidated view of these exposures, helping enterprises understand what data might be getting exposed through their custom LLMs. It assesses the security posture of the LLM development and deployment pipeline, identifying weaknesses in data handling, access controls, model integrity, and compliance. This solution is crucial for ensuring that internally developed AI capabilities do not inadvertently create new, exploitable vulnerabilities within the enterprise's data ecosystem.
The third pillar is the AI exposure solution, which focuses on the dynamic interactions of AI applications and users. This solution is designed to provide granular visibility into what AI agents are doing, how users are interacting with them, and crucially, how data and applications are getting exposed through these interactions. It moves beyond static inventory to continuous monitoring of AI behavior. This includes tracking data flows to identify potential data exfiltration attempts, monitoring for anomalous usage patterns, and detecting specific AI-centric attacks. For instance, the solution is engineered to identify jailbreak attacks, where users bypass the safety mechanisms of an LLM to elicit undesirable responses, or prompt injection attacks, where malicious prompts manipulate the AI into performing unintended actions, potentially revealing sensitive information or executing unauthorized commands. Furthermore, it helps detect data poisoning attacks, where malicious data is introduced into training datasets to compromise model integrity or introduce backdoors. By continuously monitoring these interactions, the AI exposure solution provides real-time insights into the actual risks posed by AI in an operational environment, enabling timely mitigation.
Gupta repeatedly draws a sharp contrast between these specialized AI security solutions and the limitations of traditional DLP and CASB tools. He argues that while these legacy systems are valuable for their intended purposes, their "fixed pattern rejects based identification" is fundamentally inadequate for the dynamic, contextual nature of AI threats. A DLP system might detect a credit card number based on a regular expression, but it cannot discern if an LLM is subtly leaking proprietary business strategies in response to a carefully crafted, context-dependent query. Similarly, CASB solutions, while excellent for cloud application governance, often lack the deep understanding of AI model interactions and the unique ways AI agents can access and manipulate data. The crucial differentiator, as highlighted by Gupta, is the ability to "pick up that context" and identify "risky interactions" and "risky exposures" that are not defined by static rules but emerge from the complex, often unpredictable behavior of AI systems. This contextual awareness is what Tenable's AI security offerings aim to provide, integrating seamlessly into an overall exposure management framework.
Demo / Proof of Concept
▶ Watch: Understanding the AI exposure gap: shadow AI and hidden paths (6:00)
During the presentation, Rajnish Gupta did not conduct a live demonstration or a proof of concept of Tenable's AI security solutions. The talk was primarily focused on outlining the problem of the exploding AI attack surface, detailing the challenges of visibility and governance, and introducing Tenable's approach to addressing these issues.
However, Gupta explicitly invited attendees for deeper engagement and potential demonstrations. He mentioned that Tenable had a presence at Booth 16 throughout the three-day conference, where attendees could engage in more detailed conversations and likely witness live demonstrations of their AI-aware scanning, AI SPM, and AI exposure solutions. Additionally, he highlighted a dedicated workshop titled "Identity and AI Exposure" being held in DLT 7, indicating that more in-depth technical discussions and practical insights would be available there. While the specific mechanics of a demo were not part of this particular presentation, the speaker clearly pointed to avenues where such proofs of concept would be available for interested parties.
Defensive Implications
▶ Watch: Tenable's AI-aware scanner for discovering AI agents (8:30)
The insights shared by Rajnish Gupta carry significant defensive implications for any organization grappling with the rapid integration of AI. Security teams must fundamentally shift their approach to incorporate AI-specific considerations into their broader exposure management strategy.
- Establish Comprehensive AI Inventory: The foundational defensive measure is to gain complete visibility into all AI assets within the enterprise. This means actively discovering and inventorying every AI application, GenAI tool, LLM, and AI-enabled browser extension being used across the network, regardless of whether it's officially sanctioned or falls under shadow AI. Organizations cannot protect what they cannot see. Implementing AI-aware scanning capabilities is crucial for this initial discovery phase, providing a definitive baseline of the AI attack surface.
- Define and Enforce AI Usage Policies: With an understanding of the AI inventory, the next critical step is to define clear and enforceable policies for AI usage. This includes categorizing sanctioned vs. unsanctioned AI, setting boundaries for data interaction, specifying acceptable use cases, and establishing guidelines for sensitive data handling by AI agents. Such policies must be communicated effectively across the organization and regularly reviewed to adapt to evolving AI capabilities and business needs. Governance is paramount to prevent uncontrolled data exposure and misuse.
- Implement Continuous, Context-Aware Monitoring: Relying solely on static policies or traditional security tools is insufficient. Defenders must deploy solutions capable of continuous monitoring of AI application behavior, user interactions, and data flows. This monitoring must be context-aware, moving beyond fixed pattern detection to identify subtle anomalies indicative of AI-specific attacks. Tools designed for AI exposure management can detect sophisticated threats like jailbreak attacks, prompt injection, and data poisoning attacks by understanding the nuances of AI interactions, rather than just superficial patterns. This proactive monitoring allows for early detection and rapid response to emerging threats.
- Integrate AI Security into Overall Exposure Management: As emphasized by Gartner and reiterated by Gupta, AI is an extension of the existing attack surface, not a separate problem. Therefore, AI security should not be siloed but integrated into a holistic exposure management strategy. This means connecting AI-related vulnerabilities and risks with other areas such as IT infrastructure, cloud, and identity. A unified view of exposure allows security teams to prioritize risks based on their potential impact across the entire organizational landscape, enabling more efficient allocation of defensive resources.
- Re-evaluate and Augment Traditional Security Controls: Organizations must acknowledge the limitations of traditional security tools like DLP and CASB in the context of AI. While these tools remain valuable for their intended purposes, they need to be augmented or complemented by AI-specific security solutions that can provide the necessary contextual understanding for AI interactions. Security architects should assess where existing controls fall short in protecting against AI-driven data exfiltration or manipulation and invest in capabilities that offer deeper insights into AI agent behavior and data access.
By adopting these defensive implications, enterprises can move from a reactive stance to a proactive, comprehensive strategy for securing their exploding AI attack surface, ensuring that the business benefits of AI are realized without compromising security posture.
Key Takeaways
- AI is an Exploding and Unmanaged Attack Surface: The rapid adoption of Generative AI (GenAI) and Large Language Models (LLMs) by enterprises has created a vast, dynamic, and often invisible AI attack surface, with significant growth rates (3.2x from 2024 to 2025).
- Visibility is the Foundation of AI Security: A primary challenge is the lack of comprehensive inventory and visibility into AI assets, including sanctioned AI tools, browser extensions, and widespread shadow AI. Organizations cannot protect what they cannot see, leading to critical AI exposure gaps.
- Traditional Security Tools are Insufficient for AI-Specific Threats: Existing security solutions like DLP and CASB are inadequate for AI security due to their reliance on "fixed pattern rejects based identification," lacking the contextual understanding required to detect sophisticated jailbreak attacks, prompt injection, or data poisoning attacks.
- A Holistic AI Security Strategy is Essential: Effective AI security requires a multi-faceted approach encompassing discovery, clear policy definition for AI usage, and continuous, context-aware monitoring of AI application behavior and data interactions.
- Tenable Offers Integrated AI Exposure Management Solutions: Tenable addresses these challenges with AI-aware scanning for inventory discovery, AI SPM for securing custom LLMs, and an AI exposure solution for monitoring AI agents and user interactions to detect and mitigate AI-specific threats.
- AI Security Must Integrate with Overall Exposure Management: AI is an extension of the existing attack surface, not a separate problem. Therefore, AI security measures must be seamlessly integrated into an organization's broader exposure management strategy to provide a unified view of risk and ensure comprehensive protection.
About the Speaker(s)
Rajnish Gupta is a representative from Tenable, a leading company in the field of exposure management. During his talk at Nullcon, he focused on the critical challenges and solutions surrounding the rapidly expanding AI attack surface in enterprise environments. His expertise lies in understanding the evolving landscape of cybersecurity threats, particularly those introduced by the widespread adoption of Generative AI (GenAI) and Large Language Models (LLMs), and how organizations can achieve better visibility, mitigation, and governance over these new risks. Gupta's presentation highlighted Tenable's role in helping enterprises integrate AI security into their overall exposure management strategy, drawing on the company's established background in vulnerability management and security scanning.
Reviews
Dr. Zero (Offensive Security Researcher) — HARD PASS
This is a Tenable sales pitch wearing a conference talk costume. There is no original research, no novel threat analysis, no technical depth — just a product walkthrough bookended by industry statistics and a literal invitation to visit Booth 16.
Heather Calloway (CISO) — WEAK
A vendor pitch with governance language stenciled on top. The problem framing is real — shadow AI, inventory blindness, and the limits of DLP/CASB against contextual AI threats are legitimate institutional concerns — but every road leads back to Tenable product SKUs, and the talk never escapes that gravity.