Most Enterprises Feel Safe About AI Data Access. Most of Them Got Breached Anyway.

A new survey of enterprise security leaders turns up a telling contradiction: 82.7% are highly confident in their ability to block unauthorised AI data access, yet 72% of that same group experienced an AI-related breach in the past year. AvePoint says the culprit is static data labelling — point-in-time classification that cannot keep pace with the way AI agents actually move through an organisation.

AvePoint (Nasdaq: AVPT), the data governance platform serving more than 28,000 organisations, used Black Hat 2026 to announce Kinetic Classification — a capability that continuously re-evaluates data sensitivity across a file's full lifecycle. Under the old model, a document classified as low-risk at the time of labelling stays low-risk until someone manually reviews it. Under Kinetic Classification, sensitivity is re-assessed as data changes, permissions evolve, and AI agents interact with content.

The platform extends across Microsoft 365, Google Workspace, GitHub, ServiceNow, Jira, Confluence, Box, Okta, Smartsheet, Monday.com, DocuSign, Bitbucket, and AWS S3, aggregating sensitivity signals into a single picture rather than leaving security teams to stitch together fragmented tooling.

The second piece of the announcement is new intelligence in AvePoint's Rapid Recovery system, aimed at a different phase of the same problem. When a breach does land, recovery teams typically face days of manual triage: which data matters, in what order, which identities need restoring first. The Rapid Recovery additions — Intelligent Recommendations for prioritised restoration, a Rapid Recovery Wizard for pre-built sequenced plans, and Express Recovery for Entra ID — are designed to compress that window.

The two capabilities are designed to work together: continuous classification that tracks where sensitive data lives feeds a recovery system that already knows what to bring back first.

AvePoint's third annual State of AI Report, the research underpinning the announcement, points at a gap between confidence and operational readiness that many security programmes would prefer not to examine too closely. Three-quarters of respondents who called themselves "very confident" still logged an AI-related unauthorised access incident in the past twelve months — a figure that suggests static governance controls are providing reassurance without protection.

To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter

More News