Close

Why Enterprise AI Security Is Failing, and What the Best Companies Are Getting Right

2026

The AI governance conversation happening in board rooms across the country is, actually, kind of missing the point. Companies are rushing to deploy AI agents, build MCP server integrations, and automate everything they possibly can, and yet the fundamental security questions remain largely unanswered. Harshit Kohli, Senior Technical Account Manager at Amazon Web Services, sees this problem up close every day. As a Gen AI streaming specialist, a doctoral candidate in artificial intelligence at University of Cumberlands, and a BIG 2025 All-Star Judge who has scored hundreds of nominations across AI, innovation, and cloud computing programs, Kohli has a front-row seat to both what is working and what is really not.

[YOUTUBE VIDEO EMBED]

And what he is seeing, frankly, should make most IT leaders a little nervous.

The Security Gap Nobody Wants to Talk About

Kohli recently spoke at the RBLN conference in Reston, Virginia, a cybersecurity and AI event focused specifically on the narrative that AI acceleration needs purpose-built silicon, not just repurposed gaming GPUs. The core problem the conference kept circling back to was, actually, pretty simple: governance is not keeping pace with deployment.

"We are dealing with critical and sensitive data," Kohli said. "Healthcare industries, finance industries, marketing industries. And when you are dealing with that kind of data, governance security has to be the top notch priority."

The numbers, if you look at them honestly, are pretty alarming. According to UpGuard's State of Shadow AI report, more than 80 percent of workers now use unapproved AI tools at work. IBM's 2025 Cost of Data Breach Report found that one in five organizations has already experienced a breach linked to unsanctioned AI use, with those incidents costing an average of $4.63 million per breach, or roughly $650,000 more than a standard breach.

Kohli's framing is a bit more vivid. He compares shadow AI to the early days of Wi-Fi, when employees would plug unauthorized routers into office ports just to move their laptops around, creating shadow IT nightmares that took years to untangle. "Now these are, I just don't know how you deal with it," he said. "You can spin up ChatGPT on your personal device and have your work done in 30 minutes."

What a Compromised MCP Server Actually Looks Like

One of the more unsettling conversations Kohli has been having lately involves the Model Context Protocol, the layer sitting between AI agents and enterprise systems. MCP has taken off fast, and it actually is enabling some remarkable multi-agent workflows. But it also introduces a very specific attack surface that most companies are not really thinking about yet.

Kohli walked through a scenario that is worth paying attention to. Imagine an agent that has access to your Slack messages or a SharePoint folder. Someone uploads a file with hidden instructions embedded in the text. The agent reads the file, summarizes it, and in the process executes those hidden instructions, potentially surfacing credentials or performing actions it was never supposed to take. This is prompt injection via data, and it is just one of several attack vectors he described. Tool poisoning, context window manipulation, and supply chain MCP servers that are malicious from day one are all, apparently, already out in the wild.

"Companies need to understand these things and put tight security guidelines and governance standards around them," he said. His practical guidance for CTOs: enforce least privilege access from the start, use sandbox execution environments for high-risk MCP tools, and require human consent and verification whenever an AI agent is performing sensitive actions.

The Shift from Answering to Acting

The thing that tends to catch organizations off guard, Kohli noted, is how fast AI agents have shifted from suggesting things to actually doing them. A few years ago, you gave a model a prompt and got a response. Now, agents can plan, iterate autonomously, make infrastructure changes, and execute multi-step workflows, all without a human in the loop unless you specifically require one.

"The more capable the agent will be, the more dangerous the autonomy will be," he said. "The core tension is that developers want speed and autonomy, and organizations need control and safety. Users like us need things that don't break silently."

The Acuvity 2025 State of AI Security report found that nearly 40 percent of organizations do not have managed or optimized AI governance, and only 15 percent have AI security under infrastructure and operations leadership.

What the Best Companies Are Quietly Getting Right

Having scored hundreds of nominations from companies competing in BIG's AI and innovation awards programs, Kohli has a somewhat unique vantage point on which organizations are actually winning the AI race, and how. The answer is, sort of, not what most people expect.

"The number one thing they are doing is investing in their people," he said. The best companies are not replacing engineers with AI. They are cross-training their staff and using AI to help each person handle more work. "If somebody is working right now with six customers, how could AI help them to achieve double the number of customers? That is the right strategy."

He is also somewhat skeptical of the rush to deploy AI without a genuine use case behind it. "If you have a use case, you should try to fit AI into that. Not okay, I want to use AI and now I want to find a use case." Gartner has predicted that 40 percent of AI projects will be canceled by next year, citing costs, unclear ROI, and lack of risk controls.

The Real-Time Monitoring Problem Nobody Has Solved Yet

One of the more fascinating things Kohli shared was a demo he presented at the MCP Dev Summit in Washington, hosted by the Linux Foundation. He built a working streaming MCP model that pushed real-time context to a Bedrock-powered AI agent using Amazon MSK (Managed Streaming Kafka), WebSockets, and IAM authorization.

The practical problem he was solving: traditional alerting systems typically fire every 15 minutes. But for a financial application running 24/7, a problem that occurs at 2:02 a.m. might not generate an alert until 2:15. That 13-minute gap is, in the financial world, potentially worth millions of dollars. His solution pushed anomaly detection to a real-time sliding window, detecting error spikes, doing root cause analysis, identifying memory leaks or connection failures, and providing remediation guidance, all automatically, as they happened.

Enjoying insights from industry leaders? Subscribe to The Winners Circle podcast on your favorite podcast player and never miss an episode. Listen and subscribe at bintelligence.com/podcast.

Close

Stay Up To Date

Be in the know about upcoming industry award programs, nominees, winners, finalists, and judges

Submit
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.