From chatbot to autonomous agent, the AI evolution is changing the rules of data protection in real time
Artificial intelligence is one of the most prominent topics today, yet there’s still a gap between how often it’s discussed and how well its risks are understood. Given AI’s reach, it’s no surprise that it can directly affect data integrity, and understanding this impact—both its risks and opportunities—is foundational to effective safeguards.
In the Six Degrees realm of data and information security, AI is already abundantly in use. It’s able to organize and unlock vast amounts of information, scan for risks, coordinate threat responses and streamline decision-making.
It’s a critical tool in:
- Threat detection: analyzing network traffic and user behavior to surface anomalies that signal attacks
- Phishing and social engineering: studying tone and content in messaging to flag suspicious activity
- Identity, endpoint and access management: protecting entry points such as laptops and phones while efficiently stopping threats
- Data security: labeling and safeguarding sensitive information
AI has also developed beyond these applications. Where it was once primarily generative—acting as a conversational chatbot responding to prompts—it has since become increasingly proactive and autonomous in domains such as email security, security operations (SOC), endpoint and extended detection and response (EDR/XDR), and cloud network management. Modern AI can now execute multi-step processes with minimal or no human intervention, effectively becoming agentic.
From generative AI to agentic AI
Since 2024, AI’s rapid evolution toward independent execution and problem-solving has been transformative, particularly in data security and risk management. A recent Deloitte study revealed how companies are now deploying sophisticated AI agents that set goals, reason, use tools and APIs, and coordinate with people and other agents.
By 2028: Agentic AI UseNearly 3 in 4 companies plan to deploy it.5% will use it as a core operational feature.
Source: The State of AI in the Enterprise, January 2026, Deloitte
And Forbes has predicted AI will continue moving and working alongside us, with agentic and multi-agent AI systems managing entire workflows once only controlled by humans. As AI evolves into this layered ecosystem, swiftly collaborating on both simple and complex tasks, a significant concern remains: governance. Sources like Forrester warn of major breaches without proper controls and systems in place.
When speed leads to exposure
In an era where speed is a critical metric, there’s an ever-present element of risk, particularly in data loss prevention (DLP). Traditional DLP tools were not designed for today’s AI‑driven, SaaS‑forward workplace, where sensitive data can leak through code repositories, generative AI tools and cloud integrations.
A Reddit post illustrated this vulnerability in 2025: a computer science student exposed a Gemini API key in a GitHub project they believed was private. Over the following months, attackers discovered the key and used it, running up a $55,444 bill on Google Cloud.
Each day, sensitive information flows into Slack messages, whiteboards, mockups and collaborative documents, then gets copied piecemeal into AI tools. In some instances, users deliberately exploit large language models with specially worded instructions to force unauthorized outcomes—a tactic often called prompt injection. “Without robust external guardrails and human oversight, there’s nothing stopping an AI agent from ‘helping’ a user right into a data breach,” said Six Degrees Security Consultant Tyler Spillane.
For any company with broad software access, everyone plays a role in security.

Want to see how easily AI guardrails can be bypassed? Play Gandalf, Check Point’s security challenge game. Trick the AI into revealing its secret password—it’s fun, but the implications for corporate data are sobering.
The good: You can ask an agent to ‘summarize all my emails from the weekend and flag any security alerts,’ and it just does it. The bad: You’ve essentially given a bot the keys to the kingdom. If that agent has access to a directory containing sensitive company data without strict authorization, it’s not just reading it. It’s potentially exfiltrating it.
— Tyler Spillane, Security Consultant, Six Degrees Consulting
The new frontier: Model Context Protocol and agentic AI
Model Context Protocol (MCP) helps developers overcome integration challenges that once limited AI systems’ access to data and tools. As a connective layer, MCP enables AI models to evolve from passive chat interfaces into more active, agent-like systems. It lets large language model-powered applications securely call upon business tools and other internal databases so they can automate workflows, execute commands and retrieve up-to-date information. However, these same mechanisms that make MCP useful also create potential attack surfaces.
Advancing into automated, data-connected workflows requires new approaches to security, since the tools that empower these agents can also invite new threats.
Securing the AI lifecycle: The Six Degrees approach
To help businesses prepare and move forward in the AI era, Six Degrees has developed a three-pillar approach:
- Secure the model (Check Point AI Agent Security): We deploy AI Agent Security (previously known as Lakera Guard) as a shield that sits directly on the language model, providing real-time runtime protection against prompt injections and agentic exploits.
- Secure the user (Check Point AI Workforce Security): Through browser-based security and AI-specific DLP, we ensure that sensitive data—API keys, credentials and proprietary information—never leaves your environment through a prompt.
- Secure the environment (Check Point SaaS Protect): We provide visibility into which agentic platforms are being connected to your M365 or Google Workspace, reeling in shadow IT before it becomes a permanent integration.
Reducing risk in the age of AI
AI is a transformative technology, evolving from being an added layer to becoming a core part of the infrastructure itself. Agentic and multi-agent systems are beginning to manage entire workflows, expanding both efficiency and exposure. As autonomy increases, so does risk. Without proper security tools and clearly orchestrated processes, the possibility of a breach grows. And the first step isn’t a product, it’s a policy. Organizations need a written AI use policy that defines what “responsible” looks like in practice.
Six Degrees Consulting, together with Check Point, brings enterprise-level security to AI implementation, helping ensure speed and innovation aren’t at the expense of safety. To learn more about AI integration and protecting your business, contact a Six Degrees Security Specialist now.