Enterprise AIr/artificial

Anyone else feel like AI security is being figured out in production right now?

Read original
ai-security-gapsshadow-ai-adoptionprompt-injection-attacksai-agent-permissionssecurity-frameworks-emerging

Enterprises are averaging 300+ unsanctioned AI apps, and in many cases AI security isn't even owned by security teams

Key takeaways

  • AI security is being figured out in production with enterprises running 300+ unsanctioned AI apps and most lacking dedicated AI security teams
  • Attack patterns mirror early-stage tech adoption: prompt injection, over-permissioned agents, and shadow IT rather than sophisticated exploits
  • Traditional security knowledge transfers incompletely - prompt injection ≠ SQL injection, agent permissions ≠ API auth - creating expertise gap despite emerging frameworks (OWASP, MITRE ATLAS, NIST)
  • AI is accelerating both sides: making it easier for attackers to find weaknesses while defenders struggle with ownership and skill gaps
  • Security frameworks exist (OWASP LLM/Agentic Top 10, MITRE ATLAS, NIST AI RMF) but practical implementation expertise is scarce

Why this matters for operators: Companies deploying AI tools without security governance; gap between AI adoption speed and security maturity

I cover AI×GTM intelligence like this every Wednesday.

Get STEEPWORKS Weekly

More picks

AI EcosystemsAI Weekly

AI Weekly Issue #481: Musk wants Altman fired, Anthropic passes OpenAI, Meta goes closed

  • Anthropic overtook OpenAI in revenue ($30B vs $24B run rate) driven by enterprise customers, doubling million-dollar accounts in under two months
  • Meta abandoned open-source AI strategy with first proprietary model under Superintelligence Labs, reversing Llama approach
  • AI legal/regulatory activity intensifying: Musk-Altman litigation escalating, Hollywood writers secured four-year AI protections
vendor-fundingmarket-consolidationregulatory-impact
AI EcosystemsThe Information

OpenAI Forecasts Advertising to Hit $102 billion by 2030

  • OpenAI projects advertising revenue to reach $102B by 2030, becoming its largest revenue driver
  • Near-term forecasts show aggressive growth: $2.4B in 2024 to $11B in 2025 (4x increase)
  • Represents strategic shift from subscription-first model to ad-supported monetization for AI platforms
vendor-fundingmarket-consolidationai-policy
GTM OpsSaaStr — Jason Lemkin

How Databricks Sells to Dozens of Industries Without Building a Single Vertical Product

  • Databricks uses 'imperatives' framework instead of traditional personas/ICP to sell horizontal platform across dozens of verticals without building vertical-specific products
  • Imperatives sit at intersection of three elements: customer priorities (OKRs/accountability), industry trends (market movements), and your product capabilities (differentiated value)
  • Traditional personas focus on buyer characteristics and ICP focuses on account fit, but neither forces you to speak the customer's strategic language or connect to their CEO's priorities
back-to-basics-gtmrevenue-platform-consolidationhuman-first-sales

This analysis was produced using the STEEPWORKS system — the same agents, skills, and knowledge architecture available in the GrowthOS package.