Enterprise AIr/artificial

Anyone else feel like AI security is being figured out in production right now?

Read original
ai-security-gapsshadow-ai-adoptionprompt-injection-attacksai-agent-permissionssecurity-frameworks-emerging

Enterprises are averaging 300+ unsanctioned AI apps, and in many cases AI security isn't even owned by security teams

Key takeaways

  • AI security is being figured out in production with enterprises running 300+ unsanctioned AI apps and most lacking dedicated AI security teams
  • Attack patterns mirror early-stage tech adoption: prompt injection, over-permissioned agents, and shadow IT rather than sophisticated exploits
  • Traditional security knowledge transfers incompletely - prompt injection ≠ SQL injection, agent permissions ≠ API auth - creating expertise gap despite emerging frameworks (OWASP, MITRE ATLAS, NIST)
  • AI is accelerating both sides: making it easier for attackers to find weaknesses while defenders struggle with ownership and skill gaps
  • Security frameworks exist (OWASP LLM/Agentic Top 10, MITRE ATLAS, NIST AI RMF) but practical implementation expertise is scarce

Why this matters for operators: Companies deploying AI tools without security governance; gap between AI adoption speed and security maturity

I cover AI×GTM intelligence like this every Wednesday.

Get STEEPWORKS Weekly

More picks

Human-AI Intersectionr/artificial

The Young Are Being Battered by AI as Hiring Shifts to Older Workers

  • Junior role elimination accelerating (43% of CEOs planning cuts vs 17% last year) as AI automation targets entry-level tasks, creating structural unemployment for early-career workers
  • AI ROI confidence declining sharply—only 27% of CEOs report meeting expectations (down from 38%), yet 74% are still freezing/reducing headcount based on automation assumptions
  • Hiring shift favors mid-level experience (30% vs 10% last year) as companies seek workers who can manage AI tools rather than perform tasks AI might automate—creating experience paradox for new graduates
ai-policymarket-consolidationback-to-basics-gtm
GTM OpsSaaStr — Jason Lemkin

Dropbox Hit $1B Faster Than Any B2B Company Ever. But Now, It’s The End of an Era

  • Dropbox achieved the fastest path to $1B ARR in B2B history with near-zero burn through perfected PLG, but revenue declined -1% in 2025 as file sync commoditized into free features from Google/Microsoft
  • The deceleration pattern is brutal: from 40% growth at $1B (2016) to 8% at $2B (2022-23) to negative growth at $2.5B (2025), showing how even perfect execution can't overcome category commoditization
  • Multiple second-act attempts (HelloSign, DocSend, FormSwift, Dash AI) failed to reignite growth, illustrating the challenge of expanding beyond a wedge product once the core becomes a feature not a product
plg-to-salesmarket-consolidationback-to-basics-gtm

This analysis was produced using the STEEPWORKS system — the same agents, skills, and knowledge architecture available in the GrowthOS package.