Based on Relyance AI’s position paper, presented at RSAC 2026
Almost every data security product today is built around an assumption that’s getting more wrong by the day: if you can see the important assets, you can protect them. Find the sensitive data. Classify it. Prioritize alerts. Put locks on it.
That foundational assumption is flawed — and in the age of AI agents, it’s breaking down entirely.
The Problem with Scanners
- Object questions vs. sequence problems: Today’s tools answer “where is the data?” and “which bucket has PII?” — useful, but the wrong unit of analysis
- Risk lives in interactions: A database with PII, a service identity with admin access, an AI agent calling an external API — each is fine alone. Together, they’re a breach waiting to happen
- Scanners can’t trace sequences: They examine individual layers but miss the compound risks that emerge from data flows
- AI agents make it worse: Dynamic agents create exploding possible sequences that static scanning can never keep up with
Context Changes Everything
Without context: “Sensitive data found in production database.”
With context: “This AI agent has admin access to 2.4 million customer records, connected through an unreviewed MCP server, with no data processing agreement, violating GDPR Article 5(1)(f), and it can read, write, and delete that data right now.”
A New Approach: Data Defense Engineering
- Sees compound risk: Maps relationships between AI agents, data stores, service identities, and APIs
- Understands the why: Full context chain — what’s wrong, who’s involved, what’s impacted, what to do
- Acts at machine speed: Catches issues like code commits routing data to unapproved APIs before production
- Natural language interface: Ask questions like “Which AI agents can reach customer PII in production?” or “What changed in our data flows since Tuesday?”
At Relyance AI, we’ve built Lyo — the first AI-native intelligence that traces every data journey and attaches context. Rather than a better scanner, it’s an engineer that understands what your data is doing, who is accessing it, and why.
Proud that Relyance AI was recognized with Gold at the 2026 Globee Cybersecurity Awards for this approach.