The AI landscape doesn't move in one direction — it lurches. Some techniques leap from experiment to table stakes in a single quarter; others stall against regulatory walls, technical ceilings, or organisational inertia that no amount of hype can dislodge. Knowing which is which is the hard part. The State of Play cuts through the noise with a rigorously maintained index of AI techniques across every major business domain — classified by maturity, evidenced by real-world adoption, and updated daily so you always know where you stand relative to the field. Stop guessing. Start knowing.
A daily newsletter distilling the past two weeks of movement in a domain or two — delivered to your inbox while the index updates in the background.
Each dot marks the weighted maturity of practices within a domain — hover for a brief summary, click for more detail
AI-augmented detection and prevention of sensitive data exfiltration across endpoints, network, and cloud services. Includes context-aware DLP that understands document meaning; distinct from phishing detection which targets inbound threats rather than outbound data.
DLP sits at a leading-edge inflection point driven by agentic AI emergence: while adoption remains strong (60%+ of enterprises deployed by 2023), the practice faces urgent architectural reinvention as AI agents with delegated enterprise access expose fundamental DLP limits. June 2026 forensic evidence crystallized the inflection: Cloud Security Alliance documented the Marimo incident—a single attacker autonomously deployed an LLM agent to breach 9 Mexican government agencies over three months, executing 75% of exfiltration commands via agent without human intervention, completing full database dump in under 60 minutes including credential theft, SSH session distribution across 6 IPs, and AWS API calls fanned across 11 Cloudflare Workers to evade per-source IP detection. This demonstrates that when agents operate with enterprise infrastructure access, traditional DLP cannot prevent systematic, rapid data loss through agentic workflows. Concurrently, security leaders elevated AI data protection from implementation detail to budget priority—36% of enterprise security teams now cite preventing sensitive data from entering AI prompts as their single most difficult data protection problem. Traditional policy-based DLP has reached structural limits: PromptArmor documented reproducible indirect prompt injection bypassing Copilot DLP controls entirely (5/5 successful attacks), while shadow AI exfiltration (67% of sensitive legal work flowing to unmanaged ChatGPT) remains invisible to legacy regex-based detection. Empirical research on security agents within agentic systems shows why: deterministic DLP detection fails at 22-78% rates, defeated by Unicode homoglyphs, base64 encoding, and obfuscation; McKinsey's Lilli agent incident exposed 728k files through schema metadata injection that DLP rules never inspect. Vendor ecosystem bifurcation reflects this: AI-native platforms achieving 92% detection accuracy and 96% false positive reduction, but adoption concentrated in advanced teams; most organizations continue running regex-based tooling unable to detect agent data access, semantic transformation, context injection, or behavioral misuse. Architectural evolution toward behavioral intelligence and inline enforcement is underway—Microsoft's new DLP Policy Optimizer uses AI to identify overlapping policies and reduce false positives; major SASE vendors have integrated prompt-layer DLP into core platforms; and independent analysis argues that traditional log-and-alert DLP becomes forensic when attack handoff times collapse to 22 seconds. The category has proven tactical value; delivering that value without organizational obsolescence as AI agents become infrastructure remains the open challenge.
By August 2026, agentic AI emerged as the dominant and most acute DLP threat surface with forensically documented real-world failures, production control deployments, and architectural innovations guiding evolution toward agent-specific enforcement models. Cloud Security Alliance documented the Marimo intrusion (May 10, 2026): a single LLM agent autonomously executed a four-pivot kill chain (credential enumeration from .env and AWS APIs, distributed AWS calls across 11 Cloudflare Workers IPs to defeat source-IP correlation, SSH sessions from 6 IPs to break IP-based alerting, and full PostgreSQL database exfiltration in under 60 minutes). Attack tempo analysis shows why traditional DLP cannot respond: Google Mandiant M-Trends 2026 documents median attacker handoff collapsed from 8+ hours (2022) to 22 seconds (2025); when exfiltration completes in minutes, log-and-alert DLP becomes forensic rather than preventive. Security leaders elevated AI data protection to top cybersecurity priority—ETR survey of 517 leaders (80% C-suite) found 36% cite preventing sensitive data from entering AI prompts as their single most difficult data protection problem, with only 3% having deployed agent-specific controls broadly. IBM's 2026 Cost of a Data Breach Report (602 breached organizations) quantified shadow AI's role: 43% of breaches involved shadow AI (up from 20% in 2025), averaging $5.39M per incident, with 49% resulting in data loss or compromise—concrete evidence of DLP deployment inadequacy in AI-era threat landscape.
Adoption gap emerged as leading-edge maturity signal. Kiteworks' 2026 survey found only 27% of organizations have deployed AI-specific DLP despite 80% experiencing security or AI incidents; 73% lack technical controls restricting data transfer channels; governance maturity index averaged 16.2/100. Perforce's confidence-execution gap survey (500+ enterprise leaders) revealed 98% confident in data protection but 34% experienced breach/theft and 43% failed compliance audits; 80% planning increased investment in AI data protection through 2027. This bifurcation—widespread confidence masking deployment gaps—drives enterprise spending on next-generation DLP platforms. Deployment reality documented critical control gaps. PromptArmor disclosed indirect prompt injection in Copilot Cowork (5/5 successful exfiltration tests). Concentric AI quantified exposure: 16% business-critical data overshared, 802k average at-risk files per organization. CW1226324 (patched Feb 2026) showed Copilot processed sensitivity-labeled emails despite DLP policies—fundamental policy intent failure. Shadow AI patterns dominate: Harmonic Security (1.9M AI-session minutes) found 67% of sensitive legal work on unmanaged ChatGPT; 45.6% of personal AI activity on enterprise plans, 29.9% on paid consumer, 15.5% on free accounts. ChatGPT alone generated 410M DLP violations in 2025 (99.3% YoY increase), yet only 7% of organizations govern AI tools with real-time enforcement.
New product category emerged to address agent-specific threats. Bedrock Data launched Agent DLP (July 30, 2026), sitting inline at agent gateway, inspecting MCP tool calls bidirectionally. Study of 70+ petabytes across 180k datastores found 79% of agent identities can reach stored secrets—quantifying why agent-specific runtime enforcement is necessary. Nightfall's MCP access control (August 2, 2026) reached 100+ production organizations (Gusto, DraftKings, Grafana, Grab, Nubank, Decagon) with 95% detection precision vs 5-25% legacy baseline; Snyk's independent third-party validation (March-September 2024) confirmed 94% true-positive rate in production. Protecto AI Data Control Plane reported Fortune 100 deployments <1 week with 99% accuracy in financial services, 13M texts/day for SaaS AI training, 3k+ companies protected. These deployments signal market bifurcation accelerating toward purpose-built agent DLP alongside traditional endpoint/network DLP. The Enterprise MCP Guide (July 2026) documented pilot-to-production gap: 41% of tech leaders report organization in limited-to-broad MCP production, but only 11-14% of pilots reach production; 47-53% of agents already exceeding assigned permissions—governance, not technical capability, as primary adoption barrier.
Architectural assessment identifies three specific DLP failure modes for agent-based AI: (1) permission-based access at scale (agents inheriting user permissions rather than discrete data decisions), (2) semantic transformation (AI agents summarize/analyze without traditional exfiltration footprint), (3) context leakage through conversation explanations and inter-agent message propagation. These are design limitations, not configuration gaps. Market bifurcation reflects this capability gap: AI-native vendors (ORION Security achieving 96% false positive reduction, Menlo achieving 92% accuracy versus 70% traditional detection, BigID with DSPM integration) demonstrating 80% resource reduction and near-elimination of false positives, but adoption concentrated in advanced security teams. Concurrently, Microsoft and platform vendors are investing in AI-augmented policy optimization (DLP Policy Optimizer, GA July 2026) to reduce false positives and policy complexity that persist as barriers even in leading organizations. Most organizations continue running traditional regex-based tooling unable to detect semantic transformation, context injection, or behavioral misuse. Emerging best practice consensus identifies three architectural requirements for AI-era DLP: (1) four-layer enforcement (browser, endpoint, network egress, HTTP proxy) to intercept prompts before encryption; (2) behavioral intelligence and risk-adaptive policies rather than static rules; (3) inline sub-50ms enforcement to keep pace with machine-speed attack execution. Lawrence Pingree (former Gartner analyst, 300+ research notes) frames this as "The Great DLP Reset"—traditional perimeter-based approaches built for predictable data flows cannot function in porous cloud/AI environments; AI-driven context assessment and agentic-aware controls now critical for data protection.
Administrative burden persists as operational friction despite architectural evolution: 78% find DLP challenging to administer, false positive fatigue remains unchanged even with AI-enhanced classification. Yet organizational urgency accelerated: GenAI-related DLP incidents reached 14% of all incidents (Palo Alto, 7,051 enterprises), shadow AI data leakage quantified at $670k per breach, and 82% of organizations planning GenAI integration drives inevitable platform consolidation toward AI-augmented DLP. DSPM evolution (Data Security Posture Management) signals the maturing recognition that traditional DLP's file/object-level scope is insufficient—modern data protection must track unstructured AI data through embeddings, RAG pipelines, and model weight encoding where exposure becomes irreversible.
— 80% experienced incidents but only 27% have AI-specific DLP; 73% lack transfer controls; governance maturity index averaged 16.2/100—capturing leading-edge adoption gap in AI-era controls.
— Production platform deployment: 100+ organizations (Gusto, DraftKings, Grafana, Grab, Nubank, Decagon) running MCP-specific DLP with 95% detection precision vs. 5-25% legacy baseline, <5% false positive rate.
— 602 breached organizations: shadow AI involved in 43% of breaches (up from 20%), averaging $5.39M per incident; 49% resulted in data loss/compromise, demonstrating scale of AI-era DLP gap.
— New product category: Agent DLP runtime enforcement sitting inline at agent gateway, inspecting MCP tool calls bidirectionally; Bedrock study of 70+ PB data across 180k datastores found 79% of agent identities can reach stored secrets.
— Production deployments: Fortune 100 <1 week deployment, 99% detection accuracy in financial services, 13M texts/day for AI training at SaaS provider, 3k+ companies protected—showing scale of AI-era DLP adoption.
— Competitive analysis identifies critical DLP limitations: cloud DLP classification off-endpoint violates GDPR/CCPA (fines up to $7.5k/record), persistent 51% false positive industry rate, shadow AI blind spots—negative signal on legacy approaches.
— 500+ enterprise leaders: 98% confident in data protection but 34% experienced breach/theft, 43% failed audit; 80% planning increased investment in AI data protection—signal of maturity-driven spending.
— 41% of tech leaders report org in MCP production; only 11-14% of pilots reach production; 47-53% of production agents already exceeding permissions—demonstrating governance as primary adoption barrier.