Data Security and Privacy in Enterprise Automation and AI

back to podcasts
2025-01-14 Dinesh Chandrasekar 40 min

About This Episode

In the first episode of Stratola Spectrum, Dinesh Chandrasekhar, Chief Analyst, Stratola brings together two perspectives that are increasingly inseparable: enterprise automation and data security. Joining the conversation are Amar Kanagaraj, Founder and CEO, Protecto, and Steve Shah, SVP of Product, Automation Anywhere. The discussion centers on a simple but urgent reality: as enterprises embrace generative AI and agentic automation, the surface area of data exposure expands dramatically.

Traditional enterprise systems were largely deterministic and controlled. Access was structured. Data movement was predictable. AI changes that. LLMs, agents, and automation platforms introduce non-deterministic behavior, broader user access, and new data flows across APIs, third-party services, and cloud boundaries. Sensitive data such as PII, PHI, financial information, and contractual data can now move across systems in ways that were never originally designed for AI-driven interaction.

Amar frames privacy across three critical dimensions: protecting individual rights, preventing accidental or malicious data leaks, and ensuring regulatory compliance, including data residency obligations. Steve emphasizes that automation is inherently designed to move data across systems, and when AI is layered on top, it moves context-rich and sensitive information at scale.

Key Risk Areas Discussed:

  • Prompts sent to LLMs
  • Responses generated by LLMs
  • Logs, temporary files, and data at rest
  • Agent-driven workflows spanning multiple systems
  • Cross-border cloud deployments

A recurring theme is “shift left.” Privacy and security cannot be retrofitted into AI systems; they must be designed in from the beginning. Guardrails are not optional features—they are enabling layers that allow enterprises to confidently adopt AI.

The conversation concludes with a forward-looking perspective: as agentic automation becomes more layered, distributed, and autonomous, privacy boundaries must be explicitly defined. The question is no longer whether data moves, but how controlled that movement is.

Key Takeaways

1

Agentic automation is expanding access to AI across the enterprise, and that massively increases the data exposure surface. As LLMs and agents move from back office to everyday workflows, PI and PHI can leak much more easily if guardrails are not built in.

2

AI changes the security game because it is non-deterministic, so the old control model is not enough. In traditional apps, inputs and outputs are predictable. With LLM workflows, behavior varies, so sensitive data must be identified and controlled at every touchpoint.

3

Effective guardrails are not simple redaction; they require context-aware masking that preserves LLM usefulness. If you blindly remove data, model accuracy drops. The goal is to mask sensitive fields while keeping the remaining text coherent, then unmask only for authorized users.

4

Enterprises get exposed at multiple points: user prompts, workflow steps, third-party systems, and data at rest. Risk is not only what goes into LLMs, but also what gets stored in logs, temporary files, support tickets, databases, and what comes back out as toxic or unsafe outputs.

5

Best practice is “shift-left” governance: map data flows early, set access rules, and embed guardrails into the product and data pipelines. Build privacy and compliance into design, not after deployment. Follow existing regulations like HIPAA, PCI, GDPR, DPDP, and align with security frameworks like NIST-style risk approaches.