Hello!
Almost every security team ran the same sequence this year. First, a policy restricting public GenAI tools. Then an internal assistant on a corporate model. Then a first wave of agents with production data access. Three new places sensitive data can leave the organisation — and not one of them is covered by the controls sitting on the database, which is where nearly enterprise protection lives today.
That gap is what we’ve spent this year building for. It goes live today.
Four things, thirty seconds.
- The launch: five capabilities that put protection where AI actually touches your data — the prompt, the upload, the agent call, the training set
- Shadow AI is a data problem, not an IT policy problem: blocking tools doesn’t work, masking what goes into them does
- The AI Act deferral is narrower than the headlines: high-risk obligations moved to December 2027, the transparency obligations did not move at all
- Analyst recognitions: Forrester includes Mage Data in its Data Security Platforms Landscape, Q3 2026, and QKS Group names Mage Data a Leader in data masking
Introducing Data Security and Privacy for AI
Protection Moves to the Prompt
Data protection used to happen at the database. An AI programme creates new places it has to happen instead, and the controls you already own don’t reach any of them.
- What’s new: Data Security and Privacy for AI goes live today — five capabilities covering training data, employee GenAI use, agent development, runtime masking and AI activity audit.
- How it works: Training Data Guardrails masks sensitive data before a model sees it. At runtime, AI Usage Guardrails masks sensitive data in employee prompts and uploads to public tools, AI Development Guardrails gives agent builders masking and authorisation APIs, and Dynamic Data Masking for AI proxies the agents you didn’t build, masking responses to match the human user behind each agent. Activity Monitoring for AI keeps the audit record across all of it.
- Why it matters: Restrictive policy alone hasn’t held anywhere we’ve seen it tried. People route around it, and you lose both the data and the record of what left. Masking at the point of use keeps work moving and produces the audit trail as a side effect.
Watch the overview → | Book a briefing →
The Deferral That Wasn’t
Europe moved its high-risk AI deadline by sixteen months. A lot of boards heard “delayed” and stood the work down. The obligations that bite first were never deferred at all.
- What’s new: Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. Standalone Annex III high-risk obligations move to 2 December 2027; Annex I embedded AI to 2 August 2028. The Article 50 transparency duties weren’t part of the deferral - they applied from 2 August 2026. The deferred high-risk requirements are unchanged in substance - only their application date moved.
- Why it matters: Procurement didn’t defer anything. Enterprise buyers added AI data-handling questions to security questionnaires on their own timetable, and those questions are being asked in live deals now.
Read the compliance whitepaper →
Where Analysts Place Us
Two independent assessments are worth having on file if you’re building the internal case for a platform approach. Forrester includes Mage Data in The Data Security Platforms Landscape, Q3 2026, its overview of the data security platform market and the vendors shaping it. And QKS Group names Mage Data a Leader in its SPARK Matrix™ for data masking.
Short Reads
-
Shadow AI: you can’t block your way out of it (5 minute-minute read)
What happens when employees route around approved tools. -
Masking for agents you didn’t build (7 minute-minute read)
Embed the controls when you own the code, proxy them when you don’t.