"The insider risk landscape is one of the most complex and critical security challenges facing both government and industry leaders," the DSI Production Team told Government Technology Insider.
Shadow AI, synthetic identities, and the new threat tableau
DSI frames insider risk not as the narrow problem of a disgruntled worker but as a predictive, intelligence-driven challenge reshaped by AI, hybrid work, and blurred organizational perimeters. The organization singled out several specific modern concerns: shadow AI, where employees inadvertently leak proprietary data into public generative models; sophisticated synthetic identities enabling remote infiltration; ideologically motivated insider sabotage; and rapid data exfiltration via cloud and hybrid-work channels. Each of those phenomena, DSI argued, raises both the probability of incidents and the scale of their impact.
Balancing AI adoption with governance and controls
DSI told GTI that the goal is not to block AI but to introduce it with "appropriate governance, security controls, and workforce practices." That means first mapping where AI is used, what data is fed to it, and what the tools can access or generate. Practical controls named by DSI include tightened policies around sensitive data, stronger identity and authentication, limits on third-party AI platforms, and rules for AI-generated content. Parallel actions include updating monitoring to detect data leakage, prompt manipulation, compromised AI systems, and insider misuse — and giving employees clear guidance and approved tools so they become part of the defense rather than its weakest link.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleFrom detection to prevention: behavioral insights and continuous evaluation
DSI describes a shift away from point-in-time detection toward prevention-oriented programs that combine behavioral analytics, identity data, and continuous evaluation. The recommended approach builds a baseline of normal behavior, then looks for meaningful deviations while avoiding false positives tied to legitimate role changes. Measures include risk-based access controls, least-privilege models, and data-loss prevention. Where analytics flag elevated risk, responses range from extra training and adjusted privileges to manager engagement or security review — all under the rubric that AI and analytics should “support, not replace human judgement.”
Cross-functional collaboration: security, HR, legal, IT, and leadership
DSI emphasizes that insider risk is distributed across functions: security owns tools and monitoring, HR sees workforce signals, legal and privacy set boundaries, IT manages systems and access, and leadership sets priorities. The biggest programmatic obstacles are fragmented responsibility and the need to balance security with privacy and employee trust. DSI recommends a common framework, clear roles, appropriate data governance, and defined escalation paths so that signals from identity, access, personnel changes, and security events can be correlated and acted on consistently without creating a culture of unnecessary surveillance.
What this means for technologists, HR/legal teams, and critical infrastructure operators
- Technologists and security teams: adopt identity intelligence, behavioral analytics, and continuous monitoring so access decisions are reassessed as circumstances change; apply least-privilege and separation of duties, especially for privileged accounts and operational technology.
- HR, legal, and leadership: build transparent policies and governance that allow early intervention (training, privilege adjustments, support) while protecting employee trust and privacy; define in advance how potential risks will be assessed and escalated.
- Critical infrastructure operators (energy, healthcare, transportation, defense): prioritize operational availability and safety while reducing unnecessary exposure — continuous evaluation and contextual access controls are essential where legitimate access to sensitive systems is part of the mission.
DSI predicts that AI-enabled risk analytics, predictive behavioral modeling, and continuous monitoring will push programs from reactive investigations to earlier, more contextual interventions. But their prescription is consistent: use technology to surface context and prioritize response, and preserve human oversight, transparency, and privacy safeguards so that interventions remain proportionate and workforce trust is maintained.
The organizers of the National Insider Risk Symposium — scheduled for September 15–16, 2026 — will present many of these themes directly to agencies and enterprises seeking to reconcile AI-driven productivity gains with a rapidly evolving insider threat landscape.
Read the original interview at Government Technology Insider: https://governmenttechnologyinsider.com/insider-risk-and-identity-building-a-smarter-more-human-centric-defense/




