Latest / Future of Work Tech with Fexingo: Remote Tools, AI Productivity, and Workplace Software / How AI Is Automating Your Internal Knowledge Security
Transcript
- Lucas: If today's tech conversation gave you something usable, we hope you'll consider supporting the show. Luna: We deliberately keep Future of Work Tech completely ad-free — no sponsors, no midroll interruptions. Lucas: If that model works for you, the simplest way to support it is buy me a coffee dot com slash fexingo. Luna: And we appreciate everyone who helps keep this independent. Now — let's talk about something that keeps a lot of security teams up at night. Lucas: Yeah — internal knowledge security. We've talked a lot on this show about how AI is making knowledge more accessible inside companies. But every time you open access, you introduce risk. Luna: And the traditional approach — just lock everything down and give permissions manually — doesn't scale once you have thousands of employees and hundreds of thousands of documents. Lucas: Right. So companies are starting to use AI to monitor how knowledge is actually being accessed — not just who has permission, but what patterns of behavior look suspicious. Luna: You mean like detecting an employee who suddenly downloads a thousand documents at 2 AM? Lucas: Exactly. That's the classic insider threat scenario. But AI can go further — it can build a baseline of normal access patterns for each role, each team, even each individual, and flag deviations in real time. Luna: I've heard of a big bank using this. They deployed an AI layer on top of their internal wiki and document management system. Lucas: Yeah, JPMorgan actually. They talked about this at a conference earlier this year. Their system tracks not just what documents are accessed, but how they're accessed — are you opening them in the web interface or are you programmatically pulling them via API? How fast are you scrolling? Are you copying text or taking screenshots? Luna: That level of granularity is impressive — but also a little creepy, no? There's a fine line between security and surveillance. Lucas: It's a real tension. And it's one that security teams are grappling with right now. The best implementations are transparent with employees — they tell them what's being monitored and why. Luna: Some companies are even letting employees see their own risk scores, which I think is smart. It demystifies the process. Lucas: Right. And it gives employees agency. If you know that downloading a bunch of files before quitting is going to flag you, you're less likely to do it carelessly. Luna: So what's the actual impact? Are data breaches going down? Lucas: According to a report from IBM's X-Force team earlier this year, companies that use ai driven data loss prevention tools saw a 40 percent reduction in insider-related breaches compared to those relying on static rules. Luna: That's a huge number. And it's not just about catching bad actors — it's about preventing accidents, right? Lucas: Exactly. Most data leaks aren't malicious — they're mistakes. Someone emails a spreadsheet to the wrong person, or uploads a confidential file to a public cloud. Luna: AI can catch those in real time too. I read about a healthcare company where the system flagged a file being uploaded to a personal Dropbox account and blocked it before it left the corporate network. Lucas: That's a perfect example. And the key is that the AI is context-aware — it knows that a spreadsheet with patient data is different from a publicly available research paper. Luna: How does it learn that context? Is it training on the company's own data? Lucas: Mostly, yes. The systems are usually trained on a combination of the company's document taxonomy and historical access logs. They learn what 'normal' looks like for that specific organization. Luna: So it's not a one-size-fits-all model. That makes sense — a law firm's access patterns are totally different from a software company's. Lucas: Right. And that's actually the challenge — every deployment is customized. It takes a few months to train the model on your environment before it becomes really accurate. Luna: What about false positives? If the AI flags me for something innocent, that could be annoying. Lucas: It happens. But the better systems have a feedback loop — if a manager reviews a flag and says 'that's fine, they're just doing their job,' the model learns from that. Luna: So it gets smarter over time. I like that. Lucas: Yeah. And the alternative is worse — either no monitoring at all, which leaves you vulnerable, or overly rigid rules that block legitimate work. Luna: Have there been any high-profile failures? A company that rolled this out and had backlash? Lucas: A few. There was a tech startup last year that implemented keystroke logging without telling employees, and when it came out, they had a mutiny. People quit. Luna: So transparency is non-negotiable. Lucas: Absolutely. The companies that do this well — like Salesforce, Microsoft — they have clear policies, they get consent, and they use the data only for security, not for performance evaluation. Luna: What's the next frontier? Where is this heading? Lucas: I think we'll see AI that can predict a breach before it happens — not just react to one. By analyzing subtle shifts in behavior weeks in advance, it could warn the security team. Luna: That sounds almost like predictive policing, but for corporate data. Lucas: It does. And it raises the same civil liberties questions. How much prediction is too much? At what point are you penalizing someone for a thought crime? Luna: That's why policies need to evolve alongside the tech. And it's why conversations like this matter. Lucas: Agreed. For now, the smart play is to start small — pick one sensitive knowledge base, apply AI monitoring, and see how it feels before scaling. Luna: Good advice. I think a lot of security teams will be experimenting with this in the second half of 2026. Lucas: Yeah. And as remote work stays common, protecting internal knowledge without killing collaboration is going to be one of the defining challenges of the decade.