AI: The double-edged sword breaking and fixing data security

Friday, 21 August 2026 00:02 -     - {{hitsCtrl.values.hits}}

 Dialog Axiata Group Analytics and AI Data Architect Dilshan De Saram (second from right) speaks at the panel discussion. Others from left: Concentric AI Regional Vice President – APAC Chris Farrelly, Brandix Fortude IT Infrastructure and Cybersecurity Associate Vice President Prageeth Kapuruge, VitalProbe Founder and CEO Billa Bhandari and Moderator CICRA Holdings Group Director/CEO Boshan Dayaratne       – Pix by Upul Abayasekara and Ruwan Walpola


 

  • Daily FT-CICRA second Data Privacy and Protection Summit explores how AI is transforming both cyber threats and defences

 

Artificial Intelligence (AI) is simultaneously the fastest-growing risk to enterprises and the most powerful tool available to defend against that very threat—a paradox that took centre stage at the 2nd Data Privacy and Protection Summit 2026, held on 23 July at the Oak Room, Cinnamon Grand Colombo.

The full day summit, organised by CICRA and Daily FT, drew a packed house of over 380 senior professionals spanning data protection, governance, compliance, and cybersecurity. The event was supported by Mastercard as Title Partner, Concentric AI as Strategic Partner (in partnership with Orin Corporation), People’s Bank as Exclusive Banking Partner, and LankaPay as Silver Partner.

With Sri Lanka’s Personal Data Protection Act (PDPA) enforcement drawing nearer, the summit provided a critical platform for understanding how AI enablement is transforming both the threat landscape and defensive capabilities.

Delivering the opening address, Digital Economy Deputy Minister Eng. Eranga Weeraratne stressed that the tone for data protection within organisations must be set from the top, calling on business leaders to elevate data privacy and cybersecurity from an IT function to a strategic priority.

“Privacy is about safeguarding personal and sensitive information, while protection is about ensuring the security of that data against misuse, unauthorised access, and cyber threats. Public trust, therefore, will ultimately determine the success of digital transformation,” he said.

The Deputy Minister noted that privacy and data protection must be designed into digital systems from the outset rather than being treated as an afterthought. “This is not simply an issue for IT departments. Boards of Directors, Chairpersons, and Chief Executive Officers must treat data protection and privacy as strategic priorities,” he emphasised.

Concentric AI Regional Vice President – APAC Chris Farrelly, delivered the keynote address on the session “Protecting Your Crown Jewels – AI is Breaking Data Security and Fixing It?”

Farrelly painted a stark picture of the current landscape: employees are using public AI tools daily, AI is embedded into core workflows, and copilots and assistants are being rolled out across organisations yet for security teams, AI usage remains largely invisible.

“AI is the fastest growing risk in the enterprise. And most organisations can’t see it,” Farrelly told the audience.

He warned that security teams have no visibility into prompts and responses, and data is flowing into tools they do not control. The new data exposure points created by AI are particularly concerning sensitive data entered in prompts and responses that expose confidential information.

Farrelly argued that traditional security controls were never built for this reality. They lack prompt and response level visibility, policies cannot keep pace with dynamic usage, and there is no understanding of data context.

“Data security was already struggling, and AI accelerates the problem,” he said, pointing to chronic issues including incomplete data discovery, extreme labour intensity, high false-positive rates, and an impossibility to operationalise.

However, Farrelly presented a compelling way forward: AI itself enables the solution. Unlike traditional models based on rules, regex, and labels, AI-powered security understands unstructured data, learns patterns without rules, and adapts as data and usage evolve.

The shift, he explained, is from an old model of Rules, Regex, Labels to a new model of Context, Meaning, Relationships.

He outlined what becomes possible with AI-driven data security: identifying risky users and applications, detecting sensitive data in prompts, preventing exposure in real time, and tracking prompts, responses, and violations. “From chaos to control moving from noise, uncertainty, and inaction to precision, confidence, and enforcement,” he said. 

Brandix Fortude Associate Vice President – IT Infrastructure and Cybersecurity Prageeth Kapuruge, delivered the guest address, bringing deep technical expertise to the discussion. 

He presented sobering statistics: 48,185 new CVEs in 2025 a 20.6% jump on top of 2024’s 38% surge. The mean time to exploit has dropped to 10 hours in 2026, down from 56 days in 2024. Average adversary breakout time fell to 29 minutes down from 48 minutes in 2024; in one case, data exfiltrated just four minutes after initial access. In one state-aligned campaign, 80–90% of tactical steps were performed by AI.

“The attackers are already ahead,” Kapuruge warned.

His solution: use AI Agents to defend. He distinguished between Generative AI confined to conversation and AI Agents, which are given goals, tools, and the ability to act, plan, execute, observe, and try again until the job is done.

“An LLM given goals, tools and the ability to act plan, execute, observe, and try again until the job is done,” he explained.

Kapuruge demonstrated how AI Agents change the equation through human like reasoning understanding context the way an analyst would, not by pattern matching combined with broad domain knowledge, machine-like speed, and the ability to scale with load.

He presented GuardianAI, an autonomous AI agent that achieves an average time of 120 seconds to triage an alert versus the 70-minute industry average, delivering 40% cost saving over a traditional 24x7 SOC.

Walking through real-world investigations, Kapuruge showed how the agent correctly identified a CredDumpTool alert as a false positive after reading the actual script content and understanding it was a developer’s QA test not a real attack. In another case, it confirmed a malicious account takeover when logins from Stockholm and Paris occurred 40 seconds apart, both IPs identified as Tor and VPN exit nodes.

Kapuruge also introduced Spark, an autonomous discovery and prioritisation tool that maps the entire external attack surface continuously, chains findings the way an attacker would, and conducts stack-aware threat research.

“See your organisation the way an attacker sees it continuously, autonomously, before attackers get there first,” he said.

He concluded with best practices in agent development: least privilege for agents, human-in-the-loop for critical acts, auditing everything, code level guardrails, security against prompt injection, and prompt caching with cost controls.

“AI didn’t break security. It just surfaced the tech debt we’ve been living with,” Kapuruge said.

A panel discussion followed the keynote and guest address, bringing together Farrelly, Kapuruge,  VitalProbe Founder and CEO Billa Bhandari and  Dialog Axiata PLC Data Architect Group Analytics and AI Dilshan De Saram. The session was moderated by CICRA  Group Director/CEO Boshan Dayaratne.

Bhandari addressed the emerging challenge of AI and data collection from wearable devices, highlighting how the proliferation of health and fitness wearables, smartwatches, and connected medical devices is creating vast new streams of sensitive personal data. He raised concerns about where this data is stored, who has access to it, and how AI systems are being used to analyse and derive insights from it often without adequate privacy safeguards.

De Saram focused on the ethical usage of AI, outlining Dialog Axiata’s approach to responsible AI deployment. He discussed the company’s framework for ensuring AI is used safely, including governance structures, bias detection, transparency in AI-driven decisions, and the importance of aligning AI initiatives with both regulatory requirements and customer trust. He emphasised that organisations must have a clear plan for how they will use AI ethically before they begin deployment, not as an afterthought.

The panel collectively reinforced the summit’s central theme: AI is both the problem and the solution. While attackers are leveraging AI to accelerate and automate cyber threats, defenders must equally harness AI through autonomous agents, context-aware security platforms, and ethical frameworks to stay ahead.

The 2nd Data Privacy and Protection Summit 2026 marked a defining moment for Sri Lanka’s data protection landscape. With PDPA enforcement imminent, the message from industry leaders, policymakers, and technology experts was clear: organisations can no longer afford to treat data protection as a compliance checkbox.

As Farrelly put it, the choice is no longer whether to adopt AI, but how to deploy it responsibly and effectively to defend against the very risks it creates. The summit underscored that in an era where AI is breaking data security, it is also when wielded correctly the most powerful tool to fix it.

COMMENTS