AI security emerging as separate budget line for Indian enterprises: Palo Alto Networks’ Swapna Bapat

Palo Alto Networks’ Swapna Bapat said awareness of the risks from unsecured AI is growing among chief information security officers. “If I have to use AI, I have a budget for using AI, then I have a budget to secure AI as well,” she said.

Swapna Bapat, Vice President & Managing Director, India and SAARC, Palo Alto Networks

AI security is emerging as a dedicated line item in Indian enterprises’ cybersecurity budgets as companies expand use of artificial intelligence (AI) and AI agents, according to Swapna Bapat, vice president and managing director for India and SAARC at Palo Alto Networks.

“It is definitely a new line item in the security budget. I’d say a new line item,” Bapat told The Economic Times in an interview. Bapat said awareness of the risks from unsecured AI is growing among chief information security officers. “If I have to use AI, I have a budget for using AI, then I have a budget to secure AI as well,” she said.

This comes as AI adoption spreads across different parts of organisations faster than security teams can track, Bapat said. Companies are using AI through software-as-a-service platforms, productivity tools and internally developed applications, while employees are also experimenting with models and agents, she said.


Also read: Cyberattacks drive companies to hire specialised security talent in AI, cloud & threat intelligence

“Usage is there but do the security teams have visibility? The answer is no. Not all the time, because the proliferation is faster than they can put in tools to get visibility, to get control,” Bapat said. She added that the first question many customers now ask is how to identify where AI and agents are being used across their environment.

That concern is also reflected in Palo Alto Networks’ 2026 Identity Security Landscape report, based on a global survey of 2,930 cybersecurity decision-makers. The report said organisations now have an average of 109 machine identities for every human identity, including 79 AI agent identities per human. The report added that over the next 12 months, organisations expect AI agents to increase by 85% and machine identities to increase by 77%, compared to the 56% growth in human identities.
ADVERTISEMENT

Treat AI agents like employees

Bapat stressed that as AI agents take on more tasks, companies need to treat them as machine identities within the the enterprise.

“AI agents have to be given the same treatment when it comes to securing the environment as you would any employee in the organisation. A machine identity,” she said.

According to Bapat, companies need to decide what an AI agent can access, track its actions and be able to stop it when needed. “Are you able to monitor what the agent is doing? And can you kill it at the right time, if needed?” she said.

Also read: Can AI companies be sued if autonomous agents hack other systems? Here's what legal experts say
ADVERTISEMENT

The Identity Security Landscape report said that less than half of the organisations surveyed have basic safeguards such as monitoring agent behaviour and revoking access credentials. It added that without consistent controls, security teams may struggle to stop an agent when it acts outside its intended role.

Shadow AI, data leakage add to risks

Bapat said “shadow AI” is becoming another concern as employees can download and experiment with models without security teams knowing about it. “Shadow AI is definitely a worry. Today, I can download an agent on a laptop,” she said.
ADVERTISEMENT

“Is there a curious employee in your environment who wants to download a model and build something cool? Probably yes. Do you know it is happening? Probably not,” she added.

The risks differ depending on how companies use AI, Bapat said. For companies accessing AI through third-party applications, one of the biggest concerns is data leakage. Companies want to know whether employees are sharing sensitive information with AI-enabled productivity tools, customer-management software or other applications, Bapat added.

“If the SaaS application that I am using today is AI-enabled, am I sharing too much sensitive information with that application? That is definitely a concern,” she said.

Also read: OpenAI pauses Astra AI model over critical cybersecurity concerns

Meanwhile, companies building their own AI applications face a broader set of risks, Bapat said. They need to ensure that enterprise data does not leave the organisation while models are being trained, that databases cannot be tampered with, and that models are protected from attacks such as prompt injection.

Security has to begin from day one

As more companies begin building and testing their own AI applications, Bapat said security cannot be added as an afterthought.

Companies that are not traditional software developers are also buying licences from model providers such as OpenAI and Anthropic to experiment with AI, she said. “They’re clearly experimenting and seeing. But they have to start security on day one as well,” Bapat said.

Also read: OpenAI flags possible critical cybersecurity risk in upcoming model, tightens controls

She said this applies regardless of where the AI system is deployed, on premise, within an enterprise cloud environment or on a private or public cloud. “Security remains important during use, during development, during runtime,” she said.

AI is also becoming increasingly important on the other side of cybersecurity, as a tool to defend against attacks. Bapat said the speed and scale at which attackers can operate makes the use of AI in cyber defence increasingly necessary.

“Given the speed of the attacks, given the volume of attacks, using AI to defend our customers intrinsically in our products is a must,” she added.
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › AI › AI Insights › AI security emerging as separate budget line for Indian enterprises: Palo Alto Networks’ Swapna Bapat
Text Size:AAA
Success
This article has been saved

*

+