EMA — Leveraging DSPM and Artificial Intelligence to Solve Data Security Challenges (2026 research)

Tag: S-2026-06-30-ema-dspm-ai-data-security Type: report (analyst research; announced via press release) Author(s): Chris Steffen, VP of Research (security, risk & compliance), Enterprise Management Associates (EMA) Date of source: 2026-06-30 (press release publication date) Date ingested: 2026-07-01 Authority weight: medium — credible independent IT analyst firm, but the study is sponsor-funded (F5, IBM, Selcore, Skyhigh Security, Virtru), the sample is North American and self-reported, and the full report is gated (only headline figures public). Raw file: S-2026-06-30-ema-dspm-ai-data-security.md. External URLs in the raw stub.

What it claims

EMA published research (survey of 225 North American IT, security, data-governance and technology-business leaders) on how organisations are adapting Data Security Posture Management (DSPM) as AI reshapes the data-security landscape. The headline finding is that AI is now the primary force shaping DSPM investment, governance strategy and operational priorities. Four specific findings are given: (1) securing AI data flows is now the #1 driver of DSPM investment at 64.4%, surpassing data-exfiltration prevention (56%) “for the first time”; (2) AI-governance accountability is fragmented — responsibility for AI-related data risk is split across IT (30.2%), security teams (29.8%), CDOs (20%) and governance committees (18.7%), “leaving many organizations without clear ownership”; (3) multi-cloud policy inconsistency is the top concern for 45.3%, driven by differences in residency controls, key management and security architectures; and (4) automation expectations are high — over 85% expect automated remediation to cut workloads, a third expecting >50% reductions. The report also offers guidance for evaluating DSPM platforms in an AI-driven environment. EMA’s Steffen frames DSPM as “a prerequisite for AI deployment—rather than an afterthought.”

For Paul’s vendor scan the relevance is twofold: DSPM is a control segment overlapping the privacy/sensitive-data/access-governance cluster of his watchlist (BigID, Securiti, Immuta, OneTrust, Privacera), and the accountability-fragmentation finding independently quantifies the ownership gap that DORA ICT-risk governance, GDPR data-security and FCA/PRA operational-resilience accountability expectations require regulated firms to close.

Notable quotes

“Securing AI data flows ranked as the top reason organizations invest in DSPM solutions (64.4%), surpassing data exfiltration prevention (56%) for the first time.” — EMA press release, 30 Jun 2026.

“Responsibility for AI-related data risk is divided among IT (30.2%), security teams (29.8%), chief data officers (20%), and governance committees (18.7%), leaving many organizations without clear ownership.” — EMA press release, 30 Jun 2026.

“The enterprises that treat DSPM as a prerequisite for AI deployment—rather than an afterthought—will be the ones that remain in control.” — Chris Steffen, EMA.

What’s speculative vs. asserted

  • Asserted (survey findings): the four headline percentages (64.4% AI-data-flow DSPM driver; fragmented accountability split; 45.3% multi-cloud policy concern; 85%+ automation expectation), attributed to a 225-respondent North American survey.
  • Analyst opinion / framing (label as such): “DSPM as a prerequisite for AI deployment”, “AI is the primary force shaping DSPM investment” — Steffen’s interpretive positioning, not a measured datum.
  • Not established / out of scope: no EU/UK cut (North American sample); no named regulated-FS reference; the report is sponsor-funded (potential DSPM-tooling framing bias); full figures gated, so not independently verifiable from the public page.

Topics this feeds

  • AI Governance Maturity Gap — adds a 2026 research data point on AI-governance accountability fragmentation (no clear ownership of AI-related data risk) and on DSPM investment being AI-driven — reinforcing the adoption-outpaces-governance / ownership-gap thesis from a data-security angle.
  • Agentic Data Access Governance — DSPM is the sensitive-data-posture layer adjacent to the access-enforcement vendors (Immuta, BigID, OneTrust) in that category.

Open questions raised

  • Do the North American figures read across to EU/UK regulated FIs, where DORA and GDPR make data-security governance ownership a supervisory rather than discretionary matter?
  • Does the sponsor set (five security vendors) bias the “DSPM as prerequisite” framing, and how much weight should a gated, self-reported survey carry?
  • Which named DSPM/privacy-governance vendors (BigID, Securiti, etc.) does the underlying report evaluate — not disclosed on the public page?