Mobile Data Security in the Age of AI: Why Governance Now Depends on Visibility

Matt O’Callaghan, Head of Sales &Partnerships, Corrata

Every organization can point to its controls. There is an acceptable use policy, a data protection posture, a record of who processes what and under which agreement, and a stack of tools the business can show an auditor or a regulator. On mobile, in the age of AI, a fast-growing share of what actually happens to corporate data now falls outside all of it. Not because those controls failed, but because they were designed for a world that no longer exists, one where sensitive data left the business through email attachments and file transfers, and where the risks worth governing could be listed, cataloged and signed off.

That world is gone, and the gap it leaves is a governance problem before it is a security one. The smartphone in an employee’s pocket sits at the intersection of three AI-driven risks, and each one creates exposure that existing controls neither see nor account for.

Three forces the current control set was not built for

The first is hyper-personalized social engineering. AI has turned phishing from a numbers game into precision targeting, with language models assembling convincing lures from publicly available information. Microsoft Digital Defense Report 2025 puts the click-through rate on AI-generated phishing emails at around 54%, against roughly 12% for traditional campaigns. The control most organizations rely on here is human judgment, reinforced by training, and that control is being quietly defeated. On mobile the exposure is sharper still, because the majority of phishing now arrives outside email, through SMS, WhatsApp, Teams and other channels that sit beyond the reach of conventional email security.

The second is the collapse of the remediation window. Finding and weaponizing software vulnerabilities used to demand deep expertise and time. That barrier is falling: in 2026, Google’s threat intelligence team confirmed a real-world actor using an AI-developed zero-day exploit. The median time from a vulnerability being disclosed to being actively exploited had already fallen from over two years in 2018 to a matter of hours, and that was before frontier AI models entered the picture. For anyone accountable for patch and vulnerability management, the assumption that there is time to assess, prioritize and remediate no longer holds, and mobile, where apps ship quickly and often outside formal review, is especially exposed.

The third, and the most consequential for data governance, is shadow AI and the data loss that follows it.

Shadow AI is an ungoverned data flow

Shadow AI is any use of AI tools inside a business that happens without the knowledge or approval of IT and security teams. Sometimes it is an employee pasting client data into a consumer chatbot to save time. Research from National Cybersecurity Alliance / CybSafe, 2025 suggests 43% of employees share corporate data with large language models without authorization. Just as often it is an AI feature quietly switched on inside software the company already trusts, sending data to a model provider that no one assessed, contracted with, or recorded as a processor.

For six weeks, we tracked live AI activity across managed mobile fleets: real traffic from real devices, not survey responses. Around 84% of the organizations we monitored had AI activity on their mobile fleet, and that volume was growing by roughly 40% month on month. A footprint that looks marginal today is half again as large four weeks later.

The more revealing figure is what the traffic was made of. Some 69% of the AI domains we detected were ones we had never seen before. That single number explains why blocklists fail as a control: a list is out of date the moment it is written, because the tool an employee adopted this week was not on anyone’s radar last week. It is tempting to assume this is really an “OpenAI problem,” but the interesting part is everything behind the household names: marketing, support and productivity platforms quietly shipping data to embedded models, arriving as routine updates to trusted software, with no procurement step, no data processing assessment, and nothing in the acceptable use policy to cover them. In governance terms, each is an unassessed third party processing corporate data with no record and no oversight.

This is not simply old shadow IT with a new label. Before generative AI, there was no way for an employee to move a client database into an external service in thirty seconds and get something useful back. That channel now exists, it is casual and instant, and at the network level it is almost indistinguishable from ordinary web browsing.

Why the existing stack cannot account for it

Mobile is where this exposure runs deepest. A personal phone keeps no wall between work and personal life; corporate data and consumer apps sit side by side, with no proxy, no gateway and no inspection point deciding what is allowed to leave. Endpoint detection watches for malicious processes, not where a legitimate app sends its data. Email security only covers email. Traditional data loss prevention was built for attachments and file transfers, not a browser tab or an in-app assistant streaming text to a model endpoint. Each tool does its job; this is simply not a job any of them was designed for.

The blind spot is not limited to AI, and it extends to the third parties you trust most. During one recent evaluation, our on-device inspection flagged a major banking app, precisely the kind of service you would expect to have the most secure protocols in place, negotiating a cryptographically weak connection. The bank’s servers supported a modern, secure configuration; it simply was not being prioritized. The lesson generalizes well beyond one app: even when your people are using a service that ought to be among the most rigorously secured, the data may not be as safe as everyone assumes, and you remain accountable for it either way. Trust in the counterparty is not a control.

Visibility is the precondition for governance

Maturing frameworks including ISO 42001 and the EU AI Act are raising the bar on how organizations demonstrate control over AI use and the data that feeds it. On mobile, most organizations have yet to close that enforcement gap, and the reason is fundamental: governance depends on visibility, and the order cannot be reversed. You cannot write a meaningful policy for AI you do not know is being used, you cannot enforce a policy against traffic you cannot see, and you cannot attest to a regulator or an auditor that you control data flows you have never observed.

The instinct to reach straight for a blocklist is understandable but self-defeating. Blunt blocking pushes determined employees onto personal hotspots and unmanaged devices, and the moment they move, whatever visibility you had disappears. The risk has not gone; you have simply lost the ability to see it or account for it.

The more durable approach is to make activity visible first, then govern it. Every AI service touching the fleet becomes known, sanctioned or not. New services surface as they appear rather than weeks later. Sensitive uploads can be stopped in real time, on the device, before anything crosses the line. Policy then follows what is actually happening, which is the only sequence that works when much of what you are governing did not exist last month.

None of this requires treating employees as adversaries. People reach for AI because it makes them more productive, and that impulse is not going to reverse. The task for leaders is not to stand in the way of it, but to bring it into view, to close the gap between what people are genuinely doing with corporate data and what the organization can actually govern. In the age of AI, that gap is where the real risk and the real accountability live, and on mobile, closing it starts with being able to see.

Hot Topics

Related Articles