Well, here it is: Episode 100 of The Spiro Circle.
When I recorded the first episode 18 months ago, I had a rough idea of what this show could be. I wanted it to be a place where long-form conversations about Israeli tech, geopolitics, or society could get broader attention.
Now, with a growing audience across 20 countries and partnerships with international media channels like Forbes, I am proud to see what it is becoming, and that these conversations are getting the attention they deserve. Startup Nation yearned for long-form English conversation, and I am pleased to be helping fill that missing gap.
For the 100th, I brought in Nitay Milner, co-founder and CEO of Orion Security, and Emily Fontaine, Global Head of Venture Capital at IBM Ventures, to talk about why every major company should rebuild its data security strategy in this AI era.
I find it fitting that our conversation on how a large corporate company saw potential in a scrappy Israeli startup was positioned as the 100th episode.
Thanks to all who have joined to share their stories so far, and thank you to all those who keep tuning in.
Onwards to 200. - JS
The data loss prevention industry has organized itself around a relatively stable threat model.
A disgruntled employee may copy files to a USB drive. Or a phishing attack could expose credentials to an outside attacker. Maybe someone accidentally CCs the wrong person on an email with sensitive information. Solutions focused on perimeter controls or policy rules were imperfect, but understandable when the threats were often caused by humans.
But that model is no longer sufficient. According to research by Cyberhaven Labs, whose 2026 AI Adoption and Risk Report analyzed data movements across 222 companies, nearly 40% of all AI interactions now involve sensitive data, with the average employee inputting proprietary information into an AI tool once every three days.
Threats don’t disagree insofar as they disaggregate, accelerate, and, in some new cases, remove the human from the equation entirely.
Nitay Milner, co-founder and CEO of Orion Security, offered a framework for understanding how the landscape has changed. In a recent episode with Emily Fontaine, Vice President and Global Head of Venture Capital at IBM, which backed ORION’s $32 million Series A in February 2026, he described the three categories of traditional data leakage that the DLP industry was built to address: human error, malicious insider activity, and external attackers.
“[Perhaps] I accidentally did ‘Emily@IBC’ and not ‘IBM’,” he said, by way of illustration, “and sent the entire board deck to the wrong person. That happens a lot. I call it keeping honest people honest.”
The second category, he noted, involves deliberate exfiltration, what he called the “Snowden” scenario. The third involved external actors penetrating an organization and quietly siphoning data over time.
Milner co-founded Orion Security in 2024 with CTO Jonathan Kreiner. It aims to replace traditional DLP (data loss prevention) tools with an automated, context-driven platform. Using LLMs and specialized AI agents, the platform continuously detects and analyzes data loss indicators in real time, capturing context for content sensitivity, data lineage, user identity, behavioral intent, and environmental purpose.
New anatomies, new leaks
Traditional categories of DLP remain relevant, of course. But Milner identified two new vectors that are reshaping the problem. The first is data extraction into third-party AI: employees uploading sensitive documents like earnings calls, customer records, or source code to unmanaged AI platforms before those materials are cleared for external use. “Taking the earnings call, which is super sensitive data, before the earnings call report was published, and uploading it to like an unmanaged ChatGPT or Claude,” he said. “It’s very, very sensitive, and data is now in the hands of a third party that you don’t have any agreement with.”
The second vector is data exfiltration not by humans at all, but by AI agents operating inside the enterprise. “AI agents doing human work inside the organization, having access to super sensitive data,” Milner explained. “Think about an AI agent email assistant that has access to your Google Drive, takes the entire customer list and sends it to the wrong person. That’s data exfiltration by AI.”
The scale of this emerging risk is becoming measurable. According to a 2026 Cloud Security Alliance report, 82% of organizations already have AI agents operating in production environments, while only 17% enforce runtime access controls consistently across those deployments.
A separate finding from Proofpoint’s 2025 Data Security Landscape report found that 32% of organizations identify unsupervised data access by AI agents as a critical threat.
Fontaine framed the underlying problem as one of movement, not just volume. “Data is a huge asset that must be protected, more so than ever before,” she added. “It’s moving across clouds, it’s moving across applications, agents, ecosystems. It’s moving across so much more than it was ever before. And we have to make sure it’s secure, that it is governed correctly.”
IBM Ventures, the strategic investment arm of IBM led by Fontaine, operates a $500 million fund focused on AI and quantum technologies — and its bet on Milner and the team reflects IBM’s belief that the arrival of large language models has fundamentally broken the assumptions on which traditional data security was built, creating entirely new leakage paths that legacy DLP tools cannot detect.
A new era for DLP
That governance challenge is exactly what today’s DLP industry is no longer built to handle. Policy-based systems depend on known patterns, like a credit card number matching a regex or a file name triggering a rule. They cannot, by design, interpret context or whether a particular data movement constitutes a legitimate business action or an exfiltration event.
Milner’s breakdown offers enterprises a useful starting point to identify which of the five categories (legacy or AI-era) represents the highest unaddressed exposure in a given environment, and build from there. “Understand your organization,” he concluded. “Based on this real data, get to decisions, train your employees, and help them understand how to use data safely.”










