SERIES · PART 2

2024: When AI Entered the Business Workflow

In 2023, people discovered what generative AI could create. In 2024, businesses began discovering what happens when AI becomes part of the workflow itself.

This article is Part 2 of From Generative AI to AI Agents: Why the Next Five Years Will Change Cybersecurity.

The difference may appear subtle.

It is not.

An AI system that answers a question is one thing.

An AI system that can access business information, work inside an application, assist with software development, analyze documents, and participate in a workflow is something fundamentally different.

The security question therefore began changing.

In 2023, businesses were asking:

What information are we giving AI?

In 2024, another question became increasingly important:

What systems can AI access?

That transition would become one of the foundations for the agentic AI era that followed.

2024 Was the Year AI Became Part of the Workflow

Generative AI did not remain confined to standalone chat interfaces.

AI capabilities increasingly appeared inside products and workflows people were already using.

AI-assisted functionality began appearing across areas such as:

  • Software development

  • Productivity

  • Search

  • Customer support

  • Marketing

  • Data analysis

  • Documentation

  • Research

  • Content creation

  • Business applications

The significance was not simply that more products contained AI.

The important change was that AI was increasingly positioned inside the process of doing work.

The user no longer necessarily had to leave an application, open an AI tool, ask a question, copy the response, and return to the application.

AI could increasingly become part of the application itself.

That reduced friction.

It also increased the importance of security.

From Conversation to Workflow

The 2023 model was relatively straightforward:

Human → Prompt → AI → Response → Human Action

The emerging 2024 model looked more like:

Human → Application → AI → Business Data → Recommendation or Generated Output → Human Action

This is a significant change.

The AI system is now closer to the organization's information and processes.

Instead of asking an AI model about an abstract problem, the user can ask it about:

  • a company's documents

  • customer information

  • source code

  • support tickets

  • internal knowledge

  • business data

  • project information

The AI becomes more useful because it has more context.

But context creates another cybersecurity question:

Who controls that context?

Context Became a Security Boundary

Generative AI is highly dependent on context.

Give an AI system more relevant information and it can often produce a more useful result.

This led organizations toward increasingly sophisticated AI workflows involving:

  • internal documents

  • knowledge bases

  • databases

  • application data

  • customer records

  • development repositories

  • business systems

The security problem therefore moved beyond the model itself.

The organization also needed to consider the information surrounding the model.

For example:

Who can retrieve the information?

What information can the AI see?

What information can the user see?

Are those permissions consistent?

Can information from one business context appear in another?

These are familiar access-control questions.

AI simply introduced another participant into the information flow.

AI Started Becoming a Layer Between People and Systems

Traditionally, an employee might interact directly with a business application.

For example:

Employee → CRM

or:

Employee → Database

or:

Developer → Development Environment

With AI integrated into the workflow, another layer can appear:

Employee → AI → Application

or:

Developer → AI → Development Environment

This changes the security architecture.

The AI system may now have access to information that was previously accessed directly by a human.

That means organizations need to understand not only human permissions but also how AI functionality interacts with those permissions.

The Software Development Transformation

One of the clearest examples occurred in software development.

AI coding assistants became increasingly integrated into developer workflows.

Developers could ask AI to:

  • explain code

  • generate functions

  • refactor code

  • create tests

  • identify possible bugs

  • generate documentation

  • suggest implementations

  • work across larger code contexts

This increased development productivity for many users.

But it also created a new security consideration.

The development environment contains highly valuable information.

It may include:

  • source code

  • credentials

  • environment variables

  • API keys

  • infrastructure configuration

  • proprietary algorithms

  • customer-related code

  • deployment information

An AI system operating inside that environment therefore requires appropriate boundaries.

The security question becomes:

What can the AI development assistant see, and what can it do?

AI and Business Data

The same issue appeared across other departments.

Imagine a customer-support AI.

It may need access to:

  • customer conversations

  • support tickets

  • product information

  • account information

  • knowledge bases

An AI marketing assistant may need:

  • campaign data

  • customer segments

  • analytics

  • product information

A financial assistant may need:

  • financial documents

  • reports

  • transactions

  • forecasts

The more useful the AI becomes, the more context it may require.

But access should not automatically expand simply because additional information would make the AI more capable.

This is a classic security principle:

Access should be appropriate to the task.

The Principle of Least Privilege Becomes More Important

Least privilege is not an AI-specific concept.

It has been a fundamental cybersecurity principle for years.

Users and systems should receive only the access necessary for their responsibilities.

AI makes this principle more visible because an AI system may operate across many sources of information.

Consider two hypothetical AI assistants.

Assistant A

Can read a specific knowledge base.

Assistant B

Can read:

  • the knowledge base

  • customer records

  • financial information

  • source code

  • internal documents

  • administrative systems

Assistant B may be more capable.

But its compromise or misuse could potentially have a much larger impact.

This illustrates an important principle for AI-enabled systems:

More access can create more capability, but it can also create a larger security boundary.

Identity Became More Complicated

Traditional systems usually have recognizable identities.

A user logs in.

An application authenticates.

A service account accesses an API.

AI introduces additional possibilities.

An AI feature may operate:

  • on behalf of a user

  • through an application

  • using a service identity

  • through an API

  • with delegated permissions

This creates an important question:

Who is actually performing the action?

Is it:

  • the human?

  • the application?

  • the AI system?

  • a service account?

  • an automated workflow?

The answer matters for security logging, authorization, investigation, and accountability.

This problem would become even more important when AI systems gained greater autonomy.

AI Did Not Need to Be Fully Autonomous to Create Risk

This distinction is important.

An AI system does not need to operate independently to introduce security concerns.

Even a human-in-the-loop system can create risks if:

  • excessive information is exposed

  • permissions are too broad

  • outputs are trusted without verification

  • sensitive data is processed improperly

  • malicious content influences the system

  • connected tools are poorly controlled

Human involvement reduces some risks.

It does not eliminate the need for security controls.

The Emergence of Prompt Injection Concerns

As AI systems became connected to external information, another category of security concern received increasing attention: prompt injection.

The basic concept is relatively simple.

An AI system receives instructions.

Those instructions may come from multiple sources.

A user may provide instructions.

A document may contain text.

A webpage may contain text.

A retrieved knowledge source may contain text.

If the AI treats untrusted content as instructions rather than data, its behavior can potentially be influenced.

This becomes particularly important when AI systems have access to tools.

A simple chatbot producing text presents one level of risk.

An AI system that can use tools introduces another.

The consequences of an unintended instruction can become more significant when the AI has the ability to perform actions.

From Data Exposure to Tool Exposure

This represents another major transition.

Early generative AI security focused heavily on:

What data goes into the model?

As AI became integrated with applications, the question expanded:

What tools can the AI use?

A tool could potentially be:

  • a search system

  • a database

  • a CRM

  • an email service

  • a browser

  • a code execution environment

  • a file system

  • an API

  • a business application

The AI becomes more useful because it can interact with these tools.

But each tool becomes part of the security boundary.

The Emerging Architecture

The architecture was becoming more complex.

Earlier

User → AI → Response

Integrated AI

User → AI → Business Data → Response

Tool-enabled AI

User → AI → Data + Tools → Action

That final step is the beginning of the agentic model.

Once AI can use tools, the distinction between an assistant and an agent starts becoming less clear.

The system is no longer only producing information.

It can participate in the execution of work.

Why Monitoring Became More Important

As AI became integrated into workflows, security teams needed visibility into more than traditional endpoint activity.

They also needed to understand:

  • which systems were being accessed

  • which applications were connected

  • what information was being processed

  • what actions were occurring

  • whether unusual behavior was appearing

  • which identities were involved

This does not mean every organization needed a completely new security architecture immediately.

It means that the existing security architecture needed to evolve with the environment.

The Endpoint Remained the Foundation

Even while AI moved into cloud applications and enterprise platforms, endpoints remained important.

Employees still used:

  • laptops

  • desktops

  • browsers

  • terminals

  • development environments

  • productivity applications

The endpoint was still where many business activities originated.

That made endpoint inventory, endpoint visibility, and endpoint monitoring important components of the broader security picture.

A security team needs to know what devices exist before it can understand the environment those devices are accessing.

Explore Endpoint Security →

Endpoint Inventory and AI

Consider a growing company with 50 employees.

Some employees use AI for:

  • coding

  • research

  • writing

  • marketing

  • customer support

  • analysis

The organization may have:

  • company laptops

  • personal devices

  • remote devices

  • development machines

  • shared systems

Before discussing advanced AI security, the organization needs basic visibility.

What devices exist?

Who uses them?

Which devices are managed?

Which devices are remote?

Which devices have security concerns?

Endpoint inventory provides the foundation.

Endpoint Visibility and AI

Inventory tells the organization what exists.

Visibility provides more context.

For example:

  • device information

  • endpoint state

  • relevant security information

  • configuration information

  • other available endpoint context

The more distributed the workforce becomes, the more important centralized visibility can become.

AI does not remove this requirement.

It increases the number of systems and workflows that organizations need to understand.

Endpoint Monitoring and AI

Monitoring adds the time dimension.

Inventory tells you:

What exists?

Monitoring helps answer:

What is happening?

That distinction becomes important when investigating security concerns.

An isolated piece of information may not explain what happened.

A sequence of events can provide much more context.

This principle becomes even more important when automated systems begin performing actions.

Security Monitoring Becomes Broader

Endpoint monitoring focuses on endpoints.

Security monitoring has a broader objective.

It helps organizations understand security-related information across their environment.

As AI becomes integrated into business workflows, security teams increasingly need to correlate information from multiple layers.

For example:

User → Endpoint → Application → AI → Business System → Data

A security event at one layer may make more sense when combined with information from another.

This is why security platforms need context rather than simply producing isolated notifications.

Vulnerabilities Did Not Disappear

AI adoption also did not remove traditional vulnerabilities.

Applications can still contain weaknesses.

Operating systems can still contain weaknesses.

Dependencies can still contain weaknesses.

Configurations can still create risk.

Credentials can still be compromised.

AI systems can introduce additional dependencies and integrations, but they exist inside the same broader technology environment.

This makes vulnerability management an important part of the overall security foundation.

Threat Detection in an AI-Enabled Environment

Threat detection also becomes more complicated.

Traditional threat detection focuses on identifying activity that may indicate malicious behavior.

AI-enabled environments introduce additional questions.

For example:

  • Is unusual activity coming from a user?

  • Is it coming from an application?

  • Is it associated with an automated process?

  • Is an AI workflow behaving unexpectedly?

  • Is an unusual API access pattern occurring?

  • Is a security control being bypassed?

The purpose of threat detection remains the same:

Identify potential security threats that may require investigation.

But the entities involved can become more diverse.

Security Alerts Become More Important

More systems can also mean more security information.

This creates another challenge:

Signal versus noise.

A security alert should represent information that may require attention.

It should not automatically be treated as proof of a confirmed security incident.

The workflow remains:

Monitoring → Potential Security Event → Security Alert → Investigation → Appropriate Action

This distinction becomes increasingly important as organizations automate more processes.

The Business Security Problem Was Becoming More Distributed

Traditional business environments were already becoming distributed through:

  • cloud computing

  • SaaS

  • remote work

  • mobile devices

  • APIs

  • third-party integrations

AI added another layer.

Now organizations increasingly had:

People

Devices

Applications

Cloud services

APIs

AI systems

Business data

These components interact continuously.

Security therefore becomes less about protecting one perimeter and more about understanding the relationships between systems.

AI Increased the Importance of Context

This is one of the strongest lessons from 2024.

An isolated AI model is one thing.

An AI model connected to business context is another.

The more context an AI system receives, the more useful it can become.

But that same context can increase the consequences of:

  • unauthorized access

  • data exposure

  • incorrect permissions

  • malicious instructions

  • compromised integrations

  • insecure tools

Therefore:

AI capability and security responsibility grow together.

From Human-in-the-Loop to Human-on-the-Loop

Another important conceptual transition began to emerge.

Human-in-the-loop

The human actively participates in each important action.

AI → Human Review → Action

Human-on-the-loop

The AI may perform more of the workflow while humans supervise the broader process.

AI → Action → Human Oversight

The second model can be more efficient.

But it also requires stronger controls because the human may not inspect every individual action.

This becomes especially important when AI systems operate at machine speed.

Why 2024 Was a Critical Bridge

2023 demonstrated that people wanted generative AI.

2024 increasingly demonstrated that businesses wanted AI inside their workflows.

That created the foundation for the next stage.

The progression looked increasingly like:

2023 — AI generates.

2024 — AI integrates.

2025 — AI acts.

2026 — AI agents increasingly operate across workflows.

Future — Multiple agents may coordinate across business systems.

The exact pace differs by organization and technology.

But the architectural direction is important.

What This Means for Cybersecurity Platforms

A modern cybersecurity platform cannot exist in isolation from the rest of the business environment.

It needs to provide visibility into the systems organizations depend on.

That includes a strong understanding of:

Endpoints

What devices exist?

Visibility

What information can be understood about those devices?

Monitoring

What is happening over time?

Vulnerabilities

Where are weaknesses?

Threats

What activity may require investigation?

Alerts

What security information needs attention?

Security Monitoring

How can security information be viewed together?

These capabilities do not solve every AI security problem.

They provide part of the broader security foundation required as business environments become more automated.

The Bigger Lesson of 2024

The biggest change was not simply that AI became more powerful.

It was that AI became more connected.

Connected to:

  • applications

  • documents

  • business data

  • development environments

  • productivity tools

  • APIs

  • workflows

And connectivity changes cybersecurity.

A disconnected system has a limited attack surface.

A highly connected system has more paths through which information and actions can flow.

Therefore:

The more connected AI becomes to business systems, the more important security boundaries become.

The Question Changes Again

In 2023, the question was:

What information are we giving AI?

In 2024, it increasingly became:

What systems can AI access?

The next question was inevitable:

What can AI do once it has access?

That question leads directly into the next stage.

2025: The Rise of Agentic AI

The next article in this series examines 2025 and the rise of agentic AI — the increasing move from AI assistants toward AI agents.

The central transition becomes:

AI generates → AI integrates → AI acts

Agentic AI introduces new considerations around:

  • tool use

  • identity

  • permissions

  • memory

  • planning

  • autonomous actions

  • human oversight

  • agent-to-agent interaction

  • security monitoring

The cybersecurity question becomes more fundamental:

If an AI system can take action inside the organization, how do we control and monitor that authority?

That is where the story moves from AI-assisted work toward the agentic enterprise.

Conclusion

2024 was an important transition year in the evolution of AI.

The technology was increasingly moving out of isolated conversations and into real workflows.

AI was becoming connected to:

  • business data

  • applications

  • development environments

  • productivity systems

  • APIs

  • knowledge bases

  • enterprise processes

That increased its usefulness.

It also expanded the security boundary.

The lesson was straightforward:

AI becomes more powerful as it gains more context and connectivity.

But connectivity creates responsibility.

Organizations need to understand what systems are connected, what information can flow between them, who has access, what activity is occurring, and what security concerns may require investigation.

The endpoint remains important.

Visibility remains important.

Monitoring remains important.

Vulnerability management remains important.

Threat detection remains important.

Security alerts remain important.

And a centralized security platform becomes increasingly valuable as the environment becomes more complex.

Because the future security problem is not simply:

"Can AI generate the right answer?"

It is increasingly:

"Can we understand, control, and secure what AI is connected to?"

That question sets the stage for 2025.

Continue with Part 1: 2023 or return to the series introduction.

DotlyGuard

Understand What AI Can Access

As AI connects to applications, data, and tools, visibility, monitoring, and endpoint security become part of the broader security foundation.

No credit card required.

Series: From Generative AI to the Agentic Enterprise

Introduction: From Generative AI to AI Agents

Part 1: 2023: The Generative AI Revolution

Part 2: 2024: When AI Entered the Business Workflow (this article)

Part 3: 2025: The Rise of Agentic AI

Part 4: 2026: The Agentic Enterprise

Part 5: 2027: The Multi-Agent Organization (forward-looking scenario)

Part 6: 2028: The AI-Native Business (forward-looking scenario)