Technological Advancements

AI Data Security: The Double-Edged Sword Reshaping Cyber Defence

Dialog Axiata Group Analytics and AI Data Architect Dilshan De Saram (second from right) speaks at the panel discussion. Others from left: Concentric AI Regional Vice President – APAC Chris Farrelly, Brandix Fortude IT Infrastructure and Cybersecurity Associate Vice President Prageeth Kapuruge, VitalProbe Founder and CEO Billa Bhandari and Moderator CICRA Holdings Group Director/CEO Boshan Dayaratne – Pix by Upul Abayasekara and Ruwan Walpola

has emerged as a critical challenge for Sri Lankan organisations, with artificial intelligence accelerating cyber threats while simultaneously providing new tools to detect, investigate and prevent increasingly sophisticated attacks.


AI Data Security is becoming critical as Sri Lanka prepares for stronger data protection enforcement


Artificial intelligence is rapidly changing the cybersecurity landscape, creating a difficult paradox for businesses: the same technology capable of exposing sensitive information can also become one of the most powerful tools available to protect it.

This issue was at the centre of the 2nd Data Privacy and Protection Summit 2026, organised by CICRA and Daily FT and held on 23 July at the Oak Room, Cinnamon Grand Colombo. The full-day event brought together more than 380 senior professionals involved in data protection, governance, compliance and cybersecurity.

The summit took place as Sri Lanka moves closer to enforcement of the Personal Data Protection Act (PDPA), increasing pressure on organisations to strengthen how they collect, store, process and protect personal information.

Delivering the opening address, Digital Economy Deputy Minister Eng. Eranga Weeraratne stressed that data privacy and cybersecurity must move beyond the IT department and become strategic priorities for boards and senior management.

He argued that privacy and protection should be incorporated into digital systems from the beginning rather than added later. The underlying message was that public confidence will be a decisive factor in determining whether Sri Lanka’s wider digital transformation succeeds.

Concentric AI Regional Vice President – APAC Chris Farrelly then examined the growing risks created by workplace AI adoption during a session titled “Protecting Your Crown Jewels – AI is Breaking Data Security and Fixing It?”

Farrelly highlighted the increasing use of public AI tools, copilots and AI assistants across organisations. However, he warned that security teams often have limited visibility into how these systems are being used, what information employees are entering into prompts and where resulting data is going.

This creates new data privacy Sri Lanka challenges. Confidential business information, personal data and other sensitive material can potentially enter AI systems outside an organisation’s direct security controls.

Traditional cybersecurity mechanisms, Farrelly argued, were not designed for this environment. Rule-based controls, regular expressions and static labels can struggle to understand the context and meaning of unstructured information moving through AI systems.

He presented AI-powered security as part of the solution, arguing that modern systems can analyse context, meaning and relationships rather than relying exclusively on predetermined rules. Such capabilities can help identify risky users and applications, detect sensitive information in prompts and responses, and respond to potential exposures in real time.

The challenge is becoming more urgent as attackers themselves increasingly adopt AI. Brandix Fortude Associate Vice President – IT Infrastructure and Cybersecurity Prageeth Kapuruge highlighted the speed at which cyber threats are evolving.

He cited 48,185 new Common Vulnerabilities and Exposures (CVEs) recorded in 2025, representing a 20.6% increase following a 38% surge in 2024. He also pointed to a sharp reduction in the time required to exploit vulnerabilities, highlighting the growing gap between traditional security response times and the speed of modern attacks.

Kapuruge argued that organisations must respond by using AI Agents capable of going beyond conversational interaction. Unlike conventional generative AI systems, AI Agents can be assigned objectives and provided with tools that allow them to plan, execute, observe outcomes and repeat actions.

His presentation demonstrated how such systems could assist security teams with alert triage and investigation. GuardianAI, an autonomous AI agent presented during the session, was cited as achieving an average alert-triage time of 120 seconds compared with a 70-minute industry average, alongside a claimed 40% cost saving compared with a traditional 24×7 security operations centre.

Another tool, Spark, was presented as an autonomous external attack-surface discovery and prioritisation system capable of continuously mapping an organisation’s exposure and conducting threat research based on its technology environment.

The demonstrations highlighted the potential for AI Data Security to shift cybersecurity from reactive monitoring towards faster, context-aware and increasingly autonomous defence.

However, the summit also emphasised that automation cannot eliminate the need for human oversight. Kapuruge recommended least-privilege access for AI agents, human involvement in critical decisions, comprehensive auditing, code-level safeguards and protection against prompt injection.

The issue extends beyond traditional enterprise systems. During the panel discussion, VitalProbe Founder and CEO Billa Bhandari highlighted the growing volumes of sensitive information generated by wearable devices, smartwatches and connected medical technologies.

These devices create continuous streams of personal data that can be analysed by AI systems, raising questions about where information is stored, who can access it and whether individuals have sufficient control over how their data is used.

Dialog Axiata PLC Data Architect Group Analytics and AI Dilshan De Saram focused on responsible AI deployment, including governance, bias detection, transparency and alignment with regulatory requirements. He stressed that organisations should establish a clear framework for ethical AI use before deploying systems rather than treating governance as a later consideration.

The panel, moderated by CICRA Group Director/CEO Boshan Dayaratne, reinforced the summit’s central message: AI represents both an emerging cybersecurity risk and an increasingly important defensive capability.

For Sri Lankan businesses, the approaching PDPA enforcement period makes this balance particularly important. Compliance cannot be reduced to a checklist if organisations are simultaneously adopting AI tools that can alter how personal and corporate data is collected, processed and shared.

Ultimately, AI Data Security will require organisations to combine technology with governance, accountability and human oversight. The summit’s message was not that businesses should avoid AI, but that they must understand its risks and deliberately build the controls required to use it safely.

As AI adoption accelerates, organisations that can combine faster automated defence with strong data governance will be better positioned to protect sensitive information while maintaining customer trust.