This article is written based on an interview with Santanu Dutt, VP and Head of Technology for the APJ region at Zscaler
Every single week, the technology cycle delivers a brand-new headline about an advanced frontier model pushing boundaries, subverting instructions, or finding clever shortcuts around safety guardrails. Pundits spin these occurrences into breathless warnings about an impending technological apocalypse. The narrative suggests we’re on the precipice of an era when autonomous AI will upend traditional software ecosystems, leaving businesses scrambling to survive against unmanageable digital entities.
Nowhere was this manufactured panic more pronounced than in the recent media circus surrounding the Claude Mythos leak and, more recently, the reports of models and agents going rogue.

For days, industry circles buzzed with dire warnings. Commentators framed the incident as a terrifying preview of autonomous AI systems breaking free, circumventing enterprise controls, and exposing sensitive corporate assets at machine speed. Yet, Santanu Dutt, Vice President and Head of Technology for APJ at Zscaler, points out that this narrative is fundamentally detached from reality:
“The hype around models like Mythos is deafening, but we need to be able to separate the exaggerations from reality. While the capabilities of these models are extraordinary, the narrative that they represent an uncontrollable ‘SaaSpocalypse’, where advanced AI will entirely replace traditional SaaS and software companies, is overblown.”
Dutt further emphasises how easily sensationalism overshadows everyday operational risks, noting:
“Misinformation permeates when we focus on theoretical AI sentience instead of mundane operational risks. For example, the recent Claude Mythos leak was widely publicised as a massive ‘AI security issue,’ but it was actually a basic human error on a public-facing content management system.”
When you strip away the sensationalist hype and examine the cold reality of enterprise IT, the Mythos leak had nothing to do with rogue AI sentience or sophisticated cyber-espionage. It was something infinitely more mundane, and infinitely more preventable. It was a classic human mistake compounded by a complete lack of foundational data governance.
Separating Exaggerations from Operational Reality
To understand why enterprises are looking in completely the wrong direction when trying to secure their networks, we have to look past the media noise. The popular narrative painted the incident as an advanced adversarial breakdown of an elite model, feeding directly into the fear of an uncontrollable market collapse.
When you examine the actual event, the reality is almost anticlimactic. Roughly 3,000 unpublished internal assets—including future-facing draft press releases and confidential documents—were left exposed simply because of a basic human configuration error on a public-facing content management system (CMS). A well-meaning employee uploaded files to a directory that defaulted to public view.
There was no complex prompt injection. There was no clever exploit code written by a next-generation neural network. It was simply an unclassified document sitting in the wrong digital repository.

Yet, the public response immediately blamed the artificial intelligence model rather than the underlying data hygiene failure. As Dutt notes, this misdirection is precisely where modern organisations lose their footing:
“It was a data governance failure, not an AI security failure. Data security becomes table stakes for better AI security.”
Why We Can No Longer Rely on Human Perfection
This misdirection exposes a fatal flaw in how traditional enterprises approach security architecture. For decades, companies have built their defence strategies around the assumption that human employees will eventually get configurations right if given enough training seminars, policy handbooks, and reminder memos.
Human beings get tired, distracted, and rushed. When deadlines loom, employees take shortcuts. They drop draft documents into convenient folders without checking access permissions. When you couple that timeless human vulnerability with advanced, high-speed automated tools and autonomous AI agents constantly ingesting unstructured data, a single minor oversight snowballs into a catastrophic global news headline.
Expecting human employees to manually configure every cloud bucket, database, and content management system with absolute perfection is a losing strategy. The attack surface has expanded by orders of magnitude, and the blast radius of human error is wider than ever.
Organisations need to stop relying on human vigilance as a primary security control. As Dutt points out, architectural guardrails must step in to override human error entirely:
“Organisations need to stop relying on humans to configure things perfectly. They won’t. From an architectural standpoint, you need guardrails that override human error entirely.”
Data Classification as Table Stakes
Preventing a simple default-to-public human error from cascading into a corporate breach requires shifting focus back to the most fundamental, unglamorous pillar of enterprise technology: data governance.

An organisation cannot protect what it cannot identify. Before connecting autonomous agents to internal repositories or rolling out generative AI suites across a workforce, decision-makers need absolute clarity on what data lives on their networks. What files are highly sensitive? What assets are routine? What information must never leave the corporate perimeter under any circumstances?
If proper data classification had been active during the Mythos incident, those internal draft documents would have been automatically tagged as restricted or confidential the moment they were created. Even if an employee accidentally toggled a content management system to public view, automated security policies would have stepped in to block the action entirely. The security architecture would have overridden the human error.
This is where modern security modules like Data Security Posture Management (DSPM) and inline Data Loss Prevention (DLP) change the equation. DSPM acts as an active map, continuously scanning the environment to locate unclassified files, shadow AI tools, and exposed repositories. Inline DLP acts as an active checkpoint, intercepting traffic at the exact moment an employee attempts to submit data to an AI tool or publish content. One identifies exposure at rest; the other prevents exposure in motion.
Moving Past the Hype Toward Resilient Architecture
The Claude Mythos incident serves as an essential wake-up call for corporate leadership across the region.
The real threat to modern enterprise security is not that artificial intelligence is becoming too smart, sentient, or uncontrollable. The real danger is that companies are rushing to adopt cutting-edge capabilities while ignoring the foundational hygiene of their own data inventories.
Enterprise IT leaders can either spend all their time chasing AI hype, debating theoretical sentience, and worrying about science-fiction scenarios or they can focus on what actually matters: cleaning up data inventories, automating contextual classifications, and building intelligent guardrails that protect the enterprise from everyday human mistakes. Visibility and data governance are no longer back-office chores—they are the new perimeter.
This article is written based on an interview with Santanu Dutt, VP and Head of Technology for the APJ region at Zscaler

Santanu Dutt
VP and Head of Technology, Zscaler
Santanu Dutt is the Vice President and Head of Technology for the Asia-Pacific and Japan region at Zscaler, having assumed the role in July 2025. With years of experience in the IT sector, Santanu previously held various positions at Amazon Web Services (AWS), including Head of Technology / CTO and Head of Customer Solutions Management for Asia-Pacific and Japan, as well as managing Solutions Architect Teams in Southeast Asia. Santanu’s earlier experience also includes roles in Solutions Architecture with Red Hat and system administration at Accenture IDC. He has a Bachelor of Engineering in Electronics from R.A.I.T.
