BACK TO NEWS

Protegrity on Securing Retail AI and Agentic Workflows

By Protegrity
Sep 16, 2026

Summary

5 min
  • StorMagic’s PodMagic explores how agentic AI is changing retail data security:
    Protegrity’s Clyde Williamson and Jessica Hammond discuss how retailers can move from AI pilots toward autonomous workflows while maintaining visibility, governance, and control over sensitive customer and operational data.

  • Protegrity POV: protect sensitive data wherever AI uses it:
    The conversation highlights data-centric protection, scoped agent permissions, and approaches such as tokenization, encryption, masking, and anonymization that can help organizations put sensitive data to work without unnecessarily exposing the original information.

Retailers are moving beyond AI-powered recommendations and forecasting toward systems that can retrieve data, make decisions, and take action across business workflows. That creates new opportunities for personalization and efficiency, but it also raises an important question: how can organizations put sensitive customer and operational data to work without losing control of it?

In a recent episode of StorMagic’s PodMagic podcast, Protegrity’s Clyde Williamson, Senior Product Security Architect, and Jessica Hammond, Senior Director of Product Management for Gen AI, join host Scott Mann to discuss how retailers can protect sensitive data as generative AI evolves into more autonomous, agentic workflows.

See how Protegrity helps protect sensitive data across the AI pipeline.

Retail AI Is Moving Toward Greater Autonomy

Retailers have used AI for personalization, recommendations, demand forecasting, inventory management, and fraud prevention for years. The next phase is increasingly agentic: AI systems that can interact with applications, retrieve information, use tools, and execute tasks with less direct human involvement.

Jessica explains that this shift changes the security conversation. As AI agents gain greater autonomy, organizations need a clearer understanding of what data those systems can access, what condition that data is in, and how protection continues as information moves through different applications and workflows.

Data Visibility Comes Before Data Protection

A recurring challenge for retailers is knowing where sensitive information actually resides. Customer records, payment information, personally identifiable information, and operational data may be fragmented across applications, databases, pipelines, and cloud environments.

Clyde and Jessica emphasize that organizations cannot effectively govern or protect information they cannot identify. As AI systems become capable of discovering and using data across more environments, visibility into sensitive information becomes even more important.

Protect the Data, Not Just the Perimeter

The conversation also explores why traditional perimeter-focused security becomes less effective as AI agents operate across enterprise systems. Authenticating a user or agent is important, but access alone does not determine how much sensitive information should be exposed.

Protegrity’s approach centers on protecting sensitive data itself through techniques such as tokenization, encryption, masking, and anonymization. Clyde explains that data can remain protected as it moves through enterprise environments and only be revealed when a specific business process requires access to the original value.

This can allow organizations to make more data useful for analytics and AI without automatically exposing the underlying sensitive information.

Treat AI Agents as Their Own Identities

As agents become more autonomous, Clyde and Jessica also recommend moving beyond the assumption that an AI agent should simply inherit all of the permissions of the person using it.

Organizations need to consider the identity of the agent itself, the tools and skills connected to it, the data it can access, and the actions it is authorized to perform. That includes defining scoped permissions, monitoring behavior, and evaluating the additional components an agent may use to complete a task.

The goal is not to block AI from accessing useful enterprise data. It is to provide the right representation of that data for the task, whether through protected, tokenized, anonymized, synthetic, or clear-text information when explicitly required.

Security Can Help AI Move Faster

Jessica argues that security teams should become AI enablers rather than a final gate at the end of development. When governance and data protection are considered early, organizations can design AI workflows with the appropriate controls already in place rather than introducing them after a project is ready for production.

That becomes especially important as AI development accelerates. Teams can now move from an idea to a working prototype quickly, which means information security needs to operate at a similar pace.

Preparing Retailers for What Comes Next

Looking ahead, the discussion points toward increasingly autonomous enterprise environments and greater interest in sovereign AI architectures that give organizations more control over where models run and where sensitive data is processed.

For retailers, Clyde and Jessica recommend starting with strong data fundamentals: understand where sensitive information resides, improve data quality, educate teams across the organization, and establish clear governance for both people and AI agents.

With those foundations in place, security can become an enabler for putting more valuable enterprise data to work while maintaining control over how that information is accessed and used.

Note: This summary is based on the StorMagic PodMagic episode “Securing Retail AI & Agentic Workflows with Clyde Williamson & Jessica Hammond (Protegrity)” and is provided for convenience. Please refer to the original episode for the complete discussion and context.