Oracle Charts Data-Layer Security Path as AI Threats Intensify
Oracle is repositioning enterprise security around the data layer with a three-part framework designed to counter risks introduced by AI systems. The company will detail its approach at a virtual event on September 22.

Artificial intelligence is creating novel vulnerabilities across enterprise systems, prompting Oracle Corp. to reorient its security posture toward protecting data at its source. The company's framework rests on three pillars: securing at source, securing at speed and securing through resilience, with the goal of embedding protective controls directly into the data layer where information lives.
As organizations deploy AI agents at scale, the need for tightly woven security mechanisms within the data layer has become critical for maintaining consistent policy enforcement. Oracle's direction signals a broader industry movement toward unifying security, governance and recovery functions across the entire AI technology stack.
The cloud shared responsibility model is no longer a sufficient framework in this AI-first world. Agents acting at machine speeds require what theCUBE Research calls a shared accountability model. It's not enough to protect infrastructure, apps and the data inside. AI has raised the trust bar, and customers must now consider much more deeply how adversaries using AI, and even accidental AI actions running at machine speeds bring new risks to enterprises.
Dave Vellante, theCUBE Research
Oracle's redesign of security from the data layer upward will take center stage at the company's "AI Cyberattacks Are Escalating: How to Secure Your Data Now" virtual event on September 22. Oracle leadership and external specialists will join analysts from theCUBE Research to examine the shifting threat environment and offer concrete strategies for safeguarding sensitive information, minimizing operational impact, restoring systems after breaches and adapting defenses as AI-driven attacks evolve.
New tools for enterprise security
Oracle unveiled its three-part security strategy in June in response to mounting challenges stemming from expanded artificial intelligence deployment. AI technologies have opened new avenues for unauthorized access to sensitive corporate data, leading Oracle to develop a toolkit focused on database security, patch management, testing and operational lifecycle management.
The company's offerings include Oracle Deep Data Security, which enforces privacy policies tailored to individual users within the database itself, and Oracle SQL Firewall, designed to counter SQL injection attacks—a vulnerability that permits attackers to execute harmful commands through web form inputs. In April, Oracle announced a suite of upgrades to its Oracle AI Database that incorporated Deep Data Security, enabling centralized, declarative, granular access controls and data visibility policies determined by user identity, assigned roles and operational context.
The evolution of AI agents from simple question-answering systems to autonomous decision-making tools has raised doubts about whether application-layer security alone remains adequate. By embedding Deep Data Security's enforcement mechanisms directly into the database, Oracle adds a defensive layer against unauthorized data retrieval stemming from adversarially crafted queries.
The next phase of enterprise AI adoption will depend as much on governance as model capability. As agents gain access to sensitive data and critical workflows, organizations need to know whose identity they are acting under, what privileges they inherit and where those privileges are enforced. Getting those controls right can accelerate AI adoption.
Krista Case, theCUBE Research
Focus on data resilience
Oracle's emphasis on the data layer stems from its larger vision of positioning the AI database as the central hub for agent-driven operations. According to theCUBE Research's John Furrier, the company's philosophy holds that the trajectory of AI will be shaped not by agents themselves, but by the mechanisms through which they access and interact with data.
This conviction has shaped Oracle's security approach through a strong emphasis on resilience. For many enterprises, loss of access to mission-critical data can prove devastating, and Oracle is helping organizations build resilience through validated backup systems, tested failover environments, disaster recovery infrastructure and high availability configurations. These capabilities encompass Zero Data Loss Recovery solutions that safeguard Oracle databases down to the final committed transaction, as well as the Globally Distributed AI Database, which employs Raft-based replication and automated failover mechanisms. Systems can maintain operation even when infrastructure nodes, availability zones or entire data centers fail.
The resilience challenge is not only recovering from an attack. Organizations also need to recover from authorized agents that make the wrong decisions, alter critical data or disrupt business processes at machine speed.
Krista Case, theCUBE Research