Oracle Pivots Security Strategy to the Data Layer as AI Threats Multiply
Oracle is centering its enterprise security approach on protecting data itself rather than perimeters, deploying new tools and a three-part framework designed for an era when AI agents operate at machine speed.

As artificial intelligence introduces fresh vulnerabilities across enterprise systems, Oracle Corp. is repositioning its security posture to focus on the data layer itself. The company's framework rests on three pillars—securing at source, securing at speed and securing through resilience—each designed to embed protective controls directly where data lives. With AI agents now widely deployed across organizations, embedding security mechanisms into the data infrastructure has become essential for maintaining consistent policy enforcement.
Oracle's shift reflects a broader industry movement toward weaving security, governance and recovery functions throughout the entire AI technology stack. According to theCUBE Research's Dave Vellante, "The cloud shared responsibility model is no longer a sufficient framework in this AI-first world. Agents acting at machine speeds require what theCUBE Research calls a shared accountability model. It's not enough to protect infrastructure, apps and the data inside. AI has raised the trust bar, and customers must now consider much more deeply how adversaries using AI, and even accidental AI actions running at machine speeds bring new risks to enterprises."
Oracle will detail how it is rebuilding security from the data upward—an approach built for environments where conventional application and perimeter defenses alone prove inadequate—during its "AI Cyberattacks Are Escalating: How to Secure Your Data Now" virtual event on Sept. 22. The gathering will bring together Oracle product executives and outside specialists alongside theCUBE Research analysts to examine how the threat environment is changing and offer concrete strategies for safeguarding sensitive information, minimizing downtime, restoring operations after incidents and maintaining defenses as AI-driven attacks become more sophisticated.
New tools for enterprise security
In June, Oracle unveiled its three-part security framework in response to mounting challenges created by expanding AI deployment. Wider adoption of AI systems has opened new channels for reaching sensitive corporate data, prompting Oracle to develop a toolkit focused on database security, patching, testing and lifecycle management.
The toolkit includes Oracle Deep Data Security, which enforces privacy rules tailored to individual users within the database, and Oracle SQL Firewall, designed to counter SQL injection—a vulnerability that permits attackers to execute harmful database instructions through web form inputs. In April, Oracle announced a comprehensive upgrade to its Oracle AI Database that incorporated Deep Data Security, enabling centralized, rule-based, granular authorization and data visibility policies determined by each user's identity, roles and context.
As AI agents have evolved from merely answering queries to executing substantive business actions, questions have surfaced about whether application-layer security remains adequate. By placing Deep Data Security's policy enforcement directly inside the database, Oracle adds a safeguard against unauthorized data retrieval stemming from adversarially crafted queries.
Krista Case of theCUBE Research stated, "The next phase of enterprise AI adoption will depend as much on governance as model capability. As agents gain access to sensitive data and critical workflows, organizations need to know whose identity they are acting under, what privileges they inherit and where those privileges are enforced. Getting those controls right can accelerate AI adoption."
Focus on data resilience
Oracle's emphasis on the data layer forms part of its larger vision to position the AI database as the backbone of agentic workloads. According to theCUBE Research's John Furrier, the company believes that AI's trajectory will be shaped not by agents themselves, but by where they operate and how they interact with data.
This perspective has shaped Oracle's security approach through a strong emphasis on resilience. For many enterprises, losing access to essential data can be catastrophic, so Oracle is helping organizations strengthen resilience through verified backups, tested failover systems, disaster recovery and high availability features. These capabilities include Zero Data Loss Recovery solutions that safeguard Oracle databases down to the final committed transaction, and the Globally Distributed AI Database, which uses Raft-based replication and automatic failover. Systems can remain operational even when infrastructure elements, availability zones or entire regions fail.
Case added, "The resilience challenge is not only recovering from an attack. Organizations also need to recover from authorized agents that make the wrong decisions, alter critical data or disrupt business processes at machine speed."


