AI stopped being just a chat window. It now reads, decides, and acts - and the risk is far beyond “someone tried to upload a spreadsheet into ChatGPT”. Data and action flows at machine speed, and a new approach to cybersecurity is needed. We’ll explore how the AI risk story has evolved from shadow AI and data leakage to agentic systems, runtime control, and governance at scale.