AvePoint has introduced a new data classification tool designed to track sensitive information as it changes across enterprise systems, responding to what the company says is a widening gap between organizations' confidence in their AI security and actual breach rates. The Kinetic Classification feature continuously reevaluates files as permissions shift, content evolves, or AI systems interact with data, rather than relying on one-time labels that become outdated. The launch coincides with findings from AvePoint's 2026 State of AI Report showing most organizations remain confident in their defenses even as incidents mount.
According to AvePoint's survey, 82.7% of organizations described themselves as "very" or "extremely" confident in their ability to prevent unauthorized access to data. Yet among respondents in the "very confident" group specifically, 72% reported experiencing an AI-related unauthorized access incident during the previous 12 months. The company's classification engine works across Microsoft 365, Google Workspace, and several business platforms including GitHub, ServiceNow, Jira, Confluence, and AWS S3, repeatedly reassessing files as access permissions change, content evolves, AI agents interact with data, or labels expire.
"The next wave of AI governance starts with the data itself," said John Hodges, chief product officer at AvePoint. The company argues the survey findings suggest organizations need stronger operational controls around identifying sensitive data as AI adoption expands. AvePoint Chief Technology Officer John Peluso described the capabilities as examples of how the company enables AI trust within organizations globally. Alongside the classification tool, AvePoint updated its Rapid Recovery platform with features designed to speed up recovery after security incidents, including intelligent recommendations that identify the most important data to restore first and a wizard for creating recovery plans in advance.
The disconnect between confidence and actual breach rates reflects what AvePoint characterizes as a readiness problem rather than an ambition problem. Organizations aren't struggling to adopt AI, according to the report, but they lack clear visibility into which data is sensitive, who owns it, how it changes over time, and whether AI systems should access it in the first place. The Kinetic Classification feature addresses this by treating data sensitivity as a moving target that requires continuous monitoring, particularly as AI agents begin interacting with enterprise information in ways that weren't anticipated when files were first labeled. For managed service providers and channel partners, the updates create an opportunity to build services around AI readiness, data protection, and business continuity by helping customers understand where sensitive data resides and which systems must be restored first during an incident. The approach positions continuous classification as the operational link between AI governance policy and day-to-day security and recovery requirements.

