Artificial intelligence is rapidly moving beyond experimentation and becoming part of the operating fabric of modern organisations.
Employees are using AI to research, analyse, communicate and automate. Developers are embedding it into applications and workflows. Security teams are applying it to detection, investigation and response. Vendors are incorporating AI into the platforms businesses already rely upon.
The opportunity is significant. So is the risk.
For technology leaders, the question is no longer simply whether AI should be adopted. In many organisations, that decision has already been made through formal initiatives, vendor platforms and employee behaviour.
How do we capture the benefits of AI without introducing risk faster than we can understand, govern and control it?
The balance will become one of the defining responsibilities of technology leadership over the coming years.
Many of the risks associated with artificial intelligence are not entirely new. Organisations have dealt with data leakage, excessive access, software vulnerabilities, automation failures, third-party dependencies and poor decision-making for decades.
What AI changes is the speed, scale and potential autonomy with which those risks can materialise.
A person can make an incorrect decision. An automated system may repeat that decision thousands of times. An employee can accidentally disclose sensitive information. An AI platform may expose information across a much broader dataset. An attacker can manually research an organisation. AI can accelerate reconnaissance, analysis and the development of attack techniques.
The fundamental risks are therefore familiar. What is different is the speed and scale of the consequences.
AI risk is increasingly a matter of business resilience, governance and accountability.
Good governance begins with understanding where AI is already in use. For many organisations, this is more difficult than expected.
AI may already exist within:
productivity and collaboration platforms;
development environments;
cybersecurity tools;
cloud and SaaS services;
customer platforms; and
data and analytics systems.
At the same time, employees may independently use public generative AI services to analyse documents, generate code, prepare communications, or process business information. This creates a growing problem of shadow AI.
Trying to solve this purely by blocking technology is unlikely to work. People use these tools because they are useful. The better approach is to create approved ways for employees to use AI while establishing sensible restrictions on what information can be provided to it, which platforms are trusted, and which activities require additional oversight.
Technology leaders should be able to answer a small set of fundamental questions:
Where is AI being used?
Which platforms are approved?
What information can those platforms access?
What data is being provided to external services?
Which systems can AI analyse?
Which systems can AI actively change?
Without visibility, meaningful governance is extremely difficult.
An organisation cannot adequately protect information if it does not understand where that information resides, who can access it and how it is used.
AI amplifies the consequences of poor data governance. A system connected to organisational information may access customer records, intellectual property, financial information, internal communications, employee data or operational information.
The risk is not necessarily that the AI platform itself is malicious. The problem may be that it has been granted excessive access.
This makes traditional security disciplines more important, not less.
information classification;
least-privilege access;
identity governance;
role-based access control;
logging and monitoring;
data-loss prevention; and
lifecycle management.
Before granting an AI system access to organisational data, we should ask the same questions we would ask before granting access to a person or a third-party system: What does it need? Why does it need it? Which identity is being used? What permissions have been assigned? Can those permissions be reduced? Is activity logged? Can access be revoked quickly?
These questions become even more important as AI shifts from answering questions to taking action. Agentic AI may interact with applications, invoke APIs, modify records, provision accounts, execute workflows, or modify infrastructure.
At that point, we are no longer merely governing information. We are governing authority.
An AI agent with excessive privileges poses many of the same risks as an overly privileged employee or service account, except that it may operate faster, continuously and across multiple systems. Machine identities therefore need to be treated with the same seriousness as human privileged identities.
Not every AI use case carries the same level of risk. Using AI to summarise meeting notes is materially different from allowing an autonomous system to modify production infrastructure, deactivate an account or approve a financial transaction.
The level of governance should therefore reflect the potential consequences. A useful way to think about this is in three levels:
Low-consequence activity: Research, summarisation, drafting and general productivity may require relatively lightweight controls, provided that sensitive information is appropriately managed.
Decision support: AI may analyse information and recommend a course of action, while a person remains responsible for the decision.
Autonomous action: AI may be authorised to take action without immediate human intervention.
The distinction between the last two is significant.
There is an important distinction between AI recommending an action and AI executing an action.
As confidence grows, some actions can reasonably be automated. Others, particularly those that could materially affect customers, production systems, financial outcomes or business operations, may always warrant human approval.
Agentic AI does not remove accountability.
Someone within the organisation still owns the outcome.
Organisations need to consider AI risk from two perspectives: securing their own use of AI and recognising that attackers have access to the same technology.
AI can help accelerate tasks such as:
reconnaissance;
social engineering and phishing;
vulnerability research;
attack automation; and
analysis of stolen information.
This does not make every attacker sophisticated, nor does it render existing security controls obsolete. What it does is compress timelines. Weaknesses that organisations previously tolerated for extended periods may increasingly be discovered and exploited more quickly.
That makes established security fundamentals even more important.
strong identity controls;
rapid patching and vulnerability management;
endpoint detection and response;
effective email security;
network visibility;
centralised logging and behavioural detection; and
tested incident-response processes.
AI does not replace good cybersecurity. It makes poor cybersecurity less forgiving.
There is an equally important risk on the other side of this discussion. If governance becomes so restrictive that employees cannot use AI in practice, organisations may expose themselves to a different risk: falling behind organisations that adopt it effectively.
AI has the potential to improve productivity, accelerate software development, assist security analysts, automate repetitive processes and extract insights from large datasets.
Security therefore should not begin with the question, “How do we stop people using AI?” A better question is, “How do we allow people to use AI safely?”
Good governance should create confidence, not bureaucracy. That means establishing clear ownership of:
approved AI platforms and acceptable use;
data handling and privacy;
security assessment and third-party risk;
autonomy and human oversight; and
ongoing monitoring and accountability.
AI governance cannot belong solely to cybersecurity. It intersects with privacy, legal obligations, intellectual property, technology architecture, procurement, compliance, human resources and business operations. What matters is that ownership is clear and the organisation knows who is accountable for the decisions being made.
Technology will play an important role in managing AI risk, but buying another platform cannot compensate for an organisation that has not decided how it intends to operate.
A practical AI risk model can be built on six principles:
Discover: Understand where AI is already used.
Classify: Determine the sensitivity of the information and of the business processes involved.
Control: Apply identity, access, data and security controls proportionate to the level of risk.
Govern: Establish ownership, acceptable-use requirements, and clear decision-making responsibilities.
Monitor: Maintain visibility into AI activity, identities, integrations and outcomes.
Review: Continually reassess controls as technology, business use cases and threats evolve.
This does not require every organisation to create an extensive AI governance bureaucracy. It requires a disciplined, repeatable approach to managing the technology.
Every significant technology shift has introduced new risks. Cloud computing did. Mobility did. Software-as-a-Service did. Remote work did. Artificial intelligence will be no different.
What differs is the pace of this transition. Technology leaders therefore need to avoid two extremes: adopting AI indiscriminately simply because the technology is advancing quickly, or allowing uncertainty to become an excuse to prevent adoption altogether.
The organisations that manage this transition well will sit between those positions. They will:
understand what they are protecting;
maintain visibility over where AI is being used;
control access to sensitive information;
place boundaries around autonomy;
monitor behaviour; and
retain human accountability.
Ultimately, managing AI risk is not about eliminating risk from artificial intelligence. That is neither realistic nor desirable.
It is about creating an operating model that enables organisations to take advantage of AI with their eyes open.
That means understanding the opportunity, understanding the consequences, and making deliberate decisions about where risk should be controlled and where it can reasonably be accepted.
From my perspective, the real challenge lies there. It is also where technology leadership can add the greatest value.