Transform AI from a security blind spot into a roadmap
I used to joke that every new technology came as a three-course CISO dinner: hype for the appetizer, hope for The post Transform AI from a security blind spot into a roadmap appeared first on The New Stack .
Several technology cycles have presented hype, hope, and harsh reality for enterprises. The evolution of AI follows a similar pattern. While the concept of code generation through AI dates back over three decades, its speed, scale, and authority have accelerated dramatically. Enterprises are already utilizing AI, but adoption continues to outpace governance capabilities.
A recent survey revealed that 77% of technology leaders believe AI adoption is surpassing their current governance capabilities, while 70% report business teams are deploying AI technology faster than IT can monitor. Only 11% of respondents feel fully prepared for the scale of AI-agent deployment expected within the next year. Shadow AI—employees utilizing personal AI tools without IT visibility—often exists alongside sanctioned technology, with more than 90% of companies reporting regular usage, yet only 40% having official LLM subscriptions.
As AI transitions from assistance to action, the risks evolve from summarizing documentation to accessing credentials, executing code, or modifying production systems. The solution lies in building a controlled path for AI adoption, complete with visibility, trusted inputs, controlled execution, and clear accountability. This ensures the sanctioned route is more appealing than alternative, shadow methods.
CISOs should act as copilots, understanding business objectives, anticipating risks, and guiding enterprises to safe routes. Rather than attempting to block AI, CISOs should aim to make the secure path more attractive than the alternative. This approach requires understanding current AI usage patterns, data access, actions, and potential impacts.
Stronger controls should be applied as autonomy increases. Trusted components and isolated execution environments further enhance security. Measuring the effectiveness of the sanctioned path is crucial, including tracking visibility, approved vs. unauthorized use, exceptions, and continued workarounds. The goal is for security to evolve from a post-deployment gate to an integral part of architecture and design, enabling responsible AI adoption.
Written by urgent.news from The New Stack's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.