The AI Risk Gap Is a Release Gap
Originally published on the Dromeas blog . Gartner's latest quarterly has a line I keep coming back to: to protect the value you get from AI, plan to spend at least twice as much on derisking it as you spend on the tools themselves. That's aimed at CEOs and CFOs. But if you run engineering or security, I think it lands on you faster than on anyone, because that's where AI output turns into…
Gartner's latest quarterly report highlights the critical need to focus on mitigating AI risks, rather than just investing in AI tools themselves. According to the report, CEOs and CFOs should allocate at least twice as much budget to derisking AI as they spend on the AI tools themselves. However, the report emphasizes that engineering and security teams play a crucial role in ensuring that AI outputs turn into real, valuable applications.
Derisking AI starts at the release stage, where a decision can be made to either say no or give the green light to proceed. Gartner's three pillars of risk include cost, cybersecurity, and trustworthiness. Currently, only 28% of CEOs are increasing spend on security and risk, compared to 75% who are increasing spend on technology, data, and IT. Furthermore, only 37% of CEOs feel highly prepared for cyber escalation, and only 23% of C-suite executives are confident in their organization's generative AI outputs.
The report suggests that derisking AI should begin with certifying each release. This involves creating a trusted release with a verdict and the evidence behind it, such as what was checked, what was found, and who or what disagreed with the decision. For AI-generated code, automated guardrails and containment measures should be implemented to ensure that security checks run on every change and release.
The cost of AI is often underestimated, with 45% of senior functional leaders not sticking to their planned AI budget in 2025. Revisions and fixes caught after release are far more expensive than those identified before release. To address these costs, Gartner recommends gatekeeping every release on a verdict, rather than relying on intuition or a vague "it's fine" assessment.
Finally, it is essential to know what AI tools are present in the software and maintain an AI bill of materials to comply with regulations like the EU AI Act.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.