The Shiny New Toy: Are We Racing Past AI Governance?
Key Takeaways
- AI adoption is outstripping governance. Organizations are rushing to adopt AI, but security, privacy, intellectual property and risk management need to keep pace to avoid costly surprises.
- Responsible AI begins with solid guardrails. Proactive governance helps teams develop confidently—from data protection and vendor due diligence to agent permissions and acceptable usage standards.
- The firms that scale AI successfully will find the right blend of innovation and trust. Security, privacy and governance are not roadblocks to growth. They are the basis of scalable AI adoption.
AI has become the shiny new toy in the business world. It’s dominating the conversation, from boardrooms and industry conferences to the news and everyday life. Organizations are eager to get AI projects moving, and understandably, no one wants to miss the bandwagon.
I share that excitement. In fact, I’m steering my own career toward AI security and governance because AI has changed, and will continue to change, how we work, live and play. The rapid growth of AI, and more importantly the speed at which people are adopting it, will have a more profound impact on our daily lives than the PC or the internet did. Research from the Federal Reserve Bank of St. Louis found that nearly 40% of U.S. adults had used generative AI within two years of ChatGPT’s launch, roughly double the internet’s adoption rate at the same point. But as a CISSP, one question keeps coming back to me: in the race to become an “AI company,” how do we make sure security, privacy, intellectual property rights and governance keep pace?
It’s a question worth asking early, because it’s much easier to build these protections in from the start than to add them later.
Why everyone is jumping on the bandwagon
The momentum comes from many directions. Boards and executive leadership want to understand the organization’s AI strategy. Competitors are announcing new AI capabilities and services. Vendors are adding AI features to tools we already use. And employees, eager to be more productive, are exploring AI tools on their own.
The result is a wave of AI pilots and projects across the organization. Many of them are led by business units that sit closest to the problems AI can solve, and that’s a good thing. The challenge is that the pace of adoption often outruns the process of good governance and risk assessment. Security, privacy and contract reviews don’t always get a chance to catch up before real company data starts flowing in.
Everyone involved is trying to deliver value, and that energy is worth protecting. However, the organizations that succeed with any new technology in the long run pair that energy with the right guardrails.
Security: a new attack surface to understand
AI brings some familiar security challenges, along with some new ones that many teams are still learning about.
- Prompt injection. A model can be influenced by hidden instructions in an email, web page or document it reads. There’s no single fix yet, so layered defenses are key.
- Data leakage. Depending on the vendor and plan, information entered into an AI tool may be logged, retained or used for training.
- Agent permissions. AI agents can now send email, query databases and start transactions. Scoping their access carefully keeps that power in check.
- Shadow AI. When employees adopt tools on their own, security teams lose the visibility they need to protect the organization.
- Supply chain. Open-source models, plugins and third-party APIs deserve the same vetting as any other software we bring in.
The encouraging part is that the fundamentals still apply: least privilege, logging, vendor due diligence and testing before production. The key is to ask these questions before go-live rather than after.
Privacy: respecting the people behind the data
AI runs on data, and much of that data is about people: customers, patients, employees and donors. When we’re exploring what AI can do, it’s easy to overlook that a customer list or a set of support tickets may contain personal information that deserves protection.
A few simple questions go a long way:
- What personal data is going in?
- Where is it processed and stored, and for how long?
- Does the vendor use it to train their models or in other unauthorized ways?
- Can we still honor requests to access or delete someone’s data?
- Have we been transparent with people about how their data is used?
Regulators are paying attention too. The EU’s GDPR and a growing number of U.S. state privacy laws already apply to AI, and AI-specific regulations like the EU AI Act are building on top of them. Thinking about privacy early helps keep projects from turning into compliance issues.
Intellectual property rights: protecting what makes you unique
With AI, IP risk cuts both ways.
What goes out. In 2023, engineers at Samsung reportedly pasted proprietary source code and internal meeting notes into ChatGPT while trying to get work done faster. The company reacted by temporarily banning generative AI tools on company devices. Not only did proprietary information and possible trade secrets leave the company’s control, but the incident also complicated Samsung’s own adoption of AI. What stands out to me is that the employees were simply trying to work more efficiently. It shows why clear guidance and approved tools matter so much.
What comes in. The output side raises its own questions. Who owns the code, text or images a model produces? Could that output be reproducing someone else’s copyrighted work? Can we even protect something that was mostly machine-generated? The courts and the Copyright Office are still sorting all this out.
Bringing legal and procurement resources into the early stages of an AI project to review data use, output ownership and possible liability concerns can save a lot of trouble down the road.
Bringing it together with governance
Security, privacy and IP all connect back to governance. Many organizations are still working out who owns AI risk from end to end, and that’s a natural stage for a technology moving this quickly. Three questions make a great starting point:
- Do we have an inventory of the AI tools and models we use, including features built into our SaaS apps?
- How do we decide which AI use cases move forward, and who makes that call?
- How will we monitor these systems for bias, drift, errors and misuse after they go live?
The good news is that we don’t have to start from scratch. Frameworks and regulations such as the NIST AI Risk Management Framework, the EU AI Act and the OWASP Top 10 for LLM Applications can help us design safe and secure AI programs from end to end.
Good governance isn’t about slowing things down or saying no. It’s about clear ownership, a repeatable intake process, and making risk decisions intentionally, so teams can innovate with confidence.
Good brakes let you go faster
None of this requires putting innovation on hold. A few practical steps can make a big difference:
- Take inventory. Get a clear picture of the AI already in use, including features built into existing tools.
- Publish an acceptable use policy. Explain in plain language what data can go into which tools, and provide approved options so people have a safe path to follow.
- Create a lightweight intake process. Give each new use case a quick review from security, privacy, legal and the potential business case. Low-risk ideas should move through in days, not months.
- Match the review to the risk. An AI that drafts marketing copy needs less scrutiny than one that screens job applicants or handles health data.
- Review the contracts. Understand how vendors use your data, who owns the output, and what protections are in place.
- Treat AI like any other identity. Apply least privilege to agents and integrations and log their activity.
- Invest in training. People want to do the right thing. Clear guidance helps them do it.
- Name an owner. A leader accountable for AI risk, supported by a cross-functional team, keeps everything connected.
Race cars have some of the best brakes in the world. Not because drivers want to go slow, but because great brakes give them the confidence to go fast.
AI governance works the same way. Organizations that build security, privacy and IP protection into their AI programs from day one position themselves to scale faster, earn trust and avoid costly surprises along the way.
So let’s enjoy the shiny new toy. Let’s just take a moment to read the instructions before we hand it the keys to the business.
Sources
- Bick, Blandin & Deming, The Rapid Adoption of Generative AI, Federal Reserve Bank of St. Louis (2024)
- Samsung Bans ChatGPT, Google Bard, Other Generative AI Use by Staff After Leak, Bloomberg (May 2, 2023)