Securing AI: the tool is the easy part

Article

By: Kieran Baker

Your workforce adopted AI faster than your controls did. For CIOs and CFOs, the exposure that should worry you isn't the technology you haven't bought yet. It's the expertise to make what you do buy work.
Contents

Somewhere in your organisation, right now, someone is pasting something into an AI tool they probably shouldn't be. Not maliciously. They're trying to summarise a board pack, debug a script, or knock a messy client brief into shape before lunch. The tool is very good at it, and that's rather the problem. Kieran Baker explains the challenges with AI adoption, and what good looks like when governing it.

Most leadership teams are only starting to confront the uncomfortable question: If AI adoption inside the business has already happened – is it too late? Especially if adoption didn't wait for a policy, a procurement cycle or a risk assessment. Netskope, whose platform watches AI traffic across thousands of enterprises instead of relying on what people report in surveys, says the number of staff using generative AI at work has roughly tripled in a year, and the volume of data being sent to those tools has grown around fivefold. Close to half of that usage still runs through personal, unmanaged accounts that sit outside any corporate control. In most organisations, nobody can see what is being sent. For a CIO, that's an operational blind spot. For a CFO, it's a liability sitting quietly on the balance sheet: client-confidential data, M&A material, source code and personal data, any of which can leave the building one prompt at a time.

The risk grows with adoption, and adoption isn't slowing

Netskope finds the average organisation now logs hundreds of data-policy violations involving generative AI every month, some companies seeing thousands.

It's tempting to treat this growth as a phase that governance will eventually catch up with. But the evidence points the other way.

The type of risk is also broadening. Shadow AI, and Agentic AI: both have access to your systems, with no human input and often little or no way to govern them yet.

None of this is an argument against AI. The productivity case is real, and your competitors are chasing it. It's an argument against how fast your people are adopting AI and how fast you can see and govern it, quietly creating a rapidly emerging exposure.

Why buying a product doesn't close the gap

The market often answers all these challenges exactly as you'd expect, with products. There's now a whole category of AI-security tooling: discovery engines, AI gateways, guardrails, posture management, brokers for agentic traffic. A lot of it is good, but a product is not a control. Buying an AI-security tool or solution and switching it on with the default settings and watching the dashboard fill up is not the same as being protected. It's the lesson the industry learned the hard way with firewalls, SIEM and endpoint tooling a decade ago. The end of procurement is where the work starts, not where it finishes.

These platforms are powerful because they're configurable, and that's also what makes them hard. A data-loss policy is only worth having if it understands what your sensitive data looks like, from your client identifiers to your deal codenames to your regulated records, not a generic template lifted from a setup wizard. Guardrails need tuning to your risk appetite, not somebody's default. Sanctioned tools must be told apart from shadow ones. And when an alert fires at two in the morning, someone must know whether it matters and what to do next.

These AI tool categories are new in themselves andbarely existed two years ago, and the people who can deploy and run them well are in short supply. For some, building that capability in-house means recruiting specialists who are hard to find, in a field that shifts month to month. The technology is increasingly the easy part. The operating model around it is where both the value and the difficulty.

What good actually looks like

Take away the product noise and the path is logical.

  • Start with visibility, because you can't govern what you can't see. You need an honest picture of which AI tools your people and systems are using, approved or not.
  • Then control access. Decide who can use which tools and, more importantly, what data is allowed to flow into them. The aim is to enable AI safely, not to ban it and push usage further underground.
  • Protect the data next, with data-loss and data-posture controls tuned to your information, so the right data stays usable and the wrong data never leaves.
  • Stretch that same visibility and control over the agentic traffic that's coming, before it turns into the next generation of shadow IT.
  • Then operate it. Keep tuning the policies, watch the alerts, respond to the ones that matter, and feed all of it into your wider security picture. This is the step that never really finishes, and the one most often underestimated.
  • Finally, monitoring the AI usage itself, whether it’s workforce utilisation, or automation / agents, is critical, identifying potential misuse, what agents are accessing but also understanding the use cases in an environment. While I mention this through a security operations lens, it expands to cost controls; what models can / can’t be used to control token usage and business intelligence; what do our staff need to be successful.

The point most people miss: don't let AI security sit in a silo

The move that pays off most isn't standalone AI security at all. It's integration. AI risk doesn't live in isolation. It's tangled up with identity, endpoints, email and everything else an attacker cares about, so treating AI as a separate dashboard just recreates the fragmentation security teams have spent years trying to escape.

What works is to manage the AI, web and data layer with a capable platform, then feed that activity into a single detection and response capability a. AI signals then get correlated with the rest of your security telemetry instead of being watched in their own corner, and AI exposure becomes part of how you defend the whole organisation rather than a bolt-on.

That integration, and the daily operation behind it, is the gap that needs filling. Deploy, tune, manage and monitor these platforms as a managed service, bringing in expertise where needed for round-the-clock cover that the tools demand, so you can have enterprise-grade AI security without building and keeping the team to run it.

Where to start

You don't need an off-site to begin. You need to see what's already happening. The most useful first step is nearly always a straight assessment of your current AI exposure: what's in use, through which accounts, and what data is moving. That conversation has a way of reframing the whole question, from "should we adopt AI?" to "how do we say yes to it safely?"

And that's the job, in the end. AI isn't the risk. Ungoverned AI is. Closing that gap is an operating capability, not a purchase.

To speak to us on any of these issues, get in contact with Kieran Baker.