compliance

Sharp Rise in AI Adoption for Cyber Defense Exposes Major Governance Gap

A recent SANS Institute survey reveals rapid AI adoption in enterprise cyber defense has outpaced the establishment of governance frameworks, with over 40% of practitioners reporting no formal AI policies and 60% lacking visibility into AI model use and data exposure. Despite 75% of security professionals holding governance roles, more than half indicate the absence of AI audit frameworks, highlighting a significant perception gap between security leaders and frontline staff regarding AI risk management programs. This governance shortfall raises concerns about protecting sensitive information amid expanding AI integration in cybersecurity operations.

https://www.ciodive.com/news/ai-adoption-cyber-defense-governance-gap/825462/

Shadow AI Is Really a Workflow Problem

As law firms integrate AI into legal work, the primary challenge is not just unauthorized technology use (“Shadow AI”) but inconsistent, unofficial workflows (“Shadow Workflows”) created by individual lawyers lacking firm-wide guidance. This leads to varied AI practices within the same firm, undermining governance, quality consistency, and institutional knowledge while exposing lawyers and clients to operational risks. Effective AI governance requires designing shared, scalable workflows and organizational capabilities that enable responsible, consistent AI use beyond mere technology approval.

https://aceds.org/shadow-ai-is-really-a-workflow-problem-ai-blog/

You Outsourced the AI—but You Still Own the Risk

As enterprises increasingly deploy AI systems developed by third parties, they remain legally and operationally responsible for the risks these systems pose, including discrimination, data mishandling, and customer harm. Despite limited visibility into the models’ training or updates, companies face scrutiny from regulators and courts when adverse outcomes occur, underscoring the need for robust AI risk management and governance even when AI is outsourced.

https://hbr.org/2026/07/you-outsourced-the-ai-but-you-still-own-the-risk

The New AI Trust Architecture: 5 Requirements for Agent-to-Agent Communication

Salesforce AI Research identifies a critical need for a new trust architecture to enable effective, reliable communication and negotiation between autonomous AI agents representing competing organizations. The framework requires five key elements: interpretable standards beyond fixed rules, persistent identity and reputation linked to principals, governance through boundaries rather than exhaustive scripting, structured accountability traceable to humans, and calibrated escalation to balance automation with liability. These principles aim to establish governance, legal, and ethical guardrails before AI agents handle consequential enterprise transactions at scale.

https://www.salesforce.com/blog/new-ai-trust-architecture/

Modernizing Legacy IT with AI Without Triggering Regulatory Risk

AI can accelerate the modernization of legacy IT systems, especially in regulated sectors with COBOL-based cores, but the main challenge lies in ensuring compliance and traceability to satisfy auditors and regulators. Key risks include undocumented business rules that AI may incorrectly interpret, leading to regulatory violations under frameworks like DORA, NIS2, and AI Regulation. Successful modernization requires thorough asset inventory, human validation of AI outputs, end-to-end traceability, strict data governance, and oversight of AI use to make transformations defensible and sustainable.

https://www.cio.com/article/4193445/modernizing-legacy-it-with-ai-without-increasing-regulatory-risk.html

5 AI Risk Management Frameworks for Shoring up Key Gaps

A new generation of AI-specific risk management frameworks has emerged to address gaps in traditional governance, security, and compliance models, helping organizations identify AI risks, implement controls, and demonstrate responsible AI use. Five notable frameworks include the ISO/IEC 42001 AI Management System, the NIST AI Risk Management Framework, ENISA’s AI Cybersecurity Practices, ISO/IEC 23894 guidance on AI risk, and Google’s Secure AI Framework (SAIF), each focusing on different aspects like governance, lifecycle risk management, cybersecurity, or operational security. These frameworks are complementary and vary in complexity and focus, with organizations advised to select ones that align best with their AI risk challenges and maturity level.

https://www.csoonline.com/article/4185917/5-ai-risk-management-frameworks-for-shoring-up-key-gaps.html

Gartner Security Summit 2026: Huntress 5 Key Takeaways

At the Gartner Security & Risk Management Summit 2026, the key insight emphasized was that effective security is an ongoing journey focused on resilience, honest risk assessment, and rapid recovery rather than chasing every emerging trend or technology. Organizations succeeding in the evolving threat landscape prioritize building a strong foundation in identity management, control effectiveness, and operational reality to enhance their ability to withstand and respond to incidents. This pragmatic approach highlights that security is a continuous process centered on adaptability and resilience in the face of challenges, especially with the rise of AI-driven threats.

https://www.huntress.com/blog/key-takeaways-gartner-security-risk-summit

CIOs: Tear Down the Wall Between Resilience and Data Security

AI is exposing the longstanding separation between organizational resilience—focused on system uptime—and data security—focused on protecting information—as no longer sustainable. CIOs are urged to integrate these functions by inventorying and governing unstructured data, automating compliance controls to keep pace with AI-driven threats, and establishing clear audit trails for AI agent actions to meet regulatory demands. This unified approach is essential for enabling enterprise innovation while maintaining trusted data and system recoverability in the evolving AI risk landscape.

https://www.cio.com/article/4179381/cios-tear-down-the-wall-between-resilience-and-data-security.html

Why Your Most AI-savvy Employees Are Driving Shadow AI

Employees most knowledgeable about AI often engage in using unauthorized AI tools at work to increase speed and overcome limitations of official systems, creating shadow AI challenges for CIOs. To manage this, organizations are rethinking governance and training strategies to balance encouraging experimentation with protecting data and maintaining oversight, emphasizing hands-on education that addresses technical, ethical, and security aspects while adapting AI tools to meet employee needs.

https://www.cio.com/article/4178359/why-your-most-ai-savvy-employees-are-driving-shadow-ai.html

Shadow AI Is Exposing the Same Failures Teams Have Ignored For Years

The rapid adoption of AI tools like ChatGPT and Microsoft Copilot in enterprises is outpacing cybersecurity teams’ ability to establish effective governance controls, exposing longstanding failures in how organizations implement security policies around operational workflows. Shadow AI—employees’ use of unauthorized AI tools to enhance productivity—highlights that restrictive policies alone are insufficient; sustainable governance requires aligning controls with actual work practices, providing approved, usable alternatives, and adopting a risk-based, ongoing operational approach rather than one-time policy enforcement. This shift is critical to managing AI-related risks without driving usage further outside organizational visibility.

https://www.infosecurity-magazine.com/opinions/shadow-ai-is-exposing-governance/

Scroll to Top