It's been a minute since I had a website up, but I'm back! And let me just be honest real quick and fully admit there was quite a bit of urgency for me to get this site live again, or else I would have likely kept dragging my feet.
I was blessed to be a guest on a podcast recently, sharing some thoughts about AI governance and leadership. I wanted to have a link to my brand-new digital front door live by the time the episode came out so I could have a link ready to be shared in the show notes.
So, here it is! Of course, I'll be making plenty of updates in the coming weeks, but I needed to get something out here, and because of where we are technologically at the moment, I was able to ship something in short order.
I'll let you know when the podcast episode drops, but in the meantime, allow me to share with you some thoughts that did not make the episode because I run my mouth and therefore didn't get to one of the questions I had prepped for.
Well, here it is. Let me know your thoughts.
Question: 50% of large enterprises now have dedicated AI governance committees. Is that structure actually working, or is it creating the appearance of governance without the substance?
So when I think about how to answer this question, two things come to mind. One, I think about how the biggest companies in the world — Meta and Amazon especially — either have experienced outages or the exposure of sensitive information due to how internal AI tools have been deployed. And two, I think of an article I read recently about how 2/3 of professionals surveyed admit to using unauthorized AI tools at work.
Without even going into great depth here, these instances suggest, at least to me, that perhaps AI governance in a vacuum is not getting the job done. Should we actually be taking a step back and looking at just plain old governance? Do we understand what governance truly means and what it's designed to do?
If governance is just a policy PDF buried in SharePoint, then how effective is it really? What are you really governing? A big part of governance is structure, and structure involves getting clarity on what roles people and departments and entities play in your organization.
So when we're talking about AI governance, the first question we need to consider about AI agents — even before we evaluate and decide what we're looking to automate or what processes we're looking to improve — is what role do these agents play in your organization?
The onboarding parallel
Let's say you've hired a Security Engineer and she starts tomorrow. You have an onboarding process for her; you have training she needs to go through, and if you have good IAM practices in place, you know exactly what role-based permissions she needs to have and when she needs to be given more permissions. Those things are clear.
Why aren't those processes, practices, or permissions clear for AI agents at the point of deployment? In our rush to implement these technologies and keep up with everyone else and pursue efficiency and maximize profits and keep shareholders happy, we've deployed these agents all throughout our environments without the care and consideration we give to human employees.
At my previous company, I was hired as a junior DFIR analyst, and I was brought along very slowly. I'm a second-career cyber professional. Even though I had a background in electrical engineering, I had not been in IT for the past 20 years, and so I was treated like a tech newbie.
I was essentially a project manager (which I absolutely loved, by the way) for 18 months, and it was nearly 18 months before I got permissions to anything technical — no VPN access, no EDR access, no VMs, none of that. I had to go get a particular certification, and I had to prove I could be trusted to handle sensitive information properly before I had a chance to do any real incident response work.
And I got it. I completely understood why I was being asked to prove myself. Our clients were trusting us to handle their incidents with the highest level of care and integrity, so someone like me who had been away from anything technical for nearly 20 years had to earn trust.
Are we making AI agents earn trust?
Are we making AI agents earn trust, or are we just giving them access to everything because of their advanced capabilities? You're not giving your newly hired Security Engineer or especially your neophyte Junior Analyst the keys to the kingdom on their very first day, so why are you letting up on those standards for the AI engineer agent you're deploying?
Yeah, sure, an AI agent is going to be more capable than a junior-level analyst, but maybe — just maybe — we should consider deploying that agent on a probationary period or an evaluation period so we can see how that agent's actions and performance stack up against the security controls we have in place before we give the agent more responsibility.
And that evaluation process is something we codify and develop SOPs around so there's clear understanding throughout the organization of:
- what we're commissioning agents to do
- what our expectations of them are
- what permissions are being given
- and most importantly, what the guardrails are
Getting clear on all of that is what governance means to me, and some of the news we've heard lately from the major players in this space have me wondering if any of this is taking place at a high level. Maybe it is; perhaps I'm wrong. But I don't see it yet.
