Lakshya

Securing & Governing AI · Chapter 14

Being the function that enables

The argument this whole book is for.

There is a version of a security, risk or audit function that responds to AI by slowing it down: a long questionnaire, a standing prohibition, a policy saying employees may not use these tools. It feels responsible. It is, in almost every case, the higher-risk choice.

Because prohibition does not produce abstention

It produces unmonitored use. People paste customer data into consumer chatbots on personal devices, outside your logging, DLP, contracts and incident response. The organisation gets all the exposure and none of the controls, and you find out during the incident. A sanctioned tool with logging, a data-processing agreement and an acceptable-use policy is safer than a ban, by a wide margin.

362 SECURITY JOB DESCRIPTIONS, FULL TEXT mention AI or ML at all 92% name any AI-specific risk practice prompt injection · model risk · AI red team · NIST AI RMF · ISO 42001 · EU AI Act 9% The field is talking about AI roughly ten times faster than it is building the practice to govern it.
The gap this book exists to close. Across 362 security job descriptions, 92% mention AI — but only 9% name any AI-specific risk practice. The field is talking about AI roughly ten times faster than it is building the practice to govern it, which is precisely the opportunity for anyone who learns this properly now.

What enabling actually looks like

  • Publish the paved road. A named, approved way to use AI — this tool, this data classification, these use cases, this is how you get an exception. Teams overwhelmingly take the paved road when one exists; their goal was never to evade you, it was to ship.
  • Tier your scrutiny. Spending equal effort on a notes summariser and a credit decision is how the queue becomes the bottleneck and the business routes around you.
  • Answer in days. A two-week turnaround is functionally a prohibition for a team on a sprint. Speed is a security control, because it determines whether people come to you at all.
  • Bring the mitigation, not just the risk. “This is a prompt-injection exposure” ends a conversation. “Scope the tool to read-only and put approval on send, and I can sign this off today” ships a product safely.
  • Say what you are not worried about. Explicitly clearing five of seven concerns is what earns you the two that matter.

And for you, personally

The data says something specific about your career. AI appears in 92% of security postings, and the practice to govern it in 9%. That gap will close over the next few years as the discipline matures. The people who close it are those who learned this material while it was still unusual.

You do not need to become a machine learning engineer. You need the seven chapters of Part I, the four genuinely-new risks in chapter 9, and the evidence set in chapter 12. That is a few weekends — on current numbers, some of the highest-return weekends available in this profession.

The sentence worth carrying out of this book

Your job was never to prevent the organisation from doing things. It was to make sure that when it does them, it does them in a way you can see, measure and recover from. AI does not change that mandate. It just arrived faster than usual.

← The frameworks — NIST, ISO 42001, EU AI ActPractice bank →