AI Governance through CISO's lens.
As I have seen in many organizations, AI governance is landing on the CISO's desk and governing AI is very different from how architecture or development teams see it.
Developers ask: "Does it work?" and Architecture confirm: “If it is accessible”
The CISO asks: "What can this system touch, who can make it do things and how would we know if it went wrong?"
Here's how that plays out across the AI stack:
Data and context: RAG pipelines can expose sensitive data to the wrong users if retrieval ignores existing access controls.
Agents: Once AI can take actions, it becomes a new identity in environment. It needs least privilege and human approval for high-impact actions.
Tools and integrations: Every connection expands the attack surface. Prompt injection hidden in emails, documents or web pages turns integrations into entry points.
Governance: Acceptable use, data residency, vendor risk and regulations like the EU AI Act.
Evaluation: Red-teaming before go-live isn’t just accuracy benchmarks.
Observability: An AI system that can't be audited is one that can't be defended.
Cost and scale: Runaway agents and denial-of-wallet attacks are security problems too.
But technical controls are only half the CISO’s job.
Usually, AI failures go public rapidly. Furthermore, a chatbot promising refunds it can't give or leaking customer data becomes a screenshot or viral within minutes (e.g. the Air Canada chatbot ruling showed that accountability lands on the company, not the model vendor).
That means CISOs now have to consider headlines, regulators, board questions and shareholder value alongside different standard domain related controls.
The model won't be held accountable. We will.
CISOs: is AI governance sitting with you in your organization or somewhere else?
