TL;DR: Malcolm Harkins has been inducted into the CSO Hall of Fame for decades of work in cybersecurity, risk management, and responsible AI adoption, with formal recognition planned at the CSO Cybersecurity Awards & Conference in Nashville, according to HiddenLayer.
At a glance
What this is: HiddenLayer’s announcement frames Malcolm Harkins’ CSO Hall of Fame induction as recognition for leadership in cybersecurity, risk management, and responsible AI adoption.
Why it matters: For IAM, NHI, and AI security teams, the story matters because it signals that AI governance is becoming a leadership and operating-model issue, not a narrow technical afterthought.
Context
AI security leadership is increasingly being measured by governance outcomes, not just technical deployment milestones. In this case, the article centres on recognition for a security executive whose career has focused on risk management, resilient operations, and responsible AI adoption.
For identity and access practitioners, the relevant question is how AI programmes are governed as part of the broader security model. The article points to a market where AI adoption, compliance, and operational integrity are converging in the same leadership conversation.
The recognition also shows that AI security is now being discussed in terms of enterprise trust, not only threat detection. That makes the issue relevant to teams responsible for NHI, human IAM, and the controls that sit around emerging AI systems.
Key questions
Q: How should security teams govern AI transformation across identity and access programmes?
A: Start by treating AI use cases as governed identities rather than isolated tools. Define ownership, scope, approved data sources, and downstream actions for every system that can generate, retrieve, or execute work. Then align IAM, NHI, and lifecycle controls so access is reviewable, auditable, and revocable across the full AI operating chain.
Q: Why do AI programmes need IAM and PAM oversight as they scale?
A: Because the real security exposure often sits around who can configure, connect, or extend the system. When AI becomes part of production workflows, IAM and PAM determine who can influence its behaviour, reach sensitive data, or create persistent access paths that outlive the original use case.
Q: What are the signs that AI data security controls are too reactive or too narrow?
A: A narrow program usually shows up as blind spots around unsanctioned tools, a high alert volume with low signal, and repeated risky behavior getting the same fixed response every time. Another warning sign is when each new AI application requires a new rule after the fact. If protection cannot adapt as usage changes, it is reacting to last quarter instead of current behavior.
Q: What should teams do when AI adoption reaches critical business functions?
A: They should move AI security into the same governance model used for other enterprise-risk domains. That means aligning controls, escalation paths, and accountability with the business processes the AI now supports, rather than treating the system as an isolated technical initiative.
Technical breakdown
AI security governance sits above the model layer
The article is not about a specific product capability, but it does reflect how AI security leadership now spans governance, risk management, and operational control. That matters because enterprises are no longer treating AI as a standalone technology problem. They are asking who is accountable for security decisions across the AI lifecycle, from adoption and oversight to trust and resilience. In practice, this shifts emphasis away from isolated model controls and toward security operating models that can survive real business use. Practical implication: align AI security ownership with governance, risk, and identity teams rather than leaving it inside a narrow technical function.
Practical implication: align AI security ownership with governance, risk, and identity teams rather than leaving it inside a narrow technical function.
Responsible AI adoption depends on identity and access discipline
The article links responsible AI adoption to broader security leadership, which is important because AI systems inherit the access model around them. Whether the subject is generative, predictive, or agentic, the real exposure often sits in who can connect tools, retrieve data, approve workflows, or persist privileges. That makes AI security inseparable from IAM, PAM, and NHI governance when AI touches production systems. Practical implication: review AI access paths as part of your identity programme, not as a separate AI-only control domain.
Practical implication: review AI access paths as part of your identity programme, not as a separate AI-only control domain.
AI lifecycle security is becoming an enterprise trust issue
HiddenLayer’s own positioning in the article reinforces a broader pattern in the market: organisations want to secure AI across discovery, supply chain exposure, attack simulation, and runtime protection. That lifecycle view matters because security failures rarely start at inference alone. They emerge across the chain of model sources, integrations, permissions, and runtime use. For practitioners, that means governance must extend beyond deployment approval to continuous oversight of how AI systems are introduced, connected, and operated. Practical implication: manage AI security as a lifecycle control problem, not a one-time launch review.
Practical implication: manage AI security as a lifecycle control problem, not a one-time launch review.
NHI Mgmt Group analysis
AI security leadership is now a governance discipline, not a niche technical specialty. The article recognises a career built around security risk management and responsible AI adoption, which reflects where the field is heading. Organisations are no longer asking only whether AI works, but who governs its use, how risk is assigned, and how resilience is maintained across the business. The practical conclusion is that AI security leadership now belongs inside enterprise governance, not beside it.
Responsible AI adoption depends on identity control across the AI operating model. As organisations embed AI into critical business functions, the relevant security question becomes who can act, connect, or persist through those systems. That brings IAM, PAM, and NHI governance into the same decision path as AI oversight. The practical conclusion is that AI programmes without identity discipline will struggle to maintain trustworthy operations.
The most durable AI security programmes will be measured by resilience, compliance, and trust outcomes. The article repeatedly ties leadership to the ability to support secure adoption at scale, which is a stronger standard than tool deployment alone. This is where governance, operational integrity, and risk management converge. The practical conclusion is that AI security maturity should be judged by whether the programme can sustain safe use under real business pressure.
HiddenLayer’s framing of AI protection reinforces a lifecycle view of AI risk. The article points to discovery, supply chain security, attack simulation, and runtime protection as part of one security story. That is a useful signal for the market because it shows AI security moving toward end-to-end governance rather than point controls. The practical conclusion is that practitioners should plan for continuous oversight across the AI lifecycle, not discrete checkpoints.
Named concept: AI security leadership convergence. This article illustrates the convergence of governance, risk management, identity control, and operational resilience around AI adoption. In practice, the organisations that treat AI security as an enterprise leadership function will be better positioned than those that isolate it inside a specialist team. The practical conclusion is that AI security strategy should be built as a cross-functional operating model.
What this signals
AI security is moving into the same governance tier as identity and resilience because enterprises now need accountable control over who can shape, connect, and persist through AI systems. The practical shift for security leaders is to treat AI oversight as a standing operating model, not a project phase.
AI security leadership convergence: the market is increasingly rewarding programmes that connect governance, risk, identity, and lifecycle oversight into one control model. Teams that still separate AI from IAM or PAM will keep finding gaps at the boundary where real business use begins.
For practitioners
- Define AI security ownership across governance and identity teams Assign clear accountability for AI risk decisions, access governance, and operational oversight across the teams that already manage security and identity. Keep the mandate broad enough to cover AI adoption, trust, and resilience, not just model review.
- Map AI access paths into existing IAM and PAM controls Review which users, services, and integrations can configure, query, or extend AI systems in production. Treat those access paths as part of your current IAM and PAM scope rather than as a separate AI exception.
- Review AI lifecycle checkpoints for governance coverage Check whether discovery, supply chain assurance, deployment approval, and runtime monitoring are all covered by a single programme view. Close any gap where AI systems move from pilot to production without continuing security oversight.
- Measure AI security maturity by operational resilience Use incident readiness, policy enforcement, and accountable oversight as the indicators of maturity. If the programme cannot sustain safe AI use under business pressure, the governance model is incomplete.
Key takeaways
- The article signals that AI security leadership is now judged by governance, risk management, and operational resilience, not by technical novelty alone.
- For practitioners, the important control question is who can access, shape, or persist through AI systems as they move into production.
- AI security programmes are strongest when they connect identity, lifecycle oversight, and enterprise accountability rather than treating AI as a separate silo.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack surface, NIST AI RMF and NIST CSF 2.0 set the technical controls, and ISO/IEC 42001:2023 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 42001:2023 | 4.1 — Understanding the Organisation and Its Context | The article centres on governance and accountability for AI adoption. |
| Recommendation — Build AI security ownership into your management system and assign clear accountability for risk and oversight. | ||
| NIST AI RMF | GOVERN — AI Governance and Accountability | The story frames AI security leadership as a governance and risk-management discipline. |
| Recommendation — Define AI governance roles that cover accountability, oversight, and enterprise risk decisions. | ||
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | The article’s AI security framing depends on controlling who can act through AI systems. |
| Recommendation — Review agent access paths for privilege abuse and align them with identity controls. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | The piece is about security leadership and risk management at the programme level. |
| Recommendation — Integrate AI security into your enterprise risk strategy and assign ownership across functions. | ||
Key terms
- API Security Governance: API security governance is the set of policies, controls, and oversight used to keep application programming interfaces safe and accountable. It defines who can create, expose, use, monitor, and retire APIs, then enforces authentication, authorization, logging, rate limits, schema validation, and lifecycle review across internal and external integrations.
- Identity And Privilege Abuse: Identity and privilege abuse happens when delegated authority, cached credentials, or inherited access lets an agent act beyond the intent of the original owner. In agentic systems, the problem is often ambiguity in who owns the action and whether the granted authority still matches the task.
- AI Lifecycle: The AI lifecycle is the end-to-end path from problem framing to retirement. It covers the decisions that shape a system’s purpose, data, behaviour, deployment, oversight, and decommissioning. In practice, it is the governance map that shows where risk enters and where accountability must stay active.
- Operational Resilience: Operational resilience is the ability to keep critical services running or recover them quickly after disruption. In identity-led environments, that depends on authentication services, privilege management, and recovery procedures that can be tested under realistic failure conditions.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org