TL;DR: Shadow AI appeared in 20% of breaches last year and added roughly $670,000 per incident, while more than half of surveyed IT and security professionals said security teams own AI protection, according to Panther. Governance is no longer a policy exercise because inventory, oversight, monitoring, and incident response now sit inside security operations.
NHIMG editorial — based on content published by Panther: AI governance implementation, a practical guide for security teams
By the numbers:
- Shadow AI showed up in 20% of breaches studied last year, and those incidents cost roughly $670,000 more than conventional ones.
- 300 IT and security professionals surveyed identified security, dentified security teams as the primary owners of protecting AI systems.
- The EU AI Act's GPAI obligations took effect August 2, 2025, with transparency requirements arriving August 2, 2026.
Questions worth separating out
Q: How should security teams govern AI in cybersecurity operations?
A: Security teams should govern AI in cybersecurity operations as a workflow control, not just a detection feature.
Q: Why do conversational AI systems create new identity and access risks?
A: Because they can combine data retrieval, decision-making, and execution in a single interaction.
Q: What do organisations get wrong when evaluating AI SOC platforms?
A: They often confuse better alert handling with operational response.
Practitioner guidance
- Create a live AI inventory Record every AI system, its owner, data access scope, action authority, deployment date, risk tier, and last review date so shadow AI cannot hide outside governance.
- Assign approval gates to high-impact actions Require human approval for AI actions that can change detections, update security data, or trigger downstream operational workflows, and document the fallback path if review is unavailable.
- Treat AI telemetry as governed security data Keep AI logs, prompts, and decision evidence in customer-controlled storage with retention and audit access that supports investigation and reproducibility.
What's in the full article
Panther's full blog covers the operational detail this post intentionally leaves for the source:
- The inventory template and scoring model used to tier AI systems by data access, action authority, and review needs.
- The control mapping across NIST AI RMF, ISO/IEC 42001, and the EU AI Act for teams that need implementation detail.
- The step-by-step process for adding human-in-the-loop approval to SOC workflows without breaking triage operations.
- The monitoring approach for drift, model decay, and AI-specific incident response in live environments.
👉 Read Panther's practical guide to AI governance implementation for security teams →
AI governance in security teams - what controls actually matter now?
Explore further
AI governance has crossed from compliance language into security operations. The article is right to place inventory, monitoring, and response inside the security function because those are the controls that make AI governable in practice. NIST AI RMF style thinking matters here, but only if it is translated into operational ownership, approval gates, and telemetry. For practitioners, the implication is simple: if security cannot inventory and monitor an AI system, governance is already failing.
A question worth separating out:
Q: Who is accountable when an AI system makes a harmful decision?
A: Accountability should follow the identity chain that authorized, configured, or triggered the action, including the human owner, the platform team, and any delegated agent or tool account. If the organisation cannot name that chain, the governance model is too weak for regulated AI use.
👉 Read our full editorial: AI governance implementation is now a security operations problem