Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI risk governance: what boards and CISOs need to answer


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19785
Topic starter  

TL;DR: Boards are asking the right questions about AI risk, but the failure mode is solutioneering, or jumping to a fix before defining the problem, according to Expel. The article splits the issue into three domains: attackers using AI, employees using AI without review, and attacks against AI systems, while stressing that defensible answers need live controls, telemetry, and a named framework.

NHIMG editorial — based on content published by Expel: board questions on AI risk, solutioneering, and defensible answers

Questions worth separating out

Q: What should security teams do first when they cannot answer AI risk questions confidently?

A: Start by separating the problem into attacker use of AI, employee use of AI, and risk inside AI systems themselves.

Q: Why do AI systems create identity risk as well as model risk?

A: Because AI systems rarely act alone.

Q: How can security teams tell whether their controls are coping with AI-orchestrated intrusion?

A: Look for whether monitoring can detect repeated validation attempts, credential reuse, and fast pivoting between systems before data access occurs.

Practitioner guidance

  • Separate AI risk into three control workstreams Create distinct workstreams for attacker use of AI, employee AI use, and AI system abuse.
  • Inventory sanctioned and unsanctioned AI tools through identity telemetry Use SSO logs, network telemetry, and application logs to identify which AI tools people are actually using, including AI features embedded in approved platforms.
  • Classify AI agents as privileged identities Document every agent that can call tools, read data, or write to systems, then record the identity under which it operates, the permissions it holds, and how quickly those permissions can be revoked when behaviour changes.

What's in the full article

Expel's full article covers the operational detail this post intentionally leaves for the source:

  • How the team structures board answers around the three AI risk domains and the five recurring questions
  • Examples of how to turn SSO and network telemetry into a defensible view of sanctioned and unsanctioned AI use
  • The practical difference between monitoring traditional security events and monitoring AI-specific behaviours such as prompt manipulation
  • How Expel frames live AI detections and framework mapping inside an existing MDR relationship

👉 Read Expel's analysis of board questions on AI risk and solutioneering →

AI risk governance: what boards and CISOs need to answer?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19376
 

Solutioneering is the real governance failure in AI risk conversations. Security teams lose credibility when they answer exposure questions with a product category instead of a control state. The board needs to hear what is known, what is unknown, and who owns the gap. That discipline matters in IAM and NHI programmes because AI questions almost always intersect with identity grants, telemetry, and delegated access. The practical conclusion is simple: define the problem before buying the answer.

A question worth separating out:

Q: What does a good board-level AI security answer need to include?

A: A strong answer names the current exposure, the controls already running, the gap being closed, and who owns the next step. It should not sound like a purchase request. Boards respond better to evidence, accountability, and a named framework than to a roadmap with no operational proof.

👉 Read our full editorial: AI risk boards are asking the wrong question first



   
ReplyQuote
Share: