woman analysing AI dashboard

Knowledge is Power

Artificial intelligence (AI) adoption is accelerating—and so is the hype around it. For most organisations, AI is no longer optional; it is becoming a practical business capability and a competitive differentiator. But faster adoption also introduces new cyber risks that many organisations are not yet equipped to manage.

Let’s start with a few practical questions:

Who is using AI in the organisation?
Which tools or models are in use?
What are they being used for?
And what data is being shared with them?

If those questions are difficult to answer, that is exactly the challenge. Visibility is the foundation of secure AI adoption. Without it, governance, risk management, and policy enforcement quickly become reactive rather than intentional.

A few sobering statistics help to frame the issue we face:

83%

of businesses already use AI, but only 13% have strong visibility into how it is being used.

77%

of organisations have an AI strategy, but only 26% can enforce it.

1 in 5

organisations experienced a breach linked to shadow AI last year.

Source: IBM Cost of a Data Breach, 2025

AI is scaling across users, applications, and autonomous agents faster than most security architectures can adapt. The result is a widening gap across data protection, identity controls, and hybrid environments.

Because AI is discussed using a wide range of overlapping terms, it helps to distinguish the main categories by function, access model, and business purpose.

Generative AI

Generative AI

Uses foundation models to generate new content and ideas – from text and images to code and summaries.

  • Creates new content from prompts (text, images, audio, code)
  • Used for chatbots, content creation, and automated responses
  • Typically based on public or vendor models (e.g. LLMs)

Homegrown AI

Homegrown AI

Custom built AI solutions designed and trained on proprietary data to address specific business needs and workflows.

  • Built and owned internally by the organisation
  • Tailored to specific business data, processes, and needs
  • Full control over models, infrastructure, and security

Agentic AI

Agentic AI

Autonomous AI systems that plan, make decisions and take actions across tools and systems to achieve goals with minimal human intervention.

  • Autonomous agents that plan and execute multi-step tasks
  • Interact with tools, APIs, and systems without constant human input
  • Coordinate workflows and make decisions based on context

An un-managed Risk

So far, AI adoption has often been organic and unstructured, driven by employee experimentation and business demand rather than formal governance. That can accelerate innovation, but it also increases cyber risk with no clear boundaries, controls, or ownership.

AI may already be part of day-to-day operations, but in many organisations its governance and security maturity have not kept pace.

That gap creates five interconnected risk areas.

Here are the key cyber risks organisations face when AI use is not governed effectively:

number 1 icon

Data leaks:

confidential information submitted to public AI tools can be retained or extracted in ways the organisation no longer controls.

Resulting Exposure: your business competitive data is leaked out of the organisation with potential loss of competitive advantage and client trust.

Prevention: provide clear guidance to all employees on what data they can share with AI and have guardrail polices in place to prevent such actions.

number 2 icon

Adversarial manipulation:

attackers craft inputs that override an AI’s intended behaviour to leak information or trigger unauthorised actions, bypassing traditional perimeter defences.

Resulting Exposure: This can lead to data exposure, unauthorised activity, or decisions that bypass expected controls.

Prevention: opt for an internal AI platform, equipped with cybersecurity protection and set parameters to guard against unauthorised interception.

number 3 icon

Shadow AI

the unsanctioned use of generative tools, without IT visibility, creating compliance gaps and hidden data-loss channels that governance frameworks cannot audit.

Resulting Exposure: data loss and inability to protect company assets due to lack of visibility, IT integration and governance.

Mitigation: issue clear guidelines and instructions for all employees about AI usage within your organisation and categorise them in sanctioned and unsanctioned applications.

number 4 icon

Agentic overreach:

as AI agents are granted autonomy to act across business applications, they can initiate transactions or modify records with limited human oversight, amplifying both the speed and scale of potentially harmful activities.

Resulting Exposure: potentially damaging decisions are made in automatic mode, with no alignment with company strategy and targets.

Mitigation: define clear parameter for your chosen AI, ensuring key decisions affecting competitive advantage are supervised by a human stakeholder.

number 5 icon

The AI supply chain

can introduce vulnerability through dependencies on external models and third-party integration that current vendor risk programmes rarely govern.

Resulting Exposure: disruption, security gaps, and loss of control over AI systems due to reliance on models and services the organisation does not own or fully manage.

Mitigation: extend vendor risk programmes to cover AI-specific dependencies, document all external model and integration usage, and establish clear policies for evaluating and monitoring third-party AI services.

Taken together, these risks make AI security more than a technical issue. It becomes a business governance issue with implications for resilience, compliance, and trust.

AI governance should align with established compliance frameworks including NIS2, the EU AI Act, the Cyber Resilience Act (CRA), and GDPR. These frameworks set expectations for risk management, data protection, transparency, and accountability in the deployment and operation of AI systems.

Many AI-related issues can be traced back to ad hoc deployment and weak ongoing governance. If adoption outpaces understanding, organisations lose the ability to shape AI use in a controlled and secure way.

Top Tips for a Secure AI deployment

A practical checklist for building an AI adoption roadmap that is both effective and secure.

number 1 icon

Ask IT and security teams to create a clear inventory of AI use across the organisation, including approved tools, unsanctioned usage, and high-risk workflows.

number 2 icon

Establish a clear code of conduct for AI use, especially around the handling of sensitive, regulated, or proprietary data.

number 3 icon

Define which AI tools, models, and use cases are authorised—and under what conditions they may be used.

number 4 icon

Apply human oversight to agentic AI and high-impact automated decisions, particularly where customer outcomes, financial transactions, or critical systems are involved.

number 5 icon

Build technical guardrails for autonomous AI actions, with escalation paths, approval thresholds, logging, and accountability built in from the start.

Take the rudder and steer your own course

AI will play an increasingly important role in how organisations operate—from employee productivity tools and public chatbots to background automation and agentic workflows embedded in business systems. Used well, it can strengthen efficiency, innovation, and competitive advantage.

To realise those benefits safely, organisations need clear controls over how AI is used, which data it can access, and where decisions should remain under human supervision.

If your organisation is already deploying AI, now is the time to assess risk, close governance gaps, and make deliberate choices about how future AI capabilities are secured and managed before the next wave of EU AI Act obligations takes effect in August 2026.

References:

  1. The 2025 State of AI Data Security Report
  2. Indirect Prompt Injection Attacks: Hidden AI Risks
  3. ChatGPT and LLMs: what’s the risk
  4. Industry News 2025 The Rise of Shadow AI Auditing Unauthorized AI Tools in the Enterprise
  5. Educational Resources · OWASP/www-project-top-10-for-large-language-model-applications Wiki · GitHub
  6. Enterprises are racing to secure agentic AI deployments – Help Net Security
  7. Cost of a data breach 2025 | IBM
  8. Timeline for the Implementation of the EU AI Act | AI Act Service Desk
Kyriakos Siamplettos

Kyriakos Siamplettos

Pre-Sales Consultant, Infinigate UK&I