• rcr icon

    Accelerated Cybersecurity Training Program

    Catalyst Cyber Accelerator

    Corporate Training

    Cyber Talent Acquisition

    Mastercard Emerging Leaders Cyber Initiative

    Catalyst Fellowship Program​

Ideas

Fear Not AI. Manage It.

Artificial intelligence is moving quickly, and organizations are under pressure to move with it. New tools promise greater efficiency, faster analysis, improved customer experiences, and entirely new ways of working. At the same time, stories about data leakage, hallucinations, cyberattacks, and other AI failures can make adoption feel risky.

It is understandable, then, that much of the conversation about AI risk has centred on cybersecurity.

Cybersecurity is essential, but it cannot solve every challenge that comes with adopting AI.

An AI system can be technically secure, yet it can still be used for the wrong purpose or result in unintended consequences. It can produce inaccurate or biased outputs. Employees can place too much trust in its recommendations or actions. An organization can have strong technical controls while lacking clarity about who is accountable when an AI-supported decision goes wrong.

The question for organizations, therefore, should not simply be, “How do we secure AI?” 

But rather, “How do we manage AI well?”

Below are strategies that address this question. 

  1. Start with purpose, not the technology
  2. One of the most important decisions happens before an AI system is ever deployed: deciding what we actually want it to do.

    Organizations should clearly articulate the problem they are trying to solve, who will use the system, what information it will interact with, how its outputs will be used, and what success looks like.

    Just because AI can perform a task does not necessarily mean that it should.

    This is also where risk becomes contextual. Using generative AI to brainstorm ideas for an internal meeting is very different from using AI to influence a hiring decision, advise customers, or automate part of a cybersecurity workflow. The technology may be similar, but the consequences are not.

    That distinction should influence everything that follows: the level of scrutiny, the controls put in place, the degree of human oversight, and ultimately whether the use case should proceed at all.

  1. Responsible AI requires accountability
  2. Responsible AI can sound abstract. In practice, it begins with straightforward questions:

    • What uses of AI are acceptable within the organization?
    • What data can employees provide to an AI system?
    • How will concerns around privacy, fairness, transparency, and reliability be addressed?
    • When should an AI-generated output be reviewed by a person?
    • And critically: who is accountable?

    AI should not create an accountability vacuum.

    If an AI system supports a decision, someone still needs to be responsible for that decision. If a system behaves unexpectedly, there needs to be a clear path for escalation. If a risk is identified, someone needs the authority to decide whether the risk is acceptable, whether additional controls need to be applied, or whether the use case should not proceed.

    This is why AI governance cannot sit solely within the cybersecurity or IT team. Depending on the use case, effective governance may require participation from business leaders, cybersecurity, technology, privacy, legal, risk, procurement, and the people who actually use the system.

  1. We do not have to start from scratch
  2. The good news is that organizations do not need to invent their own approach to AI risk management.

    Recognized frameworks and standards can provide structure. The NIST AI Risk Management Framework, for example, organizes AI risk management around Govern, Map, Measure and Manage, with governance acting as a cross-cutting function. NIST also emphasizes that AI risk management should continue throughout the lifecycle rather than ending at deployment.

    ISO/IEC 42001 provides another useful reference point. It establishes requirements for an AI management system and focuses on establishing, implementing, maintaining, and continually improving how an organization manages AI.

    However, frameworks should not become a box-checking exercise. NIST itself describes its Playbook as neither a checklist nor an ordered set of steps. Their value lies in helping organizations ask better questions, establish accountability, and make consistent, risk-based decisions.

  1. Secure implementation still matters
  2. Once an organization decides that an AI use case is appropriate, cybersecurity becomes essential to implementing it safely and securely.

    At this stage, we need to look beyond the interface and consider the following:

    • What data enters the system?
    • Where does it travel?
    • What model is actually being used?
    • Does the application rely on APIs, cloud infrastructure, or other providers?
    • Who can access the data?
    • How long is it retained?
    • What permissions does the AI have?
    • What happens if a prompt is manipulated or credentials are exposed?
    • What guardrails are required?

    Third-party risk becomes particularly important because the vendor itself may depend on foundation model providers, cloud services, and other subprocessors.

    Buying an enterprise AI platform does not outsource all of the organization’s risk. We still need to understand what the vendor is responsible for, what protections it provides, and what responsibilities and risks we retain.

  1. Keep humans meaningfully involved
  2. “Human in the loop” has become a common phrase in responsible AI discussions. But simply inserting a person somewhere in a workflow does not guarantee meaningful oversight.

    We should ask what that person is actually expected to do.

    • Do they have the needed competencies to perform necessary oversight?
    • Do they understand the limitations of the AI system?
    • Do they have enough context to recognize anomalous activity or a questionable output?
    • Are they verifying information, or simply approving it?
    • Do they have the authority to reject an output or stop the process?

    Human oversight should be designed around the risk and purpose of the use case. In some high-risk or high-consequence situations, a person may need to review every AI-generated output before action occurs. In others, human-on-the-loop monitoring with clear escalation criteria may be more appropriate.

    The goal is not to put a human checkpoint everywhere, but to place human judgment where it meaningfully reduces risk.

  1. Deployment is not the finish line
  2. One of the biggest differences organizations need to recognize is how quickly AI technology can change.

    An AI assistant approved today for summarization may later gain memory, access to internal repositories, new underlying models, tool use, or the ability to take actions on behalf of a user. The product may have the same name, but its risk profile may be very different.

    This makes monitoring essential.

    Organizations need visibility into how AI is actually being used, whether it continues to perform as expected, whether controls and guardrails are effective, whether new risks are emerging, and whether the assumptions behind the original approval remain valid.

    Recognized risk-management guidance reflects this continuous approach. NIST recommends testing AI systems before deployment and regularly during operations, and its Manage function calls for ongoing monitoring and improvement as systems, contexts, and risks evolve.

    Monitoring also gives organizations the information they need to respond when something goes wrong. Incident response, escalation paths, and vendor communication should therefore be well-planned before an incident occurs—not created in the midst of one.

  1. From fear to informed decisions
  2. AI introduces real risks, and effective cybersecurity helps manage them. But focusing exclusively on cybersecurity can give organizations false confidence and an incomplete picture.

    Secure AI adoption also requires purpose, responsible use, governance, accountability, risk assessment, vendor evaluation, appropriate controls, meaningful human oversight, monitoring, and continuous reassessment.

    None of this means organizations should fear AI. Nor does it mean eliminating every possible risk before experimenting with the technology. Innovation and risk management do not have to sit on opposite sides of the table.

    The goal is to understand enough about the technology, the use case, and the organization to make informed decisions about where AI creates value, what could go wrong, what safeguards are appropriate, and what level of risk the organization is prepared to accept.

    AI will continue to evolve. Our policies, controls, and understanding must evolve with it.

    We do not need to eliminate uncertainty before using AI. Rather, we need the governance, knowledge, and processes to responsibly manage that uncertainty.

    That is how organizations can move beyond both blind adoption and unnecessary fear and toward AI adoption that is purposeful, responsible and secure.

More from the Catalyst