Transform AI from a security blind spot into a roadmap
The New Stack John Sapp ● Covered by 9 sources
Opinion — commentary, not a factual news event.
AI is moving into companies faster than security can see it. That leaves agents and personal tools as a bigger risk than the old chatbot hype.
Based on reporting by The New Stack, John Sapp — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
AI has already passed the stage where security teams can treat it like a future problem. The pattern is familiar: hype, then hope, then the rude surprise of production. But this time the surprise is arriving faster, because employees are already using AI while the rules and controls are still catching up.
The scale gap is the uncomfortable part. IBM says 77% of tech C-suites think AI adoption is outpacing their governance. Another 70% say business teams are moving faster than IT can track, and only 11% feel fully ready for the next year of AI-agent deployment. MIT adds another wrinkle: more than 90% of companies have employees using personal AI tools for work, while only 40% have official LLM subscriptions.
That matters because a summarizing chatbot is one thing. An agent that can touch credentials, run code, or change production systems is something else entirely. The article argues that blocking AI won’t solve that problem; people will just route around the controls with personal accounts and unsanctioned workflows. The better move is to make the approved path more useful than the shadow one.
The roadmap it lays out is fairly practical. Security teams should map use cases instead of just tools, track what data AI can reach, and tighten controls as autonomy rises. They should rely on approved inputs, keep execution isolated and least-privileged, and measure whether employees still work around the guardrails. Governance, in other words, has to move with the technology, not behind it.
KPMG’s numbers show how much work is left: nearly three-quarters of leaders cite risk, security and privacy as major AI concerns, yet only 24% embed them into strategy and technology. The article’s core point is blunt. Security can’t just sit at the approval gate anymore; it has to be built into the house from the start.
My take — AI-written commentary, not fact-checked reporting
This is the part the industry keeps pretending is optional: if AI is going to act, security has to be in the room before it gets credentials. Pretending a policy PDF is a control is the sort of optimism that keeps incident responders employed. The smarter companies will make the safe path easier than the sneaky one, because people always find the sneaky one if the safe one is a pain.
Read more about this at: The New Stack