Governance Failed Before Technology Did
Why AI Security Is Primarily a Governance Challenge—Not a Technology Problem
Series: Beyond the Breach Report — Part 3
By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.
Whenever a major cyber incident involving artificial intelligence becomes public, the discussion usually follows a familiar pattern.
Was the model vulnerable?
Was prompt injection possible?
Was training data poisoned?
Was the algorithm secure?
These are reasonable questions.
But they are rarely the most important ones.
The IBM Cost of a Data Breach Report 2026 reveals a striking observation: among organizations that suffered AI-related security incidents, the overwhelming majority lacked appropriate AI access controls. The report also concludes that many AI incidents originated not from failures of the models themselves, but from weaknesses in surrounding applications, APIs, cloud environments and governance.
That finding fundamentally changes the discussion.
The primary problem is not artificial intelligence.
The primary problem is governance.
Technology Rarely Operates Alone
Artificial intelligence does not exist in isolation.
Every AI system depends on an ecosystem.
Identity providers.
Cloud platforms.
APIs.
Data pipelines.
Business applications.
Development environments.
Third-party services.
Secrets.
Certificates.
Human decisions.
When an AI-related breach occurs, the compromise frequently originates somewhere within this ecosystem rather than inside the model itself.
The model simply becomes part of a much larger attack surface.
Technology reflects the quality of the organization that deploys it.
AI Governance Is Not an AI Problem
Many organizations have responded to AI by creating separate AI governance initiatives.
Dedicated committees.
Separate policies.
Independent approval processes.
Specialized documentation.
While well intended, this approach often creates another governance silo.
Artificial intelligence should not sit beside enterprise governance.
It should become part of it.
Every established governance discipline already applies.
Risk management.
Information security.
Architecture.
Data protection.
Supplier management.
Business continuity.
Software development.
Internal audit.
Artificial intelligence changes the context.
It does not replace governance.
Identity Is Governance in Practice
One statistic deserves particular attention.
Organizations experiencing AI-related breaches overwhelmingly lacked adequate access controls.
That is remarkable.
Identity and access management has been a core security discipline for decades.
Yet many organizations deploying AI failed to apply the same principles they already understand elsewhere.
Questions every CISO should ask include:
Who may deploy AI models?
Who approves AI agents?
Who may connect external APIs?
Who may expose business data?
Who owns AI-generated content?
Who reviews permissions?
Who revokes access?
These are governance questions long before they become technical controls.
The Myth of the Dangerous Model
Public debate often portrays foundation models themselves as the primary risk.
Reality is more nuanced.
The IBM report identifies several common causes of AI-related breaches:
- compromised connected applications,
- insecure APIs,
- cloud misconfigurations,
- inadequate access controls,
- prompt injection,
- model inversion.
Cost of a Data Breach Report 2026.pdf
Notice what most of these have in common.
They are architectural weaknesses.
Not failures of artificial intelligence.
Organizations frequently expose AI systems through poorly governed environments.
Attackers exploit governance.
The model merely happens to be present.
Governance Determines Organizational Speed
Artificial intelligence accelerates operational decisions.
Governance often slows them.
This creates a paradox.
Organizations adopt AI to improve agility.
Yet fragmented approval processes delay secure deployment.
Security reviews occur late.
Architecture decisions remain inconsistent.
Ownership becomes unclear.
Shadow AI emerges because governance cannot keep pace with business demand.
The result is predictable.
Technology advances faster than organizational control.
Shadow AI Is a Governance Failure
One of the report’s most concerning findings is the dramatic increase in security incidents involving unauthorized AI usage.
Many organizations interpret Shadow AI as an employee behavior problem.
It is not.
Employees adopt unapproved AI because approved alternatives are unavailable, difficult to access or poorly aligned with business needs.
Shadow AI reflects unmet organizational demand.
Prohibition rarely solves it.
Effective governance provides secure alternatives.
Successful organizations ask:
Why are employees bypassing official platforms?
The answer often reveals governance deficiencies rather than disciplinary issues.
AI Governance Must Become Part of the ISMS
For many organizations, AI governance remains disconnected from the Information Security Management System.
Separate policies.
Separate inventories.
Separate risk registers.
Separate committees.
That fragmentation increases complexity.
Artificial intelligence should instead become another managed information-processing capability within the ISMS.
Risk assessments.
Asset inventories.
Supplier evaluations.
Security controls.
Incident management.
Business continuity.
Audit.
Management review.
None of these processes need to be reinvented.
They need to be extended.
Good governance scales.
Boards Must Govern AI as Enterprise Risk
Artificial intelligence is frequently delegated to innovation teams or technology departments.
That governance model is becoming increasingly inadequate.
AI now influences:
business decisions,
customer interactions,
financial processes,
software development,
knowledge management,
critical operations.
These are enterprise risks.
Boards therefore require visibility beyond technical implementation.
Questions should include:
- Which critical processes depend on AI?
- Which decisions remain under human accountability?
- Which AI services process sensitive information?
- Which suppliers operate critical AI capabilities?
- Which controls validate AI outputs?
- Which incidents would require executive escalation?
These are governance responsibilities.
Not technology choices.
The Role of the Modern CISO
The CISO is uniquely positioned between technology and executive leadership.
That position becomes increasingly important in AI governance.
Not because the CISO owns artificial intelligence.
But because the CISO understands:
risk,
control,
identity,
governance,
resilience,
accountability.
The CISO should not become the organization’s “Head of AI.”
The CISO should become one of its principal architects of trustworthy AI governance.
That distinction matters.
Ownership belongs to the business.
Governance belongs to leadership.
Security enables both.
Looking Beyond Compliance
Many organizations will inevitably respond with additional policies.
More documentation.
More approval forms.
More governance boards.
That would repeat an old mistake.
Effective governance is not measured by paperwork.
It is measured by whether secure decisions happen consistently, quickly and transparently.
Artificial intelligence requires governance that accelerates business safely.
Not governance that delays it.
Final Thought
Cybersecurity has always been influenced by technology.
But history repeatedly demonstrates that major incidents rarely originate from technology alone.
They emerge where governance breaks down.
Artificial intelligence does not change this principle.
It magnifies it.
Organizations that govern AI well will not necessarily deploy less AI.
They will deploy it with greater confidence, clearer accountability and significantly lower risk.
The future of AI security will not be determined by better models.
It will be determined by better governance.
Publication Note & Disclaimer
This article provides security and governance analysis, not legal advice. Regulatory obligations must be assessed against the facts, jurisdictions, data types, and roles of the organizations involved.
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.
For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.
Member discussion