
The first step in addressing AI risk is understanding where it is already being used across the business, and where it is most likely to affect the business. Identify which teams are relying on which tools, what data those tools access, and which AI agents are capable of taking autonomous actions. From an external perspective, it’s never been more critical to understand internet-facing services.
From there, CISOs should concentrate on the controls that reduce the greatest business risk. To hedge against actions taken by internal or client-facing tools, role-based access control and identity management should be prioritized, so an account or an agent only reaches what their job requires. Sensitive data should be classified so organizations understand what AI systems are, and aren’t, allowed to access. Prioritize continuous testing and vulnerability identification for IT infrastructure, any software or APIs being offered to clients, and any weaknesses in the software supply chains.
For organizations building software with AI, automated code review and dependency management become even more important as AI increases development speed. Faster code generation can also mean faster introduction of vulnerabilities if review processes don’t evolve alongside it.
