Securing AI: How to Manage AI Risk Without Slowing Innovation

November 12, 2025

Cheri Hotman, Managing Partner of Hotman Group, and Ranbir B. discuss how organizations can secure AI without treating security as a reason to avoid innovation. The challenge is not simply deciding whether employees can use AI. Organizations need to understand where AI is already being used, what data is exposed, how third parties handle that data, what risks the technology introduces, and what governance is needed to use AI responsibly.

Watch the Session

Watch Cheri and Ranbir discuss AI security, data exposure, shadow AI, third-party risk, prompt misuse, human oversight, employee training, continuous monitoring, and how cybersecurity leaders can balance AI risk with business value.

The Short Answer

Securing AI does not require inventing an entirely new cybersecurity discipline. Organizations already have many of the necessary building blocks: governance, risk assessment, data classification, third-party risk management, access control, monitoring, security awareness, incident response, and accountability.

What changes is the technology, the speed of adoption, the volume of information employees may provide to AI systems, and the new ways AI can create or amplify risk.

The goal is not to say no to AI. It is to understand how the organization wants to use it, identify what could go wrong, establish practical boundaries, monitor what matters, and allow people to use AI in ways that create value without exposing the business unnecessarily.

Key Takeaways

  • AI governance is still governance. Existing cybersecurity, risk, data, vendor, and governance practices should be extended to AI rather than replaced by a disconnected AI compliance program.
  • AI is already inside many organizations. Employees may be using tools before security or leadership realizes it, creating a new form of shadow technology.
  • Prompts can contain sensitive data. Organizations need rules for what information may be entered into AI systems and what should remain outside them.
  • Third-party risk matters. Organizations need to understand how AI providers store, process, retain, protect, and potentially use organizational data.
  • Policies alone are not enough. Employees need approved tools, usable guidance, training, technical controls, monitoring, and clear escalation paths.
  • AI output still requires judgment. Hallucinations, incomplete results, and overreliance create risk when users assume AI output is automatically accurate.
  • Security cannot move too slowly. If the approved path is impractical or unavailable, employees may find their own path.
  • AI risk should be communicated in business language. Leadership needs to understand the potential impact on data, customers, operations, cost, trust, and business objectives.

Why Is Securing AI Different From Simply Blocking It?

AI can create meaningful business value. It can help people research, draft, analyze, learn, automate repetitive work, and complete certain tasks more efficiently.

That makes a blanket prohibition difficult to sustain. Employees who see legitimate value in the technology may look for their own tools when the organization does not provide a usable alternative.

Security therefore has to operate inside the tension between risk and reward. The role of cybersecurity is not simply to stop adoption. It is to help the business understand the risk and establish conditions under which AI can be used responsibly.

Is AI Governance Really a New Type of Governance?

The technology is evolving rapidly, but many of the governance questions are familiar.

What technology are we using? Who owns it? What information can it access? What data can employees provide? Which third parties are involved? What actions can the system take? Who reviews those actions? What happens when something goes wrong?

“AI governance is governance.”

— Cheri Hotman

Organizations can use established cybersecurity and GRC capabilities as the foundation rather than building another isolated compliance function. Learn more about integrating AI governance without creating another compliance silo.

What Is Shadow AI?

Organizations have dealt with shadow IT for years: employees adopt technology outside the normal procurement, security, or IT process because it solves an immediate problem.

AI creates a similar challenge.

Employees can access a growing number of AI tools directly through a browser, application, productivity suite, or embedded feature. In many cases, leadership may not realize how extensively those tools are already being used.

That means the first AI governance question may not be, “Should we adopt AI?” It may be, “Where are we already using AI, and what is happening there?”

Why Are AI Prompts a Data Security Issue?

People interact differently with AI than they do with a traditional search engine.

A search query may contain a few words. An AI prompt may contain paragraphs of context, internal documents, contracts, customer information, source code, screenshots, financial information, personal information, or detailed descriptions of internal problems.

That makes data classification an important part of AI security.

Organizations should clearly define which categories of information employees may provide to approved AI systems, which require additional approval, and which should never be entered into an external AI service.

What Should Organizations Ask AI Vendors About Their Data?

AI procurement should include the same disciplined third-party risk questions organizations ask about other technologies that handle sensitive information.

Relevant questions include:

  • What information will the AI provider receive?
  • Where is organizational data stored and processed?
  • How long is the data retained?
  • Who can access it?
  • What security controls protect it?
  • Are subcontractors or additional service providers involved?
  • How is customer information separated from other customers?
  • What happens to data when the relationship ends?
  • What contractual commitments actually apply?
  • How does the organization verify that the provider's practices align with those commitments?

Should Organizations Build AI or Buy an AI Platform?

There is no universal answer.

Buying a third-party platform can provide speed, functionality, and lower implementation effort. Building or hosting more of the capability internally may provide additional control over architecture, data, integrations, and access.

Neither option is automatically secure.

The decision should be based on the organization's requirements, data sensitivity, risk tolerance, technical capability, cost, desired use cases, vendor risk, security architecture, and ability to operate and maintain the solution over time.

How Can Organizations Let Employees Use AI Without Losing Control?

Governance works better when employees have a practical approved path.

If employees are simply told not to use AI while the technology would materially help them perform their jobs, organizations may unintentionally encourage unsanctioned use.

A workable approach can combine:

  • Approved AI tools and defined use cases.
  • Clear rules for sensitive data.
  • Role-based access where appropriate.
  • Employee education and ongoing coaching.
  • Technical controls that support the policy.
  • Monitoring based on meaningful risk.
  • Defined escalation when inappropriate activity occurs.
  • Periodic review as tools and business needs change.

Why Isn't an AI Policy Enough?

A policy can establish expectations, but it does not prove those expectations are understood or operating.

Employees need to know what the rules mean in practice. They need usable tools. Managers need to understand their responsibilities. Security needs visibility. Exceptions need a process. Violations need an escalation path.

That is the difference between documenting AI governance and actually operationalizing it.

What Does Monitoring AI Use Actually Mean?

Collecting logs is not the same thing as monitoring.

Monitoring requires an organization to decide what activity matters, establish thresholds or conditions that deserve attention, review the relevant information, and take action when those conditions occur.

“Logs are not monitoring.”

— Cheri Hotman

The organization's risk assessment should help determine what needs to be monitored and what response is appropriate when AI use moves outside approved boundaries.

What Are Prompt Injection and AI Model Misuse?

AI systems can be influenced through the information and instructions they receive.

Prompt injection and related misuse can attempt to manipulate a system into behaving outside its intended rules, revealing information, ignoring restrictions, or performing actions that were not intended by the organization.

That risk becomes more significant when AI is connected to sensitive data, internal systems, applications, identities, tools, or actions. Security therefore needs to consider not only what the model can answer, but what the surrounding AI-enabled system can access and do.

Why Are Hallucinations and Overreliance Security Risks?

AI can produce useful work while still producing inaccurate, incomplete, or misleading output.

The risk increases when users stop validating the result because the tool appears confident, fast, or sophisticated.

The more capable an AI system appears, the more important it becomes to define where human judgment and quality assurance still belong.

Human oversight should be proportional to the consequence of the decision or action. Drafting internal notes is different from approving financial activity, changing production systems, making employment decisions, or taking other consequential actions.

Why Can't Organizations Wait for AI Regulation?

Technology can change much faster than formal requirements.

That means organizations cannot rely on future regulation to define every appropriate security and governance decision.

A risk-based program gives the organization a mechanism to make decisions now: understand the technology, identify the assets and data involved, evaluate credible risks, determine appropriate safeguards, assign ownership, monitor the environment, and adjust as conditions change.

How Should CISOs Explain AI Risk to the Business?

Security leaders need to understand the business they are protecting.

Technical vulnerabilities and security terminology matter, but executive leaders ultimately need to understand what those issues mean for customers, revenue, operations, intellectual property, data, legal obligations, reputation, and strategic objectives.

The same principle applies to AI.

Instead of simply saying an AI tool is risky, explain the business scenario, what could happen, how significant the impact could be, which safeguards are available, what residual risk would remain, and how the proposed approach supports the organization's objective. That is the same risk-based language explored in cybersecurity risk assessment for leadership.

What Are Signs an Organization's AI Security Program Is Falling Behind?

  • Leadership cannot identify which AI tools employees are using.
  • Employees are using personal or unapproved AI accounts for business work.
  • There is no clear guidance about what data can be entered into AI systems.
  • AI vendors are adopted without meaningful security or third-party risk review.
  • The organization has an AI policy but little training, monitoring, or enforcement.
  • AI functionality is being added to existing software without reassessing risk.
  • Teams rely heavily on AI-generated output without defined quality assurance.
  • Security becomes involved only after AI tools are already widely deployed.
  • Logs exist, but nobody has defined what should actually be monitored.
  • The organization is waiting for regulation or an audit requirement before addressing AI risk.

What Should Organizations Do Now?

  1. Inventory AI use. Identify approved tools, embedded AI features, business use cases, and unsanctioned activity already occurring.
  2. Classify the data involved. Define what information can and cannot be shared with AI systems.
  3. Assess AI risk. Evaluate how each use case could affect confidentiality, integrity, availability, privacy, customers, operations, and business objectives.
  4. Evaluate third parties. Understand where data goes, how it is protected, who has access, how long it is retained, and what contractual protections apply.
  5. Provide an approved path. Give employees practical AI options instead of relying only on prohibition.
  6. Establish clear governance. Define ownership, acceptable use, approval, exceptions, accountability, and escalation.
  7. Train people continuously. AI threats and capabilities are changing, so awareness cannot be a one-time acknowledgment.
  8. Monitor meaningful activity. Determine what behaviors or events require review and what action follows.
  9. Keep humans in the decision process where consequences matter. Validate AI output instead of assuming confidence equals accuracy.
  10. Review and improve continuously. Reassess tools, risks, use cases, vendors, controls, and employee behavior as AI and the business evolve.

Frequently Asked Questions

What Does Securing AI Mean?

Securing AI means managing the cybersecurity and business risks associated with AI systems, including data exposure, access, third-party risk, inappropriate use, model behavior, human oversight, monitoring, and the actions AI-enabled systems can perform.

What Is Shadow AI?

Shadow AI is the use of AI tools or capabilities outside the organization's approved technology and governance processes. It may occur when employees use consumer AI tools or embedded AI features without security, IT, or leadership visibility.

What Data Should Employees Avoid Putting Into AI?

The answer depends on the organization's approved tools and data-handling rules, but organizations should establish explicit guidance for confidential business information, personal information, customer data, intellectual property, credentials, contracts, regulated information, and other sensitive data.

Is an AI Acceptable Use Policy Enough?

No. Policy should be supported by approved technology, employee training, technical safeguards, monitoring, accountability, third-party risk management, and a process for handling exceptions and changing business needs.

What Is Prompt Injection?

Prompt injection is an attempt to influence an AI system through instructions or input that cause it to behave outside its intended rules. The potential impact depends on what information, tools, systems, and actions the AI application can access.

Why Is Human Oversight Important With AI?

AI can produce incorrect or incomplete results. Human oversight provides context, validation, quality assurance, and accountability, particularly when AI output influences consequential business actions or decisions.

Should Organizations Block AI Until Regulations Catch Up?

Organizations do not need to wait for regulation to manage AI risk. Existing cybersecurity, risk management, data governance, third-party risk, access control, monitoring, and governance practices can be adapted to AI use now.

About This Session

This article is based on a Hotman Group live session featuring Cheri Hotman, Managing Partner of Hotman Group, and Ranbir B. exploring the security and governance challenges created by rapidly expanding AI adoption.

The discussion examines how organizations can balance AI's potential business value with data security, third-party risk, employee use, shadow AI, prompt-related risks, human oversight, monitoring, security awareness, and evolving cyber threats.

Rather than treating AI security as an entirely new discipline, Cheri and Ranbir explore how organizations can apply established cybersecurity, risk management, governance, and GRC practices to an increasingly powerful and accessible technology.

When to Bring in Hotman Group

Organizations often need additional support when AI adoption is moving faster than the cybersecurity and governance structures around it. Hotman Group can help when:

  • Employees are already using AI, but leadership does not have a reliable inventory of tools or use cases.
  • The organization needs practical rules for what data may be shared with AI systems.
  • AI vendors or embedded AI capabilities are being adopted without consistent third-party risk review.
  • An AI policy exists but is disconnected from security architecture, identity, data governance, monitoring, employee training, or operating processes.
  • Security leaders are struggling to balance business pressure for faster AI adoption with legitimate cybersecurity and privacy concerns.
  • The organization needs clearer ownership, oversight, monitoring, escalation, and human review for consequential AI use cases.

Hotman Group helps organizations integrate practical AI governance into existing cybersecurity, risk, technology, third-party risk and governance programs instead of creating another disconnected compliance silo.

Talk with Hotman Group about securing AI in your organization

About Hotman Group

Hotman Group is a cybersecurity and Cyber GRC professional-services firm that helps organizations diagnose, design, build, remediate, implement, operate and mature cybersecurity programs. HG provides hands-on vCISO and vGRC leadership, supports multi-framework environments, and helps organizations select and implement GRC technology while connecting cybersecurity decisions to business risk and strategy.

Hotman Group helps organizations address AI risk as part of the broader cybersecurity program by connecting governance, risk assessment, data protection, third-party risk, identity, monitoring, policy, employee awareness, and technology decisions.

The objective is not to create another compliance exercise around AI. It is to give organizations practical ways to use emerging technology while maintaining appropriate oversight, accountability, and protection.

Talk With Hotman Group