All Events and Webinars

How Organisations Can Adopt AI Without Creating Unnecessary Risk

Cross Industry
NIS2
AI and Emerging Technology
Data Security and Privacy
July 15, 2026
In this discussion, Aaron Smith explores how organisations can adopt AI without creating unnecessary risk. He covers where organisations are most exposed as employees begin using AI tools, how security and compliance teams should prepare for wider adoption, and the controls needed to protect sensitive data while enabling innovation. Aaron also discusses the role of AI governance, Data Loss Prevention (DLP), user behaviour, access controls, and the key questions every CISO should be asking as AI becomes embedded across the business.

In-House Specialists

Aaron Smith

Information Security Lead

Rajkumar Rajamohan

Data Security Analyst

External Speakers

No external speakers for this session.

Key Strategic Takeaways

What is AI governance and why does it matter now?

AI governance is the set of policies, controls, and ownership structures that define how AI is used within an organisation. It matters now because AI adoption has already happened in most workplaces, often without formal approval. Employees are using tools like ChatGPT and Copilot daily to meet deadlines, paste source code, and summarise meetings. The governance gap is not about whether AI is being used; it is about whether the organisation has any visibility or control over how data flows through it.

What are the biggest data security risks created by AI in the workplace?

The most common risks are not malicious. Employees paste confidential source code, customer proposals, or financial data into generative AI tools simply to get work done faster. The Samsung incident, where engineers uploaded proprietary source code and meeting notes into ChatGPT, is one of the clearest examples of how quickly sensitive data can leave an organisation without any breach in the traditional sense. The data is gone before anyone realises it has moved. Unclassified data fed into AI tools is not protected, and most tools will use that data in ways the organisation has not reviewed or consented to.

What technical controls should organisations put in place to govern AI use?

Two controls stand out as high-priority starting points. Data Loss Prevention (DLP) tools can intercept sensitive data before it leaves the organisation via browser inputs or AI prompts, provided the DLP sits at the right point in the stack and covers custom applications. Cloud Access Security Brokers (CASBs) act as an intentional intermediary for all cloud traffic, applying DLP and keyword detection to outbound prompts and flagging classified documents being uploaded to external tools. Beyond these, access controls matter: not every employee needs access to every AI model, and restricting access by role reduces exposure significantly. SSL decryption for specific high-risk workflows is also worth evaluating.

Why do AI policies fail, and what makes one actually work?

Most AI policies fail because they are too long, too generic, and not written for the people who need to follow them. A 20-page policy covering every regulatory angle is not something a developer or finance analyst will read or act on. Effective AI policies are short, specific, and structured around clear dos and don'ts at the individual user level, similar in format to an acceptable use policy for company devices. Ownership is the other missing piece: if AI governance belongs to everyone in the organisation, it effectively belongs to no one. Assigning named accountability, whether to an executive sponsor or specific functional roles, is what turns a policy into something that actually gets enforced.

How should organisations deal with shadow AI?

Banning AI does not work. Employees will use personal accounts or unapproved tools to get work done regardless. The more effective approach is creating a sanctioned, safe path for AI use that removes the need to go off-piste. When employees have an approved tool with clear guidance on how to use it for their specific workflows, shadow AI use drops significantly. Most employees are not trying to create a security problem; they are trying to meet a deadline. Clear use cases, practical training, and accessible approved tooling address the root cause. For organisations outside highly controlled regulated environments, some level of shadow AI use is likely unavoidable, which makes monitoring and DLP controls even more important as a backstop.

No items found.

• 00:00 Introduction

• 00:24 Meet the Speakers

• 01:08 Why AI Governance Matters

• 02:34 AI Is Already in Every Workplace

• 03:31 Where AI Creates Data Security Risks

• 05:04 Why AI Governance Must Scale

• 06:46 Lessons from the Samsung ChatGPT Incident

• 09:00 Shadow AI & Safe Adoption

• 10:37 AI Governance Best Practices

• 13:10 Where Organizations Are Falling Behind

• 15:23 Essential Security Controls for AI

• 17:47 DLP, CASB & Access Controls Explained

• 20:01 Monitoring, Incident Response & AI Security

• 22:18 User Education vs Shadow AI

• 24:42 Key Takeaways for AI Governance

• 27:15 Final Thoughts & What's Next

Watch More
Compliance and Risk

From Risk to Resilience: Google SecOps, NIS2, and the Future of Security Operations

Smarttech247 CTO Robert Kehoe and Google Cloud Security's Aaron Thundercliffe discuss NIS2, AI-driven threats, and how modern SOC operations deliver real resilience.

Supply Chain & Third-Party Risk | Managing Hidden Cybersecurity Threats

Smarttech247 experts discuss how businesses can improve visibility, reduce third-party cyber risk, and strengthen resilience against supply chain attacks.

The New Ransomware Economics | Edwin Bowers & CrowdStrike on Modern Cyber Extortion

Smarttech247 is joined by CrowdStrike to examine how ransomware groups are evolving and what organisations need to do to improve cyber resilience and incident response.

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365