• Home
  • Blog
  • Taking Control of AI: Key Takeaways from CyberOne's AI Governance Webinar
Blog Banners
Taking Control of AI Key Takeaways from CyberOnes AI Governance Webinar
7:11

Artificial intelligence is now part of daily business operations. It speeds up research, streamlines documentation, automates routine tasks and lifts productivity across every department.

But as AI delivers these benefits, a new challenge is emerging. Many organisations are finding that users are adopting AI tools faster than security teams can respond. The more important question now is how to keep control as adoption accelerates.

This was the focus of CyberOne's recent webinar, Taking Control of AI & The Tools Nobody Approved. Nick Wren, Head of Technical Pre-Sales and Stuart Mann, Microsoft Security Specialist, discussed the realities of Shadow AI, the risks of uncontrolled adoption and the practical steps organisations can take to regain visibility and control.

The discussion reflected the concerns raised by webinar attendees themselves. In a live poll, participants identified protecting sensitive data, maintaining compliance and gaining visibility into AI usage as their most pressing AI governance challenges. The results highlighted a clear trend: while AI adoption continues to accelerate, organisations are becoming increasingly focused on the controls, oversight and accountability needed to support it securely at scale.

What is your biggest AI governance challenge

AI Is Delivering Value. That's Exactly Why It Needs Governance

A key message from the session was clear: AI is not a future issue. It is already part of daily operations, often through productivity tools and workflows that employees adopt before governance frameworks are in place.

For security and IT leaders, this creates a clear challenge. The business case for AI is strong, but many organisations are still building the controls needed to manage risk. The focus has shifted from whether to adopt AI to how to enable its benefits while maintaining oversight, compliance and security.

According to Nick Wren, this disconnect between adoption and governance is becoming one of the defining security challenges facing organisations today:

"AI is here to stay, and for good reason. It's saving us time, we're more efficient, the quality of the work is getting better, and we have more time to focus on what really matters. These are all reasons why users and business leaders love it. The challenge is that we're adopting AI at a pace of knots, but the security tools aren't quite keeping up."

 

Every department is finding ways to work smarter, automate tasks and improve productivity. Without a clear governance strategy, these gains can create blind spots that quickly become security risks.

The Rise of Shadow AI

Shadow IT is not a new concept, but AI brings a new layer of complexity to this. Employees can now deploy AI assistants, connect third-party tools, install browser extensions or build automated workflows with little input from security or governance teams. Often, these deployments start with good intentions like solving problems, reducing workload or improving productivity.

everyone likes to share a quick way to get something done

But what begins as a personal productivity tool can quickly become embedded in business processes.

Many organisations assume governance failures are deliberate, but most users simply choose the tools that help them work faster and more efficiently. Sustainable innovation relies on a framework that delivers visibility, accountability and control.

"People are very similar to water. They'll find the easiest path to get their job done, not necessarily the path you would want or expect. That's why governance is important. We need to understand who owns these services, who can use them, how they're being used and what controls we need to put in place."
— Stuart Mann, Senior Microsoft 365 Security Specialist

 

This reflects what many organisations already see. Employees rarely adopt AI with bad intent, but governance strategies need to move beyond restrictive policies and focus on enabling safe, productive use.

Understanding the Hidden Journey of AI Data

Later in the webinar, AI governance was determined to be a data governance challenge. While many users see AI as just a conversational tool, security teams need to understand what happens to information once it is shared with a model. Data residency, third-party processing, retention and compliance all become more complex as business information moves between platforms and services.

This is often where organisations find the gap between perceived and actual risk. A simple document upload may seem harmless, but security teams need to know where that information goes, who can access it and what controls remain once it leaves the organisation.

To illustrate this, Nick Wren walked attendees through the hidden journey data can take once it enters an AI platform:

"When someone drops a document into an AI tool, that's the first step in the data lifecycle. It starts with prompts, files, images and audio, which sounds harmless, but it could be pricing spreadsheets, draft contracts or customer emails. The moment that data is pasted in, it's effectively left the environment. From there, it can go to the model, plugins and third-party tools, so it isn't just one destination, it can be many others."

 

This marks a shift in how organisations need to approach security. Organisations need to know what information is being shared, which services process it, where it is stored and how it is protected. For businesses handling sensitive data or regulated information, these are now board-level concerns.

AI Accelerates Productivity and Risk

AI speeds up many processes. Tasks that once took hours now take minutes. Information is summarised faster, documentation is generated more efficiently and decision-making is supported at new speed.

why is ai accelerating risks

But acceleration applies to risk as much as productivity. As AI tools become more capable, organisations receive information and recommendations at a pace that was impossible just a few years ago. This creates new opportunities, but also the risk of overreliance.

Moving from Shadow AI to Strategy

While the webinar highlighted significant risks, the overall message was optimistic and forward-looking. Nick Wren and Stuart Mann emphasised that with the right strategies, organisations can turn the challenges of AI adoption into opportunities for growth and innovation.

Leading organisations are taking proactive steps to gain full visibility into their AI ecosystems, map data flows and assign clear ownership and accountability for AI-driven processes. Implementing practical governance controls ensures that innovation is supported, risks are managed and compliance requirements are met. This lays the foundation for both immediate value and long-term resilience.

"AI is accelerating risk. Complex tasks are now done really, really quickly. Where before I might have searched for something and read 10, 15 or 20 different sources, I can now ask a chatbot and get an answer instantly. That's fantastic from a productivity perspective, but if you're just believing it because it's in front of you, that becomes a problem."
— Stuart Mann, Senior Microsoft 365 Security Specialist

 

The webinar outlined a maturity model for AI governance, starting with discovery: identifying where and how AI is being used across the organisation. As AI becomes further embedded in daily operations, developing these capabilities will be essential for organisations seeking sustainable, secure and scalable growth.

Continue the Conversation with CyberOne's Webinar Series

Cyber security challenges continue to evolve. Whether the issue is AI governance, data security, identity management or new threats, organisations must maintain resilience and compliance as technology changes.

If Shadow AI and governance are priorities for your organisation, CyberOne’s next webinar, Beyond Patch Tuesday: Closing the Vulnerability Window, continues the conversation from a new angle. The session will cover how to reduce vulnerability exposure, improve patching and strengthen security posture as threats evolve.

For security leaders, IT teams and business decision-makers, these sessions are a chance to stay ahead of trends, learn from experienced practitioners and understand the challenges shaping the future of cyber security.

Register for Beyond Patch Tuesday: Closing the Vulnerability Window and join CyberOne's security specialists for another practical discussion designed to help organisations move from risk to resilience.

Watch The Taking Control of AI & The Tools Nobody Approved Webinar

Whether you're beginning your AI governance journey or looking to strengthen existing controls, this webinar provides practical insights into the realities of Shadow AI, data governance and secure AI adoption. Hear directly from Nick Wren and Stuart Mann as they explore the challenges organisations face and the strategies needed to move from reactive control to proactive governance.

Missed the live session? Watch the webinar on demand here.

Share this post

Related Articles