CultureAI
All blog posts
AI Risk

AI Adoption Is Outpacing Governance: Conversations on Managing AI Risk

Ria ManzaneroHead of Marketing
PublishedRead time5 min readShare

In brief

  • Senior leaders at a TEISS roundtable agreed that AI rollout has overtaken policy, governance and technical oversight in most organisations.
  • Visibility is the missing layer: firms need to know how AI is used and by whom, not just which tools are approved.
  • Traditional awareness training cannot close the gap on its own; intervening at the moment of risk turns risky actions into teachable moments.
  • Secure AI adoption means making every use of AI measurable, compliant and human-friendly rather than blocking innovation.

Insights from a CultureAI + TEISS roundtable on the realities of AI risk.

Executives everywhere are under pressure to deploy AI fast, but our recent roundtable on AI risk, hosted by TEISS, revealed a growing concern: AI adoption is outpacing governance, and organisations are taking on more risk than they realise.

While most enterprises have mature technical controls, many are missing visibility into how AI is being used, and by whom. Employees are integrating unsanctioned tools, experimenting with automation, and feeding sensitive data into SaaS faster than governance frameworks can adapt.

“With the rise of AI tools, the human layer of security is becoming harder to manage than ever.”

The TEISS Breakfast Briefing at London’s Goring Hotel brought together senior leaders from finance, legal, professional services, and tech to explore a critical question:

How do we enable AI innovation without losing control of data, compliance, and trust in the process?


AI Adoption Is Outpacing Governance, and Controls Can’t Keep Up

Many executives admitted that the speed of AI rollout has overtaken policy, governance, and technical oversight. One leader described how confidential HR data had already been uploaded to AI platforms before safeguards were in place. "We had to move fast to block services and retrofit controls later,” they said.

Even in more advanced organisations, there’s still an education gap. “We had to teach employees what they could and couldn’t share with AI,” another attendee explained. “They didn’t know.”

The emergence of autonomous AI agents and embedded SaaS features is further complicating visibility. “It’s not a human, but it’s not a static machine either,” one participant noted, highlighting how traditional governance models were never designed for adaptive, decision-making systems.

The result: a growing gap between executive ambition and operational assurance.

One CISO said:

““Our exec committee is passionate about using AI to drive efficiency. That puts pressure on us to push projects through quickly. We’ve seen increased data risk, but not yet the productivity benefits.”

AI Risk Management Needs Visibility, Transparency, and Context

Across both the public and private sectors, the pressure to “do more with less” is driving rapid AI deployment, often without the security and governance maturity to support it.

“There’s a rush to bolt AI onto SaaS products,” Moore observed. “But many vendors haven’t considered security.” This leaves security teams in a constant race to discover and assess new AI tools before data leaks out.

The risk isn’t just exposure. It’s opacity. One bank discovered its AI-driven fraud model was disproportionately rejecting applications from people with South Asian names. The issue traced back to biased training data that included historical fraud cases linked to the Tamil Tigers. Over time, the model learned a false correlation between name patterns and fraud risk.

“The model learned a spurious correlation between vowels in a name and the likelihood of fraud,” the executive said. “Without transparency, these issues are almost impossible to catch.”

Modern AI risk management therefore, requires visibility, explainability, and intent awareness. Organisations need to understand why models act the way they do, and why users behave the way they do, not just monitor which tools are in use.

From Training to Teaching: At the Moment of Risk

Every attendee agreed that traditional awareness training won’t close the gap. “It can’t be one and done,” said one security leader. “It has to be constant. And it has to be paired with other controls.”

AI interactions are persuasive, often overriding user judgement. “We know about hallucinations and false confidence,” said one executive, “but people forget in the moment. They see an answer and stop thinking critically.”

“There’s evidence that training can make things worse, by giving people a false sense of security."

CultureAI takes a different approach: introducing “friction” into risky workflows, with a message telling users they can’t proceed or asking them to confirm their intentions.

Rather than relying on static education, organisations are moving toward intent-aware, behaviour-based interventions: detecting risky actions as they happen and turning them into teachable moments.

This shift from training to teaching at the point of risk is fast becoming a foundation of secure AI enablement.

The New Challenges of AI Enablement

Executives also highlighted emerging challenges that extend beyond compliance: from cultural change to insider misuse.

“A new generation assumes breaches are inevitable,” one participant said. “They’re growing up with AI, and they’re bringing that mindset to work.”

Others pointed to prompt injection attacks and unintentional insider risks. “Someone will always try to make an LLM reveal confidential data,” an attendee warned. “Not out of malice, just curiosity.”

With geopolitical tensions and economic pressures rising, that curiosity can quickly become compromise. “Desperate people are more likely to sell data,” said another. “It’s a growing concern.”

These insights reinforce that secure AI adoption isn’t just about blocking tools. It’s about ensuring every use of AI is measurable, compliant, and human-friendly.

Building the Future of Secure AI Usage

Those at the briefing were in agreement: organisations can’t slow down AI innovation, but they must make it safer, more transparent, and more accountable.

The enterprises leading AI security today are shifting from control to enablement. They’re building systems that:

  • Provide continuous visibility into all AI usage, sanctioned and shadow.
  • Detect behavioural and intent-based risks in real time.
  • Deliver adaptive, in-the-moment coaching when users approach risky actions.
  • Combine compliance-grade oversight with a human-friendly user experience that encourages safe innovation.

Whether the threat comes from a rushed deployment, a careless insider, or an attacker exploiting behaviour, the key is visibility, context, and control. AI adoption should never come at the cost of confidence.

Takeaway: Safe AI Adoption Starts With Visibility and Control

The AI adoption wave is unstoppable, but without full visibility into how AI tools are being used and the intent behind that use, most enterprises are managing risk reactively.

Effective AI governance means making AI usage measurable, secure, compliant, and human-friendly, giving organisations the intelligence to empower people safely, not restrict them.

To learn how leading organisations are enabling secure AI adoption without slowing innovation, explore CultureAI’s AI Risk Assessment, which gives security and compliance teams the visibility, controls, and coaching tools to manage AI usage without killing productivity.

Uncover hidden AI risk

Start a free 2-week AI Risk Assessment. Easy setup. Fast visibility.