History has a habit of repeating itself in technology.

We saw it with cloud computing. We saw it with mobile devices. We saw it with social media. Organisations embraced the benefits, while security considerations often followed later.

Today, we are seeing a similar pattern with artificial intelligence, but AI is moving much faster.

“Most organisations aren’t struggling to adopt AI,” says Stephen Vella, CTO/COO at Computime. “They’re struggling to understand where it is being used, what data it can access and how to secure it properly.”

That matters because AI is no longer limited to generating text or answering questions. It is increasingly being integrated into enterprise data, business applications and everyday workflows. As its access and capabilities grow, AI becomes part of the organisation’s attack surface.

The shadow AI problem

One of the most immediate risks is shadow AI: employees using AI services outside an approved or monitored environment.
The intention is rarely malicious. Someone may upload a confidential proposal to improve its wording, paste source code into an AI assistant for troubleshooting, or provide business information to generate a summary.

The risk is created by convenience.

Traditional security controls generally assume that sensitive information is accessed through known applications, devices and infrastructure. AI introduces another route through which organisational data may reach services that security teams cannot see or control.

“A blanket ban is rarely the right answer,” says Vella. “If employees see real value in AI, they will continue looking for ways to use it. Organisations need to provide approved tools, clear guidance and practical safeguards.”

The objective should be secure adoption rather than outright restriction.

AI is also strengthening the attacker

AI is equally accessible to cybercriminals.

Attackers can use it to research potential targets, create convincing phishing messages, personalise social-engineering campaigns and produce malicious content more quickly.

Poor spelling, awkward phrasing and generic messaging were once common phishing indicators. AI can remove many of those warning signs, making malicious emails appear professional and contextually relevant.

“The quality of a message is no longer a reliable measure of whether it is genuine,” says Vella. “Attackers can now create polished and personalised communications at scale, so organisations cannot depend on employees recognising every threat.”

Security awareness remains essential, but it must be supported by layered controls. Strong authentication, email security, endpoint protection, identity controls and behavioural monitoring all have an important role.

The bigger risk is AI with access

The security implications grow considerably when AI moves beyond generating content and begins interacting with enterprise systems.
An AI assistant may be able to access emails, documents, customer records, internal knowledge bases, financial information or business applications. It may also be able to take actions on behalf of a user.

This raises some fundamental questions.

What identity is the AI using? What information can it access? Which permissions does it have? What actions can it perform autonomously? Who approved that access? What activity is logged? How quickly can its permissions be revoked?

“An AI system with broad access should be treated like any other powerful identity in the environment,” says Vella. “Least privilege, strong approval processes, continuous monitoring and rapid revocation are essential.”

AI should not receive extensive access simply because broader permissions make it more useful.

Visibility must come first

Organisations cannot manage AI risk without understanding how AI is being used.

Security teams need visibility into which tools are in use, who is using them, what business purposes they support and what types of information are being shared.

That visibility must extend beyond public generative AI websites. It should include embedded assistants, browser features, software-development tools and AI capabilities introduced through existing cloud platforms.

“You cannot secure what you cannot see,” says Vella. “The first practical step is discovering AI use across the organisation and separating approved business activity from behaviour that creates unacceptable exposure.”

Data classification, information protection, access management and monitoring must therefore form part of the organisation’s AI security strategy.

Security by design

At Computime, our conversations with customers increasingly focus on achieving the right balance: embracing AI’s benefits while protecting identities, sensitive information and critical business systems.

This requires approved platforms, acceptable-use policies, identity and access controls, data protection, continuous monitoring and incident-response processes designed for AI-enabled environments.

AI security cannot operate separately from the wider cybersecurity architecture.

“AI security is not a future project. It is an enterprise security priority today,” concludes Vella. “The organisations that benefit most will not simply be those that adopt AI fastest, but those that build security into that adoption from the beginning.”

Main Image:

Read Next: Placeholder