A compelling AI demonstration can make adoption look easy. A tool summarizes a lengthy report, drafts a customer response, or answers questions across company documents in seconds. The business opportunity is real. But the demonstration rarely shows what happens when the source material is wrong, a confidential document enters an unapproved service, or the system gains permission to take actions nobody intended.
For executives and boards, the right question is not simply whether artificial intelligence works. It is whether a particular use of AI delivers value within boundaries the business understands and can enforce.
Evaluate AI by the task it serves, the data it receives, and the actions it can take—not just the quality of its answers. Generative AI creates content; AI agents can also interact with applications and execute workflows. Those capabilities introduce different risks and should receive different levels of oversight.
Security should not be a reason to avoid AI. It should be the discipline that makes useful adoption sustainable. These five controls provide a practical starting point.
1. Know Where AI Is Already Being Used
An organization cannot govern tools it cannot see. Employees may already be using AI through browser-based services, features embedded in existing software, or applications connected to company accounts. A formal purchasing process alone will not capture that activity.
The NIST Generative AI Profile recommends maintaining an AI-system inventory, including information about underlying models, access methods, known issues, and human oversight responsibilities. Translate that guidance into a register people can actually maintain.
- Tool and owner: What is being used, and who is accountable for its business purpose?
- Intended use and permitted data: Which tasks and information are approved?
- Connections and access: Which applications, accounts, and underlying models does it use?
- Oversight and limitations: Who reviews results, and what known weaknesses matter?
- Shutdown procedure: Who can disable the tool or revoke its connections?
Start by asking department leaders what their teams use and why. Make disclosure constructive rather than punitive. Employees who expect punishment for experimenting are less likely to reveal the workflows that need attention.
For example, an assistant used to draft public marketing copy is materially different from one connected to customer support records. Both belong in the inventory, but they should not receive identical approval conditions.
2. Set Explicit Boundaries Around Sensitive Data
AI can only process information it can access. That makes data boundaries a business decision, not just a technical setting.
The UK National Cyber Security Centre’s secure-design guidance for AI systems emphasizes evaluating external providers’ security and controlling information sent outside the organization’s control. Before approving a service, understand what happens to inputs, uploaded files, outputs, and connected data.
Ask Questions About the Actual Product and Contract
- How long is information retained, including logs and backups?
- Can inputs or outputs be used for model training, and what settings or contractual terms govern that use?
- Who can access the information, including provider personnel and third parties?
- What access controls, deletion mechanisms, and audit capabilities are available?
- What information can connected services retrieve or share?
Do not assume every AI service trains on every user input. Equally, do not assume that a familiar vendor or paid subscription automatically provides the protections your use case requires. Verify the specific product, plan, configuration, and agreement.
Give employees concrete rules. Credentials, authentication secrets, customer records, confidential financial information, and proprietary code should not enter tools unless that use has been explicitly approved with appropriate safeguards.
Suppose a manager wants help summarizing a customer complaint. An approved workflow might use a minimized version containing only the details needed for the task, rather than uploading the customer’s entire account history. Removing a name alone may not make the remaining information safe to share.
3. Require Verification, Not Just Fluent Answers
AI-generated content can sound authoritative while being wrong. NIST describes this risk as confabulation: confidently presented false or erroneous content. Its Generative AI Profile recommends reviewing generated sources and citations during testing and ongoing monitoring.
The practical lesson is straightforward: fluent language is not evidence. A source link may be irrelevant, a quotation may be inaccurate, and a calculation may rest on an incorrect assumption.
Assign an accountable reviewer to consequential outputs. That reviewer needs access to the original evidence, enough expertise to evaluate it, and time to perform a meaningful check.
- Research and communications: Verify factual claims, quotations, and references against original sources.
- Financial work: Check source data, assumptions, formulas, and calculations.
- Software development: Review generated code and test it for functionality and security before deployment.
- Customer-facing decisions: Confirm that responses reflect current policy and the customer’s actual circumstances.
Consider an AI-generated briefing that cites a company policy. The reviewer should open the policy, confirm it is current, and check whether it supports the recommendation. Asking the same model whether its answer is correct is not independent verification.
Match review intensity to potential harm. Brainstorming a meeting agenda does not warrant the same scrutiny as advice affecting a payment, contract, or individual’s access to services.
AI should accelerate the work—not eliminate accountability for the result.
4. Limit What an AI Agent Can Do
A drafting assistant produces suggestions. An agent connected to email, files, business systems, or payment workflows may change records, send messages, or initiate transactions. That shift from generating content to exercising authority deserves explicit approval.
NCSC’s secure-design guidance recommends least-privilege access and restrictions on AI-triggered actions. In practical terms, give an agent only the permissions necessary for its approved task.
Start With Narrow Permissions and Approval Gates
Use read-only pilots where feasible. Restrict access to relevant repositories rather than entire environments. Separate the ability to propose an action from the authority to execute it. Require independent approval for sensitive changes, external communications, payments, and permission updates.
Prompt injection is a particular concern. Instructions embedded in a retrieved document, webpage, or message may attempt to redirect the system away from its authorized task. For example, a document being summarized could contain hostile instructions to retrieve unrelated confidential files and include them in the response.
Treat external content as untrusted, and test these scenarios before deployment. Check whether the system can cross data boundaries, invoke unnecessary tools, or bypass approval steps. Do not assume a filtering product or a well-written prompt eliminates the risk.
Enforce important restrictions outside the model through application permissions and workflow controls. Maintain useful activity logs and a tested way to revoke access. If an agent behaves unexpectedly, the business needs a reliable stop mechanism—not another conversation asking it to stop.
5. Update Fraud-Verification Procedures
AI adoption is not only about the tools your organization chooses. It is also about the tools criminals use against it.
In its December 3, 2024 alert, the FBI described criminals using AI-generated text, images, audio, and video to support fraud. It recommends independently verifying callers through a trusted contact number.
A familiar voice, convincing video, or polished message is not sufficient proof of identity. Your procedures should remain effective even when the impersonation looks credible.
- Independently confirm unusual payment requests and changes to bank details.
- Use a trusted number or established verification channel—not contact details supplied in the suspicious request.
- Apply existing approval requirements even when a request appears to come from a senior executive.
- Give employees permission to pause urgent requests involving money or sensitive information.
For example, if someone appearing to be the CEO requests an immediate transfer during a video call, finance should still follow the established approval process. The control should depend on independent verification, not an employee’s ability to spot a synthetic face or voice.
A Practical Checklist Before Expanding an AI Pilot
The following is an implementation proposal, not a government-mandated standard. Before scaling, confirm that the pilot has:
- An accountable owner and a clearly defined business task.
- Documented data boundaries supported by verified provider terms and settings.
- Limited permissions and approval gates appropriate to the potential harm.
- A review process with named reviewers and access to original evidence.
- Performance measures covering accuracy, usefulness, checking time, and rework.
- Stop conditions and a tested procedure for disabling access and investigating problems.
Compare the AI-assisted workflow with the existing process. Measure the effort required to produce an acceptable result, not just the volume of output. A fast draft that demands extensive correction may offer less value than its demonstration suggests.
Scale the Value, Not the Exposure
Responsible AI adoption does not require perfect certainty. It requires clear ownership, bounded access, proportionate verification, and the ability to stop when the system exceeds those boundaries.
Before approving your next expansion, bring the business owner, security team, and relevant reviewers together to complete the checklist. If they cannot explain what data the tool receives, what it can do, who checks its work, and how to disable it, the pilot is not ready to scale. Establish those controls first—then expand the uses that demonstrate real business value.