AI Is Moving Faster Than Our Guardrails: Why Most Organizations Still Aren’t Ready

Cybersecurity News

A friend recently passed along a piece on how unprepared most enterprises are for the security risks that come with artificial intelligence. They thought it might interest me. They were right, and I think it deserves a wider audience, including among those of us who will never run a Fortune 500 company but who use AI every single day.

Here at Climate Change Community, we use AI openly and intentionally as a tool for research, communication, strategy, and education. That’s precisely why this subject matters to us. If we’re going to ask people to trust AI-assisted learning, we have to understand where the cracks are, and we have to be honest about them.

The Core Problem: Adoption Is Outrunning Governance

The message of the piece is straightforward. AI went from experiment to everyday operations faster than most organizations planned for. People now use it to draft proposals, summarize documents, write code, analyze feedback, and inform decisions, frequently before security teams, legal departments, and leadership have agreed on any rules.

AI itself isn’t the villain here. The danger lies in connecting powerful tools to sensitive information and building them into important processes without visibility, controls, or a plan for when something goes wrong.

Independent research backs this up. Accenture’s 2025 State of Cybersecurity Resilience report found that 90% of large organizations aren’t prepared to protect against AI-enabled threats, that only 22% have policies covering AI training and usage, and that very few keep a complete inventory of their AI systems. Separate research reported by Help Net Security found that while most organizations planned to deploy autonomous “agentic” AI, only 29% said they were prepared to secure it.

Shadow AI: Good Intentions, Invisible Risk

One of the most important points is that most risky AI use isn’t malicious. People find a tool that helps them do their jobs, and they use it. When an organization hasn’t provided approved tools and clear guidance, that usage goes underground. The term for this is “shadow AI.”

The result is an organization that can’t say which AI systems are in use, what data they touch, who interacts with them, or how their outputs shape decisions. You can’t protect what you can’t see.

The New Attack Surface

AI doesn’t just store data. It reads, interprets, generates, recommends, and increasingly acts. That opens doors traditional security wasn’t designed to guard. The risks worth knowing include:

  • Sensitive-data exposure: customer records, source code, contracts, health information, and passwords pasted into outside tools without anyone understanding retention or training policies.
  • Prompt injection: hidden instructions planted in documents, emails, or web pages that try to hijack an AI system’s behavior or trick it into leaking information.
  • Over-connected integrations: AI tools linked to email, cloud drives, databases, and code repositories with broader permissions than they need.
  • Confident but wrong output: polished answers that are incomplete or fabricated, relied on for legal, financial, medical, or engineering decisions without review.
  • Supply-chain dependencies: third-party models, plugins, datasets, and APIs, each bringing its own vulnerabilities and provenance questions.
  • Smarter scams: phishing emails with no spelling mistakes, imitated writing styles, and synthetic voice or video that make old warning signs obsolete.

What Preparation Actually Looks Like

Start With Visibility

The first step isn’t buying another product. It’s learning how AI is already being used: which platforms are approved, which teams depend on it, which data sources are connected, which tools can take actions on their own, and which everyday software has quietly added AI features. That inventory has to be revisited regularly, because capabilities change constantly.

Write Policies People Can Actually Follow

Rules that are vague or overly restrictive get ignored and drive usage back into the shadows. Good policies separate low-risk uses, like brainstorming or formatting public content, from high-risk ones involving confidential or regulated information. And the best policies explain the why. People follow rules more readily when they understand what those rules protect.

Treat AI Agents Like Privileged Users

An assistant that drafts text is one thing. An agent that can read a mailbox, change cloud settings, approve payments, or contact customers is another. These systems should be handled like any powerful account: minimum necessary access, separate credentials, activity logging, approval gates for irreversible actions, regular permission reviews, and testing against malicious instructions. As the piece puts it, an AI agent should never hold more power than the job requires.

Keep Humans Accountable

AI can speed up work, but it can’t absorb responsibility. The more consequential the outcome, the stronger human oversight needs to be. A meeting summary needs a light touch. A wire transfer, a hiring decision, a firewall change, or a legal notice needs real verification by a real person.

Protect the Data, Not Just the Model

Much of AI security is really data security. A model is only as safe as the data, identities, and permissions surrounding it. Classification, encryption, access controls, vendor due diligence, logging, and clear deletion rules all matter, as does asking whether sensitive information needs to reach an outside model at all.

A Practical Roadmap

Organizations don’t need to freeze AI adoption until every question is settled. A balanced path looks something like this:

  1. Find out where AI is already in use, including unsanctioned and embedded tools.
  2. Sort use cases by data sensitivity, business impact, and level of autonomy.
  3. Publish clear rules on approved tools, permitted data, and human review.
  4. Vet AI vendors, contracts, and privacy commitments.
  5. Apply least-privilege access to AI systems and everything they connect to.
  6. Monitor usage, data movement, and agent actions.
  7. Train people to recognize prompt injection, data leakage, deepfakes, and AI-enhanced phishing.
  8. Rehearse incident response for compromised AI tools and agent misuse.
  9. Reassess regularly as tools, vendors, and regulations evolve.

Why This Resonates With Me

I spent just shy of 14 years as a Tech Support Specialist in the court system, working in constant dialogue with judges, court officers, and law and bench clerks. In that world, I learned that the safeguards around sensitive information are only as strong as the shared understanding of the people using them. Technology alone never secured anything. Clear rules, honest communication, and mutual accountability did.

The same lesson applies to AI. Security is not just the IT department’s job. It requires cooperation among leadership, legal, privacy, procurement, engineering, and the everyday users who actually touch the tools. That’s not so different from how we approach the Climate and Ecological Emergency: no single group can solve a systemic problem alone.

I’d go one step further. Adaptive Resiliency, the framework at the heart of our work, is about preparing communities to absorb shocks and keep functioning. Our digital systems are now part of that resilience. Climate organizations, nonprofits, mutual-aid networks, and community groups are adopting AI too, often with fewer resources than any enterprise. Member data, donor information, and the trust people place in us are worth protecting with the same seriousness.

The Bottom Line

AI is becoming part of how organizations run, ready or not. The question is no longer whether people will use it, but whether they’ll be given a safe, governed, and accountable way to do so. The organizations that thrive won’t be the ones that ban everything or adopt everything. They’ll be the ones that pair innovation with visibility, discipline, human oversight, and honest preparation for failure.

Preparing for these risks isn’t a barrier to using AI well. It’s the very thing that makes using AI well possible. Thank you to my friend for sharing this one.

Further Reading

Protecting our Children & Biodiversity’s future towards a more sustainable and habitable Earth!

Compiled & Mr. Alvarez’s Thoughts | AI Enhanced.

A note on process: AI is used as a tool to enhance my creativity and thinking. The ideas, perspective, and final judgment remain my own.

Leave a comment

Blog at WordPress.com.

Up ↑

empowerment & inner transformation...

__________________________________

Bryan Parras

An experienced organizer and campaign strategist with over two decades working at the intersection of environmental justice, frontline leadership, and movement building. Focused on advancing environmental justice and building collective power for communities impacted by pollution and extraction. Skilled in strategic organizing, coalition building, and leadership development, managing teams, and designing grassroots campaigns. Excels at communicating complex issues, inspiring action, and promoting collaboration for equitable, resilient movements.

NJTODAY.NEWS

Your neighborhood in print since 1822

Global Justice Ecology Project

Global Justice Ecology Project (GJEP) explores and exposes the intertwined root causes of social injustice, ecological destruction, and economic domination.

WP Tavern

WordPress News — Free as in Beer.

Raw Soul Food Lifestyle by Sistahintheraw

African, Caribbean & Asian Inspired Flavours for a Raw & Living Plant-Based Food Lifestyle

mydandelionmind.wordpress.com/

Going off on tangents since 2015

Cloak Unfurled

Life is a journey. Let us meet at the intersection and share a story.

alltherawthings

...happily, naturally active...

SGI-UK Bristol, Buddhism

Nichiren Buddhism in Bristol, Nichiren Buddhists in Bristol, Soka Gakkai in Bristol

Zero Creativity Learnings

In Design and Arts

Life is an exhibition

Sarah Rose de Villiers

indigolotusnavigators

Just another WordPress.com site

Auroras Blog

Personal blog about the topics business, marketing, Wordpress, the Internet, and life in general.

The Journey of A Soul

A blog by Chad Lindsey

LWC

is one with unbounded love

Pocket Perspectives

shifting views on life