Security News

Cybersecurity news aggregator

INFO News SC Media

How to Build an AI Security and Governance Program

  • What: Guide to building an AI security and governance program
  • Impact: Helps organizations manage AI risks
Read Full Article →

AI benefits/risks , AI/ML , Generative AI How to Build an AI Security and Governance Program August 24, 2026 Share By SC Media Editorial Intelligence, reviewed by Ramanan Hariharan Where Programs Fail AI governance programs commonly fail in three ways. The first: they begin with committee formation instead of inventory. Organizations create AI oversight groups, develop risk frameworks, and write acceptable use policies while employees continue using hundreds of undocumented AI tools through browser extensions, SaaS integrations, and API connections. By the time the governance committee publishes its first policy, the shadow AI population has grown beyond what manual discovery can map. The second failure mode: treating all AI tools as equivalent risk. Programs that apply uniform controls to AI-powered grammar checkers and autonomous code generation tools produce either inadequate protection for high-risk capabilities or compliance friction that drives further shadow adoption. Risk tiers based on data exposure and decision-making scope separate manageable oversight from security theater. The third failure: launching enforcement before establishing approval pathways. Organizations announce AI tool restrictions without publishing an approved tool list or a fast-track review process for low-risk applications. Users facing immediate business needs will route around governance that creates delays without offering alternatives. Approval processes must match business velocity — a fast track for low-risk tools, full review for tools processing sensitive data. Program Components An effective AI governance program operates through four integrated components that build capability in sequence. AI Asset Discovery and Classification Continuous inventory across all AI touchpoints creates the foundation for risk-based controls. NIST AI RMF's Govern function (GOVERN 1.0–6.0) establishes that AI risk governance requires organizational policies, assigned accountability, defined escalation paths, and continuous monitoring; GOVERN 1.2 specifically requires that accountability for AI risk is assigned to named organizational roles with the authority to act on identified risks, not distributed to teams without enforcement authority. Discovery covers browser extensions, SaaS applications with embedded AI features, API integrations, and AI capabilities within approved enterprise software. Classification by data exposure determines control requirements: Tier 1 processes public or read-only data, Tier 2 accesses internal data, Tier 3 processes sensitive data or operates autonomously. Risk-Based Approval Framework Tiered approval matches oversight intensity to actual risk. Tier 1 fast-track review completes within 48 hours via standardized checklist. Tier 2 requires business justification and data handling review within one week. Tier 3 involves cross-functional review with Legal, Privacy, and Information Security, targeting 2–3 weeks. Each tier produces specific artifacts: an approved tool list for IT enforcement, minimum contractual requirements, and escalation criteria for tools that exceed their approved scope. Continuous Monitoring and Control AI tool usage monitoring integrates into existing DLP and network monitoring infrastructure. The OWASP LLM Top 10 (2025) identifies supply chain vulnerabilities (LLM05) and excessive agency (LLM06) as risks that operate at the organizational program level — not only at the application development level. Supply chain vulnerabilities include third-party AI service data handling practices and training data exposure; excessive agency is bounded by what permissions the governance program grants to AI tools and agents before deployment. Monitoring targets data flows to unapproved services, changes in approved service terms, and vendor capability updates that shift tools to higher risk tiers. Re-review cycles, typically every six months, verify approved tools still meet their original classification. Enforcement and Escalation Enforcement requires pre-established authority and clear escalation paths. Technical controls include DNS blocking for unapproved services, browser extension policies, and traffic monitoring; administrative controls cover acceptable use training, policy violation consequences, and manager accountability. For organizations deploying AI agents, the AI governance program must coordinate with the agent identity program — the approval process for agentic AI tools requires scope review that the agent identity framework governs. Phased Approach Program implementation follows a four-phase sequence that builds capability and trust before expanding scope and controls. Each phase produces measurable outcomes that enable the next phase of governance. Phase 1: Visibility and Inventory — establishes the tool inventory that Phase 2 requires for risk-tiered approval The discovery phase maps existing AI tool usage across all vectors without imposing restrictions. CSA's AI Safety Initiative guidance on enterprise AI governance identifies five organizational controls required for AI risk management: AI asset inventory, risk classification by data exposure and capability, a formal approval process for AI tool adoption, continuous monitoring of approved AI tool usage, and incident response procedures for AI-related security events. Organizations that implement monitoring without completing inventory and classification produce alerts they cannot act on because the risk baseline has not been established. Discovery covers browser extension audits, SaaS AI feature inventories, network traffic analysis for AI service connections, and vendor contract review for AI-related terms. Phase 2: Approval and Baseline Controls — establishes the approval framework that Phase 3 monitors The approval framework launches with a small set of common-use AI tools to establish process credibility before expanding scope. Initial approvals focus on tools already in widespread use to avoid disrupting established workflows while demonstrating that governance can enable rather than block productivity. Framework components include risk tier definitions with specific criteria, approval workflows for each tier, contractual requirements that vendors must meet, and published lists of approved and prohibited tools. Legal and HR alignment ensures that policy violations have enforceable consequences before the program launches. Phase 3: Ongoing Monitoring and Control — establishes monitoring coverage that Phase 4 integrates Monitoring implementation begins with high-risk tool categories and expands to comprehensive coverage. Initial focus on Tier 3 tools processing sensitive data or operating autonomously provides the highest security return while building monitoring capability. Control expansion covers vendor change notifications that trigger re-review, periodic assessment cycles for all approved tools, enforcement action procedures for policy violations, and integration with existing security incident response processes. Phase 4: Integration and Optimization Program maturation integrates AI governance into existing security and risk management processes. AI tool risk assessments become part of standard vendor risk management procedures. Security awareness training incorporates AI acceptable use alongside other technology policies. Governance reporting provides metrics on AI tool adoption, risk exposure, and policy compliance to security leadership and audit functions. Governance and Ownership Clear ownership assignments prevent governance programs from becoming committee oversight exercises without operational authority. Each program component requires a named accountable role with decision-making authority and budget control. Security Team Ownership : AI tool risk classification, technical monitoring implementation, security incident response for AI-related events, and integration with existing security controls. Security teams own the risk framework but not the business approval decisions. IT/Procurement Ownership : Vendor management for approved AI services, technical implementation of approved tools, license management and cost allocation, and enforcement of technical controls like browser extension policies. IT teams execute approval decisions but do not determine risk classifications. Legal/Privacy/GRC Ownership : Contractual requirements for AI vendors, privacy impact assessments for tools processing personal data, regulatory compliance reporting, and policy violation escalation procedures. Legal teams define compliance requirements but do not approve individual tools. Business Unit Ownership : Business justification for AI tool requests, user training on approved tools, accountability for team compliance with AI policies, and feedback on governance process effectiveness. Business owners approve tools within their areas but cannot override risk classifications. Cross-functional coordination handles edge cases and policy exceptions through defined escalation paths rather than standing committees. Regular program review cycles — quarterly for the first year, biannually thereafter — adjust governance procedures based on operational experience and changing AI capabilities. Implementation Checklist Phase Action Owner Role Completion Signal Phase 1: Visibility and Inventory Conduct browser extension audit across all managed devices and catalog AI-enabled extensions by data access scope IT/Security Inventory published with risk categorization per extension Survey users about AI tool usage through anonymous form covering web applications, API integrations, and embedded AI features in approved software Security Awareness Program >70% response rate with AI tool usage documented by business function Review existing SaaS vendor contracts for AI features and data processing terms that were not part of original procurement Legal/Vendor Risk Team Contract addendum requirements identified and flagged for vendor renewal negotiations Establish A

Share this article