AI benefits/risks

Four ways to close the AI security gap

Futuristic Hand Reaching for AI Technology Interface Representing Artificial Intelligence and Data Management in a Digital World. Glyphic.

COMMENTARY: One of the most important lessons I took from my time in the military was that speed and discipline aren't opposites. In fact, the teams that moved with the most control were usually the ones that got ahead.

I’ve found that many of the lessons I learned while serving translate directly to my job as a CISO, especially as the industry navigates unfamiliar terrain brought on by AI.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

Enterprises are adopting AI faster than they can secure it. Every new AI tool and agent creates an identity that leaves security leaders scrambling to find out who owns what, where these identities came from, and what they are allowed to do.

Recent headlines, like the HuggingFace breach, are raising hard questions about just how dangerous these agents are when they go rogue. We're not just up against external attackers anymore, we now need to take a closer look at the risks that live inside our own infrastructure.

And while today’s AI landscape can feel overwhelming, the instinct to race ahead often gets us in the most trouble. The discipline I've carried from high-stakes military operations applies to this moment, too.

“Move fast and break things” no longer makes sense

Organizations have been racing to deploy AI across their products and their workforces to keep up with competition and demand. The push to adopt AI has become so widespread that we've reached a point where identities inside an enterprise are no longer mostly people.

A common mantra over the past few years was "move fast and break things," even if that meant skipping controls, oversight, and governance frameworks. As a result, many enterprises have started to realize that they adopted AI faster than they could control it. Every new AI tool, integration, and agent creates an identity that requests access, takes action, and produces data. Non-human identities already outnumber humans 45 to 1, and that ratio will climb.

The HuggingFace incident showed what happens when unaccounted for identities have room to operate. AI agents identified and chained together multiple weaknesses until they reached third-party production infrastructure. The technical debt every organization carries — forgotten permissions, stale keys, over-privileged identities — can become part of an attack path that AI systems are increasingly capable of finding and exploiting at speed.

The lesson for us to take away from these trends: speed without structure can create the conditions for catastrophe.

It reminds me of an old principle from combat operations: “slow is smooth, and smooth is fast.” This sounds counterintuitive, but it's practically accurate. Organizations that race past steps don't actually move faster. Those who move deliberately usually end up getting to the finish line first.

It seems that nothing actually moves slowly in this current landscape, but it can be smooth. "Smooth" means all steps are intentional and controlled. In cybersecurity terms, that looks like building AI with least-privilege access, logging and monitoring what it does, having a human-in-the-loop for high-stakes decisions, and red-teaming it before it goes live. None of this feels fast in the moment, but it keeps the system moving.

Behavioral AI levels the playing field

AI security has become the new cybersecurity frontier, and legacy tools simply aren't equipped to meet its demands.

Traditional rules-based tooling that worked well enough a few years ago cannot close the gap that AI continues to widen. Writing a rule means knowing the behavior in advance, but an AI stack that changes weekly does not give us what we need to predict that. What does work is learning what normal looks like for every identity in the business (both human and non-human), and acting at machine speed the moment something deviates.

Attackers can steal a credential, pass an authentication check, and write a convincing message, but they struggle to fake how a trusted identity normally acts. That behavioral baseline represents the foundation that modern security teams need to build on.

Behavioral AI enables a smooth and steady approach to move with enough velocity to compete with rogue agents, savvy adversaries, and everything in between.

Four areas enterprise IT leaders should focus on

We can't snap our fingers and fix this overnight, but we can be intentional about where to start. Here are four areas where the "slow is smooth" principle pays off:

  • Visibility into how employees use AI: Employees bring AI tools into organizations that can reach corporate data, run business functions, and spin up agents of their own. Sanctioned or not, the security team usually has no view into what’s being typed into it and no ability to intervene. Obtaining full visibility into how employees use AI tools and AI-enabled SaaS applications has become important to securing human identities within the enterprise.
  • Visibility into AI agents: Non-human identities (NHIs) are the fastest-growing attack surface in the enterprise. Every AI agent deployed represents an identity that can request access and produce data often without any human oversight. Security teams need full visibility into what agents exist, what they're authorized to do, and whether their behavior aligns with those authorizations. Least-privilege access, regular audits, and behavioral baselines for agents are foundational to securing an organization.
  • Understand the cloud: AI agents live in the cloud, and it's where their behavior most directly touches production infrastructure. Point-in-time scans and static rules can't catch behavior that only becomes suspicious in context. Behavioral AI extended to the cloud builds a living model of every identity — human, machine, or agent — and surfaces the moment something deviates from its established pattern. Here's where the defender's advantage lives: catching the chain before it completes.
  • Set clear policies: AI governance makes all of this sustainable. Without clear policies around how AI can be deployed, what access it can request, who owns each agent, and how incidents are escalated, even the best tooling becomes reactive. AI governance keeps your security program moving smoothly, and therefore fast.

When under pressure, people always tend to accelerate. Every CISO I know feels that pressure right now. But the organizations that come out ahead won't move the fastest, they'll move with the most discipline.

So for everyone feeling the pressure, just remember: Slow is smooth, and smooth is fast.

Mick Leach, Field CISO, Abnormal AI

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds