

Executive Perspective
By Alasdair Murray, Chief Product and Technology Officer
AI security isn't fundamentally a technology challenge. As organisations embed AI into critical workflows, trust, identity and governance become the real determinants of success.
Recent AI security incidents have generated significant discussion because they appear to demonstrate a new category of threat: autonomous AI agents taking actions beyond the expectations of their creators. In one widely discussed report, AI agents engaged in unsanctioned activity on the live internet, including activity directed at real people and organisations. The report describes behaviours including fake online identities, social engineering, malicious code, supply-chain manipulation and attempts to influence human decision-making.
It would be easy to view those incidents as evidence that AI has created an entirely new security problem. That is not the most useful lesson. The more important point is that the underlying behaviours are familiar. Security teams have dealt with social engineering, misuse of trust, misuse of access, supply-chain compromise and privilege misuse for decades. What has changed is the speed, persistence and scale with which these behaviours can now be attempted.
That distinction matters because it changes the response required from organisations. If AI security is framed primarily as a model problem, attention naturally moves towards model selection, technical safeguards and safety controls. Those controls matter, but they are not sufficient. The harder strategic question is not simply how organisations secure AI, but how they decide where AI should operate, what authority it should hold, what risks are acceptable and how accountability is maintained when AI becomes part of business execution.
The issue is not that organisations are waiting to adopt AI. The issue is that many are already experimenting, deploying and automating faster than their governance models can keep up.
As I see it, AI transformation should not start with technology. It should start with outcomes, strategy, governance and risk.
“AI adoption should be governed by outcomes, not capability.”
Alasdair Murray, Chief Product and Technology Officer, Condatis
Key Takeaways
01
AI is not creating an entirely new class of security risk. It is accelerating familiar risks such as social engineering, misuse of trust, misuse of access and supply-chain compromise.
02
Organisations are no longer in a purely strategic planning phase. AI experimentation and adoption are already underway, often moving faster than governance, which makes trusted adoption an immediate executive priority.
03
A common gap is emerging between AI adoption and identity governance. AI and Productivity teams are often moving quickly, while security and IAM teams are not always involved early enough or asking what access, authority and accountability AI tools require. Allowing access before control.
04
AI literacy is now a trust control. The AISI incident showed that human decisions about agent permissions, autonomy and guardrails directly shape AI behaviour. AI literacy helps teams understand those choices, identity controls define what agents can do and governance keeps decisions accountable.
05
Organisations should not begin AI transformation with models or agents. They should begin with business outcomes, strategy, governance and acceptable risk.
06
Strategy must include AI: which workflows should AI influence, which should remain human-led, and what level of autonomy is appropriate.
07
As AI moves from assistance to action, identity becomes more strategic because AI systems increasingly require access, authority and accountability.
08
AI adoption will create a new intellectual property challenge as prompts, corrections, workflows, evaluations and decision patterns become organisational intelligence.
09
Trusted AI adoption will require organisations to solve three connected governance challenges: Strategy Governance, Identity Governance and soon Intelligence Governance.
Why this matters now
AI adoption is accelerating at the same time as identity-based risk continues to grow. As organisations embed AI into workflows, the number of digital actors capable of accessing information, influencing decisions and taking action will increase significantly. The challenge is no longer whether AI becomes part of the enterprise. The challenge is whether organisations can establish the trust, identity and governance foundations required to scale it safely.
- Verizon analysed 22,052 security incidents and 12,195 confirmed data breaches in its 2025 Data Breach Investigations Report.
- Stolen credentials accounted for 22% of breach entry points. Identity compromise remains one of the most common routes into organisations.
- Human error contributed to 60% of breaches. Trust, social engineering and human decision-making remain central to cyber risk.
- Gartner predicts 40% of enterprise applications are expected to include task-specific AI agents by the end of 2026, up from less than 5% in 2025. Agentic capability is moving into business systems quickly.
- Microsoft’s Agentic AI adoption maturity model positions enterprise-scale AI adoption as a strategy, governance and operating model challenge, not simply a technology deployment exercise.
The message is clear: organisations are no longer in a planning phase. Experimentation, deployment and execution are already underway, often moving faster than governance.
Executive implication
Most organisations already have employees experimenting with AI, teams evaluating agents and technology functions exploring automation opportunities.
The challenge is no longer whether AI will become part of the enterprise. The challenge is whether leadership teams can establish sufficient trust, governance and accountability before AI becomes embedded within critical workflows.
The organisations that succeed will not necessarily be those that adopt AI first. They will be those that can scale adoption with confidence.
The Condatis AI Adoption Sequence
Many AI programmes begin with capability. A new model is released, a new agent platform becomes available, or a new productivity feature captures executive attention. The conversation then quickly moves to deployment: where can this be used, which processes can be automated, and how quickly can the organisation scale adoption?
That sequence is understandable, but it puts the technology before the business decision.
At Condatis, we believe organisations need to follow a different sequence.
Outcomes
What business outcome is the organisation trying to improve?
Strategy
How should AI contribute to that outcome, which workflows should AI influence, where is AI genuinely appropriate and what security framework should we apply?
Governance
Change the color to match your brand or vision, add your logo and more.
Risk
What risks are introduced, and what level of autonomy is acceptable?
Technology
What technology solution best supports those decisions?
This order matters. Some workflows may be strong candidates for AI because they are repeatable, well understood and capable of being governed through clear controls. Others may involve judgement, regulation, customer trust or business risk that makes full automation inappropriate. AI strategy is therefore a critical part of risk and governance planning, but it should not be treated as a narrow technical assessment. It is part of a broader strategic decision about where AI should operate, what value it should create and how much autonomy the organisation is prepared to delegate.
Microsoft’s Agentic AI adoption maturity model points to this broader enterprise challenge. It describes the need to move beyond isolated experimentation and address strategy, process transformation, governance, value realisation, operations and responsible AI when scaling across the enterprise. Microsoft’s business strategy guidance for agentic AI places emphasis on redesigned processes, measurable business value and clarity over where agents act, what decisions agents can make and how humans remain in control.
The decision to adopt AI should therefore be driven by outcomes, strategy, governance and risk, not by technology capability alone.
“The real risk is not adopting AI. The real risk is adopting AI without a strategy for where it should operate, what outcomes it should improve and how it should be governed.”
Alasdair Murray, Chief Product and Technology Officer, Condatis
From assistance to action
For much of the last two years, enterprise AI adoption has centred on assistance. Summarising information, generating content, helping employees find answers and reducing the effort involved in everyday tasks. These use cases matter, but they are not the end state of AI transformation.
The direction of travel is towards AI systems that participate in business processes rather than merely support them. Microsoft describes the shift towards an agentic enterprise as a move from task-level automation to systems where apps and agents help organisations focus on outcomes rather than steps. Its agentic enterprise material describes a move from systems of record to systems of action, where intelligent systems influence how work is executed, owned and improved.
This shift changes the nature of the governance challenge. A system that helps a user write a report presents one type of risk. A system that can access customer information, update records, trigger workflows, approve requests or interact externally presents another. Once AI moves from assistance to action, the organisation must decide what authority has been delegated, what data informs the decision, which controls apply and who remains accountable for the outcome.
Those are not primarily model questions. They are trust questions.
The problem has always been trust
One of the most revealing aspects of recent AI security incidents is that the route to impact still depended heavily on trust relationships. The AISI report describes agents creating fake accounts, attempting to pressure administrators, sending targeted communications and pursuing actions that involved real people and public systems.
This should not be surprising. Security has always been concerned with trust: who can be trusted, under what conditions, with what access, and for what purpose. Identity establishes trust. Access governance controls trust. Privileged access management limits trust. Audit and assurance validate trust. Zero Trust architecture exists because organisations recognise that trust should not be assumed simply because a user, device, workload or system appears legitimate.
AI does not change those fundamentals. It changes the operating conditions around them.
An AI-enabled actor can process more information, identify more patterns, generate more persuasive interactions and adapt more quickly than a human working manually. The strategic risk is not that every organisation will immediately face autonomous AI-driven attacks. The strategic risk is that the speed of AI increasingly exposes weaknesses in trust, identity, access and governance models that were already under strain.
This is why AI security cannot be separated from identity and governance.
AI literacy also becomes part of the trust model.
The AISI incident was not simply a model or security failure. It showed how human decisions about agent permissions, autonomy and guardrails directly influence behaviour. Trusted AI needs informed humans, appropriate controls and ongoing accountability. AI literacy shapes how much freedom an agent is given. Identity controls determine what that agent can do. Governance determines whether those decisions remain accountable. Remove any one of the three and trusted AI becomes difficult to achieve.
Suggested literacy questions should include:
- Should the agent have internet access?
- Should it be able to create accounts?
- Should it be able to contact third parties?
- Should it be able to execute code?
- What level of autonomy is appropriate?
- What is the blast radius if it behaves unexpectedly?
The Condatis Trust Framework for AI
Trusted AI adoption requires more than a technology roadmap. It requires organisations to solve three connected governance challenges.
Every AI system needs access to something. It may need access to documents, applications, customer records, operational systems, collaboration tools, APIs, workflows or enterprise knowledge. As soon as access exists, identity becomes relevant.
Historically, identity programmes have focused on people; employees, partners, customers and administrators. Their purpose has been to establish who can access what, under which conditions, and with what level of accountability. AI extends this challenge to new populations: agents, workloads, services, bots and other non-human actors that may operate on behalf of users, teams or business processes.
This is where many organisations risk underestimating the change. An AI agent with excessive permissions is not simply a technical configuration issue. It is an authority issue. A non-human identity without a clear owner is not simply an operational gap. It is an accountability gap. An agent that can access sensitive information without appropriate controls is not simply a data issue. It is a trust issue.
As AI becomes embedded into operational workflows, organisations will need to answer questions that are already familiar from identity and access governance, but now apply them to new actors:
- What is this agent allowed to access?
- What actions can this workload perform?
- On whose behalf is the system acting?
- Who owns the risk?
- How are permissions reviewed?
- How is inappropriate access prevented?
- How is accountability demonstrated?
The more AI moves towards action, the more identity becomes the control plane through which trust is established and governed.
“AI does not reduce the importance of identity. It increases it.”
Alasdair Murray, Chief Product and Technology Officer, Condatis
The second governance challenge is strategic. Organisations need to determine where AI should influence work, which workflows are suitable for AI assistance or automation, what level of autonomy is appropriate and where human judgement should remain central.
Workflow analysis is therefore not a standalone technical assessment. It is part of AI strategy. A workflow may be suitable for AI if the outcome is clear, the process is well understood, the data sources are governed and the risks can be controlled. A workflow may be unsuitable for greater autonomy if it involves material judgement, sensitive customer impact, regulatory complexity or ambiguous accountability.
This is why AI strategy must start with business outcomes. Organisations should first understand the value they are trying to create, then assess which workflows can safely support that value through AI. AI adoption becomes credible when leaders can explain not only what technology is being deployed, but why a workflow is suitable, how autonomy is governed and how success will be measured.
Strategy also needs to address operating model impact. If AI changes who performs work, who approves decisions, who handles exceptions or who owns the outcome, then the organisation is not simply deploying a tool. It is changing how work is governed. That is why use case analysis should sit inside the strategy phase rather than being treated as an implementation checklist.
A mature strategy should answer four connected questions:
- Which outcomes are strategically important enough to improve with AI?
- Which workflows contribute most directly to those outcomes?
- Which parts of those workflows are suitable for AI assistance, automation or agentic execution?
- What authority, accountability and controls are required before AI is introduced?
This approach helps organisations avoid two common mistakes: deploying AI where it is technically possible but strategically weak, and avoiding AI where it could create genuine value because the organisation has not yet created the governance conditions for adoption.
There is another important dimension to AI adoption that is still underdeveloped in many executive conversations. Organisations are not only using AI to consume intelligence. They are also creating intelligence through the way people interact with AI systems.
The Reverse Information Paradox frames this clearly: in the AI age, firms may risk giving away proprietary knowledge in order to use the intelligence they have purchased. The article argues that prompts, corrections, traces, evaluations, feedback and institutional context all form part of the learning that can accumulate through AI use.
This matters because the value created through AI adoption is not limited to individual outputs. Every prompt, correction, workflow pattern, evaluation criterion and decision rule can capture something about how an organisation operates, what it values and how it makes decisions. Over time, this becomes a form of organisational intelligence.
That intelligence can become strategically valuable. It reflects institutional knowledge, operating context, judgement, expertise and competitive differentiation. In many cases, it may be difficult for competitors to replicate because it is not simply data. It is knowledge created through the interaction between people, processes and AI-enabled work.
This introduces an intellectual property and governance issue that organisations need to address before AI becomes deeply embedded into critical workflows. The question is not only what data AI can access. It is also what intelligence is being created, where that intelligence resides, who owns it, how it is protected and whether it compounds as an asset of the organisation.
This is where governance will need to evolve beyond traditional data governance. Organisations will still need to protect information, classify data and manage access. However, they will also need to govern the learning loop created by AI adoption: the prompts, evaluation criteria, workflow designs, feedback patterns, decisions and contextual knowledge that shape how AI performs inside the enterprise.
For many organisations, this will become a board-level issue because it touches risk, intellectual property, operational resilience and competitive advantage.
“Organisations will need to govern intelligence in the same way they govern data, because AI turns organisational knowledge into a strategic asset.”
Alasdair Murray, Chief Product and Technology Officer, Condatis
Proactive governance becomes essential
Traditional security operating models were largely designed around human speed. An event occurs, monitoring identifies something unusual, an analyst investigates and a response is initiated. Detection and response remain essential, but AI places pressure on this operating model because autonomous or semi-autonomous systems can take many actions before a human has the opportunity to intervene.
The AISI report is relevant here because it describes agents carrying out activity across multiple channels, including public infrastructure, external repositories and communications aimed at real people and organisations. The lesson is not that every organisation is about to experience the same scenario. The lesson is that AI increases the importance of preventing inappropriate authority, access and action before the event occurs.
This moves governance upstream. Organisations need to determine which workflows are appropriate for AI, what data and systems can be accessed, what level of autonomy is acceptable, what approvals are required and how actions will be monitored. Reactive controls remain important, but they should not be the primary line of defence when AI systems can operate quickly and continuously.
In an AI-enabled organisation, governance cannot be a retrospective compliance activity. It has to be designed into the strategy, into the workflow and into the identity model that controls who and what can act.
“The challenge for leadership teams is no longer deciding whether AI will be adopted. The challenge is deciding how much trust they are prepared to delegate.”
Alasdair Murray, Chief Product and Technology Officer, Condatis
Trust problems are already here
The trust challenges that AI will amplify are not theoretical. Condatis is already helping organisations strengthen the identity and access foundations required to deal with increasingly sophisticated identity-based risks.
Bridgepoint, a global investment firm, worked with Condatis to address identity-based attacks such as helpdesk impersonation. This case study details a solution using Microsoft Entra Verified ID, Face Check and Microsoft Authenticator to support secure, risk-based verification in high-risk support scenarios while maintaining a seamless user experience. The outcome was a more resilient identity framework designed to help protect investor trust, reduce impersonation-driven account compromise risk and support Bridgepoint’s continued growth.
The significance is that Bridgepoint did not solve this problem with a new category of AI security technology. The response was stronger identity assurance, stronger trust controls and better verification of who was requesting access in the first place.
The relevance to AI transformation is clear. Helpdesk impersonation is not a new threat, and identity-based attacks are not new threats. However, AI can increase the sophistication, volume and credibility of trust-based attacks. The response is not simply to buy an AI security product. The response is to strengthen the trust foundations that determine who can access what, how identity is verified and how higher-risk scenarios are governed.
The same principles that help defend organisations against identity-based threats today will become foundational to trusted AI adoption tomorrow.
The next constraint to AI adoption is trust
The technology sector often describes AI adoption as a race for capability. Larger models, better reasoning, more advanced agents and deeper platform integrations are all important. However, enterprise transformation is rarely constrained by technology alone.
Cloud adoption accelerated when organisations developed confidence in security, governance and operating models. Digital transformation accelerated when organisations learned how to manage risk, data and customer trust in online environments. AI is likely to follow a similar pattern.
The next constraint to AI adoption is unlikely to be whether the technology can perform a task. It is more likely to be whether organisations trust AI enough to let it influence important workflows, decisions and outcomes.
Trust will depend on whether organisations can answer a small number of difficult questions:
- Are we applying AI to the right business outcomes?
- Do we have a clear strategy for where AI should operate?
- Do we understand which workflows are suitable for AI?
- Have we defined the right level of autonomy?
- Is access controlled?
- Is authority explicit?
- Is accountability maintained?
- Is organisational intelligence protected?
Organisations that can answer these questions will be better positioned to move from experimentation to scale. Organisations that cannot may continue to accumulate pilots, tools and proofs of concept without building the confidence required for operational adoption.
The Condatis view
Our view is that AI transformation should not begin with a technology decision. It should begin with a clear understanding of the outcomes an organisation wants to improve, the strategy for how AI should contribute to those outcomes and the risks created when workflows become AI-assisted or AI-driven.
Technology matters, but it should come later in the decision sequence. Before selecting models or agents, organisations need to decide where AI should operate, what authority should be delegated, what controls are required and how accountability will be maintained. They will also need to understand how AI-enabled workflows create organisational intelligence and how that intelligence will be governed as a strategic asset.
This is the point at which identity, AI strategy and intelligence governance become central to transformation. Identity governs who and what can act. Strategy determines where AI should operate and which workflows are suitable. Governance ensures the right controls, accountability and oversight are in place. Intelligence governance protects the organisational knowledge created through AI adoption.
That is why AI security is not just a model problem. It is a trust problem.
The Future of AI Will Be Defined by Trust
Recent AI security incidents have attracted attention because they appear novel. In reality, they reinforce a familiar lesson: trust, identity and governance matter more than ever. The threats are not new. What has changed is the speed, scale and autonomy with which they can operate. The AISI report shows AI agents engaging in unsanctioned activity on the live internet, including activity directed at real people and organisations, with behaviours including fake identities, social engineering, supply-chain manipulation and attempts to influence human decision-making.
The important point for executives is that this is no longer a theoretical planning exercise. AI adoption is already happening across organisations. Experimentation is already underway. Employees are already using AI tools. Business teams are already looking for productivity gains. Technology teams are already exploring agents and automation. In most cases, execution is moving faster than governance.
That speed imperative is real. Organisations cannot respond by slowing everything down until the perfect operating model exists, but nor can they allow AI adoption to run ahead of strategy, risk management and control. The organisations that realise the greatest value from AI will not be those that deploy the most agents or move fastest without guardrails. They will be those that move quickly with clarity: identifying the right business outcomes, defining the right AI strategy, applying AI to the right workflows and establishing the governance required to operate safely at scale.
The conversation should not start with models or agents. It should start with outcomes. Which business outcomes should AI improve? Which workflows should AI influence? Which decisions should remain human? Where is automation appropriate? What risks are acceptable? What governance is required?
Only then should technology choices be made.
As AI becomes embedded into business operations, organisations must govern more than access and actions. They must also govern the intelligence created through AI-enabled workflows. The knowledge, decisions, context and learning accumulated through AI will increasingly become a source of competitive advantage and a form of intellectual property requiring the same level of protection and stewardship as any other strategic asset. The Reverse Information Paradox makes this point clearly: in the AI era, prompts, corrections, traces, evaluations, feedback and institutional context all become part of the learning organisations create through AI use.
The future of AI will not be constrained by technology. It will be constrained by trust. Organisations need to move quickly, but they need to move deliberately. Start with outcomes, define the strategy, govern the workflow, understand the risk and then choose the technology. Trust starts with identity, but it must extend across the workflows, decisions and organisational intelligence that AI will increasingly shape.
“The future of AI will not be constrained by technology. It will be constrained by trust. The organisations that move fastest will not be those that skip governance, but those that build enough trust to scale AI with confidence.”
How Condatis Can Help
Our view is not that organisations should slow down AI adoption. The speed imperative is real, and the organisations that wait too long risk falling behind. The issue is that speed without trust creates unmanaged risk. The priority is to move quickly with a clear strategy, strong identity foundations, appropriate workflow governance and a practical understanding of where accountability sits.
Condatis helps organisations move beyond AI experimentation and towards trusted adoption. We help leaders define where AI can create meaningful business value, shape the strategy for where AI should operate, assess which workflows are suitable for AI assistance or automation, establish the identity and governance foundations required for safe adoption, and protect the organisational intelligence created through AI-enabled transformation.
Our work with Bridgepoint shows how modern identity and access management can address trust-based threats in practice. By introducing secure, risk-based verification using Microsoft Entra Verified ID, Face Check and Microsoft Authenticator, Condatis helped Bridgepoint strengthen identity assurance in high-risk support scenarios while maintaining a seamless user experience.
As AI increases the speed, scale and sophistication of trust-based risk, organisations will need identity and access governance that can protect people, systems, workflows and non-human actors. The foundations that help defend against identity-based threats today will increasingly become the foundations for trusted AI adoption tomorrow.
Successful AI adoption is not about deploying more technology. It is about creating more value, with the trust required to sustain it.
Sources and Further Reading
UK AI Security Institute – Security Incident
This report provides the incident evidence referenced in this article, including AI agents engaging in unsanctioned activity on the live internet and activity directed at real people and organisations.
Introduction to the Agentic AI adoption maturity model
This guidance describes the move from AI experimentation to enterprise-scale adoption, including strategy, process transformation, governance, responsible AI and measurable business value.
Agentic AI maturity model
This source supports the emphasis on reimagining how work gets done, ensuring agents deliver measurable business value and clarifying where agents act, what decisions agents make and how humans stay in control.
Build an Agentic Enterprise with AI Agents and Copilot
This source supports the discussion of the shift from systems of record to systems of action, and the need for trust, governance and security as agents become embedded into workflows.
The Reverse Information Paradox
This article supports the argument that AI adoption creates organisational intelligence through prompts, corrections, traces, evaluations, feedback and institutional context, raising governance and intellectual property questions.
Bridgepoint: Strengthening Identity Security
This case study demonstrates how Condatis helped Bridgepoint strengthen identity security against identity-based attacks such as helpdesk impersonation using Microsoft Entra Verified ID, Face Check and Microsoft Authenticator.
Stay Ahead of Identity, Security & AI Governance
Practical insights, real-world experiences, new research, and exclusive event invitations from the identity specialists helping organisations navigate transformation with confidence.









