No more ‘No’ for security teams

AI security governance
For years, security teams have been perceived as one of the most risk-averse functions in the organisation, and it comes with the territory. With every new application, new cloud service, new technology, there’s a security review. The image of security professionals responding with a cautious “not yet” or “have you considered the risks?” has become so familiar that it is almost accepted as part of the job. 
 
Security teams developed those processes because they reflected the technology landscape they were operating in. Infrastructure changed at a manageable pace, software releases followed relatively predictable cycles, and governance could be built around formal checkpoints before systems reached production. Restriction was rarely the objective, it’s been about managing risk.
 
The challenge is that AI has fundamentally changed the assumptions that made those operating models effective. Much of the discussion around AI governance assumes that security simply needs to catch up. New policies need writing, new frameworks need adopting and new controls need implementing. Those things certainly matter, but I believe they miss a more significant shift. 

The challenge of ‘in the moment’ innovation

Security is no longer operating in an environment where governance can be based primarily on reviewing decisions before they happen. AI has accelerated experimentation to the point where that model is becoming increasingly difficult to sustain. Developers can generate production-ready code in minutes, platform teams are creating infrastructure dynamically, and business functions are building AI-powered workflows without waiting for central technology teams.
 
The implications go well beyond productivity. Starbucks recently announced it is replacing Microsoft and IBM systems with AI-assisted software it is building itself to reduce software costs. As the economics of enterprise software shift, more organisations will decide to build rather than buy, creating far more internal applications, AI agents and cloud services for security teams to govern.
 
For security teams, new protocols and integrations appear almost weekly. The gap between an idea, an experiment and a live deployment has narrowed dramatically. Governance hasn’t become less important, far from it. If anything, the opposite is true. What has changed is the way governance needs to work. 

Slowing innovation doesn’t equal control

One of the biggest risks I see organisations creating is assuming that slowing innovation provides greater control. In practice, the relationship is rarely that straightforward. When security processes cannot move at the pace the organisation expects, people naturally look for alternatives. They experiment using personal accounts, procure AI services directly or connect models without involving security until much later. 
 
This is why visibility has become one of the defining challenges of AI security. The question security leaders increasingly need to answer is not whether AI should be used, but where it is already being used, what data it can access and whether its behaviour introduces an unacceptable level of risk. Those answers cannot come from occasional reviews or lengthy approval processes, they depend on continuous awareness of an environment that is changing every day.

A different way of thinking about risk

Not every AI deployment deserves the same response. A developer using a coding assistant presents a different challenge from an autonomous agent making infrastructure changes. An internal productivity tool summarising meeting notes is fundamentally different from a customer-facing application interacting with sensitive data or making operational decisions. Treating every use case as equally risky often creates unnecessary friction while diverting attention away from the scenarios that genuinely require close scrutiny.

The phrase "security saying no" has always been an oversimplification. Today's challenge runs deeper than that. Security's role is evolving from controlling every technology decision to providing the insight, confidence and flexibility that allow organisations to embrace AI without losing sight of risk.

Context becomes far more valuable than blanket restrictions. Understanding identities, cloud assets, data exposure, application behaviour and the relationships between them allows security teams to prioritise the issues that carry meaningful business risk. Without that context, everything starts to look equally urgent, and decision-making inevitably slows.

A change in role of the security leader

For many years, security teams have been expected to review technology decisions made elsewhere in the organisation. Increasingly, they need to shape how those decisions are made from the outset. That means working much more closely with developers, platform engineers and business teams, understanding how AI is being adopted and designing security practices that complement modern engineering rather than interrupting it.
 
The conversation becomes less about approving individual technologies and more about creating environments where experimentation can happen safely. That is a subtle distinction, but an important one. AI adoption is not a single programme with a defined start and finish. It is becoming embedded across software development, cloud operations, customer service and business productivity simultaneously. Security therefore needs to operate as a continuous capability rather than a series of approval gates.

Security tools need to be adaptable

Engineering teams increasingly expect security to integrate into the workflows they already use. Infrastructure is managed through code, deployment pipelines are heavily automated and operational decisions are becoming increasingly data-driven. As AI becomes another layer within those environments, security tools need to become equally adaptable.
 
Some organisations will want to integrate security intelligence directly into internal developer platforms. Others will automate routine investigations using AI agents or incorporate security decisions into cloud workflows. Many are exploring how different AI models can support different operational tasks depending on the problem they are trying to solve. That diversity is unlikely to disappear, and if anything, it will increase as AI capabilities continue to evolve.
 
This has important implications for security platforms. Flexibility is becoming just as valuable as functionality. Security teams should be able to work with the models and workflows that best suit their environment, rather than restructuring their operating model around the limitations of a particular tool. As organisations continue building their own AI capabilities, security needs to fit naturally alongside them, integrating into existing processes rather than introducing entirely separate ones.

Beyond the tools

That principle extends beyond technology. Security teams themselves are evolving. The skills required to succeed increasingly combine technical expertise with an understanding of cloud architecture, software engineering, AI systems and business priorities. Security leaders are spending more time helping organisations navigate change than enforcing static rules. Their influence comes from enabling informed decisions and meaningful context, rather than relying solely on formal governance processes.
 
None of this suggests that security has become easier, it’s actually quite the opposite. The pace of change, the volume of experimentation and the complexity of modern cloud environments make today’s challenges considerably more demanding than those of even a few years ago. Yet responding by adding more approval stages or insisting on greater central control is unlikely to provide the outcomes organisations are looking for.

Gatekeeping versus governance

AI is changing how software is built, how infrastructure is managed and how employees interact with technology. Security cannot remain tied to operating models designed for a much slower world. Governance still matters, but it increasingly depends on continuous visibility, contextual understanding and the ability to integrate security into the way modern teams already work.
 
The phrase “security saying no” has always been an oversimplification. Today’s challenge runs deeper than that. Security’s role is evolving from controlling every technology decision to providing the insight, confidence and flexibility that allow organisations to embrace AI without losing sight of risk. As AI becomes embedded in almost every aspect of the enterprise, that shift in mindset may prove to be one of the most significant changes the security profession has faced in decades.
Gil Geron is CEO & Co-founder of Orca Security

Gil Geron

Gil Geron is CEO & Co-founder of Orca Security. Gil has more than 20 years of experience leading and delivering cybersecurity products. Previous to his role as CEO, Gil was chief product officer from the inception of Orca. Prior to co-founding Orca Security, Gil directed a large team of cyber professionals at Check Point Software Technologies.

Author

Scroll to Top

SUBSCRIBE

SUBSCRIBE