Cybersecurity News

Filters
Tag
Reset

Filtered by tag: ai governance × Clear

Why "I approve" can become the most dangerous button in enterprise AI

Enterprises rushing to deploy autonomous AI agents risk creating accountability gaps when humans shift from active decision-makers to passive reviewers. Approval workflows can become meaningless rituals as alert volumes rise. AI agents acting on networks need governed identities, bounded permissions, and audit trails explaining not just actions but reasoning. Multi-agent chains compound traceability problems. Organizations should expand agent autonomy gradually, like junior employees earning access, backed by proper identity and observability infrastructure.

NCSC Urges Stronger Controls for Agentic AI Systems

The UK's National Cyber Security Centre has warned that agentic AI systems — which can plan and execute tasks autonomously — introduce significant security risks. The NCSC recommends organisations apply strict access controls, sandbox AI agents to limit their reach, maintain human oversight, and carefully vet the tools and data agents can access, to reduce risks from errors, manipulation or misuse.

AI vendor dependency is becoming a resilience risk

Enterprises increasingly rely on a small number of AI vendors, creating significant resilience risks if those services fail, change pricing, or shut down. Experts warn that organizations must build governance frameworks and contingency strategies into AI planning from the start, rather than treating vendor dependency as an afterthought, to ensure long-term stability and operational continuity.

Op-Ed: Australian AI agents need expiration dates, not just permissions

Matched: Australia

Australia's AI governance debate is shifting from whether to deploy AI agents to how to govern them once active. Experts argue current permission-based frameworks are insufficient, proposing AI agents be given expiration dates — automatic deactivation after set periods — rather than relying solely on access controls. This would limit risk from forgotten or compromised agents operating indefinitely within sensitive systems.

AI needs rules and rails: Why governance must move beyond policy

As AI adoption accelerates, organizations need more than high-level policy — they need practical operational guardrails. Governance must translate abstract principles into enforceable standards covering data use, model accountability, and risk management. Without structured frameworks embedded into workflows, AI systems risk drifting from business objectives, creating compliance gaps and unintended consequences. Effective governance requires collaboration across technical, legal, and business teams.

Securing adoption in the era of shadow AI

Organizations face growing risks from "shadow AI" — unauthorized AI tools employees use without IT oversight. To address this, companies should establish clear AI usage policies, create approved tool inventories, and implement monitoring. Balancing restriction with enablement is key; overly rigid controls drive workarounds. Security teams should engage employees, offer sanctioned alternatives, and build governance frameworks that allow responsible AI adoption at scale.

Australia’s use of AI is growing faster than its foundations

Matched: Australia

Australia's AI adoption and spending are increasing rapidly, but the country risks undermining its returns by neglecting foundational elements. Experts warn that gaps in data quality, governance frameworks and clear accountability structures could limit AI's effectiveness. Without addressing these underlying issues, organisations may struggle to realise the full benefits of their AI investments despite growing enthusiasm for the technology.

What Our AI SOC Analyst Can Do (and What We Won’t Let It Do)

Huntress has introduced an AI SOC analyst called Athena that can autonomously investigate security threats and take actions, but operates within boundaries defined by human analysts. The system is designed to handle routine security operations work while keeping humans in control of key decisions, illustrating how the company is approaching governance around agentic AI in cybersecurity contexts.