
In April of this year, a longtime customer located on Massachusetts’ South Shore announced they were going to use newly licensed ChatGPT to bolster their governance documentation. Following a recent program review, it was recommended that, given our familiarity with their organization’s practices, the Consulting team at K logix assist with the lift. Despite a trusted partnership, the decision was made to use artificial intelligence (AI) to update and create policies and procedures in alignment with security processes.
Why ChatGPT Couldn't Write the Policies
Come June, the customer sent a note requesting a discussion. As it turns out, the organization’s process documentation was not strong enough for ChatGPT to perform its tasks as efficiently or effectively as desired. With gaps in documentation, versioning inconsistencies, and difficulty garnering stakeholder input, the customer found that using an AI agent for this task required more manual involvement than anticipated. In the end, they concluded it was best for a consultant to assume oversight of the project.
The push toward AI adoption has accelerated rapidly, with business and security leaders alike eager to automate workflows, improve efficiency, and control costs. With AI at the top of everyone's mind, it’s easy to get carried away and try to implement before strategizing; after all, you need to give that AI update to the board! But an organization’s use of AI is only as good as the organization’s foundation. If there’s nothing for the agent to draw from, it cannot tailor its outputs in the manner necessary to realize its efficiency, which then requires more manual intervention from you than a simple review.
We spoke to K logix Cyber Risk Consulting Senior Manager, Sydney Gelb, who specializes in Governance, Risk, and Compliance, a space that is taking a new form with the rise of AI.
“It’s important to be methodical with AI. There’s an element of readiness that is required of an organization prior to its implementation. Do you know where your data sits? When was the last time you updated your SDLC process documentation? Have you thought about the risks you’re introducing by allowing an AI agent access to ‘x’ environment? These are the types of questions that need to be asked before you go in and start building a network of agents.”
Establishing proper AI governance is the key here. It ensures these questions are answered, policies are formalized, and oversight is in place when the organization begins its journey toward agentic AI.
“While the formalization of AI governance seems daunting at face value, there are existing security capabilities that can be built upon. For example, data governance programs allow an organization insight into the whereabouts of its most sensitive data, thereby enabling it to block AI from gaining access or to provide access to internal stakeholders only with the proper permissions.”
The question then becomes: where do I start? Between defining charters and governance documentation, enhancing strategic objectives, and identifying areas where AI agents should be utilized, the idea of building out an AI governance program can be a choking hazard to tackle in one bite.
“As with security programs, alignment to an industry-standard framework is key. Using available tools like the NIST AI RMF or ISO 42001, or even state legislation like the Colorado AI Act, can help an organization understand and prioritize areas of focus to maintain security while instituting new technologies.”
Remember, the emphasis here is on building and maintaining a strong foundation. While these frameworks may not eliminate every challenge associated with AI adoption, they provide concrete guidance for structuring an AI program with the proper resources, lifecycle considerations, and stakeholder relationships.
Conclusion
So, you want to use AI to revamp your policy deck. The onus is on your organization to create a structured, well-supported approach to AI adoption that allows for more seamless integration. Keep in mind, too, that most organizations are still green when it comes to AI. On most days, it can feel like time-to-implementation is running out; take a step back and measure your organization against what it takes to execute productively. Opportunities for AI inclusion in everyday workflows and processes are everywhere, but are you prepared to take advantage of them?