AI Security & Governance Notes

AI is moving into production faster than most companies can govern or secure it. The old controls no longer fit what these systems can now do.
In this series, I share short, evidenced notes on what it takes to secure and govern AI in production.

Slow approval processes drive AI tools past the company's security review.
Stanford examined 51 enterprise AI deployments across 41 organizations. Where the sanctioned path arrived after the adoption mandate, unapproved tools filled the gap. Where the control function was engaged early, it produced the architecture instead.
The diligence surface does not end where confidentiality begins.
A proposed self-regulatory body for frontier AI would take the labs building the models as members and receive every final audit report confidentially. Google's governance framework leaves the institutions deploying those models outside both. What remains is published by design, and it is more specific than most vendor questionnaires ask for.
Consumption moves the dependency, not the accountability.
Google's agent interoperability paper makes the same recommendation across five protocols: consume rather than build. Tool servers, remote agents, component catalogs, and payment paths leave the perimeter, and none of them look like AI assets in an inventory built around models.
The Firewall Got There First.
Nineteen unsanctioned events across 122 evaluation attempts, detected by commercial network monitoring rather than by anything built to watch the agents. The controls that did the work were ordinary ones, and containment rested on someone outside the organisation.
Confidence Is Not Coverage.
Schellman's 2026 State of AI Governance survey finds an AI incident or near miss at 65% of organizations and a documented response procedure at 44%. Funding is near universal and maturity is not. Where the gap sits, and what closes it.
Adoption rate is not a governance signal.
Deloitte's Trustworthy AI Governance Index scores banks from ad hoc to optimised. Weekly AI usage is identical at both ends. What separates them is not how much AI is in use, but whether anyone can see it.
The risk of catastrophic harm from AI remains, despite the countermeasures.
MIT's June 2026 Delphi study of 272 experts finds the risk of catastrophic harm from AI remains despite countermeasures: five of 24 domains hold at 1 in 10 or worse by 2030. Until governance instruments exist, the control gap sits with deployers.
The control is not the deliverable.
Most AI frameworks hand organizations a list of controls and stop there. A recent CSET reference guide traces every control back to the principle it implements, and that lineage, not the checklist, is what survives diligence.
Adoption Is Outrunning Control.
Incidents up 55%, response confidence down, and most organizations still integrating governance practices rather than operating them.
Governance is part of rebuilding around AI, not a layer on top.
The organizations pulling ahead didn't bolt AI onto existing workflows; they rebuilt around it. Governance added on top doesn't survive a system that runs the business.
From Possible Threats to Production Incidents.
Only 37% of organizations have policies to manage AI or detect Shadow AI. What OWASP's latest report means once agents start acting on production systems, and why insurers are now paying attention.
Mathieu Flamant
Founder · Tech Leader · mathieuflamant.com