AI Security & Governance Notes

AI is moving into production faster than most companies can govern or secure it. The old controls no longer fit what these systems can now do.
In this series, I share short, evidenced notes on what it takes to secure and govern AI in production.

The risk of catastrophic harm from AI remains, despite the countermeasures.
MIT's June 2026 Delphi study of 272 experts finds the risk of catastrophic harm from AI remains despite countermeasures: five of 24 domains hold at 1 in 10 or worse by 2030. Until governance instruments exist, the control gap sits with deployers.
The control is not the deliverable.
Most AI frameworks hand organizations a list of controls and stop there. A recent CSET reference guide traces every control back to the principle it implements, and that lineage, not the checklist, is what survives diligence.
Adoption Is Outrunning Control.
Incidents up 55%, response confidence down, and most organizations still integrating governance practices rather than operating them.
Governance is part of rebuilding around AI, not a layer on top.
The organizations pulling ahead didn't bolt AI onto existing workflows; they rebuilt around it. Governance added on top doesn't survive a system that runs the business.
From Possible Threats to Production Incidents.
Only 37% of organizations have policies to manage AI or detect Shadow AI. What OWASP's latest report means once agents start acting on production systems, and why insurers are now paying attention.
Mathieu Flamant
Founder · Tech Leader · mathieuflamant.com