Guides

AI Security Governance: From Tool Inventory to Verified Operation

Most AI governance begins with an inventory and ends with a policy. Both are necessary. Neither shows whether the organisation's controls are operating.

Operating guideDocument v3.12 min read

Most AI governance begins with an inventory and ends with a policy. Both are necessary. Neither shows whether the organisation's controls are operating.

IO treats AI governance as a continuous operating system across Govern, Map, Measure and Manage, borrowing the NIST AI RMF structure while adding explicit execution and verification records.

1. Govern

Define accountable owners, approved uses, data restrictions, model and vendor requirements, exception criteria, review cadence and escalation paths. Align the management-system structure to ISO/IEC 42001 where appropriate.

IO evidence: current policy version, owner, approval, attestation currency, exception owner and expiry, and the rule cited by each finding.

Boundary: IO can show that governance was enacted. It cannot determine that the policy is legally sufficient or certify ISO conformity.

2. Map

Map not only named AI applications but their access modes and relationships:

  • browser and desktop applications;
  • APIs and developer tools;
  • public and private plugins;
  • connected applications and service accounts;
  • AI embedded inside existing SaaS; and
  • models, agents, data sources, retrieval stores and subprocessors.

The sanctioned, tolerated and unsanctioned taxonomy in Palo Alto Networks' C-suite guide is a practical discovery aid. IO adds two fields: what data and authority the use can reach, and what behaviour was actually observed.

3. Measure

Classification is not effectiveness. For each material rule, define an observable measure before intervention, for example, restricted-data submissions to unsanctioned tools per active user, over a stable window. Capture the baseline when accountable work is accepted and re-measure from the same source.

The result is Verified, Unverified, Regressed or Inconclusive. Pending remains a state, not a result.

4. Manage

Route findings by risk and confidence. Low-risk and reversible actions may be automated after a sufficient verified history. Novel, high-impact or low-confidence actions require human approval. Every exception expires or is reviewed; every regressed intervention re-enters governance.

Threat conditions that change the priority

CrowdStrike's 2026 threat report describes faster intrusions, extensive malware-free activity, valid-account abuse and adversaries exploiting trusted SaaS, cloud and software relationships. These are vendor telemetry findings, not universal base rates. Their significance for IO is methodological: when attackers operate through authorised pathways, presence of an approved tool or valid credential cannot be treated as evidence of safe behaviour. Identity, data access, agent permissions and anomalous use become measurement targets.

Minimum executive view

Report these together:

  1. observed AI services and material data flows;
  2. sanctioned, tolerated, unsanctioned and unclassified population;
  3. rules with measurable enforcement versus policy-only coverage;
  4. verification coverage and result distribution;
  5. active exceptions and approaching expiries; and
  6. autonomous actions by risk tier, including overrides and regressions.

References

Next step

See it before you talk to anyone.

Two quarters of recorded activity across sixteen seats. One click, no install.