RSS Amplifier

Command Line with Camille · Jun 17, 2026

The AI Business Case Security Leaders Are Missing

0
Sign in to vote or save

Camille Stewart Gloster · Command Line with Camille

At a recent AI security event, much of the conversation focused on familiar topics: vulnerability discovery, patch management, model evaluations, governance controls, human oversight, and training. The discussion was thoughtful, practical, and technically rigorous. Yet as I listened, I found myself returning to a different question.

Why are organizations investing in AI in the first place?

The answer is not improved vulnerability management. It is not more governance reviews or additional compliance processes. Organizations are investing because they expect improvements in productivity, decision quality, customer experience, operational efficiency, and growth. They are investing because they believe AI can help them create value.

That distinction may seem obvious, but it reveals a growing disconnect in how many security leaders communicate their value. For years, security organizations have justified investment primarily through the language of risk reduction. Threats were increasing, attack surfaces were expanding, and stronger controls were needed to prevent negative outcomes. Those arguments remain valid, but they are becoming increasingly incomplete.

Framing security primarily through the lens of risk reduction has often made it difficult to connect security investments to growth, productivity, innovation, or business performance. As organizations accelerate AI adoption, many security teams are being asked to support new use cases, new technologies, and new operating models without a corresponding shift in how their value is understood or funded.

As AI becomes embedded in business operations, security’s contribution extends beyond preventing failure. It increasingly influences whether organizations can deploy new capabilities with confidence, scale them effectively, maintain control as systems become more autonomous, and adapt as technology evolves. The conversation is shifting from protection alone toward performance, reliability, and adaptability.

The business case has changed, even if many of the conversations have not.

When executives discuss obstacles to AI adoption, they rarely begin with vulnerabilities.

Instead, they raise questions about usability, ROI, trust, accountability, reliability, customer impact, regulatory obligations, employee adoption, and operational resilience. They want to understand whether AI will create measurable value, whether employees and customers will trust it, who remains accountable when systems influence outcomes, and how errors will be detected. The most forward-looking leaders are also asking a broader question: do we have the organizational capabilities necessary to adapt as the technology, the risks, and the opportunities continue to evolve?

These concerns are often categorized separately from security, yet they frequently determine whether AI initiatives succeed or stall.

An organization can have access to the most advanced models available and still struggle to create meaningful value if employees do not trust the outputs, if managers lack confidence in AI-enabled workflows, if leaders cannot determine who remains accountable for decisions, or if customers lose confidence in automated interactions. In many cases, the technology performs exactly as expected while the organization around it struggles to adapt.

This helps explain why so many promising pilot projects fail to scale. The technical capability exists, but the supporting systems of governance, accountability, training, trust, and operational oversight have not evolved quickly enough to support enterprise deployment.

Technology enables adoption. Organizational capability determines whether adoption scales.

One reason security leaders sometimes struggle to communicate value is that security teams and executive teams often operate at different levels of abstraction.

Security professionals naturally focus on mechanisms. They discuss access controls, identity systems, monitoring architectures, model evaluations, vulnerability management, and detection capabilities because those tools help reduce uncertainty and improve outcomes.

Executives are focused on outcomes. They want to know whether a customer-facing AI assistant can be deployed safely. They want to know whether software development can accelerate without introducing unacceptable quality risks. They want to know whether operational workflows can be automated while preserving accountability and reliability. The distinction matters because the same investment can be described in very different ways.

Continuous model monitoring may appear to a security team as a mechanism for identifying drift, misuse, or emerging vulnerabilities. An executive team is more likely to evaluate that same capability in terms of deployment confidence, operational reliability, regulatory readiness, and the speed at which new AI-enabled products can reach customers.

Neither perspective is wrong. The challenge is that security leaders often communicate investments through the language of controls while executives evaluate investments through the language of business outcomes.

To be fair, this is not solely a communication problem. For years, many organizations viewed security primarily through the lens of risk avoidance, compliance obligations, and incident prevention. Executive perceptions of security were often shaped less by its contribution to business performance and more by its visibility during audits, budget discussions, or major incidents. Even security leaders who successfully communicated the broader value of their work frequently struggled to influence those perceptions because security’s impact was often most visible when something went wrong.

AI changes that dynamic because the connection between security, governance, and business performance becomes much more direct. Decisions about monitoring, authorization, intervention, resilience, and oversight increasingly influence whether organizations can deploy AI capabilities at scale, accelerate adoption, maintain trust, and realize return on investment. The conversation is no longer limited to preventing bad outcomes. It increasingly shapes the organization’s ability to achieve positive ones.

This distinction becomes particularly important as organizations scale AI adoption. Without sufficient monitoring, guardrails, and oversight mechanisms, leaders often compensate by introducing manual reviews, additional approvals, and increasingly restrictive governance processes. While those measures may reduce uncertainty in the short term, they frequently slow deployment, limit experimentation, and reduce the value organizations hoped to achieve.

Well-designed security and governance capabilities create the confidence necessary to move faster without sacrificing control.

As AI adoption accelerates, bridging that gap becomes increasingly important.

One of the most significant shifts introduced by AI is that governance and security can no longer be treated primarily as implementation exercises.

Organizations frequently invest substantial effort in establishing policies, governance committees, review processes, approval mechanisms, and control frameworks. These activities are necessary and often create the foundation for responsible adoption.

The challenge is that the environment continues changing long after implementation is complete.

Models improve. Vendors introduce new capabilities. Employees discover new workflows. Business priorities shift. New integrations emerge. Data flows expand. Regulatory expectations evolve. Permissions accumulate. Assumptions that seemed reasonable six months ago become less reliable over time.

Security professionals have confronted versions of this problem for years. Identity permissions require periodic review because access expands over time. Third-party risks evolve after vendors are approved. Network architectures change. Software dependencies change. Controls that once aligned with operational reality gradually become less effective as organizations evolve.

AI accelerates this dynamic because both the technology and the workflows surrounding it are changing simultaneously.

Unlike many previous technology transformations, AI systems increasingly participate in decision-making, workflow execution, content generation, research, and operational processes. Organizations are no longer managing software alone. They are managing evolving relationships among people, systems, authority, accountability, and execution. That shift increases the importance of governance, oversight, and adaptation because the technology itself is becoming a more active participant in organizational outcomes.

The question is no longer whether an organization has implemented controls. The more important question is whether it possesses the capability to continuously evaluate assumptions, monitor changing conditions, adapt controls, and maintain alignment between technology, operations, and business objectives.

This is one reason I have argued previously that governance should be understood as a capability rather than a control function. Policies, committees, and frameworks matter, but their value ultimately depends on an organization’s ability to continuously adapt them as conditions change.

Organizations often budget heavily for implementation and lightly for maintenance. Yet value is realized over time, not at launch.

The capabilities that sustain trust, reliability, accountability, and adaptability are therefore not ancillary costs. They are part of the infrastructure required to preserve return on investment.

The 2024 CrowdStrike outage offers a useful illustration of this broader challenge.

Much of the public discussion focused on the technical cause of the incident, which was traced to a flawed update. CrowdStrike’s own Root Cause Analysis and Remediation Report provides a detailed explanation of both the technical failures and the corrective actions that followed.

Yet the most important lessons extended beyond software quality.

Organizations around the world experienced disruption because modern enterprises depend on interconnected systems that support critical business functions. The organizations that navigated the incident most effectively were often those with strong resilience capabilities, clear escalation paths, effective communication mechanisms, tested response procedures, and leadership teams capable of making rapid decisions under pressure.

Capabilities such as security, governance, operational resilience, business continuity, and crisis management are often discussed as separate disciplines. From an organizational perspective, however, they contribute to a shared objective: maintaining reliable performance when conditions change unexpectedly.

AI introduces a similar challenge. As systems become more capable and more deeply integrated into business operations, organizations increasingly need the ability to understand what those systems can do, establish appropriate boundaries, monitor outcomes, intervene when circumstances change, and continuously adjust as new information emerges.

Historically, governance and security were often treated as distinct disciplines. Governance established policies, decision rights, responsibilities, accountability structures, and oversight mechanisms. Security implemented technical controls designed to protect systems, applications, networks, and data.

As AI becomes more autonomous, that distinction becomes less clear.

Organizations do not maintain control over delegated authority through policy documents alone. They increasingly rely on identity systems, authorization frameworks, monitoring capabilities, audit trails, runtime controls, intervention mechanisms, evidence generation, and escalation workflows. Many of the capabilities that allow organizations to govern AI systems in practice are implemented through security tooling and security expertise.

This does not mean governance becomes a security function. Governance remains a broader organizational capability that spans leadership, legal, compliance, operations, risk management, and business decision-making. It does mean that security increasingly provides the infrastructure through which governance objectives are translated into operational reality.

Governing systems focuses on what organizations permit technology to do. Governing within systems focuses on how authority, accountability, intervention, and oversight are exercised once technology becomes an active participant in organizational workflows.

That distinction becomes particularly important as organizations move from governing systems to governing within systems. Many of the mechanisms that make that possible, including visibility, authorization, monitoring, intervention, and evidence generation, are capabilities traditionally associated with security.

One of the most important implications of AI is that security increasingly becomes a shared responsibility, not because security teams are less important, but because more decisions with security implications are being made outside the traditional boundaries of the security function.

Model selection decisions influence risk. Procurement choices influence risk. Workflow design influences risk. Data governance practices influence risk. Product decisions, user experience decisions, and operational deployment decisions increasingly influence security outcomes.

As AI becomes embedded across organizations, security outcomes are shaped by a broader set of actors than ever before.

This is one reason organizations may need to rethink who participates in security conversations. In a previous article on threat modeling, I argued that risk is often shaped long before a vulnerability is discovered or an incident occurs. AI amplifies that reality because many of the decisions that determine security outcomes are made during product design, workflow development, procurement, implementation, and business planning.

Expanding participation in activities such as threat modeling can help organizations surface assumptions earlier, identify risks before they become operational problems, and create shared ownership of outcomes across technical and non-technical teams.

Distributed responsibility does not eliminate the need for centralized capability. In many organizations, security remains responsible for establishing common standards, maintaining shared visibility, providing technical expertise, and operating the infrastructure that enables consistent governance across business units. As AI becomes more deeply embedded in organizational workflows, those shared capabilities become more important, not less.

Several months ago, in Security Is Performance, I argued that security should be viewed as a function that enables organizational outcomes rather than merely preventing negative ones. In The Governance Gap, I argued that governance is best understood as an organizational capability that aligns authority, accountability, and decision-making.

Organizations are beginning to deploy systems that generate content, influence decisions, conduct research, write software, interact with customers, and coordinate workflows. As those systems become more capable, leaders must determine how authority should be distributed, how accountability should be maintained, and how intervention should occur when conditions change.

The objective is not unrestricted autonomy. The objective is creating sufficient visibility, monitoring, intervention capability, and accountability to allow organizations to delegate routine work while retaining meaningful control over outcomes. As organizations increasingly rely on AI systems to influence decisions and execute tasks, they need confidence that they understand what authority has been delegated, what boundaries govern its use, and how intervention occurs when circumstances change.

These themes are explored in greater detail in The Insider You Built, which examines how organizations maintain control as increasingly autonomous systems begin participating in decisions, workflows, and execution.

That distinction matters because delegation has always been central to organizational growth. Companies scale by distributing work, authority, and decision-making across teams, business units, partners, and technology platforms. AI extends that pattern. The challenge is ensuring that delegation remains visible, governable, and adaptable as systems become increasingly capable.

Viewed through that lens, security becomes something larger than protection. It becomes part of an organization’s capacity to learn, adapt, supervise, and operate effectively in environments characterized by rapid technological change.

If security leaders want to strengthen their investment cases in the AI era, they may need to broaden the story they tell.

Threats remain real. Vulnerabilities remain important. Controls remain necessary. Yet organizations are not investing in AI because they want stronger controls. They are investing because they want better outcomes.

Security leaders therefore have an opportunity to explain how security contributes to those outcomes by creating the conditions that make innovation sustainable. Reliability, accountability, resilience, trust, adaptability, and controlled delegation are not byproducts of successful AI deployment. They are prerequisites.

Organizations looking to assess their readiness can start with a few practical questions. How quickly can they identify when AI-enabled workflows no longer align with business objectives? Who has the authority to modify, pause, or override automated decisions? How do they determine whether controls established six months ago remain appropriate today? How do they measure whether governance, security, and resilience investments are accelerating adoption or slowing it down?

The answers often reveal whether these functions are operating as strategic capabilities or merely compliance activities.

Organizations that succeed with AI will certainly manage vulnerabilities, patch systems, and implement controls. They will also develop the ability to safely delegate work, supervise increasingly autonomous systems, maintain visibility into critical decisions, intervene when conditions change, and continuously adapt as technology evolves. Those capabilities create business value.

This shift from governing systems to governing within systems is ultimately why the traditional security business case is evolving. As technology becomes a participant in organizational decision-making rather than merely a tool, organizations need capabilities that can continuously align authority, accountability, oversight, and execution.

The strongest business case for security is no longer limited to preventing bad outcomes. It is about enabling organizations to realize the benefits of AI while maintaining the reliability, control, and adaptability necessary to sustain them over time.

That is the story security leaders should be telling.

Leave a comment

2026 Series | Q2: Governance as a Capability

This article is part of a second-quarter series examining how governance is evolving into an operational capability that determines whether organizations can maintain control, resilience, and performance as AI systems scale.

Look for the Governance as a Capability tag.

Read the original on camilleesq.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.