AI’s Rise: Addressing Governance Gaps and Insider Threats

RSAC Rewind: Agentic AI, Governance Gaps, and Insider Threats

The recent RSAC Conference highlighted artificial intelligence (AI) as a dominant theme, revealing its pervasive influence in cybersecurity discussions. With nearly 44,000 attendees, 730 speakers, and 650 exhibitors, the event underscored the urgency of addressing both the potential and risks associated with AI technologies.

Full-Blown AI Adoption in Cybersecurity

Organizations have moved from a proof-of-concept phase to aggressive implementation of AI solutions. Research from the Cloud Security Alliance (CSA) indicates that 90% of organizations either currently adopt or plan to adopt generative AI for security purposes. This trend reflects a growing belief among IT and security professionals that AI can enhance their capabilities and free them for more strategic roles.

However, the rise of AI also presents significant challenges. Cybercriminals are leveraging AI to develop AI-enhanced malware, which has emerged as a primary risk for enterprise leaders. This dual-use of technology creates a modern-day Spy vs. Spy scenario, intensifying the stakes in the ongoing battle between cybersecurity defenders and malicious actors.

The term “agentic AI” was frequently mentioned at the conference, referring to AI systems that operate autonomously to achieve objectives without continuous human oversight. While this concept may signal innovation, it raises critical questions about governance and ethical implications in its application.

Security leaders are urged to focus on user involvement in Shadow AI—the unauthorized use of AI tools—and assess how these applications are being deployed within organizations. Notably, research indicates that 72% of generative AI usage in enterprises is attributed to shadow IT, emphasizing the need for better oversight and governance.

Gaps in Enterprise AI Governance

AI governance committees often concentrate narrowly on privacy and security concerns, neglecting broader issues such as legal liability, licensing exposure, and cost rationalization. Consequently, organizations may approve AI tools without conducting comprehensive risk evaluations, which include assessing intellectual property and third-party risks.

Current approaches tend to prioritize safe operations through local models and incident responses, but a shift towards broader, enterprise-focused AI planning is necessary. This strategy should align with organizational goals rather than simply functional execution.

Proliferating Insider Threats

Insider threats have existed long before the advent of modern cybersecurity, exemplified by historical cases of embezzlement and theft. Recent discussions at the conference highlighted alarming trends, such as the deception of major tech firms into hiring remote IT workers who are, in fact, North Korean cyber operatives.

Such incidents underline the critical need for collaboration among HR, legal, and security teams to detect fraudulent employment documents and address vulnerabilities in hiring platforms. Unfortunately, there is a lack of continuous dialogue about these emerging threats, with teams often focusing on compliance rather than proactive threat detection.

The RSAC Conference serves as a reflection of the current landscape in cybersecurity, where impactful trends and challenges are shared amidst a vibrant exchange of ideas. This year’s conference emphasized the importance of accountability, governance, and strategic planning in the face of rapid technological advancements.

While the challenges posed by AI and insider threats are significant, proactive measures can help mitigate potential harms. As the industry moves forward, it is essential to foster discussions on how organizations can effectively navigate these complex issues.

More Insights

State AI Regulation: A Bipartisan Debate on Federal Preemption

The One Big Beautiful Bill Act includes a provision to prohibit state regulation of artificial intelligence (AI), which has drawn criticism from some Republicans, including Congresswoman Marjorie...

IBM Launches Groundbreaking Unified AI Security and Governance Solution

IBM has introduced a unified AI security and governance software that integrates watsonx.governance with Guardium AI Security, claiming to be the industry's first solution for managing risks...

Ethical AI: Building Responsible Governance Frameworks

As AI becomes integral to decision-making across various industries, establishing robust ethical governance frameworks is essential to address challenges such as bias and lack of transparency...

Reclaiming Africa’s AI Future: A Call for Sovereign Innovation

As Africa celebrates its month, it is crucial to emphasize that the continent's future in AI must not merely replicate global narratives but rather be rooted in its own values and contexts. Africa is...

Mastering AI and Data Sovereignty for Competitive Advantage

The global economy is undergoing a transformation driven by data and artificial intelligence, with the digital economy projected to reach $16.5 trillion by 2028. Organizations are urged to prioritize...

Pope Leo XIV: Pioneering Ethical Standards for AI Regulation

Pope Leo XIV has emerged as a key figure in global discussions on AI regulation, emphasizing the need for ethical measures to address the challenges posed by artificial intelligence. He aims to...

Empowering States to Regulate AI

The article discusses the potential negative impact of a proposed moratorium on state-level AI regulation, arguing that it could stifle innovation and endanger national security. It emphasizes that...

AI Governance Made Easy: Wild Tech’s Innovative Solution

Wild Tech has launched a new platform called Agentic Governance in a Box, designed to help organizations manage AI sprawl and improve user and data governance. This Microsoft-aligned solution aims to...

Unified AI Security: Strengthening Governance for Agentic Systems

IBM has introduced the industry's first software to unify AI security and governance for AI agents, enhancing its watsonx.governance and Guardium AI Security tools. These capabilities aim to help...