AI Governance and Cybersecurity: How to Regain Control Without Stifling Innovation?

“Creating a truly multidisciplinary AI committee is the cornerstone of this approach.”

Driven by a quest for increased productivity, employees are increasingly using Artificial Intelligence solutions outside the control of the IT department, a phenomenon known as Shadow AI. This highlights a glaring gap: the integration of AI within organizations is progressing faster than the implementation of security strategies. This opens the door to unprecedented vulnerabilities.

But beyond mere technical gaps, it’s the entire legal, financial, and strategic responsibility of the company that’s at stake. And with the progressive implementation of the European AI Act, the regulation of these systems is no longer an option; it’s a legal obligation.

However, how can control be regained without stifling the team’s capacity for innovation? Laurent Galvani, cybersecurity expert at TVH Consulting, gives us his advice on structuring resilient and compliant AI governance.

Shadow AI: The True Risks Beyond Simple Data Leaks

Using AI tools without the company’s validation exposes the organization to a trio of critical risks. The first and probably most obvious danger lies in the loss of control and data leakage. When an employee submits sensitive information (contracts, HR data, strategies…) to public AI, this data can feed third-party models. The issue is not so much classic hacking as the voluntary (and uncontrolled) exposure of the company’s know-how.

This loss of control is compounded by the intellectual property puzzle. What happens, for example, when a developer uses AI to generate source code for a client? Without a defined framework, it becomes very complex to determine who owns this code and how to maintain it over time. Thus, the entire chain of legal responsibility and the ownership of generated elements (text, images, code) is compromised.

Moreover, uncontrolled use of AI introduces new specific cybersecurity threats. In addition to the worrying dependence on unaudited providers, companies face unprecedented vulnerabilities like prompt injection attacks (manipulation of queries to bypass security rules) or data poisoning.

These gaps are further compounded by challenges related to identity and access management (IAM): when an AI agent runs autonomously on the network, who is legally and technically responsible? To what databases or applications does it have actual access in the background? Without rigorous traceability, an uncontrolled AI can gain disproportionate privileges within the IT system.

This threat landscape also includes the risk of inadvertently generating vulnerable code that could be directly integrated into production. Finally, there’s a significant financial risk to consider: poor cost control related to AI usage can lead a company to exhaust its annual token budget in just a few months.

European AI Act: A Strict Compliance Schedule to Anticipate

The AI Act for Artificial Intelligence systems is what the GDPR is for personal data, imposing constraints proportional to the risk level of the systems used. Effective from early 2025 concerning the prohibition of applications posing an unacceptable risk, it reaches a new stage in August 2026. At this date, obligations become applicable to systems classified as high-risk, before a complete and gradual deployment planned by 2027.

“There is no good time to start compliance with the European AI Act. The best time was yesterday. The second best time is today.”

To achieve compliance, we recommend a structured 5-step method:

  1. Map the usage, tools used, providers, and data handled.
  2. Classify these use cases according to the AI Act criteria (minimal, limited, high risk, prohibited).
  3. Analyze the risks from a cyber, ethical, business, and legal compliance perspective.
  4. Establish governance through defined roles (AI referent) and a dedicated committee.
  5. Formalize and document the processes, AI policy, charters, and system registry.

Governance Shouldn’t Stifle Innovation: The Pillars of an Effective Strategy

Simply banning AI is utopian. If you block access on the corporate network, employees will use their personal phones to query public AI. The challenge of good governance is to strike the right balance: protect the company while providing secure alternatives. The first shield of this strategy is based on the acculturation and training of employees. It is essential that teams understand the risks associated with their usage and are trained in the right tools, with a targeted approach according to profiles, whether they’re business consultants, support functions (HR, Finance), or IT teams.

This awareness effort must be accompanied by appropriate technical measures. Technological framework includes, notably, access control solutions and the deployment of DLP (Data Loss Prevention) tools.

“For example, solutions like Microsoft Purview allow real-time information classification and automatically block the entry of sensitive data, such as a bank account number or a personal address, into AI assistants like Copilot.”

Finally, the success of this governance largely depends on listening to the business needs. IT must no longer be seen as merely a control entity, but as a true partner. By precisely understanding user needs, it becomes capable of providing centralized and secure enterprise AI environments. With these reliable alternatives, employees can increase productivity without feeling the need to circumvent established rules.

AI Committee and Usage Charter: Who to Bring to the Table?

The security related to AI usage is too complex to be relegated solely to the IT department. To draft a relevant, applicable usage charter that is respected by all employees, siloed approaches must be abandoned. Creating a truly multidisciplinary AI committee is the cornerstone of this approach. The challenge here is to ensure that no one is forgotten, as each expertise is vital to the project’s success.

The impetus must necessarily come from the top. The involvement of senior management is essential: they validate commitments, set the strategic direction, and drive momentum. Without strong sponsorship, any AI policy will lack weight and struggle to overcome employee habits. Following directly, the IT department (and CISO) handles technical management. Their role is to translate this strategic vision into a solid architecture capable of ensuring operational security and controlling access to different language models.

But technique is not enough in the face of legal risks. The legal department often turns out to be the great forgotten in these initiatives. However, they are at the forefront of anticipating disputes related to intellectual property (who holds the rights to generated code or text?) and securing contracts with AI solution providers. Alongside them, the DPO (Data Protection Officer) ensures that technological enthusiasm does not come at the expense of privacy and GDPR-related obligations.

Finally, HR, business managers, and support function directors (Finance, Marketing, etc.) must have a voice, as they carry the true operational use cases daily. This is particularly true for AI integration projects at the heart of critical information systems, whether automating processes in an ERP (such as Microsoft Dynamics 365 Business Central or SAP) or optimizing customer relations via a CRM (like Salesforce or Microsoft Dynamics 365). By integrating them from the genesis of the usage charter, the company ensures that no out-of-touch regulations are created. This collaborative approach not only helps understand their real constraints but also garners their support.

Format citation: “By becoming co-builders of the IA security framework, business units will become its best ambassadors.”

Of course, in organizations where these expertise are not all present internally (CISO, legal…), calling on an external consultant remains an excellent alternative to secure the approach.

Evaluating Maturity: Taking Action

If a leader or CISO wishes to evaluate their maturity against these challenges today, the first step is to conduct a 360° diagnostic. It’s not just about a technical audit, but a true organizational introspection. The company must objectively question whether there is a clear policy governing AI, its real mastery of daily uses (how widespread is Shadow AI in various departments?), and the solidity of barriers protecting its critical data. This first assessment is essential to define a realistic starting point.

However, conducting this evaluation internally often carries biases. Engaging an external trusted party is strategic at this stage. An expert not only adds additional credibility to convey the message to the leadership, but also offers an uncluttered vision. With ample field experience, they challenge the company against market standards and share proven feedback, saving valuable time in achieving compliance. Here is an overview of the main offerings to support this approach:

  • Comprehensive diagnostic audits: A thorough evaluation of your current usage (detection of Shadow AI) and overall security level to establish a clear risk mapping.
  • AI Act compliance support: From classifying your AI systems to creating a complete documentary register, including the required impact analyses by European regulations.
  • Externalized AI consultant service: Tailored support (AI Officer or specialized CISO) to lead your AI committee, ensure continuous regulatory monitoring, and structure your processes without burdening your internal staff.
  • Deployment of governance packages: A turnkey offer combining the technical and security configuration of a tool (e.g., Microsoft 365 Copilot), drafting your specific usage charter, and training your end users.

Planning an ERP project?
Table of contents

Dans la même catégorie :