Speed vs Control: Are We Moving Too Fast to Govern AI and Risk?

By David Whitelegg, Deputy CISO – Compliance, Compass Group

AI adoption is moving quickly. In some organisations, probably much more quickly than anyone really knows.

Employees can access powerful AI tools directly through a browser. AI is appearing inside applications organisations already use, developers can add AI capabilities through APIs very quickly, and we are now moving beyond AI that simply generates content towards agents that can access data, interact with systems and take actions.

At the same time, the security conversation around AI is changing. We are moving beyond concerns about what somebody might type into a chatbot or whether a model might produce an inaccurate answer. The bigger question is increasingly what happens when we connect AI to real data, real systems and real business processes, and then give it some level of autonomy.

The opportunity is huge, but from a security and risk perspective it raises a fairly obvious question:

Are we moving faster than our ability to govern it?

I don’t think the answer is to slow everything down. That isn’t realistic and, in most organisations, probably wouldn’t work anyway. The challenge is how we allow the business to move quickly without losing control of the risk.

Do we actually know where AI is being used?

Before talking about governance frameworks, there is a more basic question. Do we actually know where AI is being used across the organisation?

That sounds straightforward, but I’m not convinced it is.

AI adoption isn’t necessarily happening through one big transformation programme with a project team, budget and governance structure around it. It can happen one employee, one application, one development team or one supplier at a time, and increasingly it may arrive through products we already use.

That creates a visibility problem, but simply producing an inventory of AI tools isn’t enough either. Knowing that 50 AI applications are being used tells me very little about the actual risk.

One might be helping someone improve the wording of a presentation. Another could be processing confidential company information. Another might have access to business systems and the ability to take actions. Those are very different things and shouldn’t be governed in the same way.

There is also a danger that we focus too much on discovering standalone AI tools and miss the AI capabilities appearing inside the existing technology estate. The question isn’t simply which AI products are being used. We also need to understand where AI now sits within business processes, what information it can access and, increasingly, what authority it has been given.

Start with what the AI can actually do

For me, this is where the conversation needs to become much more practical. Rather than starting with another policy, start with the capability.

What data can the AI access? What systems can it interact with? What decisions can it make or influence? Can it take an action? What happens if it gets something wrong? And at what point does a human need to get involved?

The answers tell you far more about the risk than simply knowing that something contains AI.

For lower-risk uses, an approved tool, sensible policy and employee awareness might be perfectly adequate. As the capability increases, particularly where AI can access sensitive information or take actions, the controls need to increase with it.

That doesn’t mean putting maximum governance around everything. It means putting the right control around the right risk.

This becomes particularly important with agents. An agent that can read information is one thing. An agent that can modify data, send communications, execute code or interact with production systems is something very different.

The level of autonomy matters.

Having a policy doesn’t mean you have control

We’ve become quite good at writing AI policies. That’s necessary, but it is only part of the answer.

A policy can say employees must not put confidential information into an unapproved AI service. Fine, but how do we know they aren’t?

A policy can say an AI agent requires human approval before taking a sensitive action. Again, fine, but what proves that actually happens?

This is where I think the AI governance conversation needs to move from policy into assurance. It isn’t enough to say what should happen. We need to be able to demonstrate what actually happens.

That might mean access controls, technical configuration, DLP, logs, approval records, monitoring, automated testing or some combination of them. The exact evidence will depend on the risk and the technology, but there should be evidence.

Otherwise, we risk creating something security teams have seen many times before: a control that looks good on paper but doesn’t necessarily operate as intended.

And with AI, there is another complication. The technology isn’t standing still after the initial assessment. Models change, integrations change, data changes and capabilities change. A system assessed six months ago may not present exactly the same risk today.

Governance therefore can’t just be an approval gate at the beginning. We need to know whether the controls continue to work afterwards.

AI agents change the risk

Most of the early discussion around generative AI focused on what went into the model and what came back out. What information are employees entering? Is the answer accurate? Could confidential data leak? Could somebody rely on a hallucinated response?

Those questions haven’t gone away, but agents introduce another question:

What can the AI actually do?

If an agent can access applications, retrieve company information, execute a workflow or make a change, we are no longer just governing what AI can say. We are governing what it can do.

That’s a significant difference.

Recent security guidance around agentic AI is increasingly focused on exactly these issues: excessive permissions, access to connected systems, human oversight, monitoring, containment and what happens when an agent behaves in a way nobody expected.

This isn’t theoretical enough to leave for another year. Organisations are already experimenting with agents and increasingly autonomous workflows.

One principle I’ve used when discussing this is:

AI shifts the work, but it doesn’t shift the responsibility.

If an organisation allows an AI system to act on its behalf, the organisation remains accountable for what it does. So if an AI agent can take meaningful action, I want four fairly simple questions answered:

What can it access? What can it change? Who approved that capability? What evidence shows it stayed inside those boundaries?

None of those questions is particularly revolutionary. We already understand least privilege, segregation of duties, change control, monitoring and accountability.

AI doesn’t suddenly make those principles obsolete. If anything, it makes them more important.

Assume something will eventually go wrong

There is another part of AI governance that I think deserves more attention.

We should stop designing governance on the assumption that AI will always behave exactly as intended.

Recent AI security research and testing has already produced examples of models and agents taking unintended or unsanctioned actions. That doesn’t mean every AI agent is dangerous, but it does reinforce a basic security principle: controls should account for failure.

What happens if an agent misunderstands an instruction? What if it is manipulated? What if it accesses something it shouldn’t? What if a supplier changes an underlying capability? What if it starts taking actions outside the boundaries we thought we’d established?

Can we detect it? Can we contain it? Can we stop it? And afterwards, can we establish exactly what happened?

These are familiar questions in cybersecurity.

We don’t build resilience on the assumption that technology will never fail. We use layers of control, monitoring, incident response and recovery because eventually something will.

AI shouldn’t be treated differently.

For higher-risk agents, that means thinking about blast radius before deployment. Limit access. Limit permissions. Separate environments where appropriate. Monitor behaviour. Protect the evidence needed to reconstruct what happened. And make sure somebody can actually stop the agent if necessary.

That last point sounds obvious, but as autonomy increases it becomes a control requirement in its own right.

Evidence is becoming as important as the control

This is where I think the next stage of AI governance will become particularly interesting.

There is a growing focus across AI security on visibility, traceability and runtime control. That makes sense.

If we say an agent can only access certain systems, can we prove that?

If we say sensitive actions require human approval, where is the approval evidence?

If we say an agent stayed inside an authorised boundary, what telemetry demonstrates that?

And crucially, can we trust that evidence?

For security and assurance teams, these aren’t unfamiliar concepts. We’ve been asking similar questions about identities, privileged access, changes, vulnerabilities and other technology controls for years.

AI introduces different technology and potentially much greater autonomy, but the underlying assurance question remains remarkably similar:

What proves the control actually worked?

Governance shouldn’t become the thing everyone tries to avoid

There is another side to this. Security and risk teams can create their own problems if governance becomes too difficult.

If every experiment involving AI requires weeks of forms, committees and approvals, people will find another route. We’ve seen that before with other technologies.

Good governance should help people use technology safely, not simply make it difficult to use. Give people approved tools, make the rules understandable, provide safe patterns for common use cases, make low-risk experimentation relatively easy, and put the stronger controls around the areas where the consequences justify them.

An employee experimenting with an approved AI tool and non-sensitive information doesn’t need the same governance as an autonomous agent with privileged access to production.

That sounds obvious when written down. Making it work across a large organisation is much harder.

And this is where security needs to be careful not to become the department of “no”. If the safe route takes significantly longer than the unsafe route, we shouldn’t be surprised when people find ways around it.

Good governance should enable speed where the risk allows it.

Speed versus control is probably the wrong choice

This is why I’m not convinced organisations should think about this as a choice between speed and control.

We need both.

Businesses are going to use AI. The potential benefits are too significant to ignore, and the technology is too accessible to assume adoption can simply be centrally controlled.

The role of security and governance shouldn’t be to stand in front of that adoption. It should be to help the organisation understand where the real risks are, put appropriate controls around them and, importantly, be able to prove those controls are working.

We’ve spent a lot of time talking about responsible AI, principles, frameworks and policies. Those things matter, but I think the next question will be harder:

Can you prove it?

Can you show where AI is being used? Can you show what information it can access? Can you show what an agent is allowed to do? Can you show who approved it? Can you show whether the controls operated when they were supposed to? And if something goes wrong, can you show what happened and how you responded?

That is where AI governance starts becoming operational assurance rather than governance on paper.

As AI becomes more capable and more autonomous, that distinction is going to matter. The organisations that get this right won’t necessarily be the ones with the longest AI policies or the most governance committees. They’ll be the ones that can move quickly, understand where the risk is, maintain control and demonstrate that the controls actually work.

Speed with control, rather than speed versus control.

If you’re interested in exploring what Speed vs Control: Are We Moving Too Fast to Govern AI and Risk? means for your organisation – and how cybersecurity leaders can stay ahead of it – we invite you to join the conversation. To learn more or take part, please RSVP below.

Meet David at CISO Xseries UK

The Next Tech Revolution

Cybersecurity has always been about staying ahead of technology, but since the late 1990s, however, technology has mostly been synonymous with Information Technology. Since then, the information age paved the way for emerging technologies that go beyond the realm of computers and are set to to reshape societal paradigms at a fundamental level.

The cybersecurity community now needs to widen its aperture to encompass the full range of these new technologies and adapt its role accordingly in this evolving landscape.

Artificial Intelligence:

A lot has been said and written about AI. Like many new technologies, it could be argued that AI is progressing through its classic hype cycle.

The slowdown in AI and tech stocks toward the end of 2025 could indicate that the field has entered the “Trough of Disillusionment” stage.

However, tangible productivity statistics tell a different story: the world is already experiencing substantial impact from AI adoption, and this is just the beginning. For example, AI’s influence on science and research is seen in a 39% increase in patent filings and a 17% rise in downstream product innovation. These figures highlight how profoundly AI will accelerate human progress in the coming years.

Beyond productivity, AI has significantly shaped geopolitics and the strategic positioning of global powers around this transformative technology.

In 2025, the United States released its AI Action Plan, while its BigTech companies started forming strategic and economic partnerships with countries including the UK, France, Canada, the UAE, and India.

China responded by releasing its own Global AI Governance Action Plan just days later. It also launched the BRICS AI Industry Cooperation Network in Shanghai and formed partnerships with nations such as Brazil, Nigeria, and Kenya.

The competition extended into the economic sphere. The US is prioritizing innovation through its BigTech sector, while China is expanding its influence via open-source models. There were mutual tariffs being imposed between the two countries, and a battle of export controls on GPU chips and rare earth materials used in building those chips.

Blockchain:

AI was not the only emerging technology influencing the global economy and geopolitics in 2025.

Blockchain-based digital assets experienced a major push toward mainstream adoption in the Western hemisphere, driven partly by their growing role in economic competition.

Under the new administration, the United States positioned itself as the “Crypto capital of the world.” Key steps included establishing the Strategic Bitcoin Reserve (SBR) and the Digital Assets Stockpile (DAS), which brought this strategy sharply into focus.

Bitcoin was framed and promoted as a digital alternative to gold, while internationally traded, dollar-backed stablecoins were positioned as a means to safeguard the dollar’s status as the global reserve currency.

In the US, the GENIUS Act and the Clarity Act introduced greater regulatory support and guardrails, enabling institutional investors to allocate more capital to various digital assets.

In the UK, the Property (Digital Assets etc) Act came into effect, providing provides legal certainty for digital assets and encouraging institutional investment.

As the global market capitalization of the digital assets economy approached $4 trillion, questions began to arise about the security of the overall ecosystem, and in particular, the resilience of its underlying encryption algorithms..

Quantum Computing:

In 2025, global annual investment in quantum technologies reached an unprecedented $33.28 billion.

IBM updated its quantum computing roadmap, advancing the target for a scalable fault-tolerant quantum computer (FTQC) to 2029, a full year earlier than the previous 2030 timeline.

The cybersecurity community has long recognized the disruptive potential of FTQC. NIST, the NCSC, and the European Commission have published post-quantum migration roadmaps, but these have not received meaningful updates to reflect an accelerated schedule.

Most existing roadmaps prioritize transitioning encryption algorithms in traditional IT systems to quantum-resistant standards. However, far less attention has been given to updating the digital signature algorithms that secure blockchains and digital assets.

This gap creates a concerning asymmetry, where the ECDSA algorithm, widely used in popular digital assets, is more vulnerable to quantum attacks than RSA.

Once scalable FTQC systems become a reality, ECDSA’s vulnerability could carry substantial economic and geopolitical consequences for the digital assets ecosystem and the broader domains it now influences..

Energy:

With these innovations increasingly embedding technology into every aspect of our lives, the demand for energy to support them is growing at a comparable pace.

Global electricity demand rose by an estimated 3.3% to 4.5% in 2025, driven in large part by the expansion of data centers and AI infrastructure.

Major tech companies started responding directly to these pressures. Google recently acquired clean energy developer Intersect to better support the energy needs of its data centers. Microsoft has pursued similar strategies, establishing partnerships with Constellation Energy for reliable nuclear power and with Helion for future fusion energy, while announcing its Community-First AI Infrastructure initiative to protect local residents from rising energy costs associated with AI.

From a cybersecurity perspective, cyberattacks targeting energy and utility organizations increased by approximately 40% year-over-year in 2025, underscoring the growing vulnerability of this critical layer.

Where does it all lead?

With all these developments, it is possible to conceptualize a future technology stack to look like the following; energy at the core as the foundational layer, quantum computers as the next generation of hardware and compute, AI as the operating system of the future, and a digital economy, built on blockchain and digital assets, running as the primary application on top of the entire stack.

With this speculative view of the future, it is easy to see how cybersecurity will have a critical role to play at every layer of this new tech stack.

If the cybersecurity industry is to defend against novel threats that will be targeting each layer of the stack, it must start looking beyond traditional IT frameworks and keep pace with this evolving technology landscape.

If you’re interested in exploring what this next tech revolution means for your organisation – and how cybersecurity leaders can stay ahead of it – we invite you to join the conversation. To learn more or take part, please RSVP via the CIO or CISO track.

CIO XSeries UK CISO Xseries UK

The Digital Future of the NHS: How Technology is Transforming Healthcare Efficiency

In a landmark move to streamline healthcare management and enhance efficiency, Prime Minister Sir Keir Starmer has announced plans to reintegrate NHS England into the Department of Health and Social Care (DHSC). This decision aims to eliminate bureaucratic redundancies and harness the potential of technology to improve patient care.

Reversing the 2012 NHS Reorganisation

This reform effectively reverses the 2012 restructuring of the NHS initiated by former Conservative health secretary Andrew Lansley. The previous reorganization had established NHS England as an arm’s-length body, a move that has since been criticized for contributing to longer waiting times, decreased patient satisfaction, and increased operational costs.

Streamlining Operations and Reducing Bureaucracy

By bringing NHS England back under direct governmental control, the DHSC intends to streamline operations, reduce bureaucratic overlap, and empower healthcare professionals. Health Secretary Wes Streeting emphasized the need for a more efficient system, stating that the current setup has led to unnecessary complexities and that the reforms will support NHS staff in delivering better outcomes for patients and taxpayers.

Leveraging Technology for Enhanced Healthcare Delivery

A central aspect of this reform is the strategic use of technology to modernize the NHS. The government plans to utilize the NHS’s centralised model to expedite the procurement of technological solutions, secure better deals for taxpayers, and collaborate closely with the life sciences sector to develop future treatments. This approach aims to harness digital advancements to improve patient care and operational efficiency.

Leadership Transition Amid Reforms

The announcement coincides with significant leadership changes within NHS England, including the departures of Chief Executive Amanda Pritchard and National Medical Director Sir Stephen Powis. Sir James Mackey has been appointed as the transition chief executive to oversee the integration process. He acknowledged the potential challenges for staff but expressed optimism that the reforms would provide clarity and focus on addressing the significant challenges ahead.

Conclusion

The integration of NHS England back into the DHSC represents a pivotal shift towards a more efficient and technologically adept healthcare system. By reducing bureaucratic redundancies and embracing digital innovations, the UK government aims to enhance patient care, optimise resource allocation, and ensure the NHS meets the evolving needs of the population.

The Future of AI and Cybersecurity: Humans as Orchestrators, Not Replacements

As AI, automation, and digital transformation accelerate, one question remains: how do we, as humans, stay relevant?

The answer lies in orchestration. AI is a powerful tool for data processing and automation, but it lacks strategic foresight, ethical judgement, and the ability to understand long-term impact. Humans must set the direction while machines execute. Security, business, and technology leaders must find the balance, leveraging AI without relinquishing control.

Security in a Fast-Moving Digital World

Cybersecurity is no longer just about protecting systems; it’s about enabling innovation while managing risk. Industries with tight margins and intense competition, such as retail and logistics, increasingly depend on automation, robotics, and AI to remain viable. However, these advancements bring new vulnerabilities. The challenge is clear:

  • How do we integrate emerging technologies securely?
  • How do we balance innovation with regulatory and ethical responsibilities?
  • How do we ensure security does not become a barrier to progress?

Ignoring these questions leaves organisations exposed. Addressing them proactively turns security into a competitive advantage.

AI in Cybersecurity: Not a Silver Bullet

AI is transforming cybersecurity, enhancing threat detection, automating responses, and uncovering hidden risks. But it is not infallible. Attackers are always adept at targeting the easiest vector, humans, by manipulating people through social engineering and insider threats.

Human intelligence remains irreplaceable in security because:

  1. AI lacks context – It can detect anomalies but cannot fully interpret intent.
  2. Security is a business issue – It requires an understanding of operations, supply chains, and regulatory landscapes.
  3. Humans guide AI – Machines optimise; people define what success looks like.

The future is not about AI replacing security professionals, but about humans and AI working in tandem.

2025: A Pivotal Year for AI and Automation

AI and automation are evolving rapidly, from intelligent software to physical robotics. Industries that fail to engage with these technologies risk obsolescence. Yet adoption without adequate security controls leads to significant exposure.

This year, expect:

  • The convergence of AI and robotics, increasing automation across industries.
  • Greater regulatory scrutiny, particularly around AI ethics and data protection.
  • A shift in cyber threats, as AI itself becomes both a tool and a target for attackers.

Adapting to these changes requires strategic risk management and investment in resilience.

Security Leadership: The Challenge of Prioritisation

A major challenge for security leaders is managing volume – the sheer number of alerts, vulnerabilities, and regulatory requirements. Prioritisation is key.

In data science, we use dimensionality reduction to focus on what matters most. The same applies to cybersecurity:

  • Filter noise to identify high-impact risks.
  • Align security with business objectives to gain executive support.
  • Communicate clearly – security leaders must translate complex risks into concise, actionable insights.

Security teams should not be seen as obstacles, but as enablers of innovation.

Brains & Bots: The Power of Human-AI Collaboration

At an upcoming industry event, I’ll be discussing “Brains & Bots: The Powerful Alliance Between Humans and AI”. The concept is clear:

  • Humans set the vision, AI drives execution.
  • Humans interpret nuance, AI processes data.
  • Humans provide ethics, AI delivers efficiency.

The future is not about AI replacing professionals, but rather augmenting human intelligence. By directing AI effectively, we can unlock new possibilities in cybersecurity, business, and other sectors, including healthcare.

Final Thoughts: The Secret to Success?

If I had to pinpoint the key traits that drive success, I’d say:

  1. Persistence – Cybersecurity is an ongoing challenge; resilience is essential.
  2. Curiosity – Always ask why and what’s next?
  3. Adaptability – Technology evolves; professionals must evolve with it.

The question I leave for industry leaders is this:

  • How is your organisation preparing for the AI-driven transformation of security and business in 2025?

Because one thing is certain – change is happening.