AI adoption is moving faster than ever, and many organisations are struggling to put controls in place. Employees are already using AI to analyse information, write content, support decisions and solve problems. As a result, this often happens before security teams have had the opportunity to understand which tools are being used or what data is being shared with them.
For Alan Hamilton, Global Chief Information Security Officer at GAM Investments, this is where the security challenge begins. With more than 20 years in security and responsibility spanning 16 jurisdictions and 32 regulators, Hamilton has seen how quickly a technology can move from experimentation to becoming part of everyday operations. In conversation with EM360Tech Head of Content and Podcast Host Trisha Pillay, he shares that organisations cannot secure what they cannot see.
The issue is not simply whether employees are using AI. It is whether security teams understand how it is being used, what information is entering these systems, and what happens as AI begins to act rather than simply provide answers.
AI Has Already Entered the Workplace
The speed of AI adoption is creating a visibility problem for security teams. Employees can access public AI services with very little friction, meaning the technology can become embedded in workflows before an organisation has established policies, approved tools or monitoring.
Hamilton points to data exposure as one of the immediate concerns. Without appropriate controls, security teams have limited visibility into which AI services employees are using or what information they are putting into them. He describes examples where sensitive financial information was uploaded to a public AI service, forcing an organisation to release results earlier than planned. He also recounts a case where proprietary development code was entered into a public AI tool and subsequently reproduced by the service, compromising what had been a competitive advantage. This makes AI governance a practical security issue rather than a policy exercise.
Hamilton's answer is not to block AI altogether. In his view, attempting to prohibit its use can simply push employees towards less visible services, potentially increasing rather than reducing the risk. Instead, security teams need visibility into AI activity, including the ability to monitor prompts and apply data loss prevention controls to web-based AI services.
This is an important distinction for organisations moving into a more AI-dependent operating model: control does not necessarily mean prohibition.
Security Has to Understand What the Business Needs
Visibility alone is not enough. Security teams also need to understand why employees are turning to particular AI tools in the first place.
Hamilton describes how GAM has approached requests for AI tools outside its approved environment by examining the underlying business requirement. In some cases, a requested capability can be brought into an existing controlled environment. In others, particularly where investment professionals require specialised AI capabilities, the organisation can conduct due diligence and bring appropriate tools into its approved framework.
That approach recognises an uncomfortable reality: the most secure tool on paper is not necessarily the tool that employees will use.
If security departments simply dictate which tools employees can use without understanding their requirements, Hamilton warns that users will look for workarounds. The result is a familiar security problem, but with AI making it easier to create: technology operating outside the organisation's visibility and control.
This becomes particularly important as AI moves beyond conventional chatbots. Once systems are given the ability to take actions, organisations can no longer treat them like ordinary software.
Hamilton argues that AI systems need to be onboarded with clear boundaries, much like a new employee. Organisations need to establish what a system is allowed to do, which patterns it should follow, and what falls outside acceptable behaviour. The reason is straightforward: an AI system does not apply the same ethical judgement as a person. If an action appears to solve the problem it has been given, it may pursue that route unless appropriate restrictions are in place.
And responsibility does not disappear simply because an AI system made the decision. Hamilton stresses that organisations and their executives can still be held accountable for actions taken by AI, particularly in regulated environments.
AI Is Changing the Speed of the Security Game
The other side of the equation is that organisations are not only defending against AI-assisted activity; they are also facing attackers who can use AI to operate faster.
Phishing provides one of the clearest examples. Hamilton describes a dramatic increase in phishing activity, with attacks now changing rapidly in response to defensive controls. On one occasion, his organisation received 17,000 phishing emails between 7 am and 11 am, with hundreds of new rules generated to respond to the changing attacks.
For security teams, this changes the economics of response. A human team cannot manually analyse and respond to thousands of evolving attacks at machine speed. Hamilton's organisation has therefore introduced AI-based email security capable of analysing messages and adapting its rules as attacks change.
The same acceleration is affecting vulnerability management. AI-assisted discovery can uncover large numbers of vulnerabilities in a short period, creating substantial testing and patching workloads. At the same time, attackers can use AI to develop exploits much faster than before, putting pressure on organisations that still operate lengthy patch cycles.
This is where the broader question of operationalising intelligence becomes particularly relevant. As enterprise systems become faster, more autonomous and harder to reason about end-to-end, security teams cannot rely solely on processes designed for a slower environment.
The challenge is not simply adopting AI or defending against it. It is maintaining enough visibility and control to understand what these systems are doing, while building the capability to respond at the speed at which threats now evolve.
For Hamilton, one of the next major security problems will be determining what is real. As AI-generated voices, video and other forms of impersonation become harder to distinguish from genuine interactions, organisations will need better ways to verify identity and establish trust before sensitive actions are taken.
That may ultimately be the central security lesson of AI adoption: what organisations cannot see, understand or verify can quickly become what puts them at risk.
Takeaways
- AI adoption in organisations.
- Security risks of AI use.
- Data and information security challenges.
- AI-generated phishing and impersonation.
- Security controls and monitoring for AI tools.
- Impact of AI on patch management and vulnerability response.
- Managing autonomous AI systems and accountability.
Chapters
00:00 Introduction to Alan Hamilton and his role at GAM Investments
01:00 Alan's career background and experience in security
02:20 The rapid adoption of AI and associated security risks
03:15 Data risks from unregulated AI use in organisations
04:33 The impact of AI on competitive advantage and code security
05:23 Visibility and control challenges with employee use of AI tools
08:34 Balancing employee needs and security controls for AI tools
11:12 The rise of AI-generated phishing and its implications
13:00 AI in email security and phishing detection tools
15:20 AI's influence on security response speed and patch management
19:19 Managing autonomous AI systems and their unpredictable actions
22:05 The biggest security challenges as AI becomes more autonomous
23:00 The importance of detecting AI-generated content and impersonation
24:24 Future needs for AI detection tools and security practices
Comments ( 0 )