Logo
FrontierNews.ai

AI Governance Is Now a National Security Issue: What Businesses Need to Know

AI governance is no longer just a technology concern; it's becoming a critical national security issue that organizations must address at the board level. According to New Zealand's Security Intelligence Service (NZSIS) 2026 threat assessment, foreign states and their proxies are increasingly targeting private companies, universities, and research institutions through AI-enabled espionage, insider threats, and influence campaigns designed to steal intellectual property, access credentials, and sensitive information.

Why Are Foreign Actors Targeting AI and Business Data?

The threat landscape has shifted dramatically. Rather than relying solely on traditional cyber intrusion, foreign actors are now using seemingly legitimate business relationships as cover for intelligence gathering. A joint venture, research collaboration, investment opportunity, or procurement deal may mask deeper national security risks if the true end user, beneficial owner, or strategic purpose remains hidden. The NZSIS identified that these threats can arrive through front companies, supply-chain intermediaries, and organizations that lack sufficient due diligence on their partners.

What makes this particularly urgent is how AI amplifies these risks. Generative AI tools can create persuasive, targeted narratives at scale, produce convincing deepfakes, amplify polarizing content, and obscure the source of information. These capabilities lower the barriers to misuse and make it easier for threat actors to manipulate employees, shape institutional narratives, and gain access to sensitive systems over time.

How Can Organizations Protect Themselves from AI-Enabled Insider Threats?

The NZSIS assessment identifies three categories of insider risk: deliberate malicious activity, influenced activity where someone is pressured or manipulated, and unwitting activity where employees are careless or unaware of how their access could be exploited. Importantly, insider risk is not limited to disgruntled employees. It can also affect people under financial pressure, those targeted by external actors, or individuals who lack awareness of security protocols.

Organizations should treat insider risk as a people, culture, and governance issue, not simply an IT-security problem. This requires a multi-layered approach:

  • Access Controls: Implement clear rules on secondary employment and conflicts of interest, establish appropriate access controls for sensitive systems, and monitor privileged access to detect unusual activity.
  • Staff Training and Awareness: Provide security guidance for employees who hold sensitive roles or information, including travel-security protocols and training on recognizing social engineering attempts.
  • Reporting Mechanisms: Create trusted channels for employees to report suspicious approaches or incidents without fear of retaliation.
  • Exit Processes: Develop rigorous offboarding procedures to revoke access and recover sensitive materials when employees leave.
  • Warning Sign Recognition: Train managers and security teams to identify when a person may be at risk of becoming an insider threat, such as sudden financial difficulties or unusual travel patterns.

The practical question for boards and executives is whether existing policies and controls keep pace with how technology is being used. This may require reviewing acceptable-use policies, cyber incident response plans, social media protocols, staff training programs, data handling processes, and arrangements for monitoring and responding to disinformation.

What Role Does AI Literacy Play in Governance?

Beyond security measures, organizations in the European Union now face a legal obligation to ensure their staff understand AI systems. Regulation (EU) 2026/1744, which entered into force on July 27, 2026, requires providers and deployers of AI systems to take measures to support the development of AI literacy among relevant personnel. This is not a one-size-fits-all requirement; instead, organizations must tailor their approach based on how employees interact with AI and the consequences of those interactions.

The framework proposes three cumulative tiers of AI literacy, each tied to the nature and consequences of an individual's work with AI systems:

  • Baseline Awareness (L0): All personnel should understand what AI is, which systems the organization uses, and which risks can arise, including fabricated outputs, bias, data exposure, and privacy concerns. This requires a record of awareness training or equivalent measures.
  • Operational Competence (L1): Workers required to use AI systems in their roles need to understand the capabilities, limits, and failure modes of those systems; how to interpret and verify outputs; effective prompting techniques; and when to escalate concerns. This requires system-specific training records linked to roles and risks.
  • Oversight Expertise (L2): Persons assigned to operate or oversee high-risk AI systems need deep system-specific competence, including the ability to monitor for malfunction and drift, detect bias, recognize when to intervene or override, and distinguish high-risk from prohibited uses. This requires documented competence assessments reviewed at least annually.

This tiered approach helps organizations connect AI literacy initiatives to actual patterns of use and potential consequences. Rather than introducing a single certification, the framework recommends creating validated measurements first, as premature certification could become a box-ticking exercise that encourages untested courses.

What Enforcement Powers Do Regulators Now Have?

The enforcement landscape is becoming more robust. The European Commission's AI Office, which began enforcement on August 2, 2026, has both investigative and sanctioning powers to ensure compliance with the EU AI Act. The AI Office can send requests for information to verify compliance, perform model evaluations, require providers to grant access to their systems, and conduct inspections of provider premises.

Penalties are substantial. Infringements involving prohibited AI practices can result in fines of up to 35 million euros or 7 percent of the offender's total worldwide annual turnover, whichever is higher. Other breaches, including obligations for general-purpose AI models, may result in fines of up to 15 million euros or 3 percent of total worldwide annual turnover. These enforcement mechanisms apply progressively, with different provisions becoming enforceable at different dates through 2028.

The AI Office has also launched tools for individuals and businesses to support enforcement, including an AI Act Complaint Tool, a Whistleblower Tool for reporting violations, and a complaints channel for downstream providers using general-purpose AI models.

What Should Boards and Executives Do Now?

The NZSIS recommends that boards and senior leaders focus on a short set of practical actions to strengthen their AI governance posture. First, organizations should identify their most sensitive information, assets, technology, relationships, and people. Second, they should assess which of these assets or relationships may be attractive to foreign states, proxies, or other threat actors. Third, they should clarify senior ownership of national security, geopolitical, sanctions, foreign interference, and insider-risk issues at the executive level.

Fourth, organizations should apply risk-based due diligence to higher-risk investors, counterparties, suppliers, intermediaries, delegations, end users, and beneficial owners. Fifth, they should strengthen key policies, access controls, staff training, and escalation pathways for suspicious approaches or incidents. In the current environment, resilience depends on understanding the threat, identifying what matters most, and putting proportionate controls around the people, information, assets, and relationships that need protection.

Organizations that take these steps will be better positioned to engage internationally and pursue opportunities while protecting their own interests and their nation's wider security. The convergence of AI capabilities, national security concerns, and regulatory enforcement means that AI governance is no longer optional; it is now a core responsibility of organizational leadership.