Logo
FrontierNews.ai

Why AI Adoption Is Racing Ahead of Security and Governance: What Boards Need to Know

Organizations are rushing to adopt artificial intelligence faster than they can govern it, secure it, or measure its return on investment, creating a dangerous gap between ambition and readiness. According to Chris Dimitriadis, chief global strategy officer at ISACA, a professional association focused on governance and security, the disconnect stems from a fundamental misunderstanding of what AI actually is and how it should be deployed.

Why Are Companies Struggling to Measure AI's Return on Investment?

Many organizations treat AI as a plug-and-play technology, expecting immediate results without redesigning their underlying business processes. This approach almost guarantees disappointment. "There is still a misconception about AI," Dimitriadis explained. "Many people treat it as a plug-and-play technology. They expect to apply it within the organization without redesigning processes and without really embedding and integrating AI within the business. In reality, AI is more of a structural economic force that will transform products and services as a whole".

The ROI challenge also stems from two other critical gaps: a shortage of employees with the skills to identify the right AI investments, and a widespread tendency to deploy AI horizontally across an organization rather than targeting specific industry needs. Generic AI tools applied broadly rarely deliver meaningful business value, Dimitriadis noted.

What's the Difference Between Generic AI and Domain-Specific AI?

The distinction matters enormously for business outcomes. Generic AI tools are broad-based systems designed to work across many industries and use cases. Domain-specific AI systems, by contrast, are customized to address the particular operational challenges of a specific industry or sector. Finance, manufacturing, and healthcare are expected to see major adoption of domain-specific AI systems in coming years, according to ISACA's analysis.

"Simply applying generic AI tools across the organization is not going to transform the business," Dimitriadis stated. "A domain-specific AI system gives organizations the opportunity to create new products, new services and a more embedded application of AI within the business". The implication is clear: companies investing in broad, generic AI deployments without a clear industry or operational focus are likely wasting resources.

How to Build a Foundation for Sustainable AI Adoption

  • Apply a Maturity Framework: Organizations should use structured assessment tools like CMMI (Capability Maturity Model Integration) to evaluate their readiness and guide deployment decisions, rather than rushing into implementation without prerequisites.
  • Understand Data and Infrastructure Requirements: Before acquiring or building an AI solution, companies must identify the data structures, quality standards, and technical infrastructure needed to support the system effectively.
  • Plan for Organizational Transformation: AI adoption requires changes across multiple departments and workflows. Companies should budget for and forecast realistic ROI only after designing these broader organizational changes, not before.

Dimitriadis emphasized that "AI adoption is a journey. It's not plug and play. It's not, 'I installed a new AI solution, and here's the result.' It requires transformation across several parts of an organization to bring real results".

Dimitriadis

What Security and Governance Risks Are Organizations Missing?

Perhaps the most alarming finding from ISACA's research is that many organizations may face greater risk from their own AI systems than from external attackers. Companies implementing AI solutions without appropriate governance structures are opening themselves to privacy breaches, data leakage, and system manipulation. When employees enter corporate information into untrusted AI platforms, they can unintentionally expose sensitive business data.

The cybersecurity landscape is shifting in ways most organizations are unprepared for. AI systems can identify zero-day vulnerabilities (previously unknown security flaws), orchestrate attacks, and combine multiple weaknesses to launch sophisticated assaults. Critically, AI has democratized hacking: organizations no longer need expert hackers with deep technical knowledge to launch advanced cyberattacks.

"One of the questions we ask boards and directors is whether their organization is adopting AI for defense purposes faster than attackers are adopting AI to attack the company. In many cases, the answer is no," said Chris Dimitriadis.

Chris Dimitriadis, Chief Global Strategy Officer at ISACA

A significant skills gap compounds the problem. Most organizations lack employees with the expertise to predict, identify, and manage AI-related risks. Many companies also don't know how long it would take to shut down an AI system during a security incident, revealing a troubling lack of operational understanding.

Respondents to ISACA's poll ranked misinformation, privacy violations, and social engineering among the top AI risks. But attack automation represents another major threat category. As AI systems become more sophisticated, they can identify vulnerabilities and launch coordinated attacks at speeds that outpace human response capabilities.

The bottom line is stark: organizations are adopting AI at a pace that far exceeds their ability to govern, secure, and extract genuine business value from it. Success will depend on slowing down, building the right infrastructure and skills, and deploying AI strategically within specific business domains rather than chasing broad, generic implementations.