Implementing Your AI Strategy and Policy through the Five Gates

Part 1 of our AI Cyber Security Series looked at what attackers are doing with AI and Part 2 established your policy: what to classify, which tools are cleared for use, and who is accountable for the output. This instalment is about reining them in and putting the plan to work.

Implementing Your AI Strategy and Policy through the Five Gates
Photo by Ivan Aleksic / Unsplash

Writing the policy is the easy part. IBM’s 2025 Cost of a Data Breach research, drawn from 600 breached organizations studied by the Ponemon Institute, found that 63% had no AI governance policy in place to manage AI or to prevent staff using it without approval. The Cybersecurity and Infrastructure Security Agency (CISA) and its partners published their principles for AI in operational technology in December 2025. Neither threat intelligence nor written policy alone can fully close the distance between documentation and practice.

This segment focuses on moving from policy to the implementation of your strategy, starting with the five gates.

Entering the Gates

Before we begin implementation, we need to know where we stand in the implementation path. Think of the five gates as a pre-flight checklist. The gates are linked to five sequential questions that any AI use case must clear before it is deployed anywhere in the organization.

We advise running the gates as a working session with the key stakeholders present in the room:

  • Your security lead.
  • Operations lead.
  • Compliance lead.
  • IT team.
  • Procurement team.
  • A senior manager to make on-the-spot decisions.

Every question should be answered as yes, partially or no. Where the answer is yes, the supporting evidence should be documented.

Run the gates once to establish a baseline of where the organization stands, then evaluate each new use case individually. Stop at the first gate that is not passed. Remember that answering no is not a failure; it is simply the first item on your roadmap.

Clearing all five gates shows that an organization is ready to run AI in its business layer. Most organizations will not clear every gate on the first pass; this is a normal outcome that highlights the starting point for your roadmap to successful implementation.

Gate 1. Defining the Need

  1. What problem are we trying to solve?
  2. Does something we already own, or a minor change to an existing process, solve the issue without adding a new system?
  3. Is this request coming from an operator with an operational problem, or a vendor pushing a product?

The statement “We need an AI assistant” is not sufficient because it only defines a tool and not the business problem. By contrast, “Field crews spend too long finding the right procedure, and an AI assistant would make that process more efficient” is a more appropriate use case.

Question 2 forces a look at existing assets. CISA advises operators to consider solving the problem with an existing tool before introducing complexity.

Question 3 confirms that the request comes from a real operational bottleneck, not vendor marketing. A feature offered by a vendor is not the same as an issue raised by an operator.

Gate 2. Shadow AI Discovery

  1. Which AI features are already switched on, across software, email, documents, meetings, and engineering tools?
  2. Which vendors have injected AI into a product we already run via automated updates?
  3. Are staff using personal accounts for work tasks, and do we know that for a fact or are we assuming it?

This gate is an internal discovery exercise. Admin consoles, license entitlements, vendor release notes, proxy logs and your own staff can all help answer these questions. IBM found that one in five of the organizations it studied had a breach linked to shadow AI. CISA notes that some Operational Technology (OT) devices now ship with AI built in, so this review will cover the plant floor as well as the corporate office. A written inventory listing each tool, its users, its data tier and its status will clear this gate.

Gate 3. Data Classification & Safety

  1. Do we have a data classification scheme, and do people actually use it?
  2. Have we identified our highest tier information and mapped it into that scheme?
  3. Can we tell a member of staff in one clear statement what they are prohibited from typing into a chat window?

Evaluate your data classification tiers in the organization by handing a few documents to several staff members and asking them to classify them independently. If their answers differ, the scheme has not been implemented well enough for staff to apply it consistently. A good benchmark is CISA's list of engineering configuration data, which includes network diagrams, asset inventory, and schematics. Electric utilities have a head start under the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) 011 standard; they already identify and protect information about their BES Cyber Systems, which gives them a tested process and a top tier to map that information into. The rest of the organization's data still must be classified.

Gate 4. Ownership & Total Cost

  1. Who owns this program by name, rather than by committee?
  2. Who reviews the output, and do they possess the subject-matter expertise to catch a confident, plausible mistake?
  3. What is the true annual cost, including human review time, not just software licenses?

A committee can advise on ownership, but one named individual must take ultimate accountability for the program. CISA warns that AI can hallucinate, which means it can give a plausible but false answer, and should almost certainly not be used to make safety-critical decisions in OT environments.

Cost is where most implementation plans break down. Factor in licenses, integration, logging, training, and the hours staff spend verifying the integrity of AI output. This gate is passed when the program has a named owner, a qualified reviewer for each approved use, and a true annual cost that accounts for review and verification time.

Gate 5. Auditability & Incident Response

  1. If a regulator asks whether AI touched a specific submission, can we answer from concrete records rather than memory?
  2. Are accounts individual, and is usage logged?
  3. Does our incident response plan cover sensitive material inadvertently fed into the wrong tool?

Regulated operators already live by audit-ready evidence, and AI use must meet the same standard. CISA recommends collecting flow and access logs for AI endpoints, tracking data leaving by asset and identity, and logging AI actions under an identity separate from any user or machine accounts. IBM found that 97% of breached organizations reporting an AI-related incident lacked proper access controls around the AI tools. Passing this gate requires all AI tool sessions to have single sign-on, reviewable audit logs, and an established incident response plan for tool misuse.

Figure 1 summarizes the five gates as a checklist, with the evidence that counts as a pass for each one.

Figure 1: A checklist for the five gates

Making Implementation a Daily Practice

Clearing the gates does not mean the work is finished; it means you are finally cleared to start implementation. The following steps are recommended to help successfully bring AI under control within your organization.  Each step represents a small but important part of the bigger picture and contributes to the successful implementation and adoption of AI tools.

Classify Your Data, and Verify Adoption

Part 2 established a four-tier classification scheme. By embedding these tiers directly into document templates and shared file structures, the label travels alongside the file. From there, organizations must verify that the staff are applying the labels correctly. In May 2025, the National Security Agency (NSA) and its partners released AI data security guidance advising organizations to classify input data, apply strict access controls to each tier, and assign AI-generated outputs the same classification level as the source data that fed them. Practical ways to audit label adoption include conducting blind classification tests with staff, scanning for unlabeled documents, and spot-checking AI outputs against input tiers.

Publish the Approved Tool List

Maintain an AI-approved tool list that pairs each tool with the highest data tier it is cleared to handle. Always opt for enterprise agreements that explicitly prohibit vendors from using your data to train their models. Because vendor terms may change without warning, every entry must carry a review date.  For example, on April 24, 2026, GitHub Copilot began using interaction data from its personal Free, Pro and Pro+ plans to train and improve models in 2026 unless the user opts out, while the business and enterprise plans were protected. Ensure that this list is incorporated into IT policies and procedures so that staff members always have a concise, single, and definitive reference that clearly indicates what is permitted at their workstations.

Train Staff on Today’s Signals

Fold AI awareness into your organization’s training program it likely already runs, like the NERC CIP-004 program for electric utilities. The old ways to recognize a malicious request are gone. Poor grammar no longer marks a phishing message, and a familiar voice or face on a call is no longer proof of who is speaking. Train personnel to recognize the signals that can still be detected: unusual requests, odd changes to access, urgency and secrecy, and verification through a channel the sender did not choose. In addition, reviewers need dedicated training on how to check AI output against its sources and record their processes on how to efficiently verify output integrity.

Run a Scoped Pilot

For an AI tool that has already passed through the gates and is ready for implementation, always run a test pilot for this tool with all security measures active. Keep the pilot strictly in the business layer using Public or Internal data; this ensures that performance is easy to measure and any errors are simple to reverse. Effective use cases for a pilot include summarizing published standards and filings or drafting non-sensitive internal procedures. Under no circumstances should the control path, BES Cyber System Information (BCSI), or any data feeding a safety decision be included in this pilot.

Figure 2 summarizes the four steps of daily practice, from classification through to this pilot, and the test that says each one is done.

Figure 2: Applying AI security to daily practice

Write a brief pilot plan outlining the core problem, the objectives, potential failure risks, team members, the data tier limits, success metrics, and termination triggers.

Restrict the trial to an approved tool, mandate that a qualified reviewer check every output, and track the exact hours spent on review, which shows the true cost of the tool in both staff time and financial capital.

Following the pilot, evaluate your findings to make a clear decision: Expand, adjust, or stop. Shutting down a pilot that did not earn back its review time is not a failure but a sign that the governance program is working and saves money overall. Conclude the pilot with a declared result, a final decision, and the updated policy reflecting your lessons learned.

Figure 3 below walks through the pilot, from setting the boundaries to closing it out.

Figure 3: Running an AI pilot

Implementation Is Not the Finish Line

The horses are already out of the barn, and trying to herd them back inside is no longer an option. The real challenge now is reining them in, getting them under control, and figuring out where they can actually pull their weight in your organization.

Once AI is properly reined in, the next objective is finding the precise tasks where it genuinely earns its place within your organization.

Coming through October · A short series for Cyber Security Awareness Month
The Animals Are Out of the Barn. Time to Rein Them In.

The Barn Door is Open. Through October, for Cyber Security Awareness Month, we take an in-depth look at how to rein AI in, live with it safely, and guide it toward the work you actually want it to do.

Talk to an Advisor

References

  1. Chang, N., & Chacko, J. (2026, August 17). AI: Cyber Security’s New Top Threat. ACUMEN. https://blog.aesi-inc.com/ai-cybersecuritys-new-top-threat/
  2. Chang, N., & Chacko, J. (2026, September 25). Your AI Strategy Based on the Cyber Security Threat Landscape. ACUMEN. https://blog.aesi-inc.com/your-ai-strategy-based-on-the-cyber-security-threat-landscape/
  3. Cybersecurity and Infrastructure Security Agency, Australian Signals Directorate’s Australian Cyber Security Centre, National Security Agency Artificial Intelligence Security Center, Federal Bureau of Investigation, Canadian Centre for Cyber Security, Federal Office for Information Security, National Cyber Security Centre of the Netherlands, National Cyber Security Centre of New Zealand, & National Cyber Security Centre of the United Kingdom. (2025, December 3). Principles for the Secure Integration of Artificial Intelligence in Operational Technology. CISA. https://www.cisa.gov/resources-tools/resources/principles-secure-integration-artificial-intelligence-operational-technology
  4. GitHub. (2026, March 25). Updates to GitHub Copilot interaction data usage policy. GitHub Blog. https://github.blog/news-insights/company-news/updates-to-github-copilot-interaction-data-usage-policy/
  5. IBM. (2024, October 25). What is shadow AI? IBM Think. https://www.ibm.com/think/topics/shadow-ai
  6. IBM. (2025). 2025 Cost of a Data Breach Report: Navigating the AI rush without sidelining security. IBM. https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai
  7. IBM. (2025). What data leaders need to know from the Cost of a Data Breach Report 2025. IBM. https://www.ibm.com/think/insights/data-matters/cost-of-a-data-breach
  8. National Security Agency Artificial Intelligence Security Center, Cybersecurity and Infrastructure Security Agency, Federal Bureau of Investigation, Australian Signals Directorate’s Australian Cyber Security Centre, National Cyber Security Centre of New Zealand, & National Cyber Security Centre of the United Kingdom. (2025, May 22). AI Data Security: Best Practices for Securing Data Used to Train & Operate AI Systems. CISA. https://www.cisa.gov/news-events/alerts/2025/05/22/new-best-practices-guide-securing-ai-data-released
  9. North American Electric Reliability Corporation. (n.d.). CIP-011-3 — Cyber Security — Information Protection. NERC. https://www.nerc.com/globalassets/standards/reliability-standards/cip/cip-011-3.pdf
  10. North American Electric Reliability Corporation. (n.d.). CIP-004-7 — Cyber Security — Personnel & Training. NERC. https://www.nerc.com/globalassets/standards/reliability-standards/cip/cip-004-7.pdf

Read more

An Energy Transition Energy Transition Roadmap for Electrical Utilities Dimension 2: Technology

An Energy Transition Energy Transition Roadmap for Electrical Utilities Dimension 2: Technology

In our previous blog post discussing the Energy Transition Roadmap for Electrical Utilities, we looked at challenges and solutions for achieving Energy Transition objectives for the fundamental aspects of power systems – namely power generation, transmission and distribution, and customer demand. Today, we shift our focus to the technology needed to

By Richard Ganton - Senior Engineer, Operational Technology