Cybersecurity Month: The Barn Door Is Open
Knowing where Artificial Intelligence already lives inside your organization is harder than it sounds. The first three parts of our AI Cyber Security Series set the ground: Part 1 covered what attackers are doing with AI, Part 2 built the policy, and Part 3 ran the five gates to help implement the policy. Through October, for Cyber Security Awareness Month, a shorter series looks at living with AI once it is already inside: reining it in, coexisting with it, and pointing it at work.
The horses are out of the barn and now we have to see where they went. The hardest part of governing AI inside a utility is not always writing the rules; it is also knowing every place the technology has already reached, and which of those places your existing tools can see.
The Many Ways AI Enters an Organization
A staff member opened a browser tab with an AI Chat, a vendor pushed an update that switched an AI assistant on inside software you had already approved, a device shipped with an AI model embedded. Each of these paths occur in organizations and require a different set of security controls.
What has changed these recent years is the demand. The question used to be whether staff would use AI tools at all, now staff that wanted nothing to do with AI are willing to adopt this technology to streamline processes. This shift in appetite for AI tools is hard to switch off, as many staff now rely on AI to keep certain processes going, even with a human in the loop.
Attackers have made the same move. Part 1 covered many ways where AI has been integrated into offensive security operations. Your staff are not the only ones who have found use of this technology.
AI Already Touches Your Operations
It is essential to see how far the reach of AI goes in your organization before you decide what to do about it. AI does not arrive with a single product, it is embedded into multiple areas such as a feature switched on inside tools your teams already use, and as capability your vendors already shipped. For a utility, that reach can run from the front office to the plant floor.
Consider where AI already sits in a typical operator:
- The Microsoft 365 drafts and summarizes. An assistant in the word processor or the email client will condense long email chains and operational details through the model to produce a result.
- The meeting platforms may transcribe and summarize engagements by default, including during sensitive topics such as outage bridge calls and vendor design reviews where relay settings, network segments and restoration steps are discussed openly.
- Engineering workstations running code assistants. Control engineers who ask a built-in assistant to help write or explain a script pass fragments of logic, this could include process details.
- Vendor Operational Technology (OT) products now carry AI of their own. Cybersecurity and Infrastructure Security Agency (CISA) noted in December 2025 that some OT devices ship with it built in, sometimes needing internet connectivity to work.
These applications of AI never asked permission to be in your system. These implementations are in place where your own information can now meet an AI model.
Banning AI Outright is a Weakness
Applying a ban on AI use on its own fails. A blocklist to AI sites closes only one way of entry, and new model endpoints appear faster than ever before. Embedded AI behind SaaS platforms sits inside tools you cannot block without breaking the business, and a staff member on a personal phone using AI cannot be monitored without infringing staff privacy. A ban just moves AI usage to a place where you cannot control its uses. On the OT network, blocking by default stays the rule, and should stay as such. Certain exceptions may arise and will be discussed further in the series.
The cost of having these blind spots could result in security incidents. In IBM's 2026 Cost of a Data Breach study, 43% of the organizations studied had a security incident involving unapproved AI use, up from 20% the year before." The report landing page in reference 6 does not show this figure. Cite the IBM page that does: IBM, "Every AI agent followed the rules, and the data still leaked. For a utility, the material that leaves this way is rarely trivial: asset inventories, network ranges and relay settings, the details an attacker would otherwise have to work to collect. Once it is typed into an unvetted model it is out of your control.
The Path Forward
The answer to preventing AI from scaling your wall is not to make the wall taller. It is to have a clear view of everything so that you may control it. Part 3 of our main series set out the five gates for that discovery and decision work.
We will expand on this notion by mapping out where your organization should AI Exist, coexisting with the AI you cannot switch off, and where a model may sit on your network.
The horses are already out and herding them back in is not the goal. Knowing every gap in the fence is.
Coexisting With AI. Through October, for Cyber Security Awareness Month, we take an in-depth look at how to rein AI in, live with it safely, and guide it toward the work you actually want it to do.
Talk to an AdvisorReferences
- Chang, N., & Chacko, J. (2026, August 17). AI: Cyber Security’s New Top Threat. ACUMEN. https://blog.aesi-inc.com/ai-cybersecuritys-new-top-threat/
- Chang, N., & Chacko, J. (2026, September 25). Your AI Strategy Based on the Cyber Security Threat Landscape. ACUMEN. https://blog.aesi-inc.com/your-ai-strategy-based-on-the-cyber-security-threat-landscape/
- Chang, N., & Chacko, J. (2026, October 6). Implementing Your AI Strategy and Policy through the Five Gates. ACUMEN. https://blog.aesi-inc.com/implementing-your-ai-strategy-and-policy-through-the-five-gates/
- Cybersecurity and Infrastructure Security Agency, Australian Signals Directorate’s Australian Cyber Security Centre, National Security Agency Artificial Intelligence Security Center, Federal Bureau of Investigation, Canadian Centre for Cyber Security, Federal Office for Information Security, National Cyber Security Centre of the Netherlands, National Cyber Security Centre of New Zealand, & National Cyber Security Centre of the United Kingdom. (2025, December 3). Principles for the Secure Integration of Artificial Intelligence in Operational Technology. CISA. https://www.cisa.gov/resources-tools/resources/principles-secure-integration-artificial-intelligence-operational-technology
- Kiassi, O. (2026, September 16). Every AI agent followed the rules, and the data still leaked. IBM. https://www.ibm.com/think/perspectives/every-ai-agent-followed-rules-data-still-leaked