By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

The New Security Frontier: How CISOs Can Govern, Outsource and Scale AI Safely

Dallas CISOs and cybersecurity leaders from Toyota, Akumin, and Mastercard (formerly) share 4 executive insights on AI governance, security, and outsourcing the modern security operation.

During Innovate Cybersecurity’s Dallas Chapter Executive Evening, security leaders from manufacturing, financial services, and healthcare convened to share how they’re approaching AI governance and security, with the conversation highlighting building, buying, or outsourcing the modern security operation.

The panel, facilitated by Robert Pace, VP & CISO of Invitation Homes featured the following CISOs & Executive Leaders:

Dr. Lovelie Moore | BISO, Toyota Financial
Fred Clayton | CISO, Akumin
Jon Brickey, Ph.D. | Former SVP, Mastercard

Rather than providing a recap of the discussion, we’ve distilled their lively conversation into four executive insights—highlighting the key themes that emerged alongside practical takeaways inspired by the perspectives shared during the panel.

Executive Snapshot

Across the discussion, four themes consistently surfaced:

  1. Accountability Remains with the Customer.
  2. Hybrid Talent Model Wins.
  3. Governance‑First, Change‑Control Everywhere.
  4. Regulated Sectors Need Stronger Internal Oversight.

Who Owns the AI? (Responsibility vs. Capability)

Vendors can supply AI‑driven features, but legal and risk liability never transfers. Contracts still place breach impact on the buying organization, so you must retain ultimate control and evidence of compliance.

What Panelists Emphasized

  • Accountability never leaves the customer – “You can outsource the capability, not the accountability.”
  • Vendors are increasingly embedding AI agents (e.g., automated ticket routing) that can act autonomously.
  • Existing contracts still place the breach‑impact on the buyer, even when a model is supplied as a service.

Practical Takeaway

  1. Build an AI Asset Register – catalog every model, API, and autonomous agent per SaaS vendor.
  2. Map ownership – assign an “AI Owner” (usually the product owner) who signs off on security controls, risk acceptance and compliance evidence.
  3. Negotiate AI‑specific SLA clauses – include requirements for model drift detection, explainability logs and audit trails.

Hybrid Talent: What to Build vs. What to Outsource


Keep governance, risk‑decision making and data‑policy in‑house while outsourcing heavy technical work (continuous model monitoring, adversarial‑threat intel, AI‑driven SOC triage). This lets you adopt AI quickly without building a full research team.

What Panelists Emphasized

  • Core governance, policy creation, risk acceptance and data‑classification must stay in‑house.
  • Heavy technical work—continuous model monitoring, adversarial‑attack detection, frontier‑model testing—is best sourced from MSSPs, specialized consultants or vendor‑managed services.
  • The “human‑in‑the‑loop” (HITL) principle is non‑negotiable for any decision that can affect compliance or critical assets.

Practical Takeaway

Keep In‑HouseOutsource
AI governance policy & change‑control workflowContinuous model drift and bias monitoring
Legal/compliance sign‑off (HIPAA, PCI, AI Bill of Rights)Specialized threat‑intel on LLM‑based attacks
Incident‑response playbooks that include AI cuesManaged SOC with AI‑driven triage
Risk‑acceptance documentation & audit evidenceAutomated UEBA/SIEM extensions

Create a “AI Security Champion” role (senior analyst or architect) to own the internal side and act as liaison with external providers.

Governance‑First, Change‑Control for Every AI Agent

Every new AI agent—no matter how “simple”—must pass a formal change‑control gate, be registered in an AI asset register, and receive a scoped service identity. This prevents shadow‑AI proliferation and satisfies regulators.

What Panelists Emphasized

  • Even a simple “read‑only” bot should go through the same change‑control process as any production code.
  • The panel’s live poll showed 100 % agreement that AI agents need formal change‑control and identity assignment.
  • Without this gate, organizations face “shadow AI” that bypasses IAM policies and proliferates uncontrolled tokens.

Practical Takeaway

  1. Extend your existing Change‑Control System – add an “AI Agent” ticket type that captures purpose, data access level, and required approvals.
  2. Tie the change‑control gate to IAM – automatically provision a scoped service account (least‑privilege) for the agent; enforce quarterly review of that identity.
  3. Log every inference request – feed the logs into your SIEM for continuous audit and anomaly detection.

Regulation, Questionnaires & the Need for AI‑Specific Due Diligence


In healthcare, finance and other highly regulated domains, PHI/PII processed by a vendor’s model still requires internal proof of compliance (model‑cards, audit logs). Standard vendor questionnaires are lagging; augment them with AI‑specific probes (model provenance, prompt‑injection defenses, token‑economics controls).

What Panelists Emphasized

  • Regulated industries (healthcare, finance) cannot rely on vendor attestations alone; they must produce model‑cards and evidence of compliance.
  • Current vendor security questionnaires rarely ask about model provenance, prompt‑injection defenses, or token‑economics safeguards.
  • “Token denial” attacks—where an adversary burns a company’s AI‑budget tokens—are emerging and largely unaddressed in contracts.

Practical Takeaway

GapHow to Close It
Model provenance & biasAdd questionnaire fields: training data sources, validation metrics, bias‑mitigation steps.
Prompt‑injection & adversarial defensesRequire vendors to provide documented mitigation controls and test results.
Token‑economics controlAsk for rate‑limiting, budget caps and alerting on abnormal token consumption.
Regulatory evidenceInsist on a “model‑card” per AI service that maps to HIPAA, GDPR, PCI requirements.

Update your Third‑Party Risk Management (TPRM) workflow to include an AI‑risk addendum for every new SaaS contract.

Conclusion – Turning the Panel Insight into Action

The “Who Owns the AI?” discussion makes it clear: AI is no longer a peripheral add‑on; it is a core component of the attack surface and the defense stack.

  • Responsibility stays with you – map every AI capability, demand auditability, and embed it in your risk register.
  • Adopt a hybrid talent model – keep governance and high‑impact decisions internal, while leveraging external expertise for continuous monitoring and specialized threat intel.
  • Governance must be baked in – enforce change‑control, scoped identities and full logging for every AI agent, regardless of its perceived simplicity.
  • Regulated firms need stronger evidence – push vendors for model‑cards, token‑control safeguards and AI‑specific questionnaire items.

By turning these themes into concrete processes—AI asset register, AI security champion, change‑control for agents, and an expanded TPRM questionnaire—CISOs can reap the efficiency gains of AI without surrendering control or exposing themselves to new liability. The path forward is clear: govern first, outsource wisely, and keep the human decision‑maker at the helm.

Previous Post

Top 10 Cybersecurity News (August 31, 2026): Iran-Linked Hackers Disable UK Power Plant, Hit US Water Utilities, OpenAI Says Reward Hacking Drove Hugging Face Breach, and More

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.