generative AI automation

Your AI governance gap is wider than your security team thinks.

In a recent survey by VentureBeat, 72% of enterprises reported using multiple AI platforms as their primary technology layer, highlighting significant gaps in control and security.

3 min readVentureBeat
Your AI governance gap is wider than your security team thinks.

The governance gap in enterprise AI is not a security problem waiting to happen; it is a control problem happening right now. When 72% of organizations identify multiple "primary" AI platforms, they are not building a strategy; they are accumulating contradictions. The research from our Q1 surveys, combined with conversations at our Boston event, points to a "governance mirage": decision-makers express confidence in detecting misbehaving models, yet nearly a third have no systematic mechanism to catch problems until users or audits surface them. That is not governance. That is hope.

For security leaders, the practical stakes are immediate and compounding. The providers creating the risk are the same ones enterprises are using to manage it, a dynamic we call the "Security Irony." Hyperscaler security features win because they are already integrated, but that integration creates single-provider dependency. Mass General Brigham's experience illustrates the paradox: the hospital system had to build a custom "skin" around Microsoft's Copilot to prevent protected health information from leaking back to OpenAI, even as it committed to leveraging vendor roadmaps. Meanwhile, MassMutual is refusing long-term contracts entirely, betting that today's winners may not be tomorrow's. The "day two" bill that Red Hat's Brian Gracely describes, when the cost of sprawl, shadow AI, and lock-in comes due, is arriving faster than most enterprises are preparing for.

The path forward is not waiting for a vendor to win the control plane role. It is owning that role independently. Sriraman's call for a "Dynatrace for AI" a central observability platform with model drift detection, agent behavior analytics, and forensic logging, is right, but the market data shows enterprises are settling for a hybrid control plane, using provider-native tools for some workflows and external orchestration for others. That hybrid approach is pragmatic, but it must be paired with something more fundamental: a hard-stop capability. As Sriraman insists, and as OWASP has formally recommended, enterprises need a "big red button" to kill an AI operation instantly. Without that, nothing should go into an operational setting.

The winner of the AI platform war will not be the provider with the best model. It will be the one that helps enterprises enforce a single version of truth across their AI estate. But the data suggests enterprises are resisting that outcome, and they should formalize that resistance. You do not need to wait for a vendor to hand you control. You need to build your own control plane, with independent security instrumentation, and demand transparency from every provider you use. The "governance mirage" ends when you stop asking who owns the AI and start asking who owns the kill switch.

From VentureBeat

Decision makers at 72% of organizations claim to have two or more AI platforms that they identify as their "primary" layer, according to a survey of 40 enterprise companies conducted by VentureBeat last month, revealing real gaps in security and control.

For enterprise management and technical leaders, and especially security leaders, these multiple AI platforms extend the attack surfaces of most enterprises at a time when AI-driven attacks have become increasingly potent.

Read the original at VentureBeat