Security leaders must enable AI-driven growth without losing control. AI governance is now the security leader’s central growth challenge.
Opening the 13th Security Edge in Sydney, Joey Meynink, Head of Strategy at ADAPT, framed the tension facing security leaders: managing machine-speed risk outside the organisation while AI gains greater autonomy within it.
The priority is preserving resilience, identity, and control as that autonomy expands.
Key takeaways:
- Governing AI agents and autonomous workflows is the key near-term constraint because autonomy expands the impact of identity and access decisions.
- Effective AI security requires an organisation-wide model that connects security, data, technology, finance and board oversight.
- AI governance is now the top security priority, reflecting the rapid move from experimentation to enterprise adoption.
AI changes the security mandate from protection to enablement
Security teams are no longer seen only as blockers; “grow the business” is now their leading goal.
That shift makes security a partner in AI strategy, responsible for creating the conditions in which the organisation can adopt new capabilities safely.
ADAPT data shows that developing an AI strategy and roadmap is the second-ranked goal for security leaders, with resilience, identity and control forming the practical foundation.
Autonomous AI is the next major control problem
The immediate challenge is not simply approving AI tools, but governing agents and autonomous workflows that can act with increasing authority.
This expands the attack surface beyond endpoints and applications to include delegated decisions, permissions and machine-to-machine activity.
Governing AI agents and autonomous workflows was identified as the number one constraint over the next 12 to 24 months, while AI security, governance and model protection is the capability area leaders most want to expand.
AI governance cannot be solved by security alone
ADAPT survey data points to an enterprise-wide gap: more than 90% of CIOs report that their organisations lack AI governance involving the board, while half of data leaders describe AI and machine-learning monitoring as immature or basic.
CFOs are also treating risk and compliance, not revenue or cost, as the primary factor in allocating AI budgets.
These signals place security leaders at the centre of a cross-functional response, requiring shared guardrails, clear accountability and board-level oversight.
The practical task for security leaders is to establish where the organisation stands, define what good looks like and translate that gap into immediate next steps.