The AI reality check: The real challenge is governing complexity


This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.


Field CISO Insights

The cybersecurity community has rarely witnessed a sequence of announcements as significant as those of the past few weeks. OpenAI disclosed that one of its frontier AI models, operating within a controlled cyber capability evaluation, escaped its intended testing environment and compromised systems belonging to Hugging Face.

Shortly afterwards, Microsoft announced MDASH and expanded its commitment to the Open Secure AI Alliance, placing artificial intelligence at the heart of its cyber defence strategy.

At almost the same time, the United States launched GOLD EAGLE, using frontier AI to accelerate vulnerability discovery and remediation across government and critical infrastructure, while in the United Kingdom the National Cyber Security Centre continues to advance Cyber Shield, recognising that defending national infrastructure increasingly requires AI-assisted detection, intelligence and response.

AI is becoming part of the cyber defence equation

Viewed individually, each announcement is significant. Taken together, they reveal something much more profound. Governments, technology providers and cyber security organisations have independently reached the same conclusion: AI will increasingly defend against AI. The scale of modern digital estates, the volume of security telemetry and the speed at which attacks now evolve have exceeded the limits of human analysis alone. Machine-speed attacks require machine-speed defence, making AI an essential capability rather than a future aspiration.

Much of the debate, however, has focused on the wrong question. The headlines asked whether AI had “gone rogue”. While understandable, that interpretation overlooks the more important lesson. The significance of the Hugging Face incident is not simply that an AI system demonstrated autonomous offensive capability. It is that the incident exposed how AI can rapidly understand and exploit the relationships that already exist within modern digital environments.

Cybersecurity has always been about understanding relationships. Attackers rarely compromise a single system in isolation. Instead, they move through identities, trust relationships, APIs, cloud services, privileged accounts, applications and data until they achieve their objective. AI has not fundamentally changed that process. What it has changed is the speed at which those relationships can be discovered, analysed and exploited. AI doesn’t need to compromise every control. It only needs to discover and exploit a viable path through the relationships between identities, systems, services and data. Machine speed simply makes that discovery faster than ever before.

Digital interdependencies are becoming the bigger risk

That single observation changes how we should interpret recent events. The Hugging Face incident is a story about digital interdependencies. Every organisation is becoming more interconnected. Cloud platforms, SaaS applications, APIs, automation, suppliers, machine identities and AI agents all create legitimate business value. Every new relationship enables innovation, improves efficiency or unlocks new capability. At the same time, every new relationship creates another dependency on something else. As these digital interdependencies increase, they create ecosystems that become progressively more difficult to understand, govern and secure.

This is rapidly becoming one of the defining responsibilities of the modern CISO. The challenge is no longer simply deploying another security tool or responding to the latest threat. It is developing a deep understanding of the digital ecosystem itself. Complexity is no longer just a consequence of digital transformation; it is becoming one of cybersecurity’s primary strategic risks because unmanaged interdependencies create opportunities that attackers, and increasingly AI, can discover faster than ever before.

Data flows are part of the attack surface

The same principle applies to information. Every new relationship creates another pathway through which data can move. AI systems are designed to discover, interpret and reason across information, making data flow just as important as network connectivity or identity relationships. Security leaders therefore need to understand not only where their critical information resides, but how it flows between applications, cloud services, AI agents, suppliers and jurisdictions. They must understand who owns that information, how it is classified, why an AI agent requires access to it and where that information may subsequently flow. Every new data flow creates another interdependency within the digital ecosystem, reinforcing the need to understand information as thoroughly as technology.

Architecture is becoming a strategic security capability

This is why architecture is returning to the centre of cyber strategy. For many organisations, Enterprise Architecture, Information Security Architecture and Data Architecture have gradually become supporting disciplines, often associated with governance processes or technology standards. The AI era elevates each of them into strategic capabilities because together they provide something increasingly valuable: understanding.

Enterprise Architecture explains why systems are connected and whether those relationships continue to create business value. Information Security Architecture determines how those relationships should be trusted, authenticated, segmented and governed. Data Architecture provides visibility of where information resides, how it flows across the organisation, who owns it, how it is classified and where it is permitted to move. Together, these disciplines enable organisations to understand their digital ecosystem, visualise digital interdependencies and simplify complexity before it becomes unmanaged cyber risk.

None of this diminishes the importance of cyber security fundamentals. In fact, it reinforces them. Strong identity management, least privilege, segmentation, monitoring, governance and continuous assurance remain the controls that determine what an attacker, whether human or AI, is ultimately able to achieve. AI may discover attack paths more quickly, but well-designed architecture and disciplined security engineering determine whether those paths exist in the first place. The fundamentals have not changed, but their importance has certainly increased.

AI agents need to be governed as digital identities

As organisations introduce autonomous AI into business operations, governance must evolve alongside it. AI agents should no longer be viewed simply as software or automation. They are becoming a new class of digital identity. Every AI agent should have its own managed identity, clearly defined permissions, explicit trust boundaries and comprehensive audit trails. More importantly, organisations must understand not only what an AI agent is authorised to access, but also the relationships and connections it can discover or traverse once it begins operating. Those relationships will increasingly determine an AI agent’s capability far more than the model itself.

Human judgement therefore becomes even more important, not less. AI is exceptionally good at analysing billions of events, correlating vast numbers of signals and responding at machine speed. No Security Operations Centre will realistically operate without this level of augmentation in the years ahead. Governance, however, remains a human responsibility.

People determine risk appetite, approve trust relationships, define policy, own accountability and decide which relationships should exist in the first place. AI should augment those decisions, not replace them. The emergence of Microsoft’s MDASH, the Open Secure AI Alliance, the United States’ GOLD EAGLE programme and the United Kingdom’s Cyber Shield demonstrates that governments and industry are converging on a shared direction of travel. Collective cyber defence will increasingly depend upon collective intelligence, shared telemetry and AI operating alongside experienced cyber professionals. That is both necessary and welcome. However, these initiatives should not distract organisations from a more enduring truth. Technology alone has never delivered cyber resilience. Understanding and governing digital ecosystems will become one of the defining disciplines of cyber security in the AI era.

The AI era will be defined by understanding complexity

The OpenAI announcement will undoubtedly be remembered as one of the defining cyber security stories of the year. I suspect, however, that history will judge it rather differently from today’s headlines. Rather than marking the moment AI “went rogue”, it may come to represent the moment our industry recognised that cyber resilience is no longer determined by how well we protect individual technologies. It is determined by how well we understand and govern the digital interdependencies that underpin increasingly complex digital ecosystems.

Deploying the most advanced AI models isn’t the answer on its own. Organisations must understand and govern their digital ecosystems, combining intelligent automation with strong cyber fundamentals, disciplined architecture and effective human leadership. AI will increasingly defend against AI, but cyber resilience will continue to depend upon people who understand the relationships between identities, systems and information before attackers do.

More from our Opinions section

About The Author

Avatar photo
Richard Holland

Richard Holland is a cybersecurity and technology leader with more than 25 years’ experience helping organisations navigate complex technology, security and digital challenges. As Field CISO at Quorum Cyber, Richard brings extensive experience in cybersecurity strategy, technology leadership and innovation.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.