Entrata CTO and CISO: Treat AI adoption as operating-model change
Entrata's CTO and CISO argue AI adoption needs data-access controls and verification to avoid security risks.
For the past eighteen months, teams have moved from debating whether to use AI to debating how fast to deploy it, the executives said. Real adoption starts when leaders understand how work actually gets done. A finance team, product team, marketing team, support team and engineering team will not use AI tools in the same way because each group has different knowledge requirements, data sources, risk thresholds and experience. Leaders should ask what each function is trying to accomplish, what knowledge and skills are required to use AI responsibly, and what tools or data sources are necessary to produce a reliable result.
Data access is one of the clearest places where AI changes the operating model, according to the column. Teams often need information they did not previously use directly, but broader access can create privacy, compliance and security concerns. The authors recommend separating lower-risk operational data from more sensitive information and limiting the “blast radius” of data, because not every dataset carries the same risk and not every AI use case deserves the same restriction. They cite an enterprise rollout where the answer was not to give every team access to everything, but to give teams enough access to work differently while limiting potential damage. Personally identifiable information and sensitive customer data require much tighter controls.
Verification must also be built into workflows, the authors wrote. AI systems can produce work that looks polished but is incomplete, inaccurate, off-brand or noncompliant, and while human review can absorb some risk in the early stages, it does not scale well once AI becomes embedded in daily operations. In technical teams, AI can accelerate software development only if there is a reliable way to evaluate the quality, security and accuracy of what gets produced. The goal is not to make security lighter, but more precise, so the company can move faster without losing control of the environments, data and workflows that matter most.