Posts

Showing posts from May, 2026

AI Strategy #12. AI Security in the Agentic Era: From Prompt Injection to Identity and Tool Abuse

Agentic AI changes the security problem because a model is no longer limited to producing text. An enterprise agent can retrieve private data, maintain memory, choose tools, call APIs, communicate with other agents and alter the state of business systems. A successful prompt injection against a chatbot may produce a bad answer. The same injection against an agent with access to email, source code, ERP or customer data can become an authorization, data-loss or transaction-integrity incident. The important security boundary therefore moves beyond the model. Agentic AI security is not primarily about stopping the model from receiving a malicious instruction. It is about ensuring that an untrusted instruction cannot acquire trusted identity, privileged data or dangerous execution authority. This is why conventional cybersecurity remains essential but no longer sufficient by itself. Identity, least privilege, network segmentation, software supply-chain controls and incident respo...

AI Strategy #11. Enterprise AI Governance: From Policy to Runtime Control

Enterprise AI governance usually starts in the wrong place. Organizations write an AI policy, establish a steering committee and ask project teams to complete a risk questionnaire before deployment. Those controls are necessary, but they are not sufficient once AI moves from isolated experiments into hundreds of copilots, embedded models and agents operating across business systems. At that scale, governance has to become part of the enterprise operating architecture. AI governance becomes scalable when policy is converted into decision rights, lifecycle gates, machine-enforceable controls and evidence that can be inspected after the system enters production. The objective is not maximum control. A governance model that forces every low-risk productivity assistant through the same approval process as an employment decision system will eventually be bypassed. The stronger model differentiates risk, accelerates routine use cases and reserves deeper assurance for systems with g...

AI Strategy #10. EU AI Act in 2026: What Global Enterprises Need to Operationalize Now

The EU AI Act crossed an important threshold in 2026. Most of the Regulation became applicable on August 2, the European Commission and national authorities began exercising enforcement powers for applicable provisions, and new transparency requirements started affecting AI products already reaching users. But the strategic implication for a global enterprise is not simply that “EU AI regulation has started.” The more important change is that AI governance now has to distinguish legal role, system classification, model supply chain, deployment geography and operating authority at the individual AI-system level. The original version of this article framed the problem mainly as compliance for non-EU companies selling into Europe. That is too narrow. A multinational enterprise may simultaneously be a provider of one AI system, a deployer of another, a product manufacturer embedding AI into a regulated product, and a downstream customer of a general-purpose AI model. The EU AI Ac...