The question most organizations are asking is: How do we secure our AI systems?
A more important question is: How are people across the organization using AI, and what risks does that create?
As AI adoption accelerates, enterprises are investing heavily in securing models, platforms, infrastructure, and data. These investments are important, but security strategies focus primarily on the technology stack, overlooking a critical factor: how people interact with AI. Increasingly, the greatest AI security challenges emerge not from the models themselves, but from the decisions surrounding their use.
Consider a few familiar scenarios: an employee enters sensitive data into a public GenAI tool, a developer deploys AI-generated code without adequate review, or a project team grants an autonomous agent broad system access to accelerate delivery.
In each case, the AI behaved exactly as it was designed to. The real gap wasn’t the technology—it was the absence of controls around how people were using it.
The limits of one-size-fits-all AI security
When organizations treat AI security primarily as a technology problem, they naturally invest in technology solutions—AI firewalls, runtime guardrails, and AI Security Posture Management. These capabilities are important, but they solve only part of the challenge. Effective AI security depends on understanding who is interacting with AI, how they are using it, and which risks those interactions create.
AI risk is highly contextual. An employee using a generative AI assistant to draft content operates within a markedly different risk environment than a developer generating production code. Teams integrating AI into customer-facing applications face different security and governance challenges than those deploying autonomous agents with access to enterprise systems. The complexity increases further for organizations building, training, or fine-tuning their own models, where risks extend to data quality, model evaluation, provenance, and behavioral drift.
Treating these distinct user groups as though they share the same risk profile creates blind spots. Governance frameworks that appear comprehensive on paper often fail to address the exposures that matter most in practice.
What changes when you start with behavior
When you organize AI security around personas rather than systems, the questions change.
Instead of asking, “Do we have an AI firewall?” you ask, “Which of our people are interacting with AI in ways that create data exposure, and what specific controls exist for those interactions?” Instead of asking, “Is our AI policy up to date?” you ask, “Is that policy translated into engineering-enforced controls that actually hold in production, under real conditions, at the moment someone makes a decision?”
This shift—from policy to behavior, and from declared governance to enforced governance—is where I see the biggest gap in enterprise AI security today. It is a gap that is growing faster than most security programs are evolving.
In the UAE, where AI adoption continues to accelerate, that gap carries particular significance. Regulatory expectations are evolving rapidly. Boards, regulators, and customers increasingly want evidence that AI systems operate safely, transparently, and under effective governance—not simply that policies exist. That requires controls aligned with how AI is actually used across the enterprise.
The uncomfortable question
I work with organizations at every stage of AI adoption—from those just beginning to inventory AI across their environments to those deploying autonomous agents at scale.
Across all of them, one question consistently changes the conversation:
If someone in your organization made a poor AI-related decision today—shared sensitive data, deployed an over-permissioned agent, or trusted an inaccurate output—would your security program detect it? Would it know where to look?
For many organizations, the honest answer is not yet. Not because they haven’t invested in AI security, but because their investments remain organized around technology rather than the behaviors that create risk.
Securing AI begins with understanding who is using AI, how they are using it, and what controls each interaction requires. Everything else—the governance, architecture, monitoring, and security controls—builds from that foundation.
Our latest white paper, Operationalizing AI Security in Business: A Persona-Centric Framework for the UAE, explores this approach in greater detail, providing a practical framework for securing AI Consumers, AI Deployers, and Model Developers across the enterprise.
AI risk is not the same for everyone. That is why AI security starts with the persona.
