Q&A: Should enterprises actually slow down AI adoption?


Phil Christianson, CPO of Xurrent, considers, in conversation with Digital Journal, whether enterprises should actually slow down AI adoption (in light of recent news and conversations from AI leaders).  Christianson considers what a “slow down” would actually look like (and what enterprises should slow down), if AI capabilities are starting to outpace security and governance. Christianson, ‘s focus is with what’s missing in the AI governance conversation. 

Digital Journal: There’s growing discussion around slowing down AI development. Do you think enterprises should be slowing down their own AI adoption?

Phil Christianson: I think we’re conflating two very different conversations. There’s a conversation happening around the pace of frontier capability development, and then there’s the much larger population of software companies and enterprises figuring out what to do with models that already exist. Those are moving at completely different speeds.

There’s a frontier-capability race happening among a relatively small number of labs, and then there are millions of organizations trying to figure out what to do with models that have already shipped. Those aren’t the same race, and they shouldn’t be governed by the same conversation.

DJ: So what would “slowing down” actually look like for an enterprise?

Christianson: Honestly, many enterprises aren’t in a position to slow down. They’re still trying to turn AI on safely before their employees roll their own. The gap between having an AI policy and actually having AI in production doing useful work is still enormous at many organizations.

The same story is playing out on the vendor side. At Xurrent, we’ve added summarizers, low-code generators, virtual agents and AI agents that can function as members of an IT team, and we’re nowhere near the end of that list. Our customers are asking for more, not less. We need to make sure they can adopt it safely and have the right controls around it.

DJ: Are AI capabilities starting to outpace what security and governance teams can manage?

Christianson: I’d push back on that premise a little. The governance challenges haven’t fundamentally changed because we’re moving from foundational models to frontier models. They’re still the disciplines IT has been working on for years: identity, access control, change management, audit trails and knowing who approved what and why.

What’s changed is that we’re introducing a new type of actor into those workflows. An employee has an identity, a service account has defined permissions, and both operate within processes IT already understands. An AI agent can increasingly interact with those same systems and take action, so we need to apply that same discipline to something that isn’t a person and isn’t traditional software.

DJ: What do you think the AI governance conversation is missing?

Christianson: My hot take is that for AI to do anything consequential, a human still has to hand it the keys.

Someone has to give it access privileges, credentials, a browser session, API scopes or permission to act on a system. However capable these models become, there’s still very likely a person behind the keyboard who decided to point that AI at something.

That’s where I think the conversation needs to go. The thing worth slowing down isn’t necessarily the technology. It’s the rate at which organizations grant AI access without a record of who granted it, what it’s allowed to touch and how that access gets revoked.

Q: Why is that such a difficult problem for enterprises?

Christianson: A lot of organizations are still figuring out what AI looks like in production. There’s a big gap between having a policy on paper and actually having AI doing work inside the business.

IT has spent decades building processes around employees and service accounts. Organizations know how to manage access, approvals, changes and audit trails in those environments. AI is now entering those same workflows, and companies need to bring that same discipline with it.

DJ: If enterprises shouldn’t necessarily slow AI adoption, what should they be slowing down?

Christianson: I’d slow down the process of giving AI more access without knowing exactly what that access means.

Before an agent gets credentials, an API scope or permission to act on a system, an organization should be able to answer three basic questions: Who authorized it? What is it allowed to touch? And how do we revoke that access?  They should also have tools in place to monitor the actions taken.  I would also say that these considerations are not just about security and protection against AI – it’s really the same controls you’d put in place for any project. I think a great example we’ve seen is the onboarding of our AI-powered virtual agent (or chatbot). The challenge our customers have had is not about security or compliance; we have that covered. It’s about knowing whether this black box is returning the answers they want.  We’ve focused on adding administrative tooling to control, monitor and even massage the output that dramatically increased adoption.

AI adoption isn’t hypothetical anymore. Employees are using these tools, vendors are building them into their products, and customers are asking for more capabilities. The work now is making sure organizations can keep up with that adoption without losing track of who or what is acting inside their environment.



Q&A: Should enterprises actually slow down AI adoption?

#enterprises #slow #adoption

Leave a Reply

Your email address will not be published. Required fields are marked *