Organisations across every sector are accelerating their adoption of generative AI, driven by board-level expectations for rapid innovation and measurable business value. Yet the same boards are equally insistent that AI initiatives must not compromise security, privacy, or regulatory compliance, and not lead to runaway cost.
This dual mandate has placed CIOs and security leaders in a difficult position: they must move quickly enough to capture competitive advantage while ensuring that AI systems remain tightly governed, well-validated, and aligned with enterprise risk tolerance. Increasingly, these professionals need to find a way to effectively address both challenges at once – and successfully walk the AI security and ROI tightrope.
A minefield of risks to navigate
Today’s AI risks translate into an array of real-world consequences: corporate information leakage, regulatory penalties, reputational damage, contractual liability, and financial exposure.
One of the primary risks is an access management challenge: preventing sensitive information from reaching individuals or systems that should not have access to it. As organisations integrate generative AI into workflows, more data is transferred into AI platforms, creating additional exposure points. Each AI provider becomes another vendor whose controls, contractual commitments, and data-handling practices must be scrutinised.
The rise of agentic AI compounds these data security and privacy risks. Autonomous or semi-autonomous agents can perform tasks, trigger workflows, and access data without direct human oversight. This opens the door to unintended actions – an AI agent operating outside its scope or accessing restricted data – and these missteps can occur at unprecedented speed and scale.
Striking the right balance
The instinct to “lock everything down” in response to potential AI risk is understandable, but counterproductive. A system locked down to the point of impenetrability has no operational value. This is part of the security/ROI tightrope that must be walked and the balance that must be struck.
The right approach is to define AI use cases with great precision, and to understand what data each one requires. For both the organisation and individuals, this means drilling down on what information they absolutely need access to, down to the individual data element, and whether there’s a compelling business need for that access. It’s worth analysing whether the same workflow could be accomplished a different way, without access to that information.
In practice, organisations will likely want to default to “secure” for most AI use cases, and then deliberately determine what must be open and accessible rather than starting with accessibility and then trying to secure it after the fact.
Another part of the solution is creating a cultural shift within the organisation. Organisations need to foster a culture where employees are encouraged to use AI to explore better, faster, and more efficient ways of working – but to also use it thoughtfully and with sound judgment. The old cliches still apply: with great power comes great responsibility.
To help create a culture of responsibility, organisations should make it easy for their end users to “do the right thing” and harder for them to “do the wrong thing”. For instance, providing an enterprise-licensed AI platform encourages employees to stay within approved systems and reduces the likelihood they’ll turn to unsanctioned tools – lowering the chance of shadow AI.
A framework for measuring success
Concurrent with addressing security concerns, leaders can focus on the ROI side of the equation. Measuring that ROI can be challenging – but fortunately, the upfront work on defining use cases pays dividends on this front as well.
Organisations should define use cases with explicit expectations for cost savings, productivity gains, or other measurable outcomes. If you don’t define what success looks like, you can’t judge what kind of return on investment you received.
Once those success criteria are established, the path forward inevitably involves experimentation, and not every effort will deliver equal returns. There will be successes as well as projects that don’t pan out.
Identifying the bright spots – the AI use cases that deliver real value and can be replicated across the organisation – accelerates adoption and lifts overall productivity. Just as important is learning from the efforts that don’t deliver as expected. Those outcomes provide the insight needed to refine assumptions, sharpen priorities, and redirect resources.
Early use cases may require meaningful time and attention as employees learn new tools, but the learning curve shortens quickly. Over time, the wins compound, the missteps become instructive rather than costly, and the organisation grows more adept at spotting high value applications.
Keeping an eye on cost
While they’re focusing on ROI, organisations will want to pay attention to one of the elephants in the room when it comes to AI: the compute cost. Each AI interaction consumes tokens, which translate directly into energy usage and financial cost.
Organisations can reduce waste by educating employees on effective prompting, selecting the right model for the right task, and leveraging in-memory context to minimise unnecessary iterations.
These practices mirror simple energy-saving behaviours – like turning off lights when leaving a room – but applied to AI usage. Just as on the security front, this educational component and cultural shift can go a long way towards moving ROI in the right direction. Otherwise, organisations might risk seeing the productivity gains on one side of the ROI ledger being nullified by an enormous AI token consumption expense on the other.
A little discernment goes a long way
As AI becomes more deeply embedded in organisational life, discernment is rapidly emerging as one of the most consequential leadership competencies of the AI era.
Discernment means the ability to pause and assess: What are the risks with a particular AI usage? What could go wrong? What does success look like and how can we best position ourselves to build on that success? What are the potential costs or expenses – and are there ways for us to optimize around those factors so that our overall ROI isn’t impacted?
The security/ROI tightrope is not going away. But with the right approach and a discerning mindset, it is entirely possible to walk it with confidence, enabling organisations to move fast with AI without compromising the business or its reputation.
Joe Logan is Chief Information Officer at iManage. He is responsible for the alignment of security, data engineering, and IT, at the company.
The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.


