THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Risk comes from not knowing what you are doing” Waren Buffett. Technology is evolving rapidly with artificial intelligence (AI) emerging as both a powerful tool and a formidable challenge in the realm of cybersecurity. As cybersecurity practitioners, we are witnessing firsthand the transformative impact AI has on our ability to defend against increasingly sophisticated cyber threats. AI serves a dual role in cybersecurity: it acts as both a shield and a sword. On one hand, AI-powered tools enhance our defensive capabilities, enabling us to detect and respond to threats more swiftly and accurately. On the other hand, cybercriminals are leveraging AI to develop more advanced and elusive attack methods.
Early this year, the story of “The Winchester House” was brought to my attention. For those unfamiliar with it, it is a large, historic mansion located in San Jose, California, renowned for its architectural oddities and mysterious past. Architectural features of this house include staircases that lead to walls and ceilings, and doors that open out into nothing among many other peculiarities.
“The Winchester House”, with its labyrinthine layout and perplexing design choices, is a testament to the anxieties and uncertainties of its builder, Sarah Winchester, but it can also be seen as a metaphor for Artificial Intelligence (AI) risks and cyber security concerns.
As AI and associated technologies continue to be developed and deployed across sectors, industries and companies on a global scale, there is no doubt that while value and benefits are being sought by businesses and organisations, some anxiety exists about risks that AI presents. The anxiety arises from risks such as security, transparency, privacy, accountability, and bias and fairness with many jurisdictions around the world rushing to develop laws and regulations to address them. This is no small feat as the technology is advancing rapidly and countries struggle to come to grips with the wide-reaching impact of AI.
That said, European Union (EU) has developed the AI Act which came into force on 1st August 2024. The act essentially adopts a risk-based approach, aiming to have AI based systems classified into risk categories, with different degrees of regulation applying. It is important to note that the EU AI Act does not only apply to the AI developed by organisations but also to those procured by the organisation.
“AI Presents A Labyrinth Of Risks, Concerns, And Threats That Require Careful Navigation, But With A Proactive Approach, We Can Harness Its Potential While Safeguarding Against Its Pitfalls.”
So, just as this historic house was an embodiment of the physical manifestation of its owner’s anxieties, it could also be viewed as a symbol for anxiety that could be present from the various concerns surrounding AI.
The Labyrinth of AI Risks
The Winchester House, with its staircases leading to nowhere and doors opening into walls, can be seen as a representation for the unpredictable and often opaque nature of AI deployments and development. Among the main issues typically associated with AI are:
1. Unintended Consequences
Just as Sarah Winchester's architectural choices resulted in a house filled with baffling features, AI solution and systems too can produce unforeseen outcomes. For example, poorly designed AI systems might inadvertently create vulnerabilities that cyber attackers could exploit. These unintended consequences can have significant impacts on safety, data subject rights and cybersecurity.
2. Ethical Dilemmas
The Winchester House is understood to echo the personal fears of its creator and in a similar fashion, broader societal values and dilemmas can be reflected in AI. These ethical quandaries may reflect issues such as a lack of transparency, bias in AI algorithms, the loss of privacy, and even the potential for AI to be used in harmful ways to people. These challenges in ethics and even values which need to be carefully considered in all AI development and deployment, present with some anxiety among stakeholders.
3. Risk Ownership
The Winchester House expanded in seemingly endless directions, without an apparent functional blueprint or qualified design. The breath of AI risk which spans more than the domain of cybersecurity may result in a lack of coordinated approach with respect to effective management of risk. This poses the question of just who should own AI risk in an organisation.
Some organisations have since ascribed this to a “Chief AI Officer” type role, with others embedding this in the role “Chief Risk Officer” or “Chief Ethical Officer” etc. However, the most common approach appears to be that this is left to Information Technology or the cyber security function with many organisations considering AI as simply a technical or data issue. It is obvious that while IT and cyber security practitioners have a role to play in the identification, treatment and monitoring of some AI risks, a multidisciplinary or cross functional approach is necessary to address this effectively.
Addressing AI Anxiety
To mitigate AI risks and navigate its complexities, a comprehensive and proactive approach needs to be adopted. Here are some strategies to consider,
Establish Policy and Oversight Framework
Just as the Winchester House would have benefited from a master architect's guidance, it is important that a policy for the development, procurement and deployment of AI in the organisation is established. The policy in essence sets the tone and foundation for AI development, deployment and use. In addition to communicating management expectations and intent with respect to AI, the policy must make clear the general principles and governance requirements for AI in the organisation.
Collaboration and Cross Functional Engagement
With AI projects impacting various aspects of an organisation, a holistic approach towards managing AI risk is crucial. To this end, collaboration between different teams, such as risk management practitioners, procurement, data scientists, software engineers, legal and compliance officers, data protection, security teams, and business leaders should be established. This ensures that all perspectives are considered, risks mitigated, and AI solutions are responsibly developed and deployed.
Training and Awareness
Given that AI systems can be rather complex, and their impact far-reaching, it is vital that all stakeholders are educated and informed about their responsibilities and of the risks involved for a successful and ethical adoption of AI. Proper training and awareness will assist those involved in AI development and use become aware of the ethical implications, including transparency, accountability, and fairness and help prevent unethical or irresponsible applications of AI. By fostering a culture of continuous learning, good outcomes can be experienced with AI.
Standards and Frameworks
To ensure that development or deployment of AI is consistent with established policy, clear guidelines, standard and principles must be created and communicated. By creating and embedding this framework into the fabric of the design, procurement and deployment of AI systems, we can help ensure that these technologies enhance rather than compromise enterprise goals and objectives.
Conclusion
The Winchester Mystery House stands as a symbol of the complexities and fears that can shape human endeavours. Similarly, the growing rise of AI presents a labyrinth of risks, concerns, and threats that requires careful navigation. By drawing lessons from the past and adopting a proactive approach, we can build a secure framework that harnesses the potential of AI while safeguarding against its pitfalls. In doing so, we will not only address the cybersecurity challenges of AI but also ensures that organisational goals are met, paving the way for a future where AI serves as a force for positive change and innovation.