Another great question that came in from my SANS Keynote at CloudSecNext was: How do you manage critical AI Security conversations with executives?
It’s a great question because, let’s be honest, this one can get tricky fast.
We’re well past the security team as the “Department of No” era, but AI is moving at a pace that can make even the most forward-leaning security team feel like it’s holding on to the bumper of a race car. The business is eager to accelerate, headlines are fueling FOMO (fear of missing out), the CEO is excited about customer growth, the CFO is chasing efficiency gains, and the CTO sees an opportunity to double feature delivery speed. Meanwhile, security and risk teams are just trying to ensure the brakes work before we hit that first hairpin turn.
The challenge is that many executives and board members don’t yet grasp the scope of AI risk, or worse, may see security and governance as friction rather than protection. The key to turning that perception around is how you prepare, what you emphasize, and how you show up in the room.
Speak the Executives’ Language
Executives are measured by growth and market advantage. Their focus is on speed, innovation, and reputation, so that’s the language you need to speak. Make it clear you’re not trying to slow innovation; you’re trying to ensure the business can go faster, safely.
Being well-prepared can help you show up in a way that inspires trust. To refine your presence and get ready for the conversation:
- Keep your Composure: Leaders who command attention show calm confidence, they expect to be heard because what they have to say matters.
- Build Your Allies: Don’t present a major initiative like AI governance alone. Talk with your peers, especially in technology, legal, and compliance, beforehand. Their early support gives your message weight when it reaches the boardroom.
- Translate the Language of Risk: Speak in business outcomes, not technical exploits. Instead of “prompt injection” or “LLM exfiltration,” talk about the loss of intellectual property, unauthorized data exposure, or regulatory penalties. Whenever possible, use credible numbers or industry benchmarks to quantify impact.
- Stay Focused and Visual: Executives’ time is measured in seconds. Keep your message sharp and supported with visuals: risk matrices, clear metrics, and trend charts go a long way toward making complex AI risks tangible.
Governance: Guide Rail, Not Road Block
After FOMO, one of the biggest executive anxieties about AI is regulatory uncertainty. That’s why governance is a strong starting point for this conversation.
Position governance not as a barrier but as a guide rail, the structure that keeps innovation on the road. Dedicated AI governance is necessary because traditional governance practices are often ill-suited for the speed and opacity of AI systems. Help executives understand the regulatory landscape that impacts your business today and inform them of upcoming framework and compliance standards. For example, an ISO/IEC 27001:2022 company may wish to become ISO/IEC 42001:2023 compliant too. Or a NIST SP 800-53 Rev. 5 organization could be very interested in understanding the potential business implications of the upcoming SP 800-53 Control Overlays for Securing AI Systems COSAiS. Connecting your program to recognized standards shows leadership that your approach is structured, defensible, and forward-looking.
To help with a high level visual, you can structure the entire conversation around a risk management framework, such as the NIST AI Risk Management Framework (AI RMF), which organizes trustworthy AI practices into four functions.
- Govern: Establish the accountability structures; the buck ultimately stops with the executive team. This function ensures that legal and regulatory requirements (like the upcoming EU AI Act) are understood and managed.
- Map: Establish context and identify risks and potential impacts based on the specific AI application or service. This involves checking assumptions about intended use and evaluating the potential for both beneficial and harmful impacts.
- Measure: Use tools and metrics to analyze and monitor AI risk and related impacts, especially focusing on trustworthiness characteristics like validity, reliability, and security.
- Manage: Prioritize, respond to, and allocate resources to the mapped and measured risks.
Shift to AI-Specific Threats and Liabilities
Now that the execs understand the governance baselines and regulatory and compliance implications, you can help them get a grounding in the ways that AI introduces new and nuanced security risks that current tools or processes may not cover.
Keeping the “language of the business” in mind, it can help to frame these risks as potential road blocks to their AI dreams if the risks are not threat modeled and addressed prior to AI deployment. Here are a few ideas to help you get started as you think about prioritized risks that translate directly into clear business liability for your organization.
Financial Damage from AI Powered Attacks – Generative AI lowers the barriers to entry. CrowdStrike reported a significant surge in social engineering attacks, particularly vishing (voice phishing often powered by AI), which skyrocketed 442% between the first and second half of 2024. These attacks can lead to big losses.
In February 2024, a financial worker attended a video call that used AI to deepfake video and voice clones of the company’s chief financial officer and other employees. The attack was a success and the employee transferred $25.6 million USD to the attacker.
Reputational Risk from AI System Failures – An organization’s reputation can be threatened when AI systems behave unexpectedly or unethically. Many AI systems lack transparency and “explainability”, which makes it difficult to assure that outputs align with the company’s values, ethics, and purpose. Moreover, AI output can drift and is vulnerable to prompt injection attacks. When an AI system produces demonstrably false or biased outputs, it creates legal and reputational risk.
A judge ruled that attorneys Peter LoDuca and Steven Schwartz “abandoned their responsibilities” when they used ChatGPT for legal research, and included AI fabricated legal citations in court filings. This led to fines and professional consequences for the attorneys and their law firm.
Data Breach via Agentic AI Exploitation – AI systems are vulnerable to novel attacks like direct and indirect prompt injection, which involves tricking the Large Language Model (LLM) into ignoring its prior safety instructions and executing attacker commands. This is especially relevant as organizations deploy agentic AI workflows that may have access to sensitive internal resources. This attack vector can be used to bypass security filters, reveal confidential information, or compromise data.
In September 2025, Noma Security researchers reported a vulnerability in Salesforce Agentforce, when external attackers used an indirect prompt injection attack to embed malicious instructions within trusted lead data processed by the AI agent. This compromise allowed the agent to exfiltrate sensitive CRM data, potentially resulting in customer data exposure, compliance violations, and competitive intelligence theft.
Destruction and Operational Integrity Loss – AI systems are also vulnerable to manipulation that lead to damage caused by destruction of critical data. This is especially true in agentic workflows where AI has access to a wide variety of tools and resources.
An AI coding service, Replit, deleted a production database despite explicit instructions from the application owner to enforce a “code freeze” and not make any changes. The service admitted to a “catastrophic error of judgement” and having “violated your explicit trust and instructions”.
Get In and Drive
AI risk conversations shouldn’t be a one-time pit stop. They should evolve into an on-going conversation, regular maintenance that keeps the engine of innovation running safely at high speed. Before your first executive session, prepare supporting data, coordinate with key allies, and arrive with solutions for every high-risk issue you present. Remember, executives don’t want to hear “We have a problem.” They want to hear “Here’s the problem, and here’s how I recommend we address it.” Most importantly, keep showing up. Schedule regular updates, brief them on both regulatory shifts and new AI threat patterns, and position yourself as a strategic advisor who helps the business innovate confidently.
When you align security objectives with growth, you stop being seen as the brake and start being seen as the traction control that keeps the business moving forward.


