Ten controls to establish first.

Control 1

Inventory every AI assistant, model gateway, agent platform, MCP server, and coding assistant in use.

Control 2

Classify workflows by data sensitivity: public, internal, confidential, regulated, source code, and production operations.

Control 3

Route enterprise AI usage through approved providers or model gateways where possible.

Control 4

Give agents distinct identities instead of shared human accounts or broad service accounts.

Control 5

Separate read-only analysis from write-capable automation and destructive actions.

Control 6

Block secrets, customer data, and regulated data from unapproved prompts, uploads, logs, and connectors.

Control 7

Review MCP servers, browser tools, shell tools, file access, network access, and OAuth flows before use.

Control 8

Log model, user, agent, repository, tool call, policy decision, cost, and outcome metadata.

Control 9

Require human approval for production changes, credential rotation, package publishing, and customer-impacting actions.

Control 10

Add AI-specific scenarios to incident response, tabletop exercises, vendor reviews, and board reporting.

The CISO message: AI risk is an operating-model risk.

The board does not need a model taxonomy. It needs to know which AI systems are approved, what data they can touch, what agents can do, who owns exceptions, and how the organization will detect and recover from unsafe AI behavior.