All articles
Distributed AI Adoption Is Forcing Security Governance To Become An Escalation System
Matthew Sharp, Chief Information Security Officer at Xactly Corp, argues that AI decisions now surface in too many rooms at once for any single governance model to review them all.

Make The Security Digest one of your go-to sources on Google
How many departments do you have? If they're all involved, then they're all involved.
A company can approve its AI investments at the executive level and still find many of its AI decisions happening somewhere else. Marketing tests a chatbot on customer lists, support pilots a summarizer against ticket transcripts, and developers lean on models to generate code. Independent choices move company data through a third-party system, but only some reach the formal AI governance process. Adoption is often running at the departmental and individual level, leaving security without a single point where it can meaningfully review every decision. The advice to "bring the CISO in earlier" assumes one conversation is happening, but AI adoption starts dozens of them.
Matthew Sharp, Chief Information Security Officer at Xactly Corp and co-author of The CISO Evolution, has spent years arguing that security leaders need financial fluency to be useful in executive conversations. At Xactly, a Vista-backed revenue intelligence company, he's living it. AI decisions surface in product development, departmental tooling and individual workflows all at once, making a single seat at a single table insufficient.
The approved list was never going to be the whole list
Sharp frames enterprise AI as two obligations running in parallel. Companies have to "adopt AI to drive efficiency across the business," he says, and they also have to "embed AI into your value streams in order to deliver outcomes for customers." Both paths run through a stack of vendors, each with its own shared responsibility model, which puts third-party risk in front of security before anyone writes a line of integration code. A moving regulatory picture sits on top, so the questions read like scoping exercises: "What can we do within the constraints of the law, and if we do those things, what additional investments are going to be required for us to do them in a way that is compliant with the law?"
Formal programs capture only part of this. In any company with an AI-first mandate, Sharp says, "there's a lot of people in your org who are not a part of that big central set of cohort investments that are going to still have exposure to AI tools and be eager to experiment with those tools" inside their own workflows.
That experimentation is exactly what makes centralized governance incomplete, and it's hard to discourage when employees are just trying to do their jobs faster. Sharp's answer starts with expectations rather than enforcement. "At the highest level you have to have some tolerance for ambiguity," he says, "and then you also have to define your ROI as a hypothesis that gets measured and validated on the back end." Marketing, support, professional services and engineering each perceive a different payback, so the measurement has to bend to the work.
Meeting ten times isn't governance
Sharp is often asked how many people belong in the room, and his answer depends entirely on how the company is structured. If the company is running ten or fifteen AI initiatives across its core departments, there's room to experiment. Once the transformation touches everything, every department ends up in the room whether anyone planned it that way or not. "How many departments do you have? If they're all involved, then they're all involved."
The waste shows up when a standing core team gets replicated department by department. Put general counsel, the CISO, the FP&A team and corporate IT on every initiative across ten departments, and those back-office players sit through "that same meeting 10 times. That seems relatively inefficient."
The opposite failure worries him more, where a small group carries decisions it has no context to make. Four people running AI adoption for a large organization won't hold the security and privacy implications, and they almost certainly won't hold the cost picture. "Those four people had better be making high-level decisions and pulling in people in subsequent conversations," he says, "because if they're just driving it, what it means is they are aggressively adopting AI in a way that's going to put them in hot water. They just don't have enough context in order to make fully informed decisions."
Both failures point to the same answer: an escalation system where the organization knows which decisions belong in which room and when one has crossed a threshold that requires security, legal, finance or IT. Expertise gets pulled toward the decision instead of seated permanently beside it.
Moving security into capital allocation
Inside those rooms, Sharp's answer is for security to speak the language already in use. Xactly works with a cyber risk quantification vendor "that's helping us identify a median annualized loss expectancy," he says, "and as we then map that to controls and control maturity, you can gain a sense for base rate metrics, and that helps direct investments in terms of capital allocation."
Security needs a voice in investment decisions while they're still being shaped. For AI, Sharp builds the estimate from the pieces that exist. Control maturity gets measured against a cross-mapped framework covering the EU AI Act, ISO/IEC 42001 and several major vendor governance models. Regulatory exposure gets inferred from published penalty tiers, which under Article 99 of the EU AI Act reach 7% of worldwide annual turnover for prohibited practices and 3% for the provider and deployer obligations an enterprise software company is far likelier to meet. "This is the kind of data we have, here's the kinds of activities that we're doing with that data, and here is the range of inferred legal and regulatory fines that we're likely to experience."
The number carries wide error bars, and Sharp would rather name them than dress a framework score up as coverage. Ask him how exposed the company is by putting one AI tool into one marketing workflow, and he'll answer that it sits a level above that question.
AI risk still has no established price
The math stays rough because the data barely exists yet. Quantification vendors work without deep historical loss data on AI incidents, and the courts haven't produced the enforcement record that turns a law into a dollar figure. Sharp expects the AI Act to follow GDPR's playbook: marquee cases against large platforms first, then litigation that works its way down into the enterprise and mid-market.
He treats convergence among the major AI companies as another usable proxy. When the published responsible-AI approaches from Google, Microsoft, Meta, Anthropic and OpenAI broadly agree on a control, he argues, a security team has reason to treat it as an emerging standard of care. "All the major players include that these controls are considered best practices," Sharp says, so a team can expect them to "be considered reasonable by the legal community and become a part of the legal precedent."
The rules themselves keep moving, which argues for an operating model that can absorb revision. Colorado's AI law became an early reference point for state AI regulation before lawmakers repealed and replaced the statute in May 2026 and pushed the effective date to January 2027, and the AI Act itself was amended in July by the Digital Omnibus. Programs anchored to one expected regulation went back to redo the work.
"There aren't proven best practices in AI. There's no consolidation in terms of the best vendors in the space. There's no legal precedent established through long-standing years of litigation against these laws. All of those things create uncertainty that we're going to have to navigate," Sharp says. Security leaders don't have the loss history they'd normally use to price risk, so they're building estimates from what they do have: penalty tiers, framework maturity scores and whatever consensus the industry has reached so far. The governance model that holds up is the one that keeps making defensible calls as the data, the case law and the technology all continue to evolve.






