All articles
Solving The AI Security Challenge Starts With Governance And Human Verification
With AI outpacing governance, Skylan T. Jones walks through why security programs need executive access, mid-level authority, and human verification before AI can strengthen the operation.

Make The Security Digest one of your go-to sources on Google
We aren’t startup companies. We’re freight trains. We can’t move fast and break things — that can’t be the philosophy. Otherwise missions can fail, money is lost, shareholder value is diminished.
Cybersecurity is now a core business risk rather than a contained IT problem, and the fast-paced adoption of AI tools is changing how security teams operate against that backdrop. Automated threat vectors and defensive solutions are moving faster than current governance frameworks can keep up with, producing an illusion of coverage when the underlying operational foundation is weak. Throwing AI at a security problem doesn't automatically solve it. The clearer consensus emerging across the industry is that AI works best when it amplifies strong human fundamentals.
Skylan T. Jones has spent nearly a decade securing high-stakes environments where the margin for error is close to zero. He holds CISSP, CISM, CISA, and Security+ certifications and has directed global communications security programs and safeguarded zero-fail networks across military operations, the International Space Administration, and higher education. His starting point for evaluating any security program is the reporting structure that determines whether real risk gets seen by leadership.
"We aren’t startup companies. We’re freight trains. We can’t move fast and break things — that can’t be the philosophy. Otherwise, missions can fail, money is lost, shareholder value is diminished," says Jones. The drive to move fast routinely exposes structural flaws inside the human organizational chart. Burying the CISO under the CIO creates a reporting-line conflict of interest where severe threats can get downgraded when they threaten the budget. The structural problem is one of the most common obstacles to boardroom accountability in security programs, and solving it requires CISOs to move beyond delivering technical status updates and start functioning as "risk translators" for the executive team.
Translation, authority, and human verification
Where the CISO sits in the reporting structure is only half the problem. The other half is what the CISO says once inside the boardroom. The technical vocabulary security leaders use every day rarely lands with executives who are evaluating cyber risk as a business trade-off. "CISOs might make the mistake of trying to go into board meetings and speak a lot of jargon that no one wants to hear and no one understands," he notes. "The CISO might be coming from a technical background where they are used to scripting and coding their way through problem-solving. It is the CISO's job now to translate cyber risk into a business language that everyone understands, keep it brief, and make it impactful."
The same accountability problem shows up one layer down at the mid-level program owner. Without a digitized tracking framework that assigns live ownership to specific deliverables with visible timelines, security programs run on manual status-gathering and informal authority. "You could have a program manager that sits in the ops side of the organization, but the implementers all sit in different parts of the organization and none of them necessarily answer to the program manager," Jones explains. "They set out requirements that need to be done, but the system implementors tell them that they don't have to do it right now."
AI moves the whole operational tempo faster and exposes the foundational weaknesses that were tolerable at slower speed. Jones points to recent high-profile IT disruptions like the CrowdStrike Falcon content update push and the SolarWinds supply chain compromise as examples of what could happen when human verification gets removed from the loop. "There is too much trust in the AI doing the QA," he observes. "A certain level of reliance on those systems is going to be necessary, especially moving forward as codebases get larger, but we still need to have a team of humans to fact-check the machines. Otherwise, missions fail. Money can be lost, and shareholder value can be diminished."
The agentic SOC challenge
The agentic era of AI has arrived inside the SOC before most security teams have finished figuring out what to do with it, and the practical challenge is finding the right balance of human oversight against the operational speed the tools promise. Forcing AI solutions onto unprepared analysts destabilizes operational norms faster than the efficiency gains materialize. The specific SOC risk is that analysts start reading a silent dashboard as an all-clear signal instead of as a prompt to investigate what the tools might be missing. "It really just comes down to understanding your systems and your governance documents on a personal level, and not simply relying on pasting system issues into AI to ask what to do according to NIST 800-53," Jones says.
The people side of the equation is where most SOC restructuring efforts around AI run into trouble. Organizations need analysts who understand both the systems the AI is monitoring and the AI tools doing the monitoring, and cutting headcount before the AI can genuinely operate without hand-holding produces exactly the blind spots Jones warns about. "Organizations need to not be so quick to shorten their workforce and replace them with AI agents that aren't fully fleshed out and still need a lot of hand-holding," he cautions. "If you don't understand your people, and AI should be lumped in as your people, you don't understand where their weaknesses are. And then there is a blind spot with organizations."
Before the blitz-scale
The pressure to deploy AI often comes from top-down mandates demanding immediate action, and the resulting scramble to meet compliance requirements produces a fragile security posture built on governance shortcuts, without the operational foundations that would make it durable. "A command will come down from the C-suite or a one-star general demanding that we start sending out assets to support a mission, and that we need to do it yesterday," Jones says. "People will try to meet three or four different governance policies and rush to implement these programs simply to meet that command. The programs end up in a much worse position than they would have been if we had taken the time to understand what it is we are trying to implement as a program."
Jones's strategic argument is that public and private sector organizations are freight trains, not startups. Moving at blitz-scaling speed without patch management, employee awareness, governance documents, and operational foundations produces programs that fail their first meaningful test. Building scalable risk programs means slowing organizational change long enough to assess tools, map team capabilities, and lay a foundation before layering AI on top of it. "Once you build that foundation, then you can blitzscale if necessary," Jones concludes. "You build a lot more organizational value, as opposed to a program thrown together with cardboard that gets blown down by its first real audit or incident."
The views and opinions expressed are those of Skylan T. Jones and do not represent the official views, policy, position, or endorsements of GDIT, The US Air Force, or Department of Defense.






