
Talk about AI in a room full of people who didn’t watch Star Trek and Star Wars as a favourite pastime, and you’re bound to get people thinking about how they did the “Hugging Your Younger Self” or “Caricature of myself” AI trend or tell you about their fear of losing their job to AI. Yes, AI can absolutely make fun photos, and it’s getting really good at it, too. But I doubt AI will be after your job in the short run.
AI has moved way past the chatbot and meme-maker stage and can now play a vital role in both cybersecurity engineering and in compliance. We all saw the Anthropic Mythos press releasewith the fear that AI would be used to perform autonomous cyber-attacks. Now, AI won’t necessarily take your job if you can work with AI and not against it; what I’m talking about is using AI agents to reduce repetitive work and instead create actionable workflows.
The Reality of Continuous Compliance
Compliance isn’t only about passing an annual audit or getting certified. The European Union’s NIS2 Directive requires you to be continuously compliant, and you therefore cannot get a static certificate. You’re expected to be able to show at any time that you are compliant.
AI agents can lend a very helpful hand in that. As a GRC professional working with IT teams, you’ll be all too familiar with the concept of working against the clock when it comes to adhering to regulatory response times. For example, DORA (Digital Operational Resilience Act), a regulation focused primarily on financial institutions, requires you to submit an initial notification within fourhours of a major incident. If 10% of your clients are affected by an outage, it is automatically considered a major incident under these rules.
Enter Agentic AI
Get used to hearing a lot more about Agentic AI. If GenAI (Generative AI) is the parent that can produce a policy document, Agentic AI is the kid with enough energy to power a small town. This technology can automatically check the policy document against the actual controls in your network and system, if you let it. It can draft a suggested response and then immediately go back for another round of snooping for anomalies.
An open Model Context Protocol (MCP) server can actively monitor and alert you if your policy is not being followed. That adds value and reduces risk because you can spend time analysing and remediating gaps rather than finding them.
Streamlining Third-Party Risk
Now imagine AI doing that work on a scale for all your vendors. That’s time-savings multiplied by your number of third parties – for a global company we’re talking 1000 vendors or more. Checking for vendor compliance is work that is largely still being carried out by GRC teams. This often involves requesting, via comparison to other methods, insecure email, 100+ answers to questionnaires to be filled out by people who are already exhausted from filling out a differently worded questionnaire from each of their vendors!
Once they’ve finally returned the answers, the GRC clerk logs it, and it goes through the corporate papermill. By that point, the reality might be that the answer to many questions is already obsolete. Imagine instead an AI agent being constantly connected, checking for gaps in compliance and then sending alerts when it fails.
The amount of time saved here would drastically reduce the risk of incorrectly filled-out questionnaires. It would also allow more time for remediating actual gaps in compliance. Not to mention, it reduces the risk of heavy regulatory fines for non-compliance of reporting a potential major incident.
The Human Governance Filter
“But you said AI wasn’t taking over the jobs!”. Indeed, I did. Despite all the beauty of Agentic AI, it absolutely needs someone who governs it. AI always needs a safety net, a guardrail if you will.
We shouldn’t – certainly not now – let AI loose without any human oversight. Us humans are good at spotting patterns and can see when things aren’t right; we make judgment calls nearly asfast as AI creates code. Relying entirely on AI is a disaster waiting to happen.
The AI agent should investigate, find and notify and maybe even draft a fix, but not be allowed to alter production environments on its own. Yes – absolutely use an AI notetaker for your meetings to remain effective. Just make sure you first ask for permission from the participants and ensure it is fully sanctioned by your organisation. But remember, you cannot rely on it to understand complex human context or subtle tone of voice.
You wouldn’t want an agent to patch a hospital system without human oversight as the consequences could be disastrous. For example, it might take down the hospital’s primary patient database. Having a human in the loop makes sure that human common sense and ethics guide the technical work, not the other way around.
The True Cost of Shadow AI
According to data from the IBM Cost of a Data Breach Report, organisations using AI and automated tools in incident response cut their Mean Time to Identify (MTTI) and Contain (MTTC) threats by up to 33%. This optimization makes tight regulatory reporting windows much easier to comply with. While AI can help speed up and streamline your compliance and defence, IBM warns that the speed of AI adoption is outpacing security and governance. Their report highlights that a vast majority (97%) of organisations that experienced an AI-related security incident lacked proper AI access controls.
Unsanctioned or ungoverned AI (shadow AI) can add high costs to a breach. The IBM report says that shadow AI adds 670k USD (500k GBP) to a data breach, compared to an organisation where there was no shadow AI employed. Shadow AI is when an employee uses tools like a personal ChatGPT account or AI code assistants to be more effective at work. The organisation hasn’t set a proper AI policy in place, or the policy might even be actively ignored for the sake of speed.
Employees often ignore protocols under the false assumption that “nobody will notice”. The free AI tools installed are hence not being governed or monitored by internal security teams. Because of this, employees might inadvertently be entering data into the “free” AI model or giving it access to email that processes PII data. These free AI models use that sensitive corporate data to train on it, potentially exposing it to competitors or threat actors looking for the data.
You might recall when Samsung had three separate AI data leaks in one month. Employees were pasting internal meeting transcripts, source code, and chip test sequences into ChatGPT. It can happen to the best of us if we’re not careful.
The way around shadow AI is simply for organisations to lean into it. Find an AI tool that you approve of and restrict employees to using that one alone. The alternative is, unfortunately, that employees will find tools on their own, risk compromising your data and leaving you open to regulatory fines.
And if you’re wondering about the title of the article, your next GRC hire might be an AI agent or AI solution that helps you with the mind-numbing collection of questionnaires and policy documents. But you will need to keep an analyst, too.



