The arrival of Artificial Intelligence (AI) has generated considerable excitement across every sector, with few disputing its transformative potential. From improving productivity and decision-making to enhancing cybersecurity itself, AI is rapidly becoming an integral part of the modern workplace.
However, with great opportunity comes great responsibility. Recent reports of AI-related security incidents, coupled with guidance from the UK National Cyber Security Centre (NCSC), highlight an important reality: organisations must balance innovation with robust security measures. The question is no longer whether AI will be adopted, but whether it will be adopted safely and effectively.
For professionals working across government and critical national infrastructure, staying current in such a fast-moving environment can be challenging. Events such as DigiGov 2026 offer valuable opportunities to learn from peers, industry experts and practitioners.
Yet keeping pace with AI requires a structured approach to understanding AI's capabilities, managing its risks and establishing the governance needed to support its safe use.
To address this, I suggest a simple framework built around three pillars: Capability, Risk and Governance.
In my experience, the organisations achieving the greatest success with AI are not necessarily those adopting it the fastest, but those building the strongest foundations around capability, risk management and governance.
When considering AI from a cybersecurity perspective, it is helpful to view it through two complementary lenses.
The first is AI for Security which involves leveraging AI to enhance cybersecurity capabilities. For example, Fortinet has been integrating AI into its security services for over a decade.
Tip: To better understand how AI enhances security, organisations should encourage teams to follow vendor training and industry blogs to build knowledge of sophisticated AI-driven cybersecurity. This enables organisations to select, manage and use these technologies more effectively.
The second lens is Security for AI, which focuses on securing the use of AI by users to ensure the safe handling of data when accessing external AI tools. Sending sensitive data to unknown AI applications is a potential security and compliance risk, and monitoring those data flows can help prevent security incidents and support user education.
Tip: Assess organisational AI competency and identify where training can be used to address potential skill gaps.
Tip: Consider using leading free online cybersecurity training resources to maximise budgets while ensuring staff remain current. AI is a fast-moving field, and its associated risks continue to evolve, requiring a coordinated team effort. Fortinet refers to this approach as Continuous Threat Environment Management (CTEM).
With this foundation in place, organisations could have greater visibility of AI capabilities being used across the business, enabling associated risks to be identified and addressed more effectively.
The risks associated with using AI in the modern workplace may seem obvious, but without a clear understanding of how AI is being used, organisations may overlook threats that could cause significant harm.
Tip: Conduct an informal staff survey to understand current and planned AI usage as employees seek to make their working environment more efficient. Once user needs and likely interfaces are understood, it becomes easier to identify the tools being used and the associated risks.
Developing a risk map or matrix is a practical way to assess AI use cases against potential digital and human-related threats. Modern cybersecurity systems can now prevent inadvertent transmission of sensitive data to external AI applications.
Tip: Organisations should work with their cybersecurity provider to build a risk matrix and identify mitigation strategies for emerging threats. New products and capabilities, such as FortiDLP, can help balance the sensible use of AI with monitoring and prevention of inadvertent data loss.
Regularly discussing the latest threats and risk trends, every four to six months, is essential to avoid falling behind an increasingly fast-evolving threat landscape. These activities not only help define and manage risk but also allow those in leadership positions to address the third, and often overlooked, pillar of cybersecurity: governance.
Effective governance requires clear accountability. While several people may be responsible for managing and reducing a risk, a single individual should be accountable for overseeing them. If accountability or responsibility is unclear, it should be properly identified, agreed upon and formally documented.
Tip: Organisations should consider hosting an AI risk workshop with senior accountable leaders to balance the opportunities presented by new AI capabilities against the associated risks. The objective should be to develop joint recommendations and agree on a roadmap to address them. This process encourages a team approach to building adequate cybersecurity for the AI era, while also identifying additional resources that may be required.
AI has the potential to transform how organisations operate, innovate and deliver services. However, as AI becomes increasingly embedded in workplace culture, organisations must ensure that awareness of AI-related risks and the cybersecurity measures required to manage them become equally embedded. By focusing on capability, risk and governance, organisations can embrace AI with confidence, balancing innovation with security and unlocking AI's enormous potential safely, responsibly and sustainably.