The Security Strategist · Aug 27, 2026 · 24:36
Listen in the Podli app 🎧
Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.
AI adoption is moving faster than ever, and many organisations are struggling to put controls in place. Employees are already using AI to analyse information, write content, support decisions and solve problems. As a result, this often happens before security teams have had the opportunity to understand which tools are being used or what data is being shared with them.
For Alan Hamilton, Global Chief Information Security Officer at GAM Investments, this is where the security challenge begins. With more than 20 years in security and responsibility spanning 16 jurisdictions and 32 regulators, Hamilton has seen how quickly a technology can move from experimentation to becoming part of everyday operations. In conversation with EM360Tech Head of Content and Podcast Host Trisha Pillay, he shares that organisations cannot secure what they cannot see.
The issue is not simply whether employees are using AI. It is whether security teams understand how it is being used, what information is entering these systems, and what happens as AI begins to act rather than simply provide answers.
AI Has Already Entered the WorkplaceThe speed of AI adoption is creating a visibility problem for security teams. Employees can access public AI services with very little friction, meaning the technology can become embedded in workflows before an organisation has established policies, approved tools or monitoring.
Hamilton points to data exposure as one of the immediate concerns. Without appropriate controls, security teams have limited visibility into which AI services employees are using or what information they are putting into them. He describes examples where sensitive financial information was uploaded to a public AI service, forcing an organisation to release results earlier than planned. He also recounts a case where proprietary development code was entered into a public AI tool and subsequently reproduced by the service, compromising what had been a competitive advantage. This makes AI governance a practical security issue rather than a policy exercise.
Hamilton's answer is not to block AI altogether. In his view, attempting to prohibit its use can simply push employees towards less visible services, potentially increasing rather than reducing the risk. Instead, security teams need visibility into AI activity, including the ability to monitor prompts and apply data loss prevention controls to web-based AI services.
This is an important distinction for organisations moving into a more AI-dependent operating model: control does not necessarily mean prohibition.
Security Has to Understand What the Business NeedsVisibility alone is not enough. Security teams also need to understand why employees are turning to particular AI tools in the first place.
Hamilton describes how GAM has approached requests for AI tools outside its approved environment by examining the underlying business requirement. In some cases, a requested capability can be brought into an existing controlled environment. In others, particularly where investment professionals require specialised AI capabilities, the organisation can conduct due diligence and bring appropriate tools into its approved framework.
That approach recognises an uncomfortable reality: the most secure tool on paper is not necessarily the tool that employees will use.
If security departments simply dictate which tools employees can use without understanding their requirements, Hamilton warns that users will look for workarounds. The result is a familiar security problem, but with AI making it easier to create: technology operating outside the organisation's visibility and control.
This becomes particularly important as AI moves beyond conventional chatbots. Once systems are given the ability to take actions, organisations can no longer treat them like ordinary software.
Hamilton argues that AI systems need to be onboarded with clear boundaries, much like a new employee. Organisations need to establish what a system is allowed to do, which patterns it should follow, and what falls outside acceptable behaviour. The reason is straightforward: an AI system does not apply the same ethical judgement as a person. If an action appears to solve the problem it has been given, it may pursue that route unless appropriate restrictions are in place.
And responsibility does not disappear simply because an AI system made the decision. Hamilton stresses that organisations and their executives can still be held accountable for actions taken by AI, particularly in regulated environments.
AI Is Changing the Speed of the Security GameThe other side of the equation is that organisations are not only defending against AI-assisted activity; they are also facing attackers who can use AI to operate faster.
Phishing provides one of the clearest examples. Hamilton describes a dramatic increase in phishing activity, with attacks now changing rapidly in response to defensive controls. On one occasion, his organisation received 17,000 phishing emails between 7 am and 11 am, with hundreds of new rules generated to respond to the changing attacks.
For security teams, this changes the economics of response. A human team cannot manually analyse and respond to thousands of evolving attacks at machine speed. Hamilton's organisation has therefore introduced AI-based email security capable of analysing messages and adapting its rules as attacks change.
The same acceleration is affecting vulnerability management. AI-assisted discovery can uncover large numbers of vulnerabilities in a short period, creating substantial testing and patching workloa
Episodes: The Security Strategist