For CIOs and Heads of Unified Communications, the mandate has shifted dramatically: this time, saying "no" to AI isn't an option. Dan Nadir, Chief Product Officer, Theta Lake told us:
"In the past, compliance teams had the luxury of being able to not allow certain technologies to be enabled. But in 2026 - that horse has left the barn. The business is already applying extreme pressure for these tools to be widely adopted"
With 99% of firms expanding AI adoption and 88% reporting governance and security challenges, the question is no longer whether to enable AI - it's whether organizations can see and govern what happens after they do.
Beyond Guardrails: Why Access Controls Aren't Enough
Traditional security controls - authentication, access policies, data loss prevention - were designed for a world where humans created content. But AI introduces an entirely new participant that generates summaries, drafts communications, and surfaces information across everyday workflows at unprecedented scale.
Esteban Lopez, Senior Manager of Product & Technical Marketing, Theta Lake followed up to say:
"Organizations are betting big on AI, and its success depends on the quality of data it has access to and its ability to learn through meaningful human interactions. But there's no precedent for how humans will interact with AI, how AI will respond, or how AI-to-AI interactions will unfold. Traditional controls won't work - they won't scale."
The visibility gap is stark: guardrails are preventative, but verification is still required. Once AI is enabled, policies alone cannot prove what actually happened inside AI interactions. And when firms lock down AI tools too tightly, employees simply move to personal devices and unsanctioned platforms - creating Shadow AI that compliance teams can't see at all.
The New Risk Landscape: Behavior Over Content
With AI, governance has moved from monitoring what employees share to understanding how they behave. Real-world examples from Theta Lake's AI inspection platform reveal the scale of the challenge:
- Fabricated testimonials: Users requesting fictional customer quotes claiming 50%+ returns - constituting fraud and violating FINRA rules
- Compliance testing patterns: Employees repeatedly testing AI guardrails with progressively modified requests, demonstrating knowledge that requests are improper but seeking workarounds
- AI system manipulation: Attempts to manipulate AI through hypothetical scenarios, false justifications, and social engineering tactics
- Promissory language: Deliberately crafted prompts requesting "ensure" and "guarantee" language in investment contexts to imply guaranteed returns
- MNPI exposure: Users asking AI for extensive sensitive data including stock grants, customer SSNs, regulatory actions, and confidential project details
Nadir explained:
"You can't look at those behaviors and not think that somebody should intercede. Even if the AI continues to say no, you still want to know that the user is trying to circumvent the rules. They have a pattern of repeated bad behavior. That's important to know."
This represents a fundamental shift: in traditional compliance, you either sent the problematic email or you didn't. With AI, organizations can now see what employees are trying to do - and whether they're successful.
A Multi-Layered Governance Model
Effective AI governance requires a structured approach that balances enablement with oversight:
- Foundation layer: Understand where users are going (Copilot, ChatGPT, Grammarly, Anthropic), conduct risk assessments, invest in secure enterprise licenses, and block access to high-risk tools.
- Data governance: Define permissions - do AI tools inherit the same data access as individual users, or do they require separate controls?
- Baseline guardrails: Deploy structured controls for PII, PCI, and sensitive data based on user roles and context.
- Continuous inspection: Capture full-fidelity records of prompts, responses, behaviors, and downstream sharing. Analyze patterns over time to surface risks that single interactions wouldn't reveal.
Lopez goes on to say:




