// Field notes · AI governance

The CISO is becoming an AI executive

Fed examiners are asking how AI is governed across the supply chain. For enterprises "We don't use it" stopped being a credible answer a while ago. Here are the six things that bite security leaders, in the order they usually bite.

By Michael B. Housch September 7, 2026 7 min read

The CISO who treats AI as someone else's problem is already behind.

I am over the risk and security programs at Dark Matter Technologies, the company behind the Empower loan origination system and one of the top mortgage technology companies in the industry. Over the last year the questions coming from our clients have changed. Fed examiners are asking them how AI is governed, and not only internally. They want to know how it is governed across the supply chain, which means the question lands on us.

Risk and security leadership used to mean keeping threats out while aligning security with business strategy. Now it means governing, securing, and enabling AI at enterprise scale, with a regulator in the room. That is a different job, and it is worth being honest about how different.

Infographic: The CISO is becoming an AI executive. Sections cover the evolution from traditional to strategic to AI executive, the AI executive mindset (strategy, governance, security, trust, innovation), key responsibilities, AI tools every CISO should know, and the business impact of AI-driven CISO leadership.
Securing today. Enabling tomorrow. Leading with AI. Download the graphic

Here is what I tell security leaders who want to get ahead of it. Six things, in the order they usually bite you.

01AI strategy

Tie every AI initiative to a business outcome and a security objective. If you can't name both, it's a science project. That sounds harsh until you look at how most AI portfolios actually form: a vendor turns on a feature, a business unit runs a pilot, someone in engineering wires up an agent, and six months later nobody can say what the company is trying to accomplish or what it has agreed to protect. The strategy doesn't need to be long. It needs a named owner, a short list of outcomes, and a clear statement of what the company will not do with AI. That last part is what lets everyone else move fast inside the lines.

02AI risk management

Models, agents, data, and workflows each create risk the old register never contemplated. A model can be accurate on Tuesday and wrong on Friday because the world moved. An agent can be given permissions no human would ever be granted. A workflow can quietly route customer data into a place your data classification never anticipated. Inventory them, rate them, own them. The inventory is the part most teams skip, and it is the part the examiner asks for first. Include what arrived through vendors, because that is where most of it lives.

03AI governance

Policies, controls, accountability, and evidence. In regulated industries, the model risk management playbook already exists. Use it. The FRB SR 26-2 has been telling banks how to validate, monitor, and document models for more than a decade, and most of what a generative model or an agent needs is an extension of that discipline, not a replacement for it. Where the old playbook falls short is speed and scope: the number of models in play, how fast they change, and how many of them you didn't build. Adapt the cadence. Keep the structure.

04AI security architecture

Protect the applications, pipelines, models, identities, and data behind the AI. Two rules do a lot of work here. Agents get non-human identities, with the same lifecycle, least privilege, and logging you would demand for a service account that could move money. Prompts get treated as untrusted input, the same way you treat anything that crosses a trust boundary from a user or a document. Prompt injection, data leakage through outputs, poisoned training data, and over-permissioned agents are new names for old categories of failure. The controls are recognizable once you stop thinking of the model as magic.

05AI vendor oversight

Most of the AI in your environment arrived through a vendor. The LOS, the CRM, the HR platform, and the help desk all shipped AI features in the last eighteen months, and a good number of them were on by default. Third-party and supply-chain due diligence has to cover models, training data, and sub-processors now. Ask whether your data trains their model. Ask which foundation model sits underneath and who hosts it. Ask what happens when it is wrong and who tells you. If the vendor can't answer, that is the answer.

06AI literacy

Your team can't secure what it doesn't understand. Teach them how AI actually changes their day, not just the headlines. The analyst triaging alerts needs to know what a model can and cannot be trusted to tell them. The engineer building the integration needs to know why a prompt is an input and not a configuration setting. The manager approving the vendor needs to know which questions matter. Literacy is a leadership skill now, and it is one of the few controls that gets cheaper the earlier you invest in it.

The future CISO doesn't just defend the company from AI. They help the company use AI safely to compete. Augment the humans, don't replace them, and keep a person at every checkpoint that matters. That is what human-in-the-loop (HITL) means in practice: not a slogan, but a named person with the authority to override the output where the decision has consequences.

AI is an attack surface. AI is also a security capability. Holding both ideas at once is the job. The CISO Life

The advantage goes to the security leaders who can connect cybersecurity, AI governance, risk management, cloud and data protection, and business strategy into one conversation the board and the examiner both understand. That is the shift the graphic above tries to capture. The traditional CISO focused on protection. The strategic CISO added governance and resilience. The AI executive adds innovation and enablement without giving up either of the first two.

// Continue the conversation

Which of the six is your team furthest behind on? Reply on LinkedIn or bring it to the podcast.

Join the discussion on LinkedIn

#CISO #AIGovernance #Cybersecurity #RiskManagement #Fintech #MortgageTech #AISecurity
MH

Michael B. Housch is Chief Risk & Information Security Officer at Dark Matter Technologies and the founder of The CISO Life. He has spent 25+ years in financial services security leadership and writes about AI governance, risk, and the practical side of running a security program in a regulated industry.