Enterprise AI Adoption Is Entering Its Second Phase
Ido Geffen, CEO and Co-founder, Novee Security.
gettyβOnly a year or two ago, companies were still experimenting with AI and what kind of useful work it could do. They were testing whether it could write the necessary code, find security issues and reduce manual work. The measured, cautious adoption fits the usual enterprise pattern: mid-market companies tend to act more bullishly toward new technology (think cloud adoption ten years ago), while slow-moving, larger enterprises take their time to catch up to new trends.β
But this year, in conversations at Black Hat, I was surprised by how aggressively some large enterprises were pushing to more formally operationalize AI. They have more at stake to βget AI right.β Boards and shareholders expect progress, while security teams still have to manage the risks.β
For many enterprises, the question of capability has been answered. Now they have to determine whether AI can work safely, affordably and repeatedly.
That shift becomes especially important when AI moves into security. Enterprises are already spending heavily on AI to speed development and automate knowledge work, with security accounting for a smaller share of that spend. But security introduces its own economic pressures, especially when AI moves from a limited pilot into an always-on function where poor output still requires human review.
Cost is one of the first constraints security teams encounter at scale. Frontier models donβt look all that expensive at face value, but once the workload runs continuously at that scale, the program costs add up. Things like continuous pentesting can consume enormous amounts of inference while false positives create downstream validation costs. Expensive output is still a waste if humans have to spend hours proving whether it matters.β
Security leaders are also looking more critically at the safety components and how best to adopt them. In my conversations with CISOs, incidents like Hugging Face involving unrestricted AI models have made them realize that to use these powerful offensive security models, you have to bring your own guardrails. The more capable and accessible models become, the more enterprises have to decide what they are willing to run internally, what data those models can access, what autonomous actions they can take and what controls the organization itself has to provide.
Cost is one constraint. Control is another. In practice, quality governance can help companies deploy AI faster because teams know which tools are approved, what data can be used and where autonomous action needs limits.β
Blanket restrictions can create shadow AI. Employees still want the capability, so they work around controls. I think the safer approach is to say yes responsibly to AI. A solid, usable governance framework includes approved tools/models, rules around sensitive data, limits on autonomous action and security gates around higher-risk use cases. Once those decisions are made, teams have a clearer path to use AI rather than renegotiating every experiment.β
Security teams face a constraint attackers do not. Enterprises are responsible for data, compliance, business continuity and the consequences of automated actions. Attackers have no such obligations. That can create a temporary speed disadvantage while companies determine what they can safely operate, which is why governance needs to reduce decision latency rather than add to it indefinitely.
A mature AI deployment is wired into a workflow people actually use and depend on. Its output changes what happens next: which issue gets investigated, what code gets fixed or what gets approved or blocked. If the output never changes a decision or action, the deployment may still be impressive, but it hasnβt actually become operational.β
Large enterprises may be pushing hard because they no longer see security, governance and economics as side issues to solve later. Those conditions are becoming part of what makes enterprise-scale adoption possible.β
The second phase of enterprise AI will be defined by whether companies can make AI dependable enough to shape real decisions at scale. The companies that move fastest may be the ones that build governance, economics and workflow integration into the adoption model from the start.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

