The Rise of AI and the Urgent Need for Caution
AI tools have transitioned from being mere novelties to essential components of everyday work life at an astonishing pace. For countless individuals, these intelligent technologies are now integrated into their daily routines, rendering them as commonplace as email. Corey Nachreiner, the Chief Security Officer at WatchGuard Technologies, emphasizes the increasing importance of a few critical questions as AI becomes more prevalent in professional settings. “People are already utilizing AI for everyday inquiries, workplace tasks, and intimate conversations,” Nachreiner notes. “Before sending a message or command, it’s vital to pause and contemplate: What am I sharing? Who might have access to this information? What is the extent of what this tool is permitted to do for me? These considerations become significantly more pressing as AI evolves and begins to perform tasks on our behalf.”
Jack Cherkas, the Global Chief Information Security Officer at Syntax, believes that this year’s cybersecurity initiatives are timely reminders of the importance of vigilance in an age where digital threats are ever-present. “Cybersecurity Awareness Month serves as an important reminder to strengthen fundamental security practices, which remains crucial,” he asserts. “However, this year, the National Cybersecurity Alliance has adopted the theme, ‘Don’t Make It Easy for Them,’ prompting organizations to evaluate a burgeoning source of risk: artificial intelligence.”
Cherkas articulates a critical point regarding AI, emphasizing that it is not merely another piece of technology. “AI possesses the potential for transformative impact,” he states. “It can manage your accounts and permissions, access a variety of information you’ve shared with it, and take actions on your behalf. Many organizations and individuals have not fully considered the significance of these capabilities and the risks that accompany them.”
The Granting of Privileges
Nachreiner provides a cautionary take on the convenience of linking AI assistants with personal and organizational accounts. “When users permit an AI agent access to their emails, files, calendars, financial data, or other sensitive accounts, they are effectively granting it their privileges,” he warns. “If a malicious actor gains access to an AI account or its credentials, they could potentially execute any action that the user can do. This reality makes AI accounts enticing targets for cybercriminals.”
He urges individuals and organizations to treat these accounts with utmost seriousness. “Users should protect them as they would their primary email or banking accounts. Implement multi-factor authentication, exercise skepticism toward unexpected links and login prompts, and think twice before sharing sensitive information or approving new connections,” Nachreiner advises.
Cherkas proposes a straightforward test that should be employed before engaging any AI tool. “As society increasingly embraces AI, it’s essential to assess three main criteria before granting access: what the AI can see, what it can do, and who is responsible for its actions,” he insists.
The Challenge of Unwanted AI
The intricate landscape of AI integration within organizations further complicates matters. Nachreiner highlights the concept of “shadow AI,” which refers to the ways in which AI infiltrates the corporate environment. “It’s not just the chatbot that someone activates in a web browser,” he explains. “It includes plugins, extensions, and integrations that are implemented without security oversight.”
Cherkas elaborates, noting that some AI systems are integrated without any conscious decision made by users. “Moreover, we must recognize that AI often appears in situations where no active choice has been made at all,” he says. “For instance, it could be embedded within tools approved years ago that have been updated with AI functionalities or included in a browser extension.” This unintentional adoption poses unique challenges, as many of these systems go unnoticed, creating potential vulnerabilities.
The Primacy of Visibility
Both Nachreiner and Cherkas agree that organizations cannot mitigate risks they cannot see. “Without visibility, effective security is unattainable,” Nachreiner asserts. “Organizations must identify which AI tools they employ, where their data is routed, and what permissions those tools possess.” He points out encrypted traffic as an area of particular concern. “Our recent research indicates that 95% of malware is transmitted over encrypted TLS traffic, yet only 20% of security devices are equipped to inspect that content. With more workplace activities and AI integrations relying on encrypted channels, ‘encrypted’ should not be equated with ‘safe’.”
Nachreiner outlines a methodical prioritization. “Visibility is paramount, followed by establishing policy, then implementing enforcement. This order enables teams to discern what is permissible, what needs deactivation, and where safeguards are required,” he explains. “The implementation of shadow AI policies and protective measures is critically essential, an effort we have successfully undertaken at WatchGuard to safeguard our employees, customers, and partners.”
Cherkas concurs with Nachreiner’s perspective on the minimal effort required to secure AI technologies. “Don’t Make It Easy for Them serves as a poignant slogan this year. For organizations, this translates to adopting AI in a secure, pragmatic, and responsible way. For individuals, it requires just 10 minutes spent revising settings. Neither task is onerous, but both are undoubtedly overdue for many.”
In an era where AI increasingly pervades everyday transactions and interactions, keeping security at the forefront of innovation is far more critical than ever. The risks are clear, and awareness is the necessary first step in navigating this evolving digital landscape.

