Home > Cybersecurity > Expert Contributor

The Goalkeeper Nobody Is Watching: Why Defense Matters for CEOs

By Juan Carlos Carrillo Herrera - OneSec
CEO

STORY INLINE POST

DIA assistant
Juan Carlos Carrillo D Herrera By Juan Carlos Carrillo D Herrera | CEO - Thu, 06/11/2026 - 07:30

share it

Everyone talks about the striker who scores five goals a game. Nobody buys a jersey with the goalkeeper's name on it. But ask any coach: you win or lose 70% with defense.

Artificial intelligence is exactly the opposite. CEOs are mesmerized by the offensive play — ChatGPT that automates, models that predict, machines that "think." But while they watch the spectacle of goals, the defense sleeps.

And someone is about to score against you.

What You See (The Beautiful Goal)

The narrative is irresistible:

  • AI that cuts operational costs 30-40% in staffing, administration, and workflows

  • Algorithms that predict customer behavior with an accuracy once thought impossible

  • Faster automated decisions: loan approvals in minutes, not weeks

  • Personalized marketing that converts because it "knows" what each customer wants before they do

Boards see this and demand acceleration. Budget flows. AI startups grow 3x. The media talks about digital transformation. Beautiful. Exciting. Newsworthy.

And completely incomplete.

What You Don't See (The Own Goal)

While the offense celebrates, the defense has holes the size of a stadium.

1. The Biased Algorithm That Will Sue You

In 2015, Amazon built an AI algorithm to hire talent. It looked brilliant: processing thousands of résumés in seconds. But there was a problem: it was trained on Amazon's historical data, where technical roles had historically been male-dominated.

Result: the algorithm learned to discriminate. Systematically.

When they discovered it, Amazon had to dismantle the whole system. But the reputational damage was done: "How many qualified candidates did we reject without even knowing why?"

Now multiply that by a bank using AI to approve loans. Or an insurance company denying coverage. Or an HR firm that stops hiring women because the algorithm learned that's what it had seen historically.

The bill:

  • Discrimination lawsuits (can reach millions)

  • Aggressive regulation (California, EU, now Mexico is coming)

  • Loss of customer trust when it hits the news

2. The Regulation That Blindsides You

Europe already has the EU AI Act. It's live. It's regulating.

Mexico? Regulation will come in 2027-2028. But meanwhile, does your AI comply? Can you prove your automated decisions are explainable, auditable, and non-discriminatory?

If the answer is "the AI team is too busy innovating to document," you're one regulatory change away from a six-figure fine.

The EU AI Act has already processed cases where companies couldn't justify why an algorithm said "no." The fine was proportional to annual revenue. Terrifying.

3. The Gap Between What Your CISO Says and What Your Business Does

This is the most common scenario. The CISO says: "We need AI governance, model audits, training data documentation."

The CTO responds: "Sure, absolutely. But first I need to launch the model that will generate US$5 million in revenue this quarter."

Who wins? Money always wins in the short term. And the CISO goes back to their coffee. Alone.

Result: models in production without audit trails, without data lineage, without a response plan if something goes wrong.

The hidden cost: When it explodes, it explodes in public.

4. The Trust Crisis When It Hits the News

In 2023, an AI startup for HR promised to select candidates "objectively." It turned out their model offered women less money for the same roles. It went viral. Three months later, they were gone.

But before they shut down, they'd lost every customer and their ability to raise capital.

The Real Scoreboard

This isn't a technology problem. It's a governance problem.

A team without a goalkeeper doesn't lose 1–0. It loses 5–0.

In AI, that defeat is called:

  • Surprise regulation

  • Discrimination lawsuits

  • Reputational crisis that lasts for months

  • Loss of operating license if you work in regulated sectors (banking, insurance, healthcare)

Who Has Already Won This Trophy

Amazon, Google, Microsoft, Meta: all have chief AI officers with their own budget, reporting directly to the CEO, bypassing the CTO.

Why? It's not conservatism. It's because they scaled first and learned the hard way.

Example: Microsoft didn't launch Copilot without months of internal audits, bias testing, and legal accountability documentation. Result? When they released the product, they already had answers for every regulatory question.

The upfront cost was high. The cost of not doing it would have been infinite.

What a CEO Should Be Asking Today

1. Who is responsible for AI governance in my organization? (If the answer is "the CISO when they have time," you're already at risk)

2. Can I explain, in plain language, why an algorithm said "no" to a customer? (If not, a regulator won't accept it either)

3. Have I audited bias in my AI models? (Bias isn't theoretical. It's a credit line that rejects or a résumé that's discarded)

4. Does my AI team have documentation of what data was used to train these models? (Without traceability, there's no compliance)

5. Do I have a response plan if my AI causes harm? (An AI crisis without a prepared response = a reputational crisis)

The Final Whistle

The trophy goes to whoever has a solid defense.

AI without governance is like a team that scores 10 goals but concedes 15. Exciting to watch, but you lose.

Your board needs to appoint a "goalkeeper" now. Not in 2027. Now.

It could be a chief AI officer, a cross-functional committee (CISO + CTO + Legal + Compliance), or a structured governance framework. But someone must be watching the goal while the team attacks.

Because regulation is waiting on the sideline for a pass. And when it scores, you'll realize the goalkeeper matters more than the strikers.

You May Like

Most popular

Newsletter