Home > Tech > Expert Contributor

The AI Blind Spot in Cybersecurity Governance

By Alfredo Zayas - Global Lynx
CEO

STORY INLINE POST

DIA assistant
Alfredo Zayas By Alfredo Zayas | CEO - Thu, 08/06/2026 - 07:30

share it

A few months ago, I sat in a board meeting where the head of technology presented, rightly, an important achievement: the company had implemented an AI-based threat detection system that cut incident response time by more than 60%. There was applause. There was relief. And above all, there was a sense that cybersecurity had shifted from an "open problem" to a "solved problem."

That moment stayed with me because it is exactly the point where many organizations let their guard down. They bought a powerful tool. They did not build a governance structure. Those are two different things, and in corporate discourse they get confused far too easily.

In Mexico, and across Latin America more broadly, we are living through a race to adopt AI for security that is moving much faster than boards' ability to understand what they are actually approving. Ransomware attacks in the country nearly doubled in 2025, with government and education among the sectors hit hardest, and the institutions facing these incidents are discovering that traditional defense approaches are no longer enough. At the same time, universities and public institutions are announcing unlimited investment to rebuild their digital governance after breaches compromised multiple information systems. The pattern is clear: investment in technology is growing, but the governance that decides how, by whom, and under what rules that technology is used is lagging several steps behind.

As the CEO of a company that has spent three decades training and certifying technology talent, I see this gap every day, from both sides of the counter: companies that seek to certify their people in security frameworks because they just suffered an incident, and directors who show up asking, "What should we have known beforehand?" The answer is almost always the same: it was not a technical problem, it was a governance problem.

There is an understandable temptation in any boardroom: if an AI system can detect anomalies, prioritize alerts, and even contain an attack automatically, it seems reasonable to assume the risk is "handled." But governance is not a function you delegate to an algorithm. It is the structure of decisions, responsibilities, and boundaries that determines what that algorithm does, with what data, under what oversight, and with what consequences if it fails.

An AI model deployed without governance is, at best, an efficient black box. At worst, it is a new attack surface that no one on the board even knows exists. And here is the point that concerns me most as a director: most of the security frameworks Mexican companies still rely on were designed to protect networks, servers, and endpoints. They were not designed to govern models that learn, that update themselves, that can be manipulated with the right prompts, or that can leak sensitive information simply because of how they were trained.

This is not science fiction, nor a distant scenario. It is exactly the kind of risk that Mexico's most recent data governance frameworks are starting to recognize. The new open data guidelines published in 2025, for example, already build security and privacy into the design of any data publication, rather than treating them as an afterthought. That conceptual shift, from "publish first, protect later" to "design with security from the start," is precisely what boards need to apply to their own AI frameworks. The question every director should ask before approving an AI project is not only "what problem does this solve?" but "what new form of exposure are we accepting, and who is responsible for watching it?"

Five Governance Pillars That Actually Work

After supporting different organizations, including our own, through this process, five elements consistently distinguish companies that govern their security AI well from those that merely deploy it.

Clear ownership of risk. An identifiable owner at the executive level, not a diffuse committee, who is specifically accountable for the risks arising from AI systems.

Adapted frameworks, not adopted ones. Use recognized standards such as the NIST AI Risk Management Framework or ISO/IEC 42001 as a foundation, and adapt them to the company's actual operations rather than implementing them as a generic checklist.

Continuous auditing, not one-time certification. An AI model changes over time. Governance cannot rely on a single initial assessment; it needs periodic review, with documented evidence, just like any material financial control.

Training that reaches the board, not just the technical team. Most serious incidents do not happen because of a lack of tools. They happen because the people making decisions do not understand enough to ask the right questions. Training directors in the fundamentals of these risks is no longer optional.

Drills that include AI scenarios. Traditional business continuity exercises rarely account for what happens if the AI system itself becomes the attack vector, or if its automated recommendations are compromised. That needs to change.

There is a common mistake in how boards diagnose this problem: they treat it as a shortage of tools, when it is actually a shortage of human judgment capable of overseeing those tools. I can say this with the authority of someone who has spent three decades training technology professionals in Mexico: demand for cybersecurity certifications has grown steadily, but demand for training specifically in AI governance is still marginal compared to the real urgency of the problem. Companies keep certifying analysts in threat detection and incident response, necessary work, without question, but very few are certifying their middle managers and their own directors in how to evaluate a model's risk before approving it.

That asymmetry has a direct consequence. The technical team understands the model's risk but lacks the mandate or the organizational standing to stop a project the business has already decided to pursue. The board has the mandate but lacks the technical vocabulary to ask the questions that matter. That gap, between whoever understands the risk and whoever holds the authority to act on it, is in my experience where most AI governance structures that looked solid on paper actually fail.

Closing that gap does not require a director to become a machine learning engineer. It requires enough literacy to tell the difference between a well-produced sales demonstration and a genuine risk assessment, and to demand documented evidence instead of trusting a vendor's reputation. This is increasingly part of any board's fiduciary responsibility, especially in regulated industries where noncompliance costs more than money: it can cost licenses, contracts, and in some sectors, the ability to keep operating at all.

You May Like

Most popular

Newsletter