AI as an Internal Power Struggle AI is becoming one of the most politically difficult technologies o

 

SUMMERY

AI is becoming a politically complex technology within organizations, as employees often adopt and form strong opinions about it before formal governance is established. This creates internal debates where confidence can outpace expertise, turning AI discussions into competitions over tools, approaches and influence. Because AI impacts nearly every function, business, technology, legal, compliance and security teams all seek a role in shaping its adoption. The appointment of dedicated AI leadership can provide clarity, but may also create new tensions around ownership and decision-making authority. For CISOs in particular, AI presents a challenge: security concerns can be perceived as resistance to innovation or business growth. The key issue is therefore not whether security should own AI, but whether the organization clearly defines responsibilities, boundaries and decision rights. Organizations need to establish who approves AI use cases, sets guardrails, accepts risk and has the authority to stop unsafe initiatives. Without clear governance, AI-related security failures may stem less from technology itself and more from organizational politics, ego and unclear accountability.



AI is becoming one of the most politically difficult technologies organizations have had to absorb. Not because the technology itself is political, but because of what it is doing inside the organization.

AI arrived differently from most enterprise technologies. Over the past year, people across organizations became users before their companies had fully decided how AI should be governed. Some became heavy users. Many developed strong opinions about what works, what does not, and what the organization should be doing.

That changes the internal conversation. When everyone has experience with the technology, everyone feels entitled to an opinion about it. And sometimes confidence develops much faster than expertise. People make sweeping statements, defend preferred tools and approaches, and the discussion can quickly become an ego arena.

At the same time, AI touches almost every organizational function. Business leaders see productivity and growth. Technology teams see architecture and integration. Legal and compliance see exposure. Security sees data access, permissions and third-party risk. Everyone has a legitimate reason to be involved, but that also creates competition over ownership.

Management may respond by appointing a new AI leader or even a Chief AI Officer. That can create clarity, but it can also create another power center. Suddenly there may be tension with the CIO, information systems, security or risk teams, without a clear answer to who actually owns decisions and processes around AI.

This is where the CISO can find themselves in a particularly difficult position. In many organizations, security is still not one of the strongest political functions. When AI is framed as a competitive opportunity, questions about permissions, data exposure or architecture can easily be interpreted as resistance.

The result can be an uncomfortable choice: push too hard and risk being bypassed, or push too little and watch AI implementations move ahead without sufficient controls.

My colleague Adi Roze recently wrote about the danger of the CISO becoming the “empty chair” in AI decision-making. I think there is another question behind it: even when the CISO is in the room, how much influence do they actually have?

Organizations do not need security to own AI. But they do need to decide who owns what. Who approves use cases? Who sets boundaries? Who can accept risk? And who has the authority to stop something when necessary?

Without those answers, unsafe AI adoption may look like a technology problem. In reality, it may be the result of politics, ego and unclear decision-making inside the organization.