The Human Side of AI Security
by Giles Douglas, CISO
What if your biggest security risk isn’t malicious hackers but well-meaning employees trying to keep pace with modern work?
Superhuman’s Human + Technology Experience Index found that nearly 75% of employees use unsanctioned tools at work, and 65% go looking for unofficial AI on their own. It’s easy to read these stats as employee rebellion, but I read it as a support gap.
People are trying to do good work but lack the tools and guidance to do it safely. The Ponemon Institute’s 2026 Cost of Insider Risks report confirms this and gives us a real cost. Negligent insiders are responsible for most incidents, costing organizations collectively over $10 million annually.
So, alongside strengthening our risk postures, we also need to reevaluate what the human side of security means as our programs evolve to keep up with AI.
Assume good intent and recognize the power of fear
Take a step back and consider what motivates employee behavior. People want to be good at their jobs. They want to be more productive, produce better work, and be seen as contributors to their companies’ success. The overwhelming majority have never made a technology choice out of malice.
The AI hype cycle plays on exactly that good intent, manufacturing fear for anyone who hasn’t yet unlocked hyperbolic efficiency with AI. Every ad reminds employees that they could be doing more, faster. That they need to click, download, and start now, before being left behind.
Good intent creates risk when employees aren’t equipped to evaluate their choices. Fear-driven intent accelerates it. Preserving and guiding good intent is core to the future of AI security.
Here are three steps I have in mind.
Pave the road, then send employees down it
AI mandates are multiplying. “Every employee should be using AI by the end of the quarter.” “Start every task with AI.” The mandates are fine when they fit the business, but a mandate without direction fuels employee anxiety. And anxious people go looking for AI wherever they can find it.
The solution here isn’t a taller fence. It’s a smoother road. In engineering, a “paved road” is the well-supported, sanctioned way to get something done. The route is so easy and well lit that straying feels like more work, not less. AI mandates should give people that road, not just point at the horizon and say go.
Here’s what it takes:
- A real default answer: For every common job, such as drafting, summarizing, coding, and research, there should be an obvious, approved tool and a clear “use this for that.” If employees have to ask what they’re allowed to use, you’ve already lost them to the search bar. Discoverability encourages use.
- An easy on-ramp: A blank chat window is disorienting if you’ve never written a prompt. Pair approved tools with starter prompts, templates, or a curated library of skills, plus enough explanation that people can make progress through the task.
- A short request lane: When the paved road doesn’t meet a need, give people a fast, visible way to request a new tool. A fast-tracked evaluation tells employees the company is keeping pace with them, so they don’t have to gamble on something they found online. If people feel a process is onerous, they will work around it.
- Guardrails you’ve designed: Single sign-on, pre-vetted connectors, and data-retention settings configured up front mean the safe choice is also the default choice. Make them easy to set up—don’t gate it on one IT employee.
When the sanctioned path is also the fastest one, shadow AI stops being a temptation and becomes the harder option. Employees are rarely trying to break the rules. They’re trying to get to work. Build the road that gets them there.
Educate—don’t just offer educational opportunities
Ask an IT team whether they’ve trained employees on AI and security policy, and they’ll send you a bunch of links to knowledge base articles and video recordings. (I practically have a keyboard shortcut for sending them.) Ask employees the same question, and they’ll tell you nothing exists.
We have to provide training that is accurate and resonant.
Think about how far we’ve come in cybersecurity. Fifteen years ago, almost no one could define phishing. Today, most employees can spot a phishing email, a smishing text, or a sketchy link on sight. We didn’t scare them into vigilance; we made the risk understandable and easy to recognize.
We have to make AI risk real for employees in the same way. This starts by giving people a shared vocabulary, specifically for the moment an employee is about to connect a new AI tool to company data.
Here are terms all employees should understand:
- Read access: A tool can view data but not change it. Lower risk, but still exposure if the data is sensitive; it can be shared with someone who shouldn’t have access.
- Read-write access: A tool can view and also modify or delete data. This is where mistakes, or malicious prompts, do real damage—an AI tool with write access to your inbox can send email, not just read it.
- Connector / integration: Any link between an AI tool and another system (email, calendar, file storage). Every connector is a new door, and each one should have a good reason to be open.
- Prompt injection: Hidden instructions buried in a document, an email, or a web page that hijack an AI tool into doing something the user never asked for. It’s the AI equivalent of a phishing link, but it’s harder to spot.
Be light with the hammer
When an employee gets “caught” using an unapproved tool, treat it as a learning moment—for both of you.
First, assume good intent. Second, explain why unapproved tools create risk and how this particular tool does so. Your goal isn’t to shut down one tool for one person; it’s to prevent the next misuse and, ideally, turn that employee into an ambassador who spreads the word. Third, find out why they reached for the tool in the first place. Does it do something your approved stack can’t? This is the color commentary to all your telemetry data. Does it do something you already offer? Either answer is useful: You’ve found a gap to fill or a tool that needs more visibility.
I’ve had the pleasure of working with many chief information security officers and IT professionals. They are all genuinely excellent at the technical side of risk management. The people-enablement side is usually the harder, less-practiced skill for most security teams. It’s also the piece AI is forcing us to get better at. The organizations that get AI security right won’t just have big fences. They’ll be the ones whose people understand the risk, trust the paved road, and know it’s safe to ask for help. Build for the humans, and the security follows.