By Richard H

Head of Security and Infrastructure


I recently spent two days at a closed-door, invite-only summit with around fifty chief information security officers and senior security leaders. They came from regulated and high-growth industries: energy, pharmaceuticals, aviation, software and data.

The agenda was a single subject, artificial intelligence, and what it is doing to both attackers and defenders. I came away with a clearer sense of what it genuinely changes for a business like ours.

What struck me most is how much it speeds everything up while leaving the basic rules of security unchanged. For a regulated custodian, that difference matters far more than the surrounding hype suggests.

The cadence has changed

The most grounded voice in the room belonged to a keynote speaker who had spent years running security at the scale of a major international institution. His argument was that AI accelerates the problems we already have rather than inventing new ones. The defender’s playbook still works (patch, keep an accurate inventory, train your people, automate the routine work), but the speed at which all of it has to happen has changed beyond recognition. Attackers now move at machine speed while most defenders still work to a weekly rhythm, and that gap is where most of the risk now sits.

He drew a distinction I keep coming back to: cybersecurity is interesting, but cyber resilience is fascinating. For anyone safeguarding client assets that is the right instinct, as long as it is read correctly. For a custodian, resilience does not mean accepting that a breach is inevitable and planning how to recover from one. A compromise of client assets is the single outcome our business exists to prevent, and it is never something we would expect to absorb and move on from. Resilience is what holds that prevention together under pressure: layered defences so that no single failure can reach client assets, no single point of trust, and enough rehearsal of the hardest scenarios that they do not happen in the first place. Prevention is the goal, and resilience is what keeps us confident of achieving it.

Compliance is only the starting point

One observation from the practitioner discussion landed harder than any vendor pitch. As one security leader put it bluntly, every company compromised in the past six months was SOC 2 compliant.

That is not an argument against compliance. For a regulated firm, certification is non-negotiable, and our clients rightly read it as a signal of trust, a translation of our security into something the wider ecosystem and our regulators can rely on. But certification only marks the baseline that everyone in the industry has to reach; the real work begins above it. Frameworks tend to describe last year’s expectations, while attackers operate in the present, and the gap between the two is often measured in years.

The pattern in the room was telling. The organisations that had treated compliance as the destination were the ones now finding gaps in their environments. Those that had pursued resilience, and let compliance follow from it, were in noticeably better shape. For Komainu the two sit comfortably together. Our job is to align the controls that keep us compliant with the resilience that keeps client assets safe, and to stay honest with ourselves about where one ends and the other begins.

The hard part: AI inside a regulated business

If there was a shared frustration among regulated peers, it was the mismatch between the speed of the business and the speed of governance. Policies take time to produce and are frequently out of date by the time they are approved. One leader described drafting guidance for a technology that the engineering teams had already moved on from months earlier. Another had been asked to federate AI decision-making to accelerate deployment, and had concluded that the organisation simply was not ready to delegate that judgement.

In our sector that caution is simply the job. Some decisions a regulator will not allow a machine to make on its own, because accountability has to rest somewhere visible. You cannot blame an agent: if an autonomous system makes a harmful decision, the firm, and named individuals within it, remain answerable. The right response is to be deliberate about where a human stays in the loop, and to design those control points before the system goes live rather than after.

There is an upside that often gets missed. The discipline a regulated business already carries, such as rigorous logging, mature identity management, audit trails, and evidence for every control; is exactly the foundation responsible AI adoption needs. Plenty of less-regulated firms are now scrambling to retrofit what we already run as standard. Handled well, our regulatory position is an advantage when deploying AI rather than a brake on it. The mistake would be to treat all that discipline as a reason to move slowly, when it is really what lets us move with confidence.

Getting the most from AI: lift everyone, or back the capable few?

The most interesting debate of the two days was about people rather than technology.

There are two competing instincts. The first is to give everyone access and let people experiment widely: maximise adoption, accept the cost in licences and tokens, and trust staff to find value in their own work. The second is to concentrate capability in your most able people and let them build the tools everyone else uses. Both approaches have a failure mode. Open access without any coordination tends to produce ten people solving the same problem ten separate times, which is a lot of activity for very little real gain. Concentrating capability too narrowly leaves everyone else without the fluency to keep up, and a workforce that cannot use the tools will quietly fall behind.

The teams that seemed to be pulling ahead were doing both at once. They gave everyone broad access behind sensible guardrails, and they invested in a capable core whose job was to turn rough experiments into tools the rest of the business could rely on. It was striking how often the most inventive ideas came from junior, AI-native staff working from the bottom up, which is healthy as long as security joins in early rather than being called to tidy up afterwards. The most valuable engineers were still the ones who understood the fundamentals, such as how systems actually work and where a supply chain can be poisoned. AI lets more people do more, but it does not reduce the need for people who understand what sits underneath.

The answer is to do both deliberately. Raise the whole workforce’s AI literacy, including how to use these tools safely, while giving your most capable people the remit and the guardrails to build for everyone else. It also means resisting the urge to adopt AI for its own sake. The most useful advice I heard all week was also the plainest; start with the problem you actually have, and check whether AI is the right answer to it. Often it will be, and sometimes it will not.

Coach, don’t block

One principle is worth singling out, because it applies so directly to a firm full of technically capable people. Blunt bans tend not to work. Block a useful tool outright and capable staff will route around the control, onto personal devices, free accounts and other corners where you have no visibility at all. You contain far more risk by making good usage easy and visible, and by guiding people when they stray, than by pretending you can switch the technology off.

What this means for us

For a regulated custodian, all of this is reassuring and demanding at the same time. Reassuring, because the disciplines we already run are close to what responsible AI adoption needs. Demanding, because the new pace leaves no room for treating those disciplines as a finished job. A few principles we are carrying forward:

  • Put resilience in service of prevention. Treat certification as the baseline, then build layered defences so that no single failure can ever reach client assets.
  • Keep humans accountable. Be deliberate about where a person stays in the loop, especially where a regulator expects one.
  • Lift everyone and back the best. Build broad AI literacy across the workforce, invest in a capable core to build for it, and guide usage rather than banning it.
  • Start with the problem. Adopt AI where it genuinely helps, rather than because the rest of the market is doing so.
  • Get the basics right first. Most AI risk is old risk moving faster; identity, hygiene and supply chain are still where the real exposure lies.

The technology will keep changing faster than any of us can forecast. What stays constant is that security, and now the responsible use of AI, comes back to people: the judgement we keep in the loop, the fluency we build across a team, and the discipline to do the unglamorous things well. For a custodian trusted with other people’s assets, that discipline is not a constraint on innovation. It is what makes innovation safe to attempt.