Brief IA

ISACA Warns: Companies Unable to Manage AI Crises

🤖 Models & LLM·Tom Levy·

ISACA Warns: Companies Unable to Manage AI Crises

ISACA Warns: Companies Unable to Manage AI Crises
Key Takeaways
1A study by ISACA reveals that 59% of companies do not know how to quickly stop an AI incident.
2Only 21% of professionals can effectively intervene in less than 30 minutes during an AI crisis.
342% of respondents doubt their ability to analyze and explain AI incidents to regulators.
💡Why it mattersThe lack of AI governance exposes companies to significant legal and reputational risks.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

The Challenges of AI Crisis Management

Artificial intelligence, while offering considerable opportunities, also presents risks of malfunction or compromise. A recent study conducted by ISACA highlights a concerning issue: the majority of organizations are not prepared to effectively manage a crisis related to an AI system. The findings show that many of them do not know how long it would take to halt an AI emergency, nor how to identify the cause of such a problem.

According to the report, 59% of digital trust professionals do not know how long it would take their organization to interrupt an AI system in the event of a security incident. Only 21% of respondents stated that they could intervene significantly in less than 30 minutes. This means that many compromised AI systems could continue to operate unchecked, thereby increasing the risk of irreversible damage.

Ali Sarrafi, CEO of Kovant, an autonomous enterprise platform, emphasizes that these results reveal a major structural problem in how organizations deploy AI. He explains that systems are often integrated into critical processes without the necessary governance to oversee and audit their actions. If a company cannot quickly stop an AI system, explain its behavior, or even identify those responsible, it does not have control over that system.

Failures and Risks Associated with AI

Only 42% of professionals surveyed expressed some confidence in their organization's ability to analyze and clarify serious incidents related to AI. This inability to understand and explain these incidents can lead to operational failures and security risks. Moreover, without clear communication with regulators and management, companies risk legal sanctions and negative public reactions.

In-depth analysis is essential to learn from past mistakes. Without a clear understanding of incidents, the likelihood of recurrence increases. Managing AI responsibly requires effective governance, but ISACA's findings show that this is often lacking.

The question of accountability remains unclear. About 20% of respondents do not know who would be responsible if an AI system caused harm. Only 38% identified the Board of Directors or an executive as ultimately responsible.

Sarrafi insists that slowing down AI adoption is not the solution. It is crucial to rethink AI management. AI systems must be integrated into a management structure that treats them as digital employees, with clear ownership, defined escalation paths, and the ability to be paused or bypassed instantly when risk thresholds are reached. This way, systems cease to be mysterious entities and become inspectable and reliable tools. As AI becomes more deeply integrated into essential business functions, governance must be embedded from the start, with visibility and control at all levels. Organizations that succeed in this will not only reduce risk but will also be able to deploy AI with confidence.

Human Oversight and Its Limits

There is, however, some comfort: 40% of respondents state that AI actions are almost always approved by humans before deployment, and 26% evaluate AI outcomes. However, without improved governance infrastructure, this human oversight may not be sufficient to identify and resolve issues before they escalate.

ISACA's findings highlight a major structural problem in how AI is deployed across various sectors. More than a third of organizations do not require their employees to disclose where and when AI is used in work products, increasing the potential for blind spots.

Despite stricter regulations that hold senior management more accountable, organizations are failing to implement and use AI safely and effectively. Many view the risks associated with AI as a technical issue rather than a concern requiring organization-wide management.

A shift in how AI integration and actions are managed is essential. Without proper governance and accountability, companies do not control their AI systems. Without control, even the smallest errors could cause reputational and financial damage from which many companies may not recover.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.