Skip to Content
OPINION

The CISO's new privacy mandate in enterprise AI governance

Enterprise AI is pushing CISOs into a broader privacy role, requiring security leaders to help turn privacy principles into enforceable controls across AI governance, vendor oversight and incident response.

Published
Subscribe to IAPP newsletters

Contributors:

Great Gu

AIGP, CIPP/CN, CIPM, FIP

China Chief Information Security Officer

Haleon

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.

In my experience, enterprise artificial intelligence rarely enters an organization through a perfectly designed governance process. More often, it starts with a practical business request. A commercial team wants to summarize customer feedback. A legal team wants to review contracts faster. An information technology team wants to test an AI assistant. A clinical operations group wants to analyze large volumes of documentation more efficiently.

At first, the question sounds simple: Can this tool help people work faster?

Very quickly, however, it becomes a privacy and security question. What data will employees put into the tool? Can the platform access internal documents? Are prompts and outputs retained? Can the vendor use enterprise data to improve its model? Who can review the logs? What happens if an AI assistant retrieves the wrong file, exposes restricted information or generates advice on which the business should not rely?

These are not theoretical concerns. They are the kinds of questions privacy, legal, security and technology teams now face as AI moves from experimentation into daily operations.

Privacy professionals will recognize the issues immediately. AI use raises familiar questions around data minimization, purpose limitation, transparency, retention, vendor accountability and individual rights. But in practice, many of the answers depend on controls that sit close to the chief information security officer's world: identity and access management, data loss prevention, cloud security, endpoint controls, logging, monitoring, encryption, application programming interface governance and incident response.

That is why the CISO's role in privacy is changing. The CISO is still responsible for protecting systems and data from cyber threats; that responsibility has not gone away. But enterprise AI makes the CISO more relevant to privacy because AI changes how data moves, how it is reused and how risk appears.

In traditional systems, data is usually collected, stored, accessed and shared through defined applications and workflows. In AI systems, data may be retrieved through a vector database, summarized in a prompt, combined with other information, transformed into an output, retained in logs or used by an AI agent to trigger another business process. The same piece of information can move through several layers before anyone realizes it has become part of a new risk surface.

The gap is usually not in the privacy principle. Most organizations already know they should avoid unnecessary data collection, restrict access, define clear purposes and protect sensitive information. The harder question is whether those principles are actually enforceable in the AI environment.

A policy may say that employees should not upload sensitive data into unauthorized AI tools. That is necessary, but it is not enough. The organization also needs to know whether risky AI use can be detected, sensitive data is classified, approved tools are technically controlled, vendor settings are understood and there is a response process when something goes wrong.

Privacy governance only becomes meaningful when it can be translated into controls that work.

Take data minimization as an example. In a traditional privacy review, the main question may be whether a business process collects more personal data than necessary. In an AI environment, the question becomes more architectural. Which datasets are connected to the AI system? Which documents can a retrieval-augmented generation tool search? Are sensitive fields excluded, masked or tokenized? Can the system retrieve more information than the user should be allowed to see?

A privacy team can define the principle, but security and technology teams help make the principle enforceable.

The same applies to purpose limitation. An enterprise may approve an AI tool for internal productivity, but not for processing customer complaints, health information or employee performance data. That distinction cannot only remain in a governance document. It needs to be reflected in access controls, data boundaries, approved use cases, monitoring rules and user guidance. Otherwise, the organization may approve AI for one purpose while allowing it to be used quietly for many others.

One area that deserves more attention is AI conversation data. Prompts, outputs, retrieval context, plug-in activity and agent memory are often treated as technical logs. In reality, they may contain personal data, confidential information, trade secrets, regulated health data, employee records or sensitive business decisions.

A prompt may include a customer issue. An output may create an inference about a person. A retrieval system may expose a document the user did not know existed. If those records are retained, searchable or available to administrators, they become part of the organization's privacy and security risk surface.

This is where security teams can add practical value. Logging strategy, retention periods, administrator access, encryption, monitoring and incident investigation are not abstract legal concepts. They are operating controls. Privacy teams should define what must be protected and why. Security teams should help determine how that protection is implemented, tested and monitored.

Vendor risk also needs to evolve. Traditional vendor reviews often focus on certifications, hosting location, encryption, access control, incident response and subprocessors. These remain important. 

But AI vendors introduce additional questions. Does the vendor use customer data for model training? How long are prompts and outputs retained? Can the enterprise configure retention? Are embeddings deleted when source data is deleted? Does the system support tenant isolation? Can the vendor provide audit evidence? What happens if the model produces an output that reveals personal data or confidential business information?

None of these questions belongs neatly to one function. Legal teams understand contracts and liability. Privacy teams understand regulatory expectations and individual rights. Security teams understand control design and technical risk. Data teams understand lineage, quality and classification. Business teams understand the intended use case. Effective AI governance requires all of these functions.

The CISO's value is often in connecting these groups. A good AI governance model should not be a set of disconnected approvals. It should connect policy, architecture, vendor risk, user behavior and incident response into one operating model.

This does not mean the CISO should take over the privacy function. That would be the wrong conclusion. Privacy professionals remain essential because they define obligations, risk thresholds, fairness expectations and accountability models. The point is different: AI makes privacy more dependent on technical enforcement. A modern privacy program needs the CISO not as an occasional reviewer, but as a core operating partner.

For regulated industries, this partnership becomes even more important. Healthcare, life sciences, finance and critical infrastructure organizations handle data that can affect people's health, financial status, employment, safety or access to essential services. AI systems in these environments may not simply process information. They may generate recommendations, identify patterns, prioritize risks or create new inferences. When AI is connected to sensitive workflows, privacy risk can quickly become compliance risk, safety risk and trust risk at the same time.

A useful starting point is a disciplined inventory of AI use cases. Organizations need to know which AI tools are being used, what data they process, which vendors are involved, where data is stored, how long records are retained and who can access the outputs. Approved AI use cases should have clear technical acceptance criteria before they go live. Those criteria should cover access control, logging, data minimization, retention, vendor training practices, monitoring and escalation.

Incident response playbooks also need to be updated. Not every AI privacy incident looks like a traditional breach. An employee may paste sensitive data into an external AI tool. A retrieval system may expose restricted documents. An AI agent may call an internal system without proper authorization. A vendor may change how it handles customer data. These scenarios require clear detection, triage, containment and notification pathways.

Enterprise AI does not make privacy teams less important. It makes their work more operationally demanding. Principles such as transparency, purpose limitation, data minimization and accountability still matter, but they cannot remain only in policies or assessments. They have to be reflected in the way AI tools are approved, configured, monitored and investigated.

For CISOs, this creates a new responsibility. We are not replacing the privacy function, and we should not try to. But we do need to help translate privacy expectations into controls the organization can actually enforce.

The CISO's new privacy mandate is not to own privacy. It is to make privacy executable. In the AI era, that may be one of the most important contributions security leaders can make.

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Great Gu

AIGP, CIPP/CN, CIPM, FIP

China Chief Information Security Officer

Haleon

Tags:

AI and machine learningAI governance

Related Stories