Skip to Content
OPINION

Threat hunters think about AI risk differently

While many AI governance discussions focus appropriately on transparency, fairness and compliance, threat hunters tend to focus on adversarial pressure, operational degradation, automation bias and how systems behave in real world environments where users, data flows and decision-making conditions are imperfect.

Published
Subscribe to IAPP newsletters

Contributors:

Joseph McNamara

AIGP, CIPP/US

Cyber threat hunter

U.S. Army Cyber Command

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.

Organizations building artificial intelligence governance programs often focus on familiar and important concerns: transparency, fairness, accountability and regulatory compliance. These discussions are essential as AI systems become increasingly integrated in business operations. 

But operational cyber teams, particularly threat hunters, often evaluate AI risk through a very different lens, and that difference has real consequences for how governance programs succeed or fail in practice.

Threat hunters assume that any operational system exposed to users, external data or networked environments will eventually be probed, manipulated or repurposed in unintended ways. That assumption is not pessimism. It is professional habit, shaped by years of watching well-designed systems fail in ways their designers never anticipated.

Consider a healthcare organization deploying an AI-assisted triage or documentation platform. Governance discussions may appropriately focus on privacy disclosures, vendor management, human oversight and regulatory obligations. Security teams, however, are asking different questions. What happens if an attacker manipulates inputs to degrade outputs over time? How would the organization detect abnormal system behavior? What telemetry exists to identify misuse or unauthorized data exposure? What happens when operators become overly dependent on AI-generated recommendations during high-tempo operations?

These are not theoretical concerns. The U.S. National Institute of Standards and Technology's AI Risk Management Framework specifically identifies prompt injection, data poisoning, model inversion and insecure integrations as core security concerns for AI deployments. Each of these represents not just a technical failure mode but a governance blind spot when security teams are excluded from early planning conversations.

Traditional governance frameworks emphasize whether an AI system behaves as intended under expected conditions. Threat hunters ask how the system behaves under adversarial pressure or degraded operational conditions. That distinction matters because real environments are rarely the ones governance documents describe.

Governance discussions frequently emphasize the importance of keeping humans "in the loop." That requirement is codified in frameworks like Article 14 of the EU AI Act, which requires that high-risk AI systems be designed so natural persons can effectively oversee them, and which explicitly names "automation bias," the tendency to over-rely on AI outputs, as a risk deployers must actively manage. But the harder question is whether meaningful oversight is actually achievable under the conditions most operators face.

I have worked in two environments where this gap between policy and reality is visible every day. As a nurse practitioner with 20 years of clinical experience, I have watched care teams absorb AI-assisted recommendations into their workflow so seamlessly that the recommendation becomes the decision, not a data point informing one. 

As a threat hunter assigned to an Army Cyber Protection Team, I have seen the same pattern in security operations, where sustained alert volume and analyst fatigue erode the deliberate scrutiny that real oversight requires. A 2024 survey found that 62% of security operations center alerts are entirely ignored and analyst accuracy drops by 40% after extended shifts, not because analysts are careless, but because the operational environment makes sustained vigilance cognitively unsustainable. 

Research on AI-assisted clinical decision support confirms a parallel risk: over-reliance on AI tools can cause clinicians to overlook signs the AI itself might miss. Academic analysis of the EU AI Act's Article 14 has acknowledged as much, noting that empirical evidence points to significant limitations in human oversight's effectiveness, driven by cognitive constraints and automation bias that governance language does not resolve.

The operational question, then, is not whether humans are in the loop. It is whether they are meaningfully in the loop, or whether they are simply present while the system makes decisions the humans no longer have the time or context to fully evaluate.

Threat hunters are also focused on visibility in ways governance committees may not be. Policies governing acceptable AI use matter, but operational teams are the ones responsible for detecting misuse in practice. That requires telemetry, behavioral monitoring and anomaly detection capable of identifying unusual prompt patterns, unauthorized access attempts, suspicious application programming interface activity and signs that underlying data pipelines have been corrupted or manipulated. 

Data poisoning attacks are particularly difficult to detect because the compromise occurs during training, before deployment, meaning the model may behave incorrectly from day one without any obvious indication that something is wrong. In many organizations, the first indication of a problem will be a subtle behavioral anomaly, not a system failure.

This is precisely why AI governance benefits from cross-functional participation that includes operational security from the start. The IAPP's 2025 Organizational Digital Governance Report found that siloed approaches to digital governance are increasingly insufficient, and that the convergence of AI governance, cybersecurity and privacy now defines how mature organizations manage enterprise risk. 

Legal, compliance and privacy professionals bring essential expertise in regulatory obligations, transparency and accountability. Operational cyber teams bring something different: experience with adversarial conditions, behavioral anomalies and the ways systems degrade under pressure that compliance frameworks rarely anticipate.

This does not mean every privacy professional needs to think like a threat hunter. It means governance programs benefit from including people who do. Security teams should not be pulled into AI discussions only after something goes wrong. Their input during system selection, deployment planning and ongoing monitoring can surface practical risks that are invisible from a purely policy-oriented perspective.

Many governance frameworks implicitly assume AI systems will be scrutinized by competent, attentive humans operating under reasonable conditions. Threat hunters know that assumption does not survive contact with the operational environment. As organizations move from experimenting with AI to depending on it, governance programs will need to account for the reality that systems operate in not just the conditions under which they were designed and approved.

The threat hunting mindset will not solve every AI governance problem. But it may help organizations ask questions that prevent the most consequential ones.

The views expressed in this article belong solely to the author.
CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

Joseph McNamara

AIGP, CIPP/US

Cyber threat hunter

U.S. Army Cyber Command

Tags:

AI and machine learningData securityRisk managementStrategy and governanceAI governance

Related Stories