AI in Cybersecurity: The Importance of Ethical Governance

A cybersecurity study from last year found that nearly 60 percent of Indian companies did not have an AI governance policy or were still building one.
Artificial intelligence is very important to cybersecurity operations today. But without the right guardrails, it can risk the very same assets it is supposed to protect. As organisations rush to embed AI within security infrastructure, ethical governance is often overlooked.
This introduces a raft of new, at times invisible threats, further stretching security teams. To put things in context, the number of AI-related security incidents rose by 89 percent in 2025, changing the threat landscape forever.
Inadequate governance does not merely create cracks in enterprise defences to let in external threats; it also amplifies inherent risks. When governance is lacking, attackers can poison or manipulate training data into misreading threats or altogether ignoring them; it also leads to “model drift”, compromising the effectiveness of AI security tools to increase false negatives. With a decline in training data quality, the risk of invisible bias in security operations – for example, wrongly flagging specific users or behaviours – also goes up.
Other risks of weak governance include shadow AI – employees get away with using unsanctioned AI tools that leak proprietary or sensitive data into public models – and opaque, unexplainable, algorithmic decision-making that makes it hard for security teams to validate actions and meet compliance mandates.
In short, AI is the proverbial double-edged sword, a strong defensive tool that is also becoming a means of attack for malicious actors. Besides pure security concerns, AI raises key questions around accountability, data integrity, and ethical use. For example, who is responsible if an AI security tool misreads a legitimate signal as a threat and shuts down a system ? The data provider? The developers? The security team? Given the unclear liability, enterprises need to guard against both over-relying on AI and lightening human vigilance.
Ethical Governance
A responsible AI and ethical governance strategy addresses these issues to a large extent. It asks enterprises to integrate ethical principles into AI design, development, deployment, and procurement right from the start, rather than as an afterthought. Think privacy-preserving techniques such as federated learning, homomorphic encryption, data anonymisation and pseudonymisation, and differential privacy. With the rise in autonomous systems, AI governance should prioritise human-in-the-loop practices to enforce accountability in decision-making. Clearly defined data classification techniques, access controls, and retention policies offer comprehensive data protection and enable compliance with key regulations.
Last but not least, platform-driven governance offers the required tooling to operationalise policies, check for model bias and shadow AI, etc. The most capable platforms also enable lifecycle oversight – from use-case evaluation to deployment and monitoring – and automated enforcement, integrating seamlessly with data and identity management systems to embed governance within day-to-day operations. A considered approach that brings clarity on governance goals, ensures the platform integrates neatly with the existing tech stack, prioritises model monitoring and explainability, and is future-proof (scalable and adapts to evolving technology and compliance), helps organisations pick the right option.
More than just Governance
In truth, combining ethical governance with AI-enabled cybersecurity is a more strategic move than defensive action; besides protection, it leads to business resilience and risk-mitigated innovation. When governance, by way of risk assessment, bias testing, data validation, etc., is entrenched in the AI design-to-monitoring lifecycle, the organisation is able to withstand threats and change without a break in operations. Since companies with strong ethical governance are compliant with the highest standards, they can innovate with confidence, knowing that their AI models handle data responsibly and produce reliable outcomes. More importantly, ethical AI organisations enjoy the trust of customers and regulators, the value of which cannot be overstated.
Written By - Brijesh Balakrishnan, VP & Global Head - Cybersecurity, Infosys
Read More:
Why Dell believes AI PCs need consultative selling, not hardware transactions
Why managed detection and response will define the future of cybersecurity partners
Red Hat explains why hybrid cloud and open source is a channel opportunity
Nutanix explains how hybrid multi-cloud services will define channel growth










