Over the course of The Business of Security series, we’ve explored several different aspects of security, but a common theme has emerged throughout each discussion. Whether we were talking about vendor due diligence, security maturity, operational resilience, shared responsibility, or incident response, the underlying lesson was remarkably consistent: good security is not about eliminating risk. It’s about understanding risk well enough to make informed business decisions.
That’s particularly important because many organizations still view security as a function designed to say “no.” No to new vendors. No to new technologies. No to new ways of working.
In practice, the strongest security programs I’ve seen do the opposite.
They help organizations get to “yes” faster because they create a framework for evaluating risk, making decisions, and adopting new capabilities with confidence. Nowhere is that more relevant today than with artificial intelligence. As firms across the legal industry evaluate AI-powered tools and workflows, the conversation often falls into one of two camps. Some organizations rush toward adoption without understanding the implications. Others become so focused on potential risks that they struggle to move forward at all.
Both approaches create problems.
The organizations seeing the most value from AI tend to take a different path. They don’t treat governance as a barrier to innovation. They treat governance as the mechanism that makes innovation possible.
The Real Purpose of Governance
Imagine a city deciding whether to build roads.
One approach would be to prohibit roads entirely because cars occasionally cause accidents. That approach would certainly reduce some forms of risk, but it would also eliminate most of the economic benefits transportation provides.
The alternative is to build roads, establish traffic laws, install signals, define responsibilities, and create rules that make transportation predictable. The objective isn’t to eliminate every possible accident. The objective is to create enough structure that people can move safely and efficiently.
AI governance works much the same way.
Too many governance discussions begin with the assumption that the goal is control. In reality, the goal is enablement. Organizations implement governance frameworks so they can confidently adopt new technologies without having to reinvent the decision-making process every time a new product appears. Good governance reduces uncertainty. It clarifies ownership. It establishes boundaries. Most importantly, it gives business leaders a repeatable way to evaluate opportunities without relying on instinct alone.
When governance is functioning correctly, the outcome should not be fewer ideas. The outcome should be better decisions about which ideas deserve investment. Rather than slowing innovation, governance creates the conditions that allow innovation to scale safely and consistently.
AI Adoption Is Following the Same Pattern as SaaS
A few years ago, organizations experienced a wave of SaaS adoption. Teams discovered tools that solved specific business problems, entered a credit card, and started using them immediately. Every individual decision made sense in isolation. Marketing needed a tool. Finance needed a tool. Operations needed a tool. Before long, organizations found themselves managing dozens or hundreds of applications they had never formally reviewed.
AI is following a remarkably similar trajectory.
An attorney discovers an AI-powered drafting tool. A practice group begins using a contract review assistant. An operations team adopts a productivity platform with embedded AI features. Each decision appears reasonable because the value is obvious and the barriers to adoption are low. The challenge emerges when organizations realize they have accumulated a large collection of AI systems without a shared understanding of how those systems interact with firm data, client information, and business processes.
The problem is not the technology itself. The problem is the absence of visibility.
Organizations that struggled with SaaS sprawl often focused their efforts on controlling adoption. Organizations that managed it successfully focused on understanding adoption. They built inventories, established review processes, and aligned oversight efforts with risk. AI governance requires many of those same capabilities.
Evaluating AI Vendors Through a Risk Lens
One of the biggest mistakes organizations make when evaluating AI vendors is treating every application as though it carries the same level of risk.
It doesn’t.
An AI tool that helps summarize publicly available articles creates a different risk profile than one that processes confidential client documents. Likewise, an internally isolated system poses different considerations than a platform that shares information across a broader ecosystem.
This is why risk-based review models tend to work so well.
Instead of creating a single approval process for every AI initiative, mature organizations classify applications based on factors such as data sensitivity, client impact, regulatory requirements, and operational importance. Higher-risk use cases receive deeper scrutiny. Lower-risk use cases move through a lighter review process. This approach allows organizations to maintain oversight without creating unnecessary friction.
When evaluating AI vendors, firms should focus on many of the same fundamentals discussed throughout this series. How is data handled? What controls govern access? What information is retained? How is customer data used for training purposes? What happens if the relationship ends? How transparent is the vendor about its practices and governance model?
Notice that none of these questions require deep expertise in machine learning.
They’re governance questions.
The same operational discipline that helps evaluate traditional technology vendors often proves equally valuable when evaluating AI vendors.
Practical Governance Doesn’t Need to Be Complicated
One of the biggest misconceptions surrounding AI governance is that it requires extensive committees, complicated policies, and months of review before anyone can move forward.
In reality, many organizations can establish meaningful oversight with a relatively simple framework.
First, create an inventory. Understand which AI tools are being used, who owns them, and what business purpose they serve.
Second, establish risk tiers. Not every AI application requires the same level of review, and treating every request identically usually creates unnecessary delays.
Third, assign business ownership. The teams benefiting from a tool should remain accountable for how it is used. Security, compliance, and technology teams can provide guidance, but governance becomes significantly more effective when accountability remains connected to the business outcome.
Finally, establish periodic reviews. AI capabilities evolve quickly. A tool that presents minimal risk today may introduce new features, integrations, or data-handling capabilities six months from now. Governance should be continuous rather than limited to the moment of adoption.
None of these activities are particularly complex, which is precisely why they work. Throughout this series, we’ve repeatedly returned to the idea that mature security programs are built on fundamentals rather than secret techniques. AI governance follows the same pattern.
Why “No” Is Usually the Wrong Default Answer
I’ve found that organizations often frame AI governance as a choice between innovation and control. The assumption is that more governance automatically means less innovation.
In practice, the opposite is frequently true.
When no governance framework exists, every new initiative becomes a unique conversation. Questions arise about ownership, acceptable use, risk tolerance, and approval authority. Decisions slow down because nobody agrees on how decisions should be made.
A governance framework removes much of that uncertainty. It gives teams a shared process for evaluating opportunities and clarifies the conditions under which adoption can occur. Rather than defaulting to “no,” organizations can focus on identifying what would need to happen to reach “yes.”
That’s often the most useful role security and governance teams can play. They’re not there to prevent the business from adopting new capabilities. They’re there to help the business understand the implications, implement appropriate safeguards, and move forward with confidence.
The Business of Security
When we began The Business of Security series, the focus was vendor due diligence. From there we worked through security maturity, operational resilience, shared responsibility, incident response, and customer trust. Each topic approached security from a different angle, but together they point toward a broader conclusion.
Security is not a technology function.
It is a business function.
The organizations that consistently make good security decisions are the ones that approach security as an exercise in governance, accountability, operational discipline, and risk management. They understand that security exists to protect revenue, reduce operational friction, preserve trust, and enable growth. Technology supports those goals, but it is not the goal itself.
For law firms assessing vendor security, the next steps are relatively straightforward:
- Focus on operational maturity, not just compliance credentials.
- Understand where vendor responsibilities end and your firm’s responsibilities begin.
- Ask how providers communicate during incidents, not just how they prevent them.
- Evaluate AI and emerging technologies through a risk-based governance lens.
- Prioritize transparency, accountability, and resilience as much as technical controls.
- Remember that the strongest security programs are usually the ones executing fundamentals consistently.
You do not need to become a security expert to navigate these decisions effectively. You need a framework for understanding risk, asking the right questions, and evaluating whether the organizations you trust with your firm’s data operate with the same discipline and accountability that you expect from your own.
That is ultimately the business of security.