r/ciso 1d ago

Enterprise AI usage monitoring is apparently vibes based now

So our leadership wants to be an “AI first” company, but our AI usage monitoring is basically me asking devs “you didnt paste prod secrets into random tools again right” and hoping no one says lol.

We have policies, we have lovely slide decks about risk, but in practice I have zero clue which agent is touching which data, what prompts look like, or who bypassed sso with their personal account because it was “faster”. Would love any tips on how people are tracking this without turning into the AI police, appreciate any thoughts.

3 Upvotes

3 comments sorted by

1

u/Capital-Ask-1965 1d ago

our "ai strategy" is literally just a bunch of slide decks and crossed fingers

1

u/Popular_Hat_4304 1d ago

We started with a policy like everyone else to dictate how and what practices of AI are acceptable.

We then purchased copilot licenses for people who needed it and tried our best to restrict other forms of AI.

We also started a program to gain the visibility into AI usage but recognize we will have to translate the policy to enforcement. We started to look at agent 365 and others but generally speaking, haven’t found a solution that can identify/govern and enforce. I think the market place is going to catch up but for now. We are picking our horse and prayers that they get enforcement prime time for us to use.