As AI slips into everyday workflows faster than security teams can vet it, the enterprise attack surface is quietly expanding well beyond the model itself. New identities, APIs, connectors, and autonomous agents now sit within ERP, CRM, HR, and finance systems, and a compromised AI identity could prove as valuable to attackers as a privileged human credential. In this conversation with CISO Forum, Vaibhav Tare, CISO at Fulcrum Digital, explains why AI security is fast becoming an identity and governance challenge. He also outlines how to tame Shadow AI through safe enablement, what practical governance looks like as an operating model, how DPDP and GDPR shape delivery, and why organisations must build governance before scale.

CISO Forum: AI is now embedded in everyday workflows, often faster than security teams can vet it. What does the enterprise AI attack surface look like today, and which risks worry you most?
Vaibhav Tare: The enterprise AI attack surface has expanded far beyond models. Every AI deployment introduces new identities, APIs, connectors, vector databases, third-party plugins, cloud permissions, and autonomous agents interacting with enterprise systems. The biggest misconception is that AI risk begins and ends with the model itself.
The risks that concern me most are identity compromise, prompt injection, data leakage through AI applications, and excessive agent permissions. As organisations connect AI agents to ERP, CRM, HR, and finance systems, compromised AI identities could become as valuable as privileged human credentials. We are also seeing “Shadow AI” create blind spots where employees unknowingly expose proprietary or regulated data to external AI tools.
Security teams now need visibility across the entire AI lifecycle, from data ingestion and model access to runtime behaviour and human oversight. AI security is increasingly becoming an identity and governance challenge, not just an infrastructure challenge.
CISO Forum: Shadow AI is a growing concern, with employees using unapproved tools and feeding them sensitive data. How do you bring it under control without slowing down the business?
Vaibhav Tare: Shadow AI is fundamentally a visibility problem before it becomes a security problem. Employees adopt AI tools because they solve productivity challenges quickly, so banning them rarely works. The practical approach is to provide approved enterprise AI platforms, classify which data can and cannot be shared with AI systems, and continuously monitor AI application usage. Organisations should treat AI applications like SaaS applications by inventorying approved tools, monitoring API connections, and enforcing data loss prevention policies.
The objective should be safe enablement rather than restriction. When employees have secure alternatives and clear policies, adoption becomes both productive and compliant.
CISO Forum: Many organisations say AI governance is a priority, but few have working frameworks. What does practical AI governance look like on the ground, and who should own it?
Vaibhav Tare: Practical AI governance is not a policy document; it is an operating model. It starts with maintaining an inventory of AI systems, assigning business ownership, classifying AI use cases based on risk, validating models before deployment, and continuously monitoring AI behaviour after deployment. Governance should also include audit trails, human approval for high-impact decisions, and documented accountability for AI outcomes. These principles align with emerging AI risk management frameworks that emphasise governance across the entire AI lifecycle.
Ownership should be shared. The CISO owns AI security controls; technology teams own implementation; legal and compliance teams oversee regulatory obligations; and business leaders remain accountable for AI-driven decisions within their functions.
CISO Forum: “Secure-by-design” is often talked about but rarely delivered. How do you build security into AI adoption from day one rather than retrofitting it later?
Vaibhav Tare: Secure-by-design means embedding security before an AI application reaches production. That includes secure data pipelines, identity-first access controls, model validation, runtime monitoring, prompt filtering, and continuous logging.
Every AI deployment should undergo threat modelling just like any critical application. Organisations should define what an AI agent can access, what actions require human approval, and how anomalous behaviour will be detected and stopped.
Retrofitting governance after deployment is significantly more expensive than designing AI with security, privacy, and accountability from the outset.
CISO Forum: Fulcrum Digital serves clients in regulated sectors such as fintech and insurance. How do their compliance and data protection expectations shape your security approach, especially given India’s DPDP Act and global regulations like GDPR?
Vaibhav Tare: Fulcrum Digital serves clients in regulated sectors such as fintech and insurance, so security and data protection are built into our delivery model rather than treated as a separate compliance exercise. We align our security controls with frameworks such as ISO 27001 and SOC 2, while also addressing client-specific requirements under regulations such as GDPR and India’s DPDP Act. The DPDP Rules, notified in November 2025, reinforce requirements around reasonable security safeguards, access control, encryption, monitoring, and breach response and data retention.
In practice, this means strong data classification, least-privilege access, continuous monitoring, encryption, third-party risk management, secure development and documented incident response. The key principle is that compliance should support security, not becomes a paperwork exercise. Overall, our approach is risk-based and designed to protect client data while meeting the regulatory and contractual requirements of each market we operate in.
CISO Forum: Attackers are also using AI, from deepfakes to more convincing phishing. Which AI-led threats have you seen become real, and which are still hype?
Vaibhav Tare: The real threats today are AI-powered phishing, business email compromise enhanced with GenAI, deepfake voice and video impersonation, malicious code generation, and automated reconnaissance. AI has significantly improved the quality, scale, and localisation of these attacks.
The hype is the idea that AI has created entirely new categories of cyberattacks. In reality, attackers are still using familiar techniques, but AI allows them to execute them faster, cheaper, and at greater scale.
The challenge for defenders is to match that speed through automation, behavioural analytics, and AI-assisted detection.
CISO Forum: Cyber resilience is replacing prevention as the boardroom conversation. How would you define resilience, and what metrics show whether an organisation has it?
Vaibhav Tare: Cyber resilience is an organisation’s ability to anticipate, withstand, recover from, and continue operating through a cyber incident. Prevention remains important, but resilience recognises that breaches are inevitable.
Boards should focus on measurable business outcomes rather than security activity alone. Useful resilience metrics include detection and response times, recovery time objectives, backup recovery success rates, identity compromise recovery time, patching velocity for critical assets, and third-party cyber risk exposure.
Resilience is demonstrated when critical business services remain operational despite an attack.
CISO Forum: Supply chain and third-party risks continue to lead to major breaches, and a services company operates within its clients’ ecosystems. How do you manage that two-way risk?
Vaibhav Tare: Supply chain security has become one of the largest enterprise attack surfaces because organisations inherit risk from vendors, software libraries, cloud providers, and implementation partners.
Managing this requires continuous third-party risk assessments, least-privilege access for vendors, and software bill of materials where applicable, secure API governance, and ongoing monitoring rather than one-time vendor onboarding.
Trust should be continuously verified throughout the relationship, especially for partners with access to production environments or sensitive customer data.
CISO Forum: CISOs are expected to communicate risk in business terms. How do you make the case for security investment to the board, and what has worked best?
Vaibhav Tare: Boards rarely invest because of technical vulnerabilities. They invest because of business risk.
The most effective conversations translate cybersecurity into operational continuity, customer trust, regulatory exposure, financial impact, and brand resilience. Instead of discussing CVEs or threat volumes, CISOs should explain potential downtime, compliance penalties, customer impact, and recovery costs.
Security becomes a business investment when it is tied to resilience, growth, and enterprise risk management rather than fear.
CISO Forum: Looking ahead 12 to 18 months, what is the one shift every CISO should prepare for, and what advice would you give to peers building their AI security roadmap now?
Vaibhav Tare: The biggest shift will be the rise of AI identities and autonomous agents as first-class entities within enterprise environments. Organisations will soon manage thousands of non-human identities with access to business applications, APIs, and sensitive data.
My advice is simple. Treat every AI agent as a privileged identity from day one. Build governance before scale, monitor AI behaviour continuously, implement least-privilege access, and ensure human oversight exists for high-impact decisions.
The organisations that succeed with AI will not necessarily be those that deploy the most AI. They will be the ones who deploy it with the strongest foundations in security, governance, and accountability.
