3 min readAI, Security
The gap between an AI demo and AI in production
Experimenting with AI is easy. Running it in production, in a way a security officer will sign off, is a different job, and the gap is discipline rather than capability.
By Dave Tormey
There is a difference between experimenting with AI and running AI that a chief information security officer will sign off. There is no shortage of the first: copilots, agents, weekend projects and frameworks that promise autonomy. Far fewer organisations have the second.
The gap is discipline
In my experience the gap is rarely what the model can do. It is the work around it: knowing where the data is allowed to go, keeping one customer’s information apart from another’s, being able to show afterwards what the system did, controlling which model version is running, and agreeing up front what result it is meant to deliver.
AI does not remove any of those requirements. It makes each of them harder to ignore.
Where the value is
The organisations getting real value from AI are not chasing the newest tool. They are putting it into workflows they already run, inside infrastructure they already secure, with a named person accountable for the result.
AI is not a strategy on its own. It is one way of getting a result, and it should be judged on that result.