How AI is redefining risk and the CISO’s role in building trust | NTT DATA

Thu, 30 July 2026

How AI is redefining risk and the CISO’s role in building trust

How to protect data, models and infrastructure across hybrid and sovereign AI environments

 

AI is changing how organizations manage risk. Cybersecurity is no longer limited to protecting systems from attack. It has become essential to enabling organizations to innovate, operate with confidence and build trust in a world shaped by AI, data sovereignty and an increasingly sophisticated threat landscape.

In this new reality, the Chief Information Security Officer (CISO) has a broader mandate: to ensure AI is deployed securely, responsibly and with the resilience and governance needed to support long-term business success.

NTT DATA's 2026 Global AI Report: A Playbook for Private and Sovereign AI highlights the scale of this shift. According to the report, 96% of organizations are concerned that AI and generative AI could lead to privacy breaches or the misuse of customer data. At the same time, only 47% are confident they can meet their data sovereignty requirements. Excluding budget constraints, data security including privacy ranks as the top challenge to AI adoption.

These findings reveal a widening gap between the pace of innovation and organizations' ability to protect what matters most. AI promises greater efficiency, automation, richer customer experiences and smarter business models. But it also creates new forms of risk: data moving across jurisdictions, models trained on sensitive information, third-party integrations, continuous model retraining and increasingly complex cloud environments.

The era of cyber resilience

Cyber resilience goes beyond recovering from a cyberattack. It means designing organizations that can withstand disruption, adapt to change and continue operating while learning from every challenge.

That requires embedding security into every layer of the organization from architecture, data and AI models to identities, third-party ecosystems and governance. The focus shifts from protecting assets to protecting trust.

The report also highlights a significant gap in cloud security. Only 38% of organizations are confident in their cloud security capabilities, while just 48% have formal plans to manage AI- and cloud-related security risks. This gap matters because cloud security underpins data residency, regulatory compliance and the protection of AI models against unauthorized access.

For today's CISO, one of the greatest challenges is ensuring that security is designed into every business process from the outset rather than added later.

Effective governance requires robust data classification, segmented access based on zero trust principles, encryption throughout the data lifecycle, data lineage, regular red teaming exercises and centralized identity and key management. In private and sovereign AI environments, effective governance starts with architecture. Without it, organizations cannot enforce the controls they need.

The sovereignty imperative

Data sovereignty adds another layer of complexity. According to the report, 95% of organizations consider sovereign AI important to their AI strategy, yet only 29% are prioritizing concrete actions in the short term. Awareness is high, but execution is lagging behind.

For CISOs, this means being involved in decisions about architecture, cloud, data, AI, procurement and enterprise risk. Privacy and sovereignty are no longer just legal or compliance issues they have become architectural design requirements.

They determine where data can reside, which models are permitted to process it, the jurisdictions under which those models operate and the controls that must be enforced. In highly regulated sectors such as healthcare, financial services, the public sector, energy and manufacturing, the consequences of getting these decisions wrong extend far beyond data protection. Business continuity, stakeholder trust and organizational reputation are also at risk.

Hybrid environments demand a new security mindset

The challenge becomes even greater in hybrid environments. The report found that 51% of organizations identify the complexity of hybrid infrastructures as one of their biggest obstacles to running AI workloads in private cloud environments. At the same time, 97% agree that business-critical AI workloads should remain in private or on-premises environments.

These findings make it clear that organizations can no longer think in terms of choosing between public and private cloud. The challenge is no longer choosing between public and private cloud. It is determining which AI workloads belong in each environment and why.

This is where the CISO plays a critical strategic role. Beyond defining security controls, they must help the business decide what needs the highest levels of protection, where AI workloads should run and how those environments should be governed, monitored and audited. Organizations that develop this capability will be better positioned to build resilient AI strategies while maintaining regulatory compliance and operational flexibility.

Preparing for the next wave of AI-powered threats

The threat landscape will continue to evolve. Attackers are already using AI to identify vulnerabilities faster, create more convincing phishing campaigns and adapt their techniques at unprecedented speed.

To stay ahead, organizations will need security capabilities that evolve just as quickly. That includes integrating advanced threat intelligence, expanding offensive security testing through regular red teaming, augmenting security operations centers (SOCs) with AI, automating incident response, strengthening ransomware recovery capabilities and measuring resilience through business-focused metrics rather than purely technical indicators.

Ultimately, the organizations that succeed will not simply be those that prevent attacks. They will be the ones that demonstrate resilience, adapt quickly and maintain business continuity under pressure.

For today's CISO, this is an opportunity to lead with a broader vision: transforming cybersecurity into the foundation of trust that enables organizations to adopt AI with confidence, protect their data and accelerate innovation.


Related Insights

How can we help you?

Get in touch