Blog
sprinto angle right
Blogs
sprinto angle right
Risk Intelligence in the Age of AI: 5 Takeaways From a Closed-Door Roundtable

Risk Intelligence in the Age of AI: 5 Takeaways From a Closed-Door Roundtable

On August 20, 2026, Sprinto brought together a small group of CISOs, GRC leaders, and risk owners at The Oberoi, Gurugram, for a closed-door roundtable on risk intelligence in the age of AI. The leaders around the table represented insurance, fintech, edtech, steel manufacturing, HR tech, and banking, bringing very different starting points to the conversation. 

The discussion was framed around these questions: what risk intelligence means today, how AI is reshaping enterprise risk, why risk is still so hard to connect across teams, and what leaders would change if they could redesign their risk function from scratch.

There was no single answer. What emerged instead was a picture of an industry building the plane while flying it, and doing so at very different altitudes depending on how regulated, how mature, and how AI-native the organization already was.

TL;DR
  • Risk intelligence is not about collecting more findings. It is about connecting each risk to what is at stake, how much exposure the business can accept, and who has the authority to act.
  • AI is making existing risks harder to see and govern. Shadow AI, embedded vendor capabilities, subprocessors, and new data flows often extend beyond conventional ownership and assessment models.
  • Risk ownership remains a structural challenge. Startups struggle to distribute accountability beyond security teams, while larger organizations struggle to translate fragmented risks into priorities leadership will act on.
  • The answer is not simply to allow or block AI. Organizations need layered controls and graduated autonomy, giving AI more responsibility only as their data, governance, and confidence mature.

5 Things Security Leaders Are Rethinking About Risk

Across industries and maturity levels, five themes kept resurfacing throughout the discussion. Together, they show how AI is changing not just the risks organizations face, but how those risks need to be understood, owned, and managed.

1. Risk Intelligence Starts With What Is at Stake

If there was one idea that reframed the rest of the evening, it was this: risk assessment isn’t really about the risk. It’s about the stake.

If the cost of a control outweighs the potential impact of the risk it is designed to address, the organization may reasonably choose to accept that risk. Two companies can face a similar threat and arrive at very different decisions because the value at risk, regulatory exposure, business impact, and risk appetite differ.

These ideas from the discussion made that especially clear:

  • Risk appetite follows business stakes. Risk cannot be prioritized by severity in isolation. Organizations need to understand what could actually be lost, how likely that outcome is, and whether the cost of mitigating it is proportionate to the exposure. As the business grows, the same risk can demand a very different response because there is simply more at stake.
  • Regulation can change the equation quickly. A risk that the business might otherwise accept looks very different once regulatory consequences are factored in.This is one reason risk conversations increasingly need to move beyond security teams. Regulatory, financial, operational, and reputational consequences all shape whether a risk warrants leadership attention.

Rishi Srivastava, Senior privacy professional and GRC Lead, put it plainly: “Risk assessment always comes down to what’s at stake and how much appetite the organization actually has for it. The moment regulation raises the stakes, that appetite has to change too.”

  • You cannot assess what you have not classified. For organizations earlier in their risk maturity journey, data classification emerged as a practical starting point. Before deciding how much risk to accept or which controls to invest in, teams need to understand what data they hold, where it sits, who can access it, and how sensitive it is.

    That is what turns a list of risks into risk intelligence. The goal is not to treat every risk as equally urgent. It is to give each risk enough business context to decide what matters, what deserves investment, and what the organization is prepared to accept.

    2. Risk Ownership Is Still an Open Question

    Once the conversation moved from identifying risk to acting on it, another problem surfaced: ownership.

    In startups, the challenge is often less about frameworks and more about getting people to see themselves as risk owners. One participant described a familiar response when teams are asked to take accountability: “Can you just do it?” Risk gets handed back to security or compliance, even when the team making the business or technology decision is better placed to understand and manage it.

    That makes risk education an important part of building maturity. GRC teams can define the process, establish controls, and monitor outcomes, but they cannot own every risk on behalf of the business.

    At larger organizations, the problem looks different. There are more formal structures and more people responsible for risk, but getting the right risks onto the leadership agenda can be difficult. Sreeji Gopinathan, CEO of SKG Advisory, observed that established organizations can be hesitant to invest while a risk remains theoretical. Once an incident makes the potential impact tangible, however, priorities can change quickly.

    That makes the way risk is communicated just as important as identifying it. Manoj Kumar, Head of Information Security at Shiprocket, emphasized that risk needs to be translated for leadership first. Once the business impact is understood at the top, ownership and accountability become easier to establish across the organization.

    This becomes even more important with AI. A single AI use case can cut across Security, Privacy, Legal, Compliance, Product, and the business team deploying it. Each function may own part of the problem without anyone having a complete view of the risk.

    The question, then, is not simply who owns AI risk. It is whether organizations have made accountability clear enough that a risk can move from identification to decision to action without getting lost between teams.

    secure-check
    Track infosec risks live with Sprinto

    3. AI Adoption Is Expanding the Risk Surface Faster Than Governance Can Keep Up

    The question around the table was increasingly not whether organizations would adopt AI, but what happens as adoption moves faster than security and governance teams can track.

    Business teams are experimenting with new tools. Developers are using AI assistants to write code. AI is finding its way into customer experiences and operational workflows. Each use case can create value, but it can also introduce dependencies, permissions, and data flows that existing risk processes were not designed to continuously track.

    Three patterns stood out.

    • Shadow AI is growing the attack surface invisibly. Non-IT teams are now building applications with AI-generated code, sometimes with limited visibility into the underlying libraries and dependencies. Participants noted that these applications can also be difficult to integrate into standard CI/CD pipelines for security scanning, creating new visibility gaps for security teams.
    • AI is changing the third-party risk equation. Organizations are no longer assessing only what a vendor does with their data. They also need to understand which models and subprocessors sit underneath the service, what the AI can access, which actions it is permitted to take, and where organizational data ultimately travels. Participants also raised concerns about AI products that bundle capabilities together, leaving customers with limited ability to selectively control individual functions.
    • Deployment is outrunning the governance questions. A recurring pattern in the discussion was that AI use cases can move from experimentation to implementation before teams have fully answered questions about the data involved. One example involved an AI tool used in a manufacturing environment to identify potential safety issues such as spills, fire risks, and missing protective equipment. The use case demonstrated clear operational value, but it also prompted a second set of questions: Where is the data being processed? Where is it stored? Who has access to it?

    That sequence matters. When privacy, security, and risk reviews happen after deployment, governance becomes an exercise in catching up.

    4.  AI Is Making Third-Party Risk Harder to See

    The question of why risk remains so difficult to connect kept circling back to vendors. AI has not created an entirely new category of third-party risk so much as made an existing one harder to track.

    The supply chain behind an AI capability can extend well beyond the vendor an organization directly assesses. Model providers, subprocessors, cloud infrastructure, and hosting locations can all sit underneath the service, creating dependencies that conventional vendor assessments may not fully surface.

    The challenge is that organizations may have assessed the vendor they can see without fully understanding the dependency chain behind it. A vendor’s security posture is only one part of the picture when additional providers and infrastructure can introduce exposure several layers down. Participants noted that even regional hosting labels may not provide sufficient detail about the underlying infrastructure, requiring security teams to dig beyond standard vendor documentation.

    The discussion also explored a different approach to vendor access. Instead of leaving connections open continuously or transferring more data than necessary, access could become time-based, approval-based, and task-based. A vendor gets access to what it needs for a defined purpose and period, and that access closes when the task is complete.

    But more due diligence does not automatically produce better risk intelligence.

    Compliance teams already work through lengthy reports, questionnaires, certifications, and supporting evidence. As review volumes grow, the challenge is no longer getting the information but finding the issues and exceptions that actually matter.

    AI can help by processing that volume, surfacing findings, and accelerating vendor assessments. But the discussion was clear that automation cannot replace judgment. Systematic, scenario-based testing and human review remain essential, particularly when risk extends to subprocessors and dependencies beneath the vendor being assessed.

    That may be the larger lesson from third-party risk in the AI era. The problem is not simply a lack of information. It is connecting vendors, dependencies, access, controls, and business impact well enough to understand what actually deserves attention.

    5. Layered Defense Is How Governance Catches Up

    As the conversation turned from AI risk to AI governance, one question divided opinion: how restrictive should organizations be about AI use?

    For some leaders, particularly those operating in regulated environments, restricting access is a necessary starting point. Least privilege and implicit deny, where access is withheld until it is explicitly approved, can help limit exposure while organizations develop clearer policies and controls. Others argued that blanket restrictions are difficult to sustain as employees and business teams find more reasons to use AI in their day-to-day work.

    The discussion ultimately pointed beyond a simple choice between allowing and denying AI. A single switch, on or off, is not much of a governance strategy. What came up more consistently was the need for a stack of smaller, overlapping controls rather than one big one.

    Data Loss Prevention (DLP) is one of those layers, but participants were quick to point out its limitations. False positives, configuration gaps, and unmonitored channels can still leave room for sensitive information to move outside expected boundaries. Browser plugins and consumer AI tools add another visibility challenge, making it difficult to monitor AI usage end-to-end.

    The practical response is to combine controls. DLP works alongside data classification, access reviews, employee training, approval workflows, and ongoing monitoring. Each addresses a different part of the problem, from determining what data needs protection to deciding who should be able to use an AI tool and what they should be allowed to do with it.

    Anuj Pathak, Deputy Vice President at a leading financial services company, captured the human side of the challenge: “Transparency will come as the people developing AI and the people using AI mature in how they work with it.”

    Importantly, the conversation was not anti-AI. Participants also described using AI to consolidate vulnerability findings, review contracts, accelerate vendor assessments, and remove repetitive security work. The challenge is therefore not to constrain AI until it becomes harmless, but to create governance that lets organizations capture that value without giving up visibility and control.

    secure-check-waves
    Turn risk management into a Live, connected system

    What Does Risk Intelligence Maturity Look Like?

    Toward the end of the discussion, Chaitanya, from Sprinto, used the evolution of self-driving cars as a useful way to think about where GRC and risk intelligence are heading.

    At the manual stage, teams are still steering everything themselves. Risk registers live in spreadsheets, evidence is collected manually, and people connect the dots between risks, controls, vendors, and compliance requirements.

    The automated stage removes some of that repetitive work. Rule-based systems can collect evidence, monitor controls, trigger workflows, and surface issues, but people still determine what those signals mean and what to do about them.

    The augmented stage introduces AI into that decision-making process. AI can help analyze vendor documents, identify evidence gaps, connect risks and controls, or summarize large volumes of information. Humans remain in the loop, but they have more context to work with and less manual analysis to perform.

    The eventual destination is autonomous GRC, where AI can continuously identify changes, understand their impact, initiate actions, and escalate decisions that require human judgment. Much like autonomous driving, however, getting there depends on trust, context, guardrails, and confidence that the system knows when not to act.

    The discussion suggested that most organizations today are somewhere between automation and augmentation. And that may be the most useful way to think about AI maturity in GRC: the goal is not maximum autonomy as quickly as possible. It is progressively giving systems more responsibility as the organization’s data, controls, governance, and confidence become strong enough to support it.

    Risk Intelligence Needs Context, Not More Data

    Across all of these conversations, a common problem kept surfacing. Most organizations already have plenty of risk data. What’s missing is the context that connects it.

    A control fails in one system. A vendor introduces a new dependency. A regulation adds another requirement. An AI use case changes who can access sensitive information. A risk owner accepts an exception. Each signal is visible somewhere on its own, but it becomes meaningful only when connected to its business impact.

    That’s the shift Sprinto is building toward with proactive risk management. Instead of treating compliance, risk, controls, vendors, and evidence as separate workflows, Sprinto brings them into a connected GRC system. Risks map to the controls that mitigate them; control health feeds into risk posture; and treatment workflows assign owners and track actions through to resolution. Vendor risk and compliance obligations are assessed within the same operating context rather than in isolation.

    The result is a move away from point-in-time risk registers toward a more continuous view of risk. As the underlying environment changes, teams can see how those changes affect controls and posture, prioritize treatment, and give leadership a clearer picture of where attention is actually required.

    AI has a role here, too, guided by the same principle that emerged throughout the roundtable: autonomy needs context and human oversight. Sprinto AI uses organizational GRC context to assist with tasks like mapping controls to risks, analyzing evidence gaps, and accelerating vendor due diligence, while keeping humans in the loop for the decisions that matter.

    The real test of risk intelligence is whether it helps an organization see which findings matter, why they matter, who needs to act, and what should happen next, not how many findings it produces.

    secure-check-waves
    Watch Sprinto in Action

    Take the platform tour now.

    Payal Wadhwa
    Author

    Payal Wadhwa

    Payal is your friendly neighborhood compliance whiz who is also ISC2 certified! She turns perplexing compliance lingo into actionable advice about keeping your digital business safe and savvy. When she isn’t saving virtual worlds, she’s penning down poetic musings or lighting up local open mics. Cyber savvy by day, poet by night!
    Tired of fluff GRC and cybersecurity content? Subscribe to our newsletter and get detailed
    research & insights curated to help you earn a seat at the table.
    single-blog-footer-img