Tim Crockett
Tim Crockett

The debate over artificial intelligence can leave business leaders caught between promises of greater productivity and warnings about risks beyond their control. Both deserve attention. But I believe this framing can obscure a more immediate responsibility. Whatever governments and technology developers decide next, leaders still have choices to make about the information their organizations reveal and the access they give new tools.

Those choices matter to employees, customers, and suppliers whose information businesses hold. In its 2025 assessment, Britain's National Cyber Security Centre judged that attackers were almost certainly already using AI to support activities including research into potential targets and social engineering. That offers a practical reason to examine exposure today, without assuming that every new capability will produce a crisis.

My concern is that uncertainty about AI can become a reason to postpone decisions that are already within management's reach. A business cannot determine how every model develops. It can decide who approves a new connection to company systems, what employees may share, and who reviews information published on its behalf.

I think of that information as a business's wake. A vessel moves forward while the disturbance behind it remains visible. Similarly, an organization's announcements, recruitment activity, supplier references, and public appearances can leave traces that persist beyond their original purpose. Leaders should consider what those traces might reveal when examined together.

Imagine a company advertising for specialists, announcing a supplier agreement, and discussing a new market at a conference. Each disclosure might have a legitimate purpose. Taken together, however, they could suggest a direction the business has not formally announced. This is a hypothetical example, but it illustrates why reviewing individual communications may leave important questions unanswered.

An outsider's interpretation could also be wrong. Public information rarely provides a complete picture, and an AI-generated assessment should not be mistaken for established fact. Even so, I would not make the accuracy of an outsider's conclusions the basis of a security policy. The more useful question is whether the organization is revealing details it does not need to disclose.

That does not mean businesses should retreat from public view. Recruitment requires useful information. Customers deserve clarity, and partnerships often depend on openness. Excessive secrecy could undermine those relationships. I would argue for deliberate disclosure, with teams considering both the value of publishing something and what it adds to information already available.

The same discipline should guide internal AI adoption. Before connecting a tool to email, calendars, or documents, leaders should require a clear business purpose and an assessment of the access involved. Permission to test a tool should not automatically become permission to connect it to additional systems.

Existing guidance offers a starting point. NIST's AI Risk Management Framework provides a voluntary approach to incorporating trustworthiness into the design, deployment, use, and evaluation of AI systems. I see its value as a foundation for structured decisions, while recognizing that each organization must examine its own circumstances.

For a smaller business, that need not mean creating an elaborate new department. It could begin with a named manager, a record of approved tools, and a short review involving the people responsible for technology, communications, and operations. The important question is whether someone has responsibility for seeing how those decisions connect.

Without that shared view, separate teams could make reasonable choices that collectively create exposure nobody intended. With it, leaders may be better placed to remove unnecessary details, restrict excessive access, and give employees clearer boundaries. These steps cannot promise security or commercial success. They can make risk decisions more deliberate.

I would start with a defined review of recent public communications and existing AI connections. Assign an accountable executive, identify unnecessary disclosures or permissions, and set a date for addressing them. Repeat the review when a significant tool, partnership, or business activity changes.

Leaders do not need certainty about AI's future before taking responsibility for those choices. They need enough visibility to understand what they are authorizing now. A business should understand the wake it leaves as carefully as the direction it takes.

About the Author

Tim Crockett is co-founder of DGBI-USA. He has spent much of his career helping organizations assess risk and consider its implications for their people, projects, and operations. His perspective on AI adoption emphasizes practical oversight, responsible information sharing, and the role of business leaders in making informed decisions about security.