Many CEOs have a shaky belief in the transformative power of technology; they recognize its potential but doubt that will materialize. This is one of the reasons why so few CEOs take a lead role in technology initiatives.
But when it comes to Generative AI, they seem to be making an exception. In the recently published Infosys Generative AI Radar North America, 16 percent of respondents said their company CEO was the main sponsor of generative AI. This suggests that CEOs view the technology as transformational and want to back it fully by providing strategic direction and the necessary resources. But in 18 percent of organizations, the CISO was the main sponsor, personally ensuring the organization’s defenses were equal to the elevated security threat posed by generative AI.
So, to make generative AI programs work, CEOs and CISOs need to balance their respective expectations of business value and robust security. The following considerations (among many others) could help them decide what, and how much, to do.
CEOs, check if you have what it takes
CEOs know that timing matters. Most exciting is the potential to improve Enterprise Structural Ambidexterity, to reduce the basic tension between the “Enterprise Left-brain” vs. “Enterprise Right-brain” that is present in all businesses. Left brain teams and workflows focus on near term profit maximization and operations. Right brain teams focus on discontinuous growth, disruption, and invention. Acting quickly on gen AI can secure early-mover advantage, with some associated risks with being a first mover.
CEOs must greenlight the project when the required resources, including technology stack, AI ready Data and data architecture, operating model, governance framework, and talent, are in place. General AI transformation has a significant impact on culture and people, and leaders must take a top-down approach to guide this transformation constructively. This includes fully loaded tech-stack complete with computing power, data access, Gen AI tools, algorithmic models, and an infrastructure strategy orchestrating it all to create business value. Also, generative AI requires higher order technical skills combined with knowledge of engineering, design, product development, risk management etc. depending on the scale of the implementation and area of application.
Identify how you will create value
It is easy to get lost in the maze of generative AI possibilities. Enterprises should not view generative-AI in the same way that they view algorithms, bots, automations, and ML. They should be thinking about “AI Twins” that augment & assist human counterparts. Such AI-twins will have “skills” that are relevant for the roles they fulfill. CEOs must maintain focus by identifying their company’s path to business value. They need to prioritize the various opportunities before them and ensure alignment with organizational goals. While pursuing quick wins, CEOs must also identify the big business problems they will target with generative AI in the future.
At the same time, don’t ignore risk
A recent global survey on generative AI found that the majority of companies do not adequately address the risks of generative AI: just 38 percent are making efforts to mitigate cybersecurity risks; even fewer – 32 percent – are addressing inaccuracy, the risk most commonly associated with this technology. Add bias, misinformation, ethical violation, and even hallucination (yes!) to the mix, and the consequences of unaddressed risk look menacing indeed. While the CIO and CISO are responsible for creating risk management infrastructure and governance frameworks – in the Generative AI Radar about a fifth of respondents said generative AI governance was led by the CIO (21.6 percent), company board (20.8 percent) or CISO (20.5 percent) – the CEO should set the tone by sponsoring only those generative AI use cases which are within the company’s risk tolerance.
CISOs, trust nothing, test everything
As clear as generative AI’s fearsome potential are the potential risks associated with it. To cite just one example, attacks on large language models can range from prompt injections to data poisoning to adversarial attack, causing the models to act in undesirable, unexpected and malicious ways. Gen AI is fueled by data, and enterprises can mitigate Gen AI output risks and improve its performance by organizing and fingerprinting data with adequate safeguards and practices. Bringing any type of data that’s being used for Gen AI under ‘management and governance’ is as important as getting the value out of that data.
With generative AI-based attacks guaranteed to increase, and also evolve in unpredictable fashion, CISOs should look at intensifying their approach to cybersecurity. One way is to embrace “zero trust” – eliminating implicit trust to validate every digital interaction at every stage – to limit the impact of attack; towards this, CISOs must enforce zero-trust security for all interactions with gen AI tools, apps and platforms. They must also watch out for new attack vectors against which they have no defense at present. Continuous monitoring of generative AI traffic can detect suspicious patterns to alert the organization to imminent attack; also, instead of testing software at the end of the development cycle, just prior to deployment, organizations should continuously test and verify software at every stage. Attention should also be focused on API testing and security.
To mitigate the risks of generative AI, CISOs must establish a secure data foundation and prioritize security, privacy, and compliance. Enterprises with highly satisfactory AI outcomes consistently demonstrate trustworthy, ethical, and responsible data practices. These prerequisites address data verification and bias challenges, build trust, and enable practitioners to leverage deep learning and other advanced algorithms.
A Responsible AI (RAI) Framework is essential for overcoming ethical challenges and building trustworthy Gen AI/AI systems. These tenets are essential for enterprises to democratize and widely adopt Gen AI/AI models to drive business benefits.
Unfortunately, many organizations are grappling with the policies, principles and foundation necessary to create scaled AI led transformations in their business. Just one example – companies aren’t able to create external network of collaboration since they don’t have the secure and governed foundation to share their data, which could include confidential or private information. Any data they exchange with the outside world lives forever, out of their control. CISOs need to think about what happens to data once it is in a collaborative space external to the organization, who can abuse it, lay claim to it, or misappropriate it for wrongful gains. These Gen AI risks can be mitigated through secured exchange frameworks, tools, effective governance, and employee education.
In short
That even CEOs and CISOs, and not just CIOs, are sponsoring gen AI initiatives shows that organizations are taking its beneficial as well as threat potential seriously. To maximize the first and mitigate the second, CEOs and CISOs must together ensure adequate resources, identify the right opportunities, and take stringent measures, such as zero trust, to guard against the heightened security risks posed by generative AI. Generative AI capabilities will continue to soar, putting increasing pressure to ensure its responsible development as a crucial foundation.
##
ABOUT THE AUTHOR
Sunil Senan is the Global Head of Data, Analytics and AI at Infosys, working with CXOs and Chief Data/AI Officers across industries to transform their businesses using data, analytics and artificial intelligence. With over 28 years of experience in the IT sector, Sunil has a deep understanding of the opportunities and challenges that data and AI present for various industries and markets. Sunil is passionate about delivering value and outcomes for our clients, partners and stakeholders. He has a proven track record of driving growth, innovation and excellence in the data and AI space.





