惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
博客园 - Franky
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
有赞技术团队
有赞技术团队
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
阮一峰的网络日志
阮一峰的网络日志
C
Check Point Blog
爱范儿
爱范儿
T
The Blog of Author Tim Ferriss
aimingoo的专栏
aimingoo的专栏
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LangChain Blog
云风的 BLOG
云风的 BLOG
MyScale Blog
MyScale Blog
Microsoft Security Blog
Microsoft Security Blog
The Cloudflare Blog
博客园 - 三生石上(FineUI控件)

Latest from TechRadar

Quordle hints and answers for Monday, April 13 (game #1540) NYT Strands hints and answers for Monday, April 13 (game #771) NYT Connections hints and answers for Monday, April 13 (game #1037) Morbid Metal developer explains why he ditched an origami art direction in favor of gritty sci-fi — 'It worked, but it didn't really feel like me' '71% of US households get routers from ISPs': Why new FCC rules could leave millions stuck with outdated,… 'The CPU is the system’s executive layer': Intel joins SambaNova as both face existential threat from… ‘More bang for your buck’: 7 easy ways to boost your MacBook Neo’s performance for free DJI Romo P vs Roborock Saros 10R — which robot vacuum comes out on top when it comes to dodging obstacles? I put… I spent 6 hours with Genshin Impact on the Galaxy S26 Ultra, and I can't believe how far mobile gaming has come What is the release date for The Testaments episode 4 on Hulu and Disney+? I reviewed the LG G6 for 3 weeks, and it's a fantastic OLED TV that's the new best option for brighter rooms Is your bird feeder camera doing more harm than good? 3 tips for using it safely as RSPB issues urgent disease warning Chelsea vs Man City Live Streams: How to watch Premier League 2025/26 from anywhere in the world, team news How to watch Alcaraz vs Sinner for FREE: TV Channels for Monte-Carlo Masters Final Sunderland vs Tottenham Live Streams: How to watch Premier League 2025/26 from anywhere in the world, team news Are these the best-designed workout headphones ever? I used them for a month to find out How to watch Snooker 900 John Virgo online (it's free) – stream O'Sullivan vs Higgins anywhere I've only just discovered the Walk With Frodo app on Garmin's Connect IQ store — and as as a huge LOTR nerd, it's going to make the next 1,800 miles fly by 'Just not sustainable': Why your monthly £25 broadband internet bill could soon hit £45 How to watch Paris-Roubaix 2026: Free Streams & TV Info as Tadej Pogacar chases third Monument How to watch Euphoria season 3 online – stream Zendaya & Sydney Sweeney drama from anywhere today '$15K bill destroyed a solo developer’s startup': How hackers are using leaked Google API keys to… There's a sneaky way to watch UFC 327 really cheap... NYT Connections hints and answers for Sunday, April 12 (game #1036) NYT Strands hints and answers for Sunday, April 12 (game #770) Quordle hints and answers for Sunday, April 12 (game #1539) Amazon's Ring cameras are the perfect solution to secure your home on a budget — shop today's best deals… I've tested every iPhone since the iPhone 12, and Ceramic Shield 2 is the first iPhone glass I fully trust UFC 327 live stream: how to watch Procházka vs Ulberg, start time, preview, full card We're officially getting the DJI Pocket 4 on April 16, but here's how Insta360 could beat it
Why AI auditability is what every security leader should ...
Ravi Soin · 2026-05-08 · via Latest from TechRadar

When I joined Smartsheet, one of my first priorities was understanding where AI was actually operating across the business.

What I found was less a deliberate strategy than an honest reflection of how fast things had moved: AI tools embedded in workflows, some vendor-approved, some not, adopted by smart people solving real problems faster than policy could keep up with.

Chief Information and Security Officer, Smartsheet.

When I went back to some of those vendors to understand what we were actually dealing with — what data the model had accessed, what actions it had taken — the answers were thin. The audit infrastructure simply wasn't there.

That combination of tools already embedded in our environment with no traceable record of what they'd done is what sharpened my thinking. The risk wasn't the tools themselves; it was the invisibility.

The instinct for most security leaders is to ask: "How do we control it?" But control implies restriction, and as many of us have learned, restriction doesn't change behavior. It just drives it underground, where you have even less visibility. The question that actually matters is simpler but harder to achieve: "Can we trace it?"

The most helpful model I've adopted for answering that question: treat every AI agent as a new kind of "employee". Each should have a defined role, a scope of authority, and a chain of accountability.

You wouldn't let a new hire make consequential decisions without oversight in their first weeks. That same logic applies to an AI system operating inside your organization's workflows—and traceability is what makes that oversight real.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

From the rear-view mirror to real-time

There was a time when "audit" meant conducting a periodic look back at what happened. That changed with digital transformation. As technology-driven actions became more common, so did logging and observability platforms.

Audit became continuous, with data flowing in real time, providing a security layer that flags anomalies as they occur. Today, audit isn’t a post-mortem, but a real-time operational discipline.

With the rise of agentic AI, that means logging which data sources an agent queried, which actions it took autonomously versus escalated for approval, and who sat in that approval chain in real time, not reconstructed after the fact.

Here's why this matters at the board level: when an AI-assisted process produces a bad outcome—like a risk flagged incorrectly, a resource assignment triggered without manager approval, or a status update pushed out before anyone signed off—the first question you’ll face from leadership, legal, or a regulator is: "Who approved this, how, when, and why?"

If you can't answer those questions, you're facing a governance crisis on top of a process failure.

Audit as a foundation, not a checkbox

To solve this, security leaders need to build audit into their AI strategy from the start. Not as a compliance exercise, but as the foundational layer that makes agentic AI governable.

What I look for when evaluating any AI capability, whether built internally or sourced from a vendor, is a traceable chain: what data informed the recommendation, whether human sign-off was required before an action was taken, and who, if anyone, reviewed it. If a vendor can’t show me that chain, the capability isn’t enterprise-ready, regardless of how impressive the outputs are.

This isn’t about slowing teams down. It’s about giving people the confidence to act on AI outputs rather than second-guess them. When employees can see how an AI recommendation was generated and know that appropriate oversight is in place, they can begin to own decisions.

That’s not a compliance outcome; that’s a productivity outcome. Audit stops being a checkbox and becomes the mechanism that lets teams scale AI confidently while maintaining human accountability.

Your new AI employees

Returning to that model of AI as an employee: the framing changes what questions you ask. Instead of “How do we prevent AI from doing harm?” the question becomes: “What would we need to know to trust this AI’s judgement the way we trust a capable team member?”

The answer almost always comes back to the same things: clear ownership, defined decision rights, a record of actions taken, and a mechanism for human override. Those aren’t novel security concepts. They’re just being applied to a new kind of “employee”.

As security leaders, we cannot solve every AI risk overnight, but we can establish a foundation that moves beyond high-level principles into operational reality:

1. Map where AI is actually operating, including integrations surfaced through OAuth tokens and API keys in your systems, because you cannot govern what you cannot see.

2. Be explicit about which decisions require human sign off and which don’t, and commit to revisiting those boundaries every six months as the technology and its organizational impact evolve. What feels low-risk today may look very different when an agent is running it at scale.

3. Hold your vendors accountable by investing in like-minded organizations that have committed to full AI auditability and traceability, and integrate those controls with your existing monitoring platforms as they're introduced.

When AI is traceable, clearly owned, and auditable, governance stops being a bottleneck and becomes a competitive advantage. The organizations that figure this out will move faster because their people have the confidence to act on AI outputs and the tools to course-correct when needed. As the old adage goes, "trust, but verify."

The standards landscape is beginning to catch up. NIST's AI Risk Management Framework, the EU AI Act's requirements around high-risk AI systems and emerging agentic identity protocols are all pointing in the same direction: auditability is becoming a baseline expectation, not a differentiator. Security leaders who build for it now won't just be compliant—they'll be ahead.

Which brings us back to the question you should be asking, if you're not already: can you trace it?

We've ranked the best software asset management (SAM) tools.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit

Chief Information and Security Officer, Smartsheet.