Skip to main content

AI showed up in most businesses before anyone fully decided or planned for it. Your team is likely using ChatGPT, Claude, and Copilot, and the software you already pay for keeps adding AI features on its own. Most of it arrived without a decision, and that is exactly why it carries risk. The AI you never approved is running on your systems, touching your data, and yours to answer for. The first step to managing that risk is seeing what's running and making sure the foundation underneath it can carry it safely.

That was the heart of a recent conversation between Cyberleaf CEO Jeff Buss and Stephen Tracy, VP of Technology at Entech, in a live session called AI Is in Your Business, Now What? Both spend their days watching businesses adopt AI, and both keep seeing the same pattern, where the tools move faster than the foundations beneath them. What follows are the five things worth understanding from that conversation, and what each one means for your business.

 

There Is Far More AI Running in Your Business Than You Think

Most leaders picture AI as a handful of tools they chose on purpose. The number in their heads is usually low, somewhere around ten or fifteen. When Cyberleaf runs an actual scan of a client's systems, the real count tells a different story.

"One of the common things that we do is we'll ask the CEOs, how many AI tools do you think you have in your environment, and they'll say, I don't know, like 10, maybe 15, and then we do a scan and it's almost always over 100."

— Jeff Buss, CEO, Cyberleaf

Most of the AI in your business arrived without anyone deciding it should and some of it came in through employees using personal accounts to move faster. Even more of it is embedded in software you already run, from Grammarly to your CRM, switched on by a vendor update without a signature or a disclosure. Every one of those connections can send your data somewhere you can't see, and once a prompt goes in or a document gets uploaded, that data is gone.

In Stephen Tracy's experience across Entech's client base, employees aren't waking up planning to dodge the rules. They reach for whatever gets the job done, and when a policy is missing or unclear, an unapproved tool is simply the path of least resistance.

"I don't think that most employees wake up and think, I'm going to use an unsanctioned AI tool today. Most of the time it's that either a policy doesn't exist or it's not clear enough."

Stephen Tracy, VP of Technology, Entech

 

AI Amplifies Whatever Foundation You Already Have

AI works like a multiplier. Aimed at clean data and clear processes, it compounds the good, and aimed at a mess, it makes that mess faster and more confident. This is why so many businesses feel let down by tools that were supposed to change everything. The tool did what it was built to do but it amplified a foundation that wasn't ready for it. 

That's also why the wins tend to stay theoretical. When a team has a defined process and organized data behind it, AI can take something that used to eat hours, like a month-end close, and turn it into a repeatable, faster outcome. Give it scattered files and undefined steps instead, and it returns work that looks confident but holds up poorly. Stephen Tracy sees the real gains land far less often than the promised ones, and the reason almost always traces back to the foundation.

Jeff Buss explains this simply: you don't hire an employee, sit them at a desk, and say good luck. You train them, you check in, you correct them. AI needs the same care and feeding. What trips most people up is the assumption that the tool will deliver on its own, with no work behind it.

 

The Speed That Makes AI Useful Also Makes Attacks Faster

The same acceleration that helps your team helps attackers, and defenders are losing the time they once relied on. Jeff pointed to a model many security teams know well.

"CrowdStrike had this model: one minute to alert, ten minutes to investigate, sixty minutes to remediate. It was designed to beat the advanced persistent threats. And what we're seeing now is that's gone."

Jeff Buss

The window has collapsed from roughly one, ten, sixty to one, ten, fifteen. Once an attacker finds a way in, AI lets them run a prepared script and reach your data in minutes, which leaves a security team almost no time to catch and stop it. This is what Jeff means when he describes AI as a margin call for tech debt, a phrase he brought back from a national cyber forum. If you haven't cleaned up your systems, AI speeds up both the discovery of your weak points and the ability to exploit them.

 

The Risk Is What Gets Exposed to Produce the Output

The value of AI shows up in what it produces, but the risk shows up earlier in what your team hands over to produce it. When someone pastes client data into a public tool, the useful answer comes back, and the sensitive information stays in a place you no longer control. That exposure is the part most people never see, and it's why shadow AI carries the weight it does.

It's tempting to treat this as a discipline problem, when it's really a matter of trust. People reach for AI because they're trying to do a good job faster, get home to their families, and impress the people they work for. They rarely stop to consider what a personal account logged in on a work computer can expose. Stephen makes the case that shame is the thing standing in the way.

"The reason why it's called shadow AI is it's done in the shadows because people are fearful of admitting that they're using AI tools. Bringing it out in the open, and making it not this thing where people are ashamed of it, will improve cybersecurity."

Stephen Tracy

Cyberleaf's AI assessments surface this exposure directly. A personal account logged in on a work device carries everything a person types across the company network, visible in ways most employees never imagined and most legal teams haven't caught up to. Governance, done well, gives people a clear answer instead of a warning. It sets out which tools are fine, which aren't, and why. Once it's safe to say what you're using, you can help people use it well, and that is where productivity and protection start to line up.

 

What Works Isn't Glamorous, and It Goes in Order

When the conversation turned to what a leader should do first, the answer was the foundation, taken in order. If you do one thing, write the policy. If you do two, write the policy and put controls in place to enforce it. Third, get your data right.

"Get the policies in place, get the controls in place, and get your data cleaned up. That foundation is going to set you up for years of success using AI."

Jeff Buss

Identity and access management sits alongside this, making sure the right people reach the right systems and nothing more. None of this is exciting or glamorous work, it takes real effort to sift through the data and lock down the access. The payoff comes afterward, when the foundation is set and productivity climbs quickly and safely.

The pace matters as much as the sequence. There's a constant pressure to move fast, much of it created by the companies selling the tools, and Stephen Tracy's advice runs the other way. Done slowly and deliberately, the results come sooner and hold up better than a rushed rollout ever does.

"That doesn't mean it has to be done fast. It can be done in a slow, smooth manner, because you're going to see more tangible results and quicker results if you do it that way."

Stephen Tracy

In regulated industries, the lines are a bit more clear. For clients handling Controlled Unclassified Information (CUI) under CMMC, Jeff keeps it simple: no AI tools are allowed to touch that data today, and it should stay well outside anything AI can reach. Industries without that regulatory weight carry the same risks, and often more, with far less visibility into them. 

 

Where to Start

AI is here whether you invited it or not, it rewards a strong foundation and punishes a weak one at the same speed, and the businesses that win are the ones that build deliberately rather than race.

If you're not sure what's running in your systems or where your foundation stands, that's the first place to begin understanding your environment. Cyberleaf's AI readiness assessment looks at governance, controls, data, and leadership alignment, and it's built on the NIST AI Risk Management Framework. It's the same starting point Jeff described in the conversation, and it turns the question of what AI is doing in your business into an answer you can act on.

If any of this raised a question about where your organization stands, the conversation starts here →