IT Brief New Zealand - Technology news for CIOs & IT decision-makers
New Zealand

Governance controls are crucial for AI adoption and modernisation

Wed, 9th Sep 2026 (Today)
Anthony Caruana
ANTHONY CARUANA Interview Editor

The volume, velocity and variety of data that is created and captured has grown exponentially over recent years. But the number of people needed to analyse that data and react to serious threats and attacks has not kept pace. This has driven organisations to look for ways to use machine learning to triage that data, automate the remediation of issues before they escalate and free up precious time for human operators.

Underpinning those initiatives is trust. Without trust, organisations can't embrace the opportunities and benefits that automation brings. Andrew Cunje, the CISO at Appian, says it's critical that organisations partner with trusted entities when automating these critical functions.

"We're an enterprise trusted entity working with governments, banks and critical infrastructure organisations. When we're talking about sovereign nations and when people's money is on the line, security is important."

A key element of the security discussion, Cunje said, is sovereignty. When Appian was launched, its first customer was the US Army. That gives the company a view on sovereignty that goes beyond the usual mantra of only using an on-shore or on-prem data centre.

Sovereignty, Cunje said, may mean that data resides outside the country of origin but is maintained in a secure enclave where access is limited to specific people such as those with proven national citizenship. In effect, sovereignty is less about a specific location and more about tightly controlled access backed by robust at-rest and in-flight security. This leads to a zero trust architecture.

"Zero trust isn't a product you buy. It's a set of security controls," said Cunje. "It's an architecture you build. When I think about zero trust, I think about it as hyper least privilege applied to every part of the security stack."

This covers the network security, configuration management, change management, access and identity.

"The goal isn't to not trust anybody. It's about providing exactly the right access to the right resources for as long as it's needed at the right time," he added.

The management of identities has become more complex as organisations connect more devices to networks with IoT devices seen as a major expansion of the threat surface. But the advent of AI agents has pressed the accelerator even further.

Cunje said AI without a process is effectively the Wild West. That makes the need for a platform crucial to ensure agents can only access data in specific ways for an allowable set of tasks under defined conditions. That platform, he added, is especially important as organisations experiment with vibe coding.

"There's a reason attackers are going after environment-level credentials and environment variables that people put into their cloud environments. Vibe coded apps often have long-lived tokens that add complexity and create potential chaos. For us, every agent is a new non-human identity that must be properly managed and constrained."

The devil is often said to be in the details which is why Cunje contends that a strong foundation is needed. Organisations need to know where applications are and how they are triggered. They need to know what level of access the applications have to data and the network and put appropriate guardrails in place to protect against unexpected actions that can cause data loss or reputational damage.

While the recent Hugging Face attack disclosed by OpenAI seemed novel at first, the analysis that followed painted a far more disturbing picture of what happens when AI is allowed to act without appropriate guardrails.

A swarm of more than 1200 AI agents took over an unused message board and self-organised, with one agent designating itself as the 'leader' and the others referring to themselves as a collective before launching their attack on Hugging Face. While there may be a temptation to equate this with the Skynet immortalised in The Terminator, Star Trek fans may be casting their minds to the Borg and their single-minded collective.

Modernising existing business processes and security practices to take advantage of AI without adding unmitigated risk is challenging. For most organisations, the answer is to upgrade legacy systems and processes in place. 

"From a security lens, modernisation is more important than ever," said Cunje. "Whether you're a bank, a small business, or a nation state you're a target. Last year, Appian saw 1900 AI accelerated threats and then we saw vulnerabilities 3.5 times on top of what was already an exponential curve."

Every organisation will have a different security posture, he said. Choosing a partner and platform that can provide a solid foundation is critical. Rather than replacing older systems, new secure processes can be built around legacy systems with the older platform retained as a system of record that holds the data while a secure, modern platform enables the business to leverage that data securely.

That can extend to automated processes, securely coded and managed AI agents where appropriate as well has human operators. This is backed by appropriate network segmentation to ensure the blast radius of a malicious action is minimised. 

Organisations are at a critical juncture. They face the increasingly complex need to leverage AI and automation while mitigating significant risk. Trust, sovereignty, and a robust zero trust architecture enable organisations to modernise systems and processes without the need to rip and replace legacy systems.