Don’t hunt the fool’s gold in the AI gold rush

In the rush to experiment and deploy, many organisations overlook basic cybersecurity hygiene.

Summarise
    • Organisations must treat AI adoption not as a standalone initiative but as part of a
broader cybersecurity strategy.
    • Organisations must treat AI adoption not as a standalone initiative but as part of a broader cybersecurity strategy. PHOTO: PIXABAY
    Published Wed, Dec 24, 2025 · 07:00 AM

    ARTIFICIAL Intelligence (AI) is the new gold, and businesses are racing to stake their claim. From generating insights to unlocking new efficiencies, organisations across industries are betting on AI to drive growth and innovation.

    Yet, the true value of AI isn’t the algorithms themselves, but the data that fuels them.

    Intellectual property, customer records, and operational knowledge are the most valuable data assets that give companies their edge. And like gold, they must be guarded carefully.

    Rushing to mine this data carries risks. Employees experimenting with AI tools outside IT oversight can expose sensitive information, while threat actors automate attacks such as phishing with alarming precision. Amid these pressures, one question becomes urgent: who’s guarding the vault?

    The hidden cost of moving fast

    AI systems run on enterprise data, with customer records, financial information, source code, and sensitive communications constantly fed into models for training or analysis. Yet, in the rush to experiment and deploy, many organisations overlook basic security hygiene.

    Even well-meaning employees can create risk. Verizon’s 2025 Data Breach Investigations Report finds that about 15 per cent of employees routinely access generative AI systems on their corporate devices, 72 per cent do so using non-corporate e-mail and 17 per cent bypass integrated authentication altogether.

    In Singapore, Yubico’s 2025 global State of Authentication survey shows that 44 per cent of employees interacted with a phishing message in the past year. These behaviours highlight how experimentation and unsafe habits can expose sensitive corporate data – exactly the vulnerabilities threat actors are ready to exploit.

    The risks don’t stop there. Threat actors are also weaponising AI, automating phishing campaigns, crafting near-perfect impersonations, and cloning voices or e-mail at scale. The result is a rise in precision-targeted credential theft – the modern equivalent of picking the vault’s lock.

    Identity and access management: The silent risk

    The danger is even greater when those with elevated access are involved. Developers, data scientists, and engineers often hold privileged access to AI environments, source code repositories, and sensitive datasets. Even if these accounts are protected by passwords or multi-factor authentication (MFA), stolen credentials remain among the most common causes of breaches worldwide. A breach in an AI environment can expose not just one account, but entire datasets and the insights built from them.

    The damage extends from regulatory penalties under frameworks such as the European Union’s General Data Protection Regulation to the loss of hard-won trust from customers and partners.

    A three-part response: strategy, policy, and people

    Organisations must treat AI adoption not as a standalone initiative but as part of a broader cybersecurity strategy. A three-part approach can help:

    • Strategise: Map how AI intersects with identity systems, data stores, and user workflows. Set clear boundaries for what data can be processed by public versus private AI tools, and define authorised users.
    • Policy: Enforce boundaries with strong authentication. Privileged users – and anyone handling sensitive data – should authenticate using phishing-resistant methods, such as hardware security keys.
    • People: Empower employees with awareness and training. Many assume that cloud-based platforms are safe by default. Without guidance, even well-intentioned use can result in data exposure. Security awareness paired with usable, intuitive authentication ensures that human error doesn’t undermine enterprise defences. While technology may automate decision-making, trust remains a human function. When security tools are simple, people use them correctly – turning the user from the weakest link into the first line of defence.

    Security as a strategic enabler

    Cybersecurity is often framed as a cost, but it is, in fact, an enabler of trust. In the age of AI, trust means everything.

    Organisations that pair innovation with strong authentication such as MFA, passkeys, and hardware security keys can move faster but with greater confidence, protecting the data that powers AI, upholding customer trust, and strengthening resilience.

    AI may be the new gold. However, in the race to mine its value, only those who secure the vault will keep what they find.

    The writer is vice-president, Asia-Pacific and Japan, Yubico.