AI Governance Library

Engineering a Culture of AI Security

AI security is rarely treated as a cultural problem. Most organizations manage AI risk with technical controls, and do very little about the risks that people introduce: shadow AI, blind trust in hallucinated output, unintentional IP leakage and more.
Engineering a Culture of AI Security

⚡ Quick Summary

Engineering a Culture of AI Security, published by the AIUC-1 Consortium and led by Dr. Keri Pearlson and Chris DeNoia, addresses a critical blind spot in enterprise AI adoption: the human element. While organizations routinely invest in technical safeguards, traditional controls fail to mitigate employee-driven risks such as shadow AI usage, unverified hallucinations, and unintentional intellectual property leakage. Building on behavioral science research from MIT Sloan, the whitepaper establishes a structured framework demonstrating how managerial mechanisms and external influences shape organizational values, attitudes, and beliefs, which ultimately drive daily behaviors. The report outlines actionable strategies—from executive modeling and ambassador programs to paved-road Centers of Excellence—enabling security leaders to transition from punitive compliance mandates to supportive security marketing that turns employees into active defenders.

🧩 What's Covered

The whitepaper provides a comprehensive, behavior-driven blueprint for AI risk management, structured across foundational concepts, core behavioral expectations, and tactical operational mechanisms:

  • Taxonomy of Human-Centric AI Risks: Synthesizes leading standards (AIUC-1, NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP Top 10 for LLMs) into primary risk categories: Governance & Accountability, Privacy & Data, Reliability & Performance, Human & Societal Impact, Security & Safety, and Agentic & Autonomous risks.
  • The Behavioral Science Foundation: Applies Dr. Keri Pearlson’s organizational culture model, mapping how managerial mechanisms (leadership, evaluation, rewards, communication) influence internal values and generate secure actions.
  • In-Role vs. Extra-Role Behaviors: Distinguishes essential daily tasks (applying critical thinking before relying on outputs, adhering to clear data classification boundaries, understanding end-to-end data flows) from voluntary team contributions (continuous self-education, sandboxing, peer support, and reporting near-misses).
  • Five Actionable Managerial Steps: Detailed implementation guidance covering visible leadership modeling, positive recognition programs (e.g., digital defender badges), localized peer AI ambassador networks, embedding AI security into performance reviews and OKRs, and establishing AI Centers of Excellence that offer frictionless, vetted pathways.
  • Measurement Framework: Outlines actionable leading indicators (approved tool adoption rates, voluntary speak-up reports, output audit volumes) paired with lagging indicators (incident reductions, shadow AI drop-off), while warning against misleading vanity metrics.

💡 Why it matters?

Technical safeguards and firewalls cannot govern what an employee pastes into an unauthorized browser tab or whether they critically verify an authoritative-sounding hallucination. By reframing AI security from technical policing into an organizational culture discipline, this resource provides security and governance executives with a repeatable strategy to reduce enterprise exposure. Establishing frictionless paved roads ensures innovation velocity without compromising data protection, intellectual property, or regulatory compliance.

❓ What's Missing

The document focuses heavily on high-level cultural frameworks and organizational mechanisms without providing standardized rubric templates or evaluation checklists for specific job roles. Additionally, while it highlights prompt injection and agentic risks, concrete technical implementation guidelines for automated Data Loss Prevention (DLP) configurations and technical auditing pipelines within enterprise sandboxes remain high-level and warrant supplementary technical architectures.

👥 Best For

This report is essential reading for Chief Information Security Officers (CISOs), Chief Information Officers (CIOs), AI Governance Leads, Chief Risk Officers (CROs), and GRC professionals aiming to operationalize human-in-the-loop safeguards and curtail shadow AI across enterprise business units.

📄 Source Details

  • Title: Engineering a Culture of AI Security
  • Publisher: AIUC-1 Consortium
  • Lead Authors: Dr. Keri Pearlson (MIT Sloan School), Chris DeNoia (DeNoia Consulting)
  • Editors: Abby Shen, Emil Lassen
  • Format: 25-page Whitepaper / Research Report
  • Reference URL: aiuc-1.com

📝 Thanks to

Credit to lead authors Dr. Keri Pearlson and Chris DeNoia, editors Abby Shen and Emil Lassen, and the broader AIUC-1 Consortium working group comprising security leaders from organizations such as MongoDB, Salesforce, Concentrix, Mandiant, Upwork, Block, Meta, Fastenal, and Deloitte.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.