
Former Air Force officer Dan Sorensen says companies should publish a one-page 'commander's intent' for AI use, signed by the CEO, after IBM data shows 63% of breached organizations have no AI governance.
Sixty-three percent of organizations that suffered a data breach in 2025 had no AI governance policies at all, according to the IBM and Ponemon Institute Cost of a Data Breach Report. Among those that experienced an AI-related incident, 97% lacked proper access controls. Unsanctioned "shadow AI" use added an average of $670,000 to breach costs, one of the costliest factors in the study.
Dan Sorensen, a fractional vCISO and former U.S. Air Force officer who advises companies on AI governance, said the numbers match what he sees in post-incident meetings. The problem is rarely sophisticated attacks. Companies where nobody defined what safe AI use looks like leave employees to improvise. A marketing analyst pastes customer data into a free chatbot to hit a deadline. A developer runs proprietary code through an unapproved model to ship faster. When leadership goes silent on AI, people substitute their own judgment for the intent nobody stated.
Sorensen borrows a military planning concept to fix it: commander's intent. The idea is a short, plain statement of the end state and why it matters, written so the people closest to the action can make sound decisions when conditions change and the playbook runs out. "Strip away the uniform, and it's simply this: Tell people where you're going and why, then trust them to navigate," he wrote in a Forbes Technology Council post. Most companies adopting AI do the opposite, he said.
The executive suite recognizes the threat. The World Economic Forum's Global Cybersecurity Outlook 2026, based on responses from more than 800 executives across 92 countries, found 87% now rank AI vulnerabilities as their fastest-rising threat. CEOs moved AI into their top two concerns for the first time. PwC's 2026 Global Digital Trust Insights survey found only 6% of business and technology leaders call themselves very capable of withstanding attacks across the vulnerabilities surveyed. The top two barriers to using AI for defense were knowledge and skills gaps, not budget. With ISC2 measuring the global cybersecurity workforce shortage in the millions, Sorensen said no company can hire its way out of the problem. The gap is a leadership gap that must be closed with clarity, not headcount.
Sorensen said he stopped writing rules-based policies because they expire. A prohibition list ages out the moment a new model ships, and new models ship weekly. Gartner's 2026 cybersecurity trends reached a similar conclusion, telling security leaders that shadow AI is inevitable and that control-heavy centralized policies should give way to collaborative models that push accountability into the business.
The one-page document he now writes answers three questions in language an employee can repeat at the coffee machine. First, why is the company adopting AI? That is the business purpose stated plainly, such as cutting proposal turnaround from two weeks to two days, not "driving innovation." Second, what can never happen? That is a handful of non-negotiables, such as no customer data in unapproved models and no AI output reaching a client without human review. Third, what does success look like? That requires a picture people can steer toward.
NIST's AI Risk Management Framework supports this sequencing through its Govern function, which establishes accountability and risk tolerance before cataloging systems. The OWASP AI Exchange offers a similar blueprint from the security side. Companies that skip Govern and jump to technical controls are the ones whose adoption outruns them, Sorensen said.
His first recommendation: publish the intent before the policy. One page, signed by the CEO, not the CISO. Identical documents carry completely different weight depending on whose name sits at the bottom, he said. Name the upside explicitly, since IBM's data shows that organizations using AI extensively in their own security operations resolve breaches faster and cheaper. People follow leaders toward opportunity more readily than away from risk.
Next, run a quarterly AI retrospective. Ask teams what tools they are actually using and what nearly went wrong, then update the intent. Keep it blameless. The moment someone gets punished for honesty, the honesty stops. The companies bleeding $670,000 in shadow AI costs are the ones that never asked, he said.
Lastly, delegate approval authority with limits. Set preapproved pathways for new tools within defined data classifications, and escalate only at the boundary. A sales team should not need a committee to try a meeting summarizer that touches no customer data. They should need one before connecting anything to a CRM.
"It's never 'Do you have an AI policy?' Nearly two-thirds of breached organizations couldn't clear that bar anyway," Sorensen wrote. The 2026 WEF report shows the distance between organizations that embed resilience into their leadership agendas and everyone else is widening. AI did not create that divide; it just exposed it.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.