Microsoft Trusted AI

Trust is the accelerator: on being quoted by Microsoft and a fireside chat at AI Tour London

Two things landed so far this year that I’m quietly proud of…

First, Microsoft quoted me in a Microsoft Cloud Blog piece by Alym Rayani, VP of Marketing for Microsoft Security: 5 signals of trusted AI: How organizations scale AI with security, governance, and observability. The second is that the fireside chat I took part in at Microsoft AI Tour London earlier this year is now up on YouTube.

Both are about the same problem: how do you let AI act on behalf of people inside an organisation without losing visibility, control, or accountability?

The article

The piece opens with a stat that should make any CISO sit up. According to Microsoft’s Cyber Pulse AI Security Report, more than 80% of Fortune 500 companies already have AI agents in production, and 29% of employees are using unsanctioned agents their security teams can’t see. The visibility gap isn’t a future risk. It’s already inside the building.

The framing I like most is this: the organisations pulling ahead treat trust as an accelerator of AI, not a tax on it. That is exactly the conversation I have with IT Directors and CISOs every week. Nobody wants to be the department that says no. But nobody wants to be the department that gets blamed when an agent does something it shouldn’t, either.

The five signals in the article are:

  1. You can’t scale what you can’t see — observability as the prerequisite for agentic AI.
  2. Security and privacy are architectural — built into the system, not layered on afterwards.
  3. Governance is continuous — a loop, not a gate.
  4. Responsible AI is operational accountability — clear ownership, human oversight, explainability.
  5. Digital sovereignty shapes architecture — where workloads run is a design decision, not an afterthought.

Where I come in

My quote sits under Signal 4, alongside voices from The Salvation Army, Sciensus, Scope, and Advania. My point is that AI should be treated as a shared responsibility. The level of validation you apply human oversight, automated controls, and business rules should scale with the risk of the decision the AI is supporting.

“A common-sense approach is to treat AI as a shared responsibility. Where AI supports business process or decision-making, organisations should apply appropriate levels of validation, whether through human oversight, automated controls, or business rules depending on risk…When using for internal or customer-facing chatbots, the business function owner should define the governance model, including where outputs require review and where guardrails are enforced. AI interactions should generate appropriate telemetry to detect prompt abuse, attempted instruction bypass, policy violations, and other indicators of misuse.”

When a business function stands up a chatbot, internal or customer-facing, that function owner should define the governance model: where outputs need review, where guardrails are enforced. The system should generate telemetry that lets security teams spot prompt abuse, instruction-bypass attempts, and policy violations. If you can’t see it, you can’t defend.

None of this is exotic. Agents are principals. They need the same scrutiny we already give users and devices! Least privilege, conditional access, logging, and a named human who owns the outcome.

The fireside chat

Back in February, I joined a fireside chat at Microsoft AI Tour London at ExCeL.

Watch it here: Fireside chat at Microsoft AI Tour London

The theme of the day was the Frontier Firm. Organisations that are AI-first in every function, role, and process. My angle was the one I always bring: the licence you already own is more of your AI security architecture than most people realise. Purview, Defender, Entra, and Sentinel are the observability, security, and governance layers the article describes. Most of the customers I speak to have already paid for them. The gap is rarely the tooling. It’s the operating discipline; deciding who owns what, what “good” looks like, and how you’d know if it stopped being good.

It was a spur-of-the-moment opportunity, and I enjoyed being flung questions with little or no prep beyond the day.

What I’d tell a steering committee this week

If you take one thing from the article, take the four questions it says Frontier Firms can answer about every agent in their estate:

  • What agents exist?
  • Who is using them?
  • What systems and data do they access?
  • What outcomes do they drive?

If your AI steering committee can’t answer all four today, start there. Don’t start with a policy document. Start with an inventory.

And treat governance as a loop. Assessing impact, defining metrics, and monitoring continuously is a good way to understand what continuous oversight actually looks like. Approve-once-and-forget doesn’t survive contact with a system that reasons and acts.

Thank you

Being quoted alongside people running AI programmes at scale in the wild, healthcare, and MSPs is a privilege, and it reflects the work my colleagues at CDW UK & International do every day with customers who are trying to get this right. Thanks to the Microsoft Security team for the invitation to contribute.

If you want to talk about observability for agents, applying Zero Trust to AI, or what your steering committee should be asking, get in touch!

Related Posts

comments