Cybersecurity, the overlooked foundation in the race for AI

Although organizations rush to adopt artificial intelligence (AI), many do so without properly integrating cybersecurity into their strategies. Experts caution that this oversight risks not only data security but also consumer trust and business continuity.
The rapid development of AI cannot be separated from a solid security architecture. This is demonstrated by the EY Responsible AI Pulse Survey, which found that 75% of CEOs believe their AI use aligns with consumers’ ethical expectations, yet only 35% of users agree.
Furthermore, EY’s AI Sentiment Index reveals that while 82% of people already use AI, only 57% feel comfortable with it. The main concerns are system security (64%) and data privacy (61%).
Governance Still Weak.
The same study shows that AI implementation is advancing faster than the ability to govern it. Only 20% of executives believe their organization has strong governance frameworks, and just 9% have specific cybersecurity controls for AI models.
When AI systems are built without embedding data protection, access controls, traceability, and auditability by design, organizations expose themselves to failures and vulnerabilities that can negatively impact public trust.
AI Without Security.
In Colombia, the disconnect between technological innovation and cybersecurity is particularly evident. The “Board Priorities 2025” study by EY reveals that while innovation and emerging technologies rank second among board priorities, cybersecurity is only in eighth place.
Even more striking: 95% of boards prioritize AI use to capture market opportunities and improve efficiency over risk mitigation. From a technical perspective, this gap is alarming. Every new AI model expands the attack surface—from exposed APIs to poorly governed sensitive data.
The urgency to integrate these systems into hybrid or multicloud environments also poses new challenges. How prepared are these environments to withstand threats or contain data leaks?
Secure Design from the Start.
The growing adoption of GenAI and AI agents interacting with multiple applications adds complexity and risk. Security cannot be an afterthought; it must be integrated from model training through data validation, access controls, identity management, and post-deployment monitoring.
Each stage of the AI lifecycle must incorporate risk mapping, active defense mechanisms, and incident response plans. The study also highlights shortcomings in board oversight: – 53% of boards acknowledge dedicating insufficient time to cybersecurity. – 38% report receiving less information than necessary. – Only 13% believe the CISO will play a more prominent role in meetings this year.
This lack of maturity in oversight increases the risk of insecure implementations, absence of monitoring, and greater exposure to advanced attacks.
Cybersecurity experts agree that AI is neither inherently secure nor responsible without robust design. To address this gap, they propose five essential technical recommendations:
1) Security by design: incorporate security controls from the initial model architecture through to implementation.
2) Clear technical governance: define specific responsibilities within technology and security teams.
3) AI-specific controls: apply authentication, monitoring, and response mechanisms tailored to model behavior.
4) Continuous data validation: ensure data quality, legality, and traceability.
5) Adversarial scenario simulation: conduct regular stress tests and cyberattack drills.
This is emphasized by Gustavo Díaz, Financial Services Partner at EY Colombia and Cybersecurity Leader for EY Latin America’s financial sector:
“Without trust, there is no sustainable innovation. Artificial intelligence has the power to transform industries—but only if built on a foundation of robust security. It is not just about protecting data, but preserving consumer trust, business continuity, and the integrity of the digital ecosystem. In an environment where every technological advance can be an opportunity or a latent threat, cybersecurity cannot be an afterthought; it must be the starting point.”

