Dariel urges businesses to evolve security policies for the AI era
Written by: Wayne Yan Save to Instapaper
Dariel urges organisations to evolve existing security and governance frameworks rather than treating AI as an entirely new challenge.
According to Wayne Yan, responsible AI adoption requires disciplined governance, controlled permissions and strong accountability to protect trust and reduce risk.
The future of AI adoption lies in disciplined execution, governance, and responsible implementation rather than unchecked experimentation
AI Adoption And The Growing Importance Of Governance
As enterprises accelerate the adoption of Artificial Intelligence (AI) and agentic systems, the conversation around data protection is becoming more urgent.
Yet according to Dariel CTO Wayne Yan, organisations should resist the temptation to treat AI as an entirely new governance problem.
Instead, businesses should evolve and extend the same information security principles they already rely on today.
“Fundamentally, data loss prevention protocols are essential rules designed to ensure that sensitive data either has authority or not to traverse organisational boundaries,” says Yan.
“Those boundaries may be defined by geography, networks, systems, or even departments within the organisation. The type of rules embodied in data security policy are really not different for AI-oriented solutions. These are essentially the same policies one would apply under any integration-driven solution.”
Yan explains that while AI introduces new layers of complexity, the underlying governance challenge remains familiar.
Enterprises already manage ecosystems of partners, SaaS providers, cloud platforms, and integrations. AI solutions simply extend those ecosystems further.
Understanding The AI Stack
To govern AI responsibly, organisations first need to understand the building blocks of modern agentic systems.
According to Yan, these typically include:
A large language model (LLM), which may be proprietary, open-weight, or self-hosted.
Training data used to build the model, often a combination of public and private information.
Context layers that provide domain-specific enterprise knowledge.
Context-bound rules that shape how answers are generated.
APIs and integrations that allow agents to perform business actions.
“The real governance question is how private domain data traverses’ enterprise boundaries,” Yan explains.
“For example, if the LLM is hosted in a foreign jurisdiction, should it receive context that is not legally allowed to leave a legislated boundary?”
He notes that businesses do have options, including self-hosting models or limiting how external hosted services are used.
But these decisions require careful governance, particularly when organisations operate in regulated industries or across multiple jurisdictions.
“This is not unlike the governance models businesses already apply to traditional cloud or SaaS solutions,” he says.
“The responsibility of the CIO remains the same: understand your legislative requirements, define your information boundaries, and manage integration parties responsibly.”
The Trust Dilemma In AI Decision Making
While data governance remains critical, Yan believes the larger unresolved issue lies in the trustworthiness of AI-driven decision making.
“The pressing question organisations need to answer is: to what extent can they trust the decision-making capability of AI?” he says.
Unlike traditional software systems, large language models are probabilistic rather than deterministic.
This means outputs may appear plausible and convincing without necessarily being factually correct.
“Correctness is not guaranteed,” Yan explains.
“Semantic plausibility is not equivalent to factual accuracy. An answer can look right while still being wrong.”
He points to scenarios where AI agents may guide customers toward financial products, insurance policies, or automated onboarding processes.
In these environments, questions around accountability quickly emerge.
“If an AI-driven broker agent provides advice that is not in the customer’s best interests, who becomes liable?” Yan asks.
“Is it the LLM provider, the developer who assembled the solution, or the organisation that provided the contextual data? Businesses need to understand that these risks extend far beyond traditional data loss prevention concerns.”
Responsible AI Implementation
According to Yan, organisations should avoid rewriting their information security policies entirely.
Instead, they should evolve and augment existing frameworks to accommodate AI-enabled systems.
“The common problem is that information wants to be set free,” he says.
“The common solution is that effort must be applied to implement information security that confines information for permissible and lawful use. This pattern transcends technology.”
He adds that agentic systems should operate under tightly governed permissions, much like human users within enterprise environments.
“Agents designed for specific intentions should only be allowed to execute actions aligned with their mandated intent,” Yan says.
“The endpoints within the private domain must still be guarded no differently than before.”
The Future Of Responsible AI Adoption
For Dariel, the future of AI adoption lies in disciplined execution, governance, and responsible implementation rather than unchecked experimentation.
“Innovation without governance creates risk,” Yan concludes.
“Businesses absolutely should adopt AI technologies, but they need to tread responsibly. The customer trust relationship must never be jeopardised in pursuit of automation or convenience.”
Ends.
About Dariel
Founded in 2001 on the principle of delivering solutions right, the first time, Dariel bridges the gap between human ingenuity and technology.
Our strong client partnerships reflect a commitment to excellence and our consultative approach to software engineering makes us a trusted partner for innovative and sustainable tech solutions.
Proudly independent, Dariel is part of the JSE-listed Capital Appreciation Group.
For More Information
Samantha Hogg-Brandjes | GinjaNinja | This email address is being protected from spambots. You need JavaScript enabled to view it. | +27-84-458-4857
Get new press articles by email
GinjaNinja is an owner run and managed PR, integrated marketing, and communications agency. The company has evolved over 21 years to offer public relations experience across several industry sectors together with key digital and marketing services. What we value in our clients is what we value in ourselves. GinjaNinja has integrity, is hard working, dedicated, passionate, ethical, creative,... Read More
Latest from
- Why certified security infrastructure is becoming essential in South Africa’s mining sector
- The shift from upgrades to control and why it matters to CFOs
- SoftwareOne reports strong momentum with growth across all regions
- Routed recognised in Financial Times and Statista growth rankings as evoila Africa transition gains momentum
- What South Africa’s real estate agents must do now to stay compliant
- What the Masemola scandal teaches us about procurement risk
- The AI talent gap - Why South Africa must act now to save its next generation of developers
- Trellidor launches heavy-duty Steel Roller Shutter for demanding commercial environments
- Cyberlogic places focus on developing more female CEOs
- SoftwareOne Named Customers’ Choice In Gartner Peer Insights Voice Of The Customer For SAM Services
- Customer experience moves to the centre of business strategy
- Property Transactions Beyond Borders - Why Accurate Data Reduces Expat Risk and Investment Uncertainty
- Cloud security gaps persist as adoption accelerates, warns industry expert
- Cloud adoption is accelerating – but so are hidden security risks, warns Dariel
- Trellidor appoints new CEO, Damian Judge
The Pulse Latest Articles
- South African Women Are Missing This Essential Nutrient (May 20, 2026)
- Opinion Piece: Rethinking Performance: Why Behaviour Remains The Missing Link In Evaluation (May 20, 2026)
- 125 Years Of Hansgrohe And The Designers Who Made Axor A Luxury Language (May 19, 2026)
- World Whisky Day: Whisky Lovers Challenged To Stop Saving Their Best Bottles (May 15, 2026)
- Hidden Inefficiencies Are Draining South African Businesses (May 15, 2026)
