Many security leaders have seen this before: a technology begins delivering visible value and teams’ attention shifts to adoption, efficiency and scale. After all, once review processes are completed and systems begin producing results, most organizations assume the difficult work has already been done. In time, trust quietly becomes less of an active question and more of an assumption. In fact, though, if nothing breaks, trust becomes harder to measure, argues Dr. Pongpisit Wuttidittachotti, CISSP, SSCP, CCSP, CGRC, CSSLP, HCISPP, CC.
Disclaimer: The views and opinions expressed in this article belong solely to the author and do not necessarily reflect those of ISC2.
Through conversations with security leaders and cybersecurity professionals across different organizations, I began to notice a pattern that surprised me. Naturally, most of us including me, focused initially on governance. Like many security leaders, I was focused on approval processes, risk reviews and oversight mechanisms for responsible AI adoption. That approach felt reasonable: governance has always played an important role in reducing uncertainty whenever organizations introduce new technologies into operational environments.
And, at first, everything seemed to work exactly as expected and early deployments often looked encouraging: AI deployments improved efficiency, reduced repetitive work and helped teams move faster. Across several AI adoption initiatives that I was involved in, analysts received concise summaries, workflows became smoother and teams gradually incorporated AI outputs into daily operations. Once systems passed governance reviews and received approval, confidence naturally followed, because there is visible evidence that the process appeared to be working.
Over time, of course, the environment changed. New integrations were introduced, threat activity evolves and supporting systems received updates. None of this felt unusual; we are used to it, because environments constantly evolve. Dashboards still functioned, alerts continued arriving and recommendations continued to appear as expected. Everything still appeared normal – as they often do, which is why these changes can be difficult to recognize.
The Introduction of AI Inconsistencies
Across multiple conversations with SOC practitioners and security leaders, I started to notice something unexpected. Over time, experienced analysts began to identify small inconsistencies that were difficult to describe precisely. Certain outputs felt less useful than before, recommendations became harder to explain and alert prioritization occasionally felt slightly different from what teams had come to expect. None of these changes necessarily signaled obvious failure, which is precisely what made them difficult to recognize.
Individually, none of the changes appeared particularly serious, which is why they were often easy to dismiss. Over time, however, those small inconsistencies started to add up. What initially felt minor gradually created a level of uncertainty that became much harder to recognize and measure.
This is where AI behaves differently from many traditional technologies. Conventional failures usually create recognizable signals that trigger investigation and response activities. AI-related changes can be quieter and far less obvious, even while confidence gradually shifts underneath otherwise normal operations.
Repositioning AI Trust
Over a relatively short period of time, I changed how I thought about AI trust and reconsidered how trust works in operational environments. I still believe governance remains essential because organizations need clear accountability, oversight and a structured way to introduce AI responsibly. But, in practice, governance often only answers the first question: should AI be deployed at all? By itself, answering this question does not continuously validate whether AI remains trustworthy after deployment.
I found myself asking uncomfortable questions. Could teams still validate outputs months later? Could investigators explain why a system had reached a particular recommendation? Could we justify trust when environments had changed?
So, I realized I had been treating governance and assurance as if they solved the same problem. They do not: governance helps answer whether AI should be introduced; assurance matters later, when teams need visibility into whether trust still holds up in real operations.
That same realization also changed how I now think about trust in AI. In many security programs, approval activities create a sense of closure. But AI requires a different mindset, because deployment may simply mark the point where trust becomes more difficult to observe and explain.
Final Thoughts
I still believe organizations need strong AI governance; policies, accountability structures and oversight mechanisms remain essential foundations for responsible adoption. However, the more I observe AI becoming embedded within operational environments, the more I believe governance answers only the first question. The harder challenge begins after deployment, when organizations must determine whether they can still explain, validate and justify why AI-generated decisions continue to deserve trust over time.
Looking back, I used to think trust came from approval. Now I see approval differently. It simply marks the point where the harder work begins.
Dr. Pongpisit Wuttidittachotti, CISSP, SSCP, CCSP, CGRC, CSSLP, HCISPP, CC, has more than 25 years of experience spanning government, academia, healthcare and the technology industry. He has held executive, advisory and academic leadership roles in cybersecurity, governance, risk management, privacy and digital trust. His work focuses on strengthening digital trust, advancing secure AI adoption and developing cybersecurity capabilities across academia, industry and government.
Related Insights
- AI Month: Research, Resources and Insights
- For You, By You: Join Us and Build ISC2's AI Security Certification
- AI Workshops at ISC2 Security Congress 2026
