Why your CISO should be an AI strategy enabler, not the office of no

In many institutions, the CISO has been cast as the person slowing AI adoption down. That’s not how we see it at Cloudforce. 

Security leaders are not blocking AI because they are opposed to innovation. They are responding to a real governance problem: AI tools are being adopted faster than institutions can evaluate data flows, access controls, retention policies, model behavior, and compliance exposure. Faculty, staff, students, and researchers want the benefits of AI now. Security leaders need to make that possible without creating risk the institution cannot see or manage. 

 That makes the CISO a central partner in the institution’s AI strategy. 

A productive AI strategy starts by bringing AI under controls the institution already understands: identity, role-based access, auditability, data governance, and secure architecture. The question is not whether AI can be used. The question is where it runs, what data it can reach, who can use which capabilities, and how the institution can monitor and govern the environment over time. 

Start with the controls the institution already has 

Architecture determines whether an institution can extend its existing controls to AI. A governed AI platform deployed in the institution’s Microsoft cloud environment can connect AI use to the identity, access, and data-governance practices security teams already manage. 

This allows AI adoption to work within existing Microsoft identity, access, and governance patterns. It reduces the need to evaluate a new data silo for every department-level AI experiment. And it gives IT and security leaders a more consistent way to support innovation without losing institutional control. 

The CISO’s role should not be to say no to AI. It should be to define the conditions for responsible use of AI at scale. 

For higher education, those conditions are specific:  

  • Student data governed by FERPA 
  • Research data governed by IRB agreements and data use agreements 
  • Operational data that may include sensitive employee or financial information  
  • Academic use cases that need clarity rather than ambiguity.  

 A policy can state the rules. An operating model puts them into practice through approved tools, access controls, clear ownership, and ongoing review. 

When security leaders help establish that operating model, they can support a campus-wide AI mandate while protecting the trust of students, faculty, researchers, staff, and institutional partners. 

Give departments room to use AI within clear guardrails 

A strong AI strategy does not require every department to work the same way. Research computing, teaching and learning, advising, HR, finance, and student services have different needs. They do need a shared approach to identity, data access, approved models, auditability, and cost management. 

That balance gives departments room to develop useful AI workflows while the institution maintains responsibility for the controls that apply across campus. It also gives the CISO, CIO, academic leaders, and data-governance stakeholders a common basis for decisions about risk, access, and accountability. 

What this looks like with nebulaONE 

nebulaONE® grew out of conversations with institutions trying to make AI broadly available without losing control. CISOs needed to support faculty, staff, students, and researchers while protecting institutional data, intellectual property, and campus trust. 

Built on Azure AI Foundry, nebulaONE gives institutions centralized controls for access, data, and approved models. ONEchat and no-code AI Agents give people practical ways to use AI, while IT and security teams retain visibility and control. 

Brian Dreyer
Author

Brian Dreyer is Senior Director of Product Management at Cloudforce, where he leads with a deep commitment to human-centered design and technology-driven innovation. A seasoned product leader, Brian brings a unique blend of product management and product marketing expertise, enabling him to translate complex customer challenges into both compelling products and clear, differentiated market positioning. Brian’s diverse skill set bridges product management, product marketing, and user experience. He has led go-to-market strategies, overseen major software redesigns, and worked hands-on in user research while collaborating closely with UX design teams. This multidisciplinary approach allows him to consistently deliver user-centric products that drive customer value, accelerate adoption, and fuel long-term growth.

Recommended for you.