LIVE · HOW WOULD YOU LIKE TO CONSUME THIS PAGE?
Close
Privacy settings
We use cookies and similar technologies that are necessary to run the website. Additional cookies are only used with your consent. You can consent to our use of cookies by clicking on Agree. For more information on which data is collected and how it is shared with our partners please read our privacy and cookie policy: Cookie policy, Privacy policy
We use cookies to access, analyse and store information such as the characteristics of your device as well as certain personal data (IP addresses, navigation usage, geolocation data or unique identifiers). The processing of your data serves various purposes: Analytics cookies allow us to analyse our performance to offer you a better online experience and evaluate the efficiency of our campaigns. Personalisation cookies give you access to a customised experience of our website with usage-based offers and support. Finally, Advertising cookies are placed by third-party companies processing your data to create audiences lists to deliver targeted ads on social media and the internet. You may freely give, refuse or withdraw your consent at any time using the link provided at the bottom of each page.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Episode
6
/
27
Min

The Enterprise AI Accountability Moment

Join Shayne Higdon, Wallarm CEO, for this episode, which closes the series by examining what the accountability moment demands from enterprise leaders, what a mature AI governance model needs to prove rather than promise, and what the next 12 to 24 months look like for organizations that get this right.
Listen On
ABout This Episode

Join Shayne Higdon, Wallarm CEO, for this episode, which closes the series by examining what the accountability moment demands from enterprise leaders, what a mature AI governance model needs to prove rather than promise, and what the next 12 to 24 months look like for organizations that get this right.

AI deployment is not waiting for governance to catch up. Across most enterprises, the gap between how fast AI is being adopted and how well it is being governed is widening every quarter. CIOs and CISOs are not debating whether to govern AI. They are trying to figure out how, under real organizational pressure, with tools and frameworks that were built for a different threat model.

That pressure is coming from every direction at once. Boards want AI transformation to move fast. Regulators want documented evidence that it is under control. Security teams want runtime visibility and enforcement capabilities that most of their current tools do not provide. And the AI systems themselves are not waiting: they are accessing data, calling external services, and making decisions continuously, in ways that after-the-fact governance cannot meaningfully constrain.

This is the accountability moment. Not because the risk is new, but because the consequences of undermanaged AI are now concrete enough to land on a board agenda, an audit report, and a regulatory deadline at the same time. What accountability actually requires in practice is the full AI control loop: knowing what AI is running across the enterprise, seeing what it is doing at runtime, enforcing policy before damage compounds, and generating continuous evidence that the governance is real and not retroactive. Organizations that can demonstrate all four are in a fundamentally different position than those still assembling audit evidence from spreadsheets the week before a review.

  • Why is now the accountability moment for enterprise AI?
  • What has changed between the early days of AI experimentation and today's enterprise AI deployments that makes accountability such a pressing issue?
  • When we talk about AI accountability, what does that actually mean in practical terms? Are we talking about visibility, auditability, enforcement, ownership—or all of the above?
  • As organizations race to deploy AI, how should CIOs balance the speed of transformation with the responsibility to govern it effectively?
  • Why are traditional governance and security models struggling to keep pace with the way AI is being adopted across the enterprise?
  • Given those challenges, how should boards and executive teams evaluate whether their organizations are truly ready to scale AI safely and responsibly?
  • And once an organization believes it's ready, what does a mature AI governance model actually need to prove—not just promise?
  • From an operational standpoint, how do capabilities like discovery, runtime monitoring, and enforcement come together to create a closed-loop approach to AI accountability?
  • Stepping back and looking across this entire conversation, what's the one mindset shift every enterprise leader needs to make when it comes to AI security and accountability?
  • And finally, as listeners think about what's ahead, what should they expect the future of AI security and accountability to look like over the next 6, 12, or even 24 months?

Noah Labhart: [00:00:00] Hello listeners. Today we are dropping the final episode in our series entitled The AI Control Loop: How Enterprises Govern the AI They've Already Deployed, sponsored by our friends at Wallarm. Wallarm is the AI control platform for enterprise AI, protecting every AI workload, API, and application in production, giving CISOs the governance they need and CIOs the speed they demand.

Organizations choose Wallarm for a complete inventory of APIs, AI agents, and AI apps using patented AI ML-based threat detection and blocking that operates at production speeds. In our final episode, we are joined by Shayne Higdon, Wallarm's CEO, who closes the series by examining what the accountability moment demands from enterprise leaders, what a mature AI governance model needs to prove rather than promise, and what the next 12 to 24 months look like for organizations that get this right [00:01:00]

Shayne, thanks for being on the show today.

Thank you for being on Code Story.

Shayne Higdon: Thanks a lot, Noah. I really appreciate you having me. I'm looking forward to it.

Noah Labhart: Absolutely. Me as well. Really excited to dive into our topic for today, which we'll get in just a second. But before we do, tell me and my audience a little bit about you.

Shayne Higdon: Yeah. So I'd been in enterprise software for about 25, 26 years.

I started my career as a pre-sales consultant many years ago at a company called BMC Software. Largely grew up at Quest Software, where I did a lot of different things there: ran mergers and acquisitions, created a corporate venture arm, ran a couple of business units in the application performance management space, the desktop management space, and then went back to BMC.

Between there, I ultimately ran an identity and access management company that we sold to RSA, and then I went back to BMC Software, where I was president of the [00:02:00] division focused on performance and analytics, and then left after the exit to KKR, and have just played around in the market, leveraging new technologies, looking at new technologies like blockchain and other things, and then found myself here trying to help out Walmart.

Noah Labhart: Fantastic. Sounds like you've had a- an epic career and done some amazing things. Sounds like it's been an interesting path you've walked. Let's dive into the meat of it today then. So our title for the episode today is The Enterprise AI

Accountability Moment. Before we go too far, why is now the accountability moment for enterprise AI?

Shayne Higdon: AI really stopped being a side project. I think as individuals leveraging things like ChatGPT or Grok or other models that were assistive in nature, it was a neat thing. However, about 18 months ago, most of what I saw inside the enterprise was a chatbot [00:03:00] bolted on to a support queue trying to do things, something a few power users might have played with on their own laptops.

But now you've got so many organizations that are allowing it to touch production data. They're calling APIs, they're making calls that affect a customer before a human can ever take a look at it, and this whole idea of human in the loop is still important. But when I talk to CISOs now, the question has changed.

It used to be, "Are you using AI?" Now it's, "What did your AI do last week?" Or, "And can you prove it?" More importantly. That shift really has less to do with, I think, the underlying risk- being new and more to do with the exposure getting concrete enough to really be focusing at a board level. What are we doing?

How are we making sure that w- our agents, the way we're [00:04:00] deploying AI is not giving hackers keys to the kingdom? Are we aligned with regulatory deadlines and requirements? I think that's the accountability moment, and it's less a slogan today and really more of a problem To get our arms around, right? The, these three different audiences are asking the same question.

It's the management team, the board, and customers at the same time. Companies wanna make sure that if I'm going to do business with you and you're leveraging AI, that you're protecting the assets of the company, which as a customer includes my data. As a board, it includes the company's data. You've gotta do the right thing to be accountable, to have transparency, and to be auditable.

Noah Labhart: I really like how you put that, especially the part where you said AI is no longer a side project. It's become a foundational element that is expected. But what, what has changed between the early days of AI experimentation, right? Maybe that's the side project era, and today's enterprise [00:05:00] AI deployments that makes accountability such a pressing issue right now?

Shayne Higdon: Like I said, w- when early on it was just you and I leveraging ChatGPT, it was really individualistic. It might have been assistive. It was, I stopped going to Google to do a search. Instead, I would choose one of these interfaces to be able to ask a question. Someone may h- have had a ChatGPT tab open or something like Microsoft Copilot helping them write code.

If that person left the company, the whole habit o- of how a particular thing was getting written left with them. It's that, what many call tribal knowledge. It was contained by default, right? It was in, if you were writing code, it was in a repository. It was, you had a backup for, from a developer perspective so someone could take over.

I think what's different now, though, is that AI is starting to b- be wired into the systems, and they're rethinking [00:06:00] the workflows. How can I take a workflow, and first of all, can I make it agentic? But then there's just completely different workflows that simply weren't possible because of machine speed where humans couldn't have done them in the past, right?

So now an agent has access and context, and in a growing number of cases, it can act on its own. A- honestly, it can call an API, it can trigger an integration without anyone signing off on it. I think that's-- it's connected to customer data, internal systems that the risk, the profile a- and risk associated to it just gets bigger.

We call it in cybersecurity, if something goes wrong, the blast radius. It just turns into a different problem entirely, and I put it this way. The shift is from AI helping someone to do their job- To AI actually being one of the things doing the job, right? And it's what we're [00:07:00] calling agentic operators. So how can a company, whether you're a vendor like Walarm, or whether you're a retail company, or whether you're a manufacturing company, how do you leverage the proprietary things that you do and create agentic operators on top of that to help automate and make your workflows and make your business much more optimal and efficient?

Noah Labhart: That makes so much sense the way that you put that, and the agents are essentially going and doing the work of a person, and you would hold that person accountable to do those actions. But now we need to be able to hold AI accountable. And when we talk about AI accountability, what does that actually mean in practical terms, right?

So we've... And you touched, I think you kind of touched around or danced around this a bit, but when we're talking about Are we talking about visibility, auditability, enforcement, ownership, or, or all the things?

Shayne Higdon: It's really all of it, right? So I personally try to [00:08:00] resist the temptation to just pick one because I think most vendors, you know, Wallarm included, if we're not careful, we're gonna just pitch whatever piece we're the strongest at, right, many times.

So it starts with knowing, I think, what AI exists in your company. So can you do an inventory of where are things running and who own them? You'd be surprised at how often the first question doesn't really have a clear answer, right? From where you need to know what it can touch and reach to what it's actually doing at runtime, not just what it was designed to do, right?

So auditability really, really matters, but evidence you assemble after something has already happened, it's a record, right? I wanna record what happened, but it does not allow you to control what's going to happen, right? So the piece that I think people underestimate is the enforcement, the ability to stop something before the risk turns into a real incident, not just write it up afterwards, right?

So when I think [00:09:00] about a lot of our customers for Wallarm, we've been inline enforcement of transactions for, I don't know, 12, 15 years. Many of our customers like to hear that, "Hey, if something goes wrong, you can block, you can enforce, you can do something." And in that scenario, that's great to hear, but many of our customers are also afraid that if I do block something, if I do stop something, I'm going to break the application or the workflow, and I don't wanna do that because maybe it's a part of my supply chain.

In a world where agents are actually doing something and agents may not be able to reason their way out of a problem, we think, I think that there is going to be a real interest in being able to enforce, to block in real time agents of particular non-human identities, right? Where agent goes rogue, no questions asked, we just shut it down.

We block it in real time. I [00:10:00] think we're going to see that more and more than we have in the past.

Noah Labhart: Yeah, certainly. I think that's gonna have to be a re- a requirement, and it just... it's clicking with where things are going. As organizations race to deploy AI, 'cause as we talked about, it's not a side project anymore.

It's the real deal. It's foundational. How should CIOs balance the speed of transformation with the responsibility to govern it effectively? And this is the age-old question of how fast do you move and break stuff versus how much do you provide the right governance and, and boundaries in the right places?

Shayne Higdon: I don't think speed and governance are actually opposed to one another. I do CrossFit, and in that, I've had my coach tell me before, "Slow is smooth is fast." And it's a similar concept right here that I think a false choice that gets repeated a lot, good governance is what lets AI scale really past the pilot stage [00:11:00] without someone in security or legal, for that matter, hitting the brakes and saying, "Six months in, stop.

You're done." And I've seen that happen, right? A team ships fast, gets traction, and then runs to a str- security review or a compliance question that nobody thought about at the start, right? And the whole thing stalls when it ac- should actually be accelerating. So I think good governance up front, the organizations that actually move the fastest over, I don't know, I'd say a couple of year time horizon, are the ones that actually build a trusted, controlled path for AI adoption so that they're not re-litigating and trying to help convince everyone to trust every time they want to expand the footprint of AI in the enterprise.

So I think the CIO's job in this new world, and this is-- many see this as an extension of AI tran- or of digital transformation, AI being a part of that. The CIO's job, I don't think, is to slow down to make [00:12:00] it safe. It's to make it safe enough so that speed doesn't really hurt it, doesn't really matter, right?

And I think that's what's really important, this idea of slow is smooth is fast. And so if they-- if you do the right diligence up front to really document and have a pretty good understanding as to what you're doing, how you're going to be compliant, how you're gonna audit, who's gonna touch what, then you can ig- begin to accelerate.

You've got the proper security measures in place so that by the time the application, the agents are in production, the models that you're using, you're pretty confident that you've provided the necessary guardrails to be safe.

Noah Labhart: Certainly, and I really like the line you said there from CrossFit. I think that illustrates the way to go forward here, and where compliance and governance and innovation and speed shouldn't be mutually exclusive.

But why are traditional governance and security models struggling to keep pace [00:13:00] with the way that AI is being adopted across the enterprise?

Shayne Higdon: They were just simply built for a slower, more predictable world. When I think about machine speed and when an attack occurs, you've got seconds before things are beginning to, to be exfiltrated.

I think most governance today still runs on these kind of static inventories of systems and data at a quarterly a- access review with who had access to what, and what's the attestation? I think someone on the compliance team reading through logs after the fact is just simply, it's antiquated. It's just simply too slow, and I think the model assumes the thing that you're governing doesn't change much between reviews, right?

But that's not the case anymore, right? AI doesn't hold still. It doesn't stop. It doesn't wait for things to happen, right? It can call a different application. It can call a different API tomorrow than it did yesterday, so the patterns are not the same. You [00:14:00] can't govern something, I think, that operates continuously at machine speed with a process that simply checks things once a quarter.

It's just not gonna happen. There's a real mismatch and a tools gap when you try to do that, and so static governance was really never built for a system that doesn't wait for you to look at it, right? And I think that's, that's important. So you're going to have, it's an always-on approach to the governance model and then being able to flag things that are outside the bounds of normal.

Noah Labhart: Right on. No, that's totally clear. It was, it's not what it was built for. And given those challenges, how should boards and executive teams evaluate whether their organizations are truly ready to scale AI safely and responsibly?

Shayne Higdon: I think they should really start with, "Can you tell me what AI is running across the company right now?"

And who owns it? It's a simple question, but today it's hard in many ways to figure that out. I've had CEOs tell me, "I've got a AI first agenda, and I told the company that we're gonna [00:15:00] be AI first," and I've let people from various departments go roll your own model, your own agen-agentic operators. And I think that's been, in some cases, a mess because you lose sight of who's doing what, right?

And so if that takes three weeks or six people to assemble, I think that's your answer right there, is that it's fairly difficult. The harder follow-up, I think, is what data it can touch, what systems it can reach, and then whether or not you can detect and stop that risky behavior. The other thing that we're seeing is that how do you-- when you start moving towards an AI first approach, how do you look at token spend?

How do you allocate token spend to various departments? You're gonna get one bill from Anthropic, or you're gonna get a bunch of different bills, right? You may get a, an AWS bill using Bedrock, which has all the frontier models. And at some level, as the CFO, you're [00:16:00] seeing these bills that you're having to pay for in tokens, but how are you then breaking that down and understanding that Noah, who's developing an application, is spending this amount of tokens on a monthly basis to write that, and how productive is he?

Shayne's in the sales organization, and he's spending to write an agent or a skill to do a bunch of things to prep for various sales calls. And so getting your arms around that, I think is more difficult. And so I think the real board level question is pretty simple, right? Even if the answer usually isn't, can you prove your AI is operating inside the boundaries you intended right now, but it can't be last quarter's audit is the way to look at it.

So how do you have this real time dashboard that at any moment, if as a CEO you're asked that you can generate a point in time, a just-in-time inventory for all things AI across your enterprise. It's gonna be hard to get there. [00:17:00] It's gonna take a lot of planning up front, but I think that is the next step that a lot of boards are going to expect.

Noah Labhart: Good stuff. Okay, you said something there that, that piqued my interest. I wanna dive into a little bit more about what does an enterprise need to prove, right? You said it, prove that it can run within the boundaries. What does a mature AI governance model actually need to prove i-in doing that, not just promise?

Shayne Higdon: Yeah. So it needs to show that it's actually working continuously, just not producing a good story once a year. "Hey, we've adopted AI. This is what we've done." It needs to specifically and concretely show that AI assets across the company are being discovered on an ongoing basis, not just inventoried once and then thrown away or forgotten, that each one has an owner.

I believe that we're gonna see more and more organizations having an agentic manager, right? A person that is going to manage, and I don't know what the ratio is, one person [00:18:00] to 50 agents or 80 agents or 100. I don't know what that percentage is going to be. But I think we're gonna see that more and more because it needs to show that those systems, what they did, what policies were applied.

It needs to create a, a clean record of where something violated that policy, and then what did the organization do about it, right? So I think that's the real dividing line is whether that evidence gets generated as a byproduct of a system running or whether someone has to go build it from scratch the week before an audit.

Yeah, honestly, I've seen both and, and you can tell within the first five minutes of a meeting which one the company's doing. So I think that's the real test of maturity for organizations, a running record of control that exists or, or not, right? And then if anyone asks for it that week, not a policy statement somebody wrote down just once and said, "Hey, this is what we do," but actually proving, showing the report, the [00:19:00] evidence.

Like I said, I call it just-in-time inventory, almost like just-in-time Supply chain. We're gonna have to do the same thing because if you allow your organization the freedom to decide what they want to use for whatever their business case, their workflow, their function, then you're going to have to give them...

You're gonna have to have some way of casting a wide net to always be understanding. We call it shadow AI. So as companies are leveraging this, a developer going directly to an external model that's sharing a GitHub repo, you probably don't want that to happen. How do you stop it and make sure that doesn't occur?

Noah Labhart: Good stuff. I love that you said from, uh, from five minutes into the meeting, you can really see the folks that are actually accomplishing this sort of thing and holding their AI accountability, and that's, that's, that's evidence that operationally, you know, they can, they [00:20:00] can support this in real time.

From that operational standpoint, how do these capabilities like discovery, runtime monitoring, enforcement, et cetera, come together to create that closed loop approach for AI accountability?

Shayne Higdon: You have to think of it as a, I think, a couple of questions, at one of which I just talked about getting continuous answers, not just once.

Discovery is cons- consider it that map, right? What AI exists, where it's running, on what infrastructure, what's it connected to? That gives you that visibility that you may or may not have had. Then runtime monitoring is gonna tell you what it's actually doing on- once it's in motion, I think, which is often not the same thing as what it was designed to do.

Enforcement, though, is what really closes the loop. If you discovered something, you're monitoring it in runtime, at what point do you decide that you need to enforce a policy, which is the ability to actually stop something before the consequence compounds? [00:21:00] And that's where I was talking about earlier, I think that's gonna be really important with non-human identities.

You're going to see an agent do something or go rogue or make a decision based on its context that you may not want it to make, and you're gonna want to enforce a policy. You're gonna wanna shut it down right now so that the blast radius is small, and then you gonna want a record of all of that, right?

Now you're back to governance as documentation

Noah Labhart: Right on. Okay, so stepping back and looking across our entire conversation, which has real- been really illuminating on how to hold AI accountable and what businesses need to actually do, what's the one mindset shift every enterprise leader needs to make?

When it comes to AI security and accountability, what mindset shift do they need to make?

Shayne Higdon: It's a good question. I think a, an operating environment, it's... AI is that operating environment now. It's not a single component that you ultimately just have a litmus test to say, "I've got AI [00:22:00] now. I've got models, or I've got APIs, or I've got identities, data, agents, workloads."

So I think companies have to stop treating this as, "Oh, do I have the best model? It's a model problem that I've got," or, "I've got a prompt problem." I think the real challenge is governing what the whole connected system does, right? When is it actually allowed to act on its own, not protecting each of the pieces separately, right?

You deploy an MCP server to connect to external services. When I... Look, I'll admit, I think this is the harder version of the problem, when most tooling was still built around the easier component level one systems. Pulling it all together I think is gonna be really important, because I don't think AI security is about locking down a model.

It's about governing behavior across a system, and a complex system at, at that, that doesn't respect the expectations that we have drawn for the [00:23:00] organization, right? The AI agents oftentimes have... I- if you've given them a lot of context, they have a boundless way of being able to act. And so how do you bound them without limiting their ability to be productive and efficient?

Noah Labhart: Awesome. I appreciate you, you walking through all that. And I got one more question, Shayne. So as listeners think about what's ahead, where the industry is going, and how fast it's moving, what should they expect the future of AI security, and per our topic, accountability, to look like over the next six, 12, or even 24 months?

Shayne Higdon: I think we're seeing now, and I, I'm not really good at predictions, but I think a few months... We're seeing it now, but I think we're gonna continue to see most companies move from this enthusiastic, "I'm using AI," and to check a box, to actual control requirements. They're going to need to make sure that they are boxing in- And guardrailing exactly how they're using AI because I think boards [00:24:00] and regulators are gonna keep asking questions, and CEOs are gonna say and CIOs are gonna say, "We have a policy."

I just think that's not gonna be enough. I think a year from now, maybe less, I think runtime visibility and enforcement is simply gonna be table stakes, right? And we're seeing this in many ways already, where for any AI program, the pilot stage is over. It's not something a security team is gonna ask for later, right?

The timeline itself I think gets less interesting than really how it's shaped. I think the gap widens between companies producing continuous evidence of how their AI is governed and companies still assembling their evidence by hand before review, right? I don't think it closes gradually. I think it's, I think it's gonna feel like, to vendors like us, it's gonna feel like a big bang.

It's gonna show up all at once, usually the first time one of the companies has an incident and the other doesn't, or has one and has an incident and can explain exactly what happened [00:25:00] within the hour. I think that's gonna be the expectation, the expectation by partners, customers as that happens. So what actually changes over the stretch is proof, real-time control with evidence attached to it, not a better written policy sitting in some shared drive somewhere inside the enterprise, and I think that's gonna be the testament to organizations that are governing AI and those that are not, or those that are just earlier on their journey and are less mature.

Noah Labhart: I think that's spot on. I couldn't agree more, Shayne. I really appreciate you being on the show today. It's very clear, as you said in the beginning, which I really liked, AI is no longer a side project. Agents are doing the work of people, and as such, they need to be held accountable. Enterprises need to understand where and how AI is being used in their organization.

And without the just-in-time AI capabilities like you referenced, businesses won't be able to achieve AI accountability. Enterprises need to change the way they think, change their mindset, and understand the whole connected [00:26:00] system, understanding when the system is allowed to function on its own and when it needs to be restricted.

As you said as we talked, it's a hard problem to solve, but the time is now to start addressing it. So really appreciate you being on the show, Shayne. It was a great conversation.

Shayne Higdon: Likewise, Noah. Thank you for the questions. Really appreciate it and look forward to being here again soon.

Noah Labhart: As evident from Shayne's answers, the time is now for enterprises to address AI accountability.

Without it, they'll be behind the curve in terms of security and proof to customers, investors, and the market at large. We hope you've enjoyed our series, The AI Control Loop, sponsored by our friends at Wallarm

If you'd like to learn more about the company, you can visit wallarm.com. That's W-A-L-L-A-R-M.com. And thanks again for listening.

Trusted By

The world's most demanding teams run on Wallarm.

See Wallarm in action.

Discover, protect, test, and govern the APIs and AI agents across your environment — in real time.