“Our IT team’s approach is to be judicious about which capabilities we put into employees’ hands and to slow deployment when we don’t understand the risk well enough,” he says. “We’re also applying established security principles to make sure agents don’t have greater access to capabilities than they actually need. The technology may be new, but some of the most important controls are still familiar ones.”

Anant Adya, EVP and head of Americas delivery at Infosys, says he’s spending more time managing AI risks now than a year ago, a natural shift, he adds, given the company’s move from experimentation to enterprise-scale adoption.

“While it does require additional attention, it is becoming embedded into our operating model rather than simply adding hours to the day,” he says of Infosys’ added emphasis on governance, security, privacy, compliance, and responsible AI practices.