
According to George Reed from 6clicks, AI is fundamentally transforming GRC by enabling platforms to understand evidence, interpret regulatory requirements, and continuously evaluate compliance posture within the context of an organization's actual environment. As reported by 6clicks, this represents a critical shift for organizations operating complex, regulated, or sovereign environments where infrastructure cannot be easily connected to external services. The new approach enables AI-powered automation within cloud, on-premises, air-gapped, and hybrid deployments, allowing organizations to modernize their GRC programs without compromising security controls or disrupting existing processes.
The current cybersecurity challenge stems from what industry experts call Shadow AI, where employees use AI tools without proper organizational oversight. According to 63SATS Cybertech, confidential company information is likely being trained by LLM providers as individuals pass confidential data to the internet via popular language models. This represents a shift from traditional data leakage prevention systems to addressing the unauthorized use of AI tools within organizations. The company is addressing this issue through solutions, education, proof-of-concept demonstrations, and gap assessments to help enterprises understand their confidential information exposure. As noted by Alaap Shah, Member of the Firm, "We have situations that security researchers and others have already identified where data going in from one customer of that AI vendor gets pulled into the AI training, retraining model, and then ends up becoming part and parcel of the outputs that are generated for another customer."
As reported by Business Standard, not all enterprises can afford to run their own small language models or LLMs, creating additional security complexities. The company focuses on assessing security roadmaps and inherent security challenges when organizations consider deploying internal AI models. Key considerations include ensuring clean data pipelines for AI training, preventing malicious data injection, and establishing proper prompt engineering structures. Identity management extends beyond humans to include AI agents, requiring comprehensive token and usage metering systems. According to Alaap Shah, "We not only have hackers supercharged with AI solutions to use agentic AI in a way to orchestrate entire attack sequences, we also have AI being used in malicious ways to create new malware that can infiltrate systems and wreak havoc."
According to 63SATS Cybertech, the company is developing infrastructure for digital identity establishment for non-human agents. As reported by Business Standard, this includes managing the entire life cycle of AI agent identities, handling data that AI agents process, and implementing compliance frameworks. The approach focuses on restricting open usage by agents, implementing compliance checks when agents go rogue, and managing token and identity usage across the enterprise. This addresses the growing need for accountability in AI agent operations within organizations, with Alaap Shah noting that "AI is somewhat different in the sense that when you put data into an AI algorithm, sometimes that data becomes part and parcel of the models themselves."
According to 6clicks, 53% of organizations are prioritizing AI and machine learning to strengthen cybersecurity and risk management capabilities, reflecting a growing shift toward intelligent, automated assurance. The company's latest intelligent GRC (iGRC) solution introduces several fundamental capabilities that transform how GRC is operationalized. AI can now understand regulatory requirements across frameworks such as ISO 27001, NIST SP 800-53, and industry-specific standards, automatically mapping relevant evidence to controls and eliminating manual analysis. Compliance assessments become continuous rather than periodic, with AI automatically updating control effectiveness and compliance status as new evidence is ingested, providing real-time visibility into regulatory alignment and risk exposure. As emphasized by Alaap Shah, "There's nothing more important in the AI space currently than to be nimble, not only in adoption of AI technology and pivoting where you need to in terms of how you use it, but about how you govern that as well, because everything's changing frequently."
As AI and digital workflows become more prevalent in enterprises, security leaders must address emerging vulnerabilities at the intersection of AI, identity governance, and contract processes. An upcoming ETLegalWorld and ETCISO webinar, in collaboration with Zoho Sign, titled "The CISO's Blind Spot: AI, Identity and the Gaps in Your Contract Workflows" is scheduled for August 20. The session will bring together cybersecurity, legal and technology leaders to examine how weaknesses in identity frameworks and digital contract workflows can expose organizations to security, compliance and operational risks. As AI-driven systems introduce new layers of automation, access and decision-making, traditional approaches to identity and access management may not adequately address the risks associated with increasingly automated enterprise processes. The discussion will focus on how CISOs, legal teams and IT functions can establish clearer ownership of these risks while securing AI-enabled workflows without compromising business agility.