A “no” from your security team is almost never a “no” to AI. It is a no to one sentence on your request: "Give AI access to our data."

I should know. I am usually the person saying it. But also now I’m the person doing the asking too. Yeah I know..

If you are leading an AI rollout at a regulated company, you have probably taken a "no" like that to mean "security does not want AI here."

It does not mean that.

The request that gets refused

Let me walk you through a request. Some version of it is sitting in a review queue at most regulated companies right now.

A finance team wants to build their own reports because they are tired of waiting for the data team to give the report they need, and that takes two weeks. With an AI assistant, finance team could ask questions of the data in plain English and have the answer by the afternoon.

That is a good idea, and nobody on the security side thinks otherwise.

So the request goes in. And there is that sentence again: "Give AI access to our data."

The data lives in the production system. That is the live system that runs the business. It is also where the consumer names, the account details and the card numbers live.

Security says no. Pretty boring so far.

"Our data"

Here is how that sentence reads from the other side of the table, where I usually sit.

I see a tool name and the words "our data." It does not say which data.

It does not say which fields, which people, or where the data will sit once the tool has it. So I have to assume the answer is all of it, and "all of it" includes the fields that come with fines, breach notices. and a very long week with an auditor.

❝

The ‘no’ is not a verdict on AI. It is what comes out when the request is missing its most important fact.

Not every "no" works this way. Some requests should remain denied, and a good security leader will let you know which ones. However, most delayed requests are stuck because an important question hasn't been asked yet.

Saying “no” did not stop anything

This is the part most AI rollout leads never get to see.

The person who said no knows it does not end the story. The finance team still needs those reports on Monday. So somebody exports a spreadsheet, opens a free AI tool nobody approved, and pastes it in.

They are not being reckless. They are trying to get their work done.

That has a name now: shadow AI. It means AI tools that staff use without approval. Cybersecurity Dive's coverage of IBM's 2026 Cost of a Data Breach Report says shadow AI showed up in 43% of the incidents studied, about double the year before.

Your security lead knows this problem. They know every refusal pushes a little more AI use out of sight, and out of sight is the one place they cannot protect.

An approved tool is the only kind security can watch.

So a good security lead wants to get to “yes” more than you think. They are waiting for a request they can say yes to.

The question nobody asked

Back to our example. Here is how their story ends well:

Somebody asks one plain question: “which fields do you need for these reports?”

And the team, not security, does the real work here. They sit down and write the list: amounts, dates, categories, status, region, a user ID that means nothing outside the production system.

The list has no names on it. It has no card numbers and no PII (Personally Identifiable Information) in it.

A report on monthly totals does not care who the customer is. It never did.

After that, the fix is almost dull.

The data team sets up an export with every sensitive field removed, and security reviews it once. The copy sits outside the production system, in a shared folder that only the finance team can open. The AI works on the copy and never touches production.

Security never had to change its answer, because AI never went into the production system. The team got their reports. Nobody gave anything up.

Figure 1. Security's answer still stands. AI never crosses the dashed line. The team gets every field their reports use, and none of the fields security was guarding.

So, what happened?

Security was guarding the data next to yours.

So let me ask you about the AI request you are stuck on right now. How much of what it asks for does the job really need?

Most AI requests ask for far more than the task needs. Asking for everything is easier than working out which part you need.

Your support team wants ticket summaries, so they ask for the whole help desk system. The task needs the text of the tickets, not the customer's payment details. Your compliance team wants help drafting policies, so they ask for the whole shared drive, when the task needs twelve documents.

The extra part is almost always the part security is protecting.

❝

Security was never guarding the data you need. They were guarding the data sitting next to it.

Once you see that, your job changes. You stop pushing for a bigger approval. You make the request smaller, until there is nothing left in it for security to refuse.

The Runbook: four answers to bring

Do this before you meet with security. It fits on one page and takes one sitting.

  1. Name the job, not the tool. Write one sentence, like "We want to build our own monthly reports." You pass if the sentence still makes sense without the tool's name in it.

  2. List the fields the job needs. Sit with the team and write them down one by one. You pass if every field on the list shows up in the finished work.

  3. List the fields you can leave out. Names, card numbers, account details, health details. You pass if this list is longer than you expected. It also shows security you did the work and are not asking for everything.

  4. Say where the data will sit and who can open it. For example: a copy, in one folder, that only one team can open. You pass if you can count the people with access.

Bring that page to the meeting.

❝

You are no longer asking security to trust a tool with your production data. You are asking them to check a small, specific request. That makes a big difference.

Next action: before your Monday morning meeting, choose one AI request that is stuck. Write down only the necessary fields it needs. Then reply to me and let me know what was included in the original request that wasn't needed.

P.S. The smaller request helps you a second time.

Some day an auditor will ask what your AI tools can reach. "These fields, this folder, these people" is a short answer. "Everything, but we have a policy" is the start of a much longer conversation.

I'm Chaminda, a Fintech CISO and AI Adoption Lead. I have spent twenty years in cybersecurity, cloud infrastructure and reliability, keeping big systems running, including at PayPal. I'm leading an enterprise AI rollout right now, and I still build the systems I write about.

I help the person who was handed AI at a regulated company get it approved by security and actually used by people.

I'm usually the person who says “no”. That's why I can get you to “yes”.

Keep Reading