Loïc Guézo, director of cybersecurity strategy for southern Europe at Proofpoin

In Europe, AI is not only applied in pilot projects, but to the entire infrastructure through co-pilots, autonomous agents, generative SaaS applications… However, adoption has accelerated faster than governance structures, and that gap is where the risk currently lies. From Proofpoint they assure that many European organizations treat the current AI Compliance Law (EU AI Act), the first comprehensive legal framework on AI in the world, as their only reference for AI governance without taking into account that regulatory compliance and risk reduction are not the same thing.

“The EU AI Law establishes legal obligations for AI systems, which is necessary, but it is only one piece of the puzzle. An organization can comply with all the requirements and still suffer a data leak, misuse by internal personnel or an AI-amplified phishing campaign,” says Loïc Guézo, director of cybersecurity strategy for southern Europe at Proofpoint.

Applicable frameworks related to AI

There are currently three applicable frameworks – NIST AI RMF, ISO standards and the EU AI Law – which, for Proofpoint experts, do not mean choosing between one or the other, but rather combining them so that each one addresses a different issue. NIST AI RMF is designed for risk management, providing a robust framework for assessing and monitoring risks associated with AI systems; ISO/IEC 23894 and 42001 standards focus on governance and management systems to establish repeatable and measurable internal processes, as well as foster a culture of accountability within the organization; and the EU AI Act is an imperative regulatory framework to ensure that organizations comply with the legal obligations required for AI systems under its scope of application.

“For a group that operates in Europe, but is exposed to international customers or subsidiaries, the strongest approach would be to use NIST as an operational backbone, ISO standards for governance maturity and the EU AI Law for specific legal obligations,” exemplifies Loïc Guézo.

Discussions about AI tend to focus on the accuracy, explainability, and bias of models. For Proofpoint, these are real concerns, but in practice, most incidents arise from how teams use AI, how data moves through an organization, and how attackers anticipate exploitation of those tools.

AI risk is fundamentally a human risk, a data risk, and a communications risk, not just a technological risk; And that’s where governance frameworks fall short: no framework, no matter how rigorous, covers the whole picture on its own.

The first breach, corresponding to human behavior, occurs when employees share confidential information with AI tools, approving fraudulent requests or bypassing approved processes, even with policies on paper.

Data exposure is the second. AI is capable of amplifying existing weaknesses in data governance. Many organizations may discover access control flaws after AI has made them exploitable at scale.

Following closely behind are AI-powered attacks such as phishing, CEO fraud, business email compromise (BEC) and spoofing, which are becoming more sophisticated and frequent.

Shadow AI closes the list. If there is no visibility into the actual use of this technology, those responsible for an organization do not know what tools are circulating, what data flows through them, or whether internal policies are being followed.

According to Loïc Guézo of Proofpoint, “European leaders face the challenge of converting regulatory obligations into an operational security program that is measurable, actionable and aligned with business priorities.”

Actions to be carried out by organizations

As recommendations, this company proposes an action plan to build in collaboration with the CISO or security manager of the organization following these steps:

  • Establish a framework: combine the requirements of NIST, ISO and the EU AI Law into a single structure instead of having three parallel programs.
  • Map AI usage: Inventory approved systems, co-pilots, agents, and third-party integrations, and identify who is responsible for each.
  • Prioritize by business impact: A prompt with public information carries a very different risk than one that contains customer records or intellectual property.
  • Connect each governance objective with operational control: data classification, access management, data loss prevention, usage monitoring.
  • Measure risk reduction, not compliance activity: Track specific indicators, such as reduction in data sharing, AI-related data loss incidents, or reduction in excessive access permissions.

By Loïc Guézo, director of cybersecurity strategy for southern Europe at Proofpoin