AI Governance Has Arrived in CAF

Is Your Organisation Ready?

As AI adoption grows, cyber resilience needs to keep pace

Artificial intelligence has rapidly become part of everyday business operations. Employees are using AI-powered tools to write content, analyse data, create code, summarise meetings and automate routine tasks.

In many organisations, this has happened without formal planning, governance or security oversight.

That creates a challenge.

While AI can improve productivity, it can also introduce new risks. Sensitive information may be entered into public AI platforms. Employees may rely on AI-generated outputs without proper review. New software integrations can create visibility gaps for security teams.

Recognising these changes, the National Cyber Security Centre (NCSC) has expanded the Cyber Assessment Framework (CAF) to better address the risks associated with AI. For organisations working towards CAF outcomes, AI is no longer a future consideration. It is becoming a current governance challenge.

The rise of unmanaged AI

Most organisations have not formally approved every AI tool being used across their environment.

Employees often adopt new tools independently because they are easy to access, require little technical knowledge and can deliver immediate results.

This creates a situation where leaders may have limited visibility of:

  • What AI tools are being used
  • What data is being shared
  • Who has access to generated content
  • How outputs are being validated
  • Whether security controls are being applied consistently

 

The challenge is not necessarily malicious behaviour. More often, employees are simply trying to work more efficiently. The problem is that cyber risk can emerge when technology adoption moves faster than governance.

Why CAF is evolving

CAF has always focused on outcomes rather than checklists.

The framework asks organisations to demonstrate that they understand and manage cyber risks that could affect critical services and business operations.

As AI becomes embedded within business processes, it naturally becomes part of that conversation.

The questions organisations should now be asking include:

  • Do we know where AI is being used?
  • Do we understand the risks associated with those tools?
  • Are employees receiving guidance on acceptable use?
  • Can we identify when sensitive information is being shared?
  • How would we respond if an AI platform introduced a security issue?

These are governance questions, but they are also resilience questions.

As AI adoption grows, cyber resilience needs to keep pace.

Recent research from CrowdStrike found that every organisation it assessed had more AI activity than expected, with some organisations discovering more than three times the number of AI tools and agents they believed were in use. CrowdStrike also reported detecting more than 1,800 AI applications across customer environments, highlighting the growing visibility challenge facing security teams.

This is often referred to as “Shadow AI” – the use of AI tools, assistants and applications outside formal governance processes.

For many organisations, the issue is not that employees are intentionally bypassing security controls. They are simply looking for faster ways to complete their work.

The problem is that cyber risk can emerge when technology adoption moves faster than governance. Recognising this shift, the National Cyber Security Centre (NCSC) has expanded the Cyber Assessment Framework (CAF) to better address the risks associated with AI.

For organisations working towards CAF outcomes, AI is no longer a future consideration. It is becoming a current governance challenge.

AI risk is often a visibility problem

Many organisations already have strong technical security controls in place. They have invested in endpoint protection, identity management and security monitoring.

However, those controls are only effective when organisations understand what technologies are operating within their environment. If AI usage remains hidden, unmanaged or poorly understood, security teams may struggle to assess risk accurately.

This is why visibility is becoming one of the most important aspects of cyber resilience. Before organisations can manage AI risk, they need to understand where it exists.

What Does CAF 4.0 Actually Expect Organisations To Consider?

CAF 4.0 doesn’t tell organisations whether they should or shouldn’t use artificial intelligence.

Instead, it recognises that AI is becoming part of modern business operations and asks organisations to understand, manage and govern the risks associated with it.

For public sector organisations, critical infrastructure operators and organisations delivering essential services, this means being able to demonstrate that AI-related risks are considered within wider cyber resilience activities.

In practical terms, organisations should be able to answer questions such as:

  • Do we know where AI systems are being used?
  • Have we assessed the risks associated with those systems?
  • Could an AI service affect the confidentiality, integrity or availability of important data?
  • Do employees understand what information can and cannot be entered into AI tools?
  • Are suppliers using AI in ways that could introduce additional risk?
  • Can we identify and respond to security incidents involving AI platforms or services?
  • Are AI tools subject to the same governance and oversight as other business systems?

 

While these may sound like governance questions, they are ultimately resilience questions.

If an organisation cannot identify where AI is being used or understand how it could impact critical services, it becomes significantly harder to manage risk effectively. CAF is increasingly encouraging organisations to treat AI as part of their wider cyber risk landscape rather than as a standalone technology initiative.

What Organisations Should Do Next

As AI adoption continues to accelerate, organisations need to understand where AI is already being used before they can effectively manage the associated risks.

A practical first step is to assess:

  • Which AI tools employees are using
  • What data is being shared with those tools
  • Whether appropriate governance exists
  • How AI-related risks are being monitored and managed

Without visibility, there can be no control.

How Maple Networks Can Help

Understanding where your organisation stands against CAF outcomes can be challenging, particularly as new technologies and risks continue to emerge.

Maple Networks helps organisations assess their current position, identify gaps and build practical improvement plans aligned to CAF requirements. Whether you are preparing for a formal assessment or looking to strengthen cyber resilience, our team can help you take a structured and measurable approach.

Speak to Maple Networks to learn how a CAF readiness assessment can help you understand your risks and prioritise the actions that matter most.

Understand the Risks of Shadow AI