Lukas Insight | By Ts. Lukas J. Tan
After completing PDX2026, I decided to go all-in on artificial intelligence.
Nearly three weeks into this journey, I have moved beyond simply using AI tools. I am exploring how AI can learn, build, analyse, automate and operate alongside me.
My biggest discovery is simple: AI enables us to learn independently and create exactly what we need at extraordinary speed.
One person can now research a market, analyse data, prepare a strategy, develop software and automate workflows. This represents a major productivity breakthrough, particularly for small and medium-sized businesses.
But the deeper I go into AI, the more I find myself asking one uncomfortable question:
Do you know whether there is a devil inside your AI?
What Is the “Devil” Inside AI?
The devil is not AI itself. It is the hidden risk created by poor data, excessive access, unclear instructions and uncontrolled automation.
An AI system may generate a convincing answer based on inaccurate information. It may reveal confidential data because it was given the wrong permissions. An AI agent may perform an unintended action because nobody clearly defined its boundaries.
The risk becomes greater when AI moves from answering questions to operating business systems.
A human mistake usually develops at human speed. An automated AI mistake can affect thousands of records, messages or transactions before anyone detects it.
Business leaders must therefore understand three things clearly:
- What AI can access
- What AI can decide
- What AI can execute
Lessons From the Age of Hacking
I come from a generation shaped by computer viruses, hacking, data scraping, software cloning and system vulnerabilities.
That experience trained me to examine technology from two perspectives: what the system is designed to do and how someone could manipulate it.
Convenience can create an entry point. Connectivity can create exposure. Automation can multiply efficiency, but it can also multiply errors.
Traditional cybersecurity focuses on protecting devices, networks, passwords and databases. AI introduces another layer that organisations must protect: the information and context influencing its behaviour.
AI does not merely store information. It interprets information, identifies patterns, generates recommendations and increasingly completes tasks.
Securing the system is no longer enough. We must also secure the decision-making process.
Can Someone Manipulate AI Data?
Yes. AI can be influenced by inaccurate, outdated or deliberately manipulated information.
The internet can be flooded with fabricated articles, fake reviews, synthetic identities, altered images and misleading statistics. Internal databases can also contain duplicate records, incorrect labels and biased historical decisions.
If AI relies on compromised information, it may produce an answer that appears professional and logical but is fundamentally wrong.
This creates a new category of cyber risk.
In the past, attackers mainly attempted to steal information or disrupt systems. In the AI era, they may attempt to influence what an AI system believes, how it reasons and what it recommends.
An attacker may not need to change the final decision directly. Manipulating the information used to reach that decision could be enough.
A company may successfully prevent outsiders from accessing its database and still make poor decisions because the data inside cannot be trusted.
Cybersecurity protects access to data. AI governance protects how that data becomes a decision.
What Is AI Governance?
AI governance is the framework that determines how an organisation selects, uses, monitors and controls artificial intelligence.
It establishes responsibilities for data protection, system access, human approval, output verification and accountability.
Without governance, every team member may create their own rules. Confidential information could be uploaded to unapproved platforms. AI-generated recommendations might be accepted without verification. Automated actions could happen without proper authorisation.
That is not a sustainable AI strategy. It is unmanaged business risk.
AI governance turns individual experimentation into a controlled organisational capability.
What Should an AI Governance Framework Include?
A practical framework should address five core areas.
- Data. Define what information AI may access, process and retain. Personal, confidential and commercially sensitive information requires stronger protection.
- Permission. Set boundaries around the systems AI can access and the actions it can perform. Access should be based on necessity—not convenience.
- Verification. Establish how AI-generated work will be reviewed for accuracy, relevance, bias and potential harm.
- Human Approval. Identify which decisions must remain under human control. Financial transactions, legal commitments, customer data changes and other high-impact actions require appropriate safeguards.
- Accountability. Assign clear ownership. Every AI system should have someone responsible for its purpose, performance, monitoring and risks.
The strength of these controls should correspond to the potential impact. Using AI to correct grammar does not require the same governance as allowing an AI agent to modify customer records, approve payments or deploy software.
Does AI Governance Restrict Innovation?
AI governance should not stop innovation. It should enable organisations to innovate with greater confidence.
When the boundaries are clear, the team can experiment without creating unnecessary exposure. Leaders can approve automation while maintaining visibility. Customers and partners can trust that their information is being handled responsibly.
Governance is not about controlling every prompt or slowing every project. It is about creating clear authority, traceability and accountability around AI activities that can materially affect the organisation.
The winners of the AI era will not simply be the companies using the most AI tools. They will be the companies capable of using AI reliably, explaining important decisions, protecting their data and taking responsibility for the outcomes.
The Question Every Leader Must Answer
Your organisation may already be using ChatGPT, Claude, AI agents or automated workflows—even without an official AI strategy.
Members of the team may be uploading documents, analysing customer information, generating business recommendations or using AI-created code inside company systems.
The first leadership question should therefore be:
Do we know where and how AI is being used across our organisation?
An AI Governance Assessment can identify existing tools, data exposure, access permissions, approval gaps and accountability risks. The organisation can then establish a practical governance framework aligned with its operations and level of risk.
I remain strongly positive about AI. Its potential to improve productivity, strengthen decisions and help smaller organisations compete is enormous.
But opportunity without control can quickly become liability.
AI should not be feared. It should be governed with clarity, discipline and confidence.
Do not wait for the devil to appear before creating the rules.