AI Security
The security question is not what your AI reads. It is what it can do.
Microsoft frames the shift as tools moving from reading to acting. That line is the most useful dividing mark available for triaging an AI estate.
Microsoft's security guidance frames the current moment as AI tools moving from reading to acting. It is a plain phrase and it does more practical work than most maturity models, because it sorts a messy estate into two piles with genuinely different risk profiles.
Reading systems fail by being wrong
A model that summarises, classifies, drafts or answers produces output a human consumes. When it fails, the failure is a wrong answer, and the human is the control. The exposure is real — bad advice acted on, sensitive content in a summary — but it is bounded by a person in the loop and it is recoverable.
Most enterprise AI governance was written for this pile, which is why it leans so heavily on accuracy, bias and disclosure.
Acting systems fail by doing
A system that calls tools changes state. A wrong answer becomes a deleted record, a sent payment, a modified configuration. There is no human between the decision and the effect, which is the entire point of deploying it, and the recovery path is whatever your backups and audit logs happen to support.
The moment a system can act, your AI risk register stops being an accuracy question and becomes an authorisation question.
The triage that follows
Walk your inventory and mark each system read or act. The act list is short today in most organisations and it is where essentially all the incident risk lives. It deserves controls the read list does not: per-system credentials, least privilege scoped to the specific task, action logging you could reconstruct an incident from, and a defined revocation path.
The mistake we see most often is applying one AI policy across both piles. Uniform governance is exactly what Gartner warns produces agent failure — not because governance is bad, but because a control set calibrated for a summariser is simultaneously too heavy for reading and far too light for acting.
Sources
Written by the Devence Lab research team.