Beyond Compliance: Defining Security Competence for the AI-Driven Future

 

By Gigliolla Agassini, CPP, Principal Consultant, GA Advisory, and ASIS Volunteer roles: Director of PSB, Regional Board NA – Membership Committee, Chair of ITSC SC and Zsuzsanna Bencsics, ASIS European Regional Board Liaison for NextGen and Women in Security, & IFPO Europe Co-Chair

 

At ASIS Europe 2026, our workshop Beyond Compliance: Defining Security Competence for the AI-Driven Future was designed to move the conversation on AI beyond regulation alone and into the practical realities of leadership, judgment, and operational decision-making.

We opened with a simple but important premise: even in a period defined by rapid technological acceleration, the needs of the market remain deeply human. As reflected in the World Economic Forum’s Future of Jobs Report 2025, analytical thinking remains the top core skill for employers, with seven out of ten companies identifying it as essential. That matters because the organizations best positioned for the AI era will be those that can match the velocity of innovation with the competence, oversight, and judgment required to govern it responsibly.

From there, the workshop expanded the competence discussion beyond leadership teams alone. In security, readiness cannot stop at the top. Supervisors, operators, and guards increasingly need a baseline level of technical understanding, not because they are expected to become AI specialists, but because they are part of the operational reality where risk is detected, interpreted, and managed. The people in the field are an extension of the organization’s response capability, and they must therefore be considered part of the mitigation strategy.

This became even more important as we turned to AI itself. Unlike many previous technologies, AI can produce outputs that sound polished, persuasive, and credible even when they are inaccurate. That is why human oversight is so critical. The question is not only whether organizations can use AI, but whether they know when to trust it, when to challenge it, and who has the authority to intervene when something does not look right.

To make those issues tangible, the workshop was structured in three parts. We began with a short framing session focused on competence, trust, and governance. We then used live polls to take the pulse of the room and understand how participants were experiencing AI pressure, verification practices, and decision authority inside their own organizations. Finally, we moved into scenario-based group exercises designed to shift the discussion from theory to practice.

Using scenarios that ranged from AI-enabled deception, including deepfake-related risks, to the broader organizational challenges of implementing AI, participants worked through selected phases that pushed them to assess what needed to be understood first, who should decide, what controls should already exist, and where governance gaps would become visible under pressure.

What made the session especially valuable was the quality of the discussion. Different groups approached the exercises from different angles, with different assumptions and responsibilities, yet a common conclusion emerged: regardless of sector or business model, organizations will struggle to keep pace with the velocity of the AI era without a well-established governance body, a defined program structure, and decision rights that are clear before a critical moment arrives.

That is why this conversation must go beyond compliance. Compliance remains important, but on its own it is not enough. Organizations also need competence, oversight, and governance maturity that allow them to move with speed without losing clarity, accountability, or control.

The strongest message from the workshop was clear: the future of AI in security will not be shaped by technology alone, but by how well organizations combine innovation speed with human judgment, governance clarity, and responsible oversight.

No Comments

Sorry, the comment form is closed at this time.