On September 23, the UN Security Council held a high-level briefing on artificial intelligence and international security. The discussion focused on some of the largest questions now facing governments: how to keep advanced AI under human control, how to create meaningful governance, and how to ensure that increasingly autonomous systems remain observable, accountable, and safe.
That global conversation has a direct parallel inside the enterprise.
The Security Council was focused on frontier AI risks at the level of states, critical infrastructure, and humanity. But the same underlying themes are already showing up inside businesses as employees adopt AI assistants and organizations begin deploying autonomous agents across real workflows.
The scale is different. The security problem is not.
Governance Was the Dominant Theme
One of the clearest signals from the Security Council discussion was the language used throughout the session. Across roughly two and a half hours and nineteen speakers, “governance” appeared 35 times, more than any other substantive term apart from “AI” itself and a small set of general words such as “international” and “security.”
That matters. The debate was not about whether AI requires oversight. The consensus was that oversight must become structural.
Other terms appeared less frequently but carried significant weight. “Misalignment” appeared four times. “Visibility” appeared three times. “Control” appeared repeatedly throughout the session, often in connection with the risk that increasingly capable systems could act in ways humans do not intend or understand.
Together, those words tell the story of where the global AI security conversation is going:
- Governance is the destination.
- Visibility is the prerequisite.
- Control is the requirement.
- Misalignment is one of the failure modes governance must address.
- Accountability and oversight are what make governance operational.
Liberia’s Permanent Representative, H.E. Ambassador Lewis Garseedah Brown II, captured the stakes clearly when he warned that AI’s trajectory could “outstrip human control, institutional accountability, and ethical oversight.” At the UN level, that concern applies to frontier models, autonomous systems, cyber operations, and international security. Inside the enterprise, the same concern appears in a more immediate operational form: AI adoption can outstrip the organization’s ability to see what is happening, written code of conducts, and the ability to determine accountability.
A business cannot govern AI it cannot see. It cannot control AI activity it cannot interpret. And it cannot manage misalignment if it only discovers problematic behavior after an incident has already occurred.
The UN Debate Was About Frontier AI. Enterprises Face the Runtime Version.
The frontier labs deserve credit for the work they are doing on model-level safety. The Security Council heard about efforts around alignment, monitoring, evaluations, red teaming, incident disclosure, and other safeguards designed to reduce the risk that powerful AI systems could cause harm at global scale.
As Proofpoint partners with several frontier AI labs, I applaud the investments from those such as Anthropic and OpenAI to create global guardrails for humanity.
But enterprises need their own guardrails, too, that are specific to their business operations.
Model-level safety does not tell a business whether an employee is using an AI assistant to bypass an acceptable-use policy. It does not tell a security team whether sensitive customer data is being entered into an unapproved AI tool. It does not determine whether an autonomous agent should be allowed to issue a refund, approve a payment, update a ticket, send an email, or take action in a business system.
Those are not model-training questions. They are runtime governance questions that align to the written rules of the enterprise.
That is the enterprise parallel to the Security Council debate. Governments are asking how to maintain visibility and control over frontier AI systems. Businesses must ask how to maintain visibility and control over AI activity inside their own environments.
Colombia’s Warning Applies at Enterprise Scale
H.E. Dr. J. Mauricio Gaona Bejarano, Permanent Representative of Colombia to the United Nations, framed the risk in especially direct terms. Speaking about loss of control, he warned that one of the central concerns is the moment “we do no longer understand what the machine is doing.”
At the Security Council, that warning was about advanced AI systems and the potential loss of human control.
Inside an enterprise, the same concern appears in a more operational form. It is the moment a security team no longer understands which AI tools employees are using, what data is being shared, what actions agents are taking, which systems they can access, or whether those actions match the intent of the business.
That is why observability is not a nice-to-have feature in AI security. It is the foundation.
If you cannot see what AI is doing, guardrails become theoretical. If you cannot discover new behaviors as they emerge, policies remain incomplete. And if you cannot enforce controls at runtime, governance becomes an after-the-fact exercise.
From Global Guardrails to Business Guardrails
For decades, organizations have built governance around human behavior: finance policies, compliance standards, employee handbooks, acceptable-use rules, data-handling requirements, and codes of conduct.
But AI changes the operating model.
AI assistants and agents can act across systems, interpret instructions, summarize data, generate content, invoke tools, and execute workflows at machine speed. A policy written for a human employee does not automatically become a technical control that can govern an AI agent.
That is the gap enterprises now need to close.
The Security Council discussion made clear that frontier AI requires governance, visibility, and control. The enterprise version of that same requirement is an AI security solution built around three connected capabilities:
- Observability, so organizations can see how AI is being used by people and agents.
- Guardrails, so business rules can be expressed and applied across AI activity.
- Runtime controls, so enforcement happens when an action is attempted, not after the damage is done.
These cannot be separate projects. They need to operate as a continuous loop.
Operationalizing AI Governance in the Enterprise
This is the same problem we addressed at Protect in Operationalizing Security for the Agentic Era, where we introduced Semantic Business Policies and Agentic Insights.
Semantic Business Policies are about turning business intent into enforceable AI guardrails. An organization should be able to express rules in plain English, such as “never allow an outbound payout over $5,000 without approval,” “do not allow interactions with gambling websites,” or “do not send email communications outside the company,” and have those policies enforced across the enterprise AI estate.
That matters because business guardrails must apply whether the action is taken by a human using an AI assistant or by an autonomous agent acting on the user’s behalf.
Runtime enforcement is what makes those policies meaningful. It is not enough to define what should happen. AI security has to evaluate what is happening in the moment an action occurs. If an agent is authorized to answer support questions, that does not mean it should be allowed to issue refunds. If an agent is running security tests, that does not mean it should be posting to a public forum. Authorization needs to be tied to intent, context, and business policy.
Agentic Insights closes the other side of the loop. Enforcing known policies is essential, but it only covers risks the organization has already anticipated. As AI usage expands, businesses need continuous discovery of new behaviors, new patterns, and new categories of risk.
That is where observability becomes intelligence. Traditional security tools often answer, “What happened?” Enterprise AI security increasingly needs to answer, “What should I know?”
The Bottom Line
The Security Council debate showed that AI governance is no longer a theoretical discussion. At the global level, governments and frontier labs are wrestling with how to preserve visibility, accountability, and human control over increasingly capable systems.
Enterprises face the same challenge in a more immediate form.
The frontier labs are building guardrails for humanity. That work is important and should be applauded. But businesses also need guardrails for the way AI is used inside their organizations, across employees, agents, applications, and data.
The lesson from the UN discussion is not only that AI needs governance. It is that governance depends on visibility and control.
For enterprises, that means AI security must bring together observability, guardrails, and runtime enforcement in one continuous operating model. Without that, organizations will be left with written policies that cannot keep pace with autonomous action.
With it, they can adopt AI with the confidence that they can see what is happening, understand what it means, and enforce the business rules that matter before risk turns into an incident.