SECTION 08
08The roadmap: 24 months in three waves
First see what you have, then control it, then make it adapt. The first wave buys visibility, the second control, the third adaptation. Start with the third and you buy tools nobody uses.

Text in this figure
W1 · W2 · W3 · MONTHS 0–3 · 1 · Visibility · Inventory every AI system in use, including what business units adopted without security's knowledge. Assign an owner to each. Run the assessment and document each dimension's result. Draft a use and deployment policy. · Output: model register · baseline assessment · approved policy. · MONTHS 4–12 · 2 · Control · A pre-deployment security review gate, graduated by impact. Controls for training-data integrity and provenance. Model drift monitoring in production. An AI scenario in the response plan and one simulation exercise. · Output: gate procedure · model monitoring dashboard · exercise report. · MONTHS 13–24 · 3 · Adaptation · Automate repetitive response paths. Enterprise-wide behavioural analytics. Proactive simulation of attack scenarios against models. A quarterly learning cycle that adjusts controls. Reassessment against the baseline. · Output: automated playbooks · adversarial simulation report · second, compared assessment.
Applying the roadmap
Start the inventory from the business units, not the data centre: the tools marketing or HR bought on a monthly subscription are the ones most absent from the records, and the closest to sensitive data.
The decisive choice in the second wave is designing the gate so it is not routed around: light review for low-impact models, full review for critical ones. A gate that treats everything equally is abandoned within six months.
By the end of the third wave one question must be answered with a number: how much did the weakest dimension improve in two years? If the answer has no number, the programme produced activity, not capability.
The four most expensive mistakes
Starting with the tool. An advanced platform over an incomplete inventory watches part of the organisation and gives full confidence.
Separating security from the data team. Builder and protector must meet in one path, or governance becomes bureaucracy to route around.
A one-off assessment. A number with no number after it is a photograph of a moving environment.
Ignoring the shadow. The most dangerous AI systems in an organisation are the ones nobody knows exist.
Tip: use ← → to move between sections.
