A Core Focus at Next IT Security | Frankfurt 2026
Introduction
Artificial Intelligence is rapidly changing how modern organisations operate. From productivity tools and automated workflows to advanced analytics, software development, customer engagement, and decision support, AI is becoming embedded across virtually every part of the enterprise.
For organisations across the DACH region, this transformation presents enormous opportunities. AI can accelerate innovation, improve efficiency, enhance decision-making, and create entirely new business models.
But greater adoption also creates a fundamental challenge for security and technology leaders:
How can organisations embrace AI without losing control of their data, systems, identities, and decisions?
As AI moves deeper into enterprise environments, traditional approaches to governance are being tested. Employees may adopt AI tools without formal approval. Sensitive business information may be processed by external models. AI applications may gain access to internal systems. Autonomous agents may eventually perform tasks without direct human involvement.
This creates a new generation of security and governance challenges.
The keynote AI Without Losing Control: Governing the Next Generation of Enterprise Intelligence at Next IT Security | Frankfurt 2026 will explore how organisations can build effective AI governance while continuing to innovate.
The discussion will focus on four critical priorities: governing AI without slowing innovation, managing Shadow AI, protecting sensitive enterprise data, and preparing for Agentic AI and non-human identities.
Why AI Governance Matters Now
AI adoption is moving faster than many organisations’ governance frameworks.
Employees are discovering new AI capabilities and incorporating them into their daily workflows. Business units are experimenting with tools independently. Developers are integrating AI services into applications. Meanwhile, security teams may struggle to maintain visibility into which systems are being used, what information is being shared, and where AI-generated outputs are influencing business decisions.
This creates a difficult balance.
Organisations need enough governance to manage risk, but excessive restrictions can encourage employees to bypass official processes and seek their own solutions.
The result can be a growing gap between official AI strategy and actual AI usage.
Effective AI governance therefore cannot simply mean creating a list of prohibited tools. It requires organisations to understand how AI is being used, establish clear risk-based controls, protect sensitive information, and create secure pathways for responsible innovation.
At Next IT Security | Frankfurt 2026, the keynote will explore how organisations can establish this balance and maintain visibility and control as AI adoption accelerates.
What Organisations Need to Consider
AI governance increasingly requires organisations to understand:
- Where AI is being used across the enterprise.
- Which AI systems have access to sensitive information.
- How employees and business units are adopting AI tools.
- What security controls apply to AI-enabled workflows.
- How AI-generated decisions are reviewed and validated.
- Who is accountable for AI-related risks.
- How autonomous AI systems should be governed.
- How non-human identities will be managed as AI becomes more autonomous.
Governing AI While Enabling Innovation
Security Should Enable Responsible AI Adoption
One of the biggest challenges for security leaders is finding the right balance between control and innovation.
AI technology is evolving too quickly for organisations to rely on rigid policies that assume every use case can be predicted in advance. New models, applications, agents, and services are appearing continuously, and employees are finding creative ways to incorporate them into their work.
A governance framework that is too restrictive can become an obstacle.
A framework that is too permissive can expose the organisation to unacceptable risks.
The solution is a risk-based approach to AI governance.
Not every AI use case presents the same level of risk. Using AI to summarise public information is fundamentally different from using an AI system to process confidential customer records, generate software code, make financial recommendations, or autonomously interact with enterprise systems.
Governance must therefore reflect the context and potential impact of each use case.
Impact on Next-Generation IT Security
Organisations can support innovation while maintaining control by:
- Establishing clear AI governance principles.
- Classifying AI use cases according to risk.
- Defining acceptable and unacceptable AI applications.
- Creating approved pathways for employees to adopt AI securely.
- Embedding security requirements into AI development and procurement.
- Establishing clear accountability for AI risk.
- Continuously reviewing governance as AI capabilities evolve.
At Next IT Security | Frankfurt 2026, the keynote will explore how security leaders can avoid choosing between innovation and control and instead build governance models that enable organisations to adopt AI with greater confidence.
Managing Shadow AI Across the Enterprise
When Employees Adopt AI Before Security Can
One of the most immediate AI governance challenges is Shadow AI.
Employees do not necessarily wait for an organisation to approve a technology before discovering its usefulness. Publicly available AI tools can be accessed within seconds, making it easy for employees to experiment with new capabilities outside established IT processes.
The challenge is not necessarily malicious behaviour.
In many cases, employees are simply trying to work more efficiently.
They may use AI to summarise documents, analyse information, translate content, write code, generate presentations, automate repetitive tasks, or support customer communications.
The security problem emerges when organisations do not know what information is being shared with these tools or how that information is being processed.
Sensitive intellectual property, customer information, internal documents, credentials, source code, or confidential business information could potentially enter AI systems without the organisation having appropriate visibility or controls.
This makes Shadow AI both a governance challenge and a data-security challenge.
Impact on Next-Generation IT Security
Organisations are increasingly focusing on:
- Discovering where and how AI tools are being used.
- Creating approved enterprise AI environments.
- Educating employees about AI-related data risks.
- Establishing clear policies for sensitive information.
- Monitoring AI usage where appropriate.
- Providing secure alternatives to unmanaged AI services.
- Creating governance processes that reflect real-world employee behaviour.
The objective should not simply be to eliminate Shadow AI.
It should be to understand why Shadow AI exists and provide safer ways for employees to achieve the same outcomes.
At Next IT Security | Frankfurt 2026, the keynote will examine how organisations can address Shadow AI through visibility, education, risk management, and practical governance rather than relying exclusively on prohibition.
Protecting Sensitive Data in AI-Enabled Environments
Your Data Is Part of the AI Attack Surface
AI systems can create significant value from organisational data.
They can analyse documents, identify patterns, summarise information, answer questions, support employees, and automate decisions.
But the same data that makes AI useful can also make AI systems attractive targets.
Enterprise AI may interact with confidential information including customer records, financial data, intellectual property, employee information, strategic plans, source code, legal documents, and commercially sensitive material.
The challenge is therefore not simply protecting the AI model.
Organisations need to understand the complete data lifecycle.
Where does the information originate? How is it accessed? Where is it processed? Which AI systems can use it? Who can retrieve it? How long is it retained? What happens when an AI application is connected to another system?
These questions become increasingly important as AI becomes integrated into enterprise workflows.
Impact on Next-Generation IT Security
AI-enabled data security requires organisations to consider:
- Data classification before information reaches AI systems.
- Access controls based on user and application identity.
- Protection of sensitive information within AI workflows.
- Secure AI procurement and third-party risk assessment.
- Data retention and handling requirements.
- Monitoring of sensitive data access and movement.
- Separation of information according to business and security requirements.
- Human oversight for high-impact use cases.
At Next IT Security | Frankfurt 2026, the keynote will examine how organisations can unlock the value of enterprise data while ensuring that AI does not become an uncontrolled pathway for sensitive information.
AI Governance Beyond the Model
The Real Risk Is Often the Ecosystem
It is tempting to think of AI security as primarily a question of model security.
But enterprise AI rarely exists in isolation.
A modern AI application may interact with databases, cloud services, APIs, internal applications, identity systems, external platforms, plugins, data repositories, and business workflows.
This means that the security of an AI system depends partly on everything connected to it.
An AI assistant with access only to public information presents a very different risk profile from an AI agent that can access confidential corporate documents and execute actions within enterprise applications.
The more capable AI becomes, the more important the surrounding governance becomes.
Security leaders therefore need visibility not only into models but into AI systems, data, identities, permissions, integrations, and actions.
Impact on Next-Generation IT Security
A broader AI governance model considers:
- Models and AI applications.
- Data sources and repositories.
- APIs and external services.
- User and application permissions.
- Automated workflows.
- AI-generated actions.
- Third-party providers.
- Monitoring and audit capabilities.
- Human oversight and accountability.
The keynote will explore why governing the AI ecosystem is becoming just as important as governing the AI model itself.
Preparing for Agentic AI
When AI Moves From Answers to Actions
The next major shift in enterprise AI may come from Agentic AI.
Traditional AI applications often respond to prompts or generate information. Agentic systems can go further by planning tasks, interacting with tools, retrieving information, making decisions, and potentially executing actions on behalf of users or organisations.
This creates significant opportunities for automation.
It also creates a fundamental security question:
What happens when an AI system can act rather than simply advise?
An AI agent with access to business systems may be capable of sending messages, creating records, retrieving documents, modifying configurations, initiating transactions, or interacting with other systems.
The risk is no longer limited to what the model says.
It includes what the AI is allowed to do.
This changes the security model.
Organisations will need to think carefully about permissions, authorisation, monitoring, action limits, approval workflows, and the ability to stop or isolate autonomous systems.
Impact on Next-Generation IT Security
Preparing for Agentic AI requires organisations to consider:
- What actions an AI agent is permitted to perform.
- Which systems and data it can access.
- How permissions are granted and reviewed.
- When human approval is required.
- How AI-generated actions are monitored.
- How abnormal or malicious behaviour is detected.
- How autonomous systems can be stopped or isolated.
- How accountability is maintained when machines take actions.
At Next IT Security | Frankfurt 2026, the keynote will explore why Agentic AI requires organisations to rethink traditional approaches to identity, access management, monitoring, and governance.
The Rise of Non-Human Identities
When Machines Become Digital Actors
For decades, identity and access management has largely focused on people.
Users have usernames, credentials, roles, permissions, and access policies.
The rise of AI agents introduces a new category of identity: the non-human identity.
AI agents may need credentials, permissions, tokens, API access, or service accounts to interact with enterprise systems. As organisations deploy more autonomous AI, the number of machine identities could increase dramatically.
This creates a major governance challenge.
Organisations need to know:
- Which AI agents exist?
- Who owns them?
- What can they access?
- What actions can they perform?
- How are their permissions granted?
- How are those permissions reviewed?
- How can their activity be monitored?
- What happens when an agent is compromised?
A forgotten service account is already a security concern.
A highly capable AI agent with excessive permissions could create an entirely different scale of risk.
Impact on Next-Generation IT Security
Organisations preparing for non-human identities should consider:
- Maintaining an inventory of AI agents and machine identities.
- Assigning clear ownership to autonomous systems.
- Applying least-privilege access.
- Limiting the actions agents can perform.
- Monitoring machine-to-machine activity.
- Rotating and protecting credentials and tokens.
- Regularly reviewing permissions.
- Establishing rapid mechanisms for disabling compromised agents.
The keynote at Next IT Security | Frankfurt 2026 will examine why identity security is becoming a central part of AI governance and why organisations need to prepare for a future where machines increasingly act on behalf of humans.
Maintaining Human Control
Automation Does Not Remove Accountability
As AI systems become more autonomous, organisations must carefully consider where human oversight remains necessary.
Automation can improve speed and efficiency, but highly consequential decisions may require human review, particularly when errors could affect customers, employees, finances, security, or regulatory obligations.
The objective is not necessarily to place a human in every AI workflow.
Instead, organisations need to determine where human intervention provides meaningful risk reduction.
This can involve approval thresholds, exception handling, escalation processes, monitoring, audit trails, and clearly defined intervention points.
Human oversight is particularly important when AI systems can take actions rather than simply generate recommendations.
Impact on Next-Generation IT Security
Organisations can maintain meaningful human control by:
- Defining decision thresholds for autonomous systems.
- Requiring approval for high-impact actions.
- Establishing clear escalation procedures.
- Maintaining audit trails for AI activity.
- Monitoring AI agents continuously.
- Testing failure and override scenarios.
- Defining who is accountable for AI-enabled actions.
At Next IT Security | Frankfurt 2026, the discussion will explore how organisations can embrace automation without allowing accountability to disappear behind increasingly autonomous systems.
Building AI Governance That Scales
Governance Must Evolve With the Technology
AI governance cannot be a one-time project.
The technology is evolving rapidly, and organisations will continue to introduce new models, tools, applications, and autonomous capabilities.
A governance framework that works for today’s AI environment may not be sufficient for tomorrow’s.
This means organisations need governance processes that are adaptable.
They should be able to evaluate new AI use cases, classify risk, establish controls, monitor adoption, investigate incidents, and update policies as technology changes.
Governance should also be integrated into existing organisational processes rather than becoming another disconnected layer of bureaucracy.
AI risk management should connect with cybersecurity, privacy, compliance, enterprise architecture, procurement, identity management, data governance, and business continuity.
Impact on Next-Generation IT Security
Scalable AI governance can include:
- A central inventory of AI systems and use cases.
- Risk-based AI classification.
- Clear ownership and accountability.
- Secure AI procurement processes.
- Continuous monitoring and assessment.
- Integration with existing security and identity controls.
- Regular reviews of AI applications and agents.
- Governance processes for autonomous and non-human identities.
The goal is simple:
Govern AI at the speed at which the organisation is adopting it.
From Shadow AI to Strategic AI
Turning Uncontrolled Adoption Into Enterprise Capability
Shadow AI should not only be viewed as a problem to eliminate.
It can also be a signal.
Employees often adopt new technology because it solves real problems faster than existing processes. If organisations understand those use cases, they can identify where secure enterprise AI solutions could provide greater value.
This creates an opportunity to move from unmanaged experimentation toward strategic adoption.
Instead of asking employees to stop using AI, organisations can provide trusted tools, clear guidance, secure data environments, and approved workflows.
This can reduce unmanaged risk while accelerating adoption.
Impact on Next-Generation IT Security
A mature approach can help organisations:
- Identify valuable AI use cases emerging from employees.
- Replace risky Shadow AI with approved alternatives.
- Improve employee awareness and AI literacy.
- Establish clear boundaries around sensitive information.
- Accelerate safe enterprise AI adoption.
- Turn experimentation into governed innovation.
At Next IT Security | Frankfurt 2026, the focus will be on creating an environment where security does not have to compete with innovation.
The objective is to make the secure path the easiest path.
Building Trust in Enterprise Intelligence
Control Creates Confidence
Trust is becoming one of the most important requirements for enterprise AI.
Business leaders need confidence that AI systems are operating within defined boundaries. Employees need to know that their information is protected. Customers and partners need confidence that sensitive data is handled appropriately.
Regulators and other stakeholders increasingly expect organisations to demonstrate that technology is being governed responsibly.
Trust therefore requires more than AI performance.
It requires visibility, accountability, security, governance, and the ability to intervene when something goes wrong.
Organisations that can demonstrate control over their AI environments will be better positioned to scale adoption confidently.
What Trust Looks Like
Trusted enterprise AI requires organisations to understand:
- What AI systems are deployed.
- What information they can access.
- What actions they can perform.
- Who or what controls those actions.
- How activity is monitored.
- How incidents are investigated.
- How systems can be restricted or stopped.
- Who remains accountable for the outcome.
The keynote AI Without Losing Control will examine how these principles can become part of a practical enterprise AI strategy.
Why This Matters for the DACH Region
The DACH region is home to highly innovative industries spanning manufacturing, automotive, financial services, healthcare, engineering, technology, logistics, and industrial operations.
Many organisations in Germany, Austria, and Switzerland are therefore exploring AI not only as a productivity tool but as a component of critical business and industrial processes.
This makes governance particularly important.
The more deeply AI becomes embedded into enterprise operations, the more organisations need to understand where data flows, how systems interact, who has access, and what happens when automated systems make decisions or take actions.
For security and technology leaders in the DACH market, AI governance is therefore becoming a strategic question:
How do we enable AI at enterprise scale while maintaining the security, accountability, and control expected of critical business systems?
Next IT Security | Frankfurt 2026 provides a platform for examining this challenge and exploring practical approaches to governing the next generation of enterprise intelligence.
What Attendees Can Take Away
The keynote AI Without Losing Control: Governing the Next Generation of Enterprise Intelligence is designed for leaders who are responsible for navigating AI adoption while managing security, governance, and organisational risk.
Attendees will gain insight into:
- How to build AI governance without unnecessarily slowing innovation.
- How to identify and manage Shadow AI across the enterprise.
- How to protect sensitive data in AI-enabled environments.
- How to assess the security implications of enterprise AI adoption.
- How Agentic AI changes traditional security assumptions.
- Why non-human identities are becoming a critical security concern.
- How to establish appropriate controls around autonomous AI systems.
- How to maintain human oversight and accountability.
- How to create governance frameworks that can evolve alongside AI.
For CISOs, CIOs, CTOs, security leaders, architects, risk professionals, data leaders, and technology decision-makers, these issues are quickly becoming central to the future of enterprise security.
Looking Ahead
AI is moving from an experimental technology to an increasingly autonomous component of enterprise infrastructure.
The next generation of AI will not simply answer questions.
It will increasingly access information, interact with systems, make decisions, coordinate tasks, and take actions.
That transformation creates enormous potential — but it also changes what it means to maintain control.
Organisations will need to understand their AI environments, govern how AI is adopted, protect the data that powers intelligent systems, and prepare for machines that increasingly operate as digital actors.
This means AI governance must evolve beyond policies and approvals.
It must become an active part of enterprise security.
The keynote AI Without Losing Control: Governing the Next Generation of Enterprise Intelligence at Next IT Security | Frankfurt 2026 will explore how organisations can navigate this transition while maintaining security, accountability, and trust.
From Shadow AI to sensitive enterprise data, from Agentic AI to non-human identities, the security landscape is changing rapidly.
The organisations that succeed will not necessarily be those that use the least AI.
They will be those that can innovate quickly while maintaining visibility, governance, and control.
Because the future of enterprise intelligence should not be about choosing between AI and security.
It should be about building AI that organisations can trust, govern, and control.
Join the Conversation
The future of enterprise AI is already taking shape.
The challenge now is to ensure that innovation does not move faster than security, governance, and accountability.
At Next IT Security | Frankfurt 2026, the keynote AI Without Losing Control will explore how organisations can prepare for this next phase of enterprise intelligence — building governance frameworks that support innovation, protecting sensitive data, managing Shadow AI, and preparing for autonomous systems and non-human identities.