AI Vendor Values and Security Posture: Key Executive Signals from Dr. Zdenka Cumano

D

Dr. Zdenka Cumano

LinkedIn Author

Chief AI Officer @ AI Leader Edge | Ph.D., MBA, CGMA | I Build AI • Research AI • Teach MBA Students • Train C-Suite Executives | Professor @ FAU | 20+ Years Business and M&A Integrations

In a recent LinkedIn post, Dr. Zdenka Cumano highlights three critical signals from the past week that executives must consider regarding the rapidly evolving landscape of Artificial Intelligence, particularly concerning vendor values and enterprise security.

Dr. Zdenka Cumano emphasizes the immediate implications of AI governance, stating:

“Your AI vendor’s values are now a procurement risk — in both directions. The organizations that haven’t defined what their AI vendors are permitted to do are making that decision by default.”

AI Vendor Values as a Procurement Risk

Dr. Zdenka Cumano details a significant development involving the Pentagon’s decision-making on AI, noting the shift in procurement strategies. According to Dr. Zdenka Cumano, the Department of Defense initially cut ties with Anthropic due to its refusal to engage with autonomous weapons. Within hours, a contract was signed with OpenAI. This was followed by a notable public response where 875 employees from both Google and OpenAI publicly backed Anthropic’s stance on ethical AI development.

As Dr. Zdenka Cumano points out, this situation underscores a new reality for businesses:

“The organizations that haven’t defined what their AI vendors are permitted to do are making that decision by default.”

This event, as analyzed by Dr. Zdenka Cumano, suggests that a company’s AI vendor’s ethical framework and operational boundaries are becoming a direct procurement risk. Organizations that have not proactively established clear guidelines for their AI tools are inadvertently allowing external events and vendor defaults to shape their own AI governance policies.

The Lagging Security Frameworks in Enterprise AI

A second critical signal discussed by Dr. Zdenka Cumano concerns the rapid evolution of enterprise AI from a supportive tool to an autonomous actor, a progression for which security measures have not kept pace.

Dr. Zdenka Cumano explains:

“A new security analysis found AI agents are executing multi-step workflows and accessing sensitive systems without human approval — while most security frameworks were built for tools that wait for input, not agents that act.”

According to Dr. Zdenka Cumano, this shift means that many existing security frameworks, designed for AI tools that require human input, are now insufficient to manage the risks posed by autonomous AI agents. Dr. Zdenka Cumano warns that businesses that have deployed AI agents in the last six months may already have a security posture that lags significantly behind their AI capabilities. This is not a hypothetical future threat, but a present-day concern.

Apple’s AI Integration and its Implications

The third signal highlighted by Dr. Zdenka Cumano involves Apple’s confirmation of a new AI-powered Siri, set to launch with iOS 26.4, powered by Google’s Gemini under a substantial $1 billion annual deal. This integration signifies a major step in bringing advanced AI capabilities directly to consumer devices.

Dr. Zdenka Cumano notes the significance of this development:

“Every iPhone in your organization becomes a more capable AI interface this month — whether your IT team is ready or not.”

This partnership means that personal devices within an organization will increasingly serve as powerful AI interfaces, capable of drawing from on-device data such as emails, messages, and calendar information. Dr. Zdenka Cumano implies that this widespread accessibility of advanced AI capabilities necessitates immediate attention from IT departments to ensure readiness and manage potential security and data privacy implications.

The Overarching Pattern: AI Governance in Action

Dr. Zdenka Cumano concludes by identifying a unifying pattern across these three signals: AI governance has moved beyond theoretical policy discussions to become a critical, practical concern. Whether it’s a Pentagon contract, a security vulnerability report, or a major technology partnership, the distinction between organizations with clear AI governance frameworks and those without is becoming starkly evident.

As Dr. Zdenka Cumano argues, organizations with defined frameworks are able to act with confidence, while those without are forced into reactive positions. This highlights the urgent need for executives to establish robust AI governance strategies to navigate the complexities and risks associated with rapidly advancing AI technologies.

📝 About This Content

This article is based on insights shared by Dr. Zdenka Cumano on LinkedIn.

📅 Originally posted on March 5, 2026 | View original post on LinkedIn →