Exhibit A(I): The New AI Security Problem Is Evidence You Cannot Reconstruct Fast Enough

AI governance fails when teams cannot reconstruct what tools, data, and people did during the first 72 hours.

Exhibit A(I): The New AI Security Problem Is Evidence You Cannot Reconstruct Fast Enough

A useful security roundup is not a pile of scary headlines.

It is a pattern detector.

This week’s pattern is simple: the next governance failure will not come from one bad model, one infected laptop, or one missed patch. It will come from teams being unable to reconstruct what happened across phones, AI tools, malware, vendors, certificates, and human handoffs quickly enough to make a defensible decision.

That is the AI security issue hiding inside the news.

What happened

SecurityWeek’s roundup flagged a mix of stories that do not look related at first glance: tracking of U.S. military phones, CrashStealer macOS malware, a coordinated vulnerability disclosure blueprint, ransomware against a naval defense firm, and a Lidl data breach.

Silicon Republic reported that Apple has contacted about 40 former employees who left for OpenAI and directed them to preserve documents in connection with a trade secrets dispute.

The Hacker News reported that researchers linked a subgroup called CylindricalCanine to the April 2026 DigiCert incident and code-signing certificate theft.

Several other enterprise AI stories point in the same direction: marketing teams are struggling with agentic AI adoption, and Microsoft is reportedly developing a lower-cost multi-model AI security tool called Project Perception.

The details differ.

The management problem does not.

The operator lesson

AI security is becoming an evidence problem before it is becoming a model problem.

A phone tracking story asks whether an organization can see device exposure without pretending mobile telemetry is complete.

A macOS stealer story asks whether endpoint visibility covers the machines executives and developers actually use.

A code-signing incident asks whether trust in certificates is monitored as a live control, not treated as paperwork.

A trade secrets dispute asks whether employee movement, tool access, documents, and model workflows can be reconstructed without panic.

Agentic AI adoption asks whether teams know which agents acted, which data they touched, which approvals they bypassed, and which outputs became business records.

That is where many governance programs lose the thread.

They write policies for categories. Attackers, plaintiffs, regulators, and customers ask for sequences.

Why this belongs in Exhibit A(I)

The lazy AI governance question is, "Did we approve the tool?"

The useful question is, "Can we explain what happened after the tool entered the workflow?"

If the answer is no, the organization does not have an AI governance program. It has a procurement ritual.

This matters because AI tools do not stay neatly inside one control family. They touch identity, endpoint security, vendor risk, records retention, intellectual property, privacy, incident response, and legal hold.

The evidence chain is the product.

If Karla were advising a client today, I would frame it this way: your AI policy is only as strong as the timeline you can build on a bad day.

What to do this week

1. Build an AI evidence map

List the AI systems and agents that can touch company data.

For each one, capture:

  • owner
  • purpose
  • data classes
  • approval path
  • logging location
  • retention period
  • escalation contact

If any field is unknown, mark it unknown. Do not beautify the inventory.

Trade secrets, employee departures, vendor disputes, breach investigations, and regulator inquiries can all require preservation.

Make sure AI prompts, outputs, tool logs, agent traces, repository activity, device telemetry, chat messages, and document access records are not treated as separate worlds.

They are one evidence story.

3. Test one bad-day timeline

Pick one scenario:

  • developer used an unapproved AI coding tool
  • executive laptop showed stealer indicators
  • vendor certificate trust was compromised
  • departing employee used AI tools before joining a competitor
  • marketing agent changed customer-facing copy without review

Then ask one question: could we reconstruct the first 72 hours from existing logs?

If the answer requires five teams and a prayer, that is the control gap.

4. Stop calling screenshots evidence

Screenshots help humans understand. They are not enough for defensible governance.

Require source logs, timestamps, owners, immutable exports where possible, and a short written explanation of what each record proves.

Client-facing angle

Use this as a quick advisory note for clients experimenting with AI agents:

"Before approving another agentic AI tool, run a 72-hour reconstruction test. If the tool caused a legal, privacy, or security issue today, could you show who approved it, what data it touched, what it changed, and which records prove it? If not, the risk is not theoretical. It is undocumented."

That line will land because it turns AI governance from abstract fear into a practical audit.

The bottom line

The market wants AI systems that act faster.

The law, security teams, and customers will ask whether those actions can be explained later.

The gap between speed and reconstruction is where the liability lives.

Sources