- The signal coming from Google Cloud
- What changed in the AI security landscape in 2026
- Direct impact on Italian SMEs during AI adoption
- Three areas for immediate action by company leaders
- The role of digital strategy in AI security
- What vendors don't openly say
- Outlook: where AI governance is heading in 2027
Francis de Souza, Google Cloud COO, publicly stated that AI security cannot remain confined to technical teams. It must be brought to the board of directors' agenda. This signal comes at a time when many Italian companies are bringing AI into production without structured governance.
Therefore, the issue isn't just about firewalls and vulnerability assessments. It's about who makes the strategic decisions on AI adoption, what risks are accepted, and with what awareness. In fact, a poorly governed AI model can cause reputational, legal, and operational damage that no IT department can handle on its own. Plus, the European regulatory framework — with the AI Act already in force — adds direct responsibilities for top management.
In this scenario, we at SHM Studio we notice a recurring gap in Italian SMEs: AI is adopted at the operational level, but a governance vision involving management and ownership is missing. Therefore, de Souza's indication is not just a statement of principle. It's a hands-on reminder for anyone integrating AI tools into their digital stack. In this article, we look at what changes, what impact it has on SMEs, and what practical steps to consider.
The signal coming from Google Cloud
Francis de Souza, Google Cloud Chief Operating Officer, made clear statements: AI security must be a boardroom priority, not just a technical issue left to the server room. As reported by The Decoder in an article published in late May 2026. The message is straightforward and hard to ignore.
However, for many organizations—especially Italian SMEs—this is a massive paradigm shift. Until now, cybersecurity was seen as a purely technical domain. Therefore, moving it up to the C-suite level takes a cultural reboot even before a technological one.
Plus, the context in which this statement comes out is far from neutral. Google Cloud competes directly with AWS and Azure for enterprise AI infrastructure governance. So, de Souza is also speaking from a commercial interest standpoint. Even so, the message's core point remains valid and urgent.
What changed in the AI security landscape in 2026
2025 saw an acceleration in the adoption of AI tools in production. Many companies have integrated language models, predictive automation, and recommendation systems into their operational workflows. As a result, the attack surface has expanded significantly.
In fact, the risks linked to AI are not just traditional cybersecurity ones. They include prompt injection, data poisoning, hallucinations with decision-making impact, and systemic biases. These phenomena cannot be managed with an antivirus. They require policies, human supervision, and clear organizational accountability.
In particular, the European AI Act has introduced specific obligations for high-risk AI systems. Responsibilities fall directly on company management, not tech vendors. So, AI governance is no longer a choice: it's a regulatory requirement with real legal implications.
Direct impact on Italian SMEs during AI adoption
Italian SMEs find themselves in a delicate position. Many have started AI projects—chatbots, process automation, predictive analytics—without setting up parallel governance. Therefore, the risk isn't just technical: it's strategic and reputational.
For example, a retail company using an AI system for inventory management or customer recommendations needs to know who is on the hook if the model gives wrong outputs. Similarly, a B2B small business automating lead qualification with AI has to figure out who is supervising those algorithmic decisions.
We at SHM Studio we notice this gap cuts across all industries. It is not just about big corporations. In fact, smaller businesses are often more exposed because they lack dedicated tech compliance teams. So, the point raised by de Souza is spot on for the kind of chats that should be happening in Italian boardrooms today.
According to McKinsey Global Institute , organizations that integrate AI governance at the executive level record higher adoption rates and significantly fewer incidents. Plus, they show a greater ability to scale pilot projects into stable production deployments.
Three areas for immediate action by company leaders
Translating de Souza's message into concrete actions requires identifying priorities. Below are three areas that decision makers should focus on immediately.
- Ownership of AI governance: every live AI project must have a dedicated leader named at the management level. The IT contact person is not enough. You need someone with decision-making power and a clear view of the business impact.
- Mapping of model-specific risks: not all AI systems carry the same risks. A generative model has different weak spots than a classification system. So, risk assessment needs to be detailed and up to date.
- Training for non-technical management: company leaders don't need to become AI engineers. However, they must understand risk mechanisms to make smart choices. Investing in AI literacy sessions for the C-level is a key strategy today.
These actions naturally fit into the pathways of AI consulting that we propose to SMEs, where technology adoption is always accompanied by a governance framework suited to the organizational context.
The role of digital strategy in AI security
A common mistake is treating AI safety as something separate from your overall digital strategy. Actually, the two areas are deeply connected. In fact, architectural choices, the vendors you pick, and the data used to train the models directly shape your organization's risk profile.
For this reason, AI governance should be an essential part of any plan for Digital marketing and digital transformation. For example, a company using AI for ad campaign management — via Google Ads or LinkedIn Ads — must also consider the risks related to automated profiling and algorithmic transparency.
Likewise, anyone integrating AI into their process of content creation or of SEO must define clear policies on data use and editorial supervision. Finally, even the web presence — from the structure of the company website to integrations with AI systems — falls within the governance scope that needs to be managed.
What vendors don't openly say
There's an angle that deserves a critical look. The big cloud platforms—Google, Microsoft, Amazon—have a direct stake in pushing AI governance. The more companies set up formal processes, the higher the demand for enterprise tools to manage, monitor, and audit AI models. These tools are precisely what those vendors sell.
However, this doesn't invalidate the message. In fact, the fact that major market players are pushing for AI governance is a sign of the industry maturing. It means the issue is real, urgent, and bound to become an operational standard. Therefore, small and medium enterprises that take early action today will have a competitive edge over those that wait for regulatory pressure.
In short, AI governance is not a cost to bear: it is an investment in organizational resilience. Companies that integrate it now will be better positioned when regulatory requirements become stricter—and they will, as confirmed by the evolution of European approach to artificial intelligence .
Outlook: where AI governance is heading in 2027
Looking ahead to the next 12-18 months, it's reasonable to expect AI governance requirements to become increasingly formal. By the way, the first penalties linked to the European AI Act will start rolling out, setting precedents that will shape corporate practices even beyond the directly penalized cases.
Furthermore, AI governance frameworks will progressively become a standard in tenders and due diligence. SMEs that want to work with large clients or access international markets will need to demonstrate that they have documented processes. Therefore, getting structured today also means opening up commercial opportunities tomorrow.
To learn more about how to structure a digital strategy that includes AI governance, you can contact the SHM Studio team or check out the in-depth articles on our blog . Every AI adoption project we follow starts with a clear definition of responsibilities, risks, and business goals — even before choosing the model or platform.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.