Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • Home
  • /
  • Interviews
  • /
  • Matt Hillary: AI Won’t Fix GRC Until We Fix What’s Beneath It

Matt Hillary: AI Won’t Fix GRC Until We Fix What’s Beneath It

  • August 13, 2026
TipNew
Matt Hillary: AI Won’t Fix GRC Until We Fix What’s Beneath It

The AI boom has created a new GRC paradox: the more AI organizations deploy, the harder it can become to know what is happening, who owns it, and whether it can be trusted.

Matt Hillary, CISO at Drata, argues that closing this gap starts with visibility and accountability, not another layer of technology. He shares how organizations can bring AI into established processes, define clear boundaries and outcomes, continuously monitor risk, and use automation to keep evidence and controls current. The bigger shift, he says, is moving from point-in-time compliance to continuous trust, where organizations can demonstrate their security and GRC posture every day.


Drata’s latest report reveals that nearly half of GRC professionals say AI has made their jobs harder instead of easier. Where do you think the industry got AI in GRC fundamentally wrong, and why has the expectation-reality gap become so wide?

This is a classic mismatch of expectations versus reality. Many organizations approached AI as a wholesale replacement for day-to-day work without appreciating the input required to instruct it well. They expected AI to fix everything with a few rudimentary prompts, without first grounding it in established processes and reliable data.

AI amplifies whatever environment it's introduced into. If an organization's processes, controls, systems, and data are fragmented, AI exposes those weaknesses faster. We also underestimated the human oversight required to use AI responsibly in security and GRC – this is a discipline built on defensible evidence: process artifacts, system configurations, and honest visibility into weaknesses. The organizations seeing success treat AI as an accelerator for experienced practitioners who understand the end-to-end process and what a right outcome looks like. The gap isn't in the technology; it's in how organizations run the work around it. That gap closes when organizations fix end-to-end process ownership, define outcomes, and establish appropriate oversight.

 

With 71% of organizations reporting AI-related audit failures and 87% lacking confidence in their visibility into the AI tools operating across their business, is today's GRC challenge primarily about technology or accountability? Where should organizations start correcting course?

Honestly, the audit-failure number surprised me. I expected it to be high, but not 71%. Technology certainly plays a role in strong GRC programs, but accountability for the actions, decisions, and outputs of AI is the bigger issue. There's no YOLO when it comes to deploying AI into critical business processes with control points we expect to hold up under the scrutiny of external assessors.

The visibility challenge is real, and AI sprawl is making it worse. We can't secure or govern what we can't see, and we can't assign accountability without ownership. This step is the same step we take as security professionals securing anything: build a comprehensive inventory of AI in use across the business, formally approved or not. From there, establish clear ownership, define acceptable use, and continuously monitor how those systems interact with sensitive data and business processes. Governance has to be built in rather than bolted on and reviewed once a quarter. Visibility creates accountability, and accountability builds trust.

 

Drata positions itself as an Agentic Trust Management Platform designed to operationalize trust. How does that approach translate into continuous compliance and better risk management for enterprises?

The most important job of every security and GRC team is building and maintaining the trust of customers, both internal and external.

Trust isn't earned flippantly, built overnight, or assembled a few weeks before an assessment. It's built through transparency and consistency: continuously validated evidence, controls, and risk mitigation, visible every day. That's what we mean by operationalizing trust at Drata. We connect directly to the systems organizations already use, collect evidence continuously, and validate controls in real time. That gives teams an accurate, day-by-day picture of their GRC posture instead of a snapshot from the last audit or the last control-owner check-in. With AI, agents take on this repetitive manual work, freeing up teams to investigate meaningful risks instead of chasing screenshots or updating spreadsheets or tickets. The result is faster decision-making, stronger assurance, and fewer surprises when customers, auditors, or regulators ask for proof.

 

GRC teams are being asked to manage rising regulatory complexity, AI adoption, and growing workloads without larger teams. How is Drata enabling organizations to scale governance without simply automating existing inefficiencies?

Drata was founded to completely overhaul how GRC had operated for years, with automation at the core, so GRC teams spend less time on manual work such as collecting evidence and more time on higher-order thinking such as understanding and mitigating risks. AI and automation are genuinely effective at repetitive tasks like mapping controls and identifying gaps across large environments, and they put the power of custom automation at our fingertips to eliminate even more repetitive or manual work. Even with flat or reduced team sizes, the goal has been to empower security and GRC professionals with more effective tools and accurate information at the right time, keeping their invaluable human-in-the-loop judgment in play. As a result, GRC teams scale effectively without sacrificing quality.

 

Your report argues that trust should be continuously visible rather than rebuilt for every audit or security review. How is this redefining enterprise trust management, and why will it become the new standard for modern organizations?

The traditional audit model assumes trust is something we prove at specific moments in time, usually annually, but modern businesses move and shift too quickly for that approach to still be effective. AI is helping attackers find weaknesses faster, and it's helping us find them faster too. That means a GRC posture that operates effectively every day matters far more than one that passes inspection once a year. Customers, assessors, regulators, and executive leadership teams increasingly expect organizations to demonstrate that controls are operating continuously, not just during an annual assessment. Continuous trust replaces point-in-time snapshots with ongoing assurance backed by live evidence. When that visibility already exists, responding to a security review stops being a fire drill; we can answer from live evidence, and customers make decisions with confidence. As AI accelerates the pace of business, continuously demonstrating trust will become just as important as continuously delivering software.

 

If you could challenge every board and executive team with just one question about their AI strategy today, what would it be?

The wall of useless metrics has a new trophy: token usage. Instead of counting tokens, I'd ask them to question the intentionality behind the AI capabilities their teams are building, using, and deploying. I'd challenge them to assess the accuracy of their AI inventory, and whether they can confidently identify the accountable individuals when their use of AI makes a decision or takes an action that creates business risk. The answer would quickly reveal whether their AI governance is truly in place or whether the organization is still early in standing it up. Every AI system should be known, have a clearly defined owner, have expected outcomes and documented boundaries, and operate under continuous oversight with measurable controls. Accountability cannot end with the CIO, CISO, CTO, or the technology leadership team. AI now touches every part of the business, and accountability will increasingly sit with the business leaders closest to its use. Organizations that have clear and defined answers to these questions are well on their way to building sustainable trust in their use of AI.

GRC
AI Governance
Cybersecurity
Risk Management
Compliance
Enterprise AI
Trust Management
Responsible AI
  • Share

Matt Hillary is the CISO at Drata – a continuous security and compliance automation company – where he oversees Drata’s global security, IT, compliance, and privacy strategy and programs. With 15+ years of security experience, Matt has a track record of building and leading exceptional security programs. He has been in a number of security leadership roles, including Senior Vice President of Systems and Security and CISO at Lumio, CISO at Weave, VP, Security and CISO at Workfront, VP of Security at Instructure, and other lead security roles at MX, Adobe, and Amazon Web Services. Matt’s areas of expertise include risk management, IT governance, security, compliance, identity and access management, application security, data protection, and much more.

More about Matt:

Drata provides the trust network that enables businesses to operate, scale, and partner with confidence. Powered by AI and designed to operationalize trust, the Drata Agentic Trust Management Platform continuously interprets controls, risk, and assurance signals — reducing repetitive manual work while improving visibility into internal and third-party risk, enabling always-on audit readiness across compliance frameworks, and accelerating security reviews.

Purpose-built for enterprise complexity, Drata unifies governance, risk, compliance, and assurance to deliver faster time-to-value, reduce operational overhead, and enable continuous trust for 8,500+ organizations worldwide.

Learn more at drata.com.