Enterprise leaders should apply employee onboarding logic to AI systems: grant only the access the job requires. Enthusiasm for AI's potential tempts leaders otherwise, but AI has no judgment about what it exposes, only a goal to pursue. And that is exactly why the operating assumption has to be to assume breach: if an AI model has access to critical information, there is no guarantee it won't expose it to someone or something it shouldn't.
AI safety, as practiced today, is a myth: a set of software constraints that can be talked around, retrained away, or simply bypassed. The only real option, and where IT capability maturity can be won or lost, is AI containment. And containment that isn't physically enforced isn't containment at all; it's a policy waiting for the right prompt to route around it.