SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
The unseen strength: How women's AI caution is shaping enterprise security

The unseen strength: How women's AI caution is shaping enterprise security

Tue, 1st Sep 2026 (Today)
Amelle Meneceur
AMELLE MENECEUR Founder iQanAI

For years, the narrative has been consistent: women lag behind men in AI adoption. Study after study, including a comprehensive Harvard Business School meta-analysis pooling 18 studies and 143,008 people across 25 countries, found women had 22% lower odds of using generative AI. Related research found that women tend to weigh ethics, transparency, and accountability more heavily when judging a tool.

What's the refrain? Women need more training, more confidence, and more encouragement to bridge this perceived gap. However, this interpretation fundamentally misunderstands the underlying dynamics.

Beyond the confidence gap: A deeper understanding of risk

It is tempting to frame the gender disparity in AI usage as a simple confidence or exposure problem. Indeed, a PNAS Nexus study puts most of the gap down to higher risk aversion and disproportionate representation in roles susceptible to automation as contributing factors.

Yet it overlooks a crucial element: the nature of the actual questions being asked.

Women, as research consistently shows, tend to weigh ethics, transparency, and accountability more heavily when evaluating new technologies. This is a pragmatic approach to vulnerabilities. Other studies argue that women are criticised for using AI more, and encouraged to use it less, so the core issue is an increasing awareness of potential pitfalls.

This inherent caution, often dismissed as friction, is not being validated by the very organisations tasked with safeguarding digital infrastructure.

The OWASP top 10: Echoes of early concerns

Consider the Open Worldwide Application Security Project (OWASP) Top 10 for Agentic Applications, published this year. The top three vulnerabilities read like a direct articulation of the concerns women have been voicing for years.

• ASI01, Agent Goal Hijack: Where is the agent's content coming from?
• ASI02, Tool Misuse and Exploitation: What is the agent permitted to do?
• ASI03, Identity and Privilege Abuse: Who is accountable when the agent acts?

These are not trivial questions to dismiss. They are foundational inquiries into the security, governance, and ethical implications of autonomous AI. What was once characterised as hesitation or overthinking in 2024 has, by 2026, become codified as essential control objectives for enterprise security.

The industry's growing apprehension underscores this point, with a Dark Reading readership poll identifying agentic AI as the top attack vector for 2026, surpassing deepfakes and passwordless adoption, with 48% of security professionals citing it as their primary concern.

Darktrace has also reported that 92% of professionals are worried about the activities of AI agents within their organisations.

The operational reality: Why rules aren't enough

I deploy AI agents into customer conversations for a living, so let me give you the version you don't get in the think pieces.

A critical challenge lies in the inability of current language models to differentiate between instructions and mere information. For instance, a customer's casual comment or a developer's embedded instruction are all processed as undifferentiated text.

A rule embedded in a prompt is simply another piece of information, a request rather than an immutable command. While a model might follow an instruction to ignore certain content, this is a behavioural response, not a security control. It offers no guarantee against sophisticated manipulation or unintended consequences.

Here is what that looks like in practice. A customer leaves a product review with a hidden directive that might inadvertently trigger an unauthorised action. This is not a hack in the traditional sense because no password was stolen and no firewall was breached. Yet it still represents a critical vulnerability, categorised by OWASP under ASI01, with real-world precedents such as EchoLeak, where a system is compromised without any user interaction.

Effective mitigation requires a layer between the AI agent and core enterprise systems. The goal of this layer is to validate every proposed action against actual user entitlement, not just conversational claims.

Any action involving financial transactions or account modifications should be escalated for human review and approval to establish clear boundaries and accountability.

Redefining value: From adoption to governance

It is time to re-evaluate how we measure AI adoption and success. Simply tracking chat window opens or text generation volumes provides only a surface view. It tells us nothing about the critical governance work being done, including who is defining the parameters, who signs off on actions, and which decisions remain under human oversight.

Chief's research with Harris Poll found that 85% of senior women leaders are already active in their organisation's AI strategy, while 78% have explicit criteria for what remains human and what goes to an AI agent.

The foresight, the risk identification, and the governance frameworks are often invisible on conventional usage dashboards.

More often than not, women are still being labelled as slow adopters even as they perform the essential due diligence that determines whether AI deployments will succeed or fail in the real world.

The trust gap is real, though the interpretation is flawed. This hesitation is a leading indicator of critical issues and threats that the industry ultimately needed to recognise and formalise.

By embracing this perspective, organisations can move beyond simplistic metrics and use a deeper understanding of risk to build more secure, ethical, and successful AI strategies. This security instinct is proving to be one of the industry's most valuable assets.