As enterprises accelerate the adoption of artificial intelligence and digital workflows, cybersecurity leaders need to expand their focus beyond conventional infrastructure security to address risks emerging across AI systems, identity governance and contract processes, participants at an ETLegalWorld webinar said.
The discussion took place at the ETLegalWorld and ETCISO webinar, “The CISO’s Blind Spot: AI, Identity and the Gaps in Your Contract Workflows,” held on August 20 in collaboration with Zoho Sign.
The session brought together cybersecurity, technology and security leaders to examine how AI-driven automation is reshaping identity and access management, while increasingly digital contract processes are creating new security, compliance and operational risks.
The panel featured Chandramouli Dorai, Chief Evangelist, Cyber Solutions and Digital Signatures, Zoho Corporation; Yogesh Kulkarni, General Manager, Regional CISO – Intellectual Property and Head of Cyber Security Resilience, Wipro; Dr Uttam Kumar, Chief Information Security Officer, Tata Digital; Ravi Kanth Chava, IS/IT Security and Compliance Lead, Nestlé; Goutam P., Chief Information Security Officer, Page Industries; and Sandeep Jamdagni, Head of Information Technology and Security, Central Park.
A key theme of the discussion was the changing nature of enterprise identity as AI systems and agents increasingly participate in business processes. Traditional identity and access controls, designed primarily around human users, need to evolve to account for systems that can access data, initiate actions and operate with varying degrees of autonomy.
The speakers also examined the risks associated with employees using consumer or free AI tools for business purposes, including the challenges of maintaining visibility and governance when AI adoption happens outside formally approved enterprise platforms.
Another focus was third-party and supply-chain risk. As organisations increasingly rely on external AI models, platforms and technology providers, security teams need greater visibility into the technologies, data and controls underpinning those services.
The panel also highlighted the growing security implications of digital contract workflows. Contracts increasingly involve multiple users, systems and third parties, making identity verification, access permissions, approvals, electronic signatures and audit trails important components of the overall security architecture.
From a legal and compliance perspective, the discussion examined issues organisations should consider when entering into agreements with AI vendors, including data ownership, intellectual property, model training and accountability for outcomes generated or enabled by AI systems.
The convergence of security, legal and technology responsibilities emerged as another important consideration. Rather than treating contract security and AI governance as separate functions, organisations need closer coordination between CISOs, legal teams, IT and compliance functions to establish clearer ownership of risks.
The webinar also addressed the challenge of supporting business-led AI adoption without turning security controls into a barrier to innovation. The discussion emphasised the need for organisations to build security and governance into AI-enabled workflows while retaining the agility required to scale useful applications.
The session concluded with a focus on preparing organisations for the next phase of AI adoption, particularly as AI agents gain greater autonomy and become embedded across enterprise processes.
The webinar was part of the Legal Security Counsel series, which focuses on the convergence of cybersecurity, legal operations, identity and digital trust.


