HomeSecurity, Governance, & Risk

'Secure, Don't Block' Turns AI Governance Into A Business Partnership For Retail Security Leaders

August 30, 2026

Mark Alvarado, Executive Director of IT Security & Compliance at Academy Sports + Outdoors, on governing AI as a hybrid workforce that needs both people and system controls.

'Secure, Don't Block' Turns AI Governance Into A Business Partnership For Retail Security Leaders
Credit: CIOnews

Get the latest from CIOnews.

Enterprise AI, governance, risk, and leadership insights for CIOs, CTOs, CISOs, and technology leaders.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
AI isn't just another application. Governing it requires blending the technical controls you use for systems with the identity, access, and privilege management frameworks you use for people.

Mark Alvarado

Exec. Dir. of IT Security & Compliance
@
Academy Sports + Outdoors

Most security teams meet a powerful new technology the same way: they classify it as an application, slot it into the existing review queue, and decide whether to allow it or ban it. That reflex breaks down with AI, because the thing being governed doesn't behave like software. It acts more like a workforce, and a workforce with system-level speed and no conscience demands a different kind of control.

Mark Alvarado is Executive Director of IT Security & Compliance at Academy Sports + Outdoors, one of the nation's largest sporting goods and outdoor retailers. He brings more than two decades in IT, including over a decade specializing in cybersecurity, digital risk management, and regulatory strategy. His view starts by refusing the category the rest of the industry reaches for.

"AI isn't just another application. It's a hybrid, like an android or a digital person. Governing it requires blending the technical controls you use for systems with the identity, access, and privilege management frameworks you use for people," Alvarado said. AI's hybrid nature calls for both control sets at once, which means it doesn't fall cleanly into any bucket organizations are used to dealing with.

  • One system, two sets of controls: Under Alvarado's framing, organizations must govern AI as a person and a system simultaneously. That approach is unforgiving of existing weakness. "If an organization didn't already have a strong identity, access, and privilege access management program, and then you throw an AI into the system, it finds ways to slip into the cracks," he said. He reaches for Enron as the cautionary pattern: an organization that operated across multiple energy categories at once, fit no existing regulatory model, and went unchecked long enough to do real damage. AI can occupy that same blind spot, getting away from you and wreaking havoc if left ungoverned.

  • Secure, don't block: The instinct to ban a new tool outright is the instinct Alvarado most wants security leaders to resist, because blanket bans don't hold. Employees can reach capable AI on their smartphones and laptops, and a workforce that doesn't respect the organization's security program starts working around it. "Shadow IT is already a problem. AI would make that fundamentally worse, because there's a lot of business value in AI and people can get it for free on their own devices," Alvarado said. Blocking, in his read, only converts the risk into something more sophisticated and harder to see. The alternative is a governance framework that sets clear expectations up front, so employees know the guardrails rather than guessing at them.

Least privilege is harder to apply to an agent than to a person, because delegation is the entire point of the tool, and an agent has no job description or conscience to bound it. Alvarado scopes it with a short set of questions asked before access is granted. "You ask what kind of data it needs to talk to, what systems it needs to interact with, and what you're going to use it for. Those fundamental questions determine the amount of access it should have," he explained. Regulated or business-critical data pulls an agent into tight guardrails immediately. Trivial, non-critical data with no external reach earns a lighter touch. The questions set the priority, and the priority sets the controls.

  • The seasonal clock adds pressure a bank never feels: Since retail concentrates its financial year into a handful of peak windows, the calendar changes the governance conversation. When a season can define the year, the pressure to rush a system into production climbs. "When you're in an industry where seasons are so critical for making the majority of your money, then there's absolutely the urge to rush something to get in place," Alvarado said. But the work AI requires doesn't compress on demand. Contractual terms, indemnification, environment testing, and post-launch validation all have to happen before a publicly traded company connects something new to its systems, and the parties involved rarely share the same sense of urgency.

  • Pushing back by partnering, not by saying no: The resolution, according to Alvarado, is negotiation rather than refusal, because a security team known as the department of no is the team that breeds shadow IT. He would rather be a business enabler who moves in parallel with the business than a gate it learns to route around. "I like to partner with them and say, 'Help me help you. But here's what I need to work in parallel with you to make sure that while we're bringing money in the front door, the bad actor is not stealing it out the back door,'" Alvarado said. That partnership is built across the whole year, not summoned at the moment the pressure spikes, and it leans as much on people skills and a willingness to compromise on upstream or downstream controls as on any technical fix.

As for the popular line that AI is just the next cloud or the next web, Alvarado only half agrees. "It's true that AI is nothing new, but it's everywhere," Alvarado said. The attack techniques, for example, aren't new, and the foundational domains that frameworks like NIST outline still hold. What has changed is availability and velocity. He points to recent demonstrations where a capable model, with its guardrails removed, executed traditional attack methods at a speed far greater than anyone anticipated, and investigators struggled to reconstruct afterward what it had actually done. "It didn't really do anything new. It used traditional techniques and attacked the traditional areas in an IT system that a bad actor would use. But it did it exponentially faster than anyone expected," Alvarado said. The same capability is available to defenders, and its speed makes mature identity, access, testing, and cybersecurity controls more necessary, not less.

For a retailer whose calendar leaves little room to slow down, there's a balance Alvarado keeps returning to: govern AI as both a person and a system, keep it inside guardrails rather than outside the fence, and treat the business not as an adversary to be blocked but as a partner to be moved alongside, quickly and with the controls that let speed stay safe.

research report

From the Edge to the Core:
Bringing Agentic AI to the Heart of the Enterprise.