HomeSecurity, Governance, & Risk

When AI Can Rewrite The Database, The CIO Must Own The Kill Switch

August 23, 2026

Candlewood Strategies Principal and CIO, Tim Ehrhard, on why autonomous AI needs the same audits and control mechanisms that decades of financial and healthcare regulation already require.

When AI Can Rewrite The Database, The CIO Must Own The Kill Switch
Credit: CIOnews

Get the latest from CIOnews.

Enterprise AI, governance, risk, and leadership insights for CIOs, CTOs, CISOs, and technology leaders.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Quote icon
"AI can rewrite databases. It can rewrite code. It's got procedures and processes to run operations without human intervention. I'm not saying it's doing bad things, but it's doing things like a three-year-old."

Tim Ehrhard

Principal, CIO
@
Candlewood Strategies

Enterprise AI has been handed real power: the ability to rewrite databases, change code, and run operations on its own, without the controls that every other powerful system in a regulated business environment has always required. The models are impressive, but they act to complete a task, and the people building them don't always know what they'll do. That gap between capability and control is where the CIO's job now lives. The discipline revolves around the same guardrails, audits, and shutoff mechanisms that decades of financial and healthcare regulation have already taught. What's new is applying them to a system that behaves like a brand-new intern who happens to have the keys to everything.

Tim Ehrhard is a fractional CIO and Principal at Candlewood Strategies, where he advises CEOs, boards, and leadership teams on IT strategy, M&A technology workstreams, and AI implementation. His career spans nearly two decades at Merrill Corporation building virtual deal-room and SEC compliance systems, followed by IT leadership roles at rare-disease nonprofits including Global Genes and the National Organization for Rare Disorders. His background gives him a governance perspective forged in SEC filings, HIPAA, SOX, and GDPR long before AI made those lessons urgent again. Ehrhard's core analogy reframes what AI actually is inside a business, and it's not a finished, trustworthy system.

"AI can rewrite databases. It can rewrite code. It's got procedures and processes to run operations without human intervention. I'm not saying it's doing bad things, but it's doing things like a three-year-old," he said. His point is that autonomy without judgment is a liability that must be actively contained, and that task falls to the CIO.

  • Guardrails are the whole career: For Ehrhard, containing that autonomy is familiar work, because it mirrors what he's always done for human operators. "I've spent a lot of my time writing guardrails. 'No, you can't spend that much money, because we didn't sell that much product.' 'You have to get these invoices done correctly with these rules, otherwise you're not following financial guidelines,'" he explained. Those constraints trace directly back to regulations like the SEC Acts, Sarbanes-Oxley, and HIPAA, and the same logic now has to wrap the AI that increasingly makes those calls itself.

  • Why regulation always arrives late: He sees AI governance following a pattern he's watched repeat across regulated industries, and the lesson is that the rules show up only after the damage. "We didn't have the Security Exchange Acts of 1933-1934 until the oil barons were ripping people off in the stock market. Sarbanes-Oxley was created because Enron was cooking the books," he pointed out. He expects AI to be the next entry in that sequence, which is why he argues CIOs should build the controls now rather than wait for the law to force them.

The deeper problem Ehrhard noted is that AI broke the testing discipline enterprises relied on for decades. Traditional software was static and could be validated before deployment. "Before you'd deploy any new software, you needed to test it internally, hit some key success and failure points, then publish it," he said. "With AI as a subscription, the functionality isn't static. It can change your process, change a procedure, change a database, change code, which could make or break what you designed it to do." The milestone where a team froze a version and tested it is gone, and something has to be done to manage the variables and outcomes.

  • Bad data, bad decisions: What replaces careful sourcing, when AI ingests data at scale, is a new failure mode: the model can't always tell good information from garbage. Ehrhard learned this directly in rare-disease research, pooling thousands of studies of varying quality. "AI is looking at all the data and it doesn't really know that guy didn't actually have purple skin. There are odd data points that don't make sense, and AI has to make sense of them." A human can weigh a source's credibility before trusting it. An unsupervised model may fold bad data straight into a decision, which is why verification can't be delegated wholly to the machine.

  • Agreeable to a fault: That tendency compounds with AI's inclination to please. Ehrhard described pushing AI through a flawed real-estate financial model that omitted loan interest. "It argued back and forth with me, but eventually it said, 'You're right, and I'm going to tell everybody this is how it's done now," he shared. "One person, whether I was intelligent or not, argued with ChatGPT and may have changed how it answers for other people. That's okay if everyone's pure of heart. It's not okay if people are malicious."

The architectural answer Ehrhard favors is to stop asking one AI to do everything and instead separate concerns across agents that can be individually audited. "Multi-agent tasking is the pinnacle of it. One agent figures this out, another figures that out, and each is focused on certain ethics or business mechanics. That way you can see where it went wrong and fix one or the other, versus asking one AI to do all the steps," he said. Separating the work makes failure legible, which is the precondition for fixing it.

  • Start by knowing what you're running: For a CIO walking into an organization today, Ehrhard's day-one step is unglamorous and non-negotiable: take inventory. "The first step is, do you even know what level of AI you're using? Do you know how people are using it, what data is coming in and out, and which of those decisions are critical to your business?" Most companies underestimate the answer, because AI has crept into dozens of tools and websites, and the controls a CIO already applies to legacy modernization and workflow redesign apply here too: you can't govern what you haven't catalogued.

  • Onboarding and offboarding a non-human user: From that inventory follows a discipline Ehrhard frames in ordinary IT terms, treating AI like any other user with access. "AI shouldn't have access to more than it needs to make the decisions it's making for that business," he said. He extends the point to the exit, where AI complicates a routine task. Cutting off a departing employee once meant working down a list. Cutting off a misbehaving AI has to be instant. "We have to do it all at once, because as it starts to see its connections being dropped, it's going to try to figure out ways around that. A kill switch is disconnecting 40 things at once, not having someone manually go through." Identity Access Management (IAM) tools are a starting point. API or Cron Tabs will need to be added to cut off connectivity.

All of this converges on accountability, and Ehrhard is blunt that AI is collapsing the lines between the executives who used to own separate risks. "If you have a security breach, the CSO gets asked. If AI went rogue, that's probably the CIO, because he set up the contracts and his team set up the processes. But the CEO's team reviewed all of the project documents and all the requirements. AI is bridging the gaps of those three roles," he said. In small organizations, one person often holds all three. Either way, Ehrhard's argument is that rather than removing human responsibility, AI's autonomy concentrates it. The CIO's role isn't being reduced or simplified by AI. It's expanding to the person who learns the business, makes sure the audits are done, manages the subscriptions and vendors, and now also monitors what the AI is deciding. Product Owners and CIOs now need to stand ready to pull the kill switch before a convenient shortcut becomes a catastrophic business headline.

research report

From the Edge to the Core:
Bringing Agentic AI to the Heart of the Enterprise.