For executives, the main issue is not whether to use AI, but how to govern its use across product, privacy and regulatory boundaries. NordVPNโs approach highlights a familiar tension: external LLMs may accelerate delivery, but they also expand exposure to data-handling risk, vendor dependency and explainability gaps. The management question is which workloads can tolerate those trade-offs and which must remain under tighter internal control.
The portfolio implication is that AI should be funded as a capability program, not a one-off experiment. Leaders need a clear split between near-term productivity use cases and longer-term proprietary model development, with different risk appetites, success metrics and approval paths. A useful next question is whether the business can justify in-house AI on cost, latency, privacy or differentiation grounds for each use case, rather than treating all AI spend as interchangeable.
Cross-border digital businesses also need a regulatory operating model that assumes change, not stability. The articleโs point about frameworks and laws shifting quickly suggests that compliance cannot be a periodic legal review; it must be embedded into product design, vendor selection and release governance. That means explicit decision rights for legal, security, engineering and regional business owners when rules diverge across markets.
For boards and leadership teams, the practical test is resilience under uncertainty. Ask: which data can leave the environment, which models can be used externally, what evidence is needed for auditability, and how quickly can the company change behavior if a jurisdiction tightens its rules? The organizations that do this well will not simply be faster with AI; they will be faster without losing control.
Operating digital services across borders means complying with a hodgepodge of laws and guarding against potential threats from many directions. Even for NordVPN, a virtual private network provider, this calls for frequent adaptation — these days at the speed of AI.
Marijus Briedis, NordVPNโs CTO, visited New York recently with a flotilla of company colleagues ย to discuss white hat hacking, the dark web, and the company’s specialty — online privacy and access.
NordVPN, owned by Nord Security of the Netherlands, operates servers in some 118 countries and is one of the largest players in the VPN space. After giving a presentation to a room of journalists, Briedis took some direct questions on the company’s AI strategy and how it navigates the international patchwork of digital regulations.ย
Though NordVPN is still building up its in-house AI resources, Briedis made it clear that the technology would be an important part of the company’s path forward. "If you are not using AI these days, you are basically 20-30% slower than everybody who is using that," he said — the operative word being everybody.
On a prior visit to Silicon Valley’s big players, Briedis said he saw AI used by everyone from company presidents to customer engineers. So, while the full impact of AI remains to be seen, and the duration of its current boom is also unclear (it could last at least another two more years by his reckoning), Briedis stressed that AI’s role in providing a competitive edge is undisputed โ hence NordVPNโs intentions to scale up its in-house development of the technology. "Right now, if you are not using AI, you are behind really, really badly," he said.ย
Related:Why the Old Ways Are Still the Best for Most Cybercriminals
Investing in AI While Prioritizing Security ย
As NordVPN invests more in AI, security concerns, including data privacy and transparency, are top of mind. Briedis explained that NordVPN currently uses local models within its client application and supporting software, ย rather than relying on cloud-based platforms. This approach helps the company operate more efficiently, he said, by reducing latency and boosting user privacyย . "Itโs not so expensive computing, in general," Briedis said.
NordVPN does make use of third-party AI resources at the moment, but its long-term plans point to developing more AI elements in-house. "We are still using external LLMs, but in the future weโre going to introduce ours," he said. Another Nord company, Nexus AI, offers LLM routing and guard railing while NordVPN uses those external LLMs, Briedis said.
Related:5 Best Practices to Ensure Your Business Ecosystem Is Cyber-Secure
As NordVPN deepens its in-house LLM development, there may be a need to ramp up its computational power while also meeting other business needs, he said.
Rapidly Shifting Security Policies and AI Strategyย
In addition to planning for future AI tech needs, NordVPN operates in a shifting landscape of security and data privacy requirements across different nation-states. Briedis said the company has looked to the National Institute of Standards and Technology (NIST) for its robust cybersecurity framework to ensure businesses are secure.
VPNs offer services that can bypass geoblocking and localized censorship controls, ย while also masking users’ private information when they use the web. This can involve defending against bad actors who might strike from around the world and figuring out how to meet different standards for data protection.ย
NordVPN also keeps abreast of the recently released NIS2 Directive, which establishes a legal framework for cybersecurity across the European Union. Briedis said just as threats can evolve, so must security frameworks.ย
"Throughout these past 10 years, everything changed so quickly that I don’t think that we’re going to have one framework that’s going to stay for a longer period than five years," Briedis said.
Related:Translating Cyber-Risk for the Boardroom
Standing Firm on Internet Freedom While Embracing AI Regulationย
NordVPN has rankled certain national governments that are historically not keen on citizens having open access to information. Russia wanted the company, and other VPNs, to block user access to websites that the regime prohibited. Earlier this year, NordVPN shut down its servers in Russia rather than comply.
AI is having its own effect on international policies that govern digital resources. Briedis said developments with AI completely change the security environment and how security should be approached in general, and that may mean new policies on how the technology is used. "Weโre going to have an AI act coming soon in Europe. I’m pretty sure that we’re going to have something here in the U.S.," he said.
The United Arab Emirates already has laws on AI and security, Briedis said. This includes what may be the world’s first policy to regulate the use of AI in national elections. Under the National Elections Committee Policy on the Use of Artificial Intelligence, national campaigns in the UAE must register their use of AI.
Briedis seemed eager for the challenge of this evolving space, where breakthroughs in AI and new regulations may be part of the controlled chaos.ย
"The main thing here — and that’s why I’m in cybersecurity honestly — is because the field is changing constantly, you have to adapt; this is so exciting. That’s the thrill of it," he said.
Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

