How Barracuda's CIO developed a flexible strategy for responsible AI

How Barracuda’s CIO developed a flexible strategy for responsible AI

Barracuda’s approach highlights a management issue many IT leaders now face: AI adoption is no longer a discrete experiment, but an operating-model challenge. The most important move is not picking a single “best” tool; it is establishing who can approve use cases, define guardrails, and adapt policy as commercial models and risks change. A cross-functional AI council is useful because it turns AI from scattered enthusiasm into governed demand management.

The harder lesson is financial governance. Consumption-based pricing, agent sprawl, and duplicate tooling can create a shadow portfolio long before finance or architecture teams can measure value. CIOs should treat AI access like cloud spend in its early years: enforce visibility, require approval thresholds, and link experimentation budgets to explicit business outcomes. Without that discipline, “innovation” becomes an uncontrolled operating expense.

There is also a strategic trade-off in staying close to the edge without moving onto the bleeding edge. That means enabling safe experimentation while delaying broad standardization until security, compliance, and cost patterns are clearer. Leaders should ask whether current intake, procurement, and access-management processes are fast enough to keep employees inside sanctioned channels rather than driving them to unsanctioned tools.

The people dimension matters just as much. Responsible AI programs will stall if they are framed only as restriction or only as productivity pressure. Education, role-based guidance, and manager-level accountability are needed to reduce fear, improve judgment, and raise the quality of AI use cases entering the pipeline. The practical next step is to define a lightweight governance model that combines approved tools, spend transparency, role-based access, and targeted training.


 

 

As the finish line in the AI race continues to shift, Barracuda CIO Siroui Mushegian has tried to maintain a competitive pace while keeping an eye on risk.

New AI resources may tantalize workers who want to explore the technology, but they also open the door to shadow IT, runaway costs and other potential headaches for the cybersecurity and network products company.

“Every time I look at the tool set, we have new parameters that we need to ingest and negotiate,” she said.

From there, the company must determine how to roll out the latest tools to end users. That can become complicated in a period of change that moves faster than prior tech evolutions, Mushegian said.

“We have to go faster than we’ve ever gone before, simply because [AI’s] got a popularity to it and a sense of urgency that is different from digital transformations of the past,” she said.

The need for a tempered approach

Beneath that urgency, there is a need for responsible AI strategies to guard against potential internal risks and the unknowns of regulations yet to come. “We’ve seen some behavior in AI models that is less than safe, and I just want to make sure that we continue to use technology that won’t prove concerning to us,” Mushegian said.

She added that she believes the benefits of AI are worth establishing guardrails to address such concerns. For example, AI models could reimagine a company’s day-to-day operations and simplify them.

“It doesn’t involve pulling the guts out of all your go-to-market platforms or all of your business systems,” Mushegian said, “It doesn’t take years of time, and it doesn’t take millions of dollars.”

This new era of transformation could lead to operations that run on less money, with a handful of people in a room working through ideas on a whiteboard with assistance from AI technology. “That gives me a lot of hope because there are a lot of companies out there that are sitting under a lot of weight of technical debt,” she said.

Developing internal safeguards

Though the path forward for AI may change almost daily, Mushegian said she created opportunities for Barracuda’s employees to explore the technology in a safe way. “I want to make sure that we are not falling behind; I don’t want us to be on the bleeding edge,” she said. “But I’m not here to be the anti-fun police.”

Why avoid that bleeding edge? Costly surprises. For example, AI technology that was once license-based might become token-based, Mushegian said, which could lead to burning through cash fast. She added that if she had her druthers with AI, she would like to see more awareness of how expensive tokens can be when users create agents or are about to push workloads through the AI tools in their toolkits. That would include sharing the cost information with the manager or executive who needs to approve the expense before it goes through. “I think that would be wildly helpful for companies that don’t have everything tuned perfectly quite yet,” Mushegian said.

Related:InformationWeek Podcast: Overcoming middle managers’ AI pushback

In recent years, Barracuda instituted an AI council for governance, which she chairs, to establish policies and set the tone for in-house AI use. That led to frameworks to guide employees, but with the flexibility to change those parameters. “They aren’t written in stone; they can be adjusted as necessary when things are adjusted with AI usage itself,” Mushegian said.

Responsible AI usage includes visibility — understanding how staff use data and knowing what their respective roles give them access to, she said. That helps ensure that unauthorized tools are not introduced into the ecosystem and that, when needed, new tools are requested through proper channels.

This internal AI council also includes members from across the company to mitigate shadow AI and prevent the proliferation of duplicate tools. “We have subcommittees for our go-to-market teams. We have a subcommittee for products and engineering,” she said. “We also have a core group that is from compliance and legal where we’re talking about policies in general.”

Accounting for the human element

Along with enthusiasm among staffers to explore AI, there may also be concerns to address among workers reluctant to adopt the technology — possibly out of fear for their jobs. “We want to be able to meet people where they are and help them understand the concepts of AI, provide educational opportunities to them,” Mushegian said. This includes upcoming in-person training plans that would be available through the company.

Even with responsible AI strategies in place, companies may still face external influences on how they use the technology.

“I have a general concern about AI regulation,” Mushegian said. She is watching how AI behemoths with close ties to certain parts of the government and policymakers could influence how regulation takes shape.”I really hope that either there is self-regulation amongst these companies or that there is government regulation over these companies so that we feel like we are using products that are truly safe,” Mushegian said.

Has your organization developed new responsible AI strategies for this new era of transformation? Let us know at [email protected].

Original Post>

Enjoyed this article? Sign up for our newsletter to receive regular insights and stay connected.

Leave a Reply