ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The blind spot in your pocket

Sponsored by Vodafone Business and Lookout
Linked InXFacebook
bookmark_borderSave to Library

Why mobile AI visibility has become a boardroom priority

 

Senior leaders from banking, insurance, retail, law and consulting gathered at a recent Vodafone Business and Lookout-hosted breakfast briefing to confront a challenge that many organisations are only beginning to recognise: the invisible proliferation of AI on mobile devices, and the governance gap it creates.  

 

With InfoSec week underway and mounting pressure on organisations to innovate with artificial intelligence, the roundtable discussion revealed a stark disconnect between boardroom enthusiasm for AI and the operational reality of managing it securely, particularly on the devices employees carry everywhere.

 

The mobile phone has quietly become the most powerful – and least governed – endpoint in many enterprises. As agentic AI tools proliferate, capable of sending emails, accessing identity tokens and connecting to corporate systems with full digital authority, security and technology leaders are discovering that traditional approaches are failing to keep pace.

 

“We see a mandate to innovate with AI or get left behind,” one security vendor told the briefing. “But the problem is that enterprises have a simple lack of visibility as to what’s happening with those autonomous agents.”

 

The concern is not hypothetical. Participants described scenarios in which employees install AI assistants on personal devices, feed them confidential documents and blur the line between personal and professional data without any oversight. One attendee described the risk starkly: “You may be working on an Office presentation, and the moment you press a button on your personal AI tool, it just takes that data, and then it’s gone.” 

 

The governance gap

 

Across the table, a consistent theme emerged: speed is outpacing control. A retail brand representative recounted how their American parent company announced a blanket AI rollout with no UK- or EU-specific governance, no data impact assessment and no consideration of regulatory frameworks. “Everyone is thinking about speed,” they observed, “but they are not thinking about the risk.”

 

This tension between innovation pressure and governance reality was echoed by leaders from financial services, insurance and law. A director from a mid-sized law firm highlighted the dual challenge of securing both a corporate fleet and a BYOD environment – incorporating a separate charity where volunteers use entirely unmanaged devices – to handle sensitive casework. “It’s a whole related but slightly different challenge,” they noted. “Security therapy, if you like.”

 

For regulated industries, the stakes are particularly high. A transformation lead from a major global bank pointed to the complexity of operating across multiple territories, where AI governance must account for both emerging technology risks and longstanding regulatory obligations. “The ledger, by definition, is across multiple jurisdictions,” they explained. “We have to be very cautious from a regulatory perspective.”

 

’We don’t know what we don’t know’

 

A recurring theme throughout the discussion was the fundamental problem of visibility. Participants from financial services and retail acknowledged that mobile security often sits far down the priority list, overshadowed by more visible perimeter defences and cloud security.

 

One security leader admitted that while their organisation monitors endpoints rigorously, mobile devices remain largely unwatched. The result: if an incident originates from a mobile device, tracing the root cause becomes nearly impossible. Credential theft attacks via SMS phishing succeed precisely because nobody is looking at that vector.

 

Another participant put it bluntly: it is worse because we do not know what we do not know. The absence of incidents from mobile does not indicate safety – it indicates a lack of detection capability.

 

The challenge is compounded by workforce realities. One retail organisation noted that while senior staff receive corporate devices with management controls, thousands of frontline employees use personal mobiles for authentication and, inevitably, for accessing AI tools. Without mobile threat detection capabilities, these devices represent an unmonitored attack surface.

 

You can’t secure what you can’t see

 

One of the starkest observations came from incident response specialists. Despite widespread concern about AI-related threats, most organisations still struggle with basic visibility on mobile devices. “I’ve never seen an incident happen on mobile,” is a common refrain from security teams. However, as one participant pointed out, when those security teams are asked “Do you look?”, the response is often “No, we don’t really monitor on mobile devices.”

 

This blind spot has real consequences. Attackers have long recognised that mobile is a soft target: a well-crafted text message can harvest credentials that later enable a major breach, and the forensic trail is often cold by the time anyone investigates. “You can’t see an incident if you’re not watching the right place,” a cyber-response leader observed.

 

The challenge is compounded by user psychology. Even on corporate-owned devices, employees often feel a sense of personal ownership. “This is my phone – you can’t put that on my phone,” is a familiar objection, and security teams must balance privacy expectations against the need for corporate governance.

 

Blocking is not the answer

 

Traditional security thinking – “if you can’t secure it, block it” – is proving inadequate in the AI era. Participants agreed that attempting to prohibit AI outright would limit innovation and may simply drive employees to find workarounds, often on personal devices beyond any corporate control, creating even greater risks. “We can’t say no to AI,” one vendor representative argued. “We need to find a way to say yes, but safely.”

 

This is especially pressing as AI evolves from simple chatbots to agentic systems capable of sending emails, accessing identity tokens and connecting to remote services with full digital authority. The risk is no longer just data leakage; it is the complete loss of visibility over what autonomous agents are doing across mobile endpoints.

 

The conversation turned to what “safely” might look like in practice. Guardrails, rather than outright bans, emerged as the preferred model: visibility of which AI tools are being used, on which devices and with what data; policies that respect privacy while still enabling oversight; and governance structures capable of evolving as the technology matures.

 

For many, this means reassessing mobile security policies from the ground up. “What we don’t want is a situation where we’re not aware that data has been mishandled on a mobile device until the audit or the breach notification,” one participant warned. 

 

A problem waiting to happen

 

Despite the evident risks, few organisations have yet experienced a major incident directly attributable to mobile AI misuse. But several participants cautioned against complacency. “I don’t think it’s manifested itself into an incident that you can trace back definitively,” one banking security leader admitted. “But I think it’s a problem waiting to happen.” 

 

Others pointed to the broader context: the basics are still being exploited. Credential theft, phishing and misconfigured access controls remain the dominant attack vectors. AI has not yet changed the fundamentals, but it is raising the stakes and accelerating the pace at which things can go wrong.

 

A sustainability-focused AI specialist offered a different lens, urging the group to consider not just security but the wider costs of AI adoption: environmental, social and economic. “When we think about AI, it’s actually going to cost more than having people to run the jobs,” they observed. “We need to start thinking about all those elements as well.”

 

Finding a way to say yes

 

As the briefing concluded, there was consensus about two key points. Firstly, that visibility is the essential first step. Without the ability to see what AI tools are being used, where and how, governance remains theoretical. The challenge now is to build frameworks that enable innovation without sacrificing control.

 

Secondly, there was a recognition that security teams cannot position themselves as barriers to innovation. The organisations that succeed will be those that enable AI adoption while maintaining appropriate oversight. This requires a shift in mindset; from blocking the unknown to illuminating it.

 

Mobile devices are not going away, and neither is AI. The enterprises that thrive will be those that bring both into the light before the audit, or the breach notification, forces their hand. For organisations navigating this landscape, the message is clear: the device in your pocket may be the most powerful tool in your enterprise, and the one you understand least.


To learn more, please visit: www.vodafone.com and www.lookout.com 

Sponsored by Vodafone Business and Lookout
Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543