This article is based on a Q&A with Shawn Surber, Director of Solutions Engineering at Island, as part of Expert Mode from Ai4 2026 in Las Vegas.
Most of us have made a quiet peace with the idea that security’s job is to say no, and that the cost of no gets paid in calendar time. A campaign ships a week late. A tool request sits in a queue behind an eighteen-page vendor questionnaire. Annoying, survivable, and — this is the part that lets marketing leaders stop thinking about it — someone else’s line item.
Shawn Surber thinks we’ve mispriced that badly. Surber is Director of Solutions Engineering at Island, a company that builds an enterprise browser, and he’s spent what he describes as almost thirty years working his way from network security to device management to controls that sit right in front of the person doing the work. Answering questions for The Agile Brand Guide ahead of his Ai4 session on safe AI adoption, he argued that a blocked AI tool doesn’t buy you a delay. It buys you a detour, and the detour is where your data actually goes missing.
The Detour Is the Risk
Nobody stops working because a tool got denied. A copywriter with a deadline and no approved model does not close the laptop and wait for the security review to clear. Surber has watched this pattern long enough that he treats the workaround as the default outcome, not the exception:
“The cost of ‘no’ compounds rapidly. The first thing any creative person does when blocked from access to something is find a way around it. No matter how long security’s ‘not yet’ takes, they’re creating a window where teams go around them rather than through them. That takes longer, wastes resources, and creates a vulnerability where proprietary data may be exposed unnecessarily.”
For marketing specifically, he counts the damage in three places: speed in getting the message out, control over who actually owns that message, and the collaboration that dies when everyone is “quietly working in their own silo.” That last one deserves more attention than it usually gets. When a brand strategist is running a positioning exercise through a personal ChatGPT account and a demand gen manager is doing the same thing in a different tool, neither one can build on the other’s work, and neither result belongs to the company in any way legal would recognize. The team is faster than it was, and the organization is slower. Surber’s framing of the people involved is worth borrowing when you take this to your CISO: they’re not reckless, they’re “hamstrung by their own Security departments.”
“AI You Can See or AI You Can’t”
The argument against a ban isn’t that bans are unpopular. It’s that a ban changes what you can observe without changing what happens.
“The reason ‘no’ is now the more expensive answer is that the risk it’s trying to prevent doesn’t disappear under a ban; it just goes underground. You’ve traded a managed risk for an unmanaged one and told yourself you solved it. The question isn’t ‘AI or no AI.’ It’s ‘AI you can see or AI you can’t.'”
Picture the specific event. Someone pastes an unreleased campaign brief, or a customer list, into a tool nobody approved. Surber’s account of what the company knows afterward is blunt: “no record that it happened, no idea what left the building, no way to reconstruct it later.” Not “we found out late.” Nothing. For a CMO that’s a legal exposure question before it’s a security one — a customer list containing personally identifiable information that moved into an ungoverned model is a GDPR problem you can’t scope, because scoping requires records you don’t have. Q4 pricing, an embargoed product name, the agency’s unreleased creative. Same story.
Locate the Data, Don’t Describe It
Surber’s mechanism is a swap: stop trying to describe your sensitive data and start defining where it’s allowed to be.
“The solution for that is simple, but operationally difficult using traditional data control tools. Those tools require you to define what your important data looks like, which is nearly impossible in almost all contexts. It is much easier to define where your critical data lives and ensure it can only be used within company-sanctioned tools.”
Anyone who’s sat through a data loss prevention rollout knows why this lands. Pattern matching works on things with a shape — a credit card number, a Social Security number. Marketing’s crown jewels have no shape at all. There’s no regex for a positioning document, a launch calendar, or the reasoning behind a pricing change. The location-based approach also changes how the control feels from the user’s seat, which Surber thinks matters more than most security programs admit: done right, it “never feels like surveillance,” and a blocked action becomes a teaching moment rather than a silent denial.
He has an obvious stake here — Island sells the browser layer, and the browser is where his answer points. To his credit, he makes the case for the alternative himself before knocking it down. The network layer, he grants, offers “application-agnostic coverage of user traffic,” and a great deal of AI activity never touches a browser at all: server-to-server API calls, desktop applications, a model running locally on somebody’s laptop, an AI agent making a tool call. Breadth without deployment, as he puts it. His counter isn’t a claim but a question — how much of that traffic can actually be inspected once it’s encrypted and in motion? Worth putting to any vendor in this category, including his.
When the Agent Acts Under Your Brand’s Credentials
Then there’s the shift that makes all of this urgent rather than merely overdue.
“When AI just gave you a wordy response, a bad output was a draft you could edit. When an agent acts on its own, it can send emails, publish content, and spend your tokens without oversight. The blast radius rapidly moves from ‘an employee made a bad decision’ to ‘our brand has been publicly compromised.'”
Surber’s governing principle is that every agent runs on behalf of an identifiable person or team accountable for what it’s permitted to do — the same logic by which a manager owns what their team ships. He’s unsentimental about where the liability sits: “An agent operating under your brand’s credentials is your brand’s action, full stop.” Which makes this a decision rights exercise as much as a security one. If your agentic AI pilot has no named owner per agent, you have an accountability gap that a bad afternoon will find for you. And when it does, what’s in the logs decides who takes the hit. Surber wants those logs to reach further back than most teams build them: good logging captures not just what the agent did but how it was constructed, which is what lets you tell whether the fault was the user’s, the model’s, or your own process.
So the next security meeting shouldn’t open with a request. It should open with two questions Surber suggests putting on the table. First, what can you actually see about AI use right now — would you know if a customer list or an unreleased campaign got out? He’s firm that this “isn’t a policy question, it’s a visibility question,” and if the honest answer is “not much,” that’s your starting point rather than your embarrassment. Second: what’s the fastest path to letting the team keep using AI tools inside guardrails somebody can see and enforce?
As for what you trade away, his answer is nothing you’d miss. Access stays, friction stays near zero, and the only capability anyone loses is the ability to hand sensitive data to a model outside the boundary. One caution before you walk in, though. Don’t ask for a marketing carve-out. Surber is emphatic that governance of AI for marketing has to sit in the same place as governance for everyone else, because separate rules create gaps at the seams — worth pairing with whatever AI governance board your organization already has, or establishing one if it doesn’t. This isn’t a departmental decision, and the fastest way to lose the argument is to make it look like one.





