AI Can Accelerate Decisions—But It Cannot Own Them

GSX 2026 Day Two placed artificial intelligence, data and risk prioritisation at the centre of the security conversation. For Nigerian organisations, the lesson is clear: better security depends not on collecting more information, but on making better decisions with it.

Security teams today have access to more information than ever before. Cameras produce continuous footage, access-control systems record movement, guards submit incident reports, alarms generate alerts and external sources provide threat intelligence.

Yet more information does not automatically create better security.

The central question emerging from Day Two of Global Security Exchange 2026 was not simply how organisations can acquire more data or deploy artificial intelligence. It was how security leaders can make sound decisions when information is incomplete, risks compete for attention and technology can amplify both good and poor judgement.

AI needs a clearly defined purpose

Cassie Kozyrkov’s keynote, Upgrading Your Decision-Making with AI and Data, explored the relationship between artificial intelligence, data and human judgement.

One of its strongest lessons was that AI cannot compensate for an unclear objective. When an organisation has not properly defined what it wants to achieve, technology can scale ambiguity rather than resolve it.

This changes the starting point for AI adoption.

Instead of asking, “How can we apply AI?”, security leaders should first ask, “What problem is worth solving?” and “Which decision needs to improve?”

For Nigerian organisations considering video analytics, automated access control, intelligent surveillance and other AI-enabled security tools, this distinction is important. Technology should be introduced to solve a clearly defined operational problem—not because it is fashionable or because competitors are adopting it.

If the objective is vague, the information is unreliable or responsibility for acting on an alert is unclear, faster analysis may only produce faster confusion.

Human judgement remains accountable

AI can review large volumes of information, identify patterns and help security teams prioritise warnings. It can support tasks such as detecting unusual movement, reviewing surveillance footage, identifying repeated incidents and organising intelligence.

But an AI-generated recommendation is not the same as an accountable security decision.

Human leaders must still determine whether the information is reliable, whether an alert is significant, what consequences may follow and what response is proportionate. They must also establish the boundaries within which automated systems are permitted to operate.

Decision-making should therefore be treated as a deliberately designed system, not as intuition supported by whatever information happens to be available.

For Nigerian organisations, responsible AI adoption should begin with clearly defined objectives, reliable data, decision responsibilities, escalation procedures and standards for reviewing system outputs.

The appropriate question is not, “Where can we install AI?”

It is, “Which security decision needs to improve, and what combination of people, information and technology will improve it responsibly?”

Risk registers must guide action

The Day Two Game Changer session, What to Watch: Mapping Risk Priorities Using ESRM, extended the decision-making conversation into Enterprise Security Risk Management.

Its focus on risk registers, organisational priorities, intelligence and communication addressed a challenge confronting many security leaders: not every risk deserves the same level of attention.

This is particularly relevant in Nigeria, where organisations may face several risks simultaneously while operating with limited security resources.

A hospital may need to consider patient safety, restricted-area access, workplace violence, theft, cyber risk and emergency continuity. A port facility may place greater emphasis on cargo integrity, perimeter protection, insider threats and regulatory compliance. Banks, schools, hotels, estates, energy facilities and event venues will each have different priorities.

Effective security planning must therefore reflect the organisation’s actual assets, operations, responsibilities and exposure.

A risk register should not be prepared merely for an audit and then forgotten. It should identify the risk, the people or assets exposed, existing controls, warning indicators, required actions, the responsible risk owner and the date of the next review.

When operating conditions change, the register must change with them.

Nigeria needs decision systems, not simply surveillance systems

Many Nigerian organisations have invested in cameras, alarms, access-control devices and reporting platforms. Fewer have established a complete process for converting the information produced by those systems into responsible action.

A control room may receive several alerts at once. A guard may report suspicious behaviour. A camera may record an unusual event. An access-control system may flag repeated entry attempts.

What happens next?

Who verifies the information? Who determines its urgency? Who must be informed? Who is authorised to act? How is the response documented, and who reviews the outcome?

Without clear answers, the organisation does not have a functioning decision system. It has disconnected sources of information.

Poor-quality information creates another weakness. Incomplete incident reports, inconsistent dates, missing locations, unverified intelligence and weak record-keeping can mislead both human decision-makers and analytical systems.

Improving decision quality must therefore include better reporting, information verification and data management.

Security technology can only work with the information and instructions it receives. When those foundations are weak, even a sophisticated system may produce unreliable or irrelevant outputs.

Building better security decisions

Before introducing new technology or responding to a security concern, leaders should ask five questions:

  1. What decision are we trying to make?
  2. What information is genuinely required?
  3. How reliable and complete is that information?
  4. Who owns the risk and the final decision?
  5. What action, escalation or review should follow?

These questions provide a practical bridge between AI-assisted analysis and Enterprise Security Risk Management. They can also prevent organisations from investing in technology without first defining its operational purpose.

Security personnel will need broader capabilities to support this approach. Training must extend beyond routine guarding duties to include observation, accurate reporting, information verification, risk awareness, communication, escalation and responsible technology use.

Supervisors and managers must also be able to interpret information, challenge assumptions, communicate priorities and explain the reasoning behind security decisions.

The real capability is responsible judgement

The most important lesson from GSX 2026 Day Two is not that artificial intelligence will make security decisions for us.

It is that organisations must become more deliberate about how decisions are designed, supported and reviewed.

AI can process information quickly. A risk register can organise priorities. Surveillance systems can produce alerts. But leadership must still determine what matters, what action is justified and who is accountable for the outcome.

For Nigeria’s security industry, progress will come from combining appropriate technology with reliable information, capable professionals, clear procedures and responsible leadership.

That is how intelligence becomes action—and how security becomes more effective.

Think Security Differently.