You may have approved Copilot for your office, but who approved the AI already running your fleet?
Somewhere in your vendor stack, an AI feature got switched on that most likely nobody even knows about, let alone approved or wrote a governance policy for. It’s probably doing something helpful — like suggesting routes, flagging loads, or reading driver messages and summarizing them for your safety team. The problem is, it just showed up one day inside a tool you trust, and now it’s making decisions inside your operation with no real guardrails or oversight in place.
You Can’t Secure What You Don’t Know
This is a form of shadow AI — and if you run a company right now, you almost certainly have some.
Software vendors are racing to add AI features to everything, and most of them ship those features turned on by default. Think about your ELD platform, your maintenance system, your customer portal, your load-matching tool. NMFTA’s new Cybersecurity AI Governance Framework says the challenge isn’t whether AI becomes part of your operations. It’s whether you have the visibility and the controls to use it responsibly.
“The tools are already there. The governance usually isn’t.”
— Ben Wilkens, NMFTA Director of Cybersecurity
That’s exactly why the framework’s first real step isn’t a security control at all. It’s an inventory. Because you can’t govern what you haven’t found.
Risk Lives in the Gap
I’m not saying all AI is dangerous and you should ban it. AI can save real money through things like faster routing, fewer empty miles, and predictive maintenance that catches a failure before it strands a driver on the road.
Here’s the problem I keep running into as we evaluate the security of these technologies. Most of us don’t know where AI is already running in the tools we use in our operations every day.
The gap — between what you believe and what you’ve verified — is exactly where risk lives.
An AI feature you didn’t choose is a feature you can’t secure. If it makes a bad call and a load gets misrouted, who’s accountable? If it touches driver data and something leaks, whose problem is that? The danger is that it just starts working with no oversight and no secure use policy.
This isn’t just a compliance gap. It’s a real revenue risk.
Where to Start
You don’t need to overhaul all your technology this week. You need a clear answer to one question: which tools, technologies, and vendors are using AI in your business right now?
Start by writing down every vendor partner your company uses: dispatch, ELD, maintenance, customer service, back office. For each one, ask: does this have AI features — and did we ever actually review and approve it?
Once you know what’s there, you get to decide what stays, what gets an AI policy wrapped around it, and what gets a harder look. This isn’t a fear tactic. It’s clarity… and clarity is where true protection starts.
This month I’m walking through exactly what this looks like — from the AI readiness policy most companies haven’t written, to the incident response plan most aren’t practicing. If you’ve never done a real inventory of the AI already running in your operation, that’s where we’re starting.
Let me be clear: AI is a remarkable thought partner. But a thought partner still needs someone doing the actual thinking… and that’s still us. I’m excited about where we’re going. I just want us to get there with our eyes open, not our guard down.
What AI feature are you going to go check on first?
Contact us at ITArchiTeks.com to start the conversation.
Because hope is not a strategy… and proof is how you protect profit.
Written by Melanie Padron
Vice President of Strategic Growth · IT ArchiTeks
Risk Strategist · National Cybersecurity Speaker
Melanie Padron brings nearly three decades of risk management experience, spanning insurance and cybersecurity, to help trucking and logistics leaders validate security posture, strengthen resilience, and protect revenue before pressure reveals what preparation concealed.
She’s a nationally recognized cybersecurity keynote speaker and the creator of two acclaimed talks:
- Surviving a Cyber Crisis: Real Stories. Real Lessons. Real Money.
- Proof to Profit: How Leaders Protect Revenue in the Age of Ransomware and AI
To bring either conversation to your conference, association, or leadership team — visit ITArchiTeks.com or connect with Melanie directly on LinkedIn.
