Eve Goode, Digital Content Editor of ISJ speaks exclusively with Ashish Devalekar, Executive Vice President and Head of Europe at Mphasis.
Can you tell me about the role Mphasis play in the current security market?
At Mphasis, we operate at the intersection of digital transformation, security and emerging technology.
Organisations are under pressure to modernise their operations, adopt AI and other advanced technologies and deliver faster, more efficient services.
Our role in the security market is to ensure that these transformation efforts strengthen overall security and compliance rather than create new vulnerabilities.
Many clients are seeking to automate compliance and security workflows while simultaneously dealing with legacy systems, fragmented data and increasingly sophisticated threat landscapes.
Without a clear governance framework, this combination can introduce significant operational and strategic risk.
Our focus is on enabling organisations to build strong, scalable data foundations, embed policy-driven controls and deploy security-led AI as a strategic enabler of transformation.
A key part of this is establishing an underlying intelligence ecosystem – combining ontologies, knowledge graphs and deterministic reasoning – to ground AI outputs in structured, verifiable logic and capture human decision-making.
We apply this same intelligence ecosystem across our security services to design and deliver robust, scalable solutions, ensuring security is embedded from the outset rather than treated as an afterthought.
We partner closely with security and IT leaders to define integrated strategies, streamline processes and implement tools in ways that are auditable, accountable and aligned to broader transformation goals.
At a time of escalating cyber threats and tightening regulatory requirements, our goal is to ensure technology acts as an accelerator for resilience, agility and innovation, rather than as a bottleneck or source of risk.
By bridging the gap between technology capabilities and operational realities, we help organisations harness AI responsibly while maintaining end-to-end visibility and control over their security and compliance processes, supporting sustainable digital transformation.
Can you tell me the meaning of ‘AI hallucinations’ and why they create the biggest security and compliance risks?
AI hallucinations occur when a system produces output that is confident and persuasive but factually incorrect or unsupported by actual evidence.
This is a pattern particularly common in generative AI models, such as large language models (LLMs), which generate responses based on patterns in their training data rather than verifiable facts.
In the context of security and compliance, AI hallucinations are especially dangerous because incorrect outputs often sound authoritative and well-structured, which can lead humans to trust them without sufficient verification.
For instance, during automated regulatory mapping, an AI might indicate that a control exists or is compliant purely based on the presence of a keyword or phrase in a document, even if the control is not actually implemented or functioning correctly.
Organisations relying on such outputs can develop a false sense of security, which may result in flawed audits, incorrect policy guidance, or unaddressed gaps in risk management.
In practice, this means a company may believe it meets complex frameworks such as the General Data Protection Regulation or SOC2, only to discover during an audit or a security incident that key controls were missing, misconfigured or ineffective.
This is why grounding AI outputs is essential.
By anchoring LLMs within an intelligence ecosystem of structured knowledge and deterministic reasoning, organisations can ensure outputs are tied to defined relationships, rules and evidence rather than interpretation or assumption alone.
The fundamental risk is that AI blurs the line between suggestion and fact.
Security and compliance functions require precision, and errors that go unchallenged can have significant legal, operational and reputational consequences.
Hallucinated outputs, if taken at face value, can therefore lead to serious oversights that compromise both internal controls and external regulatory reporting.
Do organisations over trust AI outputs and why?
Over-trusting AI is a widespread issue, even among experienced security teams.
Mainly because AI outputs are typically fluent, polished and well-structured.
Humans are naturally inclined to equate fluency with correctness, a cognitive bias known as automation bias.
When a report appears coherent and authoritative, there is a strong tendency to trust it, even if it contains factual errors or misinterpretations.
Organisational pressures exacerbate this problem.
Security teams are often expected to do more with fewer resources, creating an environment where speed and efficiency are prioritised over thorough verification.
AI appears to offer a scalable solution, producing comprehensive-looking analyses faster than manual review processes.
The combination of persuasive outputs and operational pressure can lull even senior analysts into complacency, resulting in unverified assumptions being treated as facts.
Where AI is not grounded in a structured intelligence ecosystem, this risk is amplified, as there is limited visibility into how conclusions were derived or whether they are anchored in verifiable logic.
To counteract this, organisations need to cultivate what we call “active scepticism.”
AI outputs should be regarded as draft guidance rather than definitive conclusions.
Every recommendation should be reviewed and validated by a human expert, and clear accountability must be maintained for decisions influenced by AI.
Training staff to understand AI limitations, encouraging critical evaluation and embedding mandatory review processes are all essential steps to prevent over-reliance on potentially flawed outputs.
What does strong governance of AI compliance look like?
Strong governance of AI compliance involves a full-cycle framework that encompasses people, processes and technology.
We typically recommend a phased approach that progressively increases the level of AI autonomy while maintaining human oversight.
In the initial phase, AI acts as an observer, generating recommendations while humans retain full decision-making authority.
This stage establishes a ‘ground truth’ dataset by comparing AI outputs with validated human judgments.
At the same time, an intelligence ecosystem begins to take shape, formally capturing human decisions and translating them into structured, reusable knowledge.
In the second phase, AI is allowed to handle low-risk, high-volume tasks where alignment with human decisions has been proven through testing and validation.
Even at this stage, organisations should introduce adversarial testing to evaluate how the system handles ambiguity and unusual scenarios to ensure the AI captures subtleties and nuances that could lead to compliance errors – while higher-risk decisions remain under human control.
The intelligence ecosystem continues to mature here, strengthening consistency and traceability across decisions.
In the final phase, AI systems can, in tightly governed scenarios, make and execute certain high-risk decisions autonomously without immediate human intervention.
This is only feasible where decisions are fully grounded in the intelligence ecosystem, with deterministic reasoning ensuring outputs can be verified with evidence to ensure it substantiates any claim for how the AI arrived at the decision.
Human oversight remains essential at a governance level, with clear accountability, audit trails and the ability to intervene where required.
How can organisations measure and track hallucination risk effectively?
Measuring hallucination risk must be continuous rather than a one-time exercise.
Two key indicators are particularly valuable in this sense.
The first is Drift Rate, which measures how often AI outputs diverge from human-reviewed assessments of the same data and indicate any likelihood of errors.
The second is Citation Accuracy, which evaluates whether the evidence cited genuinely supports the AI’s conclusions.
These metrics are significantly more meaningful when AI outputs are grounded in an intelligence ecosystem, as this allows organisations to trace decisions back to structured logic, rules and data sources.
By tracking these metrics over time, organisations can establish governance thresholds.
If hallucination rates exceed a predefined limit, AI operations can be rolled back to an earlier phase with stricter controls and human oversight.
Continuous monitoring and feedback allow organisations to calibrate AI systems and governance processes, reducing risk while gradually increasing AI reliability.
This approach ensures that AI becomes a valuable assistant rather than a potential liability in compliance and security operations.
How are regulatory expectations evolving for AI in security and compliance?
Regulatory expectations are becoming increasingly stringent as AI is incorporated into critical operations and heavily regulated industries.
Across major markets like the UK, European Union and North America, regulators have made it clear that AI cannot be used as a shield for poor oversight.
Responsibility and duty of care remain with leadership and their security teams, and organisations can be held liable if AI-generated outputs lead to compliance failures.
In some cases, reliance on unverified AI results could be interpreted as gross negligence.
There is also a growing expectation from regulators that AI-assisted decisions – particularly high-impact ones – are grounded in transparent frameworks with auditable trails and outputs are validated through human review.
Third-party audits and certifications are also likely to become standard practice, as regulators seek assurance that AI systems are reliable and context-aware.
Regulatory guidance is focused on ensuring trust in AI-driven processes rather than restricting innovation, making investment into an intelligence ecosystem that captures decision logic and provides clear traceability critical in meeting these requirements – especially as AI takes on more autonomous roles.
Ultimately, regulation is not intended to restrict innovation but to ensure trust.
Organisations that can demonstrate control, transparency and accountability will be best positioned to scale AI responsibly.

