UNSCRIPTED | Episode 376
Dr. Aymen Gatri, Professor of Cybersecurity and AI Defense and Director of PMO Products at Konecranes, joins Sarah Nicastro to add a layer of pragmatic necessity to the AI buzz and make the case for why AI defense deserves as much attention as AI offense.
This episode is not about dampening excitement around AI’s potential. Aymen Gatri makes that clear from the start. The opportunity is real. The urgency is real. If organizations don’t engage with AI now, they will fall behind. The point of this conversation is something different: making sure that the genuine excitement around what AI can do doesn’t obscure a clear view of what organizations need to prepare for.
Aymen brings an unusual combination of perspectives to this conversation. He teaches cybersecurity and AI defense at the Digital Business University of Applied Science in Berlin. He also works in aftermarket service at Konecranes. The intersection of those two worlds is where the most important, and least discussed, risks to service organizations live.
The Gap Between Hype and Opportunity
Aymen’s framing of the risk is precise. There is hype around AI. There is genuine opportunity. The gap between those two things is where risk lives. Organizations that rush into AI adoption because everyone else is, because the PR is overwhelming, or because the excitement has outrun the analysis, those organizations are taking on risk they haven’t priced in.
The core case for AI in service is clear. The field service workforce shortage is real, growing, and not going away. AI’s ability to capture knowledge, distribute expertise, and support technicians in the field addresses something that was previously very hard to address at scale. First-level support, second-level support, knowledge transfer, technician guidance, these are the use cases that make immediate sense, and where the benefits are already visible.
“There is so much PR around AI. Is this hype, or is this a chance? Or is there a gap between both? That gap is where the risk exists.” — Dr. Aymen Gatri
The Three Moves and Where the Real Risks Begin
Aymen’s framework for understanding AI risk in service is structured around three moves. The first move is using AI as a tool: knowledge management, first-level support, decision assistance. This is where most organizations currently are, and where the risk is manageable.
The second move is where the risk profile changes fundamentally. When AI transitions from assisting decisions to making them, when AI agents start to act autonomously on behalf of the organization, questions of governance and accountability that haven’t been answered yet start to matter enormously. Who is accountable for what the agent does? Who owns the data it touches? What happens when it hallucinates in a mission-critical context?
The third move, where AI agents are making complex service decisions with significant operational or financial consequences, is where the risk is greatest and where the least preparation has been done.
“Starting from the next move, it’s not just an AI system doing service instead of several people. It is an AI agent that is asking, questioning, thinking, doing, reflecting, and maybe deciding. And this is where we start to encounter risks we haven’t considered.” - Dr. Aymen Gatri
Cybersecurity, Data Ownership, and the Usability Risk
The cybersecurity risk in AI adoption is not theoretical. In Europe, there are already significant regulations around product cybersecurity, organizational cybersecurity, and critical infrastructure and the AI layer adds complexity to all of them. Organizations implementing AI systems are creating new vectors for data exposure, and in many cases they haven’t mapped the data lifecycle clearly enough to understand what is being accessed, processed, or shared.
The usability risk in aftermarket service is equally significant and less widely discussed. An AI agent that isn’t governed well can make its own service decisions, discounts, escalation paths, recommendations, in ways the organization didn’t intend and can’t control. The reputational and financial exposure from that is real, and it can move fast.
There is also a trust dimension that mirrors what the service industry experienced with remote access a decade ago. Customers who were resistant to allowing remote access to their machinery are now being asked to trust AI agents with even greater access and autonomy. That trust has to be earned incrementally, built on a foundation of data privacy and cybersecurity assurance. Organizations that rush past that foundation are taking a risk with the customer relationship that is hard to recover from.
“Consider that you have an AI agent which maybe you don’t know how to control. How will customer acceptance be? This journey is not an easy journey. It’s not a quick journey.” - Dr. Aymen Gatri
AI Offense and AI Defense
The framing that sharpens everything in this conversation is the distinction between AI offense and AI defense. AI offense is what most organizations are currently focused on: implementing AI capabilities as quickly as possible, capturing the opportunity, keeping pace. AI defense is what most organizations are not focused on: building the governance, accountability, and risk management structures that make sustainable AI adoption possible.
Sarah’s basketball analogy lands well here. Offense gets the glory. But defense wins games. An organization that builds impressive AI capabilities without an equivalent AI defense capability is vulnerable, to data breaches, to hallucinations with real-world consequences, to regulatory exposure, to loss of customer trust, and to governance failures that become visible only when something goes wrong.
“AI defense is about building a very important strategy for implementing AI. You want to defend your business, your information, your privacy, your intellectual property. This is the strategy that allows you to take the opportunity while keeping the risk under control.” - Dr. Aymen Gatri
The Role of Governance and the CISO Parallel
Aymen’s recommendation is that organizations need a dedicated governance role for AI, someone whose job is not to build AI systems, but to hold the strategy for how AI is implemented, what risks it introduces, and how those risks are managed across the business. He draws the parallel to the Chief Information Security Officer role, which emerged as cybersecurity expanded from an IT function into a cross-organizational strategic concern.
Sarah pushes back thoughtfully on whether a standalone Chief AI Officer is the right structure, raising the risk of silos and the importance of AI literacy as much as AI execution capability. Aymen’s response is that the need isn’t driven by hype: it’s driven by risk. The role exists to provide a home for accountability, governance, and strategic vision, not to build things, but to ensure the organization knows what it is building toward, and what it is building against.
The message both agree on: organizations don’t have to build every AI capability themselves. The solutions exist. What they need to build is the internal capacity to evaluate them intelligently, implement them responsibly, and govern them continuously.
“Risk is not constant. Risk is variable. You never know how big the risk could be. Nevertheless, there is always a huge opportunity beyond the risk. So adapt — with a strategy behind that adaptation.” — Dr. Aymen Gatri

Follow Sarah on LinkedIn for daily insights, behind-the-scenes reflections, and the conversations shaping the future of service.
Connect with Sarah Nicastro on LinkedIn
Follow Future of Field Service on LinkedIn for new articles, podcast episodes, and event updates as they go live.
Follow Future of Field Service
Subscribe to The INSIDER - our monthly newsletter with exclusive content you won’t find anywhere else.

Join us at Future of Field Service Live London on 24 September. A day of conversation, insight, and community with service leaders across industries. Register here.