Scott Giordano, former vice president and general counsel for Spirion, discusses the implications of AI for privacy and information security. He explores the development and dangers of generative AI, its impact on cyber crime, and the need for AI regulation. Scott also highlights the benefits of taking a Career Essentials and Generative AI Course.
Generative AI has the potential to significantly impact the world by imitating intelligent human behavior and creating human-directed output based on massive amounts of training data.
Generative AI raises important implications for data privacy and information security, with a need for tight regulation to prevent illegal profiling and adverse impacts on individuals, as well as heightened scrutiny when using sensitive data for training models.
Deep dives
Overview of Generative AI
Generative AI is the capability of a machine to imitate intelligent human behavior. It imitates how human behavior and output looks like, rather than replicating the human brain. The advancement of the internet and digitization has led to the significant progress of AI, particularly generative AI, which requires digital information to ingest. Machine learning, a subset of AI, has been used in various fields, including e-discovery, where it uses examples to train models. Generative AI goes a step further by training on massive amounts of information and creating human-directed output based on that training. It is considered an incredibly powerful technology with the potential to have a significant impact on the world.
Implications of Generative AI for Data Privacy
Generative AI raises important implications for data privacy and information security practitioners. Existing laws regulate profiling and solely automated decisions without human intervention, emphasizing tight regulation. Privacy practitioners have a responsibility to ensure that products or services are not profiling individuals illegally or creating fully automated decisions that may adversely impact individuals. Moreover, using sensitive data, such as medical or children's data, for training generative AI models requires heightened scrutiny to protect privacy rights. The challenge lies in the fact that large language models used in AI training scrape data from the public internet, potentially including children's data. Policymakers, organizations, and practitioners need to address provenance, verifying the legality and legitimacy of acquired data, which aligns with existing principles in privacy laws like the GDPR.
Implications of Generative AI for Information Security
Generative AI also presents implications for information security practitioners. Prompt injection, a potential risk of generative AI, seeks to trick AI models into generating malicious code and bypassing security defenses. While current AI models have safeguards in place, prompt injection can circumvent these defenses. There is ongoing discussion and debate regarding AI's proficiency in scanning code for zero-day vulnerabilities compared to human analysis. However, caution is advised when relying solely on AI for source code analysis, as it presents a potential avenue for exploitation by malicious actors. Information security professionals aiming to specialize in AI must acquire deep knowledge in identifying and mitigating AI-related risks, including novel approaches to security testing and vulnerability analysis. Standards like the OWASP Security Principles for Artificial Intelligence document provide valuable guidelines for securing AI systems.
This episode features Scott Giordano, former vice president and general counsel for Spirion who has more than 25 years of legal, technology, and risk management expertise and was one of the first attorneys to jump into artificial intelligence. We will discuss the implications of AI for privacy and information security, current US state laws, the EU AI Act, and what companies can do to prepare for “AI everywhere.” Scott also discusses the recent “Career Essentials in Generative AI” course he took, which is offered by Microsoft and LinkedIn.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode