Resilient Cyber w/ Walter Haydock - Implementing AI Governance
Nov 22, 2024
auto_awesome
In a thought-provoking discussion, Walter Haydock, Founder of StackAware and an expert in AI governance, delves into the key challenges organizations face in AI adoption. He emphasizes the need for robust internal governance and security frameworks, sharing lessons from his fieldwork. A fascinating comparison between U.S. and EU regulatory approaches reveals how differing policies impact innovation and economic growth. Walter also highlights essential certifications for practitioners and offers actionable advice for navigating the evolving landscape of AI security.
Organizations must prioritize establishing well-defined business objectives to create effective AI governance structures and mitigate risks.
Emerging certifications like ISO 42001 are essential for validating responsible AI governance practices amidst evolving compliance requirements.
Deep dives
The Shift to AI Governance
A significant pivot towards AI governance has occurred in the cybersecurity landscape, reflecting the rapid market trends and customer demands. Organizations are increasingly prioritizing governance due to heightened concerns around compliance and the explosion of interest in AI technologies. This shift aligns with the observation that many businesses find themselves facing challenges in adopting AI while ensuring secure and compliant practices. Emphasizing the need to align business objectives before seeking technological solutions, a well-structured governance program is deemed essential for successful implementation.
Understanding Customer Challenges
Organizations at the forefront of AI adoption often recognize the complexities and risks associated with their initiatives, making them proactive in establishing governance frameworks. Many of these sophisticated companies are committed to understanding the inherent risks of AI tools and are eager to implement policies that drive responsible use. In contrast, less prepared organizations may lag in governance, mistakenly prioritizing technology over overarching business goals. Proper guidance strongly suggests that defining business objectives first allows for a more tailored and effective governance structure.
Navigating AI Certifications and Compliance
Various certifications for AI governance, such as ISO 42001 and the HITRUST AI security certification, are emerging as organizations seek to validate their practices. ISO 42001 is recognized for establishing responsible AI governance, promoting compliance and potentially offering safe harbor provisions under certain regulations. Meanwhile, HITRUST focuses on prescriptive controls aimed at protecting data confidentiality and integrity. As businesses navigate a growing landscape of compliance and regulatory requirements, maintaining a strong governance framework rooted in well-defined objectives becomes increasingly crucial.
In this episode, we sit down with StackAware Founder and AI Governance Expert Walter Haydock. Walter specializes in helping companies navigate AI governance and security certifications, frameworks, and risks. We will dive into key frameworks, risks, lessons learned from working directly with organizations on AI Governance, and more.
We discussed Walter’s pivot with his company StackAware from AppSec and Supply Chain to a focus on AI Governance and from a product-based approach to a services-oriented offering and what that entails.
Walter has been actively helping organizations with AI Governance, including helping them meet emerging and newly formed standards such as ISO 42001. Walter provides field notes, lessons learned and some of the most commonly encountered pain points organizations have around AI Governance.
Organizations have a ton of AI Governance and Security resources to rally around, from OWASP, Cloud Security Alliance, NIST, and more. Walter discusses how he recommends organizations get started and where.
The U.S. and EU have taken drastically different approaches to AI and Cybersecurity, from the EU AI Act, U.S. Cyber EO, Product Liability, and more. We discuss some of the pros and cons of each and why the U.S.’s more relaxed approach may contribute to economic growth, while the EU’s approach to being a regulatory superpower may impede their economic growth.
Walter lays our key credentials practitioners can explore to demonstrate expertise in AI security, including the IAPP AI Governance credential, which he recently took himself.
You can find our more about Walter Haydock by following him on LinkedIn where he shares a lot of great AI Governance and Security insights, as well as his company website www.stackaware.com
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode