Загрузка...

AI Incidents Aren’t Like Cyber Incidents: Governance for the New Failure Modes. Ray Orife

In this episode, Mike Bursell speaks with Ray Orife about what AI governance looks like when real systems hit real constraints: unclear accountability, agentic chains, "AI incidents" that don't behave like classic security incidents, and why AI-specific testing is now non-negotiable.

Ray explains how governance is evolving from policies into assurance: due diligence that stands up to customer scrutiny, regulator expectations, and supply-chain pressure, especially as organizations deploy AI without fully understanding how it behaves in production.

Key topics
- Why AI is not "just another SaaS tool" (autonomy changes the risk profile)
- Agentic AI: compounding failures across multi-step chains
- AI incidents: hallucinations, bias, and customer-facing blowups
- Practical due diligence: contracts, data processing terms, restricted transfers, DPIAs
- The trade-off: improving models vs. keeping customer data protected
- Why "AI-specific penetration testing" matters (prompt injection, model takeover, and data leakage)

Guest
Ray Orife - Head of Data Protection & AI Governance at Evalian

Host
Mike Bursell - Advisor, Super Protocol

Timecodes:

00:50 Cold open: what Evalian does + why AI governance exists now
01:50 What a SOC is (and what it’s for)
03:21 “Techie enough to be dangerous”: Ray’s operating mode
04:19 From solicitor to Data Protection Officer (DPO)
06:10 Pre-GDPR reality → GDPR implementation roles
10:02 Why AI entered the practice: client demand + supply-chain pressure
11:36 DPO-as-a-Service at scale: how they operationalize governance
13:00 What clients ask about AI (builders vs users)
14:28 Why AI ≠ SaaS: autonomy + unpredictable outputs
15:20 Governance landscape: Ray flags the EU AI Act and global divergence
17:02 Why “best practice” is still early: goalposts keep moving
18:55 GenAI vs Agentic AI: multi-step chains, compounding risk
21:09 The transparency problem: IT deploys tools they can’t fully explain
22:14 AI incidents vs security incidents: what changes in practice
22:44 Hallucinations: fake citations + report failures
25:08 Bias failures: high-stakes outcomes and why guardrails matter
29:59 AI and security operations
33:00 Risk map: fines, reputation, accuracy, IP, ownership
36:40 Due diligence, legal view: DPAs, transfer mechanisms, DPIAs
38:43 Standards and visibility: why ISO/SOC-type signals work
42:08 AI-specific penetration testing
48:10 Not doom: AI benefits if governance + monitoring exist
50:00 AI insurance (optional segment)
51:30 Deepfake question

#AI #AIGovernance #dataprotection

Visit Super Protocol to learn more:
- Cases studies: https://superprotocol.com/case-studies
- Healthcare solution brief: https://superprotocol.com/resources/solution-brief.pdf
- Super Swarm overview: https://superprotocol.com/about/swarm-intro
- Super Swarm Architecture in brief: https://superprotocol.com/about/swarm-architecture
- Super Swarm playlist: https://www.youtube.com/playlist?list=PLo__RdTZO_Zu5ZK27GpbpShIQsBgrVaJn
- Super Protocol website: https://superprotocol.com/
- Playlists with Podcast, demos, and more: https://www.youtube.com/@super__protocol/playlists

Видео AI Incidents Aren’t Like Cyber Incidents: Governance for the New Failure Modes. Ray Orife канала Super Protocol
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять