Course Outline
AI in the Enterprise: Strategic and Legal Perspectives
- Opportunities and risks associated with AI adoption in core business functions
- The role of executive responsibility in AI governance
- Organizational exposure related to high-risk AI systems
AI Risk Classification and Global Regulatory Landscape
- EU AI Act: risk tiers, specific requirements, and potential penalties
- The U.S. Executive Order on AI and emerging federal and state regulations
- AI-related compliance requirements within GDPR, HIPAA, and other relevant frameworks
- Overview of ISO/IEC 42001, NIST AI RMF, and OECD AI Principles
Security and Oversight of AI Systems
- AI security posture: identifying threats, vulnerabilities, and implementing safeguards
- Incident response and breach notification protocols for AI-driven workflows
- Auditing and ensuring traceability of model inputs, decisions, and outputs
Responsible AI Procurement and Vendor Risk
- Conducting due diligence when sourcing AI tools, including LLMs and APIs
- Critical contract elements: data ownership, model explainability, and SLAs
- Assessing vendor claims regarding bias mitigation, privacy guarantees, and safety
Internal Governance Frameworks and Organizational Controls
- Developing AI usage policies across various departments
- Establishing ethics committees, risk review boards, and cross-functional oversight mechanisms
- Integrating training, documentation, and compliance processes
Use Case Evaluation and Risk Scenarios
- Evaluating high-impact use cases, such as HR screening, finance scoring, and customer service bots
- Utilizing tools and templates for comprehensive AI risk assessments
- Analyzing scenarios involving misalignment, drift, hallucination, and discrimination
Emerging Trends and Future Considerations
- Anticipating regulatory evolution and global convergence
- Addressing GenAI-specific risks and expanding governance strategies
- Achieving responsible scaling of AI operations within the enterprise
Summary and Next Steps
Requirements
- Familiarity with enterprise risk, legal, or technology frameworks
- Background in executive leadership, cybersecurity, or compliance oversight
- No prior technical experience in AI development is necessary
Target Audience
- Chief Information Security Officers (CISOs)
- Legal counsel and compliance officers
- Chief Technology Officers (CTOs)
Testimonials (3)
inventory and identifying the different risk exposures within AI
Gary Cook - Cybersecurity and Information Technology Risk Division
Course - Introduction to AI Trust, Risk, and Security Management (AI TRiSM)
I really enjoyed learning about AI attacks and the tools out there to begin practicing and actively using for security testing. I took a lot of knowledge away which I didn't have at the beginning and the course met what I hoped it would be. My favorite part shown from the training was Comet Browser and was amazed at what it could do. Definitely something will be looking into more. Overall it was a great course and enjoyed learning all OWASP GenAI Top 10.
Patrick Collins - Optum
Course - OWASP GenAI Security
The profesional knolage and the way how he presented it before us