Securing AI in the Enterprise: Leverage Before You Leap

Aug. 5, 2024
Securing AI in the Enterprise: Leverage Before You Leap

It took the aerospace industry less than 100 years to move from the first successful flight in 1903 by the Wright brothers, which lasted 12 seconds and traveled 180 feet, to the first tourist in space in 2001 when Dennis Tito went 254 miles above the Earth to board the International Space Station. Should we have been so surprised that it took ChatGPT all five days to hit the million-user mark and less than a year to pass 100 million? AI and flight have been inarguably transformative for businesses and individuals alike, and both come with significant challenges and opportunities.

Integrating AI into an organization’s operations requires a deep understanding of and an established protocol for navigating the complexities and risks of digital innovation. I recently sat down with some colleagues, renowned security experts Dr. Gary McGraw, founder of the Berryville Institute of Machine Learning, and six-time former CISO Jim Routh, to discuss the intersection of creativity and cybersecurity.

Enabling an AI-driven transformation relies on a security-first mindset. The rapid creation and implementation of extremely diverse tools are redefining the business landscape and workforce daily, and the very nature of work is not an overstatement. The risks presented by this furious evolution are many and complex, but, as Gary noted, they are not monolithic. They touch social, enterprise, and line-of-business contexts and, thus, must be addressed within that context and as early as feasible during the adoption phase.

Learning from the lessons of disruptive technologies of the past doesn’t require going back to Kitty Hawk; 20 or 30 years ago in Silicon Valley is far enough; if we want to talk about technologies’ ability to upend the workplace, workers rapidly and the nature of work, as Jim pointed out. We need to look no further than the personal computer, which has revolutionized work and communication, made completing tasks faster and more efficient, and opened new possibilities that have reshaped industries and lifestyles. A more recent disruptor is the cloud, which transformed the way businesses and individuals stored, accessed and managed data by shifting those resources from on-premises infrastructure to remote servers accessible via the Internet.

An openness to opportunity and adaptation is critical; the use of AI cannot be stopped by policy, but its use can and must be nurtured and steered.

We all agreed that the key element to a secure foundation is a strong focus on the importance of governance in AI deployments beginning, as Gary stated, with observability: An organization must know every AI tool in use, what it is being used for, and who is using it. I am a firm believer that policy-based access controls are key. These support a governance framework's “who’s using what” element and enable administrators to manage enterprise risk while regulating and monitoring expensive and limited AI resources. Jim’s experience as a six-time CISO informs his contention that a flexible framework supported by an agile team responsible for keeping it workable and compliant with evolving regulations is the third element of the security mindset.

Lessons from past disruptive technologies, such as aircraft, personal computers, and the cloud, remind us of the era-defining opportunities ahead when we explore or adopt innovation strategically. Addressing risks early and within their specific contexts enables an organization to harness transformative power, such as AI, effectively and safely.

Robust governance, centered on observability and policy-based access controls, ensures AI risks can be managed and mitigated. A flexible, compliant framework further supports this approach. Balancing creativity with cybersecurity can maximize AI’s potential, safely driving innovation and securing a transformative future for businesses and individuals.

Founder and CEO of CalypsoAI, Neil Serebryany, holds multiple patents in machine learning security and is widely regarded as a leading voice in the field. Being one of the youngest venture capital investors and working on the front lines of national security innovation at the Department of Defense spurred him to create AI Security. This industry didn’t exist four years ago. CalypsoAI's mission is to become a trusted partner and global leader in AI Security. Follow Neil on Twitter and LInkedIn[email protected]

About the Author

Neil Serebryany | Founder and CEO of CalypsoAI

Founder and CEO of CalypsoAI, Neil Serebryany, holds multiple patents in machine learning security and is widely regarded as a leading voice in the field. Being one of the youngest venture capital investors and working on the front lines of national security innovation at the Department of Defense spurred him to create AI Security. This industry didn’t exist four years ago. CalypsoAI's mission is to become the trusted partner and global leader in AI Security. Follow Neil on Twitter and LInkedIn. [email protected]