Andrea Elliott
CEO & Founder @ EMG : Global GRC & Foresight Practitioner helping companies use AI Responsibly
Atlanta, Georgia, United States
Actions
Andrea Elliott is the CEO, Founder, and Managing Partner of EMG Advisory, the AI-native governance, risk and strategy practice serving regulated, high-stakes industries including Quantum Computing and Financial Services. She most recently served as Chief Compliance and Ethics Officer at a publicly traded global payments technology company, where she led a global risk and compliance transformation, built the company's AI governance framework, and led the outstanding CFPB & State AG Consent Orders to full regulatory compliance, with zero reportable incidents during her tenure. She also designed and led the GRC technology transformation to drive internal risk intelligence, transparency, and enterprise accountability, providing an end-to-end, 360 perspective on risk throughout the enterprise. With 15-plus years across risk, compliance, governance, ethics, and legal, Andrea brings a foresight practitioner's perspective to AI governance failures and mitigation. She is the author of (1) The Deadline on Implicit Governance, (2) The Proportionality Problem, (3) The Architecture of Intuition, (4) The Quiet Rewiring, (5) Bounded Autonomy, (6) The Compounding Bet, and (7) The Missing Middle. She holds a JD from Emory Law [Bankruptcy Journal & Transactional Certificate], an MBA from UGA [Finance focus with an emphasis in Consulting], and the AIGP credential from IAPP. Her undergraduate studies at Auburn University included Architecture, Industrial Design, and Business Administration.
From Andrea: "AI is rewriting what industries can do, and the leaders who govern it with seriousness and imagination will reshape theirs rather than scramble to catch up. I help those leaders imagine beyond what AI makes possible today, then usher them through the transformation for the betterment of the people their industries serve.
It starts with something deceptively simple: helping organizations make sound AI decisions they can stand behind, quickly and confidently. Done right, that discipline is not a brake on ambition. It is what lets a company reimagine what is possible with AI.
My work sits at the intersection of law, risk, ethics, strategy, and systems design. After 15+ years in risk and compliance roles, most recently as Chief Compliance Officer where I built the company's AI governance framework from the ground up, I founded EMG Advisory on a conviction: AI does not need more hype. It needs structure, accountability, and leaders who treat risk as a strategic discipline.
That is the part most people miss. Governance, Risk, and Compliance, done well, is not what slows AI down. It decides where you can afford to move fast and where you cannot, and it is inseparable from strategy; your AI strategy does not survive without it.
The other half of how I work is AI-native wiring. I think in systems, synthesize fast, and collaborate with AI at the conceptual layer as a cognitive partner, translating complexity into strategic clarity. It is also how EMG itself is built: I practice the responsible, operationalized AI I help my clients deploy.
I work with organizations that want to use AI strategically, responsibly, and with foresight. I help leaders:
Turn AI risk and compliance into strategic advantage
Make defensible AI decisions at the speed of business
Translate regulatory ambiguity into operational clarity
Anticipate second- and third-order effects before they surface
Design governance that works in practice, not just on paper
The regulatory landscape shifts faster than most AI roadmaps, and the patchwork of overlapping laws and standards leaves even willing organizations unsure what they must comply with. Pair that with AI that stalls in committee and governance impeccable on paper that no one operates by, and the gap becomes clear. Closing it is where I do my best work.
But closing the gap is the floor, not the ceiling. The organizations that govern AI with seriousness and imagination will not just keep up; they will transform what their industries can do for the people who depend on them. That is the future I am building toward."
Area of Expertise
Topics
Bounded Autonomy: Governing Agentic AI Without Killing It
On May 1, 2026, six cybersecurity agencies (CISA, NSA, ASD ACSC, the Canadian Centre for Cyber Security, NZ NCSC, and UK NCSC) published joint guidance on the careful adoption of agentic AI services. Most headlines treated it as a security advisory. The deeper signal: agentic AI has become a corporate governance problem, and almost no enterprise has the operating discipline to answer it.
This session explores 'bounded autonomy' as the governance posture that lets enterprises actually deploy agentic AI without losing control. Drawing on the speaker's 15-plus years across regulated industries and her tenure as Chief Compliance Officer at a publicly traded payments technology company, the session diagnoses why most current approaches fall into a false binary: deploy with minimal guardrails and hope nothing breaks, or ban agentic AI entirely and watch competitors move.
Bounded autonomy is a third path. It treats agentic AI as advisory by design, with structurally enforced limits on AI authority and human decisions on anything material. The architecture: advisory by default, escalation to humans on material decisions, reversibility designed in, audit trail produced continuously. Most current 'guardrails' approaches fail because they treat autonomy as a slider rather than an architecture.
Specific topics covered:
The Five Eyes' five named risk categories (privilege, design and configuration, behaviour, structural, accountability) and how to operationalize each.
The four-phase governance pattern the guidance recommends and where enterprises typically break it.
Defensibility design: how to produce the evidence trail that survives examination after an agentic incident.
The 'advisory by design' architecture for agentic systems that recommend but do not act unilaterally.
Where bounded autonomy fits in the broader AI governance lifecycle (discovery, development, deployment, monitoring, incident response, decommissioning).
Learning objectives:
Apply the Five Eyes guidance to enterprise agentic AI programs.
Distinguish bounded autonomy from generic 'AI safety' frameworks.
Design defensibility into agentic AI deployments before they ship, not after.
Operationalize advisory-by-design as a structural posture, not a checklist.
The session is grounded in the speaker's published commentary 'Bounded Autonomy' (May 2026) and the operational frameworks she has developed for agentic AI governance. Practitioner-derived frameworks, broadly applicable.
For organizers: panel placement welcome.
Black Swan Modeling for AI Risk: Who Owns the Worst-Case Scenario Before It Hits
Most AI governance programs ask 'how do we prevent this from going wrong?' Almost none ask 'when this goes wrong, who specifically is on the hook?' The first question produces frameworks. The second question produces lived accountability. This session presents black swan scenario modeling as a structured exercise that forces enterprises to confront ownership BEFORE an incident, not after.
Drawing on the speaker's 15-plus years across regulated industries and her tenure as Chief Compliance Officer at a publicly traded payments technology company, this session walks through how black swan modeling reveals what documented governance hides.
The exercise is simple to describe and uncomfortable to execute. For a specific high-stakes AI use case, the team is asked to imagine the worst-case incident: the AI tool discriminates at scale, the agentic system takes an unauthorized action with material consequence, the model produces a defamatory output that ends up in the news. Then the team is asked: who specifically is on the hook? Whose name appears on the press release? Who explains this to the board? Who, by name, gets fired if this happens?
When the team cannot answer that question cleanly, the governance program has a documented-but-not-lived gap. When they can answer it, the next question is whether that person actually has the authority and the information to prevent the worst case. If not, accountability is decoupled from authority, and the program is set up to scapegoat the named owner for failures they could not prevent.
The exercise produces several outputs:
Pre-assignment of incident response ownership at the use case level.
Identification of decision-rights gaps between accountability and authority.
Lived ownership confirmation: the named owner either accepts the worst-case scenario at their desk or pushes back, triggering a governance redesign.
Audit trail evidence that the organization considered worst-case scenarios before deploying, which is itself a defensibility asset.
Specific topics covered:
How to construct credible black swan scenarios that survive executive scrutiny.
The 'who gets fired' question as a forcing function for honest ownership conversations.
The connection between black swan exercises and the broader lifecycle decision-rights architecture.
How black swan modeling produces evidence that supports defensibility when something does go wrong.
Learning objectives:
Design black swan scenarios that stress-test AI governance ownership.
Use worst-case scenario modeling to surface documented-vs-lived decision-rights gaps.
Produce pre-incident accountability assignments that hold under examination.
Build the audit trail that supports defensibility after an incident.
Practitioner-derived frameworks, broadly applicable.
For organizers: panel placement welcome.
AI Risk Appetite: From Documented to Lived (And How to Get There)
Most enterprises have a documented AI risk appetite. Almost none have a lived one. The gap is the difference between what gets approved in a leadership offsite and what actually constrains decisions when the business is moving at AI speed. This session diagnoses why documented risk appetite fails to constrain behavior and presents an operational path to making appetite actually lived.
Drawing on the speaker's 15-plus years across regulated industries and her tenure as Chief Compliance Officer at a publicly traded payments technology company, this session walks through three structural failures of typical AI risk appetite programs.
First, risk appetite is signed off but not drafted by the owner. The traditional pattern is that ERM proposes appetite, leadership tweaks and signs. The owner never internalizes what they approved. Lived appetite requires that the owner DRAFTS the appetite themselves, with ERM in a supporting role.
Second, risk appetite is not specific enough to be actionable. Statements like 'we will not tolerate material AI risk' protect nothing because nobody knows what material means in any specific decision. Lived appetite is specific enough that frontline decision-makers can map their use case against it and reach a defensible answer.
Third, risk appetite is approved but not enforced. The pattern of 'metric flags red, gets explained away, asked to bring it to green next quarter, nothing actually happens' is endemic in enterprise risk management. AI compresses the timeline and amplifies the consequences. Without lived consequences for breach, documented appetite is theater.
The session presents a working framework: a floor (what we will not do, prohibited classes of AI use), a ceiling (what is explicitly permitted within stated bounds), and a gray middle (what requires explicit escalation and case-by-case judgment). The narrower the gray middle, the faster the workforce can operate; the more iteration on the appetite statement against real cases, the narrower the gray middle becomes.
Real-world failure modes anchor the discussion, including the Workday-style discrimination cases that exemplify the gap between documented and lived appetite.
Learning objectives:
Diagnose three structural failures of documented AI risk appetite.
Distinguish documented from lived appetite at the level of specific decisions.
Apply the floor-ceiling-gray-middle framework to AI use case categories.
Build owner-drafted appetite that workforce can actually execute against.
Practitioner-derived frameworks, broadly applicable across regulated industries.
For organizers: panel placement welcome.
What It Takes to Win the AI Era: Why Human Psychology Is the Key
Why does AI feel intuitive to some leaders and opaque to others? It is not coincidence. It is by design. AI was built in our image. It is not a foreign intelligence; it is a mirror. Machine learning was modeled on how humans learn: pattern recognition, feedback loops, reward signals, iterative refinement. Leaders who already understand reward systems, habit formation, and identity-based change speak AI's native language. The leaders who do not are still translating. Why companies fail at AI is behavioral. What it takes to win is human psychology.
The data confirms the diagnosis. Most enterprises measure AI success on a narrow scoreboard: the technology runs, outputs match expectations, hours saved translate into headcount cuts. By that scoreboard, AI looks like it works. But 95 percent of enterprise generative AI projects fail to deliver measurable ROI (MIT NANDA). Across 140 implementations analyzed, only 23 percent of failures trace to technology; 77 percent trace to strategy, governance, and change management (Folio3). The technology is doing what it was built to do. The humans around it are not.
Translation is never enough. Surface-learners master the current tool and scramble when the next capability releases. They benchmark against a linear curve in an exponential environment: the next four years will feel less like 2022 to 2026 and more like 1980 to today. Deep-learners aggregate cross-disciplinary skills that suddenly compound into AI fluency. Learning AI is learning how learning happens, and it cannot be outsourced; if you did not build the intuition, you cannot govern it. Automating today's processes is itself a trap: it optimizes for a market that may not reward the same things by 2030.
The Human Layer is the psychological ecosystem inside every AI initiative: workforce, customers, and leaders designing the incentives and safety conditions that determine whether either group will engage. Identity emerges from rewards, not directives. Most enterprises reward efficiency with more work or elimination, so people hide AI use rather than build identity around it. Psychological safety, not policy compliance, makes responsible AI use the path of least friction. This is survival, not altruism: misaligned incentives and unclear decision rights implode the AI strategy from inside.
The session lays out three behavioral requirements: leadership-level behavioral fluency that cannot be outsourced, depth of learning that compounds across AI cycles, and identity-incentive-safety design that rewards experimentation over efficiency-punishment.
Learning objectives:
Diagnose the behavioral root causes of the 80% AI initiative failure rate.
Apply The Human Layer framework to evaluate AI risk posture upstream of governance architecture.
Use three Monday-morning diagnostic questions to surface the behavioral gap behind any stalled AI program.
Move Faster Without Losing Control: The Lived Governance Architecture Most AI Programs Are Missing
Even mature AI governance programs are failing. Documented risk appetite, named ownership, frameworks, committees, policy: despite the rigor, decisions stall, wrong people make calls at wrong moments, and named owners stay exposed when something goes wrong.
Behind every failure is a person paralyzed by fear: terrified of being fired when AI goes wrong, scapegoated for decisions outside their control. So they don't decide. They decide too conservatively. Or wait for committee cover that doesn't protect them.
This session diagnoses why, drawing on the speaker's tenure as Chief Compliance Officer at a publicly traded payments company and 15-plus years across regulated industries. Ownership, accountability, and politics are not new problems. AI is the magnifying glass that amplifies them and speeds them up, crossing multiple functions simultaneously and requiring decision rights at multiple lifecycle stages.
The root cause: governance is documented but not lived. Decision rights are written but unenforced. Risk appetite is signed off but not drafted by the owner, not specific enough to act on, or set at a level no one enforces. Breach response is explanation, not action. Without lived consequences, governance is theater.
Four failure modes:
Decisions stall while executives admire the problem rather than solve it.
Decisions get made too conservatively to keep up with AI velocity.
Decisions get made by whoever feels they can act, with or without the right people in the room.
Decisions get made by someone with authority, exhausted from circular deliberation, without the information or alignment required. The Workday-style discrimination cases typically live here.
Two defensive instincts both fail: naming a single AI owner ('one throat to choke') and standing up a committee. Both feel like protection. Neither is.
The mitigation framework: a lifecycle governance architecture with lived decision rights, lived risk appetite at the right granularity, enforced consequences for breach, and transparency so everyone executing knows the rules. The contract this enables: play inside the rules and leadership stands behind you; play outside and you are exposed. It works because the rules are clear, the consequences are real, and the post-incident question shifts from 'why didn't you stop this?' to 'was the framework sound and followed?'
Done right, AI governance is the trust infrastructure that empowers the enterprise to decide confidently at speed.
Learning objectives:
Diagnose four AI governance failure modes even mature programs cannot prevent; Distinguish documented from lived decision rights, risk appetite, and consequences across the AI lifecycle; Apply a lifecycle governance architecture to AI use case categories; Build trust conditions that empower decision-makers to act confidently within clear rules.
Practitioner-derived frameworks, broadly applicable.
For organizers: panel placement welcome.
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top