Session
Automating the 'Governance': Building a Rules Engine for AI Use Case Governance at Scale
Every enterprise deploying AI faces the same problem: hundreds of teams want to ship AI features, and security needs to evaluate each one. Manual review doesn't scale. Spreadsheet-based tracking breaks. And without clear automated rules, governance becomes either a rubber stamp or a permanent bottleneck.
This session presents a practical rules engine architecture for AI use case governance that evaluates deployment requests against policy rules defined in YAML, with short-circuit 'red zone' logic for automatic rejection of high-risk patterns and graduated approval workflows for everything else. The engine processes JSON context from intake forms, evaluates against tiered policy rules, and produces auditable approval or rejection decisions.
The talk covers the full system: rule definition, evaluation logic, red zone short-circuiting, general approval criteria, integration with existing GRC workflows, and lessons learned from operating the system across dozens of AI use case submissions.
Key Learnings
• Why manual AI use case governance fails at enterprise scale and what to automate first
• Designing a rules engine with YAML-defined policies and JSON context evaluation
• Red zone short-circuit logic: automatically rejecting high-risk AI patterns without human review
• Graduated approval workflows: tiered governance based on risk classification
• Integrating automated governance into existing security review and GRC workflows
Aakash Abhay Yadav
Managing CyberSecurity GRC | OWASP AI Exchange Author
San Francisco, California, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top