Session

GRC-as-Code: How Security Teams Can Ship AI Governance Without Slowing Down Engineering

Security governance for AI systems is stuck in 2015. GRC teams write PDF policies. Engineering teams ignore them. When a developer wants to connect a new tool to their AI agent, the review takes days. By the time the policy doc is updated, the architecture has changed twice.

This session presents a policy-as-code approach to AI governance that gives GRC teams direct control over runtime enforcement without requiring engineering deployments. Using OPA/Rego as the policy engine, governance rules become version-controlled, testable, and hot-reloadable artifacts that enforce at the point of action rather than the point of review.

The talk walks through real implementation: writing Rego policies that map to NIST 800-53 controls, building a policy bundle pipeline so GRC pushes updates without deployments, and separating policy ownership from infrastructure ownership so security teams and engineering teams stop blocking each other.

Key Learnings
• Why document-based AI governance fails in fast-moving engineering organizations
• Implementing policy-as-code with OPA/Rego for AI agent runtime enforcement
• Mapping Rego policies to NIST 800-53 and ISO 27001 control families
• Building a GRC policy pipeline: version control, testing, hot-reload, and audit trails
• Organizational patterns for separating policy ownership from infrastructure deployment

Aakash Abhay Yadav

Managing CyberSecurity GRC | OWASP AI Exchange Author

San Francisco, California, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top