Session
Turning AI Governance into Controls You Can Prove
Most organizations now have an AI policy. It promises human oversight, data protection, access control, and responsible use. Many are mapping to ISO/IEC 42001, the NIST AI RMF, and the EU AI Act, while also meeting GDPR and NIS2. On paper, the governance is in place. In practice, few of these promises are backed by a technical control, and even fewer by evidence an auditor or regulator would accept.
This session tests an AI agent that passes a typical governance review. Every policy box is ticked. Then it gets hijacked through a poisoned document and leaks data, and none of the stated controls stop it or even record it.
We then work in both directions. Upward, we turn the technical failure into GRC terms: the risk register entry, the control that failed, the regulatory exposure, and the questions auditors and regulators will ask. Downward, we take common AI governance requirements such as human oversight, logging, access limits, and data protection, and turn each one into a specific technical control, an evidence source, and a way to test it.
Konstantinos Lianos
Cloud Security Specialist - Microsoft Regional Leader & Senior Microsoft Student Ambassador
Athens, Greece
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top