In this episode, Howard Holton joins the No Trust podcast team to discuss why AI governance may be one of the most important and misunderstood challenges facing cybersecurity today.
Drawing on decades of experience across IT, technology leadership, security, and emerging technologies, Howard shares his perspective on the rapid growth of the AI ecosystem, why organisations need to approach AI vendors and startups with a healthy degree of scepticism, and why applying traditional security and governance thinking to AI may not be enough.
The conversation explores the non-deterministic nature of AI, AI governance, vendor evaluation, technical debt, DevSecOps, AI-driven security operations, and the challenge of securing systems that may not behave exactly the same way twice. Howard explains why this fundamentally changes the way we need to think about identity, risk, testing, controls, and accountability.
The episode also looks at the importance of combining human judgement with AI capabilities rather than simply replacing people with automation. As organisations begin making more decisions at machine speed, understanding context, validating outcomes, and maintaining meaningful human oversight will become increasingly important.
Finally, the conversation turns to Black Hat, from navigating an increasingly crowded AI vendor landscape to the value of stepping away from the technology and experiencing the people, food, culture, and community that make conferences memorable.
Key Takeaways:
• AI governance is rapidly becoming one of the most important areas of cybersecurity and technology risk.
• AI is fundamentally non-deterministic, which challenges many traditional approaches to governance, testing, security, and assurance.
• Organisations need to understand how AI systems make decisions—not simply whether they produce the expected output.
• Traditional governance frameworks may need to evolve to deal with autonomous and non-human identities.
• Human oversight remains critical, particularly as AI systems are given greater autonomy and decision-making authority.
• AI security should be approached pragmatically, with strong DevSecOps, risk management, validation, and security fundamentals underneath it.
• The explosion of AI startups makes vendor evaluation increasingly important; organisations need to consider technical debt, long-term viability, architecture, and security rather than simply buying into the AI label.
• AI can strengthen cybersecurity operations, but organisations need to understand the variability and uncertainty inherent in AI-generated decisions.
• Pairing humans with AI can provide better security outcomes than simply attempting to automate people out of the process.
• Understanding context and gaining real-world experience remain essential—whether you're evaluating technology, managing security risk, or navigating Black Hat.
Follow & Subscribe on all Podcast platforms.
What is the Zero Trust Forum about? It’s about empowering zero trust security professionals with strategies, architecture, and real world journeys to secure the digital future, the right way!
Follow the Zero Trust Forum on LinkedIn www.linkedin.com/company/zero-trust-forum/.
Follow Jaye Tillson on LinkedIn - www.linkedin.com/in/jaye-tillson/
Follow John Spiegel on LinkedIn - www.linkedin.com/in/john-spiegel-2011543/