Your AI has access. But does It have too much?
AI can help organizations move faster, automate work, and unlock new opportunities. But when AI systems can access sensitive data, connect to business tools, or take actions on a user's behalf, governance becomes an operational security priority.
In this episode of The Art of Security, co-host Josh Davies speaks with Gina Cardelli, Principal Security Strategist at Fortra, about how organizations can adopt AI without losing visibility or control. They examine what recent AI security incidents can teach businesses about excessive permissions, exposed infrastructure, third-party tools, shadow AI, and the risks of moving too quickly.
Gina also explains how threat modeling, continuous monitoring, least privilege, and cross-functional AI councils can help organizations understand an AI system's potential blast radius and manage risk as its capabilities evolve.
Listen to learn:
- Why AI governance cannot be treated as a one-time policy exercise
- How to threat model AI use cases before deployment
- Why continuous monitoring is essential for AI systems and agents
- How third-party AI tools can introduce data and supply chain risks
- What organizations can do about shadow AI
- Why many AI security failures still begin with familiar vulnerabilities
- How to introduce practical controls without bringing AI innovation to a halt
AI governance doesn't have to be perfect on day one. But organizations need to understand how AI is being used, what it can access, and what could happen if something goes wrong.
AI security is evolving quickly. Subscribe to The Art of Security for more conversations that help you keep pace.