Copyright & Compliance for Enterprise AI From Demos to Defensible - Nina Edwards of Prudential Insurance
31m 19s
The discussion centers on how enterprises can adopt AI safely while managing compliance and copyright risks. Nina Edwards highlights that risks often arise from routine employee actions, such as using unvetted AI tools or sharing sensitive data, as seen in cases like Samsung. To address this, she recommends implementing instrumented sandboxes—controlled environments where experimentation is logged and monitored—to foster innovation without compromising security. Additionally, enterprises should establish clear governance frameworks, including standardized contract clauses for data usage and model licensing, to ensure defensibility. Edwards emphasizes the importance of discovery phases to identify shadow AI usage within organizations, as unmanaged tools can lead to significant exposure. By combining structured compliance measures with safe experimentation spaces, companies can mitigate risks, build trust, and scale AI initiatives effectively while maintaining legal and operational integrity.
Welcome everyone to the AI and Business Podcast. I'm Matthew Damello, Editorial Director here at Emerge AI Research. Today's guest is Nina Edwards, Vice President of Emerging Technology and Innovation at the Financial Insurance. With decades of experience driving strategy, innovation, and AI-enabled growth at leading financial and consulting firms, Nina brings a deep expertise in applied intelligence, emerging technology, and scaling data-driven business initiatives to today's show. Nina joins us to explore how enterprises can adopt AI safely and effectively. She shares strategies for balancing innovation with compliance, mitigating copyright and data risks, and building defensible AI practices at scale. The conversation also covers practical workflow changes, these include creating instrumented sandboxes, using red light green light governance frameworks, and implementing structured licensing approaches. Nina also explains how these measures reduce risk, boost experimentation confidence, and deliver measurable ROI across business and marketing functions. Today's episode is sponsored by the Copyright Clearance Center or CCC, but first, are you driving AI transformation at your organization, or maybe your guiding critical decisions on AI investments, strategy, or deployment? If so, the AI and business podcast wants to hear from you. Each year, Emerge AI Research features hundreds of executive thought leaders, everyone from the CIO of Goldman Sachs to the head of AI at Raytheon and AI pioneers like Joshua Bengeo. With nearly a million annual listeners, AI and business is the go-to destination for enterprise leaders navigating real-world AI adoption. You don't need to be an engineer or a technical expert to be on the show. If you're involved in AI implementation decision making, or strategy within your company, this is your opportunity to share your insights with a global audience of your peers. If you believe you can help other leaders move the needle on AI ROI, visit Emerge.com and fill out our Thought Leaders submission form. That's Emerge.com and click on Be an Expert. You can also click the link in the description of today's show on your preferred podcast platform. That's Emerge.com/expert1. Again, that's emerj.com/expert1. Without further ado, here's our conversation with Nino. Nino, welcome back to the program. It's a great pleasure having you. Thanks for having me, Matt. I'm so excited to get started. Is it Matt or Matthew? Hi, there's fun. Hi, there's fun. I feel like Matt. Yeah, well, do people do Matt. I like Matt too. There we go. They'll leave this in just for fun. The editors have a good sense of humor. But we're talking today. I know even before the mics kind of came on, I was giving you a little bit about my ex background in music industry. So I know a little bit about all of the challenges and copyright. But I think this is a moment definitely where across the board, AI has reached the point where a lot of the corporate sphere is looking back at the last 25 years going, man, maybe we should have paid attention a little bit more when the Napster thing was happening. But as AI adoption accelerates across the enterprise, legal and compliance teams are discovering that risk grows in parallel with experimentation. Everyday workflows are now involving tools and data sources that were never designed for regulated environments downwind from 25 years ago, creating uncertainty around ownership, licensing and defensibility. Just really interested in where you're seeing this in the insurance enterprise for where copyright and compliance risks surface day to day and how big is that exposure? Yeah, it's a good question. And you know what's so funny? I think when people start preparing for compliance risks, they always are looking for these like very malicious, like creepy bad actors. And it's really the everyday behavior that really trips up enterprise at the end of the day. So these are like your developers that are pasting internal code into tools that are unvited. We saw this with Samsung. I know you told me to stick to insurance, but that one was one that was like plastered everywhere. Where you had the Samsung case where the employees pasted like confidential source code and internal documents into a public AI chat tool. And the company had to end up banning Gen.A.I. like across the board because of the risk, right? This is like the worst case scenario on where you don't want to end up. The other piece in insurance companies is really around some of the customer and the customer marketing materials that you use. So when you have the AI generating or rewriting confidential documents with like the public chat pods or even like chatbots that you have brought into enterprise that are AI tinged or AI driven, this is where some of the risk starts to come in, right? You also have claims analysts that do some of their testing of prompts with the real customer data. So that is also a big, a big pain point. It's really trying to ring fence that human behavior or that everyday behavior where people are kind of looking at it as a shortcut. Which to be fair, it's what we kind of purported as when we put it out there, but doing it in a smarter way, like making sure that they don't do it. I think there was a study that showed that around 77% of employees that they had surveyed shared sensitive company data on like a chat GPT or any of the other like consumer grade, like publicly facing LLM tools. So the risk is really just, is not around just the code piece from the same, like we talked about with Samsung, but it's business content like the customer list and the marketing plans and the policy documents and even the financial data that people are just kind of putting out there onto the tools. And knowingly, that's not protected and could definitely kind of leak out there and cause like major, major breach of information. So you're basically creating like, untracked IP exposure and data handling violations. Because we have all of that policy kind of built into the ecosystem. Even before, you know, people were taking this big leap into this new sort of era of AI. And because the interactions happen very informally. So, you know, people don't have any malicious intent when they're doing it. They're just trying to do their job. They're trying to do it a little faster. Maybe they're trying to get out earlier. It doesn't really surface until much, much later. And usually you don't see it until there's an audit, a licensing challenge or even like a system inspection that happens that you're like, uh-oh, you know, we did like a huge, we have a huge issue here. We were talking in the last episode we had you on about different metrics to an extent where they're chopping up the successes of AI into increments that don't really make sense, especially around quarterly versus other forms of tracking. You were mentioning a second ago people just trying to save time. Do you think the value of hours saved tends to throw other potentially more valuable metrics in this respect or at least compliance practices under the bus? It's a good question. And so it would probably be maybe because it's the same sort of behavior that it based, the same sort of behavior and thinking that you're trying to break in both instances, right? Right. And so that's the kind of technology in a different way. At the same time, I think people aren't really thinking when they do it. They're just kind of like, they're just kind of focused on the end goal, which is like, I gotta get out of here faster. So that's why I'm like, maybe, but I think the intent upfront wasn't around, they definitely were trying to save time, but just independent for themselves. They're not really thinking about the ROI or the metric on the backend, but just, I'm going to hurry up and kind of try to kind of do something done. It inevitably ends up that they have been doing exactly what you're trying to avoid, which is just use this as a tool for our save instead of looking at it like I can move faster. And this is really the goal that I'm trying to achieve. So I think sometimes they do it outside of the main goal that you're looking at for AI, and it's more of an individual. This is how I can think to use it, which goes back to what we talked about in the other episode about the AI fluency and really people understanding how to use these tools more effectively as part of the day to day, even before it starts getting embedded in the workflows. Like that education around, hey, this is a smart way to use it. Not just what it is is going to be really crucial to prevent some of these compliance lips, right? We do compliance training every year for a reason. Absolutely. All that being said, and now that I was like, I was hearing you give that answer and I was like, you know, the thing about our spent is that's a metric for everybody. You can know it like it has the same value. It's hard to break that. Yeah, it's hard to break that thinking. Yeah, time being the one precious commodity we're all losing and has the most value, whether you're on the board or you're on the factory floor, I think, quates everything. Just even trying to think of a little bit more of, and I know there are still a lot of rulings out there in the courts that are kind of letting the dust settle around where we're going to be in the 21st century when it comes to copyright. But from the enterprise perspective, do you think there's a consensus building around what the future looks like where AI is productive, licensed and defensible? I do think that there's, there's this, there is something building around the defensible AI ecosystem where every output, whether it's code, a customer letter or a workflow has verifiable lineage, right? So this means provenance by default, right? We're talking about three models, licensed inputs, watermarked inputs, you know, we talked about with the music industry from before and then we also talked about the marketing piece right now, those watermarked outputs tied to a model registry are going to be important. So that legal can kind of vary.
verify the lineage in minutes and not weeks, right? Contract playbooks are just as important, right? So I didn't talk about this too much with the first question, but there's partnership risk in here as well. So let me actually frame it in an example. So imagine you're having a standardized clause set that's covering training data, right? Reuse, right? Indemnification, retention, and deletion, right? Instead of renegotiating the basics for each vendor, you can scale the partnerships with confidence if you have a playbook around the contracts. I think where I've seen it show up in Enterprise is that for all of the existing contracts, there was an exercise done where they put AI clauses in every contract that they have, just to make sure that they're kind of saved on the backend. And that was good for our vendor contracts, but what also needed to happen is a complete review and rework of our existing compliance policies within the company that don't necessarily have to do anything to do with vendors or anything to do with tools that also try to, again, standardize the clause set that's covering the training data rights or the reuse rights and the deletion and audit access for other things that maybe we even built internally, right? And that took some time to do because you figure some of the companies are 150 years old or 250 years old are more like a bank of New York melon, right? So that is an exercise that carries some lift in order to be able to do it, right? The other thing I think that folks are starting to think about and it's personally one of my favorites, I mean, being that I work for an emerging second innovation team are these sort of instrumented sandboxes. So these aren't about the ROI that we talked about beforehand, sure they help with that, but that's not what this is about. It's really about trust, right? Anytime you hear folks within enterprise and these are the consumers of the technology, talk about legal and compliance, there's always this big side. They're like, these are the people that are gonna tell me that I can't do anything, that are just gonna shut off the access like the Samsung example where they're like, "You ruined it for everyone, no more Jenny, I crossed the board." And it's that's the-- - Taking the toy away from you, right? - Exactly, exactly. And that's the sentiment that they get from legal and compliance and they need to kind of flip that script. And I think these instrumented sandboxes do that, right? It's a sandbox because people can experiment without jeopardizing the production systems, right? The environment is isolated. Only certain models and data are allowed, and it has limits on what you can do, right? So perfect, not the sandbox for used to when we were like five where it was no-hold-bard, but a sandbox nonetheless, right? Safe control, observable AI experimentation, this is the goal, right? Now the instrumented piece, that's usually what people are like, okay, we know sandbox, we know what that means, what's this instrumented piece? The instrumented piece means that this is the guard-reels piece. This is the part that compliance love and are like, "Okay, you get what you're saying. We see what we can do this, and now we see how we can do this, right?" So this is the instrumented piece is now the sandbox will have log-in, right? So this is who did what, with what data? This is like your-- These are your prompts, your outputs, your data sets, the use, et cetera, right? And now telemetry, right? This is how the model behave. This is the exception rates, and this is the spend, right? We need all of those stuff, cracked. We need to have visibility into all of that. Now it's the guard-reels piece of it. So this is the part that the data teams, your data scientists, all of that part of the organization want to see. These are your data filters, your reduction, your risk tiers. And for me, I like to keep risk tiers really simple. Like tier one, fully synthetic data. Like we found this, we created this, this isn't like, you know, stuff that is a golden source type of stuff, right? Tier one, low risk enterprise data, right? Tier two, medium risk data with masking, right? And then tier three, this is the one that people are like, eh, this is the highly regulated data and the approval workflow. So with automatic reduction, this is like immediate pullback of masking of anyone trying to paste in any kind of PII, any personal information. So they get that slap on the wrist and it never sees the light of day or the action is not able to get done even within the sandbox. So for all of this, it's going to have like an automatic compliance visibility, right? So you can only use the models that the company has already licensed, vetted, has risk-gored, and the governance, it has been established around all of them. And then it can enforce usage, right? So we want people to have a good time, but this isn't Vegas. We don't want you to put all our chips on the board. I'm just let it ride, right? So we want the token costs, the queries and the data sets to kind of be ring fence. We don't want any runaway costs as a part of people playing in the sandbox. So we don't want any prompt storms, right? So we can put in something like $50 a day per user within this instrumented sandbox. And I think if companies can create this safe space to play, they're in really good, good shape, right? It's a safe playground. Cameras, fences, rules, you know, letting you innovate without blowing stuff up, right? This is like what we want to see. It's kind of like what Microsoft co-pilates, Studio Enterprise, sandbox does, and the other big tech Amazon with their Ben Rock, Guard Reels and logging. Yeah, I think everyone's moving towards a future where the sandbox really, the sandbox is really let you do everything. We see this especially in adjacent technologies, like digital twins. And this confidence that we can really blow stuff up. We have a self-contained nuclear explosion. You want to get your rocks off if you were one of those kids who love to blow up stuff in the backyard as a kid. This is the place to do it. Yes. I think all at the same time, especially for sandboxing, is there's, especially for instrumented sandboxing as you were explaining it, then there's a built-in sense of this is going to slow down. You can't have compliance without a slow down. And I know there's different areas we had, David Glick from Walmart on the show a little while ago saying, oh, you don't have to sacrifice speed. You don't have to sacrifice innovation for safety. And he made a compelling case. I don't know if it's for everybody, but very compelling case. Maybe when you have Walmart-like resources, that's possible. But how do you think of slowing down or how do you think of compensating for innovation around ensuring that these sandboxes or these compliance measures are really fulfilling their mission? OK. So I'm going to go from sandbox to going on to my soapbox. So for the sandboxes. So sandbox, love it. This is going to take-- I'm going to talk about this for a while. And you're right about the Walmart. Walmart's actually one of my favorite examples of how to do it right. But yeah, you need some money to do it right. So I would say that every enterprise has to start with a discovery phase. You've got to kind of chunk it up. I don't think you need to jump to tentos down or tentos in and say, OK, we're going to do this massive thing. The discovery phase is really about, at least for me, doing an intake and inventory of where the AI is actually being used today. And I emphasize this because actually most organizations really dramatically underestimate their exposure and the risk that the AI that they have already is within the organization. And I know it's similar to what we talked about before. There's a lift to this. And it's not necessarily fun, but it is so critical to making sure that you can turbocharge innovation going forward. So you can ask leaders today, how many AI tools are in use? And they'll usually say something like, oh, maybe eight or 10 departments are piloting something. And they're always wrong. It's always the wrong answer. Then they run this real discovery that I'm talking this real discovery effort that I'm talking about. And they'll find that there's 150 unapproved browser extensions. The employees are using public chat bots for rewriting documents. They found the backdoor. Developers are using AI assistants that weren't vetted by procurement. And the entire shadow workflows that are built around automation tools that security never reviewed. You start to see what is lurking behind the scenes and you're like, oh, crap, there's-- we have a lot that we need to pull back. And you start to see the value in this discovery phase that people hate because it takes-- it does a lot of work. A lot of elbow grease kind of goes into it. So we saw this with a Samsung example that we were-- I mean, not laughing about, but we were referring to is what I will say. Where the engineers accidentally pasted proprietary-- I think it was semiconductor code-- into the public AI tool. And then they stopped the DNAI internally 100%. So then we know 100% that it's not about the bad actors. It is about the human nature, which is what we were talking about before. Right. So if people are going to reach for whatever tool makes their job easier and unless the company shines a light on where the AI lives, this is why I'm making the point. The risk remains really invisible and unmanaged. And that's what we want to make sure it doesn't happen. And here's the thing. You can't really build defensively on top of shadows. If you don't know the tools, you don't know the data flows, and you don't know where the data is flowing, you can't assign the risk. You just-- you can't do it. And if you can't assign the risk, you can't build the guard rails. So step one is not to slow people down. It's to understand where you already are and creating a single intake channel, a single like use case registry as a way for teams to tell you, here's the tool, here's the data, and here's the workflow. And you'll be shocked how quickly that starts to by itself lower the enterprise risk. So still on the stokebox. So stay with me here, Matt. Once you have a discovery, the step two piece for me is a licensing. We kind of touch it.
it before I'm going to go a little deeper. Please. I cannot stress enough before you scale license, before you automate license, before you create training sets or deploy co-pilot license because provenance is knowing exactly where content comes from. What rights you have and what you're permitted to reuse is the backbone of defensibility, right? You need these things. There's a reason, get the images, suit stability AI. There's a reason the New York Times, suit open AI in Microsoft. There's a reason Adobe emphasizes commercially saved content and there's a reason why Shutterstocks deal with open AI created so much noise and is so prominent. Enterprise won't production grade outputs, not experimental grade uncertainty. I see this all the time when we're reviewing those tools for like our marketing department or any area that is focused on content creation. Provenance problems don't just appear in generative art. So I'm not going to, you know, put this all on the art world at the end of the day. They're everywhere. Co-generation. If AI suggests GPL license fragments, can you deploy it? No. Contracts. Many enterprises later discovered that their vendor relationships did not clarify training data rights or deletion obligations, which is why we went back to all vendor contracts and put in those clauses. So building a license foundation means that you're only using models with known training sources or proper indemnification. You are ensuring that outputs have lineage. So the watermarks, the metadata or the registry entry that we had talked about before, or at least we had talked about the watermarks, and then securing commercial rights for any of the content that will be reused or redistributed. So this points again to the content generation piece that we were talking about before and making the problem and checks a part of the standard part of the workflow. Like this just has to be built in. It's not a matter of telling people anything. Don't wait to tell people and expect them to remember all the time, build it right into the workflow. Right? So this doesn't stifle innovation. Again, it's quite the opposite. When the team's know what model is licensed and the outputs are safe, they are more confident in experimenting. You know, it's no longer, oh, I can't do this because compliance is going to slap me on the hand. Or, you know, as soon as I started, they're going to shut it down and we're going to get things taken away from us. Now they're really fine with experimenting because they know what's what and they know what they can and cannot do and what's going to be safe, right? So they'll do the sharing and then the scaling will happen, right? So it removes all of the fear of the potential downstream audits that take downs and all of the forced rework, right? And now, and I'm finally getting off the soft soap box and everything. You're fine. You're fine. Yeah, I'm getting there. I'm getting there. It's a fantastic framework. Don't let me stop you. And so now, this is where the enterprise mindset really has to shift in this sort of last piece. Governance cannot be a giant red stop sign. And I've kind of been alluding to this as we, as I kind of go through these steps, governance has to feel like and function like a traffic system, right? Like we see red light green light and we're not just made. We just know it's built in and we know what it means. And I actually, when I came in and said, use the red light green light when, when kind of thinking about our AI governance at the end of the day, it's easy for people. It makes it feel less compliant. You know, compliance loves jargon. Like compliance loves to put a lot of words and whatever they do, given red light green light system, you know, it'll help people kind of, you know, like settle into this a lot better and not block the flow. So the third step is really creating governance, like a governance rhythm that pairs with innovation. And when I say rhythm, I mean something operational, not academic, right? So like the weekly by weekly AI operates, ops reviews, the portfolio reviews that prioritize high value, low risk use cases. Again, using that sort of red light green light, you know, sort of methodology behind it. And fast escalation lanes for edge cases, right? Nobody wants to have to go through 6000 committees, 5000 checks in order to do anything. Like when I say death by committee is a real thing in enterprise, it is a huge thing. No ginormous community, like committee meetings, like that has to die immediately. And the key principle here is really that defensibility is in about slowing AI down. We keep saying it and I'm going to keep saying it on my end because I think that's the point that needs to screen through with anything that you put together from a governance perspective to protect against, you know, what we were talking about in terms of copyright. So it's about making the AI that value that you create actually safe to use, share and scale. If the governance is too heavy, employees will go around it. I'm guilty of it. I will find the back door in the same way we find a way to click through the compliance. Oh my gosh, maybe I shouldn't say this. Compliance training that comes across on an annual basis. You want to just kind of get it in and kind of get it over with, but you're not really paying attention to it like you need to, right? And this is the one time where you really want people to pay attention and make sure that they're doing things very safely, right? You don't want the governance to be invisible or at-hoc because then teams won't trust it. So smart governance here is a balance. You want some fast pathways for low risk experimentation and you want clear pathways for high risk workflows. You want guard rails, not bottlenecks. And like I said before, and you also mentioned, you know, Walmart is really one of my most favorite examples. You know, their LLM sandbox is such a good example of large corporations doing it right. Like with that, the employees can experiment freely, but the data sanitized, the prompts are logged, the models are approved, the outputs have metadata, and there are risk tiers, right? And like the risk tiers that I talked about before, I kind of model off of what Walmart actually shared and the AI activity streams into an audit dashboard. So no stone unturned, like everybody that needs to know what's going on has easy and ready access to do so. So it shows that speed and safety are not mutually exclusive, right? And what the enterprise is confined is that when the governance is predictable and transparent, the teams start coming to the AI group early instead of late. Like they're coming right from the beginning because there's no fear around it. And that's when innovation actually starts to accelerate. So there is definitely a lift up front. So no shade to what people have been kind of putting out there that you can just move fast. It's fine. I think there is some work that you have to do up front. And it's not always easy work that landscaping piece that I talked about in the beginning, some big lift. But once you get through these three steps, I really feel like, you know, Sky's the limit, that rocket ship that we were talking about, boom, it just kind of goes off. And just for our final question, I know you're giving us a lot of extra time, really, really appreciate it. Just for maintaining that rocket ship, the rocket ship's off. Just going through the atmosphere, how can enterprises maintain compliance as model ecosystems evolve in regulatory expectations expand? Okay. So that's a good one. The technology will shift. And I think it's going to be a matter of practice in the same way that we have to look at all of the compliance training in our policies on an annual basis. We're going to need to continue to do that. But we're going to have to do that within the lens of AI, right? So normally we're just looking for what people are telling, what, you know, the government or the regulators are telling us we need to kind of shape up on when it comes onto compliance. And it's a very reactive sort of situation in this instance. Compliance departments and enterprises need to start to get proactive with how they regularly review their policies and their governance around AI. So the AI ops meetings that need to happen with regular cadence. So does the compliance meetings around AI and what we're doing from a governance perspective. Yeah, absolutely. And we'll have to work out at some point. Having a shared space, I think there's a lot of crossover with what you can share with the Walmart folks. And that's what we're here at Emerge. We're all about connecting, connecting those ideas and those mentalities, especially as we're seeing folks kill some golden calves as you have on this show. Just between, you know, kill the big board meeting. And I think Walmart's really going after it, you don't need a sacrifice speed for innovation or speed for compliance. But we'll have to see how that plays out, especially over the next couple of years as the regulatory space really locks in and becomes standardized for AI. Nina, thank you so much for being with us on today's show. It's been very insightful. Thank you so much, Matt. I'd love to come back anytime. Let me know. Absolutely. [MUSIC] Rapping up today's episode, I think there are three critical takeaways for enterprise leaders in finance, insurance, and other regulated industries from today's conversation with Nina Edwards, vice president of emerging technology and innovation at potential insurance. First, enterprise AI adoption requires more than technology. It requires visibility. Leaders need a clear inventory of tools, workflows, and data to understand risk and prevent untracked exposure before it becomes a problem. Second, defensible AI depends on structured licensing, verifiable outputs in governance frameworks, incorporating red light, green light controls, risk tiers, and instrumented sandboxes ensures safe experimentation while protecting sensitive information. Finally, governance and compliance should accelerate not block innovation. When policies are predictable, transparent, and built into daily workflows, teams can experiment confidently, scale AI initiatives effectively, and deliver measurable ROI without fear of
downstream audits or regulatory penalties. Interested in putting your AI product in front of household names in the Fortune 500, connect directly with enterprise leaders at market leading companies. Emerge can position your brand where enterprise decision makers turn for insight, research, and guidance. Visit emerge.com/sponsor for more information. Again, that's emerj.com/sponso. If you enjoyed or benefited from the insights of today's episode, consider leaving us a review on Apple podcasts and let us know what you learned, found helpful, or just like most about the show. Also don't forget to follow us on X, formerly known as Twitter, @emerge and that spelled again, EMERJ, as well as our LinkedIn page. I'm your host, at least for today, Matthew D'Amello, editorial director here at Emerge AI Research. On behalf of Daniel Fagella, our CEO and head of research, as well as the rest of the team here at Emerge, thanks so much for joining us today and we'll catch you next time on the AI and business podcast.
Podcast Summary
Key Points:
AI adoption in enterprises introduces significant compliance and copyright risks, often stemming from everyday employee behaviors like pasting confidential data into public AI tools.
Effective risk mitigation requires structured approaches, including instrumented sandboxes for safe experimentation, standardized contract clauses, and verifiable data lineage.
Building defensible AI practices involves balancing innovation with governance, using frameworks like red light/green light systems and ensuring transparency in AI tool usage across the organization.
Summary:
The discussion centers on how enterprises can adopt AI safely while managing compliance and copyright risks. Nina Edwards highlights that risks often arise from routine employee actions, such as using unvetted AI tools or sharing sensitive data, as seen in cases like Samsung. To address this, she recommends implementing instrumented sandboxes—controlled environments where experimentation is logged and monitored—to foster innovation without compromising security.
Additionally, enterprises should establish clear governance frameworks, including standardized contract clauses for data usage and model licensing, to ensure defensibility. Edwards emphasizes the importance of discovery phases to identify shadow AI usage within organizations, as unmanaged tools can lead to significant exposure. By combining structured compliance measures with safe experimentation spaces, companies can mitigate risks, build trust, and scale AI initiatives effectively while maintaining legal and operational integrity.
FAQs
Enterprises can adopt strategies like creating instrumented sandboxes for safe experimentation, implementing red light/green light governance frameworks, and using structured licensing approaches to mitigate risks while fostering innovation.
Risks include employees pasting confidential code or data into public AI tools, using AI to generate or rewrite sensitive documents without proper safeguards, and testing prompts with real customer data, leading to potential IP exposure and data breaches.
An instrumented sandbox is a controlled environment where employees can experiment with AI safely. It includes logging, telemetry, and guardrails like data filters and usage limits to prevent risks while boosting confidence in AI experimentation.
A discovery phase helps identify unapproved AI tools and shadow workflows, revealing hidden risks. Without understanding where AI is used, enterprises cannot effectively assign or manage compliance and security risks.
By ensuring verifiable lineage for all outputs, using licensed and watermarked inputs, maintaining a model registry, and implementing standardized contract clauses for training data, reuse, indemnification, and deletion.
Standardized contract clauses and updated internal policies help scale partnerships confidently, manage vendor risks, and ensure consistent handling of training data rights, reuse, deletion, and audit access across the organization.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.