Course Outline
AI in the Enterprise: Strategic and Legal Dimensions
- AI adoption in core business functions: balancing opportunities with risks
- The role of executive leadership in AI governance
- High-risk AI systems and potential organizational exposure
AI Risk Categorization and the Global Regulatory Environment
- EU AI Act: risk classifications, obligations, and penalty structures
- U.S. Executive Order on AI and developing federal/state regulations
- AI compliance requirements within GDPR, HIPAA, and other regulatory frameworks
- Introduction to ISO/IEC 42001, NIST AI RMF, and OECD AI Principles
Security and Oversight for AI Systems
- Strengthening AI security: identifying threats, vulnerabilities, and protective measures
- Incident response and breach notification protocols for AI-driven workflows
- Ensuring auditability and traceability of model inputs, decisions, and outputs
Responsible AI Procurement and Managing Vendor Risk
- Conducting due diligence when sourcing AI tools (including LLMs and APIs)
- Essential contract clauses: data ownership, model explainability, and SLAs
- Validating vendor claims regarding bias mitigation, privacy protection, and safety
Internal Governance Frameworks and Organizational Controls
- Developing cross-departmental AI usage policies
- Establishing ethics committees, risk review boards, and cross-functional oversight mechanisms
- Integrating training, documentation, and compliance processes
Evaluating Use Cases and Risk Scenarios
- Assessing high-impact applications (e.g., HR screening, financial scoring, customer service bots)
- Utilizing tools and templates for comprehensive AI risk assessments
- Analyzing scenarios involving misalignment, model drift, hallucination, and discrimination
Emerging Trends and Future Outlook
- Anticipating regulatory changes and global convergence trends
- Addressing GenAI-specific risks and extending governance practices
- Scaling AI operations responsibly within the enterprise
Key Takeaways and Next Steps
Requirements
- Familiarity with enterprise risk, legal, or technology frameworks
- Background in executive leadership, cybersecurity, or compliance oversight
- No prior technical expertise in AI development is necessary
Target Audience
- Chief Information Security Officers (CISOs)
- Legal counsel and compliance officers
- Chief Technology Officers (CTOs)
Testimonials (3)
inventory and identifying the different risk exposures within AI
Gary Cook - Cybersecurity and Information Technology Risk Division
Course - Introduction to AI Trust, Risk, and Security Management (AI TRiSM)
I really enjoyed learning about AI attacks and the tools out there to begin practicing and actively using for security testing. I took a lot of knowledge away which I didn't have at the beginning and the course met what I hoped it would be. My favorite part shown from the training was Comet Browser and was amazed at what it could do. Definitely something will be looking into more. Overall it was a great course and enjoyed learning all OWASP GenAI Top 10.
Patrick Collins - Optum
Course - OWASP GenAI Security
The profesional knolage and the way how he presented it before us