Course Outline
Enterprise Artificial Intelligence: Strategic and Legal Considerations
- Integration of AI into core operational functions: benefits and associated risks
- Executive accountability for AI governance structures
- Implications of high-risk AI systems on organizational liability
AI Risk Classification and the Global Regulatory Environment
- The EU AI Act: risk categorizations, compliance requirements, and enforcement mechanisms
- U.S. Executive Order on AI and the development of federal and state regulations
- Navigating AI compliance within GDPR, HIPAA, and other regulatory frameworks for government and private sectors
- Alignment with ISO/IEC 42001, the NIST AI Risk Management Framework, and OECD AI Principles
Security and Oversight of AI Infrastructure
- Strengthening the AI security posture against threats, vulnerabilities, and required safeguards
- Incident response protocols and breach notification procedures for AI-enabled workflows
- Ensuring auditability and traceability of model inputs, decision-making processes, and outputs
Responsible AI Procurement and Vendor Risk Management
- Conducting due diligence for AI tool sourcing, including large language models (LLMs) and application programming interfaces (APIs)
- Essential contractual provisions: data ownership rights, model explainability, and service level agreements (SLAs)
- Validating vendor assurances regarding bias mitigation, privacy protections, and safety standards for government deployments
Internal Governance Frameworks and Organizational Controls
- Developing standardized AI use policies across agency departments
- Establishing ethics committees, risk review boards, and cross-functional oversight mechanisms
- Integrating training, comprehensive documentation, and compliance requirements into operations
Use Case Evaluation and Risk Scenario Analysis
- Assessing high-impact applications, such as human resources screening, financial scoring, and customer service automation
- Utilizing standardized tools and templates for AI risk assessments
- Addressing specific risk scenarios: algorithmic misalignment, data drift, hallucination, and discriminatory outcomes
Emerging Trends and Future Policy Considerations
- Monitoring regulatory evolution and global standards convergence
- Managing generative AI-specific risks and extending governance controls
- Scaling AI operations responsibly within the enterprise for government missions
Summary and Actionable Next Steps
Requirements
- Familiarity with enterprise risk, regulatory, or technology governance frameworks
- Background in senior executive leadership, cybersecurity management, or compliance oversight
- Direct technical expertise in AI development is not required
Target Audience
- Chief Information Security Officers (CISOs)
- Legal counsel and compliance officers
- Chief Technology Officers (CTOs)
Testimonials (2)
I really enjoyed learning about AI attacks and the tools out there to begin practicing and actively using for security testing. I took a lot of knowledge away which I didn't have at the beginning and the course met what I hoped it would be. My favorite part shown from the training was Comet Browser and was amazed at what it could do. Definitely something will be looking into more. Overall it was a great course and enjoyed learning all OWASP GenAI Top 10.
Patrick Collins - Optum
Course - OWASP GenAI Security
The profesional knolage and the way how he presented it before us