When Risks Can Think: Managing Risk and Compliance in the AI Era

When Risks Can Think: Managing Risk and Compliance in the AI Era

Source: YouTube · ISACA HQ · published Sep 10, 2026 · 26:07

Compliance & GRC
No ratings yet Log in to rate
Transcript Available
Description

BLUF: As AI adoption accelerates, risk leaders must evolve from static compliance to dynamic governance by addressing novel risks like model drift, shadow AI, and non-human identities, while integrating risk management early in the development lifecycle to balance speed with safety 2:15.

Key Takeaways:

  • Dynamic Risk Landscape: Traditional static risk assessments are insufficient because AI introduces variables that change independently of human intervention, such as model drift and hallucinations 3:00.
  • New Threat Vectors: Organizations face amplified cyber risks from non-human identities and "shadow AI," where employees deploy unvetted AI tools that bypass security controls and expose sensitive data 5:20.
  • Visibility Gaps: A major challenge is the lack of visibility into unauthorized AI usage, as business units often implement AI systems without proper approval, creating hidden vulnerabilities within corporate networks 6:27.
  • Fragmented Governance: Siloed teams (IT, privacy, compliance) lead to fragmented risk registers and inconsistent decision-making; a single source of truth is required to ensure cohesive policy enforcement 10:10.
  • Maturity Evolution: Mature AI risk programs shift from a compliance-first mindset to a business-empowerment model, where risk insights directly inform executive strategy and maximize ROI while mitigating exposure 22:17.

Closing statement: To succeed in the AI era, organizations must treat risk management not as a bottleneck, but as an integrated partner that enables secure innovation and strategic decision-making. By building robust intake processes and continuous monitoring, leaders can harness AI's potential without compromising security or compliance.

Sources:

  • 2:15 Introduction to the concept of "risk thinking" and the shift from static to dynamic risk management.
  • 3:00 Explanation of how AI models introduce independent decision-making variables.
  • 5:20 Discussion on new threat vectors including non-human identities and amplified cyber risks.
  • 6:27 Analysis of visibility gaps caused by shadow AI and unauthorized third-party tools.
  • 10:10 The dangers of fragmented governance and siloed teams in AI adoption.
  • 22:17 Overview of the AI risk maturity model and the transition to business-driven security.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Compliance & GRC. Commonly maps to: Security and Risk Management, Asset Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

This episode of the Isaka podcast is brought to you by One Trust. As organizations move faster with AI, risk [music] is getting harder to see, govern, and scale. New challenges like model drift, hallucinations, [music] model security, and expanded data use are raising the stakes for security, compliance, [music] and business leaders alike. One trust helps organizations take a more integrated approach to risk and compliance. With OneTrust [music] Risk Solutions, teams can better assess AI and technology risk across [music] the IT ecosystem, improve visibility across stakeholders, translate emerging risk into [music] enforcable controls, and support innovation with greater confidence. If you're looking to modernize risk management without slowing [music] the business down, OneTrust can help …