Skip to main content

17 posts tagged with "Security"

Privacy, threat modelling, and secure AI delivery

View All Tags

AI Leadership in the Age of Regulated and Agentic AI

· 30 min read
AI Playbook author

Artificial intelligence leadership is often misunderstood as the ability to select the best model, approve an AI strategy or sponsor a portfolio of proofs of concept. Those activities matter, but they are not the essence of leadership.

AI leadership is the disciplined conversion of uncertain technological capability into measurable, secure, governed and socially acceptable outcomes.

Security, Compliance and Governance for Open-Source and Closed-Source LLM Deployments

· 39 min read
AI Playbook author

Deploying a large language model is not simply a question of choosing between an open-source model and a commercial API. It is an enterprise risk decision involving:

  • What information the system will process.
  • Where that information will travel.
  • Who can access the model, prompts, outputs and logs.
  • What actions the model can perform.
  • How the organisation will detect failures or attacks.
  • Which party is accountable when something goes wrong.
  • What evidence can be presented to auditors, regulators, customers and executives.

End-to-End AI Solution Engineering Playbook: Responsible AI, Governance, Security and Privacy for Banking Customer Service

· 15 min read
AI Playbook author

Before production, MonGo must show the hybrid customer-service AI is lawful, fair, secure, accountable, controllable and fit for purpose. The goal is not zero risk—it is proportionate controls, measured residual risk and evidence for every decision to continue, restrict or stop.

This article is Part VI of the Banking Customer-Service AI playbook. It follows Part I through Part V.

The Practical Core Framework Set for End-to-End AI Solution Engineering

· 22 min read
AI Playbook author

Most AI engagements fail not because the organisation lacks frameworks, but because it has too many of the wrong kind. Teams accumulate strategy canvases, maturity models, scoring formulas and governance checklists until the methodology itself becomes the delivery risk. The practical response is not a larger catalogue. It is a core set: enough structure to run end-to-end AI solution engineering, and little enough that practitioners can actually use it.

Leadership: Protect Quality, Independence and Trust

· 30 min read
AI Playbook author

A Big Four firm does not compete only through its technical expertise, global network, technology platforms or client relationships. Its most valuable asset is trust.

Clients trust the firm with commercially sensitive information, strategic decisions, financial records, personal data and complex regulatory matters. Regulators trust the firm to exercise professional judgement and uphold required standards. Investors, employees, governments and the wider public expect the firm to behave responsibly, independently and ethically.

AI Governance and Information Security: Implementing ISO/IEC 27001 as the ISMS Backbone for Enterprise AI

· 33 min read
AI Playbook author

Information security for AI should not exist as a pile of threat models, vendor questionnaires and one-off pen tests. ISO/IEC 27001 establishes an organisation-wide Information Security Management System—scope, policy, risk assessment, control selection, operation, audit, management review and continual improvement—so confidentiality, integrity and availability remain enforceable when models, retrieval systems, agents and suppliers change.

AI Red Teaming Roadmap: A Practical Guide from Fundamentals to Enterprise Security Testing

· 32 min read
AI Playbook author

Artificial intelligence systems introduce a new class of security problems. A conventional application may fail because of insecure code, weak authentication or an exposed API. An AI application can suffer from all of those problems plus prompt injection, poisoned retrieval data, unsafe tool execution, model extraction, sensitive-data leakage, misleading outputs and autonomous agent behaviour.

AI red teaming is the structured practice of testing these systems from an adversarial perspective. The objective is not simply to make a model produce an inappropriate answer. It is to discover how an attacker, careless user, compromised data source or unexpected interaction could cause the complete AI system to violate its security, safety, privacy or business requirements.