Why do 95% of enterprise AI implementations fail? According to Sandip Wadje, Managing Director at BNP Paribas, many organizations attempt complex reasoning tasks on day one rather than building a mature foundation around data hygiene and simple summarization workflows.
In this episode, Ashish sits down with Sandip to explore how global financial institutions navigate Model Risk Management (MRM), GenAI governance, and regulatory expectations across regions like the UK, EU, and US. Sandip breaks down why classical 20-year-old MRM frameworks fall short when applied to non-deterministic black-box LLMs, and why security leaders must focus on output drift and event taxonomies rather than just input prompt filtering.
We also examine the concept of the "AI Kitchen" - a cross-functional governance model bringing together IT, CISOs, legal, and Data Protection Officers alongside practical strategies for calculating AI blast radius, cleaning up overprivileged non-human identity (NHI) permissions, and training CSIRT teams for ML SecOps incidents.
Questions asked:
00:00 Introduction: AI Risk in Regulated Financial Institutions
01:50 Sandip Wadje’s Background at BNP Paribas
02:50 Classical Model Risk Management (MRM) vs. Generative AI
04:40 Governing the Black Box: Finding the Security Delta
08:00 The CMDB Problem: Building an Accurate AI Use Case Inventory
11:30 Why 95% of AI Projects Fail: Summarize, Write, Reason
15:00 Continuous Evaluation (Evals) and Catching Output Drift
18:50 Event Taxonomy: What Happens When AI Decisions Drift?
25:40 Training CSIRT and SOC Teams for ML SecOps Incidents
30:00 Compensating Controls: Remote Browser Isolation & Prompt Monitoring
34:30 Non-Human Identities (NHI) & Cleaning Birthright Permissions
36:30 Balancing a $1M Savings Against a 4% Revenue Fine
38:30 Open-Weight Models vs. Frontier LLMs in Financial Services
41:00 The "AI Kitchen": Cross-Functional AI Governance
44:30 The #1 Rule for AI Security: Understand Your Data First
Sandip Wadje: [00:00:00] We saw like ninety-five percent of the projects failed. I ended up meeting a CIO in the UK recently, and they said they burned their entire month's of budget with two days of usage, and they were very happy that the US government disconnected it.
Ashish Rajan: If you just buy one of the AI security products, you're probably only solving parts of the risk.
Sandip Wadje: Anywhere you're using AI, the risk is same because if something goes wrong, there is a domino effect. When you attach it to an AI, AI sees everything. All of a sudden, you have a use case that can be operationalized in one month or couple of days. Look, I can say one million, but this four percent fine of my total revenue is not worth it.
Sandip Wadje: Now the output has changed. As a result, your investment patterns have changed. When do you actually detect the drift?
Ashish Rajan: If you have been trying to introduce AI into a regulated space, specifically financial institutes, insurance companies, I had a great conversation with Sandeep Varje. He is the managing director and head of emerging technology and risk at BNP Paribas.
Ashish Rajan: And we spoke about things like what is the right way to assess AI models? How do you even approach the model [00:01:00] risk management? What do you do when you have a burning question of what's the right way to approach a use case that you have been presented with? Because you will have plenty of those in an organization like a bank which has four hundred plus application.
Ashish Rajan: But at the same time, how do you understand the risk as it will change? What are some of the basic things you should have? Is logging enough? Have you trained your incident response people? Should you even move to open weight models? All that and a lot more in this episode of AI Security Podcast. As always, if you have been here for a second or third time and have been following the episodes and really enjoying them, I really appreciate if you take a quick second to drop the follow or subscribe button, whichever podcast platform you listen or watch us on.
Ashish Rajan: We are on Apple, Spotify, YouTube, LinkedIn. And if you have been here for a while, thank you so much for your support. I'll see you in the next one. Enjoy the episode with Sandeep. Peace. Hello, welcome to another episode of the AI Security Podcast. I've got Sandeep with me. Hey, man. Thanks for coming on the show.
Sandip Wadje: Thank you very much for the opportunity. Really appreciate. Thank
Ashish Rajan: you. Oh, yeah, I'm looking forward to this conversation. Maybe just to set some context, if you wanna share a, a bit about yourself, your professional background.
Sandip Wadje: Thank you. So I'm currently with BNP [00:02:00] Paribas, uh, as a managing director for emerging technology risks.
Sandip Wadje: My focus is on cloud artificial intelligence, digital assets, threat intelligence. Been with the bank for nine years now. Been in the UK for fifteen years. Uh, been in cyber for twenty plus years uh, it's quite an exciting journey so far.
Ashish Rajan: That's probably the first place I want to start with.
Ashish Rajan: A lot of conversations that I have with the, let's say, the BFSI or financial security insurance-- fi-financial services insurance companies, a lot of times my conversation about AI security lands on model risk management. And I'd love to kind of maybe, well, deep dive into where is a good place to start, but I would like you to kind of just share some bits on what is model risk management according to you, and is it the right picture to start with?
Sandip Wadje: That's where the foundation has been- Yeah ... from a regulatory perspective, because almost every regulator in the world, particularly, uh, Bank of England, PRA, also, uh, the Feds in the US, uh, everyone has been clear in terms of Laying out principles for model risk management. And when it comes [00:03:00] to model risk management, we're essentially talking about classical AI.
Ashish Rajan: Yeah.
Sandip Wadje: Uh, so- Like
Ashish Rajan: not the J- LLM Not the GenAI.
Sandip Wadje: Not the GenAI
Ashish Rajan: one, yeah.
Sandip Wadje: The GenAI is evolving, right? Yeah. So, so MRM is like pre-GenAI, and a lot of those principles are, like, 15, 20 years old in terms of, uh, having those practices, uh, where, where model is not a black box, right? Where essentially, uh, e- you know everything that goes into the model and, and you know everything that's coming out of the model, so there is no non-deterministic way.
Sandip Wadje: Yeah. There is a testing and evaluation around it, but that's what essentially has been going around to lay down those principles, uh, in terms of, uh, whether it is model development, whether it is governance of model, independent verification of models. That's where in most of the banks you have a separate function which is completely independent to just judge the performance and behavior of the model before it goes into the production.
Sandip Wadje: And in large cases, uh, and almost with most of the financial services institutions, these models, the classical models, um, if they're deployed in front office or critical use cases, uh, it's common [00:04:00] practice to then share that information, uh, in, in, in fact, including, uh, the model themselves, uh, with the regulators so the regulator knows that the models are fit for purpose and they're not taking some wrong decisions.
Sandip Wadje: Yeah.
Ashish Rajan: Yeah.
Sandip Wadje: But this is the classical AI and, and then we are in a completely different trajectory for the last couple of years, yeah. How
Ashish Rajan: does that change, and what complements and what are probably not things you should move forward into the GenAI world, the black box?
Sandip Wadje: What changes with GenAI is, of course, it's non-deterministic, but then we were in a conference with a lot of model risk management professionals, CIOs, and data scientists.
Sandip Wadje: And we came to an, uh, conclusion in the table is like there are like one thousand people in the globe who actually know what's inside the model, how it actually works end to end- ... from those, you know, algorithms and the calculations, everything w- that goes into a GenAI model.
Ashish Rajan: Yeah.
Sandip Wadje: And then outside that, everyone is playing at the periphery of input and output, uh, in terms of how to deal with that black box.
Sandip Wadje: So that black box changes then, uh, how we deal [00:05:00]with that AI-
Ashish Rajan: Yeah ...
Sandip Wadje: uh, and then how we handle you know, the governance around GenAI.
Ashish Rajan: And I think this is an interesting one because a lot of people start with we can probably just drag the same model as before. People used to think we're talking about security controls.
Ashish Rajan: They were not thinking about risk management. And to what you're saying, it's a black box, and there's very few people who even understand what's inside that black box. How should people approach? Is this a new risk register? Is this like... How are you approaching-- Or I guess maybe let me just be more specific.
Ashish Rajan: How would you say to your colleagues and stuff who are in the banking industry and the FSI industry, how should they approach this? 'Cause a lot of people have still not accepted because for them there's no policy for it, so I don't want to be the guy or gal who's saying AI first. There's already a lot of skepticism, and as much as the, the world would like to believe, or at least they would want us to believe that everyone's doing AI, there's definitely a set of FSIs who have basically said, "No AI in the organization," because they're uncomfortable.
Sandip Wadje: That's true. That's
Ashish Rajan: true. So for those colleagues in the industry, what's your [00:06:00] recommendation for how to even approach this if they were to be going down that path?
Sandip Wadje: Sometimes I extend the COVID-19 analogy.
Ashish Rajan: Oh, okay.
Sandip Wadje: Is we had the pandemic. We all knew how the virus worked. We all responded differently.
Ashish Rajan: Mm-hmm.
Sandip Wadje: And sometimes-- And you will see that a lot in technology as well. Every time there has been evolution of technology-
Ashish Rajan: Yeah ...
Sandip Wadje: the tendency is we react differently in Europe, we re- react differently in US. Of course, everyone has their own selfish motivations as well as their, uh, the regional dynamics, whatever the local regulator is saying.
Sandip Wadje: But we do have tendency where whenever the next evolution of technology happens, we respond a little differently or, uh, even though it's done, the basics are the same.
Ashish Rajan: Yep.
Sandip Wadje: So i- in that context, I think there are a couple of things that stand out is if, if you have been running a financial institution for ten, twenty, thirty, forty years- There are certain things that are quite common, right?
Sandip Wadje: And this happened to me when I started looking into governance of AI. The first task that my boss gave to me saying, "We already have access management, we already have data protection." [00:07:00] Yeah. "Can you tell me the delta?"
Ashish Rajan: Yeah, yeah.
Sandip Wadje: What- "Can you tell me what is the delta I need to cover? Don't tell me that I need to start all over again."
Sandip Wadje: Yeah,
Ashish Rajan: yeah.
Sandip Wadje: So I'm like, "That's interesting homework."
Ashish Rajan: Mm-hmm,
Sandip Wadje: mm-hmm. So then I went on to do the exercise of essentially getting all the controls that we have for access control data protection, and then we did an exercise to identify, okay, what is the percentage of delta introduced by this new technology?
Ashish Rajan: Yeah.
Sandip Wadje: So that's a good way to look at, like, what is that additional delta that needs to be covered. That still doesn't change the other dynamics, which is the explanator- explainability around the output, and then which is something, again, you can address it differently by fine-tuning your governance before the project.
Sandip Wadje: Uh, identifying the right set of controls for that use case, which also means then you're prioritizing your use case in the right way, high risk use case, medium risk use case. And then you determine governance based on how critical that use case is for the organization. So determining certain controls before actually the use case goes live is also equally important.
Sandip Wadje: While I'm there on that use case topic, a lot of [00:08:00]organizations actually miss the board in a way that a regulator cares about AI usage.
Sandip Wadje: They don't care, like, whether you use OpenAI or Anthropic or anything else. They want you to tell them where and how AI is used. And a lot of that goes back to maintaining that inventory.
Ashish Rajan: Yeah.
Sandip Wadje: And not just the inventory, but very minute details of information.
Ashish Rajan: Oh,
Sandip Wadje: like
Ashish Rajan: what model-
Sandip Wadje: Yes.
Ashish Rajan: Yeah. What version of the model.
Sandip Wadje: Both and the use case information itself. We are going back to the CMDB issue.
Ashish Rajan: Oh, yeah, yeah, yeah. Okay.
Sandip Wadje: Yeah, because, uh, like regulator will ask, uh, "Give me use cases where personal data is used."
Ashish Rajan: Mm-hmm. "
Sandip Wadje: Give me a use cases where it is market-facing use cases, where this is internal use case."
Sandip Wadje: And then you're going around and, and you're in all fast-forward mode, right? You're trying to test AI and new models and things, and you're not maintaining that information. Large amount of then, you know, energy is then spent in just building that inventory in a almost like a reactive mode, which you could have been sorted out in a proactive mode.
Sandip Wadje: Mm. So the use case inventory is a critical part. The controls pre-implementation rollout is a second important part. And then how [00:09:00]do you continuously monitor the output? And this is something, again, you know, we can little bit zoom in as to how do you deal with output, which is non-deterministic in nature.
Ashish Rajan: Yeah.
Sandip Wadje: And what kind of governance can, can we put on top of that?
Ashish Rajan: Yeah. And I think I definitely would love to do... Maybe this is interesting because for people who have said no so far, they would hear your answer and go, "Well, that's not how I understood policy, because for me, I have my... Obviously, there are the regulatory standards that I have to maintain, then there is the en-enforcers of those."
Ashish Rajan: Is this coming and especially because if you're a bank which is global, which has presence in America, presence in Europe, there's all these different acts that you have to follow as well. Does this map out or does this apply when it comes to being compliant to acts as well or being able to j- Yeah, yeah.
Ashish Rajan: But, I mean, I already-- I'm not even talking about GDPR and stuff, but like, say, let's just talk about between difference between UK, Europe, and USA as well. There's like three, three different acts to follow in different situations as well, right?
Sandip Wadje: Absolutely. You have regulations to follow, but you have to keep in mind, and, and I also wanted to put the emphasis [00:10:00] on cross-functional stakeholder management, extremely important.
Sandip Wadje: Mm. Particularly with GenAI Because it is moving so fast. Now you have your board members, your CEOs who are talking to each other.
Sandip Wadje: They're probably meeting some of these CEOs in conferences, OpenAI CEO, Anthropic CEO, so they have their own perspective on what is going on.
Ashish Rajan: Yeah.
Sandip Wadje: Then you have your control function owners-
Ashish Rajan: Mm.
Sandip Wadje: -legal, privacy, your IT, CISO.
Ashish Rajan: Gov
Sandip Wadje: council. They have their own-- They're-- Yeah, they have their own perspective on- Yeah. -what GenAI means to them, and then you have regulator, and, and that's what I talk a lot about, uh, emerging tech is because my definition of emerging tech is an area for which controls have not been formalized.
Ashish Rajan: Yeah.
Sandip Wadje: Yeah. There is no agreement on what controls should be, uh, whether with-within the bank or outside the bank.
Ashish Rajan: Yeah.
Sandip Wadje: So in this case then, you have to actually take everyone on the same journey. You have to assume that maybe regulator needs to be educated, maybe the internal stakeholders need to be educated.
Sandip Wadje: So I think the first step in [00:11:00] governing AI or securing AI is to validate with everyone who you are talking to it, do I have the-- do we have the same definition-
Ashish Rajan: Mm. -
Sandip Wadje: of what AI means to you? Because for many times, people will have different interpretation of what AI means to them. Yeah, that is a good foundation to then start going in the next direction.
Ashish Rajan: I guess you're right because then you can focus on the case, use cases and then double down on that. Yes. And 'cause obviously being a bank, I-- like, I think on an average, there are over 100 applications in a regular bank in a non-GenAI space, as in the pre-GenAI era. I imagine with GenAI it's even more with, like, just- Yes.
Ashish Rajan: -the specific use cases, like I want each one of those 400-plus ones to also have LLM use cases as well. Yes. Now you-- which-- Is there, in all the work that you did, did you found any, what's the, maybe tactical use cases that are usually easy ones to say, "You know what? These are easy to govern," or "These are complex because it's complex one because there's too much personal data in there," or it-- uh, 'cause I'm coming from a perspective that if I were to wear the hat of those people who basically have [00:12:00] said no so far for AI, they've heard the story, they get the message, but now like, "Oh, which one should I-- I've got 400 use cases."
Ashish Rajan: Everyone wants a si-slice of this. What are the easy ones to start with?
Sandip Wadje: I think the easy ones to start with, and I've, I've said this quite some times now, is put them in the buckets of summarize, write, and reason. Oh. And start with summarization first, then go to write, and then go to reason. Uh, summarization is the most common corporate activity, whether it is summarizing emails, summarizing memos taking actions on certain meetings, et cetera.
Sandip Wadje: A good example of summarization can also be then cross-verifying things. Misbooking of revenue is a very good example. It's such an important and such a useful, uh, use case, uh, which is not, uh, tough at all. You're getting AI to read the contract, check the number or value in the contract, and verify in the revenue booking tool whether the number is correct.
Ashish Rajan: Mm.
Sandip Wadje: Uh, it, it then solves such a big, uh, you know, headache for the executives. So sometimes the small, small problems can have a very high value from executive perspective. And then summarization can be a re- then a really good way [00:13:00] to start with, saying, "Okay, let's try out... It's a non-deterministic technology.
Sandip Wadje: Let's try our hands with summarization. Then let's get it to write certain things, measure the quality, and then go to reasoning." Where we see things go wrong is when people try to pilot strict with reasoning on day one, and then they end up burning a lot of, you know, capital, both the political capital and the real capital-
Sandip Wadje: uh, in, in terms of, you know, execution of that use case. And that's why we saw, like, 95% of the projects failed, right? Yeah. That's what came up in the MIT survey end of last year.
Ashish Rajan: Yeah. So would you put the, you know, the AI tooling which is available on the internet, which, "Hey, let me create an image for you," or, "I can create a vibe-coded app," would that be in your reasoning bucket?
Ashish Rajan: Or would that be in the read bucket?
Sandip Wadje: The vibe coded is, again, would fall into the reasoning bucket because you create a vibe coded app-
Ashish Rajan: Yeah ...
Sandip Wadje: sounds very easy because the entire development time- timelines have shrinked.
Ashish Rajan: Yeah.
Sandip Wadje: But then who is maintaining that app? Who is closing the feedback loop? And you're back to square one.
Sandip Wadje: Yeah. So you see that productivity, [00:14:00] you don't see the effort behind the productivity to maintain and get the same output on a regular basis.
Ashish Rajan: Mm.
Sandip Wadje: So one is the type of use cases, and second is the prerequisite, right? The prerequisite is you have figured out how to, clean the data and then the, the clean data is available for AI.
Sandip Wadje: You figured out who is going to maintain the feedback loop. Yeah,
Ashish Rajan: yeah.
Sandip Wadje: A lot of the times you do pilot, and then you forget, like, you need someone twenty-four by seven to maintain the feedback loop.
Ashish Rajan: Which is this the feedback loop between the LLM and your actual data or be- between systems?
Sandip Wadje: Monitoring the output and making sure, uh, it doesn't drift.
Ashish Rajan: Like an
Sandip Wadje: eval? Yes, evals, yeah. Yeah, yeah, yeah. So you, you, you still need to fine-tune it, right? Yeah.
Ashish Rajan: It's,
Sandip Wadje: it's a non-deterministic tech, so somebody needs to look after it and fine-tune it continuously.
Ashish Rajan: Yeah. And I guess for people who probably don't-- won't even-- who don't understand eval, the simple example could be the fact that even if you're using Claude or OpenAI, you may be making it do the same thing ten times.
Ashish Rajan: The eleventh time, somehow it just forgets what it did for the first ten times, so you have to remind it again. That's technically the simplest way to explain eval. [00:15:00] Would that be right?
Sandip Wadje: Yes. I can give a simple example of translation model. Yeah. Because a lot of organizations have gone that journey.
Ashish Rajan: Yeah.
Sandip Wadje: Global organization, even like we are a very glo-- large global organization, multilingual organization. You have office in Spain, you have office in France, India, so many places. And then there are people who use, you know, uh, their kind of local language. And as a part of the day-to-day corporate job, you want, like, I want translation to be accurate.
Ashish Rajan: Mm.
Sandip Wadje: And now- Uh, a lot of companies moved from the translation software for which they used to pay a lot of money to in-house translation using GenAI. And the data scientists now will come up with different set of approaches as to how will they check accuracy of the translation. One is maybe sampling.
Ashish Rajan: Mm.
Sandip Wadje: And some human is doing the sampling and checking the translation. The second best approach is getting another AI to be validated, and the third AI to be, you know, the final checker. So it is AI doing validation of the AI output. But you may still have the cases where certain things fall out because, again, large language models are [00:16:00] predominantly built on the English language.
Sandip Wadje: Yeah. Not necessarily, uh, you know, they're going to get things right when it comes to French or Spanish or any other languages. So we look at a use case from IT perspective, we think of access control, data protection. We don't think of output and explainability around the output, and this is where things get tricky, and translation is a good example.
Ashish Rajan: Yeah.
Sandip Wadje: You can have other AI to check, you know, the output of your AI doing translation. Well, that doesn't mean that it's going to be 100% accurate.
Ashish Rajan: So in your example, uh, the translation is so going back to the output thing that we spoke about, how there should be continuous monitoring of the output piece.
Ashish Rajan: Maybe we can unpack that a bit more considering we're at least give-- we've given a few examples to the audience for translation and the three summary.
Sandip Wadje: You can continue on the translation. You can use translation-
Ashish Rajan: Yeah ...
Sandip Wadje: for communication in your town hall.
Sandip Wadje: That's awesome. Maybe one or two words go here and there wrong, you can deal with it.
Ashish Rajan: Yeah.
Sandip Wadje: You use translation on a contract document and the interpretation is wrong. Now you're looking at a much higher risk and much higher value.
Ashish Rajan: Yeah.
Sandip Wadje: So there, again, you look at the use case. It [00:17:00] was a very straightforward use case of AI, you know, understanding something in French, translating in English.
Ashish Rajan: Yeah, yeah.
Sandip Wadje: Or vice versa. And what you find yourself now is the context You know?
Ashish Rajan: Mm.
Sandip Wadje: AI wrote something in English for you to go and talk in a, in a town hall versus, uh, AI writing something that's, uh, lands on a multimillion contract.
Ashish Rajan: Yeah.
Sandip Wadje: Two different things.
Ashish Rajan: Even from an investment perspective, like a lot of banking sector is into investing in stocks and stuff as well, or companies that are about to be released.
Ashish Rajan: And to your point, a zero extra or a zero less is could, could mean a huge difference.
Sandip Wadje: Yes. Yes. Exactly. Exactly.
Ashish Rajan: Do you find that-- uh, when you were specifi- talking about the, the focus on output, bringing it back to the security side, obviously, those are very business-focused examples, 100%. So to kind of paint the whole picture from a security perspective, if I was a security person in a, let's just say, a global bank, and I had the translation now we've understood that, "Hey, we have an AI software that's gonna be used for translation of contracts."
Ashish Rajan: I have a data scientist who looks at the eval, but I [00:18:00]also have an actual person who deals with contracts looking at this as well, going, "Is this supposed to be yay or nay?" Like someone from a legal team, for example. A lot of conversation always comes down to, "Hey, let's just give that to a governance council and let them decide if this tool is good or not."
Ashish Rajan: Is that a good approach for managing this, and then it goes into the whole model risk management again after that?
Sandip Wadje: Yes. Probably not a good approach because the governance council does not understand, and that is again, we talked about this, is most of the people trying to put governance around GenAI-
Ashish Rajan: Yeah
Sandip Wadje: do not have any understanding of, uh, eval frameworks. And no one says, "Hey, can we review the eval framework from the data scientist before we decide how to, you know, do what to do with this use case?" No one. Everyone is looking at, like, what is this use case? Which model used? Uh, which application it is connecting to?
Sandip Wadje: What is the data? And, and that output focus is completely missing.
Ashish Rajan: Yeah.
Sandip Wadje: The-- I think the, the key is essentially, and, uh, this is what we did actually, is to look at like- What are the different risk [00:19:00] events coming out from AI output?
Ashish Rajan: Mm-hmm.
Sandip Wadje: Uh, and, and then what would be the potential consequences of certain things going wrong?
Sandip Wadje: So what you essentially done is you looked at your event taxonomy. You will have events that happen, right? You have a phishing attack, you have operational failure. Then you ask, "Hey, I'm using this non-deterministic technology now, what can go wrong?"
Ashish Rajan: Mm.
Sandip Wadje: And maybe there are some new risk events that you didn't think of.
Sandip Wadje: You put those new risk events, the new taxonomy, and then you ask, "Okay, now I understand things that might go wrong." And translation is a good example. Again, we can stick to it, like things might go wrong from legal perspective or this chief operating officer says something in a town hall they should not have said.
Sandip Wadje: Now, there is a reputational impact, there is a financial impact, and you can work backwards like, okay, who is responsible for this?
Sandip Wadje: Who is accountable for this? If there is a financial loss, there is a certain person responsible for it. If it's a failure in terms of data privacy rules or regulation, there is a person responsible for this.
Sandip Wadje: That also allows you to fine-tune the governance, because once you have identified [00:20:00] if GenAI does not deliver the out- intended output and something goes wrong, I now know which person is accountable for that, and that person needs to be part of that governance in terms of validating the things. And not necessarily the, the person who, with the IT hat and data protection hat on.
Ashish Rajan: Yeah.
Sandip Wadje: Because they're doing their job from that domain perspective, but they're not accountable when things go wrong from output perspective.
Ashish Rajan: Ashish, that's an interesting and important point around the e-event taxonomy as well as who's accountable in the use cases, going back to what you were talking about with the use cases.
Ashish Rajan: If it's, it's important for the use cases to have an owner, going back to what we have done in the past before, it's not like a new concept at that point in time. But if you can double-click on the event taxonomy for me, like, 'cause a lot of people would not even understand then is that just my SIEM logs or is that my collection of open telemetry for my input/output prompt, and, uh, what's, what am I giving out as an input?
Ashish Rajan: 'Cause if you look at the way vendors have sold solutions today, it's been sold on the LLM firewalls. [00:21:00] "Hey, your user may put something suspicious." And I'm not saying vendors are pitching the wrong thing, but more coming from the, the use cases that most people are trying to to- solve or talk about from a security perspective is your LLM firewall, where, hey, is this person putting something sensitive?
Ashish Rajan: Then there is the gateways. Hey, any conversation goes through us. And the other one that people have been go-- talking about is auto-automation of security, uh, work. Now, you kind of mentioned this, uh, before we started recording about how AI for security and security for AI are the s- two sides of the same coin.
Ashish Rajan: Bringing that back to this example of event taxonomy, are we already collecting this and or do we not need all this extra bedazzle that we've been sold? Or is this event taxonomy for you If you use a translation example, what would that look like?
Sandip Wadje: So, um, I'll give a completely different example of- Sure
Sandip Wadje: uh, e-event taxonomy. Let us say you're using GenAI to make investment decisions, and that investment decision is based on understanding of your financial portfolio, [00:22:00] understanding the market data, uh, understanding of, uh, open source, uh, intelligence or- Yeah ... geopolitical trends. And now if you have done governance of that particular-- Now you have a GenAI technology that is taking investment decisions on your behalf.
Sandip Wadje: Yeah. And you have done everything right, okay? Uh, you looked at prompt engineering risk, you looked at access control, you looked at data security. And for whatever reason, let's assume for the fact that the market data was manipulated.
Ashish Rajan: Yeah.
Sandip Wadje: So the output is going to drift.
Ashish Rajan: Yeah.
Sandip Wadje: You've done everything right.
Ashish Rajan: That's right, yeah.
Sandip Wadje: Yeah. But now the output has changed. As a result, your investment patterns have changed. When do you actually detect the drift? And that's where it gets interesting, is the deviations need to be continuously monitored, and that's a job itself understanding those event types. Then you understand, you ask yourself, okay, let me look at it.
Sandip Wadje: This scenario-- You might not have thought about this scenario, right? Because today you have humans who will read every market data report.
Ashish Rajan: Yeah.
Sandip Wadje: They'll punch information after it goes through three pairs of eye- Yeah ... before it lands into some investment memo- [00:23:00] Yeah ... and the decision happens.
Ashish Rajan: Yeah.
Sandip Wadje: Now, you took a decision.
Sandip Wadje: Instead of a person going through market data report, these geopolitics reports, and making me a summary that gets into my investment memo before someone takes decision-
Ashish Rajan: Yeah ...
Sandip Wadje: I've delegated everything to AI. Now you've got three different sources where the data quality or intentional manipulation of data can drift your output, and that has real, financial consequences.
Sandip Wadje: So you, you really have to work backwards on the scenarios. So I think this scenario exercise has not been, like, thought through, uh, when it comes to risk events. Yeah.
Ashish Rajan: So
Sandip Wadje: when I say risk events, it is purely to do with the drift in the AI output and how that drift is going to happen.
Ashish Rajan: And how would you catch it?
Sandip Wadje: How do you catch it?
Ashish Rajan: Yeah.
Sandip Wadje: So it's not just the-- That's where I think the s-security solutions approach that you talked about from- Yeah ... AI security perspective, I think it's predominantly to do with model is going to do something wrong- ... or user is going to do something wrong.
Ashish Rajan: Yeah.
Sandip Wadje: But there are so many other dimensions, right?
Ashish Rajan: Yeah, as a business that you would care about, which they-- And to [00:24:00] your point, I don't think the vendors can actually solve that problem as well, 'cause they can't-- 'cause this is obviously an example of, say, like, just if I was using a, I don't know, an AI legal software that's popular or like a Harvey or whatever the other popular legal one could be.
Ashish Rajan: I could be the-- using the one for investment because it just happens to be the most popular one. People's-- All my colleagues are using it, so I'm also using it. There could also be applications that are in-house, which is very common in FSI's industry. We all have custom applications that have been created.
Ashish Rajan: Now, all of them have AI bolted on or, uh, or attached to it. I feel like this principle would still apply there as well in those use cases and completely fall in that same bracket of what you were talking about in terms of the risk being created and who's testing the output continuously- Yes ... for the drift.
Ashish Rajan: That doesn't change even if it's, like, your proprietary outside applica- AI application versus an internal application. Would that be right? Did I get that right?
Sandip Wadje: That's correct. That's correct. Anywhere you're using AI, shadow AI- Yeah ... or GenAI in that sense, the risk is same. Because if [00:25:00] something goes wrong, there is a domino effect.
Ashish Rajan: Yeah.
Sandip Wadje: And you need to have accounted for that scenario. The worst thing you will do, particularly in the large financial institutions, of not having accounted for that scenario, because then no executive likes, surprises that they had not thought about.
Ashish Rajan: Yeah,
Sandip Wadje: yeah. Like, "Oh, we didn't think about this."
Sandip Wadje: That doesn't look good on you. '
Ashish Rajan: Cause to, to your point, if you just buy one of the AI security products, you're probably only solving parts of the risk, not the entire, probably the whole other set of risks that you need to care about.
Sandip Wadje: Yes. And there are different spotlights, right? We talked about this, and this one spotlight is, uh, the, uh, the asset inventory, your AI use cases, your data and metadata about use cases.
Sandip Wadje: Second is your pre go live governance, having right set of controls before you actually roll out the use case. Data lifecycle, which very much applies to that investment scenario, where if, if data intentionally or unintentionally got manipulated-
Ashish Rajan: Yeah ...
Sandip Wadje: you are able to detect that in the output drift and take some corrective actions.
Sandip Wadje: So data lifecycle. Again, in the cybersecurity context, when we say data lifecycle management, [00:26:00] everyone is thinking about, like, personal data and this. Yeah. It can be the quality of data also which can have a, a far-reaching consequences in AI output, uh, in terms of decisions that are taken. Then you have essentially the model themselves and attestation of those models from a security and behavior perspective.
Ashish Rajan: Mm.
Sandip Wadje: And then you have almost like-- And this is also we talked a lot about is, are we training our SOC teams to investigate AI incidents?
Ashish Rajan: Oh, tell me more.
Sandip Wadje: So the SOC teams today are focused more on phishing campaigns, incidents, stuff goes wrong.
Ashish Rajan: Yeah. I get an alert from my cloud security company.
Sandip Wadje: Yeah. Yes.
Sandip Wadje: Have you, have you trained-- Let's take an example of the eval framework.
Ashish Rajan: Yeah.
Sandip Wadje: Something bad has happened, and now your CSIRT got involved. They had no idea about eval frameworks- ... about what data. They'll have to access everything, right?
Ashish Rajan: Yeah, yeah.
Sandip Wadje: And
Ashish Rajan: yeah. Forensic would also need that info-
Sandip Wadje: information. So have you trained your, uh, s- CSIRT guys or, or the team saying, "Hey, we have this new technology.
Sandip Wadje: This is how it works. These are [00:27:00] the things or components of this, and, and maybe these are the things can go wrong. So when you do investigation, you have to follow these things." So I think we have to invest a lot on training our SOC teams on how to investigate AI incidents. Uh, I, I don't think effort has gone in that direction.
Sandip Wadje: Because one is SecOps.
Ashish Rajan: Yeah.
Sandip Wadje: And second is ML
Ashish Rajan: SecOps. Mm. Okay.
Sandip Wadje: Yeah. And if you look at MLOps-
Ashish Rajan: Yeah ...
Sandip Wadje: which was traditionally data scientist responsibility.
Ashish Rajan: That's right, yeah. They were doing the m- pipeline and everything.
Sandip Wadje: Yeah. Exactly. So now you have something that was predominantly data scientist responsibility- Yeah
Sandip Wadje: is scaling up, right? Yeah. Because before the GenA-- the classical AI adoption was in tranches. Like, you will do, like, 30, 40 use cases in a year, then it goes into production. And most of the time, when it, it's getting into the production, it is almost getting into production as an AI application and not necessarily as out of hand non-deterministic technology.
Ashish Rajan: Yeah.
Sandip Wadje: But now the more you go ahead, 5, 10, 30, 40 GenAI use cases, you really have to train your SOC [00:28:00] teams how to investigate them when things go wrong.
Ashish Rajan: Even forensic for that matter as well, they would have. 100%. 'Cause there is no undo button, I guess, in this context. And if you don't have the telemetry, and there's no data to collect-
Sandip Wadje: Yes.
Ashish Rajan: Yes ... then what do you do at that point in time? It's like, well, I just... Who looks at this black box-
Sandip Wadje: Yes ...
Ashish Rajan: at this point in time? Yes. Ashish, so what do you think is, like, the-- 'Cause I think earlier, and I'm sure the conversation has evolved quite a bit, and I, I will put my hat back on for p- the individual working in the regulated industry who has not deployed AI, a lot of the initial focus used to be on the fact that I can't make my AI give me the same response every single time.
Ashish Rajan: That used to be the, uh, the ultimate focus is like, "Hey, we can't let this thing go in p- in production," because of all the use case that happened where I think the chatbot gave, I don't know, a car for $1 or whatever, and they had to do... There, there were a lot of so many use cases. And I think that became like the, the number one thing people cared about.
Ashish Rajan: If it can't give me accurate responses, I'm not comfortable, as a security person, [00:29:00] not comfortable for this thing to go into production. I'm sure there are people like that who are still in that board who have not been introduced to eval, perhaps because the organization itself is not mature enough to think of evals as a thing because maybe they're not looking at it the right way, is what's the minimum that people should think about when it comes to AI security in terms of there's obviously people have enterprise browsers these days.
Ashish Rajan: Browser security is a thing. There's CLI if you-- and there's endpoint security. The list just goes on. I think what you were saying earlier, everyone is thinking about what's the delta, because I'm being asked to put this in production, but I wanted to understand what my gaps are. To your point, I followed Sandeep's advice for a lot of the use cases, but I feel I need some security things because, hey, there could be prompt injection.
Ashish Rajan: So is there like a maybe three or four things that people should think about as good foundation security things to have? But it could be browser security, 'cause apparently everyone's using ChatGPT on a browser. Where do you sit on that for, hey, [00:30:00] these are some of-- this is how what you would approach tackling some of the security components, and which one of these browser, CLI, whatever, where, where do you think are, are even relevant, if that makes sense, in the way we are going with emerging tech?
Sandip Wadje: So I talk a lot about compensating controls.
Sandip Wadje: And everything that you already have or a technology that has matured-
Ashish Rajan: Mm ...
Sandip Wadje: helps you along the way. So if you have a remote browser isolation solution-
Ashish Rajan: Yeah ...
Sandip Wadje: it's a very good DLP filter. It's going to detect certain traffic that you can stop.
Ashish Rajan: Yeah.
Sandip Wadje: So, and same goes with the authentication as well, right?
Sandip Wadje: So if there is authentication traffic going and you have RBI in between, you can use RBI as a switch to say, "Hey, you know what? This kind of traffic I'm not going to allow." So Every technology you can look at, like, how do I use this in terms of... So you first you found out the delta.
Ashish Rajan: Yeah.
Sandip Wadje: This is something is not in my hand, and a good example in DLP is, uh, regex-based approach, right?
Ashish Rajan: Mm.
Sandip Wadje: Uh, we have, we had regex-based approach. It doesn't work in GenAI-
Ashish Rajan: Yeah ...
Sandip Wadje: because people, users can be smart enough to navigate and, [00:31:00] you know, get confidential information out. So you can use compensating controls. RBA is a good example. Segmentation is a very good example, particularly from a kill switch perspective.
Ashish Rajan: Mm.
Sandip Wadje: So if you have AI agents, you should ask yourself, "Hey, can I segment this differently so that I reduce the blast radius?" So I think find out what compensating controls will work. A lot of this also goes back to the data hygiene. If you have not cleaned the data, if you have not cleaned the access management or the access rights for users or AI agents, both actually.
Ashish Rajan: Yeah.
Sandip Wadje: So if, if I'm a user with unrestricted access to all sort of data, the copilot associated with my account is going to have an access, and, and then everyone who has a shared access in the same boundary can probably see the document they should not have seen. So I think I would say you need to look at compensating controls.
Sandip Wadje: You need to look at what are the additional security issues that I'm dealing with as a result of this technology.
Sandip Wadje: And, and then you can work backwards. Uh, like for example, I would accept the fact that you still want to monitor the prompts for a lot of reasons, right? Acceptable use policy, regulatory [00:32:00] violations, et cetera.
Ashish Rajan: Yeah.
Sandip Wadje: So you're still trying to s- look at prompts. Yeah. Not just prompt injection, but you, you want to monitor all the prompts. The input prompt. Output prompt, yeah. Exactly. That also gives you, like... it's also very important data to understand your employees' behavior, how do they think, how are, are they using AI effectively- Yeah
Sandip Wadje: so that someone goes back and trains them. So yes, uh, the, the prompt is a good area where, you know, you need a new technology-
Ashish Rajan: Yeah ...
Sandip Wadje: because that area didn't exist before. So you can have something that allows you to not just stop prompt injection, but analyze the prompts and help you with, you know, essentially, uh, those things.
Sandip Wadje: But more and more I see, I think it is essentially moving towards, like- Two domains. One is the user behavior and agent behavior.
Sandip Wadje: And then I think we are seeing, and I'm, I'm sure we talked about it, we, we are seeing essentially the focus, uh, where companies are now moving towards like maybe this is an endpoint issue where I can essentially attach that user and agent behavior and track the whole, uh, activity using that endpoint.
Sandip Wadje: And I think that's where I see a lot of convergence going to [00:33:00] happen in, in next, you know, uh, couple of months or years. '
Ashish Rajan: Cause I guess to your point, at the end of the day, the developer, whatever agent they end up using would be on a, hopefully a work laptop, so that becomes the endpoint that you monitor.
Ashish Rajan: Would that endpoint analogy work in the case of AI workloads, like the applications that are now AI bolted on or AI first?
Sandip Wadje: As long as there is an identity attached to that, uh, AI usage-
Ashish Rajan: Yeah ...
Sandip Wadje: you'll be able to essentially then monitor, uh, the, the trajectory as to where that AI is going and then what actions it is taking.
Ashish Rajan: I, I can already hear the, the identity folks in the audience going, "But Sandeep, NHI, it's, we have never seen this before." Like, like do we, do we, we need a se-separate solution for that. I, I get prompting. I think you and I spoke about the NHI component in terms of, and I think I'm gonna just double-click on that as well 'cause I think there seems to be a few topics.
Ashish Rajan: There's definitely endpoint as a theme, I agree, is coming up quite often as a conversation about it. Agent as a whole is a conversation, but a lot of that agent conversation seems to end on the identity [00:34:00] piece. I'm curious as to how do you see people approach it and are there compositing controls that people call for?
Ashish Rajan: We spoke about the data compositing controls for DLP. Are there any that come in mind for NHI or agent?
Sandip Wadje: So on the identity, and I have spent a significant amount of time on identity projects, uh, uh, you know- start of my career, and for the benefit of the audience, you know, who is listening, when Sandeep has a birthright access to certain assets or applications, uh, in, in the environment, that's what visible to me.
Sandip Wadje: But there are things that are invisible to me, which are essentially low-level entitlements and things, and this is essentially, this is a known issue.
Ashish Rajan: Yeah.
Sandip Wadje: This is essentially the role design issue. What you do is you create roles for employees in the organization that, okay, Sandeep is an employee.
Sandip Wadje: There is a birthright access to have access to Windows laptop, to have access to OneDrive, and then Sandeep works for this trading division, and then that two or three other kind of, you know, applications you have access to. But this is just a role, [00:35:00] which is orchestration of certain privileges attached to your role, not necessarily everything.
Ashish Rajan: Yeah.
Sandip Wadje: But when you attach it to an AI, AI sees everything. A good test is if you go ever, it doesn't matter which corporate laptop you have, if you go to the command prompt and see what else is available to you, you'll be quite surprised, like, "Oh, wow, I didn't realize I had so many privileges associated with my account."
Sandip Wadje: So the bigger issue is, and which is something we talked about at a roundtable in Davos earlier this year, is what I find very funny, if you're using GenAI and you're starting with something new, I would expect you to clean up that access and then start, right? So to start with something new and then say, "Okay, I need a solution for that," it, that just doesn't make any sense.
Sandip Wadje: So you're essentially not following the SDLC principles, uh, in terms of, you know, implementing new AI agent. So my first recommendation is if you're building, deploying AI agents, clean up the permissions that AI should not have access to.
Ashish Rajan: Yeah.
Sandip Wadje: To give AI the unnecessary permissions and then thinking, then ask [00:36:00] yourself, "I need a monitoring tool or a preventative tool," then you essentially are finding yourself, you know, uh, in, in the, in the same thing again and again.
Ashish Rajan: But you know how I imagine, because I also started my career in identity and access management, least privilege is probably like the, those mysteries that would never get solved, and I'm sure every engineer out there is like, "But my agent requires more permission." Have you found a good answer for that in terms of when working with, on that obviously we're talking about endpoint and agent, so in that agent ecosystem of identity, going back to what you said about the use case, that determines the least privilege or is it the, the business decision?
Ashish Rajan: The
Sandip Wadje: use case determines the blast radius.
Ashish Rajan: Yeah.
Sandip Wadje: The use case determines the risk event.
Ashish Rajan: Yeah.
Sandip Wadje: And the blast radius plus risk events is a question you have to ask yourself. Because now the use case gives you some benefits of automation. So let us say by implementing that AI use case, you are saving 1 million a year.
Sandip Wadje: But the probability of that use case going wrong and you paying 4% of [00:37:00] your, you know, annual- Profit ... revenue-
Ashish Rajan: Yeah ...
Sandip Wadje: for some, uh, you know, fine, it's a completely different thing. Right. And then you, then you take a step back saying, "Look, I can save 1 million, but this 4% fine of my total revenue is not worth it."
Ashish Rajan: Yeah. "
Sandip Wadje: I'm going to park this until I get a confidence that I can actually monitor this end to end." Yeah.
Ashish Rajan: Yeah.
Sandip Wadje: So th- that's what is not happening. And then you see incidents happening because people just go super excited, try to kind of implement AI.
Ashish Rajan: And that's where the people talk about token maxing, where people just basically burning out tokens in millions and just not seeing the results.
Sandip Wadje: That's correct. That's correct. Because the models are improving, you're getting a much longer context window.
Ashish Rajan: Yeah.
Sandip Wadje: And you see the models kind of giving you the out you desired, you get excited, and then you're putting a lot of data straight onto the model and you're kind of, you know, uh, burning tokens. I ended up meeting a CIO in the UK recently, and They said, uh, they burned their entire month's of budget with two days of Fa- Fable usage.
Sandip Wadje: And, and they were very happy that the US [00:38:00]government disconnected it. Oh, really? Yeah, because they were worried that w-what would ha- you know, what would happen if, uh, if it continued. Yes. So I think with open weight model, open weight models and all, probably the token prices would go down, but that still doesn't solve the context thing.
Sandip Wadje: Yeah. As long as you have users putting a lot of data to get the output they want from AI, you will still have a lot of kind of, token consumption.
Ashish Rajan: I think-
Sandip Wadje: Even if token price goes down-
Ashish Rajan: Yeah ...
Sandip Wadje: the consumption would still drive through the, uh, your, your, uh, recurring expenses.
Ashish Rajan: Actually, this is an interesting point, right?
Ashish Rajan: 'Cause we haven't really touched on open weight models yet. A lot of people think open weight models are just free models. And obviously there's the whole GLM versions, and there's multiple versions of it, and people can have sovereignty related open weights as well. How do you explain open weight from a regulated perspective for people who misunderstand it?
Ashish Rajan: And I, maybe calling it a free model is the most sim- it's a very simplified version of it. What are the use cases for that in a bank as well?
Sandip Wadje: So everyone is testing them right now.
Ashish Rajan: Yeah.
Sandip Wadje: So I think it's too early [00:39:00] to say, uh, what would be the potential use cases given the Token Max issue.
Ashish Rajan: Yeah.
Sandip Wadje: I think everyone is looking at this as like-- and then I've seen those conversations a lot, is if you take the analogy of summarization, write and reason, maybe we can just use, uh, open weight models, open source models for summarization, write for some mid-level and maybe the frontier LLMs for, you know, the critical decision-making process.
Ashish Rajan: Yeah.
Sandip Wadje: So I have, I have met a lot of executive stakeholders in the last, you know, couple of weeks where they have actually gone ahead-
Ashish Rajan: Yeah ...
Sandip Wadje: and they have bifurcated this. Okay. So they're using open source models for low-level trivial tasks, and they're using frontier LLMs for high intensity, high decision tasks.
Sandip Wadje: So that trajectory you can already see.
Ashish Rajan: Yeah.
Sandip Wadje: But again, uh, particularly in large tier one banks, what, uh, use cases will come up with, uh, open weight or open source models it needs to be seen.
Ashish Rajan: Mm.
Sandip Wadje: And, and they introduce probably like the risk profile, in my opinion, is pretty much the same. Yeah.
Ashish Rajan: Yeah.
Sandip Wadje: Yeah.
Sandip Wadje: Yeah. So it's-
Ashish Rajan: Like the same approach as you said earlier would still work. It's just more a question of [00:40:00] maybe use case that we have not seen before and they just, "Oh, we can apply this." You may find a free model on Hugging Face, which is just really trained really well on a spec- something specific that the bank does Which technically is a free model as well, but it's just trained in a very specific use case, and that becomes a model you use for that, whatever that use case is, obviously.
Ashish Rajan: That's
Sandip Wadje: correct. That's correct.
Ashish Rajan: And I guess this kind of goes back to what you were saying earlier as well about the risk matrix, and I, I love the example that you gave, whether saving one million versus losing 4% of your, uh, annual revenue is a good analogy 'cause that makes people also reconsider their risk register- Yes
Ashish Rajan: for what their actual risk is- Yes ... which we haven't really touched on, but I think you kind of-- that's where you were hinting towards that, right?
Sandip Wadje: Yes. Yes. So you, you really have to ask yourself the blast radius for the use case, and if you're taking a use case in front of governance committee, don't talk about model risk, don't talk about the data risk.
Sandip Wadje: Uh, talk about the blast radius and ask yourself, if something goes wrong, who is accountable and is it really worth [00:41:00] it? If your data protection officer says it's not worth taking the risk of a GDPR fine, don't take it. Yeah. That productivity is not worth it.
Ashish Rajan: Oh, actually that's a good point. So when you-- when people present a use case, uh, even if it's security to a governance council, that's a better approach you found that to have enough context to make the right decision on that use case moving forward or not?
Sandip Wadje: I think the governance models itself have changed.
Ashish Rajan: Yeah.
Sandip Wadje: Uh, and I can talk a little bit about almost most of the financial institutions have gone around now in terms of creating a different kind of governance for AI, because I give the example of the feedback loop.
Sandip Wadje: And the feedback loop in large financial organizations, essentially a joint ownership now.
Sandip Wadje: It's not just one person's work, right? Because you have a use case where you are using business data.
Ashish Rajan: Yeah.
Sandip Wadje: You're using personal data. Uh, there is some... Because GenAI requires very prescriptive set of instructions as to what it should do.
Ashish Rajan: Yeah.
Sandip Wadje: So there is a business process that is unique to that function.
Ashish Rajan: Yeah.
Sandip Wadje: So you have business users, you have IT, uh, you know, uh, users, you have CISOs, you have data protection [00:42:00] officers, you have legal. They're all sharing their shared context and concerns in execution of that use case. So w- I call that is like AI kitchen.
Ashish Rajan: Yeah.
Sandip Wadje: And where one person does not add value or does not essentially give the right perspective, the output is going to drift.
Ashish Rajan: Mm.
Sandip Wadje: So what we've seen is essentially cross-functional governance getting essentially much more strict. Because previously you would have like the standard application boarding, onboarding life cycles go through the IT committee and get it done, et cetera, et cetera.
Ashish Rajan: Yeah, yeah.
Sandip Wadje: Now everyone is hyper-focused on the output and what happens when output is not as good as we think it should be, uh, the governance dimensions change.
Sandip Wadje: So I think governance is becoming more Cross-functional and more integrated in most of the organizations. So where you have third party, you have data protection, you have second line CISO, everyone on the same call-
Ashish Rajan: Wow ...
Sandip Wadje: to essentially look at that AI use case and provide opinion on that AI use case.
Ashish Rajan: [00:43:00] Wow.
Ashish Rajan: And I guess 'cause is this different to the first version of governance council that people started off with? Or this is an... Sorry, this is an evolved version, uh, where it's becoming more cross-functional across a large, I don't know, just a Tier 1 bank?
Sandip Wadje: You can also take the same analogy, right?
Sandip Wadje: Whose responsibility was DevOps?
Ashish Rajan: Mm.
Sandip Wadje: Largely CIOs, right? You know, CIOs, IT functions work with business. DevOps roll out the application. When the security data dimensions will come, the second line CISOs and other teams will get involved from a attestation and review perspective simply because we had that-- we did not have aggressive timelines-
Sandip Wadje: In terms of techno- technology has not moved this fast.
Ashish Rajan: Yeah.
Sandip Wadje: If, if you look at the cloud, we had fifteen, twenty years to work around, play with cloud, and do these things.
Ashish Rajan: Yeah.
Sandip Wadje: What has happened now is all of a sudden, uh, you have a use case that can be operationalized in one month or couple of days. It has immediate business value, but then everyone needs to be on the same table to, uh, you know, look at that use case.
Sandip Wadje: So that cross-functional coverage [00:44:00] has gone up because the elapsed time for delivery of a use case is very, very small now.
Ashish Rajan: Yeah. There's so much to unpack here, but I think, uh, I'll take a pause there. But I think we've got a lot of topics. Is there something that you want people who are starting off this journey to kind of walk away with from this conversation in terms of approach, their approach to AI in a regulated space that you would want to- want them to walk away with?
Ashish Rajan: In all the entire conversation we had, what's-- is there something that comes up as like one most important thing people should walk away with?
Sandip Wadje: I would say, uh, take time to understand your data.
Ashish Rajan: Yeah.
Sandip Wadje: Organizations who have done really well with AI are the organizations who figured out how, how to understand their data and how to work on their data before they actually went on GenAI journey.
Ashish Rajan: That's a great note to kind of, uh, wrap up the interview on as well. Where can people connect with you and find out more about the work you're doing and what you've been up to?
Sandip Wadje: Well, thank you for asking. Uh, as you know, I'm quite passionate about governance of AI. Uh, I'm part of the Cloud Security Alliance AI Safety Council, various, uh, uh, AI governance forums, so very happy for people [00:45:00] to reach out to me on LinkedIn, and I'm happy to answer their questions.
Ashish Rajan: I'll put the LinkedIn link, uh, on the show notes as well. But thank you so much for coming on the show.
Sandip Wadje: Thank you so much. Thank you. Really appreciate it. Thank
Ashish Rajan: you. No, thank you. Thanks, everyone, for tuning in. We'll see you next episode. Thank you for watching or listening to that episode of AI Security Podcast.
Ashish Rajan: This was brought to you by TechRiot.io. If you wanna hear or watch more episodes of AI Security, check that out on aisecuritypodcast.com. And in case you are interested in learning more about cloud security, you should check out our sister podcast called Cloud Security Podcast, which is available on cloudsecuritypodcast.tv.
Ashish Rajan: Thank you for tuning in, and I'll see you in the next episode. Peace.

.png)
.png)

.jpeg)

.png)













