Course Outline
AI in the Enterprise: Strategic and Legal Perspectives
- AI adoption in core business functions: balancing opportunities against risks
- Executive accountability in AI governance
- High-risk AI systems and organizational exposure
AI Risk Classification and Global Regulatory Landscape
- EU AI Act: risk tiers, mandatory requirements, and penalty structures
- U.S. Executive Order on AI and evolving federal/state regulations
- AI-related compliance within GDPR, HIPAA, and other regulatory frameworks
- Introduction to ISO/IEC 42001, NIST AI RMF, and OECD AI Principles
Security and Oversight of AI Systems
- Establishing AI security posture: identifying threats, vulnerabilities, and safeguards
- Incident response strategies and breach notification for AI-driven workflows
- Ensuring auditing and traceability of model inputs, decisions, and outputs
Responsible AI Procurement and Vendor Risk
- Conducting due diligence when sourcing AI tools, including LLMs and APIs
- Defining key contract elements: data ownership, model explainability, and SLAs
- Evaluating vendor claims regarding bias mitigation, privacy guarantees, and safety
Internal Governance Frameworks and Organizational Controls
- Developing AI use policies across various departments
- Structuring ethics committees, risk review boards, and cross-functional oversight
- Integrating training, documentation, and compliance processes
Use Case Evaluation and Risk Scenarios
- Assessing high-impact use cases, such as HR screening, finance scoring, and customer service bots
- Utilizing tools and templates for comprehensive AI risk assessments
- Analyzing scenarios involving misalignment, drift, hallucination, and discrimination
Emerging Trends and Future Considerations
- Anticipating regulatory evolution and global convergence
- Addressing GenAI-specific risks and extending governance models
- Achieving responsible scaling of AI operations within the enterprise
Summary and Next Steps
Requirements
- Familiarity with enterprise risk management, legal, or technology frameworks.
- Professional experience in executive leadership, cybersecurity, or compliance oversight.
- No prior technical knowledge of AI development is necessary.
Target Audience
- Chief Information Security Officers (CISOs)
- Legal counsel and compliance officers
- Chief Technology Officers (CTOs)
Testimonials (3)
inventory and identifying the different risk exposures within AI
Gary Cook - Cybersecurity and Information Technology Risk Division
Course - Introduction to AI Trust, Risk, and Security Management (AI TRiSM)
I really enjoyed learning about AI attacks and the tools out there to begin practicing and actively using for security testing. I took a lot of knowledge away which I didn't have at the beginning and the course met what I hoped it would be. My favorite part shown from the training was Comet Browser and was amazed at what it could do. Definitely something will be looking into more. Overall it was a great course and enjoyed learning all OWASP GenAI Top 10.
Patrick Collins - Optum
Course - OWASP GenAI Security
The profesional knolage and the way how he presented it before us