Webinar - On Demand
The AI Governance Audit: Is Your Privacy Program Built for How AI Risk Actually Works?
Join Jodi Daniels (CEO & Privacy Consultant, Red Clover Advisors) and Steve Gentry (Fractional CISO & CPO, Cognate Cyber) and the DataGrail team for a practical session on what it looks like to refresh your privacy compliance strategy for the AI era.
View Webinar
Thank you for your interest!
Please click below to view the on-demand webinar.
View WebinarInterested in seeing DataGrail in action?
Take a self-guided tour of the platform right now!
If a new window did not open with the product tour, please click here
90% of privacy programs expanded scope in 2025 to support AI governance. The challenge: compliance playbooks built for GDPR and CCPA weren't designed for how AI risk actually works today. Layer hundreds of new AI laws on top of the existing U.S. privacy patchwork, and the compliance burden multiplies fast.
DataGrail's 2026 Privacy and AI Trends Report found that over 60% of businesses marketing AI capabilities don’t disclose AI subprocessors in their legal documentation. Careful risk assessments go stale as vendors rapidly expand their AI capabilities. Nearly a third of AI products that disclose capabilities at all acknowledge higher risk practices like processing sensitive data or enabling automated decision making. Traditional privacy management wasn’t built for this, and closing the gap takes more than updating policy and training slides.
We'll cover:
- What you need to know about the AI risk already in your tech stack and how it affects your privacy posture
- How to build effective training and policy that actually produces safer employee behavior
- Where to audit your privacy program to meet the demands of AI-era compliance
Speakers

Jodi Daniels
CEO & Privacy Consultant, Red Clover Advisors

Steve Gentry
Fractional CISO & CPO, Cognate Cyber

Jordan Tucker
Host, Vice President, DataGrail
Jordan Tucker: Hello, everyone! We'll let everyone kind of trickle in here. And then can get started.
Jordan Tucker: I said this to Jodi, but if I am out of breath to anyone, it's because I'm 8 months pregnant, not because I'm nervous, so allow me to work through this today.
Jordan Tucker: Alright, let's get started. Good afternoon, everyone, or good morning, depending on where you're joining us from. Thanks for spending the next hour with us on what may be the most important shift in privacy work today.
Jordan Tucker: Today isn't a product pitch. It's a practical audit of whether the privacy program you built for GDPR and CCPA can actually keep up with how AI risk works.
Jordan Tucker: Three quick housekeeping notes. Again, while people are still getting in here, we are recording, so we'll share the recording with everyone who registered.
Jordan Tucker: the Q&A panel?
Jordan Tucker: excuse me, is open now, so drop your questions in at any point, and we'll answer them at the end. And then everything data-related you see today comes from research, that we did here at DataGrail, so we'll share that link with you before we close as well.
Jordan Tucker: All right, I am Jordan Tucker. I'm our Vice President of Sales here at DataGrail. I've been working with privacy practitioners like you for the last 4 years, and I'll be moderating the conversation today with two people who live this even more than I do. So, let me introduce you and give them a proper welcome, and share a little bit more about their backgrounds.
Jordan Tucker: So first.
Jordan Tucker: Jodi Daniels is the founder and CEO of Red Clover Advisors, a privacy consultancy that has helped hundreds of companies build and operationalize privacy programs. She serves as a fractional Privacy Officer, so she's living inside these programs, not just advising them.
Jordan Tucker: And before Red Clover, she built her privacy career at companies like Cox, Bank of America, Home Depot, and Deloitte. She's a Wall Street Journal best-selling author and co-hosts the She Said Privacy, He Said Security podcast.
Jordan Tucker: Jodi, welcome, thanks for being here. Anything I missed on your behalf?
Jodi R. Daniels: I'm glad to be here. I'm looking forward to diving into all… all things privacy and fun.
Jordan Tucker: Awesome.
Jordan Tucker: Next up is Steve. So, Steve is a three-time chief security officer. He led security and Privacy at Clary and at Workfront, held security leadership roles at Adobe, and today runs Cognit Cyber, where he serves as a fractional CISO and Chief Privacy Officer for multiple companies at once.
Jordan Tucker: And what this means is that he can talk about what security learned that privacy can borrow. Steve has run both sides of the house. Great to have you here. Anything else you'd like to add about your background, Steve?
Steve Gentry: No, no, just in constant learning mode in my career. It's been fun having privacy and be part of my…
Steve Gentry: toolbox for the last 16 years, even pre-GDPR.
Jordan Tucker: Awesome. So here's the plan. I'm gonna start by setting the table with some data, giving you a regulatory picture, and then the bulk of the time today we'll spend on the panel in three different places. So, we'll talk about policy, training, and procurement.
Jordan Tucker: We'll close out with what this means for your program, and then again, we'll leave room for questions, so drop your Q&A, questions in the chat at any time.
Jordan Tucker: All right
Jordan Tucker: Every metric I'm about to share here in the next slides comes from our DataGrail 2026 Privacy and AI Trends Report. It's the fifth year we've run this, and it's built on real privacy operations data from hundreds of companies.
Jordan Tucker: not self-survey assessments. This year, it includes something new. We audited AI disclosures across 2,400 business applications, so keep that 2,400 in mind, because it'll come back up here soon.
Jordan Tucker: First, 90% of privacy programs expanded scope in 2025 due to AI. So, if you're on this webinar today, it's probably because AI governance landed on your desk.
Jordan Tucker: And you probably didn't get, more headcount to help tackle that. And so, it's worth me being precise today about what expanded scope actually means in practice, because we see it in the data here.
Jordan Tucker: Impact assessments extended to cover AI systems, vendor reviews that suddenly need to ask about model training, individual rights processes colliding with automated decision making for the first time.
Jordan Tucker: Real work, and again, most teams did not grow. So the takeaway is simple. AI governance is now a core privacy program mandate, not an adjacent work stream you can staff later.
Jordan Tucker: Second finding, and this is a big one. You've probably heard us talk about this or seen it posted on LinkedIn, but… and this is a good one to bring back to your leadership team. So, after auditing 2,400 applications that advertise prominent AI capabilities.
Jordan Tucker: Nearly 64% of those didn't accurately disclose their AI subprocessors in their legal documentation.
Jordan Tucker: They might disclose OpenAI, but they didn't mention that they're also running DeepL or Vertex AI.
Jordan Tucker: To be fair to these vendors, this is mostly a velocity problem, not actual deception. Product teams are swapping out and adding AI providers faster than legal documentation can keep up, so the DPA you reviewed at signing may no longer describe an architecture that actually exists.
Jordan Tucker: The effect on your program is the same, though. You can't assess what vendors don't disclose.
Jordan Tucker: This has a hard operational consequence. Most AI vendors' inventories are incomplete by default, not because your team actually missed something, but because the paperwork was wrong at the source. An AI governance program solely relying on vendor reporting is building on sand.
Jordan Tucker: Your risk map has blind spots you don't actually know are there. So not to be totally doomsday, but…
Jordan Tucker: And then lastly, the third finding. Among vendors that do disclose AI capabilities, 1 in 3 come with higher-risk practices, like processing sensitive data or automated decision making. And remember, that's just what they're disclosing. So, pair it with the transparency gap from the last slide. The undisclosed exposure is almost certainly larger than you think.
Jordan Tucker: All right, now let's talk about regulation. And, again, I think these slides are really telling and something that we're all living. We'll talk about, again, the regulator side in kind of three parts. So, first is the fines. So, U.S. privacy fines went from $1.2 million in 2023,
Jordan Tucker: to $1.83 billion in 2024, to $3.4 billion in 2025, and it's projected to continue to accelerate through 2028. This is Gartner's data. That's 3 orders of magnitude in 2 years.
Jordan Tucker: The dollar values and figures aren't the only headline, so we saw an 8-state consortium of privacy regulators, which means that if you're finding something in one state, there's 7 other states that follow.
Jordan Tucker: And then we've also, seen a lot of companies be fined. So Honda settled with CPPA for $630,000. Healthline, $1.55 million, the largest under CCPA to date. Todd Snyder, who…
Jordan Tucker: as a menswear retailer, they're not even a tech company, was fined $345,000. So, enforcement today is moving from theoretical to operational, and it's not just confined to big tech.
Jordan Tucker: Alright, a lot going on on this slide, but I think you will all understand what we're trying to portray here.
Jordan Tucker: Again, everything on the left side of this amber line, GDPR, CCPA, this would… that was one era. That error was in the past. It was a handful of frameworks arriving slowly, all shaped primarily around privacy law. And you could reasonably build a compliance project around each of these laws that came.
Jordan Tucker: Now look at the right side of the line. From 2023 on, 3 different kinds of laws started landing simultaneously. Comprehensive privacy, data broker statuses, which we've seen some finds there even this week, and AI-specific regulation across states and countries.
Jordan Tucker: 52 total laws on this chart, and 9 more take effect between now and 2028.
Jordan Tucker: So we're calling, again, the right side of the line, now the AI fragmentation era, and here's the operational point of this. At 52 laws and counting, you can't take a project-per-law approach. Stops working. Nobody can run 52 compliance projects all at once.
Jordan Tucker: The only posture that scales across the wall is a risk-based program that satisfies many laws at once, which is precisely where we're going to take this panel today.
Jordan Tucker: So, put all these three topics together, and you get a theme. Playbooks built for GDPR and CCPA assume stable data flows and annual review cycles. AI capabilities now change from release to release, and so assessments go stale in weeks.
Jordan Tucker: And then the regulation layering on top of this is multiplying. Traditional privacy management wasn't built for this.
Jordan Tucker: And closing the gap takes more than just updating a policy or a trainee deck.
Jordan Tucker: So, before we open the panel properly, Jodi, I'll kick it over to you. I'd love your read on this, because you sit in these programs every week. When you look at this wall of regulation on this last slide, where do you see yesterday's controls quietly failing?
Jodi R. Daniels: It's a really interesting question, because at the same time, companies really do have to know the nitty-gritty of the laws to make sure that they're complying with all of those pieces.
Jodi R. Daniels: But what I… what I really want to emphasize is what you called out, which is, previously, people said, oh, I have a… I have a program for GDPR, oh, there's the CCPA thing, I have to have a program for that, and then each new one, it was almost a whole new program. We've gone into companies, and we've seen the GDPR assessments, and we've seen the CCPA assessments, and then we've seen the… we don't know what to do with those assessments, and you have to bridge them together.
Jodi R. Daniels: Where we're moving is the all-encompassing, what is it that the business is actually doing? And then from there, you're able to figure out where the risks are. Do you have sensitive data? Do you have automation in play? Are you making automated decisions, which show up in privacy and in AI? You're able to identify where the high risk is for the program.
Jodi R. Daniels: that really shows up in both the privacy and the AI parts of your 52-plus law situation. And so being able to, I think, get, one, people to understand you have to build a program. You can't build at that project level like you just said.
Jodi R. Daniels: At the same time, that program, I do believe, has to be flexible enough to be able to review each of the new regulations, figure out, this is the part that's different.
Jodi R. Daniels: And identify, oh, we've covered that over here, because we're reviewing sensitive data, we're reviewing automated decisions, we have a policy, we have a procedure, we know how to flag those, we have our tools in place to be able to inform us about what is new and interesting in our company, and then it's not a whole new lift.
Jodi R. Daniels: It's just a check the box, almost, except I hate check-the-box concept. It's more of a ensuring that you're covering that specific requirement.
Jordan Tucker: Yeah, so one program while still acknowledging all of the laws that fall underneath it, versus multiple programs per law.
Jodi R. Daniels: Yes.
Jordan Tucker: Awesome.
Jordan Tucker: Alright, so the framing is exactly why, there's a mismatch on this slide. So again, as Jodi said, the traditional playbook is no longer working, and so let's get into what we actually want to do about this. So our first topic today, is policy and Governance Strategy.
Jordan Tucker: And I'm gonna start with you, Steve. I think, this name's something that a lot of people are actually feeling on this call.
Jordan Tucker: Let's talk about patching versus risk programs. So, again, Steve, you draw a hard line between running a risk program and doing what you call vulnerability patching, reacting law by law, or tool by tool. Walk us through the difference and tell us, honestly, what percentage of the programs you're seeing actually fall on the risk program side of that line.
Steve Gentry: Yeah, I don't have actual data to back this up, other than anecdotal from me being in multiple companies, or the ones that I have run as an House CISO,
Steve Gentry: But if you look at most risk programs, they are actually a to-do list. It is a checklist of, like, hey, we need to patch… our Linux are,
Steve Gentry: are not pa… like, we're 9 versions behind, or our Java version is end of life. That's not a risk. I mean, it is a risk in the sense of… but that's not how the business risk functions, and that's not truly an ERM. So, it's learning to focus on things like, hey.
Steve Gentry: we're trying to stop data exfiltration. We're trying to protect reputational, risk for the business. How are we doing that? Yes, there's going to be multiple things underneath it.
Steve Gentry: But if you go in, it's not about whether you've done a patch or not, that is an action underneath a risk. That is an activity that's part of a risk.
Steve Gentry: The risk is actually bubbling those up and taking those different items. It's a difference between, you know, when you're doing problem management.
Steve Gentry: You're bubbling up multiple different entities to address the problem, not just the individual symptoms. Underneath it, like, we don't do strong vulnerability risk management. And in the AI age, you have to start adding things in, like, hey, for our incident response, can we tie in an AI agent
Steve Gentry: to who the owner of that agent is. Who set it up to begin with?
Steve Gentry: And then another piece of that also falls into, like, zombie agents. But, like…
Steve Gentry: how much are we spending on AI inside the company? Well, part of that is who's running agents, and when someone leaves a company and they set up a bunch of agents, this is no longer a discussion of, hey, like, we need to off-board this individual. We need to off-board everything that could
Steve Gentry: be running on their behalf from an AI standpoint. They could be processing customer data and sending a standard report. It also ties back to the insider threat piece. Like, when they left, did they just shift where the information was being sent to as all these agents are running? So it's…
Steve Gentry: Focusing on what's important to the business, of how you're protecting reputational, how you're protecting financial.
Steve Gentry: all those pieces and bubbling up, and then starting to look at the new paradigm that exists inside of having AI agents and AI skills and all those different pieces running into it. So yeah, this is… we're, we get too focused on the action itself versus bubbling up to what's the risk we're doing, and this is where a lot of
Steve Gentry: A lot of risk programs create glossy eyes when they're presenting to the ELT and the board, and I want to call out one last thing on that, and then I'll shut up.
Steve Gentry: A lot of discussions happen, like, oh, our board presentations are presenting to the board…
Steve Gentry: the board is the last place you're presenting to. If you're not having those same discussions with your ELT, your executive leadership team first.
Steve Gentry: The board is not, like, they're not the magic bullet. If you're trying to use your board to slap down the ELT members, you have just shortened your lifespan at the company. So as a privacy professional, if you're the DPO or the CPO at a company, and you're going to the board and saying, hey, they're not doing these things, and you've never had that same discussion internally, you're about to create a conflict in there, because the board's going
Steve Gentry: be like, okay, well, what are you doing? Why aren't you resolving this? But also, if they go to the ELT and start saying, hey, why aren't you guys addressing this?
Steve Gentry: you've just created a moat between you and the rest of the executive team. I'm not saying there's times it's not appropriate to be able to call out, but you have to start with the ELT first, and those presentations are going to be more important than your board presentations.
Jordan Tucker: Yep.
Jordan Tucker: Jodi, I'll pop it over to you. When a client of yours wants to make a shift from, again, more of a patching strategy to actually a risk program, and they're not going to get any new headcount, which is classic, what's the first structural change you tell them to make?
Jordan Tucker: And is there anything they could push aside and maybe stop doing and replace it with this?
Jodi R. Daniels: I think it's first figuring out what they are doing, and where, no pun intended, but of all those activities, where is the greater risk? If you're trying to create a perfect policy, or you're focusing in an area where the risk to the overall company is small, and I've seen this, I've seen people really try and lean in to get all the aspects that they might need for a privacy program.
Jodi R. Daniels: But yet, for, like, let's take a company, maybe they don't get a lot of privacy rights requests, but they have a lot of vendors. Well, perhaps the emphasis should be on really understanding all the vendors.
Jodi R. Daniels: And you need the ability to manage privacy rights, but maybe it's not perfect the way another company that is managing thousands of them, it needs to be able to ensure that it is running like clockwork and not a problem.
Jodi R. Daniels: So I think understanding, first, how can they literally prioritize their time, which…
Jodi R. Daniels: also gets to understanding the business, and where is the business moving quickly, and potentially processing data, or utilizing tools and making decisions that are going to impact any of the privacy and AI obligations that they have.
Jodi R. Daniels: Being able to know that is going to help you figure out, do I need to set up different kinds of conversations? Do I need to have different types of reviews? Do I need them to enter in any… anything within their own tools that they're doing? Do I need to work with the procurement team first before they just, poof, go get the new vendor? Where does all of that sit?
Jodi R. Daniels: Because to me, I… my favorite part of this slide is actually the bottom question, so I'd love to be able to address
Jodi R. Daniels: this ownership piece, because what I often see are committees. I see an AI Governance Committee, or I'm the privacy person, and oh, AI Governance, that's our committee over here. And what happens in committees is nothing. Committees are decision groupthink.
Jodi R. Daniels: someone… I do like committees. I do think having collective thought is very valuable, as long as there is a single owner. Someone has to be a decision maker, and so if anyone listening has a steering committee, and there is no single owner or decision maker.
Jodi R. Daniels: Majority wins does not really work in these types of programs. It slows it down, and there's not time.
Jodi R. Daniels: Literally, to be able to have that slowdown.
Jordan Tucker: Yeah, that was Jack.
Steve Gentry: I'm jumping in on that real quick, because one of the things that… when people are creating their privacy
Steve Gentry: committees, or data governance committees, or I… the charter is more… like, this is one of those things that goes back to governance. Policies are not the end-all, be-all, but, like, on a charter, that is a key piece of your governance program, because part of that charter is
Steve Gentry: who's… how are decisions made? Because if you're not doing any decision-making inside the committee that you're having, your committee could have been an email, or should have been an email, because it's not solving anything, you're just having a discussion.
Steve Gentry: And honestly, from an ownership standpoint, like, I am a firm believer that security and privacy should not own AI governance.
Steve Gentry: AI was not introduced into the company because it was trying to solve a security issue or a privacy issue.
Steve Gentry: This is like, hey, we want to be more productive, we want to write… have AI write code, we want to include Claude Co-work and have it start doing all these, productivity functions for us, and summarizing my emails, and automating these…
Steve Gentry: AI governance is about
Steve Gentry: how the company runs with AI, that is not a privacy or security issue, so when you quit.
Steve Gentry: Privacy or security in charge of that committee, you're going to end up losing, because that, to me, then the security person's coming in, and our focus is going to be like, well, how do we secure it? Privacy is like, what are we doing with all the data on it? To me, one of the other ELT members should own that, and we should be sitting then as a chair, just from.
Jordan Tucker: You have it.
Steve Gentry: named Steve.
Jordan Tucker: Do you have a recommendation, Steve? That was my next question. Like, you know, maybe less AI governance, but who… who should own AI governance? I think a little bit different is AI risk.
Steve Gentry: Yep.
Steve Gentry: COO,
Jordan Tucker: Interesting.
Steve Gentry: I… to me, that, like, if the person who is running the operations of the business, if you have a COO, I… I don't recommend the CFO.
Steve Gentry: CFOs often get… they… even though they run risk programs themselves.
Steve Gentry: 9 times out of 10, I see them get too focused on the financial aspect of it, and so they get… to me, the person who's running the operations of the business, so if you have a COO, that's where I would drop the… the program.
Jordan Tucker: Jodi, what are your thoughts on that ownership of AI risk between, again, privacy, security, or legal? Or, again, a rogue one that Steve just threw in, the COO?
Jodi R. Daniels: I look at both privacy and AI, I see them as both hot potatoes.
Jodi R. Daniels: And my answer's a little bit different. I think for larger companies, that might make some sense to have one of those SLTs, and that would be an ideal world. The companies that I'm finding, it really is that hot potato, because everyone is trying to still learn it. There are a lot of people that don't understand the different risks. They're so focused on the business aspect.
Jodi R. Daniels: And it's sort of a, no, I don't want that.
Jodi R. Daniels: And my view is wherever it's going to actually get traction and listened to, because I view Governance as multifaceted. There's gonna be privacy and security, there's legal, but there's more. There's so many other risks that are also a part of governance.
Jodi R. Daniels: What I've seen is why it's landed, it feels like, on more privacy program desks.
Jodi R. Daniels: Is because they had the infrastructure built for privacy programs that was very cross-functional, had to cover
Jodi R. Daniels: similar-ish kind of situations, assessments, policies, training, understand data, vendor. And because there was the foundation already.
Jodi R. Daniels: Here you go! You can do this part too.
Jodi R. Daniels: It doesn't mean that they should own the final decisions on everything. I do, again, feel like who is going to make that decision on if this is too risky.
Jodi R. Daniels: because of this long list of risks, who gets to decide, yes, it moves forward even though it's risky, or no, it does not go forward? Is it just a math problem, because that's how you've decided it? Does the business get to override it? Where does the business make that decision?
Jodi R. Daniels: Does it go all the way up to the C-suite? There's a lot of different ways of how this can play out, but in my view, it's really which team gets attention that AI Governance deserves, because on… otherwise, it gets nothing, and then there's significant risk to the company.
Jordan Tucker: Yeah.
Steve Gentry: And to me, that's a differentiation between who's operationalizing the program, and then who's providing the oversight on the program.
Steve Gentry: And if there's not C-suite oversight, and this is where my COO standpoint is coming from, is that's the oversight person who's the final decision maker.
Steve Gentry: Collaborating with their peers.
Steve Gentry: But ultimately, like, yeah, you're gonna have programs who are so used to get… like, that's why security ended up getting so involved in privacy in the beginning. We were already operationalizing a lot of these activities. And so you end up seeing a bunch of CISOs who got handed privacy and said, here, go figure this out, now that we were… we've got GDPR going live in less than a year, you're now responsible for making sure we're compliant. Like, cool.
Jordan Tucker: Yeah. Yeah, I think, I mean, we ask that question every day. Who owns… who owns privacy? Is it legal? Is it security? And it is a total hot potato, but I think, net-net, like, having a single owner, having someone who has clear ownership, I hear a lot of committees happening.
Jodi R. Daniels: So many committees.
Jordan Tucker: feel like it's, like, a secondary part of the role, and it's not. It is the role, so. Okay, let's move on to the next topic, which is training. And I think, something we could admit, probably on the privacy side, is that security
Jordan Tucker: was ahead of us here. They've been doing training for 20 years, and so, Steve, we'll start with you. Again, security has spent 20 years learning how to train the workforce on phishing simulations, measuring behavior instead of completion rates. So, what did cybersecurity training get right?
Jordan Tucker: that privacy teams building AI governance training should steal.
Steve Gentry: On behalf of security professionals everywhere, I'm going to offer my sincere apologies to the privacy world of teaching how to do everything wrong
Steve Gentry: And security awareness training.
Steve Gentry: Cybersecurity training has been so focused on trying to use a 30-minute, 1-hour, 2-hour, how many… like, train… trying to turn everybody in the company into cybersecurity professionals. It's not focused on…
Steve Gentry: how people learn. It actually violates everything that is from a scientific standpoint of how long people's attention spans focus, and how they can retain data, and so we try and jam-pack these
Steve Gentry: these sessions with a bunch of information. We do things like phishing simulation, which all the data, for those of you, like, phishing simulation doesn't work. It doesn't…
Steve Gentry: It's not actually causing fundamental change in behavior. So we've been doing these things, and we're not focused on trying to actually teach people and remind them what's important, so it's…
Steve Gentry: doing things right is when you start doing these small data sessions, regular reoccurring things, like, if you move to a… just an example of how I function in programs, when I'm running in-house programs, I'm moving to these 30, or… yeah.
Steve Gentry: no more than 5-minute little sessions, videos that are compressing data into a manageable way, hitting the key points, kind of like the TLDR of a security policy or a privacy policy.
Steve Gentry: usually will include the bloopers of me doing this, and it's usually also me including a lot of pop referencing or music references, because I'm… yeah, I'm just nuts, and my brain is all over the place as I talk, as you can tell already.
Steve Gentry: But it's these sort… and doing them once a quarter. People don't… like, if you have four quarters of training, but it totals up to less than 20 minutes, people adapt to that. I've seen high, return rates where, like, you start seeing 95% plus,
Steve Gentry: people actually paying attention to learning training, and people referencing it'll be out somewhere and be like, oh man, I remember this one that you did a few quarters ago that was talking about this, and they're remembering that data. We get so focused on trying to make security awareness, or TPRM when we start talking about that, like.
Steve Gentry: To me, these are complete security theaters. It's more about performative, and we're not focused on actually training people or giving them the relevant data. We're trying to overload them with a bunch of
Steve Gentry: functionality like they've been in their careers for 20-plus years, and they, like, coming in, they have to know all this stuff on a regular basis. Security people don't even go back and read the policies on a quarterly basis, but yet we're like, hey, well, if you violate this, well, like, they don't care.
Steve Gentry: And I know that's… it's brutal to hear from a security and privacy standpoint, but most people are just trying to get their jobs done. It's more about focusing… the security training should be like, hey, here's the TLDR, but here's how we're doing guardrails to protect you. So if you accidentally do click on a link, this is how we're making sure that you
Steve Gentry: Having given away a bunch of money. And we're here to help you and facilitate you doing your job well, versus trying to penalize you with a bunch of extra training on stuff that you're never gonna remember.
Jordan Tucker: Yeah, yeah, and I think if you only do it once a year in the AI world, you are very far behind, thinking just how quickly things are moving. Jodi, I'll pop over to you. You push hard, you talk to clients every day about third-party risk training, and
Jordan Tucker: I think thinking about training the people who actually buy the software is important, so what does that actually look like in practice?
Jodi R. Daniels: I want to echo what Steve was saying, which I think is smaller trainings, and I would also suggest role-based trainings. So, here, you could have a procurement team, but we also know, Susie over here might be able to just go get
Jodi R. Daniels: her own AI tool, and I need to educate all the teams
Jodi R. Daniels: who might be able to have access to that, and what are the risks, and how does that matter to what they're doing in their role? I think it's important to use that team's language, that team's goals, and what's important for them, and then say.
Jodi R. Daniels: paint the picture of what could happen if it goes wrong, so that they understand why it matters so much. And in terms of the method of how people are training, small role-based training, ongoing, ongoing tips, using, I've seen… I've seen all different kinds of successful things where people are trying to help them on a personal level. Let me explain, when you're going shopping and using software personally, here's why this impacts you.
Jodi R. Daniels: And I start with all of that because that is then how people are going to start paying attention.
Jodi R. Daniels: to what is important for the company. If I need the procurement or the business owners to understand there's these privacy laws, here's what it is that you could go look at on a website. We're looking for these types of information. Does the company say anything about privacy? Does it say anything about how it's using data in its AI models? Does it have a security page? Can we look at a privacy notice?
Jodi R. Daniels: That might be the business owner, that might be the procurement team, it kind of depends on the business, but whomever's going to review, it's coming up with the short list, the easy ones.
Jodi R. Daniels: That are trainable to that person, to get the quick answers, to be able to say, this is scary, or this seems okay, and as it continues down
Jodi R. Daniels: the business owner's buying, it might stop at legal with a contract review. More detailed questions are going to come up when appropriate. But at first glance, handing someone a 100-page questionnaire when we're first evaluating, do we even like vendor A, is probably not the best use of that person's time. So it's coming up with when are the right places within the whole purchase cycle
Jodi R. Daniels: That work based on how your company purchases
Jodi R. Daniels: software. Again, whether that is Susie in the business, or an actual procurement person.
Jodi R. Daniels: And as a part of that, and we have here, like, this third bullet, when does it route to a privacy review? When does it route to a security review? When do more questions have to get answered? But I'm sure I can speak for a lot of people. Many companies have these massive questionnaires, they go to a vendor, a lot of those questions aren't relevant, and the timing of it
Jodi R. Daniels: isn't relevant either. So really getting the process… I'm just a huge fan of process drives compliance, no pun intended, but that's how you get people on board, is creating something that works
Jodi R. Daniels: For the situation at hand.
Jodi R. Daniels: And then the last one, the documentation story, and we hear this from regulators all the time, because if you don't document that you had this diligence, and you went through and reviewed who all these vendors are, what you found, how you decided this was okay, this was risky, but okay, this was too risky, and you chose not to, or you knew that.
Jodi R. Daniels: That documentation, that's what regulators are looking for. If there's ever an issue, they're going to come and say, show us your diligence. And when you say, well, we really, we have that lovely call.
Jodi R. Daniels: And we had to love it all.
Jodi R. Daniels: That's not gonna work. Show your homework is what they are looking for, and we hear this all the time in many of these different kind of webinars and conferences. They really are asking for this information. So documentation is your friend.
Jordan Tucker: Yeah.
Steve Gentry: And knowing, like, states like Utah that have passed a law when it came to
Steve Gentry: how a company can be sued. Like, there is a minimum due diligence aspect of, like, hey, you can't sue a company in oblivion if they've set a baseline set of requirements and are following the, like, they're actually doing some vendor reviews, they're actually put MFA in play. Like, if they're doing basic things and saying, hey.
Steve Gentry: Risk exists, and risk happens, it is minimizing the exposure for that company, but they have to actually be doing things like validating some of their vendors. But TPRM as a whole, like.
Steve Gentry: how many companies had reviewed SolarWinds? And this is not a knock on SolarWinds, but, like, in that example, how many companies had reviewed SolarWinds? And, like, oh no, they've answered all of our questionnaire data, and, like, they're golden. We're good. This is going to be one of our strong vendors.
Steve Gentry: So this is where the TPRN piece can be a bit performative in my mindset, because you can't actually validate. You're relying on that information that the vendor is being truthful to you. So asking, like.
Steve Gentry: The longest questionnaire I've ever gotten was 891 questions.
Steve Gentry: They had no more additional data on my security program.
Steve Gentry: than they did after that. Like, you're trying to do an audit on it, and they're gonna… they're gonna give you as minimum information they can to get past that audit. They're not… nobody's throwing open their, yeah.
Steve Gentry: as a vendor selling to a customer, I'm not throwing open my risk register to them. I'm not gonna show them where all the bodies are buried, because I'm trying to fix that and do that. So TPRN, we get so focused on how the vendor is risky, or, like, instead of saying, hey, if the vendor is a risk.
Steve Gentry: how are we going to be able to prevent that? What guardrails do we have that these third parties can't completely compromise our vendors? It should be that internal process for us of protecting our business, and how they potentially may impact versus, oh, I've done this checklist.
Steve Gentry: I've done a checklist on this vendor, and I need, you know, so therefore I'm good to go, and that's where my risk ended.
Jordan Tucker: Right. Well, I think that goes to the data that we presented at the beginning, right? That, they're not actually reporting on all AIC processors. Jodi, anything last?
Jodi R. Daniels: I wanted to just, I know we're talking privacy, a lot of times this is personal information, but sometimes, especially for just TPRM, that might encompass all different types of data. And some of the vendors I've reviewed for companies, I think just… it's kind of an interesting story, and I think it helps paint the picture of you really have to understand who these third parties are.
Jodi R. Daniels: And so, as we think about different parts of the company looking at an AI tool, and asking, what is that AI tool collecting? What kind of company data am I okay with them having and using, and then what…
Jodi R. Daniels: what am I not okay with? So in a particular situation, it was a marketing team that wanted to use presentation software. It wasn't going to have personal information, but it would have company confidential information. So if we think to our
Jodi R. Daniels: data classification, we're gonna have personal, we're gonna have public, we're gonna have confidential. So I put this confidential data in, I put it over there, and as we were evaluating this vendor, we learned, well, they'd have full access to that data. And I just want to remind everyone, it's not only the personal information that I think is really important, and I get that we're talking about privacy, but these same challenges, and sometimes it's personal and it's gonna be company confidential.
Jodi R. Daniels: But that's one way to help a team like that. Hey, marketing, do you want all of this proprietary information? Or finance team, do you want all the financial information on your presentation software out with an AI vendor so that they can do whatever they want with it? It might not have been the personal information, but that other information, when we start to help explain the risk.
Jodi R. Daniels: People go, no, no, I don't think I want all of that there. They look at how a vendor and a tool might act a little bit differently. We as professionals know that there's a long list of other questions that we need to be addressing as well, but some of those really simple ones, I find.
Jodi R. Daniels: Help people kind of get it, and own it, and want to make sure that this isn't just an annoying part of a process.
Jodi R. Daniels: They actually, genuinely want to make sure that they're working with vendors and tools that they can trust.
Jordan Tucker: Yep.
Jordan Tucker: Okay, we've talked a lot about vendors, so let's, like, actually jump into this as a topic,
Jordan Tucker: And again, this is probably the most tactical one today, which is actually the procurement strategy. So, Steve, you started pushing an idea that would have sounded radical two years ago, zero data retention as a default.
Jordan Tucker: So Steve, make the case, what does zero data retention actually mean when you're buying an AI product, and is it realistic?
Steve Gentry: Yeah, so there's two different… I want to kind of differentiate the different pieces of AI here. So you've got your Gen AI tools, where ZDR plays in a lot. You can try and get ZDR contracts in on your other vendor, or your vendors that are supporting
Steve Gentry: tools with inside your product, or there's supporting tools with inside your business.
Steve Gentry: a lot of… from a GenAI standpoint, a lot of your vendors out there already have, if you're doing a corporate account or an enterprise account, they automatically include ZDR as part of the function that… so they're not training… supposedly not training their… your data, anything that you're putting in there is not being trained on their model, it's not being ingested back into their frontier model.
Steve Gentry: behind the scenes.
Steve Gentry: But if you're using a personal account, if you read, like, what Anthropic or OpenAI has, if you're using a personal account, your ZDR is not part of your
Steve Gentry: Part of your requirements.
Steve Gentry: I think, just in different roundtables I've been at with, with other CISOs over the last year, ZDR is a hot topic.
Steve Gentry: I think some people are using it as a crutch of, like, oh, well, I've got ZDR. It's like, well, where do you have it? Which vendors do you have it on there? It's the same thing with, like, oh, well, I've got identity management on top of my agents, so I'm all good. It's like, well, that's great, that's from how it's interacting with the tools.
Steve Gentry: can that harness be compromised? Can someone else hijack that harness where you have the guardrails in place and move it? And so, ZDR is fantastic. You should be looking at ways to work with your vendors to make sure, and that should be one of your default questions within
Steve Gentry: your TPRRM process, so as you're asking your questionnaire, you should be asking them, like, okay, how are you retaining data? Is it being used to train your models internally, or is it if we're in a multi-tenant environment, and even if it's logically separated, does my AI input only stay in my tenant, or do you ingest it elsewhere?
Steve Gentry: If you're a third-party vendor that uses AI in your tool, and it's something like a gamma, that you're just creating slides, like, how is that data being retained? So asking… understanding that concept of ZDR needs to expand beyond just the Gen AI, which is where I see that ask the most.
Steve Gentry: the AI questionnaires I get.
Steve Gentry: It surprises me that I'd say 1 in 4, or maybe 50%, actually include the data retention question. How that… how training is happening with whose data.
Steve Gentry: And to me, that's a fundamental aspect, because as you're going into the privacy standpoint, you want, like, okay, we as a company, part of our toolset is collecting personal data, we have privacy requirements.
Steve Gentry: What are you doing with that?
Steve Gentry: And so yeah, it's… ZDRs is great. We need to make sure we're actually expanding the focus of where we're looking beyond just thinking of it, because it often comes up with our Gen AI tools, and look at the rest of our productivity suite, and then our own product. So if you're a vendor, and you have a product that has AI functionality.
Steve Gentry: Asking your own development team how we're handling this.
Jordan Tucker: when you're purchasing a product and a vendor says, we can't do that, like, we can't reach CDR, is there an acceptable fallback?
Steve Gentry: that's part of your risk profile as a company. You have to decide that as a company. Like, this is where you have your risk acceptance forms. This is why you build… a true TPRN is third-party Risk Management.
Steve Gentry: So it's, what does that risk really look like to the company? What's the data that you're ingesting? And being able to answer those questions and others as you're kind of building that out will kind of come up with a risk score.
Steve Gentry: Well, that kind of… it will come up with a risk score that you, if you've built the program out and you're getting those data points, then you'll… you'll be able to make that decision as a company. And oftentimes, it's going to be a risk acceptance, as companies, depending on the model that you're in, more heavily regulated businesses.
Steve Gentry: Often security owns that vendor risk and can say no, but you get outside of heavily regulated industries, and even if a project's a risk, it's like, we're gonna accept it and move on, because this is a revenue generating, so…
Steve Gentry: Cool, document it, tell us when you're coming back to review it, but we're probably going to rubber stamp the risk acceptance 6 months from now, or 12 months from now, when you come back.
Jordan Tucker: What, I'm curious of all the security reviews you've done, what's the single question on these vendor assessments that you see AI vendors fail?
Jordan Tucker: Most often.
Steve Gentry: I… to me, I'm gonna actually end… even not talking about AI vendors, the one question that I often get either pushback, like, people don't ask.
Steve Gentry: internally when they're reviewing, and typically I don't see vendors offer it up, is how are you accessing my data through account impersonation, or how are you accessing our data behind the scenes? You know a SaaS company has access to your data.
Steve Gentry: that they're running, and that they're going to be in AWS GCP, they may be running their own on-prem solutions.
Steve Gentry: asking them and trying to understand how those people are getting access to that data behind the scenes for support, for bug fixes, because you're probably going to have a lot of people inside that SaaS vendor who have access to your personal data, whether… and then they may be using some type of AI tool as they're doing that, that's actually pulling that information out and doing things. We had a situation where
Steve Gentry: This was at a previous company,
Steve Gentry: the… one of the VPs had their own specific dashboard set up that had information that they were tracking on employees, and a person at the company
Steve Gentry: went in, did account impersonation, gathered, in order for an EBR, gathered a bunch of that data, including the dashboard that they had personally created that their employees didn't know about, and then dropped it in a slide deck and presented it back to that VP, and the VP was like, WTF.
Steve Gentry: Like, no, I don't want anyone seeing me, like, I'm… what do you… where'd you get this? It was like, oh, I logged in as you.
Steve Gentry: what do you mean you logged in as me? So, like, it's some of these things that I've seen that from… we don't know what the vendors are doing behind the scenes, and that includes where they may get access to be able to pull it out in order to do other things with it.
Steve Gentry: People say it's just from the support or the dev standpoint, but being able to understand what controls are in place, is it logged? Is it… does it…
Steve Gentry: Is there output there? Is, to me, one of the most… is a critical question you need to be asking all of your vendors.
Jordan Tucker: So, Jodi, take us into the contract itself, and again, thinking back to that stat earlier, 64% of vendors, you know, miss disclosing AI subprocessors. What do you insist goes into a contract or a DPA today that wasn't standard two years ago?
Jodi R. Daniels: So, the conversation that was just had around the retention, and that ties directly to privacy obligations, data minimization requirements, and programs, and how they are or are not using the data. Most companies don't want the other party using the data.
Jodi R. Daniels: That needs to be really…
Jodi R. Daniels: clarified and specific. So, just like we have here, zero retention, and what is… what is the use case in terms of how that data will or will not be… be used? What are the audit rights? And then, in terms of their own subprocessor list, I… I don't always necessarily see in the contract, here's the specific list. It's typically.
Jodi R. Daniels: We will provide you with notice, a certain time period of when that notice is going to be provided for when new subprocessors… I can't speak… sub-processors will be added.
Jodi R. Daniels: say that 5 times in a row. And how that will be communicated. And so, sometimes that's in advance, we get a say in it, we don't get a say in it, it's gonna be an email, go to this website, how… is it 30 days in advance? Is it effective right away? All of those types of parameters.
Jodi R. Daniels: That is really important information. It is changing pretty significantly. And then what will happen… there could be some pretty significant impacts, depending on who that subprocessor change might be, and where that information might go. And that's also part of why the audit writes and how… how comfortable you're going to feel if they just pick a brand new subprocessor, and how much information you're providing to this vendor.
Jodi R. Daniels: Some of these, you're going to get more wiggle room and be able to negotiate. Some of them are not. You're going to… it's going to be a take-it-or-leave-it. And in that review, I would recommend that you're reading that contract alongside… and typically this is what legal is doing, but with the TPRM team to really be able to understand, here's all the risks, here's what we're really concerned about.
Jodi R. Daniels: So that's the end of the contract review.
Jodi R. Daniels: The business owner and legal, whomever else is a part of the conversation, can figure out, here's what the risk is to the business and make the decision.
Jordan Tucker: And for everyone thinking, like, you know, some of the things that both you and Steve have mentioned, my vendors will never agree to this. Like, what's realistic for maybe a mid-market buyer to negotiate here? And where do they actually have leverage?
Steve Gentry: don't underestimate the power of your company. I know, like, this is something, as I have been in startup advisory for many years, even before I moved into a fractional capacity.
Steve Gentry: a lot of companies think, oh, like, we're, you know, we're only a $30 million company, we don't have, like, this… we've got this big company coming in. We… we have to, like, they're saying they're not gonna do it, so we don't really have power, like.
Steve Gentry: One, it doesn't hurt to ask.
Steve Gentry: Don't, don't be afraid to ask. Also, don't be afraid to push back.
Steve Gentry: Because, I mean… Salespeople want to get a deal closed. That's how they're getting their comp.
Steve Gentry: They want to get deals closed, and they're willing to go push back on a business at times in order to get things in place, and anyone who's had, on the other side of things, where you're working in-house, and you have salespeople come to you, like, oh, I told them I wanted to get them this.
Steve Gentry: Also, I will tell you, hey, push back, and be able to say no. So it goes both ways. Both you as a purchaser should be, like, don't be afraid, because you're coming from a smaller company, to speak up and ask, and then push them on things that you think are riskier behavior, and then if you're at a smaller vendor.
Steve Gentry: and you have this big company coming in, and like, hey, we're gonna do all these things, or we have, like, hey, we need you to follow our privacy policies, we need you to follow our security policies. Like, those are automatic red lines for me inside of a… inside of documentation. I'm like, hey, I can't promise to ever contractually commit to follow your policies.
Steve Gentry: I… like, if you change them, I'm literally on the hook, though, because of what the contract language is.
Steve Gentry: So, like, don't be afraid to push back and say, this is how we're running things, you need to look at our business, whether you think it's risky or not, and accept to use us as a vendor. But, like, I'm not gonna greet a bunch of extra controls from you, where you're dictating my security or privacy program.
Steve Gentry: So, no matter your company size, whether you're the purchaser or the buyer, don't be afraid to push. Yes, there are companies like Google and Microsoft are gonna tell…
Steve Gentry: Tell you to go pounding sand, but you'd be amazed at how much wiggle room you have with… with large vendors.
Jordan Tucker: Yeah.
Jodi R. Daniels: I was gonna also add, just as a reminder, this space, as many of us know, is changing radically, and make sure that you're able to be able… and identify how will you receive information if there is a new regulation
Jodi R. Daniels: Is it, you know, a watermark? Is it a disclosure requirement? Is it a removal of certain information? There's all different types.
Jodi R. Daniels: How is that communication going to happen? Where does that go? How does that evaluation happen? And so, you know, you have a contract, it's a point in time. It could be two years later, there's a major new regulation. Just the line that says that they're gonna comply with all regulations.
Jodi R. Daniels: Okay?
Jodi R. Daniels: how does… I'm always so focused on the actual operational piece, and making sure that that's a part of the contractual conversation.
Jodi R. Daniels: In decision-making process. And do you feel good that they're gonna actually make sure that they're helping you, so, especially in a service provider relationship? How… could you answer the question, they are going to ensure that I am complying with fill-in-the-blank law, assuming you're using their… their service in… in a manner that would… that would make sense?
Jordan Tucker: Yeah, I think that's a great point, Jodi. Cool, we'll move to Q&A here in a second, but, I know I said no product pitch, so we'll just do this one slide here, in case you're… you're out there wondering, like, how does this connect back to DataGrail? Is there anything to help us solve this? And so.
Jordan Tucker: just a couple points on where we can help. So, I think first and foremost, in order to handle AI risk, you must be able to detect where it exists. So, DataGrail can help find AI and MCP-connected systems.
Jordan Tucker: that are actually in use across your business. So this includes shadow IT and AI, and then the types of PII and sensitive data that it's processing.
Jordan Tucker: Second, our AI agent, Vera, uses that rich data to actually autofill AI risk assessments, so I think AI is a fantastic use case for the increasing amount of risk assessments that we're having to do today.
Jordan Tucker: So instead of doing this in a spreadsheet, you get a 90% complete assessment and a central place to collaborate and complete these.
Jordan Tucker: We'll also surface new risks uncovered in the assessment, so nothing goes unmanaged.
Jordan Tucker: And then lastly, the tracking portion. So DataGrail will automatically track, rank, and suggest mitigation workflows, empowering your teams to fix and find issues.
Jordan Tucker: Before they become major risks.
Jordan Tucker: DataGirl maintains an evidence trail that makes your program all that more defensible. So, reach out if you'd like to join more, or understand more about how DataGirl can help. You know where to find me.
Jordan Tucker: Okay, we did get a couple questions, from the audience, which is great. So the first one is… kind of falls under that topic of training, and Steve or Jodi, you can answer this, but how is AI used
Jordan Tucker: internally versus externally, and customer-facing or ADMT interactions.
Jodi R. Daniels: I'm processing.
Jordan Tucker: Buffering.
Jodi R. Daniels: I think I'm trying to understand the broader sense. So, how is AI used internally is a really broad question.
Steve Gentry: Yeah, Gwa wrote, if you can add additional contacts, that'd be fantastic, because…
Jordan Tucker: Yeah.
Jordan Tucker: Give us more context in the chat, and we'll come back to that one.
Jordan Tucker: Next question. Should AI training be a joint effort between privacy and IT security? And where does AI governance actually sit when it's, like, non-PII data involved? Which I think is interesting.
Jodi R. Daniels: I have some thoughts on that, and then, Steve, for sure, please share. So, I guess I'll say, I think…
Jodi R. Daniels: Privacy training and security training can overlap. There are certainly parts that go together. They're also really different. There are pieces for either side that need to be unique and distinct, so…
Jodi R. Daniels: Somehow, I think that the commonalities can come together, but there needs to be separate content and a separate plan for the other items, is my…
Jodi R. Daniels: my personal thoughts, to make sure that people are informed and educated in both arenas. And in terms of AI governance and how that can cover beyond just the privacy and security part, I think that goes to what we all were talking about earlier, and who owns that part, to make sure you're capturing all of the other risks, because there is more than just privacy and security. There's so many other parts.
Jodi R. Daniels: And that kind of goes to who's gonna own this whole umbrella
Jodi R. Daniels: area. If it's one of you lucky people, then I encourage you to go shopping and find your friends in the organization to make sure that you're being all-encompassing for what all those other risks are. Otherwise, I see whomever that owner is, is the one that typically says, here's all my elements, and then they're the ones who pull in all the specialists.
Steve Gentry: Yeah, I 100% agree, Jodi. Like, it is one of those things that…
Steve Gentry: because you saw a lot of that operational activities, attorneys in companies, when GDPR went live, like, hey, I've never really operationalized a program like this that had technical aspects. Will you take security? Will you handle the training? Will you handle this piece? So security guy, and I think they melded the security awareness training too closely together, and missed some of the, like, there are unique aspects of
Steve Gentry: with Privacy
Steve Gentry: they're different than security. They're two sides of the same coin, but they have different views of how they're looking at things.
Steve Gentry: And so making sure that you've not just kind of just slapped the two together and said, oh, it's fine, like, we mentioned the word privacy, like, three times in this training, so therefore it's covered. But then also going back to the… or also continuing on with the AI governance, again, yeah, PII is fantastic.
Steve Gentry: But AI governance, again, you're talking things like zombie agents. Someone's left the company, and you have this agent that's still running in the background that is costing you $8,000 a month. Or you've had situations where, like.
Steve Gentry: an agent went rogue, and they spent $500,000 on a process running over the weekend, and spent half a million dollars, or a quarter of a million dollars. Like, stuff like that, that's part of an AI governance program that has nothing to do with privacy or security. It's how AI is functioning, how that has financial impact on the organization. And again, that goes back to what we get when we think of risk. We get too often
Steve Gentry: Focused on the security or privacy aspects of it, and we've turned it into a to-do list instead of thinking about the impact to the larger business.
Jordan Tucker: Yep. One more question on the procurement topic. What disclaimer should apply to API usage, given that AI can re-identify or infer PII, even from data that's been scrubbed?
Jodi R. Daniels: I don't know if we can solve that really specific disclosure requirement here.
Jodi R. Daniels: I… I have, like, a thousand more questions to truly be able to answer that one, so… I hate not being able to answer questions, but I feel like it's a matter of what kind of API, and where is it, and what kind of data, and where is it going, and who is the vendor.
Jodi R. Daniels: You're welcome to reach out to me, whoever asked that question. I'm happy to try and have a follow-up.
Steve Gentry: Yeah, API keys, like, we… that's something that's typically involved in a… in a risk program.
Steve Gentry: Until you start getting into AI. This is a discussion I've had with many of my peers recently,
Steve Gentry: Like, as people wanting to do the equivalent of COD co-worker, they're wanting to use agents, and they're trying to automate stuff.
Steve Gentry: we've treated API keys like candy in a dish at the end of Halloween… the end of the night at Halloween, and we're just handing them out. We don't want, like… it's like, no, like, we… we have… the insider risk program that existed are kind of getting turned on in.
Steve Gentry: with… as we're looking at, because it's productivity, we're trying to increase it, that we've just started, like, API keys get handed out all the time as people are scheduling or creating new AI apps.
Steve Gentry: And I think, like, we have gone way overboard and need to come back and address this aspect inside of a company of, like.
Steve Gentry: okay, what are all these agents doing? What API access do we have? Like, has someone created a co-work that has access to, like, 30 different applications? And if that harness is compromised, then all of these credentials and all of this activity then just escapes the guardrails that we've put in place.
Steve Gentry: So yeah, this is an even broader topic that could be covered, in and of itself, of how we're handling insider risk with… with AI.
Jordan Tucker: Cool, yeah, so reach out to both Steve and Jodi for follow-ups on that one, but thank you so much, Jodi and Steve, for being here and answering all these questions. Thank you to everyone who attended the webinar. We will share out the recording, we will share out the trends report, and again, reach out to any of the three of us to learn more.
Jordan Tucker: Thanks, everyone.
Jodi R. Daniels: Thank you!