Cherry Bekaert: Risk & Cybersecurity · Cherry Bekaert

Understanding the Drivers of AI Compliance

·28 min·1 clip
Steve says shadow AI, prompt injection, model theft, and model drift are among the biggest overlooked AI risks.
1. Cherry Bekaert: Risk & Cybersecurity focuses this episode on the drivers of AI compliance and how organizations can navigate them. 2. Lauren Ross hosts Steve Urcillo, a partner in the cybersecurity group, and Morgan Haig, a senior manager at Metatology Services, and both matter because they connect governance and vendor risk. 3. The episode asks how companies should handle AI compliance when regulations, procurement demands, and cyber risks are changing at the same time. 4. Morgan contrasts the EU AI Act with U.S. executive orders and says enforcement has been pushed back more than once. 5. Morgan says the EU AI Act emphasizes model development, prohibited use cases, and data sourcing more than detailed security language. 6. Steve says organizations need an AI governance model with executive oversight, accountability, and a cross-functional AI and risk and ethics committee. 7. Steve says teams should identify coming regulatory requirements, assign ownership, and build escalation paths for high-risk AI deployment. 8. Steve ties that governance work to risk assessments that define likelihood, impact, regulatory relevance, and control mitigation. 9. Steve says an inventory of AI models, data sources, lawful bias, ownership, processing locations, and sovereignty issues is necessary for risk mitigation. 10. Morgan says U.S. organizations should prepare for changes even when executive orders do not carry the same weight as formal regulation. 11. Steve says enterprise buyers now ask more granular questions than they did 18 months ago about AI use. 12. Steve says mature organizations want to know where data comes from, whether it is used in training, and what safeguards exist on the front end and back end. 13. Steve says prompt injection should be treated like a new zero trust problem and that least privilege matters more as systems become more autonomous. 14. Steve lists ISO 27001, 42001, and SOC 2 as certifications that buyers look at when evaluating AI vendors. 15. Steve says organizations increasingly want proof of responsible AI through bias testing, fairness testing, drift reduction, and AI red teaming. 16. Morgan says many AI tools are built on a small set of frontier lab capabilities, so procurement teams must understand how models work before asking vendors the right questions. 17. Morgan says procurement teams are adding specific AI questions, validation steps, attestations, and contract language to BAAs, SLAs, and other agreements. 18. The tone is practical and interview-driven, with Lauren Ross prompting detailed answers and both guests using concrete compliance examples. 19. Listeners in healthcare, security, compliance, and vendor risk management will get the most value. 20. Listeners wanting pure theory or lightweight AI commentary may skip it. 21. Morgan says compliance frameworks help with reputational harm because due diligence, documentation, and transparency change how regulators and clients respond. 22. Morgan uses Anthropic, OpenAI, ISO, and High Trust as examples of how market signaling can shape trust after an AI failure. 23. Steve says some risks are technical, including adversarial attacks, indirect prompt injection, model theft, plugins, APIs, and AI supply chain issues. 24. Steve says shadow AI, automation bias, deepfakes, phishing, and model drift can create exposure even when the organization has approved systems. 25. The episode closes by returning to the importance of governance, monitoring, and shared responsibility across internal teams and vendors. 26. The discussion stays conversational and specific, but it is dense with acronyms, frameworks, and procurement detail. 27. The guests speak from cybersecurity and healthcare consulting perspectives, which gives the episode an operational rather than theoretical style. 28. Compliance leaders, GRC teams, and healthcare security staff will recognize the vendor and governance problems discussed here. 29. General listeners without compliance or procurement duties may find the detail level too operational. 30. The strongest throughline is that AI risk management now depends on governance, vendor scrutiny, and continuous monitoring rather than one-time approval.

As heard by us

AI compliance starts with the right questions, not checkboxes.

AI compliance is treated here as a practical problem, not a slogan. The episode stays on regulatory pressure, vendor oversight, and the way procurement teams actually buy software, which makes it useful for listeners trying to sort out a field that many organizations still only…

Read the full review in PlayNext →

Why you'd press play

You want the questions to ask before an AI vendor gets a green light.

Read the full recommendation in PlayNext →
Listen to the show on