AI Security & Governance (Securiti)

Overview :
The AI landscape broadens every single day, and as it does so, concerns arise.
The security and safety issues that are being discussed may come to you as technical failures that should, well, be technically resolved, but the AI problem crossed that boundary long ago. AI is additionally bound by geopolitical tensions as well as corporate interests. And therefore, its legislation landscape is, to say the least, chaotic.
This is my take on AI Governance after going through the course prepared by Securiti.
The following post will serve as a cheat sheet/summary of what I have learned through this course, as well as an update to the latest AI policy news.
Challenges
While AI can be effective, a blind belief in its capabilities can be damaging. Many AI-related phenomena or misuses have pushed AI Governance to become an urgent policy issue.
Hallucinations , for instance, are tricky and harmful. When an AI chatbot confidently outputs fictitious information, users or organisations can no longer reliably distinguish truth from well-formatted AI production and that dilemma can deny the utility of AI in the first place. Last year only, a Norwegian municipal council proposed a sensitive policy report citing 18 academic and official sources, 11 of which were made-up hallucinations by AI. You can read more about it here : How can Tromsø, Norway shut down some schools? Let’s ask the AI!
Bias and Discrimination at Scale are another issue. AI systems inherit and amplify the biases present in the training data, and that consequently affects the decision-making process, possibly resulting in discriminatory outcomes. In an era where AI is impactful across significant areas like credit scoring, recruitment, medical diagnostics, and power distribution, malicious actors can exploit this problem and therefore create loopholes that allow marginalization of communities.
While the first two focus on worrying about AI outputs, with the emergence of Agentic AI, the focus is shifting naturally to worrying, slightly more, about actions. Organisations are deploying autonomous agents with little to no restrictions, introducing newer and more potent attack surfaces.
All these problems and more (Military AI, Deepfakes, Autonomous Weapons ..), are all results of the lack of detection measures, monitoring or at least visibility on what is the AI doing, and how is it doing it. This phenomenon is called Shadow AI: a blind spot for security allowing problems just to happen.
Five-Step Path to AI Governance
The course simply provides the Securiti methodology for AI Governance : a 5-Step process based on industry/regulatory references like NIST AI RMF and EU AI Act.
1- AI Model Discovery
A first step of identification is crucial to this whole process. It involves locating and understanding all deployed AI systems within an organisation, across all its environments (Public Clouds, SaaS Apps, on-premise or private cloud environments). This the stepping-stone for the next steps and is also where shadow AI gets surfaced.
2- AI Risk Assessment
This step runs a risk evaluation on each cataloged model, ideally before it ever hits production. The key artifact here is the model card: a structured profile covering intended use, known limitations, toxicity scores, hallucination risk, bias indicators, copyright concerns, and even energy efficiency. Based on those ratings, you make a clear call: sanction, block, or deploy-with-guardrails.
3- Data and AI Relationships Mapping
The third step’s goal is to establish visibility : what was once the root problem of shadow AI is tackled with data flow mapping. The outcome of this step is a full dependency graph : what is each model connected to ? Be it data sources or a SaaS app, everything must be documented.
This is the step that draws the line between reactive incident response and proactive governance.
4- Data and AI Controls Implementation
Once full visibility is established, this step puts the actual guardrails in place both on the input and output side (of an LLM). Input guardrails manage operations like redaction, anonymization, entitlement enforcement, while output guardrails include LLM firewalls and prompt injection blocking.
5- AI Regulatory Compliance
The final step maps the entire work to the regulatory landscape, and that’s where it gets messy.
This landscape is fragmented and moving fast. The EU AI Act, NIST AI RMF, China’s generative AI regulations, all serve the same goal but don’t always agree on definitions, risk thresholds or documentation requirements, and an organization operating globally finds itself in a tough position because it doesn’t get to pick one.
Compliance automation comes in handy because compliance isn’t a one-time audit , it’s a continuous process that needs to keep pace with both AI deployments and the regulations evolving around them.
AI Policy Landscape
Major Schools of Thought
After the completion of this course, I was genuinely intrigued to know more about the current AI Policy lanscape, and what exactly created so much chaos.
EU Model : Rights-based/Risk-based regulation
The EU built its AI regulations around AI accountability rather than just market performance. It classifies AI by risk, banning worst uses (social scoring) and enforcing severe obligations on high-risk applications like hiring tools.
US Model : Innovation First
US under Trump’s administration urged agencies to reduce regulatory burdens in favour of market performance when it comes to AI development, through an Executive Order passed in January 2025. Fear of Chinese competition is the main motive for this urgent legislative act.
China Model : State Sovereignty
Beijing built AI governance that serves state first. While it promotes cooperation and increasingly more inclusion of AI across science, technology, industry, consumer services public welfare, governance, security, and international collaborations, it defends tight control over data and AI deployment.
Global Tensions
The EU is clashing with Big Tech backed by the US government. Meta publicly announced it would not sign the EU’s AI Code of Practice in claims that it creates “too much legal uncertainty”. The Trump administration is not happy with American companies having to comply to foreign laws in order to access European consumers.
The US itself is having an internal battle regarding AI. States are legislating on their own: Texas’s Responsible Artificial Intelligence Governance Act, Colorado’s comprehensive AI legislation and California’s AI Transparency Act are deemed “scattered” pieces of law that hinder the nation’s evolution by the White House, who’s urging for a unified approach.
Conclusion
Given the current global tensions, it’s safe to question the real intentions of governments when it comes to AI Governance. Are governments prioritizing individual privacy and safety, financial gain, global prestige or more authority ? the answer changes depending on who’s sitting at the table.
What’s clear though is the direction: The world-wide approach is now becoming “self-governance”-oriented, meaning industry-led voluntary standards instead of rigid legal obligations. AI summits are increasingly functioning as forums where Big Tech shapes the output.
In the end, governance is becoming global in form but underneath it all, the geopolitical tensions still guide the motion. The technical landscape will keep moving regardless. Whether the legal one catches up is a different question entirely.
Rating
Fun course. A little different from what I’m used to work on. Enjoyed writing this piece, for a moment there I was in highschool again writing an assignment for the English class.
4 Stars.
⭐⭐⭐⭐
