Navigating Governance in the Age of AI: Strategies for a Digital Future
Download resourcesAbout this session
Sabine Lainer, a governance, risk and compliance specialist at GoSecure, walks through how security, privacy and AI governance relate as three linked layers, each anchored in law: PIPEDA, Quebec's Law 25 and GDPR require securing personal data, and most of them also regulate automated decision-making, which is the legal hook into AI. She compares the EU's centralized AI Act, Canada's hybrid federal-provincial approach and pending AIDA, and the US's decentralized, state-by-state model (Colorado and California so far), noting all three define similarly dangerous domains: education, employment, finance, government services, healthcare, insurance and legal services. Using fictional examples (Terminator, Westworld, a novel) to illustrate the fear of unchecked automated decisions, she introduces GoSecure's AI governance framework, which scopes organizations into six categories from hardcore AI development down to casual end-user tools like Copilot, then walks through context and culture, policies, data governance, risk management and horizon scanning. She closes with the FTC's real case against Rite Aid, whose facial-recognition shoplifter detection produced biased false positives against women and people of colour because the company skipped risk assessment, testing and staff training, illustrating exactly what these emerging laws are designed to prevent.
In an era where artificial intelligence (AI) has become pervasive across numerous facets of society, the imperative for a robust governance framework to ensure its responsible and ethical development, deployment, operation, and usage. This presentation aims to introduce and dissect the concept of AI governance, shedding light on its constituent elements and the operational challenges they pose.
We will delve into the intricate terrain of AI principles, such as accountability, bias, transparency, and risk, illustrating how AI governance frameworks must deftly navigate these complexities to cultivate trust and mitigate potential harms.
The significance of regulatory compliance emerges as a cornerstone, given the swiftly evolving landscape of AI regulations worldwide. From existing legal frameworks to nascent guidelines, we will scrutinize the necessity for an adaptive AI governance framework capable of synchronizing with the rapid advancements in AI technology and the accompanying regulatory shifts.
Central to our discourse is the prominence of risk management, given the diverse array of risks spanning from privacy concerns to cybersecurity threats, algorithmic biases, and unintended consequences. Our exploration will encompass strategies for identifying, assessing, and mitigating these risks, underscoring their integral role within AI governance frameworks.
Furthermore, we will address the convergence of AI governance with privacy and security imperatives, emphasizing the imperative to safeguard sensitive data and thwart unauthorized access or misuse.
In conclusion, this presentation underscores the urgent need for the establishment of comprehensive and adaptable AI governance mechanisms. Such mechanisms are essential for navigating the complexities inherent to AI, thereby maximizing its benefits while minimizing potential risks and harms.
Key takeaways
- Treat AI governance as an extension of existing security and privacy programs, not a separate discipline built from scratch.
- Scope your organization first: hardcore AI development, hosting/operating AI, vertical development using existing models, AI-assisted development, third-party AI dependency, and casual end-user tools each need a different level of governance.
- Watch for automated decision-making in high-risk domains named across current laws (education, employment, finance, government services, healthcare, insurance, legal services); these draw the strictest scrutiny.
- Run and document a real risk assessment, testing and staff training before deploying any AI-driven decision system, as the Rite Aid facial-recognition case shows what happens when this is skipped.
- Track applicable law by whose life the AI affects, not by where your company or servers are located; jurisdiction follows the person impacted, much like GDPR.
Speakers

Sabine Lainer is the Senior Advisor at GoSecure, bringing a wealth of knowledge and experience in security and privacy. She holds degrees from the University of Applied Science in Furtwangen, Germany; Brunel University in London, UK; the University… Read moreRead less
Sabine Lainer is the Senior Advisor at GoSecure, bringing a wealth of knowledge and experience in security and privacy. She holds degrees from the University of Applied Science in Furtwangen, Germany; Brunel University in London, UK; the University of South Australia; McGill University; Concordia University; and the University of Alberta. Sabine is passionate about security, privacy, learning, and teaching. She was awarded an innovative teaching prize in 1997 and was nominated for the Women in IT Award – Security Champion in the UK in 2016. Having lived and worked in nine countries, Sabine is now a proud permanent resident of Canada. Outside of her professional life, Sabine enjoys running, cycling, hiking, paddle boarding, and indulging in science fiction and fantasy stories through various media. A dedicated Star Trek fan, she takes great pride in living in the birthplace of William Shatner.

