
Regulating AI is mandatory. Steering it well is the art.
An AI policy sitting in a drawer doesn't prevent a single data leak. Shadow AI isn't a fringe issue, it's an attack surface.
Topic
When & Where
Details
Format:
Workshop
Language:
German
Session description
Kevin Engelhardt Promoting AI competence instead of dictating it — that's the new direction under the EU AI Act since the Digital Omnibus. For a company's actual security posture, that changes little: a AI policy sitting in a drawer doesn't prevent a single data leak. Employees are already using ChatGPT, Claude & Co. in their daily work, with or without approval, with or without oversight. Every unchecked prompt is a potential leak of customer data, contracts, or source code. Shadow AI is no longer a fringe issue, but an attack surface that remains completely unmonitored in most organizations. This talk shows how security leaders can turn pure regulation into real governance, with approaches that actually work, rather than policies nobody reads.


