General session image of Congress@it-sa

Regulating AI is mandatory. Steering it well is the art.

An AI policy sitting in a drawer doesn't prevent a single data leak. Shadow AI isn't a fringe issue, it's an attack surface.

Topic

Awareness / Phishing / Fraud

When & Where

calendar_month

Tue, 10/27/2026 10:30 AM - 11:30 AM

location_on

Room Riga, NCC Ost

Download session as iCaldownload_for_offline

Details

  • Format:

    Workshop

  • Language:

    German

Session description

Kevin Engelhardt Promoting AI competence instead of dictating it — that's the new direction under the EU AI Act since the Digital Omnibus. For a company's actual security posture, that changes little: a AI policy sitting in a drawer doesn't prevent a single data leak. Employees are already using ChatGPT, Claude & Co. in their daily work, with or without approval, with or without oversight. Every unchecked prompt is a potential leak of customer data, contracts, or source code. Shadow AI is no longer a fringe issue, but an attack surface that remains completely unmonitored in most organizations. This talk shows how security leaders can turn pure regulation into real governance, with approaches that actually work, rather than policies nobody reads.

Sponsored by