Enterprise AI Governance
For many businesses around the world, security and governance strategies pre-date the artificial intelligence (AI) era. This has left many CIOs and CISOs hesitant in their approach to integrating AI into their enterprises.
“Startups Scramble to
Build Immediate AI
Security”
Dark Reading, January 20241
“AI Governance in the Age of
Uncertainty: International Law as
a Starting Point”
Just Security, January 20242
“The
AI Governance
Challenge”
S&P Global, November 20233
Chief Information Security Officer, Auditboard
Good AI governance with
Tehama’s Enclave platform
Tehama provides businesses around the globe with a key capability: to create secure and compliant “enclaves”, which are cloud-hosted highly-restricted zones (HRZs) within which only governed data is available to authorized users that may use only authorized apps and services.
This ability, to secure data and applications by creating secure access perimeters with role-based access and controls; data governance; privileged access management; and auditing and compliance support, it mission-critical in the AI era. The Enclave platform is ISO 27001, 27017, 27018 compliant, PCI compliant, and routinely penetration-tested.
Tehama's fastest growing use case is to help enterprises govern their adoption of AI.
Deliver Peace of Mind to Your Key Stakeholders
CIOs and CISOs: Good governance is your business. Regulated AI governance is on the horizon. Be prepared with Tehama.
Governments around the world are developing legislation to regulate AI and impose good governance for high-risk use cases. Examples include the European Union (EU) AI Act4; the Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence5, published by The White House in October 2023; and, Canada’s proposed Artificial Intelligence and Data Act (AIDA)6, introduced as part of the Digital Charter Implementation Act, of 2022.
The EU’s approach to data protection, for example, sets the tone for how businesses like yours should approach their security and AI governance strategies. Many countries, including Canada, the UK, and Japan, for example, have made every effort to remain compatible due to hard-won EU GDPR adequacy findings. The United States follows this same pattern for any business participating in the EU-US Data Privacy Framework 7, to ensure adequate levels of data protection.
- The AI system must be sufficiently transparent to enable users to interpret the system’s output and use it appropriately (no black boxes).
- Users must receive instructions for use that are concise, complete, correct and clear and “comprehensible”
- Conformity with the AI Act must be established before placing the AI system on the market.
- In regulated product sphere, procedure will likely be carried out by existing regulatory authorities.
- In other spheres, provider will do a self-assessment.
- Registration of the system with EU authorities.
- Declaration of conformity and CE marking.
- Notification to authorities of non-compliance.
- Establish a comprehensive quality management system.