EXPERTISE · GENERATIVE AI

Generative AI changes both the application stack and the risk model.

Generative AI systems create or transform content using foundation models. In enterprise environments, the risk surface extends beyond the model to prompts, retrieval systems, data sources, orchestration, plugins, identity, applications and runtime controls.

DEFINITION

What does this mean in an enterprise context?

Generative AI systems create or transform content using foundation models. In enterprise environments, the risk surface extends beyond the model to prompts, retrieval systems, data sources, orchestration, plugins, identity, applications and runtime controls.

CONTROL DIMENSIONS

Four lenses for executive review.

Architecture

Model choice, gateways, retrieval, orchestration and application boundaries.

Data

Sensitive-data exposure, retrieval permissions, lineage and retention.

Security

Prompt injection, insecure tool use, model supply chain and application abuse.

Governance

Use-case classification, ownership, evaluation, human oversight and evidence.

QUESTIONS TO ASK

Useful questions for leadership, risk and technology teams.

What enterprise data can the application retrieve or disclose?

The answer should identify an accountable owner, a defined control expectation and evidence that the control operates.

How are prompts, outputs and model interactions evaluated and monitored?

The answer should identify an accountable owner, a defined control expectation and evidence that the control operates.

Which controls sit in the model layer versus the surrounding application architecture?

The answer should identify an accountable owner, a defined control expectation and evidence that the control operates.

How are third-party models and services governed?

The answer should identify an accountable owner, a defined control expectation and evidence that the control operates.

RESEARCH

Independent analysis on generative ai: enterprise risk, architecture & governance.

The research library is published separately under /research/ using WordPress.

Explore research →

INDEPENDENT ADVISORY

Complex technology. Clearer risk decisions.

For AI strategy, governance, Agentic AI, security, assurance or cyber-risk requirements, describe the decision you are facing and the context around it.

Discuss an Advisory Requirement ↗