Hi all, new to the community, so I thought I'd kick off with something I keep running into. It comes up constantly in conversations with clients and colleagues, and I'm also actively researching it at the moment, so I'm genuinely interested in how others are approaching it rather than just asking for the sake of it.
AI is no longer a single, controllable entity. It has become embedded in nearly every SaaS application we rely on, often integrated seamlessly by vendors without much notice. Your CRM, ticketing system, and email client have all subtly transformed into AI-enabled tools.
Two things I'd love to hear from the community on:
- 1.
Practically, how are you managing AI risk when it's spread across your entire stack like this? Are you treating it through your existing vendor risk process, running a separate AI register, or something else entirely?
- 2.
If you work for a business that has introduced AI into its own product, how have you effectively notified users and made them aware of what you're doing and how? What's actually worked, and what fell flat?
Keen to hear real-world approaches rather than theory. What's working for you?