
AI Governance Begins with Transparency, with Jeremy Snyder
In the AI: Trust but Verify podcast, our host, Alec Crawford (@alec06830), Founder and CEO of Verapath (https://www.verapath.com), interviews guests about how they are using AI in business, where you can trust AI, and where you need to put up guard rails.In this episode of AI: Trust but Verify, Alec Crawford sits down with Jeremy Snyder, co-founder and CEO of Firetale AI, to explore the rapidly evolving intersection of AI, cybersecurity, and enterprise governance. Jeremy traces his AI journey back to the early days of natural language processing, explains why most organizations already have "shadow AI" whether they realize it or not, and discusses the growing need for visibility into employee and AI agent activity. The conversation covers prompt injection attacks, AI security, open versus closed-source models, China's AI strategy, and why organizations must rethink vulnerability management as AI becomes embedded in critical business processes.Top 5 TakeawaysYou almost certainly have AI in your organization already. Even companies that believe they have banned AI often discover employees are using ChatGPT, Copilot, Gemini, or other public tools with sensitive business information.AI governance starts with visibility. Before organizations can manage AI risk, they need to know which models employees and AI agents are using, what data they're accessing, and whether their activity complies with company policies.The biggest AI security risks extend beyond prompt injection. Vulnerabilities increasingly exist in the surrounding cloud infrastructure, APIs, integrations, and AI marketplaces—not just inside the language models themselves.The next challenge is managing AI agents, not just AI users. As enterprises deploy autonomous AI agents to execute business processes, organizations will need continuous monitoring, telemetry, and governance to ensure those agents stay on task and operate safely.AI is becoming a strategic national security issue. The competition between the U.S. and China is driving rapid innovation, but organizations cannot ignore cybersecurity, patch management, and governance as AI becomes critical infrastructure across financial services and other regulated industries.ResourcesHere are a few of the companies, platforms, and frameworks mentioned during the episode that listeners may find helpful:Firetale AI – AI security and observability platform focused on visibility into employee AI usage and AI agents. https://firetale.aiCyber Risk Institute (CRI) AI Risk Management Framework – AI governance framework developed for financial institutions. https://cyberriskinstitute.orgNIST AI Risk Management Framework (AI RMF) – Widely adopted framework for managing AI risk. https://www.nist.gov/itl/ai-risk-management-frameworkNIST SP 800-53 – Security and privacy controls for information systems used across government and regulated industries. https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/finalISO/IEC 42001 – International standard for AI management systems. https://www.iso.org/standard/81230.html
