How should I as a Security Leader learn Gen AI - Initial Thoughts !

 

    Since the last two years we have been overwhelmed with the deluge of Gen AI based applications and use cases. ChatGPT in its first avatar brought AI to our homes and daily lives. While personally, most of us continue to use Gen AI for various tasks we are also finding our organisations also discussing, brainstorming and adopting Gen AI in various forms.   The usage of Gen AI has moved from generating content to answering queries, preparing detailed plan and doing large complex tasks. 

    When we are at home we do not tend to worry so much about the security implications of Gen AI as we tend to be cautious as well as our data sets are generally smaller and do not reveal so much.  However this is also does not hold true as most recently I saw LinkedIN deciding to use its users content to train its GenAI models. This was without an intimation or warning to users except in regions like EU which have stringent privacy laws.  After the initial euphoria, the usage of Gen AI has raised several issues. The key issues include 

  1. Privacy Issues - use and leakage of persona data 
  2. Ethical Issues - bias in answering queried 
  3. Security issues - leakage of confidential data while training data.
 These issues are compounded when Gen AI models are leveraged by organisations. Organisations need to be concerned of several of these issues when leveraging Gen AI. Here the role of the Security Leader is very important. Unlike the Legal and Privacy teams, security teams work closely with the technical Engg teams and can understand the technical aspects much better. This helps them to understand the nuances better and tailor their recommendations and guidelines to ensure security is present while ensuring efficiency and productivity is not hampered. 

 Here in this blog I am trying to raise the key questions a security leader should be raising or be concerned with to ensure security of Gen AI applications within an organisation. 

There are three key areas where a security leader should be focused on in respect to Gen AI 
  1.  Securing usage of Gen AI among employees 
  2. Securing applications build with Gen AI models either in house or commercial 
  3. Leveraging Gen AI for security use cases 
I am beginning to learn these aspects and will share more as I build my knowledge by taking various courses online and reading books and white papers. 

Please do share any good resources - Courses, books and white papers which can aid my learning. 

Comments

Popular posts from this blog

API Security - A risk based approach for CISOs

2024 Year Review and thoughts

Key Steps for Building an Effective Data Protection Program: From Analysing Business Needs to Ongoing Protection