Governing the Intelligent Enterprise: AI Risk Management Frameworks for Production Systems

Wednesday, August 12, 2026
9:35 AM - 10:10 AM
CISO Forum Track (Salon III)

About This Session

AI systems are failing faster than governance can keep up. Documented AI safety incidents surged 56.4% in recent years, with hallucination rates nearly doubling and autonomous agents executing unintended real-world transactions. For AI engineers shipping production systems at scale, the question is no longer whether to implement risk management, but which frameworks actually work when things go wrong.

This talk examines the operational reality of AI risk governance through the lens of the NIST AI Risk Management Framework and its ecosystem: the EU AI Act (enforceable August 2026), ISO/IEC 42001 certification standards, and NIST AI 600-1's 12 generative AI-specific risk categories. Unlike theoretical discussions of "responsible AI," this session focuses on what production teams actually need: inventory systems for AI components, monitoring architectures that catch drift before it becomes disaster, and accountability structures that survive real incidents.

You'll learn the four-function GOVERN-MAP-MEASURE-MANAGE cycle that applies across the AI lifecycle, how to instrument AI systems for continuous monitoring, and why organizations with documented governance infrastructure respond to failures 10x faster than those operating without it. We'll cover practical implementation patterns for managing third-party model risks, red-team evaluation protocols that find vulnerabilities before adversaries do, and the emerging insurance and procurement requirements that are making governance a competitive differentiation.

This isn't compliance theater. When AI systems execute millions of decisions daily - approving loans, routing patients, generating customer-facing content, traditional human-in-the-loop review cannot scale. The gap between capability deployment and risk infrastructure is widening, not closing. Organizations that embed governance into AI design earn the trust that converts capability into sustained advantage. Those that don't are building liability at scale.

Expect tactical guidance on building AI risk management flywheels, navigating multi-framework compliance across jurisdictions, and translating voluntary standards into engineering requirements before regulators mandate them. Whether you're deploying foundation models, building agentic systems, or integrating AI into critical infrastructure, you'll leave with a practical roadmap for governing AI systems that cannot afford to fail.

Key Takeaways:
- The NIST AI RMF four-function architecture and how to implement it in production environments
- NIST AI600-1's 12 AI-specific risks and mitigation actions engineers can deploy now
- Monitoring strategies for detecting model drift, bias, and adversarial exploitation
- Building incident response capabilities before the first material AI failure
- Why organizations treating governance as optional are making an increasingly poor regulatory timing bet

For AI/ML engineers, engineering leads, architects, and CxOs responsible for production AI systems.

Speaker

Sanjeev Sharma

Sanjeev Sharma

Field CTO - StackGen

Sanjeev brings over 30 years of expertise in DevOps, Platform Engineering, and Cloud Architecture. He is a former IBM Distinguished Engineer and the company’s first Field CTO for DevOps. Sanjeev served as Senior Vice President of Engineering and Developer Platforms at Dell Technologies and SVP of Developer Platform at Truist. Sanjeev is a noted author, having written the 1st edition of ‘DevOps For Dummies’ and the bestseller ‘The DevOps Adoption Playbook.’ He blogs on at http://sdarchitect.blog.