License to Govern: The Counterintelligence Playbook for AI Security

Tuesday, August 11, 2026
10:10 AM - 10:45 AM
AI Risk Summit Tech Track (Salon II)

About This Session

Every organization thinks it has a James Bond security program. Sophisticated. Equipped. Ready for catch villains as soon as they break in.

The problem: today's threats don't break in. They already have a badge. They were credentialed by your own people, with good intentions, but without the knowledge or approval of the security team. Today’s threats look exactly like allies until they don’t.

Meet the three double agents already inside your organization: the Ghost (Shadow AI), the Mole (AI Agents), and the Sleeper (OAuth Tokens). Each credentialed. Each trusted. Each passing data through pathways your security team can't see.

Through real breach stories from Salesloft Drift, Vercel, and Klue, this session builds the case for AI Governance as a counterintelligence program — not a security product. The organizations who invest now in building this program will be in a much different place in 18 months than those who don’t.

Your workforce is the intelligence network. Enlist it in the mission.

Speaker

Patrick Dillon

Patrick Dillon

CRO - Nudge Security

Patrick Dillon has spent 20+ years partnering with security executives to solve high-stakes challenges: reducing attack surface, protecting sensitive data, and enabling security teams with solutions that manage risk at scale. Prior to Nudge Security, Patrick served as CRO at Airlock Digital and before that held senior leadership roles at Saviynt, BeyondTrust, and Hewlett Packard Enterprise, advising organizations on solutions that strengthen identity and access controls and protect critical systems. At Nudge Security, Patrick continues that work by helping security leaders gain control of shadow AI and SaaS sprawl, improve governance, and build defensible, measurable security outcomes.