[Panel] Beyond Compliance: Who Owns, Measures, and Engineers Resilience in the AI Enterprise?

Tuesday, August 11, 2026
4:05 PM - 5:00 PM
CISO Forum Track (Salon III)

About This Session

Patching, compliance, and AI adoption metrics may demonstrate activity, but they do not
necessarily prove that an organization is secure, resilient, or receiving meaningful value from its technology investments. This panel will examine how CISOs can move toward continuous
security engineering, control validation, secure-by-design practices, recovery testing, and
measurable operational resilience as technologies, threats, and dependencies continue to change.

Panelists will also discuss how responsibility for AI risk should be divided across the CISO,
CIO, Chief AI Officer, legal, compliance, data governance, and business leadership. The
conversation will focus on who can approve or stop AI-enabled deployments, how residual risk
should be accepted, and which metrics best demonstrate control effectiveness, AI asset visibility, human oversight, fallback readiness, provider concentration, and return on investment.