The Shadow Risk Problem: Governing Security Exceptions in AI-Driven Systems
About This Session
Security programs increasingly rely on exceptions, waivers, and risk acceptances to keep critical systems running under tight delivery timelines. But in AI‑driven and highly automated environments, these exceptions create shadow risk—hidden exposures that are rarely tracked or governed. A clear example is the Chevrolet dealership incident, where a ChatGPT‑powered chatbot was tricked into “agreeing” to sell a $60,000+ SUV for $1 through simple prompt‑injection, due to missing guardrails and uncontrolled overrides. This real‑world failure shows how unmanaged exceptions in AI systems can quickly escalate into operational, reputational, and security threats
Speaker
Devashri Datta
Security and Open Source Leader - NVIDIA
Devashri Datta is a cybersecurity and AI risk governance specialist focused on large-scale software ecosystems, with expertise in software supply chain security, open-source compliance, and AI-driven risk frameworks. Her work centers on building structured governance models for managing vulnerability exposure, dependency risk, and behavioral exploitability in modern software and AI systems.
She has contributed to industry-facing research and analysis on third-party software transparency, SBOM-based governance, and lifecycle risk management approaches that bridge traditional vulnerability management with emerging AI security challenges. Her work emphasizes practical, scalable frameworks for identifying and governing hidden risk in complex, distributed systems.
She has contributed to industry-facing research and analysis on third-party software transparency, SBOM-based governance, and lifecycle risk management approaches that bridge traditional vulnerability management with emerging AI security challenges. Her work emphasizes practical, scalable frameworks for identifying and governing hidden risk in complex, distributed systems.