The Shadow Risk Problem: Governing Security Exceptions in AI-Driven Systems

Tuesday, August 11, 2026
11:30 AM - 12:00 PM
AI Risk Summit Strategy Track (Salon I)

About This Session

Security programs increasingly rely on exceptions, waivers, and risk acceptances to keep critical systems running under tight delivery timelines. But in AI‑driven and highly automated environments, these exceptions create shadow risk—hidden exposures that are rarely tracked or governed. A clear example is the Chevrolet dealership incident, where a ChatGPT‑powered chatbot was tricked into “agreeing” to sell a $60,000+ SUV for $1 through simple prompt‑injection, due to missing guardrails and uncontrolled overrides. This real‑world failure shows how unmanaged exceptions in AI systems can quickly escalate into operational, reputational, and security threats

Speaker

Devashri Datta

Devashri Datta

Security and Open Source Leader - NVIDIA

Devashri Datta is a cybersecurity and AI risk governance specialist focused on large-scale software ecosystems, with expertise in software supply chain security, open-source compliance, and AI-driven risk frameworks. Her work centers on building structured governance models for managing vulnerability exposure, dependency risk, and behavioral exploitability in modern software and AI systems.

She has contributed to industry-facing research and analysis on third-party software transparency, SBOM-based governance, and lifecycle risk management approaches that bridge traditional vulnerability management with emerging AI security challenges. Her work emphasizes practical, scalable frameworks for identifying and governing hidden risk in complex, distributed systems.