|
SMALL BUSINESS CYBERSECURITY Simple, Easy to Follow Help Certified Information Systems Security Professional |
| Home | Credentials | Coaching | Contact |
|
Clean Definitions What is CyberWhat is Risk What is a Threat What is a Framework What is the Cloud What is a CISO or BISO What is a decent Plan? What is AI? Resources
Measuring and Manageing Information Risk,
Authors: Jack Freund and Jack Jones
How to Measure Anything in Cybersecurity Risk
Authors: Douglas W. Hubbard and Richard Seiersen |
What's the deal with AI? AI stands for Artificial Intelligence. As of 2025, it is still relatively new, constanstly changing, AND something that must be seriously considered because of the wonderful and aweful things that it may do. I offer the following opinions on how to govern it. Can it be done by just one person? In answer to an AI leaders offer to pay $555,000 per year to someone to lead the efforts of securing humanity from Artificial Intelligence, a kindly but firmly as possible, I say: It is the wrong way to offer a high salary for something this important. And, the focus seems to be only on the technology side when it is actually very much a governance question with a little bit of technology to facilitate the implementation. But I get it and I forgive him. He wants to attract the best technical talent that he can. Sometimes money talks. However, something as existentially important as this topic needs a group of people in a council who have nothing other than the continued success of the Earth and every living thing therein at heart, and that is priceless. A high salary would taint the pool of people interested, filling such a council with those who may not play well with others. There is a role for those types of people in this venture, but not in a council of such importance. Perhaps they can be in the solution creating group. Those in this council must be humble. They must be teachable. They must be listeners. They must be flexible. They must be trustworthy. They must think and understand deeply. They must be totally focused on this exact problem and all of its side elements (of which there are many). Such a set of people should be purely voluntary with maybe only a subsistence stipend equal to a middle-class income for the country they reside in. Perhaps the salary of a US Congress member, or the other comparable governing folks from other countries would be appropriate. I am wise enough to know that I am not nearly smart enough to single handedly solve the AI safety and security problem. But I do have opinions on the subject that I'd like to toss some organizational ideas out: Ideas to protect your data:
Ideas to create governance for AI:
From a technology (and punitive) perspective: Artificial intelligence must only be permitted to operate on and/or make changes to things that its process owners own or that the owners of the devices being operating on have expressly signed contracts permitting such operations and/or changes. An account to the AI engineer and a request for it to operate on a device owned by the requestor is considered a contract. There must be a protective mechanism created and installed on every artificial intelligence engine that establishes ownership and permission granting for other devices to connect, ask and do. Common computer devices must also have this protective mechanism installed to block unwanted incoming connections. When a "user" signs up for an account, the exchange of certificates can occur. The certificate must be tied to a particular account. This relationship is also required for any and all agentic interactions. We must be capable of identifying the root start of every thread and action as well as contributing threads and actions. The AI engine cannot be allowed to alter or taint any log file that details who or what did what and when. Every compute device or edge network device must become capable of seeing the ownership and permissions granted in order to facilitate stopping rogue AI devices from making unauthorized connections. Perhaps the granting of permissions and identification can be accomplished through the use a mutual TLS certificates with very high bit counts (4096 minimum, for example). Also, perhaps there needs to be Super-Duper-Smart-AI-Powered-Transparent filters which intercept, read and filter content from all sessions; and, which will drop sessions that they cannot keep up with. Yes...there must be self-throttling of agentic AI interactions. True. This will throttle down the speed of AI based and AI focused innovation, but only those parts that are done directly over the Internet. The Internet must be a safe place for the rest of Earch. Totally unthrottled and unbridled AI can be done in isolations laboratories. Any device, organization or state found to NOT be abiding by these regulations will be cut off from the rest of the Internet until a proper investigation is completed and mitigations or changes assured to be implemented. Each infraction thereafter will result in a fine as well. |
Testimonials
NULL at the moment. |
Please email ronald@weist.net to schedule an appointment to talk about your data (or, cyber if you must) security.