Podcast: Play in new window | Download (Duration: 11:20 — 15.6MB)
Subscribe: RSS
Summary
This episode, Marc is chattin’ with Ahmad Alokush, a technology risk, AI governance , and cybersecurity oversight expert. Their chat centers on AI governance and why organizations often approach it too narrowly. Ahmad explains that one of the biggest blind spots is treating governance as a one-time compliance exercise instead of a continuous operating discipline. He frames AI governance as an operating system for trust — something that must evolve as AI systems, business use cases, and risks evolve.
A major theme is the hidden cost of AI governance. Ahmad notes that many CFOs underestimate the true investment required, because governance includes not just technical maintenance but also data quality work, regulatory compliance, and change management. His point is that governance is not overhead; it is what makes AI’s ROI sustainable and defensible over time.
The discussion then shifts to the difference between reactive and proactive organizations. Reactive teams tend to address issues only after deployment, often after a problem has already become a crisis. Proactive organizations, by contrast, build risk assessments, bias testing, documentation, and oversight into the process before systems go live. Ahmad emphasizes the importance of visibility into AI usage, including the dangers of “shadow AI” when employees adopt tools outside approved policy.
They also chat about accountability and ownership. Ahmad points out that AI initiatives often span IT, data, HR, compliance, and business teams, which can make ownership unclear. In his view, mature governance requires a clear owner, often supported by a chief AI officer, risk committee, or audit committee, along with a living inventory of AI systems that identifies risk levels and update cadence.
Finally, the chat moves to global regulation and how organizations can manage conflicting rules across jurisdictions. Ahmad describes the need for jurisdiction-specific risk mapping, compliance by design, and deployment variants that can satisfy stricter disclosure or transparency requirements where needed. He closes by encouraging listeners to stay proactive, continuously improve, and treat AI governance as part of the organization’s long-term operating model rather than a box-checking task.
Key Points
- AI governance should be treated as an ongoing discipline, not a one-time project.
- The real cost of AI governance includes technical maintenance, data quality, compliance, and change management.
- Reactive AI programs often lead to shadow AI, poor documentation, and post-deployment crises.
- Clear ownership and a live AI inventory are essential for accountability.
- Global AI regulation requires jurisdiction-specific strategies, not a one-size-fits-all approach.
Key Quotes
- “[T]he biggest [blind spot] that I see is treating the governance like a one-time compliance project instead of like a living operating discipline.
- “[Governance] is not paperwork. It’s an operating system for trust.”
- “AI isn’t overhead. It’s the insurance that keeps ROI real.”
- “Reactive [thinking about AI] is thinking of it as a compliance task. That’s after deployment. ‘We’ll fix it after it breaks.’”
- “You have to have a live AI register with ownership, risk level, and updating the cadence for each model.”
About Our Guest
Ahmad Alokush is a globally recognized expert in AI, cybersecurity, fintech, and technology litigation, and the founder of Ahmadeus Technology Boutique. He advises foreign governments, institutional investors, and C-suite leaders on emerging technologies, M&A strategy, digital asset valuation, and complex regulatory matters, while also serving as a trusted expert witness and keynote speaker for Fortune 500 companies, AmLaw 100 firms, and global policy leaders. Known for bridging technical, legal, and business perspectives, Ahmad brings clarity, discretion, and strategic insight to high-stakes engagements in boardrooms, courtrooms, and advisory settings.
Follow Our Guest
About Our Host
National co-chair of the Cyber Center for Excellence, Marc Schein, CIC,CLCS is also a Risk Management Consultant at Marsh McLennan Agency. He assists clients by customizing comprehensive commercial insurance programs that minimize the burden of financial loss through cost effective transfer of risk. By conducting a Total Cost of Risk (TCoR) assessment, he can determine any gaps in coverage. As part of an effective risk management insurance team, Marc collaborates with senior risk consultants, certified insurance counselors, and expert underwriters to examine the adequacy of existing client programs and develop customized solutions to transfer risk, improve coverage and minimize premiums.
Follow Our Host
