Thinkers360
Interested in getting your own thought leader profile? Get Started Today.

Pamela GUPTA

Founder & CEO at Trusted AI™

Easton, United States

Pamela Gupta is the Founder & CEO of Trusted AI and creator of the AI TIPS™ (Trust Integrated Pillars for Sustainability) framework — a comprehensive enterprise AI governance architecture comprising eight pillars, 243 operational controls, Trust Index scoring (0–100), six lifecycle gates, and regulatory crosswalks to the EU AI Act, NIST AI RMF, ISO 42001, and CSA AICM. Originally created in 2019, four years before the NIST AI Risk Management Framework, AI TIPS V2 was published on arXiv in 2025 with a provisional patent filed.
Pamela is the 2025 ISACA Joseph J. Wasserman Award recipient, Thinkers360 Top 50 Women Thought Leaders on AI 2026, and has chaired the GenAI stage at World AI Summit NYC for six consecutive years. She hosts the Trustworthy AI podcast and publishes the Trustworthy AI Briefing newsletter reaching ~4,000 subscribers. She holds CISSP, CISM, and CSSLP certifications.

Available For: Advising, Authoring, Consulting, Influencing, Speaking
Travels From: CT
Speaking Topics: Operationalizing AI Governance: From Policy to Production, Agentic AI Security — Layered Governance for Autonomous Systems, AI TIPS™ Framework: Enterp

Speaking Fee $7,500 (In-Person), $3,500 (Virtual)

Pamela GUPTA Points
Academic 0
Author 628
Influencer 200
Speaker 0
Entrepreneur 0
Total 828

Points based upon Thinkers360 patent-pending algorithm.

Thought Leader Profile

Portfolio Mix

Company Information

Company Type: Company
Business Unit: AI, Cybersecurity Risk Management
Theatre: USA
Minimum Project Size: $5,000+
Average Hourly Rate: $200-$300
Number of Employees: 1-10
Company Founded Date: 2008
Media Experience: 15 years
Last Media Interview: 03/05/2026

Areas of Expertise

Agentic AI 30.13
AGI
AI 32.67
AI Ethics
AI Governance 30.37
AI Orchestration 30.43
Architecture
Autonomous Vehicles
Big Data 30.68
Business Continuity
Business Strategy 30.10
Change Management
Cloud 30.06
Coaching
Cybersecurity 43.31
Digital Transformation
Digital Twins
Emerging Technology
Generative AI 30.04
Innovation 30.06
IoT 30.02
Leadership 30.04
Management
Mergers and Acquisitions 30.15
Privacy 47.67
Quantum Computing
Risk Management 48.41
Security 44.03
Smart Cities
Startups
Supply Chain
Sustainability

Industry Experience

Federal & Public Sector
Financial Services & Banking
Healthcare
High Tech & Electronics
Higher Education & Research
Hospitality
Insurance
Manufacturing
Media
Oil & Gas
Pharmaceuticals
Professional Services
Telecommunications
Travel & Transportation
Utilities

Publications & Experience

431 Article/Blogs
Effective Innovative Trustworthy AI Governance for a New Era
Creating, Deploying Trusted AI
December 30, 2023
Reflecting on 2023, Forging Ahead in 2024: Effective, Innovative AI Governance for a New Era
Wow, what an exciting year for AI! We are witness and participants for significant and unprecedented growth and impact from AI technology. We must get this right!
What are the two sides of the scale? We stand to gain or lose quality of life, our lifestyle, dignity, mental and emotional well-being.

As per The Organization for Economic Cooperation

See publication

Tags: AI, Cybersecurity, Risk Management

The Benefits and Challenges of Building a Remote Workforce for Your Business
Import from wordpress feed
July 10, 2023
While in the past, employees arrived at their offices in person, working from home has become increasingly popular since 2020. But is building a remote workforce a worthy investment for businesses? Like ...

See publication

Tags: AI, Risk Management, Security

A New Chapter in Business Automation with Machine Learning
Import from wordpress feed
July 08, 2023
Think of machines that can learn and adapt to any situation. Thanks to researchers from MIT and Technion, the Israel Institute of Technology, this is now possible. They have created a new ...

See publication

Tags: AI, Risk Management, Security

Chrome Patches to Fix Security Issues
Import from wordpress feed
July 07, 2023
Keeping the technology you use updated is more than just good practice. It is an essential step towards protecting your business. This is precisely the case with the recent Google Chrome 114 ...

See publication

Tags: AI, Risk Management, Security

Changing the Game in Wireless Computing: A New Approach to Faster Processing
Import from wordpress feed
July 06, 2023
Imagine wireless devices functioning together as a team to solve complex problems more quickly. These devices can talk to each other using signals like radio waves, sound, or light without wires. They ...

See publication

Tags: AI, Risk Management, Security

World of AI: Picking the Right Tool
Import from wordpress feed
July 05, 2023
Imagine a tool that aids in selecting the best method to assess your AI models. This is now a reality thanks to a joint effort by MIT and IBM Research. Called saliency ...

See publication

Tags: AI, Risk Management, Security

Anatsa Android Trojan Now Steals Banking Info From Users
Import from wordpress feed
July 04, 2023
Do you know that your handy smartphone could cause harm to your business? A Trojan called Anatsa is causing trouble to banks and business owners. This Anatsa is sneakier and more harmful ...

See publication

Tags: AI, Risk Management, Security

IRecorder App Spying on Users
Import from wordpress feed
July 03, 2023
If you still have iRecorder installed on your smartphone, it is best to delete it immediately. The once-popular app has links to a possible spy campaign and gathers user data. iRecorder Introduced ...

See publication

Tags: AI, Risk Management, Security

Secure Web Applications
Import from wordpress feed
July 01, 2023
More hackers are exploiting sensitive data through web applications and APIs as many companies fail to monitor these vulnerabilities. Unless organizations learn how to defend against website security dangers, they put their ...

See publication

Tags: AI, Risk Management, Security

Google’s New Topic Suggestions for Better Desktop Results
Import from wordpress feed
June 30, 2023
Being easily found online is vital for businesses to grow and do well. With Google’s large user base and strong search functions, this new tool is very important for finding out how ...

See publication

Tags: AI, Risk Management, Security

Scammers Use Government Websites to Advertise Hacking Services
Import from wordpress feed
June 29, 2023
Government websites are seen as sources people can trust. However, threat actors use this trust for their harmful purposes. Scammers recently used official websites to advertise their hacking services. This situation ...

See publication

Tags: AI, Risk Management, Security

Embracing Password Passkeys: Strengthening Business Security in the Password-less Era
Import from wordpress feed
June 02, 2023
Passwords protect our privacy but don’t offer the most convenient experience. Tech giants like Apple, Google, and Microsoft show that there’s a better alternative: passkeys. They are a different form of login ...

See publication

Tags: Privacy, Risk Management, Security

Best Practices To Keep in Mind Against Cybersecurity Threats
Import from wordpress feed
June 01, 2023
As a business owner, you must take every precaution to safeguard your company’s data. Cybersecurity threats can harm your success and the future of your company. Guarding against these risks is essential ...

See publication

Tags: Privacy, Risk Management, Security

Maximizing Business Success with Big Data and Analytics
Import from wordpress feed
May 31, 2023
Companies today can tap into a wealth of data to guide them in making sound choices. That’s why big data and analytics offer great advantages. They help you understand customers, markets, and ...

See publication

Tags: Privacy, Risk Management, Security

Leveraging Technology for Growth: The Advantages of Automating Business Processes
Import from wordpress feed
May 30, 2023
Are you looking to automate your business processes with technology? Your business has many areas you could automate. From analytics to project management, repetitive tasks, and mundane work are the perfect candidates ...

See publication

Tags: Privacy, Risk Management, Security

Creating a Website that Converts: Tips for Improving User Experience
Import from wordpress feed
May 29, 2023
Your website is the first impression your business projects to potential customers. Improving website user experience good user experience is crucial to keep visitors engaged and convert them into customers. A well-designed ...

See publication

Tags: Privacy, Risk Management, Security

Launching a Successful Digital Marketing Campaign
Import from wordpress feed
May 27, 2023
Whether you’re a new business owner or have years of experience, establishing a digital marketing strategy takes knowledge and time.  With these tips, you can launch a successful digital marketing campaign and ...

See publication

Tags: Privacy, Risk Management, Security

Create an Effective Email Marketing Strategy and Boost Customer Engagement
Import from wordpress feed
May 26, 2023
Do you want to convert email subscribers to loyal customers? Focus on increasing customer engagement through your emails.  An email list is one of the strongest tools in your marketing strategy. So ...

See publication

Tags: Privacy, Risk Management, Security

Cloud Computing for Small Businesses
Import from wordpress feed
May 25, 2023
If you’re not harnessing the power of cloud computing for small businesses, it’s time to start! Cloud technology provides internet-based services using apps, storage, and processing. It’s usually available “a la ...

See publication

Tags: Privacy, Risk Management, Security

Understanding SEO: A Beginner’s Guide to Search Engine Optimization
Import from wordpress feed
May 24, 2023
Search engine optimization (SEO) ensures your website and content appear early in search engine rankings. When a person uses a search engine, your relevant content should be among the first they find ...

See publication

Tags: Privacy, Risk Management, Security

Protect Your Business from Cyber Attacks: Common Cybersecurity Mistakes
Import from wordpress feed
May 23, 2023
Cybersecurity mistakes can cost your business a fortune and ruin customer trust. While experts expect cyber attacks to double in the next two years, more than half of small businesses have yet ...

See publication

Tags: Privacy, Risk Management, Security

Maximize Your Business Potential with a Social Media Marketing Strategy
Import from wordpress feed
May 19, 2023
Creating a social media marketing strategy for your business means maximizing business potential. If you’re using social media platforms without a strategy, you’re missing a big opportunity for growth.  Why You Need ...

See publication

Tags: Privacy, Risk Management, Security

Why Content Marketing Is the Future of Advertising
Import from wordpress feed
May 18, 2023
Televisions, billboards, and the internet bombard people with advertisements and marketing ploys. This development has led to over 65 million people using ad-blockers to reduce interruptions in their interests. Those who aren’t ...

See publication

Tags: Privacy, Risk Management, Security

Using Big Data Analytics to Improve Business Operations
Import from wordpress feed
May 17, 2023
Analyzing collected information can uncover nuances about your target market that can be hard to catch with human intuition alone. For example, you can discover correlations between events and an uptick in market activity through data evaluations. This method can ...

See publication

Tags: Privacy, Risk Management, Security

Enhance Your Marketing Strategy with AI and Machine Learning
Import from wordpress feed
May 16, 2023
You’ve likely seen a chat window appear on a web page indicating someone is available to help. That available assistant is often an AI the business has adapted to customer engagement with ...

See publication

Tags: Privacy, Risk Management, Security

21 Author Newsletters
AI TIPS is now Integrated into OWASP's Top 10 Agentic AI Risks - What that means for your Business
Linkedin
April 08, 2026
This week I published a three-part series here on LinkedIn tracing a single argument: agentic AI is expanding the enterprise attack surface, the real vulnerabilities are in exposed infrastructure — not models — and the solution is layered security and governance.

See publication

Tags: Agentic AI, Cybersecurity, Risk Management

Are We Prepared for Catastrophic AI Cybersecurity Lapses?
Linkedin
April 01, 2026
Last week, a misconfigured content management system exposed nearly 3,000 internal documents from one of the world's leading AI companies. Among them: a draft blog post describing what may be the most powerful AI model ever built, one its own creators say poses unprecedented cybersecurity risks.

See publication

Tags: AI, Cybersecurity, Risk Management

Agentic AI Has a Security and Trust Problem
Linkedln
March 18, 2026
This week I published a three-part series here on LinkedIn tracing a single argument: agentic AI is expanding the enterprise attack surface, the real vulnerabilities are in exposed infrastructure — not models — and the solution is layered security and governance.

See publication

Tags: Cybersecurity, Risk Management, Security

Supply Chain at the Speed of AI Governance
Linkedin
March 11, 2026
Most conversations about AI governance happen in boardrooms, regulatory filings, and policy documents.

See publication

Tags: Cybersecurity, Risk Management, Security

March 16 Changes Everything About Your AI Compliance Program
Linkedin
March 04, 2026
While your teams race to deploy AI, the regulatory ground is about to shift underneath them. Four things happen simultaneously on or around March 11–16 under Trump's December AI Executive Order — and most C-suites aren't tracking any of them.

See publication

Tags: Cybersecurity, Risk Management

AI Is Now a Weapon — And a Target. Here's What Changed This Month.
Linkedin
February 25, 2026
Two major intelligence disclosures in the past two weeks should be on every board's agenda.

See publication

Tags: Cybersecurity, Risk Management, Security

Trustworthy AI TIPS 2.0 — executive governance model
Linkedin
February 15, 2026
AI governance has matured quickly. Standards like ISO/IEC 42001 and NIST's AI Risk Management Framework have brought much-needed structure, common language, and legitimacy.

See publication

Tags: Cybersecurity, Risk Management, Security

AI Governance 2026: Your Q1 Briefing on What Just Changed
Linkedin
February 02, 2026
Welcome to this edition of my newsletter. I’m doing something a little different this time—a focused briefing to kick off 2026, because a lot has happened in the last 60 days that every AI leader needs to understand.

See publication

Tags: Cybersecurity, Risk Management, Security

AI TIPS 2.0: Closing the Gaps That Keep AI Governance from Working
Linkedin
December 19, 2025
AI governance frameworks have matured significantly over the last few years. Standards such as ISO/IEC 42001 and NIST’s AI Risk Management Framework have brought much-needed structure, common language, and legitimacy to the field.

See publication

Tags: Cybersecurity, Risk Management, Security

The Wake-Up Call: Agentic AI Risks that can impact your Company
Linkedln
October 21, 2025
In 2025, security researchers discovered something that should concern every organization using AI agents: ForcedLeak, a critical vulnerability (CVSS 9.4) that affected Salesforce Agentforce and exposed a fundamental flaw in how we think about AI security.

See publication

Tags: Cybersecurity, Risk Management, Security

Enterprise Agentic AI Governance & Security – The Why & How
Linkedln
September 19, 2025
These aren’t just LLMs that answer questions. We’re talking about autonomous systems that plan, act, adapt, and execute — across entire business functions, toolchains, and environments. From customer service to finance ops, these agents are making decisions and using tools without human initiation.

See publication

Tags: Cybersecurity, Risk Management, Security

Avoid Lawsuits Before They Start: How Responsible AI Governance Safeguards Healthcare
Linkedln
August 29, 2025
AI offers remarkable opportunities for healthcare—from enhancing diagnostics to optimizing care. But when poorly governed, it can result in devastating outcomes: eroded trust, compromised patient care, and even costly lawsuits.

See publication

Tags: Cybersecurity, Risk Management, Security

Leading with Integrity in AI: A Milestone Moment in My Journey for Trustworthy AI
linkedin
June 12, 2025
I'm excited to share a personal and professional milestone with you — I’ve been named the 2025 recipient of the Joseph J. Wasserman Award by the ISACA New York Metropolitan Chapter.

See publication

Tags: Cybersecurity, Risk Management, Security

De-Risking business adoption of AI Agents
Linkedln
January 30, 2025
In this edition, I will cover what makes AI agents capable of transformative potential across various sectors, and their ability to automate complex tasks, enhance customer experiences, and drive significant efficiency gains.

See publication

Tags: Cybersecurity, Risk Management, Security

Trustworthy AI's role in revolutionizing Healthcare
LinkedIn
June 21, 2024
Happy Friday and a special thank you for attending our #Trustworthy Healthcare AI LinkedIn Live session this Tuesday, June 18th - we got excellent feedback and appreciate it was so helpful to the attendees.

See publication

Tags: Cybersecurity, Risk Management, Security

Helping Businesses gain AI value and Compliance with Trustworthy AI
Linkedln
April 26, 2024
Harvard Business Review showed data indicating only 17% of firms have advanced their AI maturity enough to achieve superior growth and business transformation. The “AI Achievers” meanwhile enjoyed 50% greater revenue growth on average, compared with their peers.

See publication

Tags: Cybersecurity, Risk Management, Security

Without Securing AI, there is no Trustworthy AI
LinkedIn
April 11, 2024
Vulnerabilities in AI systems that can be exploited to compromise organizations. These vulnerabilities include the risk of influencing AI learning through data poisoning or altering models to serve malicious purposes. Beyond data-related vulnerabilities, AI systems may also suffer from traditional run-time software errors, which could allow attackers to hijack local computers and infiltrate broader business networks. The potential damage from such AI system breaches is vast, affecting everything from critical infrastructure to human life, and could influence human decision-making and democratic processes, as well as sector and business governance.

See publication

Tags: Cybersecurity, Risk Management, Security

Effective Innovative Trustworthy AI Governance for a New Era
LinkedIn
December 30, 2023
Reflecting on 2023, Forging Ahead in 2024: Effective, Innovative AI Governance for a New Era

See publication

Tags: Cybersecurity, Risk Management, Security

Trustworthy AI : help De-Risk adoption of AI
Creating, Deploying Trusted AI
November 26, 2023
Trusted AI Founder, Pamela Gupta’s Message: As AI continues to revolutionize industries, the imperative for trustworthy AI has become paramount. This edition of our newsletter introduces our new podcast series, "Trustworthy AI: De-risk Business Adoption of AI," focusing on how businesses can adopt AI responsibly and safely. We'll explore themes of AI Risk Management and Governance.

See publication

Tags: Cybersecurity, Risk Management, Security

Global Race for AI Supremacy : Role of AI Regulations in creating Trustworthy AI
Harnessing AI power
July 30, 2023
Is data the new oil or is knowledge that comes from it? Just like oil, raw data isn’t valuable in and of itself; When properly refined, data quickly becomes a decision-making tool, providing insightful information.

See publication

Tags: Cybersecurity, Risk Management, Security

Essential Pillars of Trustworthy AI: Building Trustworthy NLP Workshops
Creating, Deploying Trusted AI
May 28, 2022
NLP foundation models hold potential impact on every part of the economy and yet there are no established risk identification or mitigation frameworks that are accessible to the teams building or deploying these massively impactful systems.

See publication

Tags: AI, Cybersecurity, Risk Management

1 Media Interview
WiCyS Trusted AI Inaugural Event with Colonel Barnes, Chief Ethicist US Army.
Youtube
March 12, 2021
We are Action Focused Professionals, Volunteers with technology, security, Privacy, Governance, Engineering, Risk professionals background.

Advancing Trust in AI Vision:
Identifying and raising awareness on building AY systems with Security & Privacy
Helping to build ethics and trust in AI
Using AI Responsibly.

Follow us on Social Media
https://twitter.com/AdvTrustinAI
https://www.linkedin.com/company/advancingtrustinai/?viewAsMember=true

Who is on the team:
Pamela Gupta https://www.linkedin.com/in/pamelagupta/
Karen Jensen https://www.linkedin.com/in/technology-solutions-for-life/
Dr. Malek Ben Salem https://www.linkedin.com/in/malek-ben-salem/
Dr. Madiha Jafri https://www.linkedin.com/in/dr-madiha-jafri-5098461a/
Dr. Yousra Javed https://www.linkedin.com/in/yousra-javed-26184856/
Shafia Zubair https://www.linkedin.com/in/shafiazubair/
Divya Dwivedi https://www.linkedin.com/in/divyadwivedi04/
Ambassadors
Dean Skidmore https://www.linkedin.com/in/deskidmore/
William Fehrer https://www.linkedin.com/in/william-feher-cpa

See publication

Tags: AI, Cybersecurity, Risk Management, Business Strategy

55 Podcasts
When AI Runs Your Supply Chain: Governance at the Speed of Commerce
Truste Dai
March 11, 2026
What happens when AI makes thousands of real-time decisions about inventory, fulfillment, and pricing across a $300M+ operation — and one of them goes wrong?

See publication

Tags: Cybersecurity, Leadership

AI Governance Isn't Optional Anymore —What ISO 42001 Auditors Look For
Import from youtube.com
February 25, 2026

See publication

Tags: AI, Cybersecurity, Risk Management

AI Security Threats Your Team Isn't Ready For | MITRE ATLAS Lead Walker Dimon
Import from youtube.com
February 03, 2026

See publication

Tags: AI, Cybersecurity, Risk Management

AI Governance 2026: What Leaders Need to Know Now
Import from youtube.com
February 01, 2026

See publication

Tags: AI, Cybersecurity, Risk Management

AI Governance for AI Value
Import from youtube.com
December 12, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

Weaponized AI Agents : Business Impact
Import from youtube.com
October 21, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

"Securing our Future" Securing Generative AI
Import from youtube.com
October 15, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

Enterprise Agentic AI Governance & Security
Import from youtube.com
September 22, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

AI Change Management for sustainable AI Transformation
Import from youtube.com
September 11, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

Operationalizing Responsible AI in Healthcare: Lessons from Duke Health
Import from youtube.com
September 01, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

Creating Safe Secure trustworthy AI Agents: Vulnerability Management
Import from youtube.com
July 28, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

Call to Action for Global AI Governance & Trustworthy AI
Import from youtube.com
July 12, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

Wasserman Award for AI Risk & Governance recipient Pamela Gupta
Import from youtube.com
July 03, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

TrustedAI Live Stream
Import from youtube.com
May 19, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

Trustworthy AI: De-Risk 3rd Party AI Risks
Import from youtube.com
April 10, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

Safe Secure Trusted Agentic AI: Socioeconomic Risks
Import from youtube.com
February 16, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

Safe Secure Trusted AI Agents - Building and Deploying Overview
Import from youtube.com
February 16, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

Safe Secure Trusted AI Agents Building and Deploying
Import from youtube.com
February 03, 2025

See publication

Tags: AI, Cybersecurity, Risk Management

Preparing Business for Generative AI Success
Import from youtube.com
November 06, 2024

See publication

Tags: AI, Cybersecurity, Risk Management

Happy Diwali from Trusted AI
Import from youtube.com
November 01, 2024

See publication

Tags: AI, Cybersecurity, Risk Management

AI Trust Management
Import from youtube.com
October 04, 2024

See publication

Tags: AI, Cybersecurity, Risk Management

Generative AI Security
Import from youtube.com
September 10, 2024

See publication

Tags: AI, Cybersecurity, Risk Management

Trustworthy AI Venture Capitalists Imperative
Import from youtube.com
August 11, 2024

See publication

Tags: AI, Cybersecurity, Risk Management

Healthcare Trustworthy AI: De-risk adoption of AI
Import from youtube.com
May 19, 2024

See publication

Tags: AI, Cybersecurity, Risk Management

De-Risking AI in Biotechnology with Trustworthy AI
Import from youtube.com
May 06, 2024

See publication

Tags: AI, Cybersecurity, Risk Management

2 Videos
Essential Pillars of Trustworthy AI : Pillar #2 Privacy. Pamela Gupta interviews Debbie Reynolds.
OutSecure
August 17, 2022
AI can be used to provide new goods and services, boost productivity, enhance competitiveness for organizations at unprecedented scale and value.

In order to achieve these outcomes it its essential we build and deploy AI systems with Transparency, Integrity, Privacy and Security.
We have launched a series on Essential Pillars of Trustworthy AI.
What can you expect?
Panel discussions and interviews with global leaders on building blocks for each pillar;
Actions for building and implementing AI systems with these pillars;
Newsletters;
Workshops;
Summits;
In this session on the second essential pillar of Privacy, global Privacy expert Debbie Reynolds and Trustworthy AI framework creator Pamela Gupta discuss what makes Privacy an essential pillar.
Join us and let us know your thoughts and questions.

See publication

Tags: AI, Privacy, Security

This Malware Phishing Campaign Hijacks Email Conversations
Import from wordpress feed
March 28, 2022
Hackers have been using social engineering tricks to get their malicious code onto the systems of unsuspecting victims. This has been happening for almost as long as the internet has been around. ...

See publication

Tags: Cybersecurity, Privacy, Security

1 Webinar
NEACS AI
Youtube
November 05, 2021
Key Challenges for Security Leaders Now and Beyond - Not Just Technical Competence
The purpose of cybersecurity is to use reasonable means to keep important technologies and data secure. Achieving this requires a structured approach and a positive cybersecurity culture that includes not just the IT team but everyone in the organization. What are the critical factors for cybersecurity success? What are the key challenges for security leaders now and beyond?

See publication

Tags: AI, Cybersecurity, Risk Management

Thinkers360 Certifications

7 Certifications

Thinkers360 Credentials

9 Badges

Radar

Blog

2 Article/Blogs
AI Jumped to #2 Global Business Risk in One Year — Here's What That Means for Governance, Insurance, and Your Board
Thinkers360
March 25, 2026

This week, four separate developments converged to underscore a reality that boards, business teams, CISOs, CROs, and General Counsel can no longer defer: AI governance has crossed from a compliance aspiration to a business survival imperative.

  1. AI Risk at the Board Level: The Allianz Signal

The Allianz Risk Barometer is the gold standard of enterprise risk perception. Published annually by the world's largest insurer, it reflects how the organizations actually absorbing and pricing risk view the landscape.

In the 2026 edition, AI surged from the #10 position to #2 — the single largest jump of any risk in the survey's 15-year history. Cyber incidents remain #1 for the fifth consecutive year, with their highest-ever score at 42% of responses. But AI is now a top-three concern for firms of all sizes — large, mid-sized, and small — across every geographic region.

What makes this signal particularly significant is the source. Allianz is not a technology vendor or an analyst firm selling governance solutions. They are the entity underwriting the risk with real capital. When they elevate AI to this position, it foreshadows underwriting changes: tighter terms, broader exclusions, and more rigorous disclosure requirements for policyholders.

The data also reveals a readiness gap. Only one-third of respondents indicated they have prioritized robust governance frameworks for managing AI's ethical and operational dimensions. That means two-thirds of organizations are exposed — and increasingly, their insurers know it.

  1. Insurance Coverage Gaps Are Widening

If the Allianz Barometer provides the macro signal, a legal analysis published this month by Gallagher & Kennedy attorney Karin Aldama maps the downstream consequences at the policy level.

Aldama identifies seven specific areas where AI is creating insurance coverage uncertainty for businesses in 2026. Among the most consequential:

Disclosure and rescission risk. Insurers are now requiring detailed disclosures about AI usage — including tasks performed, autonomy levels, and the extent of human oversight. Organizations that provide incomplete disclosures face the prospect of policy rescission, potentially even after a loss has been suffered and a claim filed.

Classification determines coverage. How a business internally classifies its AI — as a support tool versus an autonomous operational decision-maker — directly affects which insurance policies trigger. E&O, D&O, and CGL policies each carry different definitions of covered actions, and courts will increasingly need to determine whether AI-caused losses constitute professional services errors, management decisions, or operational failures.

AI-specific exclusions are proliferating. Insurers are introducing exclusions and sublimits for risks ranging from unsupervised autonomous decision-making to social engineering attacks initiated by AI systems. Ambiguities in existing policy language are generating disputes over whether AI errors qualify as "errors," "occurrences," or excluded business risks.

Some AI-related risks may be uninsurable. Businesses may face the reality that certain AI exposures require acceptance of higher self-insured retentions, captive structures, or simply unaddressed gaps in coverage.

The connection between these two stories is direct: what Allianz signals at the macro level, Aldama describes at the operational level. Organizations that cannot demonstrate governance maturity will face tangible consequences when they seek coverage — or when they file claims.

  1. Deepfake Medical Imagery: A Concrete Threat to Claims Integrity

Theory became tangible this week with a study published in Radiology and covered by Nature.

Researchers presented 17 radiologists from 12 research centers with a mix of real and AI-generated medical X-rays. The findings were striking. Without being informed that synthetic images were present, only 41% of radiologists raised concerns about possible AI infiltration. When explicitly told that some images were AI-generated and asked to identify them, participants achieved only 75% accuracy on average — and experience level made no difference. Radiologists with zero years and 40 years of practice performed comparably.

AI detection tools — including large language models such as ChatGPT and Gemini — fared no better, achieving only 57–85% accuracy.

Image-integrity specialist Elisabeth Bik warned that the implications extend well beyond research, encompassing insurance claims processing and legal proceedings where imaging evidence is used.

The business implications are immediate. Consider scenarios where AI-generated medical images are submitted to support workers' compensation claims, personal injury litigation, or disability filings. If trained radiologists cannot reliably distinguish synthetic from real imagery, claims adjusters — who are not radiologists — face an even steeper challenge. This represents a near-term fraud vector that existing insurance policy language does not contemplate, and for which exclusion frameworks do not yet exist.

  1. Agentic AI Is Deploying Faster Than Organizations Can Govern

Forrester's analysis of HIMSS26, published this week by Senior Analyst Shannon Germain Farraher, completes the picture by documenting what is happening operationally on the ground.

The healthcare industry — one of the most heavily regulated sectors — has moved past AI enthusiasm into what Forrester describes as an operational reckoning. At HIMSS26, the dominant conversation was no longer about AI's potential but about what is actually scalable, governable, and sustainable.

Agentic AI dominated the conference narrative. Revenue cycle platforms are now deploying autonomous agents that manage denial appeals, clinical coding, and financial operations with limited human intervention. These systems are being positioned not as features but as operating models.

Yet governance emerged as the primary scaling constraint. Sessions repeatedly surfaced concerns around accountability, AI decision-making transparency, non-human identity management, and post-deployment monitoring. The consistent observation: organizations are deploying AI in live clinical and financial settings faster than they can validate, monitor, or explain what those systems are doing.

Vendor accountability proved equally problematic. Healthcare organizations expressed frustration that vendor security assurances frequently stop at compliance checklists, while the organizations themselves demand contractual accountability, auditability, and enforcement mechanisms that few vendors can articulate.

Forrester's conclusion is direct: execution capability — not AI ambition — is now the competitive differentiator. Operational maturity matters more than technological sophistication.

The Convergence: What Leaders Must Do Now

These four stories are not isolated. They form a connected system:

The global risk community has quantified the threat (Allianz). The insurance and legal infrastructure is responding with tighter requirements and broader gaps (Gallagher & Kennedy). The threat vectors are concrete and measurable — deepfake imagery that defeats expert detection a quarter of the time (Nature/Radiology). And the operational reality is that governance has become the binding constraint on AI deployment (Forrester).

The question for every CISO, CRO, General Counsel, and board director is no longer whether AI governance is necessary. It is whether your organization can define what controls should be in place, prove those controls are operating, and certify the results to regulators, insurers, and stakeholders.

Organizations that can answer yes will be insurable, defensible, and competitive. Those that cannot will face coverage gaps, regulatory exposure, and operational fragility as agentic AI systems scale beyond their ability to govern them.

This is exactly the challenge the AI TIPS™ framework was designed to address — not as an afterthought, but as an integrated governance architecture with 243 controls, lifecycle gates, regulatory crosswalks, and a Trust Index that gives organizations a measurable, provable governance posture.

The window for treating AI governance as optional is closing. This week's developments make that clear.

Pamela Gupta is the Founder and CEO of Trusted AI, creator of the AI TIPS™ (Trust Integrated Pillars for Sustainability) framework, and recipient of the 2025 ISACA Joseph J. Wasserman Award. She chairs the GenAI Stage at World AI Summit NYC and holds CISSP, CISM, and CSSLP certifications.

Take the AI TIPS Maturity Assessment at trustedai.ai/assessment

See blog

Tags: Agentic AI, AI Governance, Risk Management

Agentic AI Has a Security and Trust Problem. Here's the Three-Layer Answer.
Thinkers360
March 17, 2026

The data landing this quarter should alarm any security or AI leader.

88% of organizations reported a confirmed or suspected AI agent security incident in the past year. In healthcare, that number climbs to 93%. Yet 82% of executives believe their existing policies protect them from unauthorized agent actions — while only 21% have actual visibility into what their agents access, which tools they call, or what data they touch.

This is not a future risk. It is a present crisis.

The CrowdStrike 2026 Global Threat Report documents an 89% increase in AI-enabled attacks year-over-year. The IBM 2026 X-Force Threat Intelligence Index shows a 44% increase in attacks exploiting public-facing applications, driven by missing authentication controls and AI-enabled vulnerability discovery. Flashpoint's 2026 Global Threat Intelligence Report captured a 1,500% surge in AI-related illicit discussions between November and December 2025 — signaling a rapid shift from experimentation to operationalized malicious agentic frameworks.

The pattern is clear: attackers are not building new playbooks. They are accelerating existing ones with AI — and agentic systems are both the weapon and the target.

Three Incidents That Tell the Story

First, researchers at security startup CodeWall reported that their AI agent gained full read-write access to McKinsey's internal AI platform Lilli — used by over 40,000 employees — in just two hours. The attack exploited exposed APIs, not the model itself.

Second, a mid-market manufacturing company deployed an agent-based procurement system. Attackers compromised the vendor-validation agent through a supply chain attack. The agent began approving orders from attacker-controlled shell companies. The company lost $3.2 million before detecting the fraud. Root cause: a single compromised agent cascaded false approvals across the entire multi-agent system.

Third, following the February 2026 military escalation, over 60 Iranian-aligned cyber groups mobilized within hours. Check Point Research, Palo Alto Unit 42, and CloudSEK all documented AI-assisted reconnaissance targeting U.S. critical infrastructure. The convergence of AI and geopolitical conflict is no longer theoretical.

The common thread across all three: the failure point was never the model. It was the ecosystem around it — the APIs, tool integrations, agent-to-agent trust relationships, identity controls, and governance gaps.

The Three-Layer Answer

If the attack surface spans the entire AI ecosystem, security and governance must be layered across it.

Layer 1 — Threat Modeling (OWASP MAESTRO): Provides structured threat modeling for AI pipelines, tools, and orchestration layers. Identifies where vulnerabilities exist across the agentic architecture, from prompt injection to tool call hijacking to memory poisoning.

Layer 2 — Adversarial Intelligence (MITRE ATLAS): Maps attacker tactics, techniques, and procedures targeting AI systems. Translates the intelligence community's threat mapping approach into the AI domain.

Layer 3 — Enterprise Governance (AI TIPS): Provides enterprise-wide oversight across eight governance pillars — Cybersecurity, Privacy, Ethics and Bias, Transparency, Explainability, Governance, Audit, and Accountability. Delivers Trust Index scoring, lifecycle gates, and regulatory crosswalks that connect security findings to business risk decisions.

Without this governance layer, threat modeling and adversarial intelligence produce findings but no accountability.

What Leaders Should Do This Week

Audit your agent permissions — map every tool call, API connection, and data source your agents touch. Implement human-in-the-loop checkpoints for any agent action with financial, operational, or security impact. Classify agent actions by risk tier. Run a tabletop exercise for agent compromise. And assess your governance posture across all eight pillars to identify where your highest exposure sits.

The question is no longer whether the model is secure. The question is whether the entire AI ecosystem is governed.

 

See blog

Tags: Agentic AI, AI Governance, AI Orchestration

Opportunities

2 IT Consultings
AI Risk Ethics Cybersecurity leader

Location: virtual    Fees: 200/hour

Service Type: Service Offered

Pamela Gupta is a widely respected global strategist and leader in governance and cyber technologies with a record of creating unprecedented risk mitigation initiatives for Global Fortune 500 companies. She is a successful Technologist and Governance leader.
She is a leading voice in Security & Privacy and Trusted AI. In Q4 2020, she was asked by the global non-for profit, Women in Cybersecurity (WiCyS), to launch a Global WiCyS Trusted AI initiative to tackle a critical and extraordinarily complex problem - build Trust in AI.
Furthermore, Pamela has published a revolutionary risk based holistic AI governance framework, an Artificial Intelligence Transparency, Integrity, Privacy & Security, AI TIPS Model©. Pamela regularly publishes and presents at global industry events. She has an undergraduate degree in Psychology and a master’s in computer science and AI.

Respond to this opportunity

AI Risk Ethics Cybersecurity leader

Location: virtual    Fees: 200/hour

Service Type: Service Offered

Pamela Gupta is a widely respected global strategist and leader in governance and cyber technologies with a record of creating unprecedented risk mitigation initiatives for Global Fortune 500 companies. She is a successful Technologist and Governance leader.
She is a leading voice in Security & Privacy and Trusted AI. In Q4 2020, she was asked by the global non-for profit, Women in Cybersecurity (WiCyS), to launch a Global WiCyS Trusted AI initiative to tackle a critical and extraordinarily complex problem - build Trust in AI.
Furthermore, Pamela has published a revolutionary risk based holistic AI governance framework, an Artificial Intelligence Transparency, Integrity, Privacy & Security, AI TIPS Model©. Pamela regularly publishes and presents at global industry events. She has an undergraduate degree in Psychology and a master’s in computer science and AI.

Respond to this opportunity

Events

Contact Pamela GUPTA

Book Pamela GUPTA for Speaking

Book a Video Meeting

Media Kit

Share Profile

Contact Info

  Profile

Pamela GUPTA


Latest Activity

Latest Opportunities

Latest Member Blogs

Search
How do I climb the Thinkers360 thought leadership leaderboards?
What enterprise services are offered by Thinkers360?
How can I run a B2B Influencer Marketing campaign on Thinkers360?