Your AI Policy Might Be Putting Your Company at Risk with Courtney Hans
Your AI policy isn’t something you can afford to delay working on, and this episode of Where Trust Meets AI unpacks why. Tune in as host and Drata CEO, Adam Markowitz, welcomes Courtney Hans, Vice President of Cyber Services at ANV for a breakdown of why implementing AI without intentional safeguards is like deploying any new technology without brakes. What You’ll Learn: How to implement "trust but verify" in a remote-first world Why AI implementation without guardrails is a business risk masquerading as efficiency The three critical questions every organization must ask before adopting an AI tool How to position GRC as a revenue driver, not a cost center Why continuous learning is non-negotiable for security professionals in the AI era How to translate technical risk into business impact so executives actually care This episode is a reminder that the “trust but verify” approach looks completely in an AI-powered world; but it must continue to exist, nonetheless. Episode resources: Courtney Hans on LinkedIn: https://www.linkedin.com/in/courtney-hans/ AmTrust Financial Services Website: https://amtrustfinancial.com/ Adam Markowitz on LinkedIn: https://www.linkedin.com/in/markowitzadam Drata Website: https://drata.com/ Highlights: 00:00 Introduction & Meeting Courtney Hans 00:04 How Courtney Went from English Major to Security Leader 02:15 Why You Should Stop Blocking Tools Without Guardrails 08:45 AI Adoption: Three Critical Questions Every Security Leader Must Ask 18:30 AI Automation for Administrative Work & GRC for Offensive Security 24:00 Why Translating Security Risk Into Business Impact is Non-Negotiable 35:15 Build a Career Pyramid, Not a Ladder 45:30 AI is Not Set It and Forget It 52:00 Key Takeaways & Closing Thoughts Quotes: "Trust used to be that we just trusted everyone to have good judgment, which is still true. But I think we're also looking to trust that people have the tools and the education to make the best decisions within their own operational and risk tolerance of their organization context." "People are rushing to use the tool. It's the next big new bright shiny thing, and people feel that if they are not using it, they're being left behind. It's not so different from any other tool that has been introduced into modern day society. It has great purpose, and it can be abused." "You have to be able to translate technical jargon to the average everyday non-tech savvy human user-speak. And then specifically at an executive or a board level, you have to be able to translate risk into business impact." "GRC has historically been the paper pushers or they're the nontechnical folks or that's really like a cost sink. But I absolutely think it's a revenue driver because of the trust question."