Panel - The Rise of AI Security: Defending Against AI-Powered Threats
Maria Koskinen, Markku Korkiakoski, Oona Matinpalo
The EU AI Act, a pioneering regulatory framework, categorizes AI systems by risk, integrating with GDPR and cybersecurity directives for comprehensive governance. The challenge lies in ensuring regulations remain future-proof and responsive. Organizations must shift from compliance to embedding AI governance strategically, recognizing it as a competitive asset. The rise of AI-generated misinformation and cyber threats necessitates a balance between individual skepticism and organizational transparency. Effective AI governance hinges on accountability, cross-functional collaboration, and understanding risk appetites.
"AI governance is like the base of the house. If your base is not right, then the house will not stand tall. When you do things proactively in the right way, you build strong eminence and good brand towards your customers and stakeholders."
Summary
- The EU AI Act is a significant regulatory framework that uses a risk-based approach to regulate AI, ensuring it remains future-proof with instruments to update prohibitive practices and high-risk systems. - A wider regulatory framework, including GDPR, cybersecurity directives, and liability frameworks, creates a comprehensive web for AI governance in the EU. - Organizations need to move from regulatory compliance to operational security culture, embedding AI governance as a strategic asset for resilience and competitive advantage. - AI-generated misinformation and disinformation pose significant threats, requiring a combination of individual skepticism and technological solutions. - Accountability and diverse teams are crucial for effective AI governance, with roles and responsibilities clearly defined to manage risks and foster innovation.
Article
AI security experts warn of "regulatory tsunami" as EU leads global governance efforts
Helsinki panel explores the balance between innovation and protection in the face of growing AI threats
At the VERGE conference in Helsinki, a panel of leading experts gathered to dissect what they described as an impending "regulatory tsunami" surrounding artificial intelligence security and governance. The panel, featuring Maria Koskinen, Markku Korkiakoski, and Oona Matinpalo, offered a sobering assessment of both the European regulatory landscape and the evolving threat vectors posed by increasingly sophisticated AI systems.
As organisations worldwide rush to adopt generative AI technologies, the gap between implementation and governance continues to widen, creating what panelists described as a dangerous security vacuum.
The EU's pioneering regulatory framework
Maria Koskinen, AI Policy Manager at Stateot, provided a comprehensive overview of the EU's approach to AI regulation, which she described as "a significant milestone" in global governance.
"The AI Act takes a risk-based approach, regulating systems based on their potential impact on health, safety, and fundamental rights," Koskinen explained. She outlined the four-tier system that categorises AI applications from prohibited practices to those requiring varying levels of oversight.
Koskinen also highlighted the interconnected nature of EU regulations, describing a "regulatory web" that includes GDPR, the Network and Infrastructure Security Directive, the Cyber Resilience Act, and the Product Liability Directive.
"These instruments reference each other, work together, and create a comprehensive framework for AI governance in the EU," she noted, while emphasising the built-in mechanisms designed to keep regulations future-proof as technology evolves.
Beyond the checkbox: embedding governance into operations
A central theme of the discussion was the challenge of translating regulatory requirements into meaningful operational changes. Markku Korkiakoski, CEO of Silverskin Information Security, expressed skepticism about implementation.
"If it's only regulation that creates more burden for companies, then what's the benefit?" Korkiakoski questioned. "We just put more money into development without seeing strict benefits."
This prompted a spirited response from Oona Matinpalo, data privacy lead at Deloitte Finland, who argued for the necessity of diverse teams to translate regulatory requirements into practical business processes.
"With the upcoming regulation, we at Deloitte talk a lot about a regulatory tsunami," Matinpalo said. "You need people that translate the regulatory requirements into business processes that actually work. It should be an embedded way of working rather than a checkbox."
Strategic advantage, not just compliance
The panel explored how forward-thinking organisations are positioning AI governance not merely as a compliance exercise but as a strategic advantage. Matinpalo offered a compelling metaphor:
"AI systems and functionalities are like the bricks that you build on top of the base of the house. And if your base is not right, the house will not stand tall," she explained. "AI governance links to competitive advantage because doing things proactively and ethically builds strong eminence and brand towards customers and stakeholders."
Koskinen provided practical guidance, recommending that organisations begin by creating "an AI inventory listing all AI use cases and systems used in your organisation." This transparency, she argued, allows companies to understand their risk profile and direct appropriate governance measures.
The misinformation threat landscape
When discussing the most pressing AI-powered threats, Korkiakoski highlighted misinformation and disinformation as particularly concerning vulnerabilities that "can't be fully handled technically."
"We can't spot the difference in fakes, and even if we can, fake news spreads," he warned, pointing to the difficulty of containing AI-generated false narratives once they enter the information ecosystem.
The panel debated whether individuals should bear the responsibility of being the last line of defence against sophisticated AI-generated content. Matinpalo observed a troubling trend: "We need to understand that criminals are many times sort of far ahead of us, the ones protecting our society, our data and so forth."
Koskinen advocated for a balanced approach: "A little skepticism is healthy. Source criticism is taught in schools here, and this should be adapted for the AI age."
Accountability as the guiding principle
As the discussion concluded, the panelists offered their guiding principles for the future of AI security. Koskinen emphasised "roles and responsibilities, accountability," while Korkiakoski advised organisations to "understand your threats and risks, your risk appetite, and be comfortable with it."
Matinpalo reinforced the need for diverse expertise, recommending "an AI office with diverse teams managing risks together. Solving challenges requires people with diverse backgrounds because it's a complex field."
The panel at VERGE highlighted that as AI capabilities accelerate, the true challenge lies not just in regulatory compliance but in fostering a culture of responsible governance that balances innovation with protection. As Europe leads the charge in AI regulation, organisations worldwide are watching closely to see how these frameworks will shape the global approach to AI security in the years ahead.
Part of VERGE | The AI Frontier: Creativity, Security & Collaboration