Thank you for Subscribing to CIO Applications Weekly Brief
A featured contribution from Leadership Perspectives, a curated forum for enterprise technology leaders, nominated by our subscribers and vetted by the CIOApplications Editorial Board.

Ilmarinen Mutual Pension Insurance Company.
Teijo Peltoniemi, Director, Digital Transformation and Cyber Security
More an Opportunity Than a Risk - But Requires Special Attention from Cyber Security Folks


Let’s not forget that the legal implications are not the only consequences – a firm leaking sensitive personal data while neglecting to fix information security problems is deemed to lose customers and rapidly go bankrupt. This, of course, will have an impact on everyone on the payroll.
The European Commission will complement the cyber security regulatory framework with new legislative acts, including revamped networks and information systems directive, NIS2, and digital operational resilience act, DORA. Artificial intelligence will also receive a dedicated EU regulation, namely EU AI Act. Currently it is in the proposal stage and under review in the member states.
The ethos of the AI Act resembles that of the GDPR. It is regulating AI from the data protection standpoint and complements the GDPR this way.
Why is data protection an important aspect of AI? AI solutions are often based on vast amounts of personal data. This does not only expose risks relating to the proper use of the data but also makes it an attractive target for adversaries. It is likely that AI systems used in sectors such as insurance are considered high-risk, as defined by the AI Act, and hence will require extra measures.
Data breaches are not the only information security risks with AI. There are others more AI specific, including e.g. model poisoning, whereby an AI model is compromised with bad data. A special case is generative AI, such as ChatGPT. Many organizations are keen to utilize these solutions but there are risks, such as those relating to intellectual property rights and information leakages.
Trying to just prevent the use of generative AI leads to shadow use – therefore, a better way may be to allow the use while providing governance and secure environments
I argue many regulated sectors, such as financial services industry, are quite well positioned for tightening cyber regulations. However, the AI Act may require some extra efforts. The information asymmetry between data science teams and management is usually significant and hence adequate governance methods are required.
This is not to say that the utilization of AI should be prevented. AI solutions, such as generative AI, will have a positive impact on productivity and they may even have societal significance. Therefore, I encourage to better understand them and take the appropriate measures to provide those solutions securely and responsibly.

