# AI Security for Leaders: Executive Summary

## Three Key Risks

1. **Data Exposure** - 43% of employees have pasted company data into AI tools; free-tier users are the product, not the customer
2. **Regulatory Liability** - EU AI Act fines up to 7% of global revenue; SEC requires AI risk disclosure and board oversight
3. **Shadow AI** - Employees using unvetted AI tools create invisible attack surface across your entire supply chain

---

## Five Vendor Questions (Ask Before You Sign)

1. Do you train on customer data?
2. Where does my data reside?
3. Who can access my prompts and outputs?
4. What security certifications do you hold?
5. What happens if there's a breach?

---

## The Block/Gate/Allow Framework

```
+------------------+------------------+------------------+
|      BLOCK       |       GATE       |      ALLOW       |
+------------------+------------------+------------------+
| No exceptions    | Guardrails req'd | Go fast          |
| Restricted data  | Confidential     | Public/Internal  |
| Unvetted tools   | Human review     | Light monitoring |
| Personal AI acct | Audit trail      | Annual training  |
+------------------+------------------+------------------+
       ^                  ^                  ^
   PROHIBIT            CONTROL            ENABLE
   (DLP/Network)      (Logging)         (Innovate)
```

**Principle:** Default to GATE, not ALLOW. Move categories based on evidence.

---

## Monday Morning CISO Question

> "Can you show me -- right now -- every AI tool our employees used last month and what data they put into it?"

- **If yes:** You have visibility. Optimize.
- **If no:** You've found your first priority.
- **If "we don't track that":** You've found your first investment.

---

## Next Step

Download the full AI Acceptable Use Policy template:  
`/supplementary/ai-acceptable-use-policy-template.docx`

---

*AI Security for Leaders | 20-Minute Executive Training | v1.0*
