In this Session at GISEC Global 2026, Dubai Exhibition Centre (DEC), Expo City, our Founder & CEO, Mr. Anirban Mukherji, discussed the importance of balancing AI innovation, data sovereignty, privacy, and national security in the era of frontier Large Language Models.
AI governance in healthcare has become a question boards and auditors ask directly. They want to know which AI tools reach protected health information, who's accountable for each one, and what evidence shows the controls are holding. Most health systems have a written policy and no way to produce those three answers on request, which is precisely what an auditor tests. Healthcare organizations adopted AI faster than they built the governance to account for it.
AI is changing the speed and scale of cyber risk, but the fundamentals of security remain the same. Elisa Costante, VP of Software Engineering at Forescout, discusses why visibility, risk assessment, and adaptive controls are essential for protecting organizations against rapidly evolving threats. Learn more.
On September 15, 2026, NIST published Internal Report 8587, “Protecting Tokens and Assertions from Forgery, Theft, and Misuse.” It’s built to extend NIST Special Publication 800-53 Release 5.1.1, and on paper it reads like an SSO hardening document for government agencies and their cloud vendors.
GRC teams have invested heavily in building mature control frameworks. But the real challenge? Having the visibility into whether they’re working, where gaps exist, and how to keep them running effectively at scale. As compliance programs become more complex, teams need new ways to move beyond manual processes and maintain confidence in control effectiveness. Join GRC experts from Tines for a conversation with Ayoub Fandi, Founder of GRC Engineer, to learn how leading organizations are reducing manual effort and improving visibility, and building compliance programs that scale.
The problem is not a lack of controls. It is connecting them into one attack story. The more time I spend with enterprise AI deployments, the clearer one thing becomes: AI security is incredibly fragmented. There are LLM guardrails, AI gateways, MCP security tools, API security, endpoint controls, SASE, code scanning, and runtime detection. Each solves a real problem, but agentic systems do not experience them as separate layers, and neither do attackers.
No two tech stacks are the same, so no agent can protect every organization the same way. This Short explains why human judgment needs to stay in the loop when it comes to agentic AI in security operations and what it means to build AI that handles the heavy lifting without sacrificing analyst control.
Evo already knows which AI Assets your teams pulled into your repos, which MCP servers and skills are sitting on your developer machines, which of them carry risk, and which policies they break. Getting to any of it created friction: you leave the tool you are working in, filter a UI, export a CSV, and rebuild the chart you built last quarter, every time it’s needed.
Saying a control reduces exposure is easy and almost always true. Saying it reduces exposure by a specific amount is a different claim, and the machinery for producing one is well established. Set a baseline from frequency and magnitude ranges, simulate, re-estimate the ranges with the control in place, simulate again, and report the difference. The method is sound. Applied to AI controls it runs into two problems, one about which term the control touches and one about what the estimate rests on.