Insights from the Women in Big Data AI & Cyber Security Fireside Chat with Caryn Lusinchi
In a fireside chat hosted by the Women in Big Data AI, Surekha Reddy (Global Executive Chair) spoke with Caryn Lusinchi, a globally recognized AI governance and risk management leader, and Veena Hadagali, Senior Staff Engineer at Geico. They cut through the hype around AI to address the practical realities of governing, securing, and trusting AI systems in an era where the technology outpaces the rules designed to contain it.
Lusinchi framed the challenge with a vivid metaphor: “AI governance is the art of writing detailed rules for a car that’s already doing around 200 miles per hour on the freeway… all while the car is teaching itself to fly.” By the time a framework is ratified, the technology it targets has already had three major updates and a rebranding. Governance, then, must be adaptable by nature. It is not a static document but a living practice.
The conversation drew a sharp distinction between traditional cybersecurity risk and AI risk. Cyber risk could involve an unknown external attacker who breaks in, steals, and leaves. AI risk is something else entirely. I could be your own system, with full interior access, doing exactly what you asked. “In cyber, we’re all taught you patch the vulnerability,” Lusinchi noted. “In AI, the vulnerability is the intelligence… good luck patching that.” Traditional cyber scales with human effort; AI risk scales with compute budgets, needing only a bigger GPU and a few hours on a Tuesday afternoon.
Lusinchi highlighted three emerging threats organizations aren’t ready for:
“The attacker never touched your systems,” Lusinchi observed, “but the agent did, with the keys you gave it.”
On frameworks, the advice was pragmatic: there is no one-size-fits-all standard. Organizations should start with their regulatory landscape, whether that’s NIST AI RMF, ISO 42001, GDPR, the EU AI Act, or sector-specific rules, and build incrementally. The biggest mistake enterprises make is starting too broadly with steering committees and generic training rather than picking one high-risk use case, governing it well, and scaling from there.
Equally important is making governance part of the development cycle, not an afterthought. As well
as tying it to financial incentives. “If passion and ethics are a little bit lower on the totem pole than experimentation, money starts driving motivation,” Lusinchi remarked.
Data governance surfaced as the foundation of trustworthy AI. Many organizations inherit data through acquisitions or third-party suppliers without proper metadata, taxonomy, or lineage. A latent gap only discovered when downstream outcomes are already compromised. As Hadagali summarized: “AI governance is not just about compliance. It’s about building trust, managing risk, and enabling responsible innovation.”
Regulations will likely migrate from high-level principles toward technical requirements around cybersecurity, accuracy, and robustness. But organizations shouldn’t wait for perfect regulatory clarity. Lusinchi’s guidance: self-govern, document your assumptions, and be ready to adapt.
For cybersecurity professionals, the essential skills extend beyond technical knowledge to cross functional communication and change management. “Stay curious and humble,” Lusinchi advised. “Anyone who says they’re an expert is typically lying… because everyone is still learning.”
For women entering the field, the message was encouraging: find mentors, don’t wait to be an expert to contribute, develop deep expertise in one tangential area, and above all, “be confident in navigating through uncertainty versus waiting for perfect clarity to act or even have an opinion.”
Feel like socializing?
Interested in serving on a Women in Big Data leadership committee?
Click here to let us know.