Episode Description
Summary
Alec Crawford and Anastassia discuss the intersection of AI, cybersecurity, and regulatory compliance in the context of data and digital technologies. Alec shares insights on AI risk governance, the importance of data literacy, and the evolving landscape of cybersecurity threats. They explore the role of AI in combating cybercrime, the challenges of underwriting and pricing cybersecurity risks, and the need for centralised AI governance within organisations. Alec emphasises the importance of training and change management in AI adoption.
Alec is the founder and CEO of Artificial Intelligence Risk, Inc., a platform focused on AI safety, security, and compliance for enterprises. A former Chief Risk Officer and senior risk executive at major investment firms, he now advises boards and financial institutions on how to balance the risks and rewards of AI. He writes the AI Risk Reward / STAYblog newsletter on Substack and hosts the AI Risk Reward podcast, where he explores use cases, governance challenges, and the broader societal impacts of artificial intelligence. His work lies at the intersection of sustainability, technology, and risk management, with a particular focus on securely integrating high‑risk AI systems into heavily regulated sectors such as banking and wealth management.​
Takeaways
- AI is crucial in combating cybercrime. Today, you fight AI with AI.
- Data literacy is essential for AI adoption.
- Cybersecurity insurance is evolving, but still behind. Cybersecurity insurers offer discounts to companies that use best-in-class risk management tools, as motor insurance providers did decades ago when first alarm systems emerged. Cybersecurity risk is complicated to quantify.
- AI governance is necessary for organisational safety.
- Training and change management are key to the success of AI projects. Regarding the 95 percent of failed AI pilots, the issue is a lack of change-management skills and processes, not the technologies.
- Cybercriminals are iterating faster than defenders. Their “businesses” operate much like traditional companies, with work schedules, reward systems, and related structures.
- AI can help focus attention on critical cybersecurity alerts.
- Decentralised AI requires centralised control for safety.
- Cybersecurity threats are becoming more sophisticated. Cybercriminals also exploit traditional bug bounty programs at large software companies to identify and exploit vulnerabilities.
- Companies and individuals will significantly benefit from AI. AI can revolutionize personalized healthcare and accelerate significant scientific discoveries. But all this will come at a cost, as cybercrime grows and is already the third-largest economy in the world after the US and China, if we were assessing it using the same metrics as a national economy.
Chapters
- 03:16 Introduction to AI and Cybersecurity
- 06:01 The Impact of AI on Cybercrime
- 08:35 Fighting AI with AI in Cybersecurity
- 10:35 The Evolution of Cybersecurity Insurance
- 12:54 Quantifying Cybersecurity Risks
- 14:10 Data Literacy and Governance in AI
- 16:43 The Role of Change Management in AI Adoption
- 18:51 Centralised vs. Decentralised AI Governance
- 21:21 The Future of AI and Cybersecurity
- 22:02 Real-Life Cybercrime Stories
- 24:24 The Business of Cybercrime
- 27:24 Due Diligence in Cybersecurity
- 28:48 The Shift Towards Hybrid Systems
- 31:11 Global Cybersecurity Regulations
- 33:04 Optimism vs. Caution in Cybersecurity

