Abstract
Abstract
The fast and viral uptake of Generative AI (GenAI) and large foundation models
(LFMs) in the corporate worlds is a major, but ill-managed, change in organizational
security, risk, and governance. Although GenAI involves an overwhelming number of
advantages, its implementation creates a new layer of data security threats that
traditional ICT security models were not created to cover. The chapter gives a critical
review of the situation in governance today and the particular ethical and technical
issues that come along with the integration of GenAI. It is analyzed to explain GenAI
Security Threats, such as model poisoning and prompt injection, and the highly
significant problem of data leakage and exposure of intellectual property (IP). It also
explores the Ethical Gaps, which say that inexplicable bias may yield the results of
discrimination or generate shadow vulnerability, which could not be audited. The main
contribution is the suggestion of a Socio-Technical Governance Framework that
incorporates human control, Explainable AI (XAI), and constant security surveillance
into the GenAI deployment pipeline. Actionable Best Practices of data sanitization,
model validation and defining clear lines of accountability in AI-driven decisions
support this framework. This chapter is meant to inform technology leaders and
policymakers by expressing the need to have a proactive risk-based approach to ensure
GenAI is exploited safely and in a manner that is responsible in the digital society.