{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Signed","title":"Did You Make a Security Exception for AI?","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/cce35414\"></iframe>","width":"100%","height":180,"duration":6200,"description":"Anthropic built Claude Code. Anthropic still couldn't stop its own source code from leaking straight into a competing product. If a coding tool is running behind your VPN right now with full access, this conversation names what that's already costing you.\nThomas Cooper is AI Product Lead at Expedient, where he works daily with enterprises building AI governance after the fact, once a tool is already live and the CISO's original objection has already been overruled.\nThis episode is what to check before that call happens, starting with why a SOC 2 report that only spans three months doesn't protect you, and ending with the one AI bet CIOs are making right now that they'll likely regret. If you only have ten minutes, start with the SOC 2 check at 35:28.\n\n\nFind the Risk You're Already Dealing With\nWe just sat through another vendor demo claiming their AI is different from everyone else's. How do I actually tell if that's true? → Jump to 09:15\nWe're already juggling five different AI point solutions across departments. Should we be building toward one platform instead? → Jump to 10:54\nOur AI pilot has been running for months and nobody can point to a number that justifies it. What should we actually be measuring? → Jump to 14:40\nWe're about to connect AI to our SharePoint. What actually breaks first? → Jump to 29:20\nA vendor sent us their SOC 2 report and it only covers three months. Is that actually a red flag? → Jump to 35:28\nOur AI tool is pulling from SharePoint and I'm not confident it's respecting who can see what. How does that actually break? → Jump to 39:43\nIf a lawsuit ever needed our team's AI conversations, could opposing counsel actually get them? → Jump to 43:58\nOne of our developers is running a coding tool with full access behind our VPN and nobody vetted it. How exposed are we right now? → Jump to 49:36\nHalf our team is probably pasting company data into personal AI accounts. Is that actually as dangerous as it sounds? → Jump to 53:50\nWe got hit with...","thumbnail_url":"https://img.transistorcdn.com/d8NGarPLhvklmJcOQEYdHcKCmSM85HfY2AEspyWoL-M/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82NzJl/MzE1NTFmNzgzMjVk/NTdhOTc4ZGU2YWYx/Zjc5Ny5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}