Attend CSC13
Talk Title: AI Governance for Small and Midsize Businesses
Abstract
AI governance sounds like it requires a dedicated risk officer or a governance committee—resources most SMBs simply don't have. This session breaks the concept down to what it actually is: the decisions your company makes about which AI tools you use, who's allowed to use them, what data they touch, and who's accountable when something goes wrong. No new department required, just a few new questions layered onto processes you already run.
From there, we'll walk the current compliance and risk landscape: the federal patchwork of executive action and agency enforcement (FTC, EEOC, CFPB, FDA), the EU AI Act's risk-tiered obligations for any company with EU customers or users, and the state laws actually shaping day-to-day exposure.
Next, we turn to shadow AI—the gap between the tools a company approved and the tools employees are actually using. We'll unpack why bans backfire, why adoption consistently outpaces policy, and what that means for visibility into risk.
We close on accountability: when an AI vendor's tool generates work product from your data, who owns the output, and who's liable if it's wrong? Most companies have never asked their vendor that question—we'll show you which ones to ask.
Speaker Bio
David Moalem is a cybersecurity, AI governance, and technology leader with more than 26 years of experience spanning IT, cybersecurity, risk management, governance, and enterprise technology across higher education, local government, entertainment, legal, real estate, financial, and healthcare industries. His career has evolved from hands-on infrastructure work into leading complex cybersecurity programs, advising executives, and driving responsible AI adoption in highly regulated environments.
Previously, as Head of Cybersecurity, he built an enterprise security program for a multi-billion-dollar organization spanning multiple portfolio assets. Beyond his current enterprise role driving GRC and AI Governance, David Moalem is a Security & GRC Consultant advising organizations on cybersecurity transformation and risk management. He also serves as CAIO at InterStructure, working at the intersection of AI, cybersecurity, governance, and enterprise transformation.
David brings a combination of technical depth and practical business judgment — having worked from the help desk through enterprise leadership, he understands how security and technology decisions actually get implemented. As a speaker, he brings an operator's perspective rather than a theoretical one, focusing on the real-world challenges organizations face adopting AI, managing cyber risk, building governance programs, and preparing people and processes for a rapidly changing technology landscape.