CyberKriya
EP-22 - #CyberKriya Podcast -#SAP #AI Security - with Jay Thoden Van Velzen - From Joule to Agentic Frontiers Summary: In this episode, Gaurav Singh is joined by Jay Thoden Van Velzen, a leading expert in agentic AI security at SAP, to explore how AI is transforming enterprise SAP environments. They delve into best practices, security challenges, and how organizations can responsibly adopt AI technologies like Joule within their workflows. Key Takeaways: * The evolution of AI in SAP and what differentiates generative AI (GenAI) like Joule * Key security and governance considerations when deploying AI in business processes * Architectural strategies for implementing secure, compliant, and effective AI solutions * Managing risks associated with AI misbehavior and malicious use cases * Practical steps for customers and security teams to safeguard AI initiatives * The importance of threat modeling, access control, and grounding AI in organizational policies * The role of deterministic workflows and control points in agentic AI systems * How to ensure transparency and accountability with logging and audit capabilities * The significance of shared responsibility models and vendor risk management in AI deployment * Future outlook: AI's impact on workforce productivity and strategic decision-making Chapters: * (00:04) Introduction * (01:09) Differences between traditional AI and Generative AI in SAP—Joule's role * (03:19) Security risks in SAP AI such as hallucinations and data leakage * (04:10) Grounding Joule's responses in truth for business relevance and security * (05:11) How SAP implements privacy and access protections during AI training * (06:26) Approaches to prevent privilege escalation and ensure compliant AI behavior * (08:51) Architecture of Joule's orchestration layer for controlled AI interactions * (15:00) Risks of malicious prompts and how SAP protects against them * (25:04) Differentiating malicious from non-malicious usage and handling volumes * (26:29) The components of Joule: from developer tools to business application layers * (30:17) Human-in-the-loop decision-making and operational safeguards * (32:45) Architectural patterns: separating planning and execution for control * (38:13) Fail-safes and retries to prevent AI from stepping outside bounds * (41:16) Responsibilities of SAP customers and security teams in AI security * (49:17) Grounding AI with organizational policies and real documents * (52:38) Auditing, logging, and shared responsibility in SAP AI deployments * (56:32) Myths and realities about AI replacing jobs—what the data suggests * (59:42) Balancing AI's strategic impact with human judgment and creativity. Threat modeling of AI use cases and handling agent misbehavior. Resources for further learning: SAP Responsible AI and related documentation Disclaimer: The views and opinions expressed in this podcast are those of the host and guests and do not necessarily reflect the official policy or position of any organization, employer, or company they are affiliated with. This podcast is intended for informational and educational purposes only. It does not constitute professional, legal, or cybersecurity advice. References to specific companies, products, or technologies are made solely for discussion and illustration purposes — no endorsement or criticism is implied.Listeners are encouraged to consult their own security, legal, or compliance teams before acting on any information shared in this podcast.
24 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de CyberKriya!