Zach giving a presentation about AI to an attentive audience seated around tables in a modern corporate boardroom.

AI and data security

Your AI ban made AI use invisible, and invisible is the expensive kind.

Format

Keynote or Workshop

Delivery

In Person & Virtual

Audience

Executives & Boards

Fees from

$10,000+

Prohibition is what produces the breach

More than half of the workers already using generative AI use tools their employer has not approved, in a Salesforce survey of more than 14,000 workers across 14 countries. Much of that usage runs through personal accounts, which is to say outside every control you have.

The consequences are now measurable. IBM's Cost of a Data Breach Report found shadow AI involved in one in five data breaches, adding an average of $670,000 to the cost of each one, and 63 percent of the organizations it hit had no AI governance policy in place when it happened.

Which tells you what a ban actually accomplishes. Usage stays right where it was and moves to a phone, under a personal login, where nothing is logged and nobody will mention it until something goes wrong. The tools your people use are simply ahead of the policies that cover them.

The choice in front of you is between AI you can see and AI you cannot.

I have been through the audits

At Yembo I took an AI platform through ISO 27001, SOC 2 Type II, GDPR, and NIST 800-171 while continuing to ship. So I am not going to give your board a talk about how AI is risky, which they know, or a talk about how to slow down, which they will ignore.

What I can give them is the distinction that matters: which controls genuinely reduce exposure, which ones are theater that makes an auditor comfortable and protects nothing, and what it costs to retrofit the real ones after a program has already shipped. Your security team and your AI ambitions are currently arguing, and in my experience both of them are right.

For a working session rather than a talk, the 60-Minute Security Audit walks a leadership team through its own exposure and produces a prioritized remediation list. Teams in regulated industries usually pair it with the insurance governance material.

Where I have taught and spoken

CiscoEtsyCarMaxPMIAICPA & CIMAVirginia TechCal State FullertonCydcorArkusNexusIAMEPAAUX BrightonBrighton SEO

Bring this to your board

Tell me the audience and the date, and I will tell you whether I am the right fit. If your event is better served by someone else, I will say so.

Most teams book the full day: the keynote plus the AI Opportunity Audit, a four-hour working session on your own workflows, at $25,000 flat.

See All Speaking Programs

Questions program chairs ask

Does Zach Rattner speak about AI security and governance?
Yes. Zach Rattner speaks to executive teams, security leaders, and boards on deploying AI without creating data exposure. He has taken an AI platform through ISO 27001, SOC 2 Type II, GDPR, and NIST 800-171, so the material comes from passing audits rather than from advising on them.
What is shadow AI and why does it matter?
Shadow AI is employee use of AI tools that an organization has not approved or cannot see. A Salesforce survey of more than 14,000 workers found that over half of those using generative AI at work use unapproved tools, and the IBM Cost of a Data Breach Report found shadow AI involved in one in five breaches, adding an average of $670,000 to the cost of each. Zach Rattner argues that a ban simply moves this usage onto personal accounts where nothing is logged.
How should a company let employees use AI safely?
Zach Rattner recommends providing a sanctioned tool good enough that people prefer it, combined with audit logging and clear data handling rules, rather than attempting prohibition. IBM found that 63 percent of organizations hit by shadow AI breaches had no AI governance policy, and 97 percent of those with AI-related breaches lacked proper AI access controls, which are exactly the controls a sanctioned tool provides and a ban does not.
What are Zach Rattner's speaking fees?
Zach Rattner's speaking fees start at $10,000 USD plus travel. The final number depends on the event type, the location, and whether the booking includes a workshop or a follow-up session.
Does Zach Rattner run a security workshop?
Yes. The 60-Minute Security Audit is a workshop for leadership teams of 8 to 25 people that walks an organization through its own AI data exposure, covering ISO 27001, SOC 2 Type II, and GDPR considerations, and produces a prioritized remediation list.