Artificial Intelligence & Machine Learning
,
Next-Generation Technologies & Secure Development
,
Video
Use Established Frameworks and Document Everything, Says FNZ Group’s Matthew Whale
The speed at which artificial intelligence continues to evolve is driving many financial services firms to take some risks as they move to innovate, despite the underlying regulatory uncertainty, said Matthew Whale, group CISO at FNZ Group.
See Also: Why Traditional DLP Can’t Keep Up With AI Data Growth
With AI evolving faster than regulators can keep up, Whale said security leaders are left to walk a tightrope, as their embrace of AI outpaces regulators’ rules for how they should operate.
“We’re not used to the speed of evolution and change that AI is driving at the moment. So, what you’re going to find is that the innovation is simply outstripping the regulatory ability to keep up with it, and that lag time is only going to increase,” Whale said.
Accordingly, Whale recommends security leaders carefully build on established risk management practices and frameworks, documenting everything they’re doing and why. Essential AI security controls shouldn’t be a surprise to any cybersecurity practitioner, given the need to limit access to sensitive data, restrict permissions as much as possible, and monitor what AI systems are doing as well as everything inside the organization that’s now AI-enabled, he said.
In this video interview with ISMG at the FinServ Cyber Security U.K. Summit in London, Whale also discussed:
- The different risks posed by attacks that trace to AI agents, rather than just a human operator;
- Regional approaches to regulating AI and its impact on innovation;
- How working in highly regulated environments can help CISOs secure budget and resources.
Whale has more than a decade of experience in information security, leading specialist teams in medium to large-sized financial service organizations including Hargreaves Lansdown, AXA and Computershare. He became group CISO at FNZ in October 2025, managing group and regional teams across security consultancy, risk, audit, engagement and assurance.
Click Here For The Original Source.
