# Guardrails, governance and security

218 sessions · follows the tags guardrails, security, governance, privacy
Page: https://mlopstalks.com/threads/guardrails-governance-and-security

What data can a model use, and what should it be allowed to do? Privacy and governance discussions meet newer problems with prompt injection and agent permissions.

## 2020

19 sessions.

- [What Does Best in Class AI/ML Governance Look Like in Fin Services?](https://mlopstalks.com/talks/what-does-best-in-class-ai-ml-governance-look-like-in-fin-services) (Charles Radclyffe, Technology Governance and ESG Specialist, AI Ethics). Pushed back: Charles Radclyffe disputes the view that regulation should be the only reason organizations introduce AI governance controls. [21:20](https://www.youtube.com/watch?v=l52sRMVPVk0&t=1280s)
- [Build vs Buy an ML Platform](https://mlopstalks.com/talks/build-vs-buy-an-ml-platform) (Diego Oppenheimer, Algorithmia). Pushed back: Diego Oppenheimer argues that replacing an existing system is not automatically valuable if it is working and meeting required security, compliance, upgrade, and delivery needs. [21:00](https://www.youtube.com/watch?v=1bHQE11Qq0k&t=1260s)
- [Operationalize Open Source Models with SAS Open Model Manager](https://mlopstalks.com/talks/operationalize-open-source-models-with-sas-open-model-manager) (Ivan Nardini, SAS). Pushed back: Ivan Nardini agrees with Demetrios Brinkmann that security is one of the hardest parts of building an open-source end-to-end machine-learning product. [17:03](https://www.youtube.com/watch?v=SNRsTYmb19U&t=1023s)
- [What are regulations saying about data privacy?](https://mlopstalks.com/talks/what-are-regulations-saying-about-data-privacy) (Cat Coode). Pushed back: Demetrios Brinkmann suggests that privacy regulations may be taken less seriously by smaller and disruptive companies, and Cat Coode agrees that this is often the case. [8:08](https://www.youtube.com/watch?v=Rv5Zu3VgBJ0&t=488s)

15 more from 2020 on this thread: https://mlopstalks.com/threads/guardrails-governance-and-security/2020

## 2021

21 sessions.

- [The revolution of Federated Learning](https://mlopstalks.com/talks/the-revolution-of-federated-learning) (Fabiana Clemente, MLOps Community & Ramen Dutta, TensoAI). Pushed back: Ramen Dutta argued that raw data access is not necessary for useful analysis because statistical analysis from privacy-preserving tools can provide the needed information. [18:10](https://www.youtube.com/watch?v=qRBfftNLiDQ&t=1090s)
- [Enterprise Security and Governance MLOps](https://mlopstalks.com/talks/enterprise-security-and-governance-mlops) (Diego Oppenheimer, Algorithmia). Pushed back: Diego Oppenheimer argues that security investment should be a conscious risk-reward decision rather than an identical day-one requirement for every organization. [35:09](https://www.youtube.com/watch?v=JNZk8diyIuE&t=2109s)
- [Machine Learning in Cybersecurity](https://mlopstalks.com/talks/machine-learning-in-cybersecurity) (Monika Venčkauskaitė, Vinted). Pushed back: Monika argued that machine learning cannot completely replace cybersecurity experts, while Demetrios Brinkmann questioned whether new attacks would be missed by the models. [18:21](https://www.youtube.com/watch?v=S-BZwydzd-Q&t=1101s)
- [Building Machine Learning Models into Docker Images](https://mlopstalks.com/talks/building-machine-learning-models-into-docker-images) (Luke Marsden, MLOps Consulting). Pushed back: Luke Marsden argued that building containers inside containers with a mounted Docker socket is a security problem. [49:21](https://www.youtube.com/watch?v=CHttwWGdWK4&t=2961s)

17 more from 2021 on this thread: https://mlopstalks.com/threads/guardrails-governance-and-security/2021

## 2022

22 sessions.

- [Federated Learning: Machine Learning on the Edge](https://mlopstalks.com/talks/federated-learning-machine-learning-on-the-edge) (Varun Kumar Khare, Nimble Edge). Pushed back: The speaker challenged the assumption that conventional cloud-based machine learning pipelines are sufficient, arguing that federated learning is needed for personalization, privacy, security, and cost reasons. [16:44](https://www.youtube.com/watch?v=IWxBKGPHOBQ&t=1004s)
- [FLOps with Scaleout's Open-core Platform](https://mlopstalks.com/talks/flops-with-scaleouts-open-core-platform) (Marco Capuccini, Scaleout Systems). Pushed back: Federated learning is not automatically the answer to privacy challenges when data cannot be standardized or even a small sample cannot be shared centrally. [37:51](https://www.youtube.com/watch?v=z8IHMr-Z1M8&t=2271s)
- [Trustworthy Machine Learning](https://mlopstalks.com/talks/trustworthy-machine-learning) (Kush Varshney, IBM Research). Pushed back: Krishnaram Kenthapadi questioned whether machine learning systems are different from complex machines and medicines that people trust without understanding how they work. [9:07](https://www.youtube.com/watch?v=ASSrHdTQhJo&t=547s)
- [Building Threat Detection Systems: An MLE's Perspective](https://mlopstalks.com/talks/building-threat-detection-systems-an-mles-perspective) (Jeremy Jordan, Duo Security). Pushed back: Jeremy Jordan clarified that rules and machine learning usually work together in cybersecurity rather than rules simply being replaced by machine learning. [8:41](https://www.youtube.com/watch?v=13nOmMJuiAo&t=521s)

18 more from 2022 on this thread: https://mlopstalks.com/threads/guardrails-governance-and-security/2022

## 2023

38 sessions.

- [Harnessing MLOps in Finance](https://mlopstalks.com/talks/harnessing-mlops-in-finance) (Michelle Marie Conway, Lloyds Banking Group). Pushed back: Michelle Marie Conway rejects the idea that banking's security controls are merely inconvenient, arguing that strict controls are necessary to protect customers and their finances. [29:40](https://www.youtube.com/watch?v=nIEld_Q6L-0&t=1780s)
- [LLM Security](https://mlopstalks.com/talks/llm-security) (Raahul Dutta, Elsevier & Uri Shamay, Null & Sankalp Gilda, DevelopYours). Pushed back: Whether current LLM engineering projects are ready for production use was challenged by the speakers' shared view that most are still demos and need stronger security guardrails. [52:04](https://www.youtube.com/watch?v=gFjBJozwSrs&t=3124s)
- [Product Strategy for LLM Features When LLMs Aren't Your Product](https://mlopstalks.com/talks/product-strategy-for-llm-features-when-llms-arent-your-product) (Harini Kannan). Pushed back: For non-user-facing cybersecurity use cases, LLM risks can be reduced with additional controls and testing, rather than treating the LLM as an unguarded production component. [12:27](https://www.youtube.com/watch?v=1FUV9VGVCGw&t=747s)
- [Designing for Forward Compatibility in Gen AI](https://mlopstalks.com/talks/designing-for-forward-compatibility-in-gen-ai) (Rohit Agarwal, Portkey.ai). Pushed back: Rohit Agarwal says current vector databases do not sufficiently enforce permissions, creating a risk that prompt engineering could retrieve unauthorized data. [42:32](https://www.youtube.com/watch?v=_VKMQ-tRJ_4&t=2552s)

34 more from 2023 on this thread: https://mlopstalks.com/threads/guardrails-governance-and-security/2023

## 2024

39 sessions.

- [A Decade of AI Safety and Trust](https://mlopstalks.com/talks/a-decade-of-ai-safety-and-trust) (Petar Tsankov, LatticeFlow AI). Pushed back: Petar argued that robustness verification cannot by itself establish that a machine-learning model is trustworthy because data and labeling problems must be addressed first. [26:16](https://www.youtube.com/watch?v=mnacK0CdjBk&t=1576s)
- [AI in Healthcare](https://mlopstalks.com/talks/ai-in-healthcare) (Eric Landry, Zeteo Health). Pushed back: Demetrios Brinkmann asked whether using multiple guardrail systems would be redundant overkill, while Eric Landry described using Ragas for evaluation and NeMo Guardrails for runtime protections and intent-based responses. [41:36](https://www.youtube.com/watch?v=6Rc71TsOcRk&t=2496s)
- [A Blueprint for Scalable & Reliable Enterprise AI/ML Systems](https://mlopstalks.com/talks/a-blueprint-for-scalable-reliable-enterprise-ai-ml-systems) (Hira Dangol, Bank of America & Rama Akkiraju, NVIDIA & Nitin Aggarwal, Google & Steven Eliuk, IBM). Pushed back: Nitin Aggarwal said there is no single established framework that serves as a universal or golden standard for evaluating and governing AI systems. [32:52](https://www.youtube.com/watch?v=rulov-njzQ4&t=1972s)
- [AI-Driven Code: Navigating Due Diligence & Transparency in MLOps](https://mlopstalks.com/talks/ai-driven-code-navigating-due-diligence-transparency-in-mlops) (Matt van Itallie, Sema). Pushed back: Matt disputes the idea that every codebase should have zero security warnings, arguing that the appropriate amount of technical and security debt depends on the company’s size and stage. [25:55](https://www.youtube.com/watch?v=G0mn1W3bEXo&t=1555s)

35 more from 2024 on this thread: https://mlopstalks.com/threads/guardrails-governance-and-security/2024

## 2025

41 sessions.

- [AI in Production 2025 | Keynote](https://mlopstalks.com/talks/ai-in-production-2025-keynote) (). Pushed back: The speaker rejected the assumption that one universal guardrail model is sufficient and argued that guardrails should usually be specific to the concern or application. [26:38](https://www.youtube.com/watch?v=ioCIpbAKl_M&t=1598s)
- [Which Economic Tasks are Performed with AI? Evidence from Millions of Claude Conversations](https://mlopstalks.com/talks/which-economic-tasks-are-performed-with-ai-evidence-from-millions-of-claude) (Valdimar Eggertsson, Snjallgögn (Smart Data inc.) & Sophia Skowronski, Breckinridge Capital Advisors). Pushed back: Adam Becker questions whether removing small clusters for privacy protection could distort the results. [19:26](https://www.youtube.com/watch?v=DKqocE5JHfU&t=1166s)
- [Iceberg, MCP, and MLOps: Bridging the Gaps for Enterprise](https://mlopstalks.com/talks/iceberg-mcp-and-mlops-bridging-the-gaps-for-enterprise) (Caleb Baechtold, Snowflake & Hamza Tahir, ZenML & Simba Khadder, Featureform). Pushed back: Hamza Tahir argues that both rigid stack enforcement and unrestricted stack sprawl create problems, favoring a flexible governance envelope instead. [24:04](https://www.youtube.com/watch?v=gicCH6FC-a4&t=1444s)
- [A New Way of Building with AI](https://mlopstalks.com/talks/a-new-way-of-building-with-ai) (Jiquan Ngiam, Lutra AI). Pushed back: AI integrations should adapt interfaces to model behavior rather than simply impose narrow developer-designed scopes and guardrails. [10:49](https://www.youtube.com/watch?v=D8DsW5swR34&t=649s)

37 more from 2025 on this thread: https://mlopstalks.com/threads/guardrails-governance-and-security/2025

## 2026

38 sessions.

- [Stop Building AI Like Traditional Software](https://mlopstalks.com/talks/stop-building-ai-like-traditional-software) (Aishwarya Naresh Reganti, LevelUp Labs). Pushed back: Aishwarya Naresh Reganti said prompting should be a last resort for controlling agent access, preferring deterministic guardrails and rule-based access controls. [16:30](https://www.youtube.com/watch?v=_CToYjO18J4&t=990s)
- [Tool Calling](https://mlopstalks.com/talks/tool-calling) (Alex Salazar, Arcade.dev & Nishikant Dhanuka, Prosus Group & Luciana Ledesma, MeaningStack). Pushed back: Luciana Ledesma argues against uniform governance and favors governance that scales to risk through graded intervention. [28:02](https://www.youtube.com/watch?v=mxD2Eeb_Bp0&t=1682s)
- [Time to become a hacker](https://mlopstalks.com/talks/time-to-become-a-hacker) (Matt Sharp, Flexion). Pushed back: Matt Sharp disputes the assumption that the main opportunity in AI is only generative AI investment, saying cybersecurity was the leading organizational investment in 2025. [12:14](https://www.youtube.com/watch?v=hs-Ah5Dme3U&t=734s)
- [MLflow Leading Open Source](https://mlopstalks.com/talks/mlflow-leading-open-source) (Databricks' Corey Zumar). Pushed back: Redacting all personal information is not always the right governance goal because it can remove valuable information needed for debugging and analysis. [52:40](https://www.youtube.com/watch?v=NUuZ2n_ZkqI&t=3160s)

34 more from 2026 on this thread: https://mlopstalks.com/threads/guardrails-governance-and-security/2026
