AI Risk Governance meetup by Pipedrive (October 24, 2025)

Attended "AI Risk Governance" meetup organized by Pipedrive.

Martin Ojala from Kordon.app explored how introduction of AI is changing organization threats. MAESTRO and PLOT4AI frameworks were mentioned.

Threats with AI

  • AI-powered phishing now uses cloned voices, real-world timing, and context awareness to pressure victims.
  • LLM-assisted malware evolves on-device, mutating continuously and evading detection.
  • AI-generated exploits appear within minutes of vulnerability disclosures, pushing the need for automated patching.
  • Data poisoning and prompt injection attacks exploit AI's dependence on open data and untrusted inputs.
  • Even supplier-side AI misuse can expose your organization indirectly.

Threats to AI

  • Poisoned or manipulated training data (like the Reddit SEO case).
  • Hidden prompts embedded in files or calendar events.

Threats from AI

  • Opaque decision-making leading to legal, ethical, or reputational risks.
  • Agents with overbroad permissions performing destructive actions.
  • Loss of control over work results.

"AI threat modeling doesn't need to be perfect, but it needs to be systematic. Think through how AI can go wrong, and stay up to speed with how the landscape evolves."

Here I was asking:

  1. Are we left with AI defenders fighting AI attackers?
  2. About AI models blackmailing the user.

Joseph H. - The Human in the Loop

  • Overreliance can cause skill erosion, isolation, and loss of understanding of one's own systems.
  • Humans may become the bottleneck - unqualified to verify AI outputs or too dependent on them.
  • 60% of breaches still involve human error - AI reduces some risks but introduces new ones.

"AI should extend human capability, not replace it. The goal isn't to remove the human loop - it's to strengthen it."

Here I was asking about creativity. Are humans going to lose it if AI does most of the music, art and movie generation.

Vibe coding risks

Tambet Paljasma talked about engineers relying on vibe coding more, what risks it can introduce and how to mitigate them. Unfortunately I did not pay attention, probably what Tambet was warning about 🙂

But I did notice that slides were very detailed and text-heavy. So my question was about balance of overengineering (building a complex agents pipeline to create slides) vs winging it (go fast and break things).

I got to talk with Taras Kushnir about his new project - https://privatecaptcha.com. Isn't AI going to bypass all captchas?