International Conference on AI, Data Science, Cybersecurity, Cloud Architectures, and Software Engineering

Theme: Theme details will be published soon.

22-28, April 2026 Holiday Inn Frankfurt Airport – Neu-Isenburg, Frankfurt, Germany
Back to conference
Jeffrey Fleming
Featured Speaker

Jeffrey Fleming

Session Speaker

USA

Biography

Nine Layers of AI Risk: A Unified Framework for Security, Governance, and Accountability in the Era of the EU AI Act

Abstract Title

Jeff Fleming is Managing Director of Global Cyber and AI Advisory at HaystackID and Founder of Greyveil Consulting LLC, a boutique AI governance and cybersecurity advisory practice. He holds CISSP, AIGP, PMP, GCIA, GCED, and GCIH certifications and brings cross-sector experience spanning Fortune 100 financial services, federal regulatory environments, and defense contracting. A Colonel in the Illinois Army National Guard with more than 20 years of cyber operations leadership, Jeff serves as Officer in Charge of Cyber Shield, the Department of Defense's largest unclassified cyber exercise. He developed the "9 Layers, 5 Critical Gaps" AI governance framework, aligned to NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, and EU AI Act compliance requirements, and has presented on AI risk and governance at practitioner and academic forums across North America and internationally. His advisory work covers AI security architecture, red teaming, regulatory compliance, and enterprise governance program development across healthcare, financial services, legal, and critical infrastructure sectors. Reference: Enterprise AI adoption is accelerating across regulated industries while existing cybersecurity and governance frameworks continue to fall short of the structural complexity modern AI systems require. This presentation introduces the "9 Layers, 5 Critical Gaps" framework, a practitioner-developed model that maps risk exposure across the full AI system stack from algorithm architecture and training data through application integration and end-user interaction. The framework identifies nine discrete risk layers: Algorithm and Architecture, Training Data, Pre-Training, Post-Training and Alignment, Fine-Tuned Models, Hosting and Inference, Application Layer, Integration and Orchestration, and End User. Most deploying organizations directly control only three of those nine layers but bear legal and regulatory liability across all of them under the EU AI Act, GDPR, and sector-specific mandates. That liability asymmetry is a structural governance failure that current tooling does not address. The five critical gaps sit at the intersections between layers and represent the highest-probability failure points in production AI deployments: Inherited Vulnerabilities, RAG Prompt Injection, Agent Authorization, Output Liability, and Model Provenance. Each gap maps to documented incident patterns across autonomous systems, financial services, and healthcare, grounding the taxonomy in operational evidence rather than theory. The framework aligns to NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS and cross-references EU AI Act obligations for high-risk system deployers. Attendees leave with a structured vocabulary for communicating AI risk across technical and legal audiences, a methodology for mapping control responsibility across the AI supply chain, and a practical foundation for governance program development under current and emerging regulatory requirements.