What Broke First: Shipping AI to Production Without Leaking Data or Trust
About this session
Most AI talks stop at the demo. This one is about what happens after you ship, when a wrong answer or a leaked record has a real cost.
I put generative AI into production inside regulated financial firms, where mistakes are expensive. It's a builder's case study of what broke first and the controls that fixed it. Three failures, three controls: output that was confidently wrong, and how we built verification so a plausible answer isn't taken for a correct one; sensitive data that could leak into a public tool, and the rule for what never enters a prompt; and the missing human sign-off, where we drew the line between what the AI does alone and what a person approves before it ships.
You leave with the control model we actually run: who can configure a model, what data it touches, how outputs get checked, and how to keep it auditable. Stack-agnostic, and no product pitch.
Speaker
Key takeaways
- A verification pattern that stops a plausible-but-wrong output from shipping as if it were correct.
- A data-boundary rule: what never enters a prompt, and what stays inside your controlled perimeter.
- A human-in-the-loop control model you can hand to a security or audit reviewer to test, not just trust.