What Broke First: Shipping AI to Production Without Leaking Data or Trust

About this session

Most AI talks stop at the demo. This one is about what happens after you ship, when a wrong answer or a leaked record has a real cost.

I put generative AI into production inside regulated financial firms, where mistakes are expensive. It's a builder's case study of what broke first and the controls that fixed it. Three failures, three controls: output that was confidently wrong, and how we built verification so a plausible answer isn't taken for a correct one; sensitive data that could leak into a public tool, and the rule for what never enters a prompt; and the missing human sign-off, where we drew the line between what the AI does alone and what a person approves before it ships.

You leave with the control model we actually run: who can configure a model, what data it touches, how outputs get checked, and how to keep it auditable. Stack-agnostic, and no product pitch.

Speaker

Key takeaways

  • A verification pattern that stops a plausible-but-wrong output from shipping as if it were correct.
  • A data-boundary rule: what never enters a prompt, and what stays inside your controlled perimeter.
  • A human-in-the-loop control model you can hand to a security or audit reviewer to test, not just trust.

Related sessions