Five parts: why AI breaks the assumptions behind conventional data security, the threat landscape, privacy as a distinct discipline, the regulatory and standards landscape, and the conversion of all of it into controls.
PART II · CH 3–7
Understand the modern AI attack surface
The OWASP Top 10 for LLM Applications and what changed in 2026 — prompt injection, sensitive information disclosure, excessive agency, supply chain — plus where that list stops. Shadow AI as an ungoverned perimeter, and the retrieval layer's permission-loss problem.
Six case files of documented failures, and the pattern across all of them.
PART II · CH 6
Contain agents before they become operational risk
What changes when a model can act: the identity problem for non-human actors, designing for containment, and the connector and protocol surface.
Tool scope · credentials · approval gates · step and spend ceilings · memory isolation · kill switches.
PART III · CH 8–9
Treat privacy as its own discipline
Why security controls do not discharge privacy obligations. Lawful basis and the training question, purpose limitation and function creep, transparency, data subject rights against an AI system, and accuracy where the system fabricates confidently.
Privacy-enhancing technologies: the categories, choosing one, and a realistic assessment of each.
PART IV · CH 10–12
Turn regulation and standards into obligations
The EU AI Act, India's Digital Personal Data Protection framework, data protection law generally, and the United States. Cross-border transfer, sovereign and regional AI, and sector-specific overlays.
NIST AI RMF and ISO/IEC 42001 — how they fit together, and what none of them cover well.
PART V · CH 13
Build an operating model that survives the business
The accountability question, the four artefacts, the lifecycle gates, and risk tiering so the process survives contact with delivery teams.
Inventory · assessments · control evidence · governance forum with decision authority.
PART V · CH 14–17
Put controls into practice
The control library, the first ninety days, vendor due diligence and contracting, and incident response for AI systems from preparation through notification and recovery.
Plus a glossary, board questions, checklists, a regulatory calendar and a sources appendix.