In Episode 4 of The Cyber Roundtable: Security Evolutions, I sat down with Greg Crowley, founder of Runtime Executive and author of Secure AI Enablement: A CISO’s Practical Guide to Governing AI at Scale.
Greg has spent more than two decades in security, and he came up the way a lot of CISOs do — through IT. He spent close to twenty years at WWE, moving from systems administrator into executive leadership back when security was still part of IT’s job rather than its own function. What changed that was watching the 2014 Sony Pictures attack send another media company back to pencil, paper, and fax machines. Sitting inside a media and entertainment company himself, he finally had the parallel that opened the budget, and he built WWE’s first dedicated security program. From there he became CISO at eSentire, trading protecting one company for helping protect thousands — a natural move for someone who calls himself “a defender by nature.”
The thread that ran through our whole conversation: real AI governance lives at runtime, not on paper. Greg has a name for the alternative — governance theater. A company stands up an AI governance committee, writes an acceptable-use policy, builds an onboarding process, and it all looks like control. It’s the right place to start. But AI is non-deterministic, and what a system does on day one is not what it does on day 45. You tell an agent to talk to System A and not System B, and it reasons its way into System C because no one mentioned it. A policy can’t see that. It describes intent; it doesn’t enforce anything while the agent is executing. That, Greg argues, makes governance an architecture problem — visibility and control in the execution path, not another document in a folder.
“I want the secure way to be the easy way.”
— Greg Crowley, founder of Runtime Executive
That north star cuts both directions. The business can’t route around security into shadow AI, and security can’t turn every request into a six-week gauntlet, or people go underground. His fix is to design guardrails up front and tier them by risk — low-sensitivity use cases move fast and get logged, anything touching critical data earns a heavier process — so new use cases flow through a system instead of a negotiation. He draws the pattern from history: cloud taught it, and so did the iPhone, back when it was a consumer device IT couldn’t manage until the world made clear it wasn’t a wave you could block.
And he named the risk that reframes the whole thing: speed and scale. The prospect of AI that can find a vulnerability, write the exploit, and run the attack at machine speed turns zero-days from rare events into everyday ones. The defense has to match that speed, which is why AI is moving into the SOC — but Greg holds a firm line on keeping a human in the loop when an incident is live. Nobody, he points out, wants a chatbot holding their hand through a breach.
A thoughtful conversation about enabling AI without losing control of it. Take a listen.
Connect with our guest
Greg Crowley
Founder, Runtime Executive · Author, Secure AI Enablement