Reimagining Cyber - real world perspectives on cybersecurity · Reimagining Cyber

AI Regulation: What Security Teams Need to Know - #187

February 4, 2026·29 min·1 clip
Matt says agentic AI can amplify risks from prompt injection to unintentional data loss.
1. Reimagining Cyber #187 focuses on AI regulation and security teams. 2. Tyler Moffitt, identified as a Senior Security Analyst, hosts Matt Aldridge from OpenText, and Tyler says Matt has worked with him for over 15 years. 3. The episode asks what AI regulation means for security teams, businesses of all sizes, MSPs, and 2026 planning. 4. Matt says regulation moves more slowly than AI itself, which makes the policy landscape hard to keep up with. 5. He points to the EU AI Act as a starting point and says Europe is already planning changes that also touch GDPR. 6. Matt says the EU risks over-legislating in ways that could slow development or “cripple businesses” in the region. 7. He says California’s CPRA strengthens CCPA rather than replacing it. 8. Matt notes that CPRA adds cybersecurity audits, risk assessments, and attention to automated decision-making technology, or ADMT. 9. He uses facial recognition, policing, and financial systems to show how training data quality can shape AI outcomes. 10. Matt says regulators are trying to screen training data before it reaches AI models so biases are identified earlier. 11. He contrasts heavily regulated facial-recognition use in CCTV with China’s highly developed facial-recognition systems. 12. Matt says safety, fairness, privacy, and data protection need higher priority than speed when AI decisions affect people. 13. He describes the EU’s “digital omnibus” as an initiative to amend existing regulations and adjust implementation timelines. 14. Matt says that approach aims to preserve protections while reducing the chance of holding back development. 15. For small and medium-sized businesses, he says regulation still applies if they process customer, employee, contractor, or public personal data. 16. He recommends treating AI like outsourced data processing by defining protections, agreements, and due diligence for in-house, cloud, and third-party tools. 17. Matt says MSPs and SMBs should inventory AI solutions, create approval cycles, and track what employees are already using. 18. He warns that agentic AI, bot-to-bot communication, and open local systems can expose credentials, data, and controls very quickly. 19. The episode is an interview with Tyler pushing practical questions and Matt answering in a detailed, cautionary, policy-focused style. 20. Security teams, MSPs, and SMB leaders would get the most from it; listeners wanting AI ethics theory alone may skip it.

As heard by us

A calm briefing on why AI governance already belongs in security planning.

AI regulation is the center of the episode, and it stays useful because it keeps pulling the topic back to a plain security question: how teams respond when change moves faster than process.

Read the full review in PlayNext →

Why you'd press play

Press play if you need the AI regulation briefing before the compliance pile lands.

Read the full recommendation in PlayNext →
Listen to the show on