Collaborative kitchen for AI governance
Featuring
Sandip Wadje
Sandip Wadje (Managing Director at BNP Paribas) joins Nicholas Muy (CISO at Scrut Automation) to unpack how AI adoption is exposing long-ignored gaps in data classification, access control, and enterprise governance. In this Risk Grustlers episode, they discuss the risks involved in rolling out Microsoft Copilot, the pressure AI is putting on internal controls, and what security, compliance, and risk leaders need to rethink as AI moves faster across the business.


Collaborative kitchen for AI governance
Collaborative kitchen for AI governance
Sandip Wadje (Managing Director at BNP Paribas) joins Nicholas Muy (CISO at Scrut Automation) to unpack how AI adoption is exposing long-ignored gaps in data classification, access control, and enterprise governance. In this Risk Grustlers episode, they discuss the risks involved in rolling out Microsoft Copilot, the pressure AI is putting on internal controls, and what security, compliance, and risk leaders need to rethink as AI moves faster across the business.


Description
AI is not just another tool rollout. It is forcing companies to revisit assumptions they have lived with for years.
In this Risk Grustlers episode, Sandip Wadje joins Nicholas Muy to discuss what happens when leadership wants the upside of AI immediately, while security, risk, IT, legal, and business teams are left dealing with everything underneath it.
The conversation explores what tools like Microsoft Copilot can expose inside organizations, from oversharing in SharePoint to the gap between role-based access on paper and the permissions people actually end up with in practice.
Sandip also lays out a more grounded approach for smaller teams: be honest about what is truly confidential, avoid writing controls you cannot consistently follow, give employees a safer way to work with AI, and start preparing for scrutiny around how AI is being used across the business.
Key AI governance insights from this episode
- Why does data classification suddenly become urgent when AI begins inheriting access across existing systems
- How AI exposes entitlement problems that traditional role reviews often fail to catch
- What smaller organizations should do first, instead of copying heavyweight AI control programs built for large enterprises
Quote from the Episode
“Don’t write internal controls that you would not be able to follow.”
— Sandip Wadje, Managing Director, BNP Paribas
About the Risk Grustlers Podcast
Risk Grustlers is a podcast for people working in security, risk, and governance who want sharper conversations than the usual industry soundbites. Each episode features CISOs, security leaders, and risk practitioners sharing how they think through the real operational challenges behind cybersecurity, compliance, AI governance, and enterprise risk.
Hosted by Aayush Ghosh Choudhury (CEO and Co-founder of Scrut Automation) and Nicholas Muy (CISO at Scrut Automation), this podcast series focuses on practical lessons, hard-earned perspectives, and the nuance that comes only from years spent in the security and compliance space.






















