Conference
K2's AI - Security And Privacy Issues
Security and privacy issues must be top-of-mind concerns for business professionals using AI. Yet, for far too many of these professionals, no concern is given for the potential security and privacy risks associated with AI, setting the stage for potentially disastrous results! In this session, you will learn about AI security and privacy risks and how to manage them. This session includes discussions of the major AI companies’ security and privacy policies, how AI platforms might use your data, and how you can stay in control. Given how quickly AI is spreading, this is one session you simply cannot afford to miss.
Watch
What's included
Every registration comes with the course materials — yours to keep.
- Course handout PDF
- Additional course files TXT
Course details
- Recommended CPE credit
- 2
- Field of study
- Information Technology
- Program level
- Intermediate
- Delivery method
- Group Internet Based
- Prerequisites
- None
- Advance preparation
- None
- Course number
- 26c01464
CPE Today (Devmatics, LLC) is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors (Sponsor ID 167619). State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website, nasbaregistry.org. For information about our refund, complaint, and program cancellation policies, see Company Policies or contact [email protected].
💬 Ask this course
Not sure it covers what you need? Ask a real question — answered from the actual course content, so you can decide before you enroll.
Answers come from this course's own material and can be imperfect — the full details are in the course itself.
Every way to take this course
On its own
As part of a multi-day event
These seminars include this course on their agenda. One registration covers the event — you attend this course on its scheduled day, plus everything else that day offers.
Your instructor
Tommy Stephens
Partner · K2 Enterprises · ★ 4.6 instructor rating
Tommy Stephens received a Bachelor of Science in Business Administration degree (Major in Accounting) from Auburn University in 1985. In 1992, he earned a Master of Science degree (Major in Finance) from Georgia State University in Atlanta. Presently, Tommy is a Certified Public Accountant, a Certified Information Technology Professional, and a Chartered Global Management Accountant. In 1995, Tommy began...
Full profile →Common questions
I work in a regulated industry like healthcare or financial services—can I actually use these AI tools safely, or am I just asking for compliance trouble?
Regulated industries face real compliance risks because data fed into most AI engines can be used for training, and in highly regulated sectors like healthcare and finance, that's a serious problem. The instructor walked through specific cases: QuickBooks Online doesn't even offer an opt-out for AI training, and putting HIPAA-covered data into commercial AI engines without a business associate agreement is legally questionable. Claude and Copilot (with enterprise data protection enabled) are your safest commercial options, but even then you need to scrub sensitive identifiers—social security numbers, account numbers, client names—before uploading anything. For truly confidential work, the instructor runs Claude offline using Open LLM, an open-source version disconnected from the internet, precisely to avoid this exposure.
Do I need special software or subscriptions to follow along, or can I use the free versions of these tools?
The free versions of ChatGPT, Gemini, and Claude come with significant privacy trade-offs—your data can be used for model training, and your prompts and conversations are logged. The instructor demonstrates using paid business accounts instead: ChatGPT's business tier, Microsoft Copilot for Microsoft 365 ($30/user/month with enterprise data protection), and Claude's commercial API when using tools like LibreChat or Open Router. If you want to work through the examples, you can start free, but you'll quickly see why the instructor switched to paid tiers when handling any client or sensitive information.
After this course, what will I actually be able to do differently when I'm advising clients or making decisions about AI adoption?
You'll be able to read and interpret the privacy policies and terms of service that come with AI platforms—the instructor shows the exact process he uses with ChatGPT to summarize complex 40,000+ word documents into actionable summaries, highlighting data-sharing practices, subprocessors, and opt-out rights. You'll know which engines are safe for which tasks: Claude and Copilot for client work when properly configured, what data to scrub before uploading, and how to spot when vendors are using dark patterns (like Intuit withholding refund tracking until you consent to tax data sharing). You'll also understand the regulatory landscape—EU AI Act, GDPR, state laws like California SB 53, and emerging US frameworks—so you can assess your firm's exposure and liability when deploying AI at scale.
Is this course mostly theory about regulations, or will I see real examples and workflows I can actually use?
The instructor demonstrates live workflows throughout: opening LibreChat, a self-hosted open-source AI platform with enterprise-class privacy; showing how to load your API keys into Open Router to access 500+ models through a single interface; displaying his actual privacy policy analysis tool in ChatGPT with the exact prompts he uses; and walking through how he classifies files with Azure information protection to prevent data leakage in Microsoft Copilot. He also shows the deepfake attack that hit UK engineering firm RUP—a $25 million fraud using a cloned executive's voice and video—and explains the motion-capture encoding that makes it possible, so you understand not just the risk but how it actually works. The second half shifts from concepts to concrete decisions you make when adopting AI.
What regulatory rules actually apply to my firm, and will they change by the time I finish the course?
The instructor emphasizes regulatory uncertainty as the central challenge: there is no settled federal US law on AI copyright, data privacy, or liability yet. What does apply depends on where your clients are and where your firm operates. EU AI Act requires risk management and transparency for high-risk models; it was phased in August 2024 with full compliance due August 2026. California SB 53 mandates safety frameworks and whistleblower protections for frontier AI developers—and because California is the largest state, many companies follow it nationally. Canada has PEPEDA federally plus provincial privacy acts in Ontario, British Columbia, and Quebec (where 60% of Canadians live). The US has a patchwork of state laws and no comprehensive federal standard. Rather than waiting for clarity, the instructor recommends monitoring CISA's binding operational directives, Treasury's AI cyber clearinghouse, and the NIST AI Risk Management Framework—which the course walks through alongside your firm's existing control frameworks.
You might also like
Conference
Conference
Conference
Next week
Automation, Insight & High-Performance Analytics Week
Conference