Helen Beal, co-author of the novel *Investments Unlimited*, explores the intersection of accelerated software delivery, regulatory pressure, and the transformative power of AI.
The presentation uses the narrative of Investments Unlimited to discuss how organizations can thrive in the digital age by addressing DevOps, Security, Audit, and Compliance. The book's inciting incident involves a potential regulatory action (MRIA) against the fictional firm IUI.
Key Takeaways:
- Beyond DevOps: Learn why simply adopting DevOps principles isn't enough. The challenge is systematically including all parties—Security, Compliance, and Risk (GRC)—in a shift-left mentality, leveraging the three ways of flow, feedback, and continuous learning.
- Automated Governance: Discover how AI and ML are critical for achieving continuous compliance.
- AI/ML automates the identification and aggregation of evidence to prove control effectiveness ("Continuous Evidence").
- AI-powered tools enforce "policy as code" and automate cross-referencing activity against regulatory frameworks (like SOX or GDPR).
- In DevSecOps, AI enhances SAST/DAST tools for proactive vulnerability detection and reduces false positives by learning from past remediation actions.
- The AI Outlook: The path of Generative AI, AI Agents, and AI Engineering through the Trough of Disillusionment and onto the Plateau of Productivity by 2029.
- Practical advice for adopting AI, including starting with proven process automation use-cases and leveraging Knowledge Graphs for compliance and audit readiness.