Helping Enterprises
Govern AI Before It Governs Them
Edward Galt is Vice President of Product Security at Epsilon and author of Borrowed Trust: The Executive's Guide to Securing the AI-Driven Enterprise. With over 20 years of technology experience — spanning infrastructure, software development, and enterprise application security — his work today focuses on one problem: closing the gap between how fast enterprises adopt AI and how well they govern, secure, and take accountability for it.

AI Governance

Enterprises are adopting AI faster than they are learning to govern it. Closing that gap — responsibly, and without slowing the business down — is the focus of my work.

Capability Has Outrun Accountability

AI is now trusted to write code, triage security findings, and take action inside production systems — often faster than any human process could review it. Most enterprises adopted this capability one reasonable decision at a time: a coding assistant here, a triage persona there, an agent wired into a workflow somewhere else. Individually, each decision made sense. Collectively, they created a gap between what AI is doing inside the enterprise and what anyone can actually prove about who is watching it.

My work is about closing that gap — building the inventory, identity, accountability, and measurement disciplines that let organizations move fast with AI without losing the ability to explain, specifically and confidently, what happened and who is responsible for it.

The Business

Financial and reputational exposure when AI systems act without a clear, auditable owner.

The Employees

Trust and accountability for the people working alongside AI systems making consequential decisions.

The Clients

The ability to answer, quickly and specifically, what happened to their data and who was responsible.

Research & Writing

Published writing on AI governance, application security, and what happens when enterprises adopt AI faster than they can govern it.

AI Governance Isn't a New Task for Your Security Team. It's a New Team.

Why AI oversight needs its own function, with its own headcount and authority — not a task bolted onto an already-full security team.

Read on LinkedIn

The Metrics That Lie and the Ones That Don't

Why legacy AppSec metrics can quietly mislead once AI moves the real security work upstream — and what to measure instead.

Read on LinkedIn

Efficiency Without Accountability Is Just a Faster Mistake

Why pairing every AI efficiency claim with an honest accuracy claim is the difference between a real win and a hidden risk.

Read on LinkedIn

Prompt Engineering as the New Security Policy Surface

How prompts have become machine-interpretable security controls — and why they need the same rigor as any other policy.

Read on LinkedIn

Prompts Need CI/CD Too

Why skill files and prompts are functionally code, and why almost nobody treats them with the version control and testing rigor code requires.

Read on LinkedIn

Should AI Fix Our Vulnerabilities? The Future of AppSec Is Here and It Needs Guardrails

The case for a human-in-the-loop model for AI-driven remediation — and what a mature program actually requires.

Read on LinkedIn

The Vulnerability Your AI Persona Dismissed Is Still Your Problem

The accountability gap created when AI triage personas dismiss findings with no owner, no record, and no way to catch a bad call.

Read on LinkedIn

The Chain Problem: Why Low Severity Doesn't Mean Low Risk

Why even highly accurate AI triage can miss the attack paths formed when several small, individually acceptable findings connect.

Read on LinkedIn

Why Every Enterprise Needs an AI Gateway (And Why "Just Use the API" Won't Cut It)

The case for a single, dedicated control point for all AI traffic — and why direct API access doesn't scale to enterprise governance.

Read on LinkedIn

Why MCP Security Testing Is Not Web App Testing

Why Model Context Protocol integrations need a different testing discipline than traditional web applications.

Read on LinkedIn

Your AppSec Program Has No Inventory of Its Own AI

The foundational gap behind almost every other AI governance problem: most organizations can't list the prompts, agents, and skill files already running in production.

Read on LinkedIn

The Book

Borrowed Trust: The Executive's Guide to Securing the AI-Driven Enterprise

Borrowed Trust

Enterprises are adopting AI faster than they can govern, secure, or hold it accountable — and closing that gap is the next major discipline in the enterprise. Borrowed Trust is written for executives who need to understand not just the opportunity AI represents, but the responsibility that comes with it: to the business, to its employees, and to every client whose data and trust are on the line.

Drawing on firsthand experience building and governing AI-driven AppSec programs inside a large enterprise, the book walks through where the real gaps live — inventory, identity, decision accountability, the new attack surface, honest metrics, calibrated trust in AI remediation, and the infrastructure that ties it together — and what closing each one actually requires.

Not yet available for purchase — details coming soon.

Chapters

  • Chapter 1: The New Enterprise Reality
  • Chapter 2: The Governance Gap — Why AI Oversight Needs Its Own Team
  • Chapter 3: You Can't Secure What You Haven't Inventoried
  • Chapter 4: Agents Without Identity
  • Chapter 5: When AI Makes the Call
  • Chapter 6: The New Attack Surface
  • Chapter 7: Measuring What Actually Matters
  • Chapter 8: How Much Should We Trust AI to Fix Itself?
  • Chapter 9: The Control Point — Building an AI Gateway
  • Chapter 10: The Responsible Path Forward

Background

Two decades across infrastructure, software development, and enterprise application security.

Security & Compliance

AI Governance & Inventory
Threat Hunting / Threat Intelligence
Penetration Testing
Auditing and Risk Management
Security Compliance
HIPAA / PCI-DSS Compliance
GDPR / CCPA
DevSecOps

Cloud & DevOps

AWS / Azure
Docker / Kubernetes
Microservices & Serverless
CI/CD, Jenkins, GoCD, Terraform
Git / BitBucket
Kafka, Hadoop, Cassandra, Big Data

Development Foundations

Java / J2EE, Spring, Hibernate
Microsoft .NET, C#, ASP
Linux / Unix, Kali Linux
Database Development, ETL
Mobile Development – iOS, Android
eCommerce & Systems Development

About

Edward Galt (CISSP, CISA, CRISC, COBIT, ITIL, Advanced Penetration Training, HIPAA, PCI/DSS, ADA 508) is Vice President of Product Security at Epsilon, where his work focuses on driving AppSec programs that keep pace with modern, AI-assisted development. He has over 30 years of technology experience, beginning at Procter & Gamble as a Hardware Installation Technical Lead, where he later inspired P&G's first corporate intranet (Global Laundry) to solve an internal information-sharing problem — an early lesson in closing the gap between what a system can do and how well anyone can see it working.

That infrastructure experience led him into software development, starting in Visual Basic and expanding across both the Microsoft and Java ecosystems, a breadth he has maintained ever since by continually learning new languages and platforms as the industry evolves. Along the way he has built complex systems for organizations including Dinsmore & Schohl (one of the first legal case management systems), Protocol (data center and e-commerce development management), International Paper (xpedex.com), LexisNexis (TotalPatent, the world's largest patent search and analytics engine), and Garretson Resolution Group, where he served as Principal Architect maturing complex claims administration systems.

That range of experience — legal, insurance, paper, claims administration, and e-commerce — led him to found edwardGalt Technologies, LLC, and today shapes his focus on enterprise application security and, increasingly, on AI governance: building the inventory, identity, and accountability disciplines that let organizations adopt AI quickly without losing the ability to explain what it's doing and who is responsible for it. That focus is the subject of his book, Borrowed Trust: The Executive's Guide to Securing the AI-Driven Enterprise.

Contact Us

edwardGalt Technologies, LLC P: 513.578.2711

Information:Info@edwardgalt.com
Support:Support@edwardgalt.com