
SecurityCafe — Andreas Wuchner: AI, the boardroom, and the bill nobody budgeted for
Andreas Wuchner ran large-scale security organisations for some 30 years and now invests in and advises startups, family offices, VC and PE firms. On geopolitical risk, AI governance, and what AI actually costs. Chapters 00:00 — Welcome 01:00 — In the news: 900+ agents coordinating over a shared channel 05:07 — Geopolitical risk is real, and NIST/ISO don't map it 07:39 — The CybersecNL keynote: is what we built still good enough? 11:40 — "What brings you in jail is non-compliance" 13:00 — The AI governance tooling wave 14:44 — Punish vs enable: pocket money for Big Tech kills a startup 16:53 — The minimum viable control set 17:43 — Fines: where does that money actually go? 22:50 — What AI means for the business, from a board seat 26:30 — Three types of adopters, and AI-native hiring in seven days 32:04 — "Meat proxies": what the AI-native crowd calls the rest of us 34:47 — AI is not cheap: what a €200 subscription really costs 37:10 — $20 per run vs $2.84, same job 39:22 — Outsourcing efficiency promises vs rising AI costs 41:44 — Augmentation vs a greenfield agentic machine room 43:43 — Cooling, solar, subsea, space: the infrastructure race 47:19 — What to read, what to watch Key takeaways A policy keeps you out of jail — and that's all it does. Regulators ask for governance; many tick that box with a document. Anyone declaring AI governance "done" is at the beginning. Define the non-negotiables, then get out of the way. The organisations doing this well name 10 to 50 controls that are not up for discussion and let the rest develop over time — a minimum viable control set. The alternative is the department of no. Token economics is a skill, not a budget line. The same investment-document analysis ran at roughly $20 per company; converting inputs to markdown first brought it to $2.84. A week-long AI strategy course for managers does nothing for the layer that spends the money. Mentioned Log Force — a project in Spain predicting indicators of compromise before they become threats, and spotting when agentic systems start hallucinating. Not a commercial product yet. Tehran — the espionage series from What to Watch Uber's €824,990,000 fine from the Dutch DPA for fully automated driver deactivation, under GDPR Article 22: https://www.autoriteitpersoonsgegevens.nl/en/current/uber-fined-nearly-825-million-euros-for-automated-driver-blocking The Odido breach (February 2026): some 6.4 million people and 600,000 companies, including over 5 million ID document numbers. https://nos.nl/artikel/2604461-odido-hackers-publiceren-resterende-klantdata-ook-miljoenen-id-nummers Meta's settlement over harm to minors: up to $17.1 billion, with 52 US attorneys general — not an EU case. https://www.npr.org/2026/08/26/nx-s1-5944781/meta-settlement-child-safety-lawsuit Powered by Atos
- Transcript












