Uploaded August 2026 | Updated September 2026, 6 hours ago
Eric Zielinski (Jumpmind, US)
Security leaders face an impossible mandate: deploy AI everywhere while remaining accountable when it fails. Today's AI systems make security consequential decisions, triaging alerts, blocking policy violations, evaluating access requests, yet we cannot explain how those decisions are made. We're running unauditable security controls.
Recent advances in circuit sparsity offer a path forward. By forcing most of a model's weights to zero, researchers have shown that the remaining connections form small, interpretable circuits implementing identifiable algorithms: a "string closer," a "bracket counter," a "variable type tracker." These aren't abstractions, they're the actual computational mechanisms we can now inspect, test, and harden.
This session translates circuit sparsity research into practical security engineering. We'll examine real circuit examples, including one with a built in vulnerability exploitable through targeted adversarial inputs. We'll map interpretability to AI threat models, showing how attackers probe for decision boundaries and how defenders can get ahead.
Finally, we'll cover concrete applications: treating interpretability as a security control, building circuit informed red team methodologies, establishing AI security KPIs around circuit stability, and raising the bar for vendor transparency. To equip defenders with the tools to act on this, we'll also introduce CIRCUIT, a new open source framework for AI interpretability risk management, built specifically for the security community. The goal isn't interpretability for its own sake. It's shifting AI security from "trust the accuracy metrics" to "show me the control logic and prove it's defensible.
---
Eric Zielinski is Chief Information Security Officer at Jumpmind, where he navigates the challenge at the heart of this talk: deploying AI to accelerate security while remaining accountable when those systems fail. With over two decades of cybersecurity leadership across Fortune 100 enterprises, financial services, and cloud-native SaaS platforms, he has built programs that treat AI governance as a security engineering problem, not a compliance checkbox.
As Director of AI and Cloud Security at OCC, Eric led efforts aligning generative AI governance with regulatory and enterprise risk frameworks, giving him firsthand experience with the "show me how this model makes decisions" questions now coming from regulators and boards. Previously, as CISO at Dizzion, he scaled security programs balancing innovation velocity with resilience.
Eric is a frequent speaker at industry conferences including several FIRST events, FS-ISAC, and many others, presenting on topics including securing generative AI and embedding cyber resilience in high-velocity development pipelines. He holds a Master's from Carnegie Mellon and founded Cyber Pathways, a career development initiative mentoring the next generation of cyber talent.
Eric Zielinski (Jumpmind, US)
Security leaders face an impossible mandate: deploy AI everywhere while remaining accountable when it fails. Today's AI systems make security consequential decisions, triaging alerts, blocking policy violations, evaluating access requests, yet we cannot explain how those decisions are made. We're running unauditable security controls.
Recent advances in circuit sparsity offer a path forward. By forcing most of a model's weights to zero, researchers have shown that the remaining connections form small, interpretable circuits implementing identifiable algorithms: a "string closer," a "bracket counter," a "variable type tracker." These aren't abstractions, they're the actual computational mechanisms we can now inspect, test, and harden.
This session translates circuit sparsity research into practical security engineering. We'll examine real circuit examples, including one with a built in vulnerability exploitable through targeted adversarial inputs. We'll map interpretability to AI threat models, showing how attackers probe for decision boundaries and how defenders can get ahead.
Finally, we'll cover concrete applications: treating interpretability as a security control, building circuit informed red team methodologies, establishing AI security KPIs around circuit stability, and raising the bar for vendor transparency. To equip defenders with the tools to act on this, we'll also introduce CIRCUIT, a new open source framework for AI interpretability risk management, built specifically for the security community. The goal isn't interpretability for its own sake. It's shifting AI security from "trust the accuracy metrics" to "show me the control logic and prove it's defensible.
---
Eric Zielinski is Chief Information Security Officer at Jumpmind, where he navigates the challenge at the heart of this talk: deploying AI to accelerate security while remaining accountable when those systems fail. With over two decades of cybersecurity leadership across Fortune 100 enterprises, financial services, and cloud-native SaaS platforms, he has built programs that treat AI governance as a security engineering problem, not a compliance checkbox.
As Director of AI and Cloud Security at OCC, Eric led efforts aligning generative AI governance with regulatory and enterprise risk frameworks, giving him firsthand experience with the "show me how this model makes decisions" questions now coming from regulators and boards. Previously, as CISO at Dizzion, he scaled security programs balancing innovation velocity with resilience.
Eric is a frequent speaker at industry conferences including several FIRST events, FS-ISAC, and many others, presenting on topics including securing generative AI and embedding cyber resilience in high-velocity development pipelines. He holds a Master's from Carnegie Mellon and founded Cyber Pathways, a career development initiative mentoring the next generation of cyber talent.










