AI Governance Is Just Like Driving A Race Car
By Katie Anderson, Chief Editor, Pharmaceutical Online

Though some skeptics remain, nearly every business is at some stage of AI adoption. The technology has proven applications in pharmaceutical manufacturing, but effective governance must keep pace with its rapid development. That challenge is familiar to Bill Reid, healthcare and life sciences lead in Google’s Chief Information Security Office (CISO).
At his presentation at ISPE’s AI in Life Sciences Conference, Reid explained the framework for keeping information safe when technology moves at lightening speeds. “People are concerned about whether you are moving fast enough to adopt these technologies. As a security professional, I have to think about how we are going to govern them in a particular fashion,” he explained. Using an Formula 1 racing metaphor, Reid outlined just how effectively AI can be governed at real-time speeds.
Reid started his presentation by talking about the concept of “validated agility.” “What we face is a bit of a challenge of how we are going to balance both the requirements for validated processes and yet maintaining the agility to move quickly at the rate we ought to with to AI.”
The Downforce of AI Security
For F1 cars to maintain their speed and safety during racing, they must have a significant downforce to keep the car safely on the track. He likened this downforce to security with AI usage.
“I am going to propose we think about security as a downforce that helps us stay grounded. Security is the downforce of AI innovation in life sciences. It is a foundational force that we need to have to stay on the track. We need to have confidence at high velocity,” he explained.
orF1 engineers spend considerable time creating the right amount of downforce. Reid connected that work to AI security: “With security controls, we want to have that downforce to keep our ability to stay grounded in the use of these technologies,” he said. The process begins with threat modeling, or assessing risk before determining the appropriate controls.
They ask: What are you trying to accomplish? What threats could affect that goal? Which technical controls or countermeasures are appropriate? And how will you measure the resulting telemetry?
“We are watching them and going to detect behavior changes. We want to maintain it in control. We have control boundaries. That is the beginning of what we do to build that downforce,” added Reid.
As AI produces software at high speed, it can remove traditional development constraints. According to Reid, however, that increased velocity does not eliminate the need to meet regulatory rigor.
Pumping the Brakes With AI Governance
Cyber security and AI governance is needed, but users need to understand why. Reid explained that there is a common notion that cyber security is the “office of no.” He continued, “What happens when you are the office of no is people don’t tell you things.” This of course leads to problems. Reid mentioned shadow AI, continuing that when you deny people access to the technologies but require them to innovate at the speed of others, they use the technologies and don’t tell you. The results can be IP leakage, security risks and more. To use these tools in a safe way, you need AI governance, or brakes in our F1 racing metaphor.
Reid continued, “Brakes are for going faster. If they are engineered for performance, you are going to have confidence in your turns. What governance of AI does is support the ability of AI to move quickly, like brakes in a car. It allows us to have safe exploration because it is well-governed.”
Google has introduced its Secure AI Framework (SAIF) to identify, manage, and prevent AI threats. It begins with a strong security foundation and uses AI to detect and respond to threats. Defenses are automated to keep pace with emerging and existing risks, platform-level controls support consistent security postures, and mitigation strategies create faster feedback loops. AI system risks are then mapped across the business process, including the application, model, infrastructure, and data, to help users diagnose problems. Reid said SAIF mapping translates risk into action, providing both assurance and governance. He also noted that the U.S. Food and Drug Administration has an AI credibility framework built on similar concepts. “SAIF provides the technical bridge to FDA compliance by ensuring reproducibility in automated processes,” he explained. A model registry supports traceability of each model iteration for regulatory audits, batch reproducibility provides automated checks for AI-driven synthesis, and model protection helps prevent manufacturing prompts from being compromised by injection attacks or drift.
The Pit Wall’s Continuous Communication
Those not familiar in F1 racing probably don’t know about the function of a pit wall. It is the command center where engineers, team leads and other managers monitor data on the car to make fast decisions and communicate them to the driver. It is continuous monitoring and telemetry, or real time detection and oversight. “The pit wall provides dynamic oversight, or the ability to see variation very early as quick as I possibly can. I can only do it if I have great sensing and great processing. We have to have that dynamic oversight in AI,” added Reid.
AI governance allows teams to constantly monitor their AI for any risks or changes. “Continuous monitoring identifies performance degradation as real-world data shifts,” explained Reid.
Just like F1 racing wants confidentiality in its engineering, AI governance must also protect sensitive information. Reid explained, “We have to apply the right type of controls to do that.”
Innovation At A Fast Pace
Reid’s racecar metaphor makes the message clear: effective AI governance is not about slowing innovation but enabling it to move faster with confidence. Security provides the downforce that keeps AI grounded, governance supplies the brakes for safe exploration, and continuous monitoring serves as the pit wall that detects problems early. For life sciences companies balancing rapid adoption with regulatory rigor, these controls are what make validated agility possible—and what keep AI innovation safely on track.