Digital Content Editor, Eve Goode speaks exclusively with Nan Hao Maguire, CISO at foodora, foodpanda and Yekmeksepeti about AI, data exposure and security blind spots.
Can you tell me about foodora, its role within the industry and a bit about your role at the company?
foodora is one of the leading delivery platforms in Europe, it operates across Northern and Central Europe, including Sweden, Norway, Austria, Czechia and Hungary.
We connect customers with businesses and ensure a convenient discovery and delivery experiences.
Over time, foodora has grown beyond just food delivery into a broader local commerce platform, supporting grocery and everyday retail delivery while continuing to invest in technology, logistics and operational innovation.
In many of its markets, foodora has become a well-recognised part of the local digital ecosystem and plays a meaningful role in how customers access everyday services and merchants reach their communities.
As the CISO, I don’t simply see foodora as “a food delivery app,” I see a complex digital ecosystem, one that operates as a borderless marketplace, a high-frequency logistics and quick-commerce network with a large-scale consumer data platform across multiple markets.
My role is to help secure the engine that connects the users to their everyday essentials, while ensuring the broader commerce and operational ecosystem remains resilient, trusted and able to scale securely.
Where have traditional security models fallen short in supporting AI?
Traditional security models have often struggled to keep up with AI because they were built for more predictable systems, structured software lifecycles and clearly defined data boundaries, not fast-moving, autonomous and constantly evolving technologies.
In many organisations, security has traditionally relied on centralised approvals, governance gates and manual review processes that simply move too slowly for modern AI development, where experimentation, model iteration and continuous deployment happen rapidly.
At the same time, most traditional security frameworks were designed to protect infrastructure and applications, not address newer AI-specific risks such as model integrity, training data exposure, prompt injection, autonomous behaviour or AI supply chain dependencies.
Security can no longer be seen as the function that slows AI adoption.
My role is to enable foodora to adopt and scale AI faster, safer and more responsibly than the competition.
For platforms like foodora, effective AI governance is not just about risk reduction, it is also a driver of operational efficiency, customer trust and long-term profitability.
We must evolve beyond a traditional security mindset into a strategic growth partner, bringing together platform resilience, fraud prevention, data protection and AI-driven innovation as part of a unified competitive advantage.
How do you enable secure cross-team collaboration without increasing data exposure risks?
I approach cross-team collaboration as a partnership rather than a compliance mandate.
Secure collaboration is not really a trade-off between accessibility and control, it is fundamentally an architectural challenge.
My approach is to move security away from traditional gatekeeping and instead embed it directly into developer workflows through clear data classification, secure-by-design platforms and practical automated guardrails.
The goal is to enable teams to move quickly and collaborate autonomously, while ensuring the most efficient path is also the most secure one, reducing friction without increasing unnecessary data exposure risks.
How do you balance rapid AI deployment with strong security and compliance requirements?
I believe the key to balancing rapid AI deployment with strong security and compliance is embedding security and governance directly into the engineering workflow, rather than treating them as separate approval gates.
In fast-moving AI environments, manual processes quickly become bottlenecks.
By implementing automated guardrails and secure-by-design frameworks in place, we enable teams to move quickly and autonomously while proactively managing risks around data exposure, compliance and responsible AI use.
Security works best when it is seamlessly built into how teams design, build and ship, not when it sits outside the process as a control that slows innovation.
How do you avoid security blind spots when AI ownership is distributed across teams?
Managing security in a distributed AI model means I have to move away from fragmented, team-by-team governance and focus instead on creating a consistent baseline that works across the organisation.
My preference is to standardise the key controls around data access and model deployment embedding them directly into the developer experience so they become a natural part of how teams build.
By combining this with real-time visibility and security patterns built into everyday workflows, I aim to ensure every team has the same level of awareness and accountability, regardless of where the AI work is happening.
Looking ahead, what advice would you give to organisations building a future-ready AI security and governance framework?
My advice is to treat AI security and governance as something that’s built into the engineering system from the start, not as a separate layer that slows things down later.
I’ve seen that organisations that get this right embed clear baseline guardrails directly into data, model and deployment workflows, so teams can move fast without constantly waiting for central approvals.
I also think it’s critical to build visibility and accountability into the system itself, so risks and usage aren’t something you only discover after the fact.
Ultimately, it’s about creating an environment where teams can innovate with AI confidently because safety, compliance and responsibility are already part of how they work every day.