As a modern CTO, it should probably come as no big surprise that I’m an optimist on the innovative prospects of artificial intelligence (AI). But I’ve been in this career for a long time, and that optimism is tempered with experience.
I’ve seen enough emerging technology patterns to know that it always takes a lot more time and resources than people think to evolve innovative technologies beyond their final barriers.
One helpful prioritization technique as an effective CTO is finding those situations where the technology can still deliver value even as those challenges are being figured out.
So, the question is how do we take advantage of what we have now with AI advancement and how do we get ready for what we’re going to get later once the AI barriers start to drop?
At Bitsight we’ve been working on this question for years now—even before the big GenAI boom started to explode in early 2022.
Bitsight is a company born and bred in the ethos of risk management and governance. So, our approach to AI from the start has been to apply appropriate oversight and governance frameworks around *how* and *when* specific types of AI are used. This has allowed us to move forward with trustworthy and purposeful AI for every appropriate use case without ever compromising the integrity of our products or the security posture of our customers or company.
As we’ve applied governance to the process of vetting AI technology and use cases, the following are some of the lessons we’ve learned.
1. Data security is paramount
One of the main concerns about AI from the beginning from me and others is that in many implementations of LLMs and other models, the way that they interact with data could easily cause data leakage. We needed to vet technology and AI models to figure out where it was safe to put data in and where it wasn’t.
Proper governance required us to essentially build a data classification policy first. Once we build the data classification policy, then we could say, okay, now that can help guide and govern all these different things that people want to do. For example, if the information's public or it's going to be a blog post, go ahead and put it wherever you want. But if this is something more company confidential or customer data, we have to have a very different view on the security of that.
First and foremost, we want to make sure we protect all data relating to customers and that we're not really doing anything with customers that would threaten their data.
2. Approach AI governance as a team sport
As we started to formalize our approach, my colleagues and I implicitly understood that governance needed to be the common denominator for every use case where our business wanted to apply AI. We also recognized that if we were going to square rapid adoption with effective decision-making about how AI is used, we’d need to approach AI governance as a team sport.
We’d need collaboration that crossed all departmental and org-chart boundaries if we were going to create meaningful but functional policies. At the same time, we also strived to create a system that was lightweight and wasn’t so complicated that it sapped productivity and forward motion. We didn’t want the governance framework to keep us from rapidly adopting AI innovations that lined up with our risk appetite.
What we’ve come up with has worked very well to strike that balance. We’ve created a company-wide AI council that’s the central clearinghouse for AI decisioning. The point of the council isn’t to think of AI ideas or to squash them, either. The point is to have a room full of different thinkers to understand what customers and team members want to do with AI, consider the risks from a lot of different angles, and help guide them toward a path that does not limit their creativity and allows them to achieve their goals in a way that’s aligned with our policies.
I’m on the council and so is our chief risk officer, chief innovation officer, CISO, field CISO, stakeholders from engineering, lead AI engineer, general counsel and operational counsel, and even someone who is in marketing. The council developed our initial AI policy and continues to shepherd it as the AI landscape evolves.
When my team or anyone else in the business wants to bring a new use case to the company, they submit it to the council through a ticketing system that we’re regularly reviewing. If it fits with existing policy, we approve it right away. If it doesn’t fit but causes us to update the policy, then we update it—the policy is user facing so everyone in the company has access. And if it doesn’t fit with policy and doesn’t warrant a change we will offer our concerns and potential recommendations or action items that could help it work instead.