Go back

#344 Governing Pandora's Box: Managing AI Risks with Andrea Bonime-Blanc, CEO at GEC Risk Advisory

51m 22s

#344 Governing Pandora's Box: Managing AI Risks with Andrea Bonime-Blanc, CEO at GEC Risk Advisory

The discussion centers on the dual nature of generative AI's rapid advancement: its transformative potential and the significant governance risks it introduces. A primary concern is the failure to holistically manage both the upsides and downsides of AI, exacerbated by a cultural tension between aggressive innovation and excessive caution. Effective governance is presented as a comprehensive, organization-wide responsibility—a "360-degree" effort that must start with leadership and the board of directors setting a proactive tone. This involves integrating ethical considerations and risk management throughout the entire lifecycle of technology development, from inception to decommissioning. The concept of a "poly-risk" world underscores the complexity of modern threats, which are often interconnected across technology, geopolitics, and cybersecurity. To navigate this, organizations must foster continuous learning and implement adaptive structures, such as interdisciplinary risk teams, to identify and address emerging AI risks proactively. The conversation warns against waiting for a major safety disaster to trigger governance improvements, advocating instead for robust, preemptive measures including ethical testing, auditing, and fostering a culture where concerns can be raised without fear of retaliation.

Transcription

8627 Words, 48149 Characters

English
Generative AI is transforming industries at an unprecedented pace, but as AI changes how you or your team work, one thing is clear. Your skills also need to evolve. At DataCamp, we offer everything you or your team need to adapt and thrive with AI. Whether it's business users looking to get the most out of chat GPT and co-pilot or developers and data scientists looking to find two models, you can learn the entire AI skills spectrum on DataCamp. Power your AI transformation today. Start learning at DataCamp.com. We also have people leaving companies like OpenAI because they felt that the safety and the guardrails weren't very strong so they've gone to other organizations to create their own companies to put safety first and so we have not seen that safety disaster yet but we're going to see something and the moment we see that if it's big enough there'll be a rush to creating better governance and better risk management and better auditing and better red teaming and all this stuff that we talk about but that we don't always do. But you have to be discerning and I think that's really really important right now is there's so much garbage out there and so much slop and more and more of it being created every day by AI. So we need to be discerning a selective not be overwhelmed but also be open to understanding some of the other forces that are taking place in our in our society. Welcome to DataVramed. This is Richie. The rapid advances in AI are world changing. The technology is mostly improving the world but it also introduces new risks. Today we're looking at techniques for governing technological moving targets. The focus is naturally on AI but I'd also like to know how AI fits into the broader suite of exponential technologies like quantum physics and biotech. Our guest is Andrea Bonning-Blong. The CEO and founder at GEC Risk Advisory. She got 30 years of experience in technology ethics and compliance including stintzers in executive that Bertelsman and professorship at New York University. Andrea has just written governing Pandora, a book that forms the basis for today's show. Let's find out how to govern AI and other exponential technologies. Hi Andrea, welcome to the show. Thank you so much for having me Richie. I'm looking forward to our conversation. Yeah great to have you here. So I think over the last few years AI has been advancing incredibly rapidly. How do you. Well I guess first of all was the biggest risk you've seen from the rapid advances in AI. I think the biggest risk is that we're not keeping up with both the upside and the downside. So if people are not looking at the AI and tech risks in a holistic way, keeping up with it both in terms of advances and also downsides and making sure to protect and maintain sort of an equilibrium of sorts. That to me is a very big risk and unfortunately we have you know the very bleeding edge of tech change on the one hand which doesn't really care about the risks as much and then we have the overly cautious risk averse crowd that is trying to drag them down in the words of the accelerationists. Let's call them and so we have that tension between different kinds of functions in the pursuit of new technology and I think we have to have a more holistic and more balanced approach in general. Yeah I suppose both extremes are kind of problematic so if you just like going how we will adopt the latest technology we'll build the latest thing and not really worry about risks. That's a terrible idea because something bad is going to happen but also if you like okay we must do nothing because it could be dangerous then he overly cautious and you're not going to get those upsides from the benefit of that new technology. That's right. So I so I'm going to have a middle there's a state where you are creating new technology but governing it and again it seems like when technology is moving fast governance becomes a problem. How do you deal with that? I think governance has to be has to adapt as well to the the the the speed of change that we have and I like to call it the governance of change in the work that I do and in the book that I wrote we'll talk about it later but the governance of change means that we all have to have an attitude change we all have to adapt ourselves to the fact that change is going to happen and it's going to happen fast and it's going to happen in a multifaceted way and so if we as individuals professionals experts and our teams don't try to adapt to that we're going to lose and it goes back also to the leadership of organizations companies NGOs government agencies etc to really take the seriously and see it as something that will will slip out of their hands if they don't create a proper adaptive structure to deal with it. Okay so I like the idea that everyone kind of has a role in this from individuals through to sort of NGOs and government and I guess business leads as well. You said like if we don't take the seriously it might slip out of our hands so what happens then? Tell me give me a disaster story. Well we haven't seen a major disaster yet but we're hearing a lot of I would say small stories or stories that are sort of hidden beneath the surface that come out through whistleblowers maybe and others who are concerned about how some of the advancements that are being made with LLMs and and Gen AI are actually potentially very dangerous and so we have the red alerts that we sometimes hear about from the likes of open AI we also have people leaving companies like open AI because they felt that the safety and the guardrails weren't very strong so they've gone to other organizations to create their own companies to put safety first and so we have not seen that safety disaster yet but we're going to see something and the moment we see that if it's big enough they'll be a rush to creating better governance and better risk management and better auditing and better red teaming and all the stuff that that we talk about but that we don't always do and so we're in the in the Rara Rafa is of doing anything and everything and asking for forgiveness later and sadly I think the forgiveness piece will cost and it could be lives it could be money it could be you know safety of people and so we don't really know and I think that's why we need to have a holistic integrated approach to governance from the top down from the middle out and from the bottom up and people who are on the front lines of doing the IT the technology the testing the development they're on the cutting bleeding edge of all of this and they need to have help now not later when something bad goes wrong yeah so it just seems like a common thing is that you wait until somebody goes wrong and then that's the point where you start fixing things but obviously better to things before things go wrong and actually your opening example seems pretty pertinent like it seems fairly well talking to the spot the company has like to like a very divided culture so they've got all the people trying to ship stuff and they're doing that as fast as possible then you've got a separate safety team and they're like no no no no and occasionally someone from the safety team gets annoyed and leaves and I guess that's how an anthropic was formed as a company was people leaving the safety team starting again governance can sometimes like it doesn't have the cool image show it's hard to see like it's like it's the team that says no so it told me that like what is a good what's good governance like like what's the point bit like what happens when governance took those right yeah I think it really is a whole of organization effort it isn't just the board of directors or you know the tech governance around a specific technology it's a fully integrated holistic approach to governance and I mentioned before the the top down the middle out and the bottom up and I talk about that in my book governing Pandora in the sense that there's a chapter I talk called leadership and it's about the government 360 governance basically and by 360 I mean everybody has a piece of this but it takes the governance from the top to make it happen so if the board of directors or the CEO or the management team aren't really on this issue because they haven't had their disaster yet or their big risk come to fruition or anything like that then you're you're gonna have more of a lack of daisicle attitude on the part of the top and it'll only happen if there is that incident or that regulatory requirement that comes along you know something from the outside but it really I think it starts with leadership from the top and and the board of directors really getting that tech governance is a 360 effort and that you have to incentivize the rest of the organization to work in concert with each other to make sure that at the very fruition of the of the new algorithms or of bringing in data and looking at you know it's it's shape and content and so on and how it then becomes part of your own algorithm software program or have you that at that very very granular level we have not only the technology software developers and all that but some ethics folks who can sort of ask the what ifs they can test some of the stuff before it goes into the next stage and so it's kind of a life cycle approach to governance 360 is what I like to think about it it's everybody taking part of it it has to come from the top in the first place because otherwise it won't happen it'll happen in sporadic parts of an organization and then it has to be for the life cycle of the products and services that you're creating so from inception to termination or you know decommissioning of a product and having those people who are involved with the development, implementation, sale, troubleshooting, etc. Those people include some form of ethical experts, governance experts that can help troubleshoot some of the downsides of what's potentially going to happen. Okay, well, I think you name like a lot of different teams and roles in the basically everyone's going to do something. So I like that. So maybe, maybe start with the top them because you mentioned like this would come from leadership originally. So what's the role here? How do you go about setting like a government's vision or creating governance culture? I think the front line, top front line responsibilities always with the CEO or the president, the leader of the organization, to be tech and governance savvy enough to understand that the vision mission, values of the organization have to include some of this integrated tech governance. And again, you know, every company is a little different. If you're a pure technology company, like a Microsoft or an Anthropic, that's one thing. If you are in the auto business or food business or banking business, it's another. But I would say we're all technology companies. Now, there isn't a single company out there that isn't a technology company. So the degrees of how much technology you have to govern are going to be a little different perhaps. But everybody's using AI, everybody's using Gen AI, multiple other technologies that might be interconnected with the AI and with other robotics, automation, advanced materials, biotech, all this stuff is interconnected at the end of the day. So I go back to the CEO and the leader of the management piece of the organization to really set the right tone from a values and a mission and a vision standpoint. And then that has to trickle down into how human capital organizes the incentives around these things. It's not just about getting the software and the algorithms created and then deployed and sold. It's about how you're doing it. And so incentivizing the how, doing it ethically, responsibly, accountably, doing it in a way where you will test your products multiple different ways before you actually release them into the wild and to your customers. So it starts with the CEO and the management team, but there's that layer of the board of directors. And I kind of, I specialize in the governance piece at that level, but also how does it interlace with the rest of the organization? The board of directors usually lag behind what is necessary at the management front line piece. That's changing slowly but surely, but the point here is that the board of directors needs to have savvy people in it that understand the technology, the change are ready for that governance of chains and not just governance the old fashioned way, the traditional sit back. I sit on a board versus I serve on a board, you know, that those are things that are very important right now. You have to serve proactively on a board in order to get what's going on with technology and then adapt to what your company needs and be more visionary, more scenario oriented than you've ever been. So that's a responsibility at the board level, although the direct responsibility in my opinion is the CEO. This is interesting. I guess the board of directors, I know it's not you both my pay grades, I don't interact with a lot of them. So yeah, okay, this is interesting that the board needs to be actively educated then in order to have some kind of move back. Can you stop me through how that impact works then? Like, yeah, what do they do? You know, the board of directors is supposed to supervise, oversee, you know, the whole strategy of the company, the management of the company, hold the CEO and the top team accountable through performance metrics and incentives, make sure that the reputation of the organization is being protected and that, you know, that also there is a forward looking, where's the business going? I like to think of them as the strategic and culture guideers, right, for the organization. And if something's going wrong at the CEO level or at the management level, they're the ones who have to intervene and the chairperson of the board is usually the person that's most directly involved with the CEO. Leave aside the fact that in some companies, we have the dual role of chairman of the board and CEO in one person and that is not good governance in my opinion because it means that there isn't a check-in balance between the chair and the and the CEO. But so the the governance at that level has to be you need to select the right people to be on the board, not just the cronies, the friends and family of either the CEO or the chairperson, but people who are actually qualified to be overseeing a business of whatever tenor it is, right, if it's automotive, if it's robotics, if it's biotech, it doesn't really matter. But do you have the right people who understand the business, who understand the financial wherewithal and implications of the business? And then these other things like technology, like, you know, sustainability issues, issues that have to do with the long-term strategy of the business, and also crisis and risk management because we are living in what someone else termed a poly crisis world, which I think is a very good way to describe the world we're living in. And I've added a little little nuance to that I call it a poly risk world too because our risks are so complex right now with sort of the infusion of technology and other different things like, for example, a cyber risk in the Ukraine right now would be a geopolitical issue, a cyber or tech issue, it could also involve automated machines like drones, you know, those kind of, so it's kind of a complex multifaceted risk. So the people at the board have to understand these things and have to be continuous learners. This to me is the most important thing. We all have to be continuous learners, but the people who are the guiders of the organization and the people who hold supposedly the CEO accountable, those people have more responsibility than anyone to be continuous learners and to be ahead of the curve understanding benchmarking their own industry, but also the competitors beyond their own industry that might come into the frame. Okay, yeah, certainly I'm lost to take in and I like the idea of a poly risk world yet. I don't know whether it's just like there's more use and there's more awareness of like all the different things going on, but it just seemed like yeah, at any of the moment there's always like some kind of crisis somewhere or something about to happen. So yeah, certainly lots of uncertainty. Okay, so we talked about the board this evening. You also mentioned like a lot of different teams need to be involved in AI governance. So how do you implement that, I guess, technically within the organization like do you need a committee or is there another way of doing this? Yeah, great, great question. And I'll use an example that I implemented in a company where I was a senior executive. I was in charge of risk audit corporate responsibility and cyber. For the risk piece, we had sort of an interdisciplinary enterprise risk management team. We were publicly traded company. So we had to report quarterly and annually in those kinds of things. So we kept a very a full sum risk register and did surveys every year and collected information to inform our enterprise risk management posture, which then would go up to the management and the board. This team of people would meet every six weeks or so. And this team was about 14 people from all walks of life within the organization. It was a technology company. So we had we had very senior people like the general counsel and the chief financial officer, but we also had more sort of specialized junior people who were in charge of one risk, for example, export controls. So we had these people around the table every six weeks, reviewing the latest information coming out of the enterprise risk management exercise. Anything new that came up. So it was this coming together of multiple different minds and lenses around the risk profile of the organization. So to me, that's always been a great model to say, hey, and one other thing that we did actually is if we identified a new high impact, high likelihood risk, we would put what what we called at that point. Rapid deployment forces doesn't sound very kosher at this point, but you know, two or three people who actually understood or needed to understand that particular risk better. So if it was, you know, it was cyber, you would have an IT person there, you would have a risk person there and you would have a financial person there just to pull that out of a hat. And so those rapid deployment forces would then go and really study the issue and get to the bottom of the information that we had as a company and then come back and report back to the larger cost discipline. So to me, that is a really good model of how you learn about your risks and and stay on top of it to the best and you need all kinds of tools and information flow coming in of course, but then identify the risks and so the similar model can be used for AI risk, which is, you know, we have a multitude of AI risks out there. There's this wonderful repository that MIT keeps for anybody who's interested. It's the AI risk repository. It's free. It's online. It's constantly updated and it has just a vast wealth of resources, maybe too much. But for the host of us who are in the risk space or in the audit space, even in the technology space, it's a very useful place to go and see what the latest is. So someone who would be on either Robert deployment team or interdisciplinary team looking at AI would want to make use of those kinds of resources, also other resources that benchmark the industry perhaps on AI risk. And of course, looking at your own information that's percolating up through whether it's reporting audits, whistleblower reports, I mean, we go back to OpenAI. whistleblowering was not working well at OpenAI. And so there was a lot of no speak up because there was fear of retaliation. And so you need to have a robust speak up structure in your organization that allows you to speak up about these kinds of issues without fear of retaliation. And so that's all part of what I would say is you have to find the right structure for your organization. Every organization is a little different. The right people to populate a structure and make it a very agile, adaptable group of people who are really interested and can really find the resources they need to be able to inform the organization. So that's kind of what I would say is a great way to operationalize some of this, is to have those structures and people in place. OK, so yeah, certainly if you keep shooting the message here with this bad news, you're going to run out of messages pretty quickly. So I let the idea that you need to do that culture of being able to talk about risks in the central way. Now, you mentioned that you typically going to have like a very cross team initiative together. It's typically like 14 people or something from different groups, sort of, as an example sort of size. For within individual teams to live, particularly technical teams, like if you were a data team or you're like a product team or something like that, are there any particular roles around governance that you think people should be aware of, like, as you're building stuff? Absolutely. And we're all-- I'm sure familiar with the wealth of new AI-related roles that are rising, right? And so one of the things that I encourage, certainly, some of the younger people coming into the workforce and people who are traditionally were interested and have served in roles of ethics and compliance, regulatory affairs, those kinds of things. Those people traditionally have been working in silos over here while the technical people are over here doing their thing, right? And what I'm saying people have to do at the IT front line technical teams that are dealing with the data that's coming in or looking at the quality of the data or building the algorithms and the software. You need to have someone come in with a different set of lenses. And those lenses are more of ethics-- the ethics of what you're doing, questioning where the data's coming from, if it's quality, helping the technical team look at issues from more of an ethics, compliance, regulatory, and risk standpoint. So you want to have a few people like that peppered into the teams that are on the front lines at the very, very early inception of things so that that lens can come in at an early stage and you don't end up with Google Gemini putting out visuals of black presidents from the 19th century and things-- and much worse, of course, is much worse that's happened. But you don't want that sort of thing to happen. Maybe you can't prevent it entirely, but you have to make an important effort to think about those things early on so they don't spin out of control later. Absolutely. I do not have the idea of embedding like the skills and capabilities around governments in sort of frontline teams. Otherwise, you want to have that tricky situation where you separate government's team, the government's teams, then like the team that says no, because the other team's done something silly that could have been avoided before. And this is one of the biggest problems, I think, in any kind of organization, is jurisdictional battles. I spent 18 years as a senior executive at Fort Companies. And the jurisdictional battles-- if I'm general counsel, I have control over this. If I'm risk, I'm controlling that. If I'm CFO. And those kinds of jurisdictional battles are as natural as human nature issues are, right? But we have to try to overcome some of this. And again, that's why I keep going back to the CEO and to the board. They have to set the tone for culture that incentivizes the top managers and mid-level managers and others to work together. Because we're not going to solve these problems if we don't work together and cross functionally and cross disciplinaryly. Because these questions and these issues and these technologies are so complicated. And the implications of them are so unknown that we really need to come together to help find the way to a safe future. And not everybody lives in that world. I do. Yeah, I mean, certainly, I think particularly on a legal level. I mean, I've been in companies as well. There's always people arguing about what who's responsibility is this. And I guess I've been trying to pass the book or take ownership for something where maybe you should belong to someone else. OK, so maybe on this note, what do you think a responsible technology culture looks like within an organization? Well, I think it goes back to what I was saying a little earlier about the CEO and the management team typically set the vision, the mission, the values. And then those things, hopefully, are not just paper on a wall or 0s and 1s on a screen, but actual things that matter to that organization and that have operationalization through performance management, performance incentives, how do we do the work, not just get the work done, but how are we going to get it done ethically versus unethically or those kinds of things. So it always goes back to me to how the CEO and the management team characterize the use, the deployment, the integration of technology into the products and services of their company. And I mentioned earlier too that there is no company now that isn't a technology company. We all use all kinds of technology every day, whether it's computing, whether it's automation, all kinds of software and Genai and bots and communications tools. So all of us are using these things, and all of us are integrated with each other and using them. And so it's all based on technology. If something really goes bad, a data center goes down. Cloud is cyber-attacked, whatever. We feel the impact, even if we're manufacturing needles or something. So at the end of the day, how technology intersects with your products and services and how you're going to deal with that intersection has to come from the values of the company, from how the company does business. And the way it translates directly is through performance management. And the CEO and the board have to set the tone about the culture and to me, the most important crux of the matter. And it always has been this way, but it's even more now with technology moving so fast is you have to have a safe to speak up culture and a structured one so that it's not someone feeling like they have to hide and talk to somebody about something that they're really concerned about because there's a out of control AI in your software or something. You want to have process where you can go to someone where those people are identified as helpers, as resources. You also need to have an anonymous route to report some of these things if you're a bigger company or organization. And you have to feel that you're not going to be retaliated against because you did that, because sometimes that information comes out. And so people will leave, like they left open AI, for example, like you're picking on open AI, but they're like a very good post-a-child for a lot of these issues. You know, you look at some of these others and Thropik started from day one saying, we're going to be a big corp. We're going to have all the structures in place. We're going to cater to stakeholders, not just shareholders or owners. There's a different attitude that's reflected in each of these companies. And it's showing. And we'll see who ends up more successful in the longer run. I'm betting more on Thropik than I am on open AI to be very frank. But that's my personal opinion. Interesting. A spicy take. Yeah, we'll see how it plays out. OK. So I guess for organization to wanting to get better at this, it's kind of a big, nebulous thing doing government's better. What's like a practical first step? Yeah, I think it always goes back to being well informed and having good sources for your information, which is a whole other topic that we could be talking about, in this age of disinformation, misinformation, weaponized information, et cetera. So I think we have to pick and choose, but also be open to learning things that we maybe don't necessarily always go to. So be more open to reading reliable sources on technology issues, on ethics issues, on business issues. My go-to's, for example, are the financial times, the economist. And then there's a couple of really great newsletters that-- that are free from Axios and Semaphore on technology on AI. There's a run down AI, which is another great resource. These are things that each of us can easily subscribe to. If you don't want to pay money, there's a lot of available newsletters from like I said, Axios and Semaphore and run down. But you have to be discerning. And I think that's really, really important right now is don't. There's so much garbage out there and so much slop. And more and more of it being created every day by AI. So we need to be discerning, selective, not be overwhelmed, but also be open to understanding some of the other forces that are taking place in our society. And I'm a big student of and someone who's followed geopolitical and political issues very closely. In addition to being a lawyer in my earlier career, I have a PhD in political science. I'm very interested in geopolitics and international relations, democracy versus autocracy. These things help inform you what's going on if you're interested enough. And I'm an old fogey, but I was like this when I was a young fogey. So I think you have to be curious. And that's one of the most important things for this to do well in this world is to be curious. Continuous education, the open to understanding some other forces that are not necessarily part of your day-to-day job. And that's why I said the economist is a great resource or financial times, which it's a business newspaper, but it has better political reporting and international relations reporting than in my opinion almost anybody else. So that's what I would say. No, that is interesting that when you start thinking about risks, it's not just pure technology risk. You do need to think about like business racing, like what's going on in the world and just pay attention to trends and pay attention to the news. You know, the IT personnel that are on the front lines of cyber security issues. Hopefully they understand the larger picture of cyber and security worldwide, right? So they're busy every day battling the fishing scams and the ransomware and the this and the that. But they need to pan out every now and then and why are we being attacked and who is attacking us and where is it coming from and why is it happening like this and it may be criminal gangs, it may be national security, it may be something else. But knowing having that perspective I think is really important to doing a job well. Absolutely, yeah, I suppose I mean, yeah, cyber security is obviously very you very closely you've directed to geopolitics and like all this sort of nation state gang like hacking gangs or whatever. Yeah, yeah, I'm trying to think it with that also applies to AI things as well. I'm not sure whether there's a similar sort of. Well, it doesn't a very direct way in that now we have AI turbocharged cyber and security. So we have agents out there and others others deploying AI and then agentic AI really raising the scope and impact of cyber attacks and there's also the reverse, which is the defense part of the cyber attacks is also arming up with more agents to defend and that kind of thing. But it is it is warfare and it is an escalating attack and defense kind of matrix. I guess this is one way to put it. Those who are in that world really need to understand not only the technology piece of that, but also the larger context of geopolitics and international relations. Yeah, certainly like for all the cool stuff the AI brings is like having automated cyber security attacks is not great. Yeah, some different downsides as well. So certainly with that bearing mind. Okay, so I think it's worth to just on the relationship with governance and compliance because it seems like compliance regulations is an important part of this, but maybe it's not everything. Do you want to talk us through like what your approach would be here? Sure. You know, in my day I was in charge at the companies where I was an executive for the ethics and compliance program, which is a combination of ethics on the one hand is more values driven and you know, culture and that sort of thing and the compliance pieces, what are the laws that you need to comply with and let's make that the the bottom line fundamental thing that we do. And then depending on the industry that you're in, you are more or less regulated and of course banking, for example, healthcare, some of these industries are way more regulated than others. And so each company to organization has to have an integrated approach under governance to risk compliance and ethics. You know, different companies organize it differently. It doesn't really matter how you organize it as long as you actually organize it. So a lot of that comes under the jurisdiction of the general counsel, but it sometimes is organized in a different way depending on the company. To me, it doesn't really matter how you organize it as long as it works for your type of company, your footprint, the personnel that you have, your geographic, you know, scope, are you all over the world or are you just in a couple of places. That everything determines all those different criteria determine how your governance risk and compliance program has to look like. Now there's GRC, which people talk about a lot, which is sort of the the rubric that's existed for many years, to describe not the top level but the next level of governance within an organization. And you usually would have a compliance head or a general counsel into which compliance reports, again, depending on the footprint of your organization. And so the important thing is having the right people in the right places and having the right coordination. I don't care what you call it if it's GRC, ENC, regulatory affairs, but it does have a very major legal component. So you want to have your GC or your legal department very much involved with that, whether they actually control it or someone else does because there's a chief compliance officer as well. So again, it's about the topic and how you organize to satisfy the needs of regulators and legal compliance, etc. Okay. Yeah, that's a fascinating story there. So I guess you mentioned risks and governance and compliance is being sort of three separate but related thing. Yeah. And just to put a little extra nuance on that, the risk piece is often a separate piece that is enterprise risk management and you have a chief risk officer who doesn't report to the jailcounsel is an independent or part of the panorama of functions, but hopefully is coordinating closely with the GC and his or her team. And again, depending on how things are organized, you might have a chief risk officer and an enterprise risk management program or you might not, which is a problem for bigger companies and even complex medium-sized companies. You always want to have some form of risk management that is independent from compliance and governance, but actually integrated somehow in terms of informing them for purposes of governance and compliance issues. Chief risk officer sounds like a cool job, though. It's like the kind of person who parachutes into the office or something. A sexy version of the chief risk officer. There's a very unsexy virtue to or you're plowing through information and trying to find the right nuggets that will inform your superiors and management and the board. So there's a it's nice. Not quite as James Bond that much. All right, so for anyone who's sort of interested in governance, like an arantica of skills, you think are important to learn. Some fundamental building blocks for governance is being expert in one of several different areas. It could be technology. It could be ethics and compliance. It could be risk. And so I think having having the sort of the rigor and the discipline that comes with being an expert in one of those areas or multiple areas is always a good foundation for governance. Now governance, at the end of the dates, how you define it and what are you talking about? It's always context-driven. So governance, risk and compliance is a functional group sometimes governance on its own is usually references the board of directors. And so there you have either the general council or corporate secretary that helps with the governance agenda, caters to the board of directors, organizes the meetings, yada yada yada. So that's governance in a different sense. And then there's sort of the 360 governance that I reference in my work, which is integrating all those different things in a way that you have pieces of governance at the front lines, at the IT and technology people understand and deploy with the help of other experts. For example, maybe an ethical AI expert. And then you have management in the middle, integrating that into how they manage, how they do the performance management, the incentives. And then the top of the house, really thinking through the big strategic picture and then helping to create the tactical pieces that go into the rest of the organization. Okay, I should probably guess before I ask that like this stuff you need to learn depends a lot on what you roll this. But just how like there's a big mix then. So there's some technical skills, there's some legal skills, there's some management skills in spite of being able to like communicate and plan things. and make sure it sort of gets implemented within your organization. Now, I'd love to go back to this idea of polyrisk. And one of my favorite things about your book was you put AI as being just one new technology amongst several that are having big impacts on the world. Do you want to talk us through all the other bits that weren't AI? Sure. So when I started writing, so I'll give you a little bit of the genesis of why I wrote the book. I wrote an article, I'm always writing because writing to me is learning. And then once I learned something, I can help educate others. So that's kind of the method to my madness. So I wrote a piece back two years ago for an initiative Directorship Magazine called the governance of exponential technology, something along those lines. And it was basically looking at the phenomenon of Genai, which was about a year old in terms of the public, you know, of all of us learning about chat, and so on, that, but also looking at how the Genai phenomenon was also interconnecting with a bunch of other technologies. I'm thinking of biotechnologies, synthetic bio, automation robotics, all these things, advanced materials, of course, because the more powerful the GPUs and the silicon that's being created for compute, the more we can do. So I was fascinated by the fact that this isn't just about Genai. It's about everything else that's happening in the ecosystem of technology. And one isn't affecting the other and interacting with the other and new things are being created, et cetera, et cetera. So I was fascinated by that. I got an invitation to put a proposal together for a book based on that article and that was ended up being governing Pandora with Georgetown University Press. And so when I started strategizing the book, I felt that I first had to start with context. So I talk about that geopolitical context in which, you know, the technology is flourishing. But in the second part of the book is where I wanted to do what I call a whirlwind tour of exponential technologies. And I spend a lot of time figuring out what are those technologies I want to talk about, because I'm not a technologist. I'm not an engineer. I'm not a mathematician. So I can't really explain them from a pure scientific standpoint. And I chose these five. So Genai, I was one biotech synthetic bio was another automation robotics. You know, anything from killer robots to smart cities, all that kind of stuff. Then of course, I looked at frontier computing, including quantum and a bunch of others. Those are the five categories that I figured, okay, this is not exhaustive. There's other things out there. There's energy. There's communications. But I can't do everything. What I'm trying to do is create a mindset for people to start thinking about this is all part of our lives. Our individual personal professional community, national international lives. And we need to get informed at least at a certain level. So I try to do like a, you know, a primer on each so that we all get sensitized to what's going on. And then I go on to other things in the book. But that's those are the five categories of technology. I felt are exponential in the sense that they're moving really fast. They're becoming cheaper to acquire. They're dangerous. They're fantastic. You know, they're everything. I do. Yeah. I mean, I have to say there's so many like cool technology sort of in progress at the moment. So actually of those is the something you're really excited about. Like what do you think is going to be really impactful or very cool in the next couple of years? Well, this, this is kind of a mixed message, but climate tech is moving great guns forward in all kinds of ways. And the solar piece of it is already very well known. And there was a piece actually in the economist last year talking about how solar. It was a cover story. Solar is the exponential technology that is going to be the most impactful of all. Because it's getting cheaper. It's getting easier to do and so on. And we have sun, you know, so sun and batteries and all these things that allow it to happen. But then politics interferes with that right geopolitics, international relations interferes with that. But to me, climate tech continues to move forward a pace even with a change in administration in the US where climate tech or, you know, sustainability or ESG no longer is part of the dialogue. Although it is under the under the surface in a big way, in my opinion, and technologists and inventors and innovators are going to continue to innovate. And so a lot of innovation is taking place in the climate tech piece, which I think could have an amazing impact if we get rid of some of the political noise, you know, the geopolitical noise. Meanwhile, China is doing fantastically with all of these technologies and, you know, first of all, they control solar, but they are making incredible progress with a whole variety of things, batteries, you know, electric vehicles. And they will own the climate tech world at some point, although there will be others in other parts of the world too. But that will help save, I hope, the planet from too much heating that then leads to all kinds of dire and terrible consequences for humanity, for biodiversity, it's on. So I'm the most excited about seeing that come to fruition over time. It's not going to be today or tomorrow, but that would be it. Yeah, I mean, that's a very exciting thing. I mean, like, well, first of all, like, not burning the planet, bringing it outcome. But in general, it's a happy story. I suppose maybe the common theme is like the technologies, maybe the easy part and it's the people in process is the road to the challenge. I actually wrote a piece about that recently about how, what did I call it? Climate tech is alive and well. And the planetary governance, not so much. That's the title of the piece that I wrote a couple of months ago for diplomatic career. And it's about this idea that people are inventing, innovating, doing fantastic things all over the world, frankly. But it's the politics of no of maybe of not making a decision of the COP 30, for example, got nothing done, basically. You know, that's an oversimplification. But if you don't have the most powerful countries in the world and then many others talking together about how to do things, we end up with atrophy, or theory or sclerosis. That's what you want to call it. But I think that might hopefully shake out over time with different administrations and political will. I don't know. My hope in this is that I mean, you mentioned soil technology and climate technology is getting more cheaper. The economics generally provide a persuasive argument. So hopefully you want to. Right. Exactly. That's what I keep saying is, people are in business to make money. But in order to make money sometimes, not sometimes. Most of the time, you need good data information. You know, the heating of the earth, we now have, I believe 2025 is the second hottest year on record after 2023 and 2024 wasn't so good either. The last 12 years have been the hottest years in client on in terms of the heating of the earth on record in the record started in 1850, I believe. So, you know, data speaks, right? Absolutely. That's what slogan for the show. Exactly. Data speaks and burning burning woods and boiling oceans and rising, you know, flooding flooding and fires. We're all feeling it one way or another. Some parts of the world much worse than some others. But we're all feeling it. Yeah. So I mean, some challenges, but I'm above again. We're going to be positive that the problems will be solved. All right. Super. So just finish with I always want you people to follow. So whose work are you most excited about at the moment? Yes. So I'm going to pick a couple of a couple of different organizations that I think are doing. Anthropic, first of all, I think is doing really good work in combining good governance and ethics with innovation. And they've announced that they're going to do, you know, a public offering at some point. I always look at the leaders who are the leaders and are they setting the right tone and Darius, I'm a day there is has been setting the right tone. And he's been speaking up when others don't and others are fearful or others are just, you know, playing to the current administration. So I really like the tone that he's setting combining safety, the governance with the innovation. So he's someone I would be following and their company as well. Mustafa Suleiman, who's the head of AI for Microsoft and previously co founder of DeepMind and an AI basically an AI genius. He's heading up Microsoft and he put out a blog just a week or two ago about how. And so I think there again and Microsoft has a history of thinking about the governance and the ethics of AI. Nobody's perfect. So I don't want to say, oh, you know, let's go pray at their temple. But I think they've set the right tone compared to some other companies. And the other category of not setting the right tone terms of ethics and responsibility. So I would follow Mustafa Suleiman, what he's doing at Microsoft. And then there are several other players I call the tech guardians of the universe as opposed to the tech masters of the universe in my book. Guardians are organizations all over the world. sometimes international organizations like UNESCO or the UN, other times independent NGOs or international kinds of organizations like the Africa AI Observatory for example and Center for Human Technology. There's a whole bunch of future of life. These people are really focused on the safety, the ethics, the responsibility, the accountability and I would say people should follow one or more of those organizations and see what they have to say about the issues that are coming before us in a tsunami of information. I do not have that idea of just following some of these organizations who are involved in the responsibility AI accountability because yeah that's another signal that doesn't get quite as much noise as maybe some of these technoliders like you're a CEO of an AI company you get a lot of attention but some of these other organizations maybe as little more in the background but definitely a lot of them. Great, wonderful. Thank you, some true time, Andrea. Oh thank you Richie for the great conversation, I really appreciate it.

Podcast Summary

Key Points:

  1. Generative AI is rapidly transforming industries, necessitating skill evolution, with platforms like DataCamp offering AI training.
  2. The rapid advancement of AI introduces significant risks, including a lack of holistic governance and a cultural divide between rapid innovation and safety concerns.
  3. Effective governance requires a 360-degree, organization-wide approach involving leadership, boards, and cross-functional teams to proactively manage risks throughout a technology's lifecycle.
  4. A "poly-risk" world demands continuous learning and adaptive governance structures, such as interdisciplinary risk teams, to address complex, interconnected technological threats.
  5. Proactive measures, including ethical integration, robust testing, and strong speak-up cultures, are essential to prevent disasters rather than reacting after failures occur.

Summary:

The discussion centers on the dual nature of generative AI's rapid advancement: its transformative potential and the significant governance risks it introduces. A primary concern is the failure to holistically manage both the upsides and downsides of AI, exacerbated by a cultural tension between aggressive innovation and excessive caution. Effective governance is presented as a comprehensive, organization-wide responsibility—a "360-degree" effort that must start with leadership and the board of directors setting a proactive tone.

This involves integrating ethical considerations and risk management throughout the entire lifecycle of technology development, from inception to decommissioning. The concept of a "poly-risk" world underscores the complexity of modern threats, which are often interconnected across technology, geopolitics, and cybersecurity. To navigate this, organizations must foster continuous learning and implement adaptive structures, such as interdisciplinary risk teams, to identify and address emerging AI risks proactively.

The conversation warns against waiting for a major safety disaster to trigger governance improvements, advocating instead for robust, preemptive measures including ethical testing, auditing, and fostering a culture where concerns can be raised without fear of retaliation.

FAQs

Individuals and teams need to continuously evolve their skills through learning platforms like DataCamp, which offers courses across the entire AI skills spectrum, from business applications to advanced development.

The biggest risk is failing to holistically manage both the upsides and downsides of AI, leading to a lack of governance and potential safety disasters. This includes not keeping pace with technological changes and their ethical implications.

Governance of change means adapting governance structures to the speed of technological advancements. It requires everyone from individuals to organizations to proactively manage risks and opportunities, preventing issues from slipping out of control.

Organizations should adopt a holistic, 360-degree approach involving leadership, interdisciplinary teams, and ethical experts throughout the product lifecycle. This includes setting a governance vision from the top and incentivizing responsible practices.

CEOs must set a tech-savvy governance vision, while boards need to oversee strategy, ensure accountability, and be continuous learners to understand complex risks. Both are crucial for integrating governance into the organization's culture.

AI risks are interconnected with other complex issues like geopolitics, cybersecurity, and biotech, creating multifaceted challenges. Governance must address these interdependencies to manage crises effectively.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.