Go back

Patrick Sullivan On The Rise Of AI Certification

42m 17s

Patrick Sullivan On The Rise Of AI Certification

In this episode of the AI Standards Stack, hosts Michael Minnelli and Adam Smith interview Patrick Sullivan, Vice President of Strategy and Innovation at A-Lign, a cybersecurity audit and certification firm. Sullivan explains that ISO 42001, released in December 2023, is a management system standard for AI lifecycle governance, often confused with AI security or a direct compliance tool for the EU AI Act. He emphasizes that while ISO 42001 is not a substitute for high-risk AI system requirements under the AI Act, it serves as a critical foundation for organizations to build risk management practices and meet market expectations. The standard's adoption is surging, with accredited certifications up 1800%, driven by major enterprises like Microsoft and Oracle demanding it from their supply chains. Sullivan highlights a key case where ISO 42001 certification enabled a synthetic media startup to secure over a billion dollars in investment. In the US, AI governance is market-driven, with states like Texas and Colorado using standards compliance for legal defenses or transparency, contrasting with Europe's regulatory approach. Sullivan concludes that ISO 42001 helps organizations manage risks and build trust, but it must be extended with other standards to fully address regulatory obligations like the EU AI Act's quality management system and cybersecurity requirements.

Transcription

6865 Words, 39226 Characters

English
Welcome to the AI Standard Stack with me, Michael Minnelli, Director at ZN Group. And me, Adam Smith, Chair of the AIQI Consortium. Each episode on AI Standards Stack, we discuss developments in AI assurance with guests from around the world that are leading the charge on the standards, ethics, and regulation of AI. This episode of the AI Standards Stack is supported by the United Kingdom accreditation service, UCAS, the UK's National accreditation body. UCAS ensures organizations that test, inspect, and certify AI systems are technically competent, impartial, and robust building confidence in safe, reliable, and trustworthy AI. On the show today, we're joined by Patrick Sullivan, Vice President of Strategy and Innovation and AI, an internationally recognized provider of cybersecurity audit, certification, and compliance services. With over 25 years experience in IT security and compliance, Patrick specializes in AI governance, cybersecurity, and regulatory frameworks. As an ISO committee member, he collaborates with global leaders and experts to shape the future of AI regulation and standardisation. Well, welcome to the show, Patrick. The whole idea of the AI Standards Stack podcast is really to try and unpick the full stack of standards, ethics, and regulation, and it's a pleasure to have you on. But before we dive in, would you like to just say a few words, a particularly about your background in history before a line? Oh, absolutely, absolutely. My like, well, first of all, thank you for the opportunity. As I mentioned in the lead up to this, when I saw that Adam was a participant in the series, that there was no way I was going to say no. So very, very honored and grateful to be here. So my background is varied quite frankly. Just a Campbell has a quote that one should follow their bliss. If you follow your bliss, doors will open, we're before there were only walls. And so I sat out 30 years ago at this point down the path of studying electronics. It was absolutely certain that I wanted to understand everything I could about electronic components and how to build communication systems from the ground up. What I discovered through that process is that there are in fact other tangential areas of interest that we find as we push ourselves to grow. So over the course of my career, I've been really blessed to serve in a number of different roles and a number of different capacities from network engineering, administration, healthcare, IT, at one point in my career, close to 20 years ago. Now I was fortunate to be able to help start a medical school. So lots of really interesting things have been part of my journey and the decision to continue to follow my bliss. And those areas where I find myself of most use in serving the community have led me where we are today. Well, it's an interesting area you're working and we're not going to be covering it today, but you were the working group lead for the International Association of Algorithmic Auditors. And a lot of this might strike a few people as quite mysterious. And your firm A line is well known as an auditor and certification body for technical standards. What does that mean? What do you actually do? You walk onto a site and you do what? We do X. We make people very uncomfortable. No, I'll joking aside, I'll joking aside, you know, we recognize from a standards perspective that organizations largely have an opportunity to consume standards, interpret them, and then implement those standards based on their own interpretations. So there's an entire community that exists to provide objectivity, review, and evaluation of how those standards have been implemented. And that really is we organizations like a line set, we're a third party cybersecurity assessment firm, but we assess against most of the common third party standards, sought to hip ISO, we organize, so certification body, conformity assessment body, and some vernacular. Ultimately, we exist to ensure help organization. We ensure that organizations have the objective feedback they need to ensure that the systems that they've implemented to maintain control of security privacy, their AI life cycle. Have that actually been implemented in such a way that we can offer assurance that those organizations are doing the right thing as it relates to the systems themselves. So to say it in fewer words, I have a standard I've implemented it. Now I need an objective third party to check that I've implemented it correctly and offer assurance to my community that I'm doing the right things. That's exactly where a line sets in our ecosystem. And in the jargon, you're not in the credit or your certifier. That's correct. That's correct. And who's accrediting you? So right now we carry two accreditations one through a nap and one through you. Caz. Very good. Indeclaration, delistener, I'm the senior non executive director of UCAS. So I think it's important to be clear about that sort of transparency there. Now that's fascinating. Now you do do handle a range of standards, sock one and two. As you mentioned, PC, ID, SS. And of course, we're particularly interested. I am anyway, Adda's probably bored now. But in your thoughts on ISO 42, 2001. And I'd be curious if you could just share with the audience what the evolution of 42, 2001 looked like from the role of a certifier. You know, so it started obviously a number of years ago. It's only relatively recently released. What are your thoughts on it? Yeah. And so really from the eyes of a certifier, I think we can better represent the eyes of the community. So to your point, 42, 2001 as a standard was released in December of 2023. And a lot of the early misunderstandings we saw are we on 42, 2001's utility. Rested on people thinking that it was an AI security standard. You know, most organizations are familiar with 27, 2001 and the concept of really managing information security from an organization's perspective. As 42, 2001 hit, there was a natural confusion which became in effect and understanding a pervasive misunderstanding in the community that 42, 2001 was about AI security. If we're doing 2701 real already, what real value will we find in implementing this new framework? And so we've worked very hard over the past few years. Adam, thank you for everything that you're doing to be part of the reeducation. To now we're facing different confusions. As you've likely seen, Michael, one of the big points of pushback against implementation of 42, 2001 today is the confusion that many organizations believe that 42, 2001 is intended to satisfy requirements and obligations associated with the EUA I act. And because we recognize that it does not, suddenly the credibility of 42, 2001 as a tool for organizations to improve their AI life cycle has been put in question. Again, fundamental misunderstanding, fundamental misrepresentation, there really were the hard work today rests in continuing to reeducate so that organizations, first of all, understand what 42, 2001 is referring work is. Secondly, what it is, isn't. And where it should really rest inside your organization is you're building not only your regulatory defense posture, but also your traditional compliance strategy posture. I don't know why you think I'm bored of 42, 2001 Michael. I just sat my lead audit exam and become qualified to it so I can spend more time with the standard. The more organizations I talk to, the more I realize that almost every organization needs to start with working out who they're going to be regulated by who else might have opinions about who they how they manage AI, what their AI systems are and what they do and what their role is in respect of the AI system before they can do anything else. And that is because of I so I see 42, 2001. So even if an organization isn't going to go and get certified, it's the right place for everybody to start. And one of the things I noticed very recently is the amount of accredited certifications increasing and incredible statistic. It's gone up year on year to March 2026, 1800 percent, which is a huge increase. It's not entirely surprising because there weren't that many organizations able to certify in an accredited way the year before. But that data is really starting to show really strong uptake of ISO AC 42, 2001, which is great. Totally agree. And not only do we see it in the certification, the certification data for my F, but we see it in market that we see organizations like Microsoft, Oracle recently, and ThroPec down the line. We see more and more enterprises recognizing the value and utility of 42, one certification, earning their certifications with full expectation that they'll push those expectations down their supply chain. And so the reality is even if regulation isn't a concern for the enterprises for our listeners, even if regulation isn't your number one concern today, market pressure absolutely should be. Well, you involved at all Patrick in the development of the standard prior to December 23. I got involved in ISO Special Committee 42 after December of 23. I became part of the process well after 42, 2001 was finalized. Well, it is impressive results in the last year. Exactly. I personally found the Oracle announcement of all of them and there are quite a few really impressive, you know, it's a large organization working on it for quite some period of time, you know, and I was fun enough on the phone this morning with the financial services regularly, talking about yet another charter that people might sign and I said, well, what about Oracle? And they're like, well, yeah, well, they just signed up to 42,000. I said, no, they did not sign up to it. This is a huge commitment and vastly better than the chief executive plunking a signature of his or hers on a piece of paper they haven't read. Yeah. Yeah. Yeah. Yeah. Now you sell this to people, right? That's your business. What's the sales pitch? Yeah. And so to be clear, we sell certification services. I said, as an architecture exists in and of itself, but as a certification body, you know, this has been an evolution as well, you know, quite frankly, I'd add them, you know, this I tend to be overly optimistic, not tend to see the best in everything. And so initially, my market approach to organizations was we now have an internationally recognized consensus-based framework that shows us how to responsibly develop and use AI. Why wouldn't we want to do this? And what I found is that by and large businesses don't care. And that sounds harsh I don't mean for it to sound critical in any way. But the reality is businesses are always looking for ways to ensure that they can keep their lights on. And so additional, extraneous costs or just that, unless there's a significant business justification. And Michael, what we've seen is that by and large, the significant business justification of late is risk management. We know ISO management systems are there to allow us to take a risk-based view into certain processes in our organization, whether it's security management, AI lifecycle, privacy management, whatever the case. But in managing risk, particularly around third-party vendors, we found a hook to really hang conversations around that help organizations understand there is utility in this framework. There is something here for me. I need to start building. In addition to that, we see though, and again, a no 42-01 is not a sufficient stand-in for high-risk AI system QMS requirements as they relate to the AI Act. We do see an incredible proxy, an incredible foundation to begin building, as we do wait on more information about the finalized standards, those harmonized standards to be written into the journal. And for organizations to have an effective line in the sand beyond which we know they will be required to have a high-risk QMS in place, a lot of words to say 42-01 is an incredible tool to lay a foundation that we then extend to meet the real obligations that are coming. The blipside of that is that harmonized standards for high-risk AI are not very much use if your goal is to meet customer requirements to align with business objectives or continual improvement. So there is no, they don't exactly overlap, totally. And the beauty here is to build a foundation on 42-01 that we then extend to 18286, allows us to undergo independent third-party certification to have assurance documents for the business community and have real processes and practices in place to build the technical documentation we need to withstand an audit from a notified body. I'm going to get into the international area in a minute, but just before I do so, have you got any kind of good war stories of where 42-01 has done something material, not kind of management abstract jargon, but you know where it's really made you know, you went in, did you get the notification thing about do you realize this and this is and I needed to be changed. Yeah, and so maybe maybe less a war story about corrective action, more war story about value. So we we partnered with an organization that creates synthetic media. It's probably been a year and a half, two years ago now. They wanted to be the first organization in the article that actually had the ability to offer a 42-01 certified product to the market. We evaluated them, they had built things appropriately, we audited them, issued their certification, and certification became one of the assurance pieces needed to ensure that they were able to take in additional investment. And so we saw this organization over the course of the two years after certification and Michael, I may be mistating, but they took in rounds B and C and are now evaluated at well over a billion dollars. I'm not saying that 42-01 was directly responsible for all of that, but 42-01 absolutely played a role in ensuring the continued investment that they did receive. Yeah, but we've had a couple people on the program, particularly with relations with the International Corporate Governance Network, where they've drafted this coffee house consensus, saying that countries where they invest and companies in which they invest really on a 42-01. So it's nice to hear this from the ground as well as opposed to the abstract from the level that they have, but they claim some 33 trillion dollars of their 77 trillion have signed up to this. But moving along, now you touched a few minutes ago on something I'd like to explore, which had to do with the EU's AI Act and its relationship with 42-01. Now you were clear and I'll be absolutely clear that there's technically no relationship whatsoever of the two things are effectively completely separate elements. And yet there's certainly been a lot of talk from Europe that for the non-high risk for the bulk. If you can demonstrate 42-01, we can deem you to be probably quite compliant with the EU's AI Act. How would you react to that? I would think that's a dangerous assumption to make, quite frankly, no, I call. And so first of all, I do want to step back and not to argue with you, but to express my opinion. I do think there is direct connection between 42-01 and 18-20-20 8-6, which is the standard intended to give organizations the tools they need to be successful in meeting their requirements to the AI Act. In fact, as we look in the annexes of 18-28-6, we see the direct mappings. We're in 42-01 and 90-01. We're used as takeoff points. We'll see in 18-28-6, the same high-level structure. Adam, I think it's in Excel used to create the format for 18-28-6. So to characterize them as completely disconnected and not technically related, for me is not an appropriate characterization. What I would say is that they're intended to create two very different sets of outcomes. 42-01 is meant to solve a particular problem, to create a solution for organizations to meet the needs of, and I said, "Doesn't you stay cold?" There's Adam. It's interested parties. We're looking to meet the needs of-- Yeah, that's right. Yeah. Interested parties through the build and deployment, the operationalization of 42-01. With 18-28-6, we're looking to meet the needs of the regulatory regime, specifically around product safety in the EU. Two different things. Two different things entirely. It turns out the mechanisms, the muscles that will move to create those outcomes, in many ways, have similar security. I think just to follow up on that, I think the utility of 42-01 is sometimes talked about in the context of the quality management system in the AI Act. But in reality, the quality management system in the AI Act is largely about things like serious instant reporting, post-market monitoring, which are concepts that don't exist in 42-01. It's also the framework that you use to choose all the other standards and the state-of-the-art techniques that you're going to use to ensure compliance with the rest of the AI Act. If you try and use 42-01 for that, you may get halfway, but you're not going to get anywhere near compliance with that article. Adam, Article 15, or Cybersecurity and Trustworthiness. None of that is addressed through 42-01. So, at the point, we get ourselves down the road and we produce a system that can be reused and repurposed to meet two fundamentally different sets of stakeholders, sets of interested parties. Now, picking up on this, that's kind of the European view. What's it like on the other side of the pond at IST? What are your thoughts there? My thoughts probably shouldn't be shared, necessarily on a five-kath. What I would say is, in the US, the US approach appears to be one of removing obstacles to innovation without much better clarity. So, what we do know, at this point, is that many states have gone online with their own, in effect, many AIX to be implemented at a state level. We also know, based on some recent decrees, that from a federal perspective, no state will be able to enforce regulations that become prohibitive or restrictive on innovation. So, largely in the US, we're left in a large, for lack of better words, Michael. We're in. Organizations understand that we need to be doing things. We need to be doing things to ensure that the systems we're deploying are not causing horrors. But we don't necessarily have solid guidance outside side of the international standard in 4201. And to some extent, some of our NIST frameworks to follow. And so in the US, well, let me rephrase this, in Europe, we're very much regulation driven as it relates to building good practice. In the US, we're very much market driven. We mentioned before some of the significant enterprises that have undergone 4201 certification with an expectation that their suppliers will do the same. In the US, we're really leaving the implementation of solid, responsible AI development and use practices to the market. The market will demand what the market needs from organizations so that we can have those interconnections of trust. From a federal perspective, we know that things are coming. We don't know necessarily what those things are or when they'll be coming, unfortunately. One thing I find really interesting is in the EU, we have this presumption of conformity with harmonized standards. And I understand in some states, I think, Texas and Washington, there is similar legal concepts emerging where you get an affirmative defense if you're complying with either the NIST risk management framework or ISO AC42,1. And I think in California, there's an approach where you disclose your approach to standards as part of your transparency mechanisms. So I think this is really interesting that I'm not going to say that the Brussels effect, but this idea of linking regulation to standards is taking effects in the US as well as Europe, which I personally think is great. There's no question. And I think the second regulation that you were talking about was Colorado and Colorado SB205. But in both Texas's Triga, the Texas Responsibility Ag Governance Act and in Colorado SB205, we have direct references to ISO42,1. And/or the NIST AI Risk Management Framework is being safe for our members. So yes, absolutely. From an organizational point of view, so, and we have a new Bradford in the Brussels effect is always been an interesting one. In fact, we had our one of our programs, so I should say it was superb. But I'm an organization, I'm CEO of an organization, and I've decided to go for ISO42,1 because the market demands it or I've decided to go for it because it looks like my regulators are going to require it. Does that really make a difference to you the certifier on the ground? Does that result in a different kind of implementation? Or has once I've made the jump, it's pretty similar? Once you've made the jump, it can be fairly similar. Michael, with 42.0.1 or any ISO management system, from an audit perspective, really we are tied to the scoping of the management system itself. And so Adam talked about clause four earlier. We're in those decisions are made. We're in we really clarify that the scoping of that, which this management system is intended to govern and manage. And so through that scoping, organizations will determine, not just external regulation, but also customer contractual agreements. Again, all those things that are needed for interested parties to be served well. In instances where we recognize that we do have external obligation related to regulation, those things should be documented as part of the statement of applicability for that particular management system and evaluated accordingly. So by and large, we should not see a difference in evaluation from a certification body perspective of that management system for whoever it's intended to serve. But we're there to evaluate that the organization has thought cleanly about who they are, what their role in the ecosystem is, and they thought holistically and systemically about the interested parties that are served by the services that they're putting on the market. Well, we talk a lot about the states because probably the number one AI power around. Yes. And we would argue it's a bit of an incoherent mess at the moment and you can have views. But that's OK. It's market that I got. We got number three, which is Europe, which is trying to be much more regimented and regulated and disciplined about it. What about number two, China? What indications are you seeing there? Well, we're actually saying China do some interesting things. And I know that won't be a popular opinion. But with the hard focus on robotics, I think it really is interesting to see where the Chinese initiatives are driving, not just with the development and the innovation coming, but also in their views on regulation of AI itself. So I wouldn't necessarily tie their views on privacy to those that we see anywhere else in the world. At least from the outside looking in, it does appear that the Chinese are taking a very proactive approach to ensuring privacy and to some degree product safety. Well, that leads me on to a very interesting question. And again, you touched briefly on what Adam did. I believe on the kind of the difference between a product safety regime, which has got certain types of approaches and a management system standards approach, like 9,000, 14,000 and some of the others there. So how do you feel that effects one's views on AI governance? Is it kind of-- I'll be very different as a robotics firm where I've kind of got an embedded product. I'm shipping versus say a financial services firm that's pretty much shipping out kind of thoughts based on AI or analyses based on AI. And I think the recognition, the goal, the why, absolutely sets a different tone. And I will say just openly, the concept of a product safety regime applying to AI is something that's very foreign to most American businesses. Because AI, for all intents and purposes, is intangible, it can be really hard to make the connection this intangible thing that we would have traditionally thought of as software is in fact a product being placed on the market and requires a similar approach to control and evaluation. So it's been a bit of a stretch for US businesses to accept what the AI act is actually trying to do and to build systems accordingly. From a management system perspective, however, Michael, and you were going to say something? No, I was just kind of curious that the minute I take a medical device or a robot or a physical object, I mean, that we have been subject to product safety there in terms of the control systems for it. And the AI in those products is largely a control system. So is that foreign or is it that people are trying to apply it to the intangible, purely data-driven AI? And that doesn't make sense. No, the latter. The latter. I do think when we have a tangible concrete product that touch, I think suddenly the concept of product safety and a product safety initiative become a different thing. It's in those areas that we don't necessarily have that discrete tangible product when we are leaning on purely intangible code, if you will, that it becomes difficult. But when we step back and think about the definitions very wildly about what AI is, largely there are a few common components. We'll see a component of automated decision making. But then we'll also see a component of the ability to trigger change in an environment, either virtual or physical. And with those things sandwiched together, it's really hard to argue that AI is not a product that we are in fact placing on the market. It should be treated accordingly. It's probably a poor analogy, but I've used the analogy of a toaster. If our toaster shot out nails instead of toasted breads, we would all have a very serious problem with that. The reality is that we do have decision engines that are making decisions that though they are not causing similar harms or causing horns just the same. Yeah. I mean, the concept of product safety being applied to AI is not just something that US businesses struggle with. People struggle with it in Europe as well and the UK. Particularly those sectors like HR, employment, training that are used to having a relatively unregulated market to play in. And if something is going to affect people's health, safety, or human rights, we should check it works properly before we put it on the market in my view. And some of the pushback I hear on this just doesn't stack up for me. So I hear pushback, oh, AI systems change all the time. Well, do they really-- most of the AI systems used in these high-risk environments do not? Even things like Claude and ChatGPT, when they change their system and have a new version, it's in the news. So we do know when these systems are changing. I admit they drift. There are other ways that they can change it smaller ways. And what the product safety regime says is you need to monitor these things. And if that change can affect compliance with the law, you need to go back through the conformity assessment process. So the product safety regime already handles the fact that things change. So some of the pushback I hear on applying product safety to high-risk use cases, I think, is a real stretch. Well, Adam, what I think it is is an inability to articulate the real problem. So with a toaster, again, it shoots out nails. It's really easy to say, this is a problem. We need to pull this model off the market. With AI, the first question becomes, how do I even monitor the system that I've deployed to the market? What does this even look like? And so what we see as organizations really freezing and trying to make a determination. about how to even do the thing that fundamentally they should be able to do. And I don't like it's incredibly difficult, incredibly difficult to tie the pieces together to show real conformity to obligation, but just because it's hard doesn't mean we shouldn't be doing it. Which these beyond take kind of hard, right? You're out there doing these audits and somebody who oversees a lot of these audits, they're not easy to begin with. And an allergy I frequently draw is, you know, I have pharix stingwatures and we've got people out there who sort of five pharix stingwatures. And a pharix stingwisher in a bank is no different than one on a retail shop but a golf course. You know, they're all kind of the same thing. However, the fire management system can be wildly different. You know, phar management system for a, you know, a data room for a bank of, you know, these are all quite, quite vastly different things. Now you come in and you say, well, I'm going to do 42,000 one. What sort of skills are required? Because if it's just pharix stingwatures, hey, my buddy, you know, I know about metal, I know about pressure. Give you a tick. I'm done here and fill in. You know, versus wow, how do you actually handle a fire and a very sensitive chemical plant? And you're, you're kind of in the middle of all that, aren't you? We are. We are. And Michael, the skills required honestly are difficult to find in a single individual. And so for their reason, what we've really been saying, become common is that the skill sets for evaluating against the AIMS, the 42 or 1AIMS really requires a team. But AI literacy becomes the foundation auditing skills or a foundation beyond that we really have to consider the context of the AIMS management system that we're evaluating to understand what specific skills would be needed. That is a fraud detection system is going to have fundamentally different requirements for operation than a radiological review system, a computer vision system. And so really understanding what that is based on the scoping and context that set forth in the scoping statement tells us how to think about building the team that can be successful performing that audit. And when we're looking at standards community and forced standards markets like ISO, et cetera, one of the great things we trump it is that it's industry led that industries informed. Of course, when you're talking industry, they often feel that they were moderately well involved, although buried under auditing jargon at the beginning. And then once the thing gets alive, it kind of goes off on its own and never comes back to them. Now, this standard is only two and a half years old. So it's a very early days here. But in your work out in the field, have you has your experience working in industry informed your perspective on how this guidance ought to be evolving and moving without question without question, Michael, do your point, you know, 42 or one in any consensus base standard necessarily will be inclusive. And so we have what by and large becomes generic is not the right word, but I'll use it here, a generic set of goals and requirements that again through clause four have to be custom tailored to the specific context of the organization. And I think that can be lost in the process. What we do see is that there is lots of industry representation in the standards creation process. And I would say is that just because there's lots of very industry representation doesn't mean that we necessarily have representation from organizations of varying sizes. We might have a lot of enterprise input. We might have a lot of small and medium enterprise input. But as we think about the mom and pop businesses that are still bound to the requirements of regulation in some cases at the very least or requirements of market pressure. I don't know that we necessarily have the necessary input from those groups. A big example here. We released 42 or one again in December of 2023 with the expectation that really understanding the standard and creating implementation mechanisms and implementation guides could be left to the third third party market. And the reality is most organizations don't have additional funds to hire advisors and readiness firms in that market to help themselves build the tools that they need. And so a simple solution is let's create an implementation guide. We know what the standard is. We know what the thought behind the original intent was. Let's create an implementation guide that organizations of all sizes can use to at least put themselves on the road to successfully building and implementing an agon management system. And though we're in the process of doing that now, still we're almost three years out of the standard going final in the market. So three years of organizations left wondering what do I even do with this, which I think is really at the heart of why we do see so much confusion around the utility of the standard today. And we were there before I saw 9,000 everybody talked about implementation guidelines standards templates and they never arrived with 14,000 they sort of arrived. I was involved in a corn, which is a standard for SMEs and things of that bill. Yeah, it's a shame we were not quicker. I've often said what I'd love to see is an award ceremony, you know, for the best management systems, whether it's 42,000 or 40 every year, but under the requirement that you then publish it so that people can actually see what a real working system is like and kind of break it open. But that's that's a thought. Just a couple of quick staccato questions that very quick. Are there any sectors where you do see AI standards harmonizing internationally at speed? Michael, I'll have to say no, but it's not a hard now. What I do see is we are seeing sectors like financial services, health care, regardless of geography, we're seeing those sectors tend to align on best practice and guidance. But as far as the de facto standard for that particular vertical, I haven't yet experienced that 42,000 is a product, right? So the products, as we said, is just out the gates. Right. Where's it weak? Where's it not doing the job it should do? And you can tell my next question is going to be what might be an extension of it that at all to go to but start with, you know, where's it weak? Where's a cracking and it just isn't functioning? Yeah, and the weaknesses and the cracks in the system as it's deployed to the market today. I don't know is in the framework as much as it is in the education of those that are implementing it. What I do see is that we in many ways have a hammer. And we have not yet taught people how did we old that hammer. I think that really is the next level of maturity for 42 will one as an international standard is real market education, you know, informed consumers informed buyers that understand not just the framework, the framework's easy to read. I think the standard itself is 45 or 50 pages long. So it's not, it's not that burdensome and overwhelming. What is unknown, however, is the intent in many ways. And so what we have is lots of different buyers, lots of different organizations bringing their own perspective to the standard. And in many cases, those perspectives completely messed the point. And your clients, what do they compare 42,001 with? Do they go straight and say this is kind of like a 9,000 implementation we did or do they compare it with something else or do they find it so we generous. So I think the most app comparison for most of our customers is 2701. But primarily because of that high level structure again, what we do see such commonalities there that it can be easy to educate that through one lens, we're looking at information security for another we're looking at our a life cycle. And extensions, I mean, you spent quite a bit of very useful time explaining, you know, how this fits in with the 18 to 8 six and, you know, bits and they got nest standards and all that. But what would the next, what would the next phase be in your opinion, where could we do more good? And this is more an acute need now, but we have to do better at formalizing expectations around agente AI governance. And again, thank you for the paper you and your team released earlier this week. I think that really becomes a piece of leverage that everyone can use to think more cleanly. But that that absolutely is the next immediate need for all communities working with they are. And the organization perspective, I think interoperability will be a future topic for agente. I think looking at how agents interact with each other. The paper that Patrick kindly mentioned was very much about regulatory perspective and we analyzed eight different EU regulatory acts. And particularly with regard to the AI act, it the way people are trying to use AI agents is fundamentally incompatible with the product safety regime that we were talking about before. And we're willing to bound them and ensure that there isn't behavioral drift. They're going to struggle to ever get in compliance with the current regulatory frame. And people can find that paper on the aqi.org website. I assume. Going to just putting the plugs in. We'll go on. We'll go on. Well, look, it's been a wonderful chapter. I just wanted to conclude on one question if you wouldn't mind. And it is a global question. If you could change one thing about how AI is currently governed globally, what might it be? Honestly, and this might sound counterproductive because we know consensus-based systems take time. But I do think we need more perspectives at the table, quite frankly. You know, I see this imbalance between the global and the world and global South today. We're in there is a lot of incredible development around regulation and standardization. But most of it's coming from the global north with the expectation that the global South will simply adopt. So I think there have to be more voices, more representation with global perspective. Sure. Then if I think largely we're on the right path, we just need to move more quickly, which I know is not how the process works. But everything in me wants us to close these loops as quickly as we possibly can. Oh, well, standards, as you say, you know, consensus-based standards take a while. I personally am a little dismayed at my phrases, not doing their homework. I was at an event just a couple of weeks ago. And I had to endure about eight hours of people up on stage talking about AI regulated from many nations and very senior individuals. And one of them had heard of 42,000 one. It was depressing. I finally got up in the audience and gave a five minute diatribe. And they all came up to me. I know we didn't even know it existed, but they were happy to be racing out there as AI experts. And they took their places on the panel all about standards and regulations. It wasn't as if I was asking some kind of researcher on transformer theory to talk about legal legal laws. And they were all very, very senior. So I think we're going to lot to do to get the message out. And with advocates like you and supporters like Adam, I'm glad to see it. So thank you very much. Well, thank you, Patrick, for sharing your thoughts with us today. And also like to always thank my co-host, Adam Leon Smith, for his inputs and thoughts as well. And all of you for listening to the show. And please join us next time for more on standards, ethics and regulation of AI here on our AI standards. Istandard Stack Podcast. Thank you all.

Podcast Summary

Key Points:

  1. The episode features Patrick Sullivan, VP at A-Lign, discussing AI assurance, standards, and the role of certification bodies.
  2. ISO 42001, released in December 2023, is often misunderstood as an AI security standard or a direct solution for the EU AI Act, but it is a management system for responsible AI lifecycle governance.
  3. Accredited certifications for ISO 42001 have increased by 1800% year-on-year, driven by market pressure from major enterprises like Microsoft and Oracle.
  4. ISO 42001 provides a foundation for organizations to manage AI risks and build trust, but it does not replace the high-risk AI system requirements under the EU AI Act, which require additional standards like ISO 42001's counterpart for product safety.
  5. In the US, AI regulation is market-driven rather than regulation-driven, with states like Texas and Colorado linking standards compliance to legal defenses or transparency requirements.
  6. A case study shows that ISO 42001 certification helped a synthetic media company secure significant investment, demonstrating its practical value beyond compliance.

Summary:

In this episode of the AI Standards Stack, hosts Michael Minnelli and Adam Smith interview Patrick Sullivan, Vice President of Strategy and Innovation at A-Lign, a cybersecurity audit and certification firm. Sullivan explains that ISO 42001, released in December 2023, is a management system standard for AI lifecycle governance, often confused with AI security or a direct compliance tool for the EU AI Act. He emphasizes that while ISO 42001 is not a substitute for high-risk AI system requirements under the AI Act, it serves as a critical foundation for organizations to build risk management practices and meet market expectations.

The standard's adoption is surging, with accredited certifications up 1800%, driven by major enterprises like Microsoft and Oracle demanding it from their supply chains. Sullivan highlights a key case where ISO 42001 certification enabled a synthetic media startup to secure over a billion dollars in investment. In the US, AI governance is market-driven, with states like Texas and Colorado using standards compliance for legal defenses or transparency, contrasting with Europe's regulatory approach.

Sullivan concludes that ISO 42001 helps organizations manage risks and build trust, but it must be extended with other standards to fully address regulatory obligations like the EU AI Act's quality management system and cybersecurity requirements.

FAQs

The AI Standards Stack podcast discusses developments in AI assurance, covering standards, ethics, and regulation of AI with global guests.

Patrick Sullivan is Vice President of Strategy and Innovation and AI at an internationally recognized cybersecurity audit firm. He has over 25 years of experience in IT security and compliance, specializing in AI governance, cybersecurity, and regulatory frameworks.

A-Line provides third-party cybersecurity assessment and certification services. They evaluate how organizations have implemented standards, such as ISO 42001, to ensure they are correctly applied and offer assurance to the community.

ISO 42001 is a standard released in December 2023 for managing AI lifecycles. Common misunderstandings include thinking it is an AI security standard or that it satisfies EU AI Act requirements, but it is a foundation for responsible AI development, not a regulatory compliance tool.

ISO 42001 is not a direct substitute for the EU AI Act's high-risk QMS requirements, but it serves as a strong foundation. The harmonized standard ISO 42006 will help extend 42001 to meet regulatory obligations like technical documentation for audits.

The primary business justification is risk management, especially for third-party vendors. Certification can also attract investment, as seen with a synthetic media company that used 42001 certification to secure funding and grow significantly.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.