In this interview, Peter Lee, a partner at Simons & Simons, discusses the challenges and risks of AI, particularly agentic AI, which can autonomously perform tasks like booking a haircut and taxi. He highlights the global fragility of AI infrastructure, heavily dependent on US tech companies, and stresses the importance of data sovereignty—keeping citizens' personal data within trusted jurisdictions to protect privacy. Legal accountability for AI actions is complex due to the "many hands problem" across different actors and jurisdictions, and no country has settled law on this. While the EU has the AI Act, Australia and the UK rely on existing laws, risking confusion for businesses. Lee warns that over-reliance on AI threatens critical thinking skills, akin to losing navigation skills from using Google Maps. He advises treating AI as a "sparring partner" and hiring philosophers to foster critical thinking. Soft law standards and real-time governance models can help monitor agent drift and ensure safe AI deployment. Ultimately, Lee emphasizes the need for clarity, resilience, and human oversight to balance AI's benefits with its risks.
[MUSIC] Agents have got a level of autonomy that we haven't seen before from technology. How are companies, organizations of any stripe sort of responsible for what an AI might do? Yeah, this is a very complicated, complex question. I think the law in most, in all countries, I don't think is settled on this. I think there's a much more profound threat to all professionals. In fact, all society, which is the impact of this technology on our critical thinking skills. Three years ago or two years ago, top of our recruiting list were computer scientists, data scientists. Now I'm looking to hire philosophers. [MUSIC] G'day, I'm Andrew Williams, and this is part two of our Squeeze Special Series on Artificial Intelligence. Menderoo Foundation is an Australian philanthropy driven by a commitment to create a future where people and the environment we depend on can thrive. Now they have a focus on AI, particularly how we can find the right balance between protecting people and unlocking its benefits. And recent research commissioned by Menderoo found that nearly two thirds of Australians think the pace of AI development is too fast. And they want to see the government ensure that we're resilient to the risks of AI that our laws can keep pace with how fast the tech is developing. So we've spoken to Peter Lee, who has been working at the centre of AI and the law for longer than most of us have probably known what AI is. He's a partner of the International Law Firm Simons and Simons, and he talks about how we can stay resilient in Australia when it comes to data, how we as workers can try and thrive in the age of AI rather than get left behind, and the ways in which AI can and can't organise your haircut appointment. Here's Peter. [MUSIC] Peter, this is your first time in Australia as we speak today, but you're an expert when it comes to resilience and regulation in artificial intelligence. Globally, how do you think the world at this point is kind of keeping up with a very quickly evolving technology? It's fragile, I'd say. I mean, in some aspects, we are relatively comfortable in terms of some of the underlying infrastructure, although we're heavily dependent on certain countries, notably the US, and particular large private companies within those jurisdictions for a lot of the infrastructure. I think one of the big challenges now, the new paradigm that we're facing is a gentica AI, which increases the threat area, particularly from a cybersecurity perspective for organisations and companies. I would say this is so fast moving, there aren't many people who really deeply understand this space. In terms of resilience, what would be your advice to say the Australian government, for example, to make sure that they're keeping the country resilient against whatever threats might come from this? Well, I think the main approach would be to really understand the tech stack that they are operating with, to understand where the fragility and that is, and where the reliance on overseas companies are, where your data sovereignty lies, and then really to try and understand the levers you've got to be able to at least control a bit more of that ecosystem, and understand what if some of that infrastructure becomes unavailable or there's a malicious attack or it goes offline, how are you going to keep your critical services working? And that's especially important for security services, but also health services and everything else. Could you just expand on that term data sovereignty that you mentioned before? What is that main for anyone that might not have heard it before? What I mean when I think about that is the geographical residency or location of the data that you are responsible for as a nation. Usually that's linked to personal data, which is linked to people's individual rights and the privacy that they can expect. The jurisprudence and the philosophy behind this is that people have an expectation that they will be able to maintain some privacy and their personal data will be protected. And so sovereignty in that context is about ensuring that your citizens can expect that their personal data is going to be respected and is usually kept within country or at least within countries that would not manipulate that or in any way. Just before you mentioned agentic AI, and that's a term that I know I've heard a lot more in the last couple of months, what do we mean when we talk about agentic AI? How does that differ to something like a large language model, a generative AI, the kinds of AI that most people would be familiar with at this point? Most people are familiar with generative AI and the large language models that sit underneath those generative AI systems and they're fantastic for generating content. Agentic AI is also built upon large language models with certain scaffolding around it, but agents have the ability to act and perform functions themselves and that creates new, really new opportunities, but it also creates some new risks as well. You need to be concerned about what that agent can do momentarily and the sorts of oversights you might need to control that. Talking about agentic AI or an AI agent, can you give me an example maybe from your profession of exactly what that can do for people that haven't encountered before? Yeah, I can give a real, real world example that might help people here. I think if you were to Google where to get your haircut, for example, you might get a list of 100 different barbers in your local area. If you use generative AI to ask where you should get a haircut in Canberra, you might get a more sophisticated answer and you might then ask it further questions about the style that you wanted or how quickly you wanted it done. If you ask an agent to sort your haircut out for you, then the agent would have the autonomy and the ability to go away and book that appointment, probably book your taxi there, pay for the haircuts as well. It's got the ability to conduct actions on your behalf. All you have to do is get in the taxi and get there, sit in the chair, sit with the barber. By doing that, you are handing over a lot of control, which is where those potential issues come in in a workplace environment. It's got agents have got a level of autonomy that we haven't seen before from technology. Therefore, you need to think carefully about the guardrails and permissions you give the agent so that you can be confident that what they end up doing in the actions they take are safe and secure. Recently, for example, Microsoft, a couple of weeks ago, Microsoft released a runtime governance model. This is real-time governance, which sits across agents as they operate as a technology solution and allows you to spot when agents aren't performing as you expect them to. If they're starting to drift, which means they're changing course, they're doing things that you're not expecting them to do, and it allows you to monitor that in real-time or near-real-time and then act upon it. If you need to kill the agent, you know when to do that. What this relies upon as well is a different approach to policies. I've started advocating for resident models. We need to be a bit careful about anthropomorphising this technology. I think people do find it quite useful to think about agents as digital workers sometimes. So giving that digital worker the agents a job description or a resume can really help people understand, especially non-technical people, to understand what that agent can't do and what it should or shouldn't be doing. That allows you to track its performance, a bit like you would with a human worker. And if necessary. Far, far. Yeah, indeed. So you mentioned before that an AI is often seen as a worker in a company. Now if a worker does something wrong in your business, they can be fired for it and the company is potentially liable for what they've done. How does that work when it's an AI? How are companies, organisations of any stripe, responsible for what an AI might do, particularly an agentic AI in their organisation? And I think the law in most, in all countries I don't think is settled on this. There's a couple of maybe interesting discussion points here. The first is academic lawyers sometimes call this the many hands problem because across the value chain you've got lots of different actors when it comes to deploying AI systems. So you'll have the frontier model companies, you'll have their systems developers, you'll then have the companies that might be deploying them and then you'll have the users themselves. And there'll be many more actors along the chain there. And so trying to work out when something goes wrong, who is accountable is very complex. And it's also made more complicated by the fact that these different actors are often in different jurisdictions, which have different approaches to AI law. I think the common law jurisdictions will in time start to give us some more clarity around this. Particularly, I think we're expecting a lot of litigation over the next five years or so, as people start to become impacted by these technologies. That could be because we see job displacement. So you might get actions from trade unions. You might get class actions at an environmental level from communities. And I think all of these things are going to shape the way we perceive accountability in this space. Is there a country that is leading the way in regulating this? I mean, you mentioned a lot of the power is residing with tech companies at the moment. Is there a country that you would point to and go, "Oh, this government is doing particularly well in this area or leading the way in this area?" Governments are really struggling to manage this.
technology and regulate it. And there's various different models. I think Singapore have got some very interesting guidelines now that they've released this year about agenteic technologies in particular. There are some emerging, quite powerful and I think very useful global standards, which are sometimes described as soft law, so they're not mandatory more, but their standards created by groups of experts, their organisations can implement and in some cases get certified against. And they can really help ensure that you're using best practice. It can also help in commercial arrangements as well because if you can say you're certified against a standard, then your customer often gets quite a bit of satisfaction from that. And then you've got places like Europe who have a specific act, the EU AI Act that's been developing is in effect, but there's aspects of it that are coming into effect over the next couple of years. And then we have jurisdictions like the UK and Australia that so far have decided not to bring in a specific piece of legislation to deal specifically with AI. And instead, they are relying on existing laws and sector specific developments and guidance notes and the like. Yeah, this is something that the Australian government did in December where it released an artificial intelligence plan. You've been participating here in an artificial intelligence roundtable, which is why you're here in Canberra's, we record this. And that was very much the approach. What are the potential risks of that approach from Australia's perspective? I mean, I think that the main risk is confusion and an inability for businesses, investors, members of the ecosystem to know what they shouldn't be doing with AI. And that's always the perennial problem with a patchwork of laws. And usually the only winners are the lawyers. Because we then have to advise on a really complicated structure. And so I think I would advocate for this in the UK, I think more clarity around the law in this space isn't always going to be welcome. I mean, I think the UK and Australia both benefit in many ways from being a common law jurisdiction. So in time, we may well see legislation, court cases, and judges can help shape the law and give us some more clarity. But the problem with that is that this sector, this space is moving so quickly, I'm not sure that's going to happen fast enough. So I think for the, you know, particularly for the types of global clients that I do a lot of work with, one of their biggest problems is trying to understand how they can harmonize their approach to AI globally. That's difficult on lots of levels, but you know, the appetite of a specific country or region that they're operating in to the law, to protection of people's privacy. And various other areas can be pretty problematic for them to try and work out what their strategy ought to be and how to harmonize that. So I think for Australia, it's potentially quite a challenging decision they've made not to implement a specific AI law just for that very reason of competitiveness. I'd like to think that it won't put off investors, global companies coming to Australia. In fact, in some ways, with some clarity and some sector guidance, it might make your country more attractive in some ways because you might have that flexibility, particularly on a federal level. But generally, I think most global companies are much more concerned about getting clarity globally as to what they can and can't do with this technology. Finally, obviously, you've worked within the legal system and you've worked a lot in AI. How have you seen it change the way that the legal system works in the UK or more broadly? I think the impact of AI on all sorts of white collar knowledge work is going to be absolutely profound. There was a paper that was written in the last month or so with Anthropic that looked at the impact of AI on professional work. And the legal sector in particular was one that's going to be likely to be very highly impacted. I think this comes at a couple of levels. I mean, clearly our business model as law firms is likely to be impacted because we currently rely on selling our time. And parts of the benefit of these tools should be to increase efficiency. Yeah, save time. Save time. We spend less time doing things and we still get a consistently good output. But also, I think there's a much more profound threat to all professionals. And we're often finding that people are starting to outsource their brains to these tools. I mean, it's been happening for a while. You think about people's inability to navigate when they rely on Google Maps. Yeah, Google Maps. I don't know where anything's anymore. Other technologies like that. But we're now seeing that play out in professional work as well. And so there's been some recent research done on that, which shows there does appear to be a direct correlation. And it's human nature to be a bit lazy and rely on these tools. But just relying blindly on the output is dangerous because the underlying large language models can be fraught with bias. They can hallucinate. And so I do think that's a big threat to our profession that we need to counter. And the best way to do that is to treat these tools as sparring partners we've found. And also to really understand the best ways to use them and to build in some checks and balances along the way. I was about to ask if there's a white collar worker, whether it's a lawyer or anyone of that stripe listening to you now, is that your sort of best advice to them to be able to thrive in this new areas to make sure that they're not fully reliant on an AI tool, but maybe just using it to make themselves better or more efficient. Yes, I think so. I mean, five years ago, three years ago or two years ago, the top of our recrucing list in my particular area were compute scientists, data scientists. Now I'm looking to hire philosophers because that ability to think critically is so important going forward in it. It used to be the joke when I was at university that philosophers had the most interesting degree but couldn't get a job. I think that's not going to be the case in the future. Right. Interesting. All right. That's good news for anyone with a philosophy degree, which I don't know that I necessarily expected we were going to get to in this interview, but that's great. Peter, thank you so much for your time. Really appreciate it. Thank you very much. Thanks for listening and thanks to the Mindarrue Foundation for making that interview possible. For more on their research around AI, a link is in your show notes.
Podcast Summary
Key Points:
Agentic AI introduces new levels of autonomy, allowing AI to perform actions on behalf of users, such as booking appointments or making payments.
Legal accountability for AI actions remains unsettled globally, with a "many hands problem" across developers, deployers, and users complicating liability.
Australia and the UK rely on existing laws and sector-specific guidance rather than dedicated AI legislation, risking confusion and reduced competitiveness.
Critical thinking skills are threatened by over-reliance on AI tools; hiring philosophers is becoming more important than hiring data scientists.
Data sovereignty—ensuring citizens' personal data stays within trusted jurisdictions—is key to resilience against cyber threats and infrastructure fragility.
Soft law standards (e.g., from Singapore) and runtime governance models (e.g., Microsoft's) are emerging to manage agentic AI risks.
Summary:
In this interview, Peter Lee, a partner at Simons & Simons, discusses the challenges and risks of AI, particularly agentic AI, which can autonomously perform tasks like booking a haircut and taxi. He highlights the global fragility of AI infrastructure, heavily dependent on US tech companies, and stresses the importance of data sovereignty—keeping citizens' personal data within trusted jurisdictions to protect privacy. Legal accountability for AI actions is complex due to the "many hands problem" across different actors and jurisdictions, and no country has settled law on this.
While the EU has the AI Act, Australia and the UK rely on existing laws, risking confusion for businesses. Lee warns that over-reliance on AI threatens critical thinking skills, akin to losing navigation skills from using Google Maps. He advises treating AI as a "sparring partner" and hiring philosophers to foster critical thinking.
Soft law standards and real-time governance models can help monitor agent drift and ensure safe AI deployment. Ultimately, Lee emphasizes the need for clarity, resilience, and human oversight to balance AI's benefits with its risks.
FAQs
Agentic AI is built on large language models but has the ability to act and perform functions autonomously, like booking a haircut or a taxi, whereas generative AI only generates content. It creates new opportunities but also new risks due to its autonomy.
The law is not settled, but it's complex due to the 'many hands problem' across the value chain. Litigation over the next few years, including from trade unions and class actions, is expected to shape accountability.
Data sovereignty refers to the geographical residency of data, linked to personal privacy rights. It's crucial for ensuring citizens' data is protected and kept within trusted jurisdictions, especially with AI's reliance on overseas infrastructure.
The main risk is confusion and lack of clarity for businesses and investors on what they can and can't do with AI, potentially harming competitiveness and making it harder to harmonize approaches globally.
AI will profoundly impact professional work by increasing efficiency but also threatening critical thinking skills due to over-reliance. Treating AI as a sparring partner and building in checks is advised.
Critical thinking skills are now paramount, with philosophers becoming more sought after than computer scientists for roles requiring deep analysis and oversight of AI outputs.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.