Bending Towards the G in GRC – The Inevitability Curve EP14
Yoav Raiter, CEO of Raidian.ai, joins Chris in discussing the evolution of rules, regulations, compliance, and governance. The emergence of the latest generation of AI may finally give us rapid visibility into the rules and regulations that impact us, and where we currently fit in that maze.
Transcript
This is Textron tv. Hello, I'm Chris Blak. Welcome to another episode of The Inevitability Curve, uh, where we take a topic, we take a person, and we try to look back, uh, see how we got to where we are, what today looks like, and hopefully give some like, you know, some thoughts on where we're going in the future.
With me today is a good friend and iterative business partner. You have radar Yo Yoav, how are you today? Great, great.
How are you today? It's like five degrees in Toronto, so it's almost like summer is here, Right? Yeah, well it, it is funny 'cause you know, I've done both that I've lived north of Toronto and, and I'm in Key West right now, so it's, you know, 80 degrees Fahrenheit kind of thing.
But I know when we minus 10 Celsius, that was in the spring up north, that's when you walk outside with a t-shirt because it seems so bloody warm in the sun, right? So we adjust to things, which is kind of much to our topic, right? You know, we're adjusting to all sorts of things over time, and we can, in our own lives, we can live somewhere really cold and really hot and, uh, acclimatize to that.
So we all find ways to get through. And the topic, you know, we're gonna dig into today is governance, basically, and the whole GRC, you know, for all our tech folks, governance, risk and compliance. And you're involved with, uh, you know, you and I government been advising, um, you new startup radio with AI and governance and so forth, and it's been a long, long path.
I mean, we've had rules and policy regulations literally forever, you know, thousands and thousands of years. You know, we've had compliance activities, you know, the be with a stick if you're, you know, not paying your taxes or whatever. But we're living in a complex world now, right?
And so that whole journey of how we got to where we are, how, you know, how did we get into this position in the first place? What does it even look like now? And maybe where we're going just fascinates me.
So, so let me start with, with a question on, on that one for you just to, you know, answer or take where we want, right? Right. I mean, you've been around a long time.
You, I know your background. You've lived in various regulatory environments, not just the cyber stuff, the business stuff and everything else. Right.
What do you think about the delta between the two when you first got in, you know, started dealing with rules and where we are today? What's that path look like? Yeah, I started actually dealing, uh, very heavily with regulation when I was developing a medical device, medical devices.
Um, this is like, you don't have the ability to decide, there's like rules of the fda. It's very, very tough and they expect you to actually fulfill all the regulation. However, I felt that they never checked that and that the process was very, very expensive.
Um, you had to do all kind of risk management meetings and you had to follow specific formats and stuff like that. And I think that today the opportunity lies that in a way that AI tools can help us, um, do it better, faster, and cheaper. This is definitely an industry that will change by AI to maybe govern ai.
And this will give eventually more flexibility to organization to develop faster and not stop the innovation. And there's going to be an ai, I would say, uh, supervisor that will make sure that you're following the rules and also for the authority, it'll give them the balance between security and moving fast, uh, with innovation. Well, I, I think, you know, and, and is, you know, a topic when you talk about these days is some sort of Orwellian fear that, you know, AI is gonna be watching everything we do and so forth.
Um, but this is, I I like, you know, policy hacking, right? You know, in cybersecurity in these boats sailing back and forth, you know, the, the regulations, the policy. What are the rules here?
What are the explicit rules? What are the rules written down that I need to, you know, comply with? What are the implicit rules?
You know, what do people actually do? How does that work? And Taylor, and account to three, let me edit that out if you can.
Um, I, I'll mention that to you. Okay. Lemme start that again because I think there's a jet about to go after.
When I was over my head, can you, can you hear this right now? Yoav the jet? I heard like a moving chair or something like that.
Okay, let me just do a three count Now. I hear, so There's probably two of them. I think they're F 30 fives.
Haven't looked today, but that sounds like an F 35. Ah, and you can hear that one, right? I heard like, yeah, like, uh, again, it's like a chair moving.
Really? Okay. Alright.
Okay. So Taylor in 3, 2, 1, right? So we've been dealing with rules forever, you know, I love, uh, sorry, I I really have to start restart that and here comes another one.
I'll just ignore it. Us, I mean, it's not that bad. It's always like the by eight maximum.
So two more. Yeah. And it, that's pretty good noise canceling, because this is making my ears ring, you know, I forget what it's like to be here.
Okay. In 3, 2, 1. So what we're talking about is policy hacking always one of my favorite, uh, topics, right?
So whether in, you know, cybersecurity itself or in working professionally in that space, or even sailing these boats around, you know, what are the laws, rules, regulations, where I am right now? What are the explicit written down rules? What are the implicit rules?
You know, what do people actually do? And figuring those out is, is all the, you know, all the hacking really is. And as you're saying, you know, in, in business we've had these rules all the time.
We don't always really know what they are. We're just trying to go about our, whether they're internal rules inside the company, we think we know what they are. We think we're doing the right thing, the external rules, the actual regulations, we hope somebody in the company is paying attention to those.
And as you know, you know, and each of us, I think in different roles and jobs we work, have seen how have those, you just said this, how will those rules actually checked? You know, you're telling me I need to do something, am I just gonna get caught if I get it wrong? Is somebody actually checking?
Will somebody correct me? We've moving blindly through this, through rules and regulations and policy forever. So I think there's an opportunity now to get a better handle on that operationally, you know, and to your point, you know, business or personally that it's hard to picture, what, what would it be like if you actually knew the rules and how you were, uh, uh, adhering or not to them, instead of just worrying about whether you do or not.
Yeah, I I think that, um, when we think about the old world, we actually need to think a little bit about to predict forward how AI will change the world. Um, I think there's new threats and, uh, unknown unknowns. Um, and we need to reduce the misalignment.
Uh, I would say that the AI as a new player here come with something that we're not familiar with beforehand. You had an organization that was able to set the CEO was able to set the culture and even to have z specific fingerprint on the organization. AI come with something, uh, new.
It comes with all kind of things that the company that manufacture or develop the AI built into it. You are not aware of all the training that was done, all the data training that was used for that AI model. You don't know what's the values behind that AI models.
So even if you try to work with a solution, can you really influence about the solution? Can you even, uh, trust the AI decisions? Because I think that the solution is not just people or just ai, it's going to be people working with the AI together.
And I, people will not do the same things that they did before. And it's almost like you need to look at the economy of that. And AI will change some of the industries and definitely the governance industry.
I don't think it's a reason to worry. I think it's a growth opportunity. Um, but how economy works is like, almost like, uh, I would say, uh, coffee and tea.
If coffee get cheap, uh, people will buy less tea. So there's more opportunities in, uh, that lies in the cream and sugar for that. And AI gets cheaper and companies start consuming it, but they're not have full awareness of how that will affect what they're doing.
And they're not aware of the design philosophy behind the AI or, uh, the values that from the creators. And if you are using, let's say, an ai, I will use an example of AI for sales forecast. So it's basically AI system versus the sales team who follow the company processes and their own judgment before and, and before the person was making the prediction and how the a AI algorithm is going to do it.
And how do you govern that new process. Like I think that the solution should be that an AI will govern some of the things because there's so much data in that new process. There's everything is going to change.
Um, so I think there's a new market that like being open for looking of how AI governance is working. And it's almost like what the PCs did in the eighties for, um, the bookkeepers. Um, suddenly you don't need to do arithmetics anymore.
And now you can, same as governance in AI governance, it'll replace the day-to-day, I would say, boring work of people, elevate people to do the smart things and to make decisions. And I think this is how that going to influence the industry. When you said a couple of things there that I think speak a lot to the, the where we are right now, you know, this is a transit transitional period as many are, you know, we're go, you know, five years ago nobody was doing this particular thing.
Five years from now, arguably, let's assume that, you know, most people are successful people are, 'cause it's better, faster, cheaper, making better decisions, more competitive, uh, advantage and whatnot. So right now, when you're going going between those two states, there's opportunities as you say, right? You know, if you, you know, and there's opportunities and risks in the stuff itself.
And you touched on this, you know, AI itself, everybody's sort of getting their heads around this. I think we're commonly understanding. There's training and on models, and the model data says a lot about the output you're gonna get from your ai.
How do you, in the bill of materials supply chain world, you know, the tracking of the provenance and the models and the AI used to reach, you know, make the tool you're using is a big topic today. So there's some moving pieces there, but people are working on them and people are using these tools. So some of the current deficiencies, you know, the perceived or real deficiencies with ai, people are working on these things and we're moving forward.
So I think that's a moderate to low risk in adopting things. And then there's, so that's the tool, it's the tooling itself, and then there's what you do with it and the time, you know, my, you know, uh, uh, the phrase I keep coming back to is time to transparency, right? And you apply that to lots of things and say, what if you just had more time?
It took you less time. You know, something as you say, was doing the boring work, was actually reading all the bloody regulations, you know, 24 hours a day and comparing them and letting you know when something changed as opposed to you actually reading those same regulations. What do you do that extra time?
What advantages did I give you? You know, the coffee cream and sugar, you know, it's a coffee thing, but now with all that extra time you get to do a lot more cream and sugar. And I think there's a lot of moving pieces there where if you get on the right iceberg as this changes, you have a big advantage manage.
Yeah. Um, it, it's a lot of rethinking. And I think it's also something that it's not only for government to think about, but it's also the, uh, business community need to think about.
And even like, um, just like people that are using, uh, tools at home, they also need to be part of the conversation because this, in a way even can affect how we govern in our, uh, city or in the state, or in the federal, uh, situation. Um, and it to me a little bit to the regulation, and I think today there is a fragmented state by state approach to AI regulation. And I think the absence of fe federal oversights make it really impossible to develop AI fast and compete with other country.
I think, um, there's a need for a federal agile lie with a forward thinking policies that will support innovation without too much hassle. And I believe the new executive order of Trump, uh, the 14, uh, 1 7 9 will really help. Um, I think it's important to know that we cannot win it all.
I mean, from one hand we have security and compliance, uh, they can prevent innovation and competitiveness, so we don't want to have that. But on the other hand, they can protect, uh, the AI innovation in some scenario. So I think a smart balance is required, but this is just like one thing of the government.
But let's assume that, um, there's no rules. Let's say there's no, uh, all kind of frameworks or policy or regulation that's coming. I think that businesses will apply governance inside of the organization just to make sure that some decisions are being, uh, made properly.
If you have an inventory system, and one of the things that is being predicted, that system that do purchasing, um, will use AI engines as part of the decision making. So today you have limitation with budget. Like that person can sign up to $50,000.
How do you apply that on AI on hundreds of decisions that are being done in a second? Um, I think this is like, so many questions are going to come in terms of how organization are going to deal with the changes. Well, and yeah, it, I I'm glad you went there, right, because we're talking governance and you can't go there without thinking government, right?
And yeah, I, I am not in favor and publicly not in favor of the way changes are being made at the federal level right now. Um, however, right, there's always, you know, reasons for things and the dissatisfaction with, you know, government regulatory policy, all these, you know, regulatory agencies and it's, you know, it's not a couple individuals. You know, we as Americans are, I am, you know, fed up with it.
You know, I don't know what the rules are. I do my best, you know, as an individual, as a corporate rep representative, whatever hat I'm wearing. But it is literally impossible to know all the bloody rules and in the implementation of enforcement and so forth, either selective enforcement, worse than nothing at all.
You know, that takes, you know, whether it's law enforcement officers or regulators that they just don't like you, they will, they'll enforcement of the rules. And it's so slow and bureaucratic. I mean, you know, I joke, I do, I work with the US federal government quite a lot on various things, and I like to poke at my friends there, you know, that we're gonna put together a fax, you know, we're gonna put it together, a working group, and we're gonna fax it to all Americans, because government is always slow.
And even with the best intentions, just put these things together. There's the modern world and big, slow bureaucratic, massive, slow, really bureaucratic systems. You know, even completely benevolent, wonderful systems are gonna be 10, 20 years behind the rest of us in the corporate world.
What does that mean? That means they're literally filing paper, moving things around. They don't have the time.
We spend enough money on government already. We're gonna spend ton of times more so they can literally fax things back and forth. No, we need modern systems where the average citizen or whatever country we're in has a good feeling.
They actually can tell because the information's there. I'll, I'll make the third question in the second, but make all this DOG uh, information being, you know, wonderfully secretly found is all in the public domain already. It's all out there on websites.
You can find this information if you just spend the time looking, but you don't have the time. I don't have the time. Nobody.
He does. So having transparency, the way we've done it at the governance level, literally the government level in such a way that it may all be there, but it's effective, effectively invisible. It's like you may be able to find all the laws and rules that apply to you, but you don't have the time.
It takes too long. And we need that transparency. We need to know that whatever rules are being complied with or not, if we're affecting them, we need to know their status.
And it can't just be left to some slow bureaucracy. So I agree entirely with that. And I think this is in the stuff you're doing leads us down that path.
Yeah. What we like, I'll, I'll jump for a second to what we're doing. We're actually looking at the entire regulation that's goes around the world, uh, from the EUAA act that is now actually deployed in Europe, uh, for certain capacity, but there's no penalties.
They postpone the penalties. So, um, and, and then we make sure that if you do something, you do it once and it applies to few jurisdictions, you don't need to repeat that. So today, the technology is smart enough to actually distill only the things that are relevant for your internal processes, for the AI products that you're using and for the jurisdiction.
So it can be like almost tailor made. And it's almost like there is like investigator agents that are looking into things and make sure that you are complied. And so they actually look at the risks.
There is also something very interesting, uh, Chris, about what is the risk with ai? Like when I worked on medical devices and they give you a new medical device, and with certain technology, immediately you have like wired in your blood, all the risks that can happen with that device because you want to protect the patients. But here with ai, new things are coming.
You want maybe to protect democracy, you want to protect fair competition between companies. Maybe the companies that have more money and will buy expensive AI can beat everyone else. And you have new monopolies.
So there's lots of things that companies need to think about, uh, when they use AI and when they develop ai. So we're also dealing, uh, a lot with risk and what does an AI risk mean? And we found a new kind of way of how to predict what the AI risk will be.
Um, we can actually give them scores and like find like how risky some one thing is compared to the other and how to even mitigate that. So we build like a full engineering suite around a product that you are consuming, um, in order to predict the risks and how to mitigate them and risk, you know, this is something that, it's not like a vulnerability that you give it a fix and you're done. Risk is always there and you need to manage the risks and keep an eye.
So there's going to be like those AI agents or investigators as sometimes we call them to make sure that nothing change and like someone is watching that. So think about a company that's using a tool and suddenly they will change the tool to a new tool with a little bit adjusted model that got training from a different set of, uh, data. Is that going to affect the organization?
How do you do acceptance testing for that? Like where's the risks? Like there's so many complex questions about that, and sometimes it'll take you time to even understand that there was a change in the model.
You think it's just a minor change because you get the release notes and it's very simple, but you, after six months, you find out that the business results has changed from that. Well, and that, that leads us perfectly into our, you know, our last segment. You know, where are we going with this?
And what you said, you know, not surprisingly, I guess makes me think of what I mean by inevitability curve. Like any point we're standing at is what it is. You look at the future, here's the possible futures, and you gotta pick which one you like more or less and try to navigate towards that.
And the possible or probable futures are much, much less than the actual possible. You know, there's nearly an infinite number of ways life can turn out and the world can turn out at a market can turn out, but most of 'em are just incredibly unlikely. Um, so we're left with this range and you just de described the same thing with tools and regulations, like what actually applies to me, you know, I just don't have the time to read it all.
I'm just gonna take a fairly large risk and assume that I probably know the rules or, you know, I'm gonna read them all and have 20% of the less time to do what I'm trying to do anyways. Right? So it's narrowing that you're putting bounds on ourselves so that as we're making decisions, we know the boundary is kind of what we're here and kind of where we're there, right?
Instead of thinking that perhaps it's wider and lowering our confidence to be able to get things done, right. And I think that's of the, of the, you know, the inevitability curves. What I mean is this, I as a picture in my head, you know, I'm a DHD, right?
This is the way I just think about things. I don't mean a sharp line, you know, sort of a broad line. It's kind of cupped, right?
You know, it's harder to go up to the sides, you know, as you get to the less likely things in our context here, regulations, you know, maybe you know that those are possible futures, but just a lot of things have to line up where you gotta do a lot of work and straight down the center you at least resistance more time for other things, you know, you know, run faster than the competition in the capitalism sense or whatever it is. And so, looking past this transition where we're all figuring this stuff out, you know, and whatever timeframe you'd like, I think 3, 5, 7 years is probably about right. What do you think, you know, what do you think this implies?
You know, what are businesses doing differently? What are we all doing differently? What do we accept as sort of normal that today is something we're, we would talk about in a show like this?
I would say that, uh, I'll start with something maybe provocative, uh, but I would say that, uh, CEOs are the ones that might be replaced first by ai. They're just consuming data and they're making a decision. Try to maximize profit strategies, come up with things.
These are things that AI is doing faster. So in reality, there's going to be an AI CEO that sits next to the CEO and that's his working tool. And they will also have some discussions with few AI systems in the organization that will actually chat between themself.
Uh, if we discussed before about, um, AI that's using for forecast, the data or the output from that will go to the AI for that managing HR and the AI that's managing the inventory or the supply chain, uh, for the organization systems will make hundreds of decisions, uh, in a very short time. There's no way that humans can control that. But what happen if there is actually a feedback back from the inventory to the forecast because of a previous decision saying, Hey, we, we cannot have that component in time, so the forecast will go down and that can create some circular in organizations.
And I don't think everyone were thinking yet about that complexity. And the thing is that AI is moving so fast, like the new, uh, as, as you mentioned before, even uh, the federal, uh, executive order gives 180 days to come up with something and implementing it. And we know it.
You and I from other industry takes like two to three years once you have the regulation and once it's become like something that you force, and I think this is where organization must be responsible, I already see it happening, is very big organizations in the financial industry or uh, medical devices and even critical infrastructure that they are behaving responsibly. They don't want to be in the news and to hurt the reputation because mistakes that they do with ai. So I think, uh, the leadership is really with the business community and it'll continue to be with the business community.
And also we will see other probably, uh, bodies for, I don't know if regulation like the FDA, but responsible bodies that will make sure that there's like good or simple AI tools just to govern and make sure that we keep the business world intact and we keep even democracies. I, I think I agree with all of that and it's, you know, I think, think that through, because a lot of these things have been generally postulated, you know, the last num you know, handful of years articles written people talking about it, you know, the, and I think, you know, some companies, some people, you know, bound to try a fully automated fully AI companies. Maybe it'll work, maybe it won't.
Um, you know, and, and I share the general concern of AI replacing all of those people, but I think the CCEO wrote a good example, you know, so you and I, two examples. So you and I have written press releases together, right? And I've written a billion press release in my life, and one of the first things I like about the current generation of, of AI is just, sure, I'll write a press release, but I would like to just say it out loud and have some, you know, artificial intelligence intern draft it for me in 12 seconds and give it to me.
I can change it after that, change a couple lines, change a paragraph. But instead of spending a half hour of formatting, again, the same thing I've done a million times, and I basically, I want, I, I want someone to model my behavior for me to save the time. And I've done the CEO role, you know, like you have as well.
And like you say, it's basically a, it's a decision making, uh, role where you're trying to, you know, make decisions based on data. And I don't know, you know, as much as it's been talked about, the purely a company with a purely ai, CEO, maybe if you have a really good board who are actually, you know, active and running it and using it as a, you know, as a, as a, you know, forge for their, uh, their intention maybe. But I like how you described it, you know, as a CEO, just like writing press release.
I would like a digital version of myself, you know, to run through the data and, and model the decisions that I think I would make and present 'em to me and make a, and and act on a bunch of 'em. Because most of it is like press releases. Look, as long as you're not committing me to, you know, the company to insane things, put it out there, it's a press release, it doesn't matter that much.
It's not worth my time as a CEO and yeah, know the ad hoc, just like we're saying about regulations and rules and, and compliance as a CEO, I have got a bunch of internal rules and a little startup, it may just be my bloody rules. Um, but I'm trying to keep in my head all the time have somebody model those behaviors based on the data that I have before I do it. Even that's usually I would even, yeah, I would even take it, Chris, to the level of the board.
There is definitely, people are saying that today, there's like decisions made by AI and organization. How do you know how AI is affecting the decisions? Whether someone was using AI to write a press release.
I'm sure it saves them tons of time. Uh, did they check all the facts, really? Like is there a chance that something will go wrong with the team just trusting whatever they got from the, um, the AI from the LLM?
It looks so good. Sometimes you read it and it's like you stop thinking. So people need to really think.
But in terms of decision, is it like 5% today that like organization, the decisions in organizations, this is like how much is being done or is it going to be 15% of the decisions, uh, in next year will be done by ai? So how the board at the top, looking at the CEO and responsible with, um, the, the audit committee, how, how, how they make sure that everything is run well, they're liable in terms of that. So I think there's, like, it's going beyond that.
They will need tools to help them and move forward and a, as AI advances so faster than what we're expecting, and that's like something that, uh, we need to think more about how it'll be managed Well and yeah, and the, at the board level, you know, I, I think it just, it's, it works at every level I think. But the board has a nice caricature of decision making. Look how it actually gets done.
You know, you and I in our lives and the people we know and the boards we work with, and at the executive level of companies, we look at these huge corporations, right? Huge government things. And it's easy to say up there, there's these vast ivory halls where everybody knows what's going on.
It's like, no, most of decisions are made because someone talked to somebody quite often accidentally, right? You know, and you just are all human beings. And we say, I just learned something, my, my spouse, what they do, you know?
And since we talk all the time, they may, I said something about the deci decisions we're making here at the company. I mentioned something to them, they came back to me and that's got me thinking, and that's how all the decisions are made. So just imagine for a second that you had a thousand clones a year yourself or however you wanna look at it, who could actually get all the data in advance while you're busy doing things and, and it's still you making the decisions, but you don't have to, you know, because the deci the way we've made decisions in the past is so ad hoc is sort of a wonderful, uh, example of evolution that companies exist for the length of time at all.
Yeah. And, and think also about the business opportunity today when I work, and this is how I met you, it's because of connections. We have connections between us and will that going to be replaced by ai?
Because the algorithm will say, Hey, today you're not going to that show. It's not interesting, but you have the hunch that you must go there, how many time it happened to you that you went to somewhere you didn't know, but it came up like the best event that you've been there with lots of opportunities. And if someone even take it, like will control us or will suggest things, um, certain things you will miss the interactions with other humans.
And I think this is where also something that like when you look into the future, how do mean we maintain that? I mean, you and I, we saw the PC coming up on the eighties. We saw a wide range of technology happening, but my son didn't and he's just 20 and he communicates and he acts completely different.
He works with AI nonstop. So the world is changing and it'll apply changes also on societies and the interactions between people. Well, I don't think there's anything more intelligent I can say to wrap this whole, uh, conversation.
Of course, you can go on forever and we will, the ironic thing, you know, this is just a recording of a conversation, the kind of thing we talk about all the time anyways. And over the next, I think I, I think we both agree on the next handful of years we're going to experience this. We'll see whether you and I are right or wrong about some of these things.
You know, I think a lot of them are coming regardless at some point, but I really think this decade is the time for a lot of them. Yeah. Um, yeah, thanks for the opportunity, Chris to be here.
I think that together everyone, we will need to build, uh, trust in every ai human decisions that we're taking or we make, You know, we, and we don't seem to be running outta things, outta these sky and Skynet's gonna replace us all yet. And at our ages, I think we'll certainly, you know, finish our careers and still humans will have something to do. So on that note, yo wanna thank you so much for being such a good friend, colleague, all the work we've done together, you know, all the efforts you've been to be a good human being, made the world a slightly better place, and on such a small level on a scale, the time spent today with us.
Thank you very much. Peace. Bye.


