De-Risk AI Adoption With Trustworthy AI with Pamela Gupta at AIE 2024
The EU AI Act and Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence are centered around trustworthy AI. Learn about trustworthy AI and how it impacts your business risks. Viewers will walk away with ideas for creating a winning AI Strategy with risk management and governance.
Transcript
Welcome to Trusted AI de-risk adoption of AI with trustworthy ai. My name is Pamela Gupta, and I'm CEO of trusted ai, and I'm going to talk you through about what is trustworthy AI and why it is so critical for businesses to adopt it, uh, by looking at contextually what are the risks that they can come across, and what is trustworthiness when it comes to ai. Also, why is this such a difficult problem to solve?
Let's take a look at what Gartner's position is on trustworthiness. By 2026, organizations that incorporate AI transparency, trust and security will see a 50% increase in their AI model adoption adoption. And not only that, the impact on business is alignment with business objectives of AI systems delivering on what it is that we are trying to achieve in terms of business outcomes.
A very big part of that is user acceptance. And when we look at what is the meaning of trust and the impact on users, we quickly realize that this is a multifaceted and extremely large, complex problem to solve. For the only way, in my view, that we can achieve trustworthiness and achieve AI superiority and AI adoption and deliver on that AI promise, is if we take a holistic approach to not only what those risks are, but how they are interrelated.
In other words, a holistic approach to trustworthiness based on what the business objectives are, what the impact is, and what are the interrelationships between them. I also feel very strongly that we cannot realize the full potential of AI without building trust in ai. We cannot achieve the intended outcomes with build without building trust in ai.
So you may have a question. We have been doing ai, um, not well AI also for some time now, but we have been using a risk-based and a governance approach in companies and in organizations. So what is new?
Can we not just take in our existing risk programs and extend them to ai? One common misconception is that AI is another software or another tool. The fact of the matter is these are very complex and high impact systems.
So to generalize across when it comes to the risk management is not as simple as just extending ex, uh, internal and, uh, external and internal existing risk mechanisms, risk management mechanisms. So let's take a look at what we stand to gain. 7 trillion.
If we look at the reference for what is trillion dollars, right? 7 trillion is roughly the second and third largest GS in the world combined for, uh, when it comes to countries, it is a large, significant and very impactful, uh, promise, as well as what will be a motivator for countries to lead with who whoever comes and, um, solves for the AI promise, right? Does stand to significantly gain as global leaders.
So in other words, what does that mean? Countries are looking to capitalize on using AI to become, uh, not only the ai, um, leaders, but also to provide significant economic gains for businesses in their countries in their own country. But the problem is there are these are not, as I had mentioned earlier, these are not simple system.
They're high impact. The risk around them is not understood to a degree that we can solve for it in a trivial fashion without taking a holistic approach. This is not something we can solve for.
So I have some quotes here from world, uh, either, uh, global thought leaders or business leaders, and I won't go through all of them, but I will pick one and talk a little bit about what that means in terms of an impact for a business. So taking a look at the first one, which is the rapid expansion of AI technology, along with existing integration into various business and social operations, often surpasses the current risk management capabilities of organizations. This is due to several factors, including the lack of widely accepted standards for AI risk assessment, a shortage of experts, knowledgeable in both AI and risk management, and the underestimation of the complexity and potential impact of the risks, uh, uh, associated with implementing AI systems.
So in other words, not only do we not know exactly how these systems work, there is the, the, um, you know, in new, and you all heard of the opacity of the system. Not only do we not e exactly always know how they're working, but they are also very dynamic. These are not static systems.
They are growing because they feed on data, they learn with data, and as the data changes, the AI systems themselves change and their, um, their impact and their, um, um, understanding of how they're working, of course, is going to be also be very dynamic and it's gonna change, uh, rapidly. So how do you put your hand on that pulse of change? And what is involved in managing that risk?
After all in uncertainty is the opposite of risk management, right? I will, uh, not go through all the other quotes, but the underlying message is the same, that there is complexity when it comes to risk management of AI systems. There is not enough, uh, skills to handle that to that, uh, people who understand, um, experts who understand how to manage those risks.
And consequently, the impact is there's not enough, uh, resources to solve for this problem. But also businesses are not recognizing that this is in indeed a unique, uh, issue that needs special handling. What we are seeing though is regulations that are being crafted or have already been put in place, such as the EU AI Act that will be, um, come into application in the next two years.
The text has been finalized, the White House AI blueprint, which message in intent, not how to do it, but the intent is quite clear in terms of the objective, in terms of what is expected of AI systems. And there is a common thread between both these, um, uh, these, uh, regulations and the executive order, which is not quite a regulation, but the impact is and what the expectations are that AI regulatory landscape continues to mature. That's one thing.
So it's not exactly set in stone. One thing, that's one thing. The other is the expectation, which is they are, the expectation is that the in AI risk to be reasonably ensure equality and transparency and to provide trust in automated systems.
In other words, the expectation is that these systems are going to be trustworthy. The challenge then comes what is trustworthy? What if there are no standards?
If there is no set regulation, or if the regulations are high level as they should be, then what does it exactly mean for a business when it comes to taking action to solve for this issue? If we just look at the EU AI Act expectations and which is a risk-based, um, regulation in, in other words, depending on the impact of the AI system, if it's a high risk system, then these are the requirements, uh, for the high risk AI systems. Now, one thing I'd like to point out here is it calls out the EU AI Act is talking about risk in terms of unacceptable risk, high risk, limited risk, and minimal risk.
And the risk is based in, in terms based in, uh, in terms of the impact when the system is built, the impact, what is the impact, but can that impact be different as the system continues to build? As I've mentioned earlier, these are dynamic systems and they are, uh, actually not set in, uh, stone or very static. So even a reregulate reliance on regulation for figuring out what is the impact of the system that you are building can be a challenge if one does rely on the regulations, which again, is not gonna be simple, but let's just take a look at for what is a high risk impact system expectation for, um, based on the EU AI Act.
The first one is to establish risk management systems throughout the AI systems lifecycle, conducting data governance, ensuring training, validation and testing. Data sets are relevant representative of, um, the, um, scenarios that they're gonna be implemented in to the best extent possible and free of errors and complete according to the intended purpose. Number three, drafting technical documentation to demonstrate compliance designing systems to allow automatic record, record keeping.
So you can already see the requirements are going to be, uh, slightly different. And to meet that is gonna be very different, uh, posturing by the business because these are not a mechanisms that exist in a current state. But also, if a system is changing and you are supposed to show, uh, how they're changing transparency and provision of instruction to deploys to ensure compliance, to show, uh, automatic record keeping, in other words, auditing in a continuous fashion, that becomes a very, very big challenge for most companies and for most implementation.
Last, not, uh, but not the least transparency and provision of instructions to deploys to ensure compliance designers designing system to allow human oversight and achieving required levels of accuracy, robustness, and cybersecurity. I come from a background of 20 years of creating cybersecurity strategy and risk management. And I can tell you cybersecurity for AI systems is not something that is well understood in our current state.
It is extremely d different from existing mechanisms of even doing, uh, security of static systems, which has not been perfected. You know, every day we are hearing about, um, incidents including ransomware attacks. So when it comes to how are we going to protect these, uh, massively impactful systems, which have a different threat model, and not only, and to complicate things even more, there is predictive AI and there's generative ai, and the threat models for both of those systems varies significantly.
So I group, if anything, uh, one thing comes clear from this particular, uh, point on this slide is cybersecurity is one aspect of making sure that these systems are, are, they have data governance, they have cybersecurity, they have, uh, risk management throughout, but it's not something that can be achieved with our aa, our existing, um, way of managing risk and be our current, um, approach to handling risk throughout lifecycle of a system. And this I already mentioned actually, but I'll highlight it again, that many properties of trustworthiness are relevant regardless of whether a system is high risk. For example, properties related to safety and quality and sustainability tend to matter regardless of application area, which means that it is critical to consider trustworthiness even for AI applications that do not qualify as high risk and frameworks for trustworthy AI that primarily focus on high risk applications may not be sufficient.
What I had alluded to was what you are when you are starting to build out something, it may not be a high risk or it may change. So even at the time of development and post uh, deployment, it may actually, um, have a difference in the, uh, the type of impact. Now, let's take a look really briefly at NIST AI Risk Management framework.
NIST created a, the first of its kind AI risk management framework, and it focuses on trustworthiness in, in terms of managing risks and designing to address risks designed to address risks throughout design, development, use and evaluation of AI products, services, and systems. But the focus that is on trustworthiness is really important to understand as to what, how they define they're defining trustworthiness and where the risk management is applicable in the design, development or deployment. So regardless of whether you are creating a AI system or you're deploying one, um, there are going to be risk management concerns around and issues that you have to address when it comes to trustworthiness throughout that lifecycle and throughout, regardless of whether you're deploying or uh, adopting.
And if you take a look at what ai, uh, trustworthiness, um, factors are, if you take a look at valid and reliable at the, at the base, that kind of sets the foundation for all other factors and also accountable and transparency also is going across these, um, uh, attributes. Uh, we look at what the other attributes are, in addition to being valid and reliable and accountable and transparent. They are safe.
These systems should be secure and resilient, explainable and interpretable privacy enhanced and bias. So again, uh, this is now defining what is trustworthiness. The challenge is each one of these is going to be very contextual based on what the system is doing, how it's created, where it's implemented, who it's meant for, and there are no standards to achieve any of these.
When it comes to ai. We are seeing implementations of and creation of AI systems. What we are also seeing is without regard to the trustworthiness factors, why it becomes problematic in this one.
The first example that I have here is Black room, which, um, has created a model for, um, market risk and, um, liquidity. They shelved a, their, um, AI system because the executives were not satisfied, uh, with the explanation on not only, uh, the, what the system was doing, it was creating predictions that it was coming, providing output on why a certain decision or what a certain decision was when it comes to, um, came to market liquidity, but not able to provide insight into how it came to that conclusion. And the executives for BlackRock decided that it would not be, that that would not be sufficient, you know, just because it is making better predictions and better decisions, uh, uh, is not good enough unless we can explain what was the premise and what was the, uh, reason for that.
Now, lot of these systems cause upwards of millions of dollars to create. So, and there is a business intent behind creating these models and systems if the one does not have those factors of trustworthiness when it has been built. And you have to undo everything that is a significant cost in, not only in terms of resources, but also in eroded, um, business objectives and value.
So I won't go through all of these examples, but the, the point I want to make here is regardless of the industry vertical, these trustworthiness factors are pretty horizontal in terms of meeting business objectives, meeting trust objectives when it comes to adoption of ai, uh, by the users or in this case even, um, by the, uh, management and the, um, executive team in this case. Um, one quick example also I wanna mention is a, a mortgage approval algorithms, you know, how they are exhibiting bias towards and against, depending on where you're looking at it, um, against certain factions, uh, or based on ethnicity or, or race, for example, or color. Um, uh, this is not only is it discretionary, it's non-discretionary anymore.
Um, the regulations that have been put in place and are coming down, there are about 500 bills in the Congress right now, um, in the US alone, and all of them are moving towards making sure that these systems do no harm. They're not biased, they are explainable. There is transparency, they are secure, there is privacy.
So these factors of trustworthiness are extremely critical for business to consider. I'm going to give you one more example, uh, one more, uh, we'll go through one more slide before, uh, I conclude this. And, um, so five years ago, this just came out with their ai, RMFI had mentioned.
That was the first of its kind last year. I've been looking at this problem for the last five years and had defined a framework and eight essential pillars of trustworthy ai, which is, um, years before had been tasked and came out with that. These are the eight pillars, and what I'm showing on the screen is for the eight essential pillar of trustworthy AI as defined by, um, which I had referenced in earlier by trusted ai, which is the company I'm CEO, showing that what they are and how we are currently seeing expectations or companies getting fined for not complying with or being aligned with that trust when it comes to, uh, trust factor.
So, uh, the eight pillars are security, privacy, transparency, explainability, ethics or bias, audit regulations and accountability. By the way, NIST had defined seven, I had defined eight because I included regulations as a part of what is that holistic view we need to take when it comes to trustworthiness. And the examples I'm giving here are fallouts that are happening in our implementations of AI by these different trust pillars.
And how, um, even with existing regulations, let alone ones that are shaping up and coming into, uh, existence such as the EU AI Act, how these under even existing, uh, regulations, companies are getting fined, uh, for not complying or delivering systems that have these trust, uh, characteristics. Um, let me just pick one. Trans Uber is, um, uh, has a currently is accruing fines for not being able to show transparency into why they had required, um, three drivers.
One of them, they were able to show how their, um, automation and their algorithmic, um, decisions were made, but for two of them, they were not able to show what the, um, these firings were based on algorithmic, um, uh, decisions, but they were not able to show, and I have not until this date. So they are still showing, uh, accruing fines. It's now more than half a billion dollar or half a billion euros, um, that defines our accruing.
There is an example that I have here of a German bank that was not able to show explainability as to why they gave a certain credit, um, a score and a credit rating for their users, which caused massive rollouts for the users. They, I had to pay a fine for that. There is a fine for, for TikTok for not being able to show transparency.
So that is under base. 7 million pounds by the ICO. So these are examples of, I won't go into each one of them, but I will share these slides with you later if, uh, you are so inclined.
The one big biggest takeaway for and from this is trustworthiness, risk management, AI governance, however you want to look at it, is going to be different from existing mechanisms in place. And it is extremely important for companies to bake the and integrate these factors depending on their use cases before they even design the system, let alone when they implement their or post implementation because it has a very high impact on society, on the business, and of course in terms of meeting the objective that these systems are being needed for. So with that, uh, I'm going to just, uh, reiterate what those eight pillars of trustworthiness are and why it is extremely important that we create and take a holistic approach when it comes to, uh, creating and implementing and adopting AI for best use.
Thank you.