AI Organizational Responsibilities with Ken Huang
CSA recently published “AI Organizational Responsibilities: AI Tools and Applications,” the third in a series of reports centered on AI organizational responsibilities.
Transcript
This is Textron tv. Hi everyone. Welcome back here to Techstrong tv.
Um, really happy to have this next guest on with us. We're gonna be talking about a new report that came out from our friends at the Cloud Security Alliance. Let me introduce you to Ken Wong.
It's kinda like Jensen Wong, but no relation unfortunately for Ken. ai, and he is also the co-chair of the Cloud Security Alliances AI Safety Initiative working group. And I'm interested to hear some thoughts on AI and safety from him.
Uh, they recently came out with a new, uh, report on ai, organizational responsibilities for AI tools and applications. But let's first get to know Ken. Ken, welcome to Tech Drunk tv.
It's great to have you on here. Sure. Thank you Alan.
Nice to be here. Nice to have you. Um, so Ken, I, yeah, I gave, I gave them your title and obviously you're doing some stuff with ai, but you know, you didn't s start working yesterday.
Give people a sense of your career arc and, and how you came to be the Chief Artificial Intelligence officer, as well as the co-chair of this working group. Sure, yeah. Thank you, Alan.
So I look at myself as a ai, uh, researcher and also book author. I wrote a few books on the ai. Uh, I started AI long time ago, uh, when I was actually a PhD student, uh, in University of, we are studying the intelligent ing system, like teach, uh, the university kids the accounting system.
So I published my first paper on the ai, but at that time, it's, uh, law based. So now fast forward, uh, to the GPT movement. Uh, so, uh, when GPT two coming into the life before GPT-3 coming, like charter GPT come right, I actually realized that will be important.
So I start to write the book about the this, uh, and then eventually it, uh, was published by Spring. It's called the, uh, chat, DBT and the Web Studio, right, and the landscape of the tomorrow, the, or it's impacted. So this one is a hugely popular book.
It has like 27,000 paid view in spring alone. Uh, after finishing this book, I, because my, uh, expertise is, uh, more on the cybersecurity side. So I look at everything from cybersecurity kind of glass of view.
That's why I start to write the book with all this expert together. Write the second book on the generative AI security. That book is also published the by spring, uh, last year.
Uh, currently it has a 16,000 views, uh, or paid views in spring. So my next, uh, uh, spring book will be Agent AI, CLS and Practice. So, uh, the reason why I'm involved with, uh, uh, product Security Alliance, certainly Cloud Security Alliance is front in the cloud security and also in the AI safety and security.
We have the working groups, uh, four working groups. Uh, so I co-chair two working group One is the AI Organization Responsibility working group that I co-chair with Nick Hamilton, uh, from Open ai, uh, for his GGRC head. Uh, another one is AI Control Working Group.
So we actually last year produced three white papers. So one of the last way white paper from AI organization Responsibility Working Group is the paper we are talking today. Uh, but in the AI control framework, we are building the AI control matrix.
Uh, this already goes through the public review. Now we are to the next stage is to provide the auditing guidelines that actually right after this meeting, I will chair another meeting to with expert to define the auditing guidelines for a AI consumer matrix. So it's a lots of fun.
And I also joined, uh, the oasp, their opport, they initiatives some core member of Top 10 for larger energy models. So trying to push these things forward, make my contribution. Absolutely.
You know, so Ken, I've also been in security many, many years, 25, 30 years. Um, again, we've discussed this on our text on gang show show a year, a year and a half, two years ago when Gen ai, you know, really was first bursting on the scene, we heard the usual, the usual from the security industry, which is, Hey, go slow. Mm-hmm.
Go slow. As a matter of fact, this AI has more potential for, for, for bad than anything we've done, and we've gotta go slow. Of course, there was that very famous letter signed by a hundred very famous technology and celebrity people who said, we've gotta go slow with ai, we've gotta worry about safety, and we have to worry about security.
Um, and, and you know that this doesn't get outta control. Some people said yes, some people said no, but it was out there. Certainly over the last two months, three months, that seems to have all gone by the wayside.
Now it is. Get AI at all costs. Do as much as fast as you can, right?
Of course, deep Sea came out, it was kind of a Sputnik, if you will, a Sputnik moment where companies would say, oh my goodness. You know, maybe throwing all these hundreds of billions, these people did it on a shoe string open source, right? We've, we've gotta, we gotta go fast.
We don't wanna lose the AI race. Everybody's in an AI race, countries, nations, companies, you know, everybody's in an AI race. Have we grown security and safety to the, to the side of the road and said, that's not important anymore.
Or I mean, is is it just dollars that's at stake here? And, and, and so we're sacrificing safety and security? What do you think?
Yeah, so I think the key thing is safety versus security, right? So I think, uh, the things to chat the GPT movement, the focus is really a sudden kind of waking up and say, oh, wow, this powerful, or it can make, right? So the idea is more like on the safety side, uh, especially on the dooms, they see like end of humanity, like, or it can make the damage.
So that was the like, uh, last year and, uh, since the charter DPT movement and there's a lot of, uh, people behind it, certainly, uh, I, I would say this is more theoretical in my book actually, generative AI security book. I do not say it's a generative AI safety book on purpose, because in the book I said, this is all theory actually for the enterprise to really implement, leverage the intelligence from the larger land model, uh, you really need to focus on the security like CIA side of it, right? It's, uh, it's uh, too far away in terms of end of humanity.
So in the last year, we always look at the future to see what the damage, um, should take. But this year we actually have a wake up moment say, okay, this is powerful, but not to the extent that it can end humanity. We actually really need to leverage the brain, which is a larger model to mine, the intelligence of format to build our application, especially the agent AI application.
This is, uh, certainly the next wave. I am involved in the cloud security alliance agent AI security initiative now, as well as oasp. Uh, so we actually will announce a initiative soon, uh, in partnership with oasp AI Exchange to say how we can actually test agent tech, AI security, or rather team it so that we'll announce soon and keep tuned.
Uh, so the key is like, uh, JD Van in the, uh, AI action summiters, right? Uh, mentioned that it's too much regulation that's maybe, uh, kind of inhibit the, uh, innovation and also, uh, chump the kind of appeal of the exact word, biden's, exact word on the ai. There is some reason I think the, uh, behind it, uh, is that with us not yet to, especially from the enterprise workflow perspective, it's not the doomsday yet.
We still need peoples like IA who is chief scientist of open ai, right? He's good, he need focus on that, that is really good for humanity. But the industry folks, not everyone doing the same thing, right?
The industry focus is given the deep seek or open AI lama, those are good models. How can we leverage this model to build useful applications and also make make sure this secure, right? That is the focus now.
So, uh, i, I will also speaking at a agent AI security summit in New York City, uh, the end of next month, uh, that was organized by some cloud industry initiative, especially, uh, they have the agent AI security anywhere kind of slogan for their company. So yeah, I think the conversation will start soon about the, uh, the security aspect, not the safety. So just, uh, a distinction, right?
Safety is more focused on the, uh, dunes they like as harm it can make, and also CBRN or chemical, biological, radioactive nuclear aspect of it, right? And security is more focused on the, uh, CIAs the confidentiality, the integrity, availability of the AI system so we can actually leverage the AI intelligence to streamlines our business workflow. So that's a distinction.
Excellent. Excellent. Ken, I probably took us down a rabbit hole.
I didn't realize. I didn't mean to, but it was nevertheless valuable and good discussion. But I did wanna discuss with you today this new report that your working group is published and CSA is published.
Give us an idea on the report, and I always like to say, Hey, what were the, in your mind, what were the top three key things in this report people should take notice of? Right? That's very good.
Yeah. I al always, it's really good. I always like, there's so many point we need to take a three top point, right?
That's also like we have su white paper in terms of responsibility for the organization. There's so many responsibilities. So we say, okay, we take a three white paper.
The first white paper is core responsibility, focus on model, focus on the data, focus on the vulnerability. The second one is more from the GRC and the culture aspect, right? The third one is actually you put it into use.
You building the application, you have the tools, uh, that you need to use. Uh, what's the responsibility? So the three, uh, key take away from that is first we actually look at the responsibility from like the measurement.
How do you measure it and how do you actually, uh, have the matrix, uh, to measure and also the what kind of, uh, laboratory, uh, regulation were impacted. And also looking at the Laci model, who is responsible, right? This laci model is important.
So this is kind of cross cutting behavior we have. And then the second one is really, uh, in terms of application, if you really build application, especially the agent AI application. So keep in mind that, uh, in the future the majority of AI application will be agent AI application.
Because if we really define defines agent ai, it has a certain level of autonomy. If you look at the deep research from open ai, it has agent behavior. You give a topic and it will break down the topic and it using different tools to search the internet.
And then, then it has an agent to summarize the, uh, text. And then there's another agent to analyze the content and then produce the report. Uh, another agent is just produce a report.
So this is already like in use now the, the agent, right? So we, how can we secure it? So that's the second point is when we develop application, what is your responsibility to secure it?
And the final one is really the supply chain. It's you have to leverage the third party tools. So how are they secure?
So we process this responsibility into the 70 pages document. We try to cut it, but uh, I think it's important that to put things there and people can, uh, look at, uh, look at and filter it. So, Agreed.
Agreed. Ken, you know, those are three meaty things we could jump into here if we had more time, but unfortunately we're coming on the end of our time. For people who want to maybe get the report though and dive into this, just wanna make sure I got this right.
org, right? org. It's dot org, Right?
Excuse me. You know, I was there at the RSA conference in like 2005 or oh six when they formed the, the CSA. org, and then if you look under research projects and look for AI or AI safety, it, it should show up there.
Um, Ken, what about for people who maybe want to get involved in this working group? How would, what would you recommend to them? Yeah, uh, uh, so Colorado Security Alliance has a circle like application.
So the, once they get to the, uh, working group homepage, they can assign up and goes through the circle. The, uh, beauty of, uh, joining the circle is they have access to our document, uh, is, which is Google document. So they have access and they can also get invited to the, uh, meetings.
But our meetings open, like if everyone interested, even they don't, do not want to join Circle, they can still participate in the meeting. We have open meeting people sometimes just join, uh, to learn something that's, we welcome. If you really want to learn something, it's okay.
And some people really want to contribute, so that's also really welcome. So yeah, it's, it's, that's Fantastic and that's good that it's open like that too. And that's something I know Cloud Security Alliance has always been there.
Working groups are always very welcoming to anyone who wants to, you know, participate. Yeah. And thanks for coming on Techstrong TV here today.
Appreciate it. Keep up the great work. This is, look, this is weather.
You know, money gets in the way of safety and security. Sooner or later, people always get smart and they need security and they need safety. So the work you're doing is very valuable and important and keep it up.
We thank you. Yeah, thank you. A uh, one more thing I just want to add is the UK government just changes their AI safety in institute to AI Security Institute.
There you go. So that's the trend, right? Yeah.
Excellent. Ken Wang, chief art artificial intelligence officer from distributed apps do AI as well as the co-chair of the, of the Cloud Security Alliances, AI safety Initiative, working group, maybe Safety and Security Initiative working group. Soon, yes, here on techstrong tv.
We're gonna take a break. We'll be right back.