Wasim Khaled on Why Disinformation Has Become a Board-Level Risk
Blackbird.AI CEO Wasim Khaled discusses why the spread of disinformation and misinformation has escalated into a critical board-level concern, especially following the company’s recent $28 million funding round. He explains the growing business, reputational, and security risks driving executive attention.
Transcript
Hey guys. Thanks for the throw. We're here with Sem Ked, who is CEO of Blackburn ai, and we're talking about, well, they just raised $28 million in additional funding to help combat misinformation and disinformation.
Wassim, welcome to show. Thanks for having me. We've been having, I don't know, disinformation and misinformation for as long as anybody can remember.
So, um, what's changing now in the age of AI as we look at all this stuff that's making this a little more problematic and maybe something that, you know, is, requires companies to think more about rather than just saying governments and media companies? Yeah, absolutely. I think the first thing to establish is absolutely disinformation, misinformation and, uh, and, and trying to shift people's narratives.
Uh, and perception around things have been around, um, probably since as long as the, the written language in, in the, in the printed press. Mm-hmm. Um, you know, about 10 years ago when we really started researching this area and then formed the company about five years ago, um, the idea here was less about, you know, your traditional fake news disinformation that people were talking about, and more about how is the narrative being manipulated to shift people's perception, uh, shift people's ideology, belief systems and their, and their view and understanding of reality.
Right. Um, and so, you know, we looked into this space through this frame of understanding growing narratives in the information ecosystem, how they spread through networks and, uh, trade craft driven by actors and adversaries behind those narratives for, uh, purpose on the other side, be it, um, financial reputational, uh, or even physical harm. Um, I think in the age of ai, the number one thing is the cost and the effort to build out and distribute those campaigns to build, to, to spread those narratives through networks.
The cost has dramatically dropped. Um, all of these different barriers, cultural language, all of these things have been subverted by the use of generative ai because a small group of people can target almost any topic anywhere in the world, um, and do it much more effectively than they could have even three years ago. Right.
Um, and, and now with, uh, agent, uh, technologies, you can not only create that content, audio, video, text, et cetera, but you can also create the network effects by building out bot networks that can operate autonomously without a human operator. And that's already happening, uh, in the space, which we can see using our technology. I think that's the biggest thing is, is cost compression easier to access technologies that are very powerful, that enable these campaigns to be done with the precision of what used to take a nation state to do with the, with the single actor.
Are these campaigns aimed at nation states, like political parties? We would expect, but I also feel like more of them are being aimed specifically at companies, organizations. Somebody wants to move a stock price, they're getting very subtle in their mission statements, but they have a goal.
Absolutely. So, you know, when I say nation state attacks, sometimes there are, uh, state actors, but they're often also involved in narrative attacks on enterprise organizations. Um, and again, some of that may be financial, it be maybe using the organization as almost like a lightning rod to, to prove a point, to drive their narrative home.
Because you can attract more attention if you, if you go kind of through a well-known Fortune 50 or Fortune 100. It's why a lot of the, the companies we speak to today, they feel sideswiped. Like, why is the general population online so interested in this thing that happened?
Will often, thousands of those were actually bought networks trying to decrease stock price while short sell on the other side. Or perhaps that company did something that doesn't align with the adversary's ideology. And so they're making a point, uh, making a statement by attacking that company and, and driving a narrative that can harm.
What is an organization supposed to do about all this? It's one thing to be made aware of it, but what can I do to kind of mitigate it? Or is it just a matter of, you know, once I'm aware of it, I gotta put out the counter narrative?
Yeah. I think one of the first things is understanding, uh, the intent in who's behind it, right? And, and is a narrative attack actually occurring?
Because a lot of people look at these traditional, um, social media insights, so sentiment, keywords, topics, things of that nature. And they may think that the actual population or their audience or their customers are saying and, and feeling these things about the, the thing that they might have done or they have been accused of doing or whatnot, what whatever it might be. Uh, so being able to understand what's actually happening, like the telemetry behind what's happening within the networks, the contagion like spread of that narrative, it helps them make strategic decisions.
It all comes down to making better decisions in the end. And once, and those decisions could be, like you said, um, helping to pre bunk something that might be out there. Um, being able to get those people around the table that typically happen during a crisis.
So whether that's a chief information security officer, a chief communications officer, of course, the CEO or any board members, investor relations, marketing, all of these people have to go around the table when there is a major, uh, event that impacts the organization today and together, uh, using a lot of the signals that we can provide, being able to understand what's happening and how to mitigate that and run a playbook, understand the techniques and tactics helps you understand what you're actually in for and how to disrupt, um, that potential bad outcome and those bad outcomes. Today, they might be a shorted stock, a stock price hit, but it might be, um, an attack on an executive like a CEO or someone else on your team or a physical location, um, or, um, it might be something that actually looks to create supply chain damage by driving, you know, activists, boycotts against a particular location. Manufacturing a particular ingredient could be a lot of different things.
Um, but I will say threat actors are highly opportunistic in looking for that opening. And that opening could be something very innocuous. It could be as something as simple as a, as an HR statement or policy on a website.
And then it's about taking that opportunity, recontextualizing it, and getting it in front of as many people who that recontextualization will get up in arms. Right. And wouldn't have happened without that trade craft.
And that's key is seeing that trade craft making strategic decisions based on being able to see what's really happening. Yeah. To what degree is this becoming a business?
'cause you know, we've seen things like ransomware as a service, and I can't help but wonder if there's gonna be disinformation as a service where somebody has this capability and you can hire them and contract them out to do all kinds of malicious mayhem. Uh, you mean, uh, uh, business on the other side? So yeah.
Are there disinformation for higher, uh, companies and or individuals for sure. Right. Um, and, and there's, there's individuals and there's also entire teams.
They've been around for some time and they weren't really doing this line of work in the past. I mean, everyone knows the stories now of like these massive click fraud, um, you know, factories essentially people, devices, et cetera, in different countries in the world that have been, um, doing that kind of work. And, and you see a lot of those, uh, types of setups for this kind of work as well where you did some years ago.
Now they're able to have gotten smaller because they can use a lot of technologies to do what used to take, you know, dozens and dozens of people, um, to actually do. Mm-hmm. So what exactly does your company do about all this?
I mean, I assume you're listening for signals or aggregating that, but how does that become something that manifests itself as actionable intelligence? Yeah, so what we do, um, talked a little bit about it before is we look at the data through three lenses. Um, we talked about that it's, uh, it's narratives, networks, actors, and that actually enables you to see a whole host of techniques and tactics that can be tied to response playbooks.
And those two playbooks typically now are usually comms and threat intelligence. That's kind of the, the hybrid, um, you know, people behind the, the keyboards who are looking at these types of problems. And we'll see organizations that are using our technology next to technologies like recorded future and things of that nature, be able to look at a different attack surface and therefore be able to make decisions more holistically.
Um, and they'll also be like an executive view of these things because every CEO and board, um, the problems that keep them up at night, um, are a lot of the things that we can help them understand when they look at narratives of, of high risk to them. And then of course, um, you know, one of the really interesting things is going into the next quarter or whatnot, we are actually working on our own automated response playbooks that can recommend exactly what to do based on the signals that our system has been detecting for several years now. That's the natural next extension of the product.
So who in these organizations kind of takes the lead on, uh, adopting a platform like yours who kind of wakes up in the morning and decides that this is their problem? Well, it depends on if they're in the midst of a crisis, in which case they definitely know, uh, who they're gonna, who, whose neck is on the line. Uh, but you know, typically when we're looking at proactive, uh, you know, inbound, let's say, um, again, people who wake up thinking about it, it's usually a chief communications officer or someone who's like a head of crisis comms, or it is someone in the threat intelligence team.
CISOs usually aren't like waking up thinking about this. A few of them are, and, and we work with some great ones, but usually someone in threat intelligence. Um, and it's, we're a new category, right?
Um, you know, so we, we are, we are one of those things that, that people don't really know who's in charge of that particular, um, problem set because it is new, it is hybrid, and you know, sometimes, uh, companies don't know who's on first, you know, and so a a lot of the inbound that we have, it's a lot. It's like it's during a crisis and it's whoever's been tasked with that thing. But I will just say comms and threat intelligence are the two most common.
We have a lot of people around there that we can expand to everyone from legal compliance to m and a investor relations. Um, but the two most common ones historically, um, are the ones I mentioned, CCO and, uh, threat intelligence. With this reporting into the ciso, Can we discover who's actually launching these attacks and maybe, I don't know, get the local authorities to respond in some way or to block their systems?
I mean, how aggressive and offensive can we? Yeah, Yeah. I mean, there, there are likely ways to do that, but it's just not the business that we're in.
I mean, typically what we're doing is we're showing detection within the information ecosystem, uh, and we don't really bridge to like, you know, who's sitting in that seat at that location. It's just not data that, that we consume. And it's not really business that we're interested in getting into.
We're more about, uh, narrative intelligence, uh, versus take downs, um, take downs. We do partner with some companies that, um, that do that kind of work. Uh, and so that's usually the approach if a customer really needs it.
And that's usually, um, particularly if it's like a executive protection and threats on life, um, you know, not, not the other types of things that we've been talking about. Um, we started this conversation talking about ai. Is there some way that you'll be applying AI to what you guys do, or maybe you already do, but, um, you know, there's a lot of different types of ai.
So, you know, where do we go from here as we kind of start 2026? Yeah. You know, we, we got our Blackbird AI domain before it became trendy to do so, um, you know, way back in like 2016, I think.
Um, but, uh, yeah, so my co-founder and I are both computer scientists, um, specialists in ai. A lot of our early founding teams we're, you know, longtime artificial intelligence, uh, specialists at Microsoft and Yahoo and other research firms nuance. Um, and so AI has been a core part of everything we do since the very beginning.
Um, all of our like actor detection, we've got hundreds and hundreds of, uh, AI models that are, that are tuned and calibrated to that. But more, more recently, um, in the last, uh, year and a half or so, uh, a lot of our stuff is, um, LLM outputs to make human readable reports. There's a lot of automation.
Um, we have, uh, a agent called, uh, compass, and that compass agent is like a context checking agent that goes out and like brings all kinds of relevant information back to you. So I would say AI is infused into every, every bit of the platform, um, today. And, and as we go into like more of our agentic response playbooks, it's, it's just gonna get more and more, uh, advanced and integrated with some of the newer technologies, natural language interface, et cetera.
Mm-hmm. So what's your best advice to folks or kind of, what's that one thing you see organizations do and they get confronted with these situations that just makes you shake your head a little bit and go, eh, guy, I think we need to be a little bit smarter than that. Yeah, I would say that probably it's pretty simple.
Um, it, it's just that people need to have some real awareness around what we call a narrative attack, that they exist and that they're likely gonna happen to them at some point. And a narrative attack as we defined it, is it's kind of this host of different symptoms. We're trying to find a name for narrative attacks as we define it as tradecraft, that drives some sort of outcome in the information ecosystem that can cause massive financial, reputational or physical harm in a way that would've never happened organically if someone wasn't making it happen.
Right? Manipulating the environment to create an outcome that they want that is going to harm you if people don't understand that that is happening. That is the one thing I would say is you have to wrap your head around the fact that this is a, a regular occurrence, no black swan event.
Now it's happening all the time to our clients. Um, and if unless you can detect them, you, you don't even really have a chance of understanding how to make a strategic move to make the situation better. So, um, and the only way to do that is to deploy technology and kind of fight fire with fire because, um, the ones who are doing this have been really, really adept at, at adapting to the AI driven world.
So, so, you know, the, the customers and leadership teams need to do the same. All right, folks, Sharon in here, sadly, there are people out there who apparently don't have much of a soul, so they got nothing better to do than create narrative attacks, but to be forewarned, just to be forearm. Hey, SEM, thanks for being on the show.
Thank you, Mike. Appreciate it. All right.
And back to you guys in the studio.