The Last Great Cloud Transformation Navigating Data Compliance Challenges in AI-Powered Cloud Transformations – Webinar
Transcript
Hello everyone. It's Alan Hummel for Techstrong welcome. Welcome to another edition of the last Great Cloud Transformation.
As I was telling our guests, our panel members in the green room, you know, we call it the last great cloud transformation. 'cause maybe today it is. Who knows what tomorrow brings my, my experience in technology is anytime we say this is the latest, greatest last, it, there's always something else.
I was talking to someone this morning who was at SC 24 conference in Atlanta this week, and there were not one, but two quantum computers on display there, right? Because a lot of stuff going on in, in, uh, HPE in, in high powered computing, HPC and, uh, stuff like that. So who, who knows, maybe, we'll, we'll be talking about transforming to a quantum cloud five years from now or something, and that'll be the last great cloud transformation.
But, um, anyway, for now, this is the last great cloud transformation show. And, uh, this show that we do every other week, it's usually a prerecorded session with a great panel similar to what we have here today. But then about once a month or once every month and a half, we do it live with a live studio audience.
And it really turbocharges things because we, we, uh, we ask our audience to be involved. We ask our audience to help drive the discussion. If I had my way, I'd give each of you, you know, well, probably each of you have a camera, whether you're watching on a computer or phone or what have you.
But I put each of your faces up here on video and, and we can all have a big discussion around this, but our testing with audience, you guys don't like to do that. You've gotta ask questions sort of anonymously in the chat than, than to come on board, but that's okay. You can do that too.
We use this big marker, uh, platform here for our webinars and round tables. And one of the reasons we do is the big market communications panel, which for most of you, it's in the right hand side of your, of your web browser. And you can see up on top, it has the word chat in black, and then underneath it, there are different kinds of chat.
For this, uh, event, we really only use public chat. We, we discourage using private chat because this isn't, uh, uh, Tinder or something like that. We're not, you know, we're not looking for you to, private chats can get a little weird.
Some people are not comfortable. So the public chat is the way communicate with us. Obviously, public is public, so when you put something in there, everyone who's in today's webinar or today's ground table can see what you wrote, not just me or the panel.
So be mindful of that, but feel free to put in whatever you want. And, and if you're in the audience and you wanna add on pile on answer what someone put in their chat, feel free to do that as well. That's what makes it a party.
Um, as you can see, a bunch of our, uh, a bunch of our, uh, panelists have already said hello from wherever they are. I see my friend Paul p here, Paul p comes to a lot of our round tables. I love having him in, he asks great questions.
So Paul p, good to see you. Um, but, you know, feel free to let us, I always get a kick outta seeing where everybody is from on these things. So come on in.
Uh, if you do want to ask something though of just the panel that you're not necessarily into having the rest of the audience, see next word chat, next to the word chat. You will see the word Q and a. And, uh, q and a is just that q and a.
It's what you can put in a question for q and a, and we can, um, see what's going on there, right? Excuse me, I'm trying, I'm getting mixed things on my computer. Q and A allows you to ask something exactly of our panel exclusively, exclusively, and it doesn't go to, uh, the general audience.
So feel free to use that. And generally, if I see something in q and a, I'll bring it right up to the panel anyway, so it's a good way of getting my attention. So that's the, uh, that's the communication panel here on big Marker.
Let me next turn to our panel. We're, we're blessed to have a great panel today. First I want to introduce you to my, my, my friend at sea.
He, he actually comes to us from his boat, which is, is docked off, is it Smirna Beach near there, right, Chris? Today? Yeah, we're, you know, a little windy, a little cold, so we can navigate it in some nice channels to give us cover and lots of solar power and so forth.
Yeah, we're anchored out among the dolphins, And, uh, bill is on his not Bill. Chris is on his way down to Key West eventually, and hopefully he will pass by my house on the way. We'll get a chance to grab lunch or hang out for a few minutes.
Uh, but Chris Glasco, well, Chris, why don't you introduce yourself. I don't want to embarrass you. Gosh, I've worn a lot of shoes.
I spent the nineties doing a lot of firewall stuff. I think, you know, sort of pertinent to our topics now in the two thousands and, you know, to this day, but been focusing out, I guess, a lot on situational awareness, started with sim and, uh, and, uh, you know, ISACs and threat intelligence. You know, these days I'm Vice President of Strategy, Forbes, and I spend a lot of time, uh, in the supply chain space looking at software building materials, basically how all this stuff goes together.
And I have a lot to say about today's topic, so I'll stop there. Chris is never shy about giving his opinion, so I'm sure he does. Joining Chris and I from up in Massachusetts today, Sandy Estrada, Sandy, welcome.
You, you've been on with us before on these types of round tables. Thank you very much. Thank you.
Why don't you introduce a little bit about yourself? Sure. Um, I am a career consultant.
I've spent, uh, my entire 24 plus years of, of career in consulting for the most part. Um, I am currently working, um, at Velo as the vice president of, uh, client solutions, which is basically helping organizations with their data strategy. Um, so very excited to be here.
Excellent. We're excited to have you. Last but not least is our new member on the panel.
It's his first time with us here on Textron, uh, David Liu. David, did I pronounce it right? Uh, yeah.
D uh, David Liu Liu. Okay. Yeah.
David, if you don't mind, tell us a little bit about yourself. Uh, yeah, first time caller, longtime listener. I wrote to you a lot, Alan.
Uh, Okay. Yeah, yeah. Uh, just to like, keep up with the, with the main topics, right?
So, um, yeah, so I, uh, I'm, uh, a senior, um, product marketing manager, uh, for our AI products at CloudFlare, mainly a supporting go to market. Um, and I've been in the AI compliance space, or touched upon it for about, I would say the last six years. So I started in facial recognition, object detection, um, and, uh, there was a lot of, um, issues with data compliance there, right?
Privacy issues, yeah. PII, um, and yeah, before that I was an engineer, so I, I moved to the, the business side of, of the world. But, um, yeah, that's, uh, that's basically a summary of, of, uh, what I've done so far.
Yeah, I love it. Six years in AI compliance, that's kinda like, you know, you get those people who want 15 years of Kubernetes experience for the entry level, um, right. Um, Kubernetes of course only been out nine, but anyway, um, you know, it's interesting, but David, for many of those years, ai, you know, compliance in terms of ai, I think is very different.
Maybe it wasn't than what we're seeing now in terms of, you know, the explosion of whether it's generative AI or, or machine learning kind of, uh, ai, if you will. But, you know, it's really become sort of a back burner issue to a front and center type type of thing. Um, so thank you, and what a great person to have on the panel.
Fantastic. Um, all right, so today's panel is titled Navigating Data Compliance Challenges and AI Powered Cloud Transformation. Well, before we could talk about client, uh, data compliance and the challenges with them, let's, let's just spend a moment in terms of what do we mean by an AI powered cloud transformation.
I know we seem to attach AI to everything today, today, but what is an AI powered cloud transformation mean to you, Sandy or Chris? Maybe what is, what is an AI powered cloud transformation? I'll bite.
Yeah. So, uh, so as I mentioned in the green room, just yesterday, I recorded a, an episode of, of my, my podcast, the Inevitability Curve with, uh, uh, Mickey Identity, Michelle Finn identity, the fascinating character. I'm talking just about this.
And David, you know, I'm interested in getting into this with you because been five years ago, a little more, five and a half years ago when you were already doing this, right? That I started obsessing the supply chain, right? And part of this was what Mickey and I were talking about yesterday and what we're talking about today, which is, you know, five years ago we said Oracles, we didn't say AI and l lm, we talked about Oracles reading our contracts and policies, and making the decisions on sharing information across the supply chains.
Now, I think it's becoming a lot more clear now, I think, yeah, while there's lots of aspects we can take this conversation, I see what we currently call ai, you know, being made with policy to allow organizations for the first time ever to have a good idea of where they're, where they stand in a policy context all the time, instead of waiting till some disaster happens and calling the lawyers and actually reading the contracts and regulations that nobody ever reads. So, David, do you think I'm off base, or is it, is it that, because I think it actually is transformative, right? It's not about the technology, it's nobody ever stops and actually reads the policies.
I think we're moving into the time where those policies end up being live real time filters that we run our businesses around. Yeah. Um, I, I totally agree.
I think like back when I started with the, the facial recognition, um, object detection and, and also during covid, it was, um, recognizing a face and then checking if they were, uh, if, if they were vaccinated before they entered the building. So there was that medical component as well. And I would say it was very niche, right?
Only maybe a few people within an organization had a certain understanding, and there wasn't this explosion of data governance type software to help you automate some of this compliance issues back then. Um, it was pretty manual, and you're right, a lot of it was just stuck in legalese, right? That no one really read.
Yeah, I would agree with that. I think, I think the other aspect to this is that, as you said, David, it, it's now pervasive not only within a, an organization, but across organizations in terms of how they work together, um, and, and how they facilitate business as well. Um, so some policies in terms of, you know, data localization, those kind of things, um, and how they're sharing information, you know, they're the advent of clean rooms, for example.
Um, so there's so much, um, uh, it, it's so pervasive that at this point, it's not only within your organization or pockets of your organization, is actually even how you work with other companies and partners, uh, that you interact with daily. So, You know, when I look at this problem though, I, I see a lot of the data compliance problems fall into two buckets. One is what I call preexisting conditions.
And of course, under Obamacare, we, we have to, uh, respect pre preexisting conditions. But what I mean by preexisting conditions is these are data compliance mandates that predates the whole AI group. I don't care whether you are using AI or not.
PII has to be protected, right? Uh, data sovereign issues, sovereignty issues, predate this whole AI boom lately, right? You know, I don't want my data in such and such a country or outside of my borders, or only in these places.
Um, you know, GDPR, I guess you could tie in API I, but I mean, there were certainly compliance issues for data in the cloud that let's say, AI powered cloud transformations have inherited. But the same way we've inherited them, we've also inherited kind of the, you know, until we've also inherited some of the responses that we've developed as well, right? We know PII, we want to keep in maybe in an encrypted, uh, state, for instance now, then we have a no, a new set of compliance initiatives that are specifically aimed at AI powered or AI driven transformation, AI driven applications and so forth.
Uh, the, the EU has already passed that, right? Their, their ai uh, legislation, though, I don't think it goes into effect. Is it next year or the year after?
Anybody remember? Uh, 2026. 2026.
That's what I thought. Yeah. So we have a year to kind of get comfortable with it, which is kind of the way they do things.
They did a similar kind of, you know, uh, put it into effect with GDPR. I wanna, for a moment, focus on these AI specific new regulations and what that's going to mean for data compliance in the cloud, right? Because we live in this global world, we could say, okay, well, we're just, you know, it's a little, we're getting ourselves.
If we can say, oh, we're not gonna do business with anyone in Europe. I still hear that from people. Well, we don't, we don't do business with anyone, you know, in Europe as a result.
Well, yes you do. You just, you know, it'd be very hard to kind of ize the internet where you're not doing that. Or maybe we are panel, what do you think, Chris?
God, I see you want to say something. Yeah, yeah. Well, I'll let the others speak more to the, you know, AI regulations themselves.
But, you know, I think this is, you know, I, I, for me, intellectual property has been the community in the coal mine, right? That's what drives my thoughts on this issue for both 20 years ago. And supply chain, you get this anxiety, it's like my friend, my, my intellectual property.
So as an employee of the company, I'm worried about if I'm breaking internal compliance by telling you that, you know, IP things or sharing ip. But I don't really know, I don't really know if I'm breaking it. Don't really know what the rules are, the, because We don't know what these AI compliance initiatives are.
Should we start there? Well, and again, that's, you know, you know, I'll let let the others speak to that. You know, I'm not plugged into the very specifics of, you know, the AI regulations over ai.
I'm looking at ai, you know, to help us comply with all this stuff. Let, lemme try. P-P-C-I-D-S-S, every member Heartland Payment Systems, you know, who complied with B-C-I-D-S-S regulations that got, I Looked at the minute before we were breached, The very moment, next moment they were breached, and they stayed breached for six months.
And I think the real difference in all compliance and all regulation being driven by both the need and these tools, is the idea that you can check off compliance and check it later. I think policy ends up being live. Right?
You know? So whether you're complying with something, I think becomes a better set of automated business rules that are applying to your transactions, you know, to your email rather being based on hoping that your employees remember to take their annual training. Right?
You know, so that, that, that is an enormous difference. Now, how we regulate AI and how we comply with regulations about AI is a different, different topic, which is equally fascinating. Yep.
So, David, you kind of stepped in it today, right? You, you become our resident expert when we talk about AI specific compliance, uh, regulations. Can you, can you help us define them?
Yeah. So, um, you know, we can take the EU AI Act as an example, right? The overarching theme for that AI regulation is they wanna make sure that AI systems respect, uh, fundamental rights.
So like, including human rights, um, safety, and then like ethical principles. So that's, those are the three main things that these AI acts, um, want to achieve. Um, and I would say it's also similar to, like, just last week, the Department of Homeland Security also released an AI framework, uh, for critical infrastructure, right?
So how do, um, providers like CloudFlare, um, make sure that AI is secure for, to be used in critical infrastructure? So the overall theme of all of this is, let's just make sure it doesn't get out of control. Um, and I think there's still a lot of questions, even though they're coming out with these frameworks.
Um, it's almost as if when GDPR first came out, I see a trend of, uh, a lot of consulting companies that are gonna, you know, come into this space. And, and maybe Sandy, you've already seen that, right? Um, and, uh, I also see like specialized software continuing to emerge and automate, um, these compliance issues, uh, hopefully with a click of a button.
But I think it's still early days. It's hard to tell. Uh, I don't know, Sandy, if, if you could add to that.
Well, yeah, I was just gonna add, I mean, at the end of the day, um, you know, there's the regulation and then there's frameworks to address, right? So I think there's like these two buckets of things that are happening in, in, in, in concert, right? Like Microsoft came out with their framework for effective ai.
Um, so, and then you have the EU regulations more of a policy. Um, at the end of the day, they're trying to solve, I think, for three things. One is data protections, which we already know, right?
They wanna make sure the models are actually gonna protect data. Um, and that includes, you know, being careful in terms of the data you use to, to, to, uh, build up those models. Um, but they're also looking at things like bias and fairness, right?
Which goes back to the human rights stuff, uh, David that you mentioned. Um, but a lot of that still falls into all the other compliance things that we've had in the past, right? Like if you look at the, the, uh, fair Lending Act, for example, right?
That's always been there because they, people are looking for making sure that it's not biased and it's fair. So we wanna have fair lending. Um, so there people are just trying to put these giants kind of buckets of, of policy in place so that it covers kind of all risk, if you will, including security, security of somebody's information, right?
So I, I think those, those three big buckets are really what these regulatory, um, uh, things are trying to solve for. And I agree, uh, David, there's platforms out there that have tried to get in front of it. Um, it's not necessarily a platform fix, uh, at the end of the day.
Um, but there's also a lot of, I know our firm has been thrust into this conversation because, um, we, we spend a lot of time in data, um, data management solutions to our clients and, and enabling AI capabilities for the enterprise. And we're finding ourselves building governance structures and frameworks to make sure that whether they buy a platform that includes AI capabilities or they're building stuff from scratch, or leveraging models from, from third parties, that they have a framework for assessing that risk, mitigating that risk, and ensuring they understand how to monitor and manage that moving forward as these models drift and move around, right? So it, from a regulation standpoint really comes down to data privacy, bias, security, and, and what they're looking for is explainability and, and basically transparency that these things are happening, um, within, within your organization and when, when you're implementing ai.
Yeah, I, I just, just, uh, add an analogy to that, you know, so the, the NERC SIP regulations, the electric, you know, north America Electric, uh, reliability council, uh, um, uh, grid, uh, cybersecurity regulations or something like 20 years old, but I remember nerc SIP one one was great, you know, it said, you know, critical assets must be thus and such, and all the utilities said, you know, they could just not call that a critical asset. Well, you know, that didn't last. Um, but, you know, the current versions, critical assets are still key to it.
0 regulations, and they will change, but the intent will probably stay the same. So, as Sandy says, have a plan. Think about this.
Look at the intent behind regulations that I impacting you and plan forward. Agreed, agreed. Hey, just a quick reminder to the audience.
If you guys have questions or comments or thoughts on this, um, please do let us, you know, put it in chat here or q and a and we'll, we'll bring it up to the, to the team. Um, if you don't mind, I wanna go back to the issue of data localization and data sovereignty. com Screen Boulevard, or any of our text on TV podcasts and shows.
Um, and, and my feeling is not bringing politics into this, but my feeling is as the world be each corner of, you know, all of the contenders go back to their own corners, right? And, and we're seeing sort of more of a balkanization, you know, I'm not gonna let this in. I'm not gonna store stuff there.
I'm not friendly with these people. I'm in this axis. They're in that rotation.
We're gonna see more and more of this. I don't want my data over there. I want to keep my data here behind my shores.
If you look my ip, how, how is this going to affect when we talk about things like next gen cloud, the connectivity cloud, and we talk about with CloudFlare, right? We have stuff on the edge and stuff in the hyperscaler. How does a, a hyper data localization movement or data sovereignty, regulation atmosphere play into it can't be good for us.
It's gonna put a lot of burdens out there. That's gotta be something CloudFlare worries about. Sandy, I'm sure you, you have clients who worry about this.
What do you think? Uh, yeah, so I would say from CloudFlare and, and, uh, you know, other providers that, that give this like storage infrastructure to clients, uh, it is definitely a challenge. Um, and I think it comes in consideration on both the hardware side as well as the software side.
So on the hardware side, it's about making strategic decisions on, you know, do we put storage in all 330 cities across the world that we operate in? And should we put in, should we make it available in, um, more cities, right? To make sure that it's like super localized.
Um, so there's definitely considerations on the hardware investment. Um, and I think like other providers are also considering that as well. It is, uh, an i I would say, um, like a strategic investment that needs to be considered.
Um, and then on the software side, it's like, how do you make it automated? How do you make sure that if there's a client that only wants to have data in the eu, how do you make that as easy as possible? And so far, CloudFlare has been able to create software that makes that possible, right?
So there's like a one click button that you can press and like all your data gets stored in the EU as an example. Um, I don't know, Sandy, if you have any, um, insights or trends that you're seeing, uh, Chris as well? Yeah, I mean, the, from a data perspective, there's definitely been a trend of, um, cloud platforms like Snowflake, Databricks, even Azure, where they're really allowing for cross cloud, cross region, um, you know, data sharing, um, and extrapolation.
So you don't have to move the data sets, but you can actually access them, um, from, from an organizational standpoint, they're also being smarter about how do I share my data with third parties, thinking about localization challenges in terms of, of the partnerships that I have. Um, I think the trends though, there a lot of pressure on organizations to get better about their governance overall. Um, not just with data, but with their architectures as well, um, in terms of, you know, where things go and how things are deployed, um, and how things are secured, uh, whether it's internal or externally used.
So, um, and, and that's like a space that I've seen just kind of proliferate where, um, I would say of all the projects we've had in the past, the the conversations about migrating to the cloud have gone away, and the conversations about how do I govern and manage all of this have started. Um, and that is something that as somebody who's been in this space for 25 years, I say, finally, thank you, Lord, thank you for AI for bringing this to the forefront. Because prior to this, or, or really chat pt, because prior to this, it, it, it was very quiet and very difficult.
You could never get funding for governance. Um, but there's a lot of pressure. So every, every company out there, you name it, the brand, it doesn't matter.
They're all running into that space. And, and they have to, um, for, for this reason, just the amount of sharing of data and the amount of ai, uh, exploration that's going on. And Alan, I'll, I'll take, you know, sort to be, you know, uh, repetitive.
But again, I see data localization not as a authorization issue, but as a maturity level. You know, this has been coming up throughout my career. And you know, what comes to mind is you're in the early, in the two thousands, I was on the board of a Lake association in Canada, and at the end of the day refused to use PayPal because our Canadian members data would be stored in the states, which felt a little silly at the time, perhaps a little less silly now.
And five, six years ago, they're getting the Columbian National Grid operator to sit down with a big global cloud provider. Similarly, it's like, where is this cloud stuff where literally jurisdictionally is this data health? And we didn't have the answers.
So it's not a new thing, it's just that we haven't built the capability to date because we haven't. But now, once you start doing it for resilience and redundancy and jurisdictional or legal, you know, you should know where your data is. It might matter.
Well, that, that's a start, right? Know where your data is, it's 10 o'clock, you know where your data is. Hey, we, we've got a question from the audience, and I love getting questions, so I want to jump on this.
Uh, John asked, considering that halluc hallucinations are inherent with ai, even though they can be quote unquote managed, how can we, how can AI be data compliant? That's a, that's a fantastic question. Um, I, I can take the beginning of that.
I, there are a couple things that we've seen, uh, in terms of trends. Um, one of them is we're finding that smaller models are actually less, um, hallucinated energetic, if you will. Um, so, uh, there is this movement instead of the Giants, uh, generalized model out there, um, especially within, within our corporation, they're focused on creating models that are, are, are very used case specific, um, and then building, uh, architectures that, um, really take, uh, any kind of query from an end user and then kind of push them to the right model to answer that, that question.
Um, so that it's very pinpointed and, and comes back with the right answer. So, um, some of that, because the model is smaller, they can additionally add, um, a reference in terms of where the answers are coming from. Um, so you can see this yourself actually, um, uh, I think it's, oh man, I, I wanna say it's Google Notebook ai.
Um, you can, you can literally put it make, make your own little mini model there, um, by just adding links, uh, and content and then asking it questions. And a lot of organizations are using that kind of AI to help, uh, answer very specific questions. But what they're putting in front of it, again, is kind of a router, uh, of your, of your, um, of your queries.
So it knows where to go to, to get the answer. So these, these platforms are getting a little smarter. They're, they're actually getting very pointed.
Um, and I've seen that trend. And there's also this idea of, um, going out to the internet asking for very specific, specific answers, uh, and, and, and citing where, where in the internet that the model had, uh, aggregated that data from. So, um, we're getting, we're getting better, I would say, uh, organizations are definitely moving in that direction.
But, um, if you're looking at a very large, robust model, yeah, there's gonna be hallucinations there for sure. Yeah, I can, uh, I can add to that. So, uh, two things.
The first one is gonna sound pretty simple. Um, so at a previous company that I worked at, um, There was like, kind of like a copilot bot that was created and, um, to avoid hallucinations, uh, you could tell the chat bot where if it doesn't have a certain amount of certainty, um, than just say, I don't know, right? To kind of prevent it from having, uh, from hallucinating, that's like one kind of tactical way of doing it.
Um, the other, uh, emerging trend that I'm seeing in the market is if you think back to API gateways, there's an emergence of AI gateways. So now you can plug in, in parallel to all the AI requests that your organization is, um, is, is submitting, or, um, yeah, I guess submitting to AI and then monitor the prompts as well as the responses, right? Mm-hmm.
And you can, even with some of the technologies available, uh, now, you can stop responses, um, from happening if they are not data compliant, right? So you can read the response and before the user sees that response, you just stop the, um, the AI from answering it. Um, so hopefully that helps you out, John.
And the only thing I can think of to add to that is, is again, you know, usually this populous specula, uh, fiction by the time we get to where, what they're speculating about, this is some obvious thing. Yeah. I think, you know, the Skynet, right?
The ai, you know, that, you know, you know that this Starship Enterprise is not going to have a computer, you know, so you have lots of different AI trained in different models that are comparing notes. If you're trusting any one thing to be the arbiter of all your operations or the keeping your boat above water, whatever it is, yeah, that's your problem right there. So Common sense, right?
Check more If it's Common sense is always short, short supply. And I, I think, I think sometimes legislation tries to, um, legislate common sense into people, but either you've got the con, either you have common sense or you don't. And, and you know, it's a poor excuse.
Um, I've got another question here from the Q in the Q and A tab. So the promise of 5G oh, yes, let's all pray at the alter of 5G, the promise of 5G telecommunications was, the data would be locally distributed, sort of the ultimate, you know, connectivity cloud before connectivity cloud, right? We could keep data on the edge and deliver it really fast with 5G.
So the promise of 5G tip telecommunications was that data would be locally distributed. How does that promise apply with AI data compliance? So the idea is, is it's so locally stored, distributed and delivered that it never kind of registers, if you will, in the, in the cloud, meaning maybe the hyperscaler center or whatever that, you know, you would have this AI compliance stuff kick into.
No, I'm, go ahead. Lemme try this in the supply chain world, right? You know, so, you know, I'm a yank who's lived in Canada back and forth half of my life.
Canada has always loved saying we're the number one trading partner with the us. I just saw the other day, that's not true. China is by far long and far away, and that will stay there.
Geopolitical tensions, uh, outstanding. So how do we as security people, secure supply chains when there are embedded, you know, parts from arguably, you know, politically, you know, rival nation states, and that's the, you know, and, and change all the, the geopolitics over the next 20 years. That's not gonna change.
You know, supply chains connect everything. And what I said earlier, I think is the case. I think we will have digital twins of our supply chain, and we'll be able to look at those in real time without six months of sending faxes to each other.
And if the policy says, at this point you can't see any farther because of, you know, you know, geolocation of data or whatnot, you'll know that, and you'll, you'll see that at that point. So I think, I think, and again, I hate using the acronym, but what we're calling AI right now, I think allows us to automate policy so that we get driven to be able to address these sort of issues. You know, you know, perhaps you can't get the data, but you'll know exactly why know where.
Yeah. And I, I think to automate policy, there's, there's an AI is gonna help in terms of, um, how logging what the data you do have and identifying the data sets, because I, I think that's part of the challenge. Localization laws don't apply to everything.
They apply to certain aspects of your data. Um, so that, that's, that's been the largest challenge I've seen with clients where they're still taking a very manual, uh, task approach to, um, cataloging what they have and, and making sure that they, they're on top of things. Um, and there are a lot of frameworks and capabilities, uh, that are AI driven that automate that ability to some extent.
But you still need to have a human in the loop to make sure it's accurate and complete. Um, once you're able to do that, then you can have a automated policy monitoring on top of it. Um, but that, I, I would say that we're not there yet.
Um, I, I haven't been able to find a company that has a good handle on everything in terms of I know exactly where everything is. Some are better than others, right? I, I would say financial services and healthcare are probably, uh, you know, for good reason, um, are probably on top of that.
Uh, everybody else, uh, it's a little, it's a little fuzzy, uh, especially on the consumer side. Um, so it, it's, it, it the biggest, how do I get in front of understanding what I actually own and have and offer to create within an organization where I'm storing it? Um, and then I apply an automated policy on top of it.
Fair. Yeah. I, I think my, my, my favorite line last in the, in the supply chain activities and one particular who's just not a technical person at all, not interested, trying to figure out how to put this to him.
And I said, you know what? Trillions of dollars we spend on software, we don't know where we put it. Right?
That's why all this is important. And this is the same sort of issue, you know, your data, data geolocation. Do you know where it is?
No. You know, is it in compliance with the rules? Yeah.
You don't know. So that's kind of a big deal. And, and you're right, Sandy, you go, nobody's done this yet.
However, if you think it'll stay that way or forever, you're wrong. So when is that changing? I think about now It's moving for sure.
If you don't mind. I I want to talk about another sort of scenario. So you, you know, you go, you, you, you, you're gonna not lift it shift.
You're gonna migrate to the cloud, you're gonna do a transformation. And you pick one of the big three hyperscalers, I don't care which one you pick, but you go and you do it, and now all of a sudden things are happening and moving, AI is getting bigger. We're, we're, you're discovering I want to do stuff on the edge, uh, that a localization has become an issue.
And you say, you know, something that, that hyperscaler I picked, I don't think I should put all my eggs in that basket. I gotta go multi. I wanna move some stuff over there, put some other stuff over here.
I'll leave some stuff where it was, put some stuff on the edge. I'm gonna call those guys a CloudFlare about this connectivity cloud thing they're talking about. 'cause that seems really cool.
Sounds good, right? Life is good. What is, what is data compliance?
Is that the fly in the ointment of a multi-cloud transformation like that? Does it, is it a help or a hindrance as we looked at, as we look at things like the connectivity cloud and stuff like that? Sandy, you've probably run into this with clients.
How, how hard is istic unrealistic job security for consultants? I mean, what, you know, uh, what's involved? I think it's job, job security for security people, more than anything, it's Always job security.
So CISO's got a nice job today. It's a lot of job security. Being a, a cybersecurity person or ciso.
Um, I honestly, I, when we're doing multi-cloud for our clients, um, I, I think what we push for is to think about having a, a, a data management solution that allows you to be multi-cloud. I think that's the, the biggest concern that we have is making sure that you, you have a data management solution that gives you that flexibility. What's happening under the covers, quite frankly, these days and how it happens is, is kind of, uh, it's nice because it's not a, a, it's, it's low code, no code, if you will.
Um, uh, so they, they manage it for you. But I, I think the challenge that we've seen, and and I, I hate to repeat myself, is really organizations stop losing track of what they have and understanding where they're pushing, pushing things. Um, because I, I have seen that where they're like, oh, our backup is gonna be on AWS and we have another backup on Azure, but one's, you know, in this region, one's in the other, and you're sitting there going, wait a minute, you can't move that data over there.
They, are you moving all of it? Or are you just moving part of it? And they, they don't think about those things, right?
So it, it really does come down to policy and, and ensuring you have the right framework for your policy. But, um, I, I haven't seen any real challenges beyond that, primarily because if you're doing multi-cloud, you're probably doing it within the same region. Um, just maybe a different co-located place so that, you know, you're safe from that respect.
But I haven't seen too much challenge there over overall. How about you, David? Yeah.
Uh, I would say The trend that I see with like CloudFlare customers is that, uh, especially the ones that are focusing on, uh, doing AI training, right? So they're training their own models, is they are multi-cloud. And the way that cloud flare supports that, when it comes down to a storing that training data, um, as, as well as localizing that data is we're, we kind of play like the middleman or the centralized storage hub.
Um, and, um, you know, if you had originally training data on Azure and you also have training data on GCP, they're moving that data to CloudFlare as a central area to know where everything's at, and then they'll distribute it, uh, distribute it to their, um, cloud instances when, when needed. Um, and yeah, I think like the, it's not a, an issue because our software automates the data localization. Um, so yeah.
Well, When you say their software, our software automates the data, my migration, are we using AI For data localization? Um, I would need to check with the engineering team, but from my understanding, it's, it doesn't utilize ai Doesn't, yeah. Is that, that's something I, you know, 'cause AI always, there's always two sides to the AI coin for every sort of problem that it could potentially cause the, you know, there's an equally good solution that it can provide.
And, and I guess ultimately the question is, are the solutions better than the problems, right? Because that, that that's, you know, it would make it so we could use ai, we could train AI somehow to better enable us to comply with AI compliance. Or is that an oxymoron, right?
Is it, it's kind of, uh, an enigma wrapped in a riddle kind of thing? I don't know. Is AI the answer to AI compliance, Chris?
Nothing, Yes. In short, right? And, and again, right.
You know, there's so many things that we've been complaining about amongst ourselves as a, as a community security community forever, right? Many of which, you know, over and over again, guys like, well, but that's too much and too many. And, but that's where we're going, you know, to billions of nodes or trillions or quad, whatever, you know, if we get to these levels where it's just too much to do it the way we think we should.
And I think, and again, what we call ai, but I think this set of tools we're talking about right now let's us do a lot of things that we've always should have done, never had anything like the, the, you know, the, the workforce, the horsepower to do. And even, yes, I mean, specifically monitoring ai, you know, what's the, you know, and, and just conflict in the, in the cyber world and conflict in the physical world, have a lot of analogies. You know, drones are a thing now, you know, we can say you don't want them, but what do you use to protect from drones?
Drones, AI needs to monitor ai, right? My AI is gonna be mine. And, and again, there'll be three of them error checking each other.
But yes, you have to use these tools to check these tools. A good, David, what do you think? Yeah, uh, absolutely.
So, um, there's a, a really, I think, um, interesting emerging use of AI to monitor ai. Um, and I like to ask you before I go into it, Alan, like, do you know if there are AI bots that are scraping tech Strong's website for content? Absolutely.
Yeah. And am I happy about it? No.
Am I getting compensated for it? No, But Let me give you the flip side. Were there bots scraping text drug's website before the AI bots?
Yes, That's right. But those bots most likely were hopefully helping you to, to rank higher in Google in hopefully, yes. Yes.
Okay. So then, but just to give you an idea of the dilemma of publishers today, David. Yeah.
I used to really care about how highly I ranked in Google, because Google and organic search traffic represented 75 or 80% of our traffic. But today, Google using AI keeps more and more of that search query traffic on Google. So if you, you know, think about the last time you searched for something on Google and you actually click through to a third party site, no, you get the little AI blurb of the answer to what you're looking for, and it asks you four other questions of what you might be searching for, and it gives you some more, it doesn't, by the time you get to a ranked site that's not sponsored Yeah.
You, you are three quarters down the page, Right? So I don't know if that's a good thing anymore for us here. Exactly.
Right. That's, that's, it's like how many searches Google searches does it take for someone to finally click on your website now? Yep.
And so going back to how do you monitor AI with ai, um, there's an interesting tool that CloudFlare, um, came out with, and it's free, it's called AI Audit. And what it does is it automatically uses AI to detect the AI scraper bots that come onto your website to scrape your content and then train their ai right, without compensation. And so the idea is we wanted to create a marketplace where you automatically charge these AI bots from scraping your website, right?
Because, oh, No, what is this called? It's called a, uh, the AI audit tool. So I have to tell you, full disclosure, we're a CloudFlare customer enterprise.
Yeah. So we, we should have this, no, Yeah, it's a click of a button. Just turn it on.
Telling, I'm telling my team. Yeah. Because, you know, not all of us are the Harper Collins, the News Corps that can sign multimillion dollar deals.
Exactly. com. Yeah.
And it's not fair that that should be used to train someone's LLM and we're not compensated. Exactly. Yeah.
I'm sure it already has. Oh, I know it has. But like David, not Harper Collins, I'm not the New York Times.
I don't have that kind of big stick. Yeah, no, that's, I I do love that, David. Um, but going back to your initial question, Alan, right?
Uh, in terms of AI monitoring ai, we started this entire conversation regarding compliance. Um, so I, I almost wanna go back there because for me, it, the more AI that we have, uh, the more difficult it is in terms of transparency of what we're doing, uh, with ai, um, compounding, uh, bias and, and quite frankly, a, these models, a lot of people over rely on this stuff, right? We're getting, we're gonna get into a place where it's gonna become over-reliance on ai, and then we forget that models drift, things change, uh, the ground moves be under you.
Um, and then all of a sudden you're, you're now in a, a giant risk and exposure situation by over-relying on it to monitor your AI issues. Um, so I think, you know, tread carefully, I think is where I'm going with that, uh, because it's always, uh, with a compliance lens. I think a lot of people wanna move in that direction.
I agree with it. So I look at it less as a all or nothing situation. I look at it as an accelerant.
I look at it as an enabler. Um, but I definitely am not of the, of the party quite yet, of turn it on and forget it, just let it run. No, I don't think any of us are quite there yet.
But, but I think that's the, the, the enigma wrapped in a riddle here is that AI can provide many of the solutions we need to work with ai. It's, it's just Oxymoron ish, right? Um, who knows, who knows?
Guys, we only have, uh, we got maybe 4, 3, 4 minutes left here. Try to end a little early before the top of the hour. Um, your best advice for people out here is that, you know, we talk about this rather, uh, in a scholarly way, academically, academically, real world.
This rubber meets the road for people every day. They're living this. What's your best advice for people to stay on the right side of compliance with data when it comes to, you know, AI power transformation?
And, and, and David, I know you wouldn't say this anyway, but it can't be, oh, just use CloudFlare, right? I mean, what, what, what advice would you give people? Chris, I started with you.
Let me go to you first. Sure. I, you don't get distracted by the shiny objects.
You know, all this technology is, is supposed to serve your business needs, your organizational needs. You know, I think if this, if you see opportunities, you know, that allow you to implement better governance, which I think this is all about, you know, move in that direction, right? And, and again, this by nature, I would think, you know, this set of tools should allow you to do things that were just beyond scope before.
So as you see that opportunity, do that, but don't, you know, don't, uh, redo your plans. Look to how, how these tools can help you with the plans you already had. Excellent.
Sandy, how about you? Yeah, I mean, I, I look at it as it means easy to, um, say govern, but I, I think tactically it's really making sure, and you can use AI to do this. As Chris said, you're standing, the, the regulations that apply to your use case or, or your organization, whether that's a local regularization, an industry regularization, whatever it may be, a regulation, sorry, whatever it may be.
Um, that's the first step. And then after that, I, I would literally assess your AI projects against that and understand the level of risk that you're, you're taking and have a, a way to say, is this high risk? Is this low risk for this regulation?
Um, and once you're able to identify that, think about, um, and we help our clients do this, think about all the mitigating uh, possibilities out there to address that risk, um, and have a plan for those mitigation tactics in case that risk realizes itself. Um, and then govern and monitor that over, over time. But that's for, um, everything from things you build to things you purchase, to things you have within other applications that you deploy within your enterprise.
David, I saved you for last. Yeah. I say first and foremost, uh, know where your data is and, and what it is, right?
Mm-hmm. Uh, number two, I think as everyone has emphasized on this call, it's so, it's such fast moving, right? In terms of compliance, I would recommend like, do regular assessments, work with people like Sandy, uh, work with people like Chris, right?
That are experts and to do assessments and make sure that you're keeping up. Um, and then lastly, what I've seen at some companies, um, is they have formed across functional AI governance committee, right? So it's different business leaders along with it.
You form this committee that, you know, you don't meet every week, but maybe on a quarterly or every six months basis to review like, the AI compliance component as well as AI implementation within an organization. Yeah. Fair.
First of all, guys, you know, I gotta be honest, I was a little nervous coming into this one because AI compliance, I felt like we were doing a webinar on quicksand, but, um, it, it came out better than I could have hoped for, and it was really because of, of the three of you as well as some of the folks in our audience. So thank you so much, Chris, Sandy, David, thank you all out there for, for joining in. If you're watching this on demand as 10 to 20% of you do, thank you for watching it on demand.
I'm sorry you weren't here live to ask questions of, of the, uh, panel here. Um, I would, we do put out a quick survey, uh, to hear kinda what you guys thought. It's really less than a minute.
It's like two questions or something. Amanda, if you could put that in the chat and get it out to people. It's also under handouts.
Um, thank you very much to CloudFlare for sponsoring this whole series, because it's a great topic. Not just this AI compliance, but the whole last great cloud transformation and, and what's going on. And, uh, we've really been exploring more.
I look forward to doing more of that in the coming months. Um, survey Link is in chat for anyone who wants it. Thank you all.
Again, this is Alan Shimel. If I don't speak to you or any of you before, have a great Thanksgiving holiday. If you're here in the US or wherever you may be, we head into the holiday season.
We'll see you all soon. Thank you very much. Bye-bye.
Thank you all. Bye-bye.

