Webinar | AI Governance That Doesn’t Kill Innovation

Watch on-demand | Learn how to build practical AI governance that enables innovation, manages risk and helps enterprise AI scale with US Air Force and BigID.

How to put the right controls and guardrails that help AI scale safely.

AI adoption is moving faster than enterprise control. As AI agents become part of everyday business, organisations need practical ways to balance innovation with governance, giving teams the confidence to scale AI without creating unnecessary risk.

This webinar builds on our latest AI article, Controlling AI Chaos: Governance for the Agentic Enterprise, moving the conversation from why governance matters to how organisations are putting it into practice. 

Join Ortecha and guest speakers as we explore the governance foundations that enable trusted enterprise AI without slowing innovation.

What the webinar covers:

  • Why AI needs a different approach to governance
  • The principles and guardrails trusted AI requires
  • How governance can enable innovation rather than restrict it
  • Practical ways to manage AI risk and accountability
  • The risks of shadow AI, over-automation and weak human oversight
  • Where to start: outcomes, risk tolerance, visibility and education

"Whoever writes the standards writes the future. So standards are not neutral. They embed values."

Watch the full webinar:

Transcript

Opening and Introductions (00:10-04:32)

Sean Russell (00:10):
Hello everybody. Thank you for joining. This is our second of three webinars. This one is Agentic AI governance that doesn't kill innovation. Very happy to have all of you here with us today. I'm joined by some esteemed guests.

Thank you for your attention, everyone, and let me start with introductions. So on my screen I have Gabe Arrington, U.S. Air Force. Gabe, do you want to give a quick introduction?

Gabe Arrington (02:27):
Yeah, you bet Sean. Greetings everyone. Great to be on the line with you and sharing this discussion. Gabe Arrington, I'm a senior officer in the Air Force. My background is in aviation, but I'd say for the last 15 years my focus has been at the cross-section of national security, emerging technology, public policy, most recently as the chief of disruptive technology for the Air Force and the Pentagon. So, thanks for having me.

Sean Russell (02:52):
Amazing. Incredible. Right. I'm also joined by Christopher Hoesly. Chris.

Christopher Hoesly (02:57):
Yeah. Great. Thanks, Sean. Christopher Hoesly, field CTO and VP of security for BigID. I've been with the organization for about four and a half years, but I've been in data security for just shy or actually just over a decade now. Well, hard to say that one. And everything data security and AI security is something that has been top of mind for me for quite a while now. So, yeah, thanks for letting me be here today.

Sean Russell (03:20):
Excellent. Well, thank you for joining. And last but not least, well, not actually last but not least, I haven't gone yet. Stephen Gatchell. Stephen, you want to introduce yourself?

Stephen Gatchell (03:30):
Hey, thanks Sean. Yep. Partner and head of AI strategy here at Ortecha. Been here for about eight months or so. Prior to this, I was a practitioner, you know, managing data science teams, implementing data governance strategies, AI strategies for companies like EMC, Dell and Bose. Thanks for having me today, Sean.

Sean Russell (03:50):
Oh, it is my pleasure. Last but not least, me. I'm Sean Russell. I'm the head of AI enablement at Ortecha. It's good to be waving at all of you viewers at home and really great to be joined by such esteemed and experienced guests. So, this session is about AI governance that doesn't kill innovation. I feel like what we need to start out with is how we define AI governance. And I want everybody to answer this question, but Chris, I'm going to start with you if you don't mind.

Defining AI Governance (04:33-08:28)

Christopher Hoesly (04:33):
Sure. Sure. The way that I would look at AI governance really is the idea of putting some policies and controls in place to make sure that when you're thinking about deploying your AI solutions, developing them as an organizational effort, you're really thinking about this from the idea of whether it is fully operational in a way that's compliant with everything that we need to be thinking about, but also making sure that we're following all of those security practices that sit behind the scenes, right?

So, what does that actually mean of basically keeping our idea of risk as an organization under control as we begin to roll out something like an AI solution?

Sean Russell (05:17):
Excellent. Excellent. Stephen, you're next on my round the room. How do you define AI governance?

Stephen Gatchell (05:26):
Yeah, I think it's really understanding the guardrails and the frameworks in order to implement AI in a safe and responsible manner. Quite honestly, there's a whole lot more to it and we'll get into much more detail, but I like to keep it simple so people can have that takeaway.

Sean Russell (05:43):
The safety and responsibility seem to be a running theme. Gabe, how about you? How do you define it? I would imagine you have a similar take.

Gabe Arrington (05:54):
I do. I'm going to echo some of the same things, but most of my answers are going to come from a national security lens. So governance to me is not about slowing the technology down. It's about deciding who sets the rules before the rules get set for us. So when I talk about AI governance, I mean the frameworks, the standards and the guardrails that determine how these systems get built, tested, deployed and held accountable. Echoing what Chris and Stephen have said, that covers everything from safety testing and export controls to how an autonomous system makes a targeting decision on a battlefield.

And here's why it matters from a national security lens. Technology moves faster than policy, and it always has. But the gap has never been this wide. Stakes have never been this high. We're building systems that can identify targets, evade defenses, and operate without a human in the loop. If we do not govern how these capabilities are developed and used, we surrender the initiative to others who have already decided that the rules do not apply to them. So governance done right is a force multiplier in industry, the military, etc. It builds trust across companies and allies. It creates interoperable standards and lets us move fast on things that actually matter.

Done poorly, it becomes kind of a self-inflicted wound and we tie our own hands.

Sean Russell (07:16):
Yeah. Yeah, that makes sense. So it sounds like we're centering on the same things from different angles. Sounds like we all believe that, you know, we define AI governance as guardrails, as responsibilities, as security around AI and AI solutions. It sounds like we have different things we're tackling, but we're using a lot of the same methodology. Does that resonate? Is that about right?

Gabe Arrington (07:50):
Yeah.

Stephen Gatchell (07:51):
Yeah. I think everybody always asks the question too, right: what's the difference between data and AI governance? I think they're relatively similar conversations, but in the AI space - and certainly with some of the points that Gabe brought up in a defence environment - it's exponentially more important to have that governance, security, privacy understanding and data space. So while everybody might define it a little bit differently, the core themes are the same across data and AI. I just think the implications for AI are exponentially greater.

Why AI Needs Different Governance (08:29-14:14)

Sean Russell (08:29):
So I think you're right. I think that's a fair point and it gets to the next question which is why does AI require a different kind of governance? Just hearing you talk about it, there's a lot of overlap between data governance and AI governance. Gabe, you're probably best placed to opine on this. I understand that certainly speed is one aspect of that and capability is one aspect of that. What are some other aspects that mean AI requires a different set of tools and processes and governance methods than data?

Gabe Arrington (09:13):
Yeah, it's a great point and it's affecting every sector, right? Finance to defence, and everything in between - mass logistics, etc. old models were built for tools that stay where you put them. AI does not stay where you put it. So think about how we've governed technology historically. A weapon system, a piece of hardware, a chemical process, manufacturing, etc. Those things are physical. They're traceable. They change relatively slowly. You can inspect a factory or count warheads. You can write a treaty about something that you can see and verify. Traditional governance assumes a stable target moving at a pace policy can keep up with. AI breaks every one of those assumptions.

A few examples. First, speed. The systems improve faster than any regulatory cycle can track. Diffusion. A fighter jet requires a nation-state supply chain and billions of dollars. A capable AI model can be copied, downloaded and run on hardware a small group can afford if not individuals. So the barrier to entry has collapsed. Third, dual use. There are a lot of dual-use technologies out there, but there's no clean line between the civilian version and the military version or something involved with the national defense for a country. The same computer vision that sorts photos on your phone can guide a strike drone.

And fourth - and this is the one that I've been wrestling with - autonomy. We're handing decision-making authority to systems that operate faster than human judgment and increasingly without a human in the loop. So governing a tool that a person wields is one problem. Governing a system that acts on its own at machine speed is completely different whether that's on a manufacturing line or in a national security situation.

Sean Russell (11:03):
So it sounds like whereas a data governance exercise might be... Well, let me put it this way instead. It's bad enough that a bad actor might get some of your data. If a bad actor is also equipped with the same kind of AI as you say that's used to capture images on a phone or edit images on a phone and then also be inside a strike drone that is a whole different level and it's a whole set of capabilities that bad actors didn't have before that they now need to contend with. So, Chris, is that what you're seeing on the other side of this?

Are you seeing that from a security and privacy perspective? Is it an arms race that's ratcheting up which I know is in the news and it's buzzword fever, but is it?

Christopher Hoesly (11:56):
Yeah. Yeah. I mean, honestly, from a commercial perspective, that's definitely happening and it's happening at a rate where, honestly, you wish you could look at somebody and say, 'Slow down', right? You wish you could stop and say, 'Hey, all those things that you've been meaning to do...' Right? And that's where I feel the conversation always tends to go. All the things that you've been meaning to do are now getting exposed at such an explosive rate because everything is happening faster. It's happening in a more autonomous way. You don't even know that it's actually there and you're finding out as it's going along or, in some cases, weeks later.

And we've had organizations that we've talked to that are like, "Yeah, we turned this thing on and it is like trying to put Pandora's box back together again." And frankly, we don't think we ever will. Like, we just don't think we ever will because we didn't put the guardrails in place. We didn't put general principles that we were supposed to be believing in that were part of our mission statements as a security organization or as a privacy organization. They never actually got really firmed up, right? It's kind of like molding clay.

Like it was just about there and then you forgot to put it in the kiln and actually really lock it down and the next thing you know it's spilling out everywhere because this thing came in so fast with such a voracious appetite to just answer questions and deliver what needs to be done. You're just kind of stuck sitting here going, "Okay, let's control what we can control. Let's start this over again, but we got to do this fast and we've got to think about exactly what we've learned so far and adapt quickly to it." So, yeah, for sure.

Sean Russell (13:36):
Absolutely.

Gabe Arrington (13:36):
I'm going to jump in there real quick if that's all right. Sean, can I? That's a great point, Chris. And what you just said made me think of, you know, the space domain, right? And space exploration for humanity, right? That started early, but it took years to get to the 1967 Outer Space Treaty. Now here we are today with the Artemis Accords and what that means for humanity. That's something we had years to look at, and it impacts everyday life through GPS, banking, etc. Now here we are, like you said, without the guardrails. What are we going to do?

Global Standards and Structured Distrust (14:15-21:18)

Sean Russell (14:15):
Yeah, absolutely. So that's not just a question of speed. It's also a question of - let me put it this way - geography. And I wanted to get into a question from Danielle. Gabe, I'd like you to take this one if you can because you're probably the most experienced of all of us on it. How is non-U.S. AI impacting governance? Because after all, it isn't one AI, is it? Not even one internet. So, how is non-U.S. AI impacting our ability to put in those guardrails and our capacity on that?

Gabe Arrington (15:03):
Yeah, that's a great question. Thank you for that one. Really, this is the whole ball game. Whoever writes the standards writes the future. So standards are not neutral. They embed values. They decide what is permissible, what's transparent, what accountability looks like. When the United States and its allies set those standards, they tend to reflect things like human oversight, legal accountability, restraint. When authoritarian regimes set them, they reflect something very different. So surveillance as a feature, autonomy without accountability, capability without conscience. So right now, China is not waiting for permission. It is exporting its technology, its norms, and its playbook.

It's doing so through the back door of active warfare in multiple regions. Let me give you three examples. First, Russia in Ukraine. According to Ukraine's foreign intelligence service, Chinese firms are providing Russia with the hardware and AI software enabling adaptations to its unmanned aircraft systems. We're seeing that play out in real time in the news. Last week, the BBC reported on what's called "human safari" strikes, drones targeting civilians. You know, horrible scenes. You know, a street vendor selling tomatoes last week. Second is the intelligence layer. In October 2025, Ukrainian intelligence indicated China could be providing Russia with satellite intelligence on strategic targets, including sites owned by foreign investors.

So you're seeing the application of emerging technology impact industry and investors worldwide. And then third, there's Iran. This is one that should get everyone's attention. Currently Iran's ability to execute accurate missile and drone strikes on cities across multiple states in the region is being supported by Chinese intelligence, satellite navigation, radar, electronic warfare technologies that are expanding their reach. All that is open source in the news and causing regional instability. So the strategic takeaway is that some states around the world are not waiting and not debating what right looks like for humanity. That's something that should be eye-opening for all of us regardless of national origin, race, religion, etc.

So if we cede the governance conversation, we're not just losing an argument; we're losing our voice of the future and the voice of future generations.

Sean Russell (17:46):
It's a really good point. I want to bring up a concept that you actually talk about in your chapter in The AI Opportunity. I don't know if people can see that. Available on Amazon. So, Gabe, you wrote a chapter on this and I wanted to talk about a concept that I think is relevant not just to this situation, although definitely to it, but also to businesses to lead into our next question.

It is structured distrust: a way to govern this kind of fast-moving situation where you're not sure how you'll manage potentially distrustful actors, but also AI in a situation with a lot of what-ifs and not a lot of solid answers. Do you want to talk a little bit about that as a concept?

Gabe Arrington (18:55):
Yeah, I'm going to jump in and talk about structured distrust. You know, this is something a colleague and I were talking about - Zayn Teters, who works in industry - and we gave a talk last year at the UN General Assembly based on AI governance and what we contended was that you know traditional organizations that were mostly formed coming out of World War II, the UN, NATO, etc., are not structured to absorb the intellectual rigour, debate and emotional response that AI is going to generate. And so we need a new type of organization similar to you know the red-phone links between countries during the nuclear era.

You know, we need some kind of organization that deals with these issues so that when something gets out of its sandbox, it's not construed as state-to-state international aggression. And so, you know, I contend that the United States should lead in that discussion and not only the United States, but with heavier participation from industry, academia, thought leaders and think tanks, etc. That's the kind of intellectual rigour that we need in forming organizations that will create an environment where you have structured distrust as we move forward together as humanity with this technology and it's changing everything.

Sean Russell (20:27):
Absolutely. I thought that was a really good point in the book. You talk about that kind of organization having verification mechanisms, having transparency measures that are published, and so on. And I really think that's helpful. And I think one of the ways when the horse has bolted, one of the ways to maybe wrangle back and put some governance effort on that is through kind of those efforts that help verify without necessarily restricting access. And I feel like that brings me on to a question for you, Stephen, about how you drive governance that enables action rather than overly restricting.

Enabling Innovation Through Governance (21:19-31:10)

Stephen Gatchell (21:19):
Yeah. So, look, I think Gabe brings up great points around the national security and humanity, right? But I'll make it more straightforward from an industry perspective because that's what we deal with every day, right, Sean? You and I and Chris as well. I think the challenge around enabling governance is first of all, people run away from governance. They have traditionally done that, right? Anytime you try and run a data governance program and you're walking down the hall, they literally run in the opposite direction because they think you're going to slow them down.

With the advent of AI governance and with the technologies that we have today, there are very disruptive technologies through which you can actually use AI to do your governance processes, right? How do you turn things like regulatory requirements into machine-readable requirements so that your machine speed versus human speed is a differentiation there? So you can't have somebody looking over a regulation and then clicking a button with a human in the loop to say, 'Okay, go do this action,' because now you're kind of defeating the whole purpose of AI.

And to Gabe's point, what things do you want to be fully autonomous versus semi-autonomous human in the loop and over the loop and all that fun stuff. So I think one is how do you actually utilize the technology to drive your governance that can actually do it at machine speed. So technologies like BigID, for instance, and other technologies can help do that. The second piece is really honing in on what are you trying to accomplish with AI.

What we see in the marketplace is a lot of times people are doing AI for the sake of doing AI because it's something cool and they want to be part of the cool train. But it's really like what is your company actually trying to solve from a problem perspective. So, as an example internally, right, Sean, we have to go and find business for our consulting company. Well, how do you use an agent to go out and find those people that might actually need our help in the specific areas and services that we offer and actually deliver us some leads that we might not even know about.

Those are things that help enable while you can still have the guardrails. You can still make the determination around your risk tolerance levels around which use cases can be fully autonomous because it's really low risk and if the AI does something really strange it's not going to actually affect your customer or your business compared with those things that Gabe was talking about where you certainly don't want fully autonomous when you're talking about national security and issues across borders. So put your use case into perspective, think about your risk-tolerance level, and consider how you use the existing AI technology to automate and make things machine-readable.

So you can go at machine speed versus human speed in the use cases where you can allow that risk tolerance. And then I think the second major core piece is change management. So it has nothing to do with technology. It has everything to do with the human capability of understanding what AI is and what you're trying to do. How it's going to affect their job, their job descriptions, their day-to-day jobs, what learning and capabilities they need. We talked about data literacy in the past. Now we talk about AI literacy. We talk about cultural changes to organizations, etc. So I think change management is a second huge component.

How do you get your HR group in with you to actually develop what those principles are around AI? How are they going to affect your employees? How are they going to affect your customers, etc. We're working with a customer right now in New York working on that very topic which is really interesting. And then the last component really is around the safety and the responsibility.

So when we ask whether governance can enable, if you actually have your processes in place where you're organizing from less secure data to more secure data, as an example, and you can provide access to the right data for people to use, then you can actually accelerate people utilizing the right data at the right time at the right level. Right? And we talk about things like you know the cost involved, the energy involved in using AI. If you put into place the right governance models, you're going to reduce your duplicate data. You're going to reduce the ROT data, right? Redundant, obsolete and trivial data.

You're going to actually focus people on the right stuff to use and therefore they're going to use less AI and less electricity. Better for the environment, all that fun stuff that people like to talk about when we when we talk about AI. So, a lot there, but three capabilities: put guardrails in place and use AI to do the governance; second, change management; third, understand how AI can be used and executed more efficiently.

Sean Russell (26:01):
Absolutely. Absolutely. I want to ask a question on this from the audience. Duncan asks what is the simplest way to demonstrate effective governance when the rules defining it are still evolving. So you're talking about the things that you cover in your chapter in the very same book. There we go. So Stephen also wrote a chapter in that book. I highly encourage you to buy it. It is a fantastic work. It is available on Amazon right now and not to make this a plug-fest but I also talk about it in the AI workforce playbook in my book. So we've all got books. Everybody's got books now.

That's probably a negative consequence of AI. I think we all have more things to read, don't we? But the world is changing so quickly. You mentioned change management, which was one way to address this, but you know, if AI is too fast for policy, it's probably a bit too fast for change management policy. What is the simplest way to demonstrate effective governance when the rules defining that are still evolving across different geographies?

Stephen Gatchell (27:26):
Yeah. So look, our tagline is human first, right? So, we talk about the human element of this stuff all the time. So, you're never going to keep up with the speed of AI, but you always want to understand the human component to it and how it's going to be affected. And so, the rules I'm less concerned about. It's like there's plenty of regulations out there and there's more coming clearly. Utilize those as your baseline support mechanism. Educate your people on those consistently. And then again, you can even use AI to say, I'm utilizing this new use case. Here's the existing regulatory requirements.

What do you foresee as requirements in the next 100 days, one year, whatever, and actually be ahead of what the regulatory requirements might be. And I think most companies that do AI responsibly and safely, they actually do what's best for their customers, right? And they put that in context of their customers and their employees. And so you may not have the regulatory regime moving as fast as AI is developing, but you still have your internal value system for your company and you should follow that and do it safely and responsibly. So I think that's definitely one way to approach it.

Sean Russell (28:36):
Yep. 100% agree. I'm rarely going to step in on any of these, but I'm going to step in on this one because this one's near and dear. So I think you're absolutely right, Stephen, and I would broaden that just a little bit. I think your point on focusing on the outcome is even more key and the better you define those outcomes, the better you can define the appropriate level of governance to enable, but also protect, whatever it is you're trying to do with AI. You're absolutely right, though: the key focus has to be that end user. I do think compliance with regulation and internal policies is absolutely essential.

However, that focus on the value of the customer and the importance of the customer within the organization has to be your north star when you're building out an AI governance framework. And it is, to my mind, the fastest way to demonstrate effective governance because you have that customer in mind. And so the actions that you're taking are with that customer in mind, whatever your customer is, whether it's B2C, B2B, so on and so forth. So I think that's a really good answer. Thank you for that. Anybody else want to weigh in? I realize I stepped into player role here for a minute.

Christopher Hoesly (30:11):
Oh, you're allowed to do that by the way. It's okay.

Sean Russell (30:13):
Hey, thank you. Well, you know, I appreciate it. Great. Well, we talked...

Gabe Arrington (30:21):
I'll jump in, Sean.

Sean Russell (30:22):
Oh, please do. Okay. Yeah.

Gabe Arrington (30:26):
Yeah. Just briefly, and I'll probably touch on this later, but I would say that AI governance is a long-term game and you know, educating the future generations of what that means is going to be important. And you know, we saw 4G technology proliferate in 2008, leading to peak iPad sales in 2013. Every kid that was 5 years old or older in 2013 and on has been exposed to iPads and a digital life. And so how they are going to interpret AI governance when they become college students and enter the workplace is going to drive us in certain directions. And so focusing on education is important.

The Skills Gap and the Discernment Horizon (31:11-39:50)

Sean Russell (31:11):
Absolutely. And that brings up a really good point that isn't in my notes, but I wonder if I could get everybody's take on this or just kind of jump in a little bit. You're right that this is long-term and one of the key governance challenges I think and a key difference between data governance and AI governance is that there's going to be a skills gap as these roles and many of these things become automated that weren't automated before. If something crucial or critical breaks down, that human in the loop is going to be less and less capable of addressing a serious concern. I've heard it called the discernment horizon.

And once you're past that discernment horizon, you know, you're out over your skis effectively. I feel like this is a governance challenge we haven't necessarily hit upon yet, but it's something that's coming down the pipeline. Does everybody else feel the same way? Is this happening in government? Is this happening in business?

Christopher Hoesly (32:22):
Yeah. Yeah. I'll go first because I literally had this conversation last week at Black Hat with a random startup owner that was out there and the classic statement at Black Hat last week was, 'Hey, we vibe-coded this thing. Awesome. What's it going to do?' And you go, 'Okay, cool. That's great. That's interesting. Why are you different from the next one?' They're like, 'Wait, there's somebody else that does this?' It was this full stop. You're just another, you know, piece of cereal in this grand bowl of things that everybody's trying to do and you look just like the next one. Why are you different from this one? And you don't know.

Congratulations. That actually got translated right back to the skill set where I literally had this conversation where we're acting and reacting tactically right now to everything because it's happening so fast. For the last six to nine months, it's just been AI, adopt it, go run, we'll figure it out afterwards. And now the bills are coming, actions are coming and cost is coming into play and everything like that. And then you stop and you go, "Wait a second here." If something is broken in this automation cycle, the number of people who know how to fix it or revert it back because they're not putting a rollback feature in is diminishing.

And there was one person that I've talked to for a very long time. He said this to me. He goes, "It's the same thing as COBOL programmers." And I went, "Wait a second. What do you mean?" And he goes, "Think about it. Every major financial services and insurance organization still runs on mainframes." So you can't get rid of the people that know how to actually write in COBOL and know how to navigate DB2 because if that breaks, everything else we've built upon it shuts down. He goes, 'It's the exact same thing: all this autonomous functionality and all these agent endpoints that are sitting out there.

AI is taking over and it's just going to run workflows and agents are going to handle these things. But what happens when the first one causes a spiral effect?

You need to have a team that actually knows how each and every single process actually works inside the business so that when it has to either be undone or in the worst case, rebuilt, you actually have the skill sets to actually know how to program, know how to redesign, have a database administrator, have all these people that actually have real skills for what's actually being done.' And he's building a project around that idea of basically how it aligns to a person within AI, right?

So which teams would be aligned to each area that he's building it to make sure they don't get rid of people as they're building out their product. It's a very interesting approach. I was like, 'Wow, that's actually wildly interesting,' and he's targeting it at small to medium-sized businesses, not major enterprises because he goes it's just being forgotten. These teams are being forgotten and people with lots of skills are just kind of being set to the side because they think AI can take the job. So it's very interesting from that angle.

Stephen Gatchell (35:34):
So Chris though, let me play devil's advocate. Sorry I'm taking over for a second because one of the challenges we have that I see in the marketplace is they'll be like, "Okay, well why do we need enterprise solutions or these tools or that tool or this framework or that framework because AI can just give us the answers, right? So if you have a COBOL problem, just feed in the code to some AI program and it's going to give you the answer or whatever." In all sincerity, that's how people think: 'I'm not buying any more tools in the marketplace.

I'm just going to create my own tools.' How do you address that? What are your thoughts around that? Because I'm with you on what you're saying 100%. But I think people who don't understand AI and the implications of what it can and cannot do are thinking in total terms: 'I'm just going to outsource everything to AI.'

Christopher Hoesly (36:20):
Yeah. Yeah. I look at that and I've had similar responses to enterprise level organizations, right? Fortune 50 organizations and they go, "Well, what if we just built it? The number one response right now is, 'This GSI could easily just build a Salesforce replacement.' And you stop and you think about it and you go, 'But they've been around for 15 years, iterating for 15 years and building a massively complex, beautifully written piece of software.' While a little bit verbose in a lot of situations, it goes out there and you kind of go, didn't we learn this lesson 20 years ago, right?

That random guy built the application because it was before ERPs were really solid or whatever else it was. And now we're trying to solve the problem and fix the thing that was a legacy application that was built 20 years ago so you can get off of it finally. And then you realize it's the exact question you asked Sean, which was what happens to all the skilled people who probably were around and knew how to build those things. They're either retiring or they're being displaced in this process.

You're literally creating this cycle all over again where, fine, you could custom build something, but what happens when the team that custom-built it moves on, right? Or you decided to displace them because AI created this for you and it built it and now you go great, it was only able to build that because they were able to give it all the inputs it needed to actually do this process and now you got rid of them. Well, what happens when it stops working? Well, we've got to bring them back. We're back to square one all over again of why did we just do this?

We just dumped a ton of money into something that we literally already had an answer for, but it came from the brilliant minds who were sitting there in order to create it anyway. So, it's a wildly vicious thing. We've had huge organizations literally remove organizations and then all of a sudden they call them right back in again because whatever was sitting there stopped working. And if you've ever been a part of an organization where productivity stops, it is measured in hours in the sense of dollars per hour. As soon as it hits 10 million bucks, congratulations. Everybody's going to raise their hands and go productivity is gone.

We need to bring this back together, start from scratch or restart the cycle we had spinning for the last 20 years.

Sean Russell (38:45):
I can only imagine it's the same thing in government as well. I mean, Gabe, keep me honest here, but that's an even bigger flywheel that's probably just crushing through stuff like that.

Gabe Arrington (38:56):
I'd agree.

Sean Russell (39:00):
Excellent. Excellent. Well, I'm glad I asked this question. It definitely feels like a hot button. So Chris, let's stick with you for just a minute. We just talked about resource gap and how that causes trouble. We've talked about enablement and what we need to be able to do from an outcome, change-management and governance perspective on making sure that we're enabling. You've given some good examples of companies that are doing this in an interesting way. How do you balance enablement on the one hand with security and compliance and safety? And I want everybody to weigh in, but Chris, let's start with you.

Balancing Enablement with Security (39:51-44:32)

Christopher Hoesly (39:51):
Sure. Stephen knows this. I actually don't have an IT background, right? I actually have a dual degree in English and biology, so literally nothing to do with it. And I came into the space. So English has always been this thing, and so you guys have been talking about books. I'm building out my Amazon list of more books to pick up and read which my wife is going to absolutely love. But I come back to two classes, right? And I'm going to go to a book that I absolutely love. It's by Ray Dalio. It's called Principles, right?

And he describes it as principles are the things that you simply do not compromise on. And that would be security, right? These are non-negotiable points of view for how the organization should operate, whereas enablement are your rules, right? They can be bent. They can be broken in some situations. They can be manipulated and changed over time based upon the needs. But the principles remain in place. Nothing actually changes with security as it relates to AI. In fact, it probably needs to harden even more so, right? You need to understand where data sits.

You need to understand who's got the access to it because AI is basically assuming the role of people. It's assuming the role of different areas. So if you're not locked into security practices, your core principles of don't overexpose information, don't expose it to new areas, don't allow access to everything, those things you've been building upon as your core foundation of principled ideas need to remain. In fact, like I said, they need to harden. Whereas enablement is now giving your team a set of rules that they should follow when they think about using AI. Right? Do you understand you have a set of permitted frontier models you're supposed to use?

Should you choose not to, our principles will catch you and say you're using Kimi K3, right? Since we're talking non-U.S. models. Nope. We're going to catch those. Hard stop. Fine. Hey, this is your enablement. Remember, you're using something you're not supposed to be using. This is what it's designed for. This is how you're going to work with it. Security behind the scenes is going to make sure that you don't jeopardize the organization because of something that you might not have been aware of because you use Cursor, which allows you to pick the model that you're using. Across all those areas, it's this unknown thing.

So enablement is designed to help educate and begin to build rules around it, whereas security is basically saying, 'Hard and fast: do not violate these.' We will stop you if you do. Keep that in mind moving forward. Hopefully that analogy worked for everybody, but if not, obviously, there are questions you can ask.

Sean Russell (42:42):
Yeah.

Stephen Gatchell (42:44):
If you don't mind, I want to jump in for 30 seconds here. I think the biggest thing when it comes to security and I'm with Chris on the principles like we literally have a project right now where we're designing principles around their AI usage, right? To go by hard, steadfast rules and give people room to move. But part of those principles is the risk tolerance conversation, right? I don't think there's enough conversation around what risk we're willing to take for the outcomes that AI can provide from a compliance perspective, from an efficiency perspective, whatever the topic of conversation is.

And so I would say as you go through and balance that enablement versus security and compliance and safety, you absolutely have to have the risk-tolerance conversation in a cross-functional manner of what the CISO is going to allow versus the CDO versus finance versus your CEO because they want to move fast. But when you say, 'Okay, we can move fast, but here's the risk-tolerance level. Are you accepting that?' It becomes a very interesting conversation. So I just want to make sure that the risk piece is part of it.

Sean Russell (43:52):
Yep. Really good point. Really good point. Making sure that everybody is aligned is key. Not just there, but all over AI. And I want to talk about why for just a second. There's a couple of points I want to bring up. One: a recent Ipsos study found that 21% of AI use for work in the U.S. is on a personal plan. Now, there's two reasons why that happens.

Shadow AI, Visibility and Culture (44:33-51:24)

Christopher Hoesly (44:33):
Only 21%. That's low. That's really low.

Sean Russell (44:42):
I can only report the figures I could get. But I agree with you. It feels low to me, too. But 21% is one in five people. One in five people. And I will say that a further 10% of those people admitted in the survey to feeding proprietary information into their personal account. For the uninitiated, what I'm talking about falls under the broad term of shadow AI. We had a question from the group that I wanted to ask. What are some successful methods that firms use to get visibility around shadow AI? And I imagine this is affecting government as much as it is private enterprise, if not more so.

Yeah, feel free - anybody jump in. That's for all of you.

Christopher Hoesly (45:46):
I can go first if you want just because it's kind of my world and has been my world for over a decade now. It falls into two buckets. It's proactive and reactive and it's always been that way. That's literally how it has worked with data, and now it applies to AI. Knowing what data is sitting out there is always the proactive methodology, right? Because that applies to things like compliance and governance, privacy, security. If you don't understand what's actually sitting there, there is very little hope that you're going to be able to react fast enough.

So taking a proactive stance to understanding what you do have in your environment, what is being adopted and coming to a conclusion of having a source of truth is a concept that's been around for a very long time, right? And having that proactive stance allows you to be more proactive in everything you do. Every CISO that I talk to, it's the idea of the less I have to guess about, the better off I am at reacting to what needs to happen, right? That's always their stance.

The reaction though is the other side of this house, which is basically saying: of those 21%, if they're moving that information over there, how are you able to see that? And you're going to have to do that in a way that basically says inside your corporate policies, if we determine that you have access to sensitive data and we have a way to see that you accessed sensitive data and you started to move that information out, that is our information, and you're taking it and we have the ability to go and actually give ourselves access to that information.

As a VP of security, we have those written into our policies that basically anything that's sitting out there, we get to keep track of it. We get to understand how you're working with it, how you're interacting with it. It's not flawless. It's not, you know, there are gaps in how that actually works. But when you breach that part of the agreement with how you're working for the organization, we have ways to make sure that you understand that we will make sure that you have not shared that information as well.

Now, well, we're not going to get into it because this will take us all the way to the end and I know we only have 12 minutes left, but the ability to actually act on it and go find out everything that's gone on and what they've done after the fact, that's a whole other story of legal problems and headaches. But understanding what it looks like first from a proactive stance is great. Understanding how to react when something does seem nefarious or possibly non-malicious, that's when you have to be ready to move with something like a cloud DLP or a CASB offering that sits out there.

Sean Russell (48:28):
Great.

Stephen Gatchell (48:29):
And it's worse now than ever, right? Because we're not talking about just data now. We're talking about agents. We're talking about orchestration of agents. We're talking about MCP servers. We're talking about inventory of all that stuff.

Sean Russell (48:42):
Well, I'm wondering if there isn't a cultural element to this in the governance conversation. So, is it not also that we need to instill an understanding of the risk within our teams and our people and help them kind of bring them along for the journey? Because it can feel like no big thing. Maybe I'm only doing this so I can format a table and then pop it right back into PowerPoint. Nobody will notice. Or, 'I only used this data and not that data,' not understanding that you can use various data points to triangulate information and pull these things together and that AI can do that so much faster and better.

Or, 'I PDF'd it before I put it out so that you can't manipulate it,' not understanding that a PDF is like a PNG: the layers are still there. If you've blacked everything out, it doesn't matter because AI could just read it. Is that level of knowledge not also something we need to proactively educate our teams on? I think it is. I don't know if that was really a question, sorry. We have about nine minutes left. There are two questions, and the first is from Ron: AI is mostly based on the written word.

There is a big gap between what is written down and what is in the minds of experienced people. These experienced people are getting retired or let go. I think we've talked a little bit about this. This experience is now lost and the newer generations in AI will start making the same mistakes we've seen many years ago. So we've talked about the gap, but what can we do about the behaviour? Returning to this topic for a minute, what can we do as governance people to head this off?

Because if you don't think it will be a governance issue, it will be a governance issue: making sure that there are skills to handle this. How can we prevent it? How can we be proactive about it?

Preserving Institutional Knowledge (51:25-55:48)

Gabe Arrington (51:25):
I think we tend as humans to go to two extremes, black and white, plus and minus, etc. And this is going to be a gray area where we need governance, education and discussion. We need international bodies designed to think about this. So yes, this will happen, but how do we minimise things and work through it together? I'll go back to education and future generations. I had the privilege to be a mentor and judge for the Presidential AI Challenge and one of the finalists that was recognized at the White House a couple months ago used AI with the city of Jacksonville to identify city blight.

And so, it was a kid, a freshman in high school that took what the city was doing and one person was driving around trying to prioritize where to spend taxpayer money and enabled the city - and it has since spread to other cities and states - to really maximize their resources, which in turn has helped address crime, drug use, infrastructure decay, etc. And so that's not getting rid of that person's job that used to drive around. That's maximizing their time and allowing us to improve our community.

So, you know, that's one example and I don't know where it falls on the spectrum of the extremes, but I think the active discussion is what's important leading back to governance.

Sean Russell (53:03):
Yeah, I think that's a great example. I think you're touching on something that I think about a lot, which is that, you know, are we really using AI to its best purpose if we're using it to eliminate roles and skill sets or could we be better using it to drive growth? I think that's a bigger prize. It's maybe a more challenging prize and I think what you're talking about does that: enhancing people's individual abilities to do things better, more and faster rather than simply waiting or trying to kind of replace people.

Instead, give them that bionic suit of AI capability that allows them to do these things in a better way. I really like that.

Stephen Gatchell (53:56):
Well, just one example too, Sean, right? If we're using AI to help us with some of the minor things. Like think about we're recording this session right now. AI can take this and really summarize it into a paragraph or two and take the 'nuggets' out of this very quickly versus somebody, you know, having to sit through 60 minutes or they play it at 1.5 speed. What do they do? But the point is, if you can get people with that institutional knowledge and experience, if you can free them up from doing the minutiae and free them to do more mentoring, as well as use the technology to capture their thoughts, right?

So think about years ago, you would have to sit there and type out all your thoughts on paper. Now you could just record it for people. So if somebody's leaving a company and they have all this institutional knowledge and they're like, "Wait a second. 50% of what you do is on paper because we have your presentations and stuff, but 50% is in your head." Have them share it, right? Have them record it and have them spend more time on that mentorship and less time on the day-to-day tasks. Have AI do those low-risk day-to-day tasks.

And I think that goes to what Gabe was talking about around the, you know, the education piece. We don't do enough mentorship, quite frankly, or enough institutional transfer of that knowledge from generation to generation. We just don't do it.

Sean Russell (55:12):
Really important point. Mentoring is essential, especially if we're going to be talking about passing these kinds of skill sets into areas that may not be doing them as much because AI can support. Super important.

Gabe Arrington (55:33):
And again, I'll contend that mentoring flows both ways, right? The younger generations are mentoring me and exposing me to a world that I never knew existed. And so...

Closing Takeaways (55:49-58:58)

Sean Russell (55:49):
Yeah. Every day is a school day for everyone, if you're lucky. I've got one more question and we have very little time left. First of all, I want to say thank you to my panelists. You've been fantastic. I want to ask this last question to the audience, and I'd like you to answer in the chat. You've heard a lot of information today. What's one key takeaway you're going to take from it? What did you learn today that you'll be able to put into practice or that will generate a conversation in your group or teams? You know, talk to me about what you're learning today. Pop it into the chat.

And we shall await. Hopefully, we get an answer. If we don't get an answer, you have to listen to me read from my book. I'm reading a whole passage if you don't answer. So, you better respond.

Stephen Gatchell (56:58):
Well, listen. I'm going to give a takeaway. I won't put it in the chat, though, because I think it was really interesting. And I get to talk to Chris quite often, so I'm going to pick on Gabe for a second, but listening to Gabe and the implications of the national security context in the AI space is really eye-opening, right? We talk to companies every day and they think what they're talking about is very important, which is absolutely super important in context, but when you bring a person like Gabe into the mix and talk about AI in the space of defense and so forth, it brings a whole new light.

And when we talk about governance, it is exponentially more important in the space that Gabe is talking about. It's fascinating. So, Gabe, I'll be pinging you to continue the conversation myself. Look forward to it.

Gabe Arrington (57:48):
Absolutely.

Sean Russell (57:49):
100% agree. I think this is an amazing opportunity for business, technology and government to speak together to build on each other's knowledge, experience, and situational awareness of governance. I think there's so much to learn by getting together because a lot of the problems that the government and military have now, business either already has or will have later. So these are issues that are really relevant. We are almost at time so I am going to close it here. If you asked a question and we didn't get to it, don't worry. We will get that answered for you and we will send it out to you.

Thank you so much, everybody who joined. Thank you to Christopher Hoesly, Gabe Arrington, Stephen Gatchell. I've been Sean Russell. Thank you so much and we will see you on the next one.

The speakers

Picture of Christopher Hoesly

Christopher Hoesly

Field CTO & VP Security at BigID

Picture of Gabe Arrington

Gabe Arrington

Chief, International Affairs in the U.S. Air Force

Picture of Stephen Gatchell

Stephen Gatchell

Partner & Head of AI Strategy at Ortecha

Picture of Sean Russell

Sean Russell

Head of AI Enablement at Ortecha

Your next watch ➞

Ready to put one AI initiative to the test?

In 1–2 weeks, an Enterprise AI Readiness Reality Check will help you understand whether it is ready to scale, where risk or value is exposed and what to do next.

SHARE