Author transcript
Hello there and welcome back to UC today. In our last conversation, we talked about why AI governance has become a live compliance issue, not a future one. As co-pilots, meeting assistance, and AI generated recommendations become part of everyday business communications. This time, we're getting practical. If you accept that AI assisted communications needs to be governed, the next question is where to actually start and how to do it without slowing the business down. I'm joined again by Sonia Bache, senior vice president and GM of Arctera and Enterprise Bolt. Sonia, welcome back.
Thank you, Marcus. Pleasure to be here.
Really glad to have you with us. So, let's start at the beginning if that's okay. Where should organizations actually start when assessing their AI governance readiness?
Yes, very practical question and I would say that the first step is to understand the information landscape before scaling AI initiatives within the organization. We should really ask three questions. In my opinion the number one is do we know where our business information resides across collaboration platforms. Second can we govern both human and AI generated communications consistently? And third do we have the policies oversight and auditability to use AI responsibly? AI is only as trustworthy as the information and governance behind it. The organizations that are most AI ready aren't necessarily those with the most advanced models and having an ecosystem to deploy that every day, but they are the ones with the strongest foundation of trusted information and governance. Once we have the answers to the three questions, I think our overall information governance and the mindset of the organization will be truly ready in order to expand the AI footprint in the organization.
So once that process is underway, teams of course need to know what they're actually looking for. So what types of AI generated outputs should compliance teams be paying attention to?
Yeah, they should really be paying attention to any AI generated output that influences a business decision, customer interaction or regulatory obligation. And that includes for example emails, chat messages, reports, summaries, recommendations, meeting notes and even AI generated responses shared with customers or end users. The key isn't whether a human or AI created the content. It's whether that content becomes part of the business record. As AI becomes embedded in everyday work, organizations need to govern AI generated communications with the same rigor they apply to human generated communications. If an AI generated output can influence a business outcome, it deserves the same level of governance. And it's truly the mindset shift by seeing both the communication workflows through the same lens and applying the governance layer on top of it.
You've touched on that really nicely as far as the scale of the challenge that most enterprises aren't working in just one platform. It's across several collaboration tools each with their own AI features. So with that challenge, how can organizations reduce blind spots across environments like that?
Great question. In fact, I would say that it really starts with we all need to stop thinking about governance platform by platform and really start thinking about it across the entire information ecosystem. Today as I mentioned business conversations happen across many collaboration tools and employees don't think in terms of channels. They shouldn't be even thinking about that. They simply communicate. We need a unified approach that provides consistent visibility, retention, communication, surveillance and governance across those environments. The more fragmented your view of information, the greater your blind spots. Those who reduce most effectively are the ones that govern information consistently regardless of where the conversation is taking place.
I'd like to move on to the subject of defensibility. Could you just talk us through what defensibility actually means in the context of AI governance?
Yeah, in this context defensibility means being able to demonstrate that your information is complete, it's authentic and it's managed according to governance policy. Say for example if a regulator, auditor or a court asks how an AI generated recommendation email or a business decision was created, organization need to be able to explain it with confidence, which means you really need to have a stronger data lineage, data provenance workflows that requires more than simply retaining information. It requires transparency, auditability, and consistent governance throughout its life cycle. In the AI era, defensibility isn't just about proving what happened. It's about proving you can trust what happened and that's most important.
Fantastic. We talked a little earlier about the perception in some organizations that compliance exists to slow things down and manage risk downwards. So in practical terms how can compliance teams support innovation without increasing risk?
Yeah, the role of compliance is evolving. I think saying no to enabling information responsibly, we really need to now have that mindset shift that the most effective compliance teams don't wait until the end of an AI project to assess risk. They shape and help organization from the beginning by establishing clear policies, trusted governance and appropriate oversight at every level that gives the business enough confidence to innovate faster while meeting regulatory and ethical obligations. Innovation and compliance aren't really the competing priorities. We often get into that debate that okay are they complementary? I have seen people using them interchangeably but I think those that innovate the fastest are often the ones with the strongest governance foundation because innovation and compliance aren't competing priorities. They are truly complementing each other.
Yeah, that's really interesting because you know what I'm taking away is that if governance works, it shouldn't feel like a separate process at all. What does good AI governance actually look like in the flow of work?
Yeah. I am of that opinion that AI governance shouldn't feel like a separate process. It should not. It should be embedded into the flow of work and that's very important because as employees collaborate across various communication channels with now various AI assistance, governance should work quietly in the background ensuring information is captured, protected, retained and governed without disrupting productivity. The goal is to let employees innovate with confidence knowing their information is secure, compliant, and defensible. The best AI governance is invisible by design in my opinion, but it is truly integrated into everyday workflows rather than imposed as an extra step.
So, this has been a really fascinating conversation, Sonia. I've really enjoyed it. Let's close on some priorities. What should leaders be prioritizing over the next 6 to 12 months as all of this plays out?
I like how you have defined the time frame as 6 to 12 months and I truly get it. I think how rapidly we are moving in the current landscape. I think it's important for us to really focus on a few important things. Number one, first build a strong governance foundation by understanding where business information resides and ensuring it's trusted, secure, and well managed. Second, embed governance into the flow of work so AI can be adopted consistently across collaboration platforms without creating new risks. And third, invest in transparency and accountability so that every member, every employee, customers, regulators can trust AI assisted decisions. So over the next year, success won't be defined by who deploys the most AI. It will be defined by who deploys it responsibly and earns the most trust.
Great, Sonia. Thank you very much. I think if there's one thing to take away from this for me, it's that governance done well doesn't sit outside the workflow asking people to slow down and check in, but sits inside it. And that's a different way of thinking about compliance than I think a lot of people are used to. So, thank you very much for your time today.
Thank you, Marcus.
So, for more on this subject, there's plenty more on this topic at UC today. We've pulled a wider story together in a full piece looking at why information governance is becoming the foundation of enterprise AI. Do look out for that on UC today and thank you very much for watching. We'll see you next time.