Whether you believe the hype around generative AI tools like ChatGPT is reasonable or over-inflated, it’s impossible to ignore the impact it is having on companies. As of August 2023, McKinsey found around a third of organizations are using generative AI in at least one business function.
It’s easy to see why adoption is growing on such a massive scale. Thanks to advances in large language models, and other foundational solutions, AI solutions are now more creative, insightful, and powerful than ever before. They can unlock higher levels of productivity for teams, minimize operational costs, and even transform customer experiences.
However, like any powerful new technology, generative AI comes with its own set of threats and risks to consider. In particular, companies need to be aware of the security, compliance, and privacy issues linked with generative AI tools. As compliance standards continue to evolve, here’s what organizations need to know to implement generative AI, without compromising on security.
"For firms in regulated industries, addressing these questions is not discretionary - firms need to start by leveraging AI technologies that are specifically designed as regulatory grade to be able to withstand legal or regulatory scrutiny," said Robert Cruz, VP of Information Governance at Smarsh.
"The use of AI is an exercise in good information governance. Firms need to be considering where data model inputs are coming from, and the use cases that model outputs are touching to understand how they impact existing regulatory, legal, or data privacy mandates."
Understanding the Risks of Generative AI
The meteoric rise of ChatGPT, Bard, and tools like Microsoft Copilot suggests generative AI solutions will only grow more attractive to businesses in the years to come. Analysts like Gartner believe the democratization of generative AI will be one of the major trends we see moving into 2024.
However, the analyst also notes this rise in adoption will lead to a new demand for AI trust, risk, and security management. The primary reason for this is generative AI tools are powered by data, growing stronger with each byte they consume. Without the right approach to AI development and data management, companies face a number of threats, such as:
- Data and IP theft or leakage
- Malicious content and bias
- Copyright infringement and plagiarism
The risks associated with generative AI don’t mean companies need to ignore or avoid these tools. However, they do require all organizations to take a strategic approach to implementation, focusing on the following factors.
Step 1: Practicing the Principle of Explainability
Explainability is one of the core pillars of “ethical AI”. It’s also crucial to building trust with stakeholders, and ensuring the responsible use of innovative technology. When implementing any new AI initiative, companies need to ask themselves whether they can interpret and articulate the data produced effectively, and whether the inputs and outputs can be fully understood and validated.
Consider how your organization will identify and remove potential biases in the AI system, and how you’ll be able to validate the information generated by your technology. If the executives in a business don’t understand the way a solution works as well as a data science, this is a sign you haven’t fully nailed down the concept of explainability.
At a basic level, firms should have a plain English summary of their AI models available to help them explain its performance to auditors and regulatory investigators. This summary should address the functionality of the model, key components, and even potential risk areas which need to be addressed.
Step 2: Avoid Bias from Day One
Whether you’re leveraging pre-built foundation models, or customizing generative AI solutions to suit your own business purposes, it’s important to recognize the risks in the data used to fine-tune and train these tools.
Data is at the core of any LLM, and models trained on bad data can lead to serious results. After all, the outputs of generative systems are only as unbiased as the data they were trained with. This means, by definition, AI will always be somewhat biased. Concepts like feature weighting, which involves applying more value to certain data elements, inherently creates bias.
This bias creates problems in the way information is produced. It can harm the reputation of a business, and lead to wide-spread misinformation, a significant ethical problems for organizations. Taking steps to minimize bias will be essential to protecting any company and its customers. For instance, bringing “weights” down to zero may be an option for some companies.




