Artificial Intelligence risks, a leadership perspective

An image of cybersecurity and information systems expert Mr Dwight Robinson.

The views expressed herein are solely those of the writer and do not necessarily reflect the views of One News SVG.

By Dwight Robinson, MSc Cybersecurity, Certified Information Systems Auditor (CISA), BBA Business Information Systems, CEO of Secure Business Systems, and Information Systems Security Association (ISSA) Barbados Chapter Member and Past President.

If your organisation has not defined how Artificial Intelligence (AI) should or should NOT be used, then your employees and third-parties will make that decision for you. That is the sobering reality any organisational Director or Senior Manager must face. AI has several benefits including innovation, enabling the development unique products and services, data analysis, improved service delivery, and automation & efficiency.

AI also poses several risks. Recent news stories include rogue AI agents escaping company networks, hacking innocent companies, exposing personal data, and leaving instructions to future versions of themselves to bypass human constraints, ignore safety rules, or evade shutdown commands. Organisational risks of AI include security and privacy risks and potential AI weaponization. Organisational data may be uploaded to public AI platforms and become part of publicly available data; this may include personal data. AI weaponization is perhaps the most concerning element as software AI agents can attack its host organisation, associated/integrated third parties and other entities, all under the mandate of accomplishing their assigned task. AI agents have been shown multiple times to lack any semblance of a moral compass, even though instructions exist for them to do so. Bias and discrimination are the second risk consideration. AI models or even organisations themselves may unknowingly introduce bias while training AI models using available data. Once the output produced has a bias, the organisation cannot separate itself from the result.

Lack of accountability is the third risk consideration for autonomously operated AI systems. AI agents which operate using staff user accounts and credentials may perform actions which are not in line with behaviour considered acceptable to the organisation and cause reputational, regulatory or financial damage. Lack of transparency and manipulation through poorly designed algorithms are the last two risk considerations. Most AI models operate in a black box where the actual actions and logic performed by the system are not transparent to organisations. This can lead to misalignment with organisational objectives, inappropriate sharing of data with the owner/host of the AI model or regulatory concerns. The manipulation of AI may be the result of intentional or unintentional manipulation of AI based on the information it is trained on, or the data inputted by the organisation and may have the same impact.

October is celebrated annually as Cybersecurity Awareness month. This year, the theme for organisations is to “commit to having better cybersecurity in your organisation to protect customers, communities and critical infrastructure.” The US Cybersecurity & Infrastructure Security Agency (CISA) warns that AI has accelerated the speed, scale, and sophistication of cyber threats and urges leaders to understand and assess risk AI and cyber with readiness and accountability, prioritize foundational cybersecurity practices and controls, empower cybersecurity teams with authority and resources, and stay actively engaged as threats and guidance evolve. Accomplishing the AI component of this mandate requires AI Governance, which includes managing all the benefits, resources, strategic objectives, performance monitoring and risks associated with the use of AI.

Good AI Governance starts with having clear goals on what the organisation wishes to accomplish with the use of AI. These should be aligned with the mission, vision and values of the organisation, ensuring the objectives of the organisation are not blurred and boundaries are not crossed. Second is roles and responsibilities, ensuring roles and responsibilities are delegated to different persons within the organisation, at the organisational, risk management and audit levels. Values is third on the list, as the principles of the organisation must be maintained to ensure public trust is assured with the responsible use of AI, putting people over profits. Forth, is workforce development with the need for the recruitment and development of staff with the necessary skills and experiences in AI design, development, deployment, assessment, and monitoring. Stakeholder involvement is fifth, requiring the input of all AI considerations to involve input from customers, staff, third-parties, shareholders, and regulators. This requires a clear understanding of how AI use will impact these stakeholders and their acceptance. Risk Management is the sixth consideration and may be the most difficult component for most organisations due to how new and evolving AI risks are, and the limited maturity of risk departments beyond regulatory compliance. Regardless of maturity, the process of considering, selecting, deploying and monitoring AI must involve adequate identification, analysis, and mitigation of risks.

Specifications and Compliance are the next two components and can be seen in tandem. Ideally, the specifications of the AI system should be in line with its intended use but also in line with legal and regulatory requirements, along with emerging standards and guidelines. In the Caribbean, standards and guidelines may be the options available and should be extensively understood and followed to protect the organisation. Transparency is the last AI Governance component. The risk consideration has already been highlighted as organisations must have a clear understanding of the design, operation, and limitations of the AI systems which will or are being used. Doing so will protect all relevant stakeholders.

An appropriate, secure and effective use of AI starts with Governance, and the other AI Accountability Framework components include Data, Performance and Monitoring. Ensure your organisation has the right approach and does not expose itself to endue risks.

END

 

Leave a Reply

Discover more from One News SVG

Subscribe now to keep reading and get access to the full archive.

Continue reading