AI, Government, and the Future · 2025-02-12 · 39 min
Key moments - from our scoring
Substance score
42 / 100
Five dimensions, 20 points each
Candy Alexander brings 35 years of cybersecurity experience to the challenge of trustworthy AI deployment. At NeuEon, a mid-market consulting firm, she advises clients - primarily CFOs and COOs - on operationalizing LLMs and gen AI tools responsibly. Rather than promoting technology for its own sake, Alexander insists on solving business problems first, then applying AI appropriately. She highlights a critical blind spot: most mid-market enterprises deploying Copilot or other LLMs fail to implement data classification, access controls, or data loss prevention (DLP) tools before opening these systems to employees. This exposes sensitive unstructured data - salary information, revenue figures, internal documents - to unrestricted queries. Alexander advocates for classical security hygiene: data classification schemas, Microsoft Purview or equivalent data security and protection maturity (DSPM) tools, and rigorous data governance spanning both structured and unstructured data. She frames trustworthiness differently than industry hype, distinguishing it from safety (a regulatory concern) and security (preventing interference). Trustworthiness is organizational: does this AI agent act as expected, given our data quality, model integrity, and risk tolerance? She emphasizes data fabric concepts, data lineage tracking, and clear role definition - data owners, custodians, and consumers - as foundations for enterprise AI governance.
Implement data classification schemas, apply access controls tied to role-based permissions, and deploy data loss prevention (DLP) or data security and protection maturity (DSPM) tools to scan and restrict unstructured data before feeding it to LLMs. Without these guardrails, any employee can query anything the model can access.
Trustworthiness is a security and organizational concern: whether the AI model acts as expected given your data quality, model integrity, and risk tolerance. Safety is a regulatory and systems-level concern, like ensuring autonomous vehicles don't malfunction. Cybersecurity owns trustworthiness; regulatory bodies own safety.
Data owners define data criticality and retention policy; custodians (IT, security, developers) enforce controls and ensure data integrity; data consumers validate quality and accuracy. All roles are necessary - data governance cannot be owned by security or IT alone.
Most organizations and their colleagues focus on structured data governance in ERP systems, missing that LLMs consume unstructured data - documents, web links, databases - which is rarely classified, labeled, or controlled. This exposes proprietary and sensitive information to the model.
Set retention to local copy only, verify which model version you're using (avoid those with known issues), configure role-based access to the tool, classify data being fed to the model, and apply metadata tagging so the ML system can apply permissions automatically.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a few genuinely useful points buried in the conversation - particularly the Copilot data-exposure risk and the observation that data classification metadata now matters because AI consumes it automatically - but the episode repeats 'it's all about the data' as a refrain without unpacking it substantively, and the advice on data governance, DLP tools, and access controls is well-worn CISO material.
LLMs are uh, going after unstructured data and that's the part that nobody manages
that classification and that, you know, labeling is associated to the metadata, right? And now the machine language, the MLS, the AIs are applying that automatically
The security-versus-safety distinction using the autonomous automobile analogy and the framing of 'AI as an identity in your environment' are the most interesting conceptual moves, but the bulk of the episode recycles standard data-governance and regulatory-history talking points that circulate widely in CISO circles.
we cared about the perimeter of the car network. We just wanted to make sure it was protected. Protected as opposed to safe
AI is an identity in your environment. It's another being, I hate to say, but it's close to being that now
Candy Alexander is a credible, working CISO with 35 years of experience, two-time ISSA International president, and active CSA AI working-group participant - a genuine practitioner, not a thought-leader-for-hire - but her current client work is primarily with mid-sized businesses on basic LLM deployments like Copilot, which limits the scale and depth of the practitioner insights she can share.
I've been doing a lot of volunteering with the Cloud Security alliance and their AI research groups
I'm a ciso, I'm more executive strategic and they're like, you know, talking about agentic AI system designs
The episode scores modestly on specificity: it names real laws (SB 1386, 201 CMR 17), real tools (Microsoft Purview, Perplexity, Deep Seek R1), and a concrete Copilot misconfiguration scenario, but it offers zero metrics, dollar figures, or outcome data, and the client anecdotes are kept deliberately vague.
SB 1386 or something like that in California, right. Where you had to have an information security program...then followed by the state of Massachusetts with 201 CMR 17
I also forgot to hit the button that says retention to local copy only
The host asks broadly reasonable questions but routinely pivots to sharing his own company's experience rather than following up on the guest's vague answers, and never challenges an underdeveloped claim; when the guest admits she has no rigorous answer on measuring AI trustworthiness, the host simply supplies his own analogy and moves on.
Yeah, well, I mean corner lines, we're a small, medium sized business and we're leveraging gen AI and LLM tools to increase, you know, the efficiency of new employee onboarding
it's not really an easy answer or question mark to answer because we are on the forefront of that right now
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of AI, Government, and the Future, host Marc Leh is joined by Candy Alexander, a prominent cybersecurity leader with over 35 years of experience and current Chief Information Security Officer at NeuEon. As a two-time President of the Information Systems Security Association (ISSA) International and founding President of the ISSA Education and Research Foundation, Candy brings her extensive expertise to discuss AI trustworthiness, data governance, and enterprise security challenges. Drawing from her role as CISO and Security Practice Leader at NeuEon, Candy explores the intersection of AI implementation and cybersecurity, sharing insights on how organizations can responsibly adopt AI while maintaining robust security measures. The conversation examines practical approaches to building trust in AI systems, the importance of data governance frameworks, and the evolving landscape of AI technologies from agentic systems to cognitive AI. Throughout the discussion, Candy draws upon her extensive background in cyber risk management and her experience leading the annual ISSA/ESG research project.
Transcribed and scored by The B2B Podcast Index.
Speaker A: When we talk about trustworthy AI, is this AI model, AI agent, is it acting to the level of trust versus risk and each organization is going to be different or instance use case of that, is it going to act as I expect? It involves all kinds of things like data quality, involves security of the model to make sure it's not poisoned and that it is unbiased, um, and so on and so forth. It's a long hack.
Speaker B: Welcome to AI, Government and the Future, a podcast by Corner Alliance. We explore the intersection of artificial intelligence, government and um, the future. We work with government to create results. We ignite your agency's mission by helping you to design and um, implement high impact and innovative federal programs in AI, broadband, cybersecurity, public safety and more. Being a government ally is at the core of all we do.
Speaker C: Welcome back to AI, uh, Government in the Future. I'm your host, Marc Ley and today I'm thrilled to welcome Candy Alexander to the show. Candy is a distinguished leader in CyberSecurity with over 35 years of experience, currently serving as the chief Information Security Officer and Security Practice lead at Neuron. As a two time president of the Information System Security Association International and the founding president of the Issa Education and Research Foundation, Candy has been at the forefront of aligning cybersecurity strategies with organizational objectives, emphasizing the integration of security into overall business practices. Today we'll delve into the critical role that AI plays in solving mission critical challenges across different industries. We'll explore how organizations can better align AI driven solutions with their strategic goals, address ethical and governance concerns across the board, and foster collaboration among stakeholders to maximize AI's impact within a responsible framework. Candy, welcome to the show and it's a pleasure to have you on.
Speaker A: Thank you Mark. It's great to be here and thank you very much for the invite.
Speaker C: Yeah, yeah, absolutely. So I like kind of baselining the audience, giving them a sense of how our guests currently spend their time and you know, their current priorities and the projects they're working on. So Candy, do you mind sharing a little bit about kind of the focus of your current role and what types of AI related initiatives that you currently work on?
Speaker A: Yeah, so from the day job perspective at New Eon, it's a consulting firm outside of Boston, so we deal primarily with mid sized businesses. So you know, when we talk about AI and our client base, it's pretty simple. You know, they're looking to solve simple problems with, you know, the new jazzy tool that everybody wants to play with, which is AI, of course. So you know, it goes anywhere from really understanding and implementing something as uh, simple as copilot to trying to come up with a chatbot, to I mean fill in the blank that in, you know, it's a really interesting company that I work for in that we're more strategists and advisors. So you know a lot of businesses come to us with the business problem and then we help sort through that with technology. So that's why I have a really huge emphasis on solving business problems with technology as opposed to um, the other way. Right. Of solving technology problems for business. You know, it's really important that we reverse that conversation. A lot of folks we work with are actually CFOs and COOs, interestingly enough. So I've really, in the eight years of working with this firm have really retuned my conversations, my language to be that translator of technology in business terms. And vice versa.
Speaker C: Yeah, well, I mean I come from a similar background, you know, developing kind of lean purpose built tools to improve operational efficiency, be more competitive with like product and service offerings. So I think, you know, we've got a lot of shared kind of perspective there Candy, in terms of like the types of tools that you're primarily working with, are they LLMs, like for the most part or are there other kind of a broader suite of analytical tools that you and Nuion deploy with your clients?
Speaker A: Yeah, pretty much. LLMs. I mean, you know, and den AI. It's the thing, it's again, like everybody has said time and time again, I won't go in deep on this but you know, the technology progression is happening at uh, lightning speed, at the speed of light. It's just amazing. So therefore, yeah, when we first you know, talked about me coming on it was like just emerging and now it's like we're full blown 2ft into this LLMs gen AI for common business. So that's the day job. Of course on the other side of this I do a lot of volunteer work I have throughout my career for me is the best way for me to grab onto new concepts and technologies. So with that I've been doing a lot of volunteering with the Cloud Security alliance and their AI research groups and it's been a phenomenal experience. Been able to somewhat keep up and at least understand what they're talking about because again I'm a ciso, I'm more executive strategic and they're like, you know, talking about agentic AI system designs and it's like, so they tell me I am like the balance to their Tech to keep it real and keep it honest. But I mean the most exciting I'm working on with them right now is the agentic systems, the multi agent systems, the mass. So that's been a lot of fun. Um, really interesting getting into conversations like what is security, what is safety and then what is trustworthy AI? Because everybody's talking about trustworthiness, but what exactly is that? Right?
Speaker C: No, and, and I think we can certainly explore both, you know, some evaluating the trustworthiness, reliability or utility of outputs generated by some of these LLM systems here in a minute. But I do want to go back to your day job, as you said, for a minute without sharing too much, given that I'm sure there are some sensitivities with ongoing client engagements. But Candy, have you seen any particularly impactful themes with how LLMs are being deployed to solve specific business problems? I guess another way of saying it, are there business problems that are kind of tailor made for gen AI or LLMs to support them? Given your experience?
Speaker A: I would like to say yes. But to be quite frank, no, because again I'm working with mid sized enterprises, right? They typically don't have on staff coders, they don't have, you know, a lot of times don't even have on staff IT support. They have MSPs, MSSPs and you know, they were smaller companies. So when they're talking about implementing AI, it's like I said, basic stuff and it's like Copilot. But that's as dangerous, if not more dangerous. Right? And let me give you the little more story on this client. So they came up with a brilliant idea that they wanted to do Copilot, you know, this new snazzy tool from Microsoft. And it's from Microsoft, it's going to be safe. And so I'm like, you know, hold the phone, let's think about this for a moment. You know, you go and you, you know, just open up Copilot to use within your organization. Now all employees are able to query that AI, like things like where do I stack up in the pay scale or how much revenue did we really bring in? What's really, uh, you know, things that are uh, privy according to role, right? So without putting parameters even on something as simple as Copilot or you know, pick any of your other simple models, then you're opening up your organization to all kinds of issues. So really getting them to realize that we need to really worry about the data. And when I talk about data like to my colleagues at nuion, they think about structured data. And it's like you got to understand, right, LLMs are uh, going after unstructured data and that's the part that nobody manages.
Speaker C: Yeah, well and it's a good point because essentially you're scraping whatever database or repository of unstructured documents, web links that you're exposing the gen AI to. So Candy, any best practices or kind of tools or approaches that could help organizations, I guess, be more intentional with the data that they're actually using to train models and tailoring that to maybe specific role permission groups throughout the enterprise.
Speaker A: Well, so that's the good news, Mark. Right. This is like I keep saying, there's only so many ways you can lock down a computer or data. Right. I mean this has been around for a really, really long time. And I can, you know, stay in my sleep. And that's like looking at um, the access, right to the data. What is the data do, data classification, what is proprietary, which is pii, what is internal use only. You know, the old stuff that we've been doing for years and years and years now it matters. Before people are like, uh, there they go again, you know, doing the old, did you label that document? You know, you got to know how to handle it. And I can hear people rolling their eyes. But now it matters because now that classification and that, you know, labeling is associated to the metadata, right? And now the machine language, the MLS, the AIs are applying that automatically. So that's a good news. So you know, that's like step one is having a data classification schema, uh, for the organization and then from a tooling perspective of course. Right. Microsoft has Purview. If you've ever done a Purview implementation, you know, it's not uh, for the faint of heart. Takes a lot of tuning, a lot of tweaking. And there uh, is of course that whole other market or class of solutions out there. The data protection security uh, maturity tools. Right. The dspms. Right. And they are like incredible. They are so cool to help you through that. So it will help you put those parameters on both structured data and unstructured um, data. Think back to like the genesis of this technology was the DLP tools, the data loss prevention tools that would go and scan your environment, you know, look for certain classifications or schemas or whatnot. So the tools are there, but it just seems like everybody was in a rush. You know, it's kind of like rush to the moon. Everybody's looking to get in the rocket and go. And you got to figure out what's the rocket boosters look like? Let's make sure you're going to be safe and protecting the data and putting all those frameworks in place. Then you can get into the rocket or then you can implement the AI.
Speaker C: Yeah, well, I mean corner lines, we're a small, medium sized business and we're leveraging gen AI and LLM tools to increase, you know, the efficiency of new employee onboarding and just kind of edify our operational processes to be lean, competitive and productive, you know, with internal operations. I think there is a learning curve with training or dictating to the, you know, bots or virtual assistants that we use to complement our day to day activities to maybe treat data under a certain time horizon. You know, disregard this from your training data set after 60 days or you know, we sometimes we'll do, we'll upload kind of foundational documents that are, you know, handwritten by, you know, a Corner alliance team member to kind of bring that schema or kind of a prompting logic or a training data logic to the virtual assistant or the bot to kind of at least give an initial structure. Have you seen similar approaches used or are you primarily using some of the more sophisticated tools like a DLP tool to scan the data to inform kind of a data management scheme?
Speaker A: More the latter the more, you know, heavy duty tools I think. And thank you for mentioning that because that's something that really is important as well is the retention of the data within the model. And so uh, as you can tell, like my whole aspect of AI is it's all about the data. Data is the food that generates. Right. So yeah, I mean when we talk about AI security, absolutely. Gotta uh, keep those confines and have it operate as anticipated and expected. But in order for that to happen we gotta look at the data and the data quality, you know. Right. Like what goes in, if it's junk, it's going to come out junk or you know, we really need to think about again the data. So that means, you know, data quality from retention. Right. How long and what's the scope of the data? So yeah, it's something obviously I'm quite passionate about lately.
Speaker C: Yeah, well, no, and I would agree with you. I think in addition to the data for the work that you do, understanding how these tools operate and identifying a problem to solve or a purpose for the tool and scoping whatever sort of parameters or prompting instructions or datasets to kind of make that bot purpose built for the task at hand is a best practice that I've seen, I guess in terms of maybe some of the challenges or the inadequacies of the datasets that organizations use to feed LLMs. As you've seen them, what are some of the common pitfalls or struggles that organizations go through related to data quality or data management that you help them address?
Speaker A: So there's two sides of that, right? There's the public data and the public models, right? People are not even realizing it. I did the same thing, right? I just, you know, got into a popular, you know, tool perplexity and I was like, oh cool, I'm going to start working. Uh, and because I'm security minded, I downloaded to my Mac book and it's like, okay, I'm going to keep this baby right here. I forgot to go in and check. Well, of course I wanted to check what models I'm using, right? I don't, I want to stay away from R1 and you know, Deep Seek, which, that's a whole different topic. I also forgot to hit the button that says retention to local copy only. Right? So I mean there's that, that's huge and that's on any model that you're using and people forget to set those parameters. And so it always goes back to. Again when I said before, we've been doing this a long time, system configuration, AI configuration, right? So there's the public data problem and then when we look about the internal. So those folks that are ahead of the game and are going to, you know, stay within the parameters of their domain, if you will, their environment and their, you know, the boundaries, if you will. So there's that. But then you look at the data there. I mean whether it's for AI model training and use or it's for ERP or whatever, it's like it seems that data catalogs and data warehouses and whatever term you want to use, it's always a challenge and a problem to keep it current and keep it high quality. So, so that's where again in my opinion we tried too many times to solve problems with technology alone. And so therefore it really comes back to data governance. And I know a lot of people are like, oh, uh, that's huge, it's too big. It's, you know, like I just did a LinkedIn poll to find out where are folks on um, you know, implementing a data governance. A lot of people just do it on the structured data. A lot of people think it's not worth it. So you know, you go from one end spectrum to the other. Very few are doing it on the whole enterprise data unstructured and unstructured. So when we look at that problem, if we've had that problem with the ERP systems and we've had it with the data catalogs and what have you, it's only going to compound itself when you go to feed it into your AI LLM training modules. Right. Our uh, models. So really step back and think about the roles associated with the data through the data life cycle. Of late I've been getting into this whole thing and I've been drinking that medicine for the data fabric. Right? The whole concept and methodology of the data fabric. You know, no matter which way you look at it, you can pull a thread and see the data lineage. And when you think about it from a data catalog perspective, it's important. But it's also important from AI explainability perspective.
Speaker C: Yeah, well I would say one question on data governance is you've got the CISO perspective. You're obviously working with cybersecurity technical resources through your volunteer work that you described earlier. Are there specific roles that different individuals or roles within an organization, what can each class technical and non technical resource contribute to ensure organizations are developing a um, effective data governance policy that can scale responsible use of these tools within the enterprise, using proprietary information and interacting with public models in an appropriate way. I guess any kind of key contributions from both technical and non technical resources towards that data governance.
Speaker A: It has to be, it absolutely has to be. Because this is an age old problem too, right? Like why should it and security say what happens with certain types of data? We're truly in the data uh governance models, we are custodians of that. So we ensure things happen as you know, is described or needed for the data. You have the data owners, they are responsible for that data. They define what the data criticality is, what the data life is in regards to retention. Right, goes back to that. And so it starts with the data owner and then I have a very simple approach and there's like very formal data governance methodology. But the thing is I'm an advocate for taking those models and making it work in your environment. So like the way I implement it in really simple terms security and IT and even developers, we're custodians of that data. We make sure that we're the zookeepers, we, you know, feeding care for the data. Then you have the data owner and the data owner owns that data. They say what goes with that data and they have the authority over it. Um, then you also have, because data often travels through the organization like a thread through fabric data fabric. Then um, the data ownership may shift and change as it goes through the data life cycle. So you'll have multiple data owners to the context of its use, but then you have data consumers and each one of those roles, as you know, you described, whether it's technology or non tech, they have their own role to play, whether they have authority to say what happens with the data. Consumers consume the data, they want the data have integrity, quality, accuracy. And then we have, you know, simply put, the stewards such as IT and developers and all of them and we're the zookeepers. So that's a really simple way to do it. And it still provides almost like that racy model as to what happens with the data. And then you have somewhat, hopefully good data to feed into whatever you need to.
Speaker C: Yeah. So I mean it sounds like, you know, an effective data governance framework or plan process basically defines what our organization, who owns it, what is being done to the data as it supports decision making, insights throughout the organization. Is that fair to say?
Speaker A: Absolutely. And you know, just like security, just like anything, it really requires everybody's involvement. It really does.
Speaker C: Yeah. No, I think it's well said. So I want to go back to the idea of AI trustworthiness and AI explainability because there's a lot to unpack there. So I guess Candy, starting off, how would you define AI trustworthiness and does that differ from kind of the prevailing way in which it's defined throughout the industry today?
Speaker A: Yeah, I think it does. Uh, and we've, we've had in the first few meetings when we first started with the agendec AI, like huge discussions about trustworthiness versus safety and security, whatever. So I'll give you an example. So we were talking about again, agentic agents, right. And so again the concept is they're going to go off and they're going to work on their own, you know, autonomously. Right. I'm a security professional, so I have trust issues as it is. Right. So it's like, uh, how am I going to trust an agent to do something? I need to build that trust. And so then I don't know how it came out, but somebody goes, well, yeah, because like, then you gotta worry about like safety. And it's like, hold on a second, we went from like trusting an agent to go and you know, maybe do your travel plans and then the next thing you know it's driving you to the airport. I mean that's a huge leap. So you know, when you look at the difference, in my opinion is a great analogy would be like when the autonomous automobiles came out, came out, security, cybersecurity jumped right into that and we were concerned. We did not. We're all about making sure that there is no interference and that things are going to operate as expected.
Speaker C: Right.
Speaker A: Simply put. And so we wanted to ensure that autonomous automobiles, they were not able to be infiltrated, that hackers couldn't get in and take over controls and of course all those things. Right. But we cared about the perimeter of the car network. We just wanted to make sure it was protected. Protected as opposed to safe. Then of course things started happening with autonomous automobiles and the right regulatory body came in and took over the safety aspect and that's the ntsp. So that's the handoff in my opinion. So you know, when we talk about trustworthy AI, is this AI model, AI agent, is it acting to the level of trust versus risk in each organization is going to be different or instance use case of that, is it going to act as I expect? So that's where I come in. So it involves all kinds of things like data quality, it involves security of the model to make sure it's not poisoned and that it is unbiased and so on and so forth. So it's a lot unpacked.
Speaker C: I'm curious how candy you would go about one, evaluating the trustworthiness of AI agent within an organization and if it's below standard or non satisfactory, we need to improve trust. How do you go about fostering or improving organizational trust of AI assets that may or may not be up to standard today? Because if you think about it, I don't want to say it's easy, but you can with any sort of classical or AI model. You can run the model, evaluate the results and refine the model to improve the precision, repeatability, predictive value of what the model produces. But trustworthiness is less of a point estimate of unless you assign maybe a trust score or something than a predictive model output. So I'm curious to see how you might go about evaluating and iterating a model to improve trust.
Speaker A: So there's very well known models and I would take and apply those and put them into the development cycle of that AI system. You know, whether it was the LLM or generative or you know, the agentic, include that into the development cycle to make sure that it is acting as expected. Not really an easy answer or question mark to answer because we are on the forefront of that right now. Again, the agentic AI or autonomous AI working group. I'm on with the CSA right Now they're looking at those aspects and they don't want to get in too deep because it's so there's so many variables, right? It's kind of like saying what the risk is for fill in the blank. It's different for each organization. So it's coming up with like equivalent of a risk formula. What is the trust formula? You know. So to that point I've done research and I've looked at like IEEE and you know, a lot of these other organizations. There hasn't been any recent work in this area, especially in regards to AI, which is. I'm kind of surprised and shocked, but not so now that I've said that. Watch next week somebody will publish something.
Speaker C: It'll be great with our reach, our audience reach. I'm sure IEEE will have a few explore articles on the topic in a semester or two. Um, if I think about it, if I have a new hire or a new team member, I'm probably going to micromanage them a little bit at the beginning just to make sure. Are these individuals onboarding and producing like operating within the expectations of their role? Do they need additional support? And then you kind of back off after you build some trust and there's consistency in the output and that sort of thing. So it's not a um, scientifically rigorous answer, but maybe it is as simple as the organization needs to observe, monitor and kind of interact with an agent in a test, low stakes test environment before individuals feel comfortable, you know, delegating activities to that agent and certainly making decisions based on AI generated conclusions. I mean it could be as that.
Speaker A: I am so happy that you use the analogy of a human and I know this is terrible of us to do, but I do that as well with AI, like when I'm trying to think about some of the, you know, standards we need to put in place or safeguards whatever whatever. It's AI is an identity in your environment. It's another being, I hate to say, but it's close to being that now. So you using the analogy of a new employee is absolutely on target. So there's that. And that's analogous to again what I saw with this agentic, uh, work we're doing is like, well, I'm not going to just trust anybody to go in, do this function. I need to trust it first and how am I going to build that trust? And as I mentioned, research, there's a couple of good models out there, but you just need to have that as a factor because we look at legislation as well. Mark and we haven't even defined that from a legislative perspective either. You look at the state of California in their recent proposed legislation that was shot down about having it trustworthy or having a risk assessment performed on it before you released it. So I think it's evolving. And like I said, I'm hoping it's going to come soon because I'll be right on that bandwagon.
Speaker C: Yeah. And Candy, I'm curious, given that you touched on some of the legislation and we can unpack maybe why that legislation was shot down mandating certain risk controls before AI models are put into production use. But I mean, do you see, I mean, Corner alliance, we support a lot of federal programs and organizations looking to leverage LLMs for, you know, public sector use cases to improve the efficiency or operational impact of government operations. What do you see as an appropriate role for government programs or legislators defining, you know, requirements or best practices for the use of AI tools and models? I think there's a balance to be struck between providing clarity and not being overbearing or kind of like throttling down the pace of technical innovation and surrendering maybe a competitive, uh, leadership position the US Might have. I don't know. Any, any thoughts on that?
Speaker A: Yeah, I think that's what happened with California.
Speaker C: Right.
Speaker A: It was too overbearing. I loved it. However, I'm a security person, so it's like, um, of course I loved it, but it was very inhibitive to development of technology. So, okay, maybe it was a little overstepped, but I'm a huge fan of history and I think we have to look at history in this regard. Right. So you look at computer security and history and privacy forever and ever and ever. I started, believe it or not, try to think back, I think it was in the 80s when I started working in security, and we had like one computer fraud law, like from 1987, and that was it. And so trying to get businesses to pay attention to the need for security is like, yeah, yeah. Ah, yeah, no, it's not a priority. Well, then along came some other laws. The first one was, um, SB 1386 or something like that in California, right. Where you had to have an information security program and, you know, you had to do a bunch of stuff. And then followed by the state of Massachusetts with 201 CMR 17. Okay, so now everybody's sitting up, paying attention. We're going to do it. And then along came regulations or regulatory entities like pci, hipaa. Uh, so unfortunately, regulators and legislators have to be involved to put down the parameters and I think that is where we are with AI. So the question as you touched on, to what extent are those parameters going to be? That it's a delicate balance like everything else. But I fear that if we don't have those parameters in place that our social norms and cultural weirdness of our world is going to permit and allow a lot of bad things to happen. And so that's why again with privacy laws again, gdpr, ccpa, cpra, blah, blah, we need those bumper guards. And so I think, think a lot of people, the regulators and legislators are trying to get educated on this.
Speaker B: Yay.
Speaker A: And I think this is probably one of the magical things about the public private partnership that is successful. They've never done a lot of really good things unfortunately, because nobody trusted each other. But this part, they did do it right. So I'm um, hoping and praying that we get it right for the AI world.
Speaker C: Yeah, I would agree. I think that when I think of effective like policy or standards, you know, you had mentioned IEEE earlier, Corner Alliance. We've supported organizations in the standard space identifying areas that would improve the consistency, uh, or quality of AI goods and services across the industry that are maybe non competitive or not sources of competitive differentiation. I think of what is the width of a USB C charging cable. Like nobody's buying a Samsung, uh, Galaxy or um, iPhone based on that specification, I guess. So I think if there are some kind of best practices or core elements of standard ways to build or integrate AI tools with other systems or for certain use cases that might be helpful to specify without being too prescriptive or constraining on the development of new capabilities. So I'm with you there.
Speaker A: Yeah. Again I'm not a spokesperson, I'm just another, you know, practicing professional. But the Cloud Security alliance has done a phenomenal job in stepping into this space with the research papers. I believe it's still in draft, but they have AI controls, much like their Cloud matrix controls matrix at ccm they have the AI version of that. So to your point at least having these recognized standards bodies, IEEE is another owasp. OWASP is a great resource for anybody who's in, you know, the development space of AIs and LLMs. So thankful for that and grateful for those resources and really brilliant people.
Speaker C: Yeah. Well, and I'll maybe close with a few of your thoughts on, you know, broader trends impacting the use of AI and maybe what you're really excited to see. So when you look across different industries, regions, classes of LLM or gen AI use cases, are there Emerging trends or exciting developments that you think will be particularly impactful over the next, I don't even know, 12 to 24 months. I mean given the rate of technical innovation, maybe that's even too long of a time horizon to kind of look ahead towards. But kind of what do you see on the horizon as being particularly exciting in your field of study, you know, moving forward.
Speaker A: So from my view of the world, uh, so of course the agentic. Right, that's amazing. I don't know if you had seen they had agentic agents play Minecraft and um, it was like amazing. They actually had like one of the AI agents get lost and loss of the village and while other agents got them together and you know, did a search. It's amazing, right? So I'm thinking it's only going to become more so with the autonomous agents, agentic agents. It's going to be really scary for some of us that are not trusting. But I think in addition to that progression is going to be the cognitive AI. Right. That's going to be really, really scary. We talk about some of the things that are in uh, the beginning phases of development and it's so human, like it's terrifying. And then of course prior to that happening, I, or the adoption of that I think would be the natural language models. So you know, like right now, prompt engineering, you gotta really think about. I equate it to asking my daughter when she was little, being an ADHD child, being as specific as possible because she would find that loophole. But you didn't say that that's what we're at for profit engineering. Right. And so uh, the other natural language models will be really interesting and I think that will open up adoption to even more use cases. So we really are living in an unbelievable time in history. And I don't know about you, but I am like super excited.
Speaker C: Yeah, I'm with you 100%. And I guess on that note, given your experience and kind of understanding of how things may progress and what the priorities from an AI development standpoint look like, you know, do you have any advice to offer to maybe individuals entering the workforce or technologists, policymakers interacting with the AI innovation ecosystem? Yeah. What advice would you give them on uh, how to leverage these tools effectively and responsibly?
Speaker A: So the key word, right, responsibly. And to me I love AI, love it. However, it's all about the data. So don't think about AI without understanding the data. What's happening at uh, what data is it pulling? Is it of quality? So again, it's all about the data to me. And I fear we in technology are putting more emphasis on the models and that development as opposed to the data that's being consumed.
Speaker C: Great. Well, Candy, thanks for joining us. I guess where can listeners go to check out more of your work so
Speaker A: you can follow me on LinkedIn? I am happy to share my thoughts and opinions whether people agree. And if you don't agree, even better. I mean, love a good conversation and debate. As a matter of fact, I just started a new project myself with my daughter, Kailyn Sullivan. We have a podcast we just kicked off at the beginning of the month called Cybersecurity Refined and Feral. I'll let you take the guest as to who's refined and who's feral.
Speaker C: They got to listen to find out. No, that's great. Well, Candy Alexander, Chief Information Security Officer and Security Practice Leader at New Eon, thanks for joining us today. I hope we get to connect again sometime soon.
Speaker A: Great. Thank you so much. It was a lot of fun, Mark.
Speaker C: Absolutely. See you next time.
Speaker B: AI uh, Government and the Future is the Brought to you by Corner Alliance. To find out more about Corner alliance and how we work with government to create results, visit our website@, uh, corneralliance.com and then make sure to search for AI government future in Apple Podcasts, Spotify and Google Podcasts, or anywhere else podcasts are found. And click subscribe so you don't miss any future episodes. On behalf of the team here at Corner alliance, thanks for listening.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.