The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Finance/FinTech Australia's Podcast
FinTech Australia's Podcast artwork

Step Change in AI Models: Risks and Opportunities for Australian Fintechs with Reuben AI, Entersoft Security, and Raishio

FinTech Australia's Podcast · 2026-07-29 · 49 min

0:00--:--

The episode explores the practical implications of frontier AI models for Australian fintechs, particularly the shift toward AI agents capable of writing code, using tools, and automating complex workflows. Cat Lee addresses the dual challenge of leveraging AI's efficiency gains while maintaining compliance and human-in-the-loop safeguards - arguing that as models become more capable, domain expertise and careful review become increasingly critical. Ravi Tor from Entersoft Security highlights how AI is fundamentally changing the threat landscape: attackers now use agentic AI to automate reconnaissance and exploit vulnerabilities at speed (zero-day exploitation timelines have shrunk from months to days), while supply chain attacks targeting shared vendors like Salesforce and Canvas LMS can affect entire ecosystems. Both speakers emphasize the importance of foundational security practices, pragmatic risk acceptance rather than perfectionism, and continuous communication between technical teams and leadership. The conversation stresses that governance must evolve rapidly to keep pace with capability, and that businesses need to map product changes to existing workflows to avoid change fatigue while staying ahead of the curve.

Key takeaways

  • →AI acceleration in fintech requires a dual roadmap approach - short loops for bug fixes and hot fixes alongside long-term strategic planning - to manage both agility and direction.
  • →Supply chain attacks exploiting vulnerabilities in shared vendors (like Salesforce, Canvas LMS) can compromise hundreds of organizations simultaneously, making vendor security due diligence critical.
  • →Zero-day vulnerability exploitation timelines have compressed from months to days due to AI-enabled reconnaissance, requiring businesses to shift from patching everything to assessing and accepting context-specific risks.
  • →Successful AI product design in regulated industries balances powerful new capabilities with familiar workflows and UI patterns to prevent change fatigue and maintain user engagement.
  • →Governance and board-level AI literacy must evolve urgently, as current policy and control frameworks lag behind the pace of AI capability development.

Guests

Cat LeeRavi Tor

Topics in this episode

Frontier AI modelsZero-Day Vulnerabilitiessupply chain attacksAgentic AI agentsAI-native product developmentSalesforce security vulnerabilitiesCanvas LMS breachSoftware development lifecycle securityVulnerability remediation timelinesChange management in fintech

Questions this episode answers

What are supply chain attacks and how do they exploit AI?

Supply chain attacks target vulnerabilities in third-party software or hardware vendors that multiple organizations use - for example, the Canvas LMS breach affected nearly all universities globally through a single vulnerability, then scaled across hundreds of institutions. Attackers prefer this approach because one weakness in a shared product can compromise an entire ecosystem of customers.

How fast are zero-day vulnerabilities being exploited now?

The timeline for exploiting newly discovered vulnerabilities has compressed dramatically from approximately one month to just days. Once a vendor announces a vulnerability, attackers using AI can already be inside systems exploiting it in the wild, making rapid patching essential.

How should fintech companies manage the security risks of using AI tools internally?

Companies must implement proper security checks before adopting AI tools for business processes, code development, or data handling. Ravi emphasizes that security cannot block business operations - instead, organizations should understand each vulnerability's specific impact on their business, accept context-appropriate risk, and implement proportionate controls.

How can product teams manage change fatigue while shipping AI features rapidly?

Cat recommends balancing powerful underlying capabilities with familiar user interfaces and workflows that align with industry standards. Changes should feel slightly ahead of users' expectations - surprising them positively - rather than completely unfamiliar or so familiar they add no value.

Why do attackers now have an advantage over defenders in the AI era?

Attackers often access frontier AI models before defensive tools incorporate them, giving them a 1-2 step technological lead. They can scale attacks automatically to many targets simultaneously, forcing defenders into a reactive posture and requiring equally sophisticated AI-enabled defensive tools.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C43%
  • Speaker A36%
  • Speaker B19%
  • Speaker D3%

Most-used words

security31seeing22terms17perspective17models16attacks15change14ravi14attackers14businesses13product13model13australia12sure12space12software11

Episode notes

In this FinTech Australia Podcast, Katriona Lee (Founder of Reuben AI) and Ravi Toor (Consultant at Entersoft Security), moderated by Vinnie D'Alessandro (Founder of Raishio), discuss what increasingly capable AI models mean for Australian fintechs and the broader financial services sector. The episode explores how AI is changing product development, business operations and cybersecurity, including the growing use of agentic tools by businesses and threat actors. The discussion covers supply-chain risks, governance and vendor oversight, regulatory developments in Australia and overseas, and the importance of organisational resilience, workforce capability and human oversight. Tune in for practical perspectives on how Australian fintechs can harness the next generation of AI while managing the security, regulatory and operational challenges that come with it. This season of FinTech Australia podcast is sponsored by Vanta. Compliance regulations, third-party risk, and customer security demands are all growing - and changing - fast. Is your manual audit and compliance program actually slowing you down?

Full transcript

49 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: And welcome to the FinTech Australia podcast. I'm Vin D' Alessandro and, um, I'm here to take you through a step change in AI models, risks and opportunities for Australian fintechs. So I'd like to welcome our two podcast guests. So we've got Cat Lee from Ruben AI and we've got Ravi Tor from It's a Soft Security. So, Kat, Ravi, welcome to the podcast.

Speaker C: Thanks for having me.

Speaker B: Excellent. So it's really exciting time for the whole industry with regards to AI. We've seen some amazing change come over the last couple of years in terms of those frontier models and what capability they're bringing to the industry. But in particular since about December, January, we've seen a real step change in what those frontier models are, are delivering. They're moving beyond chatbots and delivering real complex capability, including the ability to write code, use tools, run your whole work environment. So we'd love to hear from both of you about what does this step change mean for fintechs in practical terms. And Kat, we might start with you, um, with Ruben AI.

Speaker A: Yeah, perfect. Look, I'm coming at it from the perspective of being a business owner, accountable for all the decisions a business is making. Right. As well as those of our customers is. And so with that in mind, you sort of. I'm probably battling two different fronts. With efficiency, I think, comes organic complacency and we start to rely on a new set of tools, capabilities, resources that are so powerful that we don't often remember to take a step back and go, wait, should we challenge it? Should we actually go and review that? I think Ravi probably has a really unique perspective on this as well. Um, so that's kind of that dimension of shipping and delivering faster than ever before. But at the same time we can't rest on our laurels. How do we think about our compliance capabilities, our review capabilities, um, having the right human in the loop capabilities, uh, whilst keeping pace with, I guess, the urgency and the pace of delivery. Um, the other side of it is that these AI models getting so creative, how do we make sure that we're setting those boundaries, those parameters, deliver great work and still be relevant? Right. At the end of the day, we are the domain experts in this space. We should be qualifying everything that goes in and comes out, but because they're so capable, sometimes it looks great and we forget to kind of dig a little bit deeper, um, and just say, wait a, wait a minute, I still have to go in and inject my perspective, my proprietary knowledge, the experience that I've gained from being in this market, in this space, in this sector for decades, however long it might be. Yeah. I'm really kind of quite fascinated by how we as humans, as leaders, as business owners, as operators are really going to be redefining ourselves, our roles relative to how technology is changing. But I do think there's going to be um, sort of a full circle moment where more than ever before we need our people to be sharper, more reliable, more focused. Yes. I'm really excited about this discussion.

Speaker B: Absolutely. And Ravi, in your space around security services, it must be a daunting challenge to go through and try and understand all these new capabilities that are coming out, both for you to use, but also to look to maybe even attack your customers.

Speaker C: Yeah, absolutely. And from a security perspective, um, we've been using AI in some way, shape or form, or what you would probably refer to as machine learning for almost a decade. And the way we do security and the uh, AI that we're seeing today that is so commercialized is just a whole nother game, uh, in terms of it's now opened up AI for, to everyone. So you don't need to be technical to really use it, um, which is fantastic. Right, because it's making everything so much easier. Making those kind of redundant tasks that people had to do. You can automate those so much easier now. So from that perspective it's fantastic. But you're absolutely right. From a security perspective it's causing a lot of headaches. Um, what we're seeing, seeing is companies really want to use AI and I think the adoption rate is really strong in Australia. But with them wanting to bring on AI tools for um, whether that be business processing or software development or just to help the business in general to sift through client data or documents and stuff like that, um, they're kind of forgetting the good security hygiene practices. And what we're seeing is that um, they bring in AI not doing the security checks. So you're getting all these different avenues for attackers to come in at the same time. Attackers are using this just like everyone else. They're making their jobs um, so much more efficient with AI. So no longer do they have to spend days and days trying to do reconnaissance on organizations and vulnerabilities out there. They can just send out agentic AI agents and that just kind of pings uh, an alert off when they found a vulnerability and they can automate the entire attack process to you know, um, where human in the loop doesn't really need to be there, um, until right at the end when they've got the data and then it needs to, you know, close it off. Um, so we're seeing a rapid shift when it comes to security and how businesses have to, you know, not just change but kind of uplift themselves, um, and make sure they're aware of all these attacks. The attacks that are happening are getting more unique. And the biggest shift I've seen is the time it takes from ah, a software vendor or a hardware vendor, um, releasing a uh, vulnerability to an attacker actually using um, it in the wild. So it used to be usually a month, then it's dropped down to a week and now it's only days. Right. So once a company says hey, we've got a vulnerability, uh, using AI, attackers already uh, there in your system using it. So it's been rapid.

Speaker B: And look when we look at it at Profenzo, uh, for our AI development, we've been able to take that security mindset and bring that into the software development lifecycle. So before we release code we're doing our own internal checks. Now one of the big things that we're starting to see is those um, like you said, those automated attacks, those zero day attacks, but also the supply chain attacks. Um, Ravi'd love to get your views and, or maybe even explain to the audience what, what are those supply chain attacks look like in terms of software development and open source software. And how can fintechs and other businesses protect themselves against that through their software development life cycle?

Speaker C: Yeah, absolutely. So supply chain attacks are simply um, the attackers are using software or hardware within your company, uh, supply chain. So any kind of third party, uh, vendors that you might have to look for exploits and ways into your system. The most recent and probably the one that's been in the news the most has been the LMS Canvas breach which is, you know, affected almost all universities globally. Um, and that was done through uh, you know, a product that all um, universities utilize. They found a vulnerability within that, you know, that organization software. And they were able to then branch out from that single organization to hundreds and hundreds of universities across the globe, effectively shutting down not just students access to their content, but also the university's access to their materials. Um, and we're seeing that across all industries, not just uh, education, but especially fintech, um, where we're seeing uh, all kind of organizations are using similar product sets and those product sets aren't really being vetted as they should be from a cybersecurity perspective or we're taking um, the vendor's uh, word, uh, at Mouth in terms of, hey, if the vendor says they're secured, they must be secure and we're all good. Um, and what usually turns out to be the case is that those vendors haven't done their due diligence and you know, it's just a, you know, uh, you know, a chain attack. It just takes one, one weakness in that chain to cripple the entire ecosystem. Um, so, so that's probably, you know again one of the, you know, I think uh, main vectors that attackers are now using. Rather than going out to individual organizations and trying to compromise each individual organization, they're trying to find those suppliers or vendors which reach out to the most organizations. And I think one of the, you know, Salesforce, if a company is using that right now, that's been one of the biggest targets at the moment for attackers is um, you know, a few vulnerabilities were found which you know, Salesforce didn't think may have been as significant but then they were used to, you know, get into other organizations more rapidly than uh, what's been seen in the past.

Speaker B: Excellent. And thanks Ravi for that. It's definitely a fast moving environment. So we're glad we've got people like you in the community helping us out. Um, Pat, I'd love to get your thoughts on. First of all, maybe just describe a little bit of how you're using uh, AI within Ruben, AI your business, maybe talk about what your platforms look like, how you utilize it in the software development, product development space, but also using AI as part of your product. Um, you know, that's a growing capability that we're starting to see in fintechs we've seen recently. Cobble, ah released their AI builder for their financial products. Uh, it's heavily embedded in Ruben. We'd love to hear what that journey's um, been like for you and your team.

Speaker A: Yeah, I mean the term AI native is sort of a little bit overblown, isn't it? Now it's almost like the right to exist, you need to be AI enabled at the very least. And many of the new entrants of course are built on brand new technology. We're sort of testing and refining um, smaller models, off frontier models, trying to figure out how we harness the power of generic models into specific use cases. So the three key things on my mind is the lack of, I guess non linearity of product roadmaps. Now we can do so many things at the same time and parallel a lot of different parts of our roadmap which we previously couldn't do. The second is modularity and I think that's increasingly important to kind of take a more widget based approach to how we solve for problems to reduce the risk of cross contamination if something goes wrong, particularly in highly regulated industries. Right. Um, and then the third part I think is a new kind of protocol for defining how we ship. Previously we were agile enough of worshipping and on a fortnightly basis. Now we're doing it every couple of hours. And what does downtime really mean? What are people's buying expectations? What are uptime expectations? So all of those things have coalesced in a new kind of business model from a pricing perspective, how we go to market, how we talk about our business and sell, um, and what I guess the possibility of that looks like. It's really easy to then start to build lots of little niche products and get unfocused on what your core roadmap, ah, what your core proposition is. So uh, Vinny, I think there's so many different ways to answer that question. I would say first and foremost building an AI, ah, native business today is all about making sure that firstly you're building a fantastic foundation. Because Robbie, as you pointed out, there are so many layers where you can get exposure to so much risk. And because AI is still so nascent, policies are sort of catching up to how quickly we're building. All of these different cases are so creative that we really need to be um, kind of front of mind when we think about what all of the different ways it could be that our technology can be exploited and try to kind of bring that forward and be proactive about it so that we don't run the risk of things going wrong. So the way we're thinking about business building, the way we're thinking about running up, um, our kind of roadmaps is sort of, you know, very much having to be reverse engineering rather than building forward. So what I found uh, most recently is actually around two roadmaps. I have like a short loop and a long loop. The short loop is our ability to make sure that in our operating cadence we have plenty of opportunity to um, address bugs, push hot fixes. We have those, you know, real kind of ability to be very, very agile to the next level whilst having a longer term view of well, where do we want to be in a quarter from now, two quarters from now, 18 months out and working backwards from there. So having that both with the same size team is now possible, which is, you know, which is really cool. So I would say it's a privilege to be building a business in this time. I think, you know, I don't know entrepreneurs even just five years before us, I think they'd probably be very jealous of capabilities and technologies and um, the warp speed at which we can deliver now. But at the same time it's created a whole new universe of challenges that we couldn't have predicted. And so yeah, I'm excited and also nervous. Ah, that's why I guess these associations and these conversations are so important because we need to learn from each other. Right? We can kind of go, well this is a use case I hadn't seen before. Let's go educate our peers who are building in fin services as to what that means, um, from a set of implications perspective.

Speaker B: So yeah, look, that's awesome and I'm definitely going to seal your short loop and long loop. Um, I think that's something we've been doing. I don't think we've articulated it as well as that. But just on that I just want to sort of dive in around you talk about there's a lot of changes that you're delivering both internally and for your customers. Um, with that rate of change you can see change fatigue. We saw it with some of our customers. We did a huge range of bug fixes and releases over the last couple of weeks and had a few complaints of, hey, there's a lot going on. Um, you know, how do, how do we keep on top of it as product providers? Uh, and how do we make sure that our customers are getting the fixes they need but they don't feel overwhelmed? Overwhelmed by the change that's coming on top?

Speaker A: Yeah, look, I think there's no perfect science to it just yet. Um, but the way I look at it is there are, I think, um, you know, if we look back at over the last decade, there are these sort of universally, uh, accepted ways of doing business in certain industries. So for example, in the finance world for investment bankers, spreadsheets was king. Right. And so pretty much every finance professional that came through the ranks know how to operate a spreadsheet. So how we're dealing with change fatigue and that kind of, you know, uncanny valley, um, so that's like at the ends of the spectrum, right? What we've realized is there has to be a little bit of comfort so that users feel like they're in control. If something is too far fetched, the change journey or the learning curve is too significant, you will never get engagement. But if, if it's something that's just as manual and painful as it Was then what's the point of it? So that fine balance is basically from a UI perspective. And the look and feel has to feel a little bit like something that they know. But the uh, capabilities are powerful underneath. So that's the kind of magic I realized is that right next point between, okay, so it is significantly faster. I feel like there's a lot of that, you know, real time analysis that we can now get access to. But the way we do it has to be aligned with the way our business actually runs and how the industry is still accepting as a kind of standard operating procedure. Luckily for Ruben, we're operating in the asset management space and so doing a transaction is pretty much almost standardized. There's no real like framework per se, but origination. You know, you're doing your triage and screening, you're doing your due diligence, you're running investment committees. That's pretty much, much accepted process. You know, all fund managers, all asset managers or investment professionals have their own nuances and takes on it. But by and large that framework is pretty consistent across the whole industry. So we map our product, uh, to how people actually work and then we leverage the look and feel of tools that they are familiar with so that every time we do ship and improvement they kind of go, oh, I was hoping that was going to happen, or that was a nice surprise, as opposed to, I have no idea what's going on. And you know, the thing is just building itself in front of me, you kind of lose the audience. So that's what I found is like just a little bit ahead of the curve, but not so far ahead of the curve that they kind of go, ah, uh, you've lost me.

Speaker B: Yeah, yeah, understood. And Ravi, just in terms of, no doubt you and your team are feeling that, that same rate of change, that cadence that's coming out with zero day issues. How are you and your team dealing with that and how do you take your customers on that journey as well?

Speaker C: Yeah, um, I think Kat summed it up really well. Is that um, very similar in that we've got these established processes in security as well in terms of um, those processes haven't fundamentally changed in terms of how businesses should uh, mitigate risks around uh, AI security or how we as the defenders would um, respond to any, uh, kind of AI enabled attack. Um, what AI has done is, you know, made some of those uh, processes a bit more streamlined. You know, as Kat said, um, you know, small, small changes over time is, is kind of what we've been seeing in, in our Tools, um, and, and what we're seeing and, and the frustrating thing, uh, working in, in cyber especially is that at the, you know, where the defenders are probably a little bit ahead, uh, behind the curve than the attackers. The attackers are usually the ones that have a few more resources that they really want. Um, the more frontier AI models, where those models may not have come into our products just yet or our defense, ah, mechanisms. Um, uh, so there's this constant battle between attackers and defenders where they're probably using technology, um, that's one, two steps ahead of us. And then we're having to be a bit more reactive in terms of, all right, cool, there's a new attack today, it's probably going to be another new attack tomorrow. How do we actually counter that? And again, it just has to go back to, back to basics. As long as we've got what we tell customers, as long as you've got the right security in place, those fundamental securities in place. Majority of the attacks are really just trying to automate, um, those attacks that we've been seeing for years. It's just doing it at a scale and a pace that AI is just making almost impossible, uh, to keep up with unless you're also using A.I. uh, so it's just this constant battle of trying to figure out what the attackers are, ah, doing and trying to predict what their next move is and just having this constant battle. And yeah, like, it's a lot of the same stuff is happening. It's just how they're doing it, how they're embedding their AI attacks into, uh, you know, business, uh, processes and all that kind of stuff. It's just you kind of sit there and go, oh, that is really smart. Why didn't I think of that? Uh, you know, that is just so obvious, um, that you would have, you know, used this mechanism to get through. And it's usually, you know, that lack of security that is letting some of those attacks through. But it's not always the case. Some of these attacks can be quite sophisticated and it's just, um, you know, it's just kind of every day is a battle at the moment. And uh, you have to kind of, you know, be ready and be prepared for as much as we can. But we're never going to be 100% right. Nothing is 100% secure. So there's always going to be, uh, you know, risks, uh, or mitigations or vulnerabilities that, you know, need to be there, need to be studied. And you, as a business, you know, you don't need to go and patch everything or, you know, fix all the, all the, um, you know, all your code. If there's a software vulnerability in your code, it's more. So as a business, business, what I say is you just need to understand what that vulnerability means to you and your business and what does it mean to the customers in terms of if that gets exploited in some way, shape or form, is that going to be a significant impact to your customers and are you willing to effectively accept the risk? And most of the times they say no, but we would be, we're able to do, uh, containerize it or block it down a bit more before we release it. So it's just having those conversations and I never, I think a lot of security professionals make the mistake of going, no, you actually have to completely get rid of it for it to be secure. Um, whereas our approach is really nothing is ever going to be that 100% secure and you just need to take it. Um, security cannot block operation of a business. Fundamentally, security needs to work with the business and we need to make sure that businesses are progressing. Um, how do we do that in this new AI age? It's a bit more difficult, but I think it's a journey that, um, we're all on, on, on both sides.

Speaker B: Yeah, look, um, I, I think the termin terminology is around. Look, there's going to be an attack. It's, it's a when, not an if, um, and just for people to be responsive. And I, I really did like your sort of pragmatic approach, which is like, find out what's right for your business and then have that right response to it, um, which I think is really important.

Speaker D: You're listening to the FinTech Australia podcast. This season is sponsored by Vanta. Vanta is the leading trust management platform helping fintech businesses get compliant fast for frameworks like CPS234, SoC2, ISO 27001 and more. Vanta's AI and automation power everything from evidence collection and continuous monitoring to security reviews and vendor risk, whether you're starting up or scaling.

Speaker B: And look, both of you have mentioned the foundations of business and so I think that's a really good segue into talking about governance. I think, um, what I've started to see being on the board of FinTech Australia and around other boards and executives, is a real movement around how quickly governance needs to get across the opportunities, but also the risks that come with AI. Um, and we're starting to see at least a movement around how do we get the um, executives and board members skilled up on AI. So I'd love to get your perspectives on what are some of the learnings you've had in your roles and what would you like to pass on to those executives, to those board members, to, for them to think about governance and what it looks like in this new space?

Speaker A: Yeah, maybe I'll take a first dive at this. Um, you know, we're sort of at a, kind of a really interesting timing space right now where we're at the intersection where the technology is outstripping our, uh, capability around developing protocols to control it and manage it. And at the same time, just like the big Internet wave, we're at the next cusp. You know, people talked about Web3, but that sort of acceptance of that versus where we are with AI is almost a whole other level. And so I think that big step changes come with it, a massive cultural shift. And my thinking around this and uh, perspective really is boards and leadership teams need to be thinking about this as a whole of business culture. Reimplementation is sort of going, okay, we are in unprecedented times. How do we think about who we are as business leaders, operators, pioneers in many, many categories of new ways of doing business, new ways of understanding our customers, new access to data and the ability to transact. So it's a very, kind of really exciting, really cool time. But it is our, um, responsibility as this generation of leadership teams to shepherd in better culture. And so the word that I have in my mind is resilience. I have, you know, in the past, big companies. One of my strategic advisors actually, um, had shared with me, as I'm thinking about the culture of Rubin, um, and what we're going to be as sort of like, you know, I said a unified, um, ecosystem against community. Uh, I was reflecting back on intel, for example, their, their kind of culture and the language they used. Nowhere is there, you know, um, things around resilience, around learning from your mistakes, learning about, you know, embracing ambiguity and going, okay, we have absolutely no idea what to do because things are moving so quickly. But actually, fundamentally, as a business, the DNA needs to be. We keep trying, we keep learning. We can't have the big ego of knowing exactly what to do. But we as a, uh, as a group, as an entity needs to, need to be able to think about disaster recovery, think about contingencies, think about, you know, like, strategy in a much more dynamic way. So, yeah, I really think this is an opportunity for us to be better leaders, to kind of think outside of the box a little bit. And think about culture and the types of talent we want to be bringing on board, how we're coaching and training the next generation of operators in our businesses to embrace. Because the rate of change and the waves of new technology is just shortening. Those cycles are kind of closer together now. Right. So how do we make sure that no one gets left out, that inclusivity is not just about where you're from, your background, your educational kind of context, but also, you know, making sure we're taking everybody on the journey because otherwise the gap between those that are in the know and those that aren't would just get seismic. And I think that could break our society. So that's something that's been really on my mind, a bit philosophical, but also, you know, from an on the ground perspective, how do we close the gap that.

Speaker B: Yeah, look, we've definitely seen a similar thing in our space where the businesses that are struggling to bring on AI, um, they haven't had that experimental mindset. It has been big waterfall projects that have known outcomes and any deviation from that path is challenging for businesses like that. So being able to deal with that ambiguity, which I think is a great word, that AI can bring you where you need to experiment, things aren't always going to work perfectly and then being able to acknowledge, accept that and then deal with those issues as they arise and opportunities. So Ravi, love to get your thoughts around governance as well in this space.

Speaker C: Yeah, absolutely. I think Kat used a perfect word, resilience. Um, and I think that's what we tell boards all the time is, uh, a lot of companies that we're seeing are, ah, over reliant on certifications or certificates like ISO or SOC2. Um, is very popular at the moment and basically say, hey, we're compliant, ah, therefore we're good. Right. Um, and really at the end of the day it's been asking the boards, do you think your business is resilient? And going back to what I was saying earlier, it's not about, uh, if you're going to get attacked, it's when you're going to get attacked. Is your business going to be resilient enough to be able to deal with whatever attack there might be. It might be a very small incident, it might be a very large incident that affects, um, your customer base. And really it's that resilience that we try to push on not just the business and its people, but also its systems. So uh, what we talk about when we go and talk cyber is, are your systems resilient? So, um, if There was an attack that occurred. Uh, are you confident as an organization that your systems would be able to still operate, your business would still be able to operate under duress? Um, and a lot of the things that we hear back is well actually no, we never actually thought about security like that. We thought, thought about security, um, you know, that you know, if we got this certification or we got this compliance m, um then you know, that kind of, you know, we thought that that would mean that we're resilient. But you know, and I think that uh, shift in mindset is really important. Uh, I think uh, ASIC last month released a letter to um, to the, you know, the industry as a whole. And they said some really good things in there around kind of what the questions to ask the board and leadership within organizations. And one of the key things that they flagged during that was um, the over reliance. We're talking about supply chain before, but the over reliance on um, vendor presentations without the companies or the organizations genuinely examining uh, those products before they actually implemented. And what Kat was saying before about business need to be innovative, they need to take that step and get these new products. But then that also comes with the cybersecurity risk of well, are you sure that this product that you're now implementing, uh, to get that um, edge in the market is actually uh, something that's not going to compromise your business? And you never really or truly know the answer to that. Um, but what um, ASIC and also APRA have kind of flagged was that um, a lot of entities across, especially fintech and finance in general, um, that they're putting uh, they're concentrating all their kind of uh, you know, business into a single AI product or a single AI model, um, rather than actually diversifying it. So what that means is that uh, you know, if something was to happen, it's ultimately a single source of failure, right? Is if that model gets compromised or if something happens with that model, then the entire business, you know, kind of falls down because that's of that um, over Reliance. Um, and a lot of organizations didn't actually know what AI they were using. So there's no uh, asset inventory. Uh, so basically uh, what we're finding at Entersoft a uh lot is we'll get alerts that says X user over here used an unapproved AI model or LL model to do coding or something. And then we ask the organization, they go wait, that's not approved. Why are they using that? And when they go in and uh, investigate it like oh yeah, We've somehow given access to that model and this developer or this user has found that model on the Internet and has just started using it without really taking that um, you know, uh, step to go. Wait, stop. Is this actually the right thing to do? And again, that just becomes an education. Thing is, I don't think people truly understand the security implications of AI. Ah, they see it as that um, assistant that helps them do their work. And it absolutely is that. But um, I think we need to do more in terms of, of an industry, in terms of uh, in this space to actually educate um, everyone on the risks of using AI, just like um, the risks of using any software. I, um, think that's just not well understood at the moment at all. Um, but just to close that off, um, yeah, it's resilience at the end of the day and just making sure the boards are actually really across their systems, across the effectiveness of the security controls they have in place right now, and making sure that they really understand, um, from an operational sense how that business would deal with um, various cyber attacks, AI or otherwise.

Speaker B: Absolutely. And it is bringing some new challenges to boards and executives around. How do they deal with some changing or evolving issues that didn't exist maybe six months ago. So you talked about that leakage where people are using unapproved, uh, AI models. Also, if we looked at what happened recently with Anthropic and Fable and Mythos, where the US Federal government put a ban on it and suddenly those services were taken offline, those impacts hadn't really been felt by businesses before or maybe not seen at scale. And so I think businesses are now doing, um, what we're seeing in market is they're starting to do those audits around. First of all, where's my data going? They care about data sovereignty and hopefully on shoring that data. But also that model mobility is, have we built everything into one model? Is that frontier model going to be around tomorrow? Are they going to change it fundamentally and then our products don't work and then how do I move to a different model for capability or maybe even cost or security perspectives? That's not a problem they've had to solve previously. You sort of pick a platform and you stick with it. Um, but now they've got that sort of different challenge that they've got to look at. Um, and that's what um, this evolving AI challenges has brought to the industry. So look, I want to talk maybe about, um, what do we see happening with the regulators? Um, like you spoke about ASIC, we talked about certifications like SOC2, ISO 27001, the great foundations to have. But maybe they're not moving at the right pace that they need to. Ravi, ah might start with you just quickly thoughts around are you seeing moving from the regulators? Are they starting to understand the challenge?

Speaker C: Yeah I think so. I think um in Australia especially uh our financial regulators have actually been on the front foot this time which is great to um. I believe APRA released or updated their prudential standard. Uh I think it's CPS 230 around um requiring anyone as an APRA regulated entity to now um basically outline if they are using AI, how they're using it and exactly what you said um and we're seeing those regulators really focus in on AI, ASIC releasing a letter and um, the incident uh that happened with fake security investments uh earlier this year here in terms of you know um, basically actually now taking uh companies to account to say you know you're definitely not doing a ah you know good enough job and now you you know actually finding them and actually you know standing up and actually um executing on, on you know kind of their um you know standards or frameworks. It's great to see because I don't think we do that enough in Australia. Whereas you look at uh, you know across the seas and in the uk, Europe and even in America they have a lot more regulation around, around customer data or data breaches. Um we put a really good principles based framework but again um um uh there's no real uh impact to businesses in terms of financial penalties or anything if customer ah data gets exposed um as there are compared to uh people overseas. I think with standards like ISO 27001 or any kind of cyber security standard, those standards definitely aren't moving um at a pace but they definitely are kind of moving. The fundamental thing about something like ISO is that it's not a be um all end all kind of framework. It's really only to be used for a company to really establish a management system to how are we going to manage cybersecurity within an organization. And I think it does a great job at that. But I think again like I was saying people use that as kind of the coverage and again um, what we're seeing from a cyber insurance perspective, which is a really interesting shift over the last couple of years is that most cyber insurers actually don't consider ISO 27001 um in their um you know if someone was to claim a breach um and they said well we had ISO 27001. Most of the cyber security insurance providers say that's not good enough. We want to actually want to see you know, what you're doing. We actually want evidence and proof that you know, what you're, what you've said you're doing is actually what's been done and you're actually effectively mitigating those um, or you know actually effectively implementing those technical controls that you said you are um, and they want that proof. And that's what we're seeing a lot now. Um, within Australia I think we can definitely do better but I think we're definitely on the right pathway.

Speaker B: Fantastic. And Kat, um, as a um, product provider in a heavily regulated space, um, what does that mean for your team and your business as you start to develop and release these products into marketing market. Oh, sorry Kat.

Speaker A: Yeah, Besides uh, you know, putting our arms around this Alphabet soup, you know, acronyms of things that we need to care about. Right. From GDPR to DORA to you know, whatever besides that. And really like Ravi said, it's not just those high level frameworks and cadences of reviews is much more the last mile. I think that's where regulators are heading. We're seeing much more of um, the matrix of okay, we now have this big headline AI piece of legislation say in the eu. We have the EU AI act for example as a big governing kind of framework and then individual um, markets, individual jurisdictions are then thinking about how that impacts them on a market level but also at the sector level. So we're going to start to see much more specific, I think um, behavior, behavioral sort of ah, changes that uh, will have to come as a result of embedding you know, high level generic AI protocols into very niche verticals. So I'm sure that that's going to be massively governed particularly in the medical bio spaces. Fin services, FinTech will probably be the next cascade. Right, because you're dealing with people's money, you're dealing with very kind of sensitive decisions. So that's what I'm anticipating is that we're kind of, of will go past the um, you know, middle ground of oh, let's have a bunch of consultations, let's you know, think about what people kind of want and get inputs from leaders, business leaders. Of course that's going to happen but it's going to come down hard specifically on what it means not just reactively to how you going to respond at the you know, audit level, but much more from a sample perspective. I think we're going to See much more real time on the ground operating lens of how we're complying. And there's going to be much more of that in the past where you have like spot checks, people coming in, mystery shopping. I feel like a lot more of that type of governance, you know, securitization, um, is going to come through. Just because AI has such a transcendent sort of capability is changing every aspect of how we're operating, communicating that just, yeah, the old ways of doing legislation, you know, governing from a distance, I don't think will really work anymore. So that's what I'm expecting. It's going to be much more niche, much more focused and these pieces of legislation are going to be led by the practitioners in each of those kind of quite, quite a bit more discrete um, verticals, I'd say. Yeah.

Speaker B: Awesome. And look, um, would love to get your thoughts, um, just to round out the conversation around what does the next 12 to 18 months look like? I know we've had a pretty disrupted last 18 months and I, uh, know myself, I'm struggling to think, well, what's going to happen next month, let alone 6 12, 18 months into the future. But maybe if you can look at it from a perspective of we've got this new evolving AI capability, how do fintechs in Australia, uh, start to leverage this even more and what does that adoption look like for businesses moving into the future? So Ravi, we might kick off with you.

Speaker C: Yeah, I think, um, just in general, I think what we're seeing is, or what we'll see in the next 18 months, um, from an AI perspective is that we'll see a lot more models on the market. Um, what I'm seeing, uh, especially in kind of using cybersecurity tools is that a lot of the open source models now that people can now host themselves on their own infrastructure architecture, are actually becoming very capable and almost to the same level as, you know, your anthropics or your uh, chat GPT type models. Um, so I think we're going to be seeing a lot more companies, uh, not just utilizing uh, AI models, um, from these major companies, but then standing up their own and doing very specific tasks with them. And I think that is absolutely the right approach. And I think a lot of security vendors are going down that path as well. Yes, a lot of security vendors are integrating um, large LLMs, anthropic and chatgpt or OpenAI, um, models into their products. But um, yeah, a lot are uh, actually now really focusing on that niche aspect of certain issues and trying to solve those with more specialized AI tools. I think, um, again, from just a business perspective of the 18 months, I think it's just going to be that, trying to get out there that really at the end of the day comes down to, to basic security hygiene that really needs to be implemented across the business. And as long as you've got that strong foundation of cybersecurity, majority, um, of what we're seeing, majority of what we are predicting in the next 18 months, I think you'll have quite a good chance to be resilient against that. Uh, unfortunately, on the more dark side of cyber and uh, the attackers or the uh, advanced persistent threats, what we're seeing is that they're just getting more and more creative with how they use AI. AI and the turnaround times between vulnerabilities being, um, exposed or made public to them actually being exploited is significantly decreasing. Ah. And I think over the next 18 months we'll go from, um, a day or two turnaround times to a few hours if not minutes is the prediction. So again, it's just getting faster and faster and faster in terms of, um, the attackers getting out there, getting into your systems and then, then from a defense side. Yeah, just us having to respond and be a bit more vigilant in how attackers are using it. Uh, I think in terms of how the attacks are occurring and um, the types of attacks that are being utilized against businesses, I think that will kind of, it seems to be plateauing a little bit in terms of, I think people have kind of found out, um, what works, what doesn't work. But at the same time it only just takes one product to come into the market to know, prevent that and then they'll find another way around that. So, um, it's kind of impossible to say, you know, if things will change, but I think, um, kind of AI is just becoming an everyday, uh, thing. It's embedded into almost every product that you use. And so, um, you know, um, I think that shift of, you know, it's not so much how can AI replace humans. I think we're actually going the reverse. And a lot of companies are now going, oh, well, we actually try to replace human beings with AI. That hasn't really worked. So we're now going the other way. So I think we're going to see that shift across the board, especially in cybersecurity and going how can we. I think people are starting to realize that AI is a tool that um, it only makes, you know, people more, you know, powerful and more diligent and more useful if you give them the right tools, um, with, with the right setup and, and you know, it just makes things so much more efficient. So. Yeah, look, I uh, think, think uh, it's really unknown what's happening in the 18 months but uh, those are my predictions.

Speaker B: Sounds great. Um, looking forward to having those AI superpowers for our teams. And Kat, over to you. Your thoughts on the next 18 months?

Speaker A: Yeah, I'll probably zoom out a little bit and look at it from a market lens. Um, so we're sort of in this groundswell of significant individual and retail uptake of AI at the moment. We're all using multiple maybe AI tools at any given time to do our individual task based work. Um, so I'm thinking over the next 18 months there's much more of a top down adoption of those that organizations that are going to be actually embedding those into the fabric of that culture we talked about. And as a result we're probably going to see a significant resizing of talent mapping, organizational structures, operating model redesign, a lot of that type of language and a lot of type of investment in thinking about how do we, like Ravi said, complement human talent with artificial talent to kind of go, okay, there has to be the right balance of check and balance first of all, but also the right level of efficiency versus relationship. Because at the end of the day, particularly in an economy like Australia, we're very relational driven. Right. Like at the end of the day there's a finite amount of enjoyment that we have talking to our screens. It really would be really nice to have much more of that social aspect of doing business. And so yeah, I think there's a tipping point like you predicted. Um, Ravi, I think there's going to be um, bit more of an uprising I think from an uptake of AI and then it may plateau down where people go, okay, the excitement, you know, the novelty of these models not wearing off, they're still amazing and incredible. But our understanding of what it means to make them useful looks different. So, so I'm excited about that. Starting to bed down a little bit for us to feel, um, like we can coexist in such an effective way. But it also doesn't feel isolating, it doesn't feel too distant from how we used to do business. Um, so I'm excited to see how that comes out. And of course we talked about the legislations and the governance and those frameworks. I think there'll be a bit more maturity, uh, around that. So a conversation we will be having in 18 months time we'll be much more educated around real world examples of how we're executing within better, tighter frameworks. And I think that's good for business, it's good for safety. People can feel more assured that their data is protected, that there are more of those layers of defense in place. Um, but yeah, excited to see how creatively people exploiting at this moment in time, time where there's, you know, still a little bit more space to do that kind of stuff and if sufficiently motivated and why attackers are probably ahead of the curve is they've got more to gain. So yeah, I'm um, really stoked. This is a really great conversation, Minnie.

Speaker B: Look, and it was great to hear from both of you around that melding of people and AI together and not sort of keeping them bucketed apart. So, um, it's really important. I think we've all talked about that human in the loop being so critical for getting the most out of AI. So looking forward to see how that changes over the next 18 months. So, Ravi, um, thank you so much. Kat. Thank you as well for your insights and uh, thanks everyone for listening to FinTech Australia's podcast. We'll talk to you soon.

Speaker D: Thank you for tuning in for this episode of the FinTech Australia podcast. This season is sponsored by Vanta. Compliance regulations, third party risk and customer security demands are all growing and changing fast. Is your manual audit and compliance program actually slowing you down? If you're thinking there must be something more efficient than spreadsheets, screenshots and all manual processes, you're right. Audits and compliance can be so much easier while strengthening your security posture and actually driving revenue for your business. Vanta's Trust Management Plan platform automates key areas of your certification program, including compliance, internal and third party risk and customer trust, and streamlines the way you gather and manage information. And the impact is real. The recent IDC analysis found that compliance teams using Vanta are 129% more productive, so you get more time and energy to focus on strengthening your security posture and protecting your business. VANTA Continuous compliance How much easier trust can be? Go to vanta.comfintech Australia podcast to get started.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Lay of the Land: How Attackers Move in '26mnemonic security podcast · on supply chain attacks94 / 100
  • Built Fast, Broken Faster: MCP & AI App Security - with GitGuardian’s Gaetan FerryCyber Sentries: AI Insight to Cloud Security · on supply chain attacks94 / 100
  • #192 - Slowing Things Down to Speed Up Research with Jared Forney of OktaAwkward Silences · on AI-native product development90 / 100
  • Weathering the AI Vulnerability Storm with Gadi Evron, Rob Lee and Ed SkoudisCyber Leaders · on Zero-Day Vulnerabilities89 / 100
  • Everybody Wants AI. Who's Paying for It?AI Proving Ground Podcast · on Frontier AI models85 / 100
  • Code War with Allie MellenAfternoon Cyber Tea with Ann Johnson · on supply chain attacks85 / 100

More from FinTech Australia's Podcast

All episodes →
  • The Future of Account-to-Account Payments in Australia with Nium, Azupay, and Gadens72 / 100
  • CDR Momentum & Myths - A conversation on open banking with SISS Data Services, Intuit, and Wych69 / 100
  • Rethinking Payments: Square and Waave on Competition, Cost, and Choice62 / 100
  • Unlocking Digital Assets: Fireside Chat with OKX Australia’s CEO, Kate Cooper, and Build GM & Director of Sales, Dean Martin78 / 100
  • Surcharging and Reforms to the Payments Systems - Special Episode with Mastercard, Zeller and Capital Brief
Explore the best B2B Finance podcasts →
All FinTech Australia's Podcast episodes →