The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/Paradigm Shock
Paradigm Shock artwork

The Artisan Approach to AI Governance with Karl Herbert Grabbi from Credo AI

Paradigm Shock · 2026-07-28 · 42 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density13 / 20
Originality11 / 20
Guest Caliber14 / 20
Specificity & Evidence10 / 20
Conversational Craft12 / 20

Karl Herbert Grabbi argues that effective AI governance must be grounded in humanistic values and principles rather than purely technical frameworks or regulatory compliance. At Credo AI, he and his team help enterprises build trustworthy AI systems by starting with core principles - exploring why systems are being built, for whom, and how they connect to organizational missions. This philosophy-first approach contrasts sharply with the early AI governance discourse dominated by lawyers and regulators focused on compliance. Grabbi notes a significant shift emerging in 2026: security teams (CISOs) are increasingly taking leadership roles in AI governance, spearheading agent governance efforts alongside legal teams. The conversation covers how risk frameworks differ between frontier labs (managing tail catastrophic risks) and enterprises (managing immediate operational risks), and introduces the concept of harness engineering - building governance controls around agents that take autonomous actions. Grabbi emphasizes that as agentic AI proliferates, governance must move from post-deployment audit trails to real-time runtime monitoring and enforcement. The discussion bridges theoretical risk frameworks from frontier AI safety research with practical compliance needs in healthcare, banking, insurance and government deployment.

Key takeaways

  • →Values and principles must be the foundational substrate of AI governance, not an optional layer, functioning similarly to architectural blueprints or safety constraints in physical systems.
  • →Security leaders (CISOs) are now co-driving AI governance strategy alongside legal teams, reflecting new risks from autonomous agent actions like tool calls and prompt injections that go beyond traditional cybersecurity concerns.
  • →Agent governance requires real-time runtime enforcement at input and output layers rather than post-deployment risk management, fundamentally changing the urgency and architecture of governance controls.
  • →The frontier AI safety community and enterprise deployment community are solving interconnected problems - frontier labs map theoretical risks while enterprises operationalize those frameworks into practical controls like harness engineering.
  • →Token governance and risk-adjusted ROI metrics are becoming essential for CFOs and boards to track both the value delivered by AI systems and the residual risk exposure after controls are applied.

Guests

Karl Herbert Grabbi

Topics in this episode

Agentic workflowsRisk frameworksHarness engineeringAgent governanceRuntime enforcementconstitutional aiCredo AItoken governanceCISOs in AI governancefrontier labs safety research

Questions this episode answers

Why does AI governance need to be grounded in humanities and philosophy rather than just technical frameworks?

Starting with humanistic principles like values, exploration, and human flourishing provides a grounded approach to what's truly important in AI systems, enables faster deployment through aligned stakeholders, and ensures controls address both tail risks and everyday operational risks throughout the AI lifecycle rather than being bolted on afterward.

How has AI governance changed between 2021 and 2026 according to Karl Grabbi?

In 2021, AI governance was dominated by lawyers focused on regulatory compliance; by 2026, CISOs now hold significant budgetary and strategic control because real security risks from autonomous agents - code leaks, prompt injections, and uncontrolled tool calls - have materialized in production systems.

What is the difference between frontier labs' risk management and enterprise AI governance?

Frontier labs focus on tail risks - low probability, high-impact catastrophic scenarios that could occur years in the future - while enterprises manage immediate operational risks like patient diagnosis errors or credit lending decisions happening next week, but both must be grounded in the same foundational principles.

What is harness engineering and why does it matter for agent governance?

Harness engineering refers to building governance controls around autonomous agents to mitigate new risks introduced when agents take actions rather than just producing outputs, requiring real-time runtime monitoring and enforcement at input and output layers to prevent agents from executing nefarious actions.

How should companies measure the success of AI deployments according to Grabbi?

CFOs and boards should track risk-adjusted ROI and value metrics that account for both the value created and the residual risk remaining after controls are implemented, not just absolute gains or savings.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

13 / 20

The episode contains a moderate amount of actionable insight, particularly around agent governance, risk frameworks, and the shift from legal to security-led AI oversight. However, significant portions consist of philosophical framing and abstraction (humanities-focused preamble, value-based rhetoric) that, while thematically coherent, add limited concrete learnings for practitioners. The second half delivers more specificity on forward-deployed governance engineering and token governance concepts, but overall pacing includes considerable throat-clearing.

security has actually taken a pretty important seat at the table and CISOs now I think are spearheading a lot of AI governance efforts
urgency transitions from being a lowercase U to an uppercase U... you need to be governing at the runtime layer, at the execution layer, because agents are taking actions on your behalf

Originality

11 / 20

While the framing of AI governance through a humanities lens is distinctive and the forward-deployed engineer positioning is relatively fresh, core governance concepts (risk registers, compliance frameworks, NIST/ISO standards) are well-established. The connection between humanities and AI innovation, though presented compellingly, is not particularly novel - similar arguments appear in Anthropic's constitutional AI work, which the guest himself cites. The agent governance insights are timely but incremental rather than breakthrough thinking.

the humanities and AI are very closely related
building within constraints to make something obviously valuable but also safe and secure

Guest Caliber

14 / 20

Karl Herbert Grabbi holds a legitimate operational role as Director of Global Advisory Services at a governance-focused AI company with claimed engagements at Fortune 500s (McKinsey, Cisco, MasterCard). His background spans finance and data science, and he has been involved in AI governance since its early days (~2021-2022). However, his credentials are not at founder/CEO level, and his primary visibility appears consulting/advisory rather than building a major product at scale or operating a large P&L. He is a credible practitioner but not a top-tier founder or operator.

we've built close to 40 different governance programs through our forward deployed AI governance engineers
we worked with McKinsey, so we like to say we consulted the consultants

Specificity & Evidence

10 / 20

The episode lacks concrete metrics, real case studies with named outcomes, and quantified examples of governance impact. While Grabbi mentions Fortune 500 names (McKinsey, Cisco, MasterCard, healthcare companies), no specific deployments, ROI figures, risk metrics, or failure case studies are provided. He references concepts like 'token governance' and 'harness engineering' but does not ground them in concrete implementations or numbers. Claims about reducing time-to-production from five months to one month are stated generically without evidence.

if a company works with us and it's taking them five months to get an AI use case from intake to testing to validation to production, and their board tells them we need to get that five months down to one month, that's what me and my team do
we've built close to 40 different governance programs

Conversational Craft

12 / 20

The host (Anjan Roy) asks reasonably intelligent, structured questions that progress the narrative logically and often challenge the guest to be concrete. However, follow-ups are generally soft; when Grabbi offers abstractions or vague claims, Roy rarely pushes back or demand specifics. The 'cynic hat' moment near the end is a notable exception where Roy challenges the forward-deployed engineer framing, but overall the tone remains deferential and the host does not consistently extract hard evidence or press on inconsistencies.

So designing AI with craftsmanship would come back to really knowing the principles and the values as to why you're designing it
If you had to pick one unsolved problem in agent governance right now, what would it be?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B73%
  • Speaker A27%

Most-used words

governance48risk38credo22risks21agent19deployed19build17code16agents16humanities15back15help14building13forward12different11technical11

Episode notes

This conversation blends philosophy, product, and enterprise realities. Karl frames AI as an extension of human creativity and flourishing, urging leaders to ground governance in purpose and the humanities. He unpacks concrete deliverables from governance engagements such as configured workflows, knowledge graphs, control libraries, and integrations with cloud developer platforms, and highlights unsolved problems like reliably measuring agent ROI and telemetry. The episode closes with a humane reminder: translate values into code to govern in real time, then use the gains from AI to spend time on what matters most. Bio: Karl Herbert Grabbi is the Director of Global Advisory Services at Credo AI, where he leads a team of forward-deployed AI governance engineers working inside enterprises to operationalize trustworthy AI. His work sits at the intersection of innovation, risk management, and human judgment, built on the belief that durable AI governance has to be as much about values and craftsmanship as it is about frameworks and code. Karl’s LinkedIn Page Credo AI Website Sponsor Page CyberEDX.com Contact Show Parshock2025@gmail.com

Full transcript

42 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Welcome to Paradigm Shock, a podcast where the visionary meets the analytical. At Paradigm Shock, we explore the historic changes defining our times, helping you develop your own cross disciplinary edge. I'm Anshen Roy and today I'm joined by Carl Herbert Grabbe, Director of Global Advisory Services at Credo AI. Carl believes durable AI governance is as much about values and craftsmanship as it is about frameworks and code. And in this episode we get right into that and where AI is heading, especially as agentic AI takes hold. Recorded on Thursday, July 23rd. If you like what you hear, then please subscribe and spread the word. So let's get right into it. Many conversations about AI governance start in the same place. Things like frameworks, regulations, risk registers. I want to start this one somewhere different today with heart, mind and even soul. So my guest today builds trust infrastructure for AI and he's convinced that the humanities matter as much as the technical code. So Carl Herbert Grabi is the Director of Global Advisory Services at Credo AI. Carl, welcome to Paradigm Shock.

Speaker B: Anjan, it's great to be here. Thanks for having me.

Speaker A: An absolute pleasure to have you here. I've been looking forward to this one for a long time. So what's the animating belief underneath what you're building at, uh, Credo AI? Now, you've described your own approach as combining entrepreneurship with an old world sensibility. Things like refined perspective, deliberate craftsmanship, and a kind of classical reverence. Could you unpack that for me in the audience? And also, why does that combination of heart, mind and soul and not just technical skill matter, specifically for someone building trust infrastructure for artificial intelligence?

Speaker B: So there's a lot of noise in the AI space and people feel overwhelmed by the noise. So our job at Credo AI and my personal mission as well, um, is to help provide signal to that noise and often defined signal. You have to zoom out and look at why you're doing things, how they're connected to the bigger picture and ultimately how society, communities and businesses thrive because of it. So at its core, I truly believe the humanities and AI are very closely related. So let me unpack that for you. AI and Innovating in the Space, along with some of the basic foundational principles in the humanities, like art, literature, philosophy, some of these old world values are inherently related because they're getting at three key principles. And those three key principles are also evident in how we innovate with AI. The first being exploration. Humans have been exploring their minds, their bodies, their souls for generations and generations. Art explores, uh, through paint. Music explores through Instruments AI explores through machines and through code. The second key principle would be creativity. The humanities have all a bit, have been about exploring different facets of creativity and, and how we can unlock new dimensions in coming up with new solutions to problems once again, new music, new art. That's what AI thrives at. So if we can shift the narrative to one of discovery and creativity instead of fear, we're aligning AI with the humanities. And of course, the third principle is human flourishing. I think the humanities are a way to tap into the deepest desires, to flourish as humans express ourselves, our minds, our bodies, our souls, through things like literature and philosophy. But ultimately, AI is leading to a new renaissance of human flourishing through helping solve diseases. Right? Tapping into medical communities, scientific communities. And that's the ground truth of what it's being used for. And once again, I think the narratives need to double down on the positive aspects which truly connect why we're building and using AI to, and trying to do it in a trustworthy manner. And so the mission of CREDO AI is to build AI in service of humanity. So that's why I step back and look at the humanities as a, as a whole and connect that to my work at CREDO AI and how we help companies adopt AI in a trustworthy, accountable, responsible fashion.

Speaker A: Thank you for that. Uh, can you give an example of a decision that's made with craft and classical reverence looks like, versus one that's is absent, where those concepts are absent?

Speaker B: So designing AI with craftsmanship would come back to really knowing the principles and the values as to why you're designing it, who you're designing it for, who your intended audience is, and those are some of the key questions we ask when designing AI, uh, governance programs. Right. So if you can align on those principles, such as trustworthiness, accountability, privacy by design, security, and you're making sure you're taking that into account, not only can you deploy AI faster in a more controlled manner, rather you're also including the broader set of stakeholders who have a say in AI decisions being made, especially at large companies. Right. When you deploy AI, it's a team effort. The lawyers have a say, um, the compliance folks have a say, the cybersecurity teams have a say. So in a certain regard, you're gathering the values of certain teammates who are building the AI, coalescing around those values, aligning those people, and then building because of it.

Speaker A: Thank you. So AI governance sounds on one hand, on the surface, it sounds like a technical discipline. You ask the average man, uh, or woman on the street or even those that are in tech. But you keep returning to the humanities and philosophy when you talk about it here, see it here, see it in many of your writings. Why do you do that and dig into that a little bit more? And what does the humanities give you that a purely regulatory or technical lens cannot?

Speaker B: Starting to build AI or design AI from a philosophical humanities based perspective gives you a grounded approach in what's most important. So if you start with the principles, Anthropic has taken this approach, right, with their constitutional AI and how we think about sort of building AI in service of humanity, um, you're moving a bit slower at the beginning to define what's truly most important in the systems you're designing. Uh, and then on the back end, right, you're also accounting for that. But from, from the outset and throughout the life cycle of the AI design, the build and the release, you're thinking about guardrails, right at the input level and at the output level to make sure that you're accounting for certain risks that are present. You know, the frontier labs look at more catastrophic, right, safety type risks because their models could one day have that impact. So that' sort of more tail risk, right? Higher stakes decisions with, with lower odds of them happening. Whereas companies deploying AI, uh, given from the frontier models are more concerned about um, everyday risk that's right in front of us, right? Something that could happen next Tuesday instead of something that could happen 10 or 20 years down the line. But both decisions are grounded in a set of values and principles that's most important to the company that's either deploying or designing the tool.

Speaker A: So do you see as values as a, like a nice to have on top of governance or is it core to the substrate that AI governance is actually built on?

Speaker B: It's quite core. So you wouldn't think about building a house without an architecture diagram. You wouldn't think about driving a car without a seatbelt or adhering to the rules of the road. Name, uh, your analogy, right? Um, the idea is building within constraints to make something obviously valuable but also safe and secure. Um, and to sort of prevent harms to communities, society, uh, you know, businesses at large. And so values or principles, um, constitution, a guiding document. You know, it doesn't have to be over complexified. It could be, you know, something that, that speaks truly to why your company exists, the type of people you want to serve. So health care is a great example, right? Health care institutions exist to um, make and provide medicine, wellness solutions, care to the broader population. So when they design AI, they need to begin with that in mind as opposed to beginning uh, with speed or accuracy in mind. While that is important, it should be sort of coalesced along with their original mission and original goals. And that's what we get to design every day at CREDO AI AI governance programs for healthcare, insurance, banks, governments, um, that really aligns sort of their mission, their raison d'. Etre. Like the French say, reason for being with speedy innovation.

Speaker A: Right.

Speaker B: That allows them to move at the speed of trust.

Speaker A: Would you say these, this humanities based approach and values driven approach, to what extent is this trainable or coachable or hireable versus something that is, if not inherent, but something that requires more um, kind of long term prerequisites, so to speak. How do you think about that?

Speaker B: Uh, that's a great question. I think traditional education can only take you so far unless you've studied the humanities like uh, philosophy for example or ethical type thinking. But it also boils down to uh, how you approach sort of problem solving. And do you take a systems based view? Do you break things down into first principles and understand how um, the components of a system can then be built in a trustworthy, responsible manner and then how they work together to lead to an outcome? I think the world is really shifting with respect to the talent of who thrives in 2026 and also who we're, we're looking to hire at Credo AI. Um, experience is most important right now, right? Experience, skills, how you're able to use AI tools, orchestrate agentic workflows, um, of course in a governed, trustworthy manner. But things like formal education and perhaps um, old school ways of designing systems I think are quickly shifting to this new more agile, experience based, um, judgment based. I think you can automate judgment. Um, it takes years of reps and then feedback, right? Closed loop feedback to give you sort of the validation with respect to was the decision you made a good decision, uh, did it land well and if you made a mistake that's okay, but how do you build upon that mistake? Um, so there's a certain energy and attitude I think of fearlessness, of risk taking and then of collaborative spirit that has helped our team grow and scale. And we're excited to sort of keep continuing down that path as agents continue to proliferate and adopt, you know, more and more sort of uses of quad code and GPT and Gemini. We use all three. Um, so it's quite exciting to use different tools for different types of workflows.

Speaker A: Bringing this slightly back to the uh, concrete level or the kind of the industry analysis level. You know, you've been involved with AI and AI governance and AI governance adjacent fields for now, several years now. And of course we've seen an explosion in the industry the last three and a half years or so. You know, three to four years was really captured the public's uh, imagination. Uh, both the broad public as well as people that are specifically in this field. Looking back from say three or four years ago, what's something that you've changed your mind about or something that you didn't believe three years ago but you believe now specifically about AI?

Speaker B: I'll start with AI governance and then zoom out to AI in general. When AI, uh, governance first started, I was at the first ever IAPP conference in Boston, I want to say 22 or maybe even 2021. And it was a room full of lawyers. I was one of the few non lawyers there. I'm trained in finance and data science and it was a lot of attorneys looking to analyze AI, uh, governance from a regulatory compliance policy perspective, which was the topic du jour of how we govern systems. Right? We look at what governments say, what standards say, et cetera. And Fast forward to 2026 when AI has proliferated in the enterprise and agent swarms are nearly everywhere. Um, I'm seeing a shift in that dynamic where in the work we do at credo, AI and as I'm out talking to people, security has actually taken a, uh, pretty important seat at the table. And CISOs now, um, I think are spearheading a lot of AI governance efforts still closely tied to their attorney counterparts. Um, but the security risks from things like agents taking actions, making tool calls, kind of proliferating inside organizations have become real. And we've already had incidents, right? We've had um, code based leaks, et cetera, prompt injections. And so the big shift is now security sort of maybe even taking the driver's seat and legal perhaps being in the co pilot seat. Um, but I didn't see that coming six years ago because agents were not, um, deployed and or security risks were of course still accounted for in a traditional cybersecurity sense. Um, But I think CISOs are starting to own AI governance budgets and I don't see that sign, uh, stopping. And with respect to AI in general, um, I think we're still in the early innings of the agentic adoption. Um, it's easy to get caught up in a bubble where if you're following the most innovative companies and half the company is run by Agents and agents are writing 99% of their code to think that that's generally, uh, indicative of what's happening. But the early adopters account for, uh, an overwhelming percentage of media coverage. Right, so the, the first company that becomes a one person unicorn because it's one person and a thousand agents, that's going to hit the head. Um, but it's going to take years and years for more of those types of companies to follow. So perhaps there's a recency bias that, um, probably captures all industries with respect to how media reports coverage. But my antidote and how I approach staying grounded in real world perspectives, um, is actually to bring it back to the humanities and look at historical trends and read books that tell me, um, how the human species has evolved, how we've grown throughout history. What philosophers said 3,000 years ago, one of the oldest lessons in philosophy is change is the only constant. The Stoics said it, the Buddhists said it. I think probably every big school of thought has propagated that claim. So I find it comforting to stay calm in chaos and just keep marching forward in guiding principles as to why we're doing what we're doing at Credo AI, where we see the market going, making bets, doing our best to skate where the puck is going and finding the right talent and team and having some fun along the way.

Speaker A: I want to thank our sponsors. CyberedX. AI is moving faster than the rules that govern it. The gap is where careers are being made, regulators are watching, boards are nervous. And every enterprise needs someone who understands AI, risk compliance and ethics deeply enough to lead. Cyber EDX builds those experts practical training for professionals ready to step into the highest impact roles in AI. Visit cyberedx.com, own the field before it owns you. Yeah, and I should note that we're recording this on July. You mentioned security, Carl, and we're recording this on Thursday, July 23rd. So just in the last 24 to 40 hours, that's security. And AI has been very much in the news with the, uh, OpenAI's evaluation becoming the hugging face incident, escaping containment and going out and finding and executing on vulnerabilities. And of course a little plug to, uh, my podcast here with Paradigm Shock, our last episode about a month ago with Dr. Joe Anasantos, Cybersecurity professor at Notre Dame. This was happening around the time of the drama with Anthropic not releasing Mythos, uh, to the public because of some things they found very much along the lines of what happened with OpenAI, uh, yesterday. So Clearly, I think you're onto something there and that I wonder if we might see security becoming like the first class citizen, if that's where the puck is moving, uh, in AI governance. Now you had said something earlier about how the Frontier Labs and what they are focusing on about the type of frontier list, the kind of high probability, sorry, low probability, but high impact catastrophic risk, perhaps even X risk that some people that are adjacent, those communities focus on. So I wanted to get a little bit into how this word AI governance means different things to people in different communities and unpack that a little bit further. Because some people, if we were to map the field on one hand, yes, like you mentioned, you've got the Frontier Governance and they're thinking a lot about catastrophic risk. And the people around them are the various ea, uh, effective altruists and AI safety groups. And we've had several guests from those communities on this show in the past few months with more to come. But then you've got others that are much more deployment focused and compliance focused. They're thinking about audit trails, the eu, AI act, various NIST frameworks, other regulatory acts that are, that are, you know, there's an act in Korea, there's others at the various, uh, state levels in the US as well as other national acts around the world. So how much are, uh, do you believe or do you see these two communities actually talking to each other versus them solving different problems, but just using the same word?

Speaker B: To me, they're two sides of the same coin and we actually need both of them pushing progress on both of the areas where they have expertise. Because if you think about the life cycle of innovation and adoption, how it's historically went is, um, a company comes up with a new tool or a model. So if we take the Frontier Labs, for example, they need to deeply understand the risks involved with that tool and model, they need to account for those risks, and they need to build controls to help mitigate those risks. We could call those guardrails for example. Uh, and then slowly but surely that tool starts to seep into the business community and then I would argue the government community or academia, perhaps academia and business at the same time. And then government depends on the country you're in. Um, but if they have a well, well thought out plan that's executed and operationalized early on, and that plan and, and sort of the mitigations involved with it carry on into how the technology disseminates, that's great. Now where the disconnect comes is if the risk mapping exercises initially start and stay purely theoretical and don't become practical and implementable. So I think this is now where the business community sort of helps take what gets started in the frontier risk community and then operationalizes it. How does a hospital think through risk management compliance of a clod driven model that's being used to help diagnose patients? How does a bank think through an OpenAI developed um, model that they're using to make credit lending decisions? So these are complex decisions and you do need to account for the risk at the model layer, but then you need to account for the risk at the agentic, uh, layer if you're building agents on top of that model. Um, the hot term we're hearing these days is harness engineering. How are you engineering the harness around the agent to account for the certain risks? Because there are risks present from the model, um, but there's a new set of risks as the agents take action. Um, so it's frankly we do a lot of bridge building in credo AI and understanding what the frontier labs are thinking about, writing about and designing and helping big companies understand that what parts of it are most important to them, why, why should they care? Um, and then how they can deploy that but then show evidence. Everyone's talking about ROI, success metrics, KPIs. Why should my company deploy this AI? How can the board track value? This is where CFOs are playing a big role. I would probably add CFO to the third group of stakeholders playing a major role in AI and AI governance. Now how are you tracking spend and the value derived from your AI? And how is that on a risk adjusted scale? Uh, you can say we made a million dollars with this AI tool. It saved us a million dollars. But did it put our company at $10 million worth of risk if something were to. Or did it put our company at $5,000 worth of risk because we had controls to mitigate that? I think that's a big topic of conversation going into the second half of 2026. And there's this idea of token governance. I heard the term tokenomics. I think those are going to gain steam and we'll be talking a lot about them, uh, in the near future.

Speaker A: Yeah, almost a new type of financial engineering, uh, that didn't exist before with, with token economics now or token governance or where governance and economics meet at token usage. Because clearly token maxing is uh, probably not sustainable. I think that's not a bold hypothesis.

Speaker B: But uh, it goes to show how AI touches every, every sphere of knowledge, right? Economics, finance, uh, philosophy um, science, technology, it's, it's, it's one of the few innovations that, you know, has really been encyclopedic in its grasp of human thought throughout history. You can bring up AI and then contrast it with every sort of school of thought and have a great debate or dialogue around its implications for business and society.

Speaker A: I want to move a little bit more, uh, drill down into what you're working on @Credo. And you had mentioned, uh, this idea of agents and harnesses being a big area of, uh, uh, expansion and as a new field and just credo your own roots really quick. You know, you go back to trustworthy AI governance, uh, a few years back, and now you've clearly extended into agent governance and that seems to be where a lot of the field is moving. Can you describe what actually changes when the thing you're governing can take actions and not just produce outputs? How does that force you into a different, uh, frame of mind and a different risk framework? When you're looking at, again, actions beyond

Speaker B: just outputs, urgency transitions from being a lowercase U to an uppercase U. So what I mean by that is the urgency with which you need to monitor, account for and then stop risks that are present in agents becomes immediate. You need to be governing at the runtime layer, at the execution layer, because agents are taking actions on your behalf. Whereas a year ago, two years ago, there was a bit more of a comfort level around governance lagging and you know, capturing risks or implementing controls after the fact because, uh, there were more stage gates built in the process wherein the human was in the loop, um, and AI was not taking actions on your behalf. Right. AI produced an output. A human would come in and say, okay, this output, uh, is agreeable and then we can release that output. Whereas an agent, if you don't have, um, a human in the loop, or if you don't have enforcement sort of, uh, prior to the agent taking action at the input or the output level, um, the agent's just going to go out and take potentially nefarious actions for very high risk use cases. Right. So I think having a clear risk framework around your agents that buckets them in simple terms, you could use low, medium or high or prohibited and more complex financial services. We see our customers carrying on their legacy risk scoring where they look at the inherent risk and then after controls are implemented, the residual risk, um, but that all goes to say that there are new risk surfaces. The risk surfaces are, uh, coming at us fast and furious and the need to control them becomes immediate. And Urgent.

Speaker A: If you had to pick one unsolved problem in agent governance right now, what would it be?

Speaker B: Biggest unsolved problem is still tracking the value, the spend, the, the overall ROI of how agents are performing. So there are certain telemetry metrics that are now, have now become available from, you know, agent driven platforms, um, you know, the task completion rate, uh, the error rate, et cetera. But I think there's still a lot of creative thinking that needs to be done as it relates to coming up with better metrics to report to leadership, to report to boards. What if you could tell people, uh, you know, based on a scale of 1 to 5 in terms of the amount of money you're making when you deploy an agent, the amount of risks you're mitigating. Let's say you've defined five risks, right? You have privacy risk, legal risk, compliance risk, third uh, party risk, um, and operational or hallucination risks. So is the agent making money? Are you accounting for the risks? And um, have the appropriate stakeholders signed off to deploy that agent? For larger companies? There's more people who provide sign off for smaller companies. They can be more fast and more nimble. Um, that's what we're working hard to solve at credo AI and provide sort of a orchestration layer that helps you, you know, navigate that, um, but at the same time integrate the agentic workflow with the tooling set you already use. This topic comes up all the time. Integrations, right? How do you integrate the AI, uh, you're building, governing and deploying with the tools you're already using. Most companies have hundreds, if not thousands of software tools they're using. So can you implement and integrate with speed, with precision, with clarity and then ultimately with trustworthiness?

Speaker A: What's the hardest thing to when something breaks? Is it like reversibility, attribution, Speed? You had to pick one. I'm going to put you on the spot again.

Speaker B: When things break, it's people's egos because someone put their name on the line, right, to go and buy that agent, um, and then they, uh, have to back up the claim why the agent failed. I'm half joking, but that's why there's a people, process and technology element involved to every AI deployment, right? There are people behind the decision to purchase, procure a tool and to launch it. Uh, and then there's a process that needs to be in place. And what another failure point we see often at Credo, uh, AI because we've built close to 40 different governance programs through our forward deployed, um, AI governance engineers. If the workflow is not clear, if the people in the process are not aligned, um, the tooling ends up breaking or not being as efficient as you wanted it to. Um, and now there's clear evidence in the market uh, of most of the big tech companies releasing their own forward deployed engineers. Um, it's been a term that's been around for over a decade, coined by Palantir. We, you know we were, we, we made, we made the bet about two years ago and we're doubling down on our forward deployed AI governance, um, sort of experts and team to make sure that we can help companies align the people and process with the tech um, and namely also to help them adopt uh, the latest AI tools that align with the workflow. So it's not purely theoretical or we don't leave them with a PowerPoint, we like to leave them with uh, configured software that derives value.

Speaker A: Well that's a really good transition to my next question on the Ford deployed engineer function, which is specifically what you're focused on over at CREDO AI. So dig in a little bit more on making the case for embedding AI governance experts inside organizations in the same way that for deployed engineers get embedded inside organizations with their customers. Why does this need a person who can translate between the boardroom, the compliance team and the engineers actually building the agents. And along those lines, do you see this shift as industry wide or is it specific to agentic systems that are moving very quickly?

Speaker B: The idea of bringing in uh, experts from the outside who are neutral and have experience and who are battle tested is as old as time. Um, services that um, have evolved from management consulting to now forward deployed engineers. But the idea is that uh, our team of forward deployed AI governance engineers, and we're still the first company to emphasize AI governance in the FTE title. Um, and we think that's very important for obvious reasons of making sure what we're designing is trustworthy, secure, uh, uh, and safe. It's because the team is battle tested and they've built these governance programs day in and day out at Fortune 5000 at the mid market and also now it's small and medium sized businesses. Um, so we've seen the challenges that come across. Uh, we've worked with hundreds of legal compliance, privacy and security teams. Uh, and we've helped sort of manage the debates that go on within the companies, create and co design solutions that are fit for purpose, that work within their company and then that ultimately get deployed. Um, we're really proud of um, our Forward deployed team, um, who's helped design governance programs for some of the world's largest, um, you know, healthcare, uh, companies. We've actually worked with, uh, McKinsey, so we, we like to say we consulted the consultants, um, and you know, helped them deploy our, our CREDO AI platform. Um, and you know there's the Cisco, we, we've, you know, MasterCard. So some of the biggest logos and brands have, have been our partners along the way. Um, and you know we're doubling down on the mission as I said before, and I think that this, this, this renaissance of, of, of re engaging, uh, for deployed engineers as opposed to consultants. I know that it's very buzzword bingo of the day, um, but we have proven results and we've seen value, uh, through helping companies, um, reduce the time it takes to get their AI use cases into production. Right. So tying this back to clear value, clear roi. If a company works with us and it's taking them five months to get an AI use case, from intake to testing to validation to production, and their board tells them we need to get that five months down to one month, that's what me and my team do. We come in, we build a workflow around that, we design risk management processes and we help companies reach their board goals. Uh, we've gone so far as to actually help um, with deploying our team in our customers to help them run their AI governance function after we've designed a program. It's an interesting, exciting space and we're happy to be sort of at the nucleus of it.

Speaker A: Can you dig in a little, unpack a little more on the concrete deliverables that come out of a forward deployed governance engineer. You'd mentioned risk registers. So is this more documentation and processes versus say applications? Because when. First thing that comes to my mind or I think most people, when you think of engineering, you think of technical, something technical that comes out of an application of some sort. Right. Could you dig in a little bit more concretely? What are the outputs and deliverables of a, of a governance FD? Is it FDE?

Speaker B: FD? Yeah, I think we say FDage. It's a mouthful. Perhaps we need a better, um, but yeah, certainly it's so the outputs are very clear. Um, and we want to make sure that the outputs are aligned to how the company wants to build their governance program. So first and foremost it's a workflow. It's an AI governance workflow. That mentions, um, what I talked about earlier in terms of how an AI use case progresses through its Life cycle. Who needs to be reviewing it? Uh, what evidence do they have to review it? How is it risk tiered, how are controls applied? And then um, sort of how does it get deployed? Now it's not just a workflow on paper, most of the customers that work with CREDO AI, then we configure that workflow in our software, right? So we get a paper exercise of a workflow but then we have a configured software that brings it to life. Now if they're not a platform customer, we can still help them operationalize that workflow in their current ways of working because we deliver engagements for CREDO AI platform customers and then we have non platform customers. So there's a lot of optionality there. Secondarily we help them build out a robust risk, uh, assessment framework, meaning their risk framework in their organization. What should it be grounded in and why should it be Grounded in the NIST, RMF, ISO 42001, the EU AI act, the Colorado AI act, if their insurance NAICs, if they're in health care, do we need to bring into account, uh, HIPAA and other sort of regulatory consideration, we take all of that into account and make sure that the risk register we stand up, um, is fit for purpose and relevant to them while counting off on the risks, um, that our AI research team has, has been putting out. And the risks we put out sort of take all of the regulatory, um, intelligence, the governance intelligence, business context intelligence. We build it into a knowledge graph, um, which has been now being trained on six years of governance intelligence. And then our customers can leverage that knowledge graph, um, for risk scenarios that make the most sense to them. And then we have an AI control library. Once we've really chipped away and chiseled a risk framework, we build a control library that helps mitigate those risks, uh, while bringing in the right folks and the right stakeholders. And that does include technical controls, uh, things like guardrails and making sure we're preventing uh, hallucinations and toxicity. So oftentimes technical control evidence needs to come in through developer platforms like a Microsoft Azure AI Foundry and AWS at gcp. Thus we need to build integrations to those platforms to bring in technical evidence. So core to our strategy is right integrating with technical tools to help orchestrate a governance workflow. And then if they want, we also deliver a target operating model, which I know has been tried and true in the world of management consulting. But once again our operating models tied to uh, operationalizing that on a software platform wherein the reviewers, the first line of defense Second line and third line have a role in a software, our platform or whatever governance tool they're using is uh, bringing that to life. And then you know, there, there's a lot of more interesting outputs. We're designing where we recently signed um, an AI security engagement where we're going to be helping build out, ah, red teaming, adversarial testing and sort of the security suite you will, and we're excited about that service offering. We're dipping our toe into sort of the token governance and how we can design systems to help companies track the value and the cost of their agentic or traditional machine learning deployments. Um, it's a really exploding tam. Right. The total addressable market is very large with respect to the four deployed services we can offer. So we're listening to the market where we're sort of observing where the pain, where the challenges are and then making our bets in conjunction with that.

Speaker A: Now thank you for that Carl. I'm going to put on my slight cynic hat here and just say okay, but for deployed governance engineers, they're just consultants. They've been around for, you know, decades, centuries, whatever. Make the case of why it matters that these, that the Ford deployed naming matters and that this is something that is distinct from conventional consulting.

Speaker B: I think the naming is a narrative shift and I do talk to a lot of people who are allergic to management consultants, but I would tie forward deployed engineers closer to software engineers, people who build, people who deploy, people who ship, people who are outcome driven. So our whole model is outcomes and values based driven. We're not charging by the hour, we're not looking to stay there forever and have you dependent on reliant on us on day one. We align on what does value mean to you, how do we build a program to deliver that value? And then we'll track outcomes and we actually send a, um, a CSAT survey after our forward deployed engagements. Um, and most of our surveys have been, you know, five out of five thus far and we're doing our best to keep that up. Um, but it's because in the survey we ask where did you see value? And we drive it to tangible outcomes like increased speed with which we can get our AI use cases into production, increased number of risks that we built, controls around, um, number of high risk use cases that we not only identified, mitigated the risks from, but also delivered uh, value to the business from. So we have quantitative metrics to back everything up.

Speaker A: Oh, thank you for that. And yeah, it sounds to me like what you're is that you're actually building something. Thus the engineer term. Even if you're not even your outputs are not code. They're embedded into the, the final product or platform that is being delivered or deployed. And it may even speak to how engineering itself is changing. We know this software engineering itself is changing given cloud code and all the other various agentic, uh, or agentic assisted coding tools that are out there. That, so, so you. We may be. There might be a single point that a lot of these disciplines are now coming towards where your outputs are, where the most important outputs aren't necessarily the actual technical product. Because much of that, at least the execution side of that is being handled by various coding agents, so to speak. So, um, with that, if you had like one, one message to give to an executive, uh, out there, uh, something that they don't understand, or something that's not on the radar screen, what would that be?

Speaker B: The world is increasingly moving to systems that are now governed by code. So what I mean by that is you can build your governance policies, your frameworks, your rules, and then actually build them into software and build them into code so that you're governing your AI deployments in real time. So the easiest way to think about that is if an agent is taking action, the agent is run by code, right? It's just a collection of, uh, various code that it's been given, skills and tools, etc. If your governance lives in code, then you can effectively govern that agent at real time. So what we've launched at CREDO AI is an agent governor that builds, uh, governance into the agent's harness through configurations and bringing in code. Um, so just think through how to transition sort of your policies, your principles, your ways of doing things, um, into code, into GitHub, repos. Because the way of the future is that mostly everything, uh, most of the ways to run your business will be configured, uh, in different skills and tools and hooks. And these are terms you'll be hearing. Um, so the faster you can think through translating abstract qualitative concepts into code, the more efficiently you'll be ready for the future, which will increasingly, uh, be run and governed by agents. Now on the back half of that, I want to leave with a little bit of optimism in that. Why I truly believe in AI and innovation, bringing it back to the humanities is that it's allowed me discovery, uh, it's allowed me exploration and it's allowed me freedom and more importantly, it's allowed me more time with my daughter. Because if I can make, uh, a PowerPoint deck using an agent in 30 minutes. That used to take me three hours. I have two and a half extra hours to go bike riding with my 9 year old. And that's my most important mission in life, is to be a good dad. So if AI can make me a better dad, I'm all for it. And I'm all for trustworthy AI that serves humanity. And you know, I've love seeing how my daughter learns and explores. So I get to discover the world through the, through the eyes of my daughter. And that's the greatest feeling ever. So my punchline for leaning into AI is learn it, use it, use it responsibly and then go spend more time with your loved ones. Because we need more love, we need more empathy. So that's why I bring it back to the humanities and that's how I operate.

Speaker A: Well, that is a absolutely powerful way to end it. I don't think there's anything that I could add to that because I can say if AI can deliver that, that's what the industry should lead with, not with some of the other stuff that sometimes gets led with. So where can people find you? And we'll put this out in the show notes.

Speaker B: Yeah. Um, so credo AI, we're@www.credo.AI. uh, we're on LinkedIn. I'm also on LinkedIn. Carl Herbert Grabby, you can find us there. We're putting out a lot of thought leadership on our webpage. Um, and those are the best places.

Speaker A: Carl Herbert, Robert Grabi, thank you for coming on Paradigm Shock.

Speaker B: Been a pleasure. Thanks for listening.

Speaker A: Now a word from our sponsors. At Cyber edx, every board is now asking one question. Who owns AI Risk? If your organization can't answer that, you have a problem. If you can answer that with authority, you have a career. AI governance is the fastest moving discipline and most professionals are unprepared. CyberEdX trains the people who will run AI oversight for regulated enterprises. Start@CyberEdX.com Be the answer. See you in the show Notes. Thank you for listening to this episode of Paradigm Shock. If you like what you heard, then please give us a rating and leave us a review and spread the word so you can help others find this new podcast. Every little bit helps. If you have any questions or feedback, please email us@parshock2025mail.com that's parshock2025mail.com I'll be back next time for another thought provoking episode of Paradigm Shock where the visionary meets the analytical and the details matter.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Building Out Loud: AI native Startup Journey | Faith Forster and Randy SilverProductized Podcast · on Agentic workflows85 / 100
  • Beyond the Simplistic Narrative that AI will Replace Software with Mahesh RajasekharanSaaS Scaled · on Agentic workflows83 / 100
  • No-Reply Email Addresses Are Costing You CustomersEmail After Hours: The Podcast for Email Senders · on Agentic workflows81 / 100
  • Why AI Transformation Is About Alignment, Not ToolsFacilitation Lab Podcast · on Harness engineering80 / 100
  • The Power of Unified Data: Karl Simon on Leading AI InnovationCustomer Success: Pivot Your Career · on Agentic workflows78 / 100
  • Episode 431: Agent Governance Is the New App GovernanceMicrosoft Cloud IT Pro Podcast · on Agent governance77 / 100

More from Paradigm Shock

All episodes →
  • AI's Double-Edged Sword: Risks, Rewards and Race Dynamics in Cybersecurity with Dr. Joanna Santos69 / 100
  • Radical Optionality: A New Framework for AI Governance with Charlie Bullock
  • Building the Clinical Compliance Layer: The Future of Healthcare AI with Stephen Saine
  • Andrés Soltermann: The Future of Securities Lending
  • Navigating the AI Safety and Governance Labyrinth with Andrew Harrison
Explore the best B2B AI & Data podcasts →
All Paradigm Shock episodes →