Software Testing Unleashed · 2026-06-11 · 21 min
Key moments - from our scoring
Substance score
34 / 100
Five dimensions, 20 points each
Alexis Savkin, a strategist and mathematician, discusses how to integrate AI into regulated medical laboratory environments without compromising compliance. Rather than starting with API implementation, Savkin advocates a strategy-first approach using bowtie analysis for risk assessment - a single-page visualization that maps threats and controls, making compliance tangible for both technical teams and non-technical stakeholders like regulators. His method draws on analogies (internet protocols built on non-deterministic packet delivery) to prove that deterministic outcomes are achievable atop non-deterministic AI systems. He worked with a medical analysis lab to narrow their AI ambitions from an expansive ideal vision to specific, solvable problems with measurable stakeholder needs, removing two or three options due to regulatory uncertainty while maintaining architectural readiness for future agentic AI. The European Union's 2025 healthcare AI report validated his approach by recommending strategy-plus-funding-plus-stakeholders-plus-regulation integration. Savkin emphasizes focusing on one tangible problem deliverable within a month rather than solving enterprise-wide AI implementation, which makes regulatory evidence collection straightforward and scalable.
Use internet protocols as an analogy: data packets are not deterministic (they can arrive damaged or be lost), yet the internet delivers reliable service through layered controls. Similarly, AI can produce compliant, deterministic outcomes if you implement proper controls and architecture that account for non-determinism, as validated by the EU's 2025 healthcare AI report.
Bowtie analysis, a risk assessment visualization that fits on one page and shows all threats and the controls in place to prevent them, making compliance proof tangible and understandable to both technical and non-technical stakeholders.
Conduct regulatory scanning to understand the compliance landscape, then focus on solving one specific, quantifiable problem rather than trying to implement AI enterprise-wide - this makes it easier to test against existing requirements and collect necessary evidence.
Because regulations do not require this practice, and doing so introduces unnecessary compliance risk. Keeping the scope narrow and avoiding unregulated practices like sharing personal data allows organizations to remain compliant without needing costly litigation budgets.
He created an ideal picture showing how AI could use all medical context (patient history, etc.), then systematically filtered it by labeling each option as either compliant now, still prohibited, or permissible - allowing the team to focus only on what they could actually build and prove to regulators.
Our reviewer’s read on each dimension, with quotes from the episode.
There are a handful of genuine ideas - the bowtie analysis for compliance visualisation, the mathematical 'prove solvability first' framing, and the internet-protocol analogy for non-deterministic AI - but they are buried under extensive filler, small talk, and repeated restatements of the 'focus on specific problems' platitude. The density of actionable ideas per minute is low.
in mathematics, before solving the problem, sometimes we just prove that we can solve it. We don't know how, but we can prove that we can solve it
The packages that we exchange, they are not deterministics actually. They they can arrive damaged. They can be lost. Latency can be high. But using internet protocols we can build on this
The internet-protocol analogy for non-deterministic AI is frequently circulated at conferences and is not a fresh take; the 'strategy first, focus on one specific problem' advice is standard GRC/change-management wisdom repackaged. Regulators-as-friends is mild reframing rather than a contrarian argument.
I I heard it uh a lot on conferences like this is like Internet
regulators are not our enemies. Yeah. They are our friends and they are trying to uh make our uh life safer
Alexis Savkin is a genuine 20-year IT practitioner and strategist who completed a real client engagement, giving him credible hands-on perspective; however he is a solo consultant who worked on one anonymous mid-sized lab project, not a scaled operator or senior executive whose decisions have shaped a large organisation.
I'm I'm strategist firsthand
I'm an IT for more than twenty years, yeah. So I uh I created my first product in uh two thousand
Almost nothing is named or quantified: the client is anonymous, the EU report is cited only as 'forty forty page I think document' from 'I think August July,' no metrics or dollar figures appear, and the bowtie diagram itself is only described vaguely. The episode is almost entirely abstract.
First of all, it was like end of 2024, but uh that time it was not published, but in 2025, uh I think August July uh uh a report came out from uh European Union
uh forty forty page I think document
The host asks leading, multi-part questions that often trail off or answer themselves, and consistently responds to every answer with affirmation rather than a follow-up challenge. There is no pushback, no request for concrete evidence, and no productive tension throughout the conversation.
how how how does this fit?
Yeah, yeah. Yeah, so sounds great.
Computed from the transcript - who did the talking, and the words that came up most.
How to make AI work in a regulated medical lab, step by step Free e-book: The 7 success factors of software testing. 25 years of project experience in one 33-page workbook, now also in English Get it for free "Regulators are not our enemies. They are our friends and they're trying to make our life safer." - Alexis Savkin How do you bring AI into a medical lab when the regulatory landscape is still taking shape? With Alexis Savkin I talk about exactly that tension, and the answer turns out to be less about technology than about focus and strategy. We get into why starting with a very specific, measurable problem makes the regulatory side manageable, and how a single-page risk diagram convinced compliance stakeholders faster than any technical pitch. I keep coming back to his point that regulators are not enemies but partners trying to make things safer, and that the real mistake is trying to solve "AI" as one giant problem instead of one concrete thing at a time. Alexis Savkin is a Senior Strategy Consultant and the CEO of BSC Designer , a Balanced Scorecard platform.
Transcribed and scored by The B2B Podcast Index.
If you ask ChatGPT the same question, it will give you a perfectly wag detailed answer, but it won't think this long term. Regulators are not our enemies. They are our friends and they're trying to uh make our uh life safer Yeah. And in mathematics, uh before solving the problem, sometimes we just uh prove that we can solve it We don't know how, but we can prove that we can solve it.
There have like 10x more budget, but who cares? We have 10x more courage Welcome to Software Testing Unleashed, the podcast for testers, developers, and all project people who want to create great software. My name is Richie, I'm a software quality coach, keynote speaker, and author. And today I have an Episode from the OOP conference in Munich this year.
There I met Alexis Savkin and we talked about the integration of AI in a product in a regulatory environment. He found a solution, how this combination can work, and how to make regulatory. And now enjoy the episode. Hi Alexis, great to have you on the show.
Thank you, thank you. I appreciate that you are here at the OP in Munich here uh new new environment for this conference and uh is this your first OOP or no actually it's I think the third one or the fourth Ah, okay. So I'm coming here depending on the year. Yeah, yeah.
And I I read your abstract and there there were two very contraintuitive words together. It was medical regulation environment and AI Quality control and I said okay how how how does this fit? So and that's what I want to know from you. I don't have this, you know Everyone puts now AI expertise and uh I don't have this.
Yeah. And uh for me it was actually curious how they found me and uh why they decided to work with me. Uh I'm I'm strategist firsthand. Uh and after a short talk Actually they rise to explain the problem, the challenge.
So the challenge is exactly that you mentioned. That it's regulated industry on one hand. On the other hand, they are a kind of innovative organization, so they want to play with new technology. So the question was how to play with new technology But do it it from a strategy-first perspective.
And make sure that what we do is actually safe from legal point of view. So uh they have a IT people who can do all the uh integration stuff. Yeah. But the question was how to make it safe in terms of regulations in terms of Because most regulations we will talk about these, they're coming up now.
Yeah. Not last year. So a lot of question marks yeah and not so many answers. Yeah.
So probably that's why I was the right person. And I decided to pack it in a use case to present on conference. Yes. And uh we'll see the talk is tomorrow, so I don't I don't know how people will react.
Yeah. You never know what it is. Sometimes you come and uh it's a small room crowded, but sometimes you come and like Yeah. Few boring people waiting for you.
Yeah. I see. We see. I think that the topic could be very interesting for the audience here too.
So uh uh so and I assume there is a a possible way out to combine and to make the fit of these two worlds. Absolutely. In this specific case, what surprised me, uh, because when when I started working with this client, I I brought to the table my knowledge and uh the frameworks that we typically use for strategic planning like strategy maps uh other frameworks uh change uh agenda framework a lot of tools But uh one specific tool captured the attention. It was uh bowtie analysis, which is used for risk assessment Okay.
So basically with all the toolkit uh we had, we reduced it to one simple tool which is boat analysis. Because it's actually visualized for them all the threats they have And all the controls they have in place to prevent those threats. So basically for them I think it was like 80% was about solving the compliance problem. With classical tools it was solvable, but in this case it was just one page diagram where you have all your things listed And well everyone was happy.
Yeah. Because many stakeholders were involved, not just technical people. Yeah, yeah, yeah. And how how did you how did you Get there step by step through this process to make that fit to make to use this uh Yeah, so actually uh uh right now it's easy to connect the dots.
Yeah. Afterwards it's easy to connect the dots, but it was all the journey. The fourth thing uh is actually to uh look a little bit more into the stakeholders we are dealing with. uh to understand the landscape and um uh to understand how the the uh this company works because it's medical analysis lab so before I I knew only the uh what what we see from outside.
You come to uh take your probe and they do some take some samples and that's it. And in in a week and two days you get results by email. Yeah. But if you look for insight, it's like a lot of uh high-end technologies there, uh a lot of uh processes, IT processes, physical processes, a lot of testers, a lot of hardware to combine.
And uh like it was a like all the journey for discovering this, yeah. Yes, yeah. Many things I have along just just I I I can now give some better advice for people who go to you know medical labs to do tests. Yeah.
Because I know now what to look at before I I had no idea. Yeah, yeah. And and uh what is the what is the what is the problem when you when you're uh coming to say okay that uh They want to have the regulatory part but also the new innovation and especially AI which is non-deterministic and and how how uh how can you focus on the on the problems and how can you solve them with the with the m method. Yeah so I I think the first part I like by my background I'm mathematician, yeah by my formal education.
And in mathematics, before solving the problem, sometimes we just prove that we can solve it. We don't know how, but we can prove that we can solve it. So that was probably the first step that I wanted to show them that you we actually can solve it. So you mentioned like AI is something that is mm it's flexible, it's not determined it's uh changing so how do we show that we can build something on this?
Yeah in my example like uh I I heard it uh a lot on conferences like this is like Internet. Internet is built on these principles. The packages that we exchange, they are not deterministics actually. They they can arrive damaged.
They can be lost. Latency can be high. But using internet protocols we can build on this and what we have now the internet it's actually the result of this. So my first step was like to show them okay guys We will build something on this which is not deterministic.
And it's possible to do it. And the result will be deterministic. Yeah. So this was a like first step, I think icebreaker if you want.
Yeah but to basically start the dialogue. Yeah, yeah, that makes total sense to to think about with this metaphor of the internet so more analogous with other domains like if uh this uh company that is do scanning for uh cancer diagnostic can do it why you why you cannot do it. Yeah. Okay, there I have like ten X more budget but who cares?
Yeah, yeah, yeah. Okay, you said you told us this this was the icebreaker to to g to to talk more about what is really possible and how how can we how can you solve that yeah. And then you you uh designed a a process for the for this like the internet protocol? It was it was it uh was it your partner?
Uh what was the the next idea? Uh I was just trying to understand, now I understand why, but that time I was trying to understand why me. Yeah. And uh it resulted that uh they were following up with me on LinkedIn and uh what I do there I pause there whatever I do in my business so I explained that we integrated AI in our own product And I also posted there a few articles about AI topics like AI awareness, uh AI readiness uh implement an EI from strategy first approach.
So basically this attracted their attention and that's what they wanted. They wanted the process that starts not from integrating APIs not from you know hard thing but from from the top. So basically I have adapted a little bit our classical methodologies for strategic planning, started for stakeholders uh splitting the uh big problem like we want the eye it's big problem. Splitting into something most tangible, more specific, like for what you want.
We created an ideal picture. how it would be if AI could use all the context about my uh for example uh history medical history it's ideal future a lot of ideas there but then we start okay Uh this is not possible, this is still prohibited, this is like okay and this we can do. So focus on it, focus on it and um Yeah, so the rest was like uh okay now when we have the problem truly specific how do we make it more tangible? uh for stakeholders, for compliance stakeholders, for IT people, for everyone.
That's when this uh bow tie analysis thing came up So uh I just showed them like an example that they liked it very much because it's like one page and they they see all the all the metrics they want to have and most important they can show it as a proof to regulator that they actually uh implementing certain controls. So I I I I would say it was like 80% classical. Job of strategist rather than low-level implementation. Yeah.
It sounds it's it's so it makes so much sense what you say because uh When we have a big problem then we go f a strategic way and decide to cut it in in things we can solve which we cannot solve. But as you said, when we talk about AI in in nowadays in the companies They are just dealing with APIs with all the protocols and doing the stuff and trying out and making experiments but not with the big picture in the mind. Exactly. And I think another thing that is important at any kind of implementation like this is to give a sense of how this will be developed in future.
Because uh those guys they're not IT people. And I'm an IT for more than twenty years, yeah. So I uh I created my first product in uh two thousand. Yeah.
Many years past. And I know what happens with product. You know what it is. We know what happens.
Legacy is getting accumulated, the architectural problem is appearing. So with AI it's for for us it's another digital transformation. So we know that it's not just rushing and implementing APIs. It's about thinking about architecture, thinking about how it will be developing.
And uh actually the architecture that we develop together with a team It's uh really compatible with the ideas of agentic AI that is coming up now. So that's uh another reason why they are really happy. It's not something so it's not a surprise for them. They don't ask, okay, and now how would do Like migrate the old stuff to the new approach.
It was quite a logical step for them. They don't have this agentic approach yet, but It's uh ar architecturally it's possible. Yeah, okay, so you may have a it's always the the foundation for for the future uh there in the architecture. I I think that the there's a difference.
If you ask ChatGPT the same question, it will give you a perfectly wag detailed answer, but it won't think this long term, yeah. And that's the the difference like between hiring people like you and me and uh just asking Advice for AI. You expect us to be more long-term visionaries in this context. Well when we talk about the regulations, uh you s you you mentioned that uh they are always looking for documentation and for proof and for traceability and all this stuff.
How did you address that in the in that context? Well actually it's interesting. Uh First of all, it was like end of 2024, but uh that time it was not published, but in 2025, uh I think August July uh uh a report came out from uh European Union. Uh that uh was a kind of overview of state of AI in healthcare.
Okay, th thank you. Yeah. I was expecting to have like earlier. But what what they say basically it's uh forty forty page I think document.
Uh executive summary, I will have it on my slides, uh the most important conclusion they made that to make AI possible in medical domain we need to combine uh strategy, we need to combine funding, we need to combine stakeholders, we need to combine uh regulation, we need to combine uh all this stuff. So basically they uh gave a rationale for s strategic first implementation. So it was a like uh easy part. I would expect it to come earlier.
Yeah. And well in terms of making it possible uh like Uh collecting evidence is easy when you know what you need to collect. When you're focused enough. It's easy to come up with controls that uh will ensure that people actually use AI in a compliant way when you uh when you focus on speci specific controls.
So probably uh uh one of the uh Thoughts I share during my presentation will share is that instead of trying to solve AI problem, like a very big AI problem, implementing AI in organization, make us AI first, I would say Focus on a very specific tangible thing that you can do and show the value for your stakeholders, I don't know, in in one month. And this solves a lot of challenges, including the challenge of regulation. You understand what kind of evidence you need to collect.
You try it with one big thing and then you can move to another, you can scale. Yeah, yeah. Yeah, so sounds great. Do you do do you have uh this this product or a or project?
Is it Uh is it gone through the regulation? Is it already approved for for for usage and or audited from the regulatory site? Actually for for this quality control there are two parts. Uh one is when uh like imagine that a device it's using for testing is generating some error and it's uh you need to make sure that is this error is not coming to the final outcome.
So this is not regulated at all. So it's uh your responsibility and you need to make it good. And uh in terms of regulations there are specific uh like checkboxes that you need to check before you can actually use it. So it's not like uh getting certificate for this.
Yeah. Yeah. It's like uh you read the requirements and you get compliant with this. If you want later you can get some uh some certification for this but uh unfortunately right now for this very specific challenge there is no simply no regulations.
Some some some try to protect themselves by getting standard ISO Certificates but uh it will be just general uh certifications that you do your best to learn from your mistakes. Yeah yeah yeah So basically uh that's the idea that uh the regulation is not that strict actually. If you don't do crazy things like, you know, training uh AI on patients' data or sharing personal data. Yeah, don't do this anyway.
Uh the regulation is not that strict. uh but you need to limit the scope of implementation a little bit because from that ideal picture that I mentioned we have to remove like two or three uh options because of regulation is not clear now. At the same time we see uh the release of uh OpenAI released in January it was uh Chat GPT house or something like this. And people ask why why if they can do this why cannot you do it?
The budgets are different, yeah. If someone got them to the court they have budget to do this and uh their reputation is okay, it's how it is Uh other companies uh probably they don't have budget for this and most important uh that uh Probably customers are not ready to pay. In some cases it's even not clear who the customer is. Because who is the end customer?
Who is paying? You, insurance company, hospital? Who is owning the results also not clear. So I think the main theme here is to focus.
Focus on something solvable and you'll certainly solve it. Yeah, yeah. Now we have uh I think a few uh uh people listening and and watching the podcast who are also in a regulatory environment. Uh what what what would you suggest is the is the first step when because when they say okay now we want also to use AI in our product, uh how how to start?
What would you suggest is the first step to make it. Okay, so uh it's like classical recommendation from uh GRC uh domain governments risk compliance is to have uh in place certain scanning for your organization. Like if you're in this regulatory environment, uh now you can automate it uh to scan what what regulations are c coming up. Yeah so we know the landscape.
The next one would be to uh basically not trying to solve everything but focus on a specific uh challenge that you want to solve. Because if you want to solve everything you it's regulatory uh a regulator basically tells you no you cannot do this. Yeah. Big b yeah, because it's too complex for them to analyze.
But if you focus on something specific You can easier test it against the requirements that are existing now. And uh yeah actually uh regulators are not our enemies. Yeah. They are our friends and they are trying to uh make our uh life safer, yeah.
So all there's um mo most of the recommendation except you know cookies Cookies in Europe, most of recommendations are quite reasonable. Yeah, yeah, that's true. I like the approach that this is a so an important tip for using AI is What specific problem do you want to solve and then you can solve it and not just try to solve everything which is Not really a problem or just do it. Because uh if we don't understand what stakeholders actually need, We cannot answer this question what one single problem we can solve.
So whatever we do, that's why it's called strategy first. We start with analysis of stakeholders. they needs and ideally not not many can do this ideally if you can quantify these needs of stakeholders not just say we need uh analytics for our uh samples yeah but to say it's we need it within this time of period, with this precision for this kind of uh uh problems and uh yeah for this k for this we can tolerate Uh risk for this we cannot tolerate risk, yeah. So just quantify it.
Yeah, yeah. Yeah, it's great Alexis, that's a very, very great insight that you gave here. Uh I really appreciate that the way you can combine a fit a little bit together the AI and the regulatory stuff. Thank you so much that you were here in this show.
Thank you. Thank you. Thank you.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.