
The Pre-Read · 2026-08-03 · 28 min
Key moments - from our scoring
Substance score
65 / 100
Five dimensions, 20 points each
Anthony Habayev explores two core reasons AI pilots stall: the "hammer looking for a nail" problem - companies deploying AI to the wrong use cases in pursuit of AI-forward status - and poor execution quality due to immature organizational capabilities. Rather than treating AI as fundamentally different, Habayev argues organizations should apply existing governance muscles: SOX controls, three-line audit models, and objective-setting practices already embedded in CFO and audit workflows. The conversation focuses on how CFOs and auditors become the pressure that professionalizes AI deployment. By requiring ROI accountability, control verification, and measurable risk mitigation, finance and audit teams create feedback loops that improve AI quality upstream. Habayev emphasizes that agentic AI risk comes not from the technology label but from the use case and consequences - a compensation adjustment carries different risk than an automated lawnmower. For enterprise leaders managing AI infrastructure at scale, he advocates treating AI initially as a project (not just a model) requiring orchestration across data, infrastructure, and business teams, eventually maturing into embedded infrastructure with ongoing performance measurement tied to business objectives.
Two main reasons: companies pursuing AI for competitive status and deploying it to low-impact use cases (the "hammer looking for a nail"), and poor quality execution because organizations lack the mature capabilities and skills to build and sustain AI systems properly.
No - agentic risk comes from the use case and consequences, not the technology label. You can manage agentic AI risk using existing enterprise risk management, SOX controls, and three-line audit models already embedded in finance and audit functions.
A center of excellence is an insulated, well-resourced team focused on your highest-impact AI opportunities, learning what works and what doesn't. Once they develop patterns, those learnings and tools scale across the enterprise, moving from the CoE into broader adoption.
Apply the same language and practices they already use: control verification, efficacy of controls, measurable risk mitigation, and ROI accountability. Ask teams to prove ROI was achieved, drift was mitigated, and fairness controls were tested the right way.
AI moves from project to infrastructure when it becomes embedded in how the company works. Even as infrastructure, it remains a managed project requiring ongoing measurement of whether it's achieving business objectives, not just technical monitoring.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers solid, applicable frameworks for AI governance grounded in existing enterprise practices (SOX controls, first/second/third line structures, project management), which should be novel to many operators unfamiliar with this angle. However, the conversation often retreads familiar governance concepts without pushing into surprising or counterintuitive territory; much of the substance is 'apply what you already know to AI,' which is useful but not densely packed with new ideas per minute.
Apply existing governance muscle before building new frameworks. You have SOX controls first, second, third line structures and objective setting practices already mapping to AI governance needs.
Those aren't new AI concepts. Those are good organizational, execution, measurement, control concepts.
The core thesis - that risk lives in the use case and governance structures, not the technology label; that CFO/audit pressure improves AI quality - is sensible and somewhat contrarian to 'AI is uniquely risky' narratives, but it's grounded in standard risk frameworks and is not deeply original. The guest frames AI governance as 'governance applied to AI' rather than 'new governance for AI,' which is a useful reframe but fairly intuitive to experienced operators.
The agentic itself is not the risk, that's sort of a way to articulate that is like there's all these things that got to the risk was the decision what did I do to control for the variability and the accuracy of that decision.
Those aren't new AI concepts. Those are good organizational, execution, measurement, control concepts.
Anthony Habayev is a co-founder and CFO of a governance-focused AI platform with domain expertise in AI risk management and auditor backgrounds; he speaks from operational experience building compliance infrastructure. However, he is not a Fortune 500 CFO, CEO, or practitioner at massive scale implementing the systems he describes - he sells into that market. His perspective is informed but primarily vendor-side, not from the trenches of executing AI governance at a multinational.
Anthony Habayev, co founder and CFO of Monitor, an AI governance software platform helping companies build, manage and automate responsible and ethical governance.
I started this company in 2019 and you know, in 2018, 2017, you both remember everything was a black box.
The episode lacks named examples of real companies, metrics, and outcomes. Anecdotes remain abstract ('companies we work with,' 'large enterprise customers,' hypothetical lawnmower and compensation examples) without concrete data points, case studies, or dollar figures. The conversation stays at the framework level - useful but vague in execution details that would help operators understand what success looks like in practice.
I have seen as a good pattern with companies is some of the highest performing in AI started with what I would say is like a center of excellence.
I love all the AI investments we're making. We've got an inventory. I like to get my hands dirty a little bit and actually measure. Are you getting the ROI that you forecasted?
The hosts (Steve and Mike) ask reasonably sharp follow-up questions ('what point can it safely move to infrastructure,' 'who owns the decision the system made') and push back gently on vague framing. However, the questioning is mostly confirming rather than challenging; the hosts rarely push Anthony to defend weak claims, provide evidence, or articulate trade-offs. The conversation is collegial and structured but lacks the tension and pressing specificity of truly sharp interview work.
With AI changing as quickly as it is, does it ever move into infrastructure? I mean, is there a risk where, hey, this, you know, what we were doing, I mean, uh, we've experienced this ourselves.
Can I ask a basic question? Because you've mentioned a phrase a couple of times and I just Want to make sure that I definitely know what we're talking about.
Computed from the transcript - who did the talking, and the words that came up most.
AI transformation is a problem of governance, not technology. Anthony Habayeb, CEO of Monitaur, argues that organizations don’t need to spin up a new AI governance framework, but they need better use of the controls CFOs and auditors already own. In this episode: -Why AI pilots stall and what it reveals about governance gaps -How to build an AI governance framework from structures you already have -Why the agent isn’t the risk, but the use case is -Who owns accountability when an autonomous system takes action? -How CFOs and audit teams are becoming the forcing function for AI quality Subscribe for episodes on the issues shaping finance, audit, risk, and sustainability at the C-suite level.
Transcribed and scored by The B2B Podcast Index.
Speaker A: Not every conference has a keynote that stops you mid scroll. This one does. Uh, join us in Las Vegas this September for Workiva Amplify, where CEO Julie Iscous sits down with the Julia Roberts for a candid conversation about leading under scrutiny, making high stakes decisions and building trust with an audience of millions. Turns out that last part translates pretty well to the work you do every day. And that's just one keynote in a three day program covering governed AI reporting, regulation and technology. It's not one you'll want to walk out on. You'd have to be running a pretty elaborate con to justify skipping this one. Register now at workiva.com p r-alertify that's W O R K I V A.com pr-alertify or kiva.com pr amplify and we'll see you in Las Vegas.
Speaker B: I like to get my hands dirty a little bit and actually measure. Are you getting the ROI that you forecasted? Show it to me. Have you mitigated this risk of drift? Prove it to me. If I'm an auditor, I have a control that says I tested for fairness. Where's the proof that I did that and that it was done the right way? I think it's an exciting moment for AI that that's happening because that will create a pressure that improves the quality on the front end. And that loop is now going to mean that we're like professionalizing how we do AI ins a large enterprise.
Speaker A: Just like the slides you get before a big meeting, the pre Read prepares you CFOs and other executives for the next big thing. It's the global podcast where finance, sustainability, audit and risk teams come together in the C suite. If you're making decisions of scale or need to understand the leaders who are, you're in the right place. This is the pre read brought to you by.
Speaker B: We're.
Speaker A: I'm, um, Mike Rivano, pre read producer and recovering cherry coke addict. Our hosts are globetrotting, doing amazing and fun things that some of which you'll be able to hear very soon. So I'm filling in the driver's seat today. Our guest is Anthony Habayev, co founder and CFO of Monitor, an AI governance software platform helping companies build, manage and automate responsible and ethical governance. Steve and I had the pleasure of chatting with Anthony recently and here's what
Speaker C: jumped out to me.
Speaker A: Number one, your AI agent isn't the risk your use cases. Whether an AI system is agentic or not doesn't really matter as what it's authorized to do and what governance surrounds it. Risk scales with the consequences, not with the technology label. Number two, you don't have to reinvent the wheel. Apply existing governance muscle before building new frameworks. You have SOX controls first, second, third line structures and objective setting practices already mapping to AI governance needs. Companies that pattern AI risk management onto frameworks they already own get there faster. So folks, you know how to do this. You're already doing it. Next, the business owns the decision the system made. It's not an autonomous robot. There's not going to be a robot court. So when an agentix system acts, it's the business leader who funded and approved it that carries accountability, not your tech team. Designating a project owner is going to change how that person thinks about deployment risk. Finally, uh, CFOs and auditors are becoming the pressure that professionalizes AI board reporting requirements, ROI accountability and audit inquiries are creating a governance feedback loop. Anthony says that it's that pressure that's going to force better AI quality on the front end. This is a good thing. And now our conversation with Anthony Habayeb.
Speaker D: Well, Anthony Habayab, thank you again for joining us. Now we know that you've watched a lot of AI pilots, uh, succeed and then, and then maybe some stall. I'm just wondering what's actually breaking down when that happens. Is it because, uh, it's a people problem, it's a process problem, Maybe it's something else.
Speaker B: It is happening a lot. And I think that there's definitely a conversation around this. And I'd say there's probably like sort of two key and related issues. Um, one of them is the hammer looking for a nail problem and the other is, I'd say sort of lack of quality execution. I have an idea how to actually like execute that idea. Well, you know, on the hammer nail dynamic, you know, there's misaligning effort and opportunity and impact in a lot of places. So you might have such an eagerness to be an AI forward company and you start pointing your AI at things, even if it's not the right thing to point AI at. And that's, that's one of the sort of challenges that's happening, especially with, I think, you know, a company that feels such a need to be a leader or transform or catch up in some way and feeling AI could do that. They're running around looking for, you know, AI things. You know, I think the other is around, uh, quality of execution.
Speaker D: Right.
Speaker B: So you might have a great idea. But this is such a new tech in some Organizations with resources or competencies that aren't there yet. And so you start down this path of AI and well, how do I actually build it? Well, and what does good look like? And how do I build a performance system? Like, those things are newer. And so, um, you might not achieve what your objectives were for a bunch of different reasons. You just don't have the muscle yet of how to use this tech. I think those are two of the biggest things, and they're both things that can be managed well. Right. I think that there are opportunities that are solvable. And that's the good news.
Speaker D: It sounds like then this really needs to be an ongoing conversation. As in, like, hey, if we're talking about a process, there needs to be an AI element layered onto it. Either, hey, this is a great idea, we're going to go for it, or hey, this is something we could do in the future, but maybe we're not quite ready yet, or hey, no, this is just like way too out there. We don't think. I mean, could you walk us through what like, that dialogue ought to look like? If you were meeting with a team, or let's say an executive leadership team was getting together, what would be those best routines that would start to, like, suss out some of those things that could be, like, really actionable? Back to your point about, like, what works and maybe what hasn't.
Speaker B: Yeah, Steve, you know, it's a good question and the answer is pretty boring. Imagine you ask that same question, but it's not about AI. How do we prioritize what we do in a company? What's the impact? What's the level of effort? Apply the same sort of thing into the AI. Like if you were to remove this is an AI thing from that conversation, you should still apply the same sort of business understanding around that opportunity. What are my goals and objectives? What does success look like? Do I have the right people in place to execute this, to have the right budget and funding to actually see this idea all the way through if it actually becomes a thing, that early ideation, idea and planning is still critical. AI or not. And that to me is, um, I'm here, uh, inside of a governance company. But what does governance mean? That's one of those concepts that you could bring under. This concept of governance is like, hey, let's have good goal setting and good objectives, but they shouldn't necessarily be different for AI from other things. How do I improve margin? How do I decrease costs? How do I introduce new products? How to create more efficiency? What's the best way to do that. Oh, guess what? This new AI thing could solve this really well and better than maybe the RPA thing we tried before or some other process we tried before. Let's do a discrete test of this to see if our hypothesis is true and make sure you have measurement around that.
Speaker C: When we're moving beyond, like we have an AI pilot now, it's not a project anymore. We've learned it's becoming an actual infrastructure.
Speaker A: What does the risk picture start to
Speaker C: look like in an org?
Speaker B: Uh, Mike, you said something there that actually is maybe worth just quickly grabbing. You said it's not a project anymore. I actually think that one of the gaps in some of the AI opportunities is we view it as maybe just a model and not a project. So before it becomes embedded, let's first actually think about it as a project. Meaning there are these business goals we just talked about. There's some data things we have to do, there's some modeling things we have to do. There's some infrastructure things we have to do. You know, some ongoing production. Like all these pieces are, you would say, like a project. Right. And we've got to orchestrate all of these project things. And I actually think that's one of the gaps in a lot of the early adoption and usage of AI is seeing these AI things as projects that require orchestration of people in sort of stages in a way that maybe we haven't before. You know, you ship software, you have two or three Personas that tend to work closer to make that happen. Now we're talking about maybe a broader set of Personas that are collaborating to do something. So actually, people are just starting, I think, to do project before then maybe moves into being, you know, like infrastructure or more embedded. But, uh, to the focus of your question, um, you both probably remember not so long ago everyone was saying AI is going to take everybody's jobs. Now we need more engineers and more architects for AI because it's actually a more complex system than things we had before. And therefore we need more configuration and tuning and permissioning and authorizations and things like that. And I think that that's probably the biggest thing that, um, I'm seeing some of our large enterprise customers start to think about is I've got to build some broader capabilities around these things that maybe we didn't have before. Because if we're going to allow more automated decisioning or actioning by the systems within our infrastructure, then there's more robustness in hardness that needs to live around those things. And I Think that that's, that's like an emerging, I think, hiring opportunity. It's a strategic challenge. Um, but it also ties back to the. My first comment, which is projects, right? Like, you need to bring these new skills together around that project to make sure that like the production things are thought about but connected to where this whole objective started.
Speaker D: With AI changing as quickly as it is, does it ever move into infrastructure? I mean, is there a risk where, hey, this, you know, what we were doing, I mean, uh, we've experienced this ourselves. You know, what I'm doing today is very different than I was doing 30 days ago, which is different than 60 and 90 and so on and so forth. So what point can it safely move out of becoming a project and treat it as such to where it could become infrastructure?
Speaker B: Yeah, I've never thought of project or infrastructure as like, you're either or sort uh, of more of an. And is in my brain how I think about those things. But as I think about what you're asking, maybe I'd answer the question as, when does AI move from being like a center of excellence type thing to. It's truly embedded in the business. And it's like, this is just how we do work and it's sort of omnipresent. And in that sense, those tools or capabilities they do from a project side need to be enabled in a way that the company has confidence in the robustness and the hardness in the sort of like ongoing maintenance of that thing. So in my brain, I view that as a phase of a project. The project never ends. The project is the organization of things. But when you do get out there in the wild, it's actually a big gap, you know, Steve and Mike, is the frequency and the purposefulness of how you make sure that this thing is still achieving our objectives. It's, it's different than just like infrastructure monitoring. Like in what good means to the business could be different from what good means to the tech team. And how do you harmonize those things into. How do we measure? Is this doing what we need it to do? Is this delivering results? I think once you move into infrastructure and it's out there in the wild, you now start having more conversations and questions around value, impact, cost, performance. And so you need to, at a leadership level, I think, form opinions about what do those words mean, how will we define and measure those things? I think that's connected to the infrastructure concept, in my view.
Speaker C: Can I ask a basic question? Because you've mentioned a phrase a couple of times and I just Want to make sure that I definitely know what we're talking about and maybe our listeners, uh, when you're describing AI as a center of excellence, that people start thinking about that. What is that? What do you, what do we mean?
Speaker B: Yeah, one of the things, um, you know, I started this company in 2019 and you know, in 2018, 2017, you both remember everything was a black box. And then all of a sudden we talk about explainability and then we started talking about ML ops tools and then we talked about Geni and now we talk about agentic. And across all those phases, what I've seen as a good pattern with companies is some of the highest performing in AI started with what I would say is like a center of excellence where they put a key team and or people exclusively around what are our best AI opportunities. And let's try to do those really, really well insulated, enabled access is given. Go do some things really, really well. Through those handful of examples, they learned they failed, they succeeded and that's where they developed sort of like, okay, we see certain patterns and opportunities now. Let's push this out across the enterprise right now. Let's actually push rules and policies and permissions and certain tools and applications that can evangelize and embed AI, you know, across the enterprise. So that's where the CoE that I was really talking about is referring to is that starting point.
Speaker A: I appreciate that. I don't have to tell you that the reporting landscape is not slowing down. New disclosure demands AI. You actually have to stand behind regulations, reshaping what your team is responsible for. It's a lot to stay ahead of. That is exactly why WORKIVA Amplify exists. September 14th through 16th in Las Vegas. Amplify 2026 brings together the finance, sustainability, audit and risk leaders responsible for getting the story right. 90 plus sessions with real practitioners who are in the trenches doing the same work you are. Last year, 98% of attendees that they walked away with insights they could apply immediately. This is a working session, not just a theoretical conference. Register now@uh, workiva.compr-alertify that's w o r k I v a.compr-amplement if y weva.com pr amplify we'll see you in Vegas.
Speaker D: This is kind of a two part question here. The first is as teams are developing more confidence in AI because the analysis is good, the recommendations are great, you know, you start to move to where AI is not just making strong recommendations. I mean, maybe it's even, you know, maybe not Actually like pushing the button to affect a decision. But it's like, hey, this is the call. How does that change the governance conversation? And particularly if you're like a cfo, this is kind of the second part of that conversation. Uh, how does that shift the discussion with, you know, your, your audit and your risk team who are really going to want to be thinking about, well, did we ask all the right questions when making that decision today? I consider everything, and that's to say nothing of, let's say, like, financial reporting or other type of reporting that would have like traditional audit requirements. I mean, I'm even thinking about, you know, just operational efficiency and productivity from just an overall business results standpoint. You know, how is AI sort of changing the conversation?
Speaker B: Those are two, uh, good questions. So maybe the first one, I hear some conversations, uh, in, uh, across industry that the simple fact that we're doing agentic AI, that the agent itself is a risk, and actually would, I would challenge that. Like, you know, it's not the tool necessarily, it's the risk. It's how the tool is used and what's put around the tool that creates the risk. So let's sort of think through, you know, how, how a risk team might approach agentic. You could argue we, I would argue the use case is where the risk really lives. So am I going to use an agentic thing to like, automate? I don't know how I turn on my, you know, automatic lawnmower that'll like cut the grass on my, you know. I don't know why I use that example. What a terrible example. Let's say that was the thing. Pretty low risk.
Speaker D: My son's mowing the lawn right now. The, uh, sound must be carrying through. There you go.
Speaker B: That's totally what it was like. Let's say that's the thing.
Speaker A: All right.
Speaker B: That idea, that project comes in, that's a low risk thing. Here's what I need you to do. Business. Thank you for telling me. Just do these two or three things. Great, right?
Speaker A: If I come through and I'm like,
Speaker B: I'm going to use an agent to automate all of our compensation analysis and make compensation pay, uh, changes and enter all those compensation adjustments in my sort of like, you know, compensation management system. And, you know, it has access to my bank account. Let's just sort of play that out. Okay, hold on a sec. Mike, I actually need you to do a little bit more. Right. And here's the things that I need you to do in. In those examples, whether it was like A, uh, deterministic software or an agentic system, the risk still lives in what I'm going to do. And so I think that approaching these agentic applications, you can enable them to make decisions. If you do that, and if those decisions are of greater consequence, then you should have greater governance risk management in sort of a control around those applications. I think this is an important point, you know, Steve and Mike, because, uh, there is a sense that, oh, uh, my company wants to use agentic. I need an entirely new paradigm for how I think about risk because now I'm using agents. Actually you can catch a lot of this with a good, robust, generalized enterprise risk management posture. Right? Or sort of a broader AI governance risk posture, um, that is still sort of triage risk, apply governance, commensurate the risk, verify that those controls have been managed appropriately. So ultimately, did I mitigate the inherent risk in this thing by effective application of controls? And I think that flows perfectly into your second question. CFOs and audit, that's their language, right? Like control verification, efficacy of controls, measurability of the impact of risk reduction. Right. You can't do any of that without good, measurable and executable controls and tactical components of a, uh, risk management program. So what we are starting to see a lot more of, and I'd love your both opinion on this, is, okay, we're at a place as a company implementing AI and investing in AI that how's it going? Like, are we achieving the results we want? I'm a publicly traded company. I've said I'm spending 150 million on AI. What happened with it? Right. Where's my accountability of that spend? I have a board that's asked, that has a compliance committee, and I need to read out to them on all of my risk registries and my sort of status of risk posture. How am I quantifying my AI exposure? How am I demonstrating that my governance program is mitigating those risks? Um, and so I think these two things then come together, right? Such that if I have a fundamentally good risk evaluation program upfront, that is not as much about just the gentic, but more the use case and the materiality and the consequence of that thing, and I build a good program to mitigate those risks and measure my mitigation, I'm now more prepared for the CFO or audit to come in and verify what did we actually do and what was the impact of what we did. And that is a gap today. But we're starting to see the CFO and audit it's such a powerful role as that second third line dynamic and sort of like relationship with the board shows up and says, hey, Steve and Mike, I love all the AI investments we're making. We've got an inventory. We say we're responsible. I like to get my hands dirty a little bit and actually measure. Are you getting the ROI that you forecasted? Show it to me. Have you mitigated this risk of drift? Prove it to me. If I'm an auditor, I have a control that says, I tested for fairness. Where's the proof that I did that and that it was done the right way? I think it's an exciting moment for AI that that's happening because that will create a pressure that improves the quality on the front end. And that loop is now going to mean that we're like, professionalizing how we do AI inside a large enterprise.
Speaker D: And this gets back to the audit and the risk conversation. We actually have a pretty good mechanism today through, like, let's say, a SOX control framework that's meant to, you know, prevent financial misstatements. It's meant to reduce, you know, fraud. As an example, we have a way to identify the processes in an organization that kind of try to accomplish those two things. We sort of collect those and categorize those as SOX controls. They're subject to certifications and testing and that kind of thing. You could certainly do that with AI. And then kind of the third thing that I've heard people talk about is like, hey, when you're going through that initial brainstorming, you know, Anthony, that we talked about earlier, like, hey, we're just going to continue to talk about this. Could this be something that I could, could, could help with? If the answer is yes, how do we align early on what the goals and how we're going to measure those goals and what the objectives are? You know, that's one thing that our CFO has actually been very good at, is being really clear. Let's go out and experiment. But as we are doing that, let's start to collect that information and make early determinations about how we're going to measure that success and again, use the information that we collect in order to monitor that. I mean, those three things I heard almost consistently across the conversations I having in the last, uh, couple of months.
Speaker B: You know, Steve, I love those, and I think those are great examples of that. Those aren't new AI concepts. Those are good organizational, execution, measurement, control concepts. I mean, when we started in 2019, my co founder is a former IT auditor. He wrote a lot of the early guidance for Isaca on how would you build assurances around IT systems like we didn't approach the AI problem as there's nothing to build from, start from scratch, there's no existing patterns. There is first, second, third line. There is objective, challenging, there are, you know, socks controls, there's software development controls. What could AI controls look like? Uh, I really appreciate how you explain those things because I actually think that makes AI so much more approachable for an enterprise when they can pattern it into some strengths and muscles that they already have.
Speaker C: Yeah, I like the, what we keep coming back to is this isn't brand new, it feels new, but the stuff you know how to do when it comes to governance and risk, keep thinking that way. I think like you said, it makes, it makes it feel less opaque, less scary for uh, a part that does feel very new. And maybe I'm wrong here is when we're talking agentic AI, when a model takes an action autonomously, who, where does the buck stop? Who, who ends up being accountable for
Speaker A: those actions when it's the robot who's doing it?
Speaker B: Yeah, great question, Mike. And I think it is a slippery slope to not overly simplify and trivialize AI like oh come on, we know what we're doing, just do it right. And I think it is, there is a fine line there. So it's good to sort of call that out with this example before the system ever got to a place that it could make decisions. Back to using the word project again, that system did go through a journey. It started by somebody saying, what am I going to build a system to do? What is it allowed to do? What is it uh, not allowed to do? You're going to go through sort of selection of training data and context to give that system to help to sort of tune it and optimize it for what it does. And then before you ever deploy it, you're going to do, hopefully you're going to do a lot of really robust pre deployment evaluations and testing. How will it perform in these situations? In those situations you will understand and have an opinion about guardrails, where I let it go or I don't let it go, what systems it does have access to, doesn't have access to. And then you're going to encode those rules back to your infrastructure comment earlier. Encode those rules and then you're going to have some monitoring to make sure it doesn't violate those rules. So what I would say is like there was a lot of accountability for Very important jobs along the way before it ever got to a place that it was making a decision. So when earlier I said the agentic itself is not the risk, that's sort of a way to articulate that is like there's all these things that got to the risk was the decision what did I do to control for the variability and the accuracy of that decision. There was a bunch of things that got there. What I would simplify and say, and this is good, the business owns the decision that system made and it's so important that we have our business leaders feeling that appropriate accountability for. I'm giving budget to my tech team. I can't just walk away from that. I should be supporting my tech in my risk Org to make sure they have the tools and the resources they need to build accurate agentix systems. Like I know there's a lot of chatter like AI being sued. Right. I uh, think we've seen some AI things have you know, litigation and events, the company is liable for that. And so it is a shared responsibility model. But there's a project owner, there's individual steps. And I think that's also maybe to Steve's comment earlier, if you isolate those steps in some way, those individual controls, you can better then evaluate who didn't do their part of this to avoid that from happening. Instead of a group worked on this project, I don't know who did that part. So I think that that's also a uh, key piece here Mike is understanding what contributed towards the event. When the event happens, identify it. I triage what caused it. Was it a bad guardrail? Was it bad testing? There, there should be the ability to find, you know, the root cause there so the business is accountable, the system is not accountable. The idea that like you know, agents and AI are completely going to create their own patterns and be, you know, self sustaining or self accountable applications, I challenge that notion quite a bit because I know how much goes into the human orchestration and testing and validation of those things that can help to protect from, you know, good or bad outcomes. What do you think?
Speaker C: I agree. I'm a podcast guy, I'm here to learn. I think what you said makes a lot of sense is that yeah like to be like oh the AI did it feels like a uh, pretty flimsy legal uh, excuse.
Speaker D: Well and I think you know, if I analogize this back to like a SOX control again I don't mean to indicate that it's going to be quite that simple but you know, for Exox control or actually any Control. You would have a control owner. Right? You would have the person who is responsible for that. And I think indicating that ownership not only makes that clear organizationally, kind of where the buck stops, but it actually helps that individual understand what they are and are not accountable for themselves. So to go back to your compensation example of, you know, agent, uh, you know, like real time making comp changes, even like dispersing, you know, bonuses and payroll and that kind of thing. Well, if I'm the comp manager, who is responsible for that agent, I'm probably going to think about that very, very differently than, you know, if I was just one member of this big, broad, nebulous group that was, you know, working on AI Generally.
Speaker B: Most companies have committees today. Committees aren't accountable. Right. And so they can be steering, but they in themselves aren't the, uh, where the buck stops. And so that project example you gave, who's the business owner responsible for that thing? You want them to feel the opportunity and the risk of. I'm comfortable with this system being used. And how do you create that confidence for that person? That's the opportunity space here. Right. And those that do it better are winning, you know, those that are not, I think, are starting to fall behind.
Speaker A: Thank you again to our guest, Anthony Habayeb, and thank you for listening. That's right, you right now, you mean a lot to us. This has been the preread brought to you by Rekiva, the world's only unified platform for financial reporting, sustainability, audit and risk. We've got more insights and hot takes coming your way, so be sure to follow or subscribe on Apple, Spotify, YouTube or wherever.
Speaker D: Get your edge.
Speaker A: And if you like the show, please leave, review, send it to somebody. You know, word of mouth is the best. Stand on your office rooftop and shout it out. Or you know what, just bring it up on your next team call. We'll see you next time. Until then, go lead it like you mean it. Your hosts are Steve Sutter and Alyssa Zucker. I'm Mike Gravani, the lead producer and occasional host. Fill in audio engineering by Faith Springer, Drew Hayes and Tanner Heinrichs. Pedro Sousa is our graphic designer. Transcripts are created and edited by Courtney Gipsey. Thanks to our digital and social team, Mike Berg, Katie Carr and Mike Kranowski.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.