Aligning Responsible AI: Defining Ethical Guidelines for Industry-Specific Use

AI For Business


In this Help Net Security interview, Chris Peake, CISO and SVP at Smartsheet, explains how organizations need to define responsible AI to guide their development and use of AI. Masu.

Peake emphasizes that responsible AI implementation requires balancing ethical considerations, industry regulations, and up-front risk assessments to ensure AI is used transparently. .

Responsible AI

How should companies and governments implement AI responsibly to ensure ethical integrity, especially in industries that rely heavily on AI?

Responsible AI means different things for companies depending on their industry and how they use AI. So step one is to define what responsible AI means for your business. Consider the risks your business faces, the regulations and industry standards you need to comply with, and whether you are an AI provider, AI consumer, or both. For example, a healthcare organization's definition of responsible AI is likely to prioritize data privacy and its HIPAA compliance.

From there, we use our definition of responsible AI to determine a set of principles to guide the development and use of AI. Next, decide how to put the AI ​​principles into practice. For example, if one of your principles is to make AI systems understandable, teams can build AI tools to demonstrate their work and show customers how the AI ​​tools arrived at answers and insights. can be accurately understood.

It's a best practice to be transparent with your employees, customers, and partners throughout this process. Also:

  • Share AI principles publicly
  • Recognize the challenges you can expect to encounter when developing AI systems
  • Train employees how to use AI in a principled and responsible manner
  • Reveal exactly how your AI system works

Once you've taken these steps, you can integrate AI with your products and services to responsibly drive better outcomes.

Given the increasing integration of AI into cybersecurity, what are the most effective strategies to strengthen digital security against AI threats?

This is a moving target right now, as AI is being developed at a very fast pace. For example, with the advent of generative AI tools like ChatGPT, phishing emails suddenly became more sophisticated. We're starting to see perfectly grammatically crafted phishing emails that don't contain some of the telltale signs that we train our employees to look for.

The evolving nature of AI threats makes them difficult to defend against. While AI can be used to benefit an organization, it is also important to recognize that other organizations may seek to exploit it. Security, IT, and governance teams in particular need to anticipate how misuse of AI will impact their organizations.

One effective strategy for defending against AI threats is to continually upskill and train employees to better recognize and report new security threats. My team noticed that phishing emails were becoming more sophisticated, notified our employees, and evolved our phishing simulation tests accordingly. We also added a report phishing button to the sidebar of employees' inboxes, allowing them to report potential phishing emails with just two clicks.

What role does AI play in crisis management, and how can organizations prepare for AI-related failures and breaches?

As AI becomes increasingly integrated into business operations, organizations must ask themselves how to prepare for and prevent AI-related failures, including AI-enabled data breaches. AI tools allow hackers to develop highly effective social engineering attacks. For now, the starting point is to have a strong foundation in place to protect customer data. Preventing third-party AI model providers from using customer data also provides greater protection and control.

There are also opportunities for AI to help enhance crisis management. The first is related to security crises such as outages and failures, where AI can pinpoint the root of the problem more quickly. AI can quickly sift through large amounts of data to find the “needle in the haystack” that indicates the source of the attack or the service that failed. You can also use conversational prompts to display relevant data more quickly. In the future, analysts may be able to ask AI chatbots embedded in security frameworks questions about suspicious activity, such as “Tell me where this traffic is coming from.” or “What kind of host did this?”

There are also opportunities for AI to help with public crisis management. For example, in the event of a natural disaster, AI could enable response teams to more easily coordinate and manage rescue calls.

AI decision-making processes are often opaque, so what steps can organizations take to increase transparency and ensure accountability when something goes wrong with an AI system?

One of the most important steps is to document and publish how the AI ​​system works, including how public models are used and how data is protected. Encourage your team to be as specific as possible and explain in detail how everything works. Since generative AI is still relatively new and evolving, I wanted to take a scientific approach to this process, documenting what we know now, what we expect in the future, and the subsequent results. I am.

If you're developing an AI system, it's also important that the tools you're building demonstrate your work so your customers can understand the recommendations and insights the AI ​​provides. As AI becomes more integrated into our daily operations, explaining why will be critical to maintaining customer trust.

How do you foresee AI governance evolving and what are the key challenges and opportunities you foresee?

AI has great potential to enhance data security and add layers of protection. No one can manually monitor all the data flowing within a business. Intelligent systems must take on that burden. AI can grow to “understand” what is normal and flag what is not. This has the potential to significantly improve response rates and standardize processes.

One of the biggest governance challenges is the pace of AI adoption and implementation. Organizations are rapidly adopting AI, but some are skipping the critical step of informing customers about how they are integrating AI and allowing them to opt-out. This places an additional burden on security teams to ensure that vendors are not using AI without their knowledge.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *