Summary
- Explores how AI governance intersects with data and security governance.
- Examines continuous testing, validation, and incident response for AI.
- Addresses oversight for models, retrieval systems, and AI agents.
- Shares practical steps for scaling governance with enterprise AI.
Chapters
This is the Data Explored webinar series, hosted by Action. My name is Ole Olsen-Bernoe. I'm the chief evangelist here in Action, and I explore the evolution of data and AI in this webinar series, together with thoughtful and influential guests.
And my guest today is Dr. Andrea Isoni, a longtime expert in security, everything governance around data tech and AI, but in particular AI. That's why my attention was drawn to you, Andrea, in conversation in real life here in London a year ago, and since then we began speaking.
I would like you, if you don't mind, to introduce yourself a little more before we jump into the question and also the topic at hand today. I'll be introducing it more, but basically, this is a deep conversation about AI governance. I prepared a lot of questions, and there will also be time for Q&A.
But those formalities I'll take in just a minute. Andrea, please go ahead and introduce yourself. First of all, it was pleasure to be here, and thank you for organizing that, Ole.
Yeah. My name is Andrea Isoni. I'm not too big in these kind of self-descriptions, but I'm an academic translated to business.
Basically, I have a PhD in computation fluid dynamics, math stuff, and then straight after that, excuse me, finishing 2014, I went into what it was new at the moment. It seems old now. It's weird, but AI seems old, right?
It's weird, but AI started in 2014. Maybe it was a couple of years older when in San Francisco, things like that, but not too old even there. But yeah, so since 2014, all I'm doing AI, increasingly more for obvious reason we're going to discuss is AI governance, because if you read the news, definitely there is a problem about safety and security of AI.
I'm not discounting that at all, although there are caveats why certain company portray certain things, but this is another story. Yeah. We'll get to all that.
That's another story if you want I say that. But, yeah, so all I'm doing since 2014 is running or actually doing AI project myself, okay? And now with an increasing more focus on the AI governance because from the moment in which the LLM started to take over, the time where you actually develop yourself from scratch a model, you train from data, et cetera, et cetera, is ending.
The most you do is fine-tuning a model. But on the other side, you need to secure and check the model way more. So you do less of the training and more of the AI governance.
That's the shift since 2014, the major shift I've seen. And why I'm going there is because what we're going to talk today is how we can define our governance, which depends on the data governance, the security governance. Yeah, it's something separate to the rest, which we were going to try to disambiguate these three type of governance, right?
Security- Absolutely ... data, and AI. Absolutely, Andrea.
Before we jump into that, let me just set the stage by saying we have about 40 minutes left. It's a 45 minutes webinar. So, we'll be doing approximately half an hour conversation, and then a Q&A in the end.
I have more questions than I have the time to answer. But please, everyone, feel free to chip in. I'm happy to take all the questions that you have.
This is obviously a new, for many at least, it's a new topic, but what made me very interested in asking Andrea about all these questions is that you have been working with exactly this topic for so long time that you are a true expert and not just a lucky go-happy expert that changed their title and now talks about AI. You have deep knowledge about this. So that's why I wanted to ask you all these questions that I have prepared.
First of all, exactly as you mentioned, you say that AI governance is so fundamentally different than previous governance regimes, and I think we should kick off by examining some of the prior governance regimes so that we understand why. So maybe let's unfold or unpack the conversation with data governance. For you, what's data governance?
How did that emerge? And then later let's talk about how it taps into AI governance. What is data governance in itself?
Yeah. Data governance is the set of policy, procedure, testing, incident response related to the management of raw data to become hopefully as close as possible to quality data or well-managed data in a way or in a form, right? And obviously lineage, standardization.
You are expert at all these things definitely no need me. But that's what data governance should do and is the basis of anything you do on top. Yes, absolutely.
So basically, another prior regime to AI governance would be security governance, and these lines are fine to draw. I was discussing internally in Action whether or not you could actually cut it up in these ways. We can blend them, and that's the entire exercise, trying to understand what is what and how it works together.
But basically, now that we've talked a little bit or unfolded data governance, what is security governance? What is that? I remember it from more than a decade ago emerging.
Well, yeah. It's funny, but the temporal emergence of these governance, as you say. Because first there was the internet, that means you need security governance and so on, right?
And then at some point you have the data, just to give an historic and setting the stage for the audience, at some point, due to the fact that people using the internet, we were generating some data on the internet that can be used for recommendation stuff. That's the early thing, right? Recommendation books on Amazon or whatever product you want, right?
So that's the early stage of data collection for a commercial use. And anyhow, as you asked it, security governance is, again, it's the same word unfortunately, but I have to repeat it. Policy, procedure, testing, incident response, register, or things like that, that allow a company first of all to have visibility inside who is using what or not, if there is a breach, et cetera, how to solve the breach and what to do when there is a breach.
Yeah, they allow the company to first secure if something happen... By the way, something happen naturally in any case, in any governance. The role of any governance is not to guarantee nothing happens, but to first of all diminish as much as possible the malicious cases and have the best mitigation possible when naturally things happen.
That's why any governance exists, just in case someone thinks the governance is to be bulletproof or anything. That's not the reason. In fact, it's impossible.
Yeah. It's a fallacy to think that way. Yeah.
But yeah. Security is about securing your own infrastructure against malicious purposes, intent, or actors in any way or form, and what to do when some malicious actor infiltrates or does something malicious in your data, company infrastructure, whatever that is. So I want to ask one more question just to set the stage for the rest of the conversation correctly, and then there is a great question in the Q&A.
So, therefore, I'll go ahead after that question from Jewel Darlington, and we'll get to that question, Jewel. I'll just ask a last question here to really set the stage because, okay, we talked about security governance, which came after the advent of the World Wide Web and the entire security paradigm surrounding the internet and the flow of data through this open structure that the world had not seen before. Then came data governance, which was really about governing the state of the data itself, how it flew through the structure.
So not only the size of the cables and the servers and everything that security revolves around, but also the data, deeply measuring the data quality, who can access what and so forth. And now we find ourselves in an AI era catapulted forward by the emergence of large language models three, four years ago. And in this era, a new governance paradigm is emerging, which is AI governance, which is a really, for us in the present, maybe in 20 years they will smile, but for us in the present, it's extremely difficult to understand, okay, how do we actually govern AI?
How does it differ? What can we draw upon from the previous governance regimes? So how is all of that linked?
So first of all, Andrea, can you go ahead and provide some overview of what is AI governance? Yeah.
So, again, I'll do the quick definition, but it's best to have an historical understanding why it's so difficult, or at least why I think it's so difficult to disentangle AI from data, AI governance from data governance, and say, "Oh, but data governance is the same, right?" No, I tell you why, or at least why I think that. So again, the definition is the same, right? The set of policy, procedure, testing, incident response when an AI model does something wrong.
If naturally something wrong happen, you have an incident response, a mitigation strategy, a way to solve the situation, and hopefully not do that again. So basically, a feedback loop to send and change the procedure you already had up. As you notice, it's the same kind of word for all the three.
What you do in this world is different, but the wording is naturally the same. I think I want just to add that very quickly, the reason why it's so confusing is because there was, at least now it's paid off, rightfully so, but it's still sticking the mind, the idea that data is oil, everything is in the data, which is partially true, okay? Data is absolutely important, but it's not everything.
No. That's the problem. That's why people confuse.
The moment you think data is everything, you don't see the value in AI governance, right? That's a problem, I think, historically. We come from the idea that data is all, everything is the data.
Therefore, if I do the data right, everything will follow. Sadly, it's not enough. That's a problem.
That's why I think people struggle to understand that, because they come from this mentality that was portrayed in the media for a long time. I'm not saying it's wrong, it's just not enough. No, I will cut you off because I think it's actually, please, it is extremely correct what you're saying, and the way I'm phrasing it is that it's a data-centric view on things.
It's a kind of bubble where data management practices and technologists focus so much on data itself that they think it answers all of the technical issues in a company. And I think we do data, and I don't say this to bash any kind of data management principles. Yeah.
I just don't think we govern data correctly if we have this kind of view. And so now you're saying it's really limiting us in terms of AI governance. Exactly.
And by the way, we don't touch on that because nobody think about that because once you go on the data, at some point, you need to use this data. At the moment you use it, you have two way to use the data, right? Either an AI model use it or a person use it.
Now, we don't have a human governance yet, but watch out. At some point, we'll also have a human governance in. Okay, we have this.
How I'm sure, again, set a process, procedure, incident, so that the human will know something wrong or do something wrong with the data or the AI model, let's say the human governance. But I would not be surprised at some point we get to that, too. But for sure today, we are at the initial state of realizing that we have something on top that use the data, okay?
And that new thing somehow, somewhere, can go wrong by itself. That's a point. It can go wrong by itself.
Therefore, you need a set of procedure or, again, the policy, incident response, to make sure it will not go wrong or at least go wrong as less as possible, right? Mm-hmm. That I don't see any easier way to say it.
Whatever interact with the data and that thing interact, as in does something, that thing somehow need governance at some point. Yeah. If that thing is an AI, there will be an AI governance.
That is ugly to say, but that thing is a human, so it's not a thing, it's a actual human. At some point, we'll have governance too at some point out through today. By the way, we already seen that GDPR, right?
GDPR is the user of human, of data. Yeah. If you want to see that way, it's a human governance, right?
GDPR is human governance. Absolutely. Once you have the data, there is a way to hopefully clear that.
I think also, it is quite important to have in mind that when we talk about AI, it is not, as you exactly mentioned, it is not only the data used by AI. Yeah. It's the mechanism itself.
So it's more like managing an application. It has versions, it has integrations, it has a lot of things that has nothing to do with data. And so basically, I think that we have some questions.
So instead of me asking the questions, I'll ask the questions from the participants. I think that is way better. So Jewel's question first.
It's a long one, so sit tight, Andrea. All right. At the executive level, how should organizations determine where accountability sits when the data is properly governed and the security controls are functioning as intended, but the AI system still produces an authorized or materially harmful action?
Should I read that again? Okay. So data governance- Before you read it, in case you want to specify, he's talking about a different level of maturity between basically the AI governance, which is already starting, so something is already wrong, and an established maturity on security data governance.
But I ask in the person, so in case he can clarify more his question, but please read it again just in case maybe he's already there. I think the question is spot on, right? Because what it's saying is actually Data governance is working, security governance or security controls functions as intended.
So those elements, those governance disciplines, they work. But an AI system still produces an unauthorized or materially harmful action. What should the executives do?
Where should they place the accountability for that kind of unintended action from AI solutions if data governance and security is working? First of all, in a way, we are going to be very circular in this conversation. And bear with us, it's the nature of the thing.
What I'm trying to say, if you read the paper, the moment you're telling me, in the exact question, he's assuming that he's already knowing the fault is in AI. Okay? If he knows that, so basically from an output-- So he has the output, the output is wrong, and he's already determined, okay, the data is not...
When I say the data, not the data because he checks separate. The specific data that was ingested by the specific model, they're receiving the output, not just we have data separate, just to clarify, because otherwise. And the security or the specific solution he's using, et cetera, have already been checked and nothing is there.
That means it's either the training of the model or the fine-tuning of the model, or the way the data, which is already clear and good quality, is being ingested by the model somehow, or the pipeline, data pipeline as before, whatever that is, that where the problem sit. Okay? Okay, so what you're saying is that the executives in this specific situation should examine the architecture surrounding the architecture of agents or the specific model in question, and that the problem will reside in those elements and not in the data that fed it or in the security.
Correct. Exactly. But that's by exclusion, right?
But that's already in the question, right? It's basically by exclusion. I already checked the data was ingested by the specific model.
It's not. Then by exclusion, must be this. Okay?
And the question, just to clarify, is, at what level of, what did he say? At what executive level should be responsibility, something like that, right? Yes.
Where should accountability be placed, basically? Okay. All levels.
If you remember when I say the definitions of policy, procedure, testing, incident, that means all level. So there will be a policy level, there will be some people. Okay?
Then there will be procedure level. Procedure means I have a way to train the model and test the training of the model, and I structure the way to test it. I may not be the person that press the button to test, and that's the testing level.
The actual people that every week, every month, depending, they actually press the button in the computer or they write the Python script for the testing. Yeah. And then they execute it, and then they record it.
Today, 22 September, in your case, 5:22 PM, I record it, and this was the result. And this is another level. But he has a responsibility of doing the testing correct, that person.
If something goes wrong, he has the responsibility to report that this test was not. If not, either you trigger an incident response or something sort, or if it's minor, it trigger a reconciliation with the policy and the procedure in a week after because it's a minor event. Okay?
But it sit in all levels. There is- Yeah ... a person responsible for a specific thing within the governance.
Like you would do in data governance, I think, in security governance, you would do exactly the same. Yes, we would. It's sort of all connected, which is why it's so important that these teams work together.
That's a different story, but it's often not the case. We have two more questions in the chat, and I think they're all pretty good, so I want to go ahead and ask them. The next question is from, yeah, someone that does not want to use their name.
It's okay. The question is quite simple: Is AI governance, in the end, a marriage between data governance and security governance? If you want, you can explain it more, but at face value, what you're saying is no.
Because at the end of the day, what you're trying to do is something separate and uncorrelated to that. Understood. Because if it was already correlated, by the way, you break also the governance because it's self-judging yourself.
Right. It's in a tangent, but not too much. That's why sometimes I'm not too keen if whoever is a bit technical in the audience is self-judging at the LLM, LLM as a judge, this kind of mentality.
The problem of doing a governance, then the LLM itself judge itself, you go in a circular way, you break the independence somehow. So you need to be careful. So when you say it's a marriage, the problem is you need independence thing.
Right. Otherwise, you risk conflict of interest within the thing, within the different body, et cetera, and that can break the purpose itself of a governance, which should have some sort of independence. Okay?
But please, if I didn't get it, please clarify. But the most important thing is to understand that AI governance is a set of policy, procedure, testing, incident response, et cetera, to understand if a model has been trained correctly, define tuning was correct. If the output follow a certain layout, if you spec...
Excuse me, if in the fine tuning or the skills enclosed, whatever that is, you specify a certain layout of the answer, is it respecting that? Is it deviating sometimes? Why?
Why not? And when it's deviating from the layout, the simplest thing of your answer, what you're going to do? Is it because of the training?
Is it because if it was the data ingest different than before, then okay, then we need to structure it. But if it was just because the fine tuning went wrong in the specific version, then this is an AI problem. Yeah?
Yeah. Or you maybe changed, or simply as we use, what's the name now, Fable 5.0, and then it's 5.1. The moment you switch the API, something change it, and therefore, the model just mislaid a little bit.
That's nothing to do with AI governance, right? It's just because you changed slightly the API. Simple thing.
That's within the AI governance stuff. Yeah. I give you the simplest possible example just to make the point.
Nothing to do with the data. If you change slightly the API, nothing to do with the data. You just slightly change that, and for that reason, it need to change a little bit.
Yeah, absolutely. No, I hope the listener also finds that clear. There's a third question in the chat that I would like to ask.
That is from Mihir Mohanty, and the question is: What you're describing sounds like resource governance, like access, capability, control, et cetera. What about the intent-based governance for the AI as a whole when we're trying to implement an enterprise process? Now we need to get different technicalities, and there are full workshop on that, but there are different ways to do the, what you call it, intent or the safety.
I can give you idea of two main approach I use in practice, for example, in defense or certain financial organization. To give you an idea, I elaborate a little bit more on the intent, but to give you an idea of the different approach you can use. For example, one is the impact plus likelihood.
What I mean by that, whatever the AI solution you got, yeah- Just the AI. So you fine-tune or whatever, or you use just the API, but you did a pipeline of agent and data. Sorry, agent with the data, but the data is already per se, right?
You're just ingesting that. So you have structure and an agentic solution with different agents that do whatever, okay? You have two way to do the AI governance.
Data is the impact times likelihood. So you first define a risk assessment of the solution. Like I go simple, a customer service chat, and the risk is you can insult the client.
Something simple. Yeah. Just to give an idea.
So what you're going to do is the impact, okay? And one to five, you manually, by the way, there is no way out. There is a human that take responsibility to judge.
And the impact is, okay, we may lose the client. You give impact of three. The likelihood, the probability that happens, maybe four because I don't know.
It may be two. By the way, this is depending on the situation. I'm not saying that it's strictly three or strictly four for a customer chatbot.
I'm not saying that. Because there is a person that actually evaluate. Based on this risk analysis, what did I say?
Likelihood four and impact is three. Based on that, you define the testing. Okay?
Since it's very frequent, we need more frequent testing, for example. But since the impact is low, we want less testing. If the impact was very high, you want a lot of testing, testing robustness of the model- Yeah ...
testing exactly the same data, but the impact was low. But we want frequent because that happen often. You see why that's an approach.
Yeah. Andrea- The other approach is completely different, for safety. Yeah.
For example, nuclear reactor or nuclear facilities, whenever... By the way, this is beyond AI, but it can be related to AI stuff. I don't want to get into the detail, but they don't use the impact times likelihood.
They use something called safety property. So they have an AI system again, and they define proper-- They want to check robustness, vulnerability to attack. They have this, and then they try to maximize the testing for each property.
So okay, how can I test the vulnerability of this specific model? They think about testing of that robustness. And they do that.
It's a different approach, but it come from a different angle. In a nuclear plant or a electricity plant, something like that, they need a super focus on the model property, safety properties. Yeah?
Mm-hmm. That was more commercial. So it's very long and very complex.
But all I tried it in few minutes to give you a broader perspective of the different approach you could have into- Yeah ... this governance. And hopefully, you can see there's nothing about the data yet.
I'm talking about the approach to the, as you call it, the intent of the model to check that somehow. Absolutely. No, I get you.
The questions are simply, it's very nice to see, they are simply popping up at a speed where I'm not sure we can nail the answers to all of them and the questions that I have left. So this is great, but I want to keep going. I'll skip one question in the queue and get back to it because I think you were answering Mihai's question, and there's a follow-up.
Mihai is asking, "So you mentioned three parts to AI governance. We have two, data, security. What's the third one?" Model, I guess, you would call it, like the agentic architecture.
Yeah. Would you call it the model? You can put it.
Absolutely. At the end of the day, if you have a model, it's one agent. It's- Yeah ...
brutalizing, I know, but one model is one agent, roughly speaking, right? Yeah. The reason why you never say agentic before, because at the end of the day, it was one model and doing something, right?
One model rarely was interacting with that. We are now at a stage a different model can interact, do different stuff. That's why we invented this new word, agentic.
But before- Yes ... we were a single agent for years, basically. Yeah.
But- So I guess that is the answer. There's data in the model, there is security, and then there is the model itself. Yeah.
Or the agentic architecture, combining multiple agents- Yeah ... working on basis of various models. Data.
Yeah. Then the anonymous participant asked a question earlier, and it's following up, I sense, or maybe this is a new question. But when people speak on information governance, is this a dynamic umbrella term that now includes records management, data governance, and AI governance?
I don't know if you've heard that term circulating, Andrea. Personally, I find it a little sitting on the periphery of the topic. Say that again.
So when people speak on information governance- Okay ... is this a dynamic umbrella term that now includes records management, data governance, and AI governance? Yeah, look, information, for example, in ISO, the actual term for security version is information security governance.
So it's a bit of a generic term. For example ISO 27001, if I not mistake, is information security, not just security stuff like that. Yeah.
So it's a bit of a bad word, but I wanted to go the question before when they say data in the model. Training the model, sure, you can do AI governance just for the training, but most of the AI governance today is not to govern the training of the model, it's to train... Sorry, it's to govern the when it's live.
The addition of it. Yeah, absolutely. It's future.
When it's live, not when it's training. Usually, you don't do AI governance when it's training, okay? Just to clarify that quick.
So when you say the data in the model, that is already what you care about in a governance situation. When the model is live, it's serving client or whatever, and there is a risk. When you're training the model, what's the risk?
You're inside your company. It's a cost for no benefit, right? When this model is already trained, and then it's serving client, now you have some sort of risk, therefore you have a governance.
You don't do governance in a training phase, just to clarify. Yeah. No, that's an important point, right?
Because at the end of the day, governance has to be justified from a financial perspective. Correct. And so it's when it's interacting in- There is a risk of some sort.
Yes, in a context where there actually is a risk, right? We have a question also from Romain Alemo. I hope I'm pronouncing it correctly.
And the question is, "What do you recommend to enable AI across an organization and avoid it being only a topic for data office members? How to foster AI use cases of simply data-driven problem-solving outside of data-fluent people's circles." So how do you enable AI across an organization so it's not only sitting inside what I referred to earlier as the data bubble, I guess I could say. Does it make sense?
The question is whether or not you... Maybe I can rephrase it like this. Yes, please.
Amongst your clients, Andrea, do you see many projects, AI governance projects or AI projects altogether, that is anchored in data teams, or are these projects more anchored in more direct line of business teams or- Yeah ... teams? No, it's the second one.
That is kind of a Granted, it's not the right there, but put kind of aside as in you have a comment when at least the client I got over the years, and even more so now, they want a return of investment. So that means they are already thinking about a solution that somehow generated some return or whatever metric you want to do. Therefore, unless it happened a few times, the solution is to make the data storage or anything more efficient.
But this is a corner case, right? You need to do the data in some sort of efficient. But apart from that, it's more commercially driven rather than technically driven.
Mm-hmm. Yeah.
Which is quite wonderful, I have to say, because- Yeah ... there's nothing worse than being in projects where you sense that it's driven forward by technical curiosity. That needs to be there, of course, but it's a real pleasure to be involved in tech projects that actually make a difference.
Okay. There's a response from the anonymous attendee that governance needs to be applied at every stage of an AI system lifecycle, meaning that you need governance during model training to ensure that you're on training on biased data, for example. What's your take on that?
Biased data by definition is data governance. By definition, right? Nothing to do with- Yeah ...
no, no, no. So- By definition, if you have a bias in the data, that is beyond that, right? I mean, beyond the algorithms.
Yeah. I like that distinction. So you're actually not saying that the person asking this question is wrong, it's simply something that it has to be expected, before, the training of the model that a data governance activity has actually resolved that bias.
Or maybe it's a borderline case. Sure. Okay, we train the solution, we see there is a bias in the output, and then we can understand, or we should understand, okay, is the bias because the data was already biased, and then there is, again, a data governance problem.
Or for whatever reason, when we did the training, we introduced another bias. Mm-hmm. Sure.
But again, if you see it's the same, first it's the output, and then from the output, you try to understand where it's from. But look, for bias, it's very difficult. Well, everything is possible, who knows?
But if I had to bet, usually it's data governance. It's not because I want to blame the data guys, not that, but it's usually within the data. Yes.
No, I think as a data guy, I'm happy to take the blame on that one. I think your distinction is correct in the sense that you need to address the problem where the problem can be resolved, right? Yeah.
And cannot really have an AI governance team doing data governance work outside of a data governance context because then they can do the actual manual effort, or they can use an agent if they're smart, to wipe out that bias. But it would need coordination with the data governance team, right?
Sure. Actually, anonymous guest, great question. Thank you.
Mihir is also following up, and I think we will close the questions with Mihir's question because I will wrap up with one final question, and then it's actually time. We have only four minutes left. This went extremely fast, and I can see the vast majority of participants state on how we have a last question coming up.
It was so long. Let's see if we can get through all of it. Mihir is asking, traditional governance is mostly reactive, log-based, or some exhaust data.
In case of AI, that is too late. How to implement it continuously so you can say real-time governance, how do you do that? Because it changes so fast.
Yeah. Again, the purpose of, in general, governance somehow is reactive, right? You have an incident response, and you learn from that.
Again, the mentality of governance is not we need to be always 100% safe or no errors. That's not the mentality. So I will back a little bit from the mentality, first of all.
That's not right. Thinking that once you do the right governance, everything should be right, that's not why you do it that. You're doing just because you want to minimize the error and learn from that quickly and as quickly as possible.
Sure. That's the first thing. Again, I will be, excuse me, quick on this.
Now, as I briefly mentioned in another answer before, I quote things that we've been experimenting or I've seen like some sort like LLM as a judge. Obviously, if you will put another LLM or another AI to check the other AI, you can be real-time, right? Because there's no one really checking and therefore can go as quick as you want because it's an API to check the other API, et cetera.
I see a little bit of risk on that. By the way, the more you do all of this, the more the security risk increase, right? Because not only you need to secure the original API, now you need to secure another API that judge the first one.
So in a way, the blanket is always too short. In a way, you move in the blanket at some point. There are for sure way to automatize some testing, et cetera, but the more you automatize that, the more you are exposed to different cyber attack.
Yeah. So sure, you will say, "Oh, now in real time, some better AI governance." Yeah, but you got worse in the security one. Yeah.
So yeah, you're moving the blanket. Yeah. Mm-hmm.
Yeah. So careful with this kind of thing or mentality. Okay?
Yes. Yeah. That's a great perspective.
And I will skip my own final question and condense the last question that we have in the chat from Mark Doherty. And basically, I'll condense it into the question, do you think that governance activities altogether, data governance, security, and now AI, do you think they can have a single repository documenting the activities of this governance in place? What do you mean by that?
Single repository as in...? The proof that the governance has been conducted. You mean the registers?
Yeah. So the register of the testing. Yeah, exactly.
Yeah. In fact, yeah. So spot on.
So what I mean by that, so when I do workshop, AI governance workshop, and then at the end of the day, I usually give you the rule of thumb or hint, quick hint to implement tomorrow. One of the things that I say is exactly this. So the guy, the actual guy that do the testing of AI governance, since it's Python script or whatever, it's very good in many situations to combine this Python script to the security test script, or if anything, the Python script.
So the same person can do that, therefore, he can record everything in that. Now, this is a rule of thumb. I'm not saying that every situation should be like that, just to clarify, because there are always corner cases or more than corner.
But look, in many situations, it will definitely be a cost-efficient and good things to do to combine many different script or testing or different security data, et cetera. Sure. Thank you, Andrea.
There is no caveat for everything, though.
Just a rule of thumb. Yeah. Just to clarify.
Yeah. Thank you. I think that's important detail to have.
We're over time here, so I want to thank you, Andrea, for joining Data Explored, a webinar series from Action. Thank you everyone that participated and asked so great questions. Please keep them coming.
You can reach out to us or to Andrea on LinkedIn, on Substack, and a wealth of other social media where we are all present. So please stay in touch. Thank you very much for your time.
Thank you, Andrea, for joining me. Thank you. Thank you for having me.