“/>
Photo credit: William_Potter/Getty Images
In Rubrik's IPO filing this week, tucked between the parts about headcount and cost breakdowns, there was a little hint that reveals how the data management company thinks about generative AI and the risks associated with the new technology: Rubrik quietly has a governance committee used to monitor how artificial intelligence is implemented in his company.
According to Form S-1, the new AI Governance Committee includes managers from the technical, product, legal and information security teams. Together, the teams will assess the potential legal, security and business risks of using generative AI tools and consider “steps that can be taken to mitigate such risks,” the filing says.
To be clear, Rubrik is not, at its core, an AI company — its only AI product, a chatbot called Ruby that it launched in November 2023, is based on Microsoft and OpenAI APIs. But like many others, Rubrik (and its current and future investors) are thinking about a future in which AI will play a growing role in its business. Here's why AI governance could become the new normal.
Increasing regulatory scrutiny
Some companies are adopting AI best practices to take the initiative, but others are pushed to do so by regulations such as the EU AI law.
Dubbed “the world's first comprehensive AI law,” the groundbreaking law, set to take effect nationwide later this year, bans some AI use cases deemed “unacceptable risk” and defines other “high risk” applications. . The bill also establishes governance rules aimed at reducing risks that can lead to serious harms such as bias and discrimination. This risk assessment approach is likely to be widely adopted by companies looking for a reasoned path to AI adoption.
Privacy and data protection lawyer Eduardo Ustaran, partner at Hogan Lovells International LLP, expects that the EU AI law and its numerous obligations will increase the need for AI governance, which in turn will require committees. “In addition to their strategic role of developing and overseeing an AI governance program, from an operational perspective, AI governance committees are an important tool for managing and minimizing risks,” he said. “This is because a properly established and resourced committee should be able to foresee all areas of risk and work with the company to manage them before they occur.” In a sense, an AI governance committee is called “Serve as the foundation for all other governance efforts and provide much-needed security to avoid compliance gaps.”
In a recent policy paper on the impact of the EU AI law on corporate governance, ESG and compliance consultant Katharina Miller agreed and recommended companies set up AI governance committees as a compliance measure.
Legal examination
Compliance shouldn’t just please regulators. The EU AI law has teeth and “the penalties for non-compliance with the AI law are significant,” noted British-American law firm Norton Rose Fulbright.
Its scope also extends beyond Europe. “Companies operating outside the EU territory may be subject to the provisions of the AI Law if they carry out AI-related activities with EU users or data,” the law firm warned. If it is some kind of GDPR, the legislation will have international implications, especially given increased cooperation between the EU and the US on AI.
AI tools can get a company into trouble that goes beyond AI legislation. Rubrik declined to share comments with TechCrunch, likely due to the quiet period of the company's IPO, but the company's filing mentions that its AI governance committee assesses a wide range of risks.
Selection criteria and analysis include consideration of how the use of generative AI tools addresses issues related to confidential information, personal data and privacy, customer data and contractual obligations, open source software, copyright and other intellectual property rights, transparency, output accuracy and Could raise reliability, and security.
Keep in mind that Rubrik's desire to cover legal bases could have various other reasons. It could also be there, for example, to show that it is responsibly anticipating problems, which is crucial since Rubrik has previously struggled not only with a data leak and a hack, but also with intellectual property litigation.
A question of optics
It goes without saying that companies are not just looking at AI from a risk prevention perspective. There will be opportunities they won't want to miss, and neither will their customers. This is one of the reasons why generative AI tools are being used despite having obvious flaws such as “hallucinations” (i.e. the tendency to fabricate information).
It will be a good balance for companies to strike a balance. On the one hand, bragging about the use of AI could boost their ratings, regardless of how real that use is or what difference it makes to their bottom line. On the other hand, they must be aware of possible risks.
“We are at this critical juncture in AI development, where the future of AI depends heavily on whether the public will trust AI systems and the companies that use them,” wrote privacy advisor to privacy and security software provider OneTrust, Adomas Siudika, in an article blog post on the topic.
Establishing AI governance committees will likely be at least one way to help on the trust front.
Comments are closed.