Skip to main content
AI Safety Forum Australia
panelIndustry, adoption & educationCross-cutting

Industry Panel: Safe and Responsible AI Adoption

8 July 2026 · 1:30 pm–2:25 pm · Refectory

This panel brings together professionals who are putting AI to work right now and asks them about the decisions they're making day to day around safe and responsible AI adoption.

Recording

Speakers

Audience Q&A

Ask a question or upvote others.

Loading questions…

Transcript

0:03

Rishabh Gupta

Hi everyone. Thanks so much for joining us. I am joined by some industry titans in the room: we've got Rishabh from Suncorp. I'd love to hear more about what your role is there. Same as Amanda and Rajiv, but yea let's start with Rishabh. What does a responsible AI officer at Suncorp do?

0:23

Amanda Tay

Hi everyone, I'm Rishabh (Rish). At Suncorp I work as an AI safety manager and my focus is on ensuring that the way we are designing, developing, deploying, building, using AI in a safe, responsible and in a way that is aligned with our values, commitment and regulatory expectations. That's what we really do at Suncorp.

0:51

Rajiv Shah

I’m Amanda Tay, at ING. Essentially what I do and bring today would be the front-line perspective. And how do we create value for our customers, for products they actually want and need and want to use? And then how do we deploy that within our organisation in a scalable and sustainable way? My name's Rajiv Shah. I'm a director of the Australian Information Security Association, so that's Australia's peak association for cyber security. And so obviously I'm keen here to bring a cyber security perspective. My background comes from having about 30 years of experience, which is otherwise saying I'm really old.

1:23

But I used to work in things called big data and information security, and they were really boring, and no one ever wanted to talk to me at parties. And now I say I work in AI and I work in cyber security, and it's really exciting. And I even get invited to come up on stage and talk to you. In my day job, I work as a consultant and I work with governments and large

1:42

Jisoo Kim

corporate organisations helping to understand advanced technologies such as AI, work out how to do something useful with them, and also how to make sure they keep them safe and secure. So looking forward to sharing maybe some of those experiences with you.. Awesome. And just a bit about me: I'm Jisoo, I'm co-founder and director at ClearAI. We're an AI consultancy and implementation partner, but our tagline is Elevate Humanity. Basically me and two of my other co-founders, two years ago, we saw this oncoming wave of technology, and we saw all the hype, all the noise, all the snake oil salesmen, all the random plugging and playing and experimenting that was happening.

2:21

And my background is in national security. So for me, I was like: great are we now creating a really strong counter-espionage picture of Australia through AI tools? So I joined forces with my other co-founders and we're just helping businesses understand AI because, I think it helps that I'm non-technical because I can speak to those that are non-technical, and they're the majority of a lot of leadership — executives, boards. Maybe this is the wrong audience, but I like to ask who here is a computer scientist, and normally I'll get one - maybe one - person in the room put up their hand.

2:59

So we're here to bridge that gap and make AI safe and secure for businesses, and really help them get the upside but be alive to the risks as well. And that's so much of what we do. We say words like responsible AI, safe and secure adoption, human-centric adoption — they're all almost like shibboleths at this point. What do you guys think? I guess this is also a tension question as well, because we are all people that are interested in AI safety. We are all people that are aware of the risks, but we are also helping organisations use AI.

3:39

We're also helping people almost push this rapid technology along. So how do you guys deal with that? Because I sometimes feel like I have cognitive dissonance, but I think it's healthy that I have that, because if I didn't have that, I think I would possibly be the wrong person

4:00

Rajiv Shah

to be advising organisations on using AI. How do you deal with that, Rajiv? I think what's been interesting for me is once upon a time, the security department was the Department of “No”. What do you want to do? You want cyber security. And they said, no, you can't do it. And we realised very rapidly that that's not a good answer in the age of AI, because all these tools are there, they're available. What happens if you say no all the time is people probably go around you and set up all these shadow IT systems, and all this.

4:31

Or the other risk that you can have if you lock your system so far down that you can't do that, is that your organisation gets left behind because you're not willing to adopt that. So in actual fact, cyber security has had to adapt its ways. And rather than being “no, no, no”, it's got to be, “okay, how do we find a way of making sure you can do this?” And therefore I think cyber security at the end of the day has been all about risk management.

4:54

So what we can help people to do is say, if this is the outcome you want to achieve, these are some of the risks that are going to be there. And some of them we're willing to accept, and some of them we can do something about. And again, a lot of my job is in helping people to understand technology. And people say, well, security is really, really important - we have a system with one terminal in the basement, and you have to swipe it and go and use it, and then you can't write anything down when you come out again.

5:19

That doesn't make it very useful. So we have to connect things together. And the same way people want to get the benefits of AI, we have to accept that, for example, we're going to use third-party service providers. We're going to have data moving across boundaries. We're going to have things about the lack of visibility or control around that.

5:34

Rishabh Gupta

And it's actually saying, well can we control and bound that risk and work out what we're willing to accept in return for the benefits that we're getting out of this system? And is that a fair trade-off? So that's really been the important thing — you can't be the Department of “No”. You've got to find a way. It can be yes, if you're willing to do x, y, z. And that's the conversations we need to have. Yeah, I think I resonate with the way you're thinking around this.

6:02

See, the way I think around this is it's not like we need to choose opportunity over the risk. The idea here is that this opportunity can become real value for business only when people can trust it. And the trust only comes when there is scalable adoption of AI. And that actually is only driven when we have responsible AI in place. So I like to think of it like, let's imagine that we have this Formula One car. The whole point of a Formula One car is speed and performance, but you will never hear

6:41

Amanda Tay

a racing team saying, let's remove the brakes, or let's not do safety checks, or let's not do some of that telemetry. Let's take them off. You will never hear that would happen, because that would be ridiculous, because those are the things that give the driver and the team that confidence to push the car to its limit. So responsible AI is the same. It's not about blocking innovation. It's about enabling innovation and giving you that licence to scale AI safely. And I think from my point of view, you want tension.

7:17

You always want tension. It's important to feel like you're not going fast enough. If you don't feel that way, you probably are going fast enough. So you always, always want to feel tension. And we talk about AI as its own unique technology, but it's all just business anyway. And if you want to make profit, it needs to be sustainable. And you can only ever go as fast as your people will come with you and your customers will trust you. It doesn't take long to see people that have used this technology without enough foresight, and it's ruined their brand, ruined their trust, and that's all you've got in business.

7:50

So you can be responsible. You can do whatever.

7:53

Jisoo Kim

I just call it good business and good sustainable business. Remove the word AI. You need to do it for whatever you want to do in innovation. Yeah, totally. And I think trust in AI in Australia, we know, is at rock bottom. When we think about, do I trust AI, do I trust the machine inherently, it's just no. Do I trust this machine to assess my bank loan? Do I trust this machine to be aligned with my values? Do I trust this machine to know me? The answer is no. So really, AI adoption in industry is very much a people problem.

8:33

We're finding that it’s very emotional. So for me, as a consultant coming in, working with a business, people always come with their preconceptions of AI. They're like, well, it's going to take my job. You're training this to just replace me one day. So I think there's almost a way to really change this narrative, because I think we're very fortunate in Australia. We don't have Silicon Valley, we don't have Wall Street. We can really carve out our own narrative. And I think we're also seeing this in Australia a lot more, but we really need to own it, in the sense that in Australia we're not keen to just replace people, reduce headcount.

9:10

We're actually really keen to do more because we care and we can. And I think we've got a good set-up. We can do renewable energy. We're more values focused. We care about our environment, our people. Are there a couple of stories that you guys could tell where your people have at first maybe hesitated, and how you guys really changed that, flipped the switch on actually getting them along for the ride and helping them understand this is not about reducing headcount, this is actually about improving — like you're saying, Rishabh, we're a Formula One car, we need to get ready for Monaco (I don't know, I'm not a Formula One person).

9:51

But it's making sure that we're really slick and we can provide the services

9:56

Rishabh Gupta

that our customers trust us to deliver. Do you guys have stories where people have come along for the ride? So I like to talk about this. There's this very interesting book by an author called Yuval Noah Harari - it's called Sapiens - and it talks about the evolution of humankind. And one of the interesting points the author talks about is what is so special about humans that makes us so unique and so successful on this planet Earth. And one of the arguments he presents is that it's that trust that we have with each other, the shared belief, the cause of which we are able to cooperate in large numbers.

10:35

And he goes into this example saying that if we have 100,000 people going and watching a football match, we would all go peacefully and watch that match for our team. And in most scenarios we will just come back home and rest. But if the same thing would have to happen for our closest chimp-like cousins, like chimpanzees, that might not be the case. There might be chaos. And that is critical because in this increasingly automated world where humans are being replaced by AI, that very trust is being tested.

11:12

And the answer to that is responsible AI, because responsible AI gives you those foundations, things like accountability, fairness, transparency, testing — all those things are fundamental, that build on that trust and reduce that trust gap. So for me,

11:28

Amanda Tay

the answer is responsible AI. That's going to build that trust. Then we can scale on AI and use the AI to its fullest potential. So from my point of view, things have changed in the last few years. But I think the concern probably still lies there with parents and their kids and what the children are going to do. I think that's probably where we've seen the most concern, not necessarily about people in their roles. I think the way that I've seen it tackled really well, and what we do, is really show people what's possible.

12:04

No one's worried that a black-box LLM is taking the job any time soon. I think that's common sense. But when you start to play around with tools, you give some education and you start to share stories, you'll find that it cultivates a really exciting momentum.

12:20

Rajiv Shah

We have internal competitions: what is the problem? How do you want to solve it, and bring us a really good use case and we give out prizes, and there's this fun engagement level about it. Almost to the point, though, I keep on hearing “an agent can do that”, “an agent can do that”, “an agent can do that”, and in my mind I’m like, no they can’t! And so we've almost surpassed it. But I love the amount of personal energy. And the other thing is, you've got a lot of personal fluency and adoption outside of your workplace.

12:53

So it is an exciting thing. And the good thing about nowadays is that you don't have to be an expert. You can learn and be an expert — the flattening of the economy. So from my point of view, I think what's really important is making sure you set up what is the target state of what people will do and what the AI will do, and help people to understand that's where we're going towards. There was an interesting comment made in one of the talks this morning.

13:15

Even in the frontier labs where they talk about — Anthropic — 80% of the code is written by an AI model. If you got rid of all the people in Anthropic, I'm pretty sure they would shudder to a halt pretty quickly. And the same is true in any organisation. So we're not going to get rid of the people. So what we've got to do is help people to understand what their role is going to be and what the AI is going to do. And so it's like, if we're going to roll out an AI system, then what problem is it going to solve?

13:36

How is it going to change my job? It's going to take away this piece of my job, so I've got more time to go and do this. And showing people where it's going, rather than maybe the approach that we get, which is, let's just YOLO it. Let's roll out some AI, let's reduce our headcount by 10% and hope AI can make up the gap. That sort of thing never works. What you’ve got to do is to set out the vision for people - what is their job going to look like at the end of this process?

13:58

And what problems is the AI going to solve, and how does that benefit them? Because maybe it takes away the boring bits, the bits they get fed up with doing. And how is it going to benefit the organisation, because it's going

14:08

Amanda Tay

to increase our productivity or it's going to make our product to our customers better or something like that? It's interesting. I work across a whole load of things. I'd also find sometimes all I have to do is sit there with people about 3 or 4 times, just keep on saying what problem are you trying to solve, what problem are you trying to solve, and then eventually you get to the nub of what you're doing. And once everyone understands that, then everyone can build a shared vision and understanding and get behind doing it.

14:33

But if everyone's got a different idea about why they're doing something, then you very rarely get a successful outcome.

14:38

Jisoo Kim

Yeah, and I'd say time and time again we see in engagement scores, people want to do less work with ourselves and spend more time with customers and meaningful stuff. So, to add on to how you take people on the journey, is that this thing that you're wanting us to solve for can start to solve for it if we work together. I think also this actually shows us that we have a little bit of a human leadership problem. Not that what you said are problems at all — but in the sense that you fill this gap by paving the way, showing the strategy, showing the vision to your people.

15:15

But when we're coming in and working with companies — as a practical example of how to bring your people along — we always work with the CEO to make sure that they have their narrative down pat. Why are you implementing AI? The strategy. And is it around preserving your culture, protecting your people, and actually empowering them to do a better job in an increasingly enabled AI economy? And so I think the leaders that perhaps shy away from that, they might think this isn't my job anymore.

15:48

I actually would disagree. I'd say in the age of AI, with all the volatile, uncertain world that we live in, people are looking more and more for leaders. They're looking more and more for people to tell them how to feel or what they should be thinking right now, because they actually can't make sense of their world. Their world is changing every day. I now say to leaders, you don't have seasons, you now have cycles, and the cycles are very short. So you can't just be like, oh guys, we're just in a growing season.

16:20

It's like your growing cycle might actually just last a week, and then you might hit rock bottom in the market or whatever it is that Silicon Valley seems to be experiencing every day. So for me, I think it's very much a human problem that needs a human antidote. And that really comes down to communication, the narrative of a CEO saying, hey guys, we've employed a consultancy, they're coming in, they're going to be doing this. But by the way, just so you know, this is not a headcount exercise.

16:49

This is not a sizing exercise. This is purely us exploring what the opportunities are, what the risks are. And we want to hear from you. We're going to set up feedback avenues, contestability loops, because you guys are important to us. And I think that goes so far that people almost underestimate it. So I really love that you guys really hit on all those kinds of points there. For me, I think that also then raises another tension. Like Amanda, you said you're really pushing AI adoption. It then gets to a point where you're seeing AI slop emails, or you get AI-generated, “hello,

17:31

as per my previous email.” And you know what’s really annoying: I write like that, so people are like, oh, you used AI? And I'm like, no, maybe AI just trained on everything that I like, basically learn how to do, so thanks. And also I am a public servant, so my public servant writing manual is literally on the internet. So it's a bit annoying, but it's almost like then you have a different set of problems, right? You have cognitive surrender, you have complacency, you have hallucinations and verification.

18:03

It's almost like, in some ways, you're automating people's weaknesses. How do you guys deal with that, and with the organisations that you work with?

18:12

Rajiv Shah

Rajiv - have you seen that happen, and how has that been remedied? So there's a few different things, a lot of different points there. I think a lot of it's actually around the trust actually in the AI. So what do you know that you can rely on the AI to do? And where is the role of the human in that system? So lets speak a little about Robodebt, for example. It's an example that is often put up about poor AI practice. That was actually nothing to do with AI.

18:42

To be honest, calling Robodebt AI is a bit of an insult to AI systems, in my view. But the problem actually was about not thinking about which part of the decision-making process was being automated, saying you can't just actually outsource that decision-making essentially to an algorithm to go and decide who's liable and who needs to repay a certain amount of money. So I think that's the bit that we have to make sure we're really clear on — what is the trust boundary around that? I also think about some of the conversations we've had in this forum already.

19:09

People talk about what are the sort of guardrails or things you put around. You might have this model that's a black box, essentially, because it's been trained on a whole lot of data. We don't know how it operates, but what we can do is we can put constraints around it - what data

19:23

Amanda Tay

we put into it, what data we take out of it, how we then use that data, how do we build harnesses around it, and therefore how do we build out extra layers of guardrails around that mean that we can trust that? And I think that that's the really important thing. And again, we've got to be honest with everyone about that. And again, coming to your leadership point — so then we be honest with our staff, with our customers and with our stakeholders around where that trust boundary is and how much we're prepared to trust the AI and how much we're not.

19:50

And maybe on AI slop and work emails: I think that will normalise, because it's a branding issue and it's super clear where it is. And so we're all excited now. No one's considering it. But I think that will normalise. People say a lot to not say much sometimes with AI I think. But then I think again, you might just automate an article and put it online. It's not going to go viral. I go back to just good business sense. If you're advertising, you've been present, you want virality, you want people to connect with your brand.

20:24

I think you should use AI marketing; if you're not it’s silly. But it should be to inform different things.

20:31

Rishabh Gupta

But your brand voice always has to come through. So I think the proof is in the pudding. If you use AI slop in your own world, it will impact your brand and your opportunities. If you use AI slop in your branding and your marketing, that will cause you issues as well. So the only thing I would add to that is, it all comes down to value. So I'll be able to generate value out of it in terms of productivity, efficiency or better customer decisions. And that again goes to that point that Rajiv was making earlier: it all goes to trust.

21:07

And then when we think about those trust things, what we're really seeing in the industry right now is that AI is being used, embedded into products, platforms, services, customer interactions. Now AI is influencing these real outcomes. So now that changes the expectation naturally.

21:23

Jisoo Kim

It's no longer enough to say that the technology works. We are asking more questions. We are asking, do we understand the risk? Can we manage that risk properly? Are there proper controls in place? Can we as an organisation stand behind those outcomes? All that is basically good governance and effective risk management. That is it. So that is going to build that trust and drive that AI adoption at scale. Yeah. And touching on that. I feel like, with the human problems of now we're using AI and we want to make sure it's aligned to us and to our voice and branding and all of that.

22:04

But there's also really great stories in even just how bringing people along to trust AI — they are really starting to see the benefits and it's really helping boost people. So for example, we work with a few mining companies and a lot of these guys are out on sites and they're very busy - they're just under the pump all the time. So they're managing a lot. And there's actually something to be said about uptake of AI, the excitement of AI in industry and burnout. I think because people are actually just so overworked in some ways.

22:41

But I was speaking to a guy and he was saying, I just love Copilot because I can just talk to it, and I'm dyslexic and it's really awesome because I can now just say what I need to say and I can get my emails out faster. And even though it reads like AI slop, my team loves it because they finally know what I'm trying to say. They don't have to come back to me and be like, what is it that you really wanted us to do with the truck?

23:05

Rajiv Shah

So I think it's stories like that that we really need to be finding ways to enable more of. And it's really equal opportunity — we work with some companies that have multi jurisdictions. It's very hard sometimes to translate, and you've got AI that's able to do live translations and actually help fill the gaps a lot of the time. So I think that's also really cool. Have you guys seen AI in your workforces really enable and help people step up to the places that they really want to be?

23:42

So it's quite interesting what you talk about there. I think there's some really good use cases. I'll first of all do my pedantic — there are other types of AI than large language models. But if you look at things like large language models, I think they enable that natural language interface and actually help a lot of those things around verbal communication, cross-border communication. I think there's some really good use cases around that. I think one of the things that we tell people to think about is that you have to think about how you're applying — essentially they're non-deterministic.

24:08

If you want some sort of subjective output, then a large language model is quite good. Again, if you want a nicely written email, that's good. If you want to do some precise calculations or precise arithmetic, then it's not necessarily — you might need to do some sort of more mathematical technique. I think the other interesting thing is, when we start off with computers, computers are something where if you gave it the right instructions, you could guarantee it would get the right output. And AI is not like that.

24:31

AI is fundamentally an imperfect model of the world. So then we have to think about how do we use it. It's not actually something where if we give it the right instructions, we're guaranteed to get the right answer. We're going to give it some instructions and we get something that we think might be useful. And therefore we need to know how much we know. So picking the right job to use AI for, and using the right type of AI to use for it as well, is really important.

24:52

But I think you're right. Obviously all the excitement in the last couple of years has come around large language models. And they just reduce the barrier to entry to anyone's users. You don't need to be a data scientist. You don't need to have done tensor arithmetic. You don't even need to know how to

25:05

Amanda Tay

format your data neatly. All you've got to do is just go and speak, or just type freeform into something, and you can answer that. And that is massively valuable, because what that's done is vastly expanded the range of capability available to a larger number of people. But we do have to remember some of the trade-offs that we've made there and think, it's not, despite what we might think, this all seeing thing - certainly AGI is not here yet. It is not a single tool, one to rule them all, that will do everything.

25:31

So we pick the right tool for the right job.

25:34

Rishabh Gupta

I think you only have to look at the personal use of an LLM for personal counselling, and really the take-up of that and how prolific that is. And it just talks to being able to have some privacy and not be ashamed to ask a question. So if I think about what would progress people forward in the workplace: it's being able to ask questions that they may otherwise be embarrassed to ask. I'm in charge of this area, but what does this little thing mean? Boom, you've got it.

26:04

And so I think to be able to ideate safely, ask questions safely is a big thing that's going to really see people move forward.

26:12

Jisoo Kim

So I think the way I look at this is the key characteristics that make AI so valuable are the speed, the scale, the intelligence. And those are the same characteristics that make it risky. So you need to look into what are those use cases that can be automated using those characteristics. But then you also need to consider the risk side of things. Are we having the right controls, like mitigation policies, in place? So I believe if we have that in place, definitely that can generate value for that company.

26:44

And also just touching back on what you said, Amanda, with people turning to chat bots for therapy, counselling, confidential conversations. Obviously there's a risk in that, but I feel like that shows an amazing opportunity for culture and society to fill these gaps. It's almost like revealing that there are these gaps and voids that we've left, maybe just because of modernity and technology, but I feel like it's almost now giving us — and Anna talked about this in her quarterly essay — the analogue life, what does it mean?

27:19

And for me, it means that I should be spending more time checking in on my friends, face to face or over a phone call, as opposed to talking to a chat bot and venting all my worries. But yeah, so that was a little sidenote. But I guess in industry, we're seen to be adopting AI faster. And even within industry, there's the early adopters, the fast followers and then the laggards. How can industry work better with government, academia, civil society — everyone — in bringing everyone along for the ride?

27:59

Because right now I feel like there's almost a fractured two, three, four, five speed adoption track. There's the big end of town. They've been able to spend money on data and on technology for a very long time, make very large investments and very good ones. And then there's your small to medium sized businesses, and they're learning as they go, but they might think that they're behind, but maybe they'll look at a university and be like, oh, we are actually way more advanced in a university, I don't know.

28:34

So then you go even one step down into civil society — not down, but across the civil society. And some people don't even know that ChatGPT, Claude exists.

28:45

Amanda Tay

They don't even know Cowork, the risks and dangers of OpenClaw. They just — either by choice, because they want to be head in the sand. But also there's, I think, quite an uneven proliferation of this technology. So how can we work together with civil society, government, academia for the betterment of humanity in using this technology? All I would say is it continually goes back to any other societal problem that we need to solve — housing. It's not going to be government in its entirety. It's not going to be private sector in its entirety.

29:24

It's not going to be faith groups in its entirety. So in all of those things, how you move them forward and work together is to talk regularly and often and meaningfully. If you want to try and solve something over dinner, it's not going to happen. But you need regular engagement. You need to have some thought leadership, and everyone needs to contribute, because you need to be able to paint where you want to go, because what's good for one has to be good for everyone. That's what I would say,

29:48

Rishabh Gupta

to that how you can meaningfully do it. The thing that I would add to that is we are trying to build this national AI capability. And the way we are trying to do it is by making our workforce learn about AI — so, AI literacy. And I think AI is becoming an everyday thing. So it's important that the workforce understand how best to use it, when to rely on it, when to challenge it, and when to have that understanding that human judgement is required. So that's just one aspect.

30:19

But then the other thing that Amanda just touched upon is the fact that we all need to work together with regulators and government to actually see how we can evolve

30:29

Rajiv Shah

these policies that we are building, because this technology is evolving so quickly, and it's important that we reflect back on the real-world implementations and, based on that, make those policy changes. I come back to you. We need more dialogue. I think the main thing we actually need is a lot more transparency. Maybe removing some of the stigma about talking about things that went wrong. So I see this — I run a small business and I work with some of the largest government departments. I've seen the full range of speeds that we talk about.

30:56

But I think for those organisations that can get ahead and move more quickly, we've got to have more of a feedback loop, not just talking about what worked, but let's remove the stigma about talking about what went wrong, what was a disaster, why did it go wrong. What would we have done differently if we had our time again? And if we can somehow

31:11

Amanda Tay

be really transparent about that, that's how we'll then share the benefits around. Because if we just tell the good news stories, we're not telling the truth and we're not really going to get that shared learning and building of capability. Yeah, especially some of the smaller organisations without the capital to move fast. They're probably moving faster, to be honest, because they don't have the constraints. Maybe they're not realising what it is that we're doing, what they are doing and what they're not doing. And you can fully enable everything without having the cyber expertise.

31:42

So again, I think we need to continually work with industry. I say industry, but whatever it is - I'm in small business and medium - we've got to be in those forums and people need to take personal accountability. Any leader needs to take personal accountability in the community forums to know and understand as well. Because I do worry a lot about fraud and what's coming upon us and to be able to protect all of us, especially, and in order to do that, we've got to protect our small and medium sized businesses and teach them how to do it, because they won't be able to afford the level that we are at, because it's a different level of regulation.

32:24

And not only that - it’s helping people grapple with what is a director's responsibility. And what does that look like? And again, people are still coming to terms with that. We hear that from our regulators and directors. You need to get up to speed a bit more.

32:40

Jisoo Kim

And we all need to get up to speed a bit more.

32:43

Amanda Tay

Yeah, I love that. And I also love the open transparency. Transparency is one of the AI principles. We should be transparent about the mistakes. And often they're just small human errors. It's like, oh, we forgot to turn the data classifiers on. Oh no, we can fix that. And let's tell other people so they don't make the same mistakes.

33:05

Rajiv Shah

Though I think a lot of mistakes with AI, if you think investment, is just an inability — I'm not talking about my organisation, it's just examples I’ve seen — an inability to really do a business case well, inability to understand, an inability to say no and sell for what customers actually want. A lot of the tools that I interact with from different companies — I don't even want to know how much that cost you, because all it is doing is annoying me. So you’ve spend millions to just annoy me right now?

33:35

Can I see your business case? Because I'm curious. I'll give a little anecdote here. I recently had an experience of trying to work with a technology company, let's say, from whom I tried to buy some equipment, and I tried to phone them up and ask them for help. And I got the automated chatbot. And it wouldn't help me until I told it the serial number of what I'd ordered. And I was trying to say, well, I haven't ordered. It hasn't arrived. That's why I'm calling you.

33:57

I don't need anything. And I just say, can I speak to someone? No, I don't understand that. I can't help you. So somewhere in their back office is a metric saying it's brilliant. This chat bot is 100% effective because no calls ever get escalated to an operator.

34:08

Jisoo Kim

But am I incentivised to ever go and use that company ever again? And will I ever buy their AI models? Probably not. So how much did that cost and what was the opportunity cost to do it? And how much to call someone? And what did they tell the board? Totally. And I think Bunnings recently released an AI chat bot, and one of the design principles was, do not obstruct the way to speak to a human, because anytime I get automated stuff, I'm like, speak to human, human.

34:32

I just want to go straight there. It's kind of weird — even though I'm very digitally literate, I still want to speak to a human. So I think there's something to be said there. There's design choices in that. There's deployment choices and development choices in how we can share what we're seeing with government, academia, industry. I also want to flag that we're open to questions. So I'm just going to end on a couple of things. There's so many things that we haven't touched on, mainly because sometimes they're a bit spicy.

35:02

We can't talk about stuff. But I want to have two more extra questions before maybe we look at some audience questions. But I guess the main one is more for Rajiv and what you guys are seeing. If you look at the MIT AI risk domains, the number one thing that industry cares about is data security and privacy. They're like, that is our IP. That is our lifeblood. We do not want that to go anywhere. What is the best way for industry to prepare itself

35:31

Rajiv Shah

for the onslaught of AI security problems that are going to come just as the technology gets better and better? So this is a great advert. Go and speak to your local cyber security professionals, because actually this is what cyber security people have been telling you. I was having this conversation a couple of times over the last couple of days, actually, about — we talk about things like Mythos and cyber security threats. For 20 years, cyber security professionals have been telling you to go and do various basic things, correct?

35:53

Like just ask some questions before you connect this to the internet. Do I need to access control on it? Do I need authentication on it? All these sort of things here, and we've all been a bit slack and we sort of got away with it. And we've just taken the convenience benefits of just plugging everything together and having it all work seamlessly. And hidden in the noise. And that veneer is going to go away very quickly. So what you've got to do is go back to that.

36:14

So go to your local cyber security professional, they’ll tell you, they’ll help you to understand where your data is, how to classify that data, what the risks are with that data, how to protect it. You can say I want to deploy this system, whether it's an AI system or some other SaaS instance like that - we can help you to understand: what is your data? Where does your data go? Who has access to it? What are the risks? How could the system be compromised? And so on.

36:38

I'll also say this. So has anyone here got a Telstra phone? We all had a little issue on the Telstra network. And interestingly, also when we talk about data security, the other thing we need to think of from the security point of view is if you build your systems where they become critically dependent on this AI platform, what are you doing to ensure the availability of that platform, and what is your fallback plan when that platform goes out of service or has an outage or something like that?

37:01

So it's not just about confidentiality — actually availability is that bit of cyber security that often gets forgotten

37:06

Rishabh Gupta

because it's not as exciting, but actually some of us have some personal experience. It can have the bigger impact when we lose it. So I'll talk through this, not just a security lens, but an AI safety lens, much broader than that. So in large enterprises, AI can enter through many different doors. AI could be in the form of a Copilot-style assistant, or it could be embedded into third-party platforms or vendor solutions, or it could be an AI that you are building in-house. It comes in all forms and shapes.

37:40

I like to use this transport safety analogy. So let's say you have a bicycle, a car, an aircraft. We all can agree that there is a safety element to all of them, but you would not put them through exactly the same standard safety process. That would be absurd.

37:59

Amanda Tay

The idea here is, given that they all carry a different level of risk, we need to be proportionate when we are thinking about the controls and the governance that need to be in place. So I think that is the key idea — that we need to be proportionate, depending upon what is the risk there. And based on that, we need to be thinking about those controls. And then all I'd say is we've been talking in industry about cleaning up your data for ten years. It's important.

38:26

It's important. It's important. But now I guess people are realising, hang on, I can then spend money to overlay AI and it's just not going to be as effective. And so it's also one of those things like putting your data into the cloud. It's very costly. But what does it deliver for you right now? And the same thing, a lot of cleaning up of the data when you’ve got an opportunity cost to bring in some income that financial year that you're choosing to do this — again, I think we're at a pivotal point that you can't move forward.

38:56

Jisoo Kim

So it's those who had the foresight before. And again, it goes back to executive education — how much do we know data? How much do we know those things? And really driving the point of what you need to do. Totally. If I had — like this time last year, I wouldn't have said to anyone, yeah, Microsoft Copilot is really good. It wasn't. Now, yes, it's actually not too bad. But people like, oh, it's still really bad. And I'm actually like, okay, let's just do a quick little data landscape review.

39:25

And we do this for clients. One client, they came back, it was like 3.1 million files or something that they had accumulated over like 20 years. And they only use 18%. So I was like, yeah, if Copilot is surfacing answers that are completely irrelevant, that's probably why. So it's those kinds of basic things that really help paint the full picture of how do we actually make it work. And also touching on what you were saying, Amanda about business case cost. This is becoming a huge thing in industry, especially as now we're talking about token-based usage and token maxing, etc., etc. I think the one thing that I want to say to that, without going into it too much, is really everyone is being sold the V8 supercar.

40:05

You don't need the V8 supercar — maybe you just need the Corolla to get from A to B. And also, I think, just don't listen to the hype, don't listen to the Silicon Valley hype. They are always going to want to upsell and sell you the next best thing. They are always going to make you do extra plug-ins and connectors and skills, etc., etc. But really, choose what suits your organisation. Choose what suits your values and principles. Do the research if you want, as well. When it comes to data centres, where is it all going?

40:41

And all the kind of values and principles — you can even do scorecards with AI now, so it's really good.

40:50

Rishabh Gupta

So, my last question, and then we'll move to questions. What is your hopeful vision? Because we're all doing this. We're all in industry thinking about AI safety, thinking about what does safe and secure responsible AI look like. We're all doing this for a reason. It's because we have an end goal, a hopeful vision for how humanity, how our country can experience and roll out AI. What is that to you? What is the hopeful vision?

41:21

Amanda Tay

So for me, I think it's AI-enabled transformation that's going to deliver value for our customers, for our organisations, with human-centric values, accountability. All those things hopefully.

41:37

Rajiv Shah

For me: No one left behind, and that we're solving for some really meaningful things and driving society forward, and that in our everyday work, we can do what more aligns to what we sort of born and what's our innate passions, and we can work more in line with that. So I’m going to take the opportunity for a shameless plug agai, which is actually this — the future looks like the cyber security profession at the heart of enabling this transformation. Because I go back to what Minister Charlton actually opened with yesterday, when he said safety and innovation are not either or.

42:09

They're actually things that work together. And by building the safety we enable the innovation. And so again, I'll come back to the fact that cyber security professionals have been thinking about things like data security and risk management for many years, and if you have them in the conversations right at the start,

42:23

Jisoo Kim

then we can get this right. Again, we could have our time again, right? Maybe if we put some cyber security in at the start before we built the internet, maybe we would be in a much better way to resist things like Mythos and so on. But that ship has sailed, right. But we have an opportunity now — AI in a few years time is going to look very different from what it does now. But if we can start building in and getting cyber security at the heart of how we build those systems now and build that capability, we'll be in a much better place than if we decided to just build it and then secure it later.

42:52

Great. Thanks guys. I'll share mine right at the end. But we've got a couple of questions, I think. MC with online audience question So we've got about ten minutes for questions, and we want to get through as many as we can. So I might do a bit of a race. We'll go for two perspectives per question if we can. The first question, which has already been submitted, is around — there's many organisations out there working really hard to implement responsible AI governance, but it seems as though it would be really difficult for most of these organisations to put their hand on their heart and say, we've got it sorted.

43:21

What is the most common challenge that you think is preventing organisations from getting there?

43:27

Rajiv Shah

I want to say very quickly, I think it's people. You need to build it around the people and processes, not around an outcome, because at the end of the day, people are the ones that will be in the business, drive the business, come up with the ideas. So it needs to be around people. And sometimes you might have built the strategy or built the thing around an outcome or an objective. And even if you haven't, then maybe you actually don't know where your people really are at, where they're feeling with it.

43:57

So maybe doing some staff surveys or doing some interviews is really useful. It will unveil a lot.

44:03

Audience question

I might just say I think it's more fundamental than that. It's actually often about coming down to — do you know what problem you're trying to solve? You said we're really bad at producing business cases. If you don't know what good looks like, then you can't govern the outcome effectively. And therefore that upfront definition is often where a lot of the governance fails.

44:24

Amanda Tay

Thank you very much for a very interesting panel, and for being here. I'm wondering if the panellists can share some anecdotes of how they've brought mid and senior level managers along to invest in capability uplift within their organisation. And that's both within industry as well as within government. I also notice a dearth of business cases. Yet everybody's using — 85% of the public service in Queensland is using AI. 10% of the organisations have a policy for it, and even fewer are actually training people. Thanks. Yeah, that's a big problem you just spelled out.

45:05

I think for us, we have an AI academy for it where you can learn everything from what is an LLM to how do you do it safely. It's got a whole level of education that we want everyone to use, and they are generally used and taken up. We have a thing called AI Guild where essentially you don't have to be a technical person. You just come together and talk about your passions for AI. So there's a huge amount of investment into the risks, how to use it well.

45:37

We also have AI agent building — you go there and you can learn and they'll teach you how to build an agent. And there's a ton of governance Around who can use it, what data you can use. I think in banking it's a bit easier because it's super clear around what data you can use, what data you can’t use, and how it's classified. But I think we actually do it really well. We create some energy around it and it seems to be on everyone's development plan, and whatever you want to learn about it, you can.

46:11

Also, we're practical - we’ll look outside as well, if there's any bespoke learning requirement that's needed. And then when you've got everyone together,

46:19

Jisoo Kim

you learn everything from data. So I think we're doing it really well. And I think a lot of banks are doing it quite well. I was actually just going to say we have a slightly different approach, obviously, because I'm not part of the banking industry or a big organisation. Because we plan around people, we actually create, I guess — you can't assume that everyone understands why they're suddenly in this AI era. They’re just being told, hey, ChatGPT exists. And they're like, how did we get here?

46:48

So it's almost like telling that story to them of, hey, end of 2022, Sam Altman accidentally released this technology into the public and now here we are. So it's almost telling the story and situating them first and then building on the skills. But also acknowledging that everyone has different levels of understanding, technical efficiency, proficiency. People always overstate — when we run staff surveys, people always overstate their digital proficiency. And so it's also acknowledging that and actually working with your people to really see, because everyone has different learning styles as well.

47:20

Some people really thrive in a hands-on hackathon. So it's exploring that as a format. Some people really thrive on the bite-sized LMS modules, exploring that as well, but also some people really thrive on the office hours, drop in, have a one-on-one with a tutor. So we provide all those kinds of formats because we know that everyone is different. And I know you guys have been doing that in your organisations, talking to your people and finding out what works and setting up the kind of different forums for people to play in the ways that really resonate with them.

47:54

I find what doesn't work is when, I guess, boards and management are like, we've turned on Copilot licences and we've done three training sessions, why is no one using it? It's like, well, maybe the people that really thrived in that environment are using it. But have you looked at the people that have been left behind and what works for them best? MC

48:14

Rajiv Shah

Appreciating that you're all working across very different industries, what role would you like to see regulators take in supporting AI safety?

48:24

Rishabh Gupta

I think regulators can play a couple of roles. One actually is around — well, let's call it good old product safety. How can you set some minimum standards that make sure that what we go and buy, particularly things that go out to the sort of mass consumer market, are safe and secure by design? We've seen government already taking some action around this on things like sort of mandatory labelling and minimum safety standards around IoT devices. But I think as AI products go into the market, setting that minimum standard is important.

48:55

So yeah, that'll be my first suggestion on that. I think the outline that’s there as part of the national AI plan — I think that is sensible and balanced. So it talks about the principles-based approach and supporting, or basically having, these industry-specific regulations. I think that gives the organisation the flexibility to innovate, at the same time ensuring the right safeguards and controls are in place. Also, to Rajiv’s point, I think bringing in more clear guidance, some practical expectations of what we should be doing, and also some sort of common language around AI.

49:35

It's very difficult to agree on some definitions. So if I go into industry and talk

49:42

Jisoo Kim

about what an agent is, like in the panel itself, they will not agree on what is an agent. So probably bringing some consistency around that would definitely help. Yeah, definitely having standards and definitions very much defined would really help. I think what's really interesting — this opens up a whole can of worms for me in some senses, because I'm also thinking about the geopolitics of AI, the fact that Australia is so dependent on the US right now, and open source models in China seem to be taking the lead.

50:09

That is going to become a problem, perhaps a moral principle question that we ask and answer later on. But just for the regulators. So I was at the Digital Economy conference a couple of weeks ago, and they had a regulatory breakfast, and I went along to it, I have no idea. It was basically about blockchain, crypto, TradFi, DeFi, all that kind of stuff. I'm definitely not in that world, but it was so interesting to see the similarities. It had taken them ten years to finally get to a place where APRA, ASIC, all of the regulatory bodies, were finally asking firms and providers to actually get credentialed.

50:50

So there's heaps of people right now saying, I can come in and transform your business, blah, blah, blah. I actually think now it should get to a place where you have to be registered — well, just somewhat registered or vetted — so that you're not just breaking all the cyber security ISO, like ISO 27001. You just at least have to be aligned to what the Australian government is trying to do in the AI space. But we are very much out of time. I really wanted to share, just to end, my hopeful vision for where I'm hoping that AI goes.

51:26

I really hope that we tell a very powerful Australian story, that we can actually use AI to give us time back to do the things that we love most. We are a very outdoorsy, environmentally loving nation. I would love if I could really go in, never have to make a slide deck ever again, because I can go to the beach and I can get Claude to make the slide deck, but I know what I want that slide deck to say. I don't want technical skills) and lack thereof) to ever bar someone from getting a good idea out there or getting their business off the ground.

51:58

I really see it as a way to really turn the tap on on Australian ingenuity. So I really want a place where we're also thinking about the next generation and how can we actually create a stronger bottom rung for them, given that there's all this technology ahead of them that's going to help them do so much more. So what is it that we can really do to help them get that leg up in the workforce? Maybe it just looks like we're teaching them different things by the time they land their grad roles or their intern roles in our organisations.

52:25

So that's it. Thank you so much for joining us, everyone. I think we've got another session after this. So we're getting booted out. But thank you so much for your time. Cheers.