In short
EUVC Podcast Episode E337 Notes
Episode Overview
- Podcast Title: EUVC
- Episode Title: E337 | Carlos Espinal & Ryan Donnelly, Startups in Focus by Seedcamp: AI Governance and Compliance - Navigating the Future
- Date: [Date Not Specified]
- Co-hosts: Andreas Munk Holm and David Cruz e Silva
- Guest: Ryan Donnelly, Co-founder and CEO of Enzai
Episode Description This episode focuses on the growing importance of AI governance and compliance, featuring a discussion on:
- The impact of AI as a technological revolution.
- The necessity of regulations and standards for responsible AI use.
- The challenges and opportunities in AI adoption.
- Enzai's mission to help organizations leverage AI effectively and in compliance with regulations.
Chapter Breakdown
- 00:00 Introduction to the AI Technological Revolution
- 00:36 Meet Ryan Donnelly: Background and role at Enzai.
- 01:14 The Inspiration Behind Enzai: Regulatory obligations motivating the creation of Enzai.
- 02:19 Understanding Enzai’s Customers: Identifying target customers and their pain points.
- 03:13 The Role of Regulations in AI: Discussing the necessity of regulations for AI development.
- 05:07 The Evolution of AI Regulations: Timeline and development of AI regulations.
- 10:26 The Importance of Standards in AI: Standards as crucial elements for trust in AI.
- 14:20 Enzai’s Vision for the Future: Goals and aspirations for Enzai in the coming years.
- 15:49 Final Thoughts and Call to Action: Encouragement for organizations to engage with Enzai.
Key Concepts and Discussions
The AI Technological Revolution
- Historical Context: AI is compared to major technological shifts (mobile phones, dotcom boom, web invention).
- Current Landscape: Awareness of AI's potential is rising, leading to a demand for regulations.
The Role of Regulations
- Regulatory Frameworks: Importance of establishing rules to ensure responsible AI use.
- EU Regulations: The European Union's initiative to regulate AI, initiated in response to emerging risks associated with AI technologies.
Customer Pain Points
- Regulatory Challenges: Organizations are often overwhelmed by compliance obligations and struggle to integrate AI responsibly into their operations.
- Need for Education: Many organizations need guidance on navigating AI technologies and their compliance requirements.
Enzai’s Mission
- Governance, Risk, and Compliance Solution: Enzai provides organizations with tools to manage AI-related risks and adhere to regulations.
- Enabling Trust: The goal is to foster trust in AI deployment by helping organizations meet high standards.
Importance of Standards
- Establishing Trust: Standards play a critical role in building trust in AI technologies, similar to the cloud sector.
- Certification Frameworks: The emergence of new standards and certifications tailored for AI governance.
Future Vision
- Five-Year Outlook: Enzai aims to be integral to organizations' AI operations, ensuring compliance with global regulations.
- Harmonization of Regulations: A desire for unified standards across different jurisdictions to simplify compliance for multinational organizations.
Final Thoughts
- Call to Action: Organizations need to proactively engage with compliance frameworks and foster a culture of responsibility in AI usage.
- Contact Information: Potential customers are encouraged to reach out for assistance with AI governance and compliance strategies.
Conclusion Ryan Donnelly emphasizes the urgency for organizations to adapt to the evolving regulatory landscape surrounding AI. Enzai positions itself as a key partner in navigating these challenges while maximizing the potential of AI technologies.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:05Welcome, everyone. I am really excited today to have the founder of NZ AI, Ryan Donnelly on this podcast. And the reason I'm really excited is because we've been talking so much about the power of AI, but there's equal number of conversations going on around the responsibilities of that. And this is squarely in what Ryan's building. And it's one of Seedcamp's recent investments and really excited and proud to be part of your journey, Ryan. So welcome. Thanks very much. Thanks for having us and delighted to have you on the cap table as well. Nice. All right. Well, let's start with the basics. Tell me who you are.
0:40In other words, like how you got here and everything. And then why did you start Enzi? Yeah, so my name is Ryan Dunley. I'm one of the founders of this company called Enzi. What we do is we provide an AI governance, risk and compliance solution that helps organizations understand and manage the risks that come with AI while also meeting all of their wonderful emerging regulatory obligations. And it was kind of those regulatory obligations that inspired the company. I spent many years in private practice law, working out of the city of London, some of of big law firms there doing a lot of private equity, M &A, and crucially, technology regulation work.
1:14I kind of saw the whole movement to establish trust in data, and I was very interested in that, and I was particularly interested in some of the big companies that came out of the back of that movement and that groundswell of feeling to get people compliant with all the new regulations around data privacy. And I was on the lookout for my own version of that. And AI was obviously kind of like a very interesting topic, and there started to be some white papers and some regulations around that emerging sort of 2019 through to 2021. And that really inspired me to take the plunge and start this thing.
1:46And it's been a wild journey ever since. You unpacked quite a bit there with regards to who this is for. You mentioned a bit, based on your background, a lot of it having to do with regulatory obligations and law that you've dealt with big companies and their burden of regulation, as well as establishing and keeping trust, as well as managing the data. And so I think within all that, I am trying to triangulate who you deem to be your customer. Like who is it that really benefits from what you're building at the moment, but also where they are in that pain curve at the moment. Because I feel like right now we're not really fully unpacked what that pain curve is for many people.
2:26I think that they're struggling to figure it out within their organizations. And so therefore they're struggling to decide what to do about it. So maybe you can walk us through who your customers and where are they on that journey of discovery of what this issue is and what they need to do about it and what solutions they're considering to do that? Yeah. So to start like at a very super high level here on this one, there tends to be a bit of an allergic reaction whenever anyone mentions regulations around technology, because there is naturally in a technology space, a real drive to push things forward and achieve new things and push the boundaries of what is possible.
2:59And I completely agree with that. I'm super excited about the frontier of some of this AI technology, the frontier of technology generally and i can understand why people get a little bit irate whenever there's mention of regulation coming in around this sort of stuff there's an old adage which is basically good regulation is good and bad regulation is bad um and what that's really trying to hint that is that uh if you get the rules right for playing the game here they can make the game so much better that's why we have a bunch of rules in every kind of sport and there's always a bit of debate in sport over again rugby for example which i follow a lot of like should there be a new rule here or a new rule there to make the game better.
3:36And I think that you can think of regulations very much in the same way. Their goal is to make the game better here, really, when it comes to this sort of stuff. So that allergic reaction, I think, is sometimes overblown. And I think when it comes to AI, what has happened here really is naturally people have got very excited about this technology. I'm sure you hear it every day, Carlos, but this is a kind of technological revolution on the scale of the shift to mobile 10 years ago, the dot-com boom 20 years ago, the invention of the web 30 years ago, the microprocessor, like all of those kind of big things that really pushed humanity forwards i do think this is on that scale um now for to have that impact we want to see the right guardrails in place we want to see the right rules to allow the game to flourish uh it's happened so many times with so many other technological developments i've gone down weird rabbit holes looking at like how did the car become so ubiquitous well it was actually a bunch of rules around that to make it really safe same with like electricity same with all these like key things that have changed how we live our lives i just don't think ai should be any different right there is some like very sensible rules we can put in place around this and that is what obviously the european union decided kind of in 2019 when they published that first white paper they were essentially saying hey we think we've done a pretty good job in regulating data but have we missed the bigger picture here the bigger picture being not just like data which is one piece of the puzzle but that entire end-to-end algorithmic decision making everything goes into building and deploying an algorithm at every stage in that value chain contains a bunch of risk.
5:00Is that something we should be looking to regulate for? Obviously, they concluded in sort of 2021. Well, I think before that, because they started drafting the legislation, but they published in 2021 that flagship piece of legislation, the first draft from the commission around regulating AI. This came in 2021, right? People can sometimes confuse the timelines here, but this was before Gen AI had its big boom, actually. There was already a bunch of applications here of machine learning and all kinds of different AI systems that were already making huge impacts on the world. There was concern around things like bias and fairness issues and how these things propagate downstream and the second and third order consequences of some of the decisions being made.
5:40So that kind of kicked the ball off really of regulation in this space. Now, we started this business around the end of 2021. We were really looking at this. Risks weren't like hugely on everyone's radar, but I think the explosion popularity around the chat GPT really put it on people's radar. And actually, ChatGPT even called the regulators who drafted the EU Act by surprise, to be honest, because that first version of the EU Act didn't contain any of what's now known as Article 53, the GPAI, general purpose AI provisions. So they kind of had to scramble to put some rules in place around that.
6:15And I think the interpretation of that in particular is going to be super interesting now. The frameworks that are going to come out to support application of that are going to be studied within an inch of their lives. and see how workable they are. So that's something we're interested in. But this is a very roundabout way. I promise I'm getting to answer your question here. I sound like a bit of a politician with all of this, but I think it's still very early in this stage, right? So companies now are very aware of this space. When we first started the company, they were not. Large companies are aware of this.
6:42They are aware of the opportunity that AI presents. They know that this is a paradigm shift. Many of them are looking and searching for those rules to play the game, quite frankly. What are the guardrails that they need to put up to make sure that they get the most out of these technologies. Now, we're still seeing quite a few organizations that are large businesses and experts in their own defined sector. So they could be manufacturing or they could be in an area of financial services or HR or cyber. They can be relentless experts in their own area of expertise, but then they may be struggling a little bit to figure out how do they integrate this new technology into that wider piece.
7:19Some are throwing their hands up. And we have seen with our customers, even some of our contracts saying, we have to give reps and warranties there that we will not use any kind of generative AI solution whatsoever within our tech. We're seeing like blanket bans. That's obviously not sustainable, right? Because the technology is so powerful and it's going to make such a difference. People are looking for, right, how do we do this responsibly? I still think we're very much in the early innings of this game. We have before December there, finally, after about, what was that, two years of negotiations between the various EU institutions, we reached an agreement, a political agreement on the final text of that act that has been working through all the kind of checks and processes in Brussels this year and will be published in the journal within the coming weeks here now and publication in the journal is when really the clock starts ticking to get people compliant there the first provisions there are going to kick in six months from that publication in the journal those are things like prohibitions on certain types of AI systems then you're also going to see a bunch of the really operative provisions coming in about two years after that has been published in the journal there that's things like the risk management system and the quality management system organizations know from their gdpr experience that getting this set up sometimes is time consuming right and it's not the kind of thing that you can just leave for the last minute and hope the day before this act comes in you'll be fully compliant within 20 minutes um you need a bit of a strategy and we are seeing that in the market now actually we are seeing movement that we've never seen before in this space thank goodness because we're trying to build a business and get customers um people are really taking their obligation now seriously and moving and starting to put in place the kind of frameworks we're just back from a conference in brussels that was hosted by the iapp that's the international association of privacy professionals they hosted their second ai governance conference uh and we were at the first one too and the difference in conversations we noticed between the first one and the second one was kind of mind-blowing because the first one which was in boston last year towards the end of last year in october was very much the what like what is this kind of thing right okay what is this in brussels a couple of weeks ago the conversation 100 moved to the high right okay how do we put the protests in place to do this how do we manage this how do we actually get the most out of this technology so that it can really have that impact that we want to see yeah okay well it sounds like to me that you know first of all you did answer the question um it's a great background leading up to it, but it sounds to me like a lot of your customers are people who just maybe felt the pain train from GDPR and realize that the sooner you get ahead of it, the less of a challenge it's going to be when things start rolling down.
9:51So you're educating your organization from within. Is that a fair statement? Yeah, I think that's definitely it. There's another nuance to consider here as well, which is the role of standards in this area. So if you look at what happened with the cloud technologies as they became quite ubiquitous, one of the key reasons that they've got to where they got to today is of course like the utility and the value prop of them but the trust that's in them as well and one of the key elements of that trust was the likes of those certifications um that's the standard bodies started and they prepared standards and you get certified in new standards so i think of like iso 27001 which we naturally have had to get because our customers asked for it and the sock 2 standard as well it's a bit more prevalent in the us these are like information management security systems so that you know that you hold yourself to really really high standards anytime you're interacting with customer data and anything that could be sensitive and putting that in place and making sure the right checks and balances are there.
10:45I think that standards are going to play a really key role in the AI space as well going forward. You've already seen standards from the likes of the NIST, the National Institute for Standards and Technology in the US. They published their AI risk management framework a couple of years back now. You've also seen the ISO 40 2001 standard, which was published just before Christmas. We do they get compliant with that what does the process look like how can our tech help all that kind of stuff and you're also now seeing at the moment there's a new standard as well 40 2006 which is the auditing standard so very soon you're going to start to see certifications in this the way that you saw on the cloud space i think that's going to be a really good enabler there's going to be standards from the european union themselves um it's a working group called senilec which is a standard setting body they have a working group set up to look at standards in artificial intelligence and we're expecting to see those kind of later this year the first year after those so standards are going to play a really key role in this as well and measuring against standards.
11:39And yeah, we're seeing organizations take real steps to put those in place now. So do you feel like simplifying Enzi into effectively a emerging standard compliance tool for anybody who's got an AI in their organization is oversimplifying what your product does? I think so a little bit because really we are as optimistic as anyone about this technology, quite frankly. Like I'm super excited about it. I want to see it have that impact in the world. To get there, to have that impact on the world, we know it needs to be trusted, right? And we view ourselves as a vehicle to enable that trust and enable that ability for people that use these systems with a lot of confidence and know that they're doing the right things in the right way.
12:18We view ourselves as an enable to that. To be able to do that, you should be holding yourselves to very high standards. Anytime you build, deploy or use any kind of AI, we make it super easy for you to be able to do that. we try and mix like if you just did this if you just put standards in place in your organization and you didn't use a specific tool to do it there is a heap of friction in that process right because you might use like an excel or something for an inventory of all of your different ai systems you may do some technical documentation on microsoft word or confidence pages or things like that all these are great tools in their own right i love them i particularly word i mean i'm a lawyer right and i know every little quirk and bug in that platform i think it's amazing but at the same time it's not designed for the specific unique domain and anything that does that and removes as much of that friction from that journey to hold yourself to those high standards provides a heap of value it allows you to get more systems in into your business in the right way doing the right things and we ultimately view ourselves as an enabler to making sure this technology has that impact on the world yeah i mean again i am trying to be absolutely reductionist here for the purposes of being controversial.
13:23But now if I were to oversimplify what you do as an AI regulation orchestration platform with multi-jurisdictional support, would that be oversimplifying it? That's why I should pitch it to devs, actually. They would love it set out like that way. If you said that to some of our legal buyers and the privacy teams and things like that, it would just be straight over their heads. I think that's definitely one way of positioning it. I just like to think of it as the enabler to ensure that you get the most out of these technologies in the right way. Yeah. All right. So fast forward five years, the world has changed.
13:53We've had some interesting political decisions that have been made in 2024 that led to very interesting outcomes five years from now. AI is in everything. iOS 18 is feeling very old and dated, but Siri is amazing. Where is Enzai in organizations? How has it changed the world? How are organizations feeling about its role within their teams? It's a great thought. That's kind of crazy, the pace of all this stuff, isn't it? Five years, who knows what the technology is going to look like in five years. But our goal for this company and where we want to be in five years is we want to be at the beating heart of large organizations that are really maximizing the value of these kind of technologies.
14:35We want to be there as a crucial cog in that wheel to ensure that they're getting everything they possibly can from this. We expect that will involve full compliance, all the different regulations all around the world. We'd very much like to see a lot of harmony, to be honest, in those regulations around the world. It would be a very lamentable situation if there was a million and one different regulatory regimes around the world for this with all of their own different requirements. I'd like to see some standardization there because that gives businesses certainly operating across all of these borders and jurisdictions.
15:02We will be at the heart of getting them compliant with those, at the heart of getting them compliant with all of those standards. And the process will be as smooth as physically, humanly possible with as little friction from the start right through to the end and keeping everything up to date. Nice. Nice. Nice. Well, to wrap things up, first of all, thank you for joining us. But to wrap things up, I'd love to hear what you might say to somebody who's listening to this, who might potentially be a customer. What is it that they're probably going through that you would encourage them to get in touch?
15:31You're probably at a stage, a lot of organizations here are at this, where you're a large organization. You understand your sector, you're a total expert in your sector, but you may not know that much about these technologies other than have read articles about how they're very important or had some vendors come and pitch you about their solutions. you may have been throwing your hands up and saying, hey, this is a bit too confusing. We don't understand any of this. We're going to say no. That situation is not sustainable, really, because a lot of your competitors will be adopting these technologies and will be able to move very fast as a result.
15:59Come and speak to us. Work with us. We will help you with some of the initial steps around this. Some of those initial steps involve things like just putting the right policy in place, right, for making sure that you're managing the risk, putting the right structures in place across your organization, figuring out a bit of a process that you can evaluate each of these tools by, evaluate some of your own if you're building them in-house by, figure out what those high standards look like, platform it all, and then operationalize it at scale using technology like ours. And we can help with that journey and we'd love to.
16:27So get in touch at hey.enz.ai. There you have it, guys. Get in touch with Ryan. Thanks again for joining us, Ryan. Thanks very much for having me. It's a pleasure.
From the publisher
- the impact of AI as a technological revolution similar to the mobile shift, dotcom boom, and web invention
- the importance of regulations and standards in ensuring AI’s responsible use and trustworthiness
- the challenges and opportunities in AI adoption
- Enzai’s mission of enabling organizations to leverage AI technology effectively and responsibly, in compliance with emerging regulations
- Enzai’s vision of enabling trust in AI
- future regulatory landscapes and the necessary frameworks for AI adoption
Chapters:
00:00 Introduction to the AI Technological Revolution
00:36 Meet Ryan Donnelly: Co-founder and CEO of Enzai
01:14 The Inspiration Behind Enzai
02:19 Understanding Enzai’s Customers
03:13 The Role of Regulations in AI
05:07 The Evolution of AI Regulations
10:26 The Importance of Standards in AI
14:20 Enzai’s Vision for the Future
15:49 Final Thoughts and Call to Action




