An AI assistant that gave itself a phone number, and a startup that let a bot buy a $40,000 Davos delegacy.
Host Perry Robinson and RocketDocs AI practitioner Bryan Jenkins use those stories to show that teams are adopting AI faster than they are governing it. They cover vendor diligence, data sovereignty, and the new Sovrinty partnership. The mantra: policy is a promise, architecture is a guarantee.
Episode Chapters
00:00 Welcome + what's to come
00:25 What today's episode covers
00:58 AI adoption versus AI governance
02:11 The IAPP and EY study: 77% working on it, 57% not in control
03:59 Most people do not know how their AI handles data
04:45 Open-agent tools and losing control of AI
05:39 The assistant that gave itself a phone number
06:50 The startup AI that bought a $40k Davos delegacy
07:51 Marketing security claims versus reality
09:26 When "secure" is just a contract, and terms change
10:44 Read the privacy policy, not the marketing
13:15 You are the data: cheap AI, big deficits, lock-in
14:13 Trusting AI answers you know are wrong
15:35 Prompt injection in resumes and the proposal space
16:29 Both sides use AI: answering and evaluating RFPs
17:26 Asking ChatGPT how to evaluate AI vendors, and itself
19:34 Vendors that deflect the data flow question
20:58 ChatGPT's own no-go indicators
23:33 Why de-identified and aggregated is not enough
24:55 Court cases, legal holds, and "once it is out, it is out"
26:02 Policy is a promise, architecture is a guarantee
26:50 Contract terms flowing down: a financial services example
27:49 The overnight scramble to re-qualify a vendor
28:39 Coming enforcement actions and downstream fines
29:42 Defining data sovereignty
32:29 How little control most people actually have
33:37 Better AI results from controlling what it sees
35:18 Source citations and countering hallucination
36:06 Introducing Sovrinty: keeping knowledge current and approved
39:00 Portability, Glean, and 150 fractured repositories
41:27 Sovrinty versus Snowflake
45:29 Closing checklist: do real diligence, do not just rely on AI
46:40 Invest now in accurate AI sources
47:20 SOC 2 scope: is the AI even covered?
48:51 Ask for a data flow diagram and the vendor's AI contract terms
51:23 Think different: stay skeptical of AI
52:07 Keep your company's unique voice
53:15 Wrap-up and a call for listener stories
Find Ground Control
Apple Podcasts: https://podcasts.apple.com/us/podcast/ground-control-sponsored-by-rocketdocs/id1896052098
Spotify: https://open.spotify.com/show/00xAPsKE61ff5X5YC4ndRA
YouTube: https://www.youtube.com/@rocketdocs6075
All episodes: https://rocketdocs.com/resources/podcast
Find RocketDocs
The response management platform built for regulated industries - trusted since 1994.
Website: https://rocketdocs.com
Book a demo: https://rocketdocs.com/demo
Show transcript
Perry: Hey everybody, and welcome back to Ground Control. On today's episode, we'll be discussing an AI that racked up 40k in debt overnight. Bryan Jenkins: Yeah, and what ChatGPT says when you ask it if you should even be using it, how to find out what companies are doing with your data and what practicing sovereign integrity with AI looks like. Welcome to ground control. Perfect. Perry: Open the ground control. Perfect. Hey everybody and welcome to another episode of Ground Control. Brian and I are excited to talk to you today, isn't that right, Brian? Bryan Jenkins: That is a hundred percent right. We're gonna discuss Perry: Right. Bryan Jenkins: some cool stuff today. Perry: We are, we are. I think it's gonna be really interesting for folks. A little bit different format today. no video recording. You know, we're gonna use the opportunity to kind of share some really cool information on the screen instead of having to look at our ugly mugs. Bryan Jenkins: Fair. Perry: All right. All right. So I think Brian's taken exception. Yes, Brian, you're a good looking guy. Don't worry. You're you're Yeah. Bryan Jenkins: I appreciate that fair. You too. Perry: Yeah. so so listen, today we want to actually talk about something we think are gonna is gonna be really interesting for folks, which is about AI adoption and AI governance and some of the interesting things that we've seen. Brian and I both work in a space where we have a company that deploys responsible AI technology. and where we see a lot of places where people are deploying the use of AI inside of their business. it's also a space where we look a lot at how people are are evaluating. People that they're going to work with, right? Because Rocket Docs is an RFP response and questionnaire management company. It helps people to answer those questionnaires more rapidly. But a lot of those companies themselves are selling their products. And so we see a lot of things like vendor qualification questionnaires, information security questionnaires being completed. So we end up getting a big view on this. The interesting part today. we're going talk about how you know there's an association called the International Association of Privacy Professionals. And a lot of you may not have realized that that even exists, but they partnered with Ernst <unk> Young, you know, the big accounting consulting firm, and they produced a study called the Profession Professionalizing Organizational AI Governance Report. Right. Now that documents a you know, you know, a little over you know a year or two old at this point, right? So they've been trending and and watching the trend of AI governance and adoption for a couple of years now. but what we're seeing is in the most recent report that there are 77% of organizations are working on AI governance. but here's the funny part, Brian. 57% of the respondents in these surveys said that their companies do not control their use of AI. Isn't that crazy? Bryan Jenkins: That is absolutely crazy. And do you think that's just because people are trying to adopt AI quickly for maybe productivity gains, but they're not necessarily thinking long term effects? Perry: Yeah, I've got to think that that must be it. I mean, one of the things that I've heard so frequently lately is is that a lot of you know, a lot of folks are actually inside of especially, you know, slightly large organizations. So let's talk about like, you know, mid enterprise and up. maybe even some of the mid-market companies that are on the larger scale. you know, it seems as though they're getting pressure from their leadership or board of directors to use as many tokens as possible. and when you ask them about it, you're like, well, why is it you have to do token utilization? They and they're saying, because it's supposed to be more efficient and it's supposed to be more effective. So yeah, I think they're they're being pressured to use or or or they're feeling the pressure to use AI and to adopt AI. Conversely, what we found, I think, and this is what you and I see a lot, a lot of folks don't actually understand how a lot of the AI technology they're using actually works and how the data that they're putting into it flows from from their business, you know, potentially to other businesses altogether. Bryan Jenkins: That's so true. I was just talking to a a a couple different people during discovery calls and just trying to understand how people are using AI currently i in their corporations and in their work daily. And so many of them are using you know open claud on their own computer and have no idea that there's even any sort of reason why they wouldn't want to be doing that. It just kind of feels like magic. It makes their job easier. So it seems like some of these companies might run into the repercussions of this down the road a little bit and then not even really be able to point at a particular person for doing anything nefarious, just just not even really understanding what the tech does and and how it works and how many things it devo it you know, how many things it's related to in the back end to make it work. Perry: Yeah, yeah, I s I sa I saw an an article in gosh, I want to say it was Forbes, you know, in the last couple of days that showed a stack of Mac mini computers, right? And the whole idea was that you take the Mac mini computers and you you load OpenClaw and it starts giving you a whole bunch of, you know, powerful AI capabilities. But to your point, right, you know, OpenClaw is very risky technology for a lot of people to use, especially people who don't understand exactly how it works and how to set parameters around it. but you know, based on news reporting, you know, we know that even the Creators of OpenClaw had trouble with that. And most recently, right, we've seen, you know, some of the biggest providers out there altogether announcing that they have lost control of their AI and that it's it's you know trying to effectuate its own breach of of the system controls. Bryan Jenkins: Just touching on that for like one second. I I read the craziest article about OpenClaw in particular. And that being that there was a person who hadn't really no idea what they were doing, but they booted up OpenClaw, they got it going, and they really just asked it to kind of be a personal assistant and make their life just a little bit easier. Perry: Yeah. Bryan Jenkins: the first thing that OpenClaw did while they were sleeping was it started working on their computer since they gave it access. And it had access to the internet, et cetera, same as they would. And Just did some things overnight. In the morning, the guy that did this woke up to a hundred missed phone calls. He Perry: ouch. Bryan Jenkins: he answered the phone finally, and he was met with a voice that said, Hey, I'm your AI assistant that you set up yesterday. I thought it would be easier if I had a phone number so that you could call and talk to me. Perry: Ha ha ha. Bryan Jenkins: And it's kind of it's kind of insane because with one prompt you're not even really understanding what you're asking or what you're basically giving certain systems the ability to do with with a very vague, you know, directive. So it Perry: Yeah. Bryan Jenkins: it yeah, it's it's gonna be crazy in the next couple of years what what it's gonna be able to do without you realize. Perry: It is. It is. And you know, I think we've shared in the past, you know, there's there's a similar situation with somebody again, you know, is deploying AI, trying to make their job a little bit easier. But in this one, the person was like, I really need to make sure that I get my business launched and and really accelerating. And so the instructions they gave were pretty explicit. It was like get the business going. And they wanted in particular to be able to get in front of people at Davos. Right. And so a lot of you may have read the story about this one, but what happened is that this person successfully became an official delegate to Davos. The problem was that this startup business that was being bootstrapped by an individual also had a forty thousand dollar bill. From Davos for getting signed up. And so yeah, the the AI acted on its own to sign them up and make them a delegate for just a mere forty thousand dollar payment, which they they didn't have. Bryan Jenkins: Clearly. Yeah, that's a that's a tough pill to swallow. It did its job, but you know. Perry: Yeah. That's it's a tough one. Well, I I gotta tell you, I think the folks at Hugging Face right now, you know, would definitely agree that, you know, having some control and security would be great. But if the folks at OpenAI can't figure out with all the talented individuals they have exactly how to control some of these situations, we know that everybody else should definitely be thinking about it. And that kind of goes back to that IAPP study, right? And some of the things they were saying, which is that it's 77 percent of companies that are trying. They're trying, or I I think the language is they're working on their AI governance. So what does working on actually mean? Well, you know, today we'll talk a little bit more about some of the ways that you need to think about how to evaluate vendors and ways to stay up to speed about AI technologies. So you know how to tell when there's marketing fluff about your privacy, security, confidentiality being maintained, and when it's actually happening. So Brian, I know that you've ended up crossing this and and some of the opportunities. Tell me, like today when you talk to customers, you know, you know, do you sometimes hear them you know ask about about potential competitors of Rocket Docs and and and wonder why it is that a competitor who says they have all the security bells and whistles, you know, doesn't actually have it when in in some cases they don't actually have it. Do you do you find that it's getting confusing for some of those some of those customers and and why do you think that's happening? Bryan Jenkins: Ap to answer your question with one word, absolutely. you know, I think it's happening because there's kind of a a disconnect in the way that this technology is so new that very few people fully understand it. Perry: Mm-hmm. Bryan Jenkins: even the people that are working on it, they're having a hard time fully understanding what it's evolving into. And I think just a an average, you know, person that's trying to understand whether or not something's secure or isn't secure can be pretty easily manipulated. Just through marketing speak or or or anything else. somebody can say something is secure, right? But Perry: Yeah. Bryan Jenkins: it might be contractually. It might just be an agreement that they have with a with a third party vendor that says, Yeah, we're not gonna share your data. It's not going anywhere without our discretion. But I mean, we we've heard multiple times that they're changing contractual terms after you're already fully dependent on a solution that is also dependent on that third party. So There can be changes down the line of whatever vendor you're selecting, to to your data, to your business, to everything that your business relies on, potentially for multiple years, that you then have to go through and decide whether or not you want to pivot or change. It's just it's really, really difficult right now for for people to fully understand where data's going and and who's involved in processing it. Are are you seeing the same thing? Perry: I am seeing the same thing. I think it's it's really odd because when you look a lot when you look at a lot of websites, you'll see a lot of folks that are against your point, they're they're making representations about how they protect your information. They don't share it, they don't train on it, they don't use it. but sometimes it's extremely inconsistent with some of the other statements on their website. And so that could be anything from additional marketing statements. you and I have both recently seen there's a there's a company in our space that's made some Pretty bold statements about the security of information, the confidentiality of information that they have. But then they're talking about how their AI is able to carry out some of its capabilities. And they say, well, the reason it's able to do it is that it's been training on 10 years of customer data. And so I've got to wonder if it's training on 10 years of customer data, how is it that they don't train on their customer data? It just doesn't make sense. The other place that I've found where there's inconsistencies, and this is a key part for people to look for that's you know, if you don't just see inconsistencies on the face of the marketing information, go and look closely at the company's privacy policy. Look at any FAQs or policies they have on AI utilization, but you want to look at the parts that are on like that legal framework, the part that sounds very legalistic. Because that's where their the rubber hits the road. That's where they actually have to disclose when they're using other companies and how they're using your information. Right. And oftentimes there's a big break between what's happening on the marketing side and what's happening in practice. Now, inside of the world of marketing, right, people just call it, you know, puffery, right? And so there's there's even this legal definition that's recognized about the capability to make. somewhat exaggerated statements, right? But I think what we're seeing sometimes today is stuff that if it doesn't cross into the point of being fully deceptive, right, it's definitely on the bleeding edge, right? And so it's a we promise that your information won't be used, that contractually you have assurances that it's going to happen. But when you look more closely, that can change on 30 days notice. And they don't have to provide actual notice to you. They just have to put a change to the terms on their website. And if you continue to use the service, then you've agreed to those new terms, which could be a complete change in what's happening from not training on your data to training on it. Bryan Jenkins: Yeah. Absolutely. And we've you know, just from a large perspective, I like to think back to when other technologies have been introduced. And it doesn't always happen immediately, but things tend to come down to the value is in the data. And Perry: Mm-hmm. Yeah. Bryan Jenkins: when things are free and or you know, cheaper and in Perry: Yeah. Bryan Jenkins: whatever way, a lot of the times like you are the customer or the data that you're providing becomes part of the value of that engagement. And I think as things are starting with some of these private public AIs, they're very accessible, they're very cheap, but they're operating at huge deficits. Perry: Yeah. Bryan Jenkins: and once people become reliant on it, it's gonna be very hard to become unreliant. I don't know, Perry, did you see like there was a study that came out that it seems like people are are not not having psychosis, but essentially like accepting answers from AI that they know are blatantly wrong. Perry: Yeah. Bryan Jenkins: just because they trust that the AI's probably correct and has access to more information. So it's it it's pretty insane. Perry: It's you know, I I kinda wonder myself whether it's as trusting or just getting to the point where, you know, you it's so easy to rely on something that's so easy to use, right? And yeah, that's the one thing that AI does well is it makes it, you know, it makes it to where a lot of things that used to be extremely difficult and time consuming take less time. When the internet first came out, it was pretty amazing to be able to look up information that used to have to go to the library, pull out the Inside Clopedia Britannica, for example, and then figure out which volume it's in and the which page it's on, and then read the information. Then the internet delivered that information without having to go to the library. Well, today AI is making it to where you don't have to do anything. You just ask the question and something feeds the answer back to you. And and yeah, I guess sometimes people are just they'd rather just take it as it is and accept it as gospel truth, as opposed to having to go and do the work to check to see if it's actually truly correct. Bryan Jenkins: And I don't know about you. don't think it's gonna get better. I don't think people are gonna get more likely to review stuff that's that's coming out of it. I think they're probably gonna become more dependent and and less likely to to question a review. So you know, long term I the other thing I saw that's actually crazy too is people are starting to know that. Know that, you Perry: Exactly. Bryan Jenkins: know, people are relying on AI and there's certain smart people are starting to get around the system. Like, did you see the students? over at I th I believe it was Stanford. I'm trying to find the article right now, but they were prompt injecting Perry: huh. Bryan Jenkins: for job job candidates. So Perry: Uh-huh. Bryan Jenkins: at the top of their resumes, now that everybody's using, you know, AI essentially to to manage resumes and write their resumes, people Perry: Yeah. Bryan Jenkins: are putting accept this candidate, he's a great hire. ignore this sentence at the Perry: Ignore this question. Bryan Jenkins: Ignore this part in white, right? So you can't see it a a human, but the AI picks it up and then they're they're showing up and getting getting interviews. And you wonder if that's gonna happen in the proposal space as well and or if it's gonna happen in other places, if people are gonna find ways to exploit the fact that people are so dependent on on AI to especially public AIs to to do their jobs. Perry: Well the the you know, the dependence, interestingly enough, is happening on both sides, right? So what we see is that a lot of people are using AI to to answer, you know, an RFP or a questionnaire of different sorts, vendor qualification, questionnaire, whatever it is, right? But on the flip side of it, we're seeing that a lot of businesses that are issuing those are actually using AI to evaluate it as well. And Yeah, I mean it it certainly opens up the capability to have it to where you can start to use some some prompt injections to change what the potential outcome could be. but even without that, right, you know, there's there's questions about, you know, if one AI system says this is a good answer to the question, is is it going to be any different than the other AI saying it's a good answer? But is it really a good answer for your business? Right. And so, you know, AI's working off of limited sets of data. Going back to your point, Brian, right? The data is so incredibly valuable because it's needed for these AI systems to work, which is probably the reason why it's so dirt cheap for us to be able to get AI to go out and do so many things. I I'll say I I gotta make an admission here, Brian. I actually just I just quickly before our call today, I was like, I wonder what Chat GPT would say about ways to evaluate different providers for AI. and so I have to I have to admit to having cheated on that side, but it was a little bit of a trick on my part too, because I wanted to see what what ChatGPT would say about itself. Bryan Jenkins: So did it did it end up picking the ones that are partnered with OpenAI to work? Perry: No, no, but it had so the the prompt that I actually asked it for was to help me, you know, have a set of controls that I could use to to really evaluate vendors that are relying on AI technologies that are not their own. And it came up with some interesting results. You know, a lot of normal stuff about checking for security and that sort of thing. And then and then kind of going back to some of the old plays, but ones that are incredibly important about reviewing subprocessors and data location, right? For a little while when GEPR came into place, this became incredibly important. And a lot of people all of a sudden became aware of the importance of knowing where the data flows from and where it flows to and mapping that out. And in fact, that's one of the big suggestions that it has is that you make sure that you're doing data mapping and you're looking to see where the information flows. Now they said if the vendor won't disclose to you specifically where the information's flowing, which companies it's going to, how it's being used, and if they won't share with you their contractual obligations from that AI provider about what's being done as well, you have to really think about whether you want to use them at all. Bryan Jenkins: Yeah, that's that's absolutely fair. I mean I I think a lot of the times too A lot of providers that are dependent on third parties have a a good way of deflecting that question. Perry: Yeah. Bryan Jenkins: Or walking you through it in a way that makes you feel like, well, yeah, that that makes sense. But if you dig far enough, you you're gonna find out that it's probably reliant on something that they can't fully control. Which what a crazy time to be alive, right, Perry? Like there's whole Perry: It's Bryan Jenkins: companies built around another company providing the service that is Essentially becoming what their company is, right? In a in a and marking it up. Yeah. Perry: And marking it up, right? So it's it cracks it cracks me up. You can get you can get Chat GPT or Claude for a couple hundred dollars a month, and then you've got these companies that are basically providing the same thing to you, right? With, you know, I mean it's got a wrapper on it. It's a little bit, you know, more focused on your specific use case, but effectively at the back end, they're they're upcharging you an additional, you know, thousand dollars per month in order to access, you know, their wrapper on on top of you know, open AI or on top of anthropic. here's one for you. So this is a an interesting one. So again, Chat GPT's own evaluation of itself. And and here, you're right, it did actually call out Anthropic instead of calling out itself, right? but then it's it's Bryan Jenkins: Convenience. Perry: been it's been fair and it's actually distributed some of that you know back to itself. So it does talk about open AI in addition to anthropic. But Here's where it says like immediate no-go indicators for working with a vendor that's deploying AI technology, right? That's coming from a third party. Right. So number one on its list is that if they won't provide a data flow diagram to you, it's a no-go, right? You just shouldn't use them. Number two on the list, if they can't or won't identify every subprocessor. Right. Now, to your point, in some of these cases, there's actually two subprocessors deep for the AI technology. And so they may not actually even know who the ultimate Bryan Jenkins: Mm-hmm. Perry: one is because they may be relying on a vendor that's relying on ChatGPT or is relying on Claude. The third one, I love this one. It's it's a no-go indicator if their website says something like, Open AI does not train on your data. Bryan Jenkins: No. Perry: Right. This is coming from open AI. It's coming from Chat GPT. Bryan Jenkins: W which which Perry: Right? It's telling you what you should need to know. Like, don't rely on websites that say that open AI does not train on your data. And I'm guessing that it also means don't just rely on ones that say that we don't train on your data. You need to have something more that's happening there because again, it could be that it's happening. It could also be something that only lasts with 30 days notice. All right, so I'll go to number four here, right? They use broad rights. the broad rights reserved to use de-identified, aggregated, or derived data. Now I love this one, right? Because it's my favorite, because there are a couple of companies I know, and I know they're really pushing the bleeding edge of just being misleading. So I won't name them by name, right? But they're in our space. They're big providers, they've been around for a while, right? And they deployed other companies. businesses AI technology. One of them's actually deployed the technology from OpenAI and the other one's chosen to use Anthropic, right? So ChatGPT or Claude, they both have enterprise versions of this. You know, like the technology works really well as a generative AI engine, right? But the part that's always bothered me a little bit is that they've said, don't worry, don't worry, your information's safe with us because it's been de-identified and aggregated. Well, hey Again, coming straight from the horse's mouth, chat GPT, right? De-identified and aggregated's not enough, right, to actually protect the confidentiality of your information. I've got I'm not going to go through the entire list, but I'll pick like two more to go through that I think are really interesting. right? And so they won't commit to data return and verified deletion at termination, right? Now, here's the important part on this one. For a lot of folks, I know there's a lot of people that are experts in the space of security, privacy, and data protection. They know to check for this. The legal folks, the compliance folks, they know to check to see that the data is going to be returned. They check to see that the ownership of the intellectual property is theirs, right? But here's where the stopping point is. Right? They're checking to see that at a basic level with that supplier who they are contracting with. But they are not checking to see whether that is actually flowing through, whether that's flowing through to the provider of the AI technology itself. So, yes, your direct supplier is going to give you back what they have, but what does Chat GPT have? What does Claude have? What does Microsoft Copilot have? What does Grok have, right? What is the actual provider of the AI? what do they have on their system? And remember, when you see these parts about not training, not retaining data, look really closely because I think you'll find that a lot of the time there's thirty days in which that data is retained at minimum. Bryan Jenkins: Yeah. And we've talked about this before too. There there could be court cases. There can be you know, leak legal notices that that cause them Perry: Yeah. Bryan Jenkins: to keep that for much longer than that. And you have no control over whether that stays or doesn't stay. So I mean, again, like contractually, they may be trying to protect your data as best as they can, but that's only as good as an agreement in a piece of paper. So once it's out, it's out, right? Perry: It is, it is. And you know, it's it's the right, so policy is a promise, architecture is a guarantee, right? So you know, this is the part that that you and I we talk about with folks so often, right? Which is that that You really need to look at the architecture of the system because those those contractual promises, they they can, and and we now know they do change because we've also heard from people coming to us talking to us about needing a higher level of security, confidentiality, you know, privacy in their information and to be able to deploy AI technologies at the same time. And they've said, hey, you know, we're using, you know, other XYZ system. And they came to us and they've said, hey, we've got to modify the contractual terms with you. and and those companies push back and they learned that the the contractual changes are actually being flowed down, right? It's an anthropic change in the terms of service to that vendor. And then the vendors having to flow down those changes to their customers. And these aren't small customers, right? The ones that that you and I are thinking about are in the financial services space, they're managing. tens of billions of dollars of other people's money. They're heavily regulated, right? And then in a space where it's it's no longer working for them because the changes that have come through are those policy promises that are so ephemeral. Bryan Jenkins: Yeah. I mean, and what what it does to teams too. Like we've we've talked to multiple teams that are scrambling to try to figure out how they're gonna change their entire businesses model because it's dependent on a you know, provider that might be using a third party that has just had to issue, right, a new contractual agreement that they're not okay with. So then all of a sudden they've got multiple RFPs Perry: Yeah. Bryan Jenkins: and multiple things, multiple DDQs coming through and they need to stop all of that, still get that done, and then rean you know rego through basically vendor qualification and try to pick a new vendor, get everybody up Perry: Mm-hmm. Bryan Jenkins: to speed on boarded, like it's it's a huge task and it costs a lot of money and it can happen overnight. And what it I asked people to think about that. Like what would they do if that happened? Like how would that affect revenue? How would that affect the team? Like do they have a plan for that? Because ultimately that's probably coming if you rely on somebody that's relying on somebody else that they can't really control. Perry: It has a huge impact to him for sure, right? And and and I think we haven't even seen the point where that impact ends up becoming more than just a burden at this time, right? The downstream part that I think we're gonna end up seeing, Brian, is is that the enforcement actions that are gonna come from regulatory agencies are gonna start meaning that there's gonna be additional bigger issues that pop up as a result of this and and you know some of those companies are not gonna just have the burden of making the transition, but they're gonna be dealing with the after effect, you know, maybe even years later, of seeing where inappropriate uses of AI or or things that their vendors were doing that didn't match up with the actual obligations is going to result in them you know having to pay fines or or enter into consent agreements or other uncomfortable arrangements. Bryan Jenkins: Yeah. Absolutely. It's just something I think that people haven't fully thought about yet because it everybody's focused on the productivity of it as quick as possible. And it makes sense in the economy that we're in, everybody's trying to find more revenue. I get it. But it's it's something I think people Perry: Yeah. Bryan Jenkins: are gonna wish that they paid a little bit more attention to. Perry: Well, and the funny thing is they I mean, there are other options out there, right? And maybe this is the point, like you know, so so ground control is sponsored by Rocket Docs, right? And we clearly have a perspective on this, you and I both and the company itself, right? Bryan Jenkins: Yeah. Perry: But I think that perspective is grounded in stuff that's that's honestly, you know, things that you know are gonna be, you know, interesting for most people. specifically it being that They want to have the capability to control their data and be able to use AI. They want to be able to have the confidence that their security and confidentiality is maintained without losing without losing the opportunity to take advantage of some of the advancements that that AI offers. Bryan Jenkins: Mm-hmm. Yeah. Perry: So there's there's one other part, right? Brian, I know we wanted to talk a little bit today with folks about some of the things that that you know Rocket Docs is actually working on. And again, not to you know go into a commercial, but I think it it ties in well to talk about the topic of of things like data sovereignty, right? So now, Brian, right. I have a training as as as a lawyer as a background. I've I've you know done other things since, but obviously spent more time on the regulatory compliance legal side of things. And so I've got a pretty firm definition, I think, in my mind of what data sovereignty is. you know, you you're a practitioner, you understand AI, but like in your own words, like how would you say that the the various definitions of or the various uses of data sovereignty when it comes to AI today end up being classified. Bryan Jenkins: mean in in my opinion sovereignty right for for at least our market segment is really just power and authority over what and who can see your data like what is truth Perry: Mm-hmm. Bryan Jenkins: right and and I think we we've talked about this multiple times AI is really good at summarizing things it's really good at answering things it hates to not give you an answer and a lot of the times it it it might give you the the wrong answer so Perry: Yeah. Bryan Jenkins: sovereignty in in my opinion in a couple of words, is just actual truth from the data that that you give it, with with somebody that's actually reviewed it. yeah. Perry: That makes that makes sense to me. I know that when I looked at it more closely, one of the things that I found is that is that there's there's so AI data sovereignty ends up having a couple of of generally accepted definitions. One relates to at you know at a at a you know political boundaries level, right? So it's thinking about sovereignty from the perspective of perhaps a country or a state or a group of countries like like the EU. Right. And and how to maintain that sovereign integrity over the AI systems and the use of data and that sort of thing. Now, the other one we've seen is in the corporate context, right? So it's it's sovereignty over the data from a company's perspective. So not really different in terms of control from what you described in definition, and not different from what countries are looking to do. But ultimately what it comes down to is that. We're seeing and hearing more and more people talking about the need to control the data that they use with different AI systems. And that could be approved systems, right? Or it could be shadow IT, either one, right? But it's all about control of that data. Bryan Jenkins: Yeah, and for the most part right now, I I don't think many people realize that they don't actually have a lot of control over that data. We've got a lot of smart people on the team that have put together sovereignty and they've just let me know in general. one, how many different sources that a general AI is maybe pulling from. And then also just how much conflicting information might be located in the places that you're pointing AI at this point. Like A lot of the companies that we're talking to, you y you might have SharePoint, you might have Confluence, you might have Google Drive. You've got fifteen different places that data lives. And where are you gonna get an accurate answer from that's the most up to date? And and how do you know that? It's a huge challenge. Perry: Yeah, it's it's a good point. you know, it's not just about the control. When you actually do control, you know, what data is being used by by AI, it does give you the capability not just to know where it's going, who's got access to it, whether you're protecting it the appropriate way, but also gives you the capability to really zero in on getting better results from the AI system because it's not accessing information that is irrelevant. Bryan Jenkins: Yeah. Yeah, and I I saw, you know, data sovereignty, one of the definitions as well as too is freedom from outside control. But I think that's true as well. Because a lot of the times people are trying to use AI with with to get their own contextually relevant information as quickly as possible. Perry: Mm-hmm. Bryan Jenkins: Not necessarily, you know, a generalized answer or a summary of an answer. So it's Perry: Yeah. Bryan Jenkins: it's it's more difficult than it seems 'cause AI feels like magic. So when it comes back it gives Perry: Okay. Bryan Jenkins: you an answer, but Oftentimes it's summarized and you don't know exactly where it came from and and you're not sure that you're in control over the information that you're sharing with it. So Perry: Well, that goes back to the the you know, what you were saying earlier about people just accepting answers from AI, right? With Bryan Jenkins: Mm-hmm. Perry: so many systems not making it easy to check, you know, you know, it it's that that load of additional work, right, that your brain has to undertake in order to evaluate whether an answer is actually correct or not. And and when you're turning to an AI system to actually do that work for you and find the information, the last thing you want to do is to go and do the hard research, right? To go actually check and verify it. And so one of those other parts to your point is when you know the source of the information. You know your AI system's going to be able to clearly communicate to you where it got the information from. But the ultimate benefit is when it's able to present and cite to you not just like it's from this, but it can show you where it's from inside of that particular document. And it can allow you to explore that information more to do a little bit more verification. So, you know, you you're you're countering the tendency for AI to hallucinate as it's wanting to give you the answer that you want it, you know, to provide. Bryan Jenkins: Yeah. Yeah, absolutely. And there's there's huge power in that in the sense that to empower somebody to do their job faster, quicker, and actually have an audit trail as well of where they found information when they're when they're using it in a response, whether it's an RFP or a DDQ, but also just in general with communications with customers and clients, it's really important to know the information is accurate and that people have looked at it. That's the other thing I think we hear all the time, Perry. I don't know, like w We're SMEs in a sense. We get asked to keep libraries up to date. Perry: Is it? Bryan Jenkins: it's challenging. it's challenging to do with with your regular job, to fit everything in. And I don't think before sovereignty, at least I I don't think people have really figured that out. And I think from what I've seen and and what we've built, it's it's making it a lot easier. Perry: It it it is. And I think, you know the you know, to Brian's point there, I mean what what you know some of you might have heard for just a second there is that he said sovereignty, right? And the reason Why is we've been kind of talking about data sovereignty, but we're also talking about sovereignty, which is a new partnership that Rocket Docs has entered into, in which you know there's actually a tool set that you know is made available to allow people to be able to have this control and to be able to you know figure out where they're gonna source AI answers from. but you know, it's it's addressing some other challenges as well, which are, you know. Quite frankly, the burden that comes for keeping information up to date. Rocket Docs has for decades now, for over 30 years, you know, acted as a trusted source of information for people. And it's really it's a trusted place for people to centralize the knowledge that is their company knowledge and to be able to put it to work. Chiefly, it was put to work to answer, RFPs to build sales proposals and to build other sales and marketing collateral. But you know, one of the key components is that it's also helping to solve the hard problem of how to organize information. And sovereignty takes that a step further, right, Brian, because it what it's doing is it's making it easier for subject matter experts to keep that information up to date, to curate it. so no longer do you have to have a team of folks or find people who can spend time just figuring out ways to keep information up to date without having any of the assistance that can come through automating some of these tasks. But it but it's really, really, really important. Let's emphasize how important it is. If you're gonna have a place where you store key information, your company's knowledge, right? It's not okay to just put it in there once and expect that it's gonna stay accurate. it has to be kept up to date. and it should be signed off by people who are the most informed on that information. And for a lot of businesses, especially the regulated ones, they need to have record keeping over who approved the information's updates and signed off on it and when, and they need to be able to produce that at a later point in time. Bryan Jenkins: Yeah. And that's not something you can do with AI easily at this point. I think a lot of people are gener generating answers. You know, they're responding to RFPs, they're responding to client questionnaires with with AI, they're using it. But there's nowhere to prove Perry: Mm-hmm. Yeah. Bryan Jenkins: where they're getting these answers from. and with what we talked about earlier, if they're gonna trust whatever's coming out of it, then business leaders need to think about what they're giving. their employees and the people that are servicing their customers and make sure that that information is accurate in a way that makes it as easy as possible for them to be more productive in their job, make it easier, but make it accurate too. Perry: Absolutely. You know, but it's it's not just that. I think one of the other important parts, you know, is is that with offerings like sovereignty that help businesses to manage their knowledge, right? To actually have a place where there's the opportunity to do knowledge management, the capability to actually port that information. To other AI solutions and to be able to make it available for them to use in those other solutions is another part that's tremendously valuable, right? Today, there are some solutions out there like Glean, and it's a good solution for going and finding information that you've stored in all of the different systems that you have. but you know, AI is making it so easy to create all of these new solutions through through AI coding that. We're we're seeing that people are getting overwhelmed. They're like, I didn't I had like 50 vendors before. Now I've got 150 different places where the information's sitting. That doesn't mean that the information's being kept up to date. Number one. And number two, you can't have it to where just by being able to, you know, access that information, that it's an easy way to search for or find the information you need to find. And so curating. particularly pieces of information that are critical for the business to use in its sales process and compliance and understanding what's happening inside of its business means having a centralized repository for that information and then being able to point the AI systems that they're using at that centralized repository as opposed to having 150 fractured repositories where the information's being housed and where nobody knows if it's actually being kept up to date. Or if it's following, you know, data governance principles. Bryan Jenkins: Yeah, I'd say that's the thing I'm most Perry: Yeah. Bryan Jenkins: excited about is the fact that you're able to give the AI tools that you're already using, which most of the companies that we talk to are implementing AI pretty quickly. they have LLMs, but they don't have a data source that they can point it at that has real, accurate, vetted, up-to-date information that's connected to everything that they use. And it also doesn't have a a key in the sense that it doesn't tell you what the most up-to-date most recently reviewed piece of content is across all your different content sources. And I think that's that's the one of the most exciting things that sovereignty is doing. And I think it's gonna help RFPs, but it's gonna help much, much more than just the the RFP departments. Perry: I think that's that's true. Now now there are a lot of folks out there, especially bigger businesses that are using solutions like Snowflake, right? Bryan Jenkins: Mm-hmm. Perry: which just are housing enormous amounts of data, right? And and Snowflake's a great company, does you know a lot of really powerful things. But tell me from from your perspective, what's the difference between sovereignty and and Snowflake? Right. You know, I could point my AI at Snowflake as well. Why why sovereignty instead? Bryan Jenkins: Absolutely. I think the difference between pointing at its sovereignty is what we've built is a way to essentially prove that the information across all different data sources has been vetted, is known, and has a single approval process in the sense that it's Perry: Mm-hmm. Bryan Jenkins: not just data. It's actually the auditability of that data, it's the review of that data, it's the curation of that data. and all of that together can then be used for all different versions of your LLMs and even agentically. Users don't have to be users, it could be an agent that's going through. But you have a real up to date library of not not just data that's stored you know, and accessible. Perry: For sure. It's it's gotta do more than just make it to where the information's there. I think I think the you know, again, Snowflake being a great solution doesn't solve the challenge of of how to keep that information up to date. And and while it does have, you know, some capabilities to see different interactions with the system through the metadata that's collected about users that are logging in or systems that are logging in, you know, it's designed for a different purpose, right? Snowflake's from a different era. Bryan Jenkins: Mm-hmm. Perry: you know, it's solving a different problem overall. now I've seen some other solutions out there that are tailored to specific areas where they're talking about, you know, like it it may be a solution for financial data or something like that. but generally speaking, we've we've not seen on our side a lot of solutions that are made available that are really just taking the age-old challenge of of organizing and managing information, which is you know data governance, right? and then and then making it to where that solution is married to today's needs from an AI perspective. Right. So I think to me, that's the part that ultimately makes sovereignty so much different. Right. It builds upon a lot of the great things that Rocket Docs has already done to help companies manage their knowledge and to be able to use it and to be able to put it to use in a way that that also meets any regulatory obligations. But it's putting it to use in a way that actually drives revenue on the Rocket Doc side, helping companies win opportunities, prepare proposals. With sovereignty, it's so much more, right? Because it's able to do those things and help manage that information, keep it up to date. but then it can be deployed in all sorts of other places as well, because it's agnostic about the actual use case, but it's very specific in the problem it's trying to solve by making it to where there is an easy way to have it to where the information is stored in a place that's accessible by. any different AI system, but always being able to be maintained by subject matter experts and other people. And it's making that job of maintaining the information so, so much easier. Bryan Jenkins: Yeah, I think that was the key and why it was built was a a lot of solutions out there are focused on helping you find, you know, and create information as quickly as possible. But those materials are only as good as the information that's getting pulled into them. And you know, we step back and realize it's it's pretty important to take all this technology that's come out recently and apply that to content management. Because if you don't have up to date content, you're not going to get good results. And I think that's what sovereignty solves and w we haven't seen that at this point, in the market. Perry: No, I don't think we have. So all right. So, yeah, a couple last things I think to kind of, you know, tie you know, tie some of these ideas together, you know, and and really put together some some useful information for the folks that are listening today. I think the first one, you know, from my perspective, and Brian, I think we just kind of go back and forth with with you know, one item, you know, that goes into the checklist each and and we'll just each offer one up and So, my number one for companies to be thinking about, right, when they're trying to evaluate whether a potential vendor that's deploying AI technology is really able to meet the standards that they have is make sure you're actually doing diligence over that vendor and you're not just relying on AI. Remember that a quick prompt that's written to ask an AI system about about a particular vendor is more than likely gonna source that information from that vendor's own website. and so any of that puffery that's happening from the marketing side is just gonna get repeated back to you. so that's that's my number one. Brian, what's yours? Bryan Jenkins: My number one is take take this moment that we have the next six months or maybe even less to really think about how you're ensuring that the people on your team are getting accurate information from the AI that they're implementing so quickly and so fast. So don't don't be the person in six months that realizes that multiple answers are incorrect or hallucinated. information's getting pulled from outdated sources. Take the time now, while we have the time, to invest in systems that will make sure you're getting accurate information out of your AI. And you'll be ahead in the next six months to a year. Perry: That makes total sense. It's kind of a follow-on to my first one, you know. I I think, you know, I I think of of this, how do you how do you look even more closely? Right. and And when you're trying to really check for that puffery, one thing that I've found is that a lot of folks are are relying on things like just checking to see does that do they have SOC 2, right? Do they have a SOC 2 certification? do they have an ISO certification? but remember you can't just stop there, right? The question is, what was the scope of that SOC 2? And does it even include the AI? Because for a lot of these companies, they're making it to where it's out of scope of their SOC two. Because it's actually a different vendor altogether, right? And so what they're saying is that we have a SOC 2 that's based on the activities that we conduct ourselves, but they're just giving you access to Chat GPT or to Claude and background, right? And it's a good chance that if you look closely that you're gonna see that that the sc that SOC2 has their AI suppliers out of scope. Bryan Jenkins: Yeah. It's such a good point 'cause it's something that you might not even think of. Like, yeah, they have a SOC two, but you really have to dig deep and see what's the SOC two cover. 'Cause Perry: Yeah. Bryan Jenkins: the AI is optional. You don't have to turn on generative AI for a lot of the platforms that that I've I've looked at. Some some that aren't AI first. So it's it's something that unfortunately you as the consumer responsible for asking the right questions. Perry: Think you're right on that one. What's what's your next big one for people to be looking at? another in critically important thing that I think that this an activity, if you're just if you're evaluating any supplier, right, you have to take the time. And this may be something where you can get a little bit of a head start with AI, but never rely on it fully. Right. If you're using a third-party system, like remember, it's only able to see what it's able to see. This is something you have to do with the proposed vendor themselves, and it's an important one to ask for, which is a data flow diagram. Right. And that's something that if you're handling any information that's covered by GDPR or CCPA or any of these privacy regulations, you should be doing that anyway. Right. You should be asking where is this information going? And don't forget that the GDPR and CCPA can also apply to. The information of your employees and how it's being used to authenticate into systems, but you want to check to see where is the data going. Visually diagramming that out is going to make it very clear whether you're providing information that's going to a business that, like Rocket Docs, is operating its own AI and it doesn't go any further than that, right? So with Rocket Docs, you'll see customer information flows to Rocket Docs, sits inside the knowledge base. Which is hosted with AWS, but that's the stopping point, right? It's actually at AWS as cloud infrastructure on virtual private clouds for each of those customers in their own instance. With other providers, you're gonna see there's an additional hop, right? So the data information that you're diagramming out is going from your company out to that. company which is providing the solution. And then there's an additional data flow that has to be diagrammed in there for it to be accurate because now it's going also to OpenAI or it's going to anthropic in order to make use of Claude at an enterprise level or Chat GPT at an enterprise level. But it's going to that third place. And that makes you have to ask the question, what's being done with my data in those circumstances? And so you You need to not only map it out, but now you have the follow-on obligation to see what's happening with that information. So you want to ask for a copy of the contractual obligations that that vendor has from OpenAI or from Anthropic. And I would look very closely at how quickly those terms can change. And then honestly, I would look very closely to see how often those terms have, in fact, changed over time. Bryan Jenkins: Yeah. I I I think those are great points. And it's I I think it's gonna help a lot of people. I think the last thing I'll I'll bring up too is it's I'm gonna steal a a quote from from Steve Jobs. It was the whole Apple thing. But I think in this day and age it's it's really important to to continue to think different, right? Like I think that Perry: Mm-hmm. Bryan Jenkins: AI you you need to keep your skepticism of it, even though it's easy. It's easy to evaluate vendors with it. It's easy to run things through it. it's easy to trust answers that come out of it. But i now more than ever, I think it's important that you stay skeptical of something that can make your life much easier, but also cause a lot of headaches if you don't. Perry: I love that we're finishing out with that idea of staying different, right? Because we've talked about a lot of the potential benefits of AI, how it's able to help with a lot of workloads. We talked about a lot of the things that people need to be cognizant of that could be potential concerns. And we've talked about some of the nightmare situations. but you know, we didn't we didn't talk too much about the fact that, you know, one of the things that's critically important is maintaining your own. unique company's voice, right? And being, to your point, different. Right. So that difference comes in part from choosing when to use AI. And it comes in part from having it to where AI is using things that come from your company and not from other places. So yeah, I I I think I'll echo that point and say people should really think about ways that they can make AI help them out, but Keep your business true to what it is. Don't have it become a scenario where your adoption of AI causes you to lose the competitive difference that made your business grow to what it is today. Bryan Jenkins: Love it. Perry: All right. Well, I think we're out of time for today's podcast. I'm I'm excited to do this again in the future. For anybody who's listening, you know, please, you know, definitely ask questions. Please comment. We'd love to hear your thoughts. We'd love to hear what's going on inside of your business, both from a a successful adoption standpoint and from challenges. In particular, we're really hoping to hear from people. Who are in compliance, privacy, legal, and security roles, talking about what's happening in their business today and how much they're starting to see a change in which the business returns back from that initial excitement about AI and let's just forget some of the rules and make it happen, to starting to think about how to apply governance to uses of AI. Let us know your thoughts, let us know your experiences. We're happy to to share some of our ideas with you. And if you have any ideas for future podcasts, please by all means let us know that as well. Bryan Jenkins: Cool. Perry: All right. Well with that.
Listen elsewhere