Kitecast
Kitecast
Robert Smallwood: AI Governance Needs Data Governance
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Most companies rolling out AI have the sequence backward. That is the case Robert Smallwood makes on this episode of Kitecast. Smallwood has spent over a decade defining what information governance means in practice, authoring more than nine books on the subject, including his newest, AI Governance Playbook, from Bloomsbury. He is also the founder of the Institute for Information Governance and chair of the Certified Information Governance Officers Association (CIGOA). His argument is simple, and once you hear it, hard to unhear. Organizations are pouring ungoverned, uncleaned, undocumented data into AI models and then wondering why the outputs cannot be trusted.
Smallwood ties the pattern to widely cited research, including MIT's 2025 GenAI Divide study, which found that 95% of enterprise generative AI pilots fail to deliver measurable financial return. He traces that failure back to a step most teams skip entirely. Before data ever reaches a model, it needs to be inventoried, cleaned, deduplicated, and checked for bias. That is information governance work, not AI work, but without it, generative AI systems inherit every flaw already sitting in an organization's unstructured files, spreadsheets, and email. He also flags a gap he sees across most AI governance training programs. Almost none of them account for e-discovery, the process organizations must follow once litigation hits. Skip that step now, he argues, and you are building a liability nobody notices until a lawsuit forces the issue.
Agentic AI raises the stakes further. Smallwood walks through why autonomous agents need the same scrutiny as new employees: sandboxed environments before go-live, spending and action limits, kill switches, and a clear audit trail showing what data was touched, by which agent, and when. As he puts it, agents will accomplish exactly the goal they are given, which means the guardrails must be defined before deployment, not patched in afterward. That distinction between generative AI, which most companies have already normalized through tools like Copilot, and agentic AI, which is still in early, cautious pilot stages at even the largest enterprises, shapes the rest of the conversation.
Smallwood also previews his CIGO/AI and CIGO/AI-A certification tracks and the AI Gov World conference, running October 12-14 at the Flamingo in Las Vegas, where Kiteworks will be presenting and sponsoring a booth. Listen to the full episode for his take on why corporate boards still flinch at the words "information governance," why that needs to change, and what a genuinely defensible AI program looks like from the inside.
LinkedIn Profile: https://www.linkedin.com/in/robertfsmallwood/
Check out video versions of Kitecast episodes at https://www.kiteworks.com/kitecast or on YouTube at https://www.youtube.com/c/KiteworksCGCP.
Patrick Spencer (00:02)
Hey everyone, welcome back to another episode of Kitecast. I'm your host for today's show, Patrick Spencer. And joining me, it's gonna be a real treat, is Robert Smallwood. Robert, thanks for joining me.
Robert (00:13)
Appreciate the invite and good to be here.
Patrick Spencer (00:16)
Yeah, this is gonna be a lot of fun. You're coming from us out in southern Indiana, from what I understand.
Robert (00:22)
Yeah. Yeah, I'm working on
some some family property here that my grandfather settled here in nineteen ten and raised his nine children and my gr with my grandma here and my mom and my eight uncles and aunts grew up here and you know it's very kind of rural, very nature oriented and the whole family was nature oriented. My mother's name was Olive and her brothers' names were they're all named after trees, nuts and flowers. So I had Uncle Beecher, there's the beach there's the beech nut tree.
at Uncle Oak, Uncle Ash, you know, the ash tree, Uncle Phib, Philbert nut, Uncle Filbert, and Aunt Hazel, Hazelnut, and Aunt Fern, of course, and my mom Olive and then my the youngest was Mary Iris and and the the oldest actually his name was Forrest and the youngest another one in there his name was Woodfin so Wood. So they're all like you know Forrest Scott
Wood Scott, Oak Scott, Beecher Scott. So kind of a interesting
Patrick Spencer (01:25)
Now there's gonna be an influx
of these names for people who are having babies. Now you just seeded a lot of ideas.
Robert (01:30)
Maybe so, yeah. So kind
of a interesting family history there. And and this this property overlooks the Ohio River and across the river is Kentucky and it's only about thirty minutes away from Owensboro, which is where Johnny Depp grew up, actually. So yeah, I'm work working on the property. Excuse me.
Patrick Spencer (01:47)
No, that's right. Well, that's great. First
person I've interviewed while they were in an airstream, I think. There's always a first. So, well, for our for audience, let's do a quick intro for Robert and I'll let him add to the notes I have here in regards to his background. But he for those of you who who follow him, you'll already know this. But he's a leading information governance author. He's published over nine books on the topic.
Robert (01:55)
Yeah. Well, you know, still I still haven't got water hook.
Patrick Spencer (02:17)
he has a flagship textbook that's used at various universities, including Oxford, University of Michigan, up sort of north of where he's at right now, San Jose State University, among other academic institutions. He is a founder of multiple, as you probably guessed, information governance organizations, the Institute for Information Governance back in 2014, Certified Information Governance Officers Association.
Sigo, we're gonna talk about that and some of the cool things that are happening with it, particularly when it comes to AI, a little later during today's discussion. He co-founded iMerge. He is the author, and he's gonna hold up a copy of, I think he has a hard, hard, hard copy as well as a paper-bound copy of a book he co-authored called The AI Governance Playbook, published by Bloomsburg. and it just came out this year, I think, right, Robert? It's brand new.
Robert (03:10)
Yeah, yeah, Bloomsbury just came out about
a month and a half ago or so after a lot of delays because the original publisher got purchased by Bloomsbury in the UK. So it it I actually finished the book two years ago in August and really thought it would be out two years ago, but it took a while to to get through that process. But this is the foundation for the training class we train we use for the certified information governance officer in AI, which focuses on generative AI, and we have a a separate training program for
SIGO AI dash A for agentic AI governance.
Patrick Spencer (03:45)
Yeah, and then we're gonna dive into detail around that, those certifications, which are quite interesting and how the two align when it comes to generative AI versus agentic AI. Now, among other things, building on the introduction I just gave him, he also hosts because he doesn't have enough free time on his hands, obviously, with all the other things he's working on. He is the host of the IG Talk Podcast. He co founded Information Governance World Magazine.
And he's interviewed frequently in the press. That's probably where our audience has seen him before. He's been quoted in the Wall Street Journal, BBC, Washington Post, NPR, among other media outlets. And he has broad consulting pedigree. He's consulted for Abbott, NASA, Novartis, Verizon, Apple. I mean, the the name you know, you can go on the big big names he's worked with. Robert, we first encountered you.
in regards to your conference that's coming up in Las Vegas here in a few months, which we're actually gonna co we're gonna sponsor Kiteworks is. we're ex very excited about. We have a couple presentations that will be taking place along with Booth. it's a smaller audience, but it's a very niche audience, one that will understand what Kiteworks does, but particularly they'll understand what you do since it's your conference. It's called AI Gov World. It's in October, I think the thirteenth and fourteenth.
at the Flamingo. Tell our audience a bit about it. You know, when did it start? What's it consist of? Why should someone in our audience actually be interested in attending?
Robert (05:17)
Yeah, well we started it in twenty twenty, right in the midst of the COVID. We actually launched it in twenty twenty. And you know, I was sitting around thinking, well, we had done physical events, smaller events in New York, Chicago and San Francisco, and then we were planning on one in Boston and then COVID hit, so we pivoted to virtual and we did it
for two years virtual, starting out twelve hours a day of sessions online because you know, we we wanted to get some of the UK and European audience in that time zone. And and so we had about a hundred speakers each each year, the first two years.
Then and that was InfoGov World. Then the third year, the next year, we went physically and did it in San Diego for the first time, and it was InfoGov World. And the last two years we did it in San Diego. We added AI World with InfoGov World. And now we've just combined them. It's good it's A AI governance world. And it's got strong information governance roots and and and background and themes. We
You know, we include, for instance, records and information management, and we have panels on that and also eDiscovery and panels on that, which you won't find at a lot of these other events. And in fact that's the the thing I th I I see missing in most of the AI governance training that's out there, even some of the more popular training courses, they they fail to use I think the foundational constructs and principles and models of information governance, which gives you that
foundation and it's proven and and the best practices we are able to leverage into AI because AI is really just software and inf we're information governance principles and models and best practice c practices can be applied to AI. But AI is unique in that it you've got things to worry about like ethics and bias and responsible AI. You don't have to worry about that if it's a CRM or an accounting system.
so those those are the things that we need to consider there. And when you do that, when you take that approach, you you take this simple model, the information governance reference model, which has seven core facets, which are the functions that really need to be at the table when you form a steering committee for information governance. And and and every every committee will look a little different. It might have a few extra people or it might not fulfill all of those, but you certainly need to start with.
you know privacy, security, legal, IT, records and information management, risk, and business units. And when those are at the table and that you have a cross-functional approach to information governance, you can take that and leverage that same approach to AI governance. And so what we've done in the in the training and and in in my book is laid out eight basic
phases of the AI lifecycle, the generative AI life cycle, from problem definition to data acquisition and collection to data pre-processing, which is cleaning the data and trying to squeeze out bias and squeeze out duplicate duplicates and so forth, to model selection and training, model validation, all the way through to monitoring and deployment and retirement. And there's
Patrick Spencer (08:54)
Mm.
Robert (08:54)
You know, there might be seven phases, there might be nine, but we settled on eight in generative AI. And you take that as a kind of a matrix of that life cycle and you say, Hey, if I'm in legal or if I'm in records management, what am I supposed to be doing? What are my responsibilities at each phase of that life cycle? And we've had people take the course and go back and and become the kind of go to hub where where
people other people in the organization that are in those functions come and ask them, hey, you know, what should I be doing at this phase and and what are my responsibilities and what are some of the caveats and and and suggestions and tips to to help us be more successful. And with that approach, then you've got this foundational construct of information governance, but applied to
AI governance and you're able to manage it through the entire life cycle and everyone understands what their role is and what the responsibilities are through that through that life cycle. And that gets you there. Now that's not getting you deep into the weeds or anything, but it gives you that foundational approach to be able to to to manage it because you know, with the arms and legs of AI and and as as much as as chaotic as it's been in terms of the changes and the
fast pace of change, this gives you a way to wrap your arms around it and and move forward and and implement.
Patrick Spencer (10:22)
Does this evolve at all as y you see an evolution with all the AI models? Every week there's a new one that comes out. if if you're on Claude, you're gonna see all those appear. Same thing with Chat GPT. Does that affect your model at all? Do you need to update it periodically?
Robert (10:30)
Yeah. Well,
No, n generally no. because this is a a foundational approach and it doesn't matter what model you use or what models as the models change, these are still the precepts that you need to apply. and and and it gives you that foundation. because I think we all feel like the earth has been moving under our feet with the chaotic rollout of all the daily changes with AI and and this gives you that.
that foundation and and you know when you when you leverage the information governance reference model and you then you go a little further and you leverage the e-discovery reference model which has been in place for mm fifteen, twenty years now and George George Socia and Tom Geldman in Minneapolis developed that and now it's run by Mary Mack with EDRM.net.
And the first phase, which they call in the e discovery world the left side of the e-discovery reference model, that first step is the inf is information governance. Now it started out being records management and then it
became information management, then it became information governance. Then they just popped in the IG reference model there. And basically what they're saying is you got a clean house. You've got to have your IG house in order before you can feed the rest of the model, which is the e-discovery steps of identification and processing and all the way down to pre presentation. and when you do that, it sounds simple, but it it's at least
helping you to align resources on the front end of a project or a program to be able to prepare for what's inevitable, which is litigation. And a lot of these other approaches, in fact all the other approaches, don't consider that. And so if you're not talking about information governance and e-discovery in regard to AI governance, then I don't feel feel like you've got a comprehensive approach.
Patrick Spencer (12:38)
No. No, and I think many are missing that. And that was one aspect of your conference that's coming up that was attractive to us because we believe there is a legal component. And guess one of our two presenters is actually gonna be our general counsel who's gonna speak to that very subject. but you know, why do you think there's a gap or lack of awareness of that e discovery piece? Like you said, e discovery has been around for a long time. I was at Symantec way back in the day and we
acquired a technology that was a bellwether in terms of revenue generation for the company until it was sold to Broadcom. And e Discovery was the basis of that product. You know, why why is there a lack of awareness when it comes to AI and is that going to change, you think, in the next year or so?
Robert (13:20)
Well, I hope it I hope it does. I just think the lack of awareness is that the the organizations that have rolled out training programs and and and conferences and so forth, you know, if they for instance come from the privacy sector, they're very privacy centric and they they kind of have a blind spot about information governance. And let's be honest.
Information governance is not hasn't been the most popular topic, you know, in corporate world. It's kinda like, no, compliance, you know, we hate it. But now it's with with GDPR, it kinda got a a a boost because the first step in complying with privacy regulations is inventory your data state or your information assets. And that's really the first step we take with information governance. And
so that gave us a a a good, I think, a good boost there. But with with information governance, you know, it it's it's I think kind of grown up and blossomed and it's it's kind of become now when when we we see these studies like MIT saying 90% of the pilot projects in AI don't progress to full production or they fail. and that's because they're ingesting.
garbage data. They're ingesting data that hasn't been cleaned, pre-processed, that has they haven't had the information governance piece in there. And organizations, you know, when it when when boards and executive managers when it comes to information governance, they they sort of hate to to do it. In fact,
Even just in the last year, Sony Pictures got rid of their information governance office. They just felt like, well, you know, we can do without that. We don't really we're not a heavily regulated industry, so we don't have to worry too much about compliance. But what that means is you're gonna have a lot of messy data out there and a lot of unstructured information that needs to be converted to structured data to be able and cleaned up and pre-processed.
to be able to be ingested into these models. So the the days of kicking information governance cans down the road I think have come to an end. It it has to be addressed now. And and if y you're not gonna get r good results out of any AI model if you're ingesting
data that hasn't been cleaned and and deduplicated and and s and and tested for bias and so forth. And all of those things are things that you can have in place if you have a good, robust information governance program.
Patrick Spencer (15:55)
And I would assume as organizations build and you have the public sphere that AI models can obviously mine, but then organizations are increasingly creating their own custom LLMs. I have, right? And you tap into that custom LLM to create content or do data analytics or do targeted marketing, targeted selling activity, et cetera. You know, that component of cleaning the data to ensure that it doesn't have garbage so that
The A models are leveraging something that's clean so they don't hallucinate or create false information or information that isn't accurate is increasingly important. And then at the flip side, I assume tagging that from a security standpoint is critical. You have these DSPM vendors, some of them are our partners in the Kiteworks echo sphere, partner sphere. Those are critically important in terms of you can't actually protect the information unless you know what.
needs to be protected, right? So that tagging comes alongside, I would assume, the cleaning and the e-discovery process that you just described.
Robert (17:01)
Yeah, well, you know, the holy grail of information governance for for years and it still is, is being able to harvest the the value from unstructured information, unstructured data. And that makes up eighty to ninety percent of what's out there in most organizations. And by unstructured I mean PowerPoints, MS Office, it's semi structured, it has metadata and
Patrick Spencer (17:03)
What do you mean?
Robert (17:27)
an email and scan documents and PDFs and so forth. But to be able to there's a new class of software that can convert those into text using and searchable text so using and structured data. So using JSON or ASCII text, they're able to then pull out the information out of the unstructured data and and ingest it into models. And just to give you an example
You could feed in workers' comp claims into a system and then convert those into searchable text and ask and then ingest it into the AI model and ask it, hey, what's our cause well biggest l largest cause cost in the in in workers' comp claims? And it might come out and say, Well, the biggest cost is back injuries. And then you say, Well, AI model, how how do we how do we lower those costs? And
it may come back and say, Well, you need to you know, not lift more than fifty pounds, you need to have a back brace, you know, you need to train employees or whatever it might be. But you could get some real results then and insights based on what previously was unstructured
data that you couldn't really access before. So there's a lot of use cases that are that are popping up. And I really thought with three sixty five having metadata managed centrally that it would have solved that issue. Cause now you're thinking, it's all going to be clean. But
organizations that have implemented it have really struggled and it it hasn't been you know the panacea that everyone thought it might be. So there is this other piece of software that's normally needed to be able to clean up, tag, and be able to deduplicate and ingest into these models to make them productive and and to fulfill the promise of those use cases.
Patrick Spencer (19:29)
When did you I have a two fold question here for you, a two-part question? when did you become interested in information governance? That goes back quite a while, a long time before AI. And then when did you see, you know, right away when you had Chat GPT and you had other AI models really before the announcement back right after Thanksgiving, four or five years ago, when did you see information governance become a critical conversation partner when you're talking about AI?
Robert (19:56)
Yeah, well, first of all, I was implementing AI systems in in the late nineteen eighties. So when when we used it for at Wang Laboratories, you'd scan in documents, convert to searchable text, w use OCR to convert them with searchable text and look for patterns and keywords in litigation support. And so AI is not that new. It's been around forty, fifty years anyway.
Patrick Spencer (20:14)
Yeah.
Robert (20:25)
in production environments and business. It's just the calamity lately is because it's gotten into the consumer realm and and there there's some crazy things they were able to create. but i information governance really started in practice in the 2000, 2001 timeframe at the National Health Service in the UK where they required information governance training for all clinicians handling patient data. And it didn't really hit the shores of the US till of about twenty fourteen
And that's when my information governance book came out. That's when Barkley Blair and Bennett Borden and Jay Brutz and gosh, one other gentleman, another lawyer, gosh, I could see him, but he's now teaching at using my book, actually teaching IG. and
They formed what was called the IG Initiative because a lot of the vendors were finding out that they weren't able to get deals done because people didn't understand what information governance was. So they had to basically educate and do webinars and do surveys. And this IG initiative really launched in 2014, and then there was also a conference called Info InfoGovCon.
which was launched in Connecticut in twenty fourteen as well. And so just prior to that before that I'd been I started out in you know in at Wang and in in Burroughs really with document management. And then document management kind of morphed into well we need we need also
to manage our report. So that was computer app at the laser disk. That got added. And we need to have workflow. So they added that. And and it morphed into content management is what happened. And content management has all these different parts. It's you know eight or ten pieces and parts. And then sort of that market matured and just at the sort of tail end of that when there was a lot of consolidation when open text was buying up everybody basically.
Patrick Spencer (22:19)
Yeah.
Robert (22:34)
Then I started getting interested in information governance and I would say Barclay Blair kinda was the one that that really got me inspired and interested 'cause I thought, well, this is something different. This is really interesting. And I started doing reports on certain aspects of information governance and then those reports became chapters in my information governance book that was published in twenty fourteen and then
the next edition by wiley and the next edition in twenty twenty. So I see it as kind of a natural progression from document management to content management to information governance. And then that next next step is AI governance. So I've kind of stayed in that lane and it's just expanded as I gone through my career.
Patrick Spencer (23:21)
When AI existed before the big announcement, as you just noted, it's been around in various vestiges a and obviously not the level of maturity is today, anywhere close. But it was in a controlled environment. You didn't have something called shadow AI, right? You talk about shadow IT, which has been a problem for many organizations throughout the years, still is to to varying extents. Now it's really a shadow AI problem.
Robert (23:42)
Right. Yeah.
Patrick Spencer (23:52)
Does information governance help address that issue? And how?
Robert (23:56)
Well well it really should because you know it it comes down to a lot of it comes down to fundamental cybersecurity principles and and information governance approach you know with cybersecurity are generally traditionally trying to protect the perimeter, keep the bad guys out, have multiple layers, defense in depth, and and and also classifying data and documents in in security levels.
With information governance, we first do an inventory of your data state or or your information assets and determine which are the most valuable and then lock down with encryption or other tools like information rights management, those most valuable crown jewels.
And so that if and when the bad guys get in and we know they can always get in, they don't get to the crown jewels. They don't get to your most valuable information. And these are the lessons that were learned from like the Sony Pictures hack back way back when.
when, you know, they were trying to release that movie on on North Korea, North Korean leader and and they hacked Sony Pictures. And the same sort of thing happened with the ransomware attack with Colonial Pipeline, which I actually warned them of. I was doing consulting for them prior to that. And I told them, You've got, you know, your most valuable your most valuable information is is is sitting in Excel spreadsheets. You know, you can't
Patrick Spencer (25:15)
really?
Robert (25:22)
And and I literally was interviewing this guy. He told me that the information was worth billions of dollars. And I said, Well, where is it? Where do you store it? Well, it's here in the Succel spreadsheet. And I thought, Wow, you know, if he knows that, it's not gonna be long before someone else knows that. And you know, lo and behold, and I told him their information their information risk was wa off the chart. Well, these are good old boys from the oil field, and they're like, Well, kick.
Patrick Spencer (25:40)
Lo and behold.
Robert (25:50)
back, put his boots up on the desk and said, Well, we've got cyber insurance for that. Well, cyber insurance doesn't cover all your employees' data, all your employees' data getting, you know, revealed and stolen. It doesn't cover your CEO having to go to to Congress and testify. And it doesn't cover, I mean, Colonial Pipeline
Patrick Spencer (25:57)
Well.
Robert (26:11)
Is wanted to be so quiet and obscure they don't even have a sign on their building in Alpharetta, Georgia. And when you go inside, it doesn't say anything about Colonial Pipeline because they want to be under the radar because they've got like a fifteen hundred miles of pipeline that's exposed and they don't want to have happen what happens in Mexico where the cartels just drill a hole in it and suck the gas out, you know? So
Patrick Spencer (26:17)
No.
Robert (26:36)
Cyber insurance doesn't cover all of those things. And they would have just been better off implementing an information governance program in which the first step would have been to inventory your information assets and all your systems, whether they are authorized or unauthorized. And sometimes there are unauthorized systems there. So with information governance, we take an inside out approach to cybersecurity as opposed to an outside in approach. And and I think that.
You really have to take that approach to protect the most valuable information in your organization.
Patrick Spencer (27:12)
So you have all this data, spreadsheets, so some of it's largely unprotected, unfortunately, and not tagged well. you have some that's started in JSONs all over the place, and you have humans accessing it, and now you have this component of dumb AI agents accessing whatever it possibly can in order to fulfill the workflow tasks that are assigned to them.
When it comes to securing it, right? You can secure it at the perimeter, you can s try to secure it at the model, you can secure it at the data layer. We would argue the data layer is critically important, and you gotta have an audit trail so you actually know who accessed it, what AI agent, what workflow from an agentics standpoint, what humans touched it as well. What what's your perspective on that?
Robert (28:05)
w well just restate that again for me real quick.
Patrick Spencer (28:10)
Yeah. So so when you're talking about Chob can edit this, when you're talking about, you know, audit trails and knowing where your data resides and what access to accessed it, whether it's a human or it's an actual AI agent that will do anything possible within the realm of what the guardrails look like to fulfill those AI agentic tasks. How critical is it, you know, to have that unified log so you know actually
Robert (28:18)
Mm.
Mm.
Yeah. Mm-hmm.
Patrick Spencer (28:38)
What data was accessed and where it went and who accessed it and when. and moreover, you can control it at the same time. and the models that exist today from a security standpoint. You know, you have it at the perimeter, you can have it at the model layer, you can have it at the data layer. We would argue the data layer is critically important. What's your perspective when it comes to that?
Robert (29:00)
Yeah, well, first of all, agentic AI, you can just think of agents as basically like people. And in fact, there's there's now companies that are putting agents in their org charts because they can execute all of the things that people could execute with keystrokes. and I think certainly first off when you're rolling it out, you want to have some protections like you want to start out piloting it in a sandbox that's that's you know limited so that it's not gonna get out into your
whole you know live data and agents they you also need kill switches so if they start to go out of control you can stop it immediately. But also you know people have concerns about putting an agent on their PC or their laptop. There's an approach you can take which is to use a virtual private server as opposed to a virtual private network, which is basically like a a PC in the sky. So you you
you you keep it away from your laptop, from your desktop, and you test it out like that. but agents are gonna do exactly what you tell them to do, but you also have to put limits in there. Like I saw a guy do a s presentation on OpenClaw and he was one of the first people to really jump on that. And in the first month OpenClaw came out, he had it running and he's a consultant. So he had it running and he had a master agent or or what he called the Queen.
And he had multiple agents beneath that. And just to give you an for example, one would go out and search for email addresses of people within the parameters of what might make a good prospect for him. And he'd he would say, Okay, find those email addresses, but don't spend more than fifty dollars a day, you know, and then send that to the next agent. That agent takes the letter, a letter sends out that email to it, and
Each time it's reporting to this queen or this master agent at the top. So you have multiple agents there. But what he was doing is doing this not on his laptop but on a virtual private server that you can rent so that you know it wasn't touching any of his laptop data. So there's a lot of precautions, a lot more precautions that you need with a Gentic AI, and certainly all of the the the the steps that need to be taken to protect.
the organization kind of move upstream. They have to be addressed earlier on. Things like you know, legal and risk need to be involved from the beginning before you roll out agentic AI. so so you certainly have to be much more cognizant of the protections you have to have in place and use tools like sandboxing and kill switches and limits limits on whatever it can do. Because the agent you give it a goal and you just tell it, you know, accomplish this goal
And it's gonna find a way to accomplish that goal, but you have to set con confines there or limits so that it doesn't run up a thousand dollar bill on you overnight. You say, Okay, only spend fifty bucks, that kind of thing
Patrick Spencer (32:09)
Are organizations really doing what you just described, however, because there's such a huge push at the board level, at the C suite level, to even at the customers, customers and partners are pushing organizations to embrace AI at the same time. Are they jumping into the pool and then after the fact thinking about those security guardrails?
Robert (32:29)
I think maybe to to some degree, but also I I just kinda do a informal survey. every month we we have a meet and learn or meet and greet with our certified information governance officers or people that have gone through that training or or they've gone through the agentic AI or the AI generative AI training. And I I you know, just kinda do a informal poll and most of them they work for large companies, you know, Fortune five hundred.
kind of companies, but most of them they haven't really implemented a gentic AI yet. They're just getting their arms around generative AI, you know, they're just getting used to that. And testing out different models. Should we use Claude? Should we use Chat GPT? that kind of thing. And and getting those agreements in place so that for instance they don't train their model on your data, that kind of thing. So I think you know the answer is it it depends.
Patrick Spencer (33:23)
Yeah. Yeah. That makes a lot of sense.
Robert (33:26)
Mm. So I think yeah, I think generative is well entrenched because you can it's right there in Copilot. But Gentic AI, there's a lot of security risks and it c they can run amuck. So I think organizations are going a little slower and they need to. And they really need to use sandboxes and and and testing and piloting and and kill switches to be able to control those.
Patrick Spencer (33:54)
Yeah, those are good suggestions. let's backtrack a little bit. We talked a bit about it at the beginning of the podcast, and I told everyone we're gonna talk about it later on. I want to make sure we do so. You know, this concept of SIGO, you know, and SIGO for generative AI, SIGO for agentic AI. And those two life cycles look different. I'm curious to hear how they look different. You and you noted before we're
Robert (34:00)
Maybe.
Mm-hmm.
Yeah.
Patrick Spencer (34:22)
we hit the record button that there is overlay at the same time. So how those well, first of all, Siggo, you know, how what gate what was the genesis behind it? And then it's evolved obviously with the AI adoption in the marketplace. And then what's the difference between those two components when you talk about lifestyle manag management?
Robert (34:42)
Yeah, well, life for life cycle management. I felt like I was teaching some classes on the IGP, the information governance professional certification for ARMA. In fact, I was teaching classes on that before I actually took the exam. And when I sat and I had students that already passed the exam before I took it. And then I I took the exam. I remember I sat down and first ten questions I was totally lost. And I'm like,
Wow, I I've been teaching classes on this. I've written at that point like six books on this. I have no idea what they're asking here. So I thought, you know, and and they said that ten of the questions don't count on the test. And and I'm like, are we just your guinea pigs? Because they were really fuzzy, you know, and and they were a lot of it was it depends on the business scenario, you know. It could be A, B, C, or D, depending on the business scenario. So I I didn't like the exam.
I I I thought it was very theoretical and I also felt like it didn't really reflect information governance in reality in practicality, which is to hit on all seven of those facets. At the time there were five facets because privacy and security were in one box and they had added risk later. So there were five facets at the time. So I felt like you have to include legal and e discovery. You have to include privacy, security, IT, RIM, and business units and
and later we added risk. And in fact, in our training we had audit too, because that's a very important final piece to make sure that you're checking the the checkers. And and it was based on primarily my information governance book, which is you know like five hundred plus pages. So very comprehensive, more of a deep dive, a tougher a tougher
course, I think, in terms of just the training, but also more useful and more practical. And then a couple of years ago with Genitive AI came out, I was a little behind and I saw this other certifications coming up and I thought, well, let me s what are they doing?
And I looked at the IPP one and so well I like that they have lifecycle in there, but I I don't see anything on records management. And how are you gonna how are you gonna keep track of the records of the the data sets that you acquired and the various steps they went through or the models as they went through various steps. You need that version control. You need records management.
and I didn't see anything on e discovery. so I finally came upon the idea that we could apply information governance models and best practices to AI. And then I did some research on what the life cycle steps are and found that there was eight basic steps and that we could identify
In the life cycle of generative AI. So you come up with a matrix basically of the those eight phases and then the seven functions from IT to legal to privacy RAM security and so forth. So they all know what they're supposed to be doing at each phase. And then, you know, boom, agentic AI came out. And we we knew it was coming, and well, we've talked about it at our conference for a couple of years.
And Peter Stockberger, who's one of our keynotes, who's coming back, thankfully. he'll talk about it. he was the head of AI governance for Denton's, which is the world's largest law firm, and now is with Foley and Lardner. And so he was talking to us about it, but I didn't fully understand it until I really dug into it and did research. And I think we're all learning, you know, this is all new for everybody. and so I just thought, well, let's apply that same approach. And I I but I I found out that
the the seven steps were the the steps there were a little different. I mean the initial business objective problem definition that's going to be the same and retirement's going to be the same, you know, but in the middle, that's where agentic AI is is different. And so we're we just did our first class on that, but you know we have you know companies companies like large law firms and USAA and
big banks, I'm not supposed to say their names anymore, I guess, but you know, that they they have taken these courses and it gives them at least the equipment, it gives them the foundation to be able to have a a a an approach, a methodology. It gives them a methodology. And for people that came out of the IG world, then it's it's familiar and you move forward with these same models and best practices. So we have the SIGO certification, certified IG officer.
Patrick Spencer (38:52)
Yeah.
Robert (39:14)
We have CGO AI, which is certified IG officer in AI, which is focused on generative AI, and then CGO AI-A, which is the generative, I mean the agentic AI certification. And some people you know take the CGO first and then CGO AI and then CGO AI A, and some just jumped right in and took the CO AI. Depends on your business requirements at the time, what your company's working on, what your business is working on.
Patrick Spencer (39:27)
Judic.
Robert (39:44)
so there's no prerequisite, you can take it in any sequence you want. but they're the foundational concepts and and best practices are are based on proven information governance principles and models. And now let's talk about the conference a little bit.
Patrick Spencer (39:58)
How long does
it take to get one of those certifications, Robert? How how how much work is involved?
Robert (40:04)
basically you go thro three half days online and I think my internet connection is having trouble here. And and then you have two weeks to study and then everybody takes the exam. And so you can get it in two weeks basically. And it's intensive. You you gotta expect a lot of homework, you're gonna do a lot of reading. We use the books, but we also have supplemental materials.
Patrick Spencer (40:24)
Interesting.
Robert (40:31)
And so it's very intensive and I I in fact I I encourage people to take the day off before they take the exam, or at least a half day, to just kinda relax and get into that game day face, you know, to get ready for the exam. But everyone's done everyone that's took the the the training has done very well on the exam.
Patrick Spencer (40:44)
Yeah. Huh.
And these are you have chief information security officers, data privacy officers, risk management, general counsels. Who who's going through the training out of curiosity?
Robert (40:51)
And then you're certified for two years. Yeah.
All of those, yeah. All of those and records managers and information governance managers. Yeah. it was interesting when I started the SIGO you know, and and then moved to the SIGO AI, all of a sudden with SIGO AI we started getting chief risk officers taking the course. And you never would have had that if it was just information governance, you know. and we have attorneys, general counsel, deputy general counsel, assistant general counsel taking the course.
Patrick Spencer (41:06)
All the above.
Hmm.
Robert (41:31)
And you know, we we don't try to get too technical, but you do have to know things like the regulations and the standards. you know, we're used to ISO standards like in in information governance, ISO fifteen four eighty nine for records management, and and and and when we get into
further into information governance you have like ISO 38500 for IT governance, ISO 31000 for risk management, ISO 27001 for cybersecurity, ISO 27701 for privacy management information systems. But then when we get into AI, we also have ISO 24143, which is the AI standard.
And and then they also have IEEE standards which which which were new to me. So this P seven thousand series in the you know IEEE is the largest trade organization in the world. It's the electrical engineers and and and basically they that they're the reason why we can plug into an outlet and it works every time or that Bluetooth works.
and so they've developed standards on how, for instance, if we have a there's there's a there's a new protocol being developed, called hyperspatial protocol, that if you have a Tesla and a lucid and a Ford and they're all EVs and they're coming to an intersection, and then there's a fire truck that's going through and it's gonna blow through a red light, and they're all smart vehicles, they have to communicate with each other on some common protocol, some common platform to say.
Patrick Spencer (42:58)
Hmm.
Robert (43:14)
Hey, Ford Lucid, you gotta stop at this intersection because here comes a fire truck. And the fire truck has to be letting it know, everyone know. So those kind of standards are important and IEEE is very involved in in that. So we go into standards a little bit in the agenti in the in both the agenic AI and the generative AI training for Seago.
Patrick Spencer (43:22)
Yeah.
Interesting. So Robert, when it comes to information governance, do the corporate boards get it? Is this on their radar? Number one. And then number two, when it comes to information governance and AI, is it on their radar?
Robert (43:54)
I think the first case generally no. They they don't like the even the words information governance. And so I think that IG professionals need to rebrand themselves as the AI readiness department. And when you talk about AI readiness or AI enablement, then now you've got the ear of the executives. But when they used to hear records management or information governance, it's like, you know, that's just compliance stuff.
But it really is a requirement for AI readiness. but I do see AI governance is mainstream now. You see articles on AI governance in mainstream publications, and when when and you see a lot of of po posts on LinkedIn and a lot of writing about AI governance, and none of these people were involved at all in information governance.
So it's kind of brought information governance into I think the the mainstream because it yeah, it really has to you really have to have information governance to be able to execute on AI governance.
Patrick Spencer (44:51)
Bring bringing it to the table. Mm-hmm.
So where's all this headed? You know, you've been watching this for decades now. And with AI, you've been watching it for the last well, as you noted, for a long time, and particularly over the last few years. You know, where are we headed? You know, what is there are there gonna be a lot of additional compliance regulatory fines and penalties that pop up, more lawsuits, more regulations? You know, what what's gonna happen? What do you foresee in terms of you know the next few years?
Robert (45:28)
Yeah, cer certainly more of all of that.
Yeah, certainly more of all that. More more regulations, more lawsuits. I I I I think that in in the best case, it's gonna take away a lot of the the that that manual entry stuff that we all have to do with things like Excel and and and and just just you know and and just inputting data into
different applications, a lot of stuff that takes up our day. So we should be freed up to to to think more strategically and do more strategic tasks rather than bog down with administrative tasks. And that's gonna be the first, I think, big benefit. but that's gonna consume administrative jobs as well. And it's consuming already entry level jobs.
so there's gonna be a more, you know, streamlined workforce, for sure. And so people that will have real value are those that understand how to leverage AI and a agentic AI in particular for the benefit of the organization, but also have that personal, that human touch to be able to understand the the culture and the context of the organization and
and and that's what's gonna be driving real value in terms of employee value in the future. So all of that repetitious robotic stuff that a lot of us have had to do is gonna go away and there's gonna be a reshaped workforce, I think.
Patrick Spencer (47:00)
Yeah. I think you're spot on there. Well we're about out of time, Robert. So for folks who've been listening to this and are interested in the conference in October, where can they go? Or if they're interested in the certification, where should they go for that?
Robert (47:14)
for certification go to cigo.org, c i g o a which is cigoassociation.org. And we have classes in July, August, and and we and and we teach them live online with the faculty team. So you get to talk to the instructors, ask the instructors what they you know what questions you might have. And then we'll have in-person classes for CGO AI and A and Jet Agentic AI in Las Vegas in October 12th.
We'll also have an executive forum on AI governance, which we've done the last couple of years very successfully. And and then the next two days, the 13th and 14th, is the conference, which should be at the Flamingo Hotel on this trip in Las Vegas. It'll be our first time in Las Vegas. We've spent three years in San Diego. So we're really looking forward to that. So for that you go to AIWorldconference.ai.
yeah, I would have liked to have AI governance world or AI Gov World in there, but it's the same site we used last year and it's better from Google ranking standpoints to keep your site. So AI World Conference, AI World Conference.ai. And we have a special actually in June. If you register in June, we'll give you three free nights at the Flamingo Hotel. So that's a limited time offer till June 30th. but we've got a lot of interesting things planned.
Patrick Spencer (48:17)
Ha ha ha.
Robert (48:34)
Three receptions for networking, two the first night, one the second night. And we've got industry dinners focused on people in legal, healthcare, and financial services, but also privacy security and RIM. So you can sit down with peers in your vertical market and and make connections and exchange notes. And those dinners will be at Bugsy and Myers, which is in the first floor of the Flamingo Hotel.
it's a steakhouse and then the next night we'll have a group dinner at Gordon Ramsey's Pub and Grill, which is across the street across the street at Caesar's Palace. So we're trying to build in more of these networking kinds of opportunities because that's where you really get the value in an in a conference is that in person touch where you you you have common problems or issues that you can share and and help to get them fleshed out at these at these conferences.
Patrick Spencer (49:28)
No. That's great. We're gonna put a link to the conference as well as your book and your LinkedIn profile at the in the different podcast channels where we publish. So Robert, I wish we could continue this conversation. This has been quite enlightening. I appreciate your time. Thanks for jumping on the on the session with me while you're out doing some renovation work in Indiana.
Robert (49:39)
Very good.
I am. Yeah. I'm you know, working I'm truly remote. I'm off the grid. This place doesn't have electricity. So I I run off of solar generators and I've got a hot spot and you know, I'm able to keep working and trying to get this place shaped up. So yeah, I just I have these solar generators and I got a little mini fridge. And when I got that mini fridge working with the solar generator last year, it was like, huh, wow, I'm living up now.
'Cause I was buying ice every day before that, you know. So yeah, it's c it's kinda fun, but it's truly off grid, you know.
Patrick Spencer (50:22)
Yeah.
That's great. Well, thanks for your time for our audience. We always appreciate your attendance and that you can check out other Kitecast episodes at kiteworks.com. We look forward to having you view our next episode for Kitecast.