We’ve noticed you’re visiting from NZ. Click here to visit our NZS site.
We’ve noticed you’re visiting from NZ. Click here to visit our NZS site.
Every leader has questions about AI, but straight answers are hard to come by. How do you set your strategic intent, and why does it matter? What does AI mean for your role? How do you QA work in an AI age?
Most AI sessions avoid the hardest questions. This one doesn't.
In this live Q+A, our panel of AI experts will draw on their 10 years of AI experience to take on any question you bring them, directly, honestly, and unfiltered. Submit your question ahead of time and we'll anonymously answer it, with a framework or short slide where it helps land the answer.
What you'll get:
A peer-to-peer conversation, not a sales pitch or a training session
Straight answers from people who live this everyday
Pre-submitted questions answered anonymously, backed by the framework or research behind it. For example:
"How do I set my AI strategic intent?" — we'll walk through our five-step strategic intent process.
"Is AI really that capable?" — more than most think: the research shows it can already perform 90% of management tasks.
Who it's for: the AI-curious, leaders setting direction, leading a team through AI change, or accountable for how it's governed, at any level of seniority.
[Anna]
Kia ora koutou and welcome to today's AI questions answered, which will be direct, live and unfiltered discussion that tackles your AI questions that you've submitted to us. To those joining from Aotearoa, Australia or anywhere else in the world, we wish you a warm welcome to our session. I'm Anna, Senior Consultant at Allen + Clarke, and for those joining us for the first time, we are a consultancy that helps organisations make complex high stakes decisions based on evidence, defend them with confidence and build them to work for people and communities.
So we specialise in strategy, change management, evaluation or policy and increasingly, we are helping organisations decide where AI belongs in their work, where does it not and how to use it responsibly. And that's what this session is about. So let's start with some information introductions.
We have Chad online with us.
[Chad]
Hi, I'm Chad. I work with Allen + Clarke on AI strategy and delivery alongside Adam and Min. My background is in technology and product and I spend most of my time working on how we turn AI experimentation into something that actually works inside an organisation.
[Min]
Kia ora, I'm Min. I'm a Group AI Manager at Allen + Clarke. I focus on AI strategy, governance, risk and compliance, staff capability uplift and training and evaluating AI tools and vendors across the organisation.
[Adam]
That's it. Kia ora koutou, I'm Adam. You'll recognise me from a lot of the other AI webinars that we've run.
So I lead AI here at A+C. Min and Chad are more on the technical side and I'm more on the strategy, governance and org level kind of capability and value side.
[Anna]
Great. Thanks, team. So everyone has a lot of questions about AI.
The answers are not always straightforward. So I'm very happy we have this big AI expertise in the room. And so we will sometimes use a framework or a slide when it makes it a bit easier to explain.
But this is not a presentation. It's not a sales pitch. It's about your questions and answering them.
So please feel free to send live questions in the chat at any point. We will take them throughout the session. And we have pre-prepared some that you've already sent to us ahead.
But if we have, you know, any questions coming up that fit really well the theme, we will take them throughout. So please do send them to us.
[Adam]
Definitely. Make them happen.
[Anna]
Yeah, make them happen. So we're not going to start with an agenda. I think we are going straight into the questions.
So first one, we have like first three hard questions. And then we will move to the teams, how we grip them. So first question is, how can I trust an AI output without spending longer checking it than doing the work myself?
And this looks like a question for Adam.
[Adam]
Yeah, I think. Yeah, thank you. I like it.
Yeah, I mean, we get this question a lot. So the straight answer is don't check everything equally. What you want to do is you want to check in proportion to the consequence of being wrong and design the checks into the actual workflow instead of kind of leaving it to the end.
So if the marketing crew are doing their jobs correctly, there should be a slide on the screen that kind of gives you a bit of a guide on this. They're going to kill me for saying that. So on the far left are the low consequence uses such as brainstorming, you know, which don't really need much review because you're kind of going backwards and forwards with the machine.
And then on the far right are high consequence decisions, you know, where cultural or cultural nuances with thorough review by a subject matter expert kind of has to be the minimum standard, really.
[Anna]
So how do we actually do this in practice? This is a nice theory, Adam, but let's ask men about practical questions.
[Min]
Okay, so train your team, but don't train them to spot AI generated text because research shows people aren't very good at doing that. Instead, train them on when they need to review AI output and what that review should actually involve.
[Adam]
Yeah, I actually have some practical things to say. So one thing you'll start to experience the more your team use AI in their work is that traditional QA that had kind of an expert review at the pre-publication point really doesn't work anymore. And so what you want to do here or what you're watching out for is that your subject matter experts actually become a bit of a review bottleneck and their ability to detect bad work is really impeded by the fluency of AI writing.
So I do have specific tips, Anna. And so the first one is open questions. So, you know, we recommend introducing a face-to-face open questions or discussion with team members.
And what you want to do here is you want to ask things like what options were considered but disregarded, what evidence would change your view, and what you're looking for here is this gives you the ability to quickly detect whether the drafter actually understands the work that's being produced. Because, of course, in the age of AI, you can outsource your thinking but not your understanding and definitely not your accountability. So, yeah, that's kind of one practical thing you can do.
[Chad]
Yeah. And, you know, use AI in your QA process. So an AI can actually be part of the QA process itself.
One of the biggest bottlenecks we found was reviewing all the claims in a document. You know, it takes time and it's easy to miss something. So we built a tool that checks claims against original source material and also picks up proofreading things like spelling, clarity, and consistency.
It doesn't negate the need for human review. It just allows you to do these tasks more faster and focused while an expert still owns the final output.
[Adam]
Yeah. And watch out because Chad will talk about his beautiful tool all day and in minute detail.
[Anna]
So we have a second hard question which feels very topical in New Zealand right now. So this one is for Min. How do we bring along people who fear losing their jobs and give them real control over what happens to their roles?
[Min]
Okay. I really want to tell leaders, please be honest, just saying AI will not take your job does not help people because they can see, they can hear. It's already changing.
So the next slide, can you see the slide? Hopefully. Yep.
And the blue area shows what AI can really support. And the red shows that we are actually, how much we are actually using it. The technology is moving faster than organizations are changing and capability on benchmark close to our work has risen from 41% to 66 in just one year.
Yet 89% of organizations are not reporting productivity gains yet. So the better question is not about will AI affect jobs? It's more of how will the work change and who gets to shape that change?
That means starting with tasks, not jobs. Some tasks are easier for AI to support. Others depend on judgment, relationship, experience, and accountability.
And the evidence support this. The New Zealand Treasury and Jobs and Skills Australia both points towards AI being more likely to transform and augment work than replace entire jobs. So bring people into redesigned and ask people, what should AI help with and what should stay in human and what move, what's more valuable work could people do instead?
So the goal is just not about saving time, reducing costs. It is helping people to do more valuable work, make better decisions and improve services. So people need honesty, transparency, and a meaningful role in shaping what their work becomes.
Yeah. Yeah.
[Anna]
Thanks, man. That was super comprehensive. And yeah, definitely interesting and definitely a good way to think about it.
We have the third hard question, which is, well, it's time for Adam. He doesn't feel sad. He doesn't get hard ethical questions.
So is it ethical to use AI that is trained on creators work or powered by data centres that may actually harm communities?
[Adam]
Yeah, I mean, we get this question a lot as well. Yeah, exactly. And I think, you know, we've got to be upfront about it in that, you know, generative AI tools have been trained on IP from the internet, libraries, personal data, etc.
There's even examples of AI organisations buying millions of books and literally scanning the content out of it, out of the books for training data. So, you know, so there's that. And also there are real impacts from data centres.
And we can't really ignore and nor should we ignore those things. So unfortunately, on the IP front, there really is not a good solution. So, you know, some options are slightly more ethical than others.
So for example, you might choose a European Union developed AI model versus a Chinese developed model, you know, but the differences are super marginal, because to develop a generative AI system, you need a lot of data. And so, unfortunately, there's not much you can do. But in the data centre space, yes, they definitely have an environmental and a social impact.
But there are actually options here that are more environmentally friendly, like data centres that are powered exclusively by renewable energy. And some data centres now are even using wastewater from cities for their cooling. So yeah.
[Anna]
Yeah, that's good. But is there something that the organisations themselves, which is something that is within their span of control?
[Adam]
Yeah, I think the point here is to push for less impactful processing is probably the place that I would start. The main reason for that is obviously because of those data centre options, you can kind of that's where you can have the biggest influence. There's not really anything you can do about the IP front, other than obviously control whether they're using your IP to kind of build their models.
But if you're using like an enterprise system, then kind of your licensing agreement will typically exclude your data from training. So that's kind of industry standard Thanks.
[Anna]
Thanks a lot. So this was the three questions that we consider the hardest that we received and that we wanted to tackle right off the bat. But before we move to our teams, we have a little poll for you.
And we would want to know which risk is the most present in your opinion with AI? And the answer will help us to understand whether your concern is mainly about the output that AI does, or about your sensitivity of information? Or is it actually accountability or people's behaviour?
So the question you should have right now up on screen is, what worries you most about AI at work? And either that it gives you the wrong answer, or that sensitive information is being exposed, or that people just stop checking and thinking about what AI says and just copy paste it, or that no one actually owns the process once something goes wrong. So while people answer, I just want to check with you guys.
So Min, start with you. What do you think?
[Min]
I think people stop checking and thinking because they are still used to just asking and saying, oh, it will be right, and then just use that. Chad?
[Chad]
I think it would be sensitive information becoming exposed with as much coverage as in the media and potentially being paid to personal information being exposed. I think that's a big one. And then losing IP to the AI.
[Adam]
Yeah. Oh, well, I mean, obviously, they're wrong, and I'm going to be right. So I'm going to choose people stop checking or thinking.
Now, I might have seen the result. I might have seen the result.
[Anna]
Okay, so Adam has cheated. I just wanted to be right every time. Okay, but that's right.
That's right. Most of you actually fear that. It's 83% fear that people stop checking and thinking.
And yeah, to be honest. Yeah, I agree with that. Yeah, yeah, Min was right.
[Adam]
Yeah, definitely.
[Anna]
And Adam cheated.
[Adam]
I did cheat, yeah.
[Anna]
On brand.
[Adam]
Yeah, I think that comes back to the checking thing. That's why I think it's really important that we're using those kind of open questions because the open questions help us kind of detect whether or to what extent that is occurring.
[Anna]
Yeah. Well, now that we've had that covered, then we can move to our teams. So we've received a lot of questions.
So what we've done is that we grouped them together in three overarching teams. So we will just go through them. But if you have any questions live, please do not hesitate and already ask.
And we will include them in the discussion. So the themes are, the first is, where is AI actually useful and where it isn't? Second is, what can we trust and what really needs protecting and checking?
And the third is, how do we actually lead and govern AI? So off to the first theme. So where is AI useful and where it isn't?
So first question is, where do I start? And how can AI help me? So Matt, this feels like something for you.
You do that a lot here.
[Min]
Yes. So for an individual, the best place to start is simple. Just start with repetitive tasks.
You already do. And instead of asking, oh, what can AI do? Ask, what do I keep doing over and over again that AI could help me?
[Chad]
Yeah. So take that task, like Min said, what you can do. Take that to your AI of choice or what you're using.
And tell it about a task that you're actually doing now and how you do it. And then describe how everything you do. And then ask it how it would perform it or how it could actually do it better to get a good idea of how AI could be used here.
[Min]
And I think key is to learn by doing it. Don't just use AI for a predictable task. Push it, test it, and learn where it's working and where it doesn't work.
Then you can move from using AI for individual tasks to redesign the workflow. So look at the whole workflow and ask, where could AI make this process much better? The framework on this slide help you choose where to start.
It considers impact, how much it helps, risk if AI gets it wrong, the human judgment required, data sensitivity, and how difficult the change will be to adopt. So the journey is start small, learn by doing, then redesign your workflow.
[Adam]
Yeah, I think I've got a couple of other tips. If you jump on our website, we actually have a bunch of tools that you can kind of download and set up yourself. And so the first one, I'll just touch on super quickly, check them out.
The first one is what we call a prompt agent. And if you are getting started, a prompt agent is super helpful, because instead of learning to prompt yourself, you can basically put in a random stream of consciousness, and the prompt agent will take that and convert it into a really high quality prompt. I use it all the time, yeah.
[Anna]
I like writing streams of consciousness.
[Adam]
Yeah, exactly. And so our users at ANC, like Ana, use it all the time, because it's just a super fast way to create really good prompts. And if you're just getting started, that takes you from kind of average outputs to much better outputs kind of immediately.
So I'd really recommend people use that or give it a crack.
[Anna]
Yeah, I can definitely testify to that. And like staying on the, you know, how do we actually put this into practice into different fields? So we also can get some concrete examples.
So for instance, if you're an evaluator, you know, how can you use it in a quantitative and qualitative data analysis?
[Adam]
Yeah, I think Stella sent this one through. So thanks very much, Stella. So what you can see on your screen is a very oversimplified thematic analysis process, which is kind of in four stages.
The first is sorting and cleaning the material, then you've got coding it, then developing themes from the coded evidence, and then of course, applying judgment to determine what it means. So you'll notice that AI is kind of most helpful in the sorting, cleaning and coding. And won't go into here because it would dominate the whole conversation.
But we have a whole entire webinar about how to use AI for coding in particular. And so we'll send a link to that afterwards. Hopefully, someone's nodding behind the camera.
So that's good. And then for the theme development and the judgment part of that, this is where you switch to using AI as an interlocutor, which is just a super fancy word for saying an assistant you use to question the data, test hypotheses and challenge your thinking. When you go to the webinar itself, the point of still doing the coding is you need to make the data set smaller for the interlocutor to work correctly and give you high quality answers.
So we recently presented on this at ANZIA. So we're going to stop there. But if you are an evaluator or someone out there who's super interested in this, just give us a call.
Happy to have a chat about it.
[Anna]
Yeah, great. And we actually just had a live question come through. So we go ahead with those.
How can organisations provide reliable assurance that AI generated outputs are accurate, fit for purpose and safe to use, particularly when responses can vary between prompts over time? And yeah, that's a hard one.
[Adam]
That's a really good one. Yeah, I'll jump in. Thanks, Joshua.
We actually have a reasonably detailed answer to AI assurance a little bit kind of later on. The main thing is that what you want to do is you want to stack controls on top of each other, because AI is a non-deterministic or, sorry, is a probabilistic system. And therefore, to kind of manage individual prompts and stuff is a bit unrealistic, I guess.
But what you can do, again, going back to PromptAgent, and we use it for this purpose, is you can build in your prompt library into PromptAgent. And PromptAgent is kind of your first level of, not defence, but control over the sorts of prompts that your users are using. We've got a lot more to say about that a little bit later on.
Yeah.
[Anna]
Great. And we have another one. So, how should people be openly referencing that AI has been used with an output from a particular experience?
Min, do you want to take that one?
[Min]
So, it's a big discussion, because when you see people like, oh, do we have to say that we used AI? And what means I used AI? Because if I do Google searches, that means am I using AI?
And do I have to provide that saying I have used AI? But I think we have to be honest and then specifically say which part of the work that I have used AI, so people can verify later on if anyone who wants to cross-check have ideas. So, we can take responsibility on what we've done.
So, yes, I think we must put where we have used AI.
[Adam]
So, I think to build on that, our process is that every output that we have has the owners, i.e. the people that drafted, and therefore you name them specifically on the document, because that increases their level of ownership. And also, to Min's point, we define specifically how AI was used in the creation of the artifact. And we also have quite detailed processes for our workflows of where AI was used, so that if things need reviewing, or someone comes along afterwards, we can tell them specifically where AI was used.
[Anna]
Great. We have another one actually from Wesley on governance. So, in your opinion, what is the role of government in enabling use of AI in a productive and safe way?
So, yeah, Adam, maybe you want to take that one?
[Adam]
Yeah. Well, we did promise tough questions, and we're getting them, which is really great. Thank you.
So, my opinion, it's a good question. I guess the balancing act for any government agency is that AI can definitely be useful in the delivery of services. The challenge, though, is to what extent does the public, as the government's customers, where are they on that journey?
I don't personally believe that it's possible to replace public servants with AI, certainly not at the moment. And so, I think the government has a real opportunity to show, hey, when you kind of redevelop workflows, you can deliver really high quality, you can maintain the quality of service, but you can provide more services for the same kind of level of investment. And I know a lot of the kind of government agencies that we work with are looking at AI as a capability layer.
So, they're looking at it from a, you know, I have a budget, and how do I kind of maximize the value to the community at large from my budget? And, you know, and we kind of help them understand where AI can fit in there. So, hopefully that kind of answers.
[Anna]
And I would say that even, you know, if you look at it at like a bit higher level as well, as in terms of, you know, regulation, that it still needs to be subject to like data privacy law, and needs to be secure at the end of the day. So, definitely, I do see a role from sort of the regulation point of view at the government level. So, that just to add.
[Adam]
Yeah, I don't think though that you, I don't think that regulating AI per se is the right approach. My view would be that, you know, we have privacy regulation, we have, you know, data sovereignty regulations, etc. And I think the combination of those factors help create an enabling environment for New Zealand and Australia as a whole.
[Anna]
Yeah, perfect. We have another question. So, how do I manage allergic reactions using AI?
And I'm comfortable with using AI, but there's a lot of people still uncomfortable with it. So, maybe Min, you want this one? Okay.
[Adam]
Well, I think Chad might have something to say as well.
[Anna]
Chad wants this one. Okay, go for it.
[Chad]
Sure. No, I think, introduce it in small, small doses, small steps, sort of like what Min was talking about earlier with take, just take some tasks that you normally do and get started. Maybe just sit with them and show them, show them how it works, how simple something is, just take a small, small ask and work through it.
And I think it's a slow process to build somebody, to change somebody's mind on, that is allergic to AI. But I think, you know, there will be some wins there if you do do that. Yeah.
[Min]
Because I think when people try AI and feel like, oh, this is useful when they have that, aha, yes, it's actually working. And that's when they start using it. Because when I'm training staff in Allen + Clarke, that's when people who start really utilising AI, because they find it useful.
So, I think we have to find that opportunity that AI can be really useful rather than keep pushing person, you know, like it's really good, but I don't think it's good because, yeah. That's right.
[Adam]
I think we've got like, we've probably got a few kind of hard examples that we would probably point out to people of, you know, team members and other others that we kind of support that have had that aha moment. So, you know, Min co-designed a kind of theory of change workflow with our kind of theory of change experts. They were reluctant at first, they didn't actually think that AI really was going to be quite helpful.
And I think you did a great job through that process of showing them. And, you know, one of the most sceptical team members, you know, had that aha moment. And then suddenly that person is now quite a big advocate for AI, you know, and building it properly, I would say.
And then I'll just chuck in another example, which is someone completely, you know, unrelated, who, you know, through their work has to kind of summarise a lot of workshop data. And, you know, again, Min set up a way using AI to really accurately and quickly kind of summarise and theme the data. And again, that person previously barely used AI.
And suddenly they had the aha moment. And now they're like, oh, just how do I do this? This literally saved me a week's worth of work.
The quality was really good. How do I do this more? And so it's those aha moments, I think.
[Min]
And I think it's good to test from what, because they already know the content, and they can tell if it's really useful or not. So that's starting from their comfort zone. And then when they find, you know, how useful it is, then that's when we can, you know, expand there.
[Anna]
A pretty interesting question there from Anthony as well, which is the other end of this. And is there something that AI actually can't do? Oh, good one.
Yeah.
[Adam]
So there are, there's, I mean, the list is kind of endless, I would say. So I'll just touch on a couple of things, Anthony. So like for qualitative, we were speaking about that, for qualitative data analysis, people get caught out by loading in heaps data, and asking AI to kind of process it.
And that kind of bumps up against some hard limitations of how the system actually works. I won't go into more detail, there's heaps of content about it and I'm also happy to chat about it. But that's one example.
Another example is AI actually is pretty bad at understanding images, would be another example. So yeah, there are lots of areas where we as an organisation don't let AI go. Another example is judgment.
So policy work, which we're about to talk about, policy work applies a lot of kind of weighing up of options and there isn't necessarily hard data that says, hey, this is definitely the best option. So in those scenarios, AI really is not that useful because it only knows what you kind of tell it or give it. And so weighing up of options and making a judgment call really is not something it's good at.
And of course, it can't own the call, right?
[Anna]
That's right.
[Adam]
So, you know, the public isn't going to go, oh, you know, well, that's okay.
[Anna]
AI made a bad call.
[Adam]
You know, that's fine. You know, that's not going to survive.
[Anna]
Actually, on the note of maturity of AI, so we have an interesting question that we received. So how far should we move from chats to then agents and to autonomous workflows? So Chad, do you have any tips on that prediction?
[Chad]
Yeah, I think that's, you know, the answer is as far as the level of trust allows, you know, and the slide shows that we can, as we move from chat towards agents, we're giving AI more responsibility and freedom to act. So at the chat level, we're still driving the interaction. At the agent level, we give it an outcome and let it work through the task with less involvement from us.
And I think most organizations today are somewhere between, you know, between the agent and the, you know, the chat and the agent, you know, somewhere between those two stages. But the technology is already starting to move further ahead into what the slide calls the colleague state. Sorry.
So that means AI can keep working over time. Remember where it's up to, work with other AI and keep moving towards an outcome. So the gap really is about trust.
And you don't have to jump straight into full autonomy. Start with read-only access. Give it access, the least privilege access it and then increase it as your confidence grows with the outcome.
So the question is not just can it do the task? It's, you know, how much do we trust it to do on our behalf?
[Anna]
Yeah. And shifting and staying in this capability pool of questions. So interesting one for, I'll give it to Adam because he just loves talking about the different agents and co-pilots in particular.
So really keen to hear his answer about, you know, if we have co-pilots and we can add CLAW, JGBT and other agents. So how do we actually choose?
[Adam]
Yeah. You know, our advice is to use a hub and spoke approach. The point here is to choose the best tool for the job, essentially.
So on the screen is kind of a demonstration of that. So you kind of have one enterprise system and this has all your governance controls and access points connected. So if you are a Microsoft shop, that could be co-pilot, but it doesn't have to be.
And in many cases, I would suggest against that. Hopefully no one from Microsoft is watching. So, you know, the point is that that hub will safely connect to your enterprise knowledge and existing systems.
So we kind of generally advise against connecting the system to all your internal data before you have optimised it for AI use, because simply connecting it to all your data kind of materially impacts how useful the system is. And then we have the spokes, which is on the right. These are other AI systems that are designed for specific tasks.
So they might be perplexity and illicit for literature and jurisdiction scans. You know, you might use JGBT for diagram and image generation. You know, just a couple of quick examples there.
The point here is that whilst the hub is the workhorse, the most useful, it needs to be connected to your knowledge and systems. And at times, specific other tools should be used for those specific instances.
[Anna]
Yeah, great. So we actually received more questions live. So that's cool.
So Heidi asks us, do you have any suggestions how to prevent cognitive surrender to AI? And Chad, do you want to take that one?
[Chad]
Sure. I think that's a tough one. I think, you know, I think people in general just have a tendency to offload their thinking if something looks and sounds logical.
But I think we have to remember that we're the experts here and have to consciously take the effort to review everything that the AI puts out, you know, to avoid that cognitive surrender.
[Anna]
So we've answered basically, you know, checking and why human in the loop is not just a complete control. And we are moving to the next theme that builds on that. And it asks, what can we trust?
And what needs proof? We've already touched upon it a little bit. So what happens when a non-expert treats AI as a gold standard over a subject matter expert?
Min, do you want to take that one?
[Min]
Okay. Okay. Let me give you the practical example from Ellen and Clark.
We have a cultural competency skill built into our system. And importantly, it is not just designed to replace our cultural experts. It's a guardrail.
So we want to harness the power of AI, but harnessing AI is also being very clear about what, where it should stop and where it can go. So for example, someone might ask AI for advice about te reo Maori, tikanga or any other, you know, cultural sensitive topics. AI is very, very good at producing answers that sounds confident and convincing, but that doesn't mean it's right.
So rather than letting AI act like the expert, we have to build instructions and boundaries into the system. The AI can recognise this is like area that I should not just make a judgment and make the call. It can pause, explain the limitation and point the person towards someone with the right cultural expertise to verify or guide the response.
And I think this is an important distinction because the guardrail doesn't just stop us from using AI, but it helps us harness AI responsibility. Yeah. And we are effectively teaching the AI not only what it can do, but we also teach what it should not do.
So when it needs to bring the human back into the conversation. So we are not using AI to replace cultural judgment. We are using AI to help people recognise when human judgment is required.
So we are putting the organisation's expectation and boundaries into the system itself rather than relying on every individual user to make the judgment on their own.
[Adam]
Yeah. And this is what we call embedded governance within our system, where the system kind of helps you govern the organisation. So, yeah.
[Anna]
Yeah. And, you know, staying on the trust topic, how should we record AI's outputs for transparency, accountability and, for instance, OIA?
[Adam]
Yeah. So our colleague Jodie O'Neill wrote a very detailed piece on the OIA aspect. So I'll try and kind of channel her a little bit.
And of course, we'll link you to the actual write up because Adam is not an OIA expert by any stretch of the imagination. But what I kind of took from her paper is that if you're using an AI tool at work and obviously if you're a government organisation, then your chats are actually considered official information. So Jodie says that under Section 2 of the Act, it covers all information held by an agency and the ombudsman actually treats held as in the agency's control.
So enterprise AI chats are both held and in the control of an agency and therefore are official information under the Act. Jodie also notes that there's no, there is actually no threshold kind of question on there. So I'll stop there because as I said, Adam is not an expert on OIAs or the Act, but we will definitely find that link.
So do check that out because Jodie goes into not just, you know, what are your responsibilities, but she actually goes into, OK, but what do you do about it? You know, if you get an OIA, how do you kind of handle it, et cetera. So it is practical as well as kind of interesting.
[Anna]
And that's also linked to what we talked about before. How does AI sit within the different pieces of legislation, right? And another one that you can look at is exactly the privacy agreement that you're on.
So, you know, like how do we actually make sure that what, you know, should stay sensitive, stay sensitive, be it, you know, your like health data or any other sensitive information or confidential information from clients and so on. Min, do you want to? OK.
[Min]
I think the key point is just don't trust enterprise AI can cover everything because that's not the answer. And you still need to understand the specific tool because we are using many tools and without you knowing, one day just the AI pops up. So you have to check your tools and how it's configured and who's got the access and where the data goes and, you know, what you're asking to do.
So to minimize the data is, you know, data protection is very important. Only provide what you really need for that task. Don't just try to copy and paste the whole data and just put it into AI.
That's not a good practice. Removing, always remove personal information. That doesn't mean just remove the name, but it can be role or email, you know, anything related to relate that can identify the person and understand your tool.
So you know what's stored there and who can assess it and, you know, how long it's storing the data and where it's used for training or not. And is any other third party tools involved in that software? And third one, we know, you know, it's really important to know where your data goes because enterprise environment doesn't mean the data stays in Australia or New Zealand.
That's right. Yeah. So for highly sensitive data and information, maybe it will be ideal to use locally, you know, used AI that you can host inside the machine rather than sending off to somewhere else.
And remember, AI can combine many separate little pieces of information and connect all the dots. And which means that could mean something else when you actually look into it as a whole output.
[Adam]
Yeah, that's right. Yeah.
[Chad]
And there's another thing I'd watch out for here, and that's bias. So if the underlying information is biased, AI can carry that into the analysis and make the result look more objective than it really is. So we still need to challenge the conclusions and not just think about protecting the data.
[Adam]
Yeah, I think just to kind of build on what Min said, you know, if you think about security clearance, you know, you might have a bunch of documents that have a low security clearance level. But when you run an AI, if you get AI to summarize all those documents, then actually the final output being a condensed summary of all those lower security level documents actually can increase the security kind of clearance level of the output. So yeah, it gets pretty nuanced and complicated pretty quick.
[Anna]
That is a bit scary. To get to another level. So we have a third team still, so off to that one now.
And it's about the oversight. So how do we turn individual experimentation into organization level value without actually losing control over quality, accountability and capability as well? So again, for this team, you can send us again questions.
So how do we set the strategic intent and how do we balance value with privacy and security?
[Adam]
Yeah, I mean, I guess let's start with strategic intent first. So on your screen is our definition of kind of what strategic intent means for AI. And essentially, it's a combination of what role or value are you trying to create?
Then what is your ambition level and how aggressively will you pursue that ambition? And then what trade-offs are you willing to accept along the way? And those things help you calibrate your actual intent.
So the question specifically asked, you know, about finding balance. This question did. So to answer that more comprehensively, there should be a slide up here now.
So essentially, what you're looking at is a set of the trade-offs that you want to kind of workshop through. So your leadership team sets each one as a collective. And the point here is that you kind of work through them to see where the dials are.
Where the dials are set on the screen is not the right answer. This is just a demonstration. The aim here is to avoid answering them in the abstract.
So kind of nobody ever argues against trust or against being careful with personal information. And therefore, it's easy for every dial to kind of land in a safe zone. And what you end up with is a position that leads to an operating environment that actually blocks you from getting real value from AI.
So if you think about what Chad said earlier about the kind of where we are on the continuum, you know, if you set things in the abstract, you end up just with a kind of lockdown chatbot. And therefore, you're not actually experiencing the full capability of AI systems. So what you want to do is you want to calibrate against real scenarios taken from your organization's own work.
So these are kind of decisions that people are actually making with the data they actually hold. And what you want here is each kind of leader to answer individually. And then you kind of put them up as a collective picture and then have a bit more of a debate.
So again, you know, specificity actually really helps you with that. The other thing that I would say is that there's almost always a gap between ambition and risk appetite that comes out every time we work with organizations. They're like, yeah, we want to be way up here in terms of ambition.
And then they're like, yeah, but we've got to keep everything safe and protect everything. And so obviously, those two things are kind of the antithesis of each other. And so what you've got to do here is kind of workshop the practical balance between ambition and kind of that security piece.
So yeah, you can do it. You know, we do it all the time. You know, use that thing, use that diagram that we have on there to help you do it.
[Anna]
And all of this combined, like how can we know that it actually produces organizational value?
[Adam]
Who's going to take that one? Min? Do you want to take that?
The organizational value?
[Min]
Um, okay. Can you see the slide? I hope you can.
So if you see the slide on the left, you can see the evidence grade shows how strong the evidence A is and the strongest, where you can see like confident links to the improvement to AI. And D is more in the activate in directive based on things like feedback or estimate. So not every AI initiative needs to be grade A evidence.
The goal is to use enough evidence to make a good decision without creating too much measurement overhead. But on the right hand side, the benefit class shows the type of the value created. And that could be realized like cash and avoid costs, more capability, capacity, and better quality, lower risk or broader capabilities.
And these are not just ranked. They are simply different ways that AI can create values. It's not all about money or time, right?
And Ellen and Clark, so we match the evidence to the use cases. For example, like workflows, we can compare data before, you know, before and after adoption of AI. And for others, maybe usage of the data, how much we use and team's feedback may be just enough to measure that too.
So the key is just measure the value in a way that is, you know, creditable, practical, not just measure by, you know, how much profit we made because we use AI.
[Anna]
Yeah. And we have a lot of great questions today either like sent to us during the session or ahead, but we are aware that we, this is the end of the session time. So we're going to stay on because we've got heaps of questions and we'd love to get through.
But if you do need to leave, then thank you for joining us. The recording and slides will be sent to you after the session this afternoon. So we can go back to the questions.
And we have one from Joshua. Based on your experience, what are the biggest lessons organizations learn when introducing AI into business workflows? And what would be your advice for leaders to prioritize from a change management perspective?
[Adam]
Yeah, that's, oh, I guess I'll take that one. We find that organizations kind of fall into two buckets. So there's kind of organizations that are feeling kind of the pressure, so to speak, to get started.
So that's kind of one bucket. And then the other bucket is organizations that have started, but are kind of struggling to kind of measure or see value from the implementation and the costs. And for me, the issue across both those organizations is actually the same thing.
And where you need to start, if you are a leader, is you've got to get that strategic intent set up right. You've got to understand your kind of risk profile. And what, when you figure out those things, that helps you lead you down an implementation pathway.
And so depending on your kind of calibration, on your strategic intent, we kind of use three different implementation pathways. And then we kind of work on those together with the organization. So yeah, so that's kind of the main answer there.
And what you'll find is that, sorry, I think there's a bit of a problem with my mic, but I'll just finish this first. So what you'll find is that once you've got those things set up, then actually it makes it super clear for the whole organization about where you're heading with AI, what is okay, what is not okay. It influences everything from your policy, who governs AI, who leads the implementation.
All these things are super important to get right. So that's where I start. And if you haven't got that really nailed down, you really have to have to do that.
And I'm going to fix my mic.
[Anna]
Yeah, awesome. I'll go into Jack's question then. So we've talked about bringing people along with us.
So for those of us in public agencies, we're seeing ongoing distrust in public institutions in the post COVID times, plus mixed views about AI uptake, but at the same time, an experimentation in our agencies that were adopt more AI. How can we bring the public along with us? That's an interesting question, actually.
[Adam]
I've got views.
[Anna]
Okay.
[Adam]
What I would say is that the public, so you're going to end up with the public becoming more accustomed to AI because of their interactions, not with government, but with private enterprises. And so like one example is call centers, right? So if you think about your bank, your kind of internet provider, you know, all these consumer services that you have to interact with, these organizations are pushing AI implementation because it helps them deliver the services better and more efficiently.
So I know we've all had this pain, right? You've got to ring the bank to like change your address or something simple as that. And you're like, oh God, this is going to be a one hour on hold situation.
So I can say to someone, my address has changed. And you know, so in those examples, consumer products, so a bank will kind of, you will start to see this, will give you the option, hey, you can wait an hour on hold if you want, or you can talk to an AI assistant and get it resolved right now. And so consumers, like the public are going to start coming into more and more contact with these AI systems, and they're going to get more and more comfortable with them.
And so I think from a government point of view, you can kind of trail closely behind at the pace that these kind of consumer services are delivering value to the public. Because if you're not trailing behind, what's going to happen is one day you'll kind of look around and the public's like, hey, where is my, you know, why can I ring my bank and get my thing changed like that using an AI? But when I ring IRD, not to pick on me, but you know, but when I ring IRD, I'm still forced down this human only path and it's painful.
I actually, they'll start kind of demanding. And so there's going to be, there will be a shift. Definitely.
[Anna]
That's true. Never thought of that actually. But yeah, you're absolutely right.
So all the frameworks and guidelines say that organisations should monitor and audit use, but I'm interested in how audit and monitoring actually looks in reality in organisations.
[Adam]
We actually have a slide on this.
[Anna]
Oh, do we?
[Adam]
Yeah, we do. So let's try and find it.
[Anna]
There it is. There it is. Awesome.
[Adam]
Go Chad. Okay, go Chad. Throw him under the bus.
[Chad]
So to do this, we use the framework on your screen on the slide. So this is quite detailed and you can download it afterwards. But just quickly, the controls stack on top of each other and provide different levels of assurance.
The base is your existing AI system. The middle is where the AI actually operates and the top is where people and clients are. The embedded governance panel on the right is an always on layer that applies to all eight controls.
And I'll just point out a few things here. This approach does not name models or vendors. It's instead just focused on the controls themselves.
This ensures that each layer handles changes in the underlying technology. So on the right is your embedded governance. Remember, because of the way these systems operate, you can build governance into the system itself and helping to protect users and your organizations against use cases that may seem appropriate on the surface.
This is also where you plan for risks such as de-platforming and usage costs.
[Anna]
Great. I think we have more questions from people.
[Adam]
Okay, great. Yeah, let's get going.
[Anna]
So we have, how should a regulator or a public sector leader create practical assurance, governance, and quality assurance arrangements for AI when the roles, capability, and organizational arrangements are still catching up?
[Adam]
Yeah, I mean, I think those two questions are kind of really similar. And my view would be, you know, the framework that was hopefully on your screen. You know, that is kind of where we start because the person who submitted that question, sorry, I didn't catch your name.
You're absolutely right. The systems keep changing. Their usefulness keeps changing.
I mean, one day you'll wake up and come into the office and Min has experienced this and suddenly you've got 50 users contacting you saying, oh, I can't log in today or this feature that I was using yesterday is no longer there. And so the point is that your kind of framework and your implementation pathway that we spoke about needs the capacity to support users as things change. Because the change in the spaces is inevitable.
It's super fast paced. So that's why we kind of use that framework because it kind of ignores the underlying technology. And it kind of builds around that's kind of innate changes in speed.
[Anna]
Yeah, makes sense. So I think we've covered all the questions. We don't have any.
I'm looking at team. So thanks a lot. Thanks a lot, Chad, Min and Adam.
But before we wrap up, well, I would like to finish on just like a practical advice from all of you. And if someone can do just one thing next week, what do you think it should be? Start with Min.
[Min]
I would always say you have to just pick a task and let's try it because if you don't test your limit and without trying, just guessing and you're like, oh, is it too hard? Do I have to learn first? Try it.
So that's the best way to learn.
[Adam]
What do I think? So I'll go back to that kind of strategic intent piece, because that's kind of the biggest thing that I see. And the point is that, you know, you're setting your ambition level, but you've got to that you're willing to accept so that everyone from a CE to a graduate has a really clear idea of what's acceptable use and what isn't.
That doesn't just live in your kind of policy document. That has to be embedded into the system because when was the last time any of you kind of listening out there thought to yourself, you know, in the heat of the moment, Friday afternoon, you've got to get something done. You know, when's the last time you thought, oh, hang on, I think I read on page 78 of the something around the policy that what I'm about to do is not acceptable.
Let me go and check the policy. That does not happen, right? And so you can embed your governance into the system, but you need to know what the governance needs to be within the system.
And that comes back to that strategic intent and the tradeoffs.
[Anna]
That's well put. Chad, what is your advice?
[Chad]
I think as a high technical person, I can tell you that the capability of the tech is there. So I wouldn't ask, you know, is it useful and can I use it? I'd ask more, how can I integrate it safely into what I'm doing and my work today?
And just like Min said earlier, you know, get started, get started today.
[Anna]
Yeah, and I very much agree with all of you. But yeah, just like building on what Chad just said, I can speak for myself. And we've used the colleagues example on the theory of change before.
But it's really helpful for me as a person who does a lot of regulatory and policy work, for instance, to have someone who really understands AI. And we can like join these two worlds together and just work alongside. And you guys help me optimize my workflows and the way I do things.
So I definitely, you know, whether you're in policy, evaluation, strategy, you know, teaming up with people that really understand how AI works is really useful and it just will augment your quality of outputs. That's for sure. But yeah, the QA needs to be there.
Good. So thank you so much for joining today's session. So if any of today's discussion around AI has sparked further ideas or questions, our experts are always here and they're happy to continue the conversation.
So just please reach out. And as we said, we will be sending the slides out and the links to Jody's article and so on. So we'll be in touch.
And yeah, have a great rest of the day, everyone. Thank you.
[Adam]
Thank you.
[Anna]
Thank you. Bye.