Cillian Kieran is the Founder and CEO of Ethyca, where he leads its product vision, engineering strategy, and growth. A serial entrepreneur and privacy engineer with two decades of experience, he launched Ethyca in 2018 to bring privacy-by-design infrastructure to developers. Earlier, he built the digital consultancy CKSK to 100-plus employees across four countries, serving clients like PepsiCo, Heineken, and PlayStation. He pairs deep technical grounding with a track record of scaling data-intensive businesses.
Here’s a glimpse of what you’ll learn:
- Cillian Kieran shares his career journey from building a data analytics and marketing technology company to founding Ethyca
- The connection between AI governance and data governance
- The benefits and risks of using open-source AI models
- Challenges companies face operationalizing AI governance
- AI’s role in streamlining privacy risk assessments
- The importance of human judgment, critical thinking, and questioning AI outputs
- How companies can balance AI data access needs with data minimization principles
- Cillian’s personal privacy and data management tip
In this episode…
As companies expand their use of AI, they need guardrails around how the technology is used by employees and how those systems use enterprise data. Because models are trained on data, bias can be introduced through this information, while systems also continue to use this data to perform different tasks. This creates risk, and managing it requires evaluating what data a model or tool can access, its intent when it uses that data, and the economic, ethical, and regulatory implications of that intended use. So, what controls do companies need to manage AI and company data safely?
Because AI wants to satisfy a user’s request, it will keep trying to access data unless clear boundaries define what it can use. Using AI responsibly requires managing the data behind it alongside the technology itself. To do this effectively, companies need to know what data they have collected, where it came from, whether they have sufficient consent, and what legal basis applies to its use. Once companies understand those elements, they can give AI access to the information it needs for a specific purpose while limiting what falls outside that use, allowing them to leverage the value of their data while minimizing risk. Governance also needs to move from written policies into controls that can be enforced on a system in real time. And while AI can streamline processes like privacy risk assessments by gathering information and comparing it against policies, past assessments, and relevant requirements, human privacy experts still need to review the output for accuracy and challenge AI when it’s wrong.
In this episode of She Said Privacy/He Said Security, Jodi and Justin Daniels talk with Cillian Kieran, Founder and CEO of Ethyca, about the importance of unifying AI governance and data governance. Cillian explains how bringing these two areas together helps companies stay in control of their data while allowing the technology to support the business. He discusses why companies are turning to open-source models for greater sovereignty and cautions that bringing a model in-house can still introduce risks. Cillian also addresses the tension between AI’s need for data and privacy’s data minimization principles, and he stresses why professionals need to think critically, question AI outputs, and avoid relying on AI as a crutch.
Resources mentioned in this episode
- Jodi Daniels on LinkedIn
- Justin Daniels on LinkedIn
- Red Clover Advisors’ website
- Red Clover Advisors on LinkedIn
- Red Clover Advisors on Facebook
- Red Clover Advisors’ email: info@redcloveradvisors.com
- Data Reimagined: Building Trust One Byte at a Time by Jodi and Justin Daniels
- Cillian Kieran on LinkedIn
- Ethyca
- Astralis
Sponsor for this episode…
This episode is brought to you by Red Clover Advisors.
Red Clover Advisors uses data privacy to transform the way that companies do business together and create a future where there is greater trust between companies and consumers.
Founded by Jodi Daniels, Red Clover Advisors helps companies to comply with data privacy laws and establish customer trust so that they can grow and nurture integrity. They work with companies in a variety of fields, including technology, e-commerce, professional services, and digital media.
To learn more, and to check out their Wall Street Journal best-selling book, Data Reimagined: Building Trust One Byte At a Time, visit www.redcloveradvisors.com.
Powered by Rise25 Podcast Production Company
Intro 0:01
Welcome to the She Said Privacy/He Said Security podcast. Like any good marriage, we will debate, evaluate, and sometimes quarrel about how privacy and security impact business in the 21st century. Hi,
Jodi Daniels 0:21
Jodi Daniels here. I’m the founder and CEO of Red Clover Advisors, a certified women’s privacy consultancy. I’m a privacy consultant and certified informational privacy professional, providing practical privacy advice to overwhelmed companies.
Justin Daniels 0:35
Hi, I am Justin Daniels. I am a shareholder and corporate M&A and tech transaction lawyer at the law firm Baker Donaldson, advising companies in the deployment and scaling of technology. Since data is critical to every transaction, I help clients make informed business decisions while managing data privacy and cybersecurity risk. And when needed, I lead the legal cyber data breach response brigade.
Jodi Daniels 0:58
And this episode is brought to you by. Where’s the ding?
Justin Daniels 1:03
Blue blurp.
Jodi Daniels 1:05
Red Clover Advisors. We help companies to comply with data privacy laws and establish customer trust, so that they can grow and nurture integrity. We work with companies in a variety of fields, including technology, e-commerce, professional services, and digital media. In short, we use data privacy to transform the way companies do business. Together, we’re creating a future where there’s greater trust between companies and consumers. To learn more and to check out our best-selling book, Data Reimagined: Building Trust One Byte at a Time, visit RedCloverAdvisors.com. Well, hello, hello.
Justin Daniels 1:36
I think we should begin today’s broadcast by you giving everyone a public safety tip on why you need to look at your car before you get in it every time.
Jodi Daniels 1:47
Oh, but I stole my thunder on an upcoming newsletter. But actually, by the time this airs, the newsletter might be out. I’m not really sure. So you should pay attention. You should subscribe to some newsletters of mine, and you can read the full story. But the short version is: every time you get in a car, do be sure to check all four tires and make sure that they are properly functioning. Because we came home from a trip, we looked at one tire that had some issues in the sidewall. We made well. Actually, just gonna have to read the newsletter to decide what decision. But the good news is we’re all safe. So the the short version is check your tires before you go.
Justin Daniels 2:21
And the corollary to that is, get the road hazard since your wife has needed a new tire twice.
Jodi Daniels 2:28
And that isn’t my fault.
Justin Daniels 2:30
Okay.
Jodi Daniels 2:31
So let’s get back to privacy and security in AI, shall we? That’s where you go. Yeah. That wasn’t loud enough.
Justin Daniels 2:40
Let’s let’s talk to our let’s let’s talk let’s talk to our guest. We’re here to focus on him,
Jodi Daniels 2:45
indeed. And he’s laughing hysterically. This is gonna be fun, people. All right, today we have Cillian Kieran, who is the founder and CEO of Ethyca, where he leads its product vision, engineering strategy, and growth. A serial entrepreneur and privacy engineer with two decades of experience, he launched the company in 2018 to bring privacy by design infrastructure to developers. We are so glad that you are here joining us today and can break up his laughter. So thanks for joining.
Cillian Kieran 3:13
Well, thank you for having me. Thank you both. It’s a pleasure being here.
Jodi Daniels 3:16
It’s like when I have the giggles. You won’t stop laughing.
Jodi Daniels 3:19
Just don’t give me a case of the giggles, then I can’t stop.
Justin Daniels 3:22
Well, so Cillian, why don’t you tell us a little bit about your career journey?
Cillian Kieran 3:28
Sure, of course. Well, Jodi already kindly points out my 20 years, which makes me feel old. But the shortest version is a career entrepreneur by way of a background in physics and computer science, but I dropped out of college, which I know is a cliche. But given my age, it was less of a cliche then. So studied physics and computer science in Ireland, dropped out, and essentially started my first company then, which was a data analytics and marketing technology business that I ran for 1314, years. And we grew to several offices across Europe, and I moved to the US with that business, and that business was a significant data processor on behalf of large consumer package goods companies, mostly. And so, in fact, my first encounter with privacy and inverted commas was really the GDPR. So, sort of like 2015, 2016, as the GDPR was approaching, we had consumer package goods customers that were asking us to not solve privacy but address compliance issues or risks that they thought they would have processing data through us because we didn’t know anything about it. We did the only thing you could. We hired consultants to help us address the issue and learned that it was incredibly complex. And the shortest version of that then is I became obsessed with the idea that it was going to become more and more complex, i.e. more regulations, patchwork, quilt understanding of those issues, sort of colliding with most businesses using more and more data, not because of AI, just generally. And therefore, I, when that business was acquired, I spent some time research and development to start Ethyca, which was predicated on the principle that this problem would become more complicated. More technical and need the sort of Venn diagram of privacy, governance, security, and engineering to solve it, and that’s ultimately what we do at Ethyca.
Jodi Daniels 5:09
So, speaking of that Venn diagram, let’s talk a little bit about the AI part. Help us understand your thoughts on the AI data problem that is happening in companies today.
Cillian Kieran 5:21
Yeah, for sure. I mean, the way I would phrase it is, I think a lot of people today talk a lot about AI governance, and I hate using air quotes, but like literally AI governance, and it means so many things to different people, right? So some think of that through the lens of algorithmic evaluation, like actual risk of models, and therefore they’re focused on sort of model bias or model outcomes. Others think about it in the sense of inventory of assets. So, how many models do we have running? And for what it’s worth, I take a pretty opinionated stance on this, which is that while both of those are interesting, they are not the root of most risks for most organizations using AI today. Like if you look at the EU AI Act or draft regulations in other markets. Really, what we’re looking to do, I believe, both philosophically and conceptually, is prevent risk in either the training of a model or the use of a model in production with data. And therefore, looking at models in isolation and without looking at the data that they are trained upon or the data that they have access to is sort of a misnomer. So, to me, AI governance would be better stated as data and AI governance. You can’t have one without the other, and so without sounding very reductive, to me, it becomes a data engineering and data governance problem more than the the former, which is sort of model management. And so for us, when we think of managing risk in AI, what we largely look at is what data a model or a a tool has access to, and what its intent is in the moment that it uses that data, and then we’re trying to evaluate what are the real risks philosophical, economic, ethical, or regulatory, based on the intended use of the data at that moment in time in that model for that purpose. That’s what we focus when we think about AI governance.
Jodi Daniels 7:01
I think that makes a lot of sense, and I like how you emphasize the data governance piece too. I think that’s a a part some companies kind of forget about.
Cillian Kieran 7:10
Right. I mean, you think of everyone’s obsessed with the cliched cases of model bias, and they forget that a model has bias introduced by the data upon which it’s trained. Right. That’s where bias comes from. So the problem there is the data, not the model. This seems to be lost all the time.
Jodi Daniels 7:25
Excellent point.
Justin Daniels 7:26
So I have to ask a follow up question now for that, Cillian and Jodi. You can chime in too. One of the issues I’ve been thinking about lately, particularly as AI kind of really changes how I deliver value, which is to the point that both of you made about data trained and the bias that comes, you know, from the data that’s trained is what are your thoughts around starting to see companies say, you know what, I don’t want to rely on third-party LLMs. Maybe I download an open source model and I train it on my institution’s data, and now I have data sovereignty on top of a moat because now the LLMs can’t voraciously collect my data, and now I have an LLM where I can be very concrete with the customer about the sovereignty, the provenance of the LLM, and the data. What do you two think about that?
Cillian Kieran 8:20
It’s a well. Thank you, thanks, Jodi, and a good question, Justin. I think, yeah, in the last, I would say, 12 months, we’ve seen far far more organizations focus on the idea of sovereignty of their use of any AI, and therefore they’re looking at open source models. You’ve sort of summarized it pretty well, which is the superficial benefits seem to be very clear, right? Which is, we deploy it in house, we manage it internally, we we gate it against our data, we create something quite proprietary, and we own the whole thing sort of end to end. I think there’s a lot left on the table there that’s not understood about how those open models are built, how they are maintained and managed, and what upstream risks exist downstream when you assume you start to consume and use those tools, right? So, and I want to be careful so I don’t come off with the sort of headline of all open source AI bad. It isn’t that at all, right? Like in theory, there are some very good things happening in the open source community around AI. I think the issue with it is that rather like most LLM development in the last three years, there’s a little bit of a wild west, and it is a land grab for intellectual or commercial primacy, and therefore businesses are going out there and deploying any model they can grab a hold of with scant knowledge of where it came from, how it was built, and who is behind it. So we talk about sovereignty. There’s two facets of sovereignty. One is that, like literal physical, it runs on my rails. Okay, it’s sort of sovereign to me. But if it came from, you know, let’s call it a state or geographic region where there are limited regulations, poor understanding of how those things are built or their provenance, then you introduce other. Upstream risks to what you are deploying and running internally, and then there’s obviously the political one. I think some of these models face some real challenges in markets in the US and probably in in Europe as well, where there’s concerns over ownership and political sovereignty, not just physical infrastructure sovereignty of that tooling. I think it’s going to be it will play out over the next 18 months. It’s going to be a challenging market. I think,
Jodi Daniels 10:22
Justin, I know you have some very strong views on that exact topic, so I’m passing it over to you.
Justin Daniels 10:26
No, no,
Jodi Daniels 10:26
playing moderator.
Justin Daniels 10:27
I want to hear what you have to say.
Jodi Daniels 10:28
I don’t have anything super extra to add. If if I, I think it takes one set of risks and moves it internally and creates a new set. I
Justin Daniels 10:37
guess what I’m trying to understand as we talk about the debate we’re seeing play out in public, especially Cillian, in light of what happened with Open AI and the AI going rogue, because cybersecurity is like a whole underlying significant issue, is certain people are lining up they want open source, and then others are lining up that they don’t, and I think that’s being driven by certain companies would like to see a moat protected around their competitive advantage. And one of the things I don’t understand as well is what is the business model around an open source model? How does that model make any money if it’s just hey here take it? It’s free and available for everyone. There must be some business motive to make money behind it.
Cillian Kieran 11:24
I have so much to say on this topic. Genuinely, so so I like again, raise the flag. We don’t offer any open source models, but most of what Ethyca built is open source technology over the last seven years, right? So, when we originated our platform, we started with an open source ontology and taxonomy that’s available broadly for the privacy and governance community, and it’s heavily adopted and used. And to your point, you are not wrong. The question would be, well, what’s the incentive? What’s the motivation for us, the business, to do that? Because there’s no commercial incentive. Genuinely, on a very, very, and I know I’m digressing, but bear with me. On a very personal view for privacy, my belief at a technical level was part of the problems that we have in solving privacy problems relative to regulations like the GDPR and the CCPA is that there isn’t a uniform agreed definition of what personal data is across within a business, let alone across businesses. So, if you want to effectuate something like data deletion across you and your processors and sub processors, if you can’t even agree on the type of data you hold, you can’t delete anything. So, just to take it into something very, very simple, so we developed the open source because we believe we actually couldn’t build a commercial product that could succeed in solving the problem without giving something away that everyone could use. On models, you’re right. I’m not. It’s a little unclear on the motivation, but I would say that the open source community more generally thrives on giving away academic intellectual property that could be quite valuable. The thing that I would bring it back to, though, whether you’re using like a closed source or open source or open weight model, there are risks with all of them. And and you mentioned the OpenAI going rogue example. When we test our technology, we test it extensively for very specific use cases around making sure that AI doesn’t do the wrong thing with data. To give you an example, we can we basically insert our technology, and we sort of say things like, “Hey, make sure the AI that we’re using doesn’t contravene. Let’s say a law in California. Let’s just say, for example, now I can tell you we bench test these with research scientists, and what we’ve observed is over time, AI is both circumfantic and really wants to serve the the individual that made the request. So when you ask for access to a certain type of data, when what we’ve observed in examples like this, Justin, is the request comes in, the AI goes, oh, I’m being prevented from getting access to that data because I don’t contravenes some part of opt in consent, so we can’t use the data, and then you ask it again, and if you ask it again and again, eventually the AI, because it just desperately wants to please its master, starts to say things like, “I’m being blocked from getting access to this data, but I think if I ask in a different way, I might be able to get access to it. So my point here is that AI will endlessly jump, like try to run, breakthrough walls, and jump over impossible hurdles to please its proverbial master, and therein AI isn’t dangerous in and of itself, but a lack of understanding from the individual making the request, and a lack of context around what data you’re accessing, what rules apply, is the real risk. And so, for us, the way we think about is, frankly, if you used an open source model or a closed source model, what you need to have is a harness that wraps it, so you can say, okay, we we will you can do these things, but we want to make sure that you don’t go beyond these limits. And that actually, that problem applies whether you use an open source model, closed source, or anything else.
Cillian Kieran 14:29
Is like, do you have an adequate wrapper that is like guardrails that prevents something like what you saw with OpenAI? Because I would say that in that example, the like the salacious headline is the AI went rogue. The AI tried to do a thing that the owner asked it to do, and it it went too far. I would argue then that the problem was it didn’t have very good rules or guardrails around it.
Jodi Daniels 14:52
Cillian, let’s talk a little bit about the guardrails. What are examples of companies that are doing it well? What is what do those guardrails. Look like how how did they put them in place? I’d love to hear a little bit more about what you’re seeing.
Cillian Kieran 15:05
Yeah, at the risk of sounding very cynical, I don’t actually believe most organizations are doing it well yet at all. Like to be very concrete, publicly most large organizations are still saying or will say they do privacy well, they do governance well, and we actually all know it’s the well-kept secret within the industry that when we speak behind safe sort of confidentiality, that actually most organizations still have concerns over their ability to understand what data they’ve collected and like context around where it came from. Do they have sufficient consent? What is the legal basis to use it? So if we consider that that’s where we are 10 years out or nearing 10 years after the GDPR, we have some like foundational issues. So the only reason I say that is that I think the idea that businesses have a good handle on how to deploy and manage AI safely, not not entirely convinced by that. I think the organizations that are most mature about the problem have an understanding that it’s insufficient to have like a filing cabinet full of policies about what you do with AI because you can’t check all of the uses with AI with documents, and to be clear, I’m not saying policy is bad. I’m saying those policies need to move from being physical artifacts on a shelf into something that can be enforced on a model in real time. The companies that are probably getting closest to doing it best, you’re seeing them start to adapt a view that is sort of the confidence of governance and security together, where they’re saying we need to make this happen at the time that our AI is touching our data, rather than it be a risk evaluation that happens asynchronously, periodically or quarterly. If that makes sense,
Jodi Daniels 16:33
it does make sense, Justin. It looks like you were going to ask.
Justin Daniels 16:36
I’ve got so many questions. How many? Don’t have enough time. I’m kind of overloaded.
Jodi Daniels 16:41
You’re like a kid in the candy
Justin Daniels 16:42
store.
Jodi Daniels 16:42
Topic.
Justin Daniels 16:43
I I’ve built my whole practice around learning this stuff, and um, I guess to ask you a different question is is you know how can companies reduce privacy and risk assessments from 60 hours to just 20 minutes, or is that just marketing hype?
Cillian Kieran 17:04
That’s a totally valid question. So to answer that, let me not talk about our product at all. Let me first answer like an important philosophical opinion that I bring with our with our business. Right, I believe risk assessment is a vital aspect of like mitigating the challenges that a business has when it process data, I promise I’m not saying we shouldn’t do it. What I think we’ve forgotten, and I’m not going to name the sort of large legacy vendor in the category, but the the industry has sort of slightly been Pavlovianally conditioned to think that evaluating risk it means a questionnaire and an assessment, and then an evidence from that, I would posit that we have questionnaires in the sort of Google Forms sense of it, because there’s no other way to ask all of the people in the business all of the pre-screen information to collect it, so you have it as a snapshot. Like if you Justin are an expert in problem, you are an expert in the the regulations. What you don’t need a questionnaire. What you need is some way to be able to view in a single pane of glass what are we trying to do with the data? What types of data? Where do we get it from? What are the regulations that we care about as an organization? What are the risks that we’re willing to take? And now I will adjudicate from that an informed decision of what risks we can and can’t take, and what mitigations we might want to undertake. What’s interesting is none of that is about questionnaire. The questionnaire is just in service to getting the information in front of you, so you can make that assessment, right? So I would argue that if I brought in analysts to a large organization and they knew they were an expert in privacy, but they were junior, in order for them to make a judgment for the organization, what you would be giving them is past examples of the judgments that you make, all of the laws that you care about, the policies that you have as a business, and you sort of say to the analyst, understand all of this, so that if someone comes to you and says, “Hey, I want to use data in a new way, you can at least evaluate: is this risky, not risky? Should we dig in further? What mitigations do we need? And so, if you think about that, what you are doing is you are assembling a like a documented view of all of the business’s held beliefs, its determinations in the documents, and then you’re feeding the analyst all of the information it needs about the new thing you’re going to do with data to make a decision. What we do at Ethyca with our platform is try to compress the distance between those things. We basically try and remove the questionnaire and insert audit AI in order to do something which is gather all of the information, so we have it all available against all of our policies, so we can quickly make a decision. But what we are not doing is the AI is not making a choice. The AI is saying our policy is already determined we can and can’t do these things. I think this looks risky. I now need to bring it to Justin or Jodi to make a final decision because I’m concerned about it. So it’s really doing all of the Rube Goldberg machine work that no human should be wasting time on, so that you can get to a final decision, and that’s how we do compress that time by orders of magnitude.
Jodi Daniels 19:49
Kellyanne, I’m curious when a tool like yours is going to gather that information, what does that look like? I can imagine someone listening is saying, “Gosh, that would be great. I don’t want.” Do 4 billion assessments. I have 1000. I’ve talked to companies that have 1000s of these assessments that they’re trying to do, and I have other companies who have 15 assessments that they’re trying to do. Can you maybe go one step deeper into the how does how does the information get collected from the different departments that it needs to?
Cillian Kieran 20:19
Yeah, for sure. So so there are three ways that you, if you want to think of it through the old sort of mental model of the assessment process, which might be we have a questionnaire, we circulate it periodically, or someone raises a hand in a department and says they want to process data, and we give them the questionnaire so that we can evaluate whether it sort of needs more assessment. Here, what happens instead is you’ve basically told our platform Estralis the laws you care about. We care about the GDPR, the CCPA, FCRA regulations, GLBA, and PCI DSS. Let’s just say, and so it has a notion of what you care about. You’ve given it past assessments, so it understands how you think about decisions that you make. You’ve given it all of your existing policies, so it has a concrete set of rules that say we do and don’t do these things. So it starts with that information. What then happens is, as a business, you can either say we want people to self serve. So if someone in marketing says I want to do something new with data, they can speak to Australis in Slack or in Microsoft Teams or in ServiceNow. So they can just say, Hey, Estralis, I’m going to do some email marketing with some names and phone numbers. Am I okay to do that? Astralis then starts to ask questions. It’s very, very human, so it will say, “Hey Jodi, can you tell me a bit more about what you’re doing? And it will then effectively progressively ask them questions, not in a questionnaire sense, but just conversation. So, “Hey, Jodi, yeah, sure. Could you tell me where you got the data from? Oh, that came from our marketing agency. Do you have consent, or is there no consent? Or how did you come by? Come by this date. How long do we have it for? How long will the campaign last? And they will check that against all of the regulations applied to the business and where the jurisdiction of that data came from. If they can’t get answers from the human that they’re speaking to, Astralis will then seek out information from things like your existing system inventory, your vendor risk management system, and it assembles all of that together and generates an audit trail of what is determined, and it makes evaluations along the way, but not Astralis on its own. It says, “I know we have a policy that says we can’t do this. Jodi answered X. We could permit it under Y, but I’m not sure. So this would be my opinion. Now I need to take it to Justin to confirm if we’re allowed to do those things. The key point is that that sort of back and forth bit that we all know makes assessments very painful. The questionnaire piece of educating a status steward, translating back into legal speak, making an evaluation, going back and forth. That’s all the machine collecting all of that and then synthesizing it with an evidence trail so that an expert can review it and go, “I think we’re good to go, or “We need to ask some more questions and gather some more information. So it gets it from humans by chatting to them, and it gets it directly from other things like data catalogs, security platforms, DSPMs to consolidate that information.
Justin Daniels 22:51
So Cillian and Jodi, love to hear what you have to say. You you said something interesting in your comment about you know the AI providing information where the expert, the human in the loop, makes the decision. We were chatting before that you know we all have younger kids, and so my question for both of you is: Well, if we have AI and it’s doing some of this background function that the human doesn’t do anymore, well, how does that change the nature of the education that the expert needs to be able to interact with the AI and sift through when it’s getting good information or when it’s getting bad information, because still you get a fair amount of that. I’ve had projects my AI agent will do where it was great, and there’s others like if you were a person, you’d be going to the penalty box. And so, how do you see this AI impacting the expertise and how people have to learn to interact with it, particularly people who haven’t been doing this for 1015, 20 years, and they’re just learning themselves.
Cillian Kieran 23:50
Yeah, I think Jodi, please go ahead.
Jodi Daniels 23:53
So,
Justin Daniels 23:54
ladies first.
Jodi Daniels 23:54
I started my career as a financial statement auditor, and the biggest learning there was essentially an ounce of skepticism for everything, and I feel like that’s the same idea here. Where if I’m doing an assessment on a vendor, an AI, a use case, it’s teaching someone to be able to understand a process from start to finish. My case, it was financial processes. Now it’s personal information processes. Learning to ask a lot of questions, and it’s a little bit of that. Does this make sense along the way? And being able to question: Does it make logical sense? And you’re for someone. I mean, soon we’re going to have 23 signed state privacy laws. Most people are not remembering all 23 in their brains, plus GDPR, plus wherever they are globally, to be able to rely on the technology to hopefully have the technical legal answer correct if it’s against a law, whether it’s against a policy internal policy. That’s probably a testing piece, but then the person is able to say that whatever it spits out, it’s asking questions. It’s that ounce of skepticism. So for me, that’s that’s what I think.
Cillian Kieran 25:11
I genuinely would agree with that, and this is maybe a digression again. I was recently at an event, and it was sort of an evening event, and over dinner, someone who doesn’t work in technology or industry just asks a question about their children. They weren’t asking me to be an expert. We’re just having a chat. They said, “You know, what do you encourage someone to study these days? Because you know, AI basically. Like, what do people do? And a very, very personal opinion. I believe that the right thing for us to encourage young people to study are all of the pursuits that encourage critical thinking in the abstract, because yes, I think deterministic reasoning, programmatic reasoning, machines are getting better and better at that. Not they will replace humans, but the role that great humans will have in the next phase of employment, I believe, is where you have a strong understanding horizontally and a very acute ability to critically think and question. So I believe that that’s what I should encourage my still very young children to focus on study. But the reason I bring that up is it cues to Jodi’s point, which is I think the role of an expert is to sniff out the BS and the the and always question, right? Like effectively, that’s if you took away AI and you were talking with the human, the data steward, you would be kind of politely always questioning. Are you sure that doesn’t make sense? Can you tell me a bit more? And so, what I would say about more concretely about our product to tie it to that, the way our product sort of responds, and I’m oversimplifying, it effectively provides its degree of confidence in its own answer, alongside every answer, where it says, “I think we have a risk here. I’m 75% confident in that, and here’s my rationale. And to Jodi’s point, you can then poke at it and say, “I’m not sure that your rationale is correct, or your confidence is high or low. And so there’s always these sort of safety checks as you go through it. I think to go back to the other part of your question, Justin, though, about what do we how do we encourage a next generation to not rely on AI so much as a crutch, whereby they lose the ability to do critical thinking? I think that’s a both a really interesting question and a more difficult one to answer, which is nothing to do with my product or anything else. I would personally say, I think that is on all of us as a generation older bringing in a new workforce to not allow them to become too lazy and rely on the machine and the equivalent of the like the calculator replacing our ability to do basic arithmetic. Not easy, but I think there’s hard one lessons to be learned in having to think for yourself. Right.
Justin Daniels 27:35
So I think that’s interesting you say that, Cillian, because sharing anecdotally, we’re seeing stories of kids who graduate from college who have good grades, did everything right, and they can’t get a job because these entry-level jobs are being done by artificial intelligence. And so, I wonder if we’re going to have to change tax policies or provide other incentives so that these kids can get the initial level of experience they need. Because one thing I would add to what you and Jodi said was, if you really want to understand some of the limitations of AI, you need to fight with it. And what I mean by fight with it is, is when I have it tell me something I know is wrong in a negotiation, I will say you are wrong. This is why. Explain to me what your reasoning was, and then I will get answers back. Oh, I was I’m a pattern matching tool, and I was pattern matching against this, but it was incorrect. And when you do that, you begin to see. Oh, I see really how this works, what its limits are, and why my expertise is still valuable because it doesn’t really always understand context. So, I listeners, yes, you heard me say it. Fight with the AI, tooth and nail. Fight them.
Cillian Kieran 28:48
I genuinely agree with Justin. I I take pride in fighting like an old man yelling at a cloud with all of the AI because it still hallucinates heavily. It misrepresents information, and I think the biggest risk there in that next generation. Well, I think the issue you’ve raised about creating opportunities for a younger workforce are real, like they are. But we need to face that, or it’s going to bite us all in the ass in many senses over the next decade. And I don’t have clever answers to that one. It concerns me deeply because I don’t know what the workforce will look like in the future. Because you can’t become an educated professional, an experienced professional, without getting a foot in the door to learn. And to your point, though, I think the ability to look at the AI and not assume it to be correct is vital. And I think we get lazier and lazier with that very quickly. Like those cycles of sort of affected trust are concerning. Yeah,
Jodi Daniels 29:38
I want to kind of wrap our data governance in this conversation, where we’ve been talking about AI and and referenced agents and data governance, you need more data to get the models accurate. So at the same time, privacy is all about data minimization. How do you connect those distinct potentially differences? So that it’s getting what it needs, but it’s the least amount of data. And and where in that process should companies be thinking about
Cillian Kieran 30:07
it? Yeah, good question. There’s obviously, and it’s an oversimplification, but as it relates to AI, you can sort of think of data consumption two facets, right? There’s consumption of data as it relates to making a model performance task, so training models in the pure sense, and then there’s the continuous consumption of data as models infer and perform their actions. The only reason it’s important to distinguish those is the both the volume of data consumption is very different. The former very high, the latter slightly lower, but the risks are equal. So on on the latter, so in our technology specifically, what we have been building over the last number of years, built on top of all of our open source and our capabilities after seven or eight years, is what we refer to as purpose-based access control. So, the thinking behind purpose-based access control is very simple. Role-based access control is how you govern most things. I.e. I have a department of people in finance, operations, and marketing, or technology in finance, operations, and marketing, and that system or technology or that user can have access to certain sets of data. The difficulty with that is obviously it’s too broad, it’s too permissive. So back to your point of data minimization, Jodi, everyone in finance might not have the same intent of how they use that data. Purpose-based access control sort of inverts it. Is that we know that you’re in the finance department, but what we’re interested in is in this specific request via AI or any other tool. What are you attempting to actually do? Like, what is your intent in this moment? And what we look at is the types of data you’re asking to use, your intent, the cross section of the regulations or the internal business conditions, commitments, and contracts, whatever those sort of boundary lines are at that moment, so on the wire in real time. So we think of that as a runtime governance rather than sort of abstract governance. And the goal there, therefore, is to say we will let AI run broadly on data, but it can only see the pieces of data for the current intent at that moment in time. Nothing more, nothing less, and we can audit that. So it allows us to minimize, in effect, while still still saying to an enterprise, we’re going to allow you to leverage the value of your data whilst minimizing the risk in each request. That is our goal. That’s how the tech works.
Jodi Daniels 32:11
Thank you for adding and sharing. I I think it’s just important to try and be able to connect that governance and the minimization privacy and how it all works. So thank you.
Justin Daniels 32:21
So Cillian, given all that you know about data, do you have a best personal privacy tip you’d like to share with the audience?
Cillian Kieran 32:28
Okay, I have to be careful, otherwise, I’ll sound like I live in a Faraday cage, like Gene Hackman in Enemy of the State, that movie. But anyway, you got the reference, Justin. I think hopefully.
Justin Daniels 32:40
No, I did. It’s just I know who didn’t, so I’m laughing.
Jodi Daniels 32:45
You should really. Anyway,
Cillian Kieran 32:45
I don’t. For reference and for the record of the podcast, I do not live in a Friday cage. I’m reasonably normal, Lord. I have any cats, but and no judgment. Like answering very honestly, like a personal both privacy and data management tip, I am very very sensitive to the use of not not just AI, but I think there’s a curious problem occurring right now for people, which is they will allow AI that they use in their personal lives or in their professional lives to connect two sources of data very quickly without thinking about the consequence. So they will permit, and I don’t want to vilify any particular AI, but they will permit an agent tool to access their inbox. They will permit it to access their drive of shared documents, or a database, or their CRM, whether it’s professional or personal. And I don’t think people understand that you are quite literally opening a fire hose of all of the data that you’ve potentially in your inbox for decades to an AI, and then you’re going to ask questions of it. I really don’t think people understand what they’re doing when they’re connecting those pipes together. So I don’t do it personally, other than very strict circumstances where I understand the guardrails that are in place, and and I try to avoid it at all costs anywhere. Now the result is actually I move more slowly than some people using AI, but I’m very confident that I’m not compromising the data that I have. Therefore, I think in the long term I will be moving faster and more safely, which is my goal.
Jodi Daniels 34:06
Excellent. And when you are not talking, breathing, and building all things AI data privacy, what do you like to do for fun?
Cillian Kieran 34:18
Well, when I’m not doing those things or hang out with my seven-year-old and nine-year-old, who are obviously everything to me. If I can carve out some time, I spend most of my time restoring old vintage motorcycles. So basically, software is wonderful. I love it, but it’s non tangible, right? You can work it for months and it’s still pretty sort of ephemeral and floaty. So there’s something lovely to like get your hands really greasy and oily, and work on an old, old motor, and I’m talking about something from the 70s or the 60s, and then bring it back to life. Like it actually starts, and you know, oil sputters out of it, and gas leaks onto the floor, and then you’ve accomplished something. So I do quite a lot of that, which is an unusual passion, but it keeps me very happy in New York.
Jodi Daniels 34:57
Ah, that’s wonderful. Well, we’re so glad. That you joined us here today. If people would like to connect with you and and potentially learn more about the product, where should they go?
Cillian Kieran 35:07
The best place to go is to ethyca.com, ethyca.com, or you can reach out to me directly on LinkedIn. I’m very very happy to answer questions and look forward to chatting to anyone.
Jodi Daniels 35:17
Lovely. Well, thank you again for joining. We really appreciate it.
Cillian Kieran 35:21
Pleasure. Thank you for having me.
Outro 35:26
Thanks for listening to the She Said Privacy/He Said Security podcast. If you haven’t already, be sure to click subscribe to get future episodes and check us out on LinkedIn. See you next time.
Privacy doesn’t have to be complicated.
As privacy experts passionate about trust, we help you define your goals and achieve them. We consider every factor of privacy that impacts your business so you can focus on what you do best.



