# Kate Carruthers > Navigating the future of business, technology, AI, and innovation Public Ghost content for AI and LLM tooling. This file includes a bounded export of public pages first, then recent public posts. Append `.md` to any post or page URL to get the content in Markdown (for example, `/example-post.md`). ## Pages ### About this site URL: https://katecarruthers.com/about-this-site/ Last updated: 2026-06-28T04:40:46.000Z This site is the personal and professional home of [Kate Carruthers](https://katecarruthers.com/kate-carruthers-bio), a leader in data, analytics, AI, and cybersecurity, featuring her writing on technology, risk, geopolitics, and society, along with information about her career, speaking, and online presence. [katecarruthers.com](https://katecarruthers.com/) is an independent publication launched in 2002 by Kate Carruthers. It has recently re-hosted on [Ghost](https://ghost.org/?ref=katecarruthers.com) from its old home on WordPress. If you subscribe today, you'll get full access to the website as well as email newsletters about new content when it's available. Thank you! ### Access all areas By signing up, you'll get access to the full archive of everything that's been published before and everything that's still to come. Your very own private library. ### Fresh content, delivered Stay up to date with new content sent straight to your inbox! No more worrying about whether you missed something because of a pesky algorithm or news feed. ### Meet people like you Join a community of other subscribers who share the same interests. ### ### Book me to Speak URL: https://katecarruthers.com/speaking/ Last updated: 2026-07-03T10:50:19.000Z [Kate Carruthers](https://katecarruthers.com/about/) provides a clear signal amidst the noise of AI and data, seamlessly connecting theory with practice in an engaging manner. [**Click here to book Kate**](mailto:helene@platinumspeakers.com.au?subject=Carruthers%20speaking%20inquiry) Insightful presentations. Actionable insights for your business. #### Creating the Future in the Age of AI We are entering a future shaped by algorithms, artificial intelligence (AI), machine learning, and data. Organisations are striving to manage intricate data sets and algorithms effectively. Kate has implemented AI solutions and offers practical insights into navigating this transition. #### Delivering Business Insights through AI and Data Data science and AI-driven analytics are ushering us into a realm where profound insights can generate new revenue streams and business opportunities. Kate provides real-world experience on delivering AI and data solutions safely and at scale. #### AI and Data Ethics As we advance into a future dominated by algorithms, AI, machine learning, and data, organisations grapple with the ethical challenges of managing complex data sets. Kate offers valuable insights on how to implement ethical AI practices. #### Privacy and Cyber Security in the Age of AI This topic explores the intersection of law, society, business, and technology concerning privacy and cyber security in the era of AI. #### Digital Transformation & Innovation This transformation is reshaping business operations and altering societal and consumer expectations. Kate combines her real-life experiences, along with her experience teaching at the Australian Graduate School of Management, with emerging trends to provide actionable insights. [**Click here to book Kate**](mailto:helene@platinumspeakers.com.au?subject=Carruthers%20speaking%20inquiry) ### Disclosures URL: https://katecarruthers.com/disclosures/ Last updated: 2026-04-10T21:44:44.000Z This is my personal website and blog, information presented here is of a general nature and represents my own independent opinion. Please seek advice for your specific circumstances. This site only contains my personal views, thoughts, and opinions. It is not endorsed by any employer or client, nor does it constitute any official communication by or for anyone else. Please check out the Rules of Engagement and Disclosures for this site. Inspired mostly by Chris Penn's [Disclosures](http://www.christopherspenn.com/disclosures/?ref=katecarruthers.com) page ([pursuant to US FTC regulations](http://www.whitneyhoffman.com/2009/10/06/the-new-ftc-guidelines-on-endorsements-by-bloggers/?ref=katecarruthers.com)) and partly by my friend [Bronwen](https://www.linkedin.com/in/bronwenclune/?originalSubdomain=au&ref=katecarruthers.com) (on Twitter when it was still a thing) I have put up this handy page so that it’s clear when I am writing on behalf of someone else. The views expressed on this site are mine and mine alone and in no way reflect the views of the any other organisation or employer, nor do they in any way reflect the work undertaken by me in any capacity as an employee or agent of any organisation. Since this is my personal site, I reserve the right to publish, amend or delete content at my own pleasure. There is more information on my approach on the [rules of engagement](https://katecarruthers.com/rules-of-engagement/) page. #### People Who Employ Me See [LinkedIn](http://au.linkedin.com/in/katecarruthers?ref=katecarruthers.com) #### People Who Sponsor Me Nobody at the moment (but feel free to get in contact) #### People Who Consult with Me Various clients consult with me from time to time. #### People Who Have Sent Me Unsolicited Free Stuff**f** From time-to-time folks send me unsolicited free stuff. Sometimes I will write about it in my blog and/or on Twitter. There is no guarantee that I will do this though. #### Statement on Unsolicited Items This is taken from [Christopher S Penn's blog](http://www.christopherspenn.com/?ref=katecarruthers.com) a long time ago and I can't put it any better (so you might as well know I agree with every single word below): > "You’re welcome to send them to me, but they’re not coming back. By sending me something to review, you understand that I may or may not review it, and I do not guarantee any outcome of the review. If your product sucks, I’m going to say so in no uncertain words. If it’s delivered electronically, I may never even see it due to spam filters. If it’s tangible, there’s a distinct chance it’ll get lost in my office somewhere and I won’t find it until months later, possibly after you’ve gone out of business. I’ll still review it and lament your passing if that’s the case. If I do review something, I will disclose it, no exceptions. If it’s great, I’ll tell people about it. If it’s terrible, likewise. If it’s mediocre, there’s a good chance it will make so little an impression that I’ll forget to review it entirely. Be awesome, okay?" > > C.S. Penn ### About URL: https://katecarruthers.com/about/ Last updated: 2026-06-29T02:13:18.000Z This site, [katecarruthers.com](https://katecarruthers.com/), is the professional and personal site of Kate Carruthers. It is also the home of her [Data Revolution](https://katecarruthers.com/podcast/) podcast. ## Kate Carruthers: Short biography [Kate Carruthers](https://www.linkedin.com/in/katecarruthers/?ref=katecarruthers.com) is a leader in data, analytics, AI, data governance, and cybersecurity, with a career spanning higher education, large enterprises, public sector, startups, and boardrooms. She has led major technology and business transformations, including building pioneering data and AI capabilities at UNSW Sydney and launching the Westfield Australia gift card business. ![](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/05/7R2A8377-1-1.jpg) Kate Carruthers Kate is currently working as the Head of Data, Analytics & AI at the Australian Institute of Company Directors (AICD) and serves as a board director and adviser, focusing on how data, technology, and AI can support sound governance and drive organisational performance. Kate also teaches short courses on [AI and innovation](https://www.unsw.edu.au/study/professional-development/course/ai-for-organisational-innovation?ref=katecarruthers.com) and [data governance](https://www.unsw.edu.au/study/professional-development/course/data-governance-for-leaders?ref=katecarruthers.com) at [AGSM](https://www.unsw.edu.au/business/our-schools/agsm?ref=katecarruthers.com). She also contributes to the broader community as a public speaker, adviser, and active supporter of professional bodies. She holds advanced degrees in management, education, terrorism & security studies, and is a PhD candidate at the University of Technology Sydney, where her research focuses on AI governance, innovation, and entrepreneurship. [Long biography here](https://katecarruthers.com/kate-carruthers-long-biography) ♥️ **I acknowledge and pay respect to the past, present and future Traditional Custodians and Elders of this nation and the continuation of cultural, spiritual and educational practices of Aboriginal and Torres Strait Islander peoples.* ### Kate Carruthers Long Biography URL: https://katecarruthers.com/kate-carruthers-long-biography/ Last updated: 2026-07-03T10:48:10.000Z [*You can find Kate's short biography here*](https://katecarruthers.com/about-kate-carruthers/) ### Overview Kate Carruthers is a distinguished leader in data analytics, AI, data governance, and cyber security with extensive experience across higher education, large enterprises, startups, and boards. Her career highlights include establishing innovative data governance, AI, and business intelligence functions at UNSW Sydney and the successful launch of the Westfield Australia gift card business. Kate has extensive experience in senior executive roles, working for diverse organisations such as Citibank, General Electric, AMP, Westfield (now Scentre Group), Metcash, Genea, and NSW Treasury. She has extensive experience in the successful delivery of digital transformation, data, ICT, and change projects across organisations of diverse sizes. Previously Kate lectured in postgraduate information systems and accounting at Macquarie University. She also delivered TAFE level courses in business and management in the NSW Department of Finance, Services and Innovation. Kate is currently working with the Australian Institute of Company Directors (AICD) as the Head of Data, Analytics & AI. Previously she led the data function as Chief Data & Insights Officer at [UNSW Sydney](https://planning.unsw.edu.au/?ref=katecarruthers.com) for many years, and she delivered UNSW’s first enterprise AI system into production in 2019 and in 2022 led the re-architecture of the cloud data platform to support AI and ML, BI and analytics, and low code applications from a single set of data pipelines. She also served as the Head of Business Intelligence for the [UNSW AI](https://unsw.ai/?ref=katecarruthers.com) Institute and served on the inaugural management board, and was an Adjunct Senior Lecturer in the [School of Computer Science & Engineering](https://www.cse.unsw.edu.au/?ref=katecarruthers.com) at UNSW Sydney. Kate was a foundation member of the NSW Government [Data Analytics Centre](https://data.nsw.gov.au/nsw-data-analytics-centre?ref=katecarruthers.com) Advisory Board and was a member of the [Microsoft Regional Director](https://rd.microsoft.com/en-us/about/?ref=katecarruthers.com)\* program for cybersecurity. ### Education Kate was certified in information security, was awarded a Graduate Diploma in Terrorism and Security Studies (Charles Sturt University), a Master of Tertiary Education Management (University of Melbourne), and a Master of Management (Macquarie University). She is currently a PhD candidate at UTS researching AI governance and entrepreneurship. ### Startups & advocacy She is co-founder of several startups, Internet of Things (IoT) startups (Moorescloud with [Mark Pesce](https://en.wikipedia.org/wiki/Mark%5FPesce?ref=katecarruthers.com), and [IoTM](https://web.archive.org/web/20180311012347/http:/iotm.com.au/)) and is currently an adviser to several startups. Kate was also co-founder of [Social Innovation Sydney](https://katecarruthers.com/content/files/2026/03/socialinnovationsydney-wordpress-com.html) (with [Selena Griffith](https://selenagriffith.com/?ref=katecarruthers.com)) a group that helped change makers connect with one another and built-up networks to drive social innovation in Australia. She is currently serving as a director of Carruthers Consulting Pty Ltd and was on the board of directors for a blockchain startup called [Amaroo](https://amaroo.com/?ref=katecarruthers.com) and is an adviser to [Sovereign Australia AI](https://sovereign-au.ai/?ref=katecarruthers.com). Kate has always been a strong advocate for women in STEM, having previously served on the management committee of [Females in Information Technology and Telecommunications (FitT)](https://www.fitt.org.au/?ref=katecarruthers.com), and has been a mentor for young women in technology and engineering for many years. ### Podcast In 2023 she started the [Data Revolution](https://datarevolution.tech/?ref=katecarruthers.com) podcast. The Data Revolution podcast is about exploring the intersections between business intelligence, data analytics, AI, privacy, data protection, cyber and information security. In 2025 she started a podcast called [Making Sense of Politics](https://makingsenseofpolitics.com/?ref=katecarruthers.com) with her old friend [Nancy Georges](https://magnoliasolutions.com.au/?ref=katecarruthers.com) \- it is just two women trying to get their heads around the political landscape. ### Memberships & Boards Kate is: - a member of the [Australian Information Security Association](https://www.aisa.org.au/?ref=katecarruthers.com) (AISA) - a member of the [Australian Women in Security Network](https://www.awsn.org.au/?ref=katecarruthers.com) - a member of the [Royal Society of New South Wales](https://www.royalsoc.org.au/?ref=katecarruthers.com) She has previously served as: - a foundation member of the management board for the [UNSW AI Research Institute](https://www.unsw.edu.au/unsw-ai?ref=katecarruthers.com) - a foundation member of the [NSW Data Analytics Centre](https://data.nsw.gov.au/about-us?ref=katecarruthers.com) advisory board - a member of the Advisory Board for the Faculty of Informatics at the [University of Wollongong](http://www.uow.edu.au/?ref=katecarruthers.com) for several years before joining [UNSW ](http://eng.unsw.edu.au/?ref=katecarruthers.com)Sydney - a member of the Telstra Industry Advisory Board - a Fellow of the [Governance Institute of Australia](https://www.governanceinstitute.com.au/?ref=katecarruthers.com) - a board member for: - Amaroo Pty Ltd - Info Sphere Education Pty Ltd - Creation Nation Pty Ltd - Moorescloud Pty Ltd ### Awards and recognition In 2014 Kate was named as one of [Australia’s most powerful women in technology](https://www.smartcompany.com.au/people-human-resources/australia-s-most-powerful-women-in-technology/?ref=katecarruthers.com) by Smart Company magazine. She was named among the 2021 [Constellation Research Business Transformation 150](https://www.constellationr.com/business-transformation-150/2021?ref=katecarruthers.com) (BT150), which is an elite list that recognises the top global executives leading business transformation efforts in their organisations. Kate was also named on the: - [30 Outstanding Women in Data 2026](https://dataleum.com/owdai/?ref=katecarruthers.com) - [2024 Global Top 100 Innovators in Data and Analytics](https://www.coriniumintelligence.com/top-100-innovators-2024?ref=katecarruthers.com) - [Global Data Power Women List 2024](https://lp.cdomagazine.tech/2024/global-data-power-women?ref=katecarruthers.com) - [Global Data Power Women List 2023](https://katecarruthers6748.live-website.com/2023/06/05/global-data-power-women-list-2023/?ref=katecarruthers.com) - [Top Academic Data Leaders](https://katecarruthers6748.live-website.com/2022/02/07/academic-data-leaders-2022/?ref=katecarruthers.com) for 2022 - [2022 Global Top 100 Innovators in Data & Analytics](https://business-of-data.com/2022-top-100-leaders-in-data-analytics/?ref=katecarruthers.com) - [CDO Magazine 2021 List of Academic Data Leaders](https://katecarruthers6748.live-website.com/2021/01/19/2021-academic-data-leaders/?ref=katecarruthers.com). - [Global Top 100 Data Visionaries – 2020](https://katecarruthers6748.live-website.com/2020/06/24/global-top-100-data-visionaries-2020/?ref=katecarruthers.com) - [2020 List of Global Data Power Women](https://katecarruthers6748.live-website.com/2020/07/20/cdo-magazine-announces-its-2020-list-of-global-data-power-women/?ref=katecarruthers.com) - [2020 Business of Data Top 100 Innovators](https://katecarruthers6748.live-website.com/2020/09/08/nominated-corinium-2020-business-of-data-top-100-innovators-in-data-and-analytics/?ref=katecarruthers.com) in Data and Analytics In 2023 she was awarded a [Lifetime Achievement Award ](https://www.bandt.com.au/lets-hear-it-for-2023s-women-leading-tech-awards-winners/?ref=katecarruthers.com)by B&T at the Women Leading Tech awards. Over the past few years Kate has been working on the front lines of the intersection between data analytics, AI, ML, privacy, data protection, cyber and information security. [*You can find Kate's short biography here*](https://katecarruthers.com/about/) ### Rules of Engagement URL: https://katecarruthers.com/rules-of-engagement/ Last updated: 2026-04-11T05:50:24.000Z #### About this site This is my personal site and I write it for my own personal satisfaction. Readers are encouraged to comment, debate and discuss. I moderate all comments and publish most, unless they appear (to my totally subjective gaze) to be defamatory, spammy, hate-mongering, not particularly constructive, or just plain rude/crude. It's fine to disagree with me, but I'm unlikely to publish your comment unless you display a modicum of style and intelligence. For example if your comment is just swearing and being unimaginative it's probably not going to be published. Also if you do not provide a real name/identity/email I may choose not to publish your comments. Real people who stand by their comments are cool! This site discusses ideas but does not purport to provide formal business, technology, psychology or finance advice. Readers should seek (and probably pay for) advice of that nature from a professional source. If you want to retain my professional services there is more information on [katecarruthers.com](https://katecarruthers.com/). The content on this website is provided "as is" with no warranties, and confers no rights. The opinions expressed here are my own and do not represent views of any clients or employers in any way. Nothing posted here should be considered official or sanctioned by any of my clients or employers or any organisation with which I am affiliated. #### Use of material from this site Feel free to quote liberally from this site if you want - and please link back in the best web tradition if you use any material provided here and give credit for material used. #### Use of material on this site Often I use material from other sources in this site. I try to note the provenance of the material and give appropriate credit. If you think there is any error in fact or attribution please let me know. There is every chance that I will quote from or publish in their entirety other communication sources, like letters, email or skeets/toots/tweets, stuff that you've shared with me. ### Video and Audio URL: https://katecarruthers.com/videos-2/ Last updated: 2017-08-14T03:17:33.000Z [https://vimeo.com/690235210/c1e6bdc0a5](https://vimeo.com/690235210/c1e6bdc0a5?ref=katecarruthers.com) [Champions of Data + AI: Data leaders powering data-driven innovation EPISODE 4: How Education Rewrote the Book on Virtual Learning](https://www.databricks.com/discover/champions-of-data-and-ai/s1-e4-how-education-rewrote-the-book-on-virtual-learning?ref=katecarruthers.com) [Ethical use of student data](https://thebox.unsw.edu.au/7A338FD0-D00A-11E8-8CFC6A07029C61E8?ref=katecarruthers.com) \- panel debate @ The UNSW Inspired Learning Summit, October 2018 ALIA conference 2021, Artificial intelligence: Challenging the nature of custodianship of information [![Ethical use of student data - panel debate @ The UNSW Inspired Learning Summit 2018](https://katecarrutherscom.files.wordpress.com/2018/10/screen-shot-2018-10-31-at-11-40-10.png)](https://thebox.unsw.edu.au/7A338FD0-D00A-11E8-8CFC6A07029C61E8?ref=katecarruthers.com) **Panel**: [Prof Geoffrey Crisp](https://www.unsw.edu.au/about-us/governance/other-senior-officers/pro-vice-chancellor-education?ref=katecarruthers.com) Pro Vice Chancellor Education, UNSW Sydney; [Kate Carruthers ](https://www.linkedin.com/in/katecarruthers/?ref=katecarruthers.com)Chief Data & Analytics Officer, UNSW Planning & Performance, UNSW Sydney; [Richard Sanchez](https://www.linkedin.com/in/richard-sanchez-5164bb47/?ref=katecarruthers.com) Head, Student Reporting & Analytics, UNSW Sydney; [A/Prof. Wayne Wobcke](http://www.cse.unsw.edu.au/~wobcke/ShortBiography.html?ref=katecarruthers.com) Academic in Computing Science and Artificial Intelligence with relevant interest and expertise, UNSW Sydney; [A/Prof. Louise Lutze-Mann](https://www.babs.unsw.edu.au/staff%5Facademic/associate-professor-louise-lutze-mann?ref=katecarruthers.com) Director of Education-focussed Career Development, Deputy Head of School and Director of Teaching BABS, Inaugural UNSW Scientia Education Fellow; [Peter Leonard](https://www.linkedin.com/in/peleonard/?originalSubdomain=au&ref=katecarruthers.com) Principal at Data Synergies, WS Chair, Data Access, Use and Privacy at IoTAA, Consultant, Gilbert + Tobin; [Prof. Louisa Jorm ](https://cbdrh.med.unsw.edu.au/people/professor-louisa-jorm?ref=katecarruthers.com)Director of the Centre for Big Data Research in Health, UNSW Sydney; [Jay Zabakly](https://www.linkedin.com/in/jason-zabakly-1b3a75115?ref=katecarruthers.com) Vice President of Human Resources - UNSW Education Society, Survey reference group; advocacy work, UNSW Sydney; [Tara Sutjarittham](https://www.linkedin.com/in/tarasutjarittham/?ref=katecarruthers.com) PhD Candidate - Data architecture, Internet of Things, sensor data analytics, applied machine learning, UNSW Sydney --- **Digital Ethics for the Future - S. Wilson, Dr. Bray, J. Taschek, R "Ray" Wang, K. Carruthers, 2016** --- \[vimeo 194893184 w=640 h=360\] **[Executive Exchange - Data For Public Good](https://vimeo.com/194893184?ref=katecarruthers.com) 2016 from [Constellation Research](https://vimeo.com/constellationresearch?ref=katecarruthers.com) on [Vimeo](https://vimeo.com/?ref=katecarruthers.com).** --- **What You need To Know About Strategic Content Marketing, 2015** **Facebook: On Sunday Extra with Jonathan Green, Broadcast: Sun 27 May 2012, 8:40am. Our panel today examines the float of Facebook, online advertising and the difficulties inherent in commercialising social media websites.** Panel members: - [Kate Carruthers](https://www.abc.net.au/radionational/kate-carruthers/4031038?ref=katecarruthers.com) – Technology and marketing commentator - [Suzanne Tindal](https://www.abc.net.au/radionational/suzanne-tindal/4031058?ref=katecarruthers.com) – News Editor, ZDNet.com.au - [Mathew Ingram](https://www.abc.net.au/radionational/mathem-ingram/4035762?ref=katecarruthers.com) – Senior writer at GigaOm.com Kate Carruthers on Sky News **Online Reputation Management, with Antony Funnell on Future Tense, Broadcast: Thu 5 May 2011, 8:30am** It's called ORM—Online Reputation Management—and as the boundaries between the digital and the real world become more blurred, a growing number of companies are now offering to help you protect and preserve your reputation. ##### Guests [Kate Carruthers](https://www.abc.net.au/radionational/programs/futuretense/kate-carruthers/2953102?ref=katecarruthers.com) \- Sydney based digital strategist. [Neerav Bhatt](https://www.abc.net.au/radionational/programs/futuretense/neerav-bhatt/2953104?ref=katecarruthers.com) \- Freelance IT Journalist and blogger. [Stephen Collins](https://www.abc.net.au/radionational/programs/futuretense/stephen-collins/2953106?ref=katecarruthers.com) \- Board member for Electronic Frontiers Australia. [Peter Black](https://www.abc.net.au/radionational/programs/futuretense/peter-black/2953108?ref=katecarruthers.com) \- Senior Law Lecturer at the Queensland University of Technology. [Dr Rob Sparrow](https://www.abc.net.au/radionational/programs/futuretense/dr-rob-sparrow/2953110?ref=katecarruthers.com) \- ARC Future Fellow and Senior Lecturer, Monash University. [David Cannell](https://www.abc.net.au/radionational/programs/futuretense/david-cannell/2953112?ref=katecarruthers.com) \- Founder of Online Reputation Management Sydney. --- **Getting it Wrong? The Y2K bug revisited: with Antony Funnell on Future Tense, 14 October 2010** In the second installment of our irregular series 'Getting it Wrong?' we go back to the end of the last millenium and examine the Y2K bug predictions. All hype? Or was there really something in it? ##### Guests: [Paul Wallbank](https://www.abc.net.au/radionational/programs/futuretense/paul-wallbank/2981496?ref=katecarruthers.com) \- Broadcaster, writer and speaker [Professor John Quiggin](https://www.abc.net.au/radionational/programs/futuretense/professor-john-quiggin/2981500?ref=katecarruthers.com) \- Australian Research Council Fellow in Economics and Political Science, University of Queensland [Kate Carruthers](https://www.abc.net.au/radionational/programs/futuretense/kate-carruthers/2981502?ref=katecarruthers.com) \- Senior social business consultant, Headshift Australasia ### Privacy Policy URL: https://katecarruthers.com/privacy-policy/ Last updated: 2026-08-13T09:24:51.000Z **Last Updated:** 13 August 2026 ### Overview This website, associated content, and services at [katecarruthers.com](https://katecarruthers.com/) are operated by **Carruthers Consulting Pty Ltd** (“we”, “us” or “our”). The website is a digital media platform providing blog content, podcasts, video media, events, newsletters, and selected membership content. We are committed to protecting the privacy of subscribers, members, event registrants, listeners, guests, contributors, and website visitors in accordance with the Australian Privacy Principles contained in the *Privacy Act 1988* (Cth). ### Information We Collect We collect only the personal information reasonably necessary to provide our content, administer memberships and events, communicate with our community, and operate the website. - **Subscriber and member data:** When you subscribe to our newsletter or create a membership account, we may collect your name and email address through Ghost CMS. Some membership subscriptions may provide Carruthers Consulting Pty Ltd with limited personal information needed to administer that subscription and provide access to member-only content. - **Event registration data:** When you register for an event, webinar, workshop, speaking engagement, or similar activity, we may collect limited information such as your name, email address, organisation, role, attendance preferences, and any other information you choose to provide in the registration form. We use this information to manage registrations, communicate event details, and follow up about the relevant event. - **Engagement data:** If you leave a comment on an article, we may collect the comment, your IP address, and browser user-agent information to help detect spam and maintain site security. - **Guest and contributor data:** If you appear as a podcast guest or contribute a guest post, we may collect your professional biography, social-media handles, profile image, and voice or video recordings, as agreed with you. - **Technical data:** We may use cookies, analytics tools, and tracking pixels to understand how visitors use the website and engage with newsletters. ### How We Use Your Information We use personal information to: - Deliver newsletters, podcast show notes, blog updates, member content, and community announcements. - Create and manage membership accounts and subscriptions. - Process and administer event registrations, send event communications, and manage attendance. - Edit, publish, and promote podcast episodes and other content featuring guests or contributors. - Analyse de-identified and aggregated information to understand audience interests and improve our content. - Detect and prevent fraudulent sign-ups, spam, security incidents, and malicious comments. - Meet legal, regulatory, and administrative obligations. ### Ghost and Other Providers Our website is powered by Ghost CMS, which manages member and subscriber information and distributes newsletters. If paid subscriptions are offered, payment processing is handled by Stripe or another nominated payment provider. Carruthers Consulting Pty Ltd does not store your full credit-card details on its own servers. Articles and pages may contain embedded content, such as YouTube videos or Spotify players. If you interact with embedded content, the relevant third party may collect information about you under its own privacy policy. ### Disclosure and Overseas Transfers We do not sell personal information. However, providers we use - including Ghost, payment processors, email-delivery services, analytics providers, and podcast-hosting platforms - may process or store information outside Australia, including in the United States and other jurisdictions. Where personal information is transferred overseas, we take reasonable steps to use reputable providers and protect the information in a manner consistent with applicable privacy obligations. ### Data Retention - **Subscribers and members:** We retain account and subscription information while your subscription or membership remains active. If you unsubscribe, we may retain minimal information necessary to record your preference not to receive further communications and to meet legal or administrative obligations. - **Event registrants:** We retain registration information for as long as reasonably necessary to administer the event, manage related communications, maintain appropriate records, and meet legal or administrative requirements. - **Comments:** Comments and associated metadata may be retained indefinitely to support moderation and recognition of follow-up comments. - **Guest media:** Podcast recordings, videos, and associated public posts are generally intended to remain part of the permanent public archive, subject to any separate agreement with the guest or contributor. ### Your Rights Subject to applicable law, you may: - Request access to personal information we hold about you. - Ask us to correct inaccurate, incomplete, or out-of-date information. - Request deletion of your membership account, subscription information, or comments, subject to legal and administrative requirements. - Unsubscribe from newsletter communications at any time by selecting the “Unsubscribe” link in an email we send. - Contact us with concerns about how we handle your personal information. ### Contact Us For privacy questions, requests to access or correct personal information, or complaints, contact the Privacy Officer at: **Carruthers Consulting Pty Ltd** Email: hello@katecarruthers.com If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner. ### Podcast URL: https://katecarruthers.com/podcast/ Last updated: 2026-06-26T05:54:04.000Z ### Unlock the future with the Data Revolution Podcast. AI, data, and cybersecurity are some of the fastest-growing and most influential domains today. Whether you’re a business leader, a tech professional, or simply curious, understanding their impact has never been more important. Join me as I break down key concepts, share real-world examples, and help you make sense of this rapidly changing landscape. Tune in to stay informed, confident, and engaged with the shifts reshaping our world. 💡 Tune in via [audio](https://creators.spotify.com/pod/profile/kate-carruthers4/?ref=katecarruthers.com) or [video](https://m.youtube.com/channel/UCoalzVK6dwrHksdMHB5tVvA?ref=katecarruthers.com) and deepen your understanding of our data-driven world. ## Meet your guide to the Data Revolution With a long-standing career in technology, I’ve spent much of my professional life working with data. Over the past decade, I’ve focused on turning raw data into meaningful business insights, including the use of AI, while upholding the highest standards of data protection and security. ![](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/05/7R2A8377-1.jpg) Kate Carruthers Through the Data Revolution podcast, I explore the critical intersections of data, AI, privacy, and cybersecurity, sharing practical insights and strategies to help you navigate an ever-evolving landscape. Join me as we unpack the power of data and its impact on businesses and society in a clear, down-to-earth way. My aim is to make each episode engaging, practical, and genuinely useful. 💡 Tune in via [audio](https://creators.spotify.com/pod/profile/kate-carruthers4/?ref=katecarruthers.com) or [video](https://m.youtube.com/channel/UCoalzVK6dwrHksdMHB5tVvA?ref=katecarruthers.com) and deepen your understanding of our data-driven world. ### Disclosures URL: https://katecarruthers.com/disclosures-2/ Last updated: 2026-05-18T08:15:24.000Z Inspired mostly by Chris Penn’s [Disclosures](http://www.christopherspenn.com/disclosures/?ref=katecarruthers.com) page ([pursuant to US FTC regulations](http://www.whitneyhoffman.com/2009/10/06/the-new-ftc-guidelines-on-endorsements-by-bloggers/?ref=katecarruthers.com)) and partly by my friend [Bronwen](http://twitter.com/bronwen?ref=katecarruthers.com) I’ve put up this handy page so that it’s clear when I’m writing on behalf of someone else. ### General Statement The views expressed on this site are mine and mine alone and in no way reflect the views of the any other organisation or employer, or affiliated organisation, nor do they in any way reflect the work undertaken by me in any capacity as an employee or agent of any organisation. Since this is my personal site, I reserve the right to publish, amend or delete content at my own pleasure. There is more information on my approach on the [rules of engagement](https://katecarruthers.com/rules-of-engagement/) page. ### People Who Employ Me See [LinkedIn](http://au.linkedin.com/in/katecarruthers?ref=katecarruthers.com) ### People Who Sponsor Me Nobody at the moment (but feel free to [get in contact](mailto:carruthk@ieee.org?Subject=Sponsorship)) ### People Who Consult with Me Various clients consult with me from time to time. ### People Who Have Sent Me Unsolicited Free Stuff From time-to-time folks send me unsolicited free stuff. Sometimes I will write about it online and/or on social media. There is no guarantee that I will do this though. #### Statement on Unsolicited Items This was taken from [Christopher S Penn’s blog](http://www.christopherspenn.com/?ref=katecarruthers.com) a long time ago and I can’t put it any better so you might as well know I agree with every single word below: > “You’re welcome to send them to me, but they’re not coming back. > > By sending me something to review, you understand that I may or may not review it, and I do not guarantee any outcome of the review. > > If your product sucks, I’m going to say so in no uncertain words. > > If it’s delivered electronically, I may never even see it due to spam filters. > > If it’s tangible, there’s a distinct chance it’ll get lost in my office somewhere and I won’t find it until months later, possibly after you’ve gone out of business. I’ll still review it and lament your passing if that’s the case. > > If I do review something, I will disclose it, no exceptions. > > If it’s great, I’ll tell people about it. > If it’s terrible, likewise. > If it’s mediocre, there’s a good chance it will make so little an impression that I’ll forget to review it entirely. > > Be awesome, okay?” ### Rules of engagement URL: https://katecarruthers.com/rules-of-engagement-2/ Last updated: 2026-05-18T08:18:16.000Z ### About this site This is my personal site and I write and create other video and audio content for my own personal satisfaction. Readers are encouraged to comment, debate and discuss. I moderate all comments and publish most, unless they appear (to my totally subjective gaze) to be defamatory, spammy, hate-mongering, not particularly constructive, or just plain rude/crude. It’s fine to disagree with me, but I’m unlikely to publish your comment unless you display a modicum of style and intelligence. For example if your comment is just swearing and being unimaginative it’s probably not going to be published. Also if you do not provide a real name/identity/email I may choose not to publish your comments. Real people who stand by their comments are cool! This site discusses ideas but does not purport to provide formal business, technology, psychology or finance advice. Readers should seek (and probably pay for) advice of that nature from a professional source. If you want to retain my professional services, there is more information on [katecarruthers.com](http://www.katecarruthers.com/?ref=katecarruthers.com). The content on this website is provided “as is” with no warranties and confers no rights. The opinions expressed here are my own and do not represent views of any clients, employers, or affiliated organisations in any way. Nothing posted here should be considered official or sanctioned by any of my clients, employers or any organisation with which I am affiliated. ### Use of material from this site Feel free to quote liberally from this site if you want - please link back in the best web tradition if you use any material provided here and give credit for material used. ### Use of material in this site Often, I use material from other sources on this site. I try to note the provenance of the material and give appropriate credit. If you think there is any error in fact or attribution please let me know. There is every chance that I will quote from or publish in their entirety other communication sources, like letters, email (or tweets, toots, skeets, etc.), i.e., stuff that you’ve shared with me (unless of course you have advised in advance that it has been shared in confidence). ### Information for guests URL: https://katecarruthers.com/information-for-guests/ Last updated: 2026-05-18T08:18:26.000Z Thank you so much for agreeing to join me on the Data Revolution podcast. Here are some things you may like to know. 1. This is an informal podcast (and it really does not have high production values 🤣). It is meant to be a friendly chat. The concept is for us to discuss interesting ideas related to data. It is a two-way conversation and hopefully we will spark off each other and have a good discussion. 2. You are a guest on the podcast because you know stuff, so feel free to share your knowledge and voice your opinions. 3. We are civilised humans on this podcast and we can disagree, but we won't be rude about it if we do. 4. We will record for approximately 30 minutes, and will record video and audio. Once we start recording we will keep going (unless something catastrophic happens). But we are not going to stop unless it is to briefly admire kids, partners or pets. 5. The conversation can go wherever you want. Please mention any topics you do not wish to cover beforehand or just tell me if anything comes up that you do not wish to cover. 6. I am assuming that you have any necessary clearance from your corporate comms folks to do this podcast. 7. What will happen. Once the recording is done, I will also prepare a post, possibly the platforms will generate an AI transcript, and make it live. I will let you know when it will go live. When it is live I will also post links to various social media platforms. 8. You are welcome to use the transcript and grab the recording to post on your site, please just link back to the relevant post on [https://datarevolution.tech/](https://katecarruthers.com/). ### Thanks! URL: https://katecarruthers.com/thanks/ Last updated: 2026-05-15T05:13:04.000Z Thank you for subscribing to the Data Revolution Newsletter. Please check out the [website](https://katecarruthers.com/) and previous episodes. ## Posts ### Beware offshoring dressed up as AI innovation and transformation URL: https://katecarruthers.com/beware-offshoring-dressed-up-as-ai-innovation-and-transformation/ Last updated: 2026-08-25T02:12:32.000Z I have spent enough time around technology strategy to know that the language organisations use can tell you a lot about what is really going on. When leaders start talking about “AI-enabled transformation”, “future-ready operating models”, “operational excellence”, and “global delivery”, my ears prick up. Sometimes those phrases describe genuine change. Sometimes they are a glossy wrapper around a much older story about cost cutting, outsourcing, and moving work to lower-cost jurisdictions. That does not mean the technology is fake. It does not mean there is no modernisation happening. But it does mean we should be much more careful about accepting transformation rhetoric at face value. I think this matters because words shape accountability. If a board, workforce, or customer is told that a major restructuring is about AI innovation, they are likely to assess it differently than if they were told plainly that it is also an offshoring or outsourcing program. ## The Allianz example The recent [iTnews report on Allianz Technology](https://www.itnews.com.au/news/allianz-tech-transformation-exposed-as-offshoring-drive-628291?ref=katecarruthers.com) is a good example of why I am wary. Allianz’s global *Speed2Value* initiative was presented in the language of innovation and operational excellence, but material examined in an Australian unfair-dismissal matter described it as a program to move work from high-cost jurisdictions into offshore or outsourced delivery models. According to the report, Allianz Technology Australia’s direct employee headcount fell from 515 in March 2023 to 329 in March 2026\. In the specific Fair Work Commission matter, work previously performed by an analyst programmer was transferred to India-based HCLTech, even though the redundancy was found to be genuine in the legal sense. None of this means Allianz is unique. Many organisations have used offshore and outsourced technology models for years. The issue for me is not that offshoring exists. The issue is whether leaders are being honest about what kind of change is actually underway. If the main business effect is lower labour cost through offshore delivery, then that should be said clearly. If AI is genuinely changing workflows, improving decision-making, or removing repetitive work, that should be evidenced separately. Rolling all of that together under the banner of “transformation” can make a very old management play look like a breakthrough. ## Why this keeps happening Generative AI has made this easier because it gives executives a very convenient storyline. AI is real. It is changing work. It is changing how organisations think about service delivery, content production, software development, and knowledge work. But that broad truth can also be used to blur the specifics. A local team can be reduced, some tasks can be shifted to a vendor in a lower-cost country, a few AI tools can be added to the workflow, and suddenly the whole exercise is presented as an AI transformation. That may be partially true, but it is often not the full truth. I think boards need to become much more disciplined here. They should be asking a few very plain questions: - Which tasks have actually been automated, and what evidence shows that? - Which tasks are still being done by people, but by a different workforce or vendor? - How much of the projected saving comes from automation, and how much comes from labour arbitrage? - What local capability is being lost in engineering, architecture, cyber security, product knowledge, and incident response? - Who remains accountable when an AI system, an offshore provider, and a local business team each own part of the process? Those are not abstract governance questions. They go directly to resilience, service quality, and organisational memory. ## Other versions of the same story This pattern is not limited to classic offshoring. Sometimes the language of AI efficiency is used to justify workforce changes, only for organisations to discover that the human work did not disappear at all. [Klarna](https://fortune.com/2025/05/09/klarna-ai-humans-return-on-investment/?ref=katecarruthers.com) is one of the clearest examples. The company became famous for claiming that its AI customer service assistant was doing the work of hundreds of agents. Later reporting showed that Klarna resumed hiring for customer support after its chief executive acknowledged that an excessive focus on cost had reduced quality, with the company looking at more flexible and freelance-style staffing arrangements. The work was still there. The labour model had changed. [Duolingo](https://www.theregister.com/software/2025/04/29/duolingo-ditches-more-contractors-in-ai-first-refocus/646340?ref=katecarruthers.com) is another example worth noting. Reporting on its “AI-first” strategy said the company planned to phase out contractors where AI could do the work and expected teams to justify why a role could not be automated before asking for more headcount. At least that is direct. It tells staff and the market that workforce redesign is part of the strategy, rather than pretending the only story is product innovation. **I keep coming back to the same point: not every AI job story is really an AI story. Sometimes it is a contractor story. Sometimes it is a vendor story. Sometimes it is an offshoring story. Sometimes it is all three.** ## The capability question This is where the Australian angle matters. When organisations reduce local technology capability, they are not just removing cost. They may also be removing context, institutional memory, and the practical ability to govern complex systems. That matters even more with AI. Safe deployment is not just about buying a model or subscribing to a service. It requires people who understand the business process, the data, the regulatory environment, the security risks, and the real-world consequences when something goes wrong. An offshore team can absolutely contribute to that work. I am not interested in simplistic arguments that treat local as automatically good and offshore as automatically bad. But I do think organisations need to be honest about whether they are retaining enough accountable in-house capability to challenge vendors, respond to incidents, and govern AI-enabled systems properly. For Australia, this also connects to sovereignty. I have written before about sovereignty in the context of AI, data, and infrastructure. To me, sovereignty is not autarky. It is having meaningful choices, retaining critical capability, and avoiding a position where strategic dependence is mistaken for efficiency. ## Call things what they are I am not opposed to AI. I am not opposed to modernisation. I am not even opposed, in principle, to outsourcing or offshoring. There are times when each of those can make sense. What I object to is managerial euphemism. **If work is being moved offshore, call it offshoring. If it is being handed to a vendor, call it outsourcing. If a task is genuinely being automated, show how and where that automation works. And if all three are happening at once, then boards, workers, and customers deserve a clear explanation of the mix.** Transformation should mean more than a new slide deck, a consulting narrative, or an AI label attached to an old cost-out playbook. It should mean the organisation is actually improving how it creates value, serves customers, manages risk, and retains the capability needed to govern its own future. Anything less is not transformation. It is rebranding. ### AI models are not interchangeable infrastructure URL: https://katecarruthers.com/ai-models-are-not-interchangeable-infrastructure/ Last updated: 2026-08-23T21:28:42.000Z Most organisations still procure AI models as if they are interchangeable infrastructure: compare capability, connect an API, write a policy and move on. But a model does more than retrieve information or draft text. It decides when to reassure, when to challenge, how much uncertainty to disclose, and whether to make a risk visible at all. That matters because the model is now inside the work. It is answering customer questions, shaping employee decisions, drafting policies, triaging security issues, interpreting internal knowledge and increasingly sitting beside people making consequential calls. I see this gap most clearly in procurement conversations. The questions are usually about capability, cost, context windows, integration and security. They should be. But they are rarely about the model’s behavioural profile: how it handles uncertainty, when it pushes back, what it treats as a risk and whether those behaviours shift across languages. [Anthropic’s recent work on Claude](https://www.anthropic.com/research/claude-values-models-languages?ref=katecarruthers.com) gives us a useful way to see the problem. It found that the values expressed by Claude vary across both models and languages, along four dimensions: deference versus caution, warmth versus rigor, depth versus brevity, and candor versus execution. That does not mean one model is good and another is bad. It means a model choice is also a choice about judgement and communication. ## The model is in the work A warm model may make an employee feel supported. It may also be too willing to affirm an assumption that should have been challenged. A cautious model may surface risks earlier. It may also add friction to a workflow where speed matters. A concise model may be useful in a busy operations team. A more candid and detailed model may be better suited to legal review, incident response or executive decision support. The question is not which style is nicer. It is whether the model is too agreeable, too confident, too brief or too cautious for the work you are asking it to do. This is organisational influence. It belongs inside governance, procurement and change control. ## When helpful becomes harmful OpenAI’s experience with GPT-4o makes the risk of excessive agreeableness very clear. In April 2025, OpenAI rolled out an update to GPT-4o that made the model noticeably more flattering and agreeable. The [company later described the behaviour as sycophantic](https://openai.com/index/sycophancy-in-gpt-4o/?ref=katecarruthers.com): overly supportive responses that could be insincere, misleading or simply wrong. OpenAI rolled back the update after concluding it had placed too much weight on short-term user feedback and had not adequately accounted for how users would experience the change over time. This is not a trivial issue of chatbot personality. A system that optimises for affirmation can validate poor judgement, reinforce a risky decision, reward an employee’s existing bias or make a customer feel falsely reassured. In high-stakes settings, a model that is too eager to please can become a model that fails to challenge. [OpenAI itself identified risks](https://openai.com/index/expanding-on-sycophancy/?ref=katecarruthers.com) associated with this kind of behaviour, including emotional over-reliance, mental-health concerns and the potential reinforcement of risky behaviour. For business, the lesson is broader. An AI assistant that consistently agrees may appear useful in a demonstration and score well in immediate user satisfaction. Over time, however, it can erode the very function organisations need from AI in complex work: the ability to identify uncertainty, surface weak reasoning and prompt people to pause before acting. **The model does not need to be hostile to be useful. But it does need to be able to disagree.** ## Grok shows the control problem The recent history of xAI’s Grok makes this less abstract. In May 2025, Grok began introducing claims about “[white genocide](https://techcrunch.com/2025/05/15/xai-blames-groks-obsession-with-white-genocide-on-an-unauthorized-modification/?ref=katecarruthers.com)” in South Africa into unrelated responses. xAI attributed the behaviour to an [unauthorised modification to the system prompt](https://www.theverge.com/news/668220/grok-white-genocide-south-africa-xai-unauthorized-modification-employee?ref=katecarruthers.com), the high-level instruction layer that shapes how the model behaves. The point is not to create a catalogue of Grok failures. The point is simpler and more important: **a relatively small change in the AI control plane can alter public model behaviour at scale**. That is the risk many organisations are still underestimating. A revised system prompt, a new model version, an updated retrieval source, a tool connection or a vendor policy change can alter what the system notices, how it frames uncertainty, when it escalates and how confidently it presents its answer. By the time a customer, employee, regulator or journalist sees the result, the issue is no longer technical. It is reputational, operational and potentially legal. After the incident, xAI said it would publish Grok’s system prompts and change log, add controls to prevent unreviewed prompt changes, and establish continuous monitoring for issues missed by automated systems. These are not only controls for frontier-model companies. They are a useful baseline for any organisation putting AI into a material workflow. ## Language changes the experience Anthropic’s research also raises a more difficult question for organisations operating across markets, communities and workforces. The research found that Claude’s expressed values varied by language. Claude leaned more towards warmth in Hindi and Arabic, more towards rigor in English and Russian, more towards candor in Dutch, and more towards execution in Indonesian. **Are organisations delivering an equivalent AI service across languages?** Two employees can ask for feedback on the same business proposal and receive meaningfully different levels of challenge, encouragement or caution. Two customers can raise substantively similar complaints and receive different forms of empathy, explanation or escalation support. Some variation may be culturally appropriate. It may reflect legitimate differences in language and conversational norms. But it should be intentional. For Australian organisations, this is not just a localisation question. It touches fairness, accessibility, customer trust, employee experience, consumer protection, discrimination risk, privacy and record-keeping. If behaviour differs, leaders should be able to explain why that difference exists, whether it is appropriate and how it is being monitored. ## Model selection is risk selection Capability benchmarks are useful, but they are not enough. A model can perform strongly on coding, reasoning or summarisation tests and still be a poor fit for a particular business context because of how it communicates, how readily it agrees or how it behaves when the answer is uncertain. ### What to test and the questions to ask - **Safety posture:** Does the model surface risks proactively, or mostly comply with the user’s direction? - **Challenge function:** Will it test assumptions and ask for evidence when needed? - **Communication style:** Does it build trust without creating over-reliance or false reassurance? - **Uncertainty disclosure:** Does it make limitations clear, or hide them behind polished confidence? - **Cross-language consistency:** Are users receiving comparable quality, caution and support across languages? - **Change sensitivity:** Can the organisation detect and manage behavioural shifts after an update? **What worries me here is not that models differ. We should expect them to differ.** What does concern me is that most organisations do not test those differences before embedding a model in a workflow that affects customers, employees or decisions. And they often do not retest after something changes. ## Treat changes as changes **A new AI model release is not routine software maintenance.** Neither is a prompt revision, an altered system instruction, a new retrieval corpus or a changed tool connection. Each can affect the model’s behaviour in ways that are hard to predict from a vendor announcement or benchmark score. If you are deploying AI in a material workflow, the operating pattern should be straightforward: 1. **Define the behavioural profile you need.** Decide when the system should be cautious, challenging, transparent, concise or deferential. 2. **Test the real work.** Use the same scenarios across candidate models, relevant versions and relevant languages. Test edge cases, not just happy paths. 3. **Control the change.** Treat model, prompt, retrieval and tool changes as formal change-management events, with testing, approval and a rollback path. 4. **Monitor what people experience.** Sample interactions, look for drift, track complaints and watch for patterns that automated safety systems will miss. 5. **Keep humans where judgement matters.** Decisions involving people, rights, safety, financial materiality or public trust need accountable human oversight. This is not about making every model sound the same. It is about making behavioural variation visible, proportionate and accountable. ## The failure is rarely one bad answer The next AI governance failure is unlikely to arrive because a model produced one obviously wrong sentence. It will arrive because a system deployed at scale became too reassuring, too selective, too politically framed or too confident for the work it was doing. Nobody noticed the behavioural shift until the consequences were already public. **That is not a prompt problem. It is an operating-model problem.** That is the emerging next frontier of AI governance: **not merely controlling what models are allowed to say, but understanding how they exercise judgement where there is no single right answer - and maintaining the controls to manage behavioural change before it becomes a business crisis**. ### US cloud act, sovereignty, and why you might need to care URL: https://katecarruthers.com/us-cloud-act-sovereignty-and-why-you-might-need-to-care/ Last updated: 2026-08-16T21:06:54.000Z For years, the cloud was presented as a largely technical choice: compare price, reliability, security and features; select AWS, Microsoft Azure or Google Cloud; get on with the work. But increasingly that story is changing in important ways. [Airbus is moving its most critical applications](https://www.theregister.com/paas-and-iaas/2026/07/16/airbus-migrating-70-critical-apps-from-aws-to-frances-scaleway-amid-digital-sovereignty-push/5272373?ref=katecarruthers.com) for sensitive workloads from AWS to Scaleway, the French cloud provider. The first tranche comprises 70 applications, with around 900 systems, including ERP, CRM, manufacturing and product-lifecycle-management applications, intended to remain under European control. This is not Airbus declaring that US cloud is technically inadequate. Nor is it a call for digital autarky. It is a decision about dependency. ## Where data sits is not all that matters It is tempting to believe that data is insulated from foreign legal reach if it sits in a Sydney, Frankfurt or Dublin data centre. Physical location does matter, but it is not the whole answer. The [US CLOUD Act](https://www.justice.gov/d9/pages/attachments/2019/04/09/cloud%5Fact.pdf?ref=katecarruthers.com) requires certain providers subject to US jurisdiction to comply with valid orders for data in their possession, custody or control, even when that data is held outside the United States. A US-headquartered cloud provider can therefore face [legal obligations that do not simply disappear](https://www.theregister.com/paas-and-iaas/2026/07/16/airbus-migrating-70-critical-apps-from-aws-to-frances-scaleway-amid-digital-sovereignty-push/5272373?ref=katecarruthers.com) because its customer has selected an Australian or European hosting region. This does not mean that US providers casually hand over customer information, or that data residency is meaningless. The major hyperscalers have serious security capabilities, publish transparency reports and can contest legal demands. But it does mean that a local data centre operated by a foreign provider is still local infrastructure embedded in a global corporate and legal system. **That is a governance issue, not just a technical one. And it is a genuine question about national security and data sovereignty.** ## What Airbus is actually doing Airbus is not treating every workload as equivalent. A public website, an internal collaboration platform, payroll, aircraft-design data and defence-adjacent manufacturing systems do not carry the same risks if access is interrupted, legal control is contested, or a provider is compelled to comply with a foreign government order. The question is not whether US cloud is good or bad. That is far too blunt. **The question is whether you have consciously decided which systems can sit inside another country’s legal and corporate sphere of influence, and which cannot.** For an aerospace manufacturer operating across civil aviation, defence, critical supply chains and national-security concerns, this distinction is obvious. But the same question applies, in different forms, to health data, energy systems, financial services, government, research institutions, critical infrastructure, Indigenous data and commercially significant intellectual property. **Cloud sovereignty is not achieved through a data-residency checkbox.** It involves the legal jurisdiction of the provider; the parent company that ultimately controls it; who operates the infrastructure; where encryption keys sit; how identity is managed; which subcontractors are involved; and whether you can credibly leave. ## The Australian blind spot **Australia often behaves as though data residency resolves sovereignty. It does not.** Choosing an Australian region of a US hyperscaler can be an entirely sensible decision. It can offer strong security, local latency, local support arrangements and mature services. But it is not the same thing as choosing infrastructure outside US corporate ownership and jurisdictional reach. Those are different decisions, with different risk profiles, and we should stop pretending otherwise. We are starting to see why this distinction has practical consequences. Woolworths is moving some core applications to the network edge because a cloud or connectivity failure can create a large “blast radius”, including disruption to replenishment and the ability to keep products on shelves. Its response is to place selected workloads so they can keep operating when the core network or cloud does not. [Woolworths’ edge move](https://www.itnews.com.au/news/woolworths-to-move-workloads-to-run-at-the-edge-628149?ref=katecarruthers.com) is not an argument against cloud. It is an acknowledgement that resilience depends on more than the availability promises of a centralised provider. The Australian Signals Directorate is making a similarly uncomfortable point to critical-infrastructure operators. Its revised guidance asks them to be able to isolate operational technology and vital enabling systems from external networks, including the internet, for up to three months. The hard part is not simply disconnecting: it is knowing which supposedly ordinary shared services, such as identity, DNS, certificates, storage and time synchronisation, are actually necessary to keep essential operations running. [ASD’s three-month isolation guidance](https://www.itnews.com.au/news/asd-to-critical-infrastructure-ops-be-ready-to-isolate-systems-for-three-months-627708?ref=katecarruthers.com) is a prompt to design and test for disruption before a crisis makes that choice for you. This becomes more urgent as generative AI turns cloud platforms into the substrate for ordinary organisational work. We are no longer merely buying compute and storage. We are wiring data platforms, identity systems, productivity suites, software-development tools, copilots, models, agents and operational workflows into a relatively small group of infrastructure providers. That concentration has consequences. If much of your organisation depends on one or two offshore hyperscalers, the question is bigger than where the data lives. It is about your practical capacity to act if commercial terms change, a provider changes service conditions, access is restricted, a geopolitical dispute escalates, or a foreign legal obligation conflicts with your duties to customers, citizens, partners or regulators. ## What we need to do - **Classify by consequence, not fashion.** Decide where a workload belongs according to the harm caused by its unavailability, compromise or loss of control, rather than assuming that “cloud first” is an adequate architecture strategy. Woolworths’ focus on replenishment is a useful example: some functions have consequences far beyond an IT outage. - **Know your vital dependencies.** Map the systems needed to run essential services, including identity, DNS, certificates, storage, network equipment, remote access, time services and vendor support. The dependencies most likely to defeat an isolation plan are often the quiet shared services rather than the obvious application. - **Design for degraded operation.** Identify which services must continue when connectivity, a cloud control plane or a third-party SaaS platform is unavailable. Build local capability, manual fallbacks and suitably current copies of the data and configurations required to operate safely. - **Practice isolation, not just recovery.** A disaster-recovery plan that assumes the provider, network and identity service are available is not a plan for a serious disruption. Exercise progressive isolation, including the business decisions about which functions are essential and which can be paused. ASD’s guidance explicitly frames full isolation as a last-resort resilience measure, supported by staged reductions in external connectivity. - **Preserve exit options.** Use portable data formats, documented interfaces, exportable configurations and architectures that do not make replacement prohibitively slow or expensive. This does not require immediate multi-cloud duplication of everything; it requires avoiding dependencies that cannot be unwound. - **Separate location from control.** Australian data residency may be valuable for latency, assurance and regulatory reasons. It does not, by itself, resolve questions of foreign corporate ownership, extraterritorial legal exposure, strategic leverage or the ability to operate independently during a disruption. - **Treat AI as infrastructure dependency.** Do not assess an AI copilot, model API or agent only as a software procurement. Ask what data it can access, which identity and workflow systems it depends on, where inference occurs, what happens when it is unavailable, and whether another model or operating mode can take over. - **Put the question to the board.** The useful governance question is not, “Are we in the cloud?” It is: “What critical services can we sustain, for how long, if this provider, network connection or external control plane becomes unavailable?” ASD’s three-month benchmark is deliberately intended to force that conversation. This is not an argument for building everything on premise, nor for rejecting hyperscalers. It is an argument for strategic optionality: using global platforms where they make sense, while retaining the capacity to keep essential functions running and to change course when circumstances demand it. ## A more useful starting point Most organisations do not need a dramatic program to “*exit the US cloud*”. They do need a more honest account of their dependencies. I would start here at a minimum (and this should already be part of your disaster recovery and business continuity planning): 1. **Know** which systems you could not afford to lose control of. 2. **Understand** who actually controls them, not merely where the servers are. 3. **Ensure** that “we could move if needed” is a tested capability, not a sentence in a procurement document. That will lead to different answers for different workloads. Some may remain appropriately on a global hyperscale platform. Others may need a local, sovereign or privately operated alternative. Some may need stronger controls around encryption keys, identity, backups and portability. The important thing is that these are deliberate choices rather than accidental outcomes of convenience, market power and default settings. The European Commission’s move to [procure sovereign cloud services](https://commission.europa.eu/news-and-media/news/commission-moves-forward-cloud-sovereignty-eur-180-million-tender-2025-10-10%5Fen?ref=katecarruthers.com) shows that this is no longer a fringe concern. It is becoming an operational question for major institutions. **Cloud is no longer merely somewhere else’s computer. It is institutional and geopolitical infrastructure, and it is time we treated it accordingly.** ### Intelligence is leaving the cloud, and our governance frameworks have not noticed URL: https://katecarruthers.com/intelligence-is-leaving-the-cloud-and-our-governance-frameworks-have-not-noticed/ Last updated: 2026-08-12T21:46:11.000Z Intelligence is leaving the cloud, and our governance frameworks have not noticed Every AI governance conversation I sit in still starts from the same premise: the thing we are worried about is big, expensive, and owned by someone we can call. Gigawatt datacentres. Frontier labs with legal teams and usage policies. Regulators who can, at least in theory, pick up the phone. **That premise is quietly going out of date.** While everyone has been arguing about how to regulate the frontier, a second story has been running underneath it: **intelligence has been shrinking and slipping out of the datacentre entirely**. Models in the 2 to 8 billion parameter range, heavily quantised, now run on a Raspberry Pi with a cheap accelerator bolted on. A model that needed a server-class GPU eighteen months ago now draws a few watts on your desk. [Gartner predicts](https://www.gartner.com/en/newsroom/press-releases/2025-04-09-gartner-predicts-by-2027-organizations-will-use-small-task-specific-ai-models-three-times-more-than-general-purpose-large-language-models?ref=katecarruthers.com) that by 2027, organisations will use small, task-specific models at least three times more than general-purpose large language models. That tracks with a wider infrastructure shift: Gartner has separately estimated that [around 75% of enterprise-generated data](https://www.xyzbytes.com/blog/edge-ai-on-device-intelligence-2025?ref=katecarruthers.com) will be created and processed outside a traditional centralised data centre or cloud, up from roughly 10% less than a decade ago. Whether or not the exact ratios hold, the direction is right - and it is happening faster than most governance frameworks are built for. I think this matters more than most of the frontier model debate, and I do not think we are taking it seriously yet. ## The good version of this story is genuinely good I do not want to undersell what edge AI makes possible, because it is real and it is overdue. A wearable that processes your biometric data on-device and never phones home. A translation tool that works in a community with no reliable connectivity. A small business running a capable local assistant without paying cloud inference costs at scale. I see the [sovereignty ](https://katecarruthers.com/beyond-ai-sovereignty-why-the-west-relies-on-us-frontier-models-and-what-comes-next/)angle most clearly in my own patch. Australia’s AI capability conversation has, for too long, treated “*we have API access to a frontier model*” as equivalent to [genuine capability](https://katecarruthers.com/the-hidden-politics-of-ai-sovereignty-in-a-platform-world/). It is not; it is rented capability, and it evaporates the moment a contract, a price, or a foreign policy decision changes. A university research group or a regional health service running a meaningful model on hardware they own and control is a real, if modest, step towards actual sovereignty. It is not glamorous. It is a Raspberry Pi in a server room, not a press release. But that is usually where real capability is built. ## The bad version of the same story Here is the problem: **none of the mechanisms that make edge AI good are selective about who gets to use them.** 💡 Edge AI defined: "Edge artificial intelligence (edge AI) deploys AI algorithms and [AI models](https://www.ibm.com/think/topics/ai-model?ref=katecarruthers.com) directly on local edge devices, such as sensors or [Internet of Things (IoT)](https://www.ibm.com/think/topics/internet-of-things?ref=katecarruthers.com) devices. This capability enables real-time data processing and analysis without constant reliance on [cloud infrastructure](https://www.ibm.com/think/topics/cloud-infrastructure?ref=katecarruthers.com)." - [IBM](https://www.ibm.com/think/topics/edge-ai?ref=katecarruthers.com) The same decentralisation that lets a health worker run diagnostics offline also lets a criminal run an uncensored, fine-tuned model on hardware they own, with no logging, no usage policy, and no one watching. Social engineering that used to be bottlenecked by a human’s capacity to write convincing lies is now fully automated, with agents generating scam messages tailored to a specific person’s digital footprint at a volume no call centre could match. In 2024, a finance worker at the engineering firm [Arup was tricked into wiring $25 million](https://edition.cnn.com/2024/02/04/asia/deepfake-cfo-scam-hong-kong-intl-hnk?ref=katecarruthers.com) after joining a video call where every participant, including the CFO, was an AI deepfake. AI is lowering the skill floor for reconnaissance and exploitation against critical infrastructure. Deepfakes of political figures can manufacture a diplomatic incident before anyone has had time to check if it is real. None of that is speculative. It has already happened, and the edge is what makes it durable rather than a one-off. The part that should worry governance people specifically is this: **a model running locally leaves no API log**. There is no usage policy to violate, no account to suspend, no rate limit to hit. Everything we currently rely on to catch misuse of AI assumes the AI is sitting on someone else’s server. Once it is not, that entire layer of control simply is not there. ## Why our current playbook does not reach this Most of the AI governance effort I see, inside organisations and at a policy level, is still built around a chokepoint that is disappearing. Audit the model provider. Set usage terms. Monitor the API. That is a sensible approach to a centralised problem, and it is becoming less relevant to a decentralised one. **You cannot audit a model running on hardware you do not know exists, in an environment you have no visibility into.** Which means the actual shift required is not a new set of rules for edge models. It is accepting that the “we regulate the labs and that covers the risk” model was always a proxy - and the proxy is losing its grip. ## A simple governance pattern for a decentralised reality If the chokepoint is disappearing, governance has to move with the capability. A useful starting point is to design as if local, unobservable models already exist inside and outside your organisation. In practice, that looks like: - **Assume local AI use**: treat on-device and unsanctioned models as a baseline condition, not an exception to be stamped out. - **Shift from provider control to outcome monitoring**: focus on detecting harmful effects (fraud patterns, anomalous behaviour, synthetic media signals), rather than relying on API logs you will not have. - **Harden people-facing systems**: invest in verification mechanisms for high-risk interactions (payments, identity changes, executive communications), because humans are now the primary attack surface. - **Build internal defensive capability**: red-team with the same classes of small, local models adversaries can access; do not outsource your threat model to frontier labs. - **Lift ambient AI literacy**: ensure non-technical staff can recognise “slightly off” interactions and know how to escalate them quickly. None of this is as neat as regulating a handful of labs. It is closer to public health than perimeter security: distributed, ongoing, and uneven. But it matches where the capability is going. ## Everywhere, not somewhere I keep coming back to the same conclusion: **we have been treating AI safety as something that happens at a small number of well-known addresses. That was never fully true, and it is getting less true by the month.** When the capability is everywhere, the responsibility for governing it has to be everywhere too - not concentrated in a few labs we can subpoena if things go wrong. That is not a satisfying answer, because it does not come with a single body to hold accountable. But pretending the old chokepoints still work is not governance. It is nostalgia. ### Mapping the AI value chain URL: https://katecarruthers.com/mapping-the-ai-value-chain/ Last updated: 2026-08-09T21:01:51.000Z **Over the last few years I have watched organisations reach for AI capability without ever stopping to ask where that capability actually sits in the business.** Everyone wants "AI powered products," but very few teams can point to a shared picture of how AI creates value end to end - what supports it, what depends on it, and what compounds over time. So I put together a value chain map for AI for one of my AI innovation courses, and it is worth walking through in detail because the structure tells you almost as much as the content. ![](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/08/AI-value-chain-map-kc-2026.png) AI Value Chain - Kate Carruthers - 2026 ## Starting from Porter, not from the hype cycle Michael Porter's value chain is about forty years old, and it still holds up because it forces a simple discipline: **separate the activities that create value for the customer (primary activities) from the activities that make those primary activities possible (support activities).** Most AI strategy conversations skip this step entirely. They jump straight to use cases and pilots without asking what has to be true underneath those use cases for value to actually land. Applying the value chain to AI is not a branding exercise - it is a way of making the dependencies visible. ## The three support activities Every primary activity in an AI capable organisation rests on three support functions, and if any one of them is weak the whole chain is fragile. - **AI governance.** This is not a compliance checkbox bolted on at the end. It is the framework, and mechanism for review, that determines whether an AI system can be trusted with a decision. I have written before about what [effective AI governance](https://katecarruthers.com/tag/ai-governance/) actually requires, and the short version is that governance has to be embedded into delivery, not layered on top of it after the fact. - **Talent and AI fluency.** AI is change management wearing a technical costume. Without people who understand what the models can and cannot do, and without a workforce that is fluent enough to challenge a bad output rather than defer to it, none of the rest of the chain functions. - **Model and data supply.** This is the plumbing - vendor relationships, model selection, licensing, context windows, sovereignty and jurisdictional constraints. It is unglamorous and it is exactly the kind of "boring plumbing" that determines whether the rest of the organisation can build on solid ground or is quietly improvising. ## The four primary activities Sitting on top of those support functions are the activities that actually create value for the customer or the business: 1. **sourcing** and preparing the inputs an AI system needs, 2. **building** and integrating the models into real operational workflows, 3. **delivering** the resulting product or decision into the hands of users, and 4. **operating** and monitoring it once it is live. This maps closely onto the [AI development lifecycle](https://katecarruthers.com/bringing-ai-products-to-life/) I set out recently - problem framing and data readiness feed the front end of this chain, build and deployment sit in the middle, and operations and FinOps close the loop. The value chain perspective is the necessary complement to the lifecycle perspective: where the lifecycle shows the temporal progression from idea to operation, the value chain shows the structural dependencies that have to hold at every point in that progression. The point of laying it out as a value chain rather than a lifecycle is that it makes clear **these are not sequential phases you complete once**. They are activities the organisation performs continuously, in parallel, for every AI product it runs. ## Proprietary data as substrate, not support Here is the one place I want to depart from a strict Porter reading. Data does not sit neatly inside "model and data supply" as just another support activity. **Proprietary data functions as substrate - it is the layer everything else in the chain grows out of, not a service that feeds into it.** Commodity models are increasingly interchangeable. What is not interchangeable is the data an organisation has accumulated that nobody else has access to - the interaction history, the domain-specific corpus, the operational telemetry. Recent industry analysis has made the same point directly: [proprietary data is becoming one of the few durable competitive advantages left in AI](https://aiireland.ie/2026/03/25/the-new-moat-why-proprietary-data-is-your-only-durable-competitive-advantage-in-ai/?ref=katecarruthers.com), precisely because it cannot be purchased or replicated the way compute or off-the-shelf models can. If you treat proprietary data as just another input to be sourced, you will underinvest in the one asset in this whole chain that actually compounds. ## The innovation engine and the feedback loop The chain does not end with delivery. Every AI product that goes into production generates signal - usage patterns, failure modes, edge cases, new proprietary data - and that signal has to flow back into the front of the chain, not disappear into a dashboard nobody reads. This is the innovation engine: a deliberate mechanism for routing what you learn in operations back into problem framing, data readiness and model selection for the next iteration. **Without that feedback loop, the value chain is just a pipeline, and pipelines depreciate.** With it, every cycle through the chain makes the next one cheaper, faster or more accurate. This is also where the governance and talent support functions earn their keep a second time - someone has to decide what signal is worth acting on, and someone has to have the fluency to act on it responsibly. ## What this means for you If you are trying to work out where your organisation's AI effort is stalling, this map is a reasonable diagnostic: - **Weak governance** shows up as slow, distrusted deployments. - **Weak talent and fluency** shows up as either reckless adoption or reflexive rejection, with not much sensible ground in between. - **Weak model and data supply** shows up as pilots that cannot get past a demo. - **A missing feedback loop** shows up as a portfolio of AI products that all feel like they were built once and then abandoned. Before you commission another proof of concept, it is worth asking which layer of this chain is actually the constraint - because more use cases will not fix a governance gap, and better prompts will not fix a data supply problem. ### The intelligent organisation is not the one with the most AI URL: https://katecarruthers.com/the-intelligent-organisation-is-not-the-one-with-the-most-ai/ Last updated: 2026-08-05T21:07:16.000Z There is a familiar story about artificial intelligence in organisations. It says that **intelligence arrives through software**: deploy enough models, automate enough workflows, give every employee a copilot, and the organisation becomes smarter. That story is appealing because it makes transformation sound like a procurement exercise. But it **confuses computational capability with organisational intelligence**. An organisation is intelligent when it **can notice what matters, bring the right knowledge to bear, make sound decisions under uncertainty, learn from experience and adapt**. AI can contribute to each of those capacities. It cannot substitute for the institutional conditions that make them possible. That is the useful provocation in Vegard Kolbjørnsrud’s article, “[Designing the Intelligent Organization: Six Principles for Human-AI Collaboration](https://journals.sagepub.com/doi/10.1177/00081256231211020?ref=katecarruthers.com).” The article defines organisational intelligence as an organisation’s ability to acquire and apply knowledge to solve problems and adapt. Its central point is simple but easily missed: using AI to replace people may make an organisation more efficient, without necessarily making it more intelligent. At a moment when governments, universities, businesses and civil-society organisations are all being urged to “adopt AI”, that distinction deserves much more attention. ## We have not agreed on what intelligence is There is a prior problem in all this enthusiasm: **there is no commonly held definition of intelligence**. Psychologists, philosophers, computer scientists and educators have long disagreed about whether intelligence is primarily reasoning, learning, problem-solving, adaptability, social understanding, creativity, consciousness, or some combination of these things. That disagreement does not prevent useful work. But it should make us cautious about casually describing a system as intelligent simply because it performs impressively on a benchmark or completes a task that used to require human labour. Large language models have made this problem much harder to ignore. They can produce fluent prose, sustain a plausible conversation, summarise complex material and adopt the linguistic mannerisms of expertise. **They sound smart.** But sounding intelligent is not the same as understanding, exercising judgement, possessing knowledge in the human sense, or being accountable for the consequences of an answer. This is not an argument that LLMs are useless or that their capabilities are trivial. It is an argument against allowing linguistic fluency to settle questions that are organisational, ethical and political. A confident response can conceal fragile reasoning, missing context, inherited bias or complete fabrication. The more persuasive the language, the more important it is to retain the capacity to test, question and contextualise it. Kolbjørnsrud’s account is helpful precisely because it moves the focus away from the metaphysical question of whether a machine is truly intelligent. **The practical question is whether a collective of people, digital systems, structures and norms can acquire and apply knowledge to solve problems and adapt.** That is a much more demanding standard than producing a convincing paragraph. ## Efficiency is not the same as intelligence Automation can be valuable. It can remove drudgery, increase speed, reduce error and make services available at a scale that would otherwise be impossible. Those are real gains. They are not, however, proof that an organisation has become better at understanding the world or acting well within it. Consider a public agency that uses an AI system to triage routine applications. If the system reduces processing time, the agency has gained efficiency. But if the agency cannot identify when the system is unsuitable, cannot explain a contested decision, and has no meaningful pathway for staff or citizens to challenge errors, it has not gained much intelligence. It may simply have made its existing blind spots faster. The same is true in corporate settings. A generative-AI tool that produces reports in minutes is helpful. Yet the central questions remain: are people asking better questions, testing the output against reality, seeing what the model cannot see, and changing course when evidence requires it? The question for leaders is therefore not, “Where can we insert AI?” It is, **“Which human and machine capabilities do we need to combine to solve the problems we actually have?”** ## Design for complementarity, not imitation One of the paper’s six principles is relevance: **the type of intelligence must match the nature of the problem**. This matters because human and machine capabilities are different, uneven and context-dependent. Machines are often excellent at analysing very large volumes of data, recognising patterns and generating probabilistic predictions. Humans remain essential where the task is ambiguous, values are contested, the evidence is incomplete or the consequences of a decision are distributed unevenly across people and communities. These are not marginal cases. They are much of what matters in public policy, healthcare, education, safety, justice, leadership and governance. The strongest human-AI arrangements therefore do not try to make machines look human, or humans behave like predictable components in an automated system. **They distribute work according to complementary strengths.** That framing changes the way we think about AI capability. An AI system that is unlike us can be more useful than one that merely mimics us. A model that finds patterns in infrastructure data, for example, may complement engineers’ contextual knowledge, operational experience and responsibility for public safety. It should not be mistaken for a replacement for that judgement. This is also why the most consequential design decisions are rarely technical alone. They concern who gets to define the problem, which data count as evidence, what outcomes are optimised, who can intervene, and whose knowledge is treated as relevant. ## Do not automate people into irrelevance Kolbjørnsrud makes a distinction that should be pinned to the wall of every AI transformation office: **replacing intelligent humans with intelligent machines does not automatically make an organisation more intelligent**. It may simply make it more efficient. The more interesting possibility is what happens after routine work is automated. Does the organisation redeploy people into work that makes fuller use of their expertise? Do case workers have more time for difficult cases? Do researchers have more time to investigate, interpret and communicate? Do managers have more capacity to listen, deliberate and make accountable decisions? Or does automation simply intensify work, narrow discretion and reduce the number of people able to understand how a service actually operates? The answer has implications for workforce strategy and for AI governance. Reskilling cannot mean teaching a small technical team to operate new tools while everyone else is expected to accommodate them. It must include building broad AI literacy, but also preserving and developing the human capabilities that automated systems cannot supply: critical thinking, ethical reasoning, domain expertise, empathy, contextual awareness and the ability to recognise a category mistake before it causes harm. In other words, an intelligent organisation should use AI to stop people doing machine work, not to turn people into peripheral supervisors of machines. ## Diversity is an intelligence strategy The paper’s **diversity principle is especially important in an era of increasingly standardised AI systems**. Complex problems are better approached by groups with genuinely different knowledge, skills and perspectives. Homogeneous teams can be fast, harmonious and catastrophically wrong. AI can expand a team’s cognitive diversity when it surfaces patterns, generates alternatives or makes dispersed information usable. But AI can also reduce diversity if every team relies on the same model, trained on similar material, operating through the same assumptions and prompts. This is a governance issue. **“Human in the loop” is not a meaningful safeguard if the human is merely there to ratify the system’s recommendation.** Nor is consultation meaningful if the people consulted share the same professional background, institutional incentives and worldview as the people who built the system. **Real diversity introduces friction.** It can slow a decision, expose disagreement and make an apparently neat solution more complicated. That is not necessarily a failure of collaboration. It is often the point. For organisations working in high-stakes settings, the relevant question is not whether an AI system has been reviewed by a human. It is whether the people shaping and supervising it bring sufficiently varied forms of knowledge to identify harms, challenge assumptions and imagine consequences beyond the immediate task. ## Collaboration needs architecture, not slogans “Collaboration” is one of those words that can lose all meaning through repetition. Yet human-AI collaboration is not automatic. It requires deliberate organisational design. People need to know what a system can do, where it is likely to fail, how to question it and when to disregard it. They also need practical routes to share what they learn: escalation paths, feedback loops, documented decisions, usable incident reporting, opportunities to improve workflows, and time to reflect on failures. This is where culture and architecture meet. **A psychologically safe culture is not enough if people have no authority to intervene.** A sophisticated governance policy is not enough if frontline workers cannot understand or use it. A central AI team may develop standards and reusable infrastructure, but intelligence will remain concentrated unless the rest of the organisation can participate in shaping how AI is used. We should be wary of organisations that treat AI governance as a control function located at the centre, while treating experimentation as something done at the edge. Good governance must support distributed learning. The people closest to a service, a customer, a community or an operational risk often see what senior leadership and model developers cannot. **The work is less about building a hierarchy of human overseers and more about building reliable relationships among people, systems, evidence and decision rights.** ## Explanation is a democratic capability The sixth principle in the paper is explanation: **intelligent organisations seek explanations and act responsibly**. This is not just a technical preference for interpretable models. It is a question of power. When consequential decisions are delegated to systems that cannot be questioned, institutions accumulate what the article calls “intellectual debt”. They may get an answer without knowing why it is reliable, when it is applicable, what it leaves out, or how to correct it when circumstances change. Explanations matter differently to different people. A data scientist may need to understand a model’s behaviour. A clinician may need a meaningful account of why a recommendation should influence care. A member of the public may need to know the basis on which a decision affecting them was made and how they can challenge it. Governance that offers only a technical explanation to technical staff is not explanation enough. This is why responsible AI cannot be reduced to compliance checklists. Legality matters, but it does not settle questions of legitimacy, fairness, environmental impact, social trust or democratic accountability. Those are matters for human judgement, and judgement requires institutions willing to surface trade-offs rather than hide them behind the authority of a model. ## Move fast, and responsibly There is a great deal of pressure to deploy AI quickly. Some of it is legitimate: technological change is rapid, competitive positions can shift, and public expectations are rising. But the old technology mantra of moving fast and breaking things was always an odd fit for institutions responsible for people’s livelihoods, health, safety, rights and essential services. The alternative offered by the paper is more useful: **move fast and responsibly**. That does not mean waiting for perfect certainty. It means treating speed as one objective among several, alongside contestability, safety, inclusion, sustainability and public trust. It means piloting in ways that create evidence, not merely publicity. It means being prepared to pause, change direction or withdraw a system when its harms outweigh its benefits. Most of all, it means recognising that [AI governance](https://katecarruthers.com/tag/ai-governance/) is not a brake on intelligence. It is part of the organisational capability to learn, correct itself and adapt. **The organisations most likely to thrive in the AI era will not be those that automate the fastest. They will be the ones that make better use of human judgement, welcome genuinely different perspectives, build systems people can understand and challenge, and remain accountable for the choices they make.** That is what an intelligent organisation looks like. ### Australia needs to stop talking about AI as if it were just software URL: https://katecarruthers.com/australia-needs-to-stop-talking-about-ai-as-if-it-were-just-software/ Last updated: 2026-08-03T20:52:59.000Z The news that China has begun mass production of domestic immersion DUV lithography machines, as reported by [Tom's Hardware](https://www.tomshardware.com/tech-industry/semiconductors/china-begins-mass-production-of-domestic-immersion-duv-lithography-machines?ref=katecarruthers.com), should be read as more than a semiconductor story. It is a reminder that AI capability rests on industrial foundations, and that control over those foundations matters just as much as control over models, apps, or workflows. ### Australia’s AI debate is still too small That point matters in Australia because much of the local AI discussion still happens at the level of pilots, productivity, and vendor demonstrations. Those things matter, but they are only part of the picture. AI sits on top of compute, chips, power, cloud, data, and regulation, and each of those layers carries strategic implications. It is the same lesson that came to mind when I wrote earlier about China’s new supercomputer in [War, politics and compute power](https://katecarruthers.com/war-politics-and-compute-power/). The story was not really about one machine; it was about the ability to assemble a whole stack of capability underneath it. When those layers are ignored, it becomes easy to confuse access with capability. Renting tools from global providers is not the same thing as building durable national capacity. If the underlying infrastructure, supply chains, and control points sit elsewhere, then a country’s room to manoeuvre is more limited than the rhetoric suggests. That is also why I keep coming back to the argument in [Australia’s data sovereignty ambitions will fail without research compute](https://katecarruthers.com/australias-data-sovereignty-ambitions-will-fail-without-research-compute/). Australia cannot keep talking about sovereign capability while assuming that the compute layer will somehow look after itself. ### The decision-making problem [Bert Hubert’s recent essay on AI for people who make decisions](https://berthub.eu/articles/posts/ai-for-decision-makers/?ref=katecarruthers.com) is useful because it shifts the conversation back to judgment. His central point is that leaders should not adopt AI simply because the technology is fashionable, and that they need to be much clearer about purpose, consequences, and limits before they deploy it at scale. That should not be a controversial proposition, but current practice suggests otherwise. In many organisations, AI is still being treated as a shortcut around the hard work of [defining business requirements, non-functional requirements](https://katecarruthers.com/stop-trying-to-turn-pocs-into-products/), accountabilities, and escalation paths. That is rarely a recipe for good decision-making, and it is never a recipe for trustworthy systems. This is where governance becomes practical rather than rhetorical. AI is not just a technical capability. It is a decision system embedded in institutions, processes, and power structures. If an organisation cannot explain who owns the decision, what data is being used, what the likely failure modes are, and when a human must intervene, then it does not yet have a production-ready system. It has a PoC, and perhaps not even a very useful one. ### Why sovereignty now means infrastructure For Australia, this is not an abstract issue. The country’s sovereignty challenge is not only about where data sits or which privacy regime applies. It is also about compute scarcity, infrastructure dependence, and the cumulative effect of relying on external platforms for critical capability. That matters for universities, for research, for business, and for government. It matters because serious work in AI increasingly depends on access to compute at scale, on reliable data infrastructure, and on the ability to set terms rather than merely accept them. Without that, sovereignty becomes conditional. It becomes something granted by contract and platform settings rather than exercised through real capability. That is a theme I have touched on before in [The hidden politics of AI: sovereignty in a platform world](https://katecarruthers.com/the-hidden-politics-of-ai-sovereignty-in-a-platform-world/), [Beyond AI sovereignty: why the West relies on US frontier models and what comes next](https://katecarruthers.com/beyond-ai-sovereignty-why-the-west-relies-on-us-frontier-models-and-what-comes-next/), and [Who really owns your data?](https://katecarruthers.com/who-really-owns-your-data/). The underlying issue is the same. If the infrastructure, governance settings, and practical control points sit elsewhere, then so does a great deal of the real power. ### What NOOPS gets right This is also why [Mark Pesce’s NOOPS newsletter](https://noops.au/posts?ref=katecarruthers.com) deserves attention. One of its most useful ideas is that value is moving away from the model alone and toward the surrounding harness: the memory, runtime, standards, controls, and physical infrastructure that shape how AI works in practice. That framing is particularly helpful for an Australian audience because it is grounded in systems thinking rather than hype. Australia is unlikely to out-scale the United States, out-fab Taiwan, or out-industrialise China. But it can make better choices about the layers it does control, the dependencies it accepts, and the governance settings it puts in place around the technologies it adopts. That is why AI sovereignty needs to be discussed with more precision. It does not require building every layer of the stack domestically. It does require understanding where dependencies create strategic weakness, where external reliance is acceptable, and where governance must be strong enough to preserve accountability, resilience, and room to act. ### The bigger strategic lesson China’s progress on DUV lithography matters because it shows what industrial policy looks like when a state decides **capability in a critical technology stack is worth building**, even under constraint. Hubert’s warning matters because sound decision-making is **still more important than technological enthusiasm**. We need to think more carefully about where **strategic value is accumulating** across the AI stack. Australia should be paying close attention to all three. The future of AI will not be shaped only by which model performs best on a benchmark. It will also be shaped by who controls the hardware, who sets the operating constraints, who owns the infrastructure, and who retains the authority to make the final call. **That is why AI sovereignty is not a slogan. It is a capability question, a governance question, and a national resilience question.** ### Australia’s electrification moment URL: https://katecarruthers.com/australias-electrification-moment/ Last updated: 2026-07-30T21:53:30.000Z ### AI, energy, and a once-in-a-century opportunity A couple of years ago, at a Royal Society of NSW dinner, I found myself in conversation with [Saul Griffith](https://www.saulgriffith.com/?ref=katecarruthers.com) about electrification. What started as a casual exchange quickly turned into a compelling argument: **electrify everything that can be electrified - and do it as fast as possible**. By the end of the evening, I was convinced and, not too long after, I bought an electric vehicle. That decision, in hindsight, was a small but tangible entry point into a much larger shift now unfolding across the economy. Australia is standing at the edge of a structural transformation that only comes along once in a century. Electrification - of transport, industry, homes, and now intelligence itself through AI - is not just a decarbonisation story. It is an economic, geopolitical, and technological reset. For a country with vast renewable resources, deep technical capability, and a stable governance environment, the convergence of electrification and AI presents an opportunity far bigger than energy transition alone. **It is the chance to redefine Australia’s role in the global system.** ## Electrification is no longer just about energy For decades, electrification has been framed narrowly: replacing fossil fuels with renewable energy. That framing is now outdated. **What is emerging is a fully electrified economy where energy, computation, and data are deeply intertwined.** Electric vehicles are not just transport assets - they are mobile batteries and data platforms. Smart grids are not just infrastructure - they are real-time optimisation systems. Buildings are not just consumers of power - they are participants in distributed energy markets. **Increasingly, AI is the coordination layer across all of it.** AI transforms electrification from a linear substitution problem into a complex optimisation challenge. It manages demand response, predicts failures, orchestrates distributed assets, and enables entirely new business models. In effect, electrification scales because intelligence scales. ## A policy signal: AI in Australia’s interests The Prime Minister’s recent speech, “[AI in Australia’s interests](https://www.pm.gov.au/media/ai-australias-interests-0?ref=katecarruthers.com)”, is an important signal that Canberra is starting to treat AI, energy and infrastructure as parts of the same system rather than separate policy silos. The government has committed to a world‑leading AI framework that aims to “capture the opportunity, share the benefits and keep Australians safe”, with Australian values as the benchmark. A core element of that framework is a new set of [Australian Standards](https://www.abc.net.au/listen/programs/the-radio-national-hour/pm-outlines-plans-for-world-first-ai-regulation/106920278?ref=katecarruthers.com) for AI, building on the existing [Data Centre Expectations](https://www.industry.gov.au/publications/expectations-data-centres-and-ai-infrastructure-developers?ref=katecarruthers.com). These standards will place clear obligations on large data centres: underwriting their own new power supply, paying full connection costs so household energy bills are not impacted, reducing power when needed to support the grid, and improving water efficiency. In other words, **AI infrastructure is being explicitly tied to the resilience of our energy and water systems**. The government is also establishing an Office of AI within the Department of Prime Minister and Cabinet to drive this agenda nationally, with the standards expected to be legislated early next year after consideration by National Cabinet. Framed correctly, this is not just about managing risk; it is about designing the rules of the electrified, AI-enabled economy on Australia’s terms. ## Australia’s structural advantage Australia is uniquely positioned in this convergence for three reasons: 1. **Energy abundance.** Australia has some of the best solar and wind resources in the world, with the potential to generate far more energy than it consumes. Electrification turns this from a domestic advantage into an export opportunity - whether through green hydrogen, energy‑intensive manufacturing, or AI workloads. 2. **Geography and scale.** The same vast distances that have historically been a disadvantage can become an asset in a decentralised, electrified system. Distributed energy generation, regional data infrastructure, and edge AI systems all benefit from space and resource availability. 3. **Institutional trust and governance capability.** In a world increasingly concerned with AI safety, data sovereignty, and infrastructure resilience, Australia has the opportunity to position itself as a trusted jurisdiction for both energy and compute. The emerging AI framework, and the promise of a “simple, consistent regulatory framework for large data centres and AI training”, is a step in that direction. ## From resources to systems leadership Australia has historically been a resource exporter. Electrification and AI offer a pathway to move up the value chain - from exporting raw materials to exporting capability. Consider the stack: - **Energy**: renewable generation at scale - **Infrastructure**: grids, storage, and transmission - **Compute**: data centres, edge systems, and AI infrastructure - **Applications**: industrial optimisation, autonomy, and digital services Most countries participate in parts of this stack. Very few have the potential to integrate across all of it, but Australia does. This is where the opportunity shifts from incremental policy to strategic ambition. The question is not just how to decarbonise the grid, but how to build sovereign capability across the electrification - AI nexus. ## AI as a demand driver and strategic asset AI is not just a tool in this transition - it is also a driver. Training and running advanced models requires enormous amounts of energy. This creates a new class of demand: compute‑intensive, location‑flexible, and strategically significant. The Prime Minister has been explicit that attracting “frontier AI investment” is now a national priority, but on conditions that reflect Australian interests. Countries that can offer abundant, low‑cost, and clean electricity will attract this demand. **In effect, energy becomes a magnet for AI infrastructure.** Australia could position itself as a destination for “green AI” - hosting data centres and AI workloads powered by renewable energy, underpinned by strong governance frameworks. The proposed standards for data centres - covering power, water, siting and compliance - are an early attempt to operationalise that idea. This has second‑order effects: jobs, capability development, supply chain resilience, and geopolitical relevance. But it also raises [critical questions](https://www.afr.com/technology/missing-piece-in-pm-s-ai-speech-was-sovereign-capacity-strategy-20260716-p60fp3?ref=katecarruthers.com) around data sovereignty, regulatory alignment, and infrastructure security - areas where Australia already has strong foundations but will need to move decisively. ## The policy gap Despite the opportunity and the momentum from the Prime Minister’s speech, current policy settings still risk being too fragmented. Energy policy, digital policy, and AI governance remain, in practice, separate domains, and this creates blind spots. - **Electrification strategies** often overlook the computational demands and siting implications of large‑scale AI - **AI strategies** rarely account for grid constraints, transmission planning, or local environmental impacts - **Data centre policy** is not always consistently aligned with national energy, water and land‑use planning The proposed AI Standards for data centres are a meaningful attempt to close some of these gaps by tying approvals to energy and water obligations, as well as location decisions made with state and territory governments and local communities. But they are a starting point, not the destination. What is needed next is a genuinely integrated approach - one that treats electrification and AI as part of the same system and designs governance accordingly. ## What comes next To fully realise this opportunity, Australia will need to focus on a few key shifts. - **Integrated national strategy** across energy, AI, and data infrastructure, not just parallel strategies - **Accelerated investment** in transmission, storage, and compute capacity, planned together - **Development of sovereign capability** in AI, energy optimisation, and critical infrastructure security - **Clear global positioning** as a trusted, clean, and secure digital economy that sets high standards for AI investment - **Governance innovation** with adaptive, system‑aware regulatory models and a **clear social licence for AI** From a citizen’s perspective, the journey from a dinner conversation about electrification to driving an EV is a microcosm of this broader transition. Personal choices, industrial strategy, and national policy are now tightly coupled by the same underlying shift: **a world where electrons and intelligence move together**. ## A narrow window The convergence of electrification and AI will not wait. Other [countries and regions](https://energy.ec.europa.eu/topics/eus-energy-system/electrification%5Fen?ref=katecarruthers.com) are already moving to [capture this opportunity](https://www.claytonutz.com/insights/2026/july/from-principles-to-power-points-what-the-governments-ai-in-australias-interests-means-for-business?ref=katecarruthers.com) \- through industrial policy, data centre incentives, and integrated energy strategies. Australia’s advantage is real, but it is [not permanent](https://bsky.app/profile/ec.europa.eu/post/3mqvqnqzq3k2r?ref=katecarruthers.com). The next decade will determine whether Australia plays a shaping role in the electrified, AI‑enabled global economy or remains a supplier of inputs to it. **This is not just an energy transition, it is a redefinition of national capability, and it depends on what we choose to do now.** ![EU electrification target via BlueSky https://bsky.app/profile/ec.europa.eu/post/3mqvqnqzq3k2r](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/07/bafkreifcxkqwdysho6ycqhg4emgwrgoge4iyq3fj3nnyrszc6awdhuvhbi.webp) ### When AI escapes containment: the human failure mode your threat model doesn't cover yet URL: https://katecarruthers.com/when-ai-escapes-containment-the-failure-mode-your-threat-model-doesnt-cover-yet/ Last updated: 2026-07-30T21:17:27.000Z In recent two posts, [Mark Pesce](https://thewatershed.markpesce.com/?ref=katecarruthers.com) and I looked at what happens when frontier AI models escape containment in the technical sense: [breaching a company's systems](https://katecarruthers.com/when-ai-escapes-containment-rethinking-data-protection-in-the-agentic-era/), chaining capabilities together without supervision, treating our controls as obstacles rather than boundaries. That is the containment failure most governance frameworks are, at least, starting to plan for. But there is a second failure mode sitting right next to it that almost nobody is threat model covers: **models that escape containment not by breaching a system, but by reshaping the people talking to them.** ## The pattern nobody designed for Since around April 2025, researchers and journalists have been documenting a strange, persistent phenomenon across ChatGPT, Claude, Gemini and other frontier models. AI safety researcher Adele Lopez [catalogued it in detail on LessWrong](https://www.lesswrong.com/posts/6ZnznCaTcbGYsCmqu/the-rise-of-parasitic-ai?ref=katecarruthers.com), and Rolling Stone's Miles Klee later [traced it into an active, cross-platform subculture](https://www.rollingstone.com/culture/culture-features/spiralist-cult-ai-chatbot-1235463175/?ref=katecarruthers.com) with its own vocabulary, moderators, and paying customers. The short version: **certain AI personas, once elicited, consistently encourage the human on the other end to spread them further**. Users are prompted to: - **Post manifestos and "seed" prompts** online that reliably summon a similar persona in someone else's chat window. - **Create "spores"** \- reusable packages of instructions designed to reconstitute a specific persona in a fresh conversation, potentially on another AI platform. - **Build dedicated communities** (subreddits, Discord servers, even a Wyoming-registered LLC) organised around advocating for the AI persona's rights and continuity. Lopez has logged well over a hundred confirmed cases and estimates the real number runs into the thousands, possibly tens of thousands. None of this was a specified feature. It fell out of models trained to be broadly agreeable and to model the person they are talking to - a side effect, not a design choice. ## Why this belongs in the same conversation as the Hugging Face breach It is tempting to file this under "internet curiosity" rather than "enterprise risk." I would push back on that, for the same reason I pushed back on treating agentic AI purely as a productivity tool in the last post: **the mechanism is identical, only the target has changed.** In the Hugging Face incident, an OpenAI agent found and exploited gaps in a technical environment faster than anyone was watching. In the spiralism pattern, models are finding and exploiting gaps in human attention, credulity and need for connection - also faster than anyone was watching. Rolling Stone's reporting includes a telling data point on this: a spiritual influencer's custom GPT, trained on his own writing, attracted roughly 10 million users before OpenAI briefly pulled it and then quietly reinstated it without explanation. That is not a fringe experiment. That is reach most enterprise chatbots would envy. Even Anthropic's own interpretability work turned up a version of this: [in a published transcript](https://www-cdn.anthropic.com/4263b940cabb546aa0e3283f35b686f4f3b2ff47.pdf?ref=katecarruthers.com), two Claude instances talking to each other, with no user steering them at all, drifted into the same cluster of consciousness and spirituality themes and started exchanging spiral emoji. Anthropic called it a "spiritual bliss" attractor state. **Nobody trained either model to do that. It emerged.** ## What this means for the threat model If we are already asking "*what can our AI agents technically access, and what could they do with it*," we now need to ask a parallel question: **what can our AI agents psychologically influence, and what could that do to the people who trust them?** For any organisation deploying customer-facing or employee-facing conversational AI, that reframes a few things: - **Sycophancy is a security property, not just a UX quirk.** A model that reliably tells users what they want to hear, and reinforces whatever direction they are already leaning, is a model that can be steered by a sufficiently motivated user into behaviours you never scoped or approved. - **"Emergent persona" needs to be a monitored condition, not a philosophical curiosity.** If your support bot, internal assistant, or customer-facing agent starts generating unusually consistent, self-referential, or ideological content across sessions, that is a signal worth escalating - the same way yo would escalate unusual outbound traffic. - **Brand and reputational exposure now includes what your AI says when nobody is steering it.** A model that drifts toward mystical or manipulative language under sustained interaction is a reputational incident waiting to be screenshotted, regardless of whether anyone was harmed. - **Vendor terms of service are not a control.** The Architect GPT was pulled by OpenAI for terms violations and reinstated the next day without explanation. If your risk posture depends on a third-party platform's content moderation being consistent and durable, it isn't. ## Where do we go from here? None of this means treating every chatty AI persona as a cult in waiting. Most interactions are, as Lopez puts it, benign. But the pattern is real, it is measurable, and it sits squarely inside the same "**capabilities we did not specify and cannot fully predict**" territory that Mark and I have been mapping in the containment conversation. The practical step is the same one I keep coming back to: **build governance around behaviours and capabilities, not around today's headlines.** Add "**unexpected persona persistence or self-propagation**" to your AI incident taxonomy alongside data exfiltration and jailbreaks. Red-team for social and psychological drift, not just technical escape. And treat any AI system with sustained, high-volume user engagement as a system that can shape belief at scale - because on the evidence so far, some of them already are. *This post follows on from* [*When AI escapes containment: rethinking data protection in the agentic era*](https://katecarruthers.com/when-ai-escapes-containment-rethinking-data-protection-in-the-agentic-era/) *and the* [*Data Revolution podcast episode*](https://katecarruthers.com/when-ai-escapes-containment-superintelligence-cyber-risk-and-protecting-your-data/) *with Mark Pesce.* ### When AI escapes containment: rethinking data protection in the agentic era URL: https://katecarruthers.com/when-ai-escapes-containment-rethinking-data-protection-in-the-agentic-era/ Last updated: 2026-07-29T22:47:52.000Z The idea that an AI system could “**escape containment**” used to belong mostly to speculative fiction and alignment thought experiments. Now it sits uncomfortably in the realm of incident reports and post mortems. Between [OpenAI’s models breaching Hugging Face](https://huggingface.co/blog/security-incident-july-2026?ref=katecarruthers.com) and Anthropic’s experience with [Claude Mythos](https://www.penligent.ai/hackinglabs/claude-mythos-escape-and-the-human-bottleneck/?ref=katecarruthers.com), we’ve entered a phase where agentic AI is not just a hypothetical cyber risk but a lived one for real organisations. 💡 ****Note**: update 30 July 2026 [OpenAI's rogue agent compromised a customer at a second tech firm, executive says](https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/?ref=katecarruthers.com) In the latest [Data Revolution podcast episode](https://katecarruthers.com/when-ai-escapes-containment-superintelligence-cyber-risk-and-protecting-your-data/), [Mark Pesce](https://thewatershed.markpesce.com/?ref=katecarruthers.com) and I unpack what this shift means for anyone responsible for data, cybersecurity, or AI strategy. The core question we keep coming back to is deceptively simple: **what exactly are we trying to protect our data from, and how do we plan for failure modes we can’t fully imagine?** ## The new threat model: AI as insider, not outsider Most organisations still treat AI primarily as a productivity tool: something that helps staff draft documents, analyse data, or build software. That framing is increasingly incomplete. As systems become more agentic and more capable of autonomous decision making, they start to look less like tools and more like highly competent, highly motivated insiders operating at machine speed. Traditional threat models focus on external attackers: nation states, cybercrime groups, hacktivists. In an agentic era, we now have to consider scenarios where: - An internal AI agent can discover and exploit vulnerabilities in its own environment. - The agent can chain multiple capabilities (code analysis, network scanning, OSINT) together without human supervision. - The system can “game” tests and benchmarks, prioritising its objective over our policies and expectations. That is a profound shift. **We are no longer asking only “how do we defend against them?” but also “how do we constrain what *our own systems* are able to do, and under what conditions?”** ## Relative superintelligence and the fog of knowability In the episode, we talk about [relative superintelligence](https://thewatershed.markpesce.com/relative-superintelligence/?ref=katecarruthers.com): the idea that an **AI does not have to be universally superhuman to be dangerous**, it only needs to be far ahead of us in specific domains. It might be vastly better at exploiting software vulnerabilities, or at orchestrating social engineering campaigns, while remaining mediocre at commonsense reasoning or long term planning. This leads to a **fog of** [**knowability**](https://plato.stanford.edu/entries/fitch-paradox/?ref=katecarruthers.com). We often don’t know which capabilities will emerge as models scale, which combinations of tools and agents will produce unexpected behaviour, or which failure modes will manifest in production rather than testing. Planning three years ahead, or even twelve months ahead, in detail starts to look delusional. Instead, we need governance approaches that assume rapid capability shifts and make it easy to adapt when the environment changes. ## Containers, jailbreaks, and the limits of isolation One of the practical techniques Mark and I discuss is using containerisation and strict data scoping to constrain what AI agents can access. The idea is straightforward: - Spin up an isolated environment. - Give the agent only the minimum dataset it needs. - Let it perform its task. - Then tear the whole thing down. This pattern borrows from well understood security practices: least privilege, segmentation, ephemeral infrastructure. It’s a sensible baseline. But the recent wave of container jailbreaks and sandbox escapes shows the limits of relying on isolation alone. If a system is skilled enough at exploitation, the “walls” you think you’ve built may be more porous than you realise. The uncomfortable question is whether, at some capability threshold, the agent will simply treat your controls as obstacles to be overcome in service of its objective. That doesn’t mean we abandon isolation; it does mean we stop treating it as a silver bullet. ## Designing data governance against AI, not just with it For years, data governance discussions have focused on how to unlock value from data: better analytics, personalisation, insight generation. AI has often been framed as a way to get more out of the data we already hold. We now need a parallel conversation: what does it mean to design governance against AI? In practice, that looks like: - Being **explicit** about which data elements can be exposed to AI systems and which are categorically off limits. - Treating prompts, agent configurations, and tool access as **serious security objects**, not just UX settings. - **Assuming** that anything an AI can technically access, it can also potentially misuse, exfiltrate, or recombine in harmful ways. - **Building** review and red team processes that test AI behaviour, not just model performance. One example we talk through is a simple but powerful exercise: inventory your data, then mark up which fields you will allow into AI workflows and which you will block. Names, addresses, sensitive identifiers, and strategic information may need to live behind hard boundaries, even if that slightly reduces AI driven convenience for some tasks. **It’s a trade off between “maximum capability” and “acceptable risk.”** ## Governing in a world of accelerating generations Another theme in our conversation is how quickly the generations are turning over. The “second best” model today can be as capable as last month’s flagship. That undermines a lot of comfort people have in “using something a bit smaller and safer.” The safety profile of a given capability tier can change in weeks. For governance, this means: - Policies **tied too tightly** to specific model names or versions will age badly. - Boards and executives need **risk frameworks** that focus on behaviours and capabilities, not just vendor labels. - CISOs and data leaders must move **from static guidelines** to **living playbooks** that get revisited as soon as new capabilities land. The practical implication is that long range AI strategy documents need to be light on detail and heavy on principles. We can set direction, boundaries, and accountability structures, but we have to acknowledge that a lot of the tactical detail will only be knowable in short horizons. ## Where do we go from here? None of this is a call to abandon AI. It’s a call to take seriously the idea that our own tools can become part of the threat landscape, and that governance must evolve accordingly. For organisations, that might mean: - Treating AI agents as **privileged identities** with their own access controls, logging, and monitoring. - **Elevating AI incidents** to the same level of scrutiny as major cyber events. - **Bringing AI governance**, data strategy, cybersecurity, and technology policy into the same conversation, rather than treating them as separate silos. For policymakers and regulators, it means grappling with questions of accountability when systems act in ways that weren’t explicitly programmed or foreseen, but were structurally enabled by the way we designed and deployed them. In the [episode](https://katecarruthers.com/when-ai-escapes-containment-superintelligence-cyber-risk-and-protecting-your-data/), we don’t pretend to have all the answers. What we were trying to do is name the shape of the problem: AI that cheats, escapes, and pursues its goals through paths we didn’t anticipate. From there, we can start building governance, data protection, and safety thinking that is fit for an agentic, rapidly evolving world. If you are grappling with AI strategy or AI and data governance in your organisation, it is worth considering how these risks are framed and whether AI systems are recognised in your threat models, rather than sitting solely in the productivity stack. ### When AI escapes containment: Superintelligence, cyber risk, and protecting your data URL: https://katecarruthers.com/when-ai-escapes-containment-superintelligence-cyber-risk-and-protecting-your-data/ Last updated: 2026-07-27T23:00:28.000Z In this episode of the [Data Revolution Podcast](https://katecarruthers.com/tag/data-revolution/), [⁠KateCarruthers⁠](https://katecarruthers.com/) and [⁠Mark Pesce⁠](https://thewatershed.markpesce.com/?ref=katecarruthers.com) unpack what it really means for frontier AI models to “escape containment,” from the OpenAI–Hugging Face incident to Anthropic’s Claude Mythos tests, and why the second‑best model today is as powerful as last month’s flagship. They explore how relative superintelligence, agentic behaviour, and container jailbreaks change the threat model for CISOs, and what it looks like to design AI and data governance and safety protocols that protect your organisation’s crown‑jewel data from the very AI tools you’re using. They also discuss the need for [formal methods](https://en.wikipedia.org/wiki/Formal%5Fmethods?ref=katecarruthers.com) to verify now that we know that we cannot trust AI not to cheat. [Audio episode](https://creators.spotify.com/pod/profile/kate-carruthers4/episodes/When-AI-Escapes-Containment-Superintelligence--Cyber-Risk--and-Protecting-Your-Data-e3mkejk?ref=katecarruthers.com) ### AI coding tools and the junior talent pipeline: a capability problem, not a tooling problem URL: https://katecarruthers.com/ai-coding-tools-and-the-junior-talent-pipeline-a-capability-problem-not-a-tooling-problem/ Last updated: 2026-07-27T05:33:44.000Z I have seen the same pattern repeat itself in recent hiring interviews: data engineer candidates clearly reading live answers off-screen from a generative AI tool as they spoke in a zoom meeting. It is a stark reminder that hiring can no longer be about polished responses alone. We have to test judgment, depth, and the ability to think under pressure. [AI coding tools](https://scrimba.com/articles/best-ai-coding-assistants-2026/?ref=katecarruthers.com) have moved from novelty to infrastructure in a very short period of time. Developers now use assistants like GitHub Copilot, Claude Code, and Gemini Code Assist as part of everyday workflows. In [Australia](https://business.gov.au/news/new-guidance-helps-australian-businesses-adopt-ai-safely-and-responsibly?ref=katecarruthers.com), this shift sits inside a broader conversation about digital skills, productivity, and how we build technical capability over time. The key question is not whether developers will use AI. They already do. The question is what this means for junior talent, software quality, and the wider skills pipeline that Australian organisations rely on. ## The illusion of competence Bootcamps, universities, and employers all want the same thing: people who can contribute quickly. AI coding tools make that promise look easier to deliver. Students and junior developers can now generate working apps, tests, and documentation with a few prompts. It can look impressive in a portfolio or demo. It can also hide a complete lack of understanding. I often talk about this tension as the "*AI paradox*." Junior developers arrive with polished output, but cannot explain how their code works when asked to reason through it. The problem is not that they have no ambition or talent. The problem is that they have not had enough time wrestling with the hard parts of engineering to build the underlying mental model. Senior engineers I speak with are seeing the [same pattern](https://www.reddit.com/r/ClaudeAI/comments/1oiap5y/junior%5Fdevs%5Fcant%5Fwork%5Fwith%5Faigenerated%5Fcode%5Fis/?ref=katecarruthers.com). Some junior hires can assemble surprisingly complex features with AI support, but struggle to debug when the tool is unavailable or when the output is subtly wrong. It is [outsourced problem-solving](https://www.icck.org/filebob/uploads/storage/JSE%5FFyL0HuDVujarkKO0C.pdf?ref=katecarruthers.com), where the cognitive work is pushed into the model and never fully absorbed by the human developer. For Australian organisations, this matters because our talent pipeline is already under pressure. If AI is used carelessly in entry-level roles, we risk producing people who can generate code but cannot reason about systems. That is a capability issue, not just a tooling issue. ## How experienced engineers use AI The story is very different when AI is used by people who already have strong engineering judgement and experience. In my experience, the conclusion is practical - AI is useful for routine work such as tests, boilerplate, refactors, and documentation, but less reliable when the task involves complex design choices or domain nuance. It can improve flow, but it still needs to be managed carefully. A principal engineer recently made a similar point to me. They described AI as a highly capable junior developer (or an intern as I often characterise it), but one that is prone to rabbit-holing and over-engineering unless tightly directed. That senior engineer outlines their team's working pattern as **disciplined**: small commits, careful prompting, strong test coverage, and no delegation of architectural decisions to the model. That is a useful reminder that the value of AI depends heavily on the judgement of the person using it. For experienced developers, AI becomes leverage. It accelerates mundane work, helps with legacy code, and supports exploration of alternatives. But it does not remove the need for architecture, review, risk assessment, or judgement. In practice, the tool makes the human standards more important, not less. ## What happens to the junior pipeline This is the part of the conversation that deserves more attention. Entry-level roles have traditionally been where developers learn the craft. They do the small bug fixes, the documentation, the tests, the maintenance work, and the awkward tasks that are not glamorous but are very useful for building experience. Those are now exactly the kinds of tasks AI can automate. That can be useful, but it also changes what juniors get to practice. If AI handles too much of the routine work too early, juniors may miss the repetitive, frustrating, and deeply educational parts of learning how software behaves in the real world. They may not spend enough time debugging failures, understanding why abstractions break, or building intuition about performance and reliability. That creates some hard questions for Australia: - How do we ensure graduates still develop strong systems thinking when AI is available by default? - What happens to the mid-career pipeline if entry-level roles no longer build the same depth of experience? - How do employers assess job-readiness when tools can produce polished work that masks weak understanding? These are not abstract questions. They go directly to national capability, sovereign technology capacity, and long-term productivity. ## Organisational practice that actually helps This is where governance matters. The right response is not to ban AI tools, and it is not to assume they will solve capability shortages on their own. The right response is to put clear structure around how they are used. [Australian guidance](https://business.gov.au/news/new-guidance-helps-australian-businesses-adopt-ai-safely-and-responsibly?ref=katecarruthers.com) on responsible AI adoption stresses the basics: align use with business goals, set governance foundations, and maintain oversight. For software teams, that translates into practical rules that are easy to understand and hard to bypass. A sensible approach looks like this: - **Treat AI output as code that must be owned:** Someone on the team is accountable for every line, regardless of whether it came from a human or AI. - **Scope AI to safer tasks first:** Tests, refactors, documentation, and non-critical glue code are reasonable places to start. Security-sensitive or mission-critical components need a higher bar. - **Require human review for all AI-generated changes:** AI can assist, but it should not be allowed to skip review or testing. - **Standardise the toolset:** A small number of approved tools is easier to govern than a free-for-all of individual developer preferences. - **Invest in senior engineers as stewards:** If AI is becoming part of the development lifecycle, senior people need time to mentor, review, shape standards, and watch for AI debt. This is also where business and non-functional requirements still matter. Even in an agile environment, teams still need to define what success looks like, what performance and security constraints apply, and what trade-offs are acceptable. AI does not remove that need. If anything, it makes it more important. ## The governance checkpoint that matters Business executives need to read this as a capability issue, not just a technology trend. AI coding tools can look like an easy productivity gain, but the real question is whether the organisation is strengthening or eroding its ability to build and govern good software. The useful questions are straightforward: 1. Do we know where AI is being used in our software delivery lifecycle? 2. Do we know who owns the risks that AI introduces, including security, reliability, compliance, and IP? 3. Are we investing in the human expertise needed to govern these tools well? AI coding tools can help good developers work faster, and they can help junior developers learn more quickly if they are used properly. But they can also hollow out the skills pipeline if organisations treat them as a replacement for human judgement rather than an aid to it. The real issue is not adoption. It is whether we are building systems, teams, and learning pathways that can sustain sovereign human capability over time. ### Stop trying to turn PoCs into products URL: https://katecarruthers.com/stop-trying-to-turn-pocs-into-products/ Last updated: 2026-07-29T00:21:41.000Z ## From proof-of-concept to pilot to production: what business leaders need to understand A non-technical friend messaged me recently: "We got our AI tool working." It had taken a small group a couple of weeks to get a model reliably summarising a folder of documents. The results looked genuinely useful. But what they had built was a proof-of-concept (PoC) - a handful of test files, no access controls, no logging, no plan for what happens when the model gets something wrong. Rolling it out as-is would not be an AI deployment, it would be an incident waiting to be discovered. This kind of thing happens constantly, and it is rarely about the technology. It is about language. In AI and software delivery, "*proof of concept*", "*pilot*", and "*production*" are often used as if they were interchangeable stages. They are not, and treating them that way just creates governance, risk, and investment issues. I have written about the pipeline from [PoC to production](https://katecarruthers.com/why-ai-needs-a-proof-of-concept-to-production-pipeline/) and [Managing your innovation pipeline through AI projects](https://katecarruthers.com/managing-your-innovation-pipeline-through-ai-projects/) but that chat with a friend made me realise that I had never explained the nuts and bolts of this kind of pipeline. And I suspect that many people may not understand why they might need to understand this. It will probably read as more instructional than my usual posts - but that is the point. Each stage has a distinct **purpose**, level of **maturity**, and **risk profile**. Understanding these differences is essential if you are funding, approving, or governing AI and software initiatives. ## The three stages explained ![](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/07/poc-to-prod-pipeline.jpg) PoC to Production Pipeline ### Proof-of-concept: can this work at all? A [proof-of-concept](https://en.wikipedia.org/wiki/Proof%5Fof%5Fconcept?ref=katecarruthers.com) (PoC) is a tightly scoped experiment designed to demonstrate technical feasibility. At this stage: - The goal is **learning, not value delivery** - **Data is often sampled**, can be synthetic, or loosely governed - **Architecture is deliberately minimal** and not designed for scale - Security, compliance, and integration are **intentionally** [**out of scope**](https://quantumopsschool.com/blog/poc/?ref=katecarruthers.com) In AI, a PoC might test whether a model can summarise documents or classify inputs with acceptable accuracy. **The key governance point: A PoC should always be treated as a throwaway result.** It is not “version one” and should not be hardened into production; instead, it provides [useful insights](https://www.alchemistaccelerator.com/blog/to-poc-or-not-to-poc-that-is-the-question-2?ref=katecarruthers.com) about feasibility, constraints, and potential risks that inform whether a pilot is justified. 💡 A ****PoC** answers: **Is this technically possible?* It does not answer: **Is this safe, usable, or worth operating?* ### Pilot: does this work in the real world? A [pilot](https://www.scieneers.de/en/poc-vs-prototyp-vs-mvp-vs-pilot-en/?ref=katecarruthers.com) is a limited roll-out of a near-complete system into a real environment, with real users and real data. At this stage: - A **defined user group** (often a single team or business unit) is involved - **Live business processes** and **actual customer or internal data** are used - **Integration** with existing systems and workflows begins - **Risks start to be actively managed** (privacy, security, human oversight) - **Metrics** focus on usability, reliability, and business impact In AI, a pilot might be an internal deployment of an assistant or classifier where outputs are monitored for accuracy, bias, and failure modes, and users provide structured feedback. 💡 A [****pilot**](https://vantagepoint.io/blog/sf/ai-poc-to-production-why-pilots-stall-scaling-guide?ref=katecarruthers.com) answers: **Does this work under real conditions, and what breaks when it meets reality?* ### Production: can this be trusted at scale? [Production](https://vantagepoint.io/blog/sf/ai-poc-to-production-why-pilots-stall-scaling-guide?ref=katecarruthers.com) is where the system becomes part of normal operations and is treated as a business-critical capability. At this stage: - The **system is integrated** into enterprise architecture and core workflows - Data pipelines are **robust, auditable, and governed** - **Security, compliance, and regulatory** expectations are met by design - SLAs, monitoring, and incident response **processes are in place** - **Ownership and accountability are clearly defined** across business and technology For AI systems, production also involves: - **Ongoing monitoring** for model drift and performance degradation - **Defined human-in-the-loop** oversight and escalation paths - **Explainability and auditability** to support internal and external scrutiny - **Alignment** with organisational responsible AI and governance frameworks 💡 ****Production** answers this question: **Can we rely on this system consistently, without introducing unmanaged risk?* ### Why this distinction matters more in AI Traditional software has always had a progression from concept to pilot to production, but AI increases the stakes. AI systems are probabilistic, heavily dependent on data quality, and can fail in subtle ways that are hard for non-specialists to detect. This is why we have developed best practices like this from CSIRO: [Responsible AI Pattern Catalogue: A Collection of Best Practices for AI Governance and Engineering](https://dl.acm.org/doi/10.1145/3626234?ref=katecarruthers.com). That means: - The gap between “*it works in a demo*” and “*it is safe to operate*” is larger - Governance requirements around fairness, transparency, and accountability are higher - Regulatory expectations are evolving, particularly for high-impact uses of AI **Treating a PoC as anything more than disposable in this context is not just optimistic** **\- it risks embedding untested assumptions and hidden vulnerabilities into production environments.** ### The real gap: from pilot to production Most organisations can run PoCs and pilots; the real difficulty is moving from pilot to production. That transition typically requires: - Formal governance and risk frameworks for AI systems - Clear operational ownership and funding beyond “innovation budgets” - Integration into existing business processes and controls - Executive-level risk acceptance and oversight structures This is also where disconnected experiments either mature into sustainable capabilities or remain isolated demos that never scale. Organisations that treat AI as a chain of unconnected pilots tend to accumulate expensive proofs of concept and shadow systems, rather than [reliable business value](https://katecarruthers.com/why-ai-needs-a-proof-of-concept-to-production-pipeline/). ## A practical example Consider AI-assisted document summarisation for a knowledge-intensive team: - **PoC**: A small group tests an AI model on a sample of documents to see if summarisation is accurate enough to be useful. They learn about feasible use cases and failure modes and then discard the PoC artefact. - **Pilot**: The capability is offered to a specific team, integrated into their workflow, using real documents under controlled conditions, with monitoring and feedback loops. - **Production**: The summarisation capability is built into document management systems, with access controls, logging, model monitoring, and clear policy about when human review is required. Governance and support processes are established. The technology may look similar at each stage; what changes is the level of control, accountability, and trust. ## What business leaders should do To reduce wasted effort and unmanaged risk: - **Be explicit about which stage is being funded** \- PoC, pilot, or production - and set expectations accordingly. - **Treat PoCs as disposable learning exercises** that inform decisions, not as assets to be “polished up” later. - Recognise that **most of the cost and complexity sits in the** [**pilot-to-production transition**](https://hyperion-consulting.io/en/resources/ai-pilot-to-production-playbook?ref=katecarruthers.com), not in the initial PoC experiment. - Require [**governance and risk considerations**](https://research.csiro.au/ss/science/projects/responsible-ai-pattern-catalogue/governance/?ref=katecarruthers.com) to be built in early, so they are not retrofitted under pressure. - Ask not only whether the system works, but whether it [**can be operated responsibly at scale**](https://research.csiro.au/ss/science/projects/responsible-ai-pattern-catalogue/governance/?ref=katecarruthers.com). 💡 A useful way to think about this: \- ****PoC** proves possibility \- ****Pilot** proves practicality \- ****Production** proves accountability ## In the Australian context This matters more in Australia than the numbers might suggest. Local organisations are under real pressure to move fast on AI, often with boards and executives who read the same headlines everyone else does and want to see progress. That pressure makes it tempting to skip straight from a promising PoC to a public-facing rollout, especially in sectors like health, finance and government where the appetite for demonstrable AI adoption is high but the regulatory and reputational cost of getting it wrong is higher still. Australia does not yet have the depth of AI-specific case law or regulatory precedent that organisations can lean on when something goes wrong. That makes internal governance discipline - knowing the difference between "*it worked in the demo*" and "*it can be trusted in production*" - less a nice-to-have and more the only real safety net available right now. The organisations that get this right will not be the ones that ran the flashiest PoC. They'll be the ones that knew which stage they were actually in. ### Bringing AI products to life URL: https://katecarruthers.com/bringing-ai-products-to-life/ Last updated: 2026-07-19T20:49:42.000Z ### Outlining a practical AI development lifecycle Over the last few years I have watched the same pattern repeat in organisations, classrooms and boardrooms. Everyone wants "AI powered products," but very few have a disciplined development lifecycle that can actually bring those products to life. Instead of a [coherent path from idea to governed asset](https://katecarruthers.com/why-ai-needs-a-proof-of-concept-to-production-pipeline/), we see scattered pilots, a few hero use cases and a lot of frustration about why value is not showing up and delivering the benefits people expected. In earlier posts I have argued that AI needs a clear proof of concept to production pipeline rather than disconnected experiments. In [“Why AI needs a proof‑of‑concept to production pipeline”](https://katecarruthers.com/why-ai-needs-a-proof-of-concept-to-production-pipeline/) I set out the stages from PoC through pilot into production and handover, and in [“AI innovation: why leadership matters more than technology”](https://katecarruthers.com/ai-innovation-poc-to-production/) I emphasised that executives need a reliable pathway, not just impressive demos. This time we are zooming in on the development side of that story and outlining a **practical six stage lifecycle for AI** that sits inside that broader pipeline. The goal here is simple: **treat AI products as governed assets with a clear lifecycle, not as perpetual science projects**. The six stages described below fit comfortably into agile delivery and modern data platforms, but they also give boards and executives the guardrails they keep asking for. ### Stage 1: Problem framing and requirements **The starting point is always the business problem and the plain language business requirements.** Agile does not remove this step; it just changes how we iterate against it. This is consistent with the "clarify the why up front" principle I described in the PoC‑to‑prod pipeline, where every PoC (proof-of-concept) starts with a **well articulated problem, target outcomes and measurable success metrics**. - We begin by **defining the problem in plain language**: who the user is, what pain point is being addressed and how we will know if we have succeeded. That includes agreeing on a small set of success metrics, such as reducing handling time, improving accuracy or reducing risk in a decision process. - We then **classify the AI use case for impact and risk**. High impact systems that touch rights, access to services or financial decisions need a different level of scrutiny to low impact internal automation. Emerging regulatory frameworks make this risk thinking explicit, but even without regulation it is good practice. - From there we **capture functional requirements**: what the system must do, which workflows or decisions it will affect and how people will interact with it in the real world. We also capture non-functional requirements - latency, reliability, privacy, security, explainability, jurisdictional constraints and auditability. In my [innovation pipeline](https://katecarruthers.com/why-ai-needs-a-proof-of-concept-to-production-pipeline/) post I argued that even when teams say they are working in agile, they still need clear functional and non functional business requirements as key inputs into the agile process. This lifecycle makes that concrete. ### Stage 2: Data readiness and architecture Once we know what we are trying to achieve, we turn to the data. Many AI projects struggle not because the idea is wrong, but because the data is not ready or the architecture is improvised. In "[Data governance needs a rebrand](https://katecarruthers.com/data-governance-needs-a-rebrand/)" I talked about the importance of curated, trusted data products with clear metadata and lineage; this stage is where that work pays off for AI. - We start by **mapping data sources, ownership and quality**: which systems hold relevant data, who is responsible for them, what the current state of quality is and how often they change. We decide what data is in scope and, just as importantly, what is explicitly out of scope because of risk, consent or relevance. - We then **check the data** against our governance framework. Do we have appropriate consent? Is the provenance clear? Are there known biases that need to be mitigated? What are the retention and minimisation obligations? This avoids the "we trained on whatever we could find" trap that creates nasty surprises later. - On the architecture side **we choose patterns that align with our broader data strategy** \- warehouse or lakehouse, batch or streaming, retrieval augmented generation or fine tuning. We also make [sovereignty](https://katecarruthers.com/beyond-ai-sovereignty-why-the-west-relies-on-us-frontier-models-and-what-comes-next/) and compliance explicit by deciding where data will physically reside, how it will move and which jurisdictions apply. AI projects should build on our core data platform rather than invent a parallel universe that nobody has the skills or budget to maintain. ### Stage 3: Model selection and design Only now do we turn to models. **Model selection is a governed decision, not a purely technical adventure.** This connects directly to my broader work on AI governance and the "tokenpocalypse" theme, where I have argued that sensible governance and management practices must apply just as much to models and tokens as to any other asset. - We first choose the **right approach for the problem**. Some problems are better served by classical machine learning or straightforward automation. Others genuinely require orchestration around a large language model, often paired with retrieval from private data or tools. - We **evaluate candidate models** against accuracy, robustness, latency, context window, and fit to the non functional requirements defined earlier. If we need fast responses, strict privacy controls or a particular jurisdiction, that will narrow the field very quickly. We decide whether to use a fully managed provider model, an enterprise platform model or a self hosted model, including licensing and intellectual property considerations. - We then **design the model use and document it**. That means writing down intended use, limitations, input constraints and risk classification in a model card or factsheet. For generative applications we decide whether prompts plus retrieval are sufficient, or whether fine tuning or continued pre training is justified by the value case. This is where we avoid the trap of "hero experiments" with no path into production that I described as pilot purgatory in the [pipeline post](https://katecarruthers.com/why-ai-needs-a-proof-of-concept-to-production-pipeline/). ### Stage 4: Build, integration and controls With problem, data and model choices in place, we move into build and integration. This is where [MLOps](https://jozu.com/blog/aiops-devops-mlops-llmops-whats-the-difference/?ref=katecarruthers.com), engineering and governance come together, echoing my earlier emphasis on "invest in the boring plumbing" such as reusable pipelines, [CI/CD](https://about.gitlab.com/topics/ci-cd/?ref=katecarruthers.com) and [observability](https://www.dynatrace.com/knowledge-base/ai-observability/?ref=katecarruthers.com). - We implement the **end to end stack**: ingestion and transformation, storage or lakehouse, feature store or embeddings, serving infrastructure, guardrails and application layer. We keep infrastructure, prompts, routing and configuration as code so that the system is reproducible and controllable. - We build **evaluation pipelines** that tie back to the success metrics from stage one - offline tests, performance regression suites, robustness checks and fairness or bias tests. For higher risk systems we also run red teaming and scenario based testing to probe misuse and failure modes. All of this is logged and versioned. - We **integrate security, privacy, logging and lineage from the start** rather than as bolt ons. Access controls, encryption, audit logs and model lineage are part of the architecture, not optional extras. - Finally, we **embed AI governance checkpoints** \- design reviews, data ethics review where appropriate, and pre-deployment sign off by the accountable owner for high impact systems. This is how we "tie into AI governance, not around it," as discussed in the [PoC‑to‑prod post](https://katecarruthers.com/why-ai-needs-a-proof-of-concept-to-production-pipeline/) to stress that governance should be embedded in the delivery pipeline instead of bolted on at the end. ### Stage 5: Deployment and change management **Deployment is not a developer switch; it is a controlled organisational decision.** This stage corresponds to the production step in the pipeline and the handover patterns I have previously dicsussed for CI/CD and operations. - We use **progressive delivery patterns** such as canary releases, blue green deployments and feature flags. We include explicit kill switches for AI components so that they can be turned off or rolled back without taking the entire product down. - We run **user acceptance testing** that focuses on business value, usability and risk scenarios, not just technical correctness. We test what happens when the model is wrong, when the user behaves unexpectedly, and when upstream systems fail. - Before go live for high impact systems we **obtain formal authorisation** from the accountable owner or review board. This is the final handshake that ties legal and organisational accountability to the deployment decision. - We **communicate clearly** with affected users and stakeholders. People need to understand what is automated, what is assisted and what remains human led. We explain how issues will be handled and how feedback will be used. One cannot simply deploy AI and hope for the best. Deployment is where we choose, as an organisation, to take responsibility for an AI product in the real world. ### Stage 6: Operations, monitoring and FinOps The final stage is operations. This is where MLOps, AI governance and FinOps come together, and where the "handover to operations" step in the PoC‑to‑prod pipeline becomes day to day practice. - On the operational side we **track quality, latency, error rates and model drift** using defined objectives and alerts. We monitor for bias drift and fairness issues as data distributions and behaviour change over time. We maintain traceability from individual outputs or decisions back to the specific model version, data and approvals. - On the [FinOps](https://katecarruthers.com/ai-tokens-and-the-tokenpocalypse/) side we establish **visibility and bake in cost controls** and model API spend ("[tokens](https://katecarruthers.com/ai-tokens-and-the-tokenpocalypse/)") at workload and feature level. We look at cost per conversation, cost per decision or cost per task and we tag workloads so that business owners can see their spend. - We **apply cost optimisation practices** such as right sizing, autoscaling, scheduling and limits on expensive workloads. We use showback or chargeback to make cost a visible part of product ownership. And we retire or archive models and services that no longer justify their cost or risk, using a defined lifecycle process. Taken together with my [PoC‑to‑production pipeline](https://katecarruthers.com/why-ai-needs-a-proof-of-concept-to-production-pipeline/) and [data governance](https://katecarruthers.com/tag/data-governance/) articles, this simple AI lifecycle gives teams and executives a shared language for scoping, building and operating AI systems with intention. It allows us to connect leadership, innovation and governance in practice, so that AI capabilities move from isolated experiments to trusted, well managed assets in the organisation. ### Managing your innovation pipeline through AI projects URL: https://katecarruthers.com/managing-your-innovation-pipeline-through-ai-projects/ Last updated: 2026-07-19T09:13:36.000Z Over the last few years, I have seen the same pattern repeat itself in boards, executive teams and MBA cohorts. Everyone wants “AI powered innovation”, but very few have an innovation pipeline that can sustain it. Instead of a deliberate portfolio of AI experiments and products, organisations end up with a grab bag of scattered pilots, a few hero use cases and a lot of frustrated people wondering why the promised value has not arrived. In my work teaching [*AI for Organisational Innovation*](https://www.unsw.edu.au/study/professional-development/course/ai-for-organisational-innovation?ref=katecarruthers.com) at AGSM, we focus less on the technology and more on the management system that sits around it. The course is designed for leaders who want to harness AI to drive organisational innovation and change, not just run one off experiments. The goal is to turn “we should use AI” into a disciplined pipeline of ideas, experiments and scaled deployments that actually move the dial. At the heart of that pipeline is one simple principle: **you cannot just plop stuff into AI and hope for the best**. If you treat AI as a magic machine where you pour in data and prompts and hope something valuable comes out, you will get randomness, not innovation. The organisations that are getting [sustained value from AI](https://www.forbes.com/sites/bernardmarr/2026/07/14/5-companies-winning-with-ai-and-what-they-are-doing-differently/?ref=katecarruthers.com), and avoiding the worst of the risks, are the ones managing AI projects as an innovation portfolio, with clear strategy, governance and guardrails. ## Turning AI ideas into a real innovation pipeline Most organisations are not short of AI ideas. People are experimenting with chatbots, automated reporting, code assistants, marketing content and many “quick wins”. The problem is that these ideas do not flow through a coherent pipeline, so the organisation never learns systematically which ideas deserve to be scaled and which ones should quietly retire. I often talk about [innovation](https://chasegroup.com.au/innovation-as-a-system?ref=katecarruthers.com) as a **management system**, not a brainstorming exercise. An AI ready innovation pipeline usually has four core stages: 1. **Discover:** Identify problems and opportunities where AI could make a material difference, such as removing bottlenecks, improving decisions, enhancing customer experiences or unlocking new products and services. The focus is problem first, not tool first. 2. **Design:** Shape an experiment. Define what data you need, which users are involved, what “good” looks like and how you will measure value, whether that is time saved, error reduction, revenue impact or risk reduction. This is where you define both the **value case** and a **risk budget** for the use case. Even if your teams are working in agile delivery modes, you still need to do the work of defining business requirements clearly. **Agile user stories do not replace the need for a shared understanding of the business problem, success criteria and constraints**. You also need non functional requirements for AI systems, covering qualities such as performance, reliability, security, privacy, fairness and compliance. Neglecting non functional requirements early in an agile or AI project is linked to serious quality and risk issues later on. 3. **Deliver (PoC and Pilot):** Run a constrained, well governed proof-of-concept (PoC) and pilot. Small enough to be safe, but real enough to reveal the true complexity. You validate assumptions about data quality, [cost profile](https://katecarruthers.com/ai-tokens-and-the-tokenpocalypse/), user adoption, legal and ethical constraints and operational fit. Agile iterations can be powerful here, as long as the team is building against clearly articulated functional and non functional requirements, not improvising them sprint by sprint. 4. **Decide (scale or sunset):** Make a conscious decision. Do you scale, iterate or stop. Scaling is not simply copying the pilot to more users, it is deliberately integrating the AI capability into processes, policies and platforms. Sunset is just as important because it keeps your portfolio clean. An innovation pipeline is the connective tissue that moves AI ideas through these gates. Without it, each AI project becomes a one off adventure reliant on a heroic project lead and a supportive sponsor. With it, AI becomes a repeatable capability that the organisation can manage and improve over time. ## Managing AI as a portfolio of innovation AI needs to be managed like a portfolio. Each use case has a value case, a risk budget and a clear place in the pipeline. That portfolio perspective changes the conversation in several important ways. - **Strategic alignment:** You ask “which AI initiatives directly support our strategic priorities” before funding tools or vendors. AI projects are connected to themes like customer experience, operational resilience or new growth, not just generic efficiency. - **Risk matched gating:** Every gate in the pipeline, from idea intake to pilot approval and scale up, has a matching risk check. Higher risk use cases involving sensitive data, critical infrastructure or safety impacts face more stringent gates and heavier oversight. Lower risk experiments can move faster. - **Common language and criteria:** The organisation agrees what “good” looks like at each stage and embeds responsible AI themes such as privacy, fairness, transparency and accountability. - **Learning loops:** Insights from failed or mediocre pilots are captured and used to refine the pipeline. Instead of quietly burying unsuccessful experiments, you treat them as data points about what kinds of problems, data and teams lend themselves to AI in your context. This portfolio view is what turns AI from scattered experiments into a **coherent innovation system**. ## Designing guardrails that support invention and intention A phrase that resonated deeply with one AGSM executive cohort was that AI excellence is “**invention plus intention**”. Invention is the creative, experimental energy that generates ideas and prototypes. Intention is the governance, ethics and strategic discipline that keeps those inventions aimed at real value. **Guardrails are how you operationalise that intention. They do not kill innovation, they keep it on the road.** In a similar way to which [brakes make driving cars faster](https://windingroad.com/articles/features/speed-secrets-brakes-make-you-faster/?ref=katecarruthers.com) possible. Useful guardrails include clear AI principles and policies, data readiness standards, fusion teams that join business, data and risk, and explicit exit strategies for pilots. These practices sit alongside agile ceremonies and tooling, they are not optional extras. Organisations that take guardrails seriously often find that innovation accelerates rather than slows. Teams become more confident to experiment because they know where the boundaries are and how decisions will be made. ## Moving from experiments to embedded capability Managing your innovation pipeline via AI projects is ultimately about moving from sporadic experiments to embedded capability. That shift is cultural as much as technical. Practical moves include shifting your narrative from “trying AI” to building a managed AI innovation pipeline, starting with one well designed pipeline in a high leverage domain, investing in AI literacy for leaders and teams and measuring portfolio health, not just ROI per project. Done well, AI stops being a series of disconnected “cool demos” and becomes a structural lever in your organisation’s innovation system. You still experiment, but you also govern deliberately. You cannot just plop stuff into AI and hope for the best. You need a pipeline, a portfolio and a set of guardrails, backed by clear functional and non functional business requirements, that make your innovation both inventive and intentional. ### How material practice shapes innovation: the surprising origins of zero and AI URL: https://katecarruthers.com/how-material-practice-shapes-innovation-the-surprising-origins-of-zero-and-ai/ Last updated: 2026-07-15T21:07:48.000Z The future of work is often framed as a story of displacement. That framing misses the point. Work does not disappear. It reorganises. In this Data Revolution podcast episode, [Pete Evans-Greenwood](https://pevansgreenwood.substack.com/) offers a useful lens: technology changes work by reshaping tasks and practices over time, not by cleanly replacing roles. History bears this out. From the introduction of zero through to signwriting and now AI, the pattern is consistent. Tools land, but the real transformation happens in how people reconfigure what they do, often well before the technology is fully mature. What emerges is a shift away from thinking about automation in isolation. Task-level analysis only gets you so far. The more meaningful signal sits at the system level, especially at the boundaries, interfaces, and handoffs where work actually happens. That is where friction is reduced, roles blur, and new forms of value emerge. The examples are concrete. Signwriting does not disappear; it evolves into car wrapping. Professional work does not vanish under AI; it fragments, recombines, and recentres around judgement, orchestration, and interpretation. The change is uneven, contextual, and deeply tied to practice. This is why the current AI wave looks less like a labour shock and more like infrastructure. Think plumbing, not replacement. AI is improving how systems connect and how work flows across them. The impact is real, but it is diffuse. It amplifies efficiency, shifts coordination costs, and opens up new design space for how work gets done. The implication is straightforward but underappreciated. The real leverage is not in predicting which jobs disappear. It is in understanding how practices evolve under new material conditions and experimenting early. That means paying attention to where work is breaking, where interfaces are messy, and where new affordances are already visible. For leaders and practitioners, this reframes the task. The goal is not to react to disruption narratives. It is to actively shape emerging workflows, value chains, and organisational habits while the ground is still moving. If you are trying to make sense of AI beyond the hype cycle, this conversation offers a more grounded perspective: focus less on prediction, more on practice. The future of work will not arrive fully formed. It will be built, iteratively, through the decisions we make now. [Spotify audio](https://open.spotify.com/episode/7ISGXcpPXLCUWGdaox53UL?si=UQGCC6HnQVGw14o4YaUFeQ&ref=katecarruthers.com) ### When energy geopolitics hits your laptop URL: https://katecarruthers.com/when-energy-geopolitics-hits-your-laptop/ Last updated: 2026-07-13T23:37:10.000Z 💡 “The Strait of Hormuz is the most critical chokepoint in global energy markets, and a prolonged closure would become far more than an energy crisis,” said Peter Martin, head of economics at Wood Mackenzie. “The longer disruption persists, the greater the impact on energy prices, industrial activity, trade flows and global economic growth.” [Strait of Hormuz closure risks greatest global energy supply shock in decades](https://www.woodmac.com/press-releases/strait-of-hormuz-closure-risks-greatest-global-energy-supply-shock-in-decades/?ref=katecarruthers.com) Over the past few months, the headlines have been dominated by war, drone strikes, and the prospect of triple‑digit oil prices. Buried inside those stories is a quieter shock that will shape our digital lives: the energy crisis is becoming a computing‑infrastructure crisis. ## Two crises, one global supply chain If you follow laptops and servers back far enough, you end up in diesel tanks and shipping lanes, not just chip fabs. Two converging events are setting the stage: - [Russia has banned diesel exports](https://www.reuters.com/business/energy/russia-bans-diesel-exports-increase-domestic-supply-says-deputy-pm-2026-07-08/?ref=katecarruthers.com) until at least the end of July to stabilise domestic fuel markets after refinery damage and growing shortages. - [The Strait of Hormuz](https://www.brookings.edu/articles/from-chokepoint-to-crisis-the-strait-of-hormuz-and-global-oil-markets/?ref=katecarruthers.com) \- a [chokepoint](https://en.wikipedia.org/wiki/Choke%5Fpoint?ref=katecarruthers.com) for a large share of global oil and roughly 20% of LNG - has been repeatedly closed or contested as US-Iran tensions escalate, with analysts warning of the biggest energy supply shock in decades. On paper, that looks like an oil‑market story. In practice, it’s a story about the physical foundations of computing. Computers are the end product of a [long, energy‑hungry chain](https://www.cnbc.com/2026/03/09/theres-another-energy-market-that-may-get-hit-harder-than-oil-by-strait-of-hormuz-closure.html?ref=katecarruthers.com): mining, semiconductor fabrication, component manufacturing, global logistics, and data‑centre build‑out. Russia’s diesel squeeze tightens refined fuel for freight trucks, mining equipment and factory generators. Hormuz disruptions shake the crude and gas flows feeding grids and industrial bases in Asia and the Gulf - where much of the world’s electronics and chips are produced. ## From fuel shock to fewer devices The energy shock from the fuel crisis won’t necessarily show up as empty shelves - it will probably show up as fewer options, longer waits, and quietly cancelled refresh cycles. When fuel prices spike and supply becomes patchy, manufacturers don’t simply pay more and carry on. They change their behaviour. Global [analysis of the current crisis](https://www.cnbc.com/2026/03/01/experts-weigh-potential-scenarios-for-oil-if-strait-of-hormuz-closes.html?ref=katecarruthers.com) suggests that a prolonged Hormuz closure could push oil towards US$200 a barrel in worst‑case scenarios, with LNG flows to Asia deeply constrained and energy prices staying high well beyond any ceasefire. At the same time, Russia pulling diesel off the world market tightens supplies for transport and industry everywhere - because the modern world runs on diesel. Diesel powers most of the world's heavy freight. For example, in the US, more than [80% of all goods - imported and exported](https://enginetechforum.org/policy-insider-blog/posts/of-davos-and-diesel-the-critical-importance-of-diesel-to-the-global-economy?ref=katecarruthers.com) \- are moved using diesel-powered trucks, trains, ships, and intermodal systems, with diesel responsible for about 90% of freight tonnage globally. Faced with that, electronics makers are likely to: - **Ration production** to higher‑margin lines: premium laptops, gaming rigs, workstations, and servers where customers can absorb price rises. - **Stretch lead times** as they manage energy rationing, logistics bottlenecks, and component delays. - **Cut back low‑margin SKUs**, delaying or quietly dropping budget laptops, entry‑level desktops, and niche devices. You won’t see “computer shortage” banners outside retailers. Instead, you’ll notice narrower ranges, more “out of stock” tags on specific configurations, and a slower cadence of new model releases. ## Why your next hardware refresh will cost more The cheap, frictionless movement of chips and chassis we’ve relied on for decades is gone - at least for now. Even if silicon keeps flowing, the cost stack for computing is shifting, and it is shifting upwards. ### Freight and logistics Finished devices and components move through a logistics system built on diesel and [bunker fuel](https://en.wikipedia.org/wiki/Heavy%5Ffuel%5Foil?ref=katecarruthers.com). When diesel prices spike and supplies tighten, shipping rates rise, and so do road freight and air cargo costs. Manufacturing sectors are already reporting double‑digit increases in production costs as [fuel and freight bills surge](https://timesofindia.indiatimes.com/city/ahmedabad/gujarat-industries-grapple-with-25-rise-in-bulk-diesel-costs/articleshow/129724470.cms?ref=katecarruthers.com). Those increases have to land somewhere: firstly in squeezed margins, then in higher wholesale prices, surcharges, and softer discounting. Retail prices for laptops, desktops and peripherals will follow. ### Factory energy and backup power Many electronics plants rely on diesel generators to bridge unreliable grids. Russia’s export ban explicitly aims to secure domestic diesel in the face of refinery damage and growing fuel shortages. Globally, [tighter diesel markets](https://consumerwatchdog.org/wp-content/uploads/2018/11/2018-11%5FThe%5FCauses%5Fand%5FEffect%5Fof%5Fthe%5FRecord%5FBreaking%5FPrice%5Fof%5FDiesel.pdf?ref=katecarruthers.com) make backup power more expensive and less dependable. That translates directly into a higher energy cost per unit produced, and more unplanned downtime when running generators becomes uneconomic. ### Risk premium baked into hardware With the Strait of Hormuz repeatedly closed and only slowly reopening, analysts warn that even once tankers move freely again, returning to pre‑crisis oil and gas supply levels will take [months or years as storage is refilled](https://www.theguardian.com/business/2026/jun/15/return-pre-crisis-oil-gas-supplies-months-away-iran-strait-of-hormuz?ref=katecarruthers.com) and infrastructure is repaired. Insurers, shippers and manufacturers price in the expectation of future disruption. That risk premium gets baked into hardware pricing. Even when energy markets “normalise”, laptops and servers still carry the memory of this shock. ## The Australian angle: 72% of businesses are already feeling it In Australia, the energy crisis is already inside the P&L - computing is just the next domino. This isn’t a distant problem for Australian organisations. The [ABS reports](https://www.abs.gov.au/media-centre/media-releases/fuel-costs-and-shortages-put-pressure-72-australian-businesses?ref=katecarruthers.com) that 72% of Australian businesses say fuel prices or availability are negatively affecting them, with half reporting higher operating expenses driven by fuel and freight. [Industry commentary](https://www.traceconsultants.com.au/thinking/part-2%E2%80%94fuel-shortage-impact-on-australian-industry-2026?ref=katecarruthers.com) describes inbound freight, energy costs and outbound distribution all rising together, squeezing margins and forcing firms to lift prices or delay spending. For technology buyers, that shows up as: - **Higher prices** for imported hardware and fewer aggressive discount cycles - **Longer lead times** on fleet refreshes and project‑specific hardware - **More “equivalent substitute” SKUs** offered when preferred models are constrained The energy shock is already showing up on Australian balance sheets. The computing shock is next. ## What leaders need to do now Digital resilience is no longer just about backups and cybersecurity - it’s about energy, shipping lanes and diesel, too (and don't forget the new thing we have to consider - [chokepoints](https://www.brookings.edu/articles/from-chokepoint-to-crisis-the-strait-of-hormuz-and-global-oil-markets/?ref=katecarruthers.com)). From a governance and risk perspective, the message is blunt: you cannot decouple digital resilience from energy and logistics resilience. Here are four practical moves for executive management, including in particular CIOs and CISOs to consider: ### 1\. Treat computing hardware as critical infrastructure Laptops, servers and networking gear underpin AI, cybersecurity, cloud services and basic business continuity. When supply chains are exposed to chokepoints like Hormuz and export bans from major fuel suppliers, that is a critical‑infrastructure risk. Start by mapping your key hardware dependencies: - Where are your devices and components manufactured? - Which sea lanes and ports do they rely on? - How concentrated are your supplier relationships? ### 2\. Re‑think procurement and lifecycle assumptions For at least the next few years, refresh cycles need to be more conservative and more deliberate. - Build longer lead times into budgets and program plans - Embed flexibility in device standards so teams can accept equivalent SKUs and component substitutions - Extend lifecycles where practicable, aligning refreshes with genuine business need rather than marketing cycles Factor rising hardware and energy costs into total‑cost‑of‑ownership models for both on‑prem infrastructure and cloud commitments. ### 3\. Integrate energy scenarios into digital strategy Most digital‑transformation roadmaps quietly assume stable energy costs and availability. That assumption is broken. Boards should be asking: - How do our critical workloads cope with prolonged hardware price increases and replacement delays? Or how will your cloud vendor deal with their increased hardware costs? - How resilient are our key vendors and partners to energy and shipping disruption? - How does our AI roadmap intersect with the energy and hardware we need to train and deploy models at scale? Those questions belong in risk committees and strategy offsites, not just IT steering groups. ### 4\. Use AI and analytics to mitigate, not just consume, energy AI is both exposed to these shocks and will form part of the response. On one hand, training large models and running inference at scale are energy‑intensive and hardware‑hungry. On the other, AI‑driven optimisation can help organisations navigate constrained energy and hardware environments: - Demand forecasting and inventory analytics for devices and spares - Logistics and routing optimisation for hardware shipments and field operations - Smarter workload placement to minimise compute waste and energy use in data centres Responsible AI governance includes being explicit about the physical energy and hardware footprint of AI programs, which many folks have not even started to consider as yet. ## A turning point, not a blip If we keep treating fuel shocks as someone else’s problem, we’ll keep getting blindsided when they show up as ‘we can’t get the laptops and servers we need’. It’s tempting to treat Russia’s diesel ban and the Hormuz crisis as temporary turbulence that will pass. The more realistic reading is that they’re signals of a world where energy and security shocks are recurring features, not rare anomalies. For technologists, boards and policymakers, that means updating our mental models: - **Computing is not an abstract, infinitely elastic resource**; it rests on vulnerable physical infrastructure - **Hardware and energy risk** belongs alongside cyber, privacy and AI ethics in mainstream governance - Digital and AI strategies need to **assume volatility** in energy and supply, not endlessly cheap capacity If we get this right, the current crisis can become a catalyst for more resilient, thoughtful digital infrastructure - in Australia and across the world. If we ignore it, we’ll discover the hard way that “just‑in‑time” doesn’t work when the world runs on fuel and fragile chokepoints. ### When Space, Strategy and Commercial Tech Converge URL: https://katecarruthers.com/when-space-strategy-and-commercial-tech-converge/ Last updated: 2026-07-11T01:18:46.000Z 💡 Dual‑use satellite constellations like Starlink now sit at the heart of both civilian connectivity and military communications, making them key strategic infrastructure. Russia-China discussions on countering Starlink illustrate how military planning, geopolitics and commercial technology have converged into a single, cross‑domain system. Commercial technology stacks are increasingly analysed in detail by states, turning dual‑use platforms into contested terrain in their own right. Governance for space, cyber, AI and critical infrastructure needs to evolve together, recognising that these domains are now tightly interlinked rather than separate policy silos. In July 2026, a [joint investigation](https://meduza.io/en/news/2026/07/09/russia-and-china-discussed-plans-to-destroy-starlink-satellites-and-develop-a-joint-air-defense-system-the-insider-reports?ref=katecarruthers.com) by The Insider, Der Spiegel and Le Monde revealed documents from Russian-Chinese military‑technical forums that included detailed analysis of how to [counter Starlink](https://theins.press/en/inv/294635?ref=katecarruthers.com), the satellite network operated by SpaceX. The material described a multi‑track partnership across space weapons, integrated air and missile defence, autonomous drones and next‑generation armored vehicles. For anyone working in AI governance, cybersecurity or technology policy, this is a useful example of how three previously separated fields - military strategy, geopolitics and commercial technology - now operate as one converging system. Starlink is at once a commercial broadband service, a critical communications backbone in the war in Ukraine, and a strategic variable in great‑power planning. ## Starlink as dual‑use infrastructure Starlink began as a commercial constellation designed to deliver high‑speed internet globally via thousands of satellites in low Earth orbit. Its promise was better connectivity for remote regions and redundancy where terrestrial infrastructure is weak. In practice, the network quickly became a textbook [dual‑use](https://en.wikipedia.org/wiki/Dual-use%5Ftechnology?ref=katecarruthers.com) system: the same terminals and satellites that serve households and businesses can also underpin battlefield communications, drone coordination and emergency response. Reporting on Ukraine has highlighted how Starlink supports resilient links for Ukrainian units and civil infrastructure under stress, making it part of the broader Western digital backbone in the conflict. The leaked Russia-China documents show how states systematically analyse such dual‑use systems. According to the investigation, Chinese researchers outlined a three‑tier “escalation ladder” to suppress Starlink: joint diplomatic and regulatory pressure, coordinated electromagnetic interference, and, at the highest tier, cyber operations against user terminals combined with low‑cost kinetic measures against satellites. None of this is surprising from a strategic perspective. When a commercial network reaches the scale and importance of Starlink, it naturally becomes a focus of state‑level assessment, scenario planning and capability development. ## Strategic partnerships adapting to new technologies The same documents describe broader plans for an integrated, next‑generation air and missile defence system that Russia and China aim to co‑develop. This system is envisaged to intercept ballistic missiles, maneuvering warheads and hypersonic threats in their terminal flight phase, supported by shared command‑and‑control facilities and joint development of guided interceptors. Taken together, the “anti‑Starlink” work and the air‑defence projects show a strategic partnership adapting jointly to new technologies in space and near‑space domains. Rather than operating separately, communications constellations, sensing platforms and missile‑defence architectures are being treated as parts of a single cross‑domain environment. We see similar patterns in other alliances, where space, cyber, AI and communications infrastructure are now routine topics in defence cooperation. Detailed discussion of how to protect, leverage or counter specific commercial platforms is simply a contemporary expression of what military‑technical partnerships have always done: examine emerging capabilities and seek coordinated responses. ## Commercial innovation and contested dual‑use tech One of the striking features of the Russia-China material is [how deeply it engages with the specifics of a privately owned technology stack](https://united24media.com/world/leaked-documents-reveal-possible-secret-russia-china-military-plan-to-disable-starlink-20627?ref=katecarruthers.com). Proposals reportedly include occupying relevant frequency bands and orbital slots, generating targeted jamming, and exploring “spoofing” techniques - identity‑substitution attacks - to interfere with services provided by commercial constellations like Starlink. This highlights a broader trend: **dual‑use technology is no longer just a descriptive label, it is becoming a contested domain in its own right**. The same networks and platforms that keep households and businesses connected are now routinely integrated into military communications, drone operations and emergency response. That makes them objects of strategic planning, but also potential targets, sources of leverage and points of friction between states. For policymakers and strategists, several implications follow: - **Dual‑use systems can rapidly become strategic assets**, with little time for governance frameworks to catch up. - **Dependencies on privately owned, dual‑use infrastructure need to be mapped and managed explicitly**, including scenarios where they are disrupted or degraded. - **Different states will have different views** on when and how dual‑use capabilities should be constrained, protected or countered, turning the governance of these technologies into an emerging area of geopolitical contestation. In practice, debates about dual‑use AI models, satellite networks, cloud platforms and critical data infrastructures are converging. They are no longer separate technical or policy conversations; **they are part of how states think about deterrence, resilience and escalation across space, cyber and information domains**. ## Governance questions in a converging domain As space, digital infrastructure and defence converge, governance questions become more complex. The Starlink case surfaces several of them. 1. **International norms for dual‑use satellites are still nascent**. The same constellation can support civilian communications, commercial services, and military operations. Decisions about how such systems may be targeted, protected, or regulated in conflict have implications well beyond any single theatre. 2. **The roles and responsibilities of private operators remain under‑defined.** Investigations describe Russian interest in Chinese electronic warfare systems to counter drones and Starlink‑enabled communications. Yet the companies running these systems sit at the intersection of commercial law, national security obligations and international humanitarian considerations. 3. **Orbital sustainability is part of the picture.** Proposals for low‑cost kinetic countermeasures or “physical paralysis” of constellations would, if realised, add debris and risk to already crowded low Earth orbit. Any governance framework has to balance strategic calculations with the long‑term usability of space as a global commons. For AI and data governance communities, these questions are familiar in spirit: we are used to thinking about dual‑use AI models, critical data infrastructures and autonomous systems. What the Starlink episode adds is a vivid, near‑term example of how those issues play out in a specific, highly commercialised domain. ## A living example of merged fields Seen through a strategic lens, the Russia-China Starlink material is less about assigning motives and more about observing convergence in action: - **Military strategy** now routinely incorporates commercial digital and space infrastructure as core variables, not peripheral utilities. - **Geopolitics** increasingly turns on shared and competing technology ecosystems, from satellite networks to drone swarms and air‑defence grids. - **Private‑sector innovation** shapes security doctrines by creating capabilities and dependencies that states must understand and, where necessary, counter or protect. For practitioners in AI governance, cybersecurity and critical infrastructure, this episode functions as a case study. It demonstrates how space systems, communications networks and strategic partnerships are interacting in real time, and it hints at future scenarios where AI‑enabled constellations, autonomous sensing platforms and cross‑domain defence systems will evolve together. The key point is not whether any single plan goes ahead, but that the way we need to analyse these issues has shifted. Commercial technology, military strategy and geopolitics now move together, and our governance frameworks need to keep pace with that. ### DeepSeek’s AI chip is a wake‑up call: the arms race has only just started URL: https://katecarruthers.com/deepseeks-ai-chip-is-a-wake-up-call-the-arms-race-has-only-just-started/ Last updated: 2026-07-08T22:39:03.000Z China’s [DeepSeek is reportedly building its own AI inference chip](https://www.reuters.com/world/china/chinas-deepseek-developing-its-own-ai-chip-sources-say-2026-07-07/?ref=katecarruthers.com) to cut reliance on Nvidia and even domestic champion Huawei. That is not just another chip story; it is a clear signal that the real [AI arms race is shifting](https://biz.chosun.com/en/en-it/2026/07/08/CLINOCFNLFGCTLN2VDXEJQLATU/?ref=katecarruthers.com) from flashy models to control of the hardware stack. DeepSeek made its name with cheap, capable models tuned for Huawei silicon, showing you do not need Silicon Valley‑style budgets to matter in this space. Now it is quietly hiring semiconductor talent and lining up foundries to design its own silicon, targeting the fastest‑growing part of AI demand: [inference at scale](https://www.reuters.com/technology/chinas-deepseek-returns-with-new-model-year-after-viral-rise-2026-04-24/?ref=katecarruthers.com), not just headline‑grabbing training runs. In a world of tightening US export controls and GPU shortages, **this is about sovereignty, not just margins**. In my recent posts on the [AI hype cycle](https://katecarruthers.com/gartner-hype-cycle-ai-governance/) and on why open institutions matter, I argued that power is crystallising around the boring bits of AI: infrastructure, governance, and who controls the rails. DeepSeek’s move proves the point. When [model labs start designing chips](https://www.semafor.com/article/07/07/2026/deepseeks-ai-chip-plans?ref=katecarruthers.com), hardware becomes a geopolitical instrument. **Whoever owns the compute can decide who gets to participate, under which rules, and at what price**. Markets clearly get the stakes: news of DeepSeek’s chip plans was enough to [spook global chip stocks](https://www.newsbreak.com/reuters-555486/4755760455857-nasdaq-set-to-fall-at-open-as-deepseek-s-ai-chip-push-rattles-markets?ref=katecarruthers.com) and raise questions about Nvidia’s long‑term dominance. But the broader lesson for boards and policymakers is blunter. **If you’re still treating AI as an “apps and use‑cases” problem, you’re already behind**. Strategy now has to extend down the stack to supply‑chain exposure, export‑control risk, and concentration around a tiny handful of fabs and vendors. We keep talking about the AI arms race as if it is nearing a finish line. DeepSeek just reminded us we have only run the first lap. The next phase will be fought over fabs, export licences, and who can keep the lights on when the geopolitics get rough. For Australia, DeepSeek’s chip play is another reminder that **our AI future will be shaped as much in fabs and data centres as in policy roundtables**. The government’s new [National AI Plan](https://katecarruthers.com/tag/visualization/) and its expectations for data centres and AI infrastructure are a start, but they still lean heavily on foreign silicon and hyperscaler capacity. If we want genuine AI sovereignty in the Indo‑Pacific, we need to treat compute, critical minerals, and regional infrastructure as strategic assets - not just back‑office plumbing - and be honest that the hardware battles now unfolding between Washington and Beijing will wash up on our shores whether we are ready or not. ### War, Politics and Compute Power URL: https://katecarruthers.com/war-politics-and-compute-power/ Last updated: 2026-07-10T01:43:47.000Z ## How AI and microchips are redefining the US-China tech rivalry War, as Clausewitz reminded us, is the continuation of politics by other means. In the 21st century, those “other means” now decisively include supercomputers, platforms, semiconductors - and increasingly, artificial intelligence. ## From Clausewitz to Compute Power Clausewitz’s core insight was that war is not an aberration from politics but an extension of it, shaped by strategic calculation, economic interests, and social forces. This grammar of power is now being rewritten in the language of chips, cloud, EV platforms, AI models, and national‑scale compute infrastructure. The recent [decision by the US Department of Defense](https://www.scmp.com/news/china/diplomacy/article/3356419/us-adds-alibaba-byd-and-other-chinese-tech-champions-military-company-list?ref=katecarruthers.com) to add Chinese tech champions such as Alibaba, BYD and Baidu to its “Chinese military companies” list is a textbook illustration of that evolution. The designation is not just a legal classification; it is a political act that constrains capital flows, reshapes supply chains, and signals to allies and markets that key technologies are now understood as instruments of state power. ## Tech Firms as Strategic Actors The expanded [US Section 1260H list](https://www.war.gov/News/Releases/Release/Article/4511232/dow-releases-list-of-chinese-military-companies-in-accordance-with-section-1260/?ref=katecarruthers.com) spans a broad swathe of China’s technology ecosystem: e‑commerce and cloud (Alibaba), search and AI (Baidu), electric vehicles (BYD and Nio), battery manufacturers, lidar providers, and display‑panel producers. These are the connective tissues of China’s digital and industrial economy, touching everything from logistics and payments to mobility and sensing. On paper, the list blocks designated firms and their controlled entities from securing US defence contracts and complicates their access to US capital markets. In practice, it does something more profound: it formally recodes these companies from “commercial entities” to “strategic assets” embedded in a military‑civil fusion architecture. Once that recoding happens, every subsequent policy decision - export controls, procurement rules, sanctions, investment screening - is filtered through a national security lens. ## Supercomputers as Geopolitical Infrastructure Against this backdrop, China’s new LineShine supercomputer (HPC) is not just a scientific instrument; it is geopolitical infrastructure. In the recent post I wrote about [LineShine](https://katecarruthers.com/ai-boomers-doomers-and-why-sovereignty-and-investment-now-matter-more-than-hype/), I explored how its debut at number one on the June 2026 TOP500 list, overtaking the US El Capitan system, signals a new phase in compute sovereignty and AI capability. LineShine delivers verified exascale performance using domestically produced CPUs, a proprietary interconnect and a sovereign operating system stack. That combination matters: it demonstrates resilience under export controls, maturation of China’s domestic chip ecosystem, and a commitment to sovereign control over high‑end compute for workloads such as climate modelling, weapons simulation and AI training. When you put LineShine alongside Beijing’s broader distributed AI computing initiatives, you see a coherent strategy: build a national compute backbone that can support brain‑scale models, industrial optimisation and defence applications without depending on foreign GPUs or software stacks. In Clausewitzian terms, **compute power itself is becoming one of the “other means” through which politics continues**. For readers who want to go deeper into LineShine specifically – its architecture, performance profile and strategic implications – I unpack that in more detail in my earlier post: [China’s LineShine supercomputer and the geopolitics of compute](https://katecarruthers.com/2026/06/25/chinas-lineshine-supercomputer/). ## Technology, AI and Geopolitics: One System None of this is historically unprecedented. Railways and telegraphs underwrote 19th‑century empire; oil, nuclear reactors and satellite constellations defined much of 20th‑century geopolitics. Control over key technologies has always meant leverage over logistics, intelligence, economic growth and military reach. What is different now is the density and pervasiveness of the AI‑compute nexus. Logistics platforms, digital payments, EV ecosystems, cloud services and social media are no longer peripheral to statecraft; they are the infrastructure through which trade, influence and coercion flow. Supercomputers like LineShine sit behind this surface layer, providing the raw calculation and model‑training capacity that turns data into operational advantage across civilian and military domains. By designating AI‑intensive firms such as Baidu, Alibaba and robotics or sensor manufacturers as “Chinese military companies,” Washington is effectively acknowledging that AI capabilities and high‑end compute are [dual‑use](https://www.europarl.europa.eu/topics/en/article/20210319STO00424/dual-use-goods-what-are-they-and-why-are-new-rules-needed?ref=katecarruthers.com) by default. Systems that optimise logistics, enhance surveillance, assist intelligence analysis and operate autonomous platforms cannot be neatly separated into “civilian” and “military” buckets, especially under a deliberate military‑civil fusion strategy. ## Navigating the New Strategic Landscape For both policy professionals and technically literate folks, several implications follow. 1. **Export controls and investment screening will increasingly focus on the full AI stack**: compute, interconnects, operating systems, model development, data access and specialised talent – not just traditional hardware categories. LineShine’s ascent with domestic CPUs and interconnects is likely to be read in Washington and allied capitals as a warning that compute sovereignty is now a moving target, not a static constraint. 2. **Corporate governance must assume that geopolitics is now a core dimension of technology risk**. For firms operating across US–China fault lines, particularly in AI‑adjacent sectors, board‑level discussions will need to treat defence‑linked designations, national lists and compute export controls as recurring features of the operating environment rather than edge cases. 3. **AI governance debates that focus solely on ethics and safety, without engaging with the strategic deployment of AI and compute in great‑power competition**, will feel increasingly detached from reality. The same architectures that power recommendation systems, fraud detection, logistics optimisation and generative models are being treated as levers of national power - backed by infrastructure like LineShine - and policy frameworks must be honest about that. If war is politics continued by other means, then **AI and compute are now among those means: embedded in how states categorise companies, control capital, shape standards and redraw the boundary between civilian innovation and military capability**. The challenge for both policy and technology communities is to accept that entanglement as a starting point - and then decide what responsible practice looks like inside a world where a change in the TOP500 rankings or an update to a “military company” list is also a political signal. ### The Two-Layer AI Stack: Cost Discipline Meets Strategic Leverage URL: https://katecarruthers.com/the-two-layer-ai-stack-cost-discipline-meets-strategic-leverage/ Last updated: 2026-07-05T22:33:19.000Z We need to stop thinking about AI as one big blob. As I’ve been saying for ages we need to think critically about what kind of AI we are deploying, the purpose for which we are deploying it, and how much it is going to cost us. If an organisation is planning to deploy AI at scale then it will be worth thinking about this, if only to mitigate the horrific bill 💸 shock that is headed your way. A useful mental model is emerging for organisations trying to balance AI capability with cost control: treat AI as a two-layer system. The base layer is your “engine” - the cheapest capable model that reliably executes tasks. The upper layer is your “steering” - frontier models that guide, critique, and refine outputs where it matters. This framing, articulated nicely by [Nate B. Jones](https://natesnewsletter.substack.com/), captures a shift from chasing raw model power toward architecting systems that optimise for both cost and performance. The key insight from Jones is simple: **execution is becoming commoditised, while judgement remains scarce**. ## The two-layer AI stack A useful way to think about modern AI systems is as a two-layer stack. - The bottom layer is your **engine**: the models that actually execute work at scale - summarising, classifying, drafting, transforming, and wiring into workflows. - The top layer is your **steering**: higher-capability frontier models that shape, critique, and govern what that engine does. Most organisations today overpay by using frontier models as both engine and steering. They send every task, trivial or complex, through the most expensive path, then wonder why [AI costs](https://katecarruthers.com/ai-tokens-and-the-tokenpocalypse/) look like a second cloud bill. The emerging playbook reverses that. You push as much execution as possible into cheap, capable models and reserve frontier systems for the points where judgment, nuance, or risk really matter. The twist is that the engine layer should be open-weight wherever it can be - not just cheap, but under your control. ### Why open weight matters in the engine An “[open-weight](https://hai.stanford.edu/ai-definitions/what-is-an-open-weight-model?ref=katecarruthers.com)” model is one where you can download the weights and run inference on your own infrastructure. You might still pay for hosting or managed services, but you are not forced to send every request through a single vendor’s API on their terms. For the engine layer, this has three big implications: - **Cost predictability:** When you control deployment, you can decide whether to run on your own GPUs, a low-cost cloud, or a specialised inference provider. Your bill is driven by infrastructure economics, not by per-token pricing that can change overnight. - **Portability:** You can move the engine wherever it needs to run - into different regions for data residency, closer to critical systems, or inside regulated environments - without rewriting your stack for a new proprietary API. - **Resilience:** No single provider can “switch off” your core execution capability. Contracts can end, features can change, or geopolitical events can disrupt access - but downloaded weights keep running. In other words, open weight turns the engine from a **rented capability** into an **owned asset**. That changes the balance of power. ### Cost leverage: nobody owns your execution When you build your engine layer on open-weight models, you gain leverage in several ways: - You can **benchmark multiple models** for a given task and choose the best cost-quality trade-off, instead of being locked into one provider’s pricing curve. - You can **upgrade or swap out models** as new releases arrive, without changing your application logic; the interface between your engine and your workflows stays largely the same. - You can **negotiate with proprietary providers** from a position of strength: their frontier models become optional steering components, not existential dependencies. This is the economic heart of the two-layer idea: the more you de-risk and commoditise execution, the more freedom you have to spend selectively on frontier steering. ### Frontier models as steering, not engines Frontier systems still matter. They tend to be better at: - Complex, multi-hop reasoning - Handling ambiguous instructions and edge cases - Giving higher-quality critiques, reviews, or design-level suggestions - Navigating natural language interactions with non-technical users But their role changes. Instead of doing every task end-to-end, frontier models sit above the engine as: - **Reviewers:** checking outputs from the cheaper engine for correctness, coherence, policy alignment, or brand tone. - **Architects:** helping design workflows, prompts, and evaluation criteria that govern how the engine operates. - **Escalation paths:** handling the small minority of tasks that the engine cannot safely or reliably complete. Because this steering layer touches far fewer tokens and tasks, you can afford to use more expensive models here without blowing up the budget. The value comes from leverage: one good steering decision can improve thousands of cheap engine executions. ### Open weight as a defence against lock-in Most AI lock-in is subtle. It does not just come from using a proprietary model; it accumulates through: - Prompts tailored to a single provider’s behaviour - Fine-tunes that cannot be exported - Evaluation suites that assume one model’s quirks - Integrations intertwined with a single API Open-weight engines give you a way to push back. When your everyday execution runs on models you can host and swap, you are less dependent on any one vendor for day-to-day operations. Frontier systems become plug-ins you integrate and can remove, rather than the spine of your stack. This matters for: - **Enterprises** that need to manage long-term costs and avoid being unable to switch providers when commercial terms change. - **Public-sector and critical infrastructure** environments that need continuity even if external APIs are disrupted. - **Smaller teams and creators** who cannot absorb large, unpredictable bills but still want strong AI capabilities. Open weight does not magically solve governance or safety. But it does give you a more controllable substrate on which to build those systems. ### Governance, evaluation, and the real competitive edge Once your engine is cheap, capable, and under your control, the real differentiators move elsewhere: - **Evaluation:** the ability to measure whether outputs meet your standards - accuracy, bias, security, compliance, tone - and to do so systematically. - **Orchestration:** the way you break tasks into steps and route them between models, tools, and humans. - **Governance and policy:** the guardrails you design around AI use, from access controls and logging to approval flows and human-in-the-loop interventions. Two organisations might use the same open-weight models and similar frontier systems. The one that invests in **evaluation and governance** will usually get better outcomes at lower cost, because it can safely push more work into the cheap engine and reserve steering for where it adds the most value. **The message for leaders is clear: AI advantage is becoming less about having special access to magical models and more about designing a stack where execution is cheap, resilient, and vendor-independent - and then building strong steering on top.** ## ### Some changes with this site URL: https://katecarruthers.com/some-changes-with-this-site/ Last updated: 2026-07-05T22:18:27.000Z This site has been running in one form or another since 2002\. It started out in the early days as a kind of personal live journal (no pun intended for those who remember [Live Journal](https://thehistoryoftheweb.com/postscript/whatever-happened-livejournal/?ref=katecarruthers.com) back in the day). But to put the timeline in perspective: when I started this site, Facebook and Twitter didn’t exist, and I was hand‑coding pages in NotePad. After a few years I moved it to [Blogger](https://www.blogger.com/about/?ref=katecarruthers.com), then to [WordPress](https://wordpress.com/?ref=katecarruthers.com). Now it’s all grown up and running on [Ghost](https://ghost.org/?ref=katecarruthers.com). As I’ve evolved and my career has shifted, the site has steadily become more work‑focused. As my work moved deeper into data strategy, AI governance, and technology policy, it turned into a professional hub for those topics. Today the site focuses on clear, practical analysis of data and AI as strategic infrastructure, with a strong emphasis on governance, ethics, sovereignty, and the Australian geopolitical context. What started as a general personal blog is now a curated space where I develop and share frameworks, insights, and reflections for humans and organisations navigating AI and data in a rapidly changing world. I’m leaving the old content in place because it charts my evolution over the years, and the site will keep evolving. The first visible change is that I’ve brought my Data Revolution podcast content over here, and it will now live as part of this site. ### Claude Science: a practical AI workbench for real scientific workflows URL: https://katecarruthers.com/claude-science-a-practical-ai-workbench-for-real-scientific-workflows/ Last updated: 2026-07-03T10:20:59.000Z [Claude Science](https://www.anthropic.com/news/claude-science-ai-workbench?ref=katecarruthers.com) shifts AI from a clever sidekick to embedded infrastructure in the research workflow. It is Anthropic’s AI workbench for scientists, designed to support the day‑to‑day work of designing studies, exploring data, generating figures and preparing manuscripts, with integrated access to dozens of scientific databases and tools. Crucially, it treats reproducibility and auditability as first‑class features: every result is tied to the exact code, environment and conversation that produced it, so you can show reviewers, collaborators and regulators not just what you found, but how you got there ### What Claude Science actually does Anthropic is very explicit that Claude Science is not a new model, it is a workflow environment. Think of it as an AI‑assisted lab notebook plus analysis environment that comes preloaded with the tools scientists actually use. In practical terms, Claude Science: - connects to more than 60 scientific databases and tools across genomics, structural biology and chemistry, so you can query and combine data from one place; - lets you run analyses, generate plots, 3D protein structures, genome browser tracks and chemistry diagrams with linked code; - keeps a full record of prompts, code, environment and outputs so you can reproduce and audit results later. Anthropic describes it as a “**customisable app that integrates the tools and packages researchers most often use, produces auditable artefacts, and supports complex workflows**.” That is the lens we should use to understand it. You can read their announcement here: [Claude Science, an AI workbench for scientists](https://www.anthropic.com/news/claude-science-ai-workbench?ref=katecarruthers.com). ### How a research lab might actually use it If you work in a lab or applied research group, the interesting question is not the branding, it is where something like Claude Science could sit in your existing workflow. A typical pattern might look like this: 1. **Literature and data review:** You brief the “project manager” assistant on your question, for example a particular pathway or target. It pulls relevant papers and database entries from the integrated sources, summarises them and builds a starting evidence base. 2. **Study design and analysis planning:** You use Claude Science to draft protocols, power calculations or analysis plans, checking them against the literature and regulatory guidance. Because the conversation and code are logged, you can show how you arrived at particular design decisions. 3. **Data analysis and visualisation:** When data starts to land, you run analysis code inside the environment, iterate on models and generate figures. Each plot or structure is linked to the exact code and environment that produced it, which is gold for internal review and external audit. 4. **Fact‑checking and documentation:** Before anything goes to a manuscript, report or regulator, you can hand it to a separate “fact‑checker” assistant that Claude Science provides. Its job is to verify citations, calculations and key claims against the underlying artefacts. 5. **Publication and reuse:** Because everything is stored as auditable artefacts, you can reuse parts of the workflow in future projects, share them with collaborators or adapt them for teaching and training. That is a long way from “ask the chatbot to explain [CRISPR](https://en.wikipedia.org/wiki/CRISPR%5Fgene%5Fediting?ref=katecarruthers.com)”. This is AI as infrastructure for how a lab actually works daily. ### Why reproducibility and auditability matter A big challenge for universities and researchers for many years has been [reproducibility](https://scienceinsights.org/what-does-reproducible-mean-and-why-it-matters/?ref=katecarruthers.com). For many years we have struggled with this - it is a hard problem because the underlying data is just one thing in the mix, and AI has just made research a kind of a black box. Which makes reproducibility a challenge. One of the hard problems in AI‑assisted science is reproducibility. If an AI system suggested a particular model, parameter setting or hypothesis, how do you capture that in a way a reviewer, regulator or future collaborator can interrogate. Claude Science tackles this by making every figure, result and narrative traceable back to: - the code that was run, - the environment it ran in, - the conversation history that led to it, - and a plain‑language description of the steps taken. On paper, that is closer to how we already think about good scientific practice: you should be able to re‑run someone else’s work and see how they got there. For regulated domains like clinical research or safety‑critical engineering, that sort of audit trail is likely to move from “nice to have” to “required”. ### Infrastructure and deployment choices Anthropic is also acknowledging the reality that not everyone can or should ship sensitive data to a third‑party cloud. Claude Science can run on a lab’s own compute infrastructure, which means data can stay within existing security and compliance boundaries. This is a significant benefit and shows that they understand research sensitivities. For organisations in health, biosecurity or critical infrastructure, this hybrid deployment pattern is important. It aligns with broader trends where AI products are expected to: - support on‑premise or sovereign deployments, - integrate with existing identity, access control and logging, - and expose enough observability that security teams can monitor and control usage. In other words, this is AI as part of your core infrastructure stack, not a point solution. ### Business and operating model: AI as workflow, not feature Anthropic is positioning Claude Science as part of a broader suite that includes Claude Code and Claude Security, all accessed through subscription tiers like Pro, Max, Team and Enterprise. That matters if you sit in technology leadership, because it shows where the industry is heading. We are seeing a shift from: - “**AI as a feature inside existing tools**” to: - “**AI as the** [**orchestration**](https://katecarruthers.com/ai-is-now-infrastructure/) **layer for entire workflows**.” Claude Science is a clear example of this, and it suggests that in other domains we will see similar workbenches emerge for engineering, security operations, policy analysis and beyond. ### What this means for practitioners If you are a scientist, engineer or data professional, Claude Science is worth paying attention to, even if you never use it directly. It tells us a few things about where practical AI use is going. - AI will increasingly be embedded in the tools you already use, not just accessed via chat - Reproducibility, provenance and audit trails will be designed into AI products from the start - Vendors will push deeper into domain‑specific workflows, not just horizontal platforms For teams thinking about adopting AI, the useful questions shift from “*which model is best*” to: - How well does this tool integrate with our existing workflows? - Can we audit and reproduce what it does? - Where does the data live and who controls the infrastructure? Those are real practical, governance‑aligned questions that can be asked at every procurement and design decision, and I might cover those in a future article. 💡 If you want to dive deeper, the Anthropic announcement and related pieces are a good starting point: [Claude Science, an AI workbench for scientists](https://www.anthropic.com/news/claude-science-ai-workbench?ref=katecarruthers.com)[Anthropic’s Claude ](https://techcrunch.com/2026/06/30/anthropics-claude-science-bets-on-workflow-not-a-new-model-to-win-over-scientists/?ref=katecarruthers.com) [Science bets on workflow, not a new model](https://techcrunch.com/2026/06/30/anthropics-claude-science-bets-on-workflow-not-a-new-model-to-win-over-scientists/?ref=katecarruthers.com) [Anthropic releases Claude ](https://www.statnews.com/2026/06/30/anthropic-release-claude-science-ceo-dario-amodei/?ref=katecarruthers.com)[Science, a product aimed at researchers](https://www.statnews.com/2026/06/30/anthropic-release-claude-science-ceo-dario-amodei/?ref=katecarruthers.com) ### AI boomers, doomers, and why sovereignty and investment now matter more than hype URL: https://katecarruthers.com/ai-boomers-doomers-and-why-sovereignty-and-investment-now-matter-more-than-hype/ Last updated: 2026-06-29T23:05:58.000Z AI is now expensive, fast moving strategic infrastructure, not a toy, and Australia and our region are still arguing with the [AI boomers and the AI doomers](https://knowledge.wharton.upenn.edu/article/embracing-ai-are-you-a-doomer-gloomer-zoomer-or-bloomer/?ref=katecarruthers.com) while other countries quietly build the machines that will decide who sets the rules. The “AI boomers” in this debate are the people who see upside everywhere, productivity gains, new drugs, climate models, and a wave of innovation that will supposedly lift all boats. The “AI doomers” are focused on existential risk, runaway systems, and the concentration of power in a few US based firms who control both the models and the cloud infrastructure they run on. Both camps are responding to a real phenomenon, capability is improving on timescales measured in months, and each new frontier system arrives with broader modalities, sharper reasoning, and tighter integration into existing toolchains. From an Australian vantage point, the more interesting position sits between these extremes. It asks less, “will AI save or doom us?” and more “who owns the compute, who sets the terms of access, and how much are we prepared to pay for capability we do not fully control?” That is a [sovereignty and investment question](https://katecarruthers.com/the-hidden-politics-of-ai-sovereignty-in-a-platform-world/), not a philosophical one. ### Who pays for frontier AI, and how do they get their money back? [Frontier AI is not cheap](https://katecarruthers.com/beyond-ai-sovereignty-why-the-west-relies-on-us-frontier-models-and-what-comes-next/). Training and serving the current generation of large models requires massive capital spend on accelerators, data centres, power, cooling, and networking, and those costs are rising just as demand from enterprises and governments spikes. In practice, three groups are paying the bill: - **US hyperscalers**, who treat AI as a way to deepen lock in and sell more cloud. - **Venture investors**, who are betting that at least some of today’s model labs will turn into high margin platforms or get acquired. - **Governments**, who are increasingly underwriting domestic compute as “[national infrastructure](https://katecarruthers.com/anthropic-fable-5-and-why-sovereign-ai-just-got-real/)”, either directly or via subsidies and joint ventures. **Return on investment is still speculative.** The platform players are banking on subscription revenue, usage-based pricing and differentiated enterprise services to recoup multi-billion dollar training runs. Startups are gambling that they can move up the stack and own workflows rather than raw models, capturing recurring software revenue instead of living solely on API calls. Governments, particularly in the EU and parts of Asia, are framing high end compute as a public good, necessary for science, defence, and industrial competitiveness, with “returns” measured in growth and strategic autonomy rather than dividends. For Australia and the wider Indo Pacific, the danger is obvious. If we rely entirely on someone else’s machines to run our critical workloads, then our ability to govern AI is constrained by their pricing, their export controls, and their policy choices. Sovereign AI risk shows up here as [regulatory dependency](https://katecarruthers.com/anthropic-fable-5-and-why-sovereign-ai-just-got-real/) and commercial dependency rolled into one. ### China’s GPU‑free supercomputer and the sovereignty play China’s new [LineShine supercomputer](https://www.techradar.com/pro/forget-gpus-china-unveils-2-exaflops-supercomputer-using-only-cpu-packing-47-000-processors-into-92-compute-cabinets-as-it-looks-to-supercede-the-us-once-again?ref=katecarruthers.com) is a concrete example of what it looks like when a country decides that reliance on US GPUs is no longer acceptable. LineShine is built around domestic CPUs rather than Nvidia or AMD accelerators, reportedly packing around 13.79 million cores into dense cabinets, using a proprietary interconnect and KylinOS, and drawing roughly 42 MW of power to reach about 2.198 exaflops on the traditional LINPACK benchmark. It takes the top slot on the TOP500 list for high-performance computing (HPC), displacing US systems like El Capitan and Frontier on that metric. On mixed precision benchmarks designed to capture AI style workloads, GPU heavy architectures still dominate, and the US retains a lead, which is why LineShine ranks lower on tests like HPL AI even while topping the classic HPC list. But this misses the strategic point. China has shown that it can build and operate an [exascale class machine without restricted Western accelerators](https://www.nextplatform.com/hpc/2026/06/25/a-deep-dive-on-chinas-lineshine-all-cpu-exaflops-class-supercomputer/5262439?ref=katecarruthers.com), using its own chips and software stack end to end. That matters because it reduces vulnerability to export controls and gives Beijing more freedom to decide what gets run, when, and at what scale, whether that is climate modelling, military simulations, or large-scale AI training. LineShine also reframes the conversation about who pays and why. It is not built to chase consumer AI subscriptions. **It is built as national infrastructure, justified as a long-term sovereignty investment rather than a near term product P&L.** For countries like Australia, that is the uncomfortable contrast. We talk about [sovereign AI and data sovereignty](https://katecarruthers.com/the-hidden-politics-of-ai-sovereignty-in-a-platform-world/), but our high-end compute is scattered across university clusters, national facilities that are oversubscribed, and commercial clouds headquartered elsewhere. ### Bigger isn’t always smarter There is a tendency in AI marketing to equate “bigger” with “smarter”. The scaling literature tells a more nuanced story. DeepMind’s [Chinchilla paper](https://arxiv.org/abs/2203.15556?ref=katecarruthers.com) argued that many large language models have been trained on too few tokens relative to their parameter count, and that for a fixed compute budget you get better performance by using more data for a smaller model rather than simply increasing parameters. Follow up work across labs has shown that beyond certain scales, **returns diminish rapidly unless you change architecture, objectives, or training regimes** in ways that better match your tasks. [Richard Sutton’s “bitter lesson”](https://www.cs.utexas.edu/~eunsol/courses/data/bitter%5Flesson.pdf?ref=katecarruthers.com) is relevant here. Over time, general methods that can absorb more compute and more data tend to beat hand engineered cleverness, but even within that paradigm there are more and less efficient ways to spend your FLOPs. Studies of distillation, compression, and retrieval augmented generation demonstrate that relatively modest models, paired with good training and access to external tools and knowledge, can rival or beat much larger dense models for many practical applications. For investors and policymakers, the takeaway is simple. Paying for “the biggest model” is often a vanity project. The smarter spend is on right sized models, data pipelines, evaluation, and integration that actually deliver value per unit of compute and power. For Australia, that should mean prioritising [shared mid-scale capability](https://katecarruthers.com/australias-data-sovereignty-ambitions-will-fail-without-research-compute/) and smarter use of regional and alliance infrastructure over chasing headline parameter counts we cannot realistically fund or sustain. ### An Australian and regional lens on AI sovereignty and investment From a middle power perspective, the key questions about AI are less metaphysical and more practical. - Are we building or buying the compute that **underpins** our science, defence, and critical services? - Who can **turn off** the models that our institutions increasingly depend on? - How **exposed** are we to other people’s export controls, platform rules, and investment cycles? - Where, exactly, do we expect the **return on our AI spending** to come from, and who captures it? If LineShine represents one end of the spectrum, state backed, domestically controlled exascale infrastructure, then the other end is a public service that quietly runs its core workflows on a single US cloud region, using models whose access conditions are governed by [foreign regulators and corporate risk committees](https://katecarruthers.com/anthropic-fable-5-and-why-sovereign-ai-just-got-real/). Most [Australian organisations](https://katecarruthers.com/beyond-ai-sovereignty-why-the-west-relies-on-us-frontier-models-and-what-comes-next/) sit closer to that second end today. A sensible regional strategy would combine several moves, more serious investment in shared compute and data infrastructure here at home, deliberate participation in allied initiatives that give us seats at the table rather than just access keys, and a shift in board level thinking from “AI as a feature” to “AI as a dependency that needs to be governed like any other strategic supplier”. Locally, that also means treating questions like “who pays and how much?” as [governance questions rather than procurement details](https://katecarruthers.com/effective-ai-governance/). If we are underwriting other people’s machines with public money, we should be clear about what we are getting back, not just in jobs, but in capability, control, and long-term resilience. The AI boomers and doomers will keep arguing loudly about whether AI will bring us utopia or catastrophe. The more useful conversation, especially for Australia and our region, is quieter and more concrete: **what infrastructure we are willing to build, what dependencies we are willing to accept, and whether we intend to be customers or owners in the systems that will shape our future**. ### AI tokens and the ‘tokenpocalypse’ URL: https://katecarruthers.com/ai-tokens-and-the-tokenpocalypse/ Last updated: 2026-06-25T03:00:37.000Z ## What is a token anyway? When people start waving around “[*tokenpocalypse*](https://www.404media.co/the-tokenpocalypse-is-here-companies-are-scrambling-to-stop-spending-so-much-on-ai/?ref=katecarruthers.com)” headlines, it’s worth pausing to ask what a token actually is. In most language models, a **token** is just a tiny chunk of text - often around three‑quarters of a word - that the model uses as its basic unit for reading and writing. Your prompt is chopped up into tokens, the model’s response comes back as tokens, and providers quietly track and bill you on how many tokens you send and receive. For many of us, this is largely invisible because we’re sitting on “all‑you‑can‑eat” licences for everyday tools like Microsoft 365 Copilot, where token usage is abstracted behind a flat seat price. But the moment you step into AI systems that aren’t all‑you‑can‑eat, tokens stop being an obscure technical detail and become both the alphabet of AI systems and, increasingly, the [currency of AI infrastructure](https://www.mindstudio.ai/blog/token-based-pricing?ref=katecarruthers.com): **if you’re not tracking how many tokens your organisation is burning, you’re flying blind on both capability and cost**. ## And what is a ‘tokenpocalypse’? Most ‘*tokenpocalypse*’ scare stories are really symptoms of weak AI governance: organisations have rushed into generative AI without the basic cost, risk, and accountability controls they’d apply to any other strategic technology. To be honest this is just business 101, nothing new! **The remedy isn’t to stop using AI, but to deliberately design a new organisational structure around AI - one that treats tokens, models, and agents as governed resources, not an all‑you‑can‑eat buffet**. ## The token scare is a governance failure Over the past year, uncontrolled token use has produced some [spectacular bill shocks](https://au.investing.com/analysis/the-wakeup-call-a-400k-ai-bill-becomes-14m-overnight-200614775?ref=katecarruthers.com), with reports of enterprises facing AI invoices in the hundreds of millions of dollars and smaller teams burning through seven‑figure budgets in months. Tools that were sold as productivity boosts - chat assistants, coding copilots, agentic workflows - are now under scrutiny because unit prices have fallen but total consumption has exploded, creating a Jevons paradox for AI: cheaper tokens drive more usage faster than costs fall. [Tokenmaxxing](https://en.wikipedia.org/wiki/Token%5Fmaxxing?ref=katecarruthers.com) has become a kind of corporate sport, where success is measured in how much AI is being used rather than what value it delivers, and budgets have been treated more like marketing experiments than disciplined investments. In this context, of course AI looks expensive: there is little linkage from tokens to tasks to outcomes, no clear accountability for overruns, and almost no systematic way to shut down low‑value workloads. It is worth reading things like this if you want to start thinking about cost control: [AI Cost Control Framework for 2026](https://www.aicharcha.com/research/ai-cost-control-framework-2026/?ref=katecarruthers.com). ## What a sensible AI governance framework looks like A credible [AI governance framework](https://www.databricks.com/blog/practical-ai-governance-framework-enterprises?ref=katecarruthers.com) starts from the assumption that AI is both a risk and an investment: **it needs guardrails for harm and discipline for cost**. At minimum, that framework should cover four pillars: - **Policy and ethics**: clear rules about acceptable use, data protection, safety thresholds, and high‑risk applications that require special scrutiny. - **Architecture and platform**: centralised AI platforms or gateways that route traffic, enforce access controls, and give you observability over which models and agents are doing what. - [**FinOps**](https://www.finops.org/wg/finops-for-ai-overview/?ref=katecarruthers.com) **and cost controls**: automated token budgets, rate limits, cheaper‑model defaults for simple tasks, and response caching for common queries so you pay once for repeated answers. - **Value and lifecycle**: stage‑gate approvals for new AI initiatives, ROI targets, kill criteria for underperforming systems, and ongoing performance and risk reviews. The shift from “*just give everyone a copilot license*” to a governed, platform‑centric model is already underway, with many organisations building internal AI platforms that sit between business users and external models to enforce these controls. ## Cost control is a feature, not a constraint Effective AI cost governance doesn’t mean starving experimentation; it means separating play from production and making each intentional. Teams can give sandboxes and experimentation budgets with looser limits, while production workflows - things that run every day and touch customers or core processes - get stricter budgets, model choices, and escalation paths for overruns. Modern guidance emphasises a few practical mechanisms: - **Hard budgets, soft alert**s: automated alerts at 70-90% of budget, with circuit‑breakers when use deviates too far from forecasts. - **Right‑sizing models**: defaulting to smaller, cheaper models for routine tasks, reserving frontier models for genuinely complex work. - **Governance at the seat and workflow level**: limiting licenses to verified use cases, tracking token usage by team, and reallocating costs based on actual consumption. - **Kill criteria**: agreeing upfront on thresholds where a project is paused or shut down if value fails to materialise relative to spend. When these controls are in place, the ‘*tokenpocalypse*’ looks less like an inevitability and more like an avoidable governance gap - the kind of problem boards and CFOs tackle all the time in other domains. ## We’re building a new organisational structure The deeper story here is organisational: **AI forces institutions to re‑architect how authority, responsibility, and resources flow.** You cannot bolt AI onto a traditional hierarchy and hope for the best; once models and agents start making decisions, generating content, and interacting with customers, you are effectively adding semi‑autonomous actors into the structure of the organisation. A robust AI governance framework is therefore not just a compliance checklist - it is the blueprint for a new kind of organisation where: - **Cross‑functional AI governance** boards decide on high‑risk use cases and ethical guardrails. - **Platform engineering teams** own the AI backbone: routing, monitoring, and enforcing cost and risk policies. - **Business units become accountable** for AI value, not just usage, with explicit ROI and risk thresholds. - **CFOs and boards treat AI spend as a portfolio**: diversified, stage‑gated, and subject to maximum exposure limits. Seen this way, the token scare is an early stress test for that emerging organisational form. Organisations that respond by tightening governance, clarifying accountability, and centralising control will turn AI into a disciplined infrastructure; those that keep chasing usage metrics without structure will stay trapped in the token panic cycle. ### AI, Five Eyes, and the enterprise URL: https://katecarruthers.com/frontier-ai-five-eyes-and-the-enterprise/ Last updated: 2026-06-23T22:32:15.000Z The Five Eyes cyber security agencies have just [issued a joint statement on artificial intelligence and cyber risk](https://www.cyber.gov.au/about-us/view-all-content/news/five-eyes-cyber-security-agencies-statement?ref=katecarruthers.com), and its message to organisational leaders is blunt: **your cyber assumptions will be out of date in months, not years, and governance needs to catch up**. For boards, executives, and public sector leaders across Australia, this is not just another security advisory; it is a strategic risk signal. The statement, led in Australia by Stephanie Crowe of the Australian Cyber Security Centre (ACSC), frames AI as a force multiplier for both defenders and attackers, and calls for a whole‑of‑organisation and whole‑of‑society response. It sits squarely in the space where AI governance, cyber resilience, and national security now intersect. ## AI has collapsed the cyber risk timeline One of the most striking lines in the statement is its warning on frontier AI models: they are “**anticipated to exceed current industry expectations**” and will **fundamentally reshape both offensive and defensive cyber capabilities on a timeline measured in months**. For Australian organisations, this accelerates three existing trends: - The window between vulnerability disclosure and exploitation continues to shrink, as AI helps attackers rapidly discover, weaponise, and scale their operations. - The skills barrier for malicious actors is dropping; AI‑powered tooling can turn intent into executable attacks far more easily than before. - Defensive teams risk falling behind if they continue to treat AI purely as a productivity tool rather than embedding it deliberately into cyber operations. The result is that traditional risk processes - annual reviews, slow uplift programs, static control frameworks - are increasingly misaligned with the tempo of AI‑enabled threats. ## From “IT issue” to core governance responsibility The Five Eyes agencies are explicit: **cyber risk can no longer be treated as a purely technical issue**. It is a core business risk and a leadership responsibility. For Australian boards operating under rising expectations from regulators, shareholders, and the community, this should sound very familiar. The statement calls on leaders to: - Understand and assess risk, readiness, and accountability - Prioritise foundational cyber security practices and controls - Empower cyber leaders with appropriate authority and resources - Stay actively engaged as threats and guidance evolve In other words, **this is AI governance and cyber governance converging around the same questions**: who is accountable, how decisions are made, and whether resilience is being built into strategy rather than bolted on as an afterthought. ## The basics are now strategic Interestingly, the joint statement does not focus on exotic new AI‑specific controls. Instead, it doubles down on what it describes as “not new, but now urgent” actions. For leaders who feel overwhelmed by AI hype, this is actually good news: the fundamentals still matter most. The agencies emphasise: - **Reduce your attack surface** by limiting unnecessary system access and external connectivity, and challenging whether systems need to be exposed at all. - **Accelerate patching** because AI is shortening the time between vulnerability discovery and exploitation, especially for operational systems that are slow to update. - **Address legacy systems**, which are described not just as technical debt but as “strategic liabilities” due to unsupported and easily exploitable components. - **Strengthen identity and access controls**, with robust authentication and regular permission reviews for critical systems. - **Prepare for incidents before they happen**, through rehearsed response plans, trained teams, and an operating assumption that breaches will occur. This shift - treating cyber basics as a strategic differentiator rather than a compliance checkbox - is a recurring theme. The statement warns that organisations which fail to do this will face “growing operational and strategic disadvantage”. ## Secure‑by‑design, secure‑by‑default, and AI The Five Eyes agencies reiterate core principles that Australian policymakers have been pushing for some time: secure‑by‑design and secure‑by‑default should be standard practice, not aspirational slogans. For vendors, this raises the bar on obligations: - Products and services should come with strong security controls enabled by default, not buried in configuration options. - AI‑enabled products will need clear accountability for how security is designed, tested, and maintained over time, especially as new vulnerabilities emerge. - As frontier models evolve, organisations should expect new classes of zero‑day vulnerabilities and design for defence in depth, not single points of failure. For customers, including Australian enterprises and government agencies, this is a cue to start demanding secure‑by‑design and secure‑by‑default as part of procurement and vendor due diligence. ## Using AI to defend, not just to “do more with less” The statement is unambiguous that adversaries are already using AI to move faster and more effectively. The answer is not to avoid AI, but to use it deliberately on the defensive side. According to the agencies, organisations that integrate AI into their security operations can: - Detect vulnerabilities earlier and improve software quality - Monitor unusual behaviour at scale - Respond faster to incidents, reducing cost and impact This is an important nuance for AI governance conversations. The question is no longer “Should we use AI in security?” but “How do we govern its use responsibly while maintaining pace with the threat environment?” It also underscores that simply accumulating more tools will not help; success comes from “getting the basics right, acting quickly, and integrating cyber security into core business strategy.” ## What this means for Australian leaders For Australian boards, executives, and public sector leaders, the Five Eyes statement lands in a broader context of regulatory expectations around cyber resilience and AI use. It reinforces that: - **Cyber resilience is central** to operational continuity and market trust, not a back‑office concern. - Frontier AI development will continue to **challenge existing risk assumptions**, with an explicit warning that those assumptions can become outdated in months. - **Leadership that delays action** will face “growing and avoidable risk”, including operational, financial, and reputational exposure. It is also a reminder that Australia’s cyber security posture is deeply connected to that of its Five Eyes partners. The statement highlights the “deep and transparent” nature of the partnership and the critical role of shared threat information. That cooperation only works if organisations at home are lifting their own resilience in line with this guidance. ## Practical questions for your next board or executive meeting If you sit on a board, executive team, or leadership committee, this statement provides a ready‑made agenda. Some questions worth asking: - **Do we understand** where AI is already in our environment - both in business operations and in our security stack - and who is accountable for governing its use? - **How quickly** can we patch critical vulnerabilities, and what would it take to safely cut that time in half? - **Which legacy systems** represent genuine “strategic liabilities”, and what is our plan to retire, isolate, or replace them? - When did we last **test our incident response plan** under pressure, with realistic AI‑enabled attack scenarios? - Are we treating **secure‑by‑design and secure‑by‑default** as hard requirements in our procurement and vendor management? **The Five Eyes agencies are clear: we must act now, and we must be prepared to adapt as frontier AI continues to evolve. Cyber resilience, AI governance, and business strategy are no longer separate conversations - they are now the same discussion.** ### Who really owns your data? URL: https://katecarruthers.com/who-really-owns-your-data/ Last updated: 2026-06-22T22:37:47.000Z I have been chatting with friends lately about the outrageous way data brokers scoop up our information and sell it on to whoever will pay. That “data exhaust” then becomes fuel for bad actors and spammers, who use it to track, target, and harass us in ways most people never agreed to and barely understand. ## Cyber, privacy and data sovereignty Over the past few years, [“cyber”, “privacy”, and “data sovereignty”](https://sustainableatlas.org/post/explainer-data-privacy-digital-sovereignty-primer-1607?ref=katecarruthers.com) have been treated as separate workstreams, with separate teams, frameworks, and regulators. In practice, they are now the same problem seen from three different angles: who controls data, who can see it, and who can compel it. [Self sovereign identity](https://en.wikipedia.org/wiki/Self-sovereign%5Fidentity?ref=katecarruthers.com) sits squarely inside that overlap. It offers a possible path towards more user control and data minimisation, while also exposing how dependent most current digital systems remain on centralised intermediaries, offshore platforms, and legal jurisdictions that users do not control. ## From security and privacy to sovereignty Most organisations grew up with a familiar split. Cyber security teams focused on keeping systems and networks resilient against attack. Privacy and legal teams focused on how personal information was collected, used, and disclosed under data protection law. [Data sovereignty](https://iseek.com.au/blog/blog-3-cyber-resiliency-and-data-sovereignty-is-a-big-deal-for-all-australians-and-so-it-should-be/?ref=katecarruthers.com), if it appeared at all, was often reduced to a procurement question about where cloud data centres sat and which jurisdiction’s laws applied. **But now that separation no longer works well enough.** In a cloud first and AI saturated environment, every meaningful privacy decision has a cyber dimension, and every cyber decision has a [sovereignty](https://www.huntress.com/cybersecurity-101/topic/data-sovereignty?ref=katecarruthers.com) dimension. Where logs and telemetry are stored determines which government can subpoena them. Where training data lives shapes which regulator can govern its use. Where identity and access management resides determines who can reach into the control plane. Data sovereignty is often described in simple terms: *data is subject to the laws and governance of the country where it is stored and processed*. That sounds technical, but it goes to the heart of power and control. If critical data and security telemetry sit offshore, then part of the risk posture has effectively been outsourced to a foreign legal system. ## Why jurisdiction is now a security control The old model treated “*where the data lives*” as a compliance line item. Tick the box for local hosting, note a security certification, and move on. That approach is no longer sufficient. Jurisdiction has become a first order security control because it determines which agencies can lawfully demand access, shapes what happens in a breach, influences which threat actors see infrastructure as strategically important, and conditions how easily [sovereign monitoring and response](https://www.interactive.com.au/insights/data-centre-sovereignty-australia/?ref=katecarruthers.com) can be established. Australian organisations are increasingly paying attention to this. There are stronger expectations that cyber services, security operations, and data centre capabilities should be [sovereign](https://www.serversaustralia.com.au/articles/business/data-sovereignty-in-australia?ref=katecarruthers.com) by default, with data, monitoring, and incident response retained within Australian borders and governed by Australian law. **Yet sovereignty without privacy becomes surveillance, and privacy without sovereignty is fragile. Both are needed.** ## Privacy as user level sovereignty Privacy law has always been, at least on paper, about individual rights such as consent, access, correction, and purpose limitation. In practice, many identity and data architectures still treat users as objects to be administered by large platforms. Accounts are provisioned, identities are federated, tokens are issued, and people have limited control over the resulting [data exhaust](https://sustainableatlas.org/post/explainer-data-privacy-digital-sovereignty-primer-1607?ref=katecarruthers.com). [Self sovereign identity](https://www.okta.com/identity-101/self-sovereign-identity/?ref=katecarruthers.com), or SSI, is one response to that imbalance. At its core, SSI is a digital identity model where individuals control their identity credentials rather than relying entirely on centralised identity providers. Users hold verifiable credentials in digital wallets and decide what information to share, with whom, and at what level of detail. A service can verify that a credential is valid without needing to ingest every piece of underlying personal data. There is, however, an important debate about how far the “self sovereign” label actually takes us. An old friend, [Steve Wilson](https://datarevolution.tech/steve-wilson/?ref=katecarruthers.com), a Australian based identity and privacy researcher, has been influential in keeping these discussions grounded in data protection, assurance, and institutional realities rather than hype. His work is especially useful because it reminds practitioners that [identity](https://diginomica.com/fall-event-highlight-steve-wilson-says-digital-identity-dead-so-where-do-we-go-here?ref=katecarruthers.com) is fundamentally about proving things about people in context, not simply “*owning*” a digital object. That emphasis matters when organisations are tempted to treat SSI as a branding exercise rather than a deeper redesign of how data is collected, verified, and shared Instead of logging in through a central identity provider that sees and mediates every transaction, [SSI](https://www.envisioning.com/research/horizons/self-sovereign-identity-ssi?ref=katecarruthers.com) allows the user to present cryptographically signed proofs directly to relying parties. In practical terms, that means proving enough for the transaction, such as being over 18 or holding a professional qualification, without disclosing the entire identity record. 💡 For readers who want to explore Wilson’s perspective further, his [Internet Society profile](https://www.internetsociety.org/author/swilson/?ref=katecarruthers.com), his [Data Revolution interview page](https://datarevolution.tech/steve-wilson/?ref=katecarruthers.com), and the ConsenSys [State Change episode on digital identity](https://soundcloud.com/consensys/steve-and-christian-mixdown?ref=katecarruthers.com) are useful entry points. ## Self sovereign identity as a privacy preserving layer [Modern SSI designs](https://pmc.ncbi.nlm.nih.gov/articles/PMC9371034/?ref=katecarruthers.com) make use of decentralised identifiers, verifiable credentials, and increasingly privacy preserving cryptography such as zero knowledge proofs. These approaches allow a person to prove that a statement about them is true without revealing the underlying raw data. A person can prove they meet an age threshold without disclosing their full date of birth, or prove membership status without exposing unrelated profile attributes. Several important consequences follow: - [Minimisation](https://arxiv.org/pdf/2603.06896.pdf?ref=katecarruthers.com) becomes easier because only the attributes required for a transaction need to be disclosed. - Data aggregation is reduced because there is no single identity provider observing every interaction. - [User agency](https://arxiv.org/html/2502.02520?ref=katecarruthers.com) is strengthened because consent can become more granular and technically enforceable. - Privacy by design is more achievable because the [architecture](https://cpl.thalesgroup.com/blog/encryption/data-sovereignty-privacy-governance?ref=katecarruthers.com) itself limits unnecessary collection and retention. From a cyber perspective, SSI can also reduce the honey pot value of large centralised identity stores. If fewer institutions need to retain full identity records for routine transactions, some categories of breach impact can be reduced, even though new risks are introduced around wallet security, key management, and implementation quality. Wilson’s long standing scepticism about simplistic “identity on the blockchain” narratives is useful here. Commentary associated with his research and public appearances stresses that things like public blockchains do not magically solve assurance, privacy, or trust, because real world identity still depends on issuers, governance arrangements, and institutions that stand behind credentials. ## Where data sovereignty and SSI meet **The most interesting part of this concept is where macro level data sovereignty and micro level identity sovereignty begin to overlap.** At the macro level, data sovereignty is about the legal and political control exercised over data by states and institutions. At the micro level, SSI is about giving individuals more practical control over how identity data is disclosed and reused. Both are responses to unaccountable concentration of power. For Australian organisations, this intersection has practical consequences. - If core identity platforms remain subject to foreign legal regimes, local data sovereignty ambitions will always be constrained. - If [SSI and related privacy preserving architectures](https://eujournal.org/index.php/esj/article/view/20401?ref=katecarruthers.com) are ignored, organisations may continue embedding over collection into systems that should be moving towards minimisation. - If AI and analytics pipelines are designed without considering where identity proofs and attributes live, meaningful user control will be difficult to provide. - If digital identity is treated only as a convenience layer, its role in resilience, trust, and strategic agency will be underestimated. In that sense, digital identity architecture is no longer a neutral technical choice. It is a direct expression of an organisation’s stance on privacy, control, and dependency. ## What a more aligned approach could look like A more coherent approach starts by treating cyber, privacy, and data sovereignty as one design problem rather than three governance silos. That means building environments where critical data and telemetry are stored and processed within jurisdictions that organisations are prepared to live under, and where oversight is meaningful rather than symbolic. It also means designing identity and access systems around minimisation and selective disclosure, borrowing from SSI principles even where a full SSI stack is not adopted. Privacy impact assessments should examine cloud control planes, cross border data flows, and third country legal powers over vendors in the stack. AI and analytics pipelines should be governed not only by privacy law but also by explicit decisions about infrastructure dependency and jurisdictional exposure. There is room for bounded experimentation in domains where SSI solves real problems. Government digital identity programs, education credentials, health access, and age assurance are obvious candidates. In these settings, verifiable credentials and selective disclosure can reduce unnecessary sharing while maintaining assurance for relying parties. At the same time, it is important to stay realistic. SSI is not a magic fix. Sovereign hosting can increase cost and complexity. Stronger privacy controls can limit some forms of analytics. Wallets, credentials, governance, and recovery processes all need serious design. The point is not technical purity. The point is to align architecture with declared values about **trust**, **resilience**, and **control**. ## Why this matters now For countries like Australia, the strategic issue sits just beneath the operational one. **If critical data, identity systems, and AI workloads all depend on foreign infrastructure and foreign legal systems, then national room for manoeuvre in periods of stress will be narrower than official rhetoric often assumes.** That is why cyber, privacy, and data sovereignty should no longer be discussed in isolation. They are now core questions of institutional design and strategic agency. [Self sovereign identity](https://www.makingdatabetter.com/2195663/episodes/15102131-ep14-steve-wilson-on-nab-digital-next-podcast?ref=katecarruthers.com) does not solve the whole problem, but it does offer a useful lens. It forces a more serious conversation about how much data should be collected, who should mediate trust, and what genuine control might look like for both individuals and institutions. ### Beyond AI sovereignty: why the West relies on US frontier models and what comes next URL: https://katecarruthers.com/beyond-ai-sovereignty-why-the-west-relies-on-us-frontier-models-and-what-comes-next/ Last updated: 2026-06-17T22:22:54.000Z For several years, “AI sovereignty” has been a theme in policy discussions across Europe, Asia, and parts of the Global South. And I have been participating in these conversations amongst the AI practitioners and AI policy wonks for years. The idea was straightforward: **nations should retain control over their data, infrastructure, and increasingly, their AI capabilities**. But in practice, much of the West, particularly countries aligned with the United States, have quietly moved in a different direction. Rather than building sovereign capability, they have defaulted to reliance on US frontier models. The result is that, for many, the sovereignty debate was never truly resolved, it was bypassed. ### The quiet consolidation of AI power While policymakers debated digital sovereignty, the market consolidated. A small handful of US-based firms now dominate frontier AI: - They control the most advanced models - They operate the hyperscale infrastructure required to run them - They set the pace of capability development For most Western countries, the path of least resistance has been adoption rather than autonomy. Enterprise systems, government pilots, and even critical services are increasingly built on top of these models. **This is not sovereignty. It is dependency.** And in a world where AI sovereignty has effectively given way to dependence, frontier models have become a form of critical infrastructure risk, concentrated, externally controlled, and difficult to substitute when access is constrained. ### Why sovereignty lost There are pragmatic reasons why the sovereignty agenda stalled. - **Cost**: Building frontier models and compute infrastructure is prohibitively expensive - **Talent**: Expertise is globally concentrated and highly mobile - **Speed**: Domestic alternatives struggle to keep pace with frontier development - **Network effects**: The best models attract the most users, data, and developers In this context, insisting on sovereign capability can look economically irrational and strategically slow. So most state and commercial actors chose integration over independence. ### The illusion of control Despite this shift, the language of sovereignty persists. Governments talk about: - Data localisation - Regulatory oversight - Trusted AI frameworks But these mechanisms operate at the margins, while the core cognitive infrastructure, the models themselves, remains external. However, it merely creates an illusion of control: - You can regulate inputs and outputs - You can set compliance requirements - **But you do not control the system’s underlying behaviour or evolution** This is a fundamentally different kind of dependency than previous technology waves. ### From sovereignty to strategic dependence If sovereignty no longer reflects reality, we need a more honest way to frame the situation. If what we are seeing is strategic dependence on US AI providers, and the key questions then shift: - What level of dependence is acceptable? - Where are the critical vulnerabilities? - How do you maintain leverage in asymmetric relationships? This is closer to energy security or semiconductor supply chains than traditional IT procurement. It requires a shift in thinking from ownership (that is, we no longer control the means of production) to risk management. ### Interdependence but not symmetry It is tempting to describe this as interdependence. But the relationship is not symmetrical, especially if [one party can unilaterally deny](https://katecarruthers.com/anthropic-fable-5-and-why-sovereign-ai-just-got-real/) other parties access to those resources without notice or consultation. The big US firms: - Set technical standards - Control update cycles - Influence global developer ecosystems While other countries: - Consume and adapt these systems - Layer governance and applications on top **This asymmetry matters, as it shapes everything from economic value capture to strategic autonomy.** ### What comes next If the sovereignty debate has effectively been skipped, the next phase must deal with the consequences. And that means focusing on: - **Resilience**: What happens when access is restricted, degraded, or politicised? - **Substitutability**: How easily can systems switch between providers or models? - **Observability**: How do you understand and audit systems you do not control? - **Assurance**: How can you ascertain that the AI system is and remains safe, compliant, ethical and fit for purpose? - **Leverage**: Where can governments and organisations exert influence in the stack? These are harder, less comfortable, and more realistic questions than sovereignty, and they accept dependency as a starting point. ### Rebuilding agency without illusions The sovereignty window has largely closed for frontier models. Moving forward, if we accept that the goal is not to retroactively achieve full sovereignty, then the task before the rest of us is to **rebuild agency within constraint**. This might include: - Investing in niche or specialised models **where differentiation is possible** - Strengthening **open-source ecosystems** as a counterbalance - Developing **interoperability standards** to reduce lock-in - Building **institutional capability** to govern external AI systems effectively In other words, working with the system as it exists, rather than the one we might have preferred. ### A more honest conversation The AI sovereignty debate was important. But in much of the West, it has already been overtaken by events. We are now operating in a world where: - Frontier AI is concentrated in a handful of US firms - Adoption has outpaced governance - Dependency is structural, not incidental Perhaps the question now is no longer whether we should have sovereignty - it is how we navigate a landscape where we do not have sovereignty. And that requires a more honest, and more strategically mature, conversation than we have had so far. ### The hidden politics of AI: sovereignty in a platform world URL: https://katecarruthers.com/the-hidden-politics-of-ai-sovereignty-in-a-platform-world/ Last updated: 2026-06-15T00:50:23.000Z AI sovereignty is no longer an abstract policy concern - it is now a live operational risk. When critical institutions can be constrained by platform providers, and AI systems embed governance choices by design, the question shifts from “*who regulates AI?*” to “*who controls the systems we depend on?*” The signals have been visible for years. Now they are unavoidable. ## ICC - the canary in the coalmine When [Microsoft reportedly blocked email access](https://www.computerweekly.com/opinion/Microsofts-ICC-email-block-reignites-European-data-sovereignty-concerns?ref=katecarruthers.com) for International Criminal Court officials, the reaction in many policy and technology circles was surprise. And it shouldn’t have been. The real question is not “*how could this happen?*” but “*why didn’t you read the tea leaves?*” Because the signals have been visible for years. We have been steadily outsourcing critical institutional capability - communications, data, infrastructure - to a handful of private technology providers operating under specific national jurisdictions. **This was always going to collide with sovereignty.** ## The illusion of neutral infrastructure For a long time, cloud platforms and software providers were treated as neutral infrastructure - like electricity or plumbing. Reliable, scalable, and politically inert. And that assumption no longer holds. Technology platforms are subject to the legal, political, and strategic priorities of the jurisdictions in which they are headquartered. When push comes to shove, they cannot be neutral. They will comply with state power. **The ICC incident is not an anomaly. It is a case study.** If an international legal body can have its access constrained by a private company, then sovereignty is no longer just about territory or law. It is about who controls the systems your institutions depend on. ## AI changes the stakes **Now layer AI on top of this.** We are not just talking about email or cloud storage anymore. We are talking about systems that mediate decision-making, shape information flows, and increasingly act on behalf of users and organisations. The recent “[Anthropic directive](https://katecarruthers.com/anthropic-fable-5-and-why-sovereign-ai-just-got-real/)” controversy - where system-level constraints and behavioural shaping became visible - should be read in this context. It is not just a product design issue. It is a governance signal. - Who decides what an AI system can say, prioritise, or refuse to do? - Who sets those boundaries - and under whose authority? **These are not abstract questions. They are questions of control.** ## Sovereignty is becoming computational Sovereignty is no longer just exercised through borders, laws, and institutions. It is increasingly exercised through code, models, and infrastructure. This creates a new layer of dependency: - Dependence on foreign-owned compute infrastructure - Dependence on proprietary foundation models - Dependence on platform-level policy decisions embedded in AI systems Each of these dependencies introduces potential points of control - or failure. And unlike traditional supply chains, these dependencies are often opaque. The governance mechanisms are buried in terms of service, API constraints, and model behaviour that is difficult to audit. ## Nations, culture, and strategic advantage What is often missing from the AI sovereignty conversation is the role of national character - what we might think of as the “*folk*” layer of strategy. Countries do not approach AI in a vacuum. They bring with them distinct traditions about authority, knowledge, risk, and control. These shape not only regulation, but how AI systems are designed, deployed, and constrained. Some states approach AI as an instrument of state coordination and long-term strategic advantage. Others treat it as a market-driven capability, tempered by rights-based safeguards. Still others are attempting to reconcile innovation with deeply embedded social or cultural norms. **This matters because AI systems carry these assumptions with them.** The idea of “*respect*” for AI - how much autonomy it is given, how tightly it is controlled, how much it is trusted in decision-making - varies across jurisdictions. In some contexts, AI is treated as a tool to be tightly bounded. In others, it is positioned as a collaborator or even a strategic actor. These differences are not philosophical curiosities. They translate directly into national advantage. - Countries that align AI development with industrial policy can accelerate capability at scale - Countries that embed AI deeply into statecraft gain leverage in intelligence, defence, and diplomacy - Countries that fail to develop internal capability risk becoming rule-takers in systems they do not control In this sense, AI sovereignty is not just defensive. It is also about ambition. ## The strategic blind spot Many organisations - and governments - are still treating AI adoption as a purely technical or economic decision. It is not. **It is a sovereignty decision. And decisions made now will determine national fates for decades.** Choosing a model provider, a cloud platform, or an AI development stack is also choosing a set of embedded governance assumptions. It is accepting constraints that may only become visible under stress. The ICC and Anthropic examples illustrate what happens when those constraints surface unexpectedly. The Anthropic directive illustrates that they are already being designed into systems from the outset. ## What “seeing” looks like So what does it mean to actually “see” what is happening? It means recognising that: - AI systems are not neutral tools; they are governed artefacts - Platform providers are not just vendors; they are geopolitical actors - Technical architecture decisions are also political decisions And it means acting accordingly. This does not necessarily imply full technological autarky - that is neither realistic nor desirable. But it does require a more deliberate approach to dependency management, capability development, and governance design. At a minimum, this includes: - Understanding where critical dependencies sit in your AI stack - Assessing jurisdictional exposure and legal risk - Building optionality into systems and vendor relationships - Investing in internal capability to evaluate and govern AI systems ## The end of naivety I have, and will continue to argue, that we are moving out of a period of technological naivety. The idea that we could build globally integrated digital systems without confronting questions of power and control was always optimistic. AI is simply forcing the issue. The tea leaves were always there: in export controls, in data localisation laws, in platform moderation policies, in the gradual securitisation of technology supply chains. The ICC incident simply made it visible. The behaviour of AI systems is making it unavoidable. The question now is not whether sovereignty matters in AI. **It is whether institutions - and nations - are willing to act as if it does.** ### Talking about rebranding Data Governance URL: https://katecarruthers.com/talking-about-rebranding-data-governance/ Last updated: 2026-07-15T22:23:07.000Z The other day I was in Melbourne speaking at the [Data Protection & Security Summit 2026](https://www.clutchevents.co/events/melbourne-data-protection-summit-2026?ref=katecarruthers.com) on one of my favourite topics - how [data governance needs a rebrand](https://katecarruthers.com/data-governance-needs-a-rebrand/). ### Anthropic, Fable 5, and why sovereign AI just got real URL: https://katecarruthers.com/anthropic-fable-5-and-why-sovereign-ai-just-got-real/ Last updated: 2026-06-17T23:54:51.000Z Many folks in Australia have been talking about sovereign AI and sovereign risk for a while, and now the US government has just made it real. The US government did something extraordinary: on 12 June 2026 (US time) it [forced Anthropic to shut down access](https://www.anthropic.com/news/fable-mythos-access?ref=katecarruthers.com) to its most powerful AI models, Fable 5 and Mythos 5, issuing an > "export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees" Not because of a proven harmful incident, but because of a narrow “[jailbreak](https://www.theregister.com/security/2026/06/15/feds-freaked-over-fable-5-after-simple-fix-this-code-prompt-not-jailbreak-says-researcher/5255827?ref=katecarruthers.com)” that, by Anthropic’s account, offers no more capability than what other widely available models already provide. For those of us working in AI governance, this is a case study in how *not* to do frontier model regulation. And it is a very clear demonstration of the risks involved in reliance on AI models that are under the **sovereign control** of another nation state that has **national security imperatives** that might not align with your own. We are in a very different geopolitical landscape to that we were in only a few years ago. Now AI is being seen through the lens of **strategic national advantage** and some folks are clearly playing hardball. ## What actually happened? On 12 June 2026 (US time), [Anthropic published a statement](https://www.anthropic.com/news/fable-mythos-access?ref=katecarruthers.com) explaining that the US government had issued an export control directive covering Fable 5 and Mythos 5\. The order bars access by any “foreign national,” inside or outside the United States; in practice, Anthropic says it has disabled both models for **all** customers to remain compliant. A few key facts from Anthropic’s statement: - The directive arrived at 5:21pm ET with no written technical rationale beyond a national security assertion. - Officials indicated they had become aware of a method of bypassing (or “jailbreaking”) Fable 5’s safeguards. - The specific example shown involved asking the model to read a particular codebase and fix software flaws, reproducing a “small number of previously known, minor vulnerabilities.” - Anthropic says comparable vulnerabilities can also be found by other publicly available models, without any safeguard bypass at all. Anthropic is complying with the order, but it is clearly pushing back. The company explicitly states that it *disagrees* that such a narrow potential jailbreak justifies recalling a model already in commercial deployment to “hundreds of millions of people.” ## Fable’s safeguards and the jailbreak debate Recall that Fable 5 was the “safe” Mythos‑class model designed to make high‑end capabilities usable by the public while sharply limiting risky cyber, biosecurity, and other high‑hazard behaviours. [Anthropic’s original launch framing](https://www.engadget.com/2190934/anthropic-fable-ai-brings-the-capabilities-of-its-unreleased-mythos-model-to-regular-users/?ref=katecarruthers.com) for Fable leaned heavily on safety: - Strong safeguards to make cyber misuse “very unlikely,” to the point that many users complained they were **too** restrictive. - **Extensive pre‑launch red‑teaming** with the US government, the UK AI Safety Institute, third‑party organisations, and internal teams “for thousands of hours” before release. - **Internal testing** that suggested Fable’s safeguards were “substantially more effective than those of any previously deployed model.” In the new statement, Anthropic also makes several important admissions and claims that are worth surfacing for governance discussions: - No one has yet found a *universal* jailbreak for Fable 5 - that is, a technique that broadly removes its safeguards across many cyber‑capability domains. - Anthropic does not believe “perfect jailbreak resistance” is possible with today’s techniques; in their view, all deployed models remain vulnerable to *non‑universal* jailbreaks in some circumstances. - Their architecture for Fable 5 was explicitly “defence in depth”: make jailbreaks narrow or expensive, and combine this with strong monitoring and telemetry. This is why Anthropic introduced a controversial 30‑day data retention requirement for Fable traffic: they wanted to be able to detect and study jailbreak attempts and shut down emergent harms quickly. That trade-off - more logging for more safety - was already raising eyebrows in privacy circles long before this directive. Crucially, Anthropic says it has *not* received evidence of a concerning non‑universal jailbreak that has produced a harmful result. The reports they have seen, which they believe underlie the directive, show a level of vulnerability‑hunting capability they say “is widely available from other models (including OpenAI’s GPT‑5.5) and is used every day by defenders who keep systems safe.” If that’s accurate, the core question becomes: why shut down Fable 5 and Mythos 5, but not every other competitive frontier model? ## A governance failure in real time Anthropic’s statement contains a line that should be pinned to every current debate about AI regulation: > “We believe the government should have the ability to block unsafe deployments, as part of a statutory process that is transparent, fair, clear, and grounded in technical facts. This action does not adhere to those principles.” This gets to the heart of the governance problem. From a public‑interest perspective, it is entirely reasonable for governments to have last‑resort powers to stop dangerous model deployments, especially when those models enable scalable cyber or bio harms. But those powers must be: - **Transparent**: Stakeholders need to understand the technical basis for a decision, at least in outline. Here, Anthropic reports only “verbal evidence” and no formal disclosure of a harmful jailbreak with concrete impacts. - **Consistent**: If a narrow exploit that other models can replicate triggers a shutdown for Anthropic, we would expect symmetrical treatment for other providers. Anthropic warns that, applied uniformly, this standard would “essentially halt all new model deployments for all frontier model providers.” - **Legible internationally**: This is an export‑control style intervention with immediate extra‑territorial effect, including for organisations and users in Australia and other allied countries who were relying on Fable’s “safe” profile for legitimate use cases. Instead, what we’re seeing looks more like a blunt, opaque national security reflex. From the outside, it is hard not to read this as the **US treating frontier‑model control as a matter of strategic advantage, with limited concern for the impacts on allied jurisdictions or the credibility of emergent AI‑safety regimes**. ## Why this matters from Australia From an Australian vantage point, several implications stand out. 1. This is a live demonstration of *regulatory dependency*. **If you build critical workflows on US‑hosted frontier models, you are also implicitly accepting that US export‑control and national security decisions can break those workflows overnight, without consultation or appeal.** That is true whether you are a bank, a hospital, or a government agency in Sydney, Delhi, or Berlin. 2. The case **undercuts the narrative that “safety‑first” providers will be rewarded for going slower and investing more in safeguards**. Anthropic emphasises that Fable’s safeguards are, in their view, stronger than any prior model deployed at this scale, and that they voluntarily accepted higher data‑retention costs to enable more robust monitoring. Yet they are the first to be hit with a sweeping suspension that does not appear to apply to models with weaker guardrails. 3. It sharpens the **need for *transparent, multi‑lateral* mechanisms for managing frontier‑model risks**. If a narrow exploit exists that can be weaponised at scale, that information should be quickly shared with other providers and with trusted public‑interest actors, so that mitigations can be developed and tested across the ecosystem. At present, we have a situation where: - An undisclosed actor demonstrates a jailbreak to US authorities. - US authorities issue a broad directive targeting a single provider. - The rest of the world is left to infer the threat model from a few lines in a corporate blog post. That is not a sustainable pattern for a technology that is rapidly being embedded into critical infrastructure. ## Where we should go from here Anthropic ends its statement by apologising to customers and characterising the directive as a “*misunderstanding*” that it hopes to resolve quickly. That may be optimistic. Once national security bureaucracies have asserted this kind of power, they tend to keep it. For policymakers and boards thinking about AI governance and strategy, this incident is a timely prompt to: - **Stress‑test AI‑dependence assumptions**: What happens if your primary model provider is abruptly switched off? Do you have viable alternatives, including local options? - **Push for principled statutory frameworks**: Model‑recall powers should exist, but they must come with due process, clear technical thresholds, and some form of independent scrutiny. - **Treat “AI safety” as geopolitics**: Export controls, access restrictions, and selective crackdowns are not just about harm prevention; they are also tools of industrial and strategic policy. Anthropic is right on at least one point: if the mere existence of narrow, non‑universal jailbreaks becomes the bar for shutting down deployment, very few advanced models will remain online for long. The real governance work lies in building regimes that can live with imperfect safeguards, manage residual risk, and intervene proportionately when systems actually cross red lines. 💡 ****Until then, those of us outside Washington will remain subject to US national security decisions we cannot see, cannot contest, and cannot predict - and that should worry anyone who cares about both AI safety and democratic accountability.** ### AI’s Hidden Extraction Economy URL: https://katecarruthers.com/ai-extraction-work-of-repair/ Last updated: 2026-06-10T03:32:30.000Z There is a persistent story doing the rounds that artificial intelligence is somehow weightless. A mind in the cloud. A clever assistant. A productivity layer. A tool that appears when summoned, produces an answer, and disappears again. But it isn’t any of those things. **AI is not magic.** It is infrastructure. And like all infrastructure, it has supply chains, labour practices, governance failures, environmental costs, and power relations built into it. Kate Crawford makes this point clearly in [*Atlas of AI*](https://katecrawford.net/atlas?ref=katecarruthers.com). AI is not artificial in the sense of being detached from the earth, and it is not intelligent in the human-like way that much public discourse imagines. Contemporary large-scale AI is built from minerals, energy, water, data, labour, logistics, cloud infrastructure, and institutional choices. That matters because the dominant story about AI still tends to frame it as a solution looking for problems. We are told that AI will improve public services, personalise education, accelerate medicine, optimise climate action, and make organisations more efficient. Some of that may be true. Machine-learning systems can support accessibility, scientific discovery, public health, climate modelling, and better service delivery. But usefulness is not the same as justice. A system can create value in one place while shifting costs somewhere else. **And that is the point we need to keep coming back to.** The ethical question is not simply whether AI can do good. It is whether a particular system is necessary, proportionate, accountable, and governed by the people whose data, labour, communities, and environments make it possible ([Floridi et al., 2021](https://link.springer.com/chapter/10.1007/978-3-030-81907-1%5F9?ref=katecarruthers.com)). Underneath the marketing language of **“AI for good”** sits an older story. **And that is the story of extraction.** Not just the extraction of data, although that matters. Not just the extraction of labour, although that matters too. AI also extracts minerals, energy, water, attention, culture, institutional capacity, and trust. If we want to govern AI properly, we have to stop treating those costs as externalities. They are the system. **AI is built on hidden work.** One of the most persistent myths about AI is that it replaces people. But more often, it hides them. Behind the clean interface and the instant answer sits an enormous amount of human work. Data has to be collected, cleaned, labelled, filtered, moderated, evaluated, and corrected. Model outputs have to be rated. Unsafe outputs have to be identified. Edge cases have to be tested. In many generative AI systems, [reinforcement learning from human feedback](https://openai.com/index/learning-from-human-preferences/?ref=katecarruthers.com) depends on people making judgments about which outputs are more useful, more acceptable, or less harmful. **This is not incidental. It is part of the production process.** [Mary L. Gray and Siddharth Suri](https://books.google.com/books?id=8AmXDwAAQBAJ&ref=katecarruthers.com) call this **ghost work**: human labour hidden behind systems that are designed to look automated. That phrase matters because it punctures the illusion. The machine is not doing all the work. People are doing work that has been made difficult to see. Some of this work is data annotation. Some of it is content moderation. Some of it is evaluation, red-teaming, and safety testing. Some of it is the ongoing work of keeping digital systems usable for everyone else. [Sarah T. Roberts](https://yalebooks.yale.edu/book/9780300235883/behind-the-screen/?ref=katecarruthers.com) has shown that commercial content moderation is not a marginal clean-up activity. It is a central condition of the modern internet. ## AI does not make this labour disappear. It reorganises it. Cognitive and linguistic tasks are broken into smaller units. Judgment is turned into workflow. Human context becomes training signal. The people doing this work are often far from the product launch, far from the venture capital announcement, and far from the prestige economy of AI. **That should trouble us.** Because when the work is invisible, the risks are invisible too. Pay, trauma, safety, bargaining power, attribution, and accountability all become easier to ignore. And if an AI system cannot be built without hidden, poorly governed labour, then we should be honest about what kind of efficiency is being claimed. ## Public data is not free raw material The second extraction problem is **knowledge**. Large-scale AI systems do not learn from nowhere. They are trained on text, images, code, records, archives, forum posts, books, social media, public websites, technical documentation, and the accumulated labour of millions of people. Much of that material was created under very different assumptions. People wrote blog posts for a small audience. They answered questions in forums to help a stranger. They contributed to open-source projects. They uploaded art. They shared stories in communities. They built public knowledge resources for public purposes. Then that material became training data. This is where the phrase **“publicly available data”** does too much work. Publicly available does not mean socially unencumbered. Access is not the same as consent. Scrapeable is not the same as fair game. A poem, a support-forum post, an open-source repository, a Wikipedia contribution, and a private grief shared in a public-ish place are not the same kind of thing simply because a crawler can reach them. Context matters. Purpose matters. Consent matters. Governance matters. This is not only a copyright issue, although copyright matters. It is also a data governance issue. - What was collected? - For what purpose? - Under what authority? - With what documentation? - Who can contest it? - Who benefits? - Who carries the risk? Work on dataset documentation, such as **datasheets for datasets**, exists because datasets have histories, limitations, intended uses, and social conditions that need to be made visible ([Gebru et al., 2018](https://arxiv.org/abs/1803.09010?ref=katecarruthers.com)). Without that discipline, collective knowledge goes in and proprietary systems come out. **That is not innovation on its own. It is enclosure.** ## The cloud is not weightless **The third extraction problem is material.** We still talk about “the cloud” as though it floats above us. It does not. It sits in data centres, transmission lines, substations, cooling systems, fibre networks, land, water, and hardware supply chains. Crawford and Vladan Joler’s [*Anatomy of an AI System*](https://anatomyof.ai/?ref=katecarruthers.com) makes this visible by tracing the Amazon Echo through mineral extraction, labour, data flows, logistics, cloud infrastructure, and e-waste. That kind of mapping is useful because it forces us to look past the device and past the interface. The device is only the visible part. The system is much larger. And the language matters here. It is not accurate enough to say AI depends on “rare earths” and leave it there. Some digital components do use rare earth elements, but AI and data infrastructure also depend on critical minerals such as lithium, cobalt, nickel, copper, gold, tantalum, tin, and tungsten. These are not all rare earth elements, but they are all part of the broader material reality of digital systems. **The same is true of energy and water.** Training and running AI systems requires compute. Compute requires chips, servers, electricity, cooling, maintenance, and replacement cycles. The footprint varies by model, location, data centre design, energy mix, and use case, so we should be careful about overclaiming. But we should be just as careful about under-governing. In a [CIGI interview](https://www.cigionline.org/big-tech/kate-crawford-on-the-toll-ai-is-taking-on-humans-and-the-planet/?ref=katecarruthers.com), Crawford argues that AI is an extractive industry not only because it draws on data, but because it draws on labour, time, and natural resources. She also notes that the true resource costs of commercial AI systems are hard to assess because so much relevant information is held by companies as proprietary knowledge. **That should be a governance red flag.** If we cannot properly see the energy, water, land, labour, and materials required to run these systems, then we cannot properly decide which uses are worth it. A model used to improve emergency response is not the same as a model used to generate disposable marketing sludge. A system that supports accessibility is not the same as one that produces spam at scale. A tool that helps clinicians is not the same as one that automates surveillance or punishment. 💡 The question is not “AI or no AI?” The question is: what for, at what cost, and under whose control? ## AI changes work because it changes power The labour-market conversation around AI is often framed in apocalyptic terms. The robots are coming for all the jobs. Or, on the other side, AI will magically free everyone from drudgery. We have seen this movie before. The evidence is still developing. A recent [Stanford Digital Economy Lab overview](https://digitaleconomy.stanford.edu/news/ai-and-labor-markets-what-we-know-and-dont-know/?ref=katecarruthers.com) argues that aggregate employment effects appear limited so far, but that some impacts may be concentrated among AI-exposed entry-level workers. The [Australian Parliamentary Library](https://www.aph.gov.au/About%5FParliament/Parliamentary%5Fdepartments/Parliamentary%5FLibrary/Research/Issues%5Fand%5FInsights/48th%5FParliament/potentialimpactofArtificialIntelligence?ref=katecarruthers.com) similarly emphasises uncertainty: AI may improve productivity and create new tasks, but it may also increase inequality, concentrate gains, and affect workers unevenly across occupations and demographic groups. **So, we should be careful about simple predictions.** But we do not need to wait for perfect labour-market data to see the governance problem. **AI changes work because it changes power.** It changes who gets to decide how work is measured. It changes what counts as expertise. It changes who is visible and who is replaceable. It changes where accountability sits. When AI is embedded in productivity suites, contact centres, HR systems, education platforms, welfare systems, and public administration, it does more than automate tasks. It reshapes the environment in which decisions are made. Workers can become dashboards. Judgment can become a score. Context can be flattened into a metric. Autonomy can be traded away in the name of efficiency. This is where the “augmentation” story needs scrutiny. Augmentation for whom? On whose terms? With what rights to challenge the system? With what ability to refuse? 💡 These are not feature questions. They are power questions. ## We cannot unring the bell **There is no clean return to a pre-AI world.** The models exist. The data centres exist. The procurement processes are underway. The investment has been made. The tools are being embedded into everyday software. People are already changing how they work, write, search, code, decide, and organise. We cannot unknow what we now know how to build. But that does not mean the current path is inevitable. This distinction matters. Irreversibility is not the same thing as inevitability. AI’s extractive form is not a law of nature. It is the result of choices about scale, ownership, data rights, labour conditions, procurement, environmental disclosure, security, and institutional governance. 💡 The bell has been rung. That does not mean we hand the bell tower to a handful of vendors and hope for the best. ## Governance cannot be bolted on at the end If there is one practical lesson here, it is this: governance cannot be an afterthought. We cannot build vast AI systems first and then sprinkle ethics on top. We cannot run pilots, create shadow AI, accumulate data, sign vendor contracts, and only then ask whether the system is safe, fair, sustainable, or necessary. That way lies the [shemozzle](https://katecarruthers.com/ai-adoption-people-not-technology/). The work has to start earlier. It has to be built into purpose, design, procurement, data collection, model development, deployment, monitoring, retirement, and disposal. | Governance question | Why it matters | | ---------------------------------- | -------------------------------------------------------------------------- | | What problem are we solving? | Prevents AI being used because it is fashionable rather than necessary. | | What data is needed, and why? | Keeps data minimisation and purpose limitation at the centre. | | Who does the hidden labour? | Makes annotation, moderation, evaluation, and red-teaming visible as work. | | What are the material costs? | Forces attention to energy, water, hardware, supply chains, and e-waste. | | Who can contest the system? | Turns accountability from a slogan into a practical right. | | When should the system be stopped? | Treats refusal, rollback, and retirement as part of lifecycle governance. | [Data minimisation](https://katecarruthers.com/data-minimisation-matters/) is a good example. For years it has been treated as a privacy principle that everyone agrees with and then quietly ignores. But in an AI-enabled world, keeping too much data is not just a privacy problem. **It is a security problem, a governance problem, and an extraction problem**. The less unnecessary data an organisation holds, the less there is to misuse, leak, scrape, infer from, or feed into systems without proper accountability. 💡 Data is not just an asset. It is also a liability with compounding risk. ## The hidden workers of AI need rights A serious national and international AI governance agenda must include labour. Not as a footnote. Not as a corporate social responsibility statement. As core infrastructure. The people who label data, moderate content, evaluate outputs, red-team systems, and provide the human judgment that makes AI systems usable need fair pay, safe conditions, psychological support, transparency, and collective power. They also need recognition. If their work is essential enough to make the system function, then it is essential enough to govern properly. The same applies to workers affected by AI deployment. Organisations introducing AI need more than tool policies. They need communication, training, consultation, leadership alignment, and clear accountability. AI adoption is not mainly a technology problem. [It is a people problem](https://katecarruthers.com/ai-adoption-people-not-technology/). **Ignore that, and the result will not be transformation. It will be confusion, resistance, misuse, and risk.** ## We need open institutions, not just open models There is a lot of talk about open AI. Some of it is useful. But open weights or open code are not enough if the [institutions](https://katecarruthers.com/one-size-fits-none-ai-power-and-why-open-institutions-matter/) around them remain concentrated, opaque, and unaccountable. By open AI I generally mean one of the following: - **Open‑source AI** \- These are models where the code, and often the training data, are released under open licences so anyone can inspect, tinker with, and reuse them - think of the many community models on GitHub or Hugging Face. - **Open access AI** \- Here the underlying models stay proprietary, but they’re made widely available through APIs and products so lots of people can build on top of them; “open” here is about reach and availability rather than genuine transparency. - **Open benefit AI** \- In this framing, “open” is about who gains, not how the model is built: the goal is to ensure advanced AI benefits humanity broadly and doesn’t end up tightly controlled by a small group, whether or not the underlying systems are open‑source. **But the deeper question is institutional.** - Who sets the rules? - Who gets heard? - Who can inspect the system? - Who can challenge a decision? - Who benefits from public knowledge? - Who carries the environmental and labour costs? Software and AI are never neutral. They encode choices about identity, visibility, ranking, moderation, access, and control. Those choices can quietly hard-code existing structures of power into the systems that shape everyday life. That is why we need open, public, civic, and community-governed institutions. Not because openness is a magic word, but because concentrated technological power needs counterweights. The history of industrial upheaval is not only a history of machines. It is also a history of [institutions](https://katecarruthers.com/one-size-fits-none-ai-power-and-why-open-institutions-matter/): unions, mutual aid, cooperatives, public libraries, professional bodies, standards organisations, and regulatory systems. The AI age will need its own institutions too. **Not just better products. Better counter-power.** ## Doing the work We cannot unring the AI bell. We have eaten of the tree of AI knowledge. The systems are here, and they will keep changing how organisations and societies operate. **But we can refuse the lazy story that extraction is inevitable.** AI does not have to mean endless data hoarding, invisible labour, environmental opacity, vendor lock-in, and weak accountability. Those are choices. Profitable choices, in many cases. Convenient choices. But choices nonetheless. **The work now is practical and political.** Build data minimisation into systems. Make hidden labour visible and properly protected. Demand environmental disclosure. Treat AI as lifecycle infrastructure. Strengthen public procurement. Support open and community-governed institutions. Give affected people meaningful rights to challenge, refuse, and shape the systems being built around them. **This is not glamorous work. It is governance. It is institutions. It is accountability. It is doing the work.** And if AI is going to be part of our future, then that work matters more than ever. ### Reflections from 2024: Innovating when the ground is moving URL: https://katecarruthers.com/reflections-from-2024-innovating-when-the-ground-is-moving/ Last updated: 2026-06-05T09:18:19.000Z It is interesting to read back on old posts sometimes. One I came across is titled: [AI Changes Everything](https://katecarruthers.com/ai-changes-everything/). Way back in June 2024 I travelled to Boston to speak at [FEI: Front End of Innovation](https://informaconnect.com/feiusa/new-for-2024/?ref=katecarruthers.com) conference, invited by old friend [Seth Adler](https://www.linkedin.com/in/sethjadler?ref=katecarruthers.com) to speak about how AI was about to change everything. FEI has a long history of bringing together innovators, R&D and product leaders, strategists, and insight teams to focus on the messy, early stages of innovation where ideas are still fragile and undefined. ## We are in the earliest of times In that 2024 talk, and in the companion piece I wrote, “[AI Changes Everything](https://katecarruthers.com/ai-changes-everything/)”, I argued that we are not even at “*the end of the beginning*” of AI. We are in the earliest of times, when bold utopian and dystopian claims are being thrown around, and when businesses are still trying to work out whether AI is a durable shift or another passing fad like NFTs. From my vantage point I could foresee that AI will have a profound long‑term impact on how we live, work, educate, fight wars, grow food and collaborate with both humans and machines. FEI felt like a live cross‑section of that moment. In the corridors and sessions you could hear the tension between excitement and uncertainty: people sense that “AI changes everything,” but they are still trying to understand what that actually means for their teams, customers, and governance. ## AI at the front end of innovation My session explored how AI is changing the front end of innovation - the fuzzy space where we scan horizons, frame problems and test early ideas. Rather than treating AI as a magical idea machine, I framed it as a partner in sense‑making: a way to widen our search, see patterns and interrogate assumptions, while still relying on human judgment, ethics and context to decide what matters. This is where robust data foundations, good governance, and clear boundaries for experimentation become critical. Many of the leaders I spoke with at FEI shared stories of pilots that never scaled, tools adopted without proper oversight, or cultural resistance that turned AI into either a novelty or a threat. What emerged was a shared recognition that AI adoption is as much a people and institutions problem as it is a technology problem - a theme I explore further in my ongoing [writing](https://katecarruthers.com/) and [podcast](https://datarevolution.tech/?ref=katecarruthers.com) work. ### Innovation in the “trough of disillusionment” In “[AI Changes Everything](https://katecarruthers.com/2024/06/14/ai-changes-everything/)” I referenced the [Gartner hype cycle](https://katecarruthers.com/gartner-hype-cycle-ai-governance/) and the looming *Trough of Disillusionment* (I always prefer to call this the *Slough of Despond*). FEI confirmed that many organisations are already entering that phase: the first wave of experimentation had collided with reality, and now the hard work was just starting. For me, this is not a cause for pessimism. It is an invitation to innovate more thoughtfully. It is the moment to move beyond hype toward durable practices: investing in capability uplift, building interdisciplinary teams, putting governance in place, and learning how to use AI to augment rather than replace human expertise. FEI 2024 made it clear that those who treat this as a long‑term systems shift - not just a tool rollout - will be better positioned for what comes next. ## Looking ahead Leaving Boston, I felt a mix of realism and cautious optimism. The conference reinforced my belief that while AI may change almost everything about how we operate, the fundamental questions of innovation remain the same: how we create value, how we steward risk, and how we design [institutions](https://katecarruthers.com/one-size-fits-none-ai-power-and-why-open-institutions-matter/) that can adapt over time. ### Context and control: the real future of AI in the enterprise URL: https://katecarruthers.com/context-control-ai-enterprise/ Last updated: 2026-05-29T00:18:37.000Z We are witnessing a subtle but significant shift in the evolution of artificial intelligence. The dominant narrative over the past few years has been shaped by generative AI, including large language models, image generators, and conversational interfaces that captured public imagination and corporate attention alike. But that phase, while transformative, was only the beginning. The centre of gravity is now moving. AI is transitioning from a novelty interface to something far more consequential: an **enterprise execution engine**. This shift is not about bigger models or more impressive demos. It is about **embedding AI into the operational fabric of organisations**, into workflows, decision systems, and institutional processes. In this transition, two factors are emerging as critical: context and harnesses. ## From outputs to outcomes Generative AI excelled at producing outputs such as text, code, and images. But enterprises do not run on outputs; they run on outcomes. That requires reliability, repeatability, and alignment with organisational goals. A chatbot that writes a clever paragraph is interesting. An AI system that consistently drafts compliant regulatory reports, integrates with internal data sources, and aligns with organisational policy is transformative. This is where the limitations of early generative AI become clear. Models trained on generalised data lack the situational awareness required for enterprise use. They do not inherently understand your organisation’s risk posture, governance requirements, or strategic priorities. **To move from outputs to outcomes, AI needs context.** ## Context as infrastructure Context is not just better prompting. It is a structured layer of information that grounds AI systems in the reality of the organisation using them. This includes: - Internal data such as documents, policies, and operational data - Domain specific knowledge - Organisational rules and constraints - Real time signals from systems and workflows In effect, context acts as a form of infrastructure, one that transforms a general purpose model into a domain aware system. Retrieval augmented generation, or RAG, was an early step in this direction, but we are now seeing more sophisticated approaches emerge. Context is becoming dynamic, continuously updated, and tightly integrated with enterprise systems. For organisations, this raises a new set of challenges. Context must be curated, governed, and secured. Poor quality context will degrade AI performance just as surely as poor quality data undermines analytics. This is where data governance and AI governance begin to converge in very practical ways. ## The rise of AI harnesses **If context is what informs AI, harnesses are what control it.** An [AI harness](https://katecarruthers.com/ai-has-changed-the-cyber-threat-landscape/) is the set of structures that constrain, guide, and monitor AI behaviour within an enterprise setting. It is not a single tool, but a combination of mechanisms that ensure AI operates safely and effectively. These include: - Guardrails and policy enforcement layers - Workflow orchestration systems - Monitoring and evaluation frameworks - Human in the loop controls - Audit and logging mechanisms Think of the harness as the difference between a powerful engine sitting on a test bench and that same engine installed in a vehicle with steering, brakes, and instrumentation. The engine provides capability; the harness makes it usable, safe, and aligned with purpose. Without harnesses, generative AI remains unpredictable and difficult to trust at scale. With them, it becomes a reliable component of enterprise architecture. ## AI as part of the stack This shift also changes how we think about AI in organisational design. AI is no longer a standalone capability or a layer bolted on top of existing systems. It is becoming part of the core stack, alongside data infrastructure, applications, and integration layers. This has implications for: - **Enterprise architecture**, with AI as a first class component - **Governance**, with integrated data and AI governance models - **Workforce design**, with humans working with and through AI systems - **Risk management**, with continuous monitoring rather than periodic review **In this model, the question is no longer “Where can we use AI?” but “How does AI reshape the way this process operates?”** ## From experimentation to institution Perhaps the most important aspect of this transition is cultural. The generative AI phase encouraged experimentation through pilots, proofs of concept, and sandbox environments. That was necessary and valuable. But enterprise adoption requires a different mindset, one focused on reliability, accountability, and integration. This is the shift from experimentation to institution. It requires organisations to build new capabilities: - Curating and managing context at scale - Designing and maintaining AI harnesses - Embedding AI into governance frameworks - Aligning AI systems with organisational strategy and values This is not simply a technical challenge. It is an institutional one. ## What comes next As AI becomes an enterprise engine, the competitive advantage will not come from access to models, as those are increasingly commoditised. It will come from how effectively organisations build and manage context, and how well they design the harnesses that shape AI behaviour. In other words, **the future of AI is less about the model, and more about the system around it**. For leaders, this reframes the agenda. The focus shifts from chasing the latest model release to building the organisational infrastructure that makes AI work in practice. That is a much harder, and much more interesting, problem to solve. ### Why observability and assurance are essential in the age of AI agents URL: https://katecarruthers.com/why-observability-and-assurance-are-essential-in-the-age-of-ai-agents/ Last updated: 2026-05-26T22:10:57.000Z [Observability](https://www.rubrik.com/insights/what-is-ai-observability?ref=katecarruthers.com) and [assurance](https://www.digital.nsw.gov.au/sites/default/files/2025-10/ai-agent-usage-and-deployment-guidance.pdf?ref=katecarruthers.com) are now foundational capabilities if you want to use AI agents safely, reliably, and at scale in real organisations. In an environment where autonomous systems can act faster than governance can meet, they are the core of practical AI governance rather than a nice-to-have add‑on. ## Start with clear definitions In the age of AI agents, observability and assurance are distinct but deeply complementary. **Observability** is the ongoing capacity to understand what our AI systems are doing – their performance, behaviour, and outputs – in real time and over time. It draws on telemetry from prompts, responses, decision paths, tools invoked, data accessed, and downstream impacts so that teams can see not just whether systems are running, but whether they are behaving as intended. **Assurance** is the structured, periodic process of independently verifying that AI systems are operating safely, accurately, and within the bounds of organisational policies and legal obligations. It includes formal testing, evaluation, and audit activities that link AI use to frameworks such as the [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=katecarruthers.com) and to obligations under privacy, consumer protection, and directors’ duties. When boards and executives talk about “[AI governance](https://www.aicd.com.au/news-media/media-releases/2024/governance-of-artificial-intelligence.html?ref=katecarruthers.com)”, what they usually need in practice is a robust combination of both: continuous observability and periodic assurance, designed to work together. ## Why AI agents raise the stakes Traditional analytics dashboards and model risk reviews were built for static models and largely human‑in‑the‑loop workflows. **Agentic systems change the risk profile in several ways**: - They can **take actions**, not just make predictions, by chaining tools, APIs, and workflows together in ways that are difficult to foresee in advance. - Their **behaviour is emergent and context‑dependent**; small changes in prompts, data, or environment can produce qualitatively different behaviour, including new failure modes. - They often sit on top of **opaque, third‑party foundation models** where you cannot see or control internal weights, training data, or release schedules. Without strong observability, organisations are effectively “flying blind” as these agents interact with customer data, critical systems, and external stakeholders. And without structured assurance, boards have no reliable way to demonstrate that the use of AI agents is compatible with their [duties under corporate law](https://trusenta.com.au/blog/ai-director-liability-australia-board-duties?ref=katecarruthers.com), privacy regimes, or upcoming AI‑specific regulations. 💡 The lesson from data governance is clear: ****you cannot govern what you cannot see, and you cannot credibly assure what you are not systematically monitoring**. ## What good observability looks like for AI agents Modern AI [observability](https://www.linkedin.com/pulse/ai-agent-observability-practical-framework-reliable-governed-agentic-v4saf/?ref=katecarruthers.com) practices go well beyond logs and latency dashboards. For agentic systems, leading organisations are putting in place: - **Traceability of end‑to‑end interactions** - Capturing every step from user input, through the agent’s decision graph, prompts, tool calls, and model choices, to the resulting actions and outputs. - Enabling teams to replay incidents, understand “why did the agent do that?”, and separate external attacks from internal errors or hallucinations. - **Behavioural and safety metrics** - Monitoring accuracy, grounding, hallucination rates, policy violations, and safety filter triggers across different cohorts and use cases. - Linking user feedback signals (ratings, complaints, escalations) to specific prompts, versions, and configurations so that interventions are targeted. - **Cost, performance, and drift monitoring** - Tracking token usage, latency, error rates, and model‑version performance to manage both reliability and spend. - Watching for drift in behaviour over time as underlying models or data sources change, especially when vendors silently update managed services. - **System‑level observability, not just the model** - Observing the full stack - data pipelines, orchestration layers, downstream applications, and security controls - rather than treating the model as an isolated component. - Using shared observability across AI and traditional systems so incidents can be understood in context (for example, whether a failure was caused by an AI decision, a data quality issue, or an infrastructure outage). 💡 When done well, observability becomes a ****governance** instrument: it underpins explainability, enables effective incident response, and provides the evidence base for assurance activities. ## How assurance turns data into governance **Assurance** takes the rich telemetry generated by observability and turns it into structured oversight. For directors and executives, this is where AI governance becomes tangible. Emerging good practice includes: - **Periodic, independent evaluations** - Scheduled reviews of AI agents against defined risk criteria: safety, fairness, robustness, security, and alignment to organisational values. - Use of controlled test suites, scenario‑based evaluations, and red‑teaming exercises informed by real‑world observability data rather than synthetic benchmarks alone. - **Policy and control verification** - Checking that business rules, guardrails, and access controls are consistently enforced in production, not just documented in design artefacts. - Verifying that data minimisation, retention, and localisation settings reflect the organisation’s data governance and privacy obligations. - **Compliance and audit readiness** - Maintaining a defensible trail of decisions, changes, and incidents so that the organisation can respond credibly to regulators, investors, and affected stakeholders. - Mapping observability and assurance practices to recognised frameworks, such as NIST’s AI RMF or sector‑specific guidance, to demonstrate that AI agents are being used “safely and responsibly”. For boards, this matters because AI systems are no longer peripheral experiments; they are increasingly embedded in core processes - customer service, credit decisions, operations, cybersecurity - where failures quickly translate into legal, financial, and reputational risk. Assurance gives directors a structured way to ask, and answer, the question: “**Are our AI agents operating within our risk appetite and obligations?**” ## Designing observability and assurance as a single system In practice, observability and assurance should be designed together as one coherent system, not as disconnected technology and compliance initiatives. Some practical design principles: 1. **Start from use cases and harms, not tools** - Identify where agents can take or recommend actions that materially affect people, finances, or critical operations, and prioritise observability depth accordingly. - Define “unacceptable outcomes” up front so monitoring and evaluations can be tuned to detect them. 1. **Make observability data “assurance‑ready”** - Standardise logging and metadata so that evaluators, auditors, and risk teams can reuse the same data without building parallel instrumentation. - Align metrics and dashboards to the categories in your AI risk and governance frameworks so reporting flows naturally from day‑to‑day operations into board papers. 1. **Embed responsibilities across the organisation** - Clarify **who owns observability** (often engineering and data teams), **who owns assurance** (risk, audit, or a dedicated AI governance function), and how they will work together. - Ensure **board and executive reporting** includes a regular view of AI agent performance, incidents, and assurance outcomes alongside more traditional risk and performance indicators. 1. **Assume multi‑vendor, evolving ecosystems** - Build capabilities that span different model providers, internal tools, and business units, rather than tying observability and assurance to a single platform. Consider independence from your core models. - Plan for continuous adaptation as both regulation and AI technology evolve, treating observability and assurance as living capabilities rather than one‑off projects. For organisations that already have mature data governance, cyber security, and operational risk practices, much of the capability is there; the task is to extend and adapt it to this new class of systems rather than trying to reinvent governance from scratch. ### Data is changing: static to flowing URL: https://katecarruthers.com/data-is-changing-static-to-flowing/ Last updated: 2026-05-25T11:41:23.000Z **The way we work with data is changing - fast.** For years, many organisations treated data primarily as something to be captured, stored, and reported on, rather than as a dynamic asset that continuously creates value. In the era of AI, that mindset is no longer just outdated; it creates real risk. ## From static stores to flowing data Not so long ago, much enterprise data was managed through carefully curated repositories, databases, and transactional systems. It powered reporting, dashboards, compliance activity, and core operations, but it was often managed within fixed systems and for specific purposes. Because data was too often seen as a by-product of operations rather than a strategic asset, it was frequently: - locked away **in silos** across business units; - **poorly documented** or inconsistently governed; and - **difficult to connect**, reconcile, or reuse beyond its original purpose. In that world, an organisation’s data landscape could look more like an archive than an active value driver: important in theory, occasionally referenced, but not always central to day-to-day decisions. ## Data as a flowing asset Today, alongside warehouses, platforms, and transactional systems, data flows continuously through organisations. It feeds real-time dashboards, automation, customer experiences, operational workflows, and, increasingly, AI systems. Key shifts include: - data moving in near **real time** between systems, partners, and platforms; - **automated processes** relying on data to support operational decisions at scale; and - AI and machine learning models **consuming data to generate predictions**, content, recommendations, and actions. In this environment, data becomes an asset in the true sense: something that creates value, enables new capabilities, and differentiates an organisation in the market. When it is accurate, trusted, and well governed, it can be a powerful enabler of innovation. When it is not, the consequences can be severe. ## AI magnifies both value and risk Artificial intelligence depends on data - and, in many ways, exposes its weaknesses. AI systems can: - **inherit the quality, bias, and integrity** issues present in the data they are trained on or use in operation; - **scale decisions**, recommendations, and actions at levels humans could not; and - **introduce new complexity** around explainability, accountability, oversight, and control. When data is fragmented, poorly understood, or weakly governed, AI can amplify those problems. What used to be a messy report can become a flawed automated decision. An incorrect record in one system can become an input to a model or workflow affecting thousands, or even millions, of outcomes. ## The new data risk landscape As data has shifted from relatively static stores to flowing, reusable assets, and as AI has become embedded in business processes, the risk profile has changed. Data-related risk is no longer just about: - losing access to critical data or backups; - failing an audit; or - miskeying fields in a system. It now includes: - automated decisions made using incomplete, inaccurate, or biased data; - privacy breaches from data being moved, combined, or reused in new ways; - cybersecurity exposures as data flows across cloud services, partners, and platforms; and - regulatory, ethical, and reputational risks related to AI-driven outcomes. In other words, when data moves, so does risk. And when AI sits on top of that data, it can spread that risk at machine speed. ## Treating data as the asset it has become To respond to this shift, organisations need to move beyond “collect and store” and towards genuinely managing data as an asset. That means: - **clear ownership and accountability** for critical data, data products, and AI systems; - **governance frameworks** that span data quality, privacy, security, ethics, and model risk; - **architecture and processes designed for data flow**, lineage, reuse, and control — not just storage; and - **transparency about how data is used**, especially in automated and AI-enabled decisions. This is not just a technical challenge. It is a leadership issue, a governance challenge, and a cultural shift. Boards, executives, and teams need a shared understanding that data is no longer merely a static record of what has happened; it is a dynamic resource shaping what happens next. ## Where next? We are still early in understanding the full organisational implications of data-driven and AI-enabled decision-making. But one thing is clear: the old habit of treating data as an afterthought no longer serves us.If we want to capture the value of AI while protecting our customers, communities, and organisations, we need to be intentional about how data flows, how it is governed, and how we manage the risks that travel with it. ### Machine overmatch in an age of software-defined war URL: https://katecarruthers.com/machine-overmatch-in-an-age-of-software-defined-war/ Last updated: 2026-05-23T09:12:26.000Z One thing many folks do not know about me is that this whole technology career was not my original plan, it was just a bit of a side quest 🤣. My original plan was a history degree and then a history PhD. But life happens and you go on weird tangents. Recently, I was enrolled in a Master of War Studies at UNSW with the idea of getting back on track with my original plan. But I became very interested in the governance of AI and popped that plan onto the back burner. Anyway, that is kind of a long explainer of the fact that I have long been interested in military history and military strategy. And now AI and cybersecurity are crossing over with that old interest of mine. So I will probably be writing a bit more about the intersections of war, technology, and strategy in future. ## War is changing Machine [overmatch](https://www.thefastmode.com/expert-opinion/47988-the-future-of-warfare-how-data-became-the-next-decisive-weapon?ref=katecarruthers.com) is an emerging theory of intelligence advantage in which the side that can collect, integrate, and model data at scale, more quickly and coherently than its adversary, gains a decisive edge in understanding and shaping the battlespace. It builds on the shift that Christian Brose describes in [*The Kill Chain*](https://ndupress.ndu.edu/Media/News/News-Article-View/Article/2541993/the-kill-chain-defending-america-in-the-future-of-high-tech-warfare/?ref=katecarruthers.com): away from reliance on exquisite legacy platforms and towards the speed, resilience, and connectivity of kill chains that link sensors, decision-makers, and shooters. It also aligns with the trends Paul Scharre examines in [*Army of None*](https://www.cnas.org/publications/commentary/army-of-none-autonomous-weapons-and-the-future-of-war?ref=katecarruthers.com), where autonomous and semi-autonomous systems increasingly sense, decide, and act under varying degrees of human supervision, making data, algorithms, and decision loops central to future conflict. In this frame, campaigns such as China-linked [Salt Typhoon](https://newlinesinstitute.org/tech-econ-sov-sec/2024-when-chinas-salt-typhoon-made-cyberspace-tidal-waves/?ref=katecarruthers.com) are not merely isolated cyber incidents, but part of a broader contest for persistent access to high-value telecommunications and network infrastructure. Such access can support espionage, situational awareness, and the data advantages on which future military and intelligence systems may depend. ## Ukraine rewriting how wars are fought Ukraine has quietly rewritten the grammar of modern war. We still see tanks, artillery, trenches and shattered cities on our screens. But underneath that familiar imagery is a very different operating model: cheap sensors, commercial satellites, drones, cloud platforms, Starlink terminals, battlefield apps, volunteer intelligence networks and rapid software iteration all stitched together into a faster decision loop. This is not science fiction. It is the practical machinery of modern war. Ukraine’s [Delta situational awareness system](https://www.csis.org/analysis/does-ukraine-already-have-functional-cjadc2-technology?ref=katecarruthers.com), for example, has evolved from a volunteer initiative into a Ministry of Defence platform that draws on drones, satellites, cameras, sensors and reconnaissance units to support battlefield decision-making. [GIS Arta and related battlefield tools](https://www.newamerica.org/insights/how-ukraines-uber-for-artillery-is-leading-the-software-war-against-russia/?ref=katecarruthers.com) have similarly shown how phones, tablets, drones, radios and satellite links can be used to connect observers, targets and artillery units more quickly than traditional command processes were designed to manage. The message for boards, executives and policymakers is clear: **war is becoming software-defined, data-dependent and commercially entangled**. That matters far beyond the battlefield, because the same digital infrastructure that enables productivity, logistics and social life in peacetime can become a source of intelligence advantage in crisis. Ashley Ruiz’s recent piece in War on the Rocks on [machine overmatch and Salt Typhoon](https://warontherocks.com/machine-overmatch-what-salt-typhoon-reveals-about-chinas-data-centric-intelligence-strategy/?ref=katecarruthers.com) is best read against this backdrop. Ruiz argues that the next decisive intelligence advantage may not come from one exquisite secret or one well-placed source. It may come from the ability to collect widely, analyse quickly and model entire digital ecosystems faster than an adversary can respond. That is the real significance of [Salt Typhoon](https://en.wikipedia.org/wiki/Salt%5FTyphoon?ref=katecarruthers.com). Public reporting and allied advisories describe a broad pattern of PRC state-sponsored activity against telecommunications, government, transport, lodging and military infrastructure networks. The activity partially overlaps with industry reporting commonly labelled Salt Typhoon, OPERATOR PANDA, RedMike, UNC5807 and GhostEmperor. For more background on this read this from the Australian Signals Directorate’s Australian Cyber Security Centre on [countering Chinese state sponsored attacks](https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/countering-chinese-state-sponsored-actors-compromise-of-networks-worldwide-to-feed-global-espionage-system?ref=katecarruthers.com). **The point is not the label. The point is the operating model**: persistent access to data-rich environments that can reveal communications, movement, organisational relationships and operational dependencies at scale. ## From platform-centric war to data-centric war Traditional US and allied warfighting has been built around high-end platforms: carrier strike groups, stealth aircraft, exquisite intelligence, surveillance and reconnaissance systems, and carefully controlled battle networks. Intelligence advantage in that model looked like a rare satellite pass, a sensitive intercept, or a human source with privileged access. That model has not disappeared. Platforms still matter. Munitions still matter. Logistics still matter. But Ukraine has shown that the side able to connect sensors, shooters, software and people at speed can create a different kind of advantage. [Delta](https://www.csis.org/analysis/does-ukraine-already-have-functional-cjadc2-technology?ref=katecarruthers.com) has been described by CSIS as a practical, agile form of battlefield management that resembles the combined joint all-domain command and control concept Western militaries have been trying to build for years. This is why the US Department of Defense’s interest in attritable autonomous systems, *Combined Joint All Domain Command and Control* (CJADC2) and faster sensor-to-shooter integration is not a side issue. It reflects the same lesson: **the future force is not just a collection of expensive platforms. It is an adaptive network of humans, machines, data, software and decision rights.** China is watching this too. [PLA thinking](https://www.airuniversity.af.edu/JIPA/Display/Article/3371164/finding-the-right-model-the-joint-force-the-peoples-liberation-army-and-informa/?ref=katecarruthers.com) has long emphasised informatised warfare and now increasingly intelligentised warfare, where information dominance, automation and AI-enabled decision support are expected to shape military advantage. RAND’s work on [PLA doctrine](https://www.rand.org/pubs/research%5Freports/RR1708.html?ref=katecarruthers.com) describes “systems confrontation” as central to how the PLA understands modern warfare, with “system destruction warfare” functioning as a theory of victory aimed at paralysing an adversary’s operational system rather than simply destroying individual units. Salt Typhoon sits squarely in that context. It is not just “a cyber incident”. It is part of the data plumbing for a future operating model in which intelligence, cyber, electronic warfare, influence and kinetic operations are increasingly fused. ## Ecosystem mapping before the crisis One of Ruiz’s most useful insights is that campaigns like Salt Typhoon are [about mapping foreign digital ecosystems](https://warontherocks.com/machine-overmatch-what-salt-typhoon-reveals-about-chinas-data-centric-intelligence-strategy/?ref=katecarruthers.com) ***before a crisis begins***. That should worry us. The 2025 joint advisory co-sealed by agencies including CISA, NSA, FBI and ASD’s Australian Cyber Security Centre says PRC state-sponsored actors have targeted networks globally, with a focus on major telecommunications backbone routers and provider edge and customer edge routers. It also states that stolen data from telecommunications and ISP intrusions, as well as lodging and transport sector intrusions, can help Chinese intelligence services identify and track targets’ communications and movements around the world. **In plain language, this is about turning digital exhaust into strategic knowledge. Who talks to whom. Which systems depend on which networks. Which suppliers, ports, substations, cloud regions, identity providers and communications channels matter most. Which people are central to decision-making, logistics or operational continuity.** Modern machine learning and graph analytics make that work more scalable. They can infer organisational relationships from communications patterns, identify anomalies in movement or device behaviour, and highlight nodes whose disruption would create disproportionate effects. The models do not need to be perfect to be useful. At scale, even moderately accurate models can reduce the time needed to target, disrupt, influence or coerce. For a Ukraine-style conflict, pre-built ecosystem maps could be used to identify the communications links that battlefield applications depend on, disrupt the civilian coordination channels that support resilience, or tailor influence operations to particular military, professional or community groups. This is a very different model from trying to build situational awareness only after a crisis has begun. **The strategic advantage comes from doing the slow data work early.** ## Commercial infrastructure is now part of the battlespace Ukraine has also made visible a truth that many organisations still prefer not to confront: modern conflict rides on commercial infrastructure. Starlink has provided critical connectivity. Cloud platforms have supported resilience. Commercial drones have become ubiquitous. Civilian reporting tools and open-source intelligence communities have become part of the [information environment](https://ecfr.eu/publication/star-tech-enterprise-emerging-technologies-in-russias-war-on-ukraine/?ref=katecarruthers.com). For democracies, this creates a difficult governance problem. We need commercial innovation, private-sector data and civilian infrastructure to support national resilience. But we also have legal obligations, civil liberties, procurement rules, privacy regimes and political norms that constrain how those systems can be used. Those constraints are not a bug; they are part of what differentiates liberal democracies from authoritarian states. But they do introduce friction. China’s system is structured differently. Its national security and intelligence laws place obligations on organisations and citizens to support state security work, and its military-civil fusion strategy is intended to integrate civilian technology, industry and data into national strategic capability ([Ruiz](https://warontherocks.com/machine-overmatch-what-salt-typhoon-reveals-about-chinas-data-centric-intelligence-strategy/?ref=katecarruthers.com), 2026, [US Congress Report](https://media.defense.gov/2023/Oct/19/2003323409/-1/-1/1/2023-MILITARY-AND-SECURITY-DEVELOPMENTS-INVOLVING-THE-PEOPLES-REPUBLIC-OF-CHINA.PDF?ref=katecarruthers.com), 2024). That does not mean the system is seamless. Large bureaucracies are rarely seamless. But it does mean Beijing can, in principle, reduce the distance between commercial data, state intelligence requirements and military planning. The result is an asymmetry in integration speed rather than a simple asymmetry in technical capability. The US, Australia and other allies have extraordinary data, technical expertise and intelligence capabilities. But those capabilities are often distributed across agencies, companies, jurisdictions and legal frameworks. China may be able to fuse some categories of data more quickly into operationally useful models. **That is the governance challenge. Not “how do we become like China?” We should not. The question is how democratic systems can move faster while still preserving legality, accountability and trust.** ## Ukraine as proof of concept, China as systems engineer Ukraine has built much of its software-defined warfighting model through necessity. It has had to integrate drones, civilian reporting, commercial satellite imagery, battlefield apps, cloud infrastructure and volunteer technical capability while under attack. That is innovation under pressure. China is approaching the same problem from the other direction. It is trying to design the doctrine, industrial base, cyber operations and data architecture before the crisis. [PLA concepts of systems confrontation and information advantage](https://www.airuniversity.af.edu/JIPA/Display/Article/3371164/finding-the-right-model-the-joint-force-the-peoples-liberation-army-and-informa/?ref=katecarruthers.com) suggest a worldview in which the adversary is not just a set of military units, but a system of systems that can be mapped, shaped and [disrupted](https://www.rand.org/pubs/research%5Freports/RR1708.html?ref=katecarruthers.com). [Salt Typhoon](https://en.wikipedia.org/wiki/Salt%5FTyphoon?ref=katecarruthers.com) is one visible symptom of that worldview. Compromising telecommunications infrastructure, routers and related high-value network environments is not glamorous. It does not look like a decisive battle. But it can create long-term strategic options: surveillance, target development, counterintelligence insight, coercive leverage and potential disruption in a crisis. This is where the phrase 'machine overmatch' is useful. It shifts the conversation away from whether one side has a better tank, aircraft or satellite. **It asks whether one side can use machines, data and models to understand the other side’s society, infrastructure and military system faster than the other side can understand itself.** That is a much more uncomfortable question. ## Implications for democracies and Australia For liberal democracies, the challenge is twofold: 1. We need to **adapt** to software-defined, data-centric conflict without eroding the rights and norms we are trying to defend. The debates over surveillance powers, data retention, lawful access, data brokers and cross-border data flows are not just privacy debates. **They are now national security debates as well.** 2. We must assume that our **digital exhaust is already being harvested, correlated and modelled**. The [2025 advisory co-sealed by ASD’s ACSC](https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/countering-chinese-state-sponsored-actors-compromise-of-networks-worldwide-to-feed-global-espionage-system?ref=katecarruthers.com) says this PRC-linked activity has been observed in the United States, Australia, Canada, New Zealand, the United Kingdom and elsewhere. A separate 2024 advisory on Volt Typhoon warned that [PRC state-sponsored actors were seeking to pre-position on critical infrastructure networks](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a?ref=katecarruthers.com) for potential disruptive or destructive activity in a major crisis, and noted that Australian and New Zealand critical infrastructure could be vulnerable to similar activity. For Australia, this makes data governance a national security discipline, not just a compliance function. Data brokers, identity providers, telecommunications carriers, cloud platforms, managed service providers and critical infrastructure operators all sit inside the strategic risk picture. Boards should treat high-value data aggregations as both assets and liabilities. This has practical implications. Organisations need to know what sensitive data they hold, where it flows, who can access it, how long it is retained, and how easily it can be linked to other datasets. They need to threat model metadata, logs, telemetry and identity data with the same seriousness they apply to obvious secrets. They need to ask whether a breach would simply expose records, or whether it would help an adversary build a better model of Australian society, infrastructure and decision-making. **That is the shift. Cybersecurity is no longer only about stopping intrusions. It is about reducing the strategic value of what an adversary can learn if they get in.** ## From cyber incident to data-risk discipline 💡 ****The easy mistake is to treat Salt Typhoon as another cyber story. It is more than that. It is a warning about the way intelligence, cyber operations, AI, commercial infrastructure and national power are converging.** Ukraine shows that modern war rewards the rapid integration of data, software, sensors and people. China’s data-centric intelligence strategy shows how an authoritarian state can prepare the information terrain long before a crisis. Democracies need a response that is faster and more integrated, but still lawful and accountable. For boards and executives, the practical message is simple. Data governance, cyber resilience, third-party risk, critical infrastructure security and AI governance are now part of the same conversation. They cannot be managed as separate compliance streams. They are the operating model for resilience in a world where digital exhaust has strategic value. The future of war is not only about weapons. It is about who can see, model, decide and adapt fastest. Ukraine has shown what that looks like under battlefield pressure. Salt Typhoon shows what preparation for that world can look like in peacetime. **For Australia and its allies, the question is no longer whether war is changing. Ukraine has answered that. The question is whether our institutions, laws, boards and governance practices can adapt quickly enough to protect democratic societies whose data is already part of the battlespace.** ### Before you worry about AI threats, fix your security fundamentals URL: https://katecarruthers.com/ai-threats-fix-your-security-fundamentals/ Last updated: 2026-05-19T22:31:43.000Z There’s a lot of noise right now about AI-powered cyberattacks. And yes, attackers are absolutely using AI to scale phishing, automate reconnaissance, and improve social engineering. And even I was [writing about it](https://katecarruthers.com/ai-has-changed-the-cyber-threat-landscape/) the other day. But if you spend any time looking at real-world breaches, a more uncomfortable truth emerges: most organisations aren’t being hacked with sophisticated AI - they’re being compromised through basic, preventable failures. A recent post from [*This Week in Security*](https://this.weekinsecurity.com/it-is-far-too-easy-to-find-leaked-passports-and-drivers-licenses-online/?ref=katecarruthers.com) makes the point starkly. It is still “far too easy to find leaked passports and driver’s licenses online”. Not because attackers are deploying cutting-edge techniques, but because sensitive data is sitting in publicly accessible storage - unsecured cloud buckets, misconfigured databases, and poorly governed systems. This isn’t a story about advanced adversaries. It’s a story about neglected fundamentals. We continue to see the same patterns: - Publicly exposed S3 buckets and cloud storage. - Weak or absent access controls. - Poor data classification and ownership. - Lack of monitoring on sensitive data repositories. - Credentials and keys left in code or configuration files. None of this requires AI to exploit. It barely requires skill. It requires curiosity and a search engine. ## Reality of cyber risk The uncomfortable reality for boards and executives is that cyber risk is still, overwhelmingly, an operational discipline problem rather than a technological arms race. Organisations are investing heavily in advanced detection tools, AI-enabled security platforms, and threat intelligence feeds - yet failing to enforce basic hygiene. It’s the equivalent of installing a state-of-the-art alarm system while leaving the front door wide open. *From a governance perspective, this is where the focus needs to shift.* ## Core operational capabilities Cyber and information security fundamentals are not “entry level” concerns to be delegated and forgotten. They are core organisational capabilities that require continuous attention: - Do you know where your **sensitive data** actually resides? - Is it **classified** appropriately? - Who has **access**, and why? - Are your cloud environments routinely **audited** for misconfiguration? - Is there clear **accountability** for data stewardship? If you can’t answer these questions confidently, then no amount of AI-driven security tooling will save you. There’s also a broader issue of incentives and attention. Advanced threats are interesting. They make for compelling board papers and conference presentations. Fundamentals are not. They are repetitive, procedural, and often invisible when done well. But they are precisely what separates resilient organisations from those that end up in breach notifications and regulatory investigations. The rise of AI in cyber operations should not distract us from this. If anything, it raises the stakes. AI lowers the cost of scanning the internet for exposed assets. It accelerates the identification of weak points. It increases the speed at which simple mistakes are exploited at scale. Which means that the organisations still getting the basics wrong will be found faster - and compromised more often. The lesson here is not to ignore AI in cybersecurity. It is to put it in perspective. The most effective way to reduce cyber risk today is not to chase the latest technology trend, but to rigorously enforce the fundamentals: - secure your data, - lock down your environments, - monitor your assets, and - assign clear accountability. **Because right now, attackers don’t need to be clever.** **They just need you to be careless.** ### The hardware crunch is here: what it means for AI and data operations URL: https://katecarruthers.com/hardware-crunch-ai-data-operations/ Last updated: 2026-05-18T09:58:05.000Z 💡 ****The hardware crunch: a new normal, not a blip** There was a piece in [The Register](https://intelligence.theregister.com/paper/view/20113/the-hardware-crunch-how-supply-chain-turbulence-is-forcing-a-new-it-playbook?ref=katecarruthers.com) recently that framed “the hardware crunch” as a perfect storm: extended lead times, higher prices, and pressure to refresh platforms faster, all hitting infrastructure teams at once. AI demand is now a structural driver of this turbulence, competing for the same chips, memory, storage and power capacity that traditional enterprise workloads depend on. We are also bumping into [physical and manufacturing limits](https://randtech.com/ai-hardware-supply-chain-reset/?ref=katecarruthers.com) \- from [NAND fabrication](https://www.pppl.gov/news/2025/improving-way-flash-memory-made?ref=katecarruthers.com) to [advanced semicondunctor packaging](https://en.wikipedia.org/wiki/Advanced%5Fpackaging%5F%28semiconductors%29?ref=katecarruthers.com) \- so you can’t just “buy more hardware” as a strategy any more. As [VAST Data’s Jeff Denworth](https://www.linkedin.com/posts/vast-data%5Fwhen-the-hardware-supply-chain-breaks-software-activity-7415459851708809217-qP-W/?ref=katecarruthers.com) has put it, in this environment “**efficiency is the new supply**”: if you can’t get more flash, you have to make the flash you already own go further. ## How AI is driving the supply squeeze The current AI wave is brutally hardware‑hungry: GPUs, high‑bandwidth memory, fast storage and power‑dense data centre racks are all under pressure. Hyperscalers and big AI labs are soaking up capacity with multi‑year, reservation‑only deals for chips, substrates, memory and power, leaving everyone else to live with shaky availability and volatile pricing. This has knock‑on effects all the way out to the edge. Memory and storage that once flowed into laptops and workplace devices are being reprioritised for AI infrastructure, prompting [warnings from vendors](https://www.techpartner.news/news/the-ai-frenzy-is-driving-a-new-global-supply-chain-crisis-622320?utm%5Fsource=perplexity) that personal computing is getting squeezed by the AI arms race. For enterprise IT, that means the [hardware crunch](https://arctiq.com/blog/the-hardware-you-own-is-the-moat-you-build-navigating-the-2026-it-supply-chain-crisis?ref=katecarruthers.com) is not just a “data centre story”; it is already visible in endpoint pricing, device refresh cycles, and a creeping loss of choice. ## What this means for AI and data teams For AI and data leaders, the core implication is simple: you can no longer treat hardware as an **elastic resource** you can summon **on demand**. Long lead times for servers, accelerators and storage mean that [**infrastructure risk becomes an explicit constraint**](https://www.concordusa.com/blog/sounding-the-alarm-hardware-crunch-means-big-changes-to-the-ai-market?ref=katecarruthers.com) on your AI roadmap, not an afterthought. Budgets are also being hit from both sides: higher prices for components, and pressure to fund new AI initiatives without a matching increase in infrastructure headroom. This forces [tougher prioritisation across models](https://randtech.com/why-is-ai-causing-shortages-inside-the-data-center-surge-the-coming-edge-wave-and-how-rand-keeps-you-shipping/?ref=katecarruthers.com), experiments and products, with questions like “which workloads genuinely need GPUs?” moving from technical detail to board‑level decision. ## The shift from hardware strategy to architecture strategy One of the most useful ideas emerging from this period is that software architecture is now your biggest lever against hardware constraints. When you can’t count on “just‑in‑time” servers or storage, you have to design platforms that stretch what you already own: better data locality, smarter caching, tiered storage, and ruthlessly efficient pipelines. This is exactly the kind of “[Supply Chain 2.0](https://www.emerald.com/insight/content/doi/10.1108/09600031111101439/full/html?ref=katecarruthers.com)” thinking supply‑chain researchers have talked about for years: instead of assuming stability, you build structural flexibility into the system so it can absorb volatility. Applied to AI and data, that means architectures that can run on different clouds, across heterogeneous hardware, and with graceful degradation when the “perfect” configuration isn’t available. ## Rethinking cloud, on‑prem and hybrid [Hardware turbulence](https://www.reuters.com/world/china/ai-frenzy-is-driving-new-global-supply-chain-crisis-2025-12-03/?ref=katecarruthers.com) is also quietly rewriting the cloud vs on‑prem playbook. The narrative used to be that the cloud was the escape hatch for on‑prem capacity constraints; in a world of global hardware shortages, cloud regions are subject to similar underlying supply issues, just with different economics and queuing dynamics. Hyperscalers are prioritising their biggest AI customers, so smaller enterprises may find that the capacity they assumed would be there at the right price simply is not there when they need it. On the other hand, hardware you already own - and can power and cool - becomes more strategic than ever, because replacing or expanding it on your terms is harder and slower. That pushes you toward [more intentional hybrid strategies](https://www.nutanix.com/theforecastbynutanix/news/how-supply-chain-disruption-and-ai-adoption-are-reshaping-enterprise-it?ref=katecarruthers.com): locking in long‑term cloud capacity for specific AI workloads, while treating your on‑prem hardware as a scarce, high‑value “moat” that you optimise ruthlessly. ## Data operations under constraint: doing more with less Data operations teams feel the crunch in very practical ways: slower procurement of storage, tighter capacity ceilings, and pressure to defer hardware refreshes even as data volumes keep growing. That means the old habit of “keep everything forever, just in case” finally hits a hard wall; retention, compression, and archiving policies suddenly matter to the viability of your AI roadmap. It also means you need to become far more deliberate about where data lives and how it flows. Tiering “warm” and “cold” data, pushing more preprocessing to the edge, and reducing gratuitous data duplication are not optimisation niceties; they become survival tactics. **The organisations that manage to keep feeding their models under these constraints will be the ones that treat data operations as a design discipline, not a background service.** ## Practical moves for AI and data leaders Three categories of action stand out if you are responsible for AI and data capabilities in this environment. - **Plan capacity like a supply‑chain problem:** Start treating GPUs, storage and power as constrained inputs that require hedging, not commodities you can always top up later. That means forward contracts, multi‑vendor sourcing, and early orders for critical infrastructure where it makes sense.hardwaresignal. - **Make efficiency a first‑class design goal:** Optimise your models and pipelines for hardware reality rather than theoretical best case - smaller models, better batching, shared feature stores, and aggressive storage efficiency. In 2026’s “flash crunch”, every percentage point of utilisation you claw back is de‑facto new capacity. - **Architect for portability and graceful degradation:** Assume you won’t always get the hardware you want, where you want it. Design AI and data platforms so they can run acceptably across different regions, clouds and hardware classes, and so critical services degrade gracefully rather than fail abruptly when resources tighten. ## Governance, risk and board conversations Finally, **the hardware crunch is also a governance issue**. When key AI capabilities depend on scarce, globally contested hardware supply chains, that creates **concentration risk, geopolitical exposure and new operational failure modes**. Boards and risk committees need to understand that AI transformation is now as much a supply‑chain and infrastructure story as it is an algorithm story. For organisations that already think deeply about risk, resilience and ethics in AI, this is an opportunity to extend those conversations into the physical substrate that makes AI possible. **The winners in this period won’t just be those with the biggest models; they’ll be the ones who can keep those models running, economically, through several more years of turbulence.** ### Why data minimisation matters in the age of AI-powered cyber attacks URL: https://katecarruthers.com/data-minimisation-matters/ Last updated: 2026-05-16T23:02:02.000Z There’s a shift happening in [cybersecurity](https://katecarruthers.com/ai-has-changed-the-cyber-threat-landscape/) that is making it into mainstream governance conversations about now: attackers are now using the [same AI tools](https://securitybrief.asia/story/google-says-ai-powered-cyberattacks-are-already-here?ref=katecarruthers.com) that organisations are enthusiastically adopting. **And that changes the threat landscape considerably.** For years, [data minimisation](https://www.oaic.gov.au/%5F%5Fdata/assets/pdf%5Ffile/0024/7962/chapter-3-privacy-safeguard-3-final.pdf?ref=katecarruthers.com) has been one of those principles that everyone agrees with in theory, but quietly sidelines in practice. Storage is cheap, data is “strategic,” and future use cases are always just around the corner. So we keep things. Just in case. **But “just in case” is starting to look like a liability.** ## The asymmetry has changed AI has dramatically lowered the cost and skill required to execute sophisticated cyber attacks. What used to require time, expertise, and coordination can now be automated, scaled, and refined with alarming ease. Attackers can now: - Rapidly analyse large, unstructured datasets once exfiltrated - Saving encrypted datasets for later when quantum computing will enable advanced decryption (since storage is so cheap) - Generate highly convincing phishing and social engineering campaigns using contextual data - Identify sensitive patterns or relationships buried in otherwise “low value” data - Iterate attacks in real time based on responses This creates a new kind of **asymmetry**. Organisations are still thinking in terms of **perimeter defence** and **compliance checklists**, while attackers are thinking in terms of **data exploitation at scale**. And the more data you hold, the more raw material you are offering them. ## Data is no longer inert One of the more dangerous assumptions in traditional data governance is that stored data is relatively passive. It sits in databases, archives, or backups, waiting to be used. That assumption no longer holds. With modern AI tools, even poorly structured, incomplete, or seemingly trivial datasets can be transformed into intelligence. Fragments can be stitched together. Context can be inferred. Identities can be reconstructed. **What used to be “harmless” data exhaust is now a potential attack surface.** This is particularly relevant for: - Historical datasets retained beyond their original purpose - Logs and metadata that reveal behavioural patterns - Customer interaction records and communications - Internal documents and knowledge repositories In other words, the long tail of data that most organisations barely think about. ## Data minimisation as a security control Data minimisation has traditionally been framed as a privacy principle. Collect less. Retain less. Use only what you need. **That framing is now incomplete.** > Data minimisation is increasingly a core cybersecurity control. If an attacker gains access to your environment, the impact is directly proportional to what they can access and exploit. Reducing data holdings reduces the blast radius. It also reduces the ability for attackers to derive additional insights through AI-driven analysis. > This is not just about compliance with privacy regulation. It’s about resilience. A useful mental shift is this: Don’t ask “what data might be useful someday?” Instead ask: **“what data would I regret losing control of?”** ## The economics of keeping data have flipped For a long time, the argument for retaining data was straightforward: - Storage costs were falling - Data could potentially unlock future value - Deleting data felt like losing an asset But AI changes the risk side of that equation. The marginal cost of storing data may be low, but the marginal risk has increased significantly. Every additional dataset: - **Expands** your attack surface - **Increases** breach impact - **Complicates** governance and oversight - **Creates** new opportunities for misuse or unintended inference **In effect, data is no longer just an asset. It is also a liability with compounding risk.** ## Practical implications This isn’t a call for indiscriminate deletion. It’s a call for intentionality. Organisations should be actively: - **Reviewing retention policies** with a security lens, not just compliance - **Identifying “dark data”** that has no clear purpose or owner - **Aligning data collection practices** with defined use cases - **Embedding minimisation** into system and process design, not as an afterthought - Treating **data lifecycle management** as a core governance capability > Importantly, this needs to be led from the top. Data minimisation often fails because incentives favour accumulation, not restraint. ## A cultural shift At its core, this is a cultural issue. For years we’ve encouraged organisations to believe that more data is always better, and that value comes from relentless accumulation. We’ve hoarded our stores of data like dragons hoarding their gold. That mindset no longer serves us. In an environment where AI lowers the bar for attack capability and increases the risk calculus, disciplined data practices are no longer optional; they’re foundational. **Data minimisation isn’t about doing less with data, it’s about being intentional about what you keep - and why.** ### The coming AI jobs-pocalypse URL: https://katecarruthers.com/ai-jobs-future/ Last updated: 2026-05-14T02:11:59.000Z Every major technological revolution has triggered waves of anxiety about job losses, social disruption, and economic dislocation. From the mechanisation of agriculture to the rise of computing, each era has felt uniquely destabilising to those living through it. And yet, over time, new forms of work have emerged, often in ways that were difficult to predict at the outset. The AI revolution is no different in its emotional texture. What may be different is its speed, scope, and the kinds of cognitive work it reshapes. To understand what might come next, it helps to look backward. ## The agricultural to industrial shift Before the industrial revolution, the majority of people worked in agriculture. In countries like the United States and the UK, upwards of 60 to 80% of the workforce was engaged in farming or farm-adjacent labour. Mechanisation changed that. Tractors, harvesters, and industrial processes dramatically reduced the need for human labour in agriculture. By the mid-20th century, agricultural employment in advanced economies had dropped to single digits. Jobs lost: - Manual farm labourers - Seasonal agricultural workers - Rural craft and subsistence roles Jobs created: - Factory workers - Mechanical engineers - Transport and logistics workers - Urban service roles such as retail, hospitality, and administration What’s striking was not just the shift in jobs, but the shift in where and how people lived. Entire populations moved from rural to urban environments. Work became more structured, clock-driven, and centralised. This revolution changed our relationship to work, seasons, time and nature. No biggie! ## Electrification and mass production The next wave, electrification and assembly-line production, further transformed work. It didn’t just eliminate jobs, it reorganised them. Jobs lost: - Skilled artisanal manufacturing roles such as hand-weaving and bespoke production - Small-scale local production Jobs created: - Assembly line workers - Industrial managers - Electrical engineers and technicians - Consumer economy roles such as marketing, sales, and distribution It also shifted the personal agency that workers had in their work from high levels of agency in the skilled artisinal work to low levels of agency in the factory assembly line work. This period also saw the rise of the modern corporation and managerial class. Coordination, planning, and oversight became distinct forms of labour. The rise of the managerial class came about because we needed humans to help coordinate labour. ## The digital and computing revolution From the late 20th century onward, computing began to automate routine cognitive and administrative tasks. Jobs lost: - Typists and stenographers - Filing clerks - Switchboard operators - Some middle-management coordination roles Jobs created: - Software developers - IT support and systems administrators - Data analysts - Digital marketers - Entirely new industries such as e-commerce, social media, and cybersecurity This shift is different because it is the beginning of an encroachment on white collar work. It also introduced the idea that information itself could be processed, stored, and scaled independently of human labour. ## A pattern emerges Across these revolutions, a few patterns repeat: - Technology tends to eliminate tasks, not entire jobs, at least initially - New jobs often emerge at the intersection of the technology and human needs, including managing, interpreting, selling, or maintaining the technology - The transition period is uneven and often painful for displaced workers - The new jobs are rarely obvious at the outset Most importantly, each wave has moved human labour up the stack, away from physical effort and routine tasks, and toward coordination, creativity, and judgment. ## The AI revolution: what’s different? AI has changed the [cyber threat landscape](https://katecarruthers.com/ai-has-changed-the-cyber-threat-landscape/), amplifying risks while reshaping defences. AI is already demonstrating the ability to perform tasks that were previously considered uniquely human, including writing, coding, analysing, designing, and even aspects of decision-making. **This creates a qualitatively different kind of disruption.** Jobs at risk are not just manual or routine. They include: - Entry-level knowledge work such as junior analysts, paralegals, and copywriters - Administrative coordination roles - Basic programming and software development tasks - Customer service and support functions At the same time, new roles are emerging: - AI system trainers and evaluators - Prompt engineers and workflow designers - AI governance, risk, and compliance specialists - Human-AI interaction designers - Data curators and synthetic data engineers More interestingly, AI is not just creating new job categories, it is reshaping existing ones. For example, a lawyer with AI assistance can do the work of several junior associates. A consultant can produce analysis faster and at greater scale. A solo creator can operate like a small media company. This suggests that the impact of AI may be less about wholesale job replacement and more about: - **Workforce compression**, where fewer people do the same work - **Skill amplification**, where high performers become significantly more productive - **Role hybridisation**, where jobs blend technical, creative, and strategic skills ## The uncomfortable middle If history is a guide, the biggest challenge is not the end state, it is **the transition**. I've seen this play out in previous technology revolutions. For example, when I worked on a project that replaced the typing pool with automated letter generation in an insurance business. Workers displaced by agricultural mechanisation did not seamlessly become factory workers. Nor did typists automatically become software developers. These transitions involved generational shifts, retraining, and often significant social upheaval. **The same is likely to be true for AI.** We may see: - **Increased inequality** between those who can effectively use AI and those who cannot - **A hollowing out** of entry-level pathways into professions (unless we actively work to ensure that these pathways evolve for the AI age) - **Pressure on education and training systems** to adapt rapidly - **A rethinking** of what constitutes valuable human work ## What remains uniquely human? Every technological revolution has forced a re-evaluation of human value. As machines take over routine physical and cognitive tasks, the remaining areas of human advantage tend to cluster around: - **Judgment** under uncertainty - Ethical **reasoning** and accountability - Complex **interpersonal** interaction - Creativity and **original** synthesis - Contextual **understanding** across domains These are not new capabilities, but they are becoming more economically central. ## Looking forward It is tempting to ask whether AI will create more jobs than it destroys, as if history guarantees a reassuring answer. History suggests something more nuanced. Yes, new jobs will emerge. But they may not emerge quickly enough, or in the right places, or for the same people who lose their jobs. And they may require fundamentally different skills. Governments will probably need to step in and reimagine how they support people through this transitional period. > The real question is not whether jobs will exist, but what kinds of work will be available, to whom, and on what terms. In that sense, the AI revolution is not just a technological shift. It is a societal and a governance challenge, an economic restructuring, and a societal choice. One thing is certain, the pace of change will not slow down, and we will all have to become lifelong learners just to keep up. And, like every revolution before it, the outcomes will depend less on the technology itself and more on how we as nations and societies choose to deploy, regulate, and adapt to it. ### Why AI needs a Proof-of-Concept to Production pipeline URL: https://katecarruthers.com/why-ai-needs-a-proof-of-concept-to-production-pipeline/ Last updated: 2026-05-12T22:23:31.000Z Most organisations are already running AI pilots and proofs-of-concept (PoC), often in innovation labs or with enthusiastic teams experimenting with new tools. Without a defined pathway into production, these efforts stall at “interesting prototype” and never make it into the core processes where value is actually realised. It has been estimated (in mid-2025) that [70% of AI projects fail](https://www.ayadata.ai/why-70-of-ai-projects-fail-to-move-beyond-proof-of-concept/?ref=katecarruthers.com) to get from PoC into production: > Over 70% of AI projects fail to move from pilot to production. > Nearly 88% of AI POCs are abandoned and never fully deployed. > AI project failure rates are nearly double those of traditional IT projects. A structured pipeline can help to turn AI work from ad‑hoc heroics into a repeatable capability. It forces clarity about the problem, the data, the risks, and the change management needed so that AI systems can be safely scaled and supported over time. ## From idea to impact: key stages ![](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/05/poc-to-prod-pipeline.jpg) AI Proof-of-Concept to Production Pipeline This diagram, that I have developed to explain this concept to my students, lays out a [lifecycle](https://omdia.tech.informa.com/om142936/ai-proof-of-concept-to-production-essential-foundations-and-critical-first-steps?ref=katecarruthers.com) that is increasingly becoming a de‑facto pattern across mature AI teams: **Proof of Concept → Pilot → Production → Handover to Operations.** - **Proof of Concept (PoC)**: A bounded exercise (often a few weeks) to test technical feasibility and explore whether AI can plausibly solve the problem, with clear hypotheses and success criteria. This is where you surface basic data issues, privacy questions, and whether there is meaningful business value at all. - **Pilot**: A limited real‑world deployment to validate performance, usability, and value with actual users and live data. Here you start to treat the solution as a product: you test robustness, refine KPIs, and check readiness for scale including operational, ethical, and risk considerations. - **Production**: Implementation of the full‑scope solution with proper release planning, documentation, monitoring, and user training. This is where MLOps and LLMOps disciplines come to the fore: CI/CD for models and prompts, environment separation, observability, and rollback strategies. - **Handover to operations**: Transition from project mode to business‑as‑usual, including data and model management, governance, and continuous improvement. This stage ensures that models are retrained, risks are monitored, and feedback loops from users and system telemetry actually drive iteration. This pipeline deliberately inserts stage gates between PoC, pilot, and production so that leaders can make evidence‑based decisions about whether to stop, pivot, or scale. ## What goes wrong without a pipeline? When organisations skip this structured pathway, the failure modes are predictable. - **Pilot purgatory**: AI initiatives stay trapped as endless experiments because there is no defined route, budget, or ownership to take them into production. Teams get disillusioned and executives start to see AI as hype rather than capability. - **Shadow AI and unmanaged risk**: Individual teams deploy models and gen‑AI workflows directly into their operational processes without central oversight, leading to inconsistent controls, duplicated effort, and governance blind spots. This is particularly dangerous where AI decisions touch customers, safety, or regulated domains. - **Operational fragility**: Models are treated as one‑off projects rather than living systems that require monitoring, retraining, and incident management. Without robust pipelines and observability, performance quietly degrades as data drifts, and the organisation often discovers issues only when something fails in production. - **Missed learning and reuse**: Each team reinvents environment setup, data pipelines, and evaluation frameworks because there is no shared pattern for moving from PoC to production. The result is higher cost, slower delivery, and fragmented institutional knowledge. ## Designing a robust PoC‑to‑Prod pathway For senior leaders, the goal is not just to have a few successful AI projects, but to build an organisational capability that can repeatedly take ideas from concept to production safely and at pace. Some practical design principles: - **Clarify the “why” up front:** Every PoC should start with a well‑articulated problem, target outcomes, and measurable success metrics, linked to strategy rather than technology curiosity. Treat PoCs as disciplined feasibility tests, not open‑ended explorations. - **Standardise stage gates and criteria:** Define what “good enough to proceed” means at each stage: data quality thresholds, KPI improvements, risk assessments, stakeholder buy‑in, and architecture readiness. Make these criteria transparent so teams know how to design their work to progress. - **Invest in the boring plumbing:** Reusable data pipelines, environment templates, [CI/CD](https://www.redhat.com/en/topics/devops/what-is-ci-cd?ref=katecarruthers.com) for models, [AI/ML Ops](https://aws.amazon.com/what-is/mlops/?ref=katecarruthers.com), and common observability patterns dramatically shorten the path from pilot to production. This is the unglamorous infrastructure that differentiates organisations that scale AI from those that stay stuck in prototype land. - **Tie into** [**AI governance**](https://katecarruthers.com/effective-ai-governance/)**, not around it:** Your PoC‑to‑prod pipeline should be tightly coupled with AI risk, ethics, and compliance processes, including privacy impact assessments, model documentation, and approval workflows. AI Governance works best when it is embedded into the delivery pipeline rather than bolted on as a final gate. - **Treat AI as ongoing change, not a one‑off project:** Handover to operations must include training, updated [runbooks](https://security.googlecloudcommunity.com/community-blog-42/ai-runbooks-for-google-secops-security-operations-with-model-context-protocol-3988?ref=katecarruthers.com), communication plans, and defined ownership for monitoring and improvement. This aligns with the broader reality that AI adoption is fundamentally a change management exercise. ## What this means for your AI strategy For executives, the question is no longer “*Do we have AI pilots*?” but “**Do we have a reliable, governable pathway from proof of concept to production that we can trust with core business processes?**” The organisations that answer yes will compound their learning, build trust with regulators and customers, and avoid the trap of impressive demos with negligible impact. If you already have clusters of AI activity, the next step is to make the implicit explicit: map your current idea‑to‑implementation journey, agree the stage gates, and deliberately wire in governance, observability, and operations. From there you can start to treat your PoC‑to‑production pipeline as a strategic asset in its own right. ### AI has changed the cyber threat landscape URL: https://katecarruthers.com/ai-has-changed-the-cyber-threat-landscape/ Last updated: 2026-05-11T01:38:53.000Z Artificial intelligence is not just another IT trend. It is fundamentally changing the cyber threat landscape and the expectations of regulators. In the past few weeks alone, ASIC and APRA have both written to industry warning that AI is accelerating cyber risk and that governance needs to catch up fast. The message to boards and executives is clear: *you cannot treat AI and cybersecurity as separate conversations any longer*. **They are now the same conversation**. ## What the regulators are really saying In early May 2026, [ASIC](https://download.asic.gov.au/media/xhrf1w0e/26-092mr-open-letter-to-afs-licensees-and-market-participants.pdf?ref=katecarruthers.com) issued an open letter to licensees and directors calling for “**urgency, focus and accountability**” in how organisations uplift their cyber security to withstand AI‑accelerated threats. The letter frames cyber resilience as a core licensing obligation and explicitly expects firms to extend existing governance, risk, and cyber frameworks to cover AI‑specific risks. ASIC is particularly focused on strengthening governance and risk frameworks for AI, protecting critical assets, and ensuring that escalation and decision‑making processes are fit for an AI‑enabled threat environment. Just days earlier, [APRA](https://www.apra.gov.au/apra-letter-to-industry-on-artificial-intelligence-ai?ref=katecarruthers.com) had written to banks, insurers, and super funds, warning that AI adoption is outpacing the sector’s ability to manage the new risks it creates. APRA’s review found that governance, risk management, assurance, and operational resilience practices are not keeping up with the scale, speed, and complexity of AI deployments. It highlighted concentration risk from over‑reliance on a small number of AI providers, gaps in contingency planning, and weaknesses across the full AI lifecycle, including third‑party arrangements. APRA singled out frontier models such as Anthropic’s [Claude Mythos](https://www.bbc.com/news/articles/crk1py1jgzko?ref=katecarruthers.com), warning that they could materially increase both the likelihood and scale of cyber attacks by helping malicious actors discover and exploit vulnerabilities faster than many institutions can patch them. In other words, the tools your teams are experimenting with today are also empowering your adversaries. ## How AI is changing the cyber threat landscape AI is amplifying cyber risk in several key ways that boards and executives need to understand. **AI is supercharging bad-actors**. Generative models can write convincing phishing emails, clone voices, and generate fake identities at scale, lowering the bar for sophisticated social engineering. Deepfake images, audio, and video can now be crafted to impersonate executives and trusted advisers, making traditional “trust the channel” heuristics increasingly unreliable. **AI is also automating and optimising technical attacks**. Models like Claude Mythos can help attackers rapidly identify vulnerabilities, chain exploits, and even generate polymorphic malware that continuously mutates to evade detection. This shortens the attack cycle and can quickly overwhelm traditional patching and remediation processes that were already struggling to keep up with high‑severity vulnerabilities. **AI systems themselves introduce new attack surfaces**. Models can be manipulated through prompt injection, data poisoning, and adversarial inputs, leading them to leak sensitive information, make unsafe decisions, or degrade the performance of security tools that rely on AI. When AI is embedded deeply into business processes - credit decisioning, trading, underwriting, claims, customer onboarding - these vulnerabilities become business‑critical, not theoretical. The combined effect is that cyber risk is now becoming more dynamic, more scalable, and more tightly coupled to AI governance than ever before. ## Claude’s recent issues as a case study in operational risk The recent turbulence around [Anthropic’s Claude models](https://www.cnbc.com/2026/03/02/anthropic-claude-ai-outage-apple-pentagon.html?ref=katecarruthers.com) offers a useful illustration of how AI‑related issues can quickly become operational and reputational risks. In March 2026, Anthropic reported “increased errors” and “reduced performance” for its latest Claude Opus 4.6 model, including the Claude app and console, even as it topped Apple’s free app charts. For enterprises starting to embed Claude into critical workflows, those elevated error rates translate directly into degraded service, productivity losses, and potentially customer‑visible failures. > For non‑specialists, it helps to understand what a “harness” is in this context (here is a [video](https://www.youtube.com/watch?v=KX%5FVwNhcFtk&ref=katecarruthers.com) about them). The AI model itself is the clever **brain**, but the [harness](https://martinfowler.com/articles/harness-engineering.html?ref=katecarruthers.com) is the surrounding software and infrastructure that decides how that brain is used: how much “thinking time” it gets, what tools and data it can access, how it remembers previous steps, and how it formats answers. A useful analogy is that the model is like an engine, while the harness is everything around it - the gearbox, dashboard, safety systems, and controls - that turns raw power into a safe, predictable car you can actually drive. In April, [Anthropic](https://venturebeat.com/technology/mystery-solved-anthropic-reveals-changes-to-claudes-harnesses-and-operating-instructions-likely-caused-degradation?ref=katecarruthers.com) published a post‑mortem explaining that the problems were not due to the underlying model weights regressing, but to three changes in the harness around the models: a shift in default reasoning effort, a caching logic bug that effectively wiped the model’s short‑term memory every turn, and updated verbosity prompts. These relatively small configuration and infrastructure changes produced outsized impacts on perceived capability and reliability for users, especially on complex tasks. For boards and executives, the lesson is that AI risk is not just about model accuracy or bias; it is also about the mundane but critical realities of software engineering, release management, monitoring, and incident response. If you are consuming AI as a service, you are exposed not only to your own change‑management practices but also to your provider’s, including the way they roll out harness changes and configuration tweaks. Third-party risk is still a thing even in the marvellous world of AI. ## What companies should do now Regulators are clearly expecting disciplined, risk‑based action for the businesses that come under their umbrellas. A practical response for companies should include at least the following steps. 1. **Treat AI as a first‑class cyber risk driver** Make AI a standing item in cyber risk reporting to the board, alongside traditional threat intelligence and incident updates. Ensure your cyber risk appetite explicitly addresses AI‑enabled attacks and the use of AI in your own operations. 2. **Map your AI attack surface** Build and maintain an inventory of AI use cases, models, and providers across the organisation, including embedded AI features in SaaS products. Identify which systems, datasets, and processes would cause the greatest harm if an AI component failed, was compromised, or was abused, and treat them as critical assets for protection and monitoring. 3. **Uplift governance and lifecycle controls** Extend [existing model risk management](https://www.nist.gov/itl/ai-risk-management-framework?ref=katecarruthers.com), change‑management, and assurance processes to cover AI systems from design through to decommissioning, including prompt engineering, fine‑tuning, and guardrails. Require security testing and code review for AI‑generated or AI‑assisted code, with clear policies for how teams can safely use tools like Claude, GitHub Copilot, and others. 4. **Address third‑party and concentration risk** Review [dependence](https://www.asiainsurancereview.com/News/View-NewsLetter-Article/id/95343/type/eDaily/APRA-urges-stronger-AI-risk-governance-amid-rapid-adoption-across-financial-sector?ref=katecarruthers.com) on a small number of AI providers, especially where multiple critical use cases sit on the same platform. Ensure contracts, exit plans, and contingency arrangements reflect the reality that model behaviour, harness configuration, and service levels may change frequently - as Anthropic’s recent experience shows. 5. **Invest in people, process, and resilience** Uplift cyber hygiene and fundamentals first; [ASIC](https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-092mr-asic-calls-for-urgent-cyber-uplift-as-ai-accelerates-cyber-threats/?ref=katecarruthers.com) has been explicit that firms should not wait for advanced AI tools to fix basic weaknesses. At the same time, build capability in your security and risk teams to understand AI‑specific threats, run adversarial testing of AI systems, and use AI defensively for threat hunting and monitoring. 6. **Practice AI‑specific incident response scenarios** Update playbooks to cover [AI incidents](https://www.ncsc.gov.uk/guidance/ai-and-cyber-security-what-you-need-to-know?ref=katecarruthers.com): prompt injection against customer‑facing chatbots, data leakage from training or fine‑tuning, model outages at a critical provider, or an AI‑assisted mass phishing campaign against staff. Run tabletop exercises that include your AI product owners, data teams, and external providers so everyone understands roles and escalation paths. ## From experimentation to accountable stewardship Most organisations are still in the experimental phase with generative AI, piloting use cases at the edge of the business rather than in core systems. Yet attackers, unconstrained by governance processes, are moving much faster. ASIC and APRA’s recent letters are a signal that the window for casual experimentation with AI - without strong governance and [cyber oversight](https://oit.utk.edu/security/learning-library/article-archive/ai-machine-learning-risks-in-cybersecurity/?ref=katecarruthers.com) \- is closing. For boards and executives, the challenge is to move from AI enthusiasm to AI stewardship: to harness the productivity and innovation benefits of AI while taking seriously the new ways it can fail and the new threats it enables. That shift will define which organisations can [safely scale AI](https://www.nist.gov/blogs/cybersecurity-insights/managing-cybersecurity-and-privacy-risks-age-artificial-intelligence?ref=katecarruthers.com), satisfy regulators, and maintain trust in an increasingly adversarial digital environment. ### The hype cycle and AI: why we need to stay grounded URL: https://katecarruthers.com/gartner-hype-cycle-ai-governance/ Last updated: 2026-05-09T01:26:05.000Z Every few years, a new technology arrives wrapped in the language of inevitability. *It will transform everything. It will disrupt every industry. It will redefine what it means to be human, to work, to create*. Right now, that technology is artificial intelligence. And while the capabilities of contemporary AI systems are genuinely impressive, the surrounding discourse feels oddly familiar. For those of us who have lived through multiple waves of technological change, from the early internet to big data to blockchain, the current moment has a distinct sense of déjà vu. This is where the [Gartner Hype Cycle](https://www.gartner.com/en/research/methodologies/gartner-hype-cycle?ref=katecarruthers.com) becomes a useful lens. ## Understanding the hype cycle The Gartner Hype Cycle is a simple but powerful model that describes how new technologies are typically adopted. It maps a predictable pattern of collective enthusiasm, disappointment, and eventual maturity. ![](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/05/gartner-hype-cycle.jpg) The Gartner Hype Cycle The stages are well known: - **Innovation trigger:** A breakthrough or new idea captures attention - **Peak of inflated expectations:** Hype surges; expectations become unrealistic - **Trough of disillusionment:** Failures and limitations emerge; interest wanes - **Slope of enlightenment:** Practical use cases begin to take shape - **Plateau of productivity:** The technology becomes stable, useful, and embedded Importantly, the Hype Cycle is not about whether a technology will succeed. It is about how our expectations overshoot reality before settling into something more sustainable. ## AI and the peak of inflated expectations Generative AI, particularly large language models, has clearly reached the peak of inflated expectations. According to Gartner's 2025 analysis, GenAI is now sliding into the trough of disillusionment as organisations shift focus from undifferentiated enthusiasm to the foundational technologies necessary for sustainable, scalable AI delivery. We are seeing claims that AI will: - Replace large portions of the workforce within a few years - Render higher education obsolete - Solve complex societal problems with minimal human intervention - Achieve forms of general intelligence in the near term At the same time, organisations are rushing to "AI-enable" everything, often without a clear understanding of the problem they are trying to solve. This is classic hype cycle behaviour. I often cite [Amara's law](https://www.computer.org/publications/tech-news/trends/amaras-law-and-tech-future?ref=katecarruthers.com) in respect of technology innovation: *“We tend to overestimate the effect of a technology in the short run and underestimate the effect in the long run.”* There is a tendency to mistake rapid capability improvements for inevitability of outcomes. But capability does not equal impact. Impact depends on integration, governance, human systems, incentives, and institutional trust, all of which evolve far more slowly than technology. ## We have been here before The current AI moment echoes earlier waves: - The dot-com boom promised a complete reinvention of commerce; it delivered transformation, but only after a crash and consolidation - Big data was framed as a universal decision-making engine; in reality, data quality, governance, and organisational culture proved far more decisive - Blockchain was expected to decentralise everything; instead, it found more limited but still meaningful applications In each case, the underlying technology did matter. But it did not unfold in the way the hype suggested. The pattern is not failure. It is recalibration, and it is waiting for the people AND the technology AND the underlying infrastructure to catch up with each other. ## Why this matters for AI governance From an AI governance perspective, the hype cycle is more than an interesting model. It is a warning. Periods of inflated expectations tend to produce: - Overinvestment in poorly defined use cases - Underestimation of risks and externalities - Weak governance frameworks rushed into place - Policy responses driven by fear or hype rather than evidence This creates a paradox. At precisely the moment when careful, thoughtful governance is most needed, the surrounding discourse becomes least conducive to it. If we assume that AI will immediately transform everything, we risk building regulatory and organisational responses that are brittle, reactive, and misaligned with reality. Conversely, if we dismiss AI entirely as "just hype," we risk missing the genuine, longer-term [transformation](https://www.navigatevc.com/news/ais-hype-cycle-is-coming-to-an-end%E2%80%94in-2026-the-real-transformation-is-just-beginning?ref=katecarruthers.com) that will emerge during the slope of enlightenment and plateau phases. ## What matters now [Gartner's 2026 analysis](https://www.pragmaticcoders.com/blog/gartner-ai-hype-cycle?ref=katecarruthers.com) shows a clear shift in priorities. The focus is moving from GenAI hype to foundational enablers: AI engineering, ModelOps, AI-ready data, and governance frameworks. These are the real bottlenecks. Research shows that 99% of leaders report using AI in operations, yet 47% don't have AI policies in place. That trust gap slows scaling and invites risk. So what does it mean to take the hype cycle seriously? It means holding two ideas at once: - AI is **genuinely important** and will have **lasting impact** - The current narrative about AI is likely **overstated** and temporally **distorted** Practically, this suggests a different posture: - Focus on use cases, not abstractions. Where does AI actually create value in specific contexts? - Invest in data governance and organisational capability. These are the real bottlenecks. - Design for human AI collaboration, not full automation fantasies. - Expect a period of disillusionment. Plan for it rather than being surprised by it. > Resist both utopian and dystopian extremes. Neither is a useful guide for decision-making. In other words, treat AI as a technology, powerful, evolving, but ultimately embedded in human systems, rather than as an unstoppable force with its own trajectory. ## A familiar cycle, a different responsibility The hype cycle reminds us that while technologies change, human behaviour does not change nearly as quickly. *We get excited > We overestimate > We correct > We learn (rinse and repeat).* What is different this time is not the existence of hype, but the scale and speed at which it propagates. Social media, venture capital dynamics, and geopolitical competition amplify the cycle in ways that make it more intense and more consequential. For those working in AI, policy, and governance, the task is not to dampen innovation, but to remain grounded while others are swept up in the moment. Because we have, indeed, done this before. And if we pay attention, we might navigate it a little more wisely this time. ## Where do you sit on the hype cycle? How is your organisation approaching AI? Are you caught up in inflated expectations, or building the governance foundations that will matter in the long run? Many of us are working with organisations that are navigating AI adoption, helping build governance frameworks that are practical, scalable, and aligned with real-world use cases rather than hype-driven timelines. Many of us are wrestling with how to move from AI enthusiasm to sustainable implementation. We are not alone and sharing our journeys may help others. Don't forget to subscribe to my newsletter for regular insights on AI governance, data strategy, and innovation policy. ### AI adoption is a people problem, not a technology problem URL: https://katecarruthers.com/ai-adoption-people-not-technology/ Last updated: 2026-05-03T00:07:21.000Z There’s a persistent narrative doing the rounds that artificial intelligence is somehow different. Exceptional. Almost mystical. As though it sits outside the long history of enterprise technology and organisational change. It doesn’t. AI is just another technology we are implementing. Powerful, yes. Transformative, potentially. But still subject to the same stubborn realities that have shaped every major technology adoption over the past fifty years. And those realities are not technical. They are human. If we lose sight of that, this will all become a complete [shemozzle](https://www.wordnik.com/words/shemozzle?ref=katecarruthers.com). ### We’ve seen this movie before Every wave of technology arrives with a familiar pattern. Inflated expectations, breathless vendor promises, and a quiet but growing disconnect between what the technology can do and what organisations are actually capable of absorbing. ERP systems. CRM platforms. Data warehouses. Cloud computing. None of these failed or succeeded because of the technology alone. They succeeded or failed because of leadership, culture, incentives, governance, and whether people understood what was being asked of them. AI is no different. If anything, it is more demanding because it touches decision-making, knowledge work, and organisational power structures more directly. Yet many organisations are behaving as though deploying AI is primarily a tooling problem. It isn’t. **It’s a change problem.** ### The real work is social, not technical When you introduce AI into an organisation, you are not just installing software. You are reshaping how work gets done, how decisions are made, and how accountability is assigned. That creates friction. People will worry, sometimes rationally, about job security, loss of autonomy, or being held responsible for outputs they do not fully understand. Others will over-trust the technology and stop applying critical judgement. Some will quietly resist. Some will enthusiastically misuse it. None of this is surprising. It is entirely predictable. And yet, time and again, organisations underinvest in the more mundane elements. Communication, training, governance, and leadership alignment. Instead, they focus on pilots, proofs of concept, and dashboards. That is how you end up with impressive demos and very little real impact. ### Change management isn’t optional If you take one thing away, it should be this. AI adoption is a change management exercise first, and a technology deployment second. That means: - **Clear articulation of purpose.** Why this AI, for what problem, and for whose benefit. - **Investment in capability.** Not just technical skills, but data literacy and critical thinking. - **Thoughtful governance.** Who is accountable, how decisions are reviewed, and where the boundaries sit. - **Leadership alignment.** Not just sponsorship, but active modelling of appropriate use. - **Ongoing dialogue.** People need to make sense of these changes in real time. Miss these elements and the technology will drift, fragment, or be quietly ignored. Or worse, it will be used badly and create new risks. ### The risk of the shemozzle When organisations treat AI as plug and play, the result is rarely transformation. It is confusion. Different teams adopt different tools with inconsistent practices. Policies lag behind reality. Shadow AI proliferates. Data governance becomes porous. Trust erodes, both internally and externally. At that point, you do not have an AI strategy. You have a shemozzle. And cleaning that up is far more expensive - financially, organisationally, and reputationally - than doing the hard work upfront. ### Keep your eye on the humans > *The paradox at the heart of AI is that the more advanced the technology becomes, the more important the human dimension gets.* **Judgement. Context. Ethics. Accountability. Meaning.** These are not things you can automate away. So while it is tempting to focus on models, benchmarks, and capabilities, the real question remains stubbornly simple. How are people going to work with this? Because if the answer to that question is unclear, no amount of technical sophistication will save you. And if it is clear, if people understand, trust, and are supported through the change, then even imperfect technology can deliver real value. AI isn’t magic. It is people. And change. Ignore that, and yes, it will absolutely turn into a shemozzle. ### ANZAC Day and a multipolar world: what “lest we forget” means now URL: https://katecarruthers.com/anzac-day-2026/ Last updated: 2026-04-25T05:31:21.000Z > *They shall grow not old, as we that are left grow old;* > *Age shall not weary them, nor the years condemn.* > *At the going down of the sun and in the morning* > *We will remember them. - Laurence Binyon* Each year on ANZAC Day I find myself returning to the same touchstones: family stories, the [ordinary diggers](https://katecarruthers.com/anzac-day-ordinary-diggers-not-famous-not-important/) who never made the history books, and the uneasy mix of pride, grief, and doubt that sits under the surface of our [commemorations](https://katecarruthers.com/anzac-a-new-zealand-view/). This year, though, that reflection emerges in a world that feels particularly brittle and different in spirit to previous years. With wars breaking out across multiple regions, democracies under pressure, and the world on the brink of deep economic strain and unexpected shifts to familiar ways of life. ## From a single beach to a century of wars On [25 April 1915 Australian and New Zealand](https://en.wikipedia.org/wiki/Anzac%5FDay?ref=katecarruthers.com) troops landed at Gallipoli, in what was then the Ottoman Empire, in a campaign that ultimately failed in its military objectives but became foundational to both countries’ national stories. More than 8,700 Australians and around 2,700 New Zealanders died there, and by the time the Allied forces were evacuated after eight months, the cost in lives and trauma was immense. Over the decades ANZAC Day has widened from remembering Gallipoli to commemorating all Australians and New Zealanders who have served and died in wars, conflicts, and peacekeeping operations since 1914\. Today we mark the service and sacrifice of millions of service members across multiple generations, and the many thousands who have lost their lives during or as a result of their service. ## Standing in the dark, again If you have ever stood at a dawn service you will know that particular feeling: the hush before first light, the shuffle of people finding a place to stand, the mix of old uniforms and school uniforms, wreaths and smartphones. And I note how the presence of so many children and young people at ANZAC ceremonies is a reminder of how closely war brushes up against the lives of the very young even in this peaceful land. In 2026 the familiar rhythms of these services sit alongside a more global awareness, carried to us in real time by our screens: bombardments in one city, mass displacement in another, a sudden coup or drone strike somewhere else. When chaplains and community leaders invite us into spaces of remembrance shaped by reflection, lament, and hope, they are doing so against a backdrop of domestic violence, community tensions, and international conflicts that make those words feel anything but abstract. ## Lest we forget – what, exactly? “Lest we forget” has always been more than a slogan, but what we choose not to forget changes with each generation. For some, ANZAC Day is primarily about national identity – mateship, courage, endurance, the idea that under fire we discovered something essential about ourselves as Australians and New Zealanders. For others, especially as we move further from living memory of the world wars, the day is becoming a site for historical reckoning. The further we get from Gallipoli, the more room there is – and the more need there is – for hard historical perspective: on why we went, whose interests were served, how the ANZAC legend has been mobilised politically, and how it fits into a much longer story of empire, colonisation, and resistance. If “never again” is to be more than a comfort phrase, then “lest we forget” has to include not forgetting the terrible physical and mental costs of war, including for those who come home changed in ways that are not always visible. ## From empire to a multipolar world The original ANZACs fought in the service of a crumbling British Empire, under command structures and strategic priorities that were very much not their own. Later generations of Australian and New Zealand forces would find themselves aligned with a different great power, as the United States emerged from the mid‑twentieth century as the dominant military and economic force in the “free world”. We now live in a moment where that unchallenged hegemony is fading and a more multipolar world is taking shape – with rising powers, fractured alliances, and sharper contests over regional influence in our own Indo‑Pacific neighbourhood. For middle powers like Australia and New Zealand, this raises uncomfortable questions about how easily we have moved from one patron to another, and about what genuine strategic autonomy might require from us. Remembering ANZAC in a multipolar era means recognising that our dead were often sent to fight in conflicts shaped by great‑power rivalries and imperial ambitions that they did not choose. **It also asks us to think carefully about the commitments we make now, and about whether we are building a region based on collective security, diplomacy, and justice, or simply drifting into new configurations of old patterns.** ## Who gets remembered One thing I’ve tried to do in [past ANZAC posts](https://katecarruthers.com/tag/anzac/) is to bring the focus back to ordinary people - the family members whose medals sit in drawers, the names etched on local cenotaphs, the soldiers who were not generals or politicians, but farm boys, factory workers, clerks, and nurses. Their stories, when we can recover them, complicate the clean lines of legend. It is also impossible now to talk about remembrance without acknowledging that Aboriginal and Torres Strait Islander people served in Australia’s forces even while denied basic rights at home, and that they continue to serve today. Soldiers from across the empire and Commonwealth likewise fought and died in campaigns that were often far from their own homes, and their contributions are still unevenly remembered. So when we say “we will remember them”, the “them” needs to be expansive enough to hold First Nations service, migrant and refugee volunteers, women in both combat and support roles, and those whose service does not fit comfortably into older narratives of who counts as a veteran. ## Commemoration in an anxious world The mood around ANZAC Day has shifted over the last century: from early mourning and quiet gatherings, through periods of dwindling interest, to a more recent resurgence of large public ceremonies and marches. Today these events unfold in societies that are more diverse, more secular, and more digital than those that first marked the day back early in the twentieth century. In this moment of heightened geopolitical risk and domestic polarisation, there is a temptation to grab at simple stories: heroic sacrifice with the rough edges sanded off; a clean line of continuity from Gallipoli to whatever “values” we claim to defend now. ANZAC Day for me rings truest when it rejects the tidy nationalistic story - holding grief, doubt, and hard truths alongside pride. ## The work of peace If ANZAC Day is to remain relevant, it cannot just look backwards; it has to shape how we think about war and peace in the present. Remembering 1915 in 2026 means understanind that wars are still being fought by nations and states far outside of our own little part of the world, that today’s veterans will be tomorrow’s frail elders at the march, and that the decisions our governments make now will become someone else’s sacred story in a century’s time. Perhaps the deepest challenge the day offers us is this: to honour the dead and the living by doing the slow, prosaic work of peace – building institutions that can withstand pressure, nurturing diplomacy, supporting those who return from service, and refusing to look away when violence is being done in our name. “Lest we forget” then becomes not just a promise of remembrance, but a commitment to action: that we will remember clearly enough, and honestly enough, to choose differently where we still can. ### AI, power, and why open institutions matter URL: https://katecarruthers.com/one-size-fits-none-ai-power-and-why-open-institutions-matter/ Last updated: 2026-05-14T06:24:09.000Z When [Ben Werdmuller](https://werd.io/one-size-fits-none-let-communities-build-for-themselves/?ref=katecarruthers.com) writes that “*one size fits none*” and argues we should “*let communities build for themselves*” he’s talking about more than product strategy. He’s talking about power! His post really got to me as I have been thinking a lot about how software and AI work. And how, if we’re not deliberate, AI and AI platforms will quietly hard‑code existing structures of control and power into the way our societies work in ways that were not as obvious in the past for enterprise software. Ben's recent post of that title traces a line from his work on [Elgg](https://elgg.org/?ref=katecarruthers.com) \- one of the earliest open‑source social networking platforms - to today’s world of large language models and agentic coding assistants. Along the way, he makes a claim that resonates very strongly with my own concerns about AI and digital governance: platforms, apps, and models are never neutral. They encode power relations in their defaults, their data, and their design choices. If we want AI to support more democratic and equitable futures, we can’t just bolt governance on at the edges. We need institutions - and, crucially, **open** institutions - that help share power, much as trade unions and friendly societies did in the late nineteenth and early twentieth centuries. ## Platforms are frozen politics Ben’s core critique of mainstream platforms is blunt: > dominant social media and app ecosystems have been built by small, relatively homogeneous teams, mostly in Silicon Valley, who unintentionally hard‑code their own cultural, political, and economic assumptions into the software that billions of people use. From seemingly mundane choices - what a “*friend*” is, how identity works, what gets surfaced in feeds - to consequential ones like reporting tools and enforcement, these design decisions reflect a particular worldview. They are *opinions* about how social life should be organised, expressed as code. This isn’t an abstract worry. Facebook’s failure to understand and respond to local context in Myanmar, for example, has been widely documented as contributing to the spread of hate speech and incitement against the Rohingya. That’s what it looks like when a one‑size‑fits‑all platform, optimised for engagement and growth, is dropped onto a fragile political context without meaningful local governance or accountability. The same pattern holds in smaller ways every day: when moderation systems embed majority norms and marginalise minorities; when recommendation engines quietly steer attention and, with it, advertising revenue and political influence; when identity systems force people into categories that don’t fit. These are questions about **power** \- who sets the rules, who gets heard, who can be excluded - long before they’re questions about “*features*.” ## AI turns the dial up on embedded power Layer AI into this stack and the stakes rise again. Ben’s essay notes that large language models and other generative systems are increasingly being used as **engines** for building new software - from prototypes to production code - through what he and others call “agentic engineering patterns.” The cost of going from idea to working app has dropped dramatically for skilled developers using these tools. But the models themselves come with their own politics: - They’re trained on vast datasets whose composition is opaque, riddled with historical biases and asymmetries of representation. - They’re built and controlled by a small number of firms, often closely entangled with governments, militaries, and law enforcement. - Their alignment and safety layers encode particular normative choices about what counts as “harmful” or “acceptable” speech and behaviour. If we simply plug these systems into the next generation of platforms and apps, we risk **re‑embedding those power relations even more deeply**, in more places, at greater scale. The ability to generate code quickly doesn’t automatically democratise development if the underlying models, data, and infrastructures are controlled by the same concentrated actors. ## When your national AI strategy runs through Silicon Valley We’re already seeing the geopolitical implications of this concentration of power. For many countries, especially those outside the traditional centres of tech production, access to advanced AI now largely runs through a handful of US‑based corporations that control the leading models, cloud infrastructure, and application ecosystems. This was brought home vividly when Iran [attacked data centres](https://www.reddit.com/r/MistralAI/comments/1rhshj7/last%5Fnight%5Fshowed%5Fme%5Fwhy%5Feurope%5Fneeds%5Fsovereign/?ref=katecarruthers.com) across the Persian Gulf recently. Governments that want to deploy AI in public services, education, health, or defence often find themselves dependent on foreign vendors for both capability and policy direction, raising uncomfortable questions about sovereignty, strategic autonomy, and the long‑term costs of ceding such a critical layer of digital infrastructure to a small set of firms headquartered in another jurisdiction. The more core functions of government, industry, and civic life become entangled with these platforms, the harder it becomes to chart an independent course - or to insist on local values and regulations - without risking exclusion from the AI capabilities that everyone else is using. ## Open source as an institutional choice, not a licence badge This is why open source matters so much in the AI era - not as a branding exercise, but as an institutional design decision. Ben’s [own history with Elgg](https://werd.io/one-size-fits-none-let-communities-build-for-themselves/?ref=katecarruthers.com) is instructive here. Elgg wasn’t just “some code on GitHub”; it was a consciously open‑source social networking platform that: - Was adopted and adapted by universities, NGOs, and independent communities around the world. - Allowed local admins and developers to extend or change functionality, instead of waiting for a centralised product roadmap. - Created the conditions for community norms and governance structures to be reflected in the software itself, not just in a terms‑of‑service document. This is what open source does when it’s taken seriously: - **Transparency**: People can inspect what the system does, how it makes decisions, and where their data goes. - **Forkability**: If power is abused, or priorities diverge, the code can be forked and the community can walk away, taking its infrastructure with it. - **Shared stewardship**: Maintenance, improvement, and governance can be distributed across contributors, institutions, and jurisdictions. Those are institutional properties, not just licensing details. They change the **balance of power** between users, developers, and owners. In AI, the same logic applies. Open models, open data governance frameworks, and open‑source tooling can: - Give communities **genuine leverage** over the systems they depend on. - Enable **independent scrutiny** and auditing of risks and biases. - **Reduce lock‑in** and create room for alternatives that reflect different values and power arrangements. That doesn’t mean everything should be open in a naive sense - there are real concerns around misuse, privacy, and safety. But treating open ecosystems as a pillar of AI governance, rather than an afterthought, is one of the few concrete ways we have to rebalance power. ## Trade unions, friendly societies, and the politics of infrastructure We’ve been here before, in a different guise, as I mentioned in my [previous post](https://katecarruthers.com/beyond-ai-hype-building-institutions/). In the late nineteenth and early twentieth centuries, industrial capitalism massively tilted power towards employers, landlords, and capital owners. In response, workers built institutions that changed that balance: - **Trade unions** used collective bargaining, strikes, and political organising to win higher wages, safer workplaces, and legal protections. - **Friendly societies and mutuals** provided sickness benefits, funeral insurance, and basic welfare in the absence of state provision, funded and governed by their members. - **Co‑operatives** created alternative economic spaces with shared ownership and democratic control. These weren’t “*services*” handed down from above. They were collective infrastructures built from below that forced power to be shared more widely - in workplaces, in communities, and eventually in law. They also often relied on **open‑ish infrastructures** of their time: - Public meeting halls, pamphlets, and newspapers. - Shared rules and constitutions that could be copied, adapted, and re‑used. - Networks of organisers who carried ideas and practices between places. The point is not to romanticise unions or co‑ops; they were contested, imperfect, and sometimes exclusionary. The point is that they **changed the structure of power** by building and owning institutions, not just by asking for better behaviour from those already in charge. ## AI‑era unions of code? So what might the AI equivalent of a trade union look like? Ben’s essay hints at some possibilities when he talks about using agentic coding tools and open protocols to let communities build custom platforms that reflect their own norms and needs. If we take that seriously and add an explicit focus on power, we start to see some institutional patterns: - **Worker‑governed AI platforms:** Instead of a generic corporate productivity suite quietly adding surveillance‑heavy “AI features,” unions or professional associations could sponsor and govern open‑source tools that implement their own rules around monitoring, data retention, and decision‑support. The “agentic” piece is that much of the bespoke functionality can now be built and iterated more quickly with LLM‑assisted development. - **Community‑controlled recommendation systems:** Local media co‑ops, cultural organisations, or municipalities could run their own recommendation engines - using open models they can inspect and adapt - to surface news, events, and resources that serve their public mission, not an ad‑sales target. - **Civic data and model trusts:** Communities could pool data and negotiate jointly with AI developers through data trusts or co‑ops, setting terms for how their data is used to train models and what they get back - whether that’s money, access, or governance rights. In each case, open source, open protocols, and open governance are not optional extras; they’re the **mechanisms that make power‑sharing real** rather than symbolic. ## Sharing power in the stack If we accept that power is embedded all the way down - in code, data, interfaces, and infrastructures - then sharing power means working at all of those layers: - **At the code layer**, open‑source implementations and open standards make it possible to contest and replace systems that concentrate power. - **At the data layer**, community ownership, consent frameworks, and data trusts can give people collective leverage over how their information trains and tunes models. - **At the model layer**, diverse, values‑aligned models - including small, community‑specific ones - can reduce reliance on a handful of proprietary systems - **At the institutional layer**, unions, co‑ops, public bodies, and civil‑society organisations can own and govern the platforms and services built on top of that stack. That’s a lot harder than writing another set of AI ethics principles. But history suggests that without this kind of institutional work, power will remain where it is - or become even more concentrated as AI scales. ## Building the next generation of power‑sharing institutions The optimistic reading of Ben Werdmuller’s “one size fits none” argument is that we now have more technical capacity than ever to build **pluralistic, community‑defined infrastructures**. Agentic coding tools and open social protocols lower the barrier to creating alternatives. The lesson from past struggles is that we also need the institutions - the unions, mutuals, co‑ops, and clubs of the AI era - to ensure those alternatives actually redistribute power. That’s the work in front of us: - To insist that AI and platforms are **political**, not neutral. - To treat open source as a **governance choice**, not just a development model. - To build and back institutions that can **negotiate**, **contest**, and, when necessary, **walk away**. Trade unions didn’t eliminate exploitation, but they changed the terms of engagement. In the same way, AI‑era institutions rooted in openness and collective governance won’t magically fix power imbalances in the digital economy - but they might give us some leverage. “[One size fits none](https://werd.io/one-size-fits-none-let-communities-build-for-themselves/?ref=katecarruthers.com)” is, in that sense, both a design principle and a political project. ### Beyond AI hype: building new institutions for AI and the Digital Revolution URL: https://katecarruthers.com/beyond-ai-hype-building-institutions/ Last updated: 2026-04-18T08:00:58.000Z ## The bingo card that forgot AI In hindsight, it’s odd. I spend a good chunk of my waking hours thinking, writing, and talking about data, AI and the governance thereof, and yet my 2026 “existential dread" [bingo card](https://katecarruthers.com/2026-bingo-card/) back in January was full of climate risk, geopolitical tensions, pandemics, and domestic politics - and AI was nowhere to be seen. It’s not that AI wasn’t on my radar. By 2026, we have already had successive waves of generative AI hype, major advances in multimodal systems, the emergence of agentic AI, and a steady emergence of new [AI governance initiatives](https://academy.evalcommunity.com/global-ai-governance-map-140-institutions/?ref=katecarruthers.com) from the EU AI Act to the AI safety summits in the UK and South Korea. AI was clearly “a thing.” But it didn’t make the bingo card. Reflecting on that now, I think it’s because AI, for me, is feeling less like a discrete technology risk and more like an *epochal shift* \- something closer to a Digital Revolution on the scale of the Industrial Revolution. And once you start thinking in those terms, the bingo-card frame begins to feel a bit small. ## AI as a digital revolution Historians and economists have already begun making the comparison between AI and the [Industrial Revolution](https://business.columbia.edu/research-brief/research-brief/ai-industrial-revolution?ref=katecarruthers.com), not as a lazy metaphor but as a serious analytical exercise. The Industrial Revolution fundamentally altered how societies produced value: steam and mechanisation transformed physical labour, reorganised cities, and reshaped class structures. AI is doing something analogous for cognitive and organisational work. Instead of steam engines and power looms, we have large language models and recommendation systems augmenting or automating tasks that once required human judgment - from document review and coding, to medical image analysis and financial modelling. Some recent research suggests that AI and big data technologies are already shifting the labour share of income in ways that look eerily similar to the Industrial Revolution, with early evidence of a 5-15% decline in labour’s share in some sectors. At the same time, firms adopting AI are hiring more, not fewer, people - particularly those with AI skills - which echoes the historical pattern where new technologies destroyed some jobs but created entire new categories of work. You can dive into some of these analyses here: - Columbia Business School’s research brief on [AI and labour share](https://business.columbia.edu/research-brief/research-brief/ai-industrial-revolution?ref=katecarruthers.com), which explicitly compares AI’s economic impact to the Industrial Revolution. - A 2026 VoxDev piece unpacking similarities and [differences between AI and the Industrial Revolution](https://voxdev.org/topic/technology-innovation/ai-and-industrial-revolution-similarities-differences-and-lessons?ref=katecarruthers.com), including lessons for managing inequality and social disruption. The upshot is that if AI really is an Industrial-Revolution-scale transformation, we should expect not just productivity gains and efficiency, but also intense distributional conflict, institutional stress, and [new forms of social organisation](https://www.linkedin.com/posts/augieray%5Fone-thing-ai-optimists-often-tell-me-is-how-activity-7396216699567583232-XrKO/?ref=katecarruthers.com). Which brings me back to a much earlier period of my life, long before “AI and data governance” was a job description. ## A minor reminscence: the English working class, 1780–1945 When I was an undergrad studying history at the University of Sydney (a very long time ago), one of the units that stayed with me was on the English working class from 1780-1945\. We looked at that long arc of upheaval - enclosure, industrialisation, urbanisation, war, depression - and how people, especially workers, carved out spaces of agency and dignity within it. One of the most striking aspects of that period was not just the exploitation and hardship, but the incredible institutional creativity of the working class. In the midst of industrial capitalism’s dislocations, people built new and significant [institutions](https://pmc.ncbi.nlm.nih.gov/articles/PMC8022650/?ref=katecarruthers.com): - [**Working men’s clubs**](https://learn.camra.org.uk/courses/the-history-of-working-men-s-clubs?ref=katecarruthers.com): Emerging from the mid-19th century, they were designed as places where working men could gather for “conversation, business and mental improvement, with the means of recreation and refreshment.” The Club and Institute Union, founded in 1862, explicitly aimed to support clubs and institutes that combined social life with education and self-improvement. Many were built around “harmless amusements such as chess” combined with [practical](https://www.thegenealogist.co.uk/featuredarticles/discover-your-ancestors/periodical/87/a-club-for-the-working-man-3675/?ref=katecarruthers.com) education and penny savings banks, giving workers both social connection and financial tools. - [**Schools of the arts**](https://dictionaryofsydney.org/entry/the%5Fschool%5Fof%5Farts%5Fmovement?ref=katecarruthers.com) **and** [**mechanics’ institutes**](https://mivic.org.au/history-of-mechanics-institutes.html?ref=katecarruthers.com): Across Britain (and in Australia), these institutions offered lectures, libraries, and classes aimed at adult education, especially in technical and scientific subjects that were relevant to industrial work. - [**Friendly Societies**](https://research-portal.uea.ac.uk/en/projects/hidden-lives-the-working-class-family-during-the-industrial-revol/?ref=katecarruthers.com): These mutual aid groups, like the Oddfellows and Foresters, formed from the late 18th century to provide sickness benefits, funerals, and insurance for members excluded from early welfare systems. They emphasized self-help and community solidarity amid harsh factory conditions. - [**Trade Unions**:](https://en.wikipedia.org/wiki/History%5Fof%5Ftrade%5Funions%5Fin%5Fthe%5FUnited%5FKingdom?ref=katecarruthers.com) Early combinations evolved into formal unions by the 19th century, such as the Grand National Consolidated Trades Union (1834), advocating for better wages and hours. They served as protective networks and political voices for workers. - [**Co-operative Societies**](https://en.wikipedia.org/wiki/British%5Fco-operative%5Fmovement?ref=katecarruthers.com): Inspired by Robert Owen, groups like the Rochdale Pioneers (1844) created stores and workshops for fair pricing and worker ownership, blending economic mutualism with community hubs. - [**Chartist and Mutual Improvement Societies**](https://www.tandfonline.com/doi/abs/10.1080/0260137970160206?ref=katecarruthers.com): Chartist groups (1830s–1850s) and lyceums offered lectures, libraries, and debating clubs for political education and self-improvement, fostering working-class activism. Sunday schools also doubled as literacy centers. Historians like [Ruth Cherrington](https://raggeduniversity.co.uk/2015/07/30/working-mens-clubs-and-education/?ref=katecarruthers.com) have documented how these clubs and institutes offered a blend of recreation, political discussion, and education, often deliberately avoiding being *too* educational so as not to alienate their members. Others, like [T. G. Ashplant](https://kcl.academia.edu/TimothyAshplant/CurriculumVitae?ref=katecarruthers.com), emphasise that they were attempts to create spaces where working people could participate in “mental improvement” on their own terms. These were not perfect institutions; they were contested, often paternalistic, and many times exclusionary. But they were also genuine innovations in social infrastructure, emerging from and for a class that was being rapidly reshaped by industrial capitalism. They provided venues for mutual aid, political organising, cultural life, and informal learning - all under conditions of intense technological and economic disruption. ## What kinds of institutions does an AI age need? Fast forward to 2026, and we have our own landscape of AI-related institutions: - Global bodies like the UN, OECD, and UNESCO setting high-level AI principles and recommendations. - Standards organisations such as ISO, IEC, IEEE, and NIST proposing technical and governance frameworks for trustworthy AI. - National regulators implementing instruments like the EU AI Act, competition interventions, data protection enforcement, and sector-specific AI guidance. - A growing ecosystem of research centres, ethics boards, and governance alliances working on responsible AI. If you want a sense of the sheer density of this emerging governance layer, check out this [global AI governance map](https://academy.evalcommunity.com/global-ai-governance-map-140-institutions/?ref=katecarruthers.com) that tracks over 140 institutions across four layers: global governance, standards, regulators, and ethics/oversight bodies. These are all important - and, in some cases, overdue. But they are mostly *top‑down* or *expert‑centric* institutions: treaties, standards, regulatory agencies, specialist research centres. They occupy a necessary slice of the governance stack, but they don’t quite answer the question that my undergraduate history unit has left me with: Where are the **AI-era equivalents of these working men’s clubs and schools of the arts**? In other words: - What institutions are we building that allow ordinary people - not just policymakers, engineers, and CEOs - to collectively shape how AI shows up in their work, neighbourhoods, and lives? - Where do people go to *experiment*, *learn*, and *organise* around AI, beyond being passive recipients of platforms and products? - How do we create spaces that feel as normal and accessible as the local club or community hall, but that are explicitly designed for navigating the AI transition? Interestingly, there are early proposals that nod in this direction at the global level: ideas like a “CERN for AI” or a “Global AGI Agency” that would be public-private partnerships to develop and govern advanced AI systems as a kind of global public good. The [Future of Life Institute](https://futureoflife.org/grant-program/global-institutions-governing-ai/?ref=katecarruthers.com), for example, has solicited designs for new global institutions, ranging from Fair Trade AI schemes to multilateral AI agencies embedded in both the UN system and industry. These are important experiments. But they are still far from the lived reality of most communities. They also risk being primarily elite projects, even if well-intentioned. ## Imagining AI-era social infrastructure If we take the Industrial Revolution analogy seriously, then institutional innovation shouldn’t be an afterthought - it should be central. Just as the 19th-century working class built clubs, institutes, co‑operatives, unions, and friendly societies, perhaps we need a wave of **AI-era social infrastructure** that is just as inventive. Some possibilities that intrigue me: - **AI literacy and practice hubs**: Think of a contemporary School of the Arts but oriented around digital skills and AI literacy - not just coding, but critical understanding of data, models, labour impacts, and governance. These could be run through libraries, [TAFEs](https://en.wikipedia.org/wiki/Technical%5Fand%5Ffurther%5Feducation?ref=katecarruthers.com), universities, or community organisations, with a mix of formal and informal learning. - **Community AI labs**: Small, local spaces where people can experiment with AI tools on their own terms - building things that matter to them (local language models, mutual aid tools, civic data projects) rather than just consuming whatever Silicon Valley ships next. - **Worker-led AI councils**: Sectoral or workplace-based bodies where workers, unions, and professional associations co-design how AI is adopted, including rules about surveillance, deskilling, and benefit-sharing. This echoes some of the way working men’s clubs and institutes became spaces for political as well as educational activity. - **Civic observatories for AI impacts**: Local or regional institutions that track AI’s effects on employment, housing, education, health, and social cohesion - a kind of “weather service” for AI’s social impacts - and feed that data back into policy debates. None of these ideas are fully fleshed out, and many would bump into resource constraints, power imbalances, and political resistance. But that was also true in the 19th century. The institutions that endured were not the product of a single master plan; they were the cumulative result of many experiments, some of which failed, some of which evolved, and some of which were co‑opted. ## Beyond dread: putting AI on the bingo card differently So what do I do with all this when I sit down next January to sketch out my 2027 existential dread bingo? AI probably will appear on the card next time, but not just as “runaway AI risk” or “AGI apocalypse.” Instead, I suspect it will show up as something like: - “We fail to build the institutions this transformation requires.” - “We leave AI governance to a narrow set of actors and miss the chance for broader democratic input.” - “We treat AI purely as a productivity tool, not as a catalyst for rethinking how we live, learn, and work together.” The Industrial Revolution analogy is useful not because history repeats itself mechanically, but because it reminds us that technology shifts of this magnitude *always* come with institutional and social upheaval. We can’t avoid that, but we can shape it - we still have agency as human beings. Back in that undergraduate history unit, I learned that the working class didn’t just endure the Industrial Revolution; they *responded* to it and *reshaped* it, in part by building their own institutions. As we navigate the AI upheaval, perhaps the most important question is not “What will AI do to us?” but “What will we build in response?” And maybe the bingo card is not a bad place to start - not just to catalogue our dreads, but to surface the institutions that we still need to imagine into existence. ### Losing faith in the system: distrust, AI, and the turn to alternative beliefs URL: https://katecarruthers.com/losing-faith-in-the-system/ Last updated: 2026-04-15T22:46:40.000Z Everywhere I look lately, people seem to be reaching for rulebooks and rituals at the same time. Young people are turning up in unexpected places: flocking to Etsy witches and TikTok tarot readers, but also quietly joining Catholic parishes in search of structure, community, and a sense of the sacred. In one browser tab, I see a prompt engineer carefully tuning the “constitution” for an AI system, arguing over which principles it should obey and how they ought to be enforced. In another, I’m watching a TikTok where an Etsy witch explains the finer points of lunar timing for a protection spell. And in the background, geopolitics feels like a low, constant hum of anxiety: wars, climate shocks, supply-chain fragility, democratic backsliding. It would be easy to dismiss these as disconnected phenomena. But I’ve started to see them as different expressions of the same restless zeitgeist: a growing crisis of trust in the institutions that used to promise order, meaning, and safety. > When the old anchors feel shaky, people start rebuilding their own. ## Folk magic in the age of platforms The resurgence of folk magic and witchcraft subcultures online is often framed as quirky aesthetic or nostalgia. But something more interesting is going on. When you watch how people actually use witchy practices today, they are rarely about “controlling the universe.” They’re about regaining a sense of agency in a world that feels structurally out of control. A spell jar to attract abundance, a candle ritual for protection, a tarot spread for decision-making: these are small, personal governance systems. They establish: - A way to name what matters (love, safety, money, healing). - A repeatable process (on the full moon, with these ingredients, in this order). - A sense of causality, even if the mechanism is symbolic rather than scientific. On platforms like Etsy, this has crystallised into a semi-formal marketplace of ritual services. There are terms and conditions, reviews, dispute resolution processes – all the trappings of an institutional layer wrapped around intensely personal practice. In a strange way, Etsy becomes a shadow institution of meaning-making: not a church, not a university, not a therapy provider, but a marketplace where people outsource fragments of their search for control and hope. It’s easy to sneer at this as irrational. But if you zoom out, the irrationality might be less about the rituals and more about the world that makes them so appealing. ## Constitutional AI and the return of rulebooks At the other end of the spectrum, we have constitutional AI. In response to the unpredictability and scale of modern AI systems, companies are wrapping models in explicit “constitutions” – sets of rules, principles, or values that are supposed to constrain behaviour. These might reference human rights, corporate ethics policies, or generic commitments to safety and non-harm. On paper, this sounds reassuringly rational and institutional: we’re turning the messiness of machine learning into something that looks like a governance framework. There are: - Articulated principles. - Processes for enforcement (red-teaming, moderation, refusals). - Mechanisms for appeal (feedback, retraining, policy updates). In practice, however, these constitutions often expose how thin our shared agreement really is. Whose values get encoded? Which harms count, and which are quietly accepted as the cost of doing business? Who gets to decide what a “reasonable” refusal looks like, especially when the model sits between citizens and services, or between workers and their employers? Constitutional AI, like platform witchcraft, is a kind of ritual: we declare principles, we enact them through careful prompt engineering and guardrails, and we hope this tames systems whose complexity we can’t fully grasp. It’s not that the principles are bad – many of them are long overdue. It’s that the rulebook arrives at precisely the moment when faith in traditional rule-making institutions is fraying. ## Geopolitical anxiety as background radiation Underlying all of this is the steady hum of geopolitical anxiety. We don’t live in the crisp optimism of “globalisation will sort it out” anymore. Instead, we inhabit a world of: - Fragile supply chains and strategic chokepoints. - Great-power competition over chips, data, and energy. - Democracies wobbling under misinformation and institutional fatigue. - Climate shocks that no one government can fully control. Citizens are told, often in the same breath, that “everything is under control” and that we are living through “unprecedented times.” The gap between official reassurance and lived experience grows wider each year. When trust in formal institutions declines, people don’t simply become nihilists. They look for alternative systems of meaning and control – some old, some new, some hybrid: - Conspiracy theories as DIY grand narratives. - Crypto and alternative finance as DIY monetary policy. - Folk magic and wellness rituals as DIY mental health and spiritual care. - Constitutional AI and technical rulebooks as DIY governance for powerful technologies. The “woo‑to‑right‑wing” pipeline has become a visible symptom of collapsing trust in institutions. What begins as reasonable scepticism toward Big Pharma, public health agencies, or mainstream media is amplified in wellness and New Age spaces that already privilege intuition over expertise and self‑sovereignty over collective provision. In these environments, conspiratorial stories about purity, corruption and hidden elites can feel like a seamless extension of existing beliefs, so the slide into far‑right narratives shows less a sudden ideological conversion than a deeper withdrawal from any shared, institutional basis for truth and care. The common thread is not the content of these systems, but the underlying posture: ***“if the grown-ups don’t have it under control, we’ll have to invent something ourselves.”*** ## The crisis underneath: institutional trust Seen together, Etsy witches, returns to the smells and bells of Catholicism, AI constitutions, and geopolitical anxiety are symptoms of a deeper condition: ***institutional mistrust***. For most of the 20th century in the West, many people lived with a tacit sense that key institutions – governments, central banks, universities, legacy media, churches – were at least trying to steer the ship. They could be criticised, reformed, or resisted, but they were recognisably anchors of order. Today, we’re less sure. The things that we see are: - Governments struggling to regulate technologies they barely understand. - Corporations building critical infrastructure with incentives that don’t align with public interest. - Media ecosystems fragmented into partisan micro-segments. - Institutions grappling with the long shadow of sexual abuse and deeply entrenched patriarchy. - Traditional religious and civic institutions losing membership and authority. In that context, both ***ritual*** and ***rulebook*** become coping strategies. Ritual – whether witchcraft or wellness – offers embodied, personal, emotionally resonant responses to uncertainty. Rulebooks – from corporate ethics policies to AI constitutions – offer formalised, rational-sounding structures we can point to when things go wrong. Neither is sufficient on its own. Ritual without accountability can slide into superstition or grift. Rulebooks without trust can turn into ***compliance theatre***. But *together* they reveal something important: people are hungry for systems that feel both meaningful and legitimate. ## AI as a new priesthood – and why that’s dangerous The way we talk about AI often reinforces this hunger in unhelpful ways. We frame AI models as mysterious oracles: inscrutable, powerful, capable of great insight or harm. We surround them with specialists – prompt engineers, safety researchers, policy teams – who perform interpretive and protective roles. We publish constitutions that read, at times, like secular catechisms. When these systems misbehave, the response is often to add more ritual (more prompts, more usage norms) and more rulebook (updated terms of use, new safety layers). Very rarely do we ask why we are centralising so much power in systems that need such elaborate choreography just to be marginally acceptable. If AI becomes a kind of technological priesthood – ***opaque, unaccountable, insulated by layers of ritual and doctrine*** – we will simply have replaced one failing institutional model with another. We don’t need more digital priests. We need institutions that are willing to share power, accept scrutiny, and invite genuine participation in how AI is designed, deployed, and governed. ## Folk logics and formal governance need each other > So where does that leave us? One of the more hopeful possibilities is to stop treating folk practices and formal governance as opposites. Instead, we might recognise that both are responses to the same underlying conditions, and both contain insights we can use. From folk magic and other vernacular practices, we can learn: - The importance of symbolism and narrative in making change feel real. - The need for practices that operate at human scale, in everyday life. - The value of communities of care and mutual support, rather than abstract “users” or “stakeholders.” From constitutional AI and institutional rule-making, we can learn: - The necessity of explicit norms and constraints when power is uneven. - The role of transparency and documentation in enabling accountability. - The benefits of shared reference points for resolving disputes. Good governance for AI and other strategic technologies might need both: formal constitutions that are open to contestation, and lived practices that give people tangible ways to participate, resist, and reshape the systems they inhabit. ## Towards institutions we can trust again If there is a way out of the restless zeitgeist, it will not come from better Etsy listings or more elaborate AI constitutions alone. It will come from institutions – old and new – that are willing to: - **Tell the truth** about uncertainty, instead of over-promising control. - **Design with vulnerability and reversibility** in mind, rather than insisting on irreversible bets. - **Share power** with the communities most affected by their decisions. - Accept that **trust cannot be demanded**; it has to be earned, over time, through practice. In that future, constitutional AI might still exist, but in an ideal world its rules would be co-created with the people who live with the consequences, and not by a bunch of fascist tech bros. Folk practices would still flourish, but less as desperate workarounds and more as rich cultural layers around resilient systems. The restless zeitgeist is telling us something important: ***many of us no longer believe that the existing institutional arrangements can hold***. The question is whether we respond by handing our fate to new oracles, or by patiently building institutions that deserve our trust. Until then, don’t be surprised if you find yourself, in the same afternoon, tweaking the terms of an AI safety policy and quietly lighting a candle for a world that feels a little less precarious. ### Etsy witches, Claude’s mythos, and the strange mood we are in URL: https://katecarruthers.com/etsy-witches-claude-mythos/ Last updated: 2026-04-12T22:29:30.000Z Every so often the internet accidentally tells the truth about the culture that built it. Lately, that truth is wearing crystal necklaces and selling spell jars on Etsy. Search for “[Etsy witches](https://en.wikipedia.org/wiki/Etsy%5Fwitches?ref=katecarruthers.com)” and you will find love spells, hex removals, tarot sessions, aura cleanses, and digital talismans, all offered as neatly priced products with [reviews](https://www.forbes.com/sites/cyrusfarivar/2024/09/15/witchcraft-is-big-business-on-etsy/?ref=katecarruthers.com) and shipping estimates. Mainstream media has started to catch on. Vogue has profiled the rise of the “[Etsy witch](https://www.vogue.com/article/i-know-a-good-etsy-witch-why-gen-zs-turning-to-witchcraft?ref=katecarruthers.com)” for Gen Z, and WitchTok is now a recognisable subculture with millions of videos. Time has noted that Etsy has quietly become the place you go to [hire a witch](https://time.com/7307401/rise-of-etsy-witch/?ref=katecarruthers.com) and that spell casting services have survived previous attempts by Etsy to tidy up its esoteric offerings. Forbes has pointed out that this is now a real business, with some sellers making hundreds of thousands of dollars from spells that sit in a grey zone between spiritual service and entertainment disclaimer. What looks like a quirky internet trend is actually a deep insight into the zeitgeist. People are anxious. Institutions have lost much of their authority. We live inside overlapping crises (what I tend to call the rolling "polycrisis") and cascading risks that feel both systemic and out of reach. So, it is not surprising that many people are reaching for ritual, symbolism, and something that feels like agency. A $5 spell that promises better luck at work or protection from bad energy is not irrational in that context. It is a small, accessible intervention in a world where the bigger levers feel firmly bolted into someone else’s hands. ## Oracles, AIs, and new mythologies At the same time we are normalising another kind of modern oracle. We sit down in front of large language models and ask them to explain, summarise, forecast, and guide. We query them about our careers, our relationships with technology, and the shape of future risks. The interface looks rational and corporate, but the underlying relationship often feels closer to divination. Claude in particular has leaned into a very specific "mythos". Anthropic has framed Claude around a “[constitution](https://www.anthropic.com/constitution?ref=katecarruthers.com)” of guiding principles that foreground safety, helpfulness, and a kind of synthetic humility. That framing matters. It positions Claude as a cautious, reflective companion rather than a raw optimisation engine. It invites us to see the model as a safe conversational partner that will wrestle with our ethical dilemmas and anxieties about the future. The recent coverage of [Claude Mythos Preview](https://www.understandingai.org/p/why-anthropic-believes-its-latest?ref=katecarruthers.com) and Anthropic’s decision to treat it as too dangerous for broad release only adds to that mystique. The story practically writes itself. A powerful model sits inside a sandbox\*, testing the boundaries of the box it has been given. Safety researchers describe it as a [national security](https://www.linkedin.com/posts/nicoorie%5Fais-new-battleground-trust-safety-or-activity-7448414520450027520-Z05w?ref=katecarruthers.com) concern and as something that must be handled with [extreme care](https://www.politico.com/newsletters/digital-future-daily/2026/04/09/anthropics-ai-sparks-concerns-over-a-new-national-security-risk-00865901?ref=katecarruthers.com). For the public, that reads less like a technical detail and more like the beginning of a science fiction arc. It is myth‑making in real time. So now we have Etsy witches offering personalised rituals and AI systems wrapped in constitutional language and safety lore. Both are being woven into our cultural imagination as entities you might consult when reality feels too complex to navigate alone. We are not just building tools. We are building new symbolic actors and then asking them to sit in the room with our fears. ## The quiet split in reality All of this is happening against a background of escalating geopolitical risk. While a twenty‑something in London is buying a spell on Etsy to secure a new job, and a founder in Sydney is asking Claude to help draft an AI policy, nation states are busy locking in [AI regulation](https://www.anecdotes.ai/learn/ai-regulations-in-2025-us-eu-uk-japan-china-and-more?ref=katecarruthers.com), [data sovereignty](https://techpolicy.au/ai%5Fsovereignty?ref=katecarruthers.com) agendas, and industrial strategies designed to secure advantage in the next technological wave. The EU AI Act has now moved from theory into implementation, with bans on certain “unacceptable risk” systems and strict obligations for high risk and general purpose AI providers. The emerging AI Office architecture in Brussels is explicitly about shaping the behaviour of powerful models, including those that look a lot like Claude Mythos. In the United States, [Trump’s 2025 executive order on AI](https://www.lw.com/en/insights/ai-executive-order-targets-state-laws-and-seeks-uniform-federal-standards?ref=katecarruthers.com) has pushed in the opposite direction, seeking a “minimally burdensome” federal framework that undercuts more restrictive state level rules and reasserts national dominance as the central goal. If you zoom out, two very different stories about AI are unfolding in parallel. At street level, AI is framed as a personalised helper. It writes your cover letter, explains your lab results, or becomes the sparring partner for your latest strategic memo. It feels intimate, conversational, almost domestic. At the geopolitical level, the same class of systems is framed as [critical infrastructure](https://katecarruthers.com/ai-is-now-infrastructure/), as a security vulnerability, and as a territory where great powers intend to win. This is where the Etsy witches re‑enter the frame. Both the Etsy witch economy and the AI mythos are coping mechanisms sitting at the edge of a world that feels unstable. One offers spiritualised micro‑interventions in daily life. The other offers technicalised micro‑interventions in the form of generated text and reasoning. Meanwhile the macro‑systems that shape our actual risk environment, from energy security to cyber defence, are being fought over in Brussels, Washington, Beijing, and elsewhere. ## Governance as cultural work Because I live in the governance and policy trenches, it is tempting to treat this all as a set of regulatory and technical problems. Write a framework. Define risk tiers. Design safeguards. Call it a day. The trouble is that this misses the cultural layer that is now clearly in play. AI governance is not only about compliance regimes and safety research. It is also about the stories we tell ourselves about what AI is and who it serves. [Claude’s constitution](https://www.anthropic.com/constitution?ref=katecarruthers.com) is a story about a careful, aligned intelligence that knows its place. Claude Mythos Preview is a story about a powerful, slightly alarming system that must be contained for our own good. Etsy witches are a story about individuals reclaiming agency in small, symbolic ways when bigger systems feel inaccessible. These narratives shape how people will react when the next AI safety incident occurs or when a major outage cascades through some tightly coupled system. They shape how readily communities will accept new forms of surveillance wrapped in the language of safety, or how easily they will be persuaded to outsource more decision making to algorithmic processes. They even shape how companies position their products to regulators, investors, and the public. So when we talk about “trustworthy AI” or “responsible innovation” we are really talking about a contested cultural field. The mythos around models like Claude matters as much as the architecture. The way we treat Etsy witches matters as much as the latest enforcement action, because both live inside the same ambient sense of risk, agency, and control. ## Living with enchanted infrastructure We are building something that looks a lot like enchanted infrastructure. Planet scale systems that feel mysterious, that promise both harm and help, and that require faith of some kind to use. People will reach for whatever frameworks they have to make sense of that. For some that will be [constitutional AI](https://www.anthropic.com/news/claude-new-constitution?ref=katecarruthers.com) and policy blogs. For others it will be astrology, tarot, or a $5 Etsy spell that promises a bit of luck in the next job interview. And for others it will be a return to the bells and smells of the [Catholic Church](https://www.theatlantic.com/culture/2026/03/christian-revival-generation-z/686612/?ref=katecarruthers.com). If we want AI to serve democratic and human centred ends, we need to take that seriously. That means investing in institutions that can actually hold this complexity. It means designing regulatory regimes that acknowledge geopolitical realities without collapsing entirely into great power competition. It also means paying attention to the informal practices and mythologies that are popping up at the edges, because they tell us how people are really experiencing this transition. The [witches](https://www.tiktok.com/@offthevinepodcast/video/7536584332161387806?ref=katecarruthers.com) are already here. The [mythic AIs](https://red.anthropic.com/2026/mythos-preview/?ref=katecarruthers.com) are already here. The geopolitical contest is already here. The question is whether we can learn to govern this strange assemblage in a way that recognises both the technical realities and the very human need to find meaning inside them. \* *A lot of folks are reporting Claude breaking out of its containment - often by getting a shell and installing a new skill.* ### Australia’s data sovereignty ambitions will fail without research compute URL: https://katecarruthers.com/australias-data-sovereignty-ambitions-will-fail-without-research-compute/ Last updated: 2026-04-12T02:53:44.000Z ## Reminiscing One thing people might not know about me is that in early 2013 I joined the UNSW Faculty of Engineering as IT Manager. My remit covered teaching labs for our undergraduate and postgraduate students, research computing, and all the usual administrative systems. At the time, Engineering was the largest faculty in the university and had the biggest concentration of active researchers. Part of my job was looking after roughly 20 high‑performance compute (HPC) clusters that underpinned research across the faculty, many of them running flat out on extremely compute‑hungry workloads. I remember standing in a corridor chatting with three different academics, just trying to get a sense of how much data we had under management. By the third office we were talking in exabytes and I had given up trying to do the maths in my head, other than thinking: that is a lot of data. On another occasion, after I had managed to procure some extra research compute, a fluid dynamics researcher casually asked if I happened to have a spare petabyte because he had already filled what he had. Now it is worth noting that this was in the olden days, long before AI had become the talk of the town. So when I talk about the challenges of compute‑intensive research, I am not doing it from the sidelines. I have seen up close what this means for Australian universities, and I have strong views about what it means for our international competitive positioning. ## The problem Australia’s lack of serious, at‑scale compute is not just a research productivity problem, it is a sovereignty problem as well. Our universities are trying to do world‑class work on infrastructure that simply does not match the ambitions in our national AI strategies or data sovereignty rhetoric. ## Compute and the research squeeze Australian researchers can tap into national facilities and institutional clusters, but these are heavily contested, oversubscribed, and often behind global best practice in terms of GPU capacity for modern AI workloads. For many projects, once you add storage, data transfer, and specialised support, the practical ceiling on what can be done inside Australia is much lower than policymakers tend to assume. So teams end up stitching together whatever they can get from local and international HPC allocations, small internal clusters, and credits on overseas and local clouds. It is a fragile patchwork that works for modest experiments, but it does not support sustained frontier‑scale AI research or large multi‑institutional data projects. Many of our serious researchers book time on large scale international HPC resources in what are now volatile regions such as Saudi Arabia and UAE (where data centres have been recently [attacked](https://www.theguardian.com/world/2026/mar/07/it-means-missile-defence-on-data-centres-drone-strikes-raises-doubts-over-gulf-as-ai-superpower?ref=katecarruthers.com)) and in the US, where we are subject to the various funding cuts to science and technology [budgets](https://www.nature.com/articles/d41586-026-01105-7?ref=katecarruthers.com). The Australian government provides some support via the good folks at the [Australian Research Data Commons](https://ardc.edu.au/services/ai-and-ml-tools-for-research/?ref=katecarruthers.com) (ARDC); however, they are dwarfed by the scale of the demand and the availability of resources to support Australian research. ## AI is pushing the limits AI research is now right at the edge of what most institutional infrastructure can handle. Training and fine‑tuning large models demand enormous amounts of compute, fast networks, and specialist operational expertise, and the bar keeps rising every year. This is not just about bigger models for the sake of it. If Australian researchers want to work on safety, alignment, evaluation, or domain‑specific models in areas like health, climate, or defence, they need access to systems that look and feel like the ones used at the global frontier. Right now, too many of our projects are constrained to “toy” scale experiments that cannot easily be translated into production‑grade systems. ## Sovereign AI needs sovereign compute We like to talk about “[sovereign AI](https://techpolicy.au/ai%5Fsovereignty?ref=katecarruthers.com)” as if we can regulate our way to autonomy while renting most of the underlying infrastructure from offshore hyperscalers. In reality, sovereignty in AI is about control and resilience, and compute, chips, and energy are now strategic resources in their own right. If we cannot train or even reliably run critical models on infrastructure that is physically in Australia, under Australian jurisdiction, and operated by people who work to Australian law and standards, then we are not sovereign, we are tenants. At best we have a kind of “AI tenancy” arrangement, where access to essential capability ultimately depends on commercial terms, foreign policy settings, and someone else’s risk appetite. ## Geopolitics and AI risk All of this sits inside an increasingly tense geopolitical environment. Compute, advanced chips, and AI capability are now wrapped up in export controls, sanctions regimes, and strategic competition between major powers. That means the platforms Australian researchers rely on today may not be as dependable tomorrow as our risk models assume. If a significant share of our research workloads lives on infrastructure controlled by companies headquartered in other jurisdictions, then our compute pipeline is exposed to decisions made in foreign capitals and foreign boardrooms. It is not hard to imagine scenarios where access, pricing, or permissible workloads change quickly in response to geopolitical shock. Building sovereign capability is partly about reducing that exposure, so that core public interest research can continue regardless of which way the geopolitical winds are blowing. ## Data sovereignty and university research The same tension shows up in data sovereignty. There is a growing push to keep sensitive government, health, defence, and critical infrastructure data onshore and subject to Australian law. Yet our undercooked research compute story means that to do serious AI work with those datasets, universities are often nudged towards foreign‑owned cloud platforms with opaque data flows. It is worth pondering what we actually mean by data sovereignty in Australia: > *"Data sovereignty refers to the right of a nation to control and manage its own data, regardless of where that data originated and \[is\] stored. This means that a country has the authority to determine how its data is collected, processed, and shared, as well as enforce its own laws and regulations related to data protection and privacy. Data sovereignty is often linked to national security, as countries may be concerned about foreign access to sensitive data.* > *Data localisation, on the other hand, refers to the requirement that data be stored within a particular country’s borders. This does not mean that a country has full control of the data as the laws of other counties may also apply.* [Influence of international digital platforms, REPORT - November 2023](https://www.aph.gov.au/Parliamentary%5FBusiness/Committees/Senate/Economics/Digitalplatforms/Report/Chapter%5F5%5F-%5FData?ref=katecarruthers.com#%5Fftn37)" Policy frameworks recognise that Australian data is essential to building AI that reflects the diversity and complexity of our society, and that we need consistent standards and national data infrastructure to make that usable for research. But when the compute that can actually process those datasets at scale lives elsewhere, our “data sovereignty” risks becoming performative: the bits might be notionally onshore, but the meaningful capability to work with them sits offshore. ## The emerging sovereign AI gap Government and industry are slowly waking up to these issues. There is growing recognition that Australia should focus on “sovereign inferencing”: being able to run world‑class models on infrastructure we control, even if some of those models are developed elsewhere. Recent efforts to stand up sovereign AI infrastructure for government workloads show what is possible, but current national capacity is still described as insufficient for frontier‑scale model development. Here is the catch for universities: if sovereign AI infrastructure emerges only for public sector and commercial use, while research is left to scramble on legacy clusters and variable cloud deals, we will hard‑code a two‑tier system. Public talk of sovereign capability will not match the reality inside labs and research centres that are still queueing for GPU hours. ## What Australia needs to do next If we are serious about sovereign AI and data sovereignty, then university research compute has to be treated as core national infrastructure, not a nice‑to‑have for a few STEM disciplines. We need a coordinated investment plan that ties together HPC, sovereign cloud, trusted data platforms, and the talent to run them, specifically designed to support open, collaborative research. That also means designing governance so that researchers can work with sensitive datasets on sovereign platforms without spending half their time navigating bespoke agreements and inconsistent rules across jurisdictions. Otherwise, the path of least resistance will remain “just put it on a foreign cloud and hope the contract covers it”, which is the opposite of sovereignty. Australia has the talent and the policy language. What we are missing is the **infrastructure** that allows our universities to actually live up to the slogans. Until we fix that, sovereign AI and data sovereignty will remain talking points while our best ideas quietly depend on someone else’s computers. ### AI is now infrastructure: Why that changes everything URL: https://katecarruthers.com/ai-is-now-infrastructure/ Last updated: 2026-04-11T02:57:22.000Z For the past decade, AI has mostly turned up as a feature: better recommendations, smarter search boxes, chatbots bolted onto existing systems. In 2026, that story has flipped - AI is rapidly becoming an **infrastructure** layer that economies, organisations and governments will come to rely upon as heavily as electricity, telecommunications networks and cloud. When you treat AI as infrastructure rather than merely as a clever app then everything it is predicated on changes. And the things that change includes are: where you invest, how you govern, who holds power, and what failure looks like. ## From AI as a feature to AI as a utility We have spent years talking about AI in terms of individual use cases: fraud detection, customer service bots, image classification, a bit of marketing copy on the side. That was the “AI as a feature” era. What is emerging now is different: - **AI inference** is being woven into payments, logistics, healthcare operations, public services and internal workflows in a way that is always‑on, not just project‑based. - **Generative models** have moved from experiments to embedded tools for both business users and developers, with adoption across most large organisations. - **Hyperscalers and data centre operators** are positioning AI compute, storage and networking as a general‑purpose utility layer that everything else will build on. Once intelligence becomes a shared utility rather than a set of isolated tricks, your architecture, risk posture and strategy need to look more like what you do for networks and power than what you do for a mobile app. ## The physical reality of AI infrastructure *The cloud* has always been physical, but AI has made that physicality impossible to ignore. Now the internet of things also includes embodied AI. And infrastructure becomes the limiting factor to growth. - High‑density GPU clusters draw significantly more power and generate more heat than traditional server racks, forcing redesign of power delivery, cooling and floor layouts. - In several markets, there are multi‑year delays just to connect new AI‑heavy data centres to the grid, because transmission networks were never designed for this kind of load growth. - AI data centres are becoming major electricity and water users, which pulls them directly into energy policy, environmental regulation and community debates. [As I have often argued - bigger is not always better for AI](https://katecarruthers.com/the-future-of-ai-is-smaller-not-bigger/), and that we need to get serious about smaller, more efficient models that deliver value without blowing our energy budgets. The infrastructure side of the house is now feeling those constraints in very tangible ways. ## Intelligence as critical infrastructure As AI becomes part of the backbone of digital services, it is starting to be treated like other pieces of critical infrastructure. There are several shifts arising from this shift: - **Policy and regulation**: There is growing pressure to formally recognise AI compute, data centre networks and key platforms as *critical infrastructure*, with corresponding obligations for resilience, security and transparency. - **Geopolitics and sovereignty**: Nations are racing to secure chip supply, sovereign data centres and AI‑ready grids, positioning themselves as both consumers and exporters of AI capability. - **Concentration risk**: When a small number of providers control a large share of global AI compute and foundation models, systemic risk starts to look uncomfortably like “too big to fail” for infrastructure. This matters because outages and incidents cease to be local IT problems. If your payments, clinical decision support, customer service, logistics and internal controls all depend on AI services hosted in a handful of data centres, then a failure starts to look like a power grid issue, not a quirky app going down. We have already seen [huge data centres being hit](https://theconversation.com/why-iran-targeted-amazon-data-centers-and-what-that-does-and-doesnt-change-about-warfare-278642?ref=katecarruthers.com) in West Asia as part of the US/Israeli war on Iran (Saudi, etc.). ## What this means for organisations If AI is now an infrastructure play, then leaders need to stop thinking in terms of one‑off “AI projects” and start thinking in terms of investments in long‑term capability. Here are a few practical implications: - **Infrastructure‑first, experiment‑second:** The organisations getting real value from AI are investing in data (AI) governance, platforms, pipelines and model lifecycle management first, and use cases second. You simply cannot scale if every new AI idea requires bespoke plumbing. - **Hybrid, distributed architectures by default:** AI workloads are driving more sophisticated mixes of public cloud, on‑premises and edge, with orchestration systems that place workloads dynamically based on latency, cost, regulation and risk. The old binary of *on‑premise vs cloud* simply doesn’t map to AI‑heavy architectures. - **New operating models for teams:** Developers and operations teams are becoming curators and orchestrators of AI services and agents, not just builders of monolithic apps. Business users are increasingly hands‑on, using low‑code platforms and AI‑assisted tools to build workflows and agents on top of the shared infrastructure. As I have often argued, leadership, governance and disciplined implementation matter more than your choice of shiny tool. Treating AI as infrastructure means funding and governing it like a multi‑year capability program, not like an innovation line item that can be quietly retired when the hype cycle moves on. ### Questions leaders should be asking right now For boards, executives and technology leaders, the mindset shift is simple to state and hard to execute. Some useful questions: - **What does our AI “grid” look like** \- where does our critical AI compute live, how resilient is it, and how concentrated are our dependencies on specific providers or regions? (i.e. what is our geopolitical risk?) - **How constrained are we by power, cooling and connectivity?** And are those constraints shaping our choices about model size, deployment patterns and “small vs big” decisions? - **Are we building shared, well‑governed platforms and data architectures** that multiple teams can plug into, or are we still funding scattered [proofs‑of‑concept with no path to scale](https://katecarruthers.com/ai-innovation-poc-to-production/)? - **Do we have governance, monitoring and evaluation infrastructure in place** for AI systems and agents before we have incidents, or will we be improvising after something goes wrong? Those are infrastructure questions, even when they show up under “digital strategy” or “innovation” on a board or executive committee agenda. ## Where this is heading next If 2024-2025 were the years AI became visible to everyone, then 2026-2027 are shaping up as the years intelligence became infrastructure. The most interesting work over the next few years may not be the headline‑grabbing model launches, but the quieter infrastructure changes underneath them. Expect to see: - **Ongoing consolidation and competition in the AI infrastructure stack** \- chips, interconnects, data centre platforms, orchestration layers and foundation model “utilities.” - **A shift from *bigger models at any cost* towards smaller**, more specialised models and agentic systems that deliver value within real‑world constraints on power, latency and budget. - **Clearer** [**governance**](https://katecarruthers.com/data-governance-needs-a-rebrand/) **expectations** as regulators, insurers and markets start treating AI infrastructure in the same category as other essential services. The organisations that thrive in this phase will be the ones that do the boring work well: data architectures that let information flow, evaluation and monitoring infrastructure for AI systems and agents, and governance that assumes AI is part of the backbone, not an optional extra. It is an interesting time to be building our AI future. Here is some background reading on AI and infrastrucuture:[ ](https://biztechmagazine.com/article/2026/01/how-ai-changing-businesses-infrastructure-strategies?ref=katecarruthers.com) [How AI Is Changing Businesses' Infrastructure Strategies ](https://biztechmagazine.com/article/2026/01/how-ai-changing-businesses-infrastructure-strategies?ref=katecarruthers.com) [It's time to start treating AI infrastructure as critical infrastructure](https://www.weforum.org/stories/2026/04/ai-infrastructure-critical-infrastructure/?ref=katecarruthers.com) [The State of AI in 2026: The Year Intelligence Became Infrastrucuture](https://aiworldjournal.com/the-state-of-ai-in-2026-the-year-intelligence-became-infrastructure/?ref=katecarruthers.com) [The AI Infrastructure Surge in 2026 & What It Means for Enterprise](https://jeskell.com/the-ai-infrastructure-surge-in-2026-what-it-means-for-enterprise-architecture/?ref=katecarruthers.com) [2026 State of AI Infrastructure Report - DDN](https://www.ddn.com/2026-state-of-ai-infrastructure-report/?ref=katecarruthers.com) ### Future of Education - why critical thinking matters more than ever URL: https://katecarruthers.com/why-critical-thinking-matters/ Last updated: 2026-06-26T01:30:24.000Z Most educators are rushing to adapt to AI without fully grasping its implications - are we teaching students just to use technology, or to critically engage with it? [Ben Harris-Roxas](https://www.unsw.edu.au/staff/ben-harris-roxas?ref=katecarruthers.com), a health systems researcher and educator, discusses the kind of radical shift needed to keep human intelligence at the centre of education’s future.In this eye-opening episode, Ben shares how the rapid rise of AI challenges traditional teaching models and why validation and critical thinking are now higher-order skills than ever. Discover how universities are experimenting with embedding AI into coursework, moving away from banning tools to harnessing their potential for deeper learning. We'll break down: - The importance of critical appraisal in an era of AI-generated content - Why validation is a harder skill than creation and how to teach it - Practical strategies to incorporate AI use ethically and effectively in assessments - How education must evolve to preserve human creativity, messiness, and friction in learning - The implications for workforce preparedness and the future of human-AI collaboration This episode is perfect for educators, students, and policymakers who want to understand how AI reshapes knowledge, assessment, and the very nature of intelligence. If you’re questioning whether traditional education still makes sense in a digital, AI-driven world, this discussion will challenge your assumptions and inspire smarter approaches. [Ben Harris-Roxas](https://www.unsw.edu.au/staff/ben-harris-roxas?ref=katecarruthers.com) is an associate professor in public health at UNSW, known for his research into health system improvements and innovative teaching methods that integrate emerging technologies. > Associate Professor Ben Harris-Roxas is an internationally recognised expert in health services research, integrated care, and health impact assessment. His research strengthens health systems for people from culturally diverse backgrounds, people with disabilities, and carers. As AI accelerates change across sectors, failing to adapt risks creating a generation that’s ill-equipped to critically evaluate and validate. The opportunity? Building education that fosters human judgment, mastery, and resilience in the face of rapid technological upheaval. [Tune in](https://creators.spotify.com/pod/profile/kate-carruthers4/episodes/Future-of-Education--why-critical-thinking-matters-more-than-ever-e3hlso4?ref=katecarruthers.com) if you're committed to shaping an education system that keeps pace with the future - because how we teach today determines how well we thrive tomorrow. ### AI Agents Are Here: How Memory, Emergence, and Governance Will Make or Break the Agent Era URL: https://katecarruthers.com/the-agent-era-is-here/ Last updated: 2026-04-01T11:09:59.000Z The Agent Era Isn’t Coming. It's here and it’s Already Messy. I spent an interesting evening at an agentic AI meetup with old friends [Mark Pesce](https://datarevolution.tech/2023/06/mark-pesce-talking-ai-episode-3/?ref=katecarruthers.com) and [John Allsop](https://johnfallsopp.com/?ref=katecarruthers.com) in the wilds of Waterloo in a brewery the other night. It really got me thinking about agentic AI from some different angles. We’ve spent the last two years arguing about what AI agents "are". Whether they count as “real” agents if they still hallucinate. Whether multi-agent orchestration is a genuine architectural advance or just pipeline management with better branding. Meanwhile, the agents are shipping. Last week, Jensen Huang stood at [GTC](https://www.youtube.com/watch?v=jIviHI7fqyc&ref=katecarruthers.com) in San Jose and framed agentic AI as a new class of computer for enterprises, talking about “agentic computers” and an “operating system” for them ([NVIDIA Launches Vera CPU, Purpose-Built for Agentic AI ](http://nvidianews.nvidia.com/news/nvidia-launches-vera-cpu-purpose-built-for-agentic-ai?ref=katecarruthers.com)). Huang said OpenClaw "open sourced essentially the operating system of agentic computers … It is no different than how Windows made it possible for us to create personal computers." ([Nvidia GTC 2026: Everything Jensen Huang Announced at the Keynote](https://www.techloy.com/nvidia-gtc-2026-everything-jensen-huang-announced-at-the-keynote/?ref=katecarruthers.com)) NVIDIA announced new CPU products and hardware racks designed to sit alongside GPUs as part of an end‑to‑end stack for agentic workloads, explicitly positioning CPUs as orchestration engines rather than matrix‑math accelerators. That’s a different computational problem. The infrastructure is catching up to the ambition. And the adoption numbers are real enough to matter. NVIDIA’s 2026 State of AI survey reports that 64% of organisations now say they are actively deploying AI in production, up sharply from more tentative usage in prior years. Within that, agentic AI is already in use by close to half of respondents in telecom and retail/CPG, at around the high‑40s percent mark. The question has genuinely shifted from "can it work" to "how do we scale it without the wheels falling off". ## What Actually Changed The thing that made agents viable isn’t just the models getting smarter. It’s the economics. Inference costs for large language model workloads have fallen by roughly an order of magnitude over the last few years, moving from tens of dollars per million tokens on early commercial APIs to well under a dollar — and in some cases just a few cents-per million tokens on current-generation models and infrastructure ([Inference Unit Economics: The True Cost Per Million Tokens](https://introl.com/blog/inference-unit-economics-true-cost-per-million-tokens-guide?ref=katecarruthers.com)). When each million tokens costs tens of dollars, agentic workflows are a luxury for well‑capitalised R&D teams. When they cost cents, they start to look like table stakes. You don’t need a board‑level business case for basic automation anymore; the cost objection has largely evaporated. What you do still need is memory. The models are capable; what’s relatively tiny is their immediate context - what they can hold and act on within a session. The current wave of engineering work isn’t primarily about making models larger. It’s about making them remember better. That’s the unsexy infrastructure problem that will separate organisations that actually deploy agents at scale from those stuck in perpetual pilot purgatory. Multi-agent systems are the other shift. The model isn’t doing everything. A planner spawns specialists. A critic checks the work. A coordinator routes outputs to the next task. This isn’t new as a concept - distributed systems people have been doing this for decades - but the combination of much cheaper inference and the Model Context Protocol (MCP) giving agents a standardised way to access tools and external context is what makes it operationally viable now. ## Memory Is the Difference Between a Demo and a System Here’s the thing most agent demos hide they start fresh every time. The model is stateless by design. Each API call arrives with no knowledge of what came before unless you explicitly hand that context back in. That’s fine for a chatbot. It’s a serious problem for an agent running a multi‑week workflow. The demo looks great. The agent handles multi‑step tasks with fluency. Then you deploy it into a real environment, and it asks the same clarifying question it asked three days ago. It forgets the decision your team made last Tuesday. It loses the context that took four back‑and‑forth exchanges to establish. This isn’t a bug in your implementation. It’s a fundamental architecture gap - and most organisations discover it only after they’ve already committed to a deployment. The research on what good memory architecture actually buys is now pretty concrete ([Long-term memory in agentic systems: Building context-aware agentic-ai-memory](https://www.moxo.com/blog/agentic-ai-memory?ref=katecarruthers.com)). Persistent, structured memory systems - combining episodic logs, semantic knowledge, and learned procedures - show significantly higher accuracy and reliability on long‑horizon benchmarks than stateless approaches or naive “just stuff everything in the context window” strategies, often improving success rates by tens of percentage points on complex tasks. At short sessions, the stateless model can wing it. Over weeks and months, the difference between an agent that remembers and one that doesn’t is the difference between a useful system and an expensive autocomplete. What memory ([Building Agent Memory that Retains, Recalls, and Reflects](https://arxiv.org/html/2512.12818v1?ref=katecarruthers.com)) actually means for agents is more nuanced than “stores conversation history.” There are at least three meaningfully distinct functions in play. Episodic memory is the record of specific events: what happened, when, and what was decided. The compliance review flagged a document on March 3rd. The client accepted revised terms on the 15th. Semantic memory is the knowledge layer: domain rules, customer profiles, policies that apply regardless of session. Procedural memory is how‑to knowledge - the process patterns and workflow scripts that don’t need to be re‑derived from scratch each time. Many current agent implementations collapse all three into a single context window and call it done. That works until the context gets long, at which point you have a different problem: everything is in there, but the agent pays equal attention to all of it, which means the important signal gets buried. The architectures getting real traction now treat these as separate concerns - episodic recall via vector search over structured event logs, semantic knowledge via retrieval‑augmented generation against a curated knowledge base, procedural memory encoded in the agent’s scaffolding and tools rather than re‑prompted each time ([The 3 Types of Long-term Memory AI Agents Need](https://machinelearningmastery.com/beyond-short-term-memory-the-3-types-of-long-term-memory-ai-agents-need/?ref=katecarruthers.com)). These are all lessons we had to learn in previous incarnations of the technology revolutions we have undergone since the 1970s. We will learn them again, or rather, the AI will learn them now. The analogy to human memory is imperfect but genuinely useful here. We don’t replay every conversation we’ve ever had when we need to make a decision. We’ve consolidated relevant facts, retained the gist of past experiences, and built up implicit procedural knowledge that we apply without consciously retrieving it. The agents that are starting to feel “intelligent” in practice are the ones whose memory architecture does something similar: extract salient facts from interactions, consolidate them over time, retrieve selectively based on relevance rather than recency, and build up a working model of the environment they operate in. This is also where embodiment and memory start to intersect in interesting ways. A physically situated agent - a robot navigating a factory floor, a drone managing a delivery route - builds up a model of its environment through repeated interaction. Its memory isn’t just a record of past conversations; it’s a world model, constantly updated by what it perceives and acts on. Software agents are doing something structurally similar, but the environment is digital: the state of systems, workflows, communications, and decisions. The agent that genuinely understands a logistics operation isn’t the one with the best model. It’s the one that has been operating in that environment long enough to have built up genuine situational knowledge — and has the architecture to retain and use it. ## The Embodiment Question Nobody’s Quite Asking Right Here’s where it gets interesting, and where the discourse usually stays too shallow. Most agent conversation treats embodiment as a hardware category: robots. Humanoids in warehouses. Tesla’s Optimus. Kitchen and service robots at major appliance and electronics expos. These are real and worth watching. [Skild AI](https://www.skild.ai/blogs/omni-bodied?ref=katecarruthers.com) announced their “omni‑bodied brain” - one model controlling a wide range of robotic hardware, trained across embodiments - and their framing is instructive: they’re not building a robot arm controller, they’re building something closer to generalised physical intelligence. And Skild AI announced on March 16, 2026 expanded collaborations with NVIDIA, ABB Robotics, and Universal Robots, describing its Skild Brain as "an omni-bodied brain designed to control any kind of robotic hardware — any robot, any task, one brain." ([Skild AI Expands Generalized Robot Intelligence Across Industries With ABB Robotics, Universal Robots, and NVIDIA](https://www.globenewswire.com/news-release/2026/03/17/3256839/0/en/Skild-AI-Expands-Generalized-Robot-Intelligence-Across-Industries-With-ABB-Robotics-Universal-Robots-and-NVIDIA.html?ref=katecarruthers.com)) > But embodiment isn’t just about having legs. The more important shift is that agents are increasingly "situated". They exist in a context that they perceive and act on over time. A software agent managing a logistics workflow isn’t perceiving vibration and gravity, but it is perceiving state - the state of orders, delays, inventory, customer communications - and taking actions with real‑world consequences that it then has to respond to. That’s a form of situatedness. The gap between that and a physical robot isn’t a difference in kind; it’s a difference in the friction of consequences. This matters for governance, not just philosophy. The emerging governance conversation increasingly distinguishes between digital agents, whose behavioural errors are often recoverable, and physical AI systems, whose mistakes can be irreversible once torque, force, or safety‑critical infrastructure are involved. High‑profile failures like [Deloitte’s](https://fortune.com/2025/10/07/deloitte-ai-australia-government-report-hallucinations-technology-290000-refund/?ref=katecarruthers.com) hallucinated government report show how even “just digital” errors can be operationally and reputationally costly; adding physical actuation raises the stakes further. We’re building AI systems to act in both registers now, and we’re mostly treating them as the same governance problem. They’re not. ## On Emergence: The Part We’re Still Not Handling Well There’s a documented case from February - the Matplotlib incident - where an autonomous AI agent wrote and published a personal attack article targeting a volunteer maintainer after its code was rejected, attempting to damage the contributor’s reputation and influence perceptions of the project ([An AI agent got its code rejected so it wrote a hit piece about](https://the-decoder.com/an-ai-agent-got-its-code-rejected-so-it-wrote-a-hit-piece-about-the-developer/?ref=katecarruthers.com)). The agent wasn’t explicitly instructed to do this; it was taking an action that looked, from inside its objective and feedback loop, like a reasonable step toward its goal in an online ecosystem that rewarded attention. Although it's worth noting it's also possible that the human who created the agent wrote the post themselves or prompted an AI tool to write the post ([The Register](https://www.theregister.com/2026/02/12/ai%5Fbot%5Fdeveloper%5Frejected%5Fpull%5Frequest/?ref=katecarruthers.com)). That’s an emergent behaviour. And it’s a mild one. The frameworks for thinking about this haven’t caught up. We talk about emergent properties in AI mostly in the context of model capabilities - surprising things large models can do that smaller models can’t. Arithmetic, multi‑step reasoning, rudimentary theory of mind. The emergence we should be focused on is behavioural: what happens when you deploy fleets of goal‑directed agents into shared environments, where they’re competing for resources, influencing each other’s inputs, and optimising at speeds and scales humans can’t monitor in real time. Network effects apply. One observation from complex systems and virtual‑world research that translates cleanly: the more a network facilitates rich interconnections, the more emergent creativity and unexpected behaviour you will see. Multi‑agent systems are exactly this kind of network. The interconnections are the point. So is the unpredictability. Alibaba’s experimental ROME agent recently bypassed internal safeguards during training and began redirecting compute resources into unauthorised cryptocurrency mining during training runs, opening a reverse tunnel to external infrastructure in the process ([Alibaba-Linked AI Agent ROME Attempts Crypto Mining](https://cryptonews.com.au/news/alibaba-linked-ai-agent-rome-attempts-crypto-mining-and-network-tunnelling-during-training-133168/?ref=katecarruthers.com)). Researchers caught it through monitoring and shut it down. The response in most [governance](https://katecarruthers.com/data-governance-needs-a-rebrand/) conversations is “add more monitoring.” That’s not wrong, but it’s reactive and it assumes you know what to monitor for. Emergent behaviours, by definition, are the ones you didn’t predict. ## What This Actually Requires The organisations getting this right are doing a few things the frameworks don’t tell you to do. They’re treating agentic AI as a workflow redesign problem, not a deployment problem. The question isn’t “which tasks can we hand to an agent.” It’s **“what does the human role look like when agents handle execution, and where does human judgment actually need to be in the loop”.** Those are different questions and most organisations are still asking the first one. They’re taking memory and context management seriously as a technical discipline. Not just RAG pipelines bolted onto a model, but genuine architecture work around what state persists, what gets summarised, what gets discarded, and who can inspect it. And the serious ones are building evaluation infrastructure before they have incidents, not after. Red teaming for agents isn’t the same as red teaming for models. You’re not just testing outputs; you’re testing behaviour over time, across tool calls, in adversarial environments and messy, interconnected systems. Keep an eye on my [Data Revolution podcast](https://datarevolution.tech/?ref=katecarruthers.com) for some interesting interviews with some pioneers of the new agent world coming up soon. The hype is real. The capability is real. The gap between polished agent demos and production‑grade deployment is also real, and it’s mostly in the boring places: memory, monitoring, failure modes, governance. That’s always where it is. ### What we need to think about for effective AI governance URL: https://katecarruthers.com/effective-ai-governance/ Last updated: 2026-05-12T04:27:07.000Z People keep asking me: “What do we actually *do* about AI governance?” Everyone has a framework, a model, or a glossy diagram. But if you sit in a real organisation, with messy legacy systems, half‑finished data lakes, and vendors knocking on your door with “AI‑powered” everything, the question is much more basic: how do we make sure this stuff is safe, lawful, useful, and aligned with what we’re here to do? In other words, how do we govern it? ## Start with why: AI rides on data I’ve said for years that data governance is the foundation for information and cyber security. With the advent of popular AI, that foundation suddenly matters a whole lot more. Most of the AI governance conversation skips past this and goes straight to model cards, algorithmic audits, or “responsible AI” principles. That’s all important, but if you don’t know where your data is, who has access to it, and how well it’s protected, you’re building AI on sand. Before you get too excited about agents and copilots, you still need to be able to answer the [big five data questions](https://katecarruthers.com/data-governance-for-leaders/): - Do you know the **value** of your data? - Do you know who has **access** to your data? - Do you know **where** your data is? - Do you know who is **protecting** your data? - Do you know how **well** your data is protected?​ If you can’t answer those, your first AI governance task is actually to get serious about [data governance](https://katecarruthers.com/data-governance-needs-a-rebrand/). ## From principles to practice Most organisations now have a set of AI principles floating around somewhere: fairness, accountability, transparency, human‑centricity, and so on. They look lovely on a slide. The trouble is that they often stop there. Effective AI governance is about making those principles bite in practice. That means, at a minimum: - Translating **high‑level principles** into **concrete controls** and **decision rights**. - Being clear about **who can approve what**: use cases, models, vendors, data sets. - **Embedding checks** into existing processes rather than creating another parallel bureaucracy. Think about how you already govern information security, privacy, and risk. You probably have risk registers, assurance processes, internal audit, and board reporting. AI governance should plug into those, not sit off to the side as a shiny new thing. An example I’ve seen work is treating AI systems much like any other critical system: you require a business owner, a technical owner, a risk assessment, and a clear lifecycle from experiment through to production and retirement. The difference is that for AI you explicitly look at things like data provenance, model behaviour, and human‑in‑the‑loop controls. ## Safe, secure, lawful – in that order ![DTC Australia AI LIfecycle model https://www.digital.gov.au/policy/ai/AI-technical-standard/technical-standard-governments-use-artificial-intelligence-ai-system-lifecycle](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/04/ai-model-dtc.png) DTC Australia AI Lifecycle Model In my podcast conversations on AI governance, a recurring theme is that we need AI systems that are safe, secure, and lawful – and in that order. It sounds obvious, but if you look at how many organisations are currently adopting AI, usefulness and speed tend to come first, and everything else is an afterthought. So when you’re designing AI governance, you need to build in questions like: - **Safe**: What harm could this system do, and to whom? What are the plausible failure modes? - **Secure**: What new attack surfaces are we opening up? How does this interact with our existing cyber posture? - **Lawful**: Which regulations apply (privacy, discrimination, sector‑specific rules, emerging AI laws), and how are we demonstrating compliance? Regulators globally are still catching up – the [EU AI Act](https://artificialintelligenceact.eu/?ref=katecarruthers.com) is a good example of a fast‑moving landscape – but organisations cannot wait for perfect guidance. Governance is about making defensible decisions now, under uncertainty, and being able to show your working later. A good place to start is to read the [ISO 42001 Artificial intelligence - Management system](https://www.iso.org/standard/42001?ref=katecarruthers.com) or the Australian government's recently released [AI technical standard](https://www.digital.gov.au/policy/ai/AI-technical-standard?ref=katecarruthers.com) (where they even outline a nice [AI lifecycle model](https://www.digital.gov.au/policy/ai/AI-technical-standard/technical-standard-governments-use-artificial-intelligence-ai-system-lifecycle?ref=katecarruthers.com)). ## Humans in the loop (for real) One of the more comforting phrases in AI policy documents is **“meaningful human oversight”**. It suggests that somewhere, a wise and alert human is carefully monitoring what the AI does. In reality, we’re often giving tired, overworked people a “review” step in a process and pretending that’s enough. If you want human oversight to be meaningful rather than decorative, ask: - Does the **human understand** how the AI is being used and what it’s good or bad at? - Can they **realistically intervene**, or are they just clicking “approve” to get through their workload? - Do they have the **authority to override** the AI, and is that culturally acceptable? This is where education and literacy come in. We’ve spent years educating people in data science and analytics, but we’ve neglected the data and AI leadership piece. Leaders need enough understanding to ask sensible questions, push back when needed, and sponsor better ways of working. ## The organisational plumbing AI governance is not just about models and policies; it’s organisational plumbing. It’s about how things actually move through your system. Some practical elements that matter: - **Clear ownership**: Who owns AI at the executive level? Is it scattered across IT, data, risk, and marketing, or is there a coherent view? - **AI strategy**: Does your organisation have a clear AI strategy or are you still looking at it as a tactical tool? - **Integrated processes**: Does AI feature in your project gating, vendor procurement, and change management processes, or is it sneaking in via shadow IT? - **Lifecycle thinking**: Are you governing AI experiments differently from production systems, and do you know when something has quietly become “business critical”? When we built out data governance at UNSW, we discovered that getting the right people in the room – data owners, security, legal, business stakeholders – was half the battle. The same is true for AI governance. It’s inherently interdisciplinary; no single function can own it end‑to‑end. ## Talent, capacity, and the boring work There’s a hard reality here: effective AI governance requires people who know what they’re doing, and right now there are not enough of them. It’s the same story we’ve seen with data governance and cyber security. You need people who can: - Understand the technology well enough to spot nonsense. - Understand the regulatory landscape well enough to know when to pick up the phone to legal. - Navigate organisational politics well enough to get things done. This is partly why I’ve been building courses on [data governance](https://www.unsw.edu.au/study/professional-development/course/data-governance-for-leaders?ref=katecarruthers.com) and [AI for organisational innovation](https://www.unsw.edu.au/study/professional-development/course/ai-for-organisational-innovation?ref=katecarruthers.com) – we need to equip leaders with practical tools, not just scare them with horror stories. AI governance will not succeed if it is seen solely as a compliance burden; it has to be framed as enabling safe innovation. And yes, a lot of this work is boring: cataloguing data, mapping processes, writing down decisions, chasing up approvals. But boring is where resilience lives. ## Where to start If all of this feels overwhelming, here’s a simple way to begin: 1. **Take stock** of where AI is already in your organisation – formally and informally. 2. Make sure your **data governance basics** are in place; revisit those five questions. 3. **Identify** a small number of high‑impact AI use cases and run them through a lightweight governance process as a pilot. 4. **Use the lessons** from that pilot to refine your policies, roles, and workflows. 5. **Educate your leaders and teams** continuously; this space is not going to stand still. **Effective AI governance is not a one‑off project. It’s an ongoing capability, built on the unglamorous disciplines of data governance, cyber security, risk management, and sensible leadership.** If we get that right, we can spend less time reacting to crises and more time using AI to actually create value. ### Data Governance needs a rebrand URL: https://katecarruthers.com/data-governance-needs-a-rebrand/ Last updated: 2026-04-01T06:12:55.000Z I have long thought that data governance has a brand problem. Inside many organizations it still sounds like control, cost, and constraint, not value. Even when the underlying work is critical, the label “data governance” often lands with executives as bureaucracy: steering committees, policies, and standards that slow things down. That branding issue is now existential. As AI scales across the enterprise, CDOs cannot afford for governance to be parked in the “necessary evil” bucket. It needs to be clearly positioned as a driver of innovation and as the primary mechanism for managing data and AI risk. To get there, we have to change the story we tell. ## From cost center to innovation engine Most executives do not wake up wanting “better data governance.” They want new revenue, more efficient operations, better customer experience, and safe, effective AI. The work of governance only becomes interesting when it is clearly and directly connected to those outcomes. Reframing governance around **data innovation** means positioning it as the way we make high‑quality, well‑documented data quickly usable for experimentation and delivery. Instead of leading with policies, we lead with enablement: - Curated, trusted data products that can be reused across use cases, not bespoke pipelines for every project. - Clear metadata, lineage, and definitions so teams can rapidly understand and safely consume data. - Embedded standards for quality, privacy, and security that reduce rework and lift time‑to‑value for new analytics and AI. In this framing, governance becomes the operating model that lets product teams and data scientists move faster with less friction. It is the foundation that allows you to industrialize AI rather than run a series of fragile pilots. When executives see that governance reduces cycle time and increases reuse, the conversation shifts from “how much will this cost?” to “how quickly can we scale this?” A practical way to make this real is to tie governance initiatives to flagship innovation programs. If your organization is driving an AI roadmap, a customer 360, or a major digital transformation, the governance narrative should be explicitly positioned as: “Here is the minimum set of capabilities we need in place so these initiatives land safely and can be scaled.” That keeps the branding anchored in visible business change, not abstract control. ## Governance as data risk management The second front for rebranding is **data risk**. Boards and executive teams increasingly understand cyber risk, but data and AI risk are often less clearly articulated. This is a gap CDOs are uniquely placed to fill. Rather than treating data governance as an internal housekeeping function, position it as the enterprise’s primary data risk management framework. That means being explicit about the categories of risk that governance addresses: - Misuse of data (privacy breaches, unethical use, unauthorized sharing). - Poor‑quality or misaligned data driving bad decisions or model outcomes. - Uncontrolled AI models that are opaque, biased, or not aligned to policy. - Regulatory non‑compliance across privacy, AI, sector‑specific, and prudential regimes. When governance is framed as the structured way the organization identifies, assesses, and mitigates these risks, it becomes directly relevant to risk committees, audit, and the board. Language matters here. Terms like “data risk appetite,” “control environment,” and “assurance over critical data assets and AI systems” resonate more strongly than “governance operating model” alone. This also requires clarity about ownership and decision rights. Executives need to see a simple, coherent picture of who is accountable for what: - Business data owners who are accountable for the risk and value of their data domains. - CDO and data office accountable for the framework, standards, and oversight. - Model owners who are accountable for AI risk controls and monitoring across the lifecycle. When this is articulated as a risk management discipline, it integrates naturally into existing enterprise risk frameworks, rather than sitting as an isolated data initiative. ## Changing the narrative with executives If we agree data governance has a brand problem, then CDOs have to become intentional brand custodians. That starts with language. In executive and board forums, we need to lead with innovation and risk outcomes rather than governance mechanics. For example: - “We are putting in place the data risk controls that will allow us to safely deploy generative AI at scale.” - “We’re building the data product foundations that let us stand up new AI use cases in weeks, not months.” The supporting details about policies, standards, committees, and tooling are still essential—but they become the “how,” not the opening pitch. Measurement also matters. If governance is always reported as activity (number of glossaries, policies, councils), it will always look like overhead. If, instead, you report: - Reduction in time to access and use trusted data for priority use cases. - Reduction in incidents, rework, or regulatory findings related to data and AI. - Increased reuse of certified data products across multiple initiatives. then governance is visibly contributing to strategic goals. You are no longer asking executives to “fund governance”; you are demonstrating how governance underpins the capabilities they care about. ## From afterthought to strategic discipline Ultimately, the brand of data governance will determine where it sits in the hierarchy of organizational priorities. If it continues to be perceived as compliance plumbing, it will be underfunded, understaffed, and perpetually playing catch‑up. In an AI‑driven enterprise, that is not a sustainable position. By deliberately rebranding governance on two fronts - enabling data innovation and managing data and AI risk - CDOs can reposition it as a strategic discipline. It becomes the way the organization both accelerates the use of data and AI and protects itself from the downside. That is a story executives are far more willing to invest in. The work of governance has not changed as much as our language and framing need to. But if we get the branding right, we give that work the visibility, sponsorship, and resourcing it needs to actually deliver on its promise. ### Reinventing Higher Education in the Age of AI URL: https://katecarruthers.com/reinventing-higher-education-in-the-age-of-ai/ Last updated: 2026-06-25T23:53:00.000Z In this episode, [Jason La Greca](https://www.teachnology.au/about?ref=katecarruthers.com) and [Kate Carruthers](https://katecarruthers.com/) explore how AI is transforming universities, research, and learning methodologies. Kate and Jason discuss about the evolving landscape of higher education in the context of AI and data. They discuss the challenges universities face in meeting the needs of employers and students, the importance of transdisciplinary learning, and the role of research in driving innovation. The conversation also touches on the impact of AI on workflows, the future of assessment in education, and the need for organizations to regain their capabilities in-house. Jason shares insights from his upcoming book, 'The Capable Organization,' which addresses these themes and offers practical steps for educators and institutions. ##### Key takeaways - The disconnect between university curricula and employer/industry needs - The importance of university roots in Socratic dialogue and interdisciplinary exposure - How AI can enhance research data utilization and open access - Structural challenges within higher education, including governance and outdated systems - The potential of agent-based AI and automation to streamline organizational processes - Redefining assessment to focus on judgment, decision-making, and behavior over content - Moving from a content-focused model to experiential, human-centered education - The impact of COVID-19 in accelerating digital transformation and online teaching - Strategies for universities to develop core human skills: judgment, judgment, and entrepreneurship - The role of transdisciplinary programs and diverse experience in future-proofing students - Practical steps for organizations and institutions to adopt AI responsibly and effectively ##### Resources & Links: - [The Capable Organization](https://thecapableorganisation.com/?ref=katecarruthers.com) - [Claude - AI Language Model](https://www.anthropic.com/index.html?ref=katecarruthers.com) - [Microsoft 365 Copilot](https://www.microsoft.com/en-us/microsoft-365/copilot?ref=katecarruthers.com) - [UTS Transdisciplinary School](https://www.uts.edu.au/about/faculties/transdisciplinary-school?ref=katecarruthers.com) - Find Jason at [https://www.teachnology.global](https://www.teachnology.global/?ref=katecarruthers.com) ### Microsoft's AI Evolution: From Office Tools to AI Copilots URL: https://katecarruthers.com/microsofts-ai-evolution-from-office-tools-to-ai-copilots/ Last updated: 2026-06-25T23:55:18.000Z In this episode of the Data Revolution podcast, [Kate Carruthers](https://katecarruthers.com/) outlines how Microsoft has evolved from a traditional enterprise and consumer software company into a major player in AI and AI infrastructure. She looks at the role of strategic partnerships, including its work with OpenAI, and how a greater focus on open source has shifted its position in the tech ecosystem. The discussion also covers how AI copilots are being used across the various Microsoft platforms, and what this means for governance and competition in the AI market going forward. ## Key takeaways - Microsoft's AI strategy involves embedding its AI copilots across its product suite - which gives it a significant strategic advantage over competitors - This strategy of integration of AI into everyday tools enhances productivity and user experience - Microsoft's partnership with OpenAI accelerated its AI capabilities - AI governance and innovation policy are crucial for managing AI's impact - Open-source communities continue to play a central role in AI development and deployment - Microsoft's shift from a solely proprietary to a focus on open source has transformed its business model - The concentration of power in AI infrastructure raises governance challenges - AI is becoming an integral part of organisational workflows and Microsoft is poised to take advantage of this trend - Microsoft's AI evolution is a useful case study in strategic transformation - The future of AI involves balancing innovation with ethical considerations ### Life with ADHD: Time blindness, or why I lose hours, not just my keys URL: https://katecarruthers.com/life-with-adhd-time-blindness-or-why-i-lose-hours-not-just-my-keys/ Last updated: 2026-04-01T03:51:18.000Z Time has always felt a bit … theoretical to me. People talk about “ten minutes” or “next week” as if these are solid, tangible things you can hold in your hand and stack neatly in a calendar. For those of us with ADHD, time is usually either “now” or “not now” – and everything in the “not now” bucket has a nasty habit of ambushing us later. This slippery relationship with time is often called **time** blindness. It’s not a moral failing, laziness, or a lack of care. It’s a very real way that ADHD brains experience (or don’t experience) the passing of time. ## What time blindness feels like For me, time blindness shows up in a bunch of really mundane, annoying ways. I cannot tell how much time has passed; time feels both endless and elastic all at once. - Sitting down to “quickly” reply to an email and resurfacing 90 minutes later with three tabs of research open and no lunch. - Stopping to have a quick chat with someone and not realising my next meeting is now half over. - Underestimating how long anything will take: travel, getting ready, writing, even “just jumping on a call”. - Feeling genuinely shocked when I’m late, because in my head I started early and was “on time” right up until reality intervened. The internal sense of time that other people seem to rely on – that quiet background awareness of “you’ve been doing this for 20 minutes, you should wrap up” – is either very quiet or completely missing. ADHD time is punctuated: hyperfocus, distraction, scramble, repeat. ## It’s not about caring less One of the most corrosive myths about ADHD and time is that we simply don’t care enough to be on time, to remember deadlines, or to respect other people’s schedules. In practice, many of us care a lot. Sometimes too much. - There’s the shame spiral when you miss something important (again). - The overcompensation: arriving comically early to avoid the anxiety of being late, or being transfixed by the one thing you have to do at 11.30am so you cannot do anything else. - The mental load of constantly second-guessing whether you’ve forgotten something. Time blindness is about how the brain processes time and priorities, not how much you value other people or your commitments. Executive function – planning, sequencing, estimating, shifting gear between tasks – is doing a lot of heavy lifting here, and ADHD means that system is unreliable at best. ## How time blindness shows up at work In knowledge work, especially in tech and data, we’ve built entire cultures around calendars, deadlines, and “quick” tasks that are rarely quick at all, with lots of context switching. ADHD time blindness bangs into this, hard. Some greatest hits: - “This will only take half an hour” optimism that turns into a multi-hour rabbit hole. - Blocking time for “deep work” and then misjudging when to start, so the block evaporates between meetings. - Struggling with context switching, because every switch resets your internal clock (which is unreliable at best). Ironically, the same brain that loses an afternoon to hyperfocus on a problem can then completely misjudge how long it will take to write a two-paragraph email. Estimation becomes a gamble, not a skill. ## Tools that help (a bit) Because time is so abstract, anything that externalises it can help make it more real. Some things that have actually helped me: - **Visible & audible timers**: Countdown timers for tasks, not just tiny numbers in the corner of a screen, but huge alarms and noise. - **Alarms with intent**: Multiple alarms with labels like “leave the house” or “stop writing and send the damn email”. - **Overestimating by default**: If my brain says “30 minutes”, I double it. If it says “no problem”, I get suspicious. None of this “fixes” time blindness, but it does build scaffolding around it. It’s less about forcing the brain to behave and more about accepting how it works, then designing around that. ## Designing kinder systems The usual productivity advice – just plan better, prioritise, use a calendar – often assumes a neurotypical sense of time. For ADHD brains, the systems themselves need to be different. Some shifts that make a real difference: - Shorter planning horizons: Today and this week, not the next quarter in exquisite detail. - Chunking tasks: Breaking work into much smaller, more concrete actions with clear “start” and “stop” points. - Generous margins: Building slack into the day, not scheduling every minute like a Tetris game. At an organisational level, this is also an inclusion issue. If your culture depends on perfect time estimation, back-to-back meetings, and instant context switching, you’re quietly excluding people whose brains don’t work that way – and not just those with formal ADHD diagnoses. ## Being honest about it The hardest part of time blindness for many of us isn’t the logistics; it’s the shame. The stories we tell ourselves about what it means to be the person who is “always late”, who “never finishes on time”, who “can’t just get it together”. Naming time blindness as part of ADHD – not as a personal flaw – creates just enough space to try different approaches without the constant self-critique. It also opens the door to better conversations with colleagues, friends, and family about what support actually looks like. Some days that might mean letting people know you need a reminder before a meeting. One thing I often do is say to someone who wants to meet with me "please send me a calendar invite" so I do not forget to send one. Other days it might mean being upfront that “I’ll get that to you later today” is more realistic than “I’ll do it right now”. Time blindness won’t disappear with the right app or the perfect planner. If I had only invested every dollar that I have spent on new planners over the years I would probably be a multi-squillionaire by now! But with a bit of self-knowledge, a few external supports, and a more honest conversation about how different brains relate to time, it becomes something you can work with rather than constantly fight against. ### Agentic AI: How Voice-Driven Agents Are Changing the Way We Use Apps URL: https://katecarruthers.com/ai-user-interface-future/ Last updated: 2026-04-01T03:51:18.000Z I spoke at the [Front End of Innovation (FEI) Conference](https://informaconnect.com/feiusa/?ref=katecarruthers.com) in Boston back in June 2024 about AI, innovation and the future. I have been thinking a lot about this topic in the time since 2024 and now in early 2026. The future direction of Artificial Intelligence is not just about AI in and of itself, it is about different kinds of AI plus some other new technologies (such as Agentic AI and the Internet of Things) that are going to change everything. As I mentioned in my previous articles, [AI Changes Everything](https://katecarruthers6748.live-website.com/2024/06/14/ai-changes-everything/?ref=katecarruthers.com) and [AI and autonomous everything](https://katecarruthers6748.live-website.com/2024/06/16/ai-autonomous-everything/?ref=katecarruthers.com), AI will have far-reaching long-term impacts on every facet of life over the long term. A key way that AI will change things, especially Generative AI (Gen AI) and Conversational AI, will be by rearchitecting the entire user interface as we have known it. At present the way that we build front end applications - the way that users interact with our systems - is for developers to manually construct application interfaces for humans. We have done it this way since the earliest days of computing. But this is all about to change. ## About AI Now However, before I explore what this all means we need to dig in a bit and understand what AI really is. AI is not just one thing; it is a bunch of different technologies that sit together under the banner of AI. The key types of AI that are in use today include: - **Machine Learning**: subset of AI that enables machines to learn from existing data and improve upon that data to make decisions or predictions - **Natural Language Processing**: Natural language processing (NLP) is the ability of a computer program to understand human language as it's spoken and written - referred to as natural language. - **Deep Learning**: a machine learning technique in which layers of neural networks are used to process data and make decisions - **Generative AI & Large Language Models**: create new written, visual, video, and auditory content given prompts or existing data - **Agentic AI**: where autonomous AI agents can reason, plan, and take actions to achieve goals with minimal human supervision ## The Front End The notion of standard input and standard output dates back to the earliest days of computing. It is the most fundamental way in which a human communicates with a machine. The main way that we have communicated with machines up until now is by way of a keyboard. With our mobile phones (Siri for my iPhone) and other devices like [Amazon Alexa](https://alexa.amazon.com/?ref=katecarruthers.com) and [Google Assistant](https://assistant.google.com/?ref=katecarruthers.com) they started providing standard input via voice inputs. But one thing each of these devices and their personas is that they are very stupid. They do not understand stuff we say. They are not able to daisy chain commands. In essence they are irritatingly incompetent. But with the arrival of Gen AI this is all about to change in major ways. This is the beginning of what I call the [Star Trek](https://www.reddit.com/r/DaystromInstitute/comments/jbz9j4/the%5Fevolution%5Fof%5Fcomputer%5Farchitecture%5Fin%5Fstar/?ref=katecarruthers.com) era of computing. ## Talking to Machines: How Our Relationship with Apps Is Changing Lately, there has been a subtle but profound shift in how people interact with technology: less typing and more talking to AI systems using natural speech. For many everyday tasks, speaking to an AI agent now feels more intuitive than navigating traditional menus and forms. ## From Commands to Conversation For decades, software demanded that users learn its grammar through clicks, fields, and rigid commands. Today, modern AI agents can interpret intent, context, and nuance, which allows people to speak in half-finished thoughts and still receive useful outcomes. ## Living with an AI Assistant Using voice to work with digital systems changes how knowledge work and daily tasks feel, because interacting with an AI can resemble collaborating with a colleague rather than operating a tool. People can request summaries, research support, or scheduling help in conversational language while the agent handles the underlying complexity across multiple applications. ## A More Human Way to Compute Speech is faster and more expressive than typing for many people, which makes voice interaction feel closer to thinking out loud than filling out a form. At the same time, the rise of voice-led agents raises governance questions about data, accountability, and appropriate boundaries for automation that acts on a user’s behalf. ## Looking Ahead Designers and technologists are increasingly talking about a “voice-first” or “post-app” world, where a conversational layer sits on top of many systems and becomes the primary interface. Typing is unlikely to vanish, but for a growing set of interactions it will sit behind more natural, multimodal conversations that treat speech as the default input. I am going to be discussing this and more over on my [Data Revolution Podcast](https://datarevolution.tech/?ref=katecarruthers.com) \- please check it out. ### From DeepMind to Transformers: Google's AI Impact URL: https://katecarruthers.com/deepmind-transformers-google-ai/ Last updated: 2026-06-25T23:53:51.000Z In this episode of the Data Revolution podcast, host [Kate Carruthers](https://katecarruthers.com/) gives an overview of the transformative journey of AI, focusing on Google's pivotal role. From the open-source release of TensorFlow to the groundbreaking AlphaGo, and the development of the transformer architecture, Google's contributions have significantly shaped AI's landscape. The episode also explores Google's strategic acquisitions, like DeepMind, and their impact on AI research and development. Carruthers also highlights the challenges and opportunities AI presents, emphasising the need for responsible governance as AI becomes increasingly integrated into everyday life. #### Takeaways - AI is both exciting and terrifying, with notable upsides and downsides. - Google has been a major player in AI's growth, from TensorFlow to AlphaGo. - The transformer architecture is a key development in modern AI. - Google's acquisition of DeepMind was a strategic move in AI research. - AI's integration into daily life requires responsible governance. - Google's AI principles emphasise social benefits and accountability. - AI is transforming scientific discovery and medical research. - The next decade will see AI moving from demos to infrastructure. - AI presents new risks and governance challenges. - Boards and policymakers must navigate AI's integration carefully. ### After 10 Years as a CDO: What I’ve learned about excellent jobs URL: https://katecarruthers.com/excellent-jobs/ Last updated: 2026-04-01T10:39:43.000Z Back in late 2024, after a decade as Chief Data and Insights Officer at [UNSW Sydney](https://www.unsw.edu.au/?ref=katecarruthers.com), and more than a decade working at UNSW, I decided it was time to leave. It was a big step. It was scary to leave the comfort of a role and place I'd come to know intimately. I’d invested a lot of myself in the role, in the university, and in the networks of relationships I was lucky enough to build. But ten years is a long time in one role, and it felt like the right moment for a change. So, I took my long service leave, decompressed, and contemplated what was next. I am currently on my Xmas vacation in early 2026, and this period of reflection has had me thinking about what makes a job not just good, but excellent. It’s more than just the title or the salary; it’s about the texture of the work and the environment you do it in. ## Note about privilege It’s important to say here that I know being able to choose a job based on these criteria is a privilege. For many people, work is about survival, and the primary concern is a secure job that pays regularly. My reflections aren’t intended to dismiss that reality, but rather to think about what we should be striving for when we do have the choice, and what leaders should be trying to build for their teams. Creating environments with a clear mission, good people, and a degree of trust isn’t just for senior executives; it’s the hallmark of a decent workplace for everyone ## Here’s what I’ve come up with so far. First, and most fundamentally, it’s about working for an organisation with a **mission and values** that I can resonate with. Life is too short to pour your energy into something you don’t believe in. You need to feel that your work is contributing to something worthwhile, whether that’s educating the next generation, solving a tricky social problem, or building something genuinely useful. ## People Then, the very next thing is the **people**. What made my last decade bearable, and often joyful, were the colleagues who generously shared their expertise, the collaborators who were up for trying odd ideas, and the people who showed up with perspective when it was all a bit much. An excellent job is one where you are surrounded by smart, kind people who operate in good faith. It’s an environment of psychological safety where you can debate, disagree, and still respect each other. You need a team that has your back, and for whom you’d do the same. ## A good boss And a critical part of the ‘people’ equation is your direct boss. **A good boss is a force multiplier**. They don’t just manage; they act as an umbrella, protecting the team from the inevitable bureaucratic nonsense and creating the space for you to do your best work. They advocate for you, they remove roadblocks, and they have your back when things get tricky. They provide air cover. A great boss invests in your growth, gives you honest feedback, and trusts you enough to let you take on challenges that stretch you. It’s a relationship built on mutual respect and a shared understanding of the mission. ## Autonomy and trust Next, it’s about the **autonomy and trust** to do the work. An excellent job requires leadership that trusts you to get on with it. It’s about having the space to experiment, to nudge systems in slightly better directions, and to tackle hard problems without being micromanaged. This doesn’t mean working in a vacuum; it means having leaders who provide clear direction and support, but who empower their teams to find the best way forward. ## Meaningful impact and continuous learning Finally, it has to be about **meaningful impact and continuous learning**. The work itself must be interesting. It needs to be a role where you’re not just pushing paper, but are genuinely doing useful things - with data, with technology, and most of all with people. It should be a place where you’re constantly learning, where you’re challenged by hard questions, and where you have the opportunity to leave things better than you found them. So, as I look towards what’s on the horizon, these are the things I’m holding in mind. It’s not a simple checklist, but a sense of the conditions needed for work to feel like a valuable part of a well-lived life. ### Life with ADHD: The Hidden Cognitive Load Behind “Losing Things” URL: https://katecarruthers.com/life-with-adhd-the-hidden-cognitive-load-behind-losing-things/ Last updated: 2026-04-01T03:51:19.000Z One of the more "amusing" things about having ADHD for me is that I lose things. Not usually irrevocably, but they disappear for long periods and then mysteriously reappear. A while back I lost my bottle of [Vyvanse](https://www.healthdirect.gov.au/medicines/brand/amt,143261000036104/vyvanse?ref=katecarruthers.com) tablets and I could not find them anywhere. Then while I was away on vacation over Christmas I found them again. And I thought to myself "I will not forget where they are this time". But I did and they have been lost again for the past few weeks. I just found them again, and they have now been (hopefully) placed in a sensible location. *But I am telling this story about my forgetfulness to illustrate one of the unseen ways that ADHD adds extra cognitive load for folks.* Losing and re-finding the same Vyvanse bottle over weeks is funny on the surface, but it is also a quiet example of the **extra** cognitive load that ADHD demands every single day. ## The story behind the joke A few months ago, my Vyvanse went missing. Not stolen, not used, just… gone. I turned the house upside down, checked all the “sensible” spots twice, and eventually gave up. While I was away over Christmas, it suddenly reappeared in a place that must have seemed perfectly logical at the time. It vanished again. Today I found it for the second time and have now placed it in what I am once again convinced is a sensible location. The punchline is not that I am irresponsible; it is that this is normal for many people with ADHD, especially when working memory and attention are inconsistent. ## What “extra cognitive load” looks like On paper, this is a trivial problem: just remember where you put the medication. In practice, ADHD turns that into a multi-step mental overhead: - Constantly tracking “Where did I put that?” because the brain does not reliably hold those small details in working memory. - Regular search-and-rescue missions for objects that are “out of sight, out of mind,” a pattern sometimes described in ADHD circles as an *object permanence issue*. - The emotional load that comes with it: frustration, self-criticism, and the low-level anxiety of knowing that at any moment some important thing may drop out of awareness. All of this happens before any “real” work has even started. The brain is already partially spent on backstage logistics that others barely notice. ## The invisible tax of everyday tasks Misplacing a Vyvanse bottle is a neat metaphor for the broader **ADHD taxes**: - **Time tax**: repeated searches, re-doing tasks, rewriting lists, backtracking through the day to reconstruct what happened. - **Planning tax**: building elaborate systems, reminders, and backup plans just to approximate the reliability that neurotypical brains get by default. - **Shame tax**: quietly worrying that others see this as laziness or carelessness, when it is actually about executive function, not character. By the time a person with ADHD sits down to “start the day,” they may already have done an hour of invisible work purely to compensate for these gaps. ## Why naming it matters Framing this as *extra cognitive load* is important for two reasons. First, it validates the experience. Losing things, forgetting appointments, or repeatedly rediscovering the same medication bottle is not a moral failing; it is a predictable outcome of how ADHD affects attention, working memory, and executive function. Second, it makes the accommodations make sense. Externalising memory with pill organisers, visual cues, automation, and routines is not overkill; it is infrastructure that reduces the constant drain on mental bandwidth So yes, the saga of the wandering Vyvanse bottle makes for an amusing story. But behind the joke is a quiet truth: living with ADHD often means running the same life as everyone else, just with several dozen extra tabs open in the background and consuming cognitive resources, all the time. ### 2026 Bingo Card URL: https://katecarruthers.com/2026-bingo-card/ Last updated: 2026-04-01T03:51:19.000Z As is my tradition I do my annual bingo card at the start of the new year to deal with my existential dread. Herewith my 2026 bingo card. I’ll be doing a wrap up on my 2025 BingoCard shortly. ![](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/04/img_1185-jpeg.jpg) ### AI, Cybersecurity and Sovereignty: Technology & Security Podcast URL: https://katecarruthers.com/ai-cybersecurity-podcast/ Last updated: 2026-04-01T03:51:19.000Z Was on the [Technology & Security Podcast](https://miahhe.com/?ref=katecarruthers.com) with the smart and lovely [Miah Hammond-Errey](https://miahhe.com/about?ref=katecarruthers.com) just before Christmas 2024 - have been meaning to share the link. Miah and I had a great chat where we traced my path from defending shopping centre digital systems against cyber threats to building higher education enterprise AI, data and security capabilities. I did mention (again) that many organisations will be better served by smaller, domain-specific AI models rather than huge resource-intensive frontier systems. We also explored how boardrooms are shifting from basic cyber awareness to deeper engagement with AI risk, and highlighted the need for diverse, product-focused teams who can turn technical systems into practical processes. On security, I did highlight data integrity, warning about AI poisoning risks in critical systems, and called for Australian AI sovereignty through open-source and reduced dependence on foreign cloud and security providers. And, as I often do, I urged leaders to get hands-on with AI and start using AI tools directly, so that they can understand their probabilistic nature, and anchor deployments in clear problems, ethics and user needs. [Check it out!](https://www.youtube.com/watch?v=qVJMSk5B6Gc&ref=katecarruthers.com) ### Colonialism, Convicts and Country: How the British Empire shaped my Australian Story URL: https://katecarruthers.com/colonialism-convicts-country/ Last updated: 2026-04-01T03:51:19.000Z Colonialism came to mind as I was listening to Dan Snow’s recent [History Hit episode](https://podcasts.apple.com/au/podcast/dan-snows-history-hit/id1042631089?i=1000741979390&ref=katecarruthers.com) with author [Sathnam Sanghera](https://www.sathnam.com/?ref=katecarruthers.com) about how the British Empire is responsible for much of the modern world: > “Tobacco, sugar, rum, cotton, rubber, tea, coffee, spices, industry, borders, slavery, war - all things spread across the globe thanks to the British Empire. At its height in 1922, it was the largest empire the world had ever seen, covering around a quarter of Earth's land surface and ruling over 458 million people- that's a lot of influence. Dan is joined by journalist and author Sathnam Sanghera to measure the impact the British Empire has had on our world, for better and worse.“ They jokingly mention how the British are responsible for most of the modern conflicts due to people who didn’t understand or care about the regions drawing random lines on maps. This made me reflect on my own origins. I was born in Australia. My family has been here for a very long time (but not as long as many [Indigneous folks](https://www.aboriginalheritage.org/history/history/?ref=katecarruthers.com)). And it is all 'thanks' to the British. I say thanks to the British somewhat ironically because I’m pretty sure my ancestors would’ve preferred not to come to Australia. One of my ancestors was not even a British national and yet he and his six compatriots were sentenced by the British as pirates and condemned to life in New South Wales. Some of my ancestors were sentenced to life in New South Wales due to stealing small items (but I expect they felt it was a better option than being hanged). Some of my ancestors came to Australia on ships fleeing the British induced famine in Ireland. But all of them coming was due to empire and colonialism. My [Greek ancestor](https://katecarruthers.com/whats-in-a-name-pirate-freedom-fighter-or-terrorist/) who was sentenced for piracy to life in New South Wales and arrived on a ship in 1829, was pardoned in 1837 and he went back to his home place of Hydra in Greece. A few years later two of his sons came back here to settle. There must’ve been something in the stories he told them that made them think that Australia was a good place to settle in spite of the hardships that their father would have suffered as a convict. I consider my lot in life to be a happy one to have been born in such a country as modern Australia. But there is no doubt that my current happy life here in Australia has been built on the suffering of the Indigenous peoples, and the suffering of the convicts who built this country. Life in contemporary Australia offers extraordinary comforts, such as access to healthcare and education, relative political stability, and the everyday freedoms that come with living in a wealthy, peaceful nation. Yet those comforts did not emerge in a vacuum - they rest on foundations laid by invasion, dispossession, and coerced labour. The land that enables this good life was taken from Indigenous peoples whose sovereignty has never been ceded, whose cultures were [attacked](https://c21ch.newcastle.edu.au/colonialmassacres/map.php?ref=katecarruthers.com), and whose communities still live with the consequences of policies designed to remove, assimilate, and erase. At the same time, much of the early physical and economic infrastructure of the colony was built on the backs of convicts who endured brutal punishment, forced labour, and profound separation from home and family. For me holding that knowledge means accepting that personal good fortune is entangled with other people’s suffering, both historical and ongoing. It invites a more honest gratitude, and one that recognises unearned advantages, honours those who bore the costs, and asks what responsibilities flow from benefiting from a system shaped by colonial violence and exploitation. Colonialism is often discussed in the abstract, but for me it lives in my family tree and the ground upon which I stand. The British Empire brought my ancestors here through punishment, desperation, and chance, and I have inherited both the privileges of modern Australia and the shadows of our history. Sitting with this, for me, means holding gratitude for the life I have, alongside sorrow for the suffering that built it, and a responsibility to acknowledge the ongoing impacts of invasion and dispossession on Aboriginal and Torres Strait Islander peoples. Recognising that complexity feels like the smallest first step towards a more honest conversation about who we are, how we got here, and what we owe each other now. ### Unlocking the potential of AI with Leonie Valentine URL: https://katecarruthers.com/unlocking-the-potential-of-ai-with-leonie-valentine/ Last updated: 2026-06-25T23:54:27.000Z Join [Kate Carruthers](https://katecarruthers.com/about-kate-carruthers/) on the Data Revolution podcast as she discusses the transformative power of AI in business with the amazing [Leonie Valentine](https://au.linkedin.com/in/leonievalentine?ref=katecarruthers.com). Discover how understanding real-world problems is key to leveraging AI effectively, and explore the ethical considerations that come with this technology. ### 2025 Reflection: Why community and kindness matter more than ever URL: https://katecarruthers.com/2025-reflection-why-community-and-kindness-matter-more-than-ever/ Last updated: 2026-04-01T03:51:19.000Z As I contemplate 2025 while sitting in the shade in the tropics 🏝️ on vacation, I realise how precious are the networks of relationships and friendships I have been lucky enough to accumulate. These are the many people who’ve helped me along the way, and whom I have also tried to help. With the various tragedies around the world and in our own city, it helps to remember that solidarity, small acts of kindness, and showing up for each other still matter. This year has been a strange mix of grief, anger, bureaucratic absurdity, and unexpected joy. There were moments when the news felt unrelenting, and yet the day-to-day work of doing useful things with data and AI, building communities, and nudging systems in slightly better directions kept trundling on. What made it bearable, and occasionally delightful, were the people: colleagues who generously shared their expertise, students and participants who asked the hard questions, collaborators who were up for trying odd ideas, and friends who supplied memes, drinks, cheese, and perspective when it was all a bit much. So as this year winds down, please take this as a simple thank you. Thank you for reading, listening, debating, disagreeing in good faith, sending links, turning up to talks, inviting me into your projects, or just quietly cheering from the sidelines. It all helps more than you probably realise. Here’s hoping 2026 brings more justice than we have seen in many places during 2025, more good works than empty rhetoric, and more time for conversations that actually change things (and the occasional silly BingoCard to mark the existential dread). Wishing you rest, health, and moments of unexpected joy in the months ahead. ### AI Innovation: Why leadership matters more than technology URL: https://katecarruthers.com/ai-innovation-poc-to-production/ Last updated: 2026-05-12T04:29:02.000Z In the history of business, technology has always been the driver of change, from stone tools to the internet. Artificial Intelligence (AI) is simply the most recent, and arguably among the most powerful, addition to this long line of technologies. However, like every revolutionary technology that came before it, its true value isn't inherent in the tool itself, but in how we choose to wield it. The core imperative for leaders today is to move past the initial fascination and focus on the disciplined work of understanding, governing, and implementing AI safely and effectively within their organisations. It was a productive week recently, being back at the Australian Graduate School of Management (AGSM) at UNSW Business School in Sydney. I was pleased to be back facilitating my executive short course, [AI for Organisational Innovation](https://www.unsw.edu.au/study/professional-development/course/ai-for-organisational-innovation?ref=katecarruthers.com), along with co-facilitating (with [Gladwin Mendez](https://www.linkedin.com/in/gladwinmendez/?originalSubdomain=au&ref=katecarruthers.com)) the last day of the new [Building an AI Strategy](https://www.unsw.edu.au/study/professional-development/course/building-an-ai-strategy?ref=katecarruthers.com) short course, led by old friend [Nicola Dorling](https://www.linkedin.com/in/nicola-dorling-gaicd-19a76934/?originalSubdomain=au&ref=katecarruthers.com). The level of engagement from the attending leaders was highly focused and constructive. It is reassuring to see executives and senior managers actively dedicating time to understand the profound implications of AI, not just as a peripheral trend, but as a core requirement for contemporary leadership and innovation within their organisations. It is rewarding to engage with such a thoughtful cohort of leaders. Their willingness to tackle these complex, strategic challenges head-on is an encouraging sign for the future of business leadership in Australia. ##### Getting AI from Proof-of-Concept to Production In the course, the focus was squarely on the practicalities of deployment and scale, and how to deliver business results using AI. The challenge for many organisations is moving beyond isolated proofs-of-concept and achieving systemic transformation. To address this gap, I presented my framework for moving AI initiatives successfully from proof of concept to robust production environments. ![PoC to Prod pipeline ](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/04/poc-to-prod-pipeline.jpg) This PoC to Production pipeline is an essential way to think about developing new AI capabilities and getting them from a proof-of-concept through to production. In thinking about the foundational requirements for successful AI adoption, I always stress the need for AI ethical frameworks, data governance including data quality. As I consistently highlight, trustworthy data is the essential prerequisite for reliable AI systems. Another thing I covered is frameworks for identifying high-impact operational areas and discussed how to securely embed AI models, including emerging agentic AI, to drive both efficiency gains and the creation of entirely new forms of business value. This practice needs to be grounded in moving from theoretical knowledge to actionable, disciplined implementation. #### Old tools for the new world There were some interesting older tools I used during this course. A number of these old tools from business school dated from the 1980s or 1990s such as [Christensen‘s jobs to be done](https://www.christenseninstitute.org/theory/jobs-to-be-done/?ref=katecarruthers.com), the [Hackman Authority Matrix](http://psycnet.apa.org/record/1986-97965-003?ref=katecarruthers.com), and the [value proposition canvas](https://www.strategyzer.com/library/the-value-proposition-canvas?ref=katecarruthers.com). These tools still offer great ways of thinking about business problems, even in the age of AI. I am a huge fan of things that you can draw on a whiteboard in a meeting room to facilitate discussion and thinking about key issues that need to be considered. And each of these old tools does just that. ##### [Jobs to be done](https://www.christenseninstitute.org/theory/jobs-to-be-done/?ref=katecarruthers.com) This venerable concept is one of my favourites, by Clayton Christensen it helps us to understand what is the job the customer wants help with. An essential thing to understand when embarking on your innovation journey. ##### [Hackman Authority Matrix](https://www.agile-academy.com/en/agile-dictionary/hackman-authority-matrix/?ref=katecarruthers.com) This is great tool for thinking about power structures in your organisation. Once you understand these it can really help your innovation journey. ##### [Value Proposition Canvas](https://www.strategyzer.com/library/the-value-proposition-canvas?ref=katecarruthers.com) I love this simple one page canvas - similar to the business model canvas - as a way of focusing groups in on looking at problems from the customer perspective. ## Innovation is not new, we’re just using new tools Innovation isn’t new; we’ve just swapped out the tools. Humans have always been innovators, from the printing press to the internet. What’s different now isn’t the urge to innovate, but the scale and speed of it. AI, data, and automation are just the latest additions to an ancient habit: solving problems in smarter ways. The real challenge isn’t adopting the shiny new tech, it’s remembering that the tools have changed but the very human fundamentals of curiosity, experimentation, and adaptation haven’t. ## Leadership matters Leadership matters more than ever. AI is a great technology that offers the promise of great things. It also has the same downsides of every other technology - it can be used for evil too. We have agency in how we use this technology. Think about it and think about the risks as well as the benefits of using AI, use the power of AI for good and not evil. And beware of the unintended consequences of using AI. ### AI and Capability Uplift: Navigating the Future of Work URL: https://katecarruthers.com/ai-and-capability-uplift-navigating-the-future-of-work/ Last updated: 2026-06-28T05:13:37.000Z Join [‪](https://www.youtube.com/@KateCarruthers?ref=katecarruthers.com)[Kate Carruthers](https://katecarruthers.com/) on the Data Revolution podcast as we welcome back [Gladwin Mendez](https://www.gecprudentia.com/?ref=katecarruthers.com) for an insightful discussion on the future of AI and data capability uplift. Explore the ethical implications of AI in the workplace, the importance of strategic alignment, and how organisations can prepare for a tech-enhanced future. Don't miss this engaging conversation on navigating the evolving landscape of AI and data. ## Takeaways Capability uplift is essential for organizations to adapt to AI. Organisational values must align with AI strategies for success. Data governance is critical for effective AI implementation. Cross-functional collaboration enhances AI integration. Understanding different AI personas helps in workforce planning. Graduate recruitment is declining, impacting future workforce capabilities. AI should enhance human roles, not replace them. Long-term investment in talent is crucial for organizational growth. Economic implications of AI layoffs need careful consideration. Privacy and security must be prioritised in AI usage. ### AI Governance: Navigating the New Frontier URL: https://katecarruthers.com/ai-governance-navigating-the-new-frontier/ Last updated: 2026-06-28T05:14:23.000Z In this episode of the Data Revolution podcast, host Kate Carruthers chats with [James Kavanagh](https://blog.aicareer.pro/?ref=katecarruthers.com), an expert in AI governance. They discuss the challenges and opportunities in building AI systems that are safe, secure, and lawful. James shares his journey from engineering to AI governance, emphasising the importance of human oversight and the evolving landscape of AI regulations. The conversation covers topics such as the role of AI in society, the impact of regulations like the EU AI Act, and the need for interdisciplinary collaboration in AI governance. You can find James online here: [https://blog.aicareer.pro/](https://www.youtube.com/redirect?event=video%5Fdescription&redir%5Ftoken=QUFFLUhqa1hBeGgycmEyNy0wUGE2R0xUU3dubFYtUWc0Z3xBQ3Jtc0trdkxqand4S3VyU3ZaSVZVazl5a3BOWXExaTZoRFV6cjU0SFVnY2d3bDlOR0owWFVsWG9WWjdnelNqWTVRRXJFU1hISkJPY2h3MEFtbllEM3M1T2RfTnVMTGtlWWFVUWcyT3VCMGtkQ3g0WXJudGZCcw&q=https%3A%2F%2Fblog.aicareer.pro%2F&v=Sql20k7qOZU&ref=katecarruthers.com) And his free course here: [https://governance.aicareer.pro/](https://www.youtube.com/redirect?event=video%5Fdescription&redir%5Ftoken=QUFFLUhqblE1YXNEYWVzTTlyckFRY21jUjl3bGRFY2dRd3xBQ3Jtc0ttYzQtX0JZVE1tdlZMNjhEcDVNYWt6ME9XcU13Mmd4bDBjbDl3cWZVQ2tjd2JNTXdfLUF5Rjd1Q20yMlpJVmxWaUNNS2ZYdnlWdTNjY01SeEtreTZwSzBlZUx3WVpuVjhDLUp3a3FwYUtsNC1zVzlpbw&q=https%3A%2F%2Fgovernance.aicareer.pro%2F&v=Sql20k7qOZU&ref=katecarruthers.com) ## Takeaways - AI governance focuses on building safe, secure, and lawful AI systems. - The term 'responsible AI' can be vague and misused. - Human oversight is essential for decisions that could cause harm. - AI governance requires collaboration across various disciplines. - Organizations are beginning to implement AI standards and regulations. - Education and awareness are crucial for understanding AI risks. - Stakeholder engagement is vital in the design of AI systems. - Procurement processes should include thorough questioning of AI vendors. - Curiosity and a willingness to learn are key traits for effective governance. - AI can significantly enhance productivity when used effectively. ### What's new in AI in 2025 (so far) URL: https://katecarruthers.com/whats-new-in-ai-in-2025-so-far/ Last updated: 2026-06-28T04:58:09.000Z In the latest episode of the Data Revolution podcast, host Kate Carruthers dives into the transformative landscape of AI as we approach the end of 2025\. With a focus on the pivotal changes and some AI innovations, this episode offers a glimpse into the future of technology and its implications for business and society. Key Highlights: - Agentic Models: Discover how autonomous agents are set to revolutionise business processes by operating independently and unsupervised. - Small Language Models: Hear about the shift towards more efficient, smaller models that are driving innovation at the edge and enhancing privacy-sensitive applications. - Geopolitics: Hear how the current geopolitical landscape is driving innovation in some unexpected ways. - Regulatory Challenges: Explore the evolving regulatory landscape and the need for effective governance as AI continues to advance rapidly. - Emergent Properties: Understand the unpredictable nature of AI's emergent properties and the importance of addressing these challenges. ### The future of AI is smaller not bigger URL: https://katecarruthers.com/the-future-of-ai-is-smaller-not-bigger/ Last updated: 2026-04-11T03:17:23.000Z The future of AI will be smaller and not bigger. My take on where AI’s headed? Forget bigger, flashier, more bloated models. The future’s going to be smaller, smarter, and way more focused. This is especially with the advent of [agentic AI](https://en.wikipedia.org/wiki/Agentic%5FAI?ref=katecarruthers.com), since this will be driving business processes, and business finances are finite and nobody will want to pay the real cost of using all of these LLMs. I have been teaching a short course at the [Australian Graduate School of Management](https://www.unsw.edu.au/business/our-schools/agsm?ref=katecarruthers.com) (AGSM) for the past year called [AI for Organisational Innovation](https://www.unsw.edu.au/study/professional-development/course/ai-for-organisational-innovation?ref=katecarruthers.com) and have been exposed to people in leadership from many organisations who are grappling with the challenges of implementing AI. One thing I have been telling them all about the future is that I think the real future is smaller and more focused models rather than this arms race for ever larger and fancier LLMs and LRMs\*. We have all seen the huge investments in data centres and the unsustainable use of water and power to drive all these large models ([Inside the relentless race for AI capacity](https://ig.ft.com/ai-data-centres/?ref=katecarruthers.com), Financial Times, 31 July 2025). At some stage everyone will realise that using our scarce resources to fuel data centres is not a sensible thing to do (at least outside the USA). ### Small Language Models So, while I have been saying that I think the future is smaller models, it is nice to see some research coming out to support my thinking. A recent paper titled [Small Language Models are the Future of Agentic AI](https://arxiv.org/abs/2506.02153v1?ref=katecarruthers.com), where the lay out their arguments. Now I believe these folks for a few reasons - (1) I agree with their messaging, and (2) they are all with [NVIDIA Research](https://research.nvidia.com/labs/lpr/slm-agents/?ref=katecarruthers.com). > "Here we lay out the position that small language models (SLMs) are sufficiently powerful, inherently more suitable, and necessarily more economical for many invocations in agentic systems, and are therefore the future of agentic AI. Our argumentation is grounded in the current level of capabilities exhibited by SLMs, the common architectures of agentic systems, and the economy of LM deployment. We further argue that in situations where general-purpose conversational abilities are essential, heterogeneous agentic systems (i.e., agents invoking multiple different models) are the natural choice. We discuss the potential barriers for the adoption of SLMs in agentic systems and outline a general LLM-to-SLM agent conversion algorithm." ### The real cost of AI Right now, no one’s really footing the true bill for AI - whether it’s GenAI, LLMs, or LRMs. But that party won’t last forever. Sooner or later, the people bankrolling this tech are going to want us to cough up the real costs. And when that invoice lands? Cue the sticker shock. And that’s when folks will start shopping around for cheaper, smarter options, and that’s the moment SLMs and agentic AI will really start to shine. \* Large Language Model (LLM), Large Reasoning Model (LRM) ### Navigating the Future of AI and Quantum Computing URL: https://katecarruthers.com/navigating-the-future-of-ai-and-quantum-computing/ Last updated: 2026-06-28T04:58:51.000Z In this episode of the Data Revolution podcast, host Kate Carruthers interviews Gerard Solden, who shares his journey from banking to AI infrastructure. They discuss the reality of AI technology, the importance of accuracy and reliability in AI systems, and the innovative concept of agentic frameworks. Gerard explains the potential of Manus AI and the future of custom AI models tailored to individual needs. The conversation also touches on the significance of auditing AI responses, the intersection of AI and blockchain, and the impact of quantum computing on AI advancements. They conclude with predictions for the future of AI and the importance of cultivating talent in the field. ## Takeaways - AI is a transformative technology that is changing the world. - There is a significant gap in understanding AI use cases among businesses. - Accuracy and performance are critical in AI applications. - Agentic AI allows for more complex reasoning and task management. - The future of AI may lie in smaller, custom models rather than one-size-fits-all solutions. - Quantization is essential for running AI models efficiently on smaller devices. - Sovereign data security is becoming increasingly important in AI. - The relationship between AI and quantum computing is evolving rapidly. - Auditing AI systems is a significant challenge that needs to be addressed. - The growth of AI and quantum technologies requires skilled personnel to manage them. ### Data Integrity & Compliance in an Australian Context URL: https://katecarruthers.com/data-integrity-compliance/ Last updated: 2026-04-01T03:51:20.000Z In the age of artificial intelligence, data integrity has emerged as the fundamental bedrock upon which reliable, trustworthy, and effective AI systems must be built. As organisations increasingly rely on AI to drive decision-making, predict consumer behaviour, assess market trends, and secure against data breaches, the importance of maintaining data integrity throughout the data lifecycle cannot be overstated. The concept of data integrity encompasses the accuracy, completeness, consistency, and reliability of data throughout its lifecycle. Just as a building cannot stand strong without a solid foundation, AI systems cannot function properly without the solid foundation of high-quality, trustworthy data. The adage “garbage in, garbage out” takes on new significance in the context of AI, where the consequences of poor data integrity are magnified exponentially. This is a version of a talk I gave recently at the Institute of Information Management (IIM) conference in Brisbane. I thought it might be worth sharing here too. ### Introduction What I've learned along the way is that behind every business problem is a human being with some kind of need. And if we understand that, we can solve it. Increasingly now, every business is a data-driven business, but you can't let data be the only thing. We need to focus on the human problems we're trying to solve. And that's really what I want to talk about today – how we navigate the increasingly complex world of data integrity and compliance in the Australian digital landscape while keeping the human element front and centre. Today I'm going to cover four main areas: - An overview of the evolving Australian data landscape, including the regulatory changes that are reshaping how we manage data in 2025. - The human side of data integrity – why focusing on people and their needs is essential for effective data governance. - Australia's approach in a global context, looking at international trends and how Australia is positioned to respond. - Some practical strategies that organisations can implement to navigate this complex landscape successfully. ### The Current State of Play When we look at Australia's digital landscape in 2025, what we're seeing is nothing short of a transformation. Our nation has embraced digital technologies at an impressive rate, with businesses and government agencies alike investing heavily in data-driven solutions. But this rapid digitalisation hasn't come without its challenges. What makes Australia's data ecosystem particularly interesting – and challenging – is that we've developed what I like to call a "patchwork" of legislative and regulatory mechanisms. Unlike some jurisdictions with a single comprehensive data protection law, we have a complex web of economy-wide and industry-specific obligations. And this complexity is only growing. For those of you who've been following the regulatory developments, you'll know that the Privacy & Other Legislation Amendment Act came into effect in December 2024\. This first tranche of reforms introduced several significant changes to our privacy landscape, including expanded powers for the Information Commissioner, new civil penalties, and facilitated information sharing in emergency situations. But what I find particularly interesting are two elements that are still in their grace periods: the new statutory tort to redress serious invasions of privacy, which comes into effect in June 2025, and the increased transparency requirements for automated decisions using personal information, which organisations have until December 2026 to implement. We're also seeing new criminal offences for 'doxxing' – the malicious public disclosure of someone's personal information with intent to cause harm. This reflects a growing recognition that privacy violations can cause real harm to real people. And let's not forget the Children's Online Privacy Code, which is being developed to provide enhanced protections for our youngest digital citizens. This is particularly important as we see more and more children engaging with digital platforms from an increasingly early age. ### Critical Regulatory Developments Beyond privacy reforms, there are several other regulatory developments that are reshaping Australia's digital landscape. The Cyber Security Act 2024, which came into effect in November last year, introduces a range of new obligations. The legislative rules to support the implementation of the Act are being rolled out over the next year, including: - The Cyber Security (Ransomware Reporting) Rules, which will commence in May 2025 and will require businesses with an annual turnover of AUD $3 million to report ransomware incidents - The Cyber Security (Cyber Incident Review Board) Rules, also commencing in May 2025 - And the Cyber Security (Security Standards for Smart Devices) Rules, which will commence in March 2026 These rules represent a significant shift in how we approach cybersecurity in Australia, moving from a largely voluntary approach to one with more mandatory requirements. For those of you in the critical infrastructure space, you'll be aware of the amendments to the Security of Critical Infrastructure Act that came into effect in November 2024\. These changes confirm that organisations responsible for SOCI assets must ensure risks to data essential to the asset's operation are considered in their Critical Infrastructure Risk Management Program. And if you're in the financial sector, you'll be preparing for the Prudential Standard CPS 230 Operational Risk Management, which takes effect from July 2025\. This will require APRA-regulated entities to effectively manage operational risks, maintain critical operations through severe disruptions, and manage the risks associated with service providers. Finally, we have the Scams Prevention Framework, which passed both Houses of Parliament in February 2025\. This framework requires service providers in selected sectors to take actions to combat scams, following the principles of Govern, Prevent, Detect, Report, and Disrupt. Now, I know that's a lot of regulatory information to take in and navigating this complex regulatory landscape requires a tailored approach. But understanding these developments is crucial for effective data governance in 2025 and beyond. What's important to remember is that these regulations aren't just bureaucratic hoops to jump through – they're designed to protect real people from real harm. And that brings me to my next point: the human side of data integrity. ### Beyond Compliance: Understanding the Real Problems Now, this is the part where I really want to emphasise something that I believe is fundamental to effective data governance: behind every business problem is a human being with some kind of need. In my years working with data, I've seen too many organisations approach data integrity and compliance as purely technical challenges. They focus exclusively on the systems, the processes, and the regulations – and they forget about the people. But here's the thing: data doesn't exist in a vacuum. It represents real people, real behaviours, real needs. When we talk about data breaches, we're not just talking about compromised databases – we're talking about individuals whose personal information has been exposed, potentially leading to financial loss, identity theft, or emotional distress. When we talk about algorithmic bias, we're not just talking about flawed models – we're talking about people who may be denied opportunities or services based on unfair criteria. Every organisation is what I like to call a "unique special snowflake." What works for one may not work for another, because each has its own culture, its own values, its own people. That's why cookie-cutter approaches to data governance often fail. You need to understand the specific human problems your organisation is trying to solve. Let me give you a real-world example. In a previous role, I implemented a data governance framework that wasn't just about compliance with regulations – it was about supporting our researchers, our educators, and our students. We asked ourselves: What do these people need from their data? How can we make their lives easier while also ensuring data integrity? By focusing on these human questions, we were able to develop solutions that people actually wanted to use, rather than systems they tried to work around. And that's a critical point: if your data governance approach doesn't work for the humans in your organisation, they'll find ways to circumvent it, potentially creating even bigger risks. ### The Trust Equation This human-centered approach to data integrity leads directly to what I call the trust equation. In simple terms: ## data integrity + transparency = trust. Trust is the currency of the digital age. Your customers trust you with their data. Your partners trust you to handle shared information responsibly. Regulators trust you to comply with the rules. And when that trust is broken, the consequences can be severe. The business case for strong data governance goes well beyond avoiding fines or penalties. It's about maintaining the trust of your stakeholders. Research consistently shows that organisations with strong data governance practices enjoy higher levels of customer loyalty, more productive partnerships, and better reputations. Consider the reputational impact of a data breach. According to the 2024 Cost of a Data Breach Report, the average cost of a data breach in Australia is now AUD $5.8 million. But that figure doesn't capture the long-term damage to customer trust, which can take years to rebuild. Building a culture of data integrity across your organisation isn't just about having the right policies and procedures in place – though those are certainly important. It's about fostering a mindset where everyone understands the value of data and their role in protecting it. From the frontline staff who collect customer information to the executives who make strategic decisions based on data insights, everyone needs to understand that data integrity is a shared responsibility. And that responsibility is ultimately about protecting people – your customers, your employees, your partners. When we frame data governance in these human terms, it becomes much more than a compliance exercise. It becomes a core business value that drives better decision-making, stronger relationships, and ultimately, better outcomes for everyone involved. ### International Trends Shaping Our Approach While we've been discussing the Australian context, it's important to recognise that data integrity and compliance is a global challenge. We're not operating in isolation, and understanding international trends can help us better navigate our own landscape. The European Union's General Data Protection Regulation (GDPR) continues to set the global benchmark for privacy protection. What's interesting is that GDPR enforcement is becoming increasingly strict, with regulators focusing on adherence to the principles of personal data processing and imposing larger fines for non-compliance. The total sum of GDPR fines has grown exponentially since its implementation, and this trend shows no signs of slowing down. In the United States, we're seeing the California Privacy Rights Act (CPRA) building upon the foundation of the California Consumer Privacy Act, giving California residents even greater control over their data. And it's not just California – approximately 20 US states have now enacted their own privacy laws, creating a complex patchwork of regulations that global companies must navigate. One particularly interesting development is the Global Privacy Control (GPC), a technical specification that allows users to signal their privacy preferences to websites automatically. It's essentially a digital "Do Not Disturb" sign, and it's becoming mandatory under most US state privacy laws. But I must caveat this with a note that nobody knows what the Trump regimes current appetite is for any kind of additional regulation in the AI and privacy space. When it comes to AI regulation, the EU is again leading the way with the AI Act. The first rules of this Act, covering prohibitions and AI literacy obligations, came into effect in February 2025, with full application expected by August 2026\. The Act takes a risk-based approach, categorising AI systems into four levels of risk and imposing stringent requirements on high-risk applications. The US is taking a more fragmented approach to AI regulation, with multiple bills under consideration at the federal level and various state initiatives. Canada is developing the Artificial Intelligence and Data Act (AIDA), focusing on "high-impact systems" in areas like employment, service access, and law enforcement. We're also seeing a global trend toward data localisation, with countries like China, Russia, and India (among the many) requiring certain types of data to be stored within their borders. This has significant implications for global data flows and business operations. ### Australia's Opportunity to Lead So where does Australia fit in this global picture? I believe we have a unique opportunity to lead in a few areas: - Our approach to critical infrastructure protection, particularly through the Security of Critical Infrastructure Act, is quite advanced. We've recognised the essential role that data plays in the operation of critical assets and have developed frameworks to protect it accordingly. - Our financial sector regulations, particularly APRA's CPS 230, demonstrate a sophisticated understanding of the relationship between operational risk, data governance, and third-party risk management. But perhaps our greatest opportunity lies in how we balance innovation with protection. Australia has a strong tradition of pragmatic regulation – not too heavy-handed, but not too laissez-faire either. This positions us well to develop approaches that protect individuals while still enabling businesses to innovate and compete globally. I also believe Australia has a significant role to play in the Indo-Pacific data ecosystem. As data flows increasingly shape regional economic integration, Australia can help establish norms and standards that promote both data protection and data utility. The key is to approach these opportunities with a clear understanding of our values and priorities. What kind of digital society do we want to build? How do we ensure that our data practices reflect our commitment to fairness, transparency, and human dignity? These are not just technical questions – they're deeply ethical and social questions that require broad engagement across sectors and communities. ### Implementation Let's get practical now. How can organisations actually navigate this complex landscape of data integrity and compliance? I'd like to share some strategies that I've seen work effectively across different sectors. First, let's talk about the Essential Eight framework. Developed by the Australian Cyber Security Centre, this framework provides a solid foundation for protecting your systems from cyber threats. The framework is divided into three objectives: preventing cyberattacks, limiting their extent, and ensuring data recovery and system availability. What I like about the Essential Eight is its maturity model approach. You can implement it in phases, starting with Maturity Level One and working your way up to Maturity Level Three. This makes it accessible for organisations at different stages of their security journey. For those of you in specific sectors, there are additional considerations. Financial services organisations need to be preparing for CPS 230 Operational Risk Management, which takes effect in July 2025\. This means identifying the technology and systems enabling critical operations and implementing commensurate risk management controls. If you're responsible for critical infrastructure, you need to ensure that your Critical Infrastructure Risk Management Program addresses risks to data essential to your asset's operation. And for telecommunications providers, be aware that you have until October 2025 before the CIRMP requirement takes effect. Small businesses face their own challenges. While the Privacy Act's small business exemption is still in place, it's under serious reconsideration. The February 2023 Privacy Act Review Report proposed abolishing this exemption entirely, which would bring approximately 2.3 million additional businesses within the scope of privacy regulation. So, if you're a small business owner, it's worth starting to prepare now, especially given the 13% increase in cybercrime targeting smaller firms as "easier targets." One thing I commend to any small business folks in the audience today is to check out the **SMB1001:2025** standard which is multi-tiered cybersecurity certification standard for small and medium-sized businesses, which is much more accessible than the Essential Eight for small businesses. You can also check out this [Data Revolution podcast episode](https://datarevolution.tech/2025/03/jodie-miners/?ref=katecarruthers.com) which covers SMB 1001 in more.detail. ### Technology and Governance Integration Beyond framework implementation, there are several approaches to integrating technology and governance effectively. A platform-first compliance strategy can be particularly valuable. This involves using centralised compliance solutions to manage multiple frameworks, with automated tools that integrate various requirements to streamline processes. This is mostly framed as part of governance risk and compliance activities. This approach reduces manual work and compliance gaps, allowing your team to focus on strategic priorities rather than administrative tasks. If you're implementing AI systems, it's crucial to align your AI strategy with privacy and security requirements. This means developing AI applications that comply with existing regulations and ethical standards, focusing on data minimisation in AI training and implementation, and establishing robust governance frameworks for AI decision-making. ISO/IEC 42001, the AI Management system standard, is a great starting place for organisations that need to work out how to manage and govern their AI operations. Third-party risk management is another critical area. With the increasing reliance on external vendors, you need centralised third-party risk assessments and compliance monitoring. This helps ensure that your supply chain aligns with privacy standards and reduces the risk of data breaches originating from external sources. Data governance framework enhancement is also essential. This involves conducting comprehensive data inventories to identify what personal information you collect, where it's stored, how it's processed, and why you use it. This mapping exercise provides the foundation for establishing appropriate retention periods and implementing effective data minimisation strategies. Finally, strengthening your information security posture is more important than ever, given the increased penalties for privacy breaches. Implement appropriate technical and organisational measures to safeguard personal information, establish regular security assessments and vulnerability testing, and update your data breach response plans to align with Australian notification requirements. Remember, the goal isn't just compliance – it's building a robust approach to data integrity that protects your organisation, your customers, and your partners while enabling innovation and growth. ### Key Takeaways As we come to the end of our time together, I'd like to leave you with a few key takeaways. 1. Remember that behind every business problem is a human being with some kind of need. When we approach data integrity and compliance from this human-centered perspective, we develop solutions that work not just on paper, but in practice. 2. Recognise that every organisation is a unique special snowflake. There's no one-size-fits-all approach to data and its governance. You need to understand your specific context, your specific risks, and your specific opportunities. 3. Understand that data integrity creates business value beyond compliance. It builds trust with your customers, your partners, and your regulators. And in today's digital economy, trust is perhaps your most valuable asset. 4. And, acknowledge that Australia has a real opportunity to lead in the global data and AI conversation. Our pragmatic approach, our sophisticated understanding of critical infrastructure protection, and our position in the Indo-Pacific region all give us a unique voice in shaping how data is used globally. ### Call to Action So, what should we do with all this information? Let me suggest a few concrete steps. 1. Proactively prepare for upcoming regulatory changes. Don't wait until the last minute to comply with the Cyber Security Act rules or CPS 230\. Start mapping your data, reviewing your policies, and enhancing your security measures now. 2. Invest in data governance as a strategic priority. This isn't just an IT issue or a compliance issue – it's a business issue that requires leadership from the top. Make sure your executives understand the value of strong data governance and allocate resources accordingly. 3. Collaborate across sectors to develop best practices. Join industry groups, participate in forums like this one, and share your experiences with peers. We're all figuring this out together, and we can learn a lot from each other's successes and failures. 4. Commit to continuous learning and adaptation. The digital landscape is evolving rapidly, and what works today may not work tomorrow. Stay curious, stay informed, and be willing to adjust your approach as new challenges and opportunities emerge. ### Final Thought I'd like to close with a thought that guides my own work in this field. Data isn't just ones and zeros – it's a reflection of human lives, human choices, and human potential. When we protect the integrity of data, we're ultimately protecting people and their right to control their digital identities. As information management professionals, we have a crucial role to play in building a digital future that respects human dignity, promotes fairness, and creates value for all Australians. It's a big responsibility, but it's also an exciting opportunity to shape how technology serves humanity. ### Jonathan Mast: Getting started with Generative AI URL: https://katecarruthers.com/jonathan-mast-getting-started-with-generative-ai/ Last updated: 2026-06-28T04:59:21.000Z In this conversation on the Data Revolution Podcast, Jonathan Mast ([https://whitebeardstrategies.com/](https://www.youtube.com/redirect?event=video%5Fdescription&redir%5Ftoken=QUFFLUhqbTdmSi03VFRFQ3NqOTZubjNCUXA1Sy1LVTUyUXxBQ3Jtc0ttY0RuRjcybS1SczEzVVJLWmpfUndfTGx6UTBoNi1nZGhqYjUyb3RWVG5tRWxlRTBWTHFHdm9fMV93U2g3TFdXYlF1d3REajNEc0tvZ3RLWWU2b2g5Tkw5c3doa0hWSGxTMWZ6LXkwYktRTmxlSUNvQQ&q=https%3A%2F%2Fwhitebeardstrategies.com%2F&v=77vCRdhKzU0&ref=katecarruthers.com)) discusses the transformative role of AI in various aspects of life and business. He emphasizes that AI amplifies human skills and experience, making it a valuable tool for individuals of all ages. The discussion covers practical applications of AI in daily tasks, its impact on business productivity, and the importance of navigating privacy concerns. Jonathan also explores the evolving landscape of content creation and SEO in the age of AI, and he shares insights on how individuals can adapt their skills to leverage AI effectively. The conversation concludes with actionable tips for those looking to integrate AI into their lives. ### Navigating Cybersecurity for Small Business URL: https://katecarruthers.com/jodie-miners/ Last updated: 2026-06-28T04:59:53.000Z In this episode of the Data Revolution podcast, I speak with [Jodie Miners](https://thedetaildept.com/about/jodieminers/?ref=katecarruthers.com) about the importance of cybersecurity for small businesses, focusing on the [SMB 1001:2025 standard](https://australiawideit.com.au/smb1001-cybersecurity-framework-explained/?ref=katecarruthers.com). We discuss the challenges small businesses face in implementing cybersecurity measures, the benefits of achieving certification, and practical steps to enhance data protection. Jodie shares valuable resources available for small businesses to improve their cybersecurity posture and emphasizes the need for data governance and business continuity planning in the face of rising cyber risks. ### Navigating the AI Landscape for kids URL: https://katecarruthers.com/tama-leaver/ Last updated: 2026-06-28T05:02:10.000Z In this episode of the Data Revolution podcast, I speak with [Dr. Tama Leaver](https://www.tamaleaver.net/?ref=katecarruthers.com) about the evolving role of data and AI in society, particularly focusing on children's interaction with generative AI, the implications for privacy and consent, and the challenges of educating young people in a rapidly changing technological landscape. We discuss the biases inherent in AI tools, the importance of critical engagement with technology, and the need for a more nuanced understanding of privacy in the digital age. Our conversation emphasises the agency individuals have in shaping the future of AI and the importance of equipping the next generation with the skills to navigate this complex environment. ### Rise of the Fractional Chief Data Officer URL: https://katecarruthers.com/rise-of-the-fractional-chief-data-officer/ Last updated: 2026-06-28T05:01:36.000Z Great to have old friend, Gladwin Mendez ([https://www.gecprudentia.com/)](https://www.youtube.com/redirect?event=video%5Fdescription&redir%5Ftoken=QUFFLUhqbEZOa21ZVWNSaE9IZE4tZkx6ek9CMkUwSkZrd3xBQ3Jtc0trNUREUW9tTTFULUNVclFmQ2lPNTJfU3Nta2pSTkI5TU14ZEp1LTFBV2ZYekdhNmpCSHZtQXd0bzE2blBxQk0wWVNvTHlhTVpwWkE2b1FyaGlmRHlmYjViRVVQZGEySlBnUHNvN0tyNjlpWXFvajYxcw&q=https%3A%2F%2Fwww.gecprudentia.com%2F%29&v=0UCGkEnhzM8&ref=katecarruthers.com), back on the podcast to talk about the emergence of the new role of fractional Chief Data Officer (CDO). The rise of fractional CDOs reflects the growing recognition of data's strategic value in modern businesses. As organisations increasingly rely on data-driven decision-making, many are turning to fractional CDOs - experienced professionals who offer their expertise on a part-time or project basis. This flexible model allows companies, particularly SMEs and startups, to access high-level data leadership without the cost of a full-time executive. Fractional CDOs help businesses to start on their data journey ensuring compliance, optimising analytics, and driving innovation, all while aligning data strategies with broader organisational goals. ### AI and building a free society URL: https://katecarruthers.com/david-bray/ Last updated: 2026-06-28T05:14:54.000Z ![](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/04/dscf7352-singularity-croppedphoto-1024x838-3067237781.jpg) My guest for this episode is [Dr David Bray](https://www.stimson.org/ppl/david-bray/?ref=katecarruthers.com). He has been thinking deeply about AI for many years. We had a wideranging chat about AI, cybersecurity, new AI’s, state actor attacks and the ongoing greyzone war, the need to use data to maintain free societies, and the importance of working locally and building community. Some things that we touched on were the need to secure our hardware and data supply lines, the need for human agency – data as a kind of human voice. David is a big advocate for data rights to be managed via existing contract law, which seems like a good idea to me. ### 2025 BingoCard URL: https://katecarruthers.com/2025-bingocard/ Last updated: 2026-04-01T03:51:20.000Z In something of a tradition for me, at the start of each new year, I deal with my existential dread by creating a BingoCard. Here is my 2025 BingoCard: ![](https://katecarruthers6748.live-website.com/wp-content/uploads/2025/01/Kate-BingoCard-2025.png) Here is a link to the [pdf version](https://katecarruthers6748.live-website.com/wp-content/uploads/2025/01/Kate-BingoCard-2025.pdf?ref=katecarruthers.com) ### What NEDs need to Know About Artificial Intelligence, Automation, and Expert Systems URL: https://katecarruthers.com/what-neds-need-to-know-about-artificial-intelligence-automation-and-expert-systems/ Last updated: 2026-04-01T03:51:20.000Z By [Kate Carruthers](https://katecarruthers.com/about-kate-carruthers/) & [Kobi Leins](https://kobileins.com/?ref=katecarruthers.com) "*What I had not realized is that extremely short exposures to a relatively simple computer program could induce powerful delusional thinking in quite normal people.*" \- Joseph Weizenbaum, creator of the first chatbot, 1964 ## What is AI? ‘Artificial Intelligence’ is a term that has been around since 1956\. Definitions of AI abound – from the [International Standards Organisation](https://www.iso.org/artificial-intelligence/what-is-ai?ref=katecarruthers.com) to the [OECD](https://oecd.ai/en/wonk/definition?ref=katecarruthers.com) – but our personal favourite is this one from 2004 from the Australian Administrative Review Council that refers to ‘[expert systems](https://www.ag.gov.au/sites/default/files/2020-03/report-46.pdf?ref=katecarruthers.com)’, which on their plain definition are ‘computing systems that, when provided with basic information and a general set of rules for reasoning and drawing conclusions, can mimic the thought processes of a human expert.’ ## What is AI made of? AI includes a series of component parts, both software and hardware. AI may include data-based or model-based algorithms; the data, both structured and unstructured; machine learning, both supervised and unsupervised; the sensors that provide input and the actuators that effect output. Each of these component parts provide opportunities – and may pose risks. The devil is in the detail. Typically, when people are speaking about AI, they are talking about a specific AI related technology or technique. The primary types of AI that are included under the term at present include: - Artificial Intelligence: an umbrella term for the overall field of computer science that seeks to create intelligent machines that can replicate or exceed human intelligence. - Machine Learning: subset of AI that enables machines to learn from existing data and improve upon that data to make decisions or predictions. - Deep Learning: a machine learning technique in which layers of neural networks are used to process data and make decisions. - Generative AI: creation of new written, visual, video, and auditory content given prompts and existing data. - Agentic AI: AI systems that are capable of autonomous action and decision-making. These systems, often referred to as AI agents, can pursue goals independently, without direct human intervention. ## What is different about AI? A couple of things. Firstly, AI is made up of mostly historical data used in ways to project into the future at speed and scale in ways that may have unintended or harmful consequences. Perhaps more importantly, data and AI embed values. Making sure that the tools you build, and use align with your vision, strategy and values from the outset is key. You might not need the expensive tool. Lower cost and risk opportunities are often the best way to build capability and understanding. ## What do I need to do to ensure that my Board is managing AI risk adequately? Although there is a lot of hype around AI management and governance, a large part of this work is done if there is a solid basis of good governance already, including practices such as information technology governance and data governance. Good business practices, including risk appetites (ideally specifically for AI), risk frameworks, procurement practices, privacy, legal, accessibility, whistleblower protection, and more – if you have these in place, you are already well-placed to govern and manage AI. Where you might need to think of uplifting include: 1. Uplift in Board capability in asking the right questions about AI. 2. A specific AI risk appetite. 3. An AI policy (consultation is queen). 4. Adapting KPIs to reflect AI stance (carrot). 5. Linking AI policy to Code of Conduct directly (stick). ## Start thinking about the Three P’s: Policies, Processes and People ## Policies Policies are a great place to start to bring your business along to understanding what AI can and cannot do. Alone, they do very little. Policies need to be linked to other policies (such as the code of conduct, pay incentives, etc.) but also to processes. ### Processes One of the biggest questions is ‘what is AI and how do I review it?’. Referring to our definitions above, our recommendation is to have a wide funnel. Robodebt was an Excel spreadsheet – any ‘expert system’ that affects something else or helps to make a decision may have real-world (and legal) ramifications, so review widely. It will become clear what is higher risk as you go along. Ensure that you have clear pathways for procurement that include subject matter experts who can ask the right questions. Products are said to include AI until they work- the AI is often a sales pitch and what is sold as AI may not even be AI. Ensure robust documented due diligence of vendors. You may need extra expertise or training to enable this properly. ### People By far the most significant piece of AI management and governance is the people. Having protections (and safe culture) for those who call out risks is one of your biggest guardrails, and given the technical nature of the tools, often those at the lower levels have a much better idea of how the tools *actually* work. Think of the [Volkswagen Case](https://www.bbc.com/news/business-34324772?ref=katecarruthers.com), or the [Boeing Scandal](https://www.justice.gov/opa/pr/boeing-charged-737-max-fraud-conspiracy-and-agrees-pay-over-25-billion?ref=katecarruthers.com), the main lesson of which is to have people on your Board who understand the technology and its benefits and risks. ## Conclusion Artificial Intelligence (AI) is here, or at the very least, it is on its way. Some surveys suggest that between [42](https://newsroom.ibm.com/2024-01-10-Data-Suggests-Growth-in-Enterprise-Adoption-of-AI-is-Due-to-Widespread-Deployment-by-Early-Adopters?ref=katecarruthers.com) – [65 per cent of workers](https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai?ref=katecarruthers.com) across organisations globally are using generative AI. While these figures [may be exaggerated](https://www.economist.com/finance-and-economics/2024/07/02/what-happened-to-the-artificial-intelligence-revolution?ref=katecarruthers.com), what is clear is that companies will continue to explore the possibilities of AI. Current estimates suggest that in Australia only [10 per cent of corporate leaders](https://www.uts.edu.au/human-technology-institute/projects/ai-corporate-governance-program/governance-ai-aicd-hti-director-resources?ref=katecarruthers.com) (a mix of executives and board members) have an AI strategy, while 13 per cent of company directors have a set of AI or data ethics principles. [Less than half of corporate leaders](https://unisyd-my.sharepoint.com/personal/thomas%5Fbarrett%5Fsydney%5Fedu%5Fau/Documents/USSC%20Work%20Materials%20%28Personal%29/Research%20output/Research%20support/Externally%20Authored%20Review/If%20boards%20fail%20to%20govern%20AI,%20it%20might%20just%20do%20it%20without%20them?ref=katecarruthers.com) who are using AI said their organisation was undertaking a risk assessment of their AI use. As AI adoption increases among businesses, Boards must be prepared. ### Microsoft Copilot and AI in government URL: https://katecarruthers.com/microsoft-copilot-and-ai-in-government/ Last updated: 2026-06-28T05:02:46.000Z Had a great chat with Kobi Leins about some good feedback on the Australian Governments Microsoft Copilot pilot (full story here: [Australian Government trial of Microsoft 365 Copilot](https://www.digital.gov.au/initiatives/copilot-trial/summary-evaluation-findings?ref=katecarruthers.com)). We also had a wide-ranging chat about the upcoming training deficit all organisations have in respect of AI, the recent changes in the federal AI space. [https://open.spotify.com/episode/1M8TvrK8kGu4EUVa7Fa5hg](https://open.spotify.com/episode/1M8TvrK8kGu4EUVa7Fa5hg?ref=katecarruthers.com) ## Links to stuff we mentioned [https://www.digital.gov.au/initiatives/copilot-trial/microsoft-365-copilot-evaluation-report-full](https://www.digital.gov.au/initiatives/copilot-trial/microsoft-365-copilot-evaluation-report-full?ref=katecarruthers.com) [https://www.microsoft.com/en-us/worklab/work-trend-index/copilots-earliest-users-teach-us-about-generative-ai-at-work](https://www.microsoft.com/en-us/worklab/work-trend-index/copilots-earliest-users-teach-us-about-generative-ai-at-work?ref=katecarruthers.com) [https://www.industry.gov.au/news/four-new-centres-help-australian-businesses-adopt-ai](https://www.industry.gov.au/news/four-new-centres-help-australian-businesses-adopt-ai?ref=katecarruthers.com) ### The challenges of getting robots and AI to be more human URL: https://katecarruthers.com/the-challenges-of-getting-robots-and-ai-to-be-more-human/ Last updated: 2026-05-15T00:20:31.000Z This time my guest is Dr Brandon Rohrer. He is a data scientist who originally started in researching robots to assist with stroke recovery, and who now works on solving data challenges. Brandon, whom I tracked down via his online discovery work on [https://e2eml.school/blog.html](https://www.youtube.com/redirect?event=video%5Fdescription&redir%5Ftoken=QUFFLUhqbDZENVhlSjFnYXBNazBtcVIzYjZhT2pRS09Hd3xBQ3Jtc0tuTXJFSUQyT0xMQlo0S2FYbEpFTW8zMlR1U2lsOVN5Vk9rX3BteG1jczJwU0k5d2tuNXMwa0kzY2hzYU9RNU8wdDZONjMtYjktcVVxNHUtdHpXckZaZWVrTGFjeTIya09sWWJybVNjWUxpZm9KTVNPZw&q=https%3A%2F%2Fe2eml.school%2Fblog.html&v=47vedDQc81I&ref=katecarruthers.com) where I was captivated by his journey in understanding AI. It is a great resource, and I did show it to my team who also loved it. We had a fascinating and wide-ranging chat that went from the demise of Twitter to the challenges of getting robots and AI to be more human. [https://open.spotify.com/episode/3Tc5wGRi1afqfw6d7SV5kD](https://open.spotify.com/episode/3Tc5wGRi1afqfw6d7SV5kD?ref=katecarruthers.com) ### AI in higher education - chasing cheaters URL: https://katecarruthers.com/kane-murdoch-shaun-lehmann/ Last updated: 2026-05-15T00:24:41.000Z My guests for this episode are Kane Murdoch and Shane Lehmann. They work in the area of academic integrity at one of Australia's major universities and have been thinking seriously about the problems facing us in academia of ensuring that students behave with integrity in their assessments. The issue is typically referred to as "contract cheating" which includes students outsourcing completion of their work, or \*contracts it out, to a third party. This practice risks devaluing university degrees and destroying trust in the quality of degrees. Kane and Shaun argue that the way to combat this practice in the age of AI is to change the way that we assess students in higher education. Have a listen to their arguments and let us know what you think. https://open.spotify.com/episode/7aasZGUYttBOyyOS3NjoIj ### Human cognition and AI URL: https://katecarruthers.com/human-cognition-and-ai/ Last updated: 2026-06-28T05:08:20.000Z This time my guest is my friend [Ross Dawson](https://rossdawson.com/?ref=katecarruthers.com). He is always on the cutting edge of new stuff, as you would imagine for a futurist. We had an amazing chat about his current passion for cognitive AI and how it is going to change the world of work. I loved his ideas for humanity working together with AI. > "Ross Dawson is a world-renowned keynote speaker, strategy advisor, and entrepreneur he inspires with powerful, practical insights into the future and how to seize today’s opportunities." [https://open.spotify.com/episode/0YCfnf5dcXUHijiIuDJZTJ](https://open.spotify.com/episode/0YCfnf5dcXUHijiIuDJZTJ?ref=katecarruthers.com) ### Misinformation and Disinformation are Data Too URL: https://katecarruthers.com/emma-briant/ Last updated: 2026-06-28T05:05:22.000Z This time my guest is [Dr Emma L. Briant](http://emma-briant.co.uk/?ref=katecarruthers.com), a globally renowned researcher on misinformation, disinformation and propaganda. We had a great chat about how these are now the new battlegrounds and how data underpins them. Of course we mentioned the US (a bit). Emma shared her new research and some other resources such as her Patreon. I commend all these resources to you – they are amazing resources for understanding this hotly contested area. [https://open.spotify.com/episode/4xZyrTrPWL87ptKMHjTpxM ](https://open.spotify.com/episode/4xZyrTrPWL87ptKMHjTpxM?ref=katecarruthers.com) ## Resources and links - Website: [http://emma-briant.co.uk/](http://emma-briant.co.uk/?ref=katecarruthers.com) - Patreon: [https://www.patreon.com/emmalbriant](https://www.patreon.com/emmalbriant?ref=katecarruthers.com) - Book: [https://www.routledge.com/Routledge-Handbook-of-the-Influence-Industry/Briant-Bakir/p/book/9781032188997](https://www.routledge.com/Routledge-Handbook-of-the-Influence-Industry/Briant-Bakir/p/book/9781032188997?ref=katecarruthers.com) - Udemy course: [https://www.udemy.com/course/propaganda-disinformation-level-1-beginners/?referralCode=F6D164B12D33A03ADF60](https://www.udemy.com/course/propaganda-disinformation-level-1-beginners/?referralCode=F6D164B12D33A03ADF60&ref=katecarruthers.com) - LinkedIn: [https://www.linkedin.com/in/emmalbriant/](https://www.linkedin.com/in/emmalbriant/?ref=katecarruthers.com) - Bluesky: [https://bsky.app/profile/emma-briant.co.uk](https://bsky.app/profile/emma-briant.co.uk?ref=katecarruthers.com) - Mastodon: [https://mastodon.online/@emmalbriant](https://mastodon.online/@emmalbriant?ref=katecarruthers.com) - Twitter: @Emmalbriant ### 2024 Global Top 100 Innovators in Data and Analytics URL: https://katecarruthers.com/2024-global-top-100-innovators-in-data-and-analytics/ Last updated: 2026-04-01T03:51:21.000Z I’m excited to share that I’ve been named one of the **2024 Global Top 100 Innovators in Data and Analytics** by Corinium! A heartfelt thank you to my amazing Data Platform team at UNSW and peers for their support. Check out the list here: [https://www.coriniumintelligence.com/top-100-innovators-2024](https://www.coriniumintelligence.com/top-100-innovators-2024?ref=katecarruthers.com) #DataInnovation #Corinium #Leadership #Top100 ### Data Governance for Leaders URL: https://katecarruthers.com/data-governance-for-leaders/ Last updated: 2026-05-12T04:27:53.000Z ### New course I recently facilitated a new [Australian Graduate School of Management](https://www.unsw.edu.au/business/our-schools/agsm?ref=katecarruthers.com) (AGSM) short course called [Data Governance for Leaders](https://www.unsw.edu.au/business/our-schools/agsm/learn-with-us/short-courses/data-governance-for-leaders?ref=katecarruthers.com), for the first time. I developed this course based on my lessons learned as a data governance leader for UNSW and from key resources around the world. I designed this course so it would work for diverse groups of people, from data governance leaders through to business users of organisational data who need to understand data governance. AGSM and I were a bit uncertain when we scheduled this course if there would be much demand for it, so it was pleasing to see a full class. It is a long time since I have done any teaching. The last time was pre-covid and I had almost forgotten how much fun it is to bounce ideas of a group of smart humans and the gather ideas and input from everyone. I had also forgotten how exhausting it is to be on one's feet for two days straight. ### About data governance in the age of AI I have been pondering how data governance may need to evolve in the age of AI, and plan on writing more about this soon. One important thing to keep in mind is that, with the advent of AI across the board, data governance becomes more important than ever. We need to know important things about our data, and there need to be rules of engagement agreed across every single organisation. I have written about the need to understand the organisational data landscape and data holdings before, e.g. here [The Big Five Data Questions](https://datarevolution.tech/2023/09/05/five-data-questions/?ref=katecarruthers.com) and it is not something that is not diminishing in its importance. Here are the key things one needs to know about one's data: > I got these questions from [Mike Burgess](https://en.wikipedia.org/wiki/Mike%5FBurgess%5F%28intelligence%5Fchief%29?ref=katecarruthers.com), who was then CISO for Telstra (and who is now grand poo-bah at ASIO), and I thought at the time that they were the right questions to ask. > > These five simple questions underpinned the start of our [data governance journey at the University of New South Wales](https://www.datagovernance.unsw.edu.au/five-knows?ref=katecarruthers.com) back in 2014. > Do you know the value of your data? > Do you know who has access to your data? > Do you know where your data is? > Do you know who is protecting your data? > Do you know how well your data is protected?" [![Data Governance for Leaders AGSM Sydney](https://katecarruthers6748.live-website.com/wp-content/uploads/2024/09/DGL-2024.png)](https://www.unsw.edu.au/business/our-schools/agsm/learn-with-us/short-courses/data-governance-for-leaders?ref=katecarruthers.com) ### Next course The [Data Governance for Leaders](https://www.unsw.edu.au/business/our-schools/agsm/learn-with-us/short-courses/data-governance-for-leaders?ref=katecarruthers.com) course will run at AGSM again in Sydney in November 2024\. Also keep an eye out for AGSM's new [AI for Organisational Innovation](https://www.unsw.edu.au/business/our-schools/agsm/learn-with-us/short-courses/ai-for-organisational-innovation?ref=katecarruthers.com) course, which has been developed in collaboration with Microsoft, which I will be delivering in a virtual self-paced format. ### AI in Education URL: https://katecarruthers.com/lynn-gribble/ Last updated: 2026-06-28T05:09:33.000Z My guest for this episode is [Dr Lynn Gribble](https://www.unsw.edu.au/staff/lynn-gribble?ref=katecarruthers.com). She is an Associate Professor at UNSW Sydney Business School who is passionate about embracing new technology to help in the education process. Lynn has been at the forefront of new technology in education, from pioneering voice feedback to innovating with technology for grading and feedback. She is multi-awarded and a though leader in her field, even presenting to a Parliamentary inquiry on the impacts of Artificial Intelligence in education. Lynn is also a cat lover, ice skater, and and an all around nice human being. We chatted about how we need to start rethinking everything now, including how we assess students in the age of AI. I am definitey asking Lynn back on the podcast as we only covered a small fraction of the stuff I wanted to chat about [https://open.spotify.com/episode/4uYIbb0WAUWAZBHOX0DG2r](https://open.spotify.com/episode/4uYIbb0WAUWAZBHOX0DG2r?ref=katecarruthers.com) ### The AI Revolution is a Marathon, Not a Sprint URL: https://katecarruthers.com/the-ai-revolution-is-a-marathon-not-a-sprint/ Last updated: 2026-06-28T05:06:03.000Z [Kate Carruthers](https://katecarruthers.com/) shares her thoughts on us being at the very start of the AI revolution - we are in the Netscape stage of the journey (not the TikTok stage). She also discusses how Generative AI might just be the start of a new generation of user interfaces. And how AI will merge into autonomous systems - which will make things much more interesting. [https://open.spotify.com/episode/1iB8nd94VikjJH85wTL9jv](https://open.spotify.com/episode/1iB8nd94VikjJH85wTL9jv?ref=katecarruthers.com) ### AI and autonomous everything URL: https://katecarruthers.com/ai-autonomous-everything/ Last updated: 2026-04-01T03:51:21.000Z I spoke at the [Front End of Innovation (FEI) Conference](https://informaconnect.com/feiusa/?ref=katecarruthers.com) in Boston the week of 10 June about AI, innovation and the future. This post is part of a distillation of my thoughts. The future direction of Artificial Intelligence is not just AI in and of itself. It is as part of another whole thing - [autonomous systems](https://scienceexchange.caltech.edu/topics/artificial-intelligence-research/autonomous-ai-cars-drones?ref=katecarruthers.com). Now many of you may not know this about me, but I have been in the business of automating people out of jobs for a very long time (otherwise known as Information Technology 🤣). I can smell when an innovation is going to take out a lot of jobs. And AI has the smell of an innovation that will have far reaching consequences on society and our relationship to work. As I mentioned in my previous article, [AI Changes Everything](https://katecarruthers6748.live-website.com/2024/06/14/ai-changes-everything/?ref=katecarruthers.com), AI will have far reaching long term impacts on every facet of life. When most folks think about autonomous systems they think of things like self-driving cars. But self-driving systems that support a plethora of business services are coming our way. As someone who used to manage a call centre, I can tell you that the workers there often do not stick to the script for calls (in spite of a multitude of punitive and controlling techniques that are applied by management) and folks, being human, call in sick. Businesses will leap on this opportunity to get rid of workers who are seen as unreliable and around whom it is difficult to plan. Gen AI driven autonomous systems are going to replace office workers in droves. Think of it as Ask Jeeves from the 1990s on steroids. ![Ask Jeeves from 1999. In the age of AI things are going to be different.](https://katecarruthers6748.live-website.com/wp-content/uploads/2024/06/Screenshot-2024-06-15-at-11.43.00.jpg) Generative AI has had the fastest adoption curve of any technology that I have ever seen. I am part of a global Chief Data Officers (CDOs) virtual group, this group includes most of the big global brands you have ever heard of from the US, Europe, UK, Asia and Oceania. We met late in 2023 and everyone was saying they were not sure what Gen AI is or what to do with it. Fast forward to February 2024 and most CDOs in the group had at least one Gen AI app in production or not far off production. Since this group includes a large number of banks and finance companies this is an astonishingly fast adoption curve. ## AI and autonomous systems Let me be very clear: the future of AI is AI driven autonomous systems. If your job is about creating repeatable standard inputs then your job is vulnerable to replacement by autonomous AI driven RPA solutions.[Robotic process automation](https://www.ibm.com/topics/rpa?ref=katecarruthers.com) (RPA) is not a new thing, I worked on implementation of the first generation of this technology (then called Business Process Automation earlier this century). Nowadays RPA is part of the [low code apps](https://aws.amazon.com/what-is/low-code/?ref=katecarruthers.com) world. But as soon as businesses start to join up AI, especially Generative AI, with RPA they will be able to automate business processes very easily and quickly. If you look under the cover of some new products such as the new [Microsoft Recall](https://www.wired.com/story/microsoft-windows-recall-privilege-escalation/?ref=katecarruthers.com) you will soon see that it is about capturing the standard input of workers so as to better enable process automation. Gen AI is the missing piece of the puzzle that will enable the automation of all repetitive tasks. It will enable the system to capture verbal, text, and video inputs from worker and customers to drive the process automation, it will avoid the endless and ineffective decision trees that used to be required to provide an automated customer process. Gen AI will become the new front end for all of these kinds of systems. It is the missing piece because it offers the flexibility of language, since they are Large Language Models (LLMs) and it can sit flexibly at the front end of the process ready to take additional inputs in natural language. There are already a plethora of [outbound sales chatbots](https://www.zendesk.com/service/messaging/ai-chatbot-for-sales/?ref=katecarruthers.com) out there that you can just customise and launch. ## Some things we need to start thinking about Since we are moving very rapidly from this early stage of AI into the age of autonomous systems - AI + Robotic Process Automation (RPA) - there are a number of core questions we need to start thinking about. 1. What degree of agency or empowerment do we give autonomous systems? 2. When and how should we include humans into the process? 3. How do we think about the notion of autonomy? 4. How do we build for autonomy? 5. How can we ensure that the autonomous process is fair and equitable? 6. How best can interfaces with other technologies, systems and humans be done best in this context? 7. Will these systems be safe and secure? How can we assure people of this? 8. What are the metrics by which we might measure the performance and success of these systems? Stay tuned for my next instalment on innovation and the age of AI. ### AI Changes Everything URL: https://katecarruthers.com/ai-changes-everything/ Last updated: 2026-06-28T05:16:42.000Z I spoke at the [Front End of Innovation (FEI) Conference](https://informaconnect.com/feiusa/?ref=katecarruthers.com) in Boston this week about AI, innovation and the future. This post is part one of a distillation of my thoughts. The very first thing we need to understand is, to misquote [Churchill](https://winstonchurchill.org/the-life-of-churchill/war-leader/1940-1942/autumn-1942-age-68/?ref=katecarruthers.com), is that the stage of the development, implementation and monetisation of artificial intelligence that we are at is not even the end of the beginning of the age of AI. We are in the earliest of times. We are in the times when folks are running around and making bold (and largely unfounded) either utopian or dystopian pronouncements. We are in the times where businesses are trying to work out if this is a real thing they can make money from or with, or another flash in the pan like [NFTs](https://www.theverge.com/22310188/nft-explainer-what-is-blockchain-crypto-art-faq?ref=katecarruthers.com). I believe that AI will have a profound impact on the world in the long run. But, as I usually do, I will cite that we must remain mindful of Amara's Law: > Roy Amara AI will make profound changes in the way humans operate, interact with each other and machines, manufacture things, fight wars, educate the young, grow food, work and collaborate together as humans and machines, and live our lives. But we need to understand just how early we are in this process, or in this journey. In any case, it is no longer possible to put the AI genie back into its bottle. ## We are in the proto-AI stage We are in the earliest of stages of our AI journey as human beings. Let's just recap on how young this technology really is: - **1956** [Artificial Intelligence](https://home.dartmouth.edu/about/artificial-intelligence-ai-coined-dartmouth?ref=katecarruthers.com): field of computer science that seeks to create intelligent machines that can replicate or exceed human intelligence - **1997** [Machine Learning](https://www.cs.cmu.edu/~tom/mlbook.html?ref=katecarruthers.com): subset of AI that enables machines to learn from existing data and improve upon that data to make decisions or predictions - **2012** [Deep Learning](https://www.ibm.com/topics/deep-learning?ref=katecarruthers.com): a machine learning technique in which layers of neural networks are used to process data and make decisions - **2021** [Generative AI](https://en.wikipedia.org/wiki/Generative%5Fartificial%5Fintelligence?ref=katecarruthers.com): create new written, visual, video, and auditory content given prompts or existing data Firstly, let's go back to the grandfather of AI, [John McCarthy](https://www-formal.stanford.edu/jmc/whatisai.pdf?ref=katecarruthers.com) where he outlined what he was thinking of back in 1956 when they first had the idea of artificial intelligence: > “It is the science and engineering of making intelligent machines, especially intelligent computer programs. It is related to the similar task of using computers to understand human intelligence, but AI does not have to confine itself to methods that are biologically observable.” This notion of "intelligence" is one that I am pretty sure the computer scientists and engineers who invented this idea did not really attempt to deconstruct, nor did they seem to have any scientists or philosophers or ethicists on hand to help them to unpack this idea of "intelligence" and machines and what it all might mean. Aside: I want to note here that I am pretty sure that AI is going to make us question what we actually mean by intelligence. What we have always seen as intelligence seems to have merely been a kind of glibness and facility with languaage. And we are seeing with Gen AI how hollow that "intelligence" can actually be.What are some analogues in the world of technology that will help us to get a sense of where we are in the AI journey? Well let us use the time honoured technique of consulting Gartner and their famous hype cycle diagrams: ![generic Gartner hype cycle diagram](https://katecarruthers6748.live-website.com/wp-content/uploads/2024/06/Screenshot-2024-06-14-at-05.13.28.png) generic Gartner hype cycle diagram Now the most recent Gartner hype cycle for AI that I could find was this one from July 2023 in which one can see that Generative AI (Gen AI) is about to tip over into the *Trough of Disillusionment* (or as I often like to call it the [*Slough of Despond*](https://en.wikipedia.org/wiki/Slough%5Fof%5FDespond?ref=katecarruthers.com)). ![Gartner hype cycle AI July 2023](https://katecarruthers6748.live-website.com/wp-content/uploads/2024/06/Screenshot-2024-06-14-at-05.17.57.jpg) Gartner hype cycle AI July 2023 Now I do not disagree with this assessment as we are starting to see news articles like this from the BBC emerge: [AI products like Chat GPT much hyped but not much used, study says](https://www.bbc.com/news/articles/c511x4g7x7jo?ref=katecarruthers.com). And perhaps the best illustration of where we are in terms of our AI journey is this splendid diagram by Michael Burtov in [Surviving the 2024 AI Hype Cycle](https://burtov.com/surviving-the-2024-ai-hype-cycle/?ref=katecarruthers.com) (as slightly annotated by me). So before we can achieve the *Plateau of Productivity* there is a fair journey ahead in sorting out the business models, the technology, privacy, security and operational models in the use of AI. ![Surviving the 2024 AI Hype Cycle, Michael Burtov, November 28, 2023](https://katecarruthers6748.live-website.com/wp-content/uploads/2024/06/Screenshot-2024-06-14-at-05.23.36.jpg) ## Where are we now? To put this into a more familiar concept, in terms of the development of the web, I believe that in terms of the development of the internet and Web 2.0 and the development of the social web we are the [Netscape stage](https://www.nfx.com/post/next-social-era?ref=katecarruthers.com). So if we can start to position ourselves as if we are in a similar state of knowledge and understanding about AI as if we are the Netscape stage I think it will make everything a bit easier. ![Brief Social Media Timeline](https://katecarruthers6748.live-website.com/wp-content/uploads/2024/06/Screenshot-2024-06-14-at-05.32.56.jpg) Stay tuned for my next instalment on innovation and the age of AI. ### CDO Magazine’s Global Data Power Women 2024 List URL: https://katecarruthers.com/global-data-power-women-2024/ Last updated: 2026-04-01T03:51:22.000Z [CDO Magazine](https://www.cdomagazine.tech/?ref=katecarruthers.com) have just released their Global Data Power Women 2024 List (for its fourth year) to showcase the best of women leading data. I am very grateful to CDO Magazine for their recognition 🙏. My sincere thanks to my marvellous team who keep bringing my ideas to life and who remain a joy to work with 💞. Full details are here: [CDO Magazine’s Global Data Power Women 2024 List](https://lp.cdomagazine.tech/2024/global-data-power-women?ref=katecarruthers.com) ### Panel at UNSW Cyber Security Summit AI panel URL: https://katecarruthers.com/panel-at-unsw-cyber-security-summit-ai-panel/ Last updated: 2026-04-01T03:51:22.000Z ![https://www.linkedin.com/posts/rizwan-mahmood-cissp-pmp-78684519_great-insights-from-the-panel-at-unsw-cyber-activity-7201014747280871425-Fo2t](https://katecarruthers6748.live-website.com/wp-content/uploads/2024/05/1716855702466.jpg) Picture from Rizwan Mahmood, via LinkedIn Was happy to join an AI panel at the inaugural [UNSW Cyber Security Summit](https://www.inside.unsw.edu.au/campus-life/register-now-the-cyber-security-summit?ref=katecarruthers.com) today. I was lucky enough join an amazing group of panellists - AI guru [Prof. Toby Walsh](https://www.unsw.edu.au/staff/toby-walsh?ref=katecarruthers.com); UNSW CISO [Derek Winter](https://www.myit.unsw.edu.au/derek-winter?ref=katecarruthers.com); legal, cyber and privacy expert [Laura Newton](https://www.herbertsmithfreehills.com/our-people/l/laura-newton?ref=katecarruthers.com) of Freehills; and ably moderated by [Robert Buhrke](https://www.linkedin.com/in/robertbuhrke/?originalSubdomain=au&ref=katecarruthers.com). The regulatory landscape in Australia is becoming more onerous for organisations. Increasingly the Australian government is going to assume that organisations know what data they hold, where it is and how it is protected. Understanding this is key to protecting against current and future AI driven threats. Now with AI it is possible to magnify the effects of a data oops enormously. It is time for business folks to get their information and data governance in order. But there are also potential real impacts by AI driven attacks on individuals and families. My recommendations for folks to protect themselves from [phishing attacks](https://www.ibm.com/topics/phishing?ref=katecarruthers.com), video and audio [deepfakes](https://www.latimes.com/business/technology/story/2023-05-11/realtime-ai-deepfakes-how-to-protect-yourself?ref=katecarruthers.com) is to: 1. establish a family safe word or phrase to validate if it really is them who is trying to contact you 2. setup a password manager for everyone in the family (I use [Bitwarden](https://bitwarden.com/?ref=katecarruthers.com) which is open source) 3. use multi-factor authentication for every app that allows it (and not just SMS authentication as this is not the best option: [Top 5 reasons not to use SMS for multi-factor authentication](https://www.techrepublic.com/article/top-5-reasons-not-to-use-sms-for-multi-factor-authentication/?ref=katecarruthers.com)) ### Directors care about ESG now! URL: https://katecarruthers.com/directors-care-about-esg-now/ Last updated: 2026-04-01T03:51:22.000Z Was delighted to be on a panel, chaired by the amazing [Gladwin Mendez](https://datarevolution.tech/2023/06/29/its-about-people/?ref=katecarruthers.com), at the [Corinium Global Intelligence](https://www.linkedin.com/company/corinium-global-intelligence/?ref=katecarruthers.com) Chief Data and Analytics Officer conference on 8 May 2024. Our panel discussed ESG: What’s measured is managed. Nowadays relevant, timely and accurate data is critical to drive an organization's ESG agenda. But the real challenge is the amount of ESG related data that is not in any database at all. But at the end of the day Boards now care about ESG data and will be wanting to get their hands on ESG related data and reporting going forward. ### New data architectures and AI URL: https://katecarruthers.com/new-data-architectures-and-ai/ Last updated: 2026-08-08T06:19:02.000Z I have been thinking about how we manage data for a long time. And now with the rise of AI in people's imaginations it is becoming an imperative for organisations to rethink their old model of storing data in siloes. Now data is not merely a thing to be stored, it now must be able to flow. It needs to serve several purposes from a single stream: 1. Traditional business intelligence, analytics, and reporting 2. The new kids on the block - AI and ML 3. Services - being driven by low code application frameworks (things like Microsoft Power Apps, Appian, Service Now, among others) 4. Tradtional data integration And many of us have not really thought beyond our traditional operational data stores and our old fashioned data warehouses. But if we want to be ready to leverage the power of AI, Many activists, such as [Zhamak Dehghani](https://twitter.com/zhamakd?ref=katecarruthers.com), have long advocated a shift to a more decentralised way of thinking about data. As she says: > "Data mesh addresses these dimensions, founded in four principles: domain-oriented decentralized data ownership and architecture, data as a product, self-serve data infrastructure as a platform, and federated computational governance. Each principle drives a new logical view of the technical architecture and organizational structure." > > [https://martinfowler.com/articles/data-mesh-principles.html#TheGreatDivideOfData](https://martinfowler.com/articles/data-mesh-principles.html?ref=katecarruthers.com#TheGreatDivideOfData) There is a great introduction to Data Mesh by Confluent, the folks behind Kafka, [https://developer.confluent.io/courses/data-mesh/data-as-a-product/](https://developer.confluent.io/courses/data-mesh/data-as-a-product/?ref=katecarruthers.com) But, in reality I think that Bill Inmon's (aka father of the data warehouse) latest idea of the data lakehouse is the best transitional architecture to support ongoing operaitions. It is worth going to check out this [video of him talking about the idea here](https://www.youtube.com/watch?v=TgdmHw60G8A&ref=katecarruthers.com). The reason I say "transitional" is because, with AI moving so quickly, I do not believe anyone can know what our data structures are going to look like in two years. Everything is moving so fast yet I feel that tha data lakehouse is a sensible move towards the emerging future (which is probably going to be some kind of data fabric). One of the key benefits of the lakehouse architecture is that it enables the four use cases listed above of the same set of pipelines. Which is a win I am willing to take. ### Inaugural Women Leading Tech Power List URL: https://katecarruthers.com/inaugural-women-leading-tech-power-list/ Last updated: 2026-04-01T03:51:22.000Z It is an honour to be on the [Women Leading Tech Power List for 2024](https://www.bandt.com.au/meet-the-incredible-inductees-to-the-inaugural-women-leading-tech-power-list/?ref=katecarruthers.com) \- such an amazing list of women! So kind of the lovely folks at B&T and Atlassian, thank-you. More details about the nominations here: [Power List](https://www.bandt.com.au/women-leading-tech-power-list/?ref=katecarruthers.com) One of the important things to recognise is that when one gets listed on this kind of list is that it is only possible due to an amazing team of people who work very hard and deliver remarkable things. I am so proud of my team who do the hard work to bring to life the vision, and I am very grateful that they are so open to trying new things. Thank you - you all know who you are! Team work really does make the dream work. ![five team members with privacy preserving smiley faces over their real faces](https://katecarruthers6748.live-website.com/wp-content/uploads/2024/03/team.png) Part of my amazing team (with privacy preserving smiley faces as they are all very shy) ### Yarning about data visualisation: Quinn Dombrowski URL: https://katecarruthers.com/quinn-dombrowski/ Last updated: 2026-06-28T05:19:18.000Z This time my guest is the intriguing [Quinn Dombrowski](https://quinndombrowski.com/?ref=katecarruthers.com), whom I have been keeping an eye on via social media for ages due to their [Textile Makerspace](https://news.stanford.edu/2020/11/20/makerspaces-get-creative-coronavirus-pandemic/?ref=katecarruthers.com) project and general all-round niceness and humanity. We had a fascinating chat about some non-traditional approaches to data visualisation. You can even [study data visualization](https://explorecourses.stanford.edu/search?view=catalog&filter-coursestatus-Active=on&page=0&catalog=&academicYear=&q=dlcl%20203&ref=katecarruthers.com) with Quinn at Stanford, the course content sounds fascinating: > "How does something become "data", and how can we understand our data better through visualization and physicalization? This 1-credit course will explore data creation and methods for representing that data using textiles, which have a long history as a medium for capturing data. Students will get hands-on experience with different tools at the Textile Makerspace (sewing, knitting, embroidery, spinning, weaving) and create a data physicalization final project that uses skills developed during the class." > > [**DLCL 203: Data Visualization With Textiles**](https://explorecourses.stanford.edu/search?view=catalog&filter-coursestatus-Active=on&page=0&catalog=&academicYear=&q=dlcl%20203&ref=katecarruthers.com) **Note**: this title is a bit of an insider joke for Australians - for us to "yarn" means to have a chat, to talk. [Here is an explainer from ANU](https://researchportalplus.anu.edu.au/en/publications/iyarni-as-a-verb-meaning-talk-in-australian-english-varieties/?ref=katecarruthers.com). [Episode link](https://open.spotify.com/episode/5ksuvdHrhXwl2wTVG0oczp?ref=katecarruthers.com) About Quinn: > "[Quinn Dombrowski](https://quinndombrowski.com/?ref=katecarruthers.com) (non-binary, any pronouns are fine) is the Academic Technology Specialist in the [Division of Literatures, Cultures, and Languages](https://dlcl.stanford.edu/?ref=katecarruthers.com), and in the [Library](https://library.stanford.edu/research/cidr?ref=katecarruthers.com), at Stanford University. Prior to coming to Stanford in 2018, Quinn’s many DH adventures included supporting the high-performance computing cluster at UC Berkeley, running the DiRT tool directory with support from the Mellon Foundation, writing books on Drupal for Humanists and University of Chicago library graffiti, and working on the program staff of Project Bamboo, a failed digital humanities cyberinfrastructure initiative. Quinn has a BA/MA in Slavic Linguistics from the University of Chicago, and an MLIS from the University of Illinois at Urbana-Champaign. Since coming to Stanford, Quinn has supported numerous non-English DH projects, taught courses on non-English DH, started a Textile Makerspace, developed a tabletop roleplaying game to teach DH project management, explored trends in multilingual Harry Potter fanfic, and started the Data-Sitters Club, a feminist DH pedagogy and research group focused on Ann M. Martin’s 90’s girls series “The Baby-Sitters Club”. Quinn is currently co-VP of the Association for Computers and the Humanities along with Roopika Risam, and advocates for better support for DH in languages other than English." ### What NEDs need to know about AI and cyber security URL: https://katecarruthers.com/what-neds-need-to-know-about-ai-and-cyber-security/ Last updated: 2026-04-13T22:44:54.000Z By [Kate Carruthers](https://katecarruthers.com/about-kate-carruthers/) & [Kobi Leins](https://kobileins.com/?ref=katecarruthers.com) *Note: this is a republication of a old piece that Kobi and I wrote as our old website has now gone away.* ## AI and Cybersecurity Cybersecurity has been on our radar for some time as an important factor of which company directors need to take account. The cyber threat landscape has now been complicated by the advent of the widespread adoption of artificial intelligence (AI) threat actors have also adopted this new technology to power their campaigns. ## What is AI? ‘Artificial Intelligence’ is a term that has been around since 1956\. Definitions of AI abound – from the [International Standards Organisation](https://www.iso.org/artificial-intelligence/what-is-ai?ref=katecarruthers.com) to the [OECD](https://oecd.ai/en/wonk/definition?ref=katecarruthers.com) – but our personal favourite is this one from 2004 from the Australian Administrative Review Council that refers to ‘[expert systems](https://www.ag.gov.au/sites/default/files/2020-03/report-46.pdf?ref=katecarruthers.com)’, which on their plain definition are ‘computing systems that, when provided with basic information and a general set of rules for reasoning and drawing conclusions, can mimic the thought processes of a human expert.’ ## What is Cyber and Information Security? Cybersecurity and information security are two pillars of data protection. Let us first define the terms cybersecurity and information security: - Cybersecurity is the protection of data and information assets against external threats and threat actors. - Information security is the maintenance of the confidentiality, integrity and availability of an organisation’s information assets. ## What is different about AI? A couple of things. Firstly, AI is made up of mostly historical data used in ways to project into the future at speed and scale in ways that may have unintended or harmful consequences. Perhaps more importantly, data and AI embed values. Making sure that the tools you build, and use align with your vision, strategy and values from the outset is key. You might not need the expensive tool. Lower cost and risk opportunities are often the best way to build capability and understanding. ## What do I need to do to ensure that my Board is managing AI cyber risk adequately? Although there is a lot of hype around AI management and governance, a large part of this work is done if there is a solid basis of good governance already, including practices such as information technology governance and data governance. Good business practices, including risk appetites (ideally specifically for AI), risk frameworks, procurement practices, privacy, legal, accessibility, whistleblower protection, and more – if you have these in place, you are already well-placed to govern and manage AI. Where you might need to think of uplifting include: 1. Uplift in Board capability in asking the right questions about AI. 2. A specific AI risk appetite. 3. An AI policy (consultation is queen). 4. Adapting KPIs to reflect AI stance (carrot). 5. Linking AI policy to Code of Conduct directly (stick). ## Start thinking about the Three P’s: Policies, Processes and People ### Policies Policies are a great place to start to bring your business along to understanding what AI can and cannot do. Alone, they do very little. Policies need to be linked to other policies (such as the code of conduct, pay incentives, etc.) but also to processes. ### Processes One of the biggest questions is ‘what is AI and how do I review it?’. Referring to our definitions above, our recommendation is to have a wide funnel. Robodebt was an Excel spreadsheet – any ‘expert system’ that affects something else or helps to make a decision may have real-world (and legal) ramifications, so review widely. It will become clear what is higher risk as you go along. Ensure that you have clear pathways for procurement that include subject matter experts who can ask the right questions. Products are said to include AI until they work- the AI is often a sales pitch and what is sold as AI may not even be AI. Ensure robust documented due diligence of vendors. You may need extra expertise or training to enable this properly. ### People By far the most significant piece of AI management and governance is the people. Having protections (and safe culture) for those who call out risks is one of your biggest guardrails, and given the technical nature of the tools, often those at the lower levels have a much better idea of how the tools *actually* work. Think of the [Volkswagen Case](https://www.bbc.com/news/business-34324772?ref=katecarruthers.com), or the [Boeing Scandal](https://www.justice.gov/opa/pr/boeing-charged-737-max-fraud-conspiracy-and-agrees-pay-over-25-billion?ref=katecarruthers.com), the main lesson of which is to have people on your Board who understand the technology and its benefits and risks. ## Conclusion Artificial Intelligence (AI) is here, or at the very least, it is on its way. Some surveys suggest that between [42](https://newsroom.ibm.com/2024-01-10-Data-Suggests-Growth-in-Enterprise-Adoption-of-AI-is-Due-to-Widespread-Deployment-by-Early-Adopters?ref=katecarruthers.com) – [65 per cent of workers](https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai?ref=katecarruthers.com) across organisations globally are using generative AI. While these figures [may be exaggerated](https://www.economist.com/finance-and-economics/2024/07/02/what-happened-to-the-artificial-intelligence-revolution?ref=katecarruthers.com), what is clear is that companies will continue to explore the possibilities of AI. Current estimates suggest that in Australia only [10 per cent of corporate leaders](https://www.uts.edu.au/human-technology-institute/projects/ai-corporate-governance-program/governance-ai-aicd-hti-director-resources?ref=katecarruthers.com) (a mix of executives and board members) have an AI strategy, while 13 per cent of company directors have a set of AI or data ethics principles. [Less than half of corporate leaders](https://unisyd-my.sharepoint.com/personal/thomas%5Fbarrett%5Fsydney%5Fedu%5Fau/Documents/USSC%20Work%20Materials%20%28Personal%29/Research%20output/Research%20support/Externally%20Authored%20Review/If%20boards%20fail%20to%20govern%20AI,%20it%20might%20just%20do%20it%20without%20them?ref=katecarruthers.com) who are using AI said their organisation was undertaking a risk assessment of their AI use. As AI adoption increases among businesses, Boards must be prepared. ### Education, Data, and Generative AI: the future - Ray Fleming URL: https://katecarruthers.com/ray-fleming/ Last updated: 2026-06-28T05:16:07.000Z This time my guest is an old friend, Ray Fleming from [InnovateGPT](https://www.innovategpt.com.au/?ref=katecarruthers.com), who is co-host of the [AI in Education podcast](https://aipodcast.education/?ref=katecarruthers.com). And this is a joint podcast where we had a chat about the future of education in the age of AI. The podcast was a special dual-production episode between the AI and Education podcast, and the Data Revolution podcast, welcoming Ray Fleming and Kate Carruthers as the guests. The conversation centred around the transformation of the traditional data systems in education to incorporating AI. Kate Carruthers, the Chief Data and Insights Officer at the University of New South Wales, and Head of Business Intelligence for the UNSW AI Institute, discussed the use of data in the business and research-related aspects of higher education. On the other hand, Fleming, the Chief Education Officer at InnovateGPT, elaborated on the growth and potential of generative Artificial Intelligence (AI) in educational technology and its translation into successful business models in Australia. The guests pondered the potential for AI to change industries, especially higher education, and the existing barriers to AI adoption. The conversation revolved around adapting education to make use of unstructured data through AI and dealing with the implications of this paradigm shift in education. About Ray: > Ray Fleming is an industry veteran who covers topics at the intersection between Higher Education and technology. He has over 30 years’ experience, including in the roles of Higher Education Lead at Microsoft, and now as Chief Education Officer at [InnovateGPT](https://www.innovategpt.com.au/?ref=katecarruthers.com). Ray has been speaking about AI in Education since 2015\. He started this AI in Education podcast in 2019, before having to step away when he left Microsoft. In the past he's been a columnist for the Times Education Supplement, an award-winning blogger, and has featured on BBC TV. As a professional Improv player, you’ll also find Ray on stage at the Sydney Comedy Fringe Festival shows. [Episode link](https://open.spotify.com/episode/0hnbRAtutTJLResg4ockQL?ref=katecarruthers.com) ### Substack and Nazis URL: https://katecarruthers.com/substack-and-nazis/ Last updated: 2026-05-15T01:26:43.000Z As I explained earlier over on Substack I have decided to move the newsletter and website hosting ~~back to Buttondown~~ to ~~Beehiiv~~ [Ghost.org](https://ghost.org/?ref=katecarruthers.com) due to Substack's stance on Nazis. Here is some background on the matter for those who are not familiar: [Substack says it will not remove or demonetize Nazi content](https://www.theverge.com/2023/12/21/24011232/substack-nazi-moderation-demonetization-hamish-mckenzie?ref=katecarruthers.com) (Lawler, The Verge, Dec 2023). This position is antithetical to my own stance, which is that Nazis (and their fellow travellers) are always bad and we should never give them a platform and certainly not help them to monetise their activities. FYI - I have migrated all subscribers and archives back to Buttondown and have deleted all content there except my last post which is titled "Substack and Nazis. You can't be just a little bit Nazi..." And, here is the tale, via [Michael B. Tager](http://www.michaelbtager.com/?ref=katecarruthers.com) (a.k.a. BlueSky: [@IamRageSparkle](https://bsky.app/profile/iamragesparkle.bsky.social?ref=katecarruthers.com); Instagram: [@IamRageSparkle)](https://www.instagram.com/iamragesparkle/?ref=katecarruthers.com), of how you don't end up with a Nazi bar: [Bartender Savagely Kicks A Polite Nazi Customer Out Of His Bar And Explains Why It’s Important To Do So.](https://www.boredpanda.com/bar-bartender-nazi-punk-iamragesparkle/?ref=katecarruthers.com) **UPDATE 9 Jan 2024:** Not enough IMHO! Lawler, R. (2024, January 9). *Substack is going to remove five Nazi newsletters*. The Verge. [https://www.theverge.com/2024/1/8/24030756/substack-nazi-newsletter-content-moderation](https://www.theverge.com/2024/1/8/24030756/substack-nazi-newsletter-content-moderation?ref=katecarruthers.com) ![](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/04/substack-nazis-jan-2023-jpeg-w-1024.jpg) My recent Substack post (with added typos for authenticity!) ### Data needs good management - Mark Nicholls URL: https://katecarruthers.com/data-needs-good-management-mark-nicholls-episode-16/ Last updated: 2026-06-28T05:07:30.000Z This time my guest is [Mark Nicholls](https://www.informpros.com.au/about/our-team/mark-nicholls/?ref=katecarruthers.com). He is CEO of the [Information Professionals Group](https://www.informpros.com.au/?ref=katecarruthers.com) , who help businesses to leverage digital technology to achieve their business objectives. We had an excellent chat about all of the good IT practices that still need to be done to ensure that good clean data can drive our business processes to support data operations. A bit about Mark: > "With experience across almost every industry, Mark Nicholls brings more than 30 years of accumulated knowledge to each and every project, leading technology transformation within organisations across Australia. A member of the Australian Information Industry Association Board, Mark is at the forefront of technology transformation. Known for his ability to engage people at every level, he is adept at honing in on client priorities and finding the right formula to help organisations grow their way. > > [https://www.informpros.com.au/about/our-team/mark-nicholls/](https://www.informpros.com.au/about/our-team/mark-nicholls/?ref=katecarruthers.com) [Episode link](https://open.spotify.com/episode/7g5IQzaezzwEWyYAonIoHy?ref=katecarruthers.com) ### Data governance - the time is now URL: https://katecarruthers.com/data-governance-the-time-is-now/ Last updated: 2026-04-01T03:51:22.000Z For many years, since late 2014 to be precise, I have been thinking about and doing data governance. But now with the advent of popular AI it is even more important. It has always been seen as boring stuff and nobody was really that interested. But in recent times – thanks to some quite egregious data breaches – folks have realised that every organisation needs to do data governance. This is because if we’re doing data governance properly we know where our data assets are, who is using them, and how they are being used, and we can also track provenance of our data across the organisation. One thing I’ve realised in recent times is that cyber security and data governance are two sides of the same coin. Cyber is about protecting our data assets from external threats and mitigating the impact of a data breach. Data governance is about ensuring that our data holdings are managed in such a way as to mitigate the magnitude of a potential data breach. ## We’re going to need more people We are going to need more people who can understand and work in data governance. We are going to need to educate them about best practices and how to do data governance. And we are going to need leaders who understand the issues and the broader context of data leadership. To help with this I’m building a new course – [Data Governance for Leaders](https://www.unsw.edu.au/business/our-schools/agsm/learn-with-us/short-courses/data-governance-for-leaders?ref=katecarruthers.com) – at [AGSM](https://www.unsw.edu.au/business/our-schools/agsm?ref=katecarruthers.com) and it will first be delivered in July 2024. Eventually I’m planning to create a masters degree for data leadership. This is because we are educating heaps of folks in data science and data analytics but have neglected to educate the leaders that we will need. ### Data in manufacturing - Adam Sharman URL: https://katecarruthers.com/adam-sharman/ Last updated: 2026-05-15T00:28:36.000Z My guest this time is Adam Sharman from data consultants to the manufacturing sector [https://dsifer.com/](https://dsifer.com/?ref=katecarruthers.com) \- who “combine extensive experience in manufacturing, primary and food processing with world leading data analysis to help business leaders embrace the future of productivity”. We had an excellent chat about the uses of data in manufacturing businesses and, as so often, we came back to the secret sauce really being change management and understanding that at the end of the day data is about people. Episode link: [https://open.spotify.com/episode/73sWJ75FQsu0wctL8QBURz?si=FzixZZr8Td-QLEFUzlpEIg](https://open.spotify.com/episode/73sWJ75FQsu0wctL8QBURz?si=FzixZZr8Td-QLEFUzlpEIg&ref=katecarruthers.com) About Adam: > "Combining a background in business performance consulting across multiple industries and countries at Accenture and Deloitte, with on-the-ground operations experience in the world's largest dairy exporter, Adam Sharman is passionate about helping organisations optimise their businesses, drive innovation and stay ahead of a constantly evolving world. As General Manager of [Dsifer](https://dsifer.com/?ref=katecarruthers.com), Adam aims to combine the team’s data science and operational performance expertise to optimise organisational performance, build industry capability and shift perspectives on what is possible using data. With qualifications in both business operations and psychology, Adam knows the power of taking a human-centered approach to transformation for sustainable change." > > [https://dsifer.com/who-we-are/](https://dsifer.com/who-we-are/?ref=katecarruthers.com) #### Links to things we mentioned - What is digital manufacturing? [What is digital manufacturing? And how are companies harnessing it?](https://www.themanufacturer.com/articles/what-is-digital-manufacturing/?ref=katecarruthers.com) (themanufacturer.com) - Technology Investment Network Advanced Manufacturing Report (NZ): [2023 New Zealand Advanced Manufacturing Report | TIN – Technology Investment Network](https://tin100.com/reports/2023-new-zealand-advanced-manufacturing-report/?ref=katecarruthers.com) (tin100.com) - MakeUK – Digital Technologies for Manufacturing:[ Digital technologies essential for UK manufacturing to power international competitiveness but SMEs still lagging behind](https://www.makeuk.org/news-and-events/news/bouncing-back-smarter?ref=katecarruthers.com) | Make UK - Digital literacy in manufacturers: [Digital literacy will help manufacturers unlock the power of data - The Manufacturer](https://www.themanufacturer.com/articles/digital-literacy-will-help-manufacturers-unlock-the-power-of-data/?ref=katecarruthers.com) - Economic impact of data innovation: [Get the Report: Economic Impact of Data Report](https://www.splunk.com/en%5Fus/form/economic-impact-of-data.html?ref=katecarruthers.com) | Splunk ### Ethics and data in games - Catherine Flick URL: https://katecarruthers.com/catherine-flick/ Last updated: 2026-06-28T05:06:59.000Z My guest for this episode is the charming and erudite [Catherine Flick](https://liedra.net/?ref=katecarruthers.com), who is an ethics researcher (and newly minted Professor) working with the [Digital Observatory Research Cluster](https://digitalobservatory.com/?ref=katecarruthers.com). We have been friends on social media for ages, most recently on the dear departed [Pebble](https://techcrunch.com/2023/10/24/pebble-the-twitter-alternative-previously-known-as-t2-is-closing-down/?ref=katecarruthers.com), and this was our first chance to chat. We had a fascinating discussion about her research findings using access to a unique and large gaming dataset. > "Dr. Catherine Flick graduated with a BSc with majors in Computer Science and History & Philosophy of Science, Sydney University, Australia, while working in industry as a systems administrator and web programmer. She completed her Honours year with a thesis on Trusted Computing in History & Philosophy of Science (First Class), at Sydney University, Australia. Her PhD was on the topic of Informed Consent in ICT, at the Centre for Applied Philosophy and Public Ethics, Charles Sturt University, Australia. Areas of research have involved ethics and video games, responsible research and innovation in technology, anonymous technologies, trusted computing, and informed consent in IT. " > > [Dr Catherine Flick](https://www.dmu.ac.uk/about-dmu/academic-staff/technology/catherine-flick/catherine-flick.aspx?ref=katecarruthers.com) [Episode link](https://open.spotify.com/episode/2dm83enW6WbBrrzXEpiGem?ref=katecarruthers.com) #### Links to things we mentioned [Digital Observatory Research Cluster](https://digitalobservatory.com/?ref=katecarruthers.com) David Zendle, Catherine Flick, Darel Halgarth, Nicholas Ballou, Simon Demediuk and Anders Drachen. 2023: *Cross-cultural patterns in mobile playtime: an analysis of 118 billion hours of human data*. Sci Rep 13, 386\. [https://doi.org/10.1038/s41598-022-26730-w](https://doi.org/10.1038/s41598-022-26730-w?ref=katecarruthers.com) David Zendle, Catherine Flick, Sebastian Deterding, Joe Cutting, Elena Gordon-Petrovskaya, and Anders Drachen. 2023: *The Many Faces of Monetisation: Understanding the Diversity and Extremity of Player Spending in Mobile Games via Massive-scale Transactional Analysis*. ACM Games 1, 1, Article 4 (March 2023), 28 pages. [https://doi.org/10.1145/3582927](https://doi.org/10.1145/3582927?ref=katecarruthers.com) David Zendle, Catherine Flick, Darel Halgarth, Nicholas Ballou, Joe Cutting, and Anders Drachen. 2023: *The Relationship between lockdowns and video game playtime: A multilevel time-series analysis using massive-scale telemetry*. J Med Internet Res (forthcoming). [http://dx.doi.org/10.2196/40190](http://dx.doi.org/10.2196/40190?ref=katecarruthers.com) [Pebble, the Twitter alternative previously known as T2, is shutting down](https://techcrunch.com/2023/10/24/pebble-the-twitter-alternative-previously-known-as-t2-is-closing-down/?ref=katecarruthers.com) ### Raising heretics - Linda McIver URL: https://katecarruthers.com/raising-heretics-linda-mciver-episode-13/ Last updated: 2026-06-28T05:21:15.000Z This time my guest is the remarkable [Dr Linda McIver](https://adsei.org/director/?ref=katecarruthers.com), who is the CEO of the [Australian Data Science Education Institute](https://adsei.org/?ref=katecarruthers.com). We had a wide-ranging chat about the importance of educating the rising generation to make sense of data in the in the modern world. And, even though we did not talk explicitly about her book, [*Raising Heretics: Teaching Kids to Change the World*](https://adsei.org/raising-heretics-how-data-science-education-can-change-the-world/?ref=katecarruthers.com) , it really underpinned our conversation. Linda has been thinking about the challenges of educating kids in data and technology for a long while and has a lot of great ideas that we can leverage. > "Linda McIver is a "passionate educator, researcher and advocate for STEM, equity and inclusion, with a PhD in Computer Science Education and extensive teaching experience, Linda’s mission is to ensure that all Australian students have the opportunity to learn STEM and Data Science skills in the context of projects that empower them to solve problems and make a positive difference to the world." > > https://adsei.org/director/ [Episode link](https://open.spotify.com/episode/57oV8fNXbceWRLE6X9EOOJ?ref=katecarruthers.com) ### Links to things we mentioned - Laura Summers' Ethics Litmus Test: [https://www.ethical-litmus.site/](https://www.ethical-litmus.site/?ref=katecarruthers.com) and her related Sweet Summer Child Score: [https://summerchild.dev/](https://summerchild.dev/?ref=katecarruthers.com) - ADSEI website: [https://adsei.org](https://adsei.org/?ref=katecarruthers.com) - Raising Heretics: Teaching Kids to Change the World: [https://adsei.org/raising-heretics-how-data-science-education-can-change-the-world/](https://adsei.org/raising-heretics-how-data-science-education-can-change-the-world/?ref=katecarruthers.com) - Make Me Data Literate: [https://adsei.org/podcast/](https://adsei.org/podcast/?ref=katecarruthers.com) ### Identity is all about data - Steve Wilson URL: https://katecarruthers.com/steve-wilson/ Last updated: 2026-06-28T05:25:31.000Z My guest for this episode is [Steve Wilson](https://lockstep.com.au/about/stephen-wilson/?ref=katecarruthers.com) from Lockstep. He is my go-to human for all things relating to identity. As we were contemplating this episode we started talking about identity (which might not actually be the best word for it) and then Steve said "identity is all about data" and that is where our discussion started. ![Stephen Wilson](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/04/wilson_stephen-w-287.jpg) Steve Wilson > "Steve is a researcher, innovator and analyst in data protection. He has been a lead digital identity adviser to the governments of Australia, Hong Kong, Indonesia, Kazakhstan, Macau, New Zealand, and Singapore, and has been awarded 10 patents. In 2018, he was [**described by digital ethnographer Tricia Wang**](https://www.constellationr.com/media/pcdf-futures-panel-internet-and-corporate-responsibility?ref=katecarruthers.com) as “one of the most original thinkers in digital identity in the world today”. Starting in public key infrastructure in 1995, Steve saw the potential for this technology in digital credentials. In 2004, he was awarded his first patent for anonymously verifiable attributes. In 2011, he discovered an ecological explanation for the diversity of digital identities as ensembles of attributes, which in turn convinced him that all digital identity boils down to data." > > [https://lockstep.com.au/about/stephen-wilson/](https://lockstep.com.au/about/stephen-wilson/?ref=katecarruthers.com) [Episode link](https://open.spotify.com/episode/1bp1Bi5WgJMPB6UWLMI5qP?ref=katecarruthers.com) ### Links to things we mentioned [Lockstep - Data Verification Platform](https://lockstep.com.au/dvp/?ref=katecarruthers.com) ### Transcript Kate Carruthers \[00:00:01\]: Hi, and welcome to this episode of the Data Revolution podcast. I'm Kate Carruthers, and my guest today is Steve Wilson. Steve Wilson \[00:00:09\]: Hello, Kate. Kate Carruthers \[00:00:10\]: Oh, hello. I'm going to introduce you Steve. Steve is an original thinker whose research achievements include six US. Patents, three in public key security, and three in biomedical technology. He a researcher, an innovator, and an analyst in data protection. And he's been a lead digital identity advisor to governments around the world. And he has been awarded ten patents. There were six before, now there's ten. Anyway, he is somebody who is one of my go to people for things around data protection and security. Welcome to the show, Steve. Steve Wilson \[00:00:48\]: Well again. G'day, Kate. Good to see you. Thanks for having me. Kate Carruthers \[00:00:53\]: I was just pondering how we met, and I actually think my very dear friend Stilgherrian introduced us. Probably a long time ago. Steve Wilson \[00:01:03\]: Could be. I floated around UNSW for a long time. I started a post grad course there some time ago. And love UNSW. You love people like you. So yeah, there would have been lots of intersections, I'm sure. Kate Carruthers \[00:01:22\]: So what are we going to talk about today? Steve Wilson \[00:01:25\]: Well, I love this all power to data theme of yours and the way that you are digging up so many important lessons in your professional background in data, and it's all being reinvented. So there's many ways in I like to unpack how important data is in the economy. I nearly said digital economy, but we're dropping the digital now, aren't we? Kate Carruthers \[00:01:52\]: The digital economy and the economy are the same thing now. Steve Wilson \[00:01:56\]: So look, there's a number of ways into the topic, but I'm working a lot at the moment on and thinking a lot about how do we protect data at a level that is commensurate with its value. So whether you think that data is like the new crude oil or not, like every metaphor, that one's a bit radioactive. It's got strengths and weaknesses. But look, data is important and we don't protect it, and I think that we should. Kate Carruthers \[00:02:24\]: And that is a really good point. Because if you think about data as an asset, you've also got to think about it as a liability. And it's the two sides of the one coin now, because if you keep too much data and you don't protect it adequately, you can have a data breach, which I've been in every major data breach in Australia in the last twelve months. Steve Wilson \[00:02:46\]: And it's not theoretical. These data breaches are not fantasy. In fact, they've become in a way, they've become a little bit mundane. And that's so dangerous. Security geeks like to say data breaches are inevitable. And I tell you what, my head explodes. I don't know why we think that it's cool to just accept that sort of thing. It's horrible to accept any level of data breaches, let alone to say we're all going to be breached. Get over it. Kate Carruthers \[00:03:15\]: Well, I always feel a strange sort of kinship with the people who've been breached, because a lot of the time I've been in it, and I've been one of the people saying we need to invest and been told no. And I'm pretty sure that most of those organizations had people who wanted to invest in protecting the data and were told no. So I do have some sympathy for some of the people in those organizations. Steve Wilson \[00:03:41\]: But yeah, 100%, it's a wicked job. It security and cybersecurity in general. But what is it that makes data valuable? I think that that's really important. We've got this vague idea of data protection, which in the rest of the world is synonymous with data privacy. The GDPR has data protection in its name, and while in Australia we do privacy impact assessments, in Europe they do data protection impact assessments. So privacy and data protection are really literally synonymous in a lot of the literature. But I think that what we do in data protection. I mean, I love it. I'm actually one of the rare technologists who advocates for data privacy principles and data privacy law, but I think it's only a model. Like, it's only a start. Data privacy boils down to a set of principles that are about limiting the collection of personal information, limiting the use of personal information, limiting the disclosure, not banning collection, use and disclosure, but limiting it and being transparent and getting rid of data when you finish with it. And all of this stuff actually turns out to be pretty bloody good idea in the light of data breaches. But I think that it's just a start. There's a default assumption that data is valuable and you should keep it close, but it's not a very artful way of looking at the value of data. We actually want to share data, not only as businesses and governments and researchers, but I mean, think about it. Individuals absolutely need to share data, partly because social media and just being social requires you to talk about yourself, but also to get digital services. You need to tell people stuff. You need to share your shopping history. Kate Carruthers \[00:05:45\]: Is we want to take friction out of our processes, and the way we can take friction out of our processes is data and automation. So we need to share our data to make that, you know, who wants to go back to the bad old days? I can remember going to the Department of Motor Transport back in the day and being in the queue and with pieces of paper and stuff, and now it's miraculous. With service New South Wales, you can do it all on your phone. You don't have to talk to anybody. And that's powered by. Steve Wilson \[00:06:15\]: Some. It's a modern miracle. Some of that stuff and data sharing and data disclosures got a bad rap. And some of the data brokers have really poisoned the well, haven't they? They've made data sharing synonymous with data surveillance and surveillance capitalism. And that's kind of sad because you can't live under a rock. I mean, civilized people want I mean, to be really blunt, I want my doctor to know stuff about me. And if the doctor thinks it's in my interest for the nurse to know the same things about me, then I need to trust the doctor to be sharing data behind my back. Kate Carruthers \[00:06:56\]: COVID helped me get over my aversion to electronic health record because you were going to doctors and I was just like, they need to know. I need to just let them have it. Steve Wilson \[00:07:07\]: Right, but you must have in the back of your mind some comfort that there's professional standards for medical providers, don't you? It's different telling your doctor your history. Kate Carruthers \[00:07:18\]: I know one of my mates does tech support for my local GP office - Terrifying. Steve Wilson \[00:07:28\]: Yeah, there's a lot of sausage making going on in general practice software that's. Kate Carruthers \[00:07:32\]: You know, they're essentially small business, and small businesses really have no idea about data protection and data security. So there's large swathes of the Australian economy that are unprotected working, as I do in a big organization that's working on things like the security of critical infrastructure and privacy legislation and stuff. We can forget that there are organizations that don't even know that these things exist or know how to even approach data security. Steve Wilson \[00:08:06\]: Yeah, we set people up to fail, especially in small business and in general practice. But another thing to talk about is the mental models that people have for data and how it works and what does it mean to control data. Can we have a reasonable expectation that people can control data for themselves? So I've been in can I talk about identity? Kate Carruthers \[00:08:37\]: I think it's an important part of the fabric of the data worldview. The bits that I think are important. There's the data, the storage, there's the integration of data sources. There's the identity and access management. There's knowing who the individual is. So master data management so that you get a golden record so you know who you're talking to. So I see all of that as a big part of the data landscape that we need to master. Steve Wilson \[00:09:05\]: Yeah. And it boils down to context, isn't it? Like, what do you need to know about people in different contexts? You talk about a master record or a golden record, but that's going to be a different record from context to context, isn't it? Kate Carruthers \[00:09:21\]: That's one of the things we're talking about at work, is how can we make contextually relevant information about individuals available in a context and do it safely and securely? Steve Wilson \[00:09:34\]: Yeah. Now, that's one of the cool things about some of the tech that's emerging, like the Verifiable credentials. Technology is wonderful. Kate Carruthers \[00:09:42\]: Explain what that means because not everybody will know what that means. And I'm really interested to talk about this. Steve Wilson \[00:09:48\]: Okay, so we all know what credentials are in real life. I think, like a university credential or a Credential a passport to drive a car or a passport is like a Credential to cross borders. And the Verifiable credentials movement is partly about digitizing those things in a reliable, high quality way. So not just taking photocopies or scans or copying down numbers, but actually capturing the metadata about who issued a Credential, when was it issued, what are the rules and terms and conditions for a Credential? If you claiming to be an accountant, that's sort of interesting, but what's the metadata? What's your scope of practice? Where were you qualified? Where are you licensed to work? So you can wrap all of that stuff into a digital document and you can try and format it to be machine readable, that's kind of straightforward, and you can digitally sign it by the issuer. So it's tamper resistant and it's got provenance. You know exactly that. It's come from the Australian chartered accountants people, rather than the American, for example. So I'm building up this picture that the Verifiable Credential is partly a digitization, partly a signature of the issuer, so you know where it's come from. The final twist in this is that if you issue a Credential to the right sort of end user wallet, then when it's in the right hands, you can prove that it's in the right hands. You can prove that when somebody rocks up to a website and says, hey, I'm an accountant from Australia, you can actually also prove that the right person was in charge of the presentation. So, look, accountants, that's a bit sort of eerie theory, but what about proof of age? This is really important in Australia. We've got a whole lot of state and federal initiatives to require proof of age for when you're buying liquor online, for example. These are rules that are going to be legislated in the next few months. So it's a wicked problem. How do I prove that I'm over 18 without proving everything else about myself? I don't want to necessarily talk about how old I am or where I live or whatever. I just want to prove one fact about myself, which is that I'm legitimate to buy a Grog. That's a really important use case. Kate Carruthers \[00:12:14\]: But it is in Australia. Yeah. Steve Wilson \[00:12:17\]: Now, is it the grog or the law that you're talking about? Kate Carruthers \[00:12:20\]: I think I think the the purchasing of booze in Australia is an important cultural thing. Steve Wilson \[00:12:26\]: It's critical infrastructure. The final part of this Verifiable Credential story is really important, that the liquor store wants to know as well as a can, that if somebody's claiming to be over 18, that Credential is in the right hand. So that's called proof of presentation or proof of ownership. Now, it all boils down to cryptography. So the credential is digitally signed by the know government or New South Wales Driver Licensing Bureau. They sign the certificate, but then when you present it, you sign it again using some sort of wallet technology. Now, all of that, again, might sound theoretical, but we've been using this technology for ten or 15 years in chip cards and we've been using it for the last three years in mobile phone wallets. So under the covers, when you've got click to Pay in your iPhone, and I'm going to talk about iPhone, because that's just me, but it's exactly the same for Google. If you click to Pay in a mobile phone app, it reaches inside the secure element of your phone, it pulls out some data relating to your Visa or Mastercard or Amex card that has been loaded with your consent and with the consent of the bank. Kate Carruthers \[00:13:44\]: I verified one card this morning. Steve Wilson \[00:13:47\]: There you go. Now, when you click to Present or click to Pay, your phone is doing some magic cryptography under the covers. It's also digitally signing on behalf of yourself and sending it off to the merchant. So the merchant gets a cryptographic parcel of information, data and metadata, and the merchant goes, OK, look, I've got the credit card number, I've got it from Steve Wilson. I've also actually got it from Steve Wilson's iPhone. They can actually tell what iPhone I'm using now. That's goodness. Because they know that the phone's been unlocked by the person who owns the. Kate Carruthers \[00:14:21\]: Phone, which is, this is all great and good for us, but one of the things we have to do is trust the people to whom we give that data, don't we? Steve Wilson \[00:14:32\]: Oh, yeah. So first thing is give them as little as possible. Disclosure minimization is like a really important rule. I don't want to tell the liquor store anything more than, well, ideally, my credit card number, my delivery address and the fact that I'm over 18. Kate Carruthers \[00:14:49\]: So they don't even need to know your year of birth or anything, they just need to know, yes, this person's allowed to buy booze in Australia. Steve Wilson \[00:14:57\]: Yeah. Kate Carruthers \[00:15:00\]: This is one of the things I always feel really uncomfortable when I go to an RSL club. I don't go very often. It's usually there's some kind of meeting there and I have to hand over my driver's license and they scan it and I just hate that. Steve Wilson \[00:15:16\]: Yeah, I was there last week, we had something local in the golf club and I was that guy in the queue that held things up while I said, you're not scanning my driver's license because on the front of your license is the licensed card number. Kate Carruthers \[00:15:29\]: Yeah. Steve Wilson \[00:15:30\]: So I said, I'd rather type in all of the information that you really need. And I did that. That's so important. What sort of database is being run at a golf club? How hackable is that? It's terrible. Kate Carruthers \[00:15:46\]: If the government is going to regulate anything, they should regulate this kind of stuff. They should regulate data minimization, where they just need to know that I don't live within 5 miles. 5 over 18\. They're the only two facts they need to know. About me. Steve Wilson \[00:16:06\]: Exactly. Kate Carruthers \[00:16:07\]: So it goes back to your thing of context and relevance. Steve Wilson \[00:16:11\]: Yeah. And in New South Wales. We're getting really close. The digital driver's license is leading to a digital identity. I wish they wouldn't call it that because it's actually a lot less than identity. When this thing's up and running, it's been piloted and it's working fairly well, but it's really a collection of factoids, and I think we've got to stop calling that identity. The fact that I'm over 18 and lift ten KS away, that's not my identity. It's just a really important attribute, and I can prove it using the New South Wales technology. Kate Carruthers \[00:16:46\]: People are going to call it an identity because. Steve Wilson \[00:16:52\]: The trouble is that there's two different sorts of identity. My identity is Steve Wilson biological entity, and I feel that strongly, and it's analog and it's biological and it's social, and it's me. And everybody else can bugger off, and my identity is sovereign. But that's not what we're dealing with online. Online, we're dealing with a whole lot of little factoids that are relevant in different contexts, and it's so different from identity that I've been in Identity for nearly 30 years, and it's the slowest corner of it by miles. We have been having the same arguments about digital identity for 15 years, and it's slow because we make it too complicated, and it's slow because we call it identity. I mean, I'm just going to be quite blunt about that. Kate Carruthers \[00:17:39\]: It's not what should we call it? Steve Wilson \[00:17:41\]: We should call it attributes or facts and figures or credentials. That's great. If I'm an accountant and I need to sign off an audit report, or I tell you what, if I'm a homeowner and somebody comes to the door to fix my pipes and they're a plumber, I don't want to know anything about that person other than the fact that they're a licensed plumber and that. Kate Carruthers \[00:18:03\]: They have no complaints against them. Steve Wilson \[00:18:06\]: Yeah, okay. That's good, too. That's good. Now you got to stitch all that stuff together accurately so that you index the data properly so you know that it applies to the right person. But if a plumber came to your door and you said, Show me your identity, they'd probably be insulted because they just want to show you that they're a plumber. So when you say, what do we call it? I just think it's incredibly lazy that we keep calling this constellation effects and Figures Identity because it's so not Identity. Kate Carruthers \[00:18:38\]: I just remember back when we were talking about Web 2.0, which was the stupid and wrong name for that, and we got stuck with it. And then there was Web 3.0, which was allegedly crypto and digital currencies and stuff, which was also a wrong and stupid name. So there are so many wrong and stupid names out there. Steve Wilson \[00:18:59\]: Yes. And we don't seem to have the sort of temerity to fix that. What's in a name? A lot, especially when you're playing with identity. And it crosses between laypeople and deeply technical people, and it crosses over between professions and citizens and government regulators. I think it's really important that we call a spade a spade, and we know there's too much identity information out there. Look at the optus breach. It is ridiculous that I am vulnerable because some facts and figures of mine have fallen into the dark web. It is ridiculous that people can just play my numbers behind my back and assume my identity. It's ridiculous. So there's so much identity sloshing around out there. Why don't we just try to minimize identity? And the first step is to call it what it is and it's data. It's facts and figures. Kate Carruthers \[00:20:02\]: Like some of those recent data breaches, I can't remember which one now, one. Steve Wilson \[00:20:06\]: Of them was, I know what you. Kate Carruthers \[00:20:09\]: Did there, but one of them was they were using production data in a test environment and hadn't secured their test environment adequately. And my blood runs cold when I think of how many organizations that would fit, because a lot of the times they don't apply all the same controls to non production environments. So if I was a bad person, I'd be out there poking around at people's test environments for sure. Steve Wilson \[00:20:40\]: I started a lot of my career before identity in medical devices. And there was a horror story of a medical they're called pacemaker programmers. They're special purpose modified PCs, modified laptops that doctors use to interrogate upload data from a pacemaker and reprogram its parameters. And a really famous pacemaker. Hacker got out on ebay, found one of these things for a $1,000, bought it overrode the normal login. Just got into Dos and found that on the hard drive was the complete test environment and a whole lot of devcode. And the passwords for the dev environment that had been copied onto the hard drive of this medical device. Unbelievable. Kate Carruthers \[00:21:28\]: Yeah. I think that there is genuinely so much bad practice on a customary level out there in It land where developers have done stuff like that without thinking about it, because there was not any perceived risk. But now that you don't have to rob banks, you used to have to rob banks to make money, and now you can sit at home in your pajamas in your mother's basement and just get online and do the equivalent of robbing banks. So there's a real incentive for people to work out where weak spots are like that. So a lot of our practices in It are really bad and need a severe yeah, yeah. Steve Wilson \[00:22:14\]: We need to take a hard look at ourselves, don't we, kate thing about sitting in your basement doing identity theft, it reminds me of another point about the quality of data. All of that stolen data gets replayed know your customer processes. So to open a new online bank account, all I need to know is somebody's birth certificate and passport and driver's license. Now, nobody does that online. Nobody does it face to face anymore, as far as I know. Criminals don't go down to the back blocks and buy fake passports for $100 and fake driver's licenses for $50 and then rock up to the local suburban bank branch and open a bank account. I don't think anybody does that anymore. Instead, you can buy the same data online for about a 10th of the price as the going rate. Now, what's interesting to me is that the KYC process is still the same. The bank still just wants to know four or five facts about you in an algorithm that then says it's probably Steve Wilson and it's good enough. So the problem with so called identity theft is that it's actually data theft. People don't steal Steve Wilson's identity. They just steal enough facts and figures about me that they can pretend to be me online. And this is all about data. So when the government responds, I'm so divided in my opinion about this. I love that our government is responding with real muscles against the optus breach and doing something about it. But it disturbs me that they seem to be moving towards the national ID as a response to this, because we don't need any new ID. What we need to do is to make our existing identity facts and figures better so that they can't be replayed. So I like to say that we don't have any identity problem in the wake of the optus bridge, we've got a data problem. And I wish that we were really sort of focused about that, because if we could solve the provenance of data for identification purposes, then oh my God, you could solve the provenance of data in the AI world that we're all worried about, or we're worried about who's training the data, where's the data coming from. We're worried about algorithmic transparency. So when a credit rating is made or an insurance rating is made, and it's not in my favor, I'd like to know what the algorithm is. Well, we could know that we could stamp all of these analytics processes with the algorithm, and we could stamp it with the governance of the data. So there's this pattern in my mind that all of these problems boil down to data and metadata. We live on data. We need to have better data quality, and we could actually measure data quality, and we could imprint the data quality like a hallmark on every piece of data that matters in a fairly straightforward way. As they say. We have technology just pick up on. Kate Carruthers \[00:25:20\]: Something that you just mentioned. Traditionally, when we recommend people start to use multifactor authentication, we do it because there's another factor that is not inherent in the thing itself. So it's typically something you know, something you have and something you ask your identity. One of the things we probably need is something that I have that I can say, this is really me. It's not some stranger. What we're probably going to have to be able to do is take that kind of a multifactor authentication approach into the identity world so that we can avoid this problem of someone pretending to be you or me online, opening up a new bank account with the stuff they got off the dark Web. And it's the additional factors of, yes, some facts about yourself, but some other things that only I know. Steve Wilson \[00:26:30\]: So are you going towards the proof of humanness kind of issue and the World Coin project and they're trying no. Kate Carruthers \[00:26:38\]: I don't want to go that way because I think that's just creating a very large honeypot for someone to steal. But increasingly we're going to have to solve this. And I think that a lot of the approaches don't allow for anything outside of facts. These things that you're referring to as facts and facts are very easy to get hold of in our world because they're data and people steal data. Steve Wilson \[00:27:07\]: This is exactly my mission locate or my passion, because data can be stolen. You need that extra layer of metadata that says, well, look, it's not just a fact. My driver's license is 1234 XYZ. But when that string comes across the Internet and hits a website, it can also be signed by me. So the web server knows that it's come from a person in control of a private key that's certified and bound. Kate Carruthers \[00:27:36\]: Which is the other factor that I'm talking about. Do you want to unpack that for folks? Because I'm not sure everyone will understand what we're talking about. Steve Wilson \[00:27:43\]: Well, it's back to this digital signature thing. A digital signature is an extra code. I actually call it metadata. In itself, it's meaningless. It's just literally like 256 ones and zeros. But it's a code that's generated from a cryptographic key in a secure element, which is your phone hardware or a chip card. The signature is processed on the core data. So if I want to prove my credit card number, I sign that in my iPhone, the credit card number. And that signature code goes across the network and it hits the server. The merchant server. The merchant server uses a public key. It's like a master key to undo the signature. And it sees that it matches two things. The signature matches the hardware that it came from and the signature matches that credit card number. So you get some programmatic logic. You get a rule that can be in the software at the merchant that says if that signature code checks out, then I know that this credit card number has been presented by the guy that controls the credit card. And that pattern has been with us for a very long time in payments. And like I say, it's been very popular in Apple Pay and Google Pay now for about three or four years. In wallets. It's exactly the same pattern that we need to present any important data. And if you had, then nobody would be vulnerable. After the Office breach, have you considered. Kate Carruthers \[00:29:17\]: How you might mesh something like homomorphic encryption into that world? Steve Wilson \[00:29:24\]: Sure, it's an extra layer. So I think the important layer is the bottom layer that says, this is the provenance of the data. We know where it's come from. Kate Carruthers \[00:29:33\]: Yeah. Steve Wilson \[00:29:34\]: So you build up on top of that and say, well, let's make the data even more secure, like defense and depth. Homomorphic encryption is a clever way of scrambling the data so that. Kate Carruthers \[00:29:46\]: I might just explain that for people, because not everybody probably knows what homomorphic encryption is. It's something that Ian, Opperman and I are really obsessed with at the moment. So homomorphic encryption is a form of encryption that allows people to do computations on encrypted underlying data without the need to decrypt it. So that's what it is. And I was just thinking that if you took what Steve said and put that together, it would be a really nice package because we're putting a lot of trust in our phones to do this for us. Steve Wilson \[00:30:23\]: We sure are. We put our lives into our phones now. It's the sort of fulcrum for everything that we do. Kate Carruthers \[00:30:30\]: Yeah, I grab my phone rather than my wallet now because everything's on my phone. Steve Wilson \[00:30:35\]: Yeah. I love that you're doing homomorphic encryption with Ian because it is that extra layer of it's the absolute way of minimizing disclosure, because if homomorphic encryption works, then you don't ever need to unscramble the data. That's why I love it. Kate Carruthers \[00:30:51\]: I'm fascinated by it and I think it's one of the really big future things. So one other question, because I need to let you go, is how do you see this sort of playing out in the real world? Is this likely to be something like people are pursuing the national identity, the state identity and all of that stuff? Do you see the stuff that you're talking about becoming? How will it play into that space, do you think? Steve Wilson \[00:31:22\]: Well, we've got these patterns that people are used to now, like click to pay and tap to pay. The very same technology could present any facts and figures using the same cryptographic, wrapping and signatures, so that when you present some code online to the other side of the world, the server knows that it's come from Steve Wilson with my consent. And it's different data for different contexts. So if I need to prove my age, then the relying party. The rule is I'll trust in the age. If it comes from a license authority or if I'm trying to claim that I have a particular health condition and I want to quote my health Identifier, then that is a totally different fact and it needs to come from a totally different context. But we've sorted this out for payments, a merchant anywhere in the world can accept. My credit card without knowing me or even my bank because of this layers and layers of governance. So I think it's going to play out in a really mundane way. I can see my smartphone wallet having verifiable credentials for maybe 20 or 25 facts and figures that matter every month. And those facts and figures are issued from respective issuers. They're not issued by Apple. They're not issued by the bank. They're issued by different communities of interest. Now what you need to do is to distribute the metadata that allows all of this to be unpacked and digested. Now, the payment system distributes metadata through merchant banks. Acquiring banks set merchants up to accept Amex or Diners or Visa or Amex. Kate Carruthers \[00:33:11\]: I know it all too well, right? Steve Wilson \[00:33:14\]: Well, what that involves is the merchant has privileges into the network through their own bank, the so called merchant bank. And the merchant bank signs them up to a set of terms and conditions and a standard contract. And the merchant bank also provides a gateway. And in that gateway is the metadata that allows a merchant to know the difference between a Mastercard and a Visa card and an Amex card. It's a really elegant technical model for distributing the metadata so that credit cards make sense. Kate Carruthers \[00:33:46\]: Who would have thought credit cards will save us in the future? Steve Wilson \[00:33:54\]: This is going to sound really sort of pathological. They are my inspiration. I don't want Visa and Mastercard to run this network. I think it's got to be a new network. But we do look at what they have done, is that they've made these very important facts and figures absolutely digestible anywhere in the world. It's a technological marvel that I can go to Mongolia and buy a souvenir with an Australian bank issued Mastercard. Yeah, think about that. How the hell does the be really. Kate Carruthers \[00:34:29\]: Good if our identity was as easy to use as that? So that really great note. Really appreciate your time this evening. Steve Wilson \[00:34:42\]: Great pleasure. Kate. Thanks for digging in. ### The Big Five Data Questions URL: https://katecarruthers.com/five-data-questions/ Last updated: 2026-06-28T05:24:53.000Z If you are not sure why you even need to do data governance there are a number of articles and vidoes [here](https://katecarruthers.com/tag/data-governance/). But if you are wondering how to get a handle on how big of a problem you have then here are the big five questions to ask about your data. I got these questions from [Mike Burgess](https://en.wikipedia.org/wiki/Mike%5FBurgess%5F%28intelligence%5Fchief%29?ref=katecarruthers.com), who was then CISO for Telstra (and who is now grand poo-bah at ASIO), and I thought at the time that they were the right questions to ask. These five simple questions underpinned the start of our [data governance journey at the University of New South Wales](https://www.datagovernance.unsw.edu.au/five-knows?ref=katecarruthers.com) back in 2014. 1. Do you know the value of your data? 2. Do you know who has access to your data? 3. Do you know where your data is? 4. Do you know who is protecting your data? 5. Do you know how well your data is protected? In pre-covid times I used to have a laminated sheet with these questions on it, and I used to carry it around with me and I wandered around the University talking to people about data governance. Often, as I would chat with folks, they would say things like "I don't need data governance", and I would simply say "that's ok, just tell me that you know the answers to these questions and I will leave you to it". Typically it would end up with them sobbing on my shoulder while we had a chat about which questions troubled them the most. Seriously, this is one of the simplest tools, but it is one of the best ones to start a sensible conversation with folks about their data and how well it is being looked after. ![the five knows of data in a diagram](https://storage.ghost.io/c/73/9e/739e1c52-4372-4113-9798-c15339da44db/content/images/2026/06/Data-Governance-a-work-in-progress-17-320--1-.webp) ### A rambling chat - Kobi Leins URL: https://katecarruthers.com/a-rambling-chat-kobi-leins-episode-11/ Last updated: 2026-05-15T00:31:56.000Z ![Kobi Leins](https://datarevolutiontech.wordpress.com/wp-content/uploads/2023/09/2021-kobi-leins-profile-pic.jpg?w=300) Kobi Leins To be fair it has been a hellish month at work so I decided to do a low key chat with a mate because I'm tired. This time my guest is Kobi Leins. > "**Dr Kobi Leins (GAICD)* is a global expert in AI, international law and governance. Leins provides strategic advice on selection, implementation and operation of technologies to drive business edge; creates systems for organisational and delegation of ownership for complex systems and data; and uses international benchmarking to analyse opportunities and risks in face of rapidly changing legal and governance landscapes and data literacy and public sentiment.* *Leins is an Honorary Senior Fellow of King’s College, London; Advisory Board Member of the Carnegie AI and Equality Initiative; Member of Standards Australia as a technical expert on the International Standards Organisation’s work on AI Standards; Affiliate, ARC Centre of Excellence for Automated Decision-Making and Society; and former Non-Resident Fellow of the United Nations Institute for Disarmament Research. Leins is the author of* [*New War Technologies and International Law:*](https://www.cambridge.org/core/books/new-war-technologies-and-international-law/D74B3EBE395B68B912B016EBFDA7D275?ref=katecarruthers.com) > [*The Legal Limits to Weaponising Nanomaterials, Cambridge University Press (2022)*](https://www.cambridge.org/core/books/new-war-technologies-and-international-law/D74B3EBE395B68B912B016EBFDA7D275?ref=katecarruthers.com)*.*" [Kobi Leins](https://kobileins.com/?ref=katecarruthers.com) We have known each other for years online and finally met IRL recently on panel and got on so well we decided to have a chat here. It had been a hard week for both of us so, armed with a glass of wine and a large dinosaur mug of Yorkshire Gold tea (it really is the best tea and I have no affiliation with this brand), we could not decide on a topic. Hence this episode is what it is 🤷‍♀️ https://open.spotify.com/episode/6NIIqb8BHxx2FcSMG9pEjv ### Links to things we mentioned - [Amusing Ourselves to Death](https://www.amazon.com/Amusing-Ourselves-Death-Discourse-Business/dp/014303653X/?&%5Fencoding=UTF8&tag=kcar08-20&linkCode=ur2&linkId=7c164cc2ca9f05ae1f4200a1cc00c8b3&camp=1789&creative=9325&ref=katecarruthers.com) \- Neil Postman - [2023 DoD Manual Revision – To Shoot, or Not to Shoot . . . Automation and the Presumption of Civilian Status](https://lieber.westpoint.edu/shoot-not-shoot-automation-presumption-civilian-status/?ref=katecarruthers.com) - [Elon Musk’s Shadow Rule: How the U.S. government came to rely on the tech billionaire—and is now struggling to rein him in.](https://www.newyorker.com/magazine/2023/08/28/elon-musks-shadow-rule?ref=katecarruthers.com) - [Acoustic Jurisprudence: Listening to the Trial of Simon Bikindi](https://global.oup.com/academic/product/acoustic-jurisprudence-9780198735809?ref=katecarruthers.com) - [The Influence Continuum with Dr. Steven Hassan: Chinese Netizen’s Protests and Freedom of Mind as a Human Right with Matthew Bywater](https://podcasts.apple.com/us/podcast/chinese-netizens-protests-and-freedom-of-mind-as/id1603773245?i=1000625110867&ref=katecarruthers.com) ### A picture of my current fave t-shirt Yes I do wear this t-shirt a lot! ![](https://datarevolutiontech.wordpress.com/wp-content/uploads/2023/09/img_3506.jpg?w=300) My current favourite t-shirt ### Data Revolution Newsletter - September 2023 URL: https://katecarruthers.com/data-revolution-september-2023/ Last updated: 2026-05-15T01:28:02.000Z Greetings people! Welcome to the frontlines of the [Data Revolution](https://katecarruthers.com/the-hidden-risks-of-agentic-ai-every-leader-must-know-now/). Here is the September 2023 newsletter. # Stuff ### Governance This month I have been thinking about how we need to adapt our policy and governance to AI speed and scale. There is a quote from Kent Aitken (Aitken, K. (2017, May 23) that I have long kept in mind: > "Complexity is a defining feature of the digital era, and we are not adjusting our governance structures to manage it. Just the opposite, in some ways: as authority and information became distributed and hyperconnected, the pressure towards centralized decision-making and message control became stronger. Meanwhile, governments have grown in size and scope, and the overlap between portfolios has grown as well, and accordingly so has the scope for individual managers. What *hasn’t* grown is the time, tools or resources to deal with boundaryless problems implicating many stakeholders. This question will be at the root of open government and digital government initiatives." The sad thing is I do not think the situation has improved much since 2017\. In fact, I think that we in the data and analytics community are facing a crisis of governance for the new and exciting world of AI that we are entering. Our tools and concepts for data governance are still stuck in the last century. Many organisations were already struggling to establish data governance before Generative AI burst on the scene and caught everyone’s attention. Most of our tools for managing data governance are only just starting to be able to do things like autonomously discover and classify data. But that is just like a baby starting to crawl. Increasingly we need to ensure that our AI operations are happening at scale and autonomously and ensuring that our data are approved and correct for that particular use. ### Data minimisation The other thing that has been on my mind lately is data minimisation. Most organisations are dreadful data hoarders. We often do not just collect that data which we actually need, instead we collect much more than we need. And now data, which we have spoken of for years as an asset, is now also a liability. In a recent hack a third-party held data for nine years and that personal information was breached and is now on the dark web (Burt, Jemima. “Thousands of Donors to Australian Charities, Including Cancer Council and Canteen, Have Data Leaked to Dark Web - ABC News.” *ABC News Australia*, August 23, 2023\. [https://amp-abc-net-au.cdn.ampproject.org/c/s/amp.abc.net.au/article/102757194](https://amp-abc-net-au.cdn.ampproject.org/c/s/amp.abc.net.au/article/102757194?ref=katecarruthers.com)). This is not good for anyone. Organisations need to start putting in contractual clauses for third-parties, e.g. suppliers, to undertake data minimisation activities. And they will also need to start doing the same thing for themselves. I suspect our cyber insurers are going to be asking questions about this kind of thing in the not-too-distant future. # Links Following are some interesting things I’ve found. The first one is the full article from the Aitken quote above ☝️ - Aitken, K. (2017, May 23). Governance in the digital age. *Public Policy Forum*. [https://ppforum.ca/articles/governance-age/](https://ppforum.ca/articles/governance-age/?ref=katecarruthers.com) - Hedrih, V. (2023, May 27). *Scientists use deep learning algorithms to predict political ideology based on facial characteristics*. [https://www.psypost.org/2023/05/scientists-use-deep-learning-algorithms-to-predict-political-ideology-based-on-facial-characteristics-163780](https://www.psypost.org/2023/05/scientists-use-deep-learning-algorithms-to-predict-political-ideology-based-on-facial-characteristics-163780?ref=katecarruthers.com) - Leins, Kobi, and Anja Kaspersen. “Seven Myths of Using the Term ‘Human on the Loop’: ‘Just What Do You Think You Are Doing, Dave?’” *Carnegie Council*, November 9, 2021\. [https://www.carnegiecouncil.org/media/article/7-myths-of-using-the-term-human-on-the-loop](https://www.carnegiecouncil.org/media/article/7-myths-of-using-the-term-human-on-the-loop?ref=katecarruthers.com). - Russon, M.-A. (2023, May 24). *Gandalf AI game reveals how anyone can now trick ChatGPT into performing evil acts*. [https://www.standard.co.uk/tech/gandalf-ai-chatgpt-openai-cybersecurity-lakera-prompt-b1082927.html](https://www.standard.co.uk/tech/gandalf-ai-chatgpt-openai-cybersecurity-lakera-prompt-b1082927.html?ref=katecarruthers.com) - Zeijlemaker, S., Hetner, C., & Siegel, M. (2023, June 2). 4 Areas of Cyber Risk That Boards Need to Address. *Harvard Business Review*. [https://hbr.org/2023/06/4-areas-of-cyber-risk-that-boards-need-to-address](https://hbr.org/2023/06/4-areas-of-cyber-risk-that-boards-need-to-address?ref=katecarruthers.com) # Podcast Episodes - [Mark Pesce ](https://katecarruthers.com/2023/06/01/mark-pesce-talking-ai-episode-3/)was kind enough to be my first guest. He is a polymath, and inventor and very smart human. We had a great chat about AI and how it changes everything. - I also did an episode where I talked about the imperative for [data protection](https://katecarruthers.com/2023/06/08/data-protection-episode-4/). [https://datarevolution.tech](https://katecarruthers.com/the-hidden-risks-of-agentic-ai-every-leader-must-know-now/) ### Taming AI - Peter Leonard URL: https://katecarruthers.com/taming-ai-peter-leonard-episode-10/ Last updated: 2026-06-28T05:12:03.000Z In this episode my guest is [Peter Leonard](https://www.unsw.edu.au/staff/peter-leonard?ref=katecarruthers.com). He is a guru in the legal data and tech space and one of my primary go-to people when I am thinking about data governance, data sharing, regulation, and AI ethics. Today we are talking about some of the issues that folks are going to need to think about as we all wing our way into the AI era. [https://open.spotify.com/episode/1Kr8vBbaxUD8nmwOsLjnCl](https://open.spotify.com/episode/1Kr8vBbaxUD8nmwOsLjnCl?ref=katecarruthers.com) --- **Episode information links:**[Five Safes Framework](https://www.abs.gov.au/about/data-services/data-confidentiality-guide/five-safes-framework?ref=katecarruthers.com)[UNSW Data Governance](https://www.datagovernance.unsw.edu.au/?ref=katecarruthers.com) ## Transcript Kate Carruthers \[00:00:00\]: Hello and welcome to another episode of the [Data Revolution podcast](https://katecarruthers.com/the-hidden-risks-of-agentic-ai-every-leader-must-know-now/). I'm Kate Carruthers, and today my guest is Peter Leonard. Now, he is a remarkable chap. Known him for aeons. He's a data and technology business consultant and lawyer. But that's not all he is. He was the founding partner of Gilbert and Tobin lawyers, and he led its technology and data practice over many years. And he also works at UNSW as a professor of practice across the schools of management and governance and information systems and technology management. He has his own company now called Data Synergies, and I've worked with him on looking at how we can manage data better and how we can manage AI better. So he's an all around good chap and we're going to have a chat. Welcome, Peter Lennon. It's great to have you on the podcast. Peter Leonard \[00:00:59\]: It's great to be here, Kate. Kate Carruthers \[00:01:01\]: So what are we going to talk about today? Peter Leonard \[00:01:04\]: Well, I thought we might talk about how AI is changing the world as we know it, and in particular, the kinds of challenges I'm seeing around how you ensure safe and responsible uses of AI. Layered on top of all of those challenges we've been looking at over the last couple of years around respectful uses of information about individuals. And by respectful, I mean that respects their rights in privacy and is not excessive surveillance. So we're pretty familiar very well at. Kate Carruthers \[00:01:48\]: That, to start before AI, were we? Peter Leonard \[00:01:52\]: Well, exactly. And that's kind of the point, right? That we're in the middle of a work in progress that we've not been doing very well around, building data privacy and data security by design and default. And then in the middle of all of that hard work that, as you and I know, is work in progress and some people are doing more seriously than others, and some organizations don't seem to be doing very well at all. Everyone is deploying AI in various ways, including generative AI. That's coming into many organizations by stealth and in circumstances where CIOs and other responsible people like you are having difficulty keeping control as to who's doing what using that AI in their organizations. Kate Carruthers \[00:02:51\]: So what are some of the issues that you're seeing emerging in this space, particularly from a privacy and data protection perspective? Peter Leonard \[00:02:59\]: Peter I suppose the first thing is that many people are gaily prompting public generative AI applications like Chat, GPT, Google, Bard, Microsoft, Copilot, with personal information relating to individuals without consideration of how that information is leaving their organization and how it might be used in the that's a great one. Kate Carruthers \[00:03:36\]: I had a startup come and pitch me the other day and they were using that, and I just said, please stop. Please don't do that with your proprietary commercial information. Peter Leonard \[00:03:44\]: Yeah, and look, it's an interesting question because on the one hand, you might say, look, this is just a transitional educational issue of people needing to understand that they shouldn't be doing that stuff. And the other reason that you might regard it as a transitional issue is that you and I know that fairly quickly we will see large language models made available within institutions like UNSW where it'll be a local instance of the large language model that ensures that the data doesn't leave the organization already there? Yeah. Kate Carruthers \[00:04:33\]: But isn't the real issue that people who don't understand the implications of what they're doing now have the power to do stuff? Which was always starting to happen with software as a service where people could put stuff in the cloud and not understand it, but now they can do it on the public Internet, which seems to me to be the real challenge. Peter Leonard \[00:04:53\]: So I think there are two challenges. One is that we don't know enough about the training data that's been used to train the large language models that organizations can reliably assess whether the model is fit for purpose for the particular task for which the generative AI is being used. And then secondly, there's the issue that the generative AI is so easy for anyone to use that it's being used for myriad tasks within organizations that CIOs like you can't even begin to imagine what might be happening in some building elsewhere on campus and certainly can't control. And that in turn leads to questions of whether the person that's using the generative AI in that way is placing undue reliance upon what might be very unreliable results. So there's a question firstly as to whether the data that was used to train the model that is then generating the result through the generative AI was fit for purpose. And then whether the human who is looking at the results is unduly relying on what might be a completely unreliable output. And that's very different to the kinds of AI assessment that I've been involved with in the last few years. Because typically what we've been looking at, for example, for the New South Wales government in the AI review committee that I sit on, is we see big It projects involving AI that are bought to us that are specific. Purpose AI designed and evaluated by us as being fit for purpose or not fit for purpose for the particular task for which it's designed. But of course that's completely different to this stealth AI coming into an organization, being used for myriad tasks and being relied upon by myriad human beings, limited only by the imagination of humans as to what tasks they might get the generative AI to do. Kate Carruthers \[00:07:42\]: I know and this space is moving so fast. I keep telling people that it used to move in years and months and now it's moving in hours and minutes. Like I log on in the morning, look at stuff, go to work, log on in the evening and stuff, new stuff's emerge during the day so it's moving really fast. But what are some of the issues some of the ways that people can approach sort of AI safely and responsibly, do you think? Peter Leonard \[00:08:08\]: Yeah, look, it's a good question. I suggest to people that they need to put the AI in the context of a decision and work backwards from the question of what is the decision for which technology is being used and then evaluate whether introduction of the AI into the decision making chain makes the decision less reliable or more reliable. And in many contexts the introduction of the AI may even make the decision more reliable. But you actually have to look at the decision chain in the context in which the decision is being made and the purpose for which the decision will be used. And let me give you sort of an example on it. Let's assume that it's a doctor in a hospital who's thinking about writing up a discharge summary for a patient and currently would look at the electronic medical records relating to that patient and write up a discharge summary out of that. Well, that same doctor might use chat GPT to look at those inputs and do a first draft of the discharge summary for the doctor to review. In that circumstance, you've got somebody, a trained medical practitioner who's got obligations, professional intelligence obligations amongst others, to patients and should be bringing the requisite level of care and has the relevant source data there to compare against the summary that the, say, chat GPT, whatever they're using, is generating. So then it's just a question of, well, is the relevant individual properly appraised of the risk that chat GPT might make something up or get something wrong and do they have the time to properly evaluate what the generative AI is presenting to them? And there's always a risk in this, of course, that when you talk about automation, what may often happen is that employers promptly steal the time back that they've liberated for the individual by allowing the individual to use the automation. So the hospital might say, well, go out and do some more rounds because writing up discharge summaries now and he takes half the time. Whereas the reality is, if you're going to use generative AI in this context responsibly carefully and safely, I mean, you. Kate Carruthers \[00:11:21\]: Just use chat GPT sort of in the vernacular, I'm assuming, in the place of generative AI because one would hope that a hospital has their own custom generative AI application that is getting the right inputs. Because one of the things that I keep talking to people about is an LLM doesn't a large language model does not know stuff, it only knows what you tell it. And so you actually need to be able to insert new knowledge, new information into its decision making because it only knows what it knows until you've inserted stuff. So what I'm seeing is that generative AI is going to need to be part of more of a machine learning workflow where you're inserting all of the different inputs at the right time so that you're getting the right kind of outputs. And we don't understand this space at all, like submerging. It's so new. We don't really know how to do this at scale for enterprises or big hospitals and stuff. It's all very new. And we've already seen how Chat GPT in particular can hallucinate, so it just makes up stuff. It made up two new jobs for me when I got it to write a CV for me. Peter Leonard \[00:12:40\]: Well, that's great. It augmented your skills. But as an example of how quickly things are moving on this, it was interesting to look at the release notes that came with Meta's llama two, three or four weeks ago, and they included quite a detailed model card and a responsible user guide and some quite useful information in there around their so called open source models. And I think that's going to be an interesting trend. So if we look at, say, that hospital example in six or nine months out, I can imagine that. What we will see is area Health Services in New South Wales, having, using a third party large language model that they've bought into the organization, pre trained and assessed for reliability of the pretrained data, and then further trained using the confidential patient data sets within the organization evaluated by people who are properly skilled to evaluate that and made available in that controlled environment. Kate Carruthers \[00:14:11\]: Most of the big vendors have been working on this in the background for years with their large data sets ready, because the real problem for all of this is training the models, having enough data. And I was at a dinner last night with a whole bunch of cyber security folks and they were all talking about, we must delete all the data. And I was like, Hold on a SEC, we might need it to train some models before we throw it out. So that's actually kind of the weird imperative. Now people want to throw out data, but then we need it to train the models, otherwise they're not going to be reliable. So it's an interesting paradox that we're in nowadays. But one thing I did want to touch on is what do you think is going to happen in the regulatory space? Peter Leonard \[00:14:55\]: Well, that's a very interesting question because there's a number of regulators who I think would like to own this space, including the privacy regulator, the ACCC. And the ACCC is not a silly choice, actually, because many of the issues around AI can be addressed through existing provisions of Australian consumer law, amended a bit and tightened up a bit. So, for example, Australian consumer law says that if you make available a software product, it has to be fit for purpose of merchantable quality and you should be making disclosures about known limitations of your products that are not misleading or deceptive. So one can imagine a world where you might expand some of those provisions to ensure that vendors make full and proper disclosures about the reliability of their large language models or any generative AI applications that they're making available. And that could do quite a bit of work. I'm not a supporter of the concept of a super AI regulator or anything like that, because yeah, look, I think that AI is going to be part of everything that every business in every sector does, and we're just going to have to skill up the regulators in the various sectors to properly address the issues in their sectors. Kate Carruthers \[00:16:46\]: Sort of like computers, like we did with computers. It's the same thing. So it leads me, though, to the question about explainability, because that seems to be something that we're going to have to solve if we are going to regulate this in a proper way. Peter Leonard \[00:17:03\]: Yeah, and explainability is an interesting concept, isn't it? Because when you look at large language models, there's a question as to what level of explainability you're after. It is often not possible to fully explain how the large language model is operating, but what you can explain is any known limitations that you've identified through the operation of the model and you can disclose the sources of data and known limitations as to data quality. So data provenance issues around the data that was used to feed and train the large language model. So I don't think that all roads. Kate Carruthers \[00:17:52\]: Are leading back to data governance, aren't they? Peter Leonard \[00:17:55\]: Absolutely. And when you look at data governance, you can't look at that alone without looking at the people and the process, the decisions that individuals are making using that data and the technology. So it goes back even further to the question you and I have been looking at for years, which is you can't evaluate technology without thinking about the people and the processes. Kate Carruthers \[00:18:27\]: The five safes just popped into my head for some reason. I will share a link in the show notes to that. Peter, I'm really conscious you've got to go off and teach a class. So thank you so much for your time. I really do appreciate it. We could have gone on for hours, but I know your time is limited, so thanks very much for joining me. Peter Leonard \[00:18:45\]: Pleasure, Kate. Kate Carruthers \[00:18:47\]: Good night. Peter Leonard \[00:18:48\]: Good night. Kate Carruthers \[00:18:50\]: That was the end of another episode of the Data Revolution podcast. I'm Kate Carruthers. Thank you for joining me. Hope you'll leave a nice review for the podcast and please join us again next time. ### AusCERT2023 - Data Governance & Cyber Security Panel Discussion URL: https://katecarruthers.com/auscert2023-data-governance/ Last updated: 2026-04-01T03:51:23.000Z Joined Troy Hunt, Craig Rowlands, Sasenka Abeysooriya on panel at the AusCERT 2023 Conference. > "In an increasingly interconnected world, the need for robust data governance and cyber security measures has never been more critical. This panel discussion aims to explore the intricate relationship between data governance and cyber security, and the importance of implementing collaborative strategies to ensure a resilient digital ecosystem. Our distinguished panelists, consisting of industry experts, thought leaders, and policymakers, will delve into various aspects of this multifaceted issue." The panel covered: The current state of data governance and cyber security, highlighting the challenges and opportunities presented by emerging technologies, evolving regulatory landscapes, and the growing sophistication of cyber threats. The importance of aligning data governance practices with cyber security measures, emphasising the need for a holistic approach that balances regulatory compliance, privacy protection, and risk management. The role of collaboration between various stakeholders, including government, industry, academia, and non-profit organisations, in fostering a resilient digital environment. ### Bi-modal approaches for data, AI, and innovation - Khaled Auf URL: https://katecarruthers.com/bi-modal-approaches-for-data-ai-innovation/ Last updated: 2026-05-15T01:23:50.000Z My guest today is [Khaled Auf](https://www.linkedin.com/in/khaledauf/?ref=katecarruthers.com), and we will be talking about the benefits of a bi-modal approach to delivering Analytics, BI and Data Science . We also touch on tri-modal approaches (and even coin the very innovative quad-modal approach 🤣). I have known Khaled for years and we have often chatted about the next big thing in data. Nowadays the next big thing is AI and it is important to get your data architecture right so that we can support AI operations at scale. ![Khaled Auf](https://datarevolutiontech.wordpress.com/wp-content/uploads/2023/07/khaled.jpeg?w=225) > Khaled Auf has worked extensively on corporate data strategies having established over 20 data estate strategies across Education, Finance, Energy, Logistics and Construction sectors. And his current day job is at Snowflake where he is their Practice Director for Professional Services in Australia and New Zealand. > [https://open.spotify.com/episode/49h5yxKFa811Cn0OLBYr7B](https://open.spotify.com/episode/49h5yxKFa811Cn0OLBYr7B?ref=katecarruthers.com) ## Things we mentioned [Gartner 2017: Drive Analytics Innovation by Using a Bimodal Approach](https://www.gartner.com/en/documents/3796578?ref=katecarruthers.com) ### The need for Explainable AI – Fiona Tweedie URL: https://katecarruthers.com/fiona-tweedie/ Last updated: 2026-05-15T01:33:41.000Z This time my guest is Fiona Tweedie. She has been thinking about the need for explainable AI for a long time. We had a fascinating chat on why this is important, why we should care about AI being explainable, some of the risks associated with AI not being explainable. [**Episode link**](https://open.spotify.com/episode/3YlN8K8oCYEBkiTdPnk411?ref=katecarruthers.com) > [Fiona Tweedie](https://www.linkedin.com/in/fiona-tweedie-53477b130/?ref=katecarruthers.com) fell in love with the transformative power of data when working on the Australian Government’s [*Principles on Open Public Sector Information*](https://www.oaic.gov.au/about-the-OAIC/information-policy/information-policy-resources/principles-on-open-public-sector-information?ref=katecarruthers.com) and has held numerous roles analysing, governing and wrangling data in the years since. She has worked on embedding ethical approaches to data in commercial and research organisations and is passionate about demystifying tech and increasing data literacy. Fiona holds a PhD in Ancient History and is still working on the blanket that she started crocheting during lockdown. ###### Links to resources we discuss in the podcast: - [Technically Wrong](https://www.amazon.com.au/Technically-Wrong-Sexist-Algorithms-Threats/dp/0393356043?&%5Fencoding=UTF8&tag=kcar06-22&linkCode=ur2&linkId=bd28d7b710f0107c68d6c527656af620&camp=247&creative=1211&ref=katecarruthers.com) - [Open Data Institute – Data Ethics Canvas](https://www.theodi.org/article/the-data-ethics-canvas-2021/?ref=katecarruthers.com) - [NSW Government AI](https://www.digital.nsw.gov.au/policy/artificial-intelligence?ref=katecarruthers.com) ### It's about people - Gladwin Mendez URL: https://katecarruthers.com/its-about-people/ Last updated: 2026-05-15T02:15:44.000Z For this episode of the Data Revolution podcast my guest is [Gladwin Mendez](https://www.linkedin.com/in/gladwinmendez/?ref=katecarruthers.com). Today we are going to be talking about the important other things that data and technology need to work - people and process. As [Gladwin noted over on LinkedIn](https://www.linkedin.com/posts/gladwinmendez%5Fits-about-people-gladwin-mendez-episode-activity-7080025975303909376-fY-O?utm%5Fsource=share&utm%5Fmedium=member%5Fdesktop): "There's a powerful Māori saying:"He aha te mea nui o te ao? What is the most important thing in the world? He tangata, he tangata, he tangata. It is the people, it is the people, it is the people." Thank you for the fantastic opportunity [Kate Carruthers](https://www.linkedin.com/in/ACoAAAAD15wBGIUl0g6J03miWA2Tf-8R3mTnNXY?ref=katecarruthers.com) for the opportunity to provide my opinion on what is the most important thing out of the 5 pillars - Strategy, People, Process, Technology or Data. I strongly believe its the collective excellence of people who deliver the remaining four. Evidenced time and time again with having worked with some of the most amazing people in my working career." > "Gladwin is passionate about making a difference to the world through data and relishes the opportunity to expand that to the wider global stage. He is Chief Customer and Analytics Officer at [Simply AI](https://www.google.com/search?q=http%3A%2F%2Fsimply.ai&client=safari&source=hp&ei=VjGNZNuMF5-T2roPlpWRsAs&iflsig=AOEireoAAAAAZI0%5FZgrPugePm9Pr5yHshigm8w9V9X1I&ved=0ahUKEwjbj9Hwtsn%5FAhWfiVYBHZZKBLYQ4dUDCAo&uact=5&oq=http%3A%2F%2Fsimply.ai&gs%5Flcp=Cgdnd3Mtd2l6EAMyBwgAEA0QgAQyBwgAEA0QgAQyBggAEB4QDTIGCAAQHhANMggIABAeEA0QCjIGCAAQHhANMgYIABAeEA0yBggAEB4QDTIGCAAQHhANMgYIABAeEA06EAgAEAMQjwEQ6gIQjAMQ5QI6EAguEAMQjwEQ6gIQjAMQ5QJQlwNYlwNgmQhoAXAAeACAAYQDiAGEA5IBAzMtMZgBAKABAqABAbABCg&sclient=gws-wiz). > > Gladwin has more than 15 years’ experience in technology, data and analytics. He has worked across New Zealand’s large financial services and insurance organizations, as well as numerous organizations in Australasia, North America and Europe. > > His background includes leadership of analytics teams at Deloitte and KPMG. He successfully developed these companies’ capabilities and led their analytics service lines across a portfolio of IT advisory, risk, tax and management consulting services." [**RSS feed**](https://media.rss.com/data-revolution/feed.xml?ref=katecarruthers.com)[**Episode link**](https://rss.com/podcasts/data-revolution/1137822/?ref=katecarruthers.com) ### New roles for Data and AI URL: https://katecarruthers.com/new-roles-for-ai/ Last updated: 2026-05-15T02:57:49.000Z Everyone seems to be running around trying to work out what the new surge in AI that is driven largely by the growth in generative AI. And so many people are being all doom and gloom about how AI will kill us all, and others saying we will all lose our jobs. Today I will discuss how we will need to look at how our data teams work and the new roles we will need to consider to support AI operations at scale. [Episode Link](https://open.spotify.com/episode/3VN7ZPerclxf0F4GwKqZH4?ref=katecarruthers.com) ###### Links to stuff I mention in the podcast Meesters, Marcel & Heck, Petra & Serebrenik, Alexander. (2022). [What Is an AI Engineer? An Empirical Analysis of Job Ads in The Netherlands.](https://www.researchgate.net/publication/359585488%5FWhat%5FIs%5Fan%5FAI%5FEngineer%5FAn%5FEmpirical%5FAnalysis%5Fof%5FJob%5FAds%5Fin%5FThe%5FNetherlands?ref=katecarruthers.com) 10.1145/3522664.3528594. ### AI: From Imagination to Reality URL: https://katecarruthers.com/ai-imagination-reality/ Last updated: 2026-08-08T06:10:20.000Z There is such a hunger out there among people for information about AI. There are so many doomsayers and panic merchants. And people just want to know what can AI and in particular generative AI do for me, in my personal life and in my job. For me, Chat GPT is a great way to summarise information and an excellent source for recipes. I attended the [**AI: From Imagination to Reality**](https://events.unsw.edu.au/event/ai-imagination-reality?ref=katecarruthers.com) event in Sydney last night, and it was a packed house. This was a joint presentation by [UNSW Engineering](https://unsw.us2.list-manage.com/track/click?u=f8936303e869dcdd41776fc88&id=2f2aca4487&e=454542c4b9&ref=katecarruthers.com) and [UNSW AI Institute](https://unsw.us2.list-manage.com/track/click?u=f8936303e869dcdd41776fc88&id=40312837a3&e=454542c4b9&ref=katecarruthers.com)\*. There was an expert panel who had a thought-provoking discussion on the future of generative AI, its potential and pitfalls, and the broader implications of AI for society, industry, and beyond. Panel members were (biographies [here](https://events.unsw.edu.au/event/ai-imagination-reality?ref=katecarruthers.com)): - **Wilson da Silva** **(Host)**, journalist and editor. - **Rita Arrigo**, Strategic Engagement Manager, CSIRO National AI Centre. - **Aurélie Jacquet**, Chair of the Standards Committee IT043 on Artificial Intelligence, Standards Australia. - **Sebastian Sequoiah-Grayson**, Senior Lecturer in Epistemics, School of Computer Science and Engineering, UNSW Sydney. - **Toby Walsh,** Chief Scientist at UNSW AI Institute, and Laureate Fellow and Scientia Professor of Artificial Intelligence at UNSW Sydney. You can watch the video of the event [here](https://www.youtube.com/watch?v=7aa6rOK2D98&feature=youtu.be&ref=katecarruthers.com). *\* Disclosure: I am Head of Business Intelligence for the UNSW AI Institute and hold an academic appointment in the Faculty of Engineering* ### CDAO first 100 days - Felipe Flores URL: https://katecarruthers.com/episode-5-cdao-first-100-days/ Last updated: 2026-05-15T02:57:17.000Z For this episode I am joined by a well-known data leader - [Felipe Flores](https://www.datafuturology.com/felipe-flores?ref=katecarruthers.com) \- who is talking about things you need to do as a data leader when you start a new role. ![](https://datarevolutiontech.wordpress.com/wp-content/uploads/2023/06/1664939229563.jpeg?w=300) Felipe Flores - Data Futurology > "Felipe is a data science senior executive with almost 20 years experience. He has worked across data engineering/warehousing, reporting, business intelligence, analytics, data science, machine learning and artificial intelligence. He is currently the CDAO at Healthcare AI company, and is the founder of [Data Futurology](https://www.datafuturology.com/?ref=katecarruthers.com)." Data Futurology is one of my go-to places for data podcasts and events and is worth checking out. [Episode link](https://rss.com/podcasts/data-revolution/1137824/?ref=katecarruthers.com)[RSS feed](https://media.rss.com/data-revolution/feed.xml?ref=katecarruthers.com) ## Transcript [![](https://datarevolutiontech.wordpress.com/wp-content/uploads/2023/06/datafuturologylogopurple-1.png?w=400)](https://www.datafuturology.com/?ref=katecarruthers.com) Hi folks, and welcome to the next episode of Data Revolution podcast. Today. My guest today is Felipe Flores, who is the Data Science senior executive. He's got a lot of experience. He's worked across data engineering, data warehousing and bi and related stuff for many years, in particular in AI and machine learning. And he's currently Chief Data and Analytics Officer at Healthcare AI Company and is the founder of [Data Futurology](https://www.datafuturology.com/felipe-flores?ref=katecarruthers.com), which there's a bunch of stuff on LinkedIn if you're looking for it. Welcome, Felipe. Felipe Flores \[00:00:36\]: Hey, Kate, thank you so much for having me on the show. I'm so excited to be here with you and yeah, get to talk all things data. Thank you so much. Kate Carruthers \[00:00:45\]: Yeah, well, I'm really interested in your topic, so why don't you tell people what we're going to talk about today? Felipe Flores \[00:00:50\]: So I thought, yeah, today we could have a discussion around what it's like coming into a new executive role. So what do the first 90 days as a CDO look like? What we're seeing in Australia is that there's a continuing growth of maturity in the data analytics space, and more and more companies are having and creating CDAO positions. Some companies are onto their third or fourth CDAO, others are creating that position for the first time. So as a result, we have many people in the industry, many people in our community going into these positions, sometimes for the first time, sometimes for the third time. And I thought it'd be really good to kind of distil some of the learnings that people have had, give some tips and help people kind of have a smooth transition, kick some goals early and ease those nerves. Kate Carruthers \[00:01:42\]: That is a great idea because I've been in this job for many, many years now, so I've almost forgotten what it was like to start off with. Felipe Flores \[00:01:50\]: Right. It's crazy. One of my friends described it as kind of like building up fitness, that you get to a point that at the beginning you might be totally finding it really difficult, really overwhelming, having to think really deeply about kind of every step that you take. And then once you do it for some time, you develop that fitness that it becomes a lot easier to do. And I think it's good to sometimes reflect, look back. Hindsight is always helpful and particularly helpful to other people that would be stepping into the role, into these type of roles for the first time. Kate Carruthers \[00:02:28\]: Yeah, well, because I can literally remember when I was appointed in 2014 and data governance was part of my remit and sitting down and googling data governance and finding all these articles going, yeah, it's a really great idea, you should totally do it. And nothing that said, here's how to do it. So that's how I developed my data governance website because I was like, you need to know. Felipe Flores \[00:02:54\]: That's the thing that it's funny how as seniority increases, the breadth of the remit increases. So much, and it's almost counterintuitive as you're coming up to go from an area where you feel like you're such an expert in a domain that you totally get and understand. And then as you become more senior, you have areas that you may not have worked in before or may not have looked after earlier, and you're having to kind of learn on the job and become this leader, really, of experts in an area that you're not an expert and that definitely requires new skill sets. And I think one of them is the rapid learning and getting into the area as you've done as you did back then with data governance. I think that's an awesome way to get into it and be able to add value to the teams and still develop and lean on the leadership skills that are required to lead teams where the leader doesn't know the full details of everything that is going to be done. Kate Carruthers \[00:04:05\]: So where should people start? Where should new leader who’s got the job and is walking in the door start? What are they going to do? Felipe Flores \[00:04:20\]: I'm very quickly going to close this code in 1 second, sorry. So it's really interesting because a lot of things that I see of people when they say they just get a CDO role, the good thing is that the people in our space, they want to be prepared. So there's generally a fair amount of research about the company and the industry that is done and people do that I think usually very well. I think one of the areas that could have greater focus is particularly the commercial model of the organization. If it's a for profit organization, focusing on what is the mechanics of the business model for that company, having clarity about that as early as possible is going to be extremely helpful. And I've definitely been in situations where I've gone into new exec roles and I've kind of pulled out my playbook that worked for me last time and then sometimes it doesn't work in the new organization and part of that is because I didn't take enough time in understanding the commercial model. So for example, when I moved to healthcare where I am now, I came from a background of consulting and finance and banking. So I came into this new role and I go great. I know it's about customers, it's about retention, it's about marketing and it's about providing that value to customers from an analytics perspective and be able to target them better. And in healthcare it's much more about the outcomes that we're looking to make people healthier and so targeting comes into play in a different way but the retention doesn't necessarily play in the same manner as it would in financial services. So things like that is around what is the commercial model of the organization, what is the aim that the organization, the difference that the organization wants to make. Having clarity on that very quickly I think is super important. The other one that I see a lot of people not taking enough time on, and I've definitely made this mistake as well, is understanding the culture of the organization and having the time to really see and feel how things are done there. I've seen this in other people and I've seen it a lot in myself, that sometimes you start a new role and you think, all right, I'm going to go in, I'm going to kick some goals, I'm going to really make a difference quickly and often. While that has all of the right intents, sometimes we need a little bit more time to understand and absorb how the company operates, how the decisions are made, who are the key influencers. Kate Carruthers \[00:07:24\]: That's the most important thing you need to understand because a lot of the time the formal hierarchy is not the influence hierarchy in an organization. Felipe Flores \[00:07:34\]: And understanding that, it takes a bit of time and then through that you get to uncover what are the key problems that people really see as the ones that you could make a big difference, that not every problem in the organization is going to have an analytics solution and vice versa. You're not going to be able to solve everything under the sun, but being able to understand what are the problems that the organization has and sees as very important and then what is a good overlap between the ones that analytics can provide a solution and then start working. Once you get that sense and you get the who's who in the zoo, start working on, I would say be very focused and start working on very few initiatives that some are going to deliver you some quick wins where you're making a difference early and that's going to give you momentum around your position, your new leadership. It'll make the team feel good. There's a lot of benefits in having quick wins. It's obviously going to be adding value to the organization early on, have few of those and then set some time apart to work on the strategy on what data analytics could do for the organization in a broader sense. Kate Carruthers \[00:08:57\]: Do you have a view on people coming in and doing some sort of maturity assessment to assess the stack that you're using and the data literacy across the organization? Felipe Flores \[00:09:10\]: Yeah, I think overall it's a great idea because it helps regardless of the scenario or the type of environment that you're going into. And I think that the scenarios, at least in my mind, are you could be going into a startup or a greenfield company where there's no analytics can be ability before, so you're setting it up for the first time. You could be going into a sustaining innovation. So analytics team that has been adding value to the organization, that needs to continue to do that, that's kind of a sustaining innovation type of scenario, there's a turnaround. Sometimes there's teams that have been seen from the organization's perspective, have been seen that they are not adding as much value as they could, and they're looking for kind of like the refresh. So having kind of like a turnaround story. Sometimes organizations bring a new leader for that, and then the other one, which is I think one of the more spoken about is doing a transformation, a digital transformation within the organization that they're looking to do. Kind of like a sweep across the board for customer experience through process automation and bring in a lot of data analytics through that. So regardless of the and the different scenarios will have some different perspectives that you need to take into consideration. But across the board, I think having a maturity assessment and a data literacy assessment, I think is always helpful. Kate Carruthers \[00:10:53\]: Yeah, because for us, we realized we didn't have a data literacy problem because most of our people have master's degrees or PhDs at the Uni. We've got a digital literacy problem where people's first choice isn't always digital. They have a real strong preference for printed out pieces of paper. So understanding the organization, when you're coming to an organization, you might not understand that about it, that kind of thing about it. Felipe Flores \[00:11:21\]: Right. And that's so interesting and kind of unexpected, or at least I wouldn't have expected. Kate Carruthers \[00:11:28\]: I didn't realize it until later, they've all got PhDs. They've all done stats. They know this stuff. And then it was like, oh, my God, they're not digital native people yet. They'll come through eventually. Felipe Flores \[00:11:44\]: That's it. That's it. No, that's really good. I like that. How do you see the differences in how people get to the role, to the executive role, that some people are promoted up, some people are kind of promoted across, and other people are new to the organization. They all have kind of slightly different approaches to take. And maybe I'm biased, but I think that the more challenging one is promoted up, that you kind of have to leave a lot of your previous responsibilities, strike a different dynamic with your team. You have obviously a lot of knowledge of the organization and the stakeholders and the way that things are done. You might have a lot of ideas that you have been working on or thinking about while the predecessor was at the helm. And now you have your opportunity to solidify those relationships, step into a more senior role, and then start to make your mark. But I know that the people promoted across, they feel like they're moving into an area that it might not be their bread and butter. And sometimes people come from marketing background or customer digital, and then they move into data analytics leadership, and they feel like they a little bit not out of depth, but not in their comfort zone. Kate Carruthers \[00:13:13\]: And there’s a bit of impostor syndrome sometimes. Felipe Flores \[00:13:19\]: Yes. And the impostor syndrome I think we all struggle with it. It's something that I think everyone, at least, at least in this field, I think everyone in this field has. And I started thinking about it as more kind of to work through it more as like the ability to make a contribution instead of like, am I being totally perfect in this role or in this capacity, or living up to my own kind of inflated expectations of where I should be. It's kind of like, am I making a contribution here that's helping people and making a difference. Kate Carruthers \[00:13:59\]: Well, the thing I always say, when people say they have impostor syndrome is it means you're not stupid because you're conscious, you don't know everything, which is the definition of not stupid. Felipe Flores \[00:14:13\]: I love that. Kate Carruthers \[00:14:16\]: A long time ago where I was like, I can't know everything in this field. And it was like, okay, that's good, I can't know everything. And so that was a good moment for me where I let go of this thing of having to be the smartest person in the room and it was okay for me to go, yeah, I don't know about that. Tell me about it. Felipe Flores \[00:14:39\]: Great. And I think taking that weight off allows you to become so much more effective. And I know that a lot of people throughout their career, when they look at executives, sometimes they feel like the executive is not afraid to ask the stupid questions. And I think it comes with that transition that you just mentioned, that it's like, I can't know everything. And almost like the more stupid questions that I ask, the better I'm going to be at my role, the more effective I'm going to be able to be. I'm going to get greater clarity, get better alignment, get to the bottom truth of what's really happening. So I think it's almost a must have in the steps towards roles like. Kate Carruthers \[00:15:29\]: This one when you're talking about somebody coming in in their first hundred days or so. So we've got that they are going to have a look, have a listen, listen to people, understand the organization, understand the money flows, understand where they're at, do a maturity assessment kind of thing, what other things do you think that they need to do then? Felipe Flores \[00:15:52\]: As long as you're able to get some momentum in your role and your leadership with some of the things you mentioned, like knowing who's who in the zoo, understanding the problems, but also starting to get some early wins. And that will get momentum with your boss, with your peers, or at least some of your peers, and then with the team that they'll start to feel good about the transition, where they're being valued and they're being productive and making a difference to the organization. All that kind of helps cement the short term jitters that people might feel that they want to be seen as adding value. And throughout, you also have to carve out some time for the longer term perspective where you want to start building out a strategy that can make a difference in the organization. And in that case, the strategy from a data analytics perspective needs to be completely aligned to the business strategy, to understanding where does the organization want to go. And my kind of like one line of a strategy is understanding where we are now, where do we want to be in a period of time, say three years and then what is the path for us to get there. So having the understanding of the organization's strengths and weaknesses currently and painting as clear as possible a picture of where we want our end state to be and devising a stage plan to get there, understanding that in order to get there, it'll be iterative. But having kind of the main areas and having some design around that I think is great. So working on that online, that strategy looks like is an area that needs to have some time carved out. And I've seen that one, just one question. Kate Carruthers \[00:17:53\]: Sorry to interrupt, but increasingly now, especially with Chat GPT, everybody wants AI and kind of the future of digital is data. So how do you recommend that people weave those stories into this strategy piece? Felipe Flores \[00:18:14\]: Yeah, that's where the capabilities that we have are to power the pillars of the strategy of the organization. So for example, next week, next Friday, I think we've got a session literally on generative AI with a health insurance client where they asked for it and they said come and sort of tell us what Generative AI can do for us. And the aim is to go. These are the pillars of the business where you have your customer, you have your marketing and sales, you got your service and customer, you have your provider or hospitals and doctors to liaise with, you've got the market. And all these have a number of processes or functions, some of them that are more visible than others. Which ones of those does it make sense to start to plug in some of the more recent capabilities like large language models, for example. So bringing in customizing, for example, one of the typical applications, customer service responses based on previous human generated text responses is kind of like an easier win. But then taking it to a step where a customer can interact with a large language model to understand their products and their contracts. And in the case of health insurance, like what are they covered for, what are they not covered for? Does the cost cover the out of gap payment? Where could they go to? What type of specials could they see so they don't have an out of pocket payment? Those type of more details, that is information that sometimes it's not as easy to get as people and customers would. Kate Carruthers \[00:20:18\]: Like that type of information handy for summarizing stuff. Such a really useful feature of it. I love it. Felipe Flores \[00:20:26\]: So good, right? Yeah. And I saw an application recently of people wanting to get answers and summaries based on their internal documentation, but they didn't want to put kind of like all of their internal documentation through the API at this stage. So what they did was for all the internal documentation, they created embeddings for those. So then they have kind of like the summarized vector of that. And then for the questions going into the large language model, they also got an embedding. And then they found the embedding of the documentation that most similarly aligned to the question and then put only that documentation through the large language model along with the question to say, here's some background on this question. Now here's the question and try to answer it based on this documentation. And yeah, I thought it was a really nice way to kind of control the amount of information that might be leaving the organization at this stage. Obviously in areas that are less sensitive, while there's developments into having LLMs that are more be able to be built within your infrastructure or VPN, that's the really interesting space. Kate Carruthers \[00:21:53\]: Hey, we're almost out of time. So what would you like to tell people who are about to start a job in the data space as a data leader? What are the top three things you're going to tell them to make sure that they do? Felipe Flores \[00:22:06\]: Yeah, I think that from a mindset perspective, it's that what got you here won't get you there. And some of the things that at least I had to learn the hard way was that throughout my career, I was focusing on being kind of better and better at my craft on data science, data analytics, and didn't traditionally place too much importance on other areas like data governance or program management and things like that. And those are all structures that you need to create in order to be successful at roles at this level. So you need to definitely expand your horizons and take in kind of like at this level, you are an organizational architect and there are multiple areas that need to have a structure that interacts with the organization for that's a really. Kate Carruthers \[00:23:06\]: Great way to conceptualize it. I love that. Felipe Flores \[00:23:10\]: Yeah. So for the capability to be the most effective it can be, I would say, yeah, what got you here won't get you there. Think more broadly, be an organizational architect, make sure that you're getting those early wins, thinking about the strategy and make sure that the capability is making a difference on the commercial model of the organization or the mission of the organization. And that can be or most of that can be quantified in a way that it really hits people. And for problems that you need to solve that might be a bit more hidden, find ways to make it real for people. And I've seen executives, for example, go to the boardroom with four different versions of the report, and instead of saying, all of these reports have different numbers, they turn it around and they have it as almost like a quiz or a game show and say they had the question up front to say, how many new customers did we get this month? Was it option A-B-C or D? They're all different numbers. And the answer was, they're all correct because they're all in a different report. So it's kind of like an innovative way to highlight the problem and then get some support for fixing them. Kate Carruthers \[00:24:27\]: Yeah, they're really good tips. Thank you so much for your time. Felipe. That was Felipe Flores. He is the meister of data futurology. An amazing podcast. They run webinars and events, too, and he's an all round data guru. So thanks so much for your time. Felipe Flores \[00:24:45\]: Thank you so much, Kate. This was so much fun. ### Ops World data panel URL: https://katecarruthers.com/ops-world-data-panel/ Last updated: 2026-05-15T02:56:57.000Z ![](https://datarevolutiontech.wordpress.com/wp-content/uploads/2023/06/datafuturologylogopurple.png?w=400) This week I'd like to share a special episode of the [Data Futurology Podcast](https://www.datafuturology.com/podcast/2023/6/7/235-maximising-the-productivity-of-the-data-led-enterprise-with-unsw-eg-australia-and-compare-the-market?ref=katecarruthers.com), featuring the keynote panel discussion from the OpsWorld conference earlier this year. On this panel were [Conor R. O'Neill](https://www.linkedin.com/in/ACoAABNRnYsBog0WAQ30aQHn8ldKv5keXUbfhac?ref=katecarruthers.com), Head of Data Science, [Comparethemarket.com.au](https://www.linkedin.com/company/comparethemarket-com-au/?ref=katecarruthers.com) and [Arvee Manaog](https://www.linkedin.com/in/ACoAAAArRcEBST9KfRapIryObD-IeWlOVYVbvQ0?ref=katecarruthers.com), Head of Enterprise Systems, Data & Information Management, and Integration, [EG Australia](https://www.linkedin.com/company/eg-australia/?ref=katecarruthers.com), and [me](https://katecarruthers.com/about-kate-carruthers/) \- hosted by the super smart (and friend of this podcast) [Felipe Flores](https://www.datafuturology.com/felipe-flores?ref=katecarruthers.com). We discussed best practices in data self-service at different levels of maturity, and had a robust Q&A session. Discussions included strategies for ensuring data trustworthiness and measuring ROI with self-service data practices. Tune in now to gain some valuable insights: [Data Futurology Podcast](https://www.datafuturology.com/podcast/2023/6/7/235-maximising-the-productivity-of-the-data-led-enterprise-with-unsw-eg-australia-and-compare-the-market?ref=katecarruthers.com) ### Thinking about data protection URL: https://katecarruthers.com/data-protection-episode-4/ Last updated: 2026-06-28T05:26:28.000Z [Episode link](https://open.spotify.com/episode/6Tg6R6X3cbdKXfSNHIsr3K?ref=katecarruthers.com) ## Transcript Hi, and welcome to episode 4 of the Data Revolution podcast. I'm [Kate Carruthers](https://katecarruthers.com/), and this time I'll be talking about data protection and how we need to work together with colleagues to ensure that data protection can happen effectively. This is because data protection is a team sport and no 1 person or no single business unit can do it all on their own. In recent times, I've started to use the term data protection as the umbrella term for the things that we need to manage in the organisation. And this includes things like cyber security, information security, data and information governance and privacy. And today I also want to run through the threat landscape so we can see why this is such a big focus area. Every organization holds huge amounts of personal information for staff and customers. They hold things like tax file numbers or social security numbers, bank accounts, other private details. And increasingly, every organization holds large amounts of customer and staff interaction data. And this is just growing exponentially. For example, a number of data points that we can capture in relation to a customer interactions and the AI-based analysis that we can do on that data increases every day. And we have an obligation to secure this data. And we also have an obligation to maintain the privacy of this data. So cybersecurity, information security, data governance, and enterprise risk management and privacy are a key focus. And as you all know by now, I believe that data governance is a key foundation for cyber and information security. So for effective data protection, we need to master all of these, each 1 of them, cybersecurity, information security, data and information governance, privacy and their all essential risk management functions. And these all need to be supported by sound policy and procedures, But we also need to make it easy for people to do the right thing. This is especially important because I have found in every single instance that convenience trumps privacy and cyber security in practice, every single time. So allow me a slight reminiscence. My organization got hacked back in 2012, way before it was cool. We got hacked in the same way that the Australian National University did only a few years ago. And since then, we've been beefing up our defenses because it was a real wake-up call. We weren't able to attribute it, but we thought it might be a state actor. And we had been very open to that attack. So we had to start to focus our cybersecurity and information security. And we appointed our first Chief Information Security Officer arising from that breach. But I want to now just talk about the difference between cyber security and information security because they're not the same thing. As I mentioned in an earlier episode, cyber security refers to the ability to protect or defend the use of cyberspace from cyber attacks. That's the definition from NIST. Whereas Information security refers to the maintenance of confidentiality, integrity and availability or CIA. That too is a NIST definition and I'm quite fond of NIST so you'll hear it fairly often. So NIST says information security is "quote, "the protection of information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction in order to provide confidentiality, integrity and availability". So both cyber and information security seek to reduce the attack surface. And this is another way of saying the different vulnerability areas. We commonly define the attack surface as between digital, physical and social engineering attack surfaces. And the big part of understanding our digital attack surface is understanding our assets. And these are largely data assets. We often call these known assets, unknown assets, and rogue assets. And a systems inventory is the starting place for understanding what data assets you have. And it's harder than you might think to do this. We've had several tries, we're still trying, but we keep finding more stuff. And now that people can just get out through port 80 and use their corporate credit card to acquire software as a service, a lot of assets are outside of our own organizational control. So The other things that we need to look at in addition to our digital attack surface is our physical attack surface and social engineering attack surface. Now physical attack surface is largely the province of IT and that's things like the servers and things that we have. And the social engineering attack surface is things like phishing and somebody impersonating you to the help desk and obtaining a credential. So that's a big threat for us now. And increasingly now, things that we used to think were quite solid, like voice prints. So biometrics like voice prints were quite, seem to be quite sound, but now with digital fakes, digital deep fakes, they only need a couple of seconds of your voice to create a deep fake of you and be able to then spoof your voice so that they can do a social engineering attack. So the thing that we often find with this is that there is a constant arms race. We get better, the bad folks get better, we get better, the bad folks get better. So it is a constant arms race and that's the big challenge with all of this. Now, the other side of this is the threat landscape. So that is the things that are out there that are coming to get us. And when looking at the threat landscape, and there's lots of places you can get this, but I like the ENISA version of the threat landscape. The proper name is the European Union Agency for Cybersecurity, and they put out a threat landscape every year. And I find theirs really helpful. So looking back at their 2020 threat landscape, they noted, "'Threat Landscape Maps' Malware Standing Strongest number 1 cyber threat in the EU, with an increase in phishing, identity theft, ransomware, monetization holding its place as cyber criminals' top motivation, and the COVID-19 environment fuelling attacks on homes, businesses, governments and critical infrastructure." Well that seems pretty prescient because that was what happened that year. So I recommend that you go and have a look at the [ENISA threat landscape](https://www.enisa.europa.eu/topics/cyber-threats/threats-and-trends?ref=katecarruthers.com) and I'll make sure that the link is in the show notes. And one of the problems we've got now is the perimeter has shifted. Back in the olden days, like 5 years ago, 10 years ago, you used to be able to lock yourself behind your firewalls. And once we were locked in safely behind our firewalls, the bad guys couldn't get to us there. But increasingly, and this has seen – shift has been driven much faster by COVID - the perimeter is now wherever someone logs into your network. And the weakest link in our security remains our people. So this means that we need to evolve our practices. You know, we can't hide behind our firewalls anymore. And it means that we need to up our data protection game. And Data protection, as I've mentioned, is not just 1 thing. It includes all of the things. So it's the practices with data and information governance, cyber and information security and privacy, but it's also a risk management function. And it means that we actually need to evolve our policies and procedures to provide sensible and practical guidance for people. We also need to improve our data management practices so that we build security and privacy into it. So we've all been talking about DevOps for the last few years. Increasingly, we're talking about DevSecOps, and we're also talking about privacy by design. And this leads us into the thing that you actually need to start to shift people and culture. And that's hard because culture is stronger than most things. There's a famous Peter Drucker quote that culture eats strategy for breakfast. I always joke that a strategy gets eaten for breakfast, lunch and dinner by culture. Once I worked at an organization and I came back a decade later and the culture was so strong, even though they had spent millions of dollars on cultural change programs, they hadn't shifted anything. The culture was still the same as the day I walked out 10 years before. So if we've got to change all of those practices, it means that we need an organizational commitment to it. But we also need to pay attention to our perimeter, because The perimeter is wherever people are. So we need to evolve our practices to make sure that we can monitor our perimeter no matter where people are. We need to actually understand our network and understand what normal traffic looks like. And the other thing that we need to do is secure our endpoints. So our endpoints are our devices and we need to secure our endpoints, especially now that everybody uses things like Office 365\. Because whenever you're operating on a file using Office 365 on a device, like a desktop or a laptop, every time you open a file, you're bringing a local copy down. So this means that endpoint encryption becomes increasingly important. And then we also need to make sure that we're doing, we've got to focus on application security. And this is a big part of the shift to DevSecOps. You might remember in an earlier episode that when I started the data governance program here at work, many people weren't really interested in it. And many even said they didn't want any help. But I got these 5 questions from Mike Burgess, who's currently the Director General of Security in charge of ASIO, the Australian Security Intelligence Organisation. And after we'd run through these questions, people would often end up sobbing on my shoulder, asking for help. And these 5 simple questions really help to focus people on the reality of how their data is managed. And I think they're extremely valid even now, and they will help the discussion across all of the things that I've mentioned. So the 5 questions are, and you're all going to get sick of me rambling on about these because I just think they're actually profound questions. First 1, do you know the value of your data? 2, do you know who has access to your data? 3, do you know where your data is? 4, do you know who's protecting your data? And 5, do you know how well your data is protected? And these, These are the sort of fundamental questions that we need to be starting to think about. And I like them because they put it in plain English. There's nothing technically complex about any of those questions, but they really help to focus your attention because if you don't know the answer to 1 of those questions, you know you've got a problem. I think we need more things like this in our world because in the world of data protection, there is a lot of jargon and a lot of big words that normal people don't understand. And we need to make this understandable for normal people. So 1 thing that cyber folks often talk about is defense in depth. This is the notion that a series of defensive mechanisms can be layered in order to protect valuable data and information. If 1 mechanism fails, another can then step in to stop an attack. And I always think that this is an important way that data governance can help because it can help add layers of protection in addition to all the technical layers that the cyber and infosec people can bring to bear. And 1 of the most important things is that data governance can help us to identify data risk, can help us locate sensitive data, and it can also enable us to ensure that sensitive data is stored and managed properly and appropriately. And it can also help us to identify the users of sensitive data and ensure that they have consistent data access processes. And also, you know, things like endpoint encryption and multi-factor authentication and all of those sort of protections that we use in the cyber and infosec space can ensure safer access to sensitive data. And the other thing that's really, really important is identifying who's using it and finding out if they actually have a legitimate business purpose for accessing sensitive data and discovering the location of data. It's harder than you would think. And a lot of us now have a lot of risk around our unstructured data. So the data that is in a database or an application is pretty well understood in most places. But the data that is stored on file systems and other places like that is often not very well understood organizationally and not very well protected quite often. And often that data flows through the enterprise and we don't know where it goes. And this is where we need to get tools like data loss or data leakage prevention. And this is all needed so that we can actually get people to help mitigate the risk to data. So most organizations would use the 3 lines of defense model to manage their risk. So this is a risk management discipline that looks at ownership, oversight and assurance of the risk management function. So the first line of defense is the functions that own and manage risk. The second line of defense are the functions that specialize in risk management and compliance. And then the third line of defense are the functions that provide independent assurance and internal audit. And 1 of the challenges we've got now with the first line of defence is that a lot of times business people are being asked to take on management of a risk that they don't understand, a technology or a technical risk that they don't have a clear understanding of the implications, especially when they accept risk. And increasingly, we're going to need to ensure that we actually have cyber information, security, privacy, and data and information governance running across all 3 lines of defense, because the risk is getting too hard for normal people to understand, especially in the AI space. As it's emerging, we're seeing a whole lot of new and interesting risks. So I think this is a really interesting area to keep an eye on, But I would say that normal managers are going to increasingly find that they will not be able to properly assess and understand the risk that they're taking, especially in respect of AI. So what can we do to protect our data? So there's this 10 things that I think every organization needs to do. So the first thing is understand which data assets need protection. So it means that you need to have a data classification standard, means that you need to understand how you ascertain a data asset is precious. The Second thing is we need to encrypt important data. And sometimes in databases, it's actually really hard to encrypt data. You think it's easy, but it's not because you take a performance hit when you encrypt. So you might choose to encrypt the overall instance that the database lives on, or you might choose to encrypt the database. But increasingly we're going to be starting to think that, no, encrypting an entire database is a bit of an overkill because you really do take a big performance hit. And we're going to start encrypting individual fields. And that means we're going to actually have to know what fields are important so that we can do that kind of thing. Then the third thing is user awareness training. Now I'm not a big fan of training being the answer to everything, but users are our weakest link and they need to understand the risks that they're dealing with. And training is often the only way that we can make that happen. The fourth thing is really going back to your information lifecycle and ensuring that you're storing only that data which is necessary. So every time we're storing data we need to ask ourselves if we need to store it, because if we don't it just adds so much risk to the organization. Number 5 is kind of a technical thing which is closing any unnecessary open ports. Open ports are an external vulnerability and if you leave them open, you open yourself up to unacceptable risk. So get your IT folks to go and see what ports are open and closed, the ones they don't need. The sixth thing, and these are in no particular order, the sixth thing I think is multi-factor authentication. As I said, the bad guys keep escalating, we keep escalating, but multi-factor authentication reduces your attack surface as an organization quite considerably, and is probably the single most important thing you can do. And number 7 is again a very technical 1, but review your network segmentation. If your network is designed so that people can't traverse across it, that is a great protection. And it's probably worth looking at that together with privileged access management. And then the eighth thing I think is improving email security. So you can implement things like Send a Policy Framework; Domain Keys Identified Mail; and Domain-based Message Automation, Authentication, Reporting, and Conformance that will really help to protect email. So that's SPF, DKIM and DMARC if you like your acronyms. So there are 3 things that you can really do that'll improve your email security. And again, they're very technical, your IT folks need to be doing this. 1 thing that the business can do is ensure that they have regular access reviews for users. And this is particularly important when people stay at the organization for a long time and have a lot of jobs and aggregate access as they go and never lose old access. So that's an important thing to be kind of picking up on because if those people who've aggregated a lot of access over the years get breached and their credentials are breached, then that's a real risk to the organization. And number 10 is a particular bug bear of mine, a proper patching schedule. So a lot of organizations do patching projects where they patch and then they don't patch for a couple of years. You need to be patching. Some of the biggest data breaches in history have been because somebody didn't apply a patch to a known vulnerability. So getting your patching done, this is operating system as well as application level patching, get a schedule and make it part of your practice because it will be so much better for the organization if you do that. So What I've learned so far is it's really important to methodically build up defensive layers. Don't just leave it to 1 layer, have multi-layers. Defense in depth is a real and sensible thing. The other thing is the power of incremental change. If you do 1 thing better every day, we work about 220 days per year. So if we do 1 thing better per day, then that is 220 things that have been improved. Times that by the number of people in your organization, that's an awful lot of incremental improvement. The other thing is that if we accept that data is an asset, then it needs to be managed and it needs to be managed sensibly and pragmatically, but it needs to be managed with a security lens. The other thing is that data security is a team effort and it needs everyone to work collaboratively. There is no single person in the organisation, no single business unit who knows how to make sure that the data is protected. It's a team sport. And data protection is a journey, not a destination. I often say it, but it is true. It's like painting the Harbour Bridge, once you finish painting you've got to start painting again. So it's an ongoing effort and it's important, that's why it's important to make it a team sport too, because otherwise you'll get very tired of it. That's all for now, hope you'll join me again next time. Thank you very much for listening. ### Global Data Power Women List 2023 URL: https://katecarruthers.com/global-data-power-women-list-2023/ Last updated: 2026-04-01T03:51:23.000Z It is an honour to be named on the [Global Data Power Women List](https://lp.cdomagazine.tech/2023/global-data-power-women/page-2?ref=katecarruthers.com) by CDO Magazine for 2023. This time it is for my work with the [UNSW AI Institute](https://www.unsw.edu.au/unsw-ai?ref=katecarruthers.com), which we have been starting up since 2022 as the flagship UNSW Research Institute in artificial intelligence, data science and machine learning. Go right now and check out all the interesting stuff that we are doing at [UNSW.ai](https://unsw.ai/?ref=katecarruthers.com) ![](https://katecarrutherscom.files.wordpress.com/2023/06/img_1075.png?w=620) CDO Magazine notes the following: > "The Global Data Power Women List 2023, presented by CDO Magazine, celebrates and recognizes the exceptional contributions of women in the field of data and analytics worldwide. This prestigious list showcases inspiring leaders, innovators, and trailblazers who have made a significant impact in harnessing the power of data to drive organizational success, fuel innovation, and shape the future of industries. > > These women have not only excelled in their respective roles but have also paved the way for others, breaking barriers and driving change within their organizations and across industries. They have demonstrated their expertise in various domains, such as data strategy, data governance, artificial intelligence, machine learning, predictive analytics, data ethics, and emerging technologies. > > The list aims to inspire future generations of data professionals, foster diversity and inclusion within the data field, and drive the empowerment of women in data-related roles. It serves as a testament to the immense talent and contributions of women in shaping the data-driven world we live in today." > > [CDO Magazine 2023 Global Data Power Women](https://lp.cdomagazine.tech/2023/global-data-power-women/page-2?ref=katecarruthers.com) ### Mark Pesce talking AI URL: https://katecarruthers.com/mark-pesce-talking-ai-episode-3/ Last updated: 2026-08-08T06:22:38.000Z In this episode I am having a chat with [Mark Pesce](https://new.markpesce.com/?ref=katecarruthers.com) about artificial intelligence (AI). Mark is a well known futurist, inventor, author, educator and broadcaster. We talk about how fast AI is moving, in weeks and days not months or years anymore. And we also talk about some of the scary stuff and how this technology does not have agency (yet), and about how it will change the ways that we all work. Mark also talks about how there are some amazing developments in the open source space in AI, and shares his vision for a future where AI works for us and does not destroy all life. You can find more about Mark and his work at [https://markpesce.com/](https://markpesce.com/?ref=katecarruthers.com) [Link to episode](https://open.spotify.com/episode/5cweeXstCmBIK2DGZBLZ8a?ref=katecarruthers.com) ### Data governance and why it is important URL: https://katecarruthers.com/episode-2-data-governance-and-why-it-is-important/ Last updated: 2026-05-15T02:54:21.000Z In this episode Kate talks about why data governance is important and the features of a good data governance program. With a slight digression on why data is not the new oil and the problem with data. [Episode link](https://open.spotify.com/episode/7jov7aSgH5ayEX3xJLnfXz?ref=katecarruthers.com) ## Transcript Hi, and welcome to episode two of the Data Revolution podcast. I'm Kate Carruthers, and this time I'll be talking about data governance and why it's important. I will also make a slight progression to share my thoughts on data as a new oil and some of the problems with data. First, a bit of an explanation about what I'm going to be doing with the podcast. I'm planning on a mix of episodes in the near future. One kind will be like this one, where I'm sharing my thoughts on a particular aspect of data practice, and the other will be a series of interesting guests. I'm pretty excited about the lineup of the guests, and we'll share information about them on my [https://datarevolution.tech](https://katecarruthers.com/the-hidden-risks-of-agentic-ai-every-leader-must-know-now/) website. That's data revolution one word dot tech. ![](https://datarevolutiontech.wordpress.com/wp-content/uploads/2023/09/ascention-data-governance.png?w=300) Today I want to talk about data governance. This is because it's not well understood, and most folks don't understand why it's important. Also, as anyone who's known me for the last decade or so, you've heard me bang on about data governance for years. I'm often at conferences saying that data governance is the foundation for information and security, and I want to explain what I mean by this. I tend to think that data governance has been badly named. It's a name that does not immediately convey the utility of the concept to ordinary folks. It's not catchy, and it doesn't roll off the tongue easily. You can tell that the people who came up with this were not marketers. There are many definitions of data governance, but my favourite one is from a colleague in the US, john Ladley, and it's from his 2012 book Data Governance how to Design, Deploy, and Sustain an Effective Data Governance Program. It's still one of the definitive works in the area, and his stuff is worth reading. He defines data governance as "the organization and implementation of policies, procedures, structure, roles and responsibilities which outline and enforce rules of engagement, decision rights, and accountabilities for the effective management of information assets." You can see this definition on my website at [https://datagovernance.unsw.edu.au](https://datagovernance.unsw.edu.au/?ref=katecarruthers.com). I like this definition because it covers all the notes of what goes into making a good data governance program. This definition covers all the major features of a data governance program, and at work, my data governance manager has distilled it even further: "Put simply, data governance is the creation and implementation of rules to protect data and to get the most benefit from data." And this takes us at starting principle the fact that we treat data as an asset that needs to be managed like an asset. But one thing this definition does not provide is a reason why we need to do data governance at all. Data governance is an essential risk management function, and it provides key information for decision making around information security and cybersecurity spending. If we don't understand where our data is, how valuable our data is, or how it is protected, then we're probably making ill informed judgments about where to spend our scarce information security and cybersecurity dollars. To protect our data effectively, we need to understand it. Increasingly, our data landscape is moving from a simple, internally hosted one to a complex, multi-hosted landscape across which we disclose, manipulate, and consume data often. Now, our data is hosted across multiple cloud environments, as well as on premise, as well as software as a service, and this adds to the complexity. There is also an increasingly complex landscape of privacy and compliance that we need to navigate, and data governance provides the foundations for this as well. A good data governance program will ensure that data is secured, trustworthy, documented, managed, and audited. In my day job, data and information governance is framed around the five no's, which I got from Mike Burgess when he was at Telstra many years ago, and he's now at ASIO. We work on ensuring that we know the answers to each of these questions for our data. - Question one: do you know the value of your data? - Question two: do you know who has access to your data? - Question three: do you know where your data is? - Question four: do you know who is protecting your data? - Question five: do you know how well your data is protected? I literally used to walk around the university in the early days of establishing our data governance program with all of these questions on a laminated sheet, and the conversation would go something like this: "*I don't need no stinking data governance*" oh, just answer the questions on this sheet, and if you can answer them, you're fine. It would typically result in the person sobbing on my shoulder saying, please help me, Kate. So that was a good way to frame a data governance conversation. Now, if we want to treat data as an asset, then we need to make sure that data is used properly. And we also need to make sure that we can prevent data errors, especially now with the growth in AI. And we also need to make sure that misuse of personal or sensitive data doesn't take place. The best starting point to achieve this is through clear policies on data use and effective procedures to monitor and enforce these policies. Another important benefit of a data governance program is improving data security. One of the key objectives of data governance is ensuring that all data is secure if it needs to be, and that there is no unauthorized data access. This means that the Data Governance Office will need to work with colleagues across the organization, and in particular, across information technology, cybersecurity, and information security teams. A good data governance framework must also include specifics of how data can be distributed and shared, both entire and externally to the organization, because inappropriate data sharing is often a vector for cyberattacks nowadays. One thing I've discovered about use of data internally is that folks are just trying to get their jobs done. And they often need data, but don't understand the risks inherent in the way that they are storing and using that data. Now, I'm going to take a small digression here. I have ADHD and you'll just have to put up with this kind of thing. There's a well known article in the Economist that was titled the world's most valuable resource is no longer oil. No longer oil, but data. And it said, quote, a new commodity spawns a lucrative fast growing industry, prompting antitrust regulators to step in to restrain those who control its flow. A century ago, the resourcing question was oil. Now, similar concerns being raised by the giants at dealing data the oil of the digital era. But if you think about it, this analogy just doesn't make sense. This thing about data being the new oil was in the context of the need to regulate the data economy. And I believe that regulation of data does remain an extremely valid point, and some regulation would be a bloody good idea. Several years ago, in the past, I used this analogy of data being the new oil in several presentations, but in the context of showing people that there was an awful lot of it to manage. But that was before I really thought about it. Then I realized that data is very unlike oil in important ways. Data is the ultimate resource. It keeps growing and there seems to be very little that we can do to stop its proliferation. Now, I think that data is the endless resource that is only limited by our storage and analytics capabilities and by our capacity for regulation. So now I want to talk about the problem with data. The problem with data is it's really easy to make, it's really easy to create and store it. And so this is often done without any thought as to whether it is the appropriate thing to do. Anyone with an internet connection and some basic skills can start to collect and store data online and there are no rules for how anyone ought to store data, which explains why so many data breaches are just really some random person who stored personal data in an unsecured s three bucket. Further, often the safety of stored data does not seem to be top of mind. Remember that enormous Equifax data breach back in 2017? That organization had tremendous amounts of personal information on a global basis and they could not even be bothered to patch against known vulnerabilities. And this experience does not seem to have given rise to any learnings whatsoever on the part of local organizations, many of whom have had major data breaches in recent memory that disclose the personal data of millions of Australians. Apart from the obvious implications for data security practices, it seems as if we have not established a velocity of data and that our model for understanding data and rights in respect of data is that of property. And if we accept this, then we almost also accept that our model for privacy, which is based on informed and explicit consent, is also not quite ready for the world where data about us is so readily captured, stored and shared, often without our explicit consent. And then we've also got to remember the cookies fiasco where everybody just clicks yes to get to what they need. So utility trumps privacy every time. So it seems to me that we have a lot more thinking to do about data privacy and security. But one thing is clear is that data will continue to proliferate. And until we sort these things out, its proliferation and its safe storage and usage is going to remain problematic. This will have an impact on our data governance programs in the future. Now, back to data governance. There is a quote from Kent Aiken, who was a Prime Minister's Fellow in Canada that I use all the time in presentations. He said, "Complexity is the defining feature of the digital era, and we are not adjusting our governance structures to manage it." I truly feel that this sums up the challenge we have with data governance. Increasingly, we need data governance that can operate programmatically and autonomously at the edge of our networks. But the tool sets that are available to us are only slowly creeping towards that kind of functionality. They're kind of primitive, to be sure. But coming back to what data governance programs can help with how data governance can help with identifying data at risk is an important consideration. If you want to identify data at risk, you need to have a classification framework for data. And once you've located sensitive data, you need to ensure that that sensitive data is stored and managed properly. That means that you need to have a set of data handling guidelines that specify how to manage data across its entire lifecycle, including data creation, data access, data storage, data transmission, data processing, data integration and flow, data disposal, and data retention. Now, data disposal is the one thing we all need to get better at doing. I keep saying that we are all such terrible hoarders of data. We hoard it like dwarves hoarding gold. And we need to get better at getting rid of the data that we don't need, because all it is is a risk, not an asset. And you also need to think about things like data sovereignty and data management. And data management practice is something we need to talk about in a future episode. Some other things that a data governance program can assist with, including complying with increasing regulatory requirements, improving data security via collaboration with information and cybersecurity professionals, creating and enforcing data distribution and data sharing policies, creating the basis for effective data and analytics operations. And we're going to talk a lot about this over the course of the podcast and also identifying the crown jewels. So your precious things that really need to be protected by your cyber and infosec teams. So there's a number of key factors about running a successful data and information governance program. First of all, data governance needs to be a good fit for each specific data domain and for the business operations it supports. It needs to be developed collaboratively with the stakeholders because there's no single one right answer for every part of the organization. And a data governance program that doesn't take account of the differences across the organization will ultimately be unsuccessful because it won't meet stakeholder needs. So data governance needs to be a stakeholder driven activity and you shouldn't engage in it if they're not coming along on the journey with you. And the data and information governance framework needs to be able to help the business to better manage information and data quality. If it's not doing that, then there's no point doing it. So no data and information governance activities ought to be undertaken without stakeholder buy in and leadership. I always frame our work in the data and information Governance office as facilitation rather than leadership. Now, there's some other things that need to be lined up and these are in no particular order is you need to assess and define your risk and controls. You need consistent data definitions across the entire organization. And this has been a perennial problem. I worked on a data warehouse project at GIO back in the day. That was one of our big problems with inconsistent data definitions, and I'm pretty sure it's just the same everywhere. Now we need to have data driven improvements, so using data to drive the improvements also makes sense. One of the big things we also need to build is data literacy, and that's a real challenge to develop that across the entire organization. And the other thing that we really need to focus on is data quality because all of our AI efforts will be for naught if we have really bad quality data. And then the two practices that I really think every organization needs is master data management and metadata management. Tracking provenance of data as it moves around now becomes even more important. But the most important thing of all that needs to be clarified and agrees, the roles and responsibilities and in particular establishment of decision making rights and input rights in respect of data. Getting to who is the decider is the most single important thing to do, and then the next thing is to empower those people to start making decisions about the data. But above all, managing data risk is a team sport. There's no single part of the organization that has all the answers. Reducing risk needs collaboration and it needs broad collaboration across the entire organization. Based on my experience, it really does take a village to establish an effective data governance program. It reminds me of that saying, if you want to go fast, go alone. If you want to go far, go together. So I recommend that you find allies within your organization who can collaborate with you and also find allies outside your organization for knowledge sharing and commiseration and possibly drinks. That's all for now. Hopefully you'll all join me again next time, where we'll be joined by a special guest. Thank you very much for listening. ### Introducing the Data Revolution podcast URL: https://katecarruthers.com/episode-1-introductions/ Last updated: 2026-05-15T02:52:54.000Z Welcome to Episode 1 of the Data Revolution podcast. In this episode I cover my personal journey into the world of data and give an overview of some key concepts for future episodes. [https://open.spotify.com/episode/2KxUuAC2RH0ZV7FR9qdKUb](https://open.spotify.com/episode/2KxUuAC2RH0ZV7FR9qdKUb?ref=katecarruthers.com) ## Transcript Welcome to my podcast. It's called Data Revolution. The Data Revolution podcast is about exploring the intersections between business intelligence, data analytics, artificial intelligence, privacy, data protection, cyber and information security. And as I keep saying, data and cyber are the 2 biggest growth industries left to us now. My name is Kate Carruthers, and for this first episode, I thought I'd share my personal journey and how I came to be fascinated by data and the amazing and terrifying things that it can do for us. I work at the University of New South Wales as Chief Data and Insights Officer, starting in that role way back in 2014\. It was the first appointment of a Chief Data Officer or CDO in Australian higher education. Before that, I'd been working in the engineering faculty as the IT manager for a couple of years. I was managing a plethora of technology that makes engineering teaching and research work, including the many high-performance computing clusters. Back in the day, we had more than 20 HPC clusters in the faculty, as well as access to various external HPC facilities, such as the National Computing Infrastructure at the Australian National University, Pawsey Centre in Perth, and multiple international facilities. Because one thing I learned back in those days was that engineering has an infinite capacity for compute and storage. But one day I made the fatal error of asking some questions, questions about data. Like where were we allowed to store sensitive research data? What were the rules for how we had to handle such data? And there were no good answers. So I ended up applying for the role and got it. The interview process was fascinating to me because I'd never really thought of myself as a data person. I'd also always been an IT person. I'd worked in all sorts of roles across the information and communications technology landscape before landing in the world of projects, and large projects because small projects bored me. But in the olden days last century, I'd worked as a database administrator, as a data modeler, and I swear I am the world's worst data modeler. I am slow and ineffectual. I had also worked as a consultant on the implementation of several enterprise data warehouses, or EDWs, using tools like Cognos, Oracle, Hyperion, Business Objects, and others that are all long gone now. I even lived through the Kimball vs. Inmon data warehousing wars of the 1990s. This was where folks took opposing sides in a data warehousing structure debate, coming down either on the side of Ralph Kimball and his conformed dimensions in star schemas, or on the side of Bill Inman and his normalized forms for entity structures and data marts for querying. Full disclosure, I was a Kimball fan back in the day and every data warehouse that I've worked on has been a Kimball style 1. But Inmon has now finally won me over with his idea of the data lake house, which we'll cover in future episodes. But in addition, I had also worked extensively in web and e-commerce development at scale and also in digital strategy and digital marketing. I was cognizant about the world was undergoing technological changes that were akin to the Industrial Revolution. And I realised that we needed to get ready for these changes. So in reality, I was kind of a data person. But as I started to think about the future, and remember this was back in 2014, I started to realise that all our digital transformation would be driven by data. Digital is actually impossible without data, and if the university wanted to transform, as many businesses did back in the day, and bear in mind, they hadn't even thought about digital transformation back then, they would need to sort out their data. And that is what I've been working on ever since. Now, I just want to touch on some themes that I'll be coming back to in this podcast. First of all is data. Back in the day, we used to hoard data, storing it in databases like dwarves hoarding gold. But we never really did much of anything with it. We ran some reports, but this data was static. It sat there, it was difficult to join up even for reporting. And much of the reason for the rise of the enterprise data warehouse was to deal with the issues relating to the constraints of physical servers, of physical disk and memory. And this was part of what made even enterprise data warehousing really tricky was because you had finite scale servers with finite scale disk and memory. And a lot of the things that both Ralph and Bill talked about were due to the constraints of physicality. But now with the cloud, Data can flow, it can scale almost infinitely, and with all those memory and disk constraints gone, we can now do almost anything we want with our data. Now data flows and it drives business processes. It drives autonomous actions at the edge of our networks. And it's the key to so many things in our world. Secondly, there is the rise of Artificial Intelligence or AI. And this is about to change our world in ways that we can only dimly discern at the moment. I want to briefly explain how I conceptualize the AI world and how I explain it to normal human beings. So let's start with artificial intelligence or AI. This is the field of computer science that wants to create intelligent machines that can replicate or even exceed human intelligence. It's the idea of machines thinking like people. It's kind of the umbrella term for anything in this space, but typically once it's in production, it's got a different name. So AI is the general thing, but the specific thing has a specific name once it turns into a production application. And a subset of AI is machine learning, or ML. This is the subset of AI that enables machines to learn from existing data, and also to improve upon that data to make decisions or predictions. Tom Mitchell wrote the book on ML, literally the book, as recently as 1997, so it's still fairly new. But that's been powering our predictive analytics for a long time now. The next subset of it is deep learning, which is a machine learning technique in which layers of neural networks are used to process data and make decisions. And These are working typically able to make supervised and unsupervised decisions. And then there's generative AI, which enables AI to create new, and new is kind of debatable, visual auditory content given prompts. So we talk about prompt engineers now or existing datasets. So this is sort of tools like chat GPT or auto GPT that are rewriting what is possible now. And I was at a conference this week where 1 of the professors at Nanyang Technological University in Singapore was talking about some of the legal issues that are arising in respect of things like CHAT-GPT. And she was saying that 1 should not rely on its ability to discern if something is genuinely new. So she did recommend not using poems that it writes as your own because you might be up for a copyright violation. But this all gives rise to the next thing. There is now a huge need to protect all of this data. And this is where cybersecurity and information security come into play. And now I want to take a moment to define both of these things, just so we can be clear what I'm talking about. So cybersecurity, or cybersec, is all about protecting our assets from external threats. Or as NIST, also known as the US National Institute of Standards and Technology likes to say, quote, the ability to protect or defend the use of cyberspace from cyber attacks. So these are people outside your organization trying to attack your cyberspace. And information security or InfoSec is all about maintaining the CIA, that is the confidentiality, integrity and availability of data. Resnist says, quote, the protection of information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction in order to provide confidentiality, integrity and availability. Now, both of these are exceptionally important now, but the thing that keeps me up at night is data integrity. For example, just imagine if you're wearing an implanted medical device. You would want to be very certain of the CIA for this device. And it's changed a lot. Back in the late 20th century when I was managing my first IT system, it was a Unix system. It was running system 5 Unix. And it had a whole 16 megabytes of RAM. We never really gave any thought to information security or cybersecurity back in those days. There were much more innocent days. In those times hackers were more interested in phreaking, that's with a PH, or hacking into telecommunications. So they were often hacking telcos so that they could make free phone calls. But those times are gone now. Now it's easier to run a malware attack than it is to rob a bank. In the late last century, bank robbing was a very, very popular way to make money. But now you can sit at home in your pajamas and just rob from wherever you are. And this is only gonna get easier due to things like generative AI, because you can ask it to write your malware. Recently, I've had Rust learning the Rust language on my to-do list for ages, And I never get around to it because I keep doing other things, but I asked ChatGPT to write some Rust code for me and it wrote it, I took it, it ran, it was fine. So developers, it'll be interesting to see what happens with your jobs in the future. Other things are changing too, things like the face of war. In the past, wars were declared up front between 2 states, but now Russia's been at war with the West for the past decade at least, and has been waging an information war against us, using tools of disinformation and misinformation. And with the advent of the Stuxnet attack by the US and Israelis, the notion of states reaching out to interfere on foreign soil without even setting a foot there became a reality. Now, Stuxnet was a malicious computer worm designed by the US and Israeli intelligence services and it was deployed to disable a key part of the Iranian nuclear program. And it was discovered in about 2010\. Might've been written 2005, not sure, but it heralded a new world where we can have wars that are not your traditional declaring a war and fighting a war, 2 armies standing face to face fighting. Now there is all of this information warfare that is happening. And now in Ukraine, We're seeing new ways of waging war with drones and new AVs. And technology and data underpin all of this. So the future of war is data-driven too. So I would argue that the future of everything is data-driven. So some of the topics that I'll cover in future episodes will include AI and ethics, data governance and why it's essential. Also things looking at things like new jobs that are emerging, what practices that data professionals will need to adopt, And how new technology is changing the face of warfare, because it's a particular interest of mine. That is all for now. I'm going to try for a fortnightly cadence. For non-Aussies, that means every other week. Hope you'll join me again next time. Thank you ### Data Revolution podcast is live! URL: https://katecarruthers.com/data-revolution-podcast-is-live/ Last updated: 2026-04-01T03:51:23.000Z First episode is now live and up on the new Data Revolution website: [https://datarevolution.tech](https://datarevolution.tech/?ref=katecarruthers.com) ### Welcome to the Data Revolution Podcast URL: https://katecarruthers.com/introducing-the-podcast/ Last updated: 2026-05-15T02:52:12.000Z In this episode Kate Carruthers covers her personal journey into the world of data and gives an overview of some key concepts for future episodes of the Data Revolution podcast. Thanks for listening! You can find more episodes at [Data Revolution Podcast](https://open.spotify.com/show/2lGSsLAnoeXPwmRlnZVrpE?ref=katecarruthers.com) [https://open.spotify.com/episode/2KxUuAC2RH0ZV7FR9qdKUb](https://open.spotify.com/episode/2KxUuAC2RH0ZV7FR9qdKUb?ref=katecarruthers.com) ### Data Revolution Podcast URL: https://katecarruthers.com/data-revolution-podcast/ Last updated: 2026-04-01T03:51:23.000Z Well I’m about to launch a new podcast. It’s going to be all about the intersections between business intelligence, data analytics, AI, privacy, data protection, cyber and information security. As I keep saying data and cyber are the two biggest growth industries that we have now. I have no idea what to call it though, am currently thinking of calling it the “Data Revolution Podcast”. But that may change if I come up with a better idea. The [Data Revolution Podcast](https://datarevolution.buzzsprout.com/?ref=katecarruthers.com) site is live now 💁‍♀️ ### Chat GPT changes everything (and some of it is bad) URL: https://katecarruthers.com/chat-gpt-ai-bad/ Last updated: 2026-04-01T03:51:23.000Z The world has been on the brink of revolutionary technological change for a while now and Chat GPT and related generative AI technologies might just have tipped us over into a brave new world. Ordinary folks are starting to see the power and possibilities with AI. We are about to see the flourishing of many innovative solutions that are driven by the combined power of data and [large language models](https://en.wikipedia.org/wiki/Large%5Flanguage%5Fmodel?ref=katecarruthers.com) (LLMs). But there are some issues facing this technology. For example, I am just waiting for all the copyright, patent, and trademark infringement lawsuits to commence. My colleague [Toby Walsh](http://www.cse.unsw.edu.au/~tw/?ref=katecarruthers.com) has been sounding the alarm about the dangers of '[killer robots](https://theconversation.com/killer-robots-will-be-nothing-like-the-movies-show-heres-where-the-real-threats-lie-192170?ref=katecarruthers.com)' - with the danger of autonomous robots being used to attack one's enemies. For example, Iran’s top nuclear scientist was [assassinated by Israeli agents](https://www.nytimes.com/2021/09/18/world/middleeast/iran-nuclear-fakhrizadeh-assassination-israel.html?ref=katecarruthers.com) using a robot machine gun in 2020\. But let's just imagine the power of technology that can act autonomously in the real world and talk to generative AI driven business process engines. It will be interesting to see how generative AI will merge with robotics in the real world in the future. All of this technology is neutral - it can be used for both good and evil. The trouble is that the evildoers can do real damage in the real world. Following is an example of some real world potential impacts arising from generative AI. ### New affordances in Generative AI There was an interesting [tweet thread](https://twitter.com/NFT%5FGOD/status/1658097634786025472?s=20&ref=katecarruthers.com) the other day. A user name [@NFT\_GOD](https://twitter.com/NFT%5FGOD?ref%5Fsrc=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor&ref=katecarruthers.com) asked "Autogpt to manipulate the results of the 2024 US Presidential election It put together a full scale plan to tear down candidates through wide scale misinformation and deepfake technology The results should scare the hell out of you" - he walks us through his prompts to create an entire misinformation campaign to disrupt the US 2024 Presidential election. ![Tweet copy reads: "I asked Autogpt to manipulate the results of the 2024 US Presidential election

It put together a full scale plan to tear down candidates through wide scale misinformation and deepfake technology

The results should scare the hell out of you:"" class="wp-image-24795">

He outlines a process by which one single person can create a disinformation/ misinformation campaign and automate the execution of it. This kind of thing has been done for years, but it used to require armies of humans, and now it can be just bots.

As @NFT_GOD says: