Episode 852 ·

Exploring the Tension Between AI Law and Innovation with Kevin Korpics and Reza Zaheri from Quantum Metric

Today, we're talking to Kevin Korpics, Field CTO and Reza Zaheri, CISO at Quantum Metric. We discuss the impact of AI law in the EU, the levels of regulation that affect your business based on risk, and how to stop being a workaholic.

All of this right here, right now, on the Modern CTO Podcast!

To learn more about Quantum Metric, check out their website here.

Produced by ProSeries Media: https://proseriesmedia.com/

For booking inquiries, email [email protected]

About Kevin Korpics

Kevin Korpics is a Field CTO at Quantum Metric, bringing versatility to his role by contributing across sales, customer success, marketing, and product development. With a focus on translating business challenges into effective AI implementations, Kevin plays a key role in developing and implementing the Felix AI product. His expertise lies in bridging the gap between technical solutions and practical business applications, particularly in the realm of customer insights and AI-driven analytics.

About Reza Zaheri

Reza has over 23 years of leadership and hands-on experience managing Digital Forensics, Incident Response, Cyber Security Awareness and Security Engineering programs for Fortune 100 companies - having both lead as well as conducted cyber investigations across the United States and Latin American for many of those years. He also founded his own security training company, incorporating his unique style of presentation storytelling, emotions and humor into his curriculum to personally train over 80,000 people on cyber security awareness, a topic for which he is extremely passionate. Reza is now honored to be serving as Quantum Metric’s CISO for the past 4 years, a company with a world-class and unparalleled digital analytics product, and an amazing culture to match.

About Quantum Metric

As the pioneer in Continuous Product Design, Quantum Metric helps organizations put customers at the heart of everything they do. The Quantum Metric platform empowers a customer-centric culture, helping business and technology teams align faster on customer needs and prioritize the opportunities that will drive the most value.

Today, Quantum Metric captures insights from 29 percent of the world’s internet users, supporting globally recognized brands in retail, travel, financial services, and telecommunications.

Transcript

(Intro Narrator at 00:00:00) Today, we're talking to Reza and Kevin from Quantum Metric about GDPR for AI and how we should innovate with it. Thank you to US Cloud for being our podcast takeover for this quarter. To learn more about how you can save on Microsoft support, listen to the end of the episode or go to uscloud.com today. You're listening to Joel Beasley, Modern CTO.

(Joel Beasley at 00:00:27) I was actually very intrigued about this conversation because I didn't know this was happening. GDPR for AI, that's something that's occurring over in your world. Can you tell me about that?

(Reza at 00:00:38) So what we're seeing here, Joel, in the EU is this healthy tension, if you will, between AI innovation and regulation. I'm sure your audience members will know these AI models that we're dealing with right now—they're collecting vast amounts of data. The more the merrier. And some people could argue that some of the ways that some of these models have collected this data is questionable. So over here in the EU, these companies are trying to figure out how to strike the right balance between enabling the business to use AI as productively as possible, to benefit from it as much as possible and remain competitive. But at the same time—and you'll hear me say this a lot, and I'm saying this purposefully—to use it in a very ethical and responsible way. This is something that's been pushed a lot, especially with this EU AI Act that you're mentioning.

(Reza at 00:01:30) And if I can explain what ethical AI means, it's basically an AI system or model that is designed in a way that's very safe for everyone to use. It's fair. There's no inherent bias in the system. It doesn't infringe on our fundamental need for privacy. It doesn't infringe on our human rights and values. And so this EU AI Act that you mentioned, which is aiming to set the gold standard for AI, it's an interesting law. It's just gone into effect towards the end of last year. Some of it's already in effect, and it's going to be fully in effect by 2026.

(Reza at 00:02:10) But this really pushes this notion of ethical and responsible use of AI. And so with the EU AI Act, basically, the way it's broken down—it's actually an interesting law. It takes a risk-based approach when it comes to AI and regulation. So there's four levels of risk, Joel. The highest is basically unacceptable. It's just an absolute no-no. This AI model is infringing on our rights. It may even threaten our safety as humans. So those types of AI systems are an absolute no-no in the EU. The next level is high. So that's high risk. The way I could explain that is it's an AI model that makes very significant or consequential decisions about us, like hiring decisions or lending money. So that's high risk.

(Reza at 00:03:06) And then limited risk is a low-risk model, like basically your chatbots, really. And then the lowest one is minimal, which is, for all intents and purposes, not really regulated because it's such low risk. And so depending on where your AI model that you're working with falls into these categories, it will be regulated accordingly. One other thing, if I could say—they're very big on transparency here now in the EU. And what I mean by that is they want these AI models to be very open and honest. They want everyone to know that they're engaging with this AI, how it operates under the hood. So one good example I can give you and your audience is now you can see there's more of these newer reasoning models, these longer thinking models. So you're basically typing a prompt. You'll ask a question, and then instead of just spitting out the response right then and there, it will systematically break down exactly how it's thinking in real time.

(Reza at 00:04:04) So you see it. You literally see it in real time, the thought process of how it's arriving at the answer. Yeah. Yeah. It's really cool. I mean, it's so cool to see this, to behold. And so this is something that we're moving towards. They're really big on this. And there's also a big push for AI literacy, which I'm sure we can definitely talk about as well. But yeah, the final thing I'll say is just like I think you described it very well as far as being the GDPR for AI. Just like with GDPR, there's big fines now for noncompliance. So businesses that are operating in the EU that are going to be working with these AI models, they should definitely take heed and take a close look at this EU AI Act.

(Joel Beasley at 00:04:49) I've got some questions here for you. So this is more forward looking, right? When you started out, you mentioned there's a lot of controversy around how these were formed, but then the majority of your response and focus was on the future and categorizing your models and where you will fall in the regulatory landscape. Are they just focused moving forward on let's categorize these models and dump them into a regulatory landscape? Or are they actually trying to go dig up the past and be like, hey, you know, you guys owe these people money because you've trained your models on their data?

(Reza at 00:05:24) Yeah. So the big thing for us right now—and I say us, I mean, it also applies in the US and other countries, but definitely in the EU—is about building trust. So there's this kind of inherent mistrust for AI, generally speaking. People just don't know what they don't know. They don't understand this, so therefore, they don't trust it. And so a lot of these initiatives, like these things about being transparent, being open, being honest, being ethical, this is all about really making sure that there's more public awareness around AI. Again, it's very forward thinking to answer your question. And to have them to basically trust these systems more and embrace them more. So I hope that makes sense.

(Joel Beasley at 00:06:11) Yeah. And so the AI Act, where is it actually right now? Is it proposed law? Is there something in place? Is there something you can go read? Where is it at right now?

(Reza at 00:06:23) Yeah. So basically it came out in August 2024. So that's when it officially came out. But for it to be fully implemented, fully enforced, I believe it's in August 2026. But in February, just this past February 2025, parts of the law just came into effect. One of them, in particular, is this AI literacy piece where the requirement is that anyone that is working with AI, either working with them or developing, building out AI, that they have some form of reasonable AI literacy. So they basically understand how to use AI, what are the general risks and pitfalls of working with these models. So that's the main thing right now that's being enforced, but it will go fully into effect in 2026.

(Joel Beasley at 00:07:13) And when you mentioned the high-risk models, like significant hiring decisions, lending money, you also mentioned that one of the goals of this, and you can correct me if I'm wrong, is that there's no inherent bias in the system, things like that, making sure that it's coming to the right conclusions. In the bill, in the paperwork, are they actually addressing specific situations or how to actually do this? And I'll give you one example. I had on a guest a few years ago that talked about Apple Pay or Apple Credit. Some major person in tech, he was very upset that his credit limit was different than his wife's credit limit, and now there's bias. But then they went in this big report on it, and it turns out that it didn't actually know that it was women. It just followed the trend of purchases and then associated with the credit. So the model itself had no context of woman, yet it was biased towards women based off of the purchase history. Interesting.

(Joel Beasley at 00:08:20) That's a complicated situation. So I'm not asking for you to state your exact opinion on that specific situation. I'm asking in the bill itself, are they handling stuff, or is it kind of like currently too fluffy, like language is fluffy? It's just like, hey, we're just going to try to be good. We're going to try to make sure it doesn't have this stuff. Where is the bill at?

(Reza at 00:08:40) Yeah. No, that's a good question. You know, as you know, I'm sure your audience members know, Joel, this is a work in progress. AI obviously just kind of blindsided everyone, really, in earnest a year or two ago. And so they're not looking for perfection, per se. Really, it's more the spirit of the law than the letter. I mean, obviously, yes, there are specific stipulations saying they shouldn't be biased, that it needs to be fair, that there isn't anything that these things don't spit out anything offensive or things of that nature.

(Joel Beasley at 00:09:15) It is very subjective words though.

(Reza at 00:09:17) Exactly. Exactly. But really, what they're looking for—and there's also, for instance, this ISO 42001. There's a new standard that's come out as well that we can talk about as well, which basically, again, it's similar to the ISO 27001, but really it's just for AI systems. And really what they're saying, what they want is they don't want companies to just slap a bunch of stuff together and go, okay, great, I'm on the AI bandwagon. You know, let's do this. They're looking for evidence, and they want to make sure that there's good intention around and purpose around building these AI models that, again, are ethical, they are fair. They want to see efforts towards that goal. Right?

(Joel Beasley at 00:10:02) Right.

(Reza at 00:10:02) So for instance, with bias, one of the things, one of the really interesting things about transparency they push for—there's this thing called human-in-the-loop testing with AI. And so what human-in-the-loop testing is, for any AI system that generates output, they want a human in that loop, some kind of a subject matter expert that can look at that output and go, okay, yeah, that's accurate, that's fair. That doesn't infringe on privacy or human rights or anything like that. And so being able to demonstrate these types of things goes a long way to say, look, of course we can't—there's no AI model today that's absolutely perfect because a lot of this stuff is being trained on data that they've collected from the Internet. And as we know, Joel, the Internet is very flawed. But they just want to see that there is a goodwill effort towards that end, as far as ethics and non-biased, et cetera.

(Joel Beasley at 00:11:11) And when we talk about companies, AI and privacy, what's the biggest thing that they're currently getting wrong?

(Reza at 00:11:17) So that's an interesting question. And I'm sure Kevin can attest to this as well. So, you know, because we have, you know, Quantum Metric, we have this Felix AI product that we offer. So we get questionnaires from prospects, from customers. And Kevin and I, we read a lot of these questionnaires. And I will say, Joel, that when we read some of these, the fear is palpable. You can tell there's this mistrust, like I was mentioning earlier. People just they don't trust AI. They don't know. And so I don't blame them. I absolutely do not blame them whatsoever. This AI train is moving so fast. There's so much coming at us. There's literally multiple breakthroughs happening every week in the world of AI. And so I get it. They don't know what they don't know. And so what we see is that, unfortunately, some folks, they unfortunately kind of assume the worst-case scenario when it comes to AI. And they assume that we're building our own AI model in-house. We're training it with sensitive data. We're using customer data to train these models. And just basically the way we're doing it is super risky, really dodgy the way we're implementing it. And it couldn't be further from the truth, Joel. You know, and Kevin, I know you remember. We spoke with one individual recently. We explained to him that we use Google Gemini, the Enterprise edition, and it's a very—we have a secure and private slice of that Gemini pie. So we have very strict agreements in place with Google not to train on our data, not to fine-tune any future models, et cetera, et cetera. But, you know, inherently, this person we spoke with just didn't trust Google. And they just thought it—even if it's the Enterprise version, not even the public one, Google will take this data and train on it. And again, we understand it's a very visceral reaction we're seeing with AI right now. So I get it. And so I'd say at the end of the day, we're the custodians of our customer data. It's our responsibility. It's incumbent upon us to allay their fears, to reassure them, to let them know we're working with trustworthy, reputable AI vendors that take security and privacy super seriously. You know, it's their stated goal to protect this data. So yeah. So that's what we see.

(Joel Beasley at 00:13:33) Then you weigh the risk-reward factor. So look, I have a healthy distrust of large institutions in general.

(Reza at 00:13:41) Yeah. Yeah. Yeah.

(Joel Beasley at 00:13:42) Because, and here's the reason why. It's because large institutions are just people. And I have—you want to make sure they're fallible and they can make mistakes and they can have a stated goal and they can have a rogue engineer. Right? But that being said, you can't live your life in a box. You can't hide in a room. You can't let—because look, because what's going to happen is you're in a competitive landscape. Welcome to the economy. And there's going to be a competitor, whether they're smaller, your size, or whatnot, that is going to say, yeah, the risk-reward curve, I'm good with that, and then they're going to pass you by. And so it's more than just a do I trust them to maybe not train on my data? And it's more of, like, what would happen if I don't move forward technologically to my business?

(Reza at 00:14:26) Amen. Yeah. Amen. Amen.

(Joel Beasley at 00:14:28) You know what I mean? Gotta say something. We gotta get Kevin saying something. Kevin's here.

(Kevin at 00:14:32) No, I was going to jump in in terms of, like, you're saying around the challenges or what companies get wrong. There's certainly the security aspects of it. But in general, we talked a little bit about getting the right data. But a little bit to Reza's point is also not getting the wrong data.

(Kevin at 00:14:49) So, you know, don't feed your model from bad sources that are gonna really pollute everything to get those foundations in place. But as well, just around all those questionnaires and some of the challenges that we've had, it's where companies still need to adjust a bit their internal processes, policies, approval workflows, and a lot of cases just fundamental understanding of sometimes how IT solutions work and certainly how AI solutions work. You know, all the models aren't the same. You know, some of the other examples that we have, some of these questionnaires, they come in with a base assumption, it seems, that it's either a custom built proprietary model, where we're using Google Gemini, which is a static model that, you know, we're not changing it. We're not training it. We're not influencing it. But, you know, how the questions or the assumptions or just the understanding of how things work, there's a strong bias or assumptions in a certain track. So it's also then trying to deal with that type of education. But those are also blockers within an organization because they'll just think AI is not safe.

(Kevin at 00:15:41) We can't trust it. It's sending our data off to the public Internet. We can't be using this for our enterprise solutions, sharing our employee data or sharing our customers' data, which gets back, you know, the GDPR pre-AI. You know, some of the fundamental objectives of the GDPR was securing citizen data, you know, making sure that their data is secure and it's protected. And then everything else around it is, you know, handling consequences of not doing that correctly.

(Kevin at 00:16:33) But it's, you know, a lot of it's just education throughout the chain of businesses.

(Joel Beasley at 00:16:39) Yeah. And I get the sentiment. That's why I like it. I actually was excited when I heard about the GDPR thing. The fact that they were—forget the execution and the details because I didn't get super—we talked about it for years on here, but it's been a while. But the general idea of the country caring about the data was intriguing to me. And I like the idea of them caring about the AI. I just think it's an impossible task on the low level. It's like quantum physics, right? Gravity works up here. Down there, it's very different. The idea is good. It's like, hey, we should have some structure around this AI. But then when you get down to it, there's a lot of questions where the bias and the morality come together. And it's like, well, what's your moral structure? And that dictates what the correct type of bias is, and then you have to figure out how to deal with it. So it just gets really, really muddy in the details. Luckily, we don't have to solve that problem today.

(Kevin at 00:17:40) Exactly. Exactly.

(Joel Beasley at 00:17:42) Alright. I wanna talk about people actually implementing this AI. There was a note here that said it's very similar to implementing security and how companies have done that. Can you break that down for me?

(Reza at 00:17:54) Yeah. Yeah. Absolutely, Joel. Yeah. So, you know, the more and more we worked with AI in the past year, we saw—yeah, I mean, there's a lot of overlap, right? You know, I guess look, AI is a very cutting edge type technology, right? It's super fancy. But at the end of the day, it's technology, just like any other tech. And we're gonna—you know, we really need to apply a lot of the same principles and standards and best practices as we do with other technology. I will say—and we saw this—we approached it, you know, both from a technical perspective as well as a policy, and I can talk a little bit about both if you like. You know, on the technical side, I would say, you know, the most important—by far the most important thing—is to focus on the data that we're using to make sure that we're not putting any sensitive data, any customer data into any of these AI models to not train them, to not fine-tune them, to not store or share any kind of this data as well. That's just an absolute imperative, right?

(Reza at 00:18:50) There's—if we're using AI to generate any kind of code, right? Because that's becoming quite popular in recent months with these AI code assistants. You know, again, you know, the need is more pressing than ever right now, Joel, to make sure that we have humans doing some kind of review, some peer review if you're having the security team scan using security tools looking for bugs and vulnerabilities. You know, make sure anything that's put into the AI model as well as anything that comes out is checked. It's sanitized. Right? We say in the security world, just clean, so it's nothing malicious or anything offensive or anything of that nature. And then also, as I mentioned, you know, a lot of testing and monitoring, you know, the human-in-the-loop thing I talked about and a lot of the monitoring. So that's on the technical side, and, obviously, we can talk about more about that.

(Reza at 00:19:36) On the policy side, you know, I highly recommend that people do an AI risk assessment, and this is actually something that's also pushed through the EU AI Act, which is basically, just reach out to your employees or, you know, look in your tooling and see what AI is being used in the company. What are they using it for? What are the use cases, right? And just kinda understand the lay of the AI land in your company. And then have a really good procurement process in place, right? We're not gonna ban AI. That's just impossible. You know, it's kinda like trying to ban use of the Internet at this point. And so, you know, especially us on the security side, we wanna make sure that our employees know that we fully embrace their efforts to use AI. We get it. This is it. We're in this new brave world.

(Reza at 00:20:31) But to do that, we still need to vet, you know, security, legal, compliance. We still need to vet what tools are being suggested to be brought into the environment and why, for what use cases. So that's really important. And then finally, to have a really good AI policy, right? Simple. Just break it down. What are the dos and don'ts? What is acceptable uses of AI? What is unacceptable? Don't make it draconian, right? Don't make it really tough because people are just—guaranteed they're gonna work around it, right? There'll be the shadow AI, and we can talk about that where people are just—you know, because there's so much cool tech out there, right? And they wanna kick their tires on this stuff. They wanna become better with the role.

(Reza at 00:21:05) So those are the main things, you know, from the technical and the policy side. And then also there's the, you know, separately, we could talk—there's some really good security AI frameworks where the people, your audience members, can lean on. They basically teach, you know, teach them again about this—you know, I say it again—this ethical and responsible interaction with AI and what are the security risks and threats of these AI models and also the mitigations. And, you know, there's four or five that we've looked at. Google, they have, it's called SAIF, S-A-I-F. I think they were the first in the industry to come out with a security framework. So that's really good for people to look at. NIST, they have a really good AI framework. MITRE, so M-I-T-R-E, it's called ATLAS. That is fantastic. So we've definitely been using MITRE ATLAS framework. And then the OWASP, top 10 for AI. So O-W-A-S-P.

(Reza at 00:22:05) That one's really fantastic as well. And then also I mentioned the, you know, the ISO 42001 earlier. But yeah. So those are some of the things, you know, again, there's so much overlap when it comes to security and AI that it's actually not as hard as people might think.

(Joel Beasley at 00:22:20) Yeah. I do wanna talk about shadow AI. I love shadow AI. I am a bad employee. That's why I had to go start my own business because I'm outcome driven. You give me an outcome, I look at the open marketplace, and I go choose whatever's available in the marketplace to achieve the outcome in the shortest, most efficient way possible. That being said, it does not work very well for enterprise employees because they have a curated company store of what tools you're allowed to use. What's going on right now? What are—I'm gonna call them my buddies. What are my shadow AI buddies? What are they doing in the enterprises right now, and how do you catch them, and what's going on with that?

(Reza at 00:23:00) Yeah. So, look, A, I like your style, Joel. I'll tell you that. But B, so yeah. So shadow AI, you could think of it kind of like, I don't know, the cousin of shadow IT. It's basically, you know, it's AI that's being brought—like, employees that basically go and install some AI tool, some super fancy tool that's kinda piqued their interest without the knowledge or approval of IT or security. It's just like on the IT side, but it's just for AI. I will say—so first of all, I'll say that I've heard, you know, anecdotally and read that this is a huge problem, Joel. For the vast number of companies, a lot of people are dealing with the shadow AI thing right now.

(Reza at 00:23:39) You know, people mean well for the most part when they're installing this stuff, right? They want to become better at their jobs. They wanna become more efficient. It's all about efficiency now. Maybe the tools they're using right now aren't really cutting it. They may not even know what the policy is, whether this is a do or a don't, as far as what's acceptable. And, yeah, it's just tempting. There's so much cool stuff coming out there. So, you know, this is what's happening, but yeah, there's definitely ramifications. There's implications, you know, there's issues that come with this. First of all, obviously, security and IT don't know what's going on, right? So they don't know what these AI tools are. Are they taking in sensitive data? Are they storing it? Are they using it to train future models?

(Reza at 00:24:22) You know, what is it hallucinating, right? Is it just spitting out garbage to the end user? So we don't even know about the quality of it. And then, obviously, what is this tool that's even in our environment? What kind of security risks are you bringing in into the environment? So, you know, as I mentioned before, it's really education, having a really good AI policy, and ultimately, just letting people know it's cool. We get it. We know you wanna use AI. We embrace it. We're with you. We encourage you to use it, but just talk with us. Let's have a conversation, bring it to our attention, and we'll vet it and let you know if it's good or not. So but that's yeah. That's shadow AI in and out.

(Joel Beasley at 00:25:05) Do some paperwork, put it in a queue six months later. Kevin.

(Reza at 00:25:09) Yeah. Right? What is it? Yeah.

(Kevin at 00:25:11) I didn't wanna—

(Reza at 00:25:12) Mention that, but yeah.

(Joel Beasley at 00:25:13) I do wanna get Kevin's thought on this. Kevin, I wanna put you on the spot here. Let's say, you know, like, when people on a diet, they get the good food that is low-calorie that they can snack on. They can achieve the craving without actually causing a lot of damage. That's where I'm going with this. How can the shadow IT people, the people that wanna play with these new tools, how can they get their hands on them and play with them but without using the company data, without doing that? Give me some ideas on how they can do that.

(Kevin at 00:25:43) Well, what—because what I was gonna say is a little bit of Reza's point of, you know, people—and to your own as well—that, you know, people will try to find—especially clever engineers. You're gonna know what's out there and you're gonna use whatever's at your disposal. But I think going back to some of the kind of company education and policies that, ideally, they can't just put things on a six-month pile, but come back with some sort of a solution that teams can use. If there's a void of a solution, someone's gonna fill it with something that they can find. So if you have some worthwhile solutions that your employees can use with some light policies to give some guidance on what to do and what not to do. That's ideally the best solution.

(Kevin at 00:26:29) There's a lot—especially for larger enterprises, there's enough things out there now. You know, if you're on Microsoft, you're on Azure, there's Copilot. You know, there's Amazon solutions. There's Google solutions. So if you're an enterprise, you're probably running on one of those larger platforms, and they're gonna have some sort of a solution. So we went through a similar type of that type of cycle. If there are things available, we got—we, you know, we specifically got Gemini for Workspace, got that enabled throughout the company, had some early adopters. People started to test it out, started to use it in their day-to-day tasks, and saw that it was quite helpful. And I think with Reza's help and a lot of the team, we got support to, you know, make it available to every single employee in the company.

(Kevin at 00:27:19) And then, you know, there's a lot of work that the team did to help point those teams into how can they actually use it in their day-to-day job. You know, we ran sessions on, really, per area of the company, you know, from marketing to product to engineering. What are the specific use cases that you can use this day-to-day in a safe way, and what not to do, or what to do, what not to do.

(Joel Beasley at 00:27:46) I hate interrupting, but this is—I'm really curious about this one point here. You said that you're rolling out different trainings in different departments. The individual that's responsible for the overarching—I'm gonna go get figure out how to apply it to marketing. Who's the driving force within the org that's going around and helping facilitate this AI training?

(Reza at 00:28:09) Go ahead, Reza. Yeah. So okay. So, you know, as we mentioned before, you know, we're very close partners with Google. And so we approached Google with this, and we said, look, we—you know, as Kevin mentioned, we wanna roll out this training to the company in earnest. And so what we did initially, we had—so we had a project manager that was responsible for the, you know, for the overall training. She sent out a questionnaire to the whole company. Say, hey. What are you using AI for? What would you like to use AI for? What are very specific use cases for your department, so for sales, for marketing, for engineering, etcetera? And then she took that information back to Google and basically said, help us create workshops around this so we can, you know, address different people's specific needs based on their role.

(Reza at 00:29:00) And so yeah. So we had these workshops that went on for about a month and a half. They were very well received. And, you know, the good news is because we use—so we use Gemini for Felix AI, but we also use Gemini for Workspace in the company. So this is what people use for their day-to-day work, right? So whether in an email or working with documents, you know, chat, meetings, etcetera. And so we have these very strict agreements in place with Google where they can work in a safe space, right? They can type whatever they want in as far as a prompt or anything that comes back as a response. None of that Google will touch or even look at. It's not used, not looked at by human reviewers or trained for any future models.

(Reza at 00:29:37) So it allows us to encourage, really encourage people. Please use this, embrace it. Share if you have a cool prompt, share it with some others. If you have a cool use case, share it with others. So that was a very cool project. And yeah, it was received with quite fanfare.

(Joel Beasley at 00:29:55) Yeah. Hey, this is a Kevin section. Kevin, we got some questions coming at you. How are companies using AI differently in different regions of the world?

(Kevin at 00:30:06) So I guess like everything, historically, regionally with any kind of infrastructure, some of the investments have helped lead the way in North America, Europe, key markets in Asia. Obviously, they went with some nuances in terms of the data privacy. There's—we talked a little bit about the EU, but China, Middle East, there's a lot of individual policies and protections going on that are also have have their own differences. And also some of the use cases are a bit different as well. So in terms of more sophisticated customer experiences, personalized banking, customer services, et cetera.

(Kevin at 00:30:43) LatAm and Africa, it's certainly growing quite a lot. But I think they sometimes have the advantage to leapfrog some traditional infrastructure, like they did back in the day with the traditional landline getting Internet access. There was a heavy investment to try to get Internet broadly if you wanted to lay some landlines and fiber optic, whatever it was. But they just jumped straight ahead to mobile data, for example. And there's a bit of that going on as well where some of the learnings from the initial early mover markets, they can jump ahead and focus right on those use cases, but usually also a large focus on the mobile channels. Most people, especially with Internet growth, large amount of people, got their mobile devices, and there's huge opportunities there. That's where a lot of the focus is.

(Joel Beasley at 00:31:38) And what is—I know what Quantum Metric does, but I actually, I was so curious to get into the GDPR for AI, whatever, that I forgot to actually ask what you both do at Quantum Metric. Kevin, what do you do at Quantum Metric?

(Kevin at 00:31:53) So I'm a field CTO. So it's a bit of everything, especially in the size of company like Quantum. And I've done things varying from sales, customer success, touched on a little bit of marketing, and dabble in helping out translate legal requirements and working with Reza quite a bit. But now I'm really doing a lot more focus with product, working with our engineering, and specifically with our Felix AI product, helping to translate that between some of those business challenges and what we can actually do to effectively implement them.

(Joel Beasley at 00:32:32) And Reza?

(Reza at 00:32:32) Yeah. So I'm the chief security officer, the CISO at Quantum Metric.

(Kevin at 00:32:36) Okay.

(Reza at 00:32:36) So yeah, I've been here four years, having a good time. Very cool company. And then, I mean, I have a background in incident response, digital forensics. Security awareness is something that's very near and dear to my heart. Done a lot of security awareness training. But yeah, CISO now.

(Joel Beasley at 00:32:56) No, that's great. Thanks so much. I like the CISOs. We'll do another podcast where you tell me all the stuff that you've seen.

(Kevin at 00:33:05) Well, how do I know?

(Reza at 00:33:06) Do a—

(Joel Beasley at 00:33:06) Breach podcast.

(Kevin at 00:33:07) You'll have to edit that whole thing out. Yeah.

(Reza at 00:33:08) Oh yeah. It'll be a five hour pod. I mean, the things I've seen—

(Joel Beasley at 00:33:12) We'll put a black shadow over you and change your voice.

(Kevin at 00:33:19) Yeah. Oh my goodness.

(Joel Beasley at 00:33:20) Okay. So customer insights. I know you're doing a lot. I learned about what you were doing, making the customer service and customer insights more interesting. But I want to know from you, Kevin and Reza, what is the coolest detailed thing that you're seeing happen right now with Felix?

(Kevin at 00:33:38) I know actually probably Mario and Adam actually touched on a little bit. It's things that we're doing really with that intelligent automation. So there's a—we started off with doing a digital session summary. So you can quickly see, from tens of minutes or an hour-long type of web or app session that you have, what actually happened there, summarizing it down to something useful. That might actually be relevant across multiple sessions.

(Kevin at 00:34:11) So if you took a week or you start swapping between devices, giving a bit of a bigger picture on what you were doing. But it's more than how we're starting to apply that in multiple areas and use cases, specifically in contact center, call center. It feels really quite straightforward and really quite simple, but the impact it's having has been quite surprising. It's really just getting a live agent on a chat or that live agent on the phone that immediate feedback of why is that person calling and not make them start over their conversation. Don't start over your explanation of why you're there.

(Kevin at 00:34:57) I'm gonna know in two seconds by reading this summary. What was the intent? What were you trying to do on that digital channel? Why did you call in? What problems did you have?

(Kevin at 00:35:06) And then a lot of contextual information that the agent would have normally gone back to the customer and asked them over five minute period of time back and forth. What was your frequent flyer number? What was your booking reference? All of these types of things, which is extremely painful for any customer that's calling in and also just laborious, time consuming for the agent as well. So it's really just cutting through all of that in a quite intelligent way and making it very, very specific. So I think having the capability to summarize those digital sessions is one thing which we started from that had really great success.

(Kevin at 00:35:40) But it's now tailoring it and applying it to those specific use cases, which we can really see amazing feedback from customers, but as well as the agents themselves. In some cases, they give feedback that they're salivating to work on these types of workflows, that they have this type of information because it's kind of night and day difference for them.

(Joel Beasley at 00:36:04) Yeah. You should talk to my mortgage company. They had the worst experience ever. I needed some form or something. I tried to download it in the portal last month, and I talked to five different people.

(Joel Beasley at 00:36:15) And every time I had to authenticate with all of my personal information and tell it to them and back. It got transferred to another department, another department, another department. And then finally, I just gave up. I was like, I just won't do it.

(Kevin at 00:36:30) Yeah. It's way too common. I feel the same as well because I'm like, you should you do know this information. I'm on your side or I'm in route, right?

(Joel Beasley at 00:36:38) They know I was just on it. They know my information. They know my phone number. They know all—they know my voice because I've talked with them before. They should—the fact that voiceprint isn't standard across everything right now is just a testament to how slow we move as humans to implement stuff.

(Kevin at 00:36:56) That's amazing. I think even in those contact center use cases, they are very operational and process and playbook driven. So just trying to get them to change is always a bit of a challenge. But this has helped. Part of the success of it is building something that fits within their existing workflow.

(Kevin at 00:37:16) It's not trying to rip it all out and start over and do something completely different. It's augmenting what they're already doing, shortcutting a number of things and making it easy for them. Because we digging into it, it's really getting down to like the matter of seconds. You don't want to make them click a button that they don't have to click. Just get it right in front of them, make it as easy as possible, and minutes matter.

(Reza at 00:37:39) My favorite—and I'm not even, you're gonna hate me for saying this, Joel, but my favorite feature of Felix, I can't talk about because it's just about to come out. It's imminent as far as the release. I just can't say anything yet, so it's a bit of a cliffhanger. I'm sorry.

(Kevin at 00:37:56) Ah, there we go.

(Reza at 00:37:58) Yeah. But I'm telling you, it's really cool. It's really cool. Yeah. And I'm not doing this to tease. I'm just saying that it's really cool.

(Joel Beasley at 00:38:06) Okay. So as we start to wrap up, I've got about two or three questions left for you guys. For CTOs, technology leaders who are looking to add AI to their analytics, what's your top tip to keep it simple?

(Reza at 00:38:22) Like you said, keep it simple. Focus on the data. Focus on the data. Protect the data. Do not put any sensitive data into these systems. Do not put any customer data into these systems. If for any reason you are obliged to, make sure it's encrypted. Encryption is your friend. But I would say focus on the data. I mean, it goes a long way to being compliant. So and keep it simple. Just stick to the best practices, right? They're called best practices for a reason because they really work. So that would be my advice.

(Kevin at 00:38:53) For me, it's just some things that I've actually personally learned throughout this journey that we've been going on. One, I mean, starting, obviously, with a clear strategy and vision. What are you trying to achieve? What problem are you trying to solve? But the maybe less obvious thing that I started to realize is that there's some extra degree of flexibility that you need in the process where a traditional development project feels a bit more linear. You define some requirements. You typically know how to build them. You go off coding them, building them, testing them, getting them released. Whereas with some AI Gen AI projects, one, I know our team's learning along the way. We don't always know what's possible, sometimes what's not possible. We have an idea of where we want to get to in the end, but sometimes the route to get there isn't as clear when it involves some Gen AI things.

(Kevin at 00:39:49) It's either the data or just the prompting to do it or the outcomes, the results that you get out of it aren't necessarily what you expect. So it's just that extra level of learning on the job as you go, the kind of more time that you might need to get to that end goal that you wanted to get to. And I guess a few more iterations in the process as well that you maybe normally wouldn't be doing. We've also found that we sometimes get to better outcomes than we ever thought we were gonna get to. So yeah, just keeping an open mind and sort of following where it takes you.

(Joel Beasley at 00:40:29) And then a lot of people that are listening to the show, they listen because they're trying to become better leaders, right? So from the human side of things, not necessarily the Quantum or the AI, just you as individuals and professionals, you've obviously gotten very far in your career. I'm always curious to know one piece of leadership advice, and here's the constraints for you because you get tons of leadership advisors, books, there's seminars, there's everything. The constraint of the advice that I want is something that you heard, you implemented, and you've kept it long term.

(Kevin at 00:41:04) I'll start this one, Reza. I guess, yeah. It was actually earlier on in my working career. I had a really good manager. And the more I look back, the more I did actually learn from him. And it was all just sort of natural things. And the one thing that really stuck with me, I think I was a project manager at the time and running a project. It was quite complex in a within a global organization, probably a little bit over my skis for a young project manager, but still just battling through. And maybe it's my personality as well that I want to solve problems and deal with things on my own. And this project kind of ran into some problems.

(Kevin at 00:41:49) It was pretty much down to the wire and it was getting delayed. And it's just one of those things where my manager was like, you know, we'd rather hear about those problems and issues earlier than later. Great if you can solve them yourself, but we're all here to help and work together on it. And it's something that sticks with me, and it's also some things to just remind others in our organization, especially some of the younger teams, especially in Quantum. We have a lot of little mini heroes within Quantum that people love working here, and they love serving our customers, and they love getting things done and accomplishing things.

(Kevin at 00:42:24) But sometimes you can't do it on your own, and you just need some help along the way. And it's not a bad thing to ask for help along the process. And obviously, then just reminding people that as a leader, making sure people are clear that it is open door to ask for help. And that's sometimes hard as well because you're always pushing teams to pushing people to deliver more and more.

(Joel Beasley at 00:42:52) Reza, do you need any help?

(Reza at 00:42:54) Yeah. So earlier in my career, I was a real workaholic, right? Especially when you're working in security. I mean, it's just an industry that just doesn't stop. And so I remember that specifically in my thirties, I was just working crazy. I mean, there was just always something going on. And I was working late nights, you know, leaving the office at eight, nine o'clock at night. I remember once my boss at the time, the CISO, she came up and she's like, what are you doing, you know? And I was like, I'm slammed. I got so much work. I can't leave.

(Reza at 00:43:31) And she's like, listen. Go home. Work will be here tomorrow. It doesn't make a difference if you leave at seven or eight or nine. You're still gonna have tons of work tomorrow. So just go home, enjoy your life, just breathe, just hang out, and work to live. And that was—it changed my life, you know, hearing that from her. And so this is something—yes, I mean, obviously I worked hard to get to where I am, but now I've realized work is always gonna be there.

(Reza at 00:44:03) And just really enjoy your life and yeah, just enjoy all the moments you have. I know it's cliche. I'm sure maybe some others have said it as well, but I don't think it can be said enough. I would say that. And then also just concentrate on soft skills. I think for us, we work in tech, so there's a lot of focus on being technical and really knowing your niche and what's going on. But I think the quicker people can learn soft skills early in their career, the better. And I think it goes a long way when we become leaders to have those skills.

(Joel Beasley at 00:44:35) Yeah. And I resonate with that. I've actually, both things you've said, learning to ask for help and then also not being a workaholic. Yeah. You can justify it so easily. I've got young kids. I've got to provide. I've got to grow all this stuff. And then when I backed off a little bit, things actually got better when I started caring more about my health and—

(Reza at 00:44:58) Exactly, my relationship.

(Joel Beasley at 00:44:59) And my family. Yeah. Then it's like, oh, I can breathe. And then it forces you with that constraint of time that you do have at work. You're like, what is the most powerful thing I can get done within this block of time?

(Joel Beasley at 00:45:11) And then all the small stuff kind of fades away, and you can just relax and get the one thing that needs to get done.

(Reza at 00:45:17) 1000%.

(Joel Beasley at 00:45:19) Yeah. Yeah. I wish you could just tell somebody that. If you're listening to this, you just have to walk through it. There's no—I don't think it's something you can learn without making the mistake and doing it.

(Kevin at 00:45:31) One of those life lessons for sure.

(Joel Beasley at 00:45:33) It is. It is. Yep. Well, Kevin, Reza, this has been fantastic. I thoroughly enjoyed hanging out and speaking with you.

(Joel Beasley at 00:45:39) We made a podcast. How do you feel?

(Reza at 00:45:42) Loved it. Very cool. It was cool hanging out with you and your distinguished audience. Thank you very much.

(Joel Beasley at 00:45:48) I was surprised to learn how Microsoft Unified Support works. Apparently, Microsoft decides your support fee based on the amount of software that you buy instead of billing you for the actual support hours that you use. This means that you pay for support that you might never use. The pay-as-you-go model is a much better model, but Microsoft doesn't offer that. I did find a company that does offer this, and they're called US Cloud, and 50 of the Fortune 500 use them.

(Joel Beasley at 00:46:13) Not only is it better, faster support with all US-based engineers, it's also cheaper. 94% of US Cloud clients report saving a third or more when switching from Microsoft Unified Support to US Cloud. Now you'll just have to figure out what to do with all of that extra money. If it were me, I'm responsible, so I'd reallocate that money to improve my team.

(Joel Beasley at 00:46:33) What would you do, Josh?

(Intro Narrator at 00:46:34) I think I'd just try and buy a ticket to space.

(Joel Beasley at 00:46:37) Alright, astronaut Josh. For out-of-this-world savings, visit uscloud.com to book a call and find out how much your team can save. Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.