3 minute read

Why aren’t we experimenting with AI faster?

At the Public Sector Data & AI Summit in Westminster, I listened to organisations talk about where they’ve got to with AI, and the range surprised me. While some in the room seemed hesitant to experiment, others appeared much further ahead. This made me consider more carefully where Datagraphic stands on responsible AI adoption and why.

Why organisations approach AI adoption so differently

At one end of the scale there are organisations which are still keeping themselves at a distance from AI and are hesitant to carry out any experiments with it. At the other end there are organisations that have moved quickly, sometimes failing to fully consider what that actually involves. What’s being typed into AI tools? Where does that information end up, who can see it, and who’s accountable if something goes wrong?

It’s understandable why organisations end up at either end of that spectrum: caution comes from a sensible instinct, and so does urgency in a world where there is real pressure to appear to be using AI. Holding back indefinitely makes it harder to discover what AI can do. Moving too quickly can mean overlooking what responsible use requires.

What responsible AI adoption involves

That’s the bit worth getting comfortable with. Moving carefully isn’t the same as standing still, even though the two can look alike from the outside. There’s a real difference between holding off indefinitely and experimenting while working through some fairly basic questions:

  • What information are people entering into these tools?
  • Where do the prompts and the outputs go once people submit them?
  • Does the provider retain any of it or used it to improve the model, rather than keeping it within the organisation’s control?
  • Who has access, and under what permissions?
  • Who is accountable when an AI-generated output goes into a piece of client work or a public-facing decision?

One of the clearest examples of this came from a session at the summit run by Mills & Reeve, on confidentiality and risk.

Their point was straightforward:

Organisations can have statutory and common law obligations to keep certain information confidential. A public chatbot gives users access to a model hosted and operated by its provider. The provider may store prompts and outputs for purposes including service operation, quality assurance, safety review and model improvement.

We should therefore assume that anything typed into a publicly available chatbot could be exposed beyond your organisation. Different tools and settings will handle information in different ways, which is a useful, practical point, and exactly the kind of thing that gets skipped over when the pressure is to move fast.

It also matches what the UK’s National Cyber Security Centre has been saying about what it refers to as ‘shadow AI’; the use of AI tools that haven’t been formally approved by an employer.

The warning given is essentially the same as that presented in the Mills & Reeve slide:

Sensitive or proprietary information sent to a consumer AI service may be retained or used to improve it, depending on the privacy controls in place, reducing the organisation’s visibility and control.

Datagraphic’s approach to AI adoption

Datagraphic is genuinely interested in AI. Under a research project led by our Cyber Security Team, we’ve been building and experimenting with a Local Large Language AI Model, within an internal testing environment. However, we never adopt new tools without being 100% confident they are secure, robust and productive. Before we would ever use anything on a larger scale, we have to understand what the tool actually does with our data, who is responsible for what it produces, and where the boundaries are. We address the practical questions seriously before we scale up anything, rather than after.

So the questions I came away with weren’t really how quickly we can adopt AI. They were closer to this: how do we keep experimenting safely, with confidence?  How do we ensure we don’t lose sight of what we could achieve and what we’re actually agreeing to when we do? These are the questions I’ll come back to in the next two pieces, starting with where AI genuinely helps and where another approach might work better.