Datalyst 2026
Welcome Address - Stewart Robinson
Datalyst was held on 26th June 2026 at The National Innovation Centre for Data at The Catalyst in Newcastle upon Tyne. Stewart welcomed us who is from Newcastle Business School which uses data and needs data to improve their business, they are a researcher of over forty years. Their journey was from small data where you do what you can with what you have, their expertise is computer simulation and played with AI in the 1990s, so what's changed? Volume and recentcy of data, computing capacity and speed along with connectivity to each other means it has change to bring in a data scene and AI revolution. Decision making is ultimate aim of all of our efforts and is the reason for today to help further understanding including analysis of data and how to use this to guide decision making.
Compere - Steffen Peddie
Steffen started in Data entry and used a ZX 80 to make a small hamster to dance and welcomed those here to the second year with a lot of content in different rooms, if there is a burning question you can enter this on the spur of the moment. Have sponsors and partners who are helping out today and can find exhibitors and remember to hydrate. They also have a bingo card, as are very proud of games of bingo in the North East, there is a prize bit have to do own analysis and research, also have host of events and point is not speakers but also to speak to other like-minded people and may be introduced to an entirely new idea and keep your minds open.
Opening Keynote - Lee Rorison (Seriös Group), Paul Wealls (Lenovo)
Lee mentioned happy to be representing Serios which is a data solutions company founded in February 2020 and were looking to place business and couldn't think of anywhere better than the North East, their missions is to enable businesses to take control of their data, delivering rapid value without compromise. They deliver data solutions to big corporate enterprises in private sector although are proud of work with partners who work with public sector. They are different from traditional consultancy and have own framework with fixed price, fixed timeline and fixed outcome, they try to differentiate to do the right thing for the customer and have high IP led data solutions.
Paul is from Lenovo and before had their own company and met Lee as part of the event now known as AI IoT Hub and has been part of bleeding edge solutions and decided to do something front of house and found themselves in sport and Motorola is their brand and have partnered with Serios especially in world of AI. Lee working with Lenovo in a partnership and asked how they found and wanted to work with them. Paul mentioned everyone knows everybody and spoke toe Sunderland Football club and asked about their data and they mentioned were in a great place and discovered Serios group and they had known each other a decade earlier, this helps leap things forward for adoption, their brand is everywhere and is not just marketing and technology and value of Serios helps leap ahead in a very quick time.
Football is changing quickly, not just on the pitch bit in how clubs operate, engage fans and make decisions where more data is being generated from matches, training, scouting and fan activity than ever before. Serios has financial services as their biggest vertical amongst others and football is a big business, and misconception is focus on player performance but a clubs commercial operations are so they need ERP capabilities and CRM but football clubs are not as mature as other businesses and is uncommon to find a football club you can match to a tier one bank but the problems are the same, where real value is on commercial side where football club wants a competitive advantage and win on the pitch to drive those revenues.
Serios first landed in Sunderland Football Club in 2022, data had become the new thing but club was restricted on money for data but wanted to do the new thing and Serios partnered initially for data engineering support with no initial strategy for data, but was to align with what other businesses and within three months they were promoted due to work club was doing on pitch but what this brought was more investment and allow them to compete at that level and were already there when commercial side asked about customers as fans.
Transforming Sunderland AFC's data insight, they had two SalesForce instances capturing customer data but the solution was Serios One which is their AI data solutions technology integrating multiple data streams into a single governed platform. If not get information after a game in a few hours they will have moved on so need to react very quickly and is where their framework came in to model and pipeline data where don't need to code or take on transformation where just need to apply metadata to data where could bring together retail and ticketing in a matter of days and once demonstrated this wanted more such as payments to align spending habits around stadium and retail stores to understand fan and customer where every single touch point a fan has now are ingesting this into platform with zero code and config and now helping to move into a new AI enabled era.
Lee mentioned they have been working with Sunderland for three years and signed an extended deal with this investment driven by need to drive revenues and recognising value of integrating data. Benefits of the Serios One platform is it integrates into their data they get one view of what they need from players, customers and competition where typically these can be across many systems, along with trusted foundation for AI with solid data foundations allowing kickstarting of AI where don't have to wait so can get things going from the get go. Serios One is a superpower for data teams where replaces bespoke, code-heavy delivery with AI-native and metadata driven operating model which significantly improves speed, quality and engineering output.
Paul asked about the World Cup and difference in what is being seen on screen compared to before, what viewpoint have you not seen before is referee cams which is from Lenovo, for F1 they have 26 cameras with real time stabilisation and colour correction and helped transform this four or five years ago. Lenovo have build a sports business service and what they are looking for is fan engagement so if not connecting they are not going to grow revenue, diversify and monetise. Also it is performance gains for real-time intelligence where need data for this and improve operational efficiently and work with other partners, they also help those who have many different systems to have something that works better and look at how they transform sales like micro transactions from Roblox, most younger people follow players rather than clubs.
Paul mentioned some of the things they have been doing include the referee cameras, 3D avatars common in other parts of the world but not so much in the UK where can have a real player avatar rather than generic one where needed. The top club to be expected to win is Germany with second is Canada plus England third based on the data at the moment. Lenovo can offer a solution to see what is going on where can ger 360-degree operational visibility with faster incident response. Referee cam is big standout thing but critical thing is talking about exciting stuff once data is cleaned up and lots of organisation don't realise this and are all in the same stage, all people have the buzz word of AI and then ask how, what, why they don't know.
Lee mentioned the future of elite sport will be driven by data enabled by AI, football clubs don't need more data they need to control the data they already have with a governed data foundation to enable AI. Lenovo Command Centre is a great product and allows commercial football clubs to run venue and operate commercially but need to bring the data sets together for these to be consumed by this with a lead time of eight weeks to get commercial operations into shape and one clean feed into the Lenovo Command Centre. It as exciting football is it is no different as a normal business and for a future state and will be driven by AI where this won't replace people as they are still important to get them what they need and what they need quickly.
Governance, AI & Ethics - Janet Bastiman - Chair (RSS), Kevin Telford (FinPact), Alex Craig (Muckle), Matthew Forshaw (Alan Turing), Adam Brown (Seriös Group)
Janet mentioned are going to have a lively session on AI governance and legalities. Adam is head of data and strategy, Matthew is from DSIT and Turing INstircutr, Alex from Muckle LLP and Kevin founder of smarter decisions.
Janet asked is anyone actually doing governance and ethics right? Adam mentioned not many 93% are using AI in a daily basis and only 7% have embedded it on a daily basis, it is a question of doing it well and technology is moving forward and very few people are doing it right, well or at all. Alex is saying people are doing AI and there are pockets of organisations doing governance and just like change to data protection legislation in 2018 there is lack of knowledge of what is being used, control and direction but it is not malicious and governance is being left behind as is less exciting. Kevin mentioned governance foundations and ethics is a foundation and the next one is data assets to built on this along with talent streaming and creating environment for innovation but this is rare, people are still using old systems and infrastructure and trying to shoe horn this in. Matthew mentioned there is a positivity bias and hear of things going right but not challenges being faced but don't know solution except way of sharing anonymously of issues that have been faced.
Janet mentioned about cultural change and rather than adding AI in then having that success story on top, there should be a thing that you shouldn't be trying or should there be a what should people be doing? Alex mentioned talking about business transformation journey where is a senior leadership team need to be engaged but will include people who have a lower understanding of things so there is an education training piece at this level and a planning piece about were the organisation is going and have seen people try to shoe horn AI into an existing system which hasn't gone well so need to look at challenges and inefficiencies and what can be done quicker and faster, what does AI look like from a legal perspective and engage people as part of that journey.
Janet asked do historic governance processes work or do need to rethink? Alex mentioned some of this will be relevant, such as data protection but may need updating but many organisations don't have an AI policy but need to guide staff on what is okay and what isn't with policy and procedure. Adam mentioned there are no skills and accountability on what is available and how to best use it, the fun thing about AI it is the wild west and people don't know potential of AI, but were cautious as a business about AI and looked at use cases and have accelerated use of AI but need understanding and transparency of use cases. Kevin mentioned all the legislation is there such as data protection, GDPR but it is not knitted together in AI infrastructure but will need more regulations and accountability and bring in explainability, transparency and what AI was used for, what outcomes and how it was tested and have diligence in place as can't rely on legislation for this.
Janet asked are there the right skills in place, is there enough knowledge to apply governance and are there new skills needed? Adam mentioned everything is there and need training, explainability of things is important, there are things that weren't explained before but in AI you have to explain why an AI made a decision and how it made a decision and document what it does and how it does it. Kevin mentioned may have things but may not be organised and people have the skills but it is more about organising this against a clear mandate but it is about organising skills. Matthew mentioned it is about availability of skills is not felt evenly and can have quite substantial skill gaps and have worked with Skills England about things and responded to well evidenced gap in leadership for executive education and wanted to reduce financial barrier for smaller organisations as skills is one of those barriers starting at leadership level. Alex mentioned when start out you will generally learn a specific trade of type of work, when develop in career you deal with more things and develop and hopefully organisation will provide training, there is knowledge in silos but issue it is not integrated across organisations and people don't know different facets and parameters when looking at new technology and AI adoption, there is not going to be every SLT who wants to go on an AI skills course. Kevin mentioned where there is a gap is being job ready to hit the ground running so needs to be corporates in academia to have a fluid curriculum and allow SMEs to inform on this in a much more controlled way and bridge soft skills with AI skills but there are many programmes around the UK so have people who are going into employment will need certain skills, not interfering with education but supplementing this.
Janet mentioned we don't necessarily have right skills in right places, should this be a regulated thing about doing governance and testing of AI be a regulated profession? Matthew mentioned have approach to when it was hot the building was safe, so there is value in have a regulated person and have a curriculum that is flexible including exploring AI assurance roadmap, should these be regulated professionals and what is competency of the people in those roles, so there is something to explore for a unified approach. Adam mentioned if you impose regulation and training it will impact smaller businesses and these need to compete against this, so principle based approaches and provide training needed. Kevin mentioned when have title Dr or letters after name these are powerful with trust, need to see things that are embedded right now which is a critical phase right now and without expertise will be a huge mistake. Alex can see both arguments and should be something we interrogate, so could have a standard with practitioners in certain sectors who know issues in that sector. Adam mentioned there are regulations in data but if add more regulations in AI could stifle innovation . Alex mentioned introduction of data protection legislation can be difficult and were new things introduced last year so need to look at what a useful framework would look like.
Janet mentioned the EU AI act? Alex mentioned we have had situations like Brexit but organisations are operating across Europe so need to still look at this, the law is always slow and always behind, fundamentally there is a debate which is not jurisdictional but global. Kevin mentioned depending on where you are is how you think between governance and risk, now data is part of the agenda where have a framework that is embedded and data legislation and application of this needs to be safe and need to have shared data and have regulations and boundaries at minimal levels, where can explore in a less restrictive way. Adam mentioned the EU AI act is a good start and depending on size of risk you apply different governance as a great foundation that you don't have to abide by unless trade in EU.
Janet mentioned is it fair to do it until told you can't, or do it slowly and ask for permission? Alex mentioned just because there isn't equivalent of EU AI Act but there are other acts like director's act such as GDPR if processing personal data and if using some kind of AI platform will be processing personal data so you can't wait until someone says no as won't be compliant. Alex mentioned you have to have someone accountable for an AI system. Alex mentioned it is not a one person exercise, the AI adoption piece is not one team or person. Kevin mentioned having guardrails and things in place where people can work outside these things but in many organisations in financial sector doesn't happen as it is the way they work, and it is everyone's responsibility.
Janet asked how can you ensure governance about AI is made actionable and considered correctly? Adam mentioned changing model so if have data governance about data and quality issues so is where people who have AI solutions would be accountable to and embed these systems quickly. Kevin mentioned to embed everything with a purpose and what is being done align with objective and do major projects including AI move forward as an organisation and can you track this all the way to the top and what data assets do you need, there are frameworks and principles that can drive things forwards and put human at the front, human in loop, in control and design and all the way through.
Janet asked biases in AI, what is there in AI that businesses need to be aware of that is not obvious and what things should be in place? Adam mentioned AI hallucinates, take transcripts and automatically assume this is all working so need to check what AI does and need to build in ability to do this, get AI to check work over and over and then get human involved. Matthew mentioned about sycophancy aspect where if AI misses something it will pick most probable thing. Alex mentioned need to understand what AI has been trained on and meant to be a good part of society and people have relied on AI incorrectly and in one case a lawyer outsourced their thinking to AI even though it had mentioned not being sure. Kevin mentioned it needs to be human first and validate outcomes are real, people want to trust something is being used by human, governance or can be trusted with a lot of work to get there. Janet mentioned AI is fundamentally statistics under the hood and there are other issues like right answer for wrong reason.
Janet asked one thing to do? Adam mentioned read EU AI Act, Matthew mentioned we ill have a leader who has better approach for upskilling so reflect on what this means, Alex mentioned if in senior leadership don't leave it up to one person and Kevin mentioned having right training in place.
AI & Automation - Rishi Sapra (Avanade)
Rishi is a Microsoft MVP and has worked for a few different companies working with VBA, Access data insights and could you get to these insights quicker and more easily and context of data has been interesting to them. Rishi is a Microsoft MVP and has worked for a few different companies working with VBA, Access and Excel and have enjoyed
Which of these roles can AI replace in data, in a sense all of them, as they are always producing analysis and standard stuff but can't replace the part where apply own knowledge. Not just “Chatbot” AI but AI in Excel, everyone has used this at some point and show agents that can run processes that before required VBA. Excel has over a billion users and natural language is how we have communicated for years which opens up possibilities to people who would never had access before.
Where we have been? Heard this before with Self-Service BI in tools like PowerBI which has grown to hundreds of features. In 2010s things like this were sold as self-service but in most enterprises the reporting estate is a mess so self-service AI can deliver on this promise. The challenge is the Ai data is messy and you need to bring data into a data platform and if there is data there it is still a mess.
So what about all these weaknesses, what about a team of specialised agents, make your weaknesses you're agents strengths have a business analyst agent and could have researcher role, you can have Foundry IQ as a basis for knowledge, could also have data engineer roles and tester roles with everything you need defined in skills in Markdown. Agents can help implement a plan with context and need teams with their own context windows.
You can give data to an AI agent which can understand the data where can see the thought process and then can get the output as needed which could include other processes such as GDP conversion along with relevant reasons for things within the data being processed, You can also use skills where could produce financial statements including relevant formulas which would require an accountant to learn over years to do these things.
They looked at how much time has it saved them, why did it take longer than they thought? Agents can see what is going on and can bring together a lot of information, could find problems that don't exist such as finding older data or misunderstanding business processes and could generate VBA code and the code would be generic and overly specific which were based on misunderstood requirements such as knowing how could connect to Xero, but issues from things done without asking or not doing things as needed can be an issue.
You need to manage AI behaviour as AI doesn't reduce work it intensifies it where there are more things you need to do and this is the real challenge where need to be clear and intentional about things. An agent plans and carries out tasks, where has perception to see your data, reasoning to work out steps, actions where it actually does things or a memory where it remembers what worked and building a picture of time. Not a chatbot, a worker – three challenges with real processes where have data everywhere in ERP, CRM etc and probabilistic where it won't give same answer twice so need to do things in code as that is deterministic and need context as it can't hold all our process knowledge through a prompt.
Build an agent like you're hire where have a job description for the role it is responsible for, have skills or tools for domain knowledge and have MCP with access to systems and how to use them safely along with data and logic for the data it works with. Can have an existing process and used Claude and Excel using an implementation plan for this process to create a skill to be used in Excel and used it to create this just by running a custom skill. There is a demo at ldidata.com where there is a tutorial to build a custom skill.
Self-service Ai framework is to learn the data fundamentals as need to understand Excel, PowerBI so when asking agents to do things then know what good looks like, need the understanding. Then need to have somewhere to store the data where separate storage, logic and analytics, build workflows components then iterate, build and trust. You have skills where turn business proves into a custom skill, catalogue where browse search and trust a library of skills and then have brain of knowledge. Define the governance, tools with MCP servers, logic for your rules that fit together and can have multiple agents which live inside this that represents different roles needed.
Will agents replace us? Spreadsheets automated away the jobs of bookkeepers but boosted financial analylists.
Scaleup, Funding & Investment - Neil Stephenson, Chair, Chris McCourt (Mercia), Andrew Jenkins (Kinewell), Alex Craig (Muckle), Beth Crosier (CO4CH)
Neil mentioned these kind of sessions can be theoretical, is from Stephenson Capital with experience in tech sector. Beth is a former CFO and has fundraised for different businesses and is now an angel investor and helps early stage investors help to grow. Andrew is founder of Kinewell which optimises design and construction of off-shore wind farms and has raised money with Mercia. Chris works for Mercia ventures which invests money on behalf of funds and have £2 billion of assets and manage North East Enterprise fund investing up to a million pounds. Alex is partner at muckle LLP law firm and look after a range of businesses and sees if there are any problems.
Neil asked why Andrew is looking for funding? They have grown through North East startup infrastructure and had developed great tech but challenge is bringing to market but grant funding doesn't fund sales and marketing efforts so needed that money to supercharge from their initial sales and explored a range of options, they were self-funded and did some modelling with financial model on what they would do in different circumstances and what would they need to do to maintain sustainability, needed to do down investment route and started to looking and speaking to various people and North East Accelerator Fund came about.
Neil asked Chris what was interesting about Kinewell, as an early stage investor it is difficult to get head around historic so best way is to start with people and met Andrew and quite liked him as are backing people as well as the plan, is the plan realistic and are the people able to do this or can they be augmented so for them they don't want to work with people they don't like, are letting someone new into the business and Kinewell is fundamentally a software business and it was looking at the market they were operating in and were working on great projects and names they could get behind and is a market going through and continuing to go through heavy growth and potential to be a high growth business with lots of boxes ticked from day one.
Neil asked about preparation work and biggest issue is finances and asked Beth about this is startup accelerators is getting pitch ready but they help people to deal with investors and the way they think about role of finance and data changes when take someone else's money and moves away from compliance and book keeping to value creation and teaching founders skills to find an investor who is aligned on the plan and skills to deploy investment in right way, investors understand need to invest money and will get things wrong so is a balancing act.
Neil asked about timing of conversation before VCs? Beth mentioned many companies have already spoken to VCs or angel investors so the best way is to engage early and be ready to speak to VCs when are ready to speak to VCs and many people aren't ready for it
Neil mentioned about software point of view and intellectual property so for Alex spoke about when getting reach and get house in order so depending on organisation then for software look at ownership and what kind of system it is, when have founder there will be people doing software before entity was set up which is all fine but the investor will want everything in a tidy package in the right place, and have to get on with legal advisor, need to be in a really good place and if need to sort out an IP assignment can get this sorted.
Neil mentioned fit is an important thing from investor and investee? Andrew mentioned you need someone you can trust and get on with, there are challenges within it and there's a careful balance so want highest valuation and say good things and not bad things but you need to raise these to get help to solve them, need trust and honesty and if this doesn't happen then nothing happens. Chris mentioned the thing that is different from their point of view was Andrew was passionate and ambitious but once got past those conversations it is about having an open and honest dialog including about valuation and listened to points and had a dialog over couple of months. Beth mentioned need to have mutual respect, then respect the other's expertise and where people move into other's space can be an issue.
Neil mentioned being interested in what investor is looking to get out of this from a business raising funds? Andrew mentioned trying to de-risk and accelerate the reduction of cost of offshore wind, firstly this was climate change but conversation has shifted to energy security and no matter the argument need more energy generation, if genuinely adding value then this can work and right technical innovation and structure can help with this and the money side will follow. Chris mentioned wanting to get a material return on their investment, they have to believe on the way in that there is the possibility to get ten times money from each investment, rather than expectation, the market has to be growing fast enough to expect this and for half invested businesses they don't get their money back but the rest do deliver more than they invested so look to get 2-3x what they invested, they invest in 2 out of 100 businesses and reason they say no a lot is the business is not ready for an institutional investor.
Neil mentioned there are a lot of things you don't know, they have not made anything ever from the original business plan, and when it goes wrong you need to pivot. Chris mentions in an early-stage business you can see one quarter ahead or six months and maybe a year but longer is much harder.
Keynote - Dame Chi Onwurah
Chi says are looking at the very best of data, innovation in the North East in the room, they are the MP for Newcastle Central & West covering The Catalyst and chair for Science, Innovation and Technology Select Committee and holds government to account for various technologies that are offering opportunities and engine for growth and prosperity.
Driving the new industrial revolution, Labour has key ambition to transform state and private sector with technology and barrier was hype around AI, but despite this it is a gamechanger to drive a new industrial revolution. AI is fundamental to future growth and have to be significant player in the AI race and is not automatic and has to be built, it is not just adoption but education for real social and economic value so need to equip services and businesses for the best outcomes and work with tech sector for right regulatory approach in mind.
The North East has been here before where we pioneered the first industrial revolution and is the home of greats like Stephenson, Armstrong and Parsons including Rachel Parsons who was a pioneer in marine engineering and role of women has been underplayed but the North Easy has produced people with minds and work ethic, with talent, ingenuity and determination to lead again as the economy changes.
North East is rising to the challenge with a datacentre in Northumberland for world class AI and cloud computing with 1600 direct jobs with the datacentre delivering 400 jobs but as it is part of AI industrial zone it extends to 1600 jobs in the community. Have seen AI innovation at the RVI and investment from Lockheed Martin for space engineering and also have new Metros. Are seeing investment and transformation, but are we doing enough to drive that into regional growth. Newcastle University is helping drive regional economy and rebalance national economy to address inequalities that drive division both economically and socially and have seen economic growth from Manchester via work by Andy Burnham.
Don't actually collect data on regional growth and investment and impact of clusters of innovation on what is happening so this is a barrier, as well as understanding and attracting same levels of investment that London and South East has. There is a report, Flying Blind, which is an emphasis on not having this data but progress is being made and we have a fast-growing sector which is world leading in many areas particularly in AI. We have Sage, Ubisoft and BBC Tech Hub in the North East and many more jobs in creative and innovation businesses. We have the future economy growing in the area around The Catalyst to drive innovation into jobs and communities and combined with more investment and be able to say in parliament that North East is fertile ground for world class digital powerhouse and innovation is critical for growth but there is disparity in investment in R&D in North East compared to rest of country.
Must ensure AI is shaped for the public good, it always strikes them that are always willing to accept the market and tech to change our lives and is not up to us to shape this, and by not taking legislative or regulatory action are shaping this. Have seen technology scandals such as failures in Horizon system for Post Office and these scandals can create long term damage for public trust and when can do tech effectively is when have public trust. Need to make sure private sector produces and delivers services that are safe to use, haven't had that approach to tech but increasingly there is a demand to have same safety and safeguards as the real world. Engineering and tech is considered exciting but exploitative so need it to have public trust that it is useful and being shaped by government and academia.
Need to make sure have right building blocks for safe production and adoption of AI and overcome barriers such as legacy systems, vendor lock-in and in Newcastle are tackling issue of AI safety at Newcastle University. Need to ensure AI is sustainable where datacentres is energy intensive and power use is growing six fold and water usage challenges need to be overcome and ensure sustainability. Need to ensure AI reduces and not widen inequality and enter a new industrial age where no region or no one is left behind and AI must reflect shared values for diversity and not dehumanise and misjudge our fellow humans.
For the North East it is not just an economic opportunity but an opportunity to reshape our future and not just participate in this new industrial revolution be part of it and work for everyone.
Dashboard to Decisions - Phil Thirlwell (Datavyse)
Phil is here to talk about decision making and started Datavyse a year ago, will do a short activity and talking about in terms of decision making. From Dashboards to Decisions to use AI assistant analytics to reduce time. A familiar request can we get a dashboard showing something, but can not really help sometimes as who needs visibility, what action are they going to take.
The shift from reporting output to decision support where old default is build the report or dashboard but better question is what decision are they trying to improve and need to help understand what people need and what decisions to take. Dashboards are now one of several consumption modes dashboard / report is best for exploring trends, drilling into data and monitoring performance. Conversational analytics for quick questions, and users who don't want to hunt through reports or proactive alert for risks and information and others.
AI is great but getting into the basics still matters. Dashboard to decision framework is what decision are solving for, what do we need and can we rely on it and how doe this help people act. It can come down to data quality, can they trust it and when making a recommendation why they should make that decision and dashboards may not be the best decision.
Exercise is use the decision framing tool where choose a stakeholder and then complete the decision framing tool from a request of can we get a dashboard showing sales and onboarding pipeline. As a sales rep you want to compare yourself to others and have a league table, have hottest lead.
Customer Success Manager would be what to do about declining customer relationships, have a single customer view that is complete, have a dashboard about this and have alerts if have a big drop in this and look at if the retention rate has been improved.
Sales - what are my hot leads, what is next phone call, how many calls and previous success rate, are you best person who can convert that and be able to integrate this into a CRM, this doesn't need to be a dashboard but a workflow and have a priority for how to work down this.
Finance director - needs decisions centred around have done it before and can you close this and don't want to explore data and not data literate so have a dashboard for this.
For a request there will be different decisions and what are data foundations that need to be in place for business to make better decisions, dashboards are not dead we just don't necessarily see them but is a better way to make decisions faster.
Developing an AI Policy - Ian Pay (ICAEW)
Ian is talking about developing an AI policy, they are from ICAEW who have 170,000 chartered accountants with students on their programme and one of largest networks of accountants and oldest in world. They specialise in audit analytics and data acquisition.
What's most exciting about the AI revolution? Who has a policy and who has one that has been updated in last twelve months. What excites people about AI revolution? Empowerment, people don't need to know as much about things so now Excel is a grid and a chatbot so don't need to learn ins and outs. Speed allows you to do more faster. Remove mundane tasks.
Governance excites them the most, people are interested in these topics, and AI has fuelled this conversation and engaging in a way they never used to do before AI. Most businesses and most employees want to adopt AI but are unsure where to start, data security is a real concern and shadow AI is a real risk who use AI in an organisation that you don't know they are using. Research earlier this year showed security and privacy was a challenge when adopting AI. People want to use AI and not sure where to start.
AI challenges are data quality, skill sets where may have gaps in knowledge and team structures, reliability of AI where start get comfortable about outputs from AI and what this means, methodology, standards and regulation, time and cost, data and cyber security, ethics and governance. It is such a changing market and certainty you will get same answer each time comes into question.
Data and security about where it is stored and risks about AI in the security space along with ethics and accountability in terms of trust, confidentiality, objectivity, bias and transparency where have clear strategies about responsible use. Rule number one for any AI policy? Do not put confidential data in public AI tools, people don't realise the risk as you lose ownership of information and no longer yours to govern.
What is your risk appetite, this is an important thing to get around, are you quite risk averse? Block access to most tools, supervise / review AI activity, hesitance towards embedded AI. Risk tolerant where let staff experiment safely, embrace uncertainty and unpredictability but puts more trust on individual on how they are using AI. Where do you sit on the spectrum and what AI risks matter to you?
Addressing AI risks including ethics such as being free from bias and people are comfortable about what AI is doing with basics around deterministic and probabilistic based on statistics. Another risk is compliance about things with principles of GDPR and other regulatory requirements such as EU AI act but many risks are making sure on top of risks. Another risk accountability for example for example have you given explicit permission for an AI bot to be in a meeting and may over rely on it being correct and if using tools with some sort of AI then who is responsible of this and may need to look into these with regards to who is taking responsibility. Reliability of AI regarding model drift that they evolve over time so need to be alert to risk of how answers are handled as this happens.
AI policy key components include define purpose and scope, categorise tasks and suitability for AI, data and IP considerations, review / monitor processes, approach to third-party tools, ethical considerations, organisational governance and escalation routes. It is very easy early on to get hung up on tools should be using but instead think about this on a task basis, such as a public tool, internal tool or using a third-party tool for this task or is one where are not comfortable to use AI for this at all. It is important to touch on data and intellectual property, who owns the data and what rights do you have for the data. Have some level of sense checking or can have a look at what prompts are being sent in Copilot for example and actually explain to employees that can see some of the prompts are using. Also who owns the policy is important or is there a committee for this or is there an escalation route to raise questions or where have things not sure about have a route for this.
What to avoid, specific tool names unless absolutely necessary so have this in broad terms, don't focus on negative behaviours as need to focus on positive behaviours, don't have technical jargon or legal wording. Don't lecture or have laboured educational content on AI, need to have a separate approach to this. Don't have solution or line-of-service specific guidance and risk assessments.
Bring your policy to life is foundations where encourage experimentation and focus on role of human, build trust in every sense. Opportunities where talk about ways AI can be used, give staff avenues to discuss AI adoption and raise queries and think about policy's role in client conversations and engagement where emphasise ethical behaviours, training and binding commitments and develop supporting materials.
Trust in AI where have trust in teams to support responsible adoption and share what does and doesn't work, due diligence with vendors, monitor output and with customers and clients be transparent, talk about guardrails and controls and don't go to customer or client and say things are really difficult or confusing, but say what you are doing and how are getting comfortable about use of AI.
Practical AI Safety - Mac Misiura (Red Hat)
Mac has a PHd in Mathematics and works for RedHat and is a big open source player and works with AI safety team there and will cover how you ensure an LLM won't produce content that violates your policies, will define risks and mitigation, strategies and evaluate and red team your gen AI apps and manage these at scale.
Ai safety is important as there is pressure to shop generative AI apps fast but can lead to scenarios where things can go wrong and people are shipping things too fast. Example was a Chevy dealer chatbot that sold a truck for a $1and another instance of a chat bot which was essentially giving Python code advice recently had issues related to AI safety. Earnst and Young had a report which contained hallucinated references.
Security research shows that given enough time all LLMs are vulnerable to adversarial attacks causing them to engage in risky behaviour such as violating guidelines and producing harmful content and adversarial attacks are getting creative such as using poetry to jailbreak the LLM. Fable 5 was jailbroken by a chunked with distinct prompts where jailbreak gets around model's security features.
How do we define risk, defining risk of GenAI is a non-trivial task since there is no universal definition of risk, potentially leading to different interpretations and risks can be context dependent making generalisations even more difficult and risk can evolve over time making it difficult to keep up with latest developments, risks can be difficult to quantity making it hard to measure their impact. Risk taxonomies where there are many different ones that attempt to categorise various risks such as Nvidia Aegis, MLCommons, IBM AI Risk Atlas, AI Risk (AIR) and MIT Risk Repository but with generative AI need to have some taxonomy to detect vulnerabilities in a system. There are top 10 risks for LLMs with prompt injection being number one.
Vast majority of LLMs will have risks associated with them so why can't you train a frontier model to be safe where model alignment and safety fine-tuning has made progress where can make a safer model but is slower and less usable and lose flexibility of model. Alignment is general where policies are specific and can't encode every organisation's unique policy. Alignment is static where risks evolve where model was trained once but compliance requirements change a new regulation or novel attack can't wait for a retrain. Have guard rails at runtime with different layers of orchestration. Alignment is best effort as you don't know how a closed source model was trained, guardrails are enforceable where avoid wasting tokens letting harmful inputs through.
Base line risks and risk assessment where at minimum every generative AI application should protect against privacy violations or prompt injection but every organisation is different so can carry out a risk assessment against a taxonomy against your domain. Can generate risks and vulnerabilities associated with your application by specifying the intent and then can get a risk taxonomy selected, you can start to build a picture of what to build on top of a model to avoid it going haywire.
Risk mitigation, enter the guardrails which are runtime inspection layers that sit between your application and the model. The high level architecture is where every prompt-response pair is inspected where no model changes are needed, inspect and act where can block, redact or let it through and auditable where every decision is logged, explainable and deterministic and have same API where outputs can be monitored for hateful speech or hallucinations. Most guardrails work as a drop-in replacement for the endpoint such as chat completions for OpenAI-based APIs.
Technique spectrum are guardrail techniques where can have RegEx, keyword or entity detection but don't capture nuance so can have classifiers which are lightweight models which are cheap to run to capture hateful speech and sensitive data or could configure other LLMs as a judge to do guardrails detection with this model and are very good and flexible to capture a plethora of different things. No single technique covers everything, in practice you should layer all three. The art of the blend where have cheap detectors first, expensive detectors run last and only on messages that survived the cheaper checks.
Can't we just use a third-party guardrail solution, third-party moderation APIs are a good start but relying on them alone has drawbacks where locked into one provider and don't have control of what goes into these where data that leaves perimeter is an issue so more companies are talking about sovereign AI. No customisation where can't readily add own detectors etc and suit the company needs.
Open-source solution is NeMo Guardrails initially started by nVidia to add guardrails into LLM where can add it in a matter of seconds in Python but there is also a guardrails server where can use this in your application. Don't have to set up guardrails for default risks and is easy to deal with things like PII and hateful speech and there is a catalogue where can set up RegEx based checks and can configure any model on HuggingFace can be configured as a detector or guardrails to have rails around your LLM. Guardrails won't provide additional context to the prompt it will either let this though or not.
You've deployed guardrails so need to look at latency, bottlenecks and more plus evaluation is important where can have local and production and then send requests and evaluate as needed. Red teaming allows you to test you defences where can have cyber security experts to do this manually and there are ways to automate this and can perform tens of thousands od requests. Don't set and forget, constantly evaluate the system and ideally done at the platform level.
Human Centric Analytics - Christina Phillips (LJMU)
Christina teaches business analytics and will be sharing about this in a taster workshop. Human centric analytics, the human is not just the end user, they produce the data, they interpret the data where there is what data says, what people think it says and what it actually saiys, carries risk, make trade-offs and changes practice.
Human centred design for analytics where grow knowledge of the locus of research, foster agency and discourse, seek agreeable level or granularity, multiple iterations of development, chance to reflect discuss and ideate and emergent solutions at the boundary of practice where involve humans at every step of the process.
Human centric design is where people need to talk to each other with iterations of simple models so need to have parameter choices which is important and what is being used are important choices as not all models support all options. If don’t have human involvement can have automation but if have complexity and more human involvement, then need more human centred design.
Think about a situation, a planned dashboard, an AI tool, a model, a forecast, a KPI pack, a decision-support process or an improvement project, think of something you are doing or others are doing? Think about the people involved, problem clarity, human judgement, data meaning, granularity, implicit knowledge, behaviour change, responsibility and trust / ownership.
Before you build consider how much might need this HCA? Who needs to be involved, what do they know that the data does not, what might they disagree about, what level of detail might support action, what simple representation could start the conversation, need to keep analytics simple to begin with, the point is to make the route sophistication intelligible.
One thing talked about that may be problematic? Planning to put together a HR dashboard as have siloed separated data so will have problems they won't know before bringing this forward. One highly risky project was introducing KPI and metric which may unfold some information that people might not want out there as people get siloed in companies, so if what is what metric is then can help them and process may help. Another issue as making NHS triage and want to bring AI into this with a lot of issues including validation, so if send wrong people into wrong settings people may get the wrong care. Another common theme from projects was buy in from senior management where have a few that have buy in that were successful but other projects without buy in have not been as successful and can have bottom up rather than top down, sometimes you need to work with senior leaders to get them to be more proactive.
Closing Remarks - Stewart Robinson (NUBS)
It has been an interesting day and a chance to reconnect their roots in field of analytics, data science and AI. The foundations of what they have done has been the same, just how it manifests itself stays the same. Some of the things that came out were observations from the day which was don't shoehorn AI into existing things, importance of governance, risk and safety of AI is really important. Keeping up with pace of change is extremely challenging and feels like a world that is moving very rapidly and events like this help keep up with the pace of change. There is also importance of keeping human in the loop and validity is a real question need to think about and be reminded how the North East is a hub for AI and tech.