interview with Alex Shandro
“Governing AI properly requires significant investment. There is often a reluctance to invest in governance around AI, but it always pays off.”
Maurice
Hello everybody and welcome to another edition of C&F Talks where I get to speak to one of the speakers at one of our upcoming events. Today it's my great pleasure to have with me Alex Shandro, he's Partner and Global Head of AI Advisory at A&O Sherman and Alex is going to be joining us at the fourth annual AI Regulation Summit which is being held in London on the 1st of October. Alex, welcome.
Alex
Thank you very much for having me.
Maurice
Great to have you with us. Let's turn to our first question.
Consumer Protection and the Rise of AI Agents
As AI moves from passive chat tools to autonomous AI agents capable of making purchasing decisions, how must consumer protection laws evolve to keep up?
Alex
Okay so look, we're talking here about agentic commerce which we'll be featuring at our AI Regulation Summit. It is obviously one of the frontier use cases for AI agents and I should just start by saying it's one thing. So agentic commerce is one of these umbrella terms that's thrown around a lot at the moment but really captures a huge spectrum of different AI use cases deployed at different stages of the consumer shopping experience and that spectrum really is a spectrum of autonomy.
So you have agents that can assist, do comparing, find things, generally help the consumer to make a purchase at one end and then agents operating pretty autonomously end-to-end integrated with loyalty programs at the other. Now that autonomous end of the spectrum, we're not there yet. In fact, we're probably not even close.
There are a lot of technological barriers and regulatory ones that need to be overcome. But to answer your question about how consumer laws are really sort of applying to this spectrum, to simplify, the more you move along that spectrum to the autonomous end of it, the more we push at the boundaries of existing laws and I'm referring there not just to consumer laws which you mentioned but also to payment laws, to privacy laws, to AI regulation and I'll just unpack that if that's okay in about one minute which really what I mean is accountability. So who is liable when things go wrong and if you apply this to shopping, all sorts of things could go wrong.
So you could have inaccurate product data, you delivery failures, you could have misalignment with the consumer sort of intent, data leakage, privacy violations, cyber breaches, IP infringement, bias, it's a very long list. And if you start from the premise that AI tools are simply that, they are simply tools and therefore have no legal personality and therefore no prospect of liability attaching to the AI itself, then who is liable for any of those different harms when they happen? And I think the presumption needs to be, and there's been some very interesting commentary in the UK on this, including from the judiciary, the presumption needs to be that the deployer of the tool is liable. So the person using the tool is liable for the effects of the tool.
But who is that? Is that the retailer? Is it the AI platform provider? Is it the payment provider? Or is it a combination of the three? And here is why it matters to consumers to bring it back to your question. If a consumer uses an agent to do their shopping, can they cancel a contract if the agent makes a mistake? Are terms agreed by agents enforceable? How do you deal with fraud? How do you deal with an agent going off and doing something unexpected? How does the retailer verify that the agent even has authority to do this transaction on behalf of the consumer? How do you deal with chargebacks? These are just some of the many questions that existing laws don't have an answer for. So really, anyone trying to do this stuff, if you're a retailer or a payment provider, you're having to take a view in a way that's robust and defensible.
And that is inescapably, I'm afraid, going to result in a high compliance burden, because you have to take that view across all of your jurisdictions.
Maurice
Yes, I can see that. Obviously, there's a fair degree of uncertainty throughout all these issues.
Building Effective AI Governance Frameworks
And turning to companies themselves, how can they build AI governance frameworks that are flexible enough to handle model drift and evolving models, the fact that AI is reinventing itself and getting better all the time, rather than treating compliance as a static one-time orders in a rapidly changing world?
Alex
Sure. Yeah, no, look, nice segue. I think governing AI is really hard.
And I say that as someone who spends most of my waking life trying to do that. And embedded in your question is one of the reasons for that, which is change is happening all the time. The technology is changing constantly.
And every step change amplifies risk. Laws and policies are changing constantly and diverging increasingly globally. And the commercial landscape is changing constantly.
So by that, I mean, the business drivers for AI systems to be developed and deployed. So we're well used to dealing with this notion of use case creep when businesses use general purpose models. That's the risk that you onboard an AI system for one thing, but because it's general purpose, someone else can use it for something completely different for which you've not thought through the risks.
That's a well-known challenge for AI governance. But agentic AI changes it again, because you start giving AI systems tasks to do with more or less human oversight. Then how do you deal with performance jumps, technology shifts, use case creep in that context when the risks are so much greater and that the spate of recent incidents where models have allegedly escaped their containment is evidence of that.
But that's a completely separate conversation. So you asked me how you deal with this. Well, it's the same three pillars, just applied differently.
So the three pillars that we talk about when we advise our clients on governance are designing the use case properly and the governance to reinforce that use case. And I mean that in a very granular way. Operational controls, so technical configurations, system-based guardrails, data permissioning.
And actually here is probably where for agentic AI specifically, most of the legwork needs to be. We know now from all of these incidents that you cannot simply give your AI system a set of rules to follow and expect them to follow those rules. So they are probabilistic.
They will break the rules that you give them and be quite honest about that. And that can have potentially catastrophic unintended consequences. We now have clients of ours that have lost massive amounts of data because agents have done something unexpected because they haven't been properly monitored by systems.
So if you take humans out the loop, you put systems in the loop. So that sort of second pillar of sort of operational controls is absolutely critical. And then your third one is contractual risk allocation, which again is a slightly different topic, but it's not in itself of course a panacea.
You want to avoid the harm happening in the first place before you then deal with how you allocate that along the value chain.
Key Corporate Compliance Challenges Under the EU AI Act
Maurice
You mentioned there that there's a divergence in approaches, and I suppose that's very clear when you look at the difference between the UK, US and the EU. And with key provisions of the EU AI Act rolling out, what do you think is the single biggest compliance blind spot that you're currently seeing in corporate boardrooms?
Alex
Sure, look, we are actually talking a lot directly to boards of some of the biggest companies and banks in the world, because the board has a critical role to play in this, of course.
And I think what it boils down to, to deal with all of the challenges, some of which we've just been alluding to, is that governing AI properly requires significant investment. And that's often not part of the equation when businesses are onboarding AI systems for productivity gains. There is a reluctance to then invest in governance around that, but it always pays off.
And I guess, what are the specific blind spots that result from not investing sufficiently? Well, one is that you might look at AI as a sort of standalone technology programme, when really it is already embedded and distributed throughout the business and throughout your supply chain as well, critically. So boards often like to focus on high profiles of internally developed systems, things that are going to transform a particular product or create a new business line. And all of that's really important.
But boards shouldn't neglect that AI is already embedded in different parts of the organisation. And there will be dependencies downstream and upstream across all sorts of aspects of the AI stack, whether that's models, data, applications, customer relationships, where risks can arise that can now, with agentic AI, be catastrophic, as recent incidents have shown us. So that's one.
Just one other sort of blind spots is, again, I see this every day, that we associate compliance with AI specific laws, like the EU AI Act, when really, the regulatory landscape around AI is, yes, it's those things, but that's a very narrow part of it. It's every other technology agnostic body of law that is currently being tested by these unique challenges that AI is raising, and causing governments to shift policy in very esoteric, individual ways to suit their specific economic and geopolitical objectives. So export controls are a huge focus for us right now, we're doing a lot of advice on export controls.
Can you live with a situation where you can use a US AI model one day, but then not the next, because the US federal government has imposed restrictions? Do you turn to China for open weight models, which are just as good now nearly, but carry their own regulatory and other risks? These are like genuinely existential, strategic board level questions, which a year ago were probably not sufficiently part of the conversation about governance and compliance.
Maurice
So yes, it's a massively complex area. As you say, there's a lot of non-AI specific legislation and regulation that impacts the development of AI.
The Future of Global AI Regulation
But just going back to this concept of divergence for a moment, do you think that the EU AI Act will establish itself as, if you like, a global baseline for regulation, like the GDPR Act did? Or are we heading towards a highly fragmented global regulatory landscape? And if so, what are the consequences of that?
Alex
Oh, look, there's no doubt it's the latter. We are seeing and will continue to see significant divergence globally in all areas of regulation, as just mentioned. And that's because every country occupies a different place in the AI value chain and has different economic interests.
And not just economic interests, but because AI is a dual use technology, national security interests too. So I think we will continue to see divergence. Absolutely.
In terms of the consequences, well, there's many, some of which we've already touched on in terms of what it means for governance. But I think one interesting thing for any multinational business is to look at what sort of your key markets are actually doing. And now that we have more and more evidence of some of these really catastrophic risks around AI, these data incidents that we've seen, I mean, AI and cyber is probably the biggest boardroom worry right now.
But if you look globally at what's happening, it's really interesting that China is legislating prolifically around AI. So it is really trying to establish itself along with the EU as a regulatory superpower. And its thesis, primarily economic driven, is that if they can give businesses certainty through regulation, businesses will adopt, and adoption will then be the real fuel for economic growth.
And it won't matter that there are a few months, although possibly only one month now, behind the frontier in terms of actual model performance. And in parallel with that, they're also obviously open sourcing their AI models, driving the convergence of AI models themselves as a commodity. So it's a very interesting strategy.
And I think it is shedding new light on what the EU has done with the AI Act. And I'm not a massive defender of the AI Act. And actually, in practice, I think for most of our clients, it only has very narrow application.
But I do think that some aspects of the AI Act, at least in substance, will turn out to have been quite prescient. And I think it's interesting that China is following suit, that California is following suit in certain ways like transparency. So over time, and look, this has a long way to play out over time, we might see some sort of convergence in very specific areas across the global regulatory landscape.
AI Sovereignty, Geopolitics and National Security
Maurice
You highlighted the national security interests, which takes us on really to I think, our final question for the interview today. What does AI sovereignty mean for businesses? How is it affected by geopolitical and national security issues? To an extent, you've already answered that in relation to China, and so on, but in a broader sense?
Alex
I slightly shudder at that term AI sovereignty. And I say that knowing full well, I'll be speaking on that topic at the summit.
But I shudder because it's a term that's now commonly used. In its literal sense, it's a misnomer. Because no one, no business, no government could possibly have true sovereignty over their AI capabilities, because the dependencies are everywhere.
Even in the US, you know, they're still fundamentally dependent on Taiwan, and Taiwan in turn on ASML, and we could go on for a long time. So what do we mean by for a business? And this is really important. And we are talking to a lot of clients and their boards about this.
It means, which strategic choices should you make to control and invest along the value chain. So if you imagine that the chain sort of starts with energy, then it goes to infrastructure, then you've got data, then you've got the models, then you've got applications, and you've got the end user, that sort of full chain from energy to end user, where in that chain is the given business to performing a role or dependent on someone else to perform a role. And you find those dependencies.
And then you need to strategically decide, where do we need to invest so that we remove that dependency? Why does it matter to us? And that will be a different answer for every business. And that answer will keep changing as technology changes. But the recent export control restrictions on anthropic and the sounds that we've been getting from Beijing about their own sort of frontier models, these are really important questions.
So I'm not saying that a business will ever have a hope to build a proprietary model. I don't think that's going to happen, at least not for large language models anyway. Clearly, it wouldn't happen.
So then you partner with a diverse group of partners to get those models in, and then you focus on what's really different for you, which will be your data, it will be your applications, it will be how you bring it to your end users and your people. And so I think that's where things are going to settle and where we're going to see the investment. And there's all sorts of nuanced, quite tricky technical questions there for a about geography, about vendors, about contract terms, about how you deal with procurement, about what you do to clean up your data and who helps you do that.
And none of these have simple, quick answers. So as I keep saying, it will all take time and it will all take a lot of investment.
Maurice
Well, we're certainly seeing a lot of investment, I think, aren't we? But yes, you're absolutely right.
It will take a lot of time. Maybe you can quite see how it all plays out. To our viewers, if you'd like to hear more from Alex on these absolutely fascinating issues, I have to say, then please do visit our website, where you'll find details of the upcoming conference, the fourth annual AI Regulations Summit, our website, www.cityandfinancial.com. So we very much hope to see you at the event.
It just remains for me to say, Alex, thank you very much for joining us today.
Alex
Pleasure, thanks for having me.

