Lukáš Kintr, Director of the National Cyber and Information Security Agency, explains how government and major companies can use artificial intelligence while retaining control over data, models, and supply-chain risks.
How can we establish guidelines for implementing artificial intelligence in government and large enterprises to enable Czechia to rapidly capitalise on AI’s economic and innovation advantages, while ensuring quantifiable cybersecurity resilience and oversight of supply chain, data, and model-related risks?
Much as with cloud computing years ago, we now have the chance to harness the significant potential that artificial intelligence offers. Beyond its many benefits, AI adoption also involves risks similar to those associated with cloud technology. That similarity is no coincidence. Most large language models run on cloud infrastructure, as few organisations have the computational resources to run them independently. One of the most significant risks, therefore, is giving up “physical” control over the data we input into AI systems. The servers hosting this data are not under our direct oversight, which creates threats such as potentially weaker protection of our rights and the data itself, unauthorised access to information, data misuse, and similar concerns. Naturally, there are methods to mitigate these threats, but ultimately, everything will depend on the level of trust we place in the cloud or AI provider. To illustrate what happens when we completely disregard the above considerations, imagine handing your unlocked smartphone to a stranger on the street and asking him to hold it for a moment.
We have successfully addressed the cloud challenge. We choose our service providers, determine where our data is stored and processed, implement encryption, and track who accesses our information. In other words, we no longer hand our unlocked smartphone to a stranger; rather, we hand it to someone we trust, keep it secured with a lock, and monitor its activity. Or simply keep a tight grip on it.
While AI has distinct features compared to cloud computing, I am confident that in this instance as well, we will be able to adapt and utilise it in a way that minimises the associated risks.