Back to all analysis news

The great GenAI trade-off: Balancing responsiveness with responsibility

GenAI can expose the business to many risks, ranging from privacy violations to an array of data-related prejudices that can arise when building and using machine-learning models

Adam Spearing
Adam Spearing

07 January, 2025

The great GenAI trade-off: Balancing responsiveness with responsibility
Image: Supplied

TT

16

Heisenberg’s Uncertainty Principle tells us there is trade-off between certainties of measurement. The more accurately we measure position, the less accurately we can measure momentum, and vice versa.

Artificial intelligence (AI) suffers from a similar balancing act between responsive and responsible AI. Business leaders want insights before competitors come to the same conclusions. But they are also faced with appeasing customers, employees, investors, and regulators on the issue of responsible AI.

Unlocking the benefits of generative AI (GenAI) can expose the business to many risks, ranging from privacy violations to an array of data-related prejudices that can arise when building and using machine-learning models. How does the CIO solve this trade-off?

GenAI: Within and without

Like any new tech, GenAI’s adoption does not come without challenges and risks. Brand image is at stake, so it is to the advantage of every AI adopter to consider the risks to security and customer privacy before taking any steps toward adoption.

GenAI’s risks stem from its dual role as both an inward- and outward-facing tool. Increasingly, organisations are going beyond cost optimisation to transform external customer interactions.

If CIOs can get the inward-outward balance right, they can reap the rewards from their GenAI investments and deliver new value for the business. To accomplish rapid response while adequately managing risk, data governance will be critical, as will a coherent AI vision that accounts for the current tendency to overestimate GenAI’s short-term impacts and underestimate its longer-term potential.

This is not a new mistake unique to GenAI. It has become something of a tradition with emerging technologies. However, with GenAI it becomes a potentially critical error. If we, say, rush to reinvent processes for the sake of efficiency, we may overlook vital issues of data integrity.

Given the potential risk of a data breach, CIOs seeking to maximise the value of GenAI at speed and scale must never take their eyes off the importance of data security.

Elastic governance

To properly address the Great GenAI trade-off between responsiveness and responsibility, enterprises must begin and end with governance. CIOs must come to see data and AI governance not as manuals that are written once and rigidly followed thereafter. Policy must be elastic — subject to change as, for example, the CIO’s relationship with risk officers changes.

Culture, including the organisation’s approach to management, must also change to fulfill the goal of maximising gains from GenAI while protecting the business, its people and its customers.

One way of plugging AI skills gaps in the GCC is to upskill from within. As low-code and no-code platforms have aided the rise of the citizen developer, challenges have emerged. GenAI represents a democratisation of development.

CIOs may need to reimagine their role in the organisation. They are now much more than just infrastructure stewards. They are data custodians who must pay due attention to both security and potential for innovation. The CIO must now lead on data governance, which starts with establishing the ability to identify the location of data in real-time. Tech leaders must comprehensively map and monitor each data source inside or outside the business.

This issue may be the greatest challenge in corporate IT today. While visibility has never been more critical, it has also never been more difficult. Data moves to serve the needs of providers and their customers. And if tracking its current location is a challenge for the CIO, this presents a risk when it comes to protecting that data and maintaining its quality.

Verification and refinement are significant elements of responsible AI, so tech leaders must define and develop a forward-looking data strategy that is tightly coupled to business goals, but also imposes strict frameworks that ensure quality, privacy and security.

Learning from others

Sustainable success in AI requires a cultural shift. The CIO will be both AI champion and AI teacher, encouraging colleagues to look at data differently by highlighting the connection between it and business value.

By promoting data fluency, the CIO becomes a value creator. They will also engage with partners and peers to shape the market. They will make use of existing networks while creating new ones. Through this continuous learning, CIOs will improve their understanding of GenAI and what their priorities should be to maximise its value-add.

Within these knowledge-exchange networks, CIOs will find GenAI vendors who will come under increasing pressure to be transparent about how their algorithms operate, going so far as to allow their customers to inspect them. That transparency must extend to clear explanations of where data is stored, sent, and processed. And vendors will be expected to comment openly on how data can be managed within the complex and fast-moving regulatory environments we find in regions such as the GCC.

GenAI represents an opportunity and a challenge for CIOs. Leaders must go back to the drawing board on data governance and put it front and centre. There is an opportunity for AI to play a role in data governance by continuously monitoring for potential vulnerabilities and operating autonomously to remedy them. It appears as if GenAI is not bound by limits in terms of what use cases it can satisfy. It will be up to the CIO to impose such limits in consultation with colleagues, as they decide where to deploy it, what roles should be reshaped, and what business processes should be optimised.

The stakes are high. Mastering the responsiveness-responsibility trade-off means competitiveness and prosperity. Getting it wrong could mean the end of a brand.

The writer is the head of AI Innovation, EMEA, ServiceNow.

Read: ‘AI can serve the greater good’, says Amazon CTO Dr Werner Vogels

Abu Dhabi sets up ADRA to streamline business registration

The authority will develop a unified database consolidating data on economic establishments across Abu Dhabi’s mainland and its non-financial free zones

Kudakwashe Muzoriwa
Kudakwashe Muzoriwa

07 January, 2025

Abu Dhabi sets up ADRA to streamline business registration
Image credit: Christopher Pike/ Getty Images

TT

16

The Abu Dhabi Department of Economic Development (ADDED) has set out measures to simplify processes for businesses as part of the emirate’s broader strategy to diversify its economy away from oil.

The department launched the Abu Dhabi Registration Authority (ADRA), a centralised business registry authority that will be the single point for business registration.

ADRA will develop a unified database consolidating data on economic establishments across Abu Dhabi’s mainland and its non-financial free zones. The move is aimed at facilitating the management of the commercial registry, streamlining licencing procedures, managing regulatory affairs and ensuring compliance.

The authority will introduce new types of licences, creating opportunities to attract talents, investors, and entrepreneurs while opening a window to benefit from Abu Dhabi’s diverse and robust economy.

“The establishment of ADRA marks a new milestone in Abu Dhabi’s remarkable economic journey. As an arm of ADDED, ADRA supports our initiatives to accelerate the emirate’s economic growth and diversification by offering streamlined procedures, expert guidance, and access to a thriving business ecosystem,” said Ahmed Jasim Al Zaabi, chairman of ADDED.

“ADRA plays a pivotal role in attracting new investments across key sectors, contributing to the realisation of Abu Dhabi’s economic vision. It ensures compliance with international standards and global regulations by all economic establishments in the emirate’s mainland and non-financial economic free zones.”

Abu Dhabi’s economy expanded by 3.9 per cent in the third quarter of 2024, as per preliminary government estimates. Notably, the non-oil GDP saw a significant surge of 5.9 per cent during the same period, driven by growth in the construction, manufacturing, and finance and insurance sectors.

The emirate has intensified its diversification efforts, focusing on key areas such as tourism, logistics, manufacturing, and industry to ensure sustained economic growth in the future.

Read: Abu Dhabi GDP grows 4.5% in Q3 ’24, led by non-oil sector

Zand Bank, Klickl International partner to advance digital finance

Zand Bank (Zand) has announced a strategic collaboration with Klickl International (Klickl), a Web3 open finance platform. The partnership aims to bolster Klickl’s operations by leveraging Zand’s banking solutions and products. The collaboration comes on the heels of Zand’s recent achievement of becoming the first UAE bank to offer digital asset custody services, following approval […]

Gulf Business
Gulf Business

07 January, 2025

Zand Bank, Klickl International partner to advance digital finance
Image: Zand Bank

TT

16

Zand Bank (Zand) has announced a strategic collaboration with Klickl International (Klickl), a Web3 open finance platform.

The partnership aims to bolster Klickl’s operations by leveraging Zand’s banking solutions and products.

The collaboration comes on the heels of Zand’s recent achievement of becoming the first UAE bank to offer digital asset custody services, following approval from the Virtual Asset Regulatory Authority (VARA).

Additionally, the upcoming launch of Zand’s UAE dirham-backed stablecoin is set to further strengthen its efforts to bridge the gap between traditional finance (TradFi) and decentralised finance (DeFi), reinforcing the bank’s leadership in the digital assets space.

Klickl to benefit from Zand’s infrastructure

Klickl, headquartered in the UAE and established in 2017, will benefit from the digital bank’s infrastructure, which will streamline its financial management and enhance its business processes within the Web3 ecosystem.

The collaboration aims to meet the growing needs of the digital economy.

Michael Chan, CEO of Zand, emphasised the significance of the collaboration, saying: “We are pleased to announce our collaboration with Klickl International, aligning with the UAE’s bold vision to accelerate the digital economy. We are dedicated to delivering seamless and secure banking experiences through continuous innovation, forward-thinking, and a client-first approach.”

Klickl CEO Michael Zhao expressed his enthusiasm about the partnership, stating: “Partnering with Zand Bank marks a pivotal moment in our journey towards reshaping the digital finance landscape. With Zand’s support, we are unlocking new possibilities for businesses and consumers, driving meaningful change in the industry.”

Cyberhealth: How to protect your company’s systems in 2025

Failure to maintain proper cyber hygiene can lead to compromised sensitive data, operational disruptions, and significant financial losses

Rami Nehme
Rami Nehme

07 January, 2025

Cyberhealth: How to protect your company’s systems in 2025
Image: Supplied

TT

16

As we begin the new year, many of us take the opportunity to reflect on our resolutions, whether they pertain to personal finances, career goals, or health. While individuals can often take charge of their personal health independently, businesses, especially in the realm of cybersecurity, require a more collaborative approach.

In 2025, the security landscape will present numerous challenges, and it is crucial for organisations to recognise the need for teamwork and proactive strategies to ensure the health and resilience of their digital assets.

In the UAE, a Cyber Security Council survey, published in March 2024, uncovered more than 155,000 vulnerable assets in the country and found that 40 per cent of critical vulnerabilities had gone unaddressed for longer than five years. If the nation is to attain the resilience to stave off campaigns by increasingly sophisticated threat actors, every enterprise will need to practice rigorous cyber hygiene.

Cyber hygiene can be defined as a comprehensive set of best practices designed to prevent organizations from becoming vulnerable to cyber threats. This responsibility extends across all levels of the organisation, from end users to technical teams, including DevOps, IT, and security personnel. Everyone must adopt a daily routine of cybersecurity practices to collectively enhance the organisation’s security posture.

Much like personal hygiene, which requires regular attention to maintain health, cyber hygiene necessitates ongoing vigilance to safeguard against potential threats. Failure to maintain proper cyber hygiene can lead to compromised sensitive data, operational disruptions, and significant financial losses.

Practice makes perfect

Let’s start with five basic cyber-hygiene practices. First, software updates cannot be treated as optional, but as the UAE Cyber Security Council found, many updates are ignored, even though they are released to protect against known vulnerabilities. Attackers are always looking for these vulnerable assets.

Second, enforce password-strength principles.

Ensure users choose complex, unique strings of diverse characters (uppercase letters, numbers, and special symbols), and avoid birthdays, pet names, and other memory-friendly words that are easy to guess. Ensure each password is unique to an account. Third, implement multi-factor authentication because as strong as a password may be, it is just one layer of security and is vulnerable to theft.

Fourth, think about how data is backed up. Whether you opt for external hardware or a cloud storage solution, test your choice and make sure you perform restoration drills.

Lastly, fifth, stay vigilant. Make sure every user knows that nefarious parties are perfectly capable of sending emails, text messages, and other communications that appear genuine. Be sure they know that every link clicked, and every network joined, is a potential threat.

If security leaders have trouble getting buy-in from decision-makers, the business case for these practices is simple and strong.

Good cyber hygiene brings business continuity in the event of an incident and earns trust from customers, partners, investors, and regulators. In this way, basic cyber hygiene minimises risk by mitigating the impact of any potential breach.

Tools for tasks

Investment in the right tools can help address a range of problems. While many are targeted at specific industries, others have broader relevance. Continuously updated antivirus software still has a place in the organisation.

Multi-scanning — the technique of having multiple AV agents scanning resources — helps increase detection rates of malware, even zero-day threats. These solutions go beyond file hygiene to guard against fraudulent or malicious websites. They provide protection against ransomware. And their privacy features can even prevent tracking by advertisers.

The list of hygiene tools goes on. Virtual private networks (VPNs) encrypt data and mask IP addresses, leading to private, secure connections. Password managers allow the creation and storage of passwords and even allow strong (complex and unique) passwords to be shared via text or email, meaning they never have to be written down.

Software and hardware firewalls allow organisations to restrict outside access to home and business computers and a range of other connected devices. This protects data and accounts from compromise by blocking malicious traffic, but users still must be urged not to install unvetted software or click on unknown links.

Going further

These tools come together with best practices to protect organizations from the modern cyberthreat landscape, which is becoming more dangerous with every passing month. But basic digital hygiene is only the beginning. There are more advanced practices that allow individuals and enterprises to go further with their cyber hygiene.

You can start by conducting regular audits of your digital footprint. Review all the permissions granted to apps and websites. Many websites store payment data, for example. When we minimize permissions by only maintaining those that are necessary, we can greatly reduce our exposure to cyber-incidents or the unwanted collection of your data.

Make sure you have the visibility to monitor your environment for anything that looks suspicious. Leave no stone unturned. If you see something that appears out of place, then investigate. This could be a new device on your network or an unrecognised charge on your credit card. Be wary of these flags and investigate them early. If you do not, a minor incident could quickly become a major problem.

Carry out periodic diagnostics on your systems and clean up as appropriate. Ensure each of your devices runs optimally in terms of both performance and security, for both hardware and OS.

If needed, seek out the vendor’s guide on the correct configuration. Do not hesitate to run virtual machines in isolated environments for the testing of new software or to see what threats an untrusted website holds.

Using a secure, contained ecosystem means any malware will be trapped inside the virtual environment, and will be unable to have any impact on the live network. This approach adds another layer of security on top of those provided by security tools.

Ongoing vigilance is key

Cyber hygiene is a journey, not a destination. It is a process that calls for organisations’ ongoing commitment. It requires vigilance and consistency. The basic practices and some standard tools can certainly strengthen the digital immune system.

The writer is a regional sales director – UAE, South Gulf, Levant & Pakistan, OPSWAT.

PureHealth’s Ardent Health expands US footprint with strategic acquisition

PureHealth’s ongoing international expansion through Ardent Health reflects a broader ambition to reshape global healthcare landscapes

Gulf Business
Gulf Business

07 January, 2025

PureHealth’s Ardent Health expands US footprint with strategic acquisition
Image: Getty Images/ For illustrative purposes

TT

16

UAE-based PureHealth has continued to strengthen its international presence through its associate, Ardent Health, which has recently acquired 18 urgent care clinics across New Mexico and Oklahoma from NextCare Urgent Care.

This marks a significant expansion in Ardent’s US network.

The newly added clinics, six in New Mexico under Lovelace Health System and 12 in Oklahoma under Hillcrest HealthCare System, represent a crucial step in Ardent’s growth strategy.

The acquisition aligns with PureHealth’s ongoing focus on driving global expansion through a targeted bolt-on approach.

This strategy aims to enhance healthcare accessibility across the globe while bolstering its presence in high-potential markets.

This transaction builds upon Ardent’s recent acquisition of nine urgent care centers in East Texas and Topeka, Kansas, in 2024.

The additional locations increase Ardent’s reach in mid-sized urban communities across the United States, advancing its goal of creating a consumer-centric healthcare ecosystem.

PureHealth marks a key milestone in its international operations

The transaction also reflects the growing value of PureHealth’s investment in Ardent Health, which saw a successful initial public offering (IPO) in July 2024, just over a year after PureHealth’s investment in the company in May 2023.

Marty Bonick, CEO of Ardent Health, expressed enthusiasm about the expansion, stating, “Expanding our urgent care footprint represents significant progress in our mission to create a consumer-focused ecosystem of care in each of the communities we serve.”

He emphasised that the move would improve patient access to convenient, high-quality services, adding, “These additional access points also bring new patients into our network while creating enhanced capacity to serve patients within our clinics and emergency departments.”

Ardent Health’s strong performance underscores the effectiveness of its strategy.

In its third-quarter 2024 results, the company reported $1.45bn in revenue, a 5.2 per cent increase compared to the same period in 2023. Admissions also grew by 6.4 per cent year-over-year, further signalling the health system’s continued momentum.

Saudi’s PIF secures $7bn murabaha credit facility

The Shariah-compliant financing structure forms part of PIF’s continued objective of diversifying its funding sources

Gulf Business
Gulf Business

07 January, 2025

Saudi’s PIF secures $7bn murabaha credit facility
Image: Getty Images

TT

16

The Public Investment Fund (PIF) of Saudi Arabia has closed its first-ever murabaha credit facility, raising $7bn as part of its ongoing medium-term capital-raising strategy.

The deal was backed by a broad syndicate of 20 international and regional financial institutions.

Fahad AlSaif, head of PIF’s Global Capital Finance Division and the Investment Strategy and Economic Insights Division, highlighted the significance of the new facility.

“This inaugural murabaha credit facility demonstrates the flexibility and depth of PIF’s financing strategy and use of diversified funding sources, as we continue to drive transformative investments, globally and in Saudi Arabia,” he said.

PIF has strong credit ratings

The sovereign wealth fund, which is at the forefront of Saudi Arabia’s ambitious Vision 2030 reform plan, has garnered strong credit ratings from leading agencies, including Aa3 from Moody’s and A+ from Fitch, both with stable outlooks.

The fund maintains four primary sources of funding: capital injections from the Saudi government, transfers of government assets, retained earnings from its investments, and loans and debt instruments.

This new financing move underlines PIF’s strategy to remain well-capitalised and capable of driving significant investments, both within the kingdom and internationally, as it continues to support the diversification of Saudi Arabia’s economy.

More news in analysis