Artificial intelligence (AI) is the current shiny new object a lot of IT people are playing with to see if it can help their businesses become more profitable. But like any new technology, there are always questions about how it's being used, how secure it is, and which use cases are a best fit.

WitnessAI is a San Mateo, California-based startup that is concentrating on an aspect of internal-use AI that a lot of companies haven't considered: how corporate data can be leaked by the incorrect use of AI tools. CEO and co-founder Rick Caccia, a veteran of Google and Palo Alto Networks, explains the company's purpose and secure-enablement technology.

Chris: Rick, explain to me what a secure enablement platform is and how it powers your business?

Rick Caccia: When we talk about a secure enablement platform, we’re focusing on secure usage and AI compliance. It addresses concerns companies have about their employees using AI systems in ways that might pose security risks. For example, employees might unknowingly expose sensitive information by uploading it to external AI platforms like ChatGPT. Our platform helps companies see what employees are doing, gives them control, and ensures compliance without stifling productivity.

Chris: We're finding out that there’s a growing risk with AI use in businesses. Can you give an example?

Rick: Absolutely. One company I spoke with had a developer upload their entire mobile app's source code to an AI to optimize it. Another example is employees sharing sensitive financial data, like earnings reports, with AI platforms. These are common issues across many companies. The problem is, businesses often don’t know this is happening until it’s too late, leading to data breaches or compliance violations.

Chris: What compliance are companies concerned about when it comes to AI?

Rick: It depends on the industry. For companies operating in Europe, it could be about complying with GDPR (General Data Protection Regulation) to ensure customer data isn’t leaked. For others, like financial firms, it’s about ensuring sensitive financial information isn’t released before regulatory deadlines. Our platform helps businesses track and manage these risks by providing visibility into AI interactions, which is crucial for compliance.

Chris: You mentioned the issue isn’t always about attacks. Can you clarify that?

Rick: Right. When we first started, we thought the biggest concern would be security attacks related to AI use. But when we talked to CISOs, they were more worried about the mundane aspects, like not having any visibility into what employees were doing with AI tools. For example, they couldn’t see when employees were using AI in tools like Microsoft Word’s Copilot or on their personal devices. These are boring but critical concerns. It’s not about traditional security threats, but governance and compliance.

Chris: So how does your platform provide this visibility and governance?

Rick: Our platform sits within the company’s network and monitors all AI interactions. We capture things like prompts, responses, and the intentions behind them. For example, if someone’s writing a contract, we can redact sensitive information such as customer names or pricing. If someone is using an external AI to write code, we can block that activity or route it to an internal system. It's about giving companies control over how AI is used within their environment.

Chris: That makes sense. How are companies reacting to this?

Rick: The demand has been overwhelming. Since we shifted our focus to compliance visibility and governance, we’ve signed up 30 customers in a month. Everyone from airlines to banks and utilities is showing interest because they all face the same challenges. It’s about AI risk management, which is becoming a key concern for many organizations.

Chris: Are there specific industries that are more concerned about AI compliance?

Rick: Every industry is feeling this. For example, law firms are worried that using AI might break internal ethical walls between clients, while hospitality companies are concerned about large-scale contracts leaking to competitors. The potential penalties are huge, and while the issues may seem mundane, the financial and reputational risks are very real.

Chris: You mentioned earlier that only a small percentage of companies have fully deployed AI despite high experimentation rates. Why is that?

Rick: That’s right. According to a study by MIT Review, while 77% of big companies have experimented with AI, only 9% have fully deployed it. The reason is the lack of governance infrastructure around AI. They don’t have visibility or policies in place to manage AI use so they’re hesitant to move forward. Our platform helps solve that problem by providing the necessary oversight and compliance tools.

Chris: Are you seeing a lot of interest from chief privacy officers and CISOs?

Rick: Definitely. The chief privacy officers are especially concerned because their data—customer data, financial information, everything—could be at risk if it’s unknowingly exposed through AI. CISOs, on the other hand, are worried about the lack of visibility into what’s happening with AI tools. Our platform addresses both sides of the coin by offering governance and risk management.

Chris: It sounds like you’re solving a very specific but widespread problem.

Rick: Exactly. It’s not flashy, but it’s crucial. AI compliance and risk management might not make headlines, but it’s where businesses are feeling the most pain right now. And we’re helping them address that in a scalable and efficient way.