In the movie Jurassic Park, Dr. Ian Malcolm (played by Jeff Goldblum) says, “I'm simply saying that life finds a way” in reference to dinosaurs finding a way to reproduce despite all being the same gender. Like life in Jurassic Park, technology also finds a way – a way into the enterprise, a fact not lost on IT and security teams that have had to deal with everything from Google Search to mobile phones creeping their way into the organization. Once inside the enterprise, they reproduce like the dinosaurs in Jurassic Park.
The latest technology that users are accessing at work is ChatGPT, which carries unique implications and challenges, leaving some CISOs and other technology leaders wondering if they should block ChatGPT. And many have. According to a report by HR Brew, many companies -- including Apple, JP Morgan Chase, Amazon, Accenture and other -- have banned or limited its use.
What approach should you take? Like any critical question, this one isn’t easy to answer. But it is one that James Robinson, deputy CISO at SASE provider Netskope, recently had to address.
Robinson told SDxCentral that Netskope has a long history of doing things with machine learning (ML) and artificial intelligence (AI), but recently that focus has become more intense. “The AI push is kind of a big change, especially for LLMs [large language models] that became accessible to you, to me, to anybody.”
[ More artificial intelligence coverage ]So when it came to ChatGPT, Robinson said the company didn’t want employees or teams to be left behind. “We are in a pretty difficult economic environment. There's no hiding that and folks being left behind puts them in a bad position. We also knew that we had to do it responsibly.”
Don't block ChatGPT for everyone, do use it carefullyRobinson said that in talking to other security leaders, peers and clients, it’s pretty split with what to do with generative AI – that is, blocking or allowing. But, he added, the number of companies willing to allow ChatGPT would go up if they had a path for using it safely. “I think companies have a fear of opening up because someone's going to do something silly – and we know something silly is always going to be done. That's kind of what you do with new technology.”
The key, according to Robinson, is setting guardrails. He said he has met with colleagues, customers and prospects and outlined those guardrails. He said he convinced some to change their mind by helping them realize it’s not a zero-sum game. ”Maybe you're not going to open it up for everybody, that's fine. But you know that you're going to have to open up access for a select group with some of the guardrails.“
Until you understand the risk, saying no is, of course, always an option for IT and security teams. But Robinson said his advice is to say, “OK, we're going to say no for most, and then we're going to take this group of people that we want to pilot with and say you’re going to get access.” For those who have access, Robinson, you add multilevel controls in place and provide education. “That's how we've approached it ourselves and how I've gotten others to be more comfortable with it.”
Most users, Robinson said, appreciate being treated as responsible employees. However, he adds that by having data-protection controls in place, if someone starts moving code or certain files, “we can jump on that point and say, ‘we tried giving you some freedom and you took it a little too far.’ And then we have our incident-response plans. We didn't have to adjust any response plans. We already had them in place.”
Back to basics with generative AIGenerative AI can be an opportunity to re-educate employees about what intellectual property is, for example. Robinson said that’s where the education angle comes in. Netskope uses ChatGPT as an opportunity to remind people about intellectual property, making it clear that “this is what we expect you to do. Here's what we don't expect you to do.”
“But we also had technical controls in place to then catch when people are doing things so we can pop up and say, ‘Hey, y'all, we noticed that you're going to this website, have fun, but remember, don't share intellectual property.’”
Robinson said Netskope has created internal channels where workers can share tips and tricks. “That's exactly what we want. They're actually meeting with our internal security team with ideas on ways that we can be more effective as well, which is powerful.” He contrasted that to the normal reaction when security gets involved. “Usually when the security person walks in the room, all the air gets sucked out. No one's talking.”
With a technology as notorious as ChatGPT, curiosity is going to be hard to overcome at all levels of employees.
“I think for most it was first a curiosity,” Robinson said. “How can this cool thing do this really cool stuff? Let me see it.” Added to the curiosity is the fact it’s so accessible. ”You can do it from your phone, you can do it from any browser. There aren’t a lot of hurdles.”
It’s not just the nontechnical parts of the workforce that are curious to use ChatGPT and generative AI in general. Robinson said even the company’s data scientists are getting in on it. And that makes it more accessible to others, who think, “I have the same same technology at my fingertips as you do.” They [data scientists] use it and, in some cases, that makes it more tangible and real, he said.
Can enterprises rely on ChatGPT?It was only months ago that reports abounded about the accuracy issues of ChatGPT, but, to use an anthropomorphism, ChatGPT is really a child and is growing and learning every day. “I think it's getting better,” Robinson said. “That's a critical part that maybe the general public doesn't get is that there is a learning element. And that is pretty expensive. It's almost been crowdsourced in many ways.”
“Sometimes you still have to have a base knowledge of something before you can just rely on it. Or you look kind of foolish.”
Robinson draws a parallel to when Wikipedia first came out. “I remember the information on there was crazy. But now my children are able to reference Wikipedia in school work.” He also points out that there was a time when you couldn’t reference the internet in school reports. “Your teachers wanted you to reference books.” He said people will become more comfortable with ChatGPT as it gets better and they'll be able to reference it. “I think the danger is if people trust it without verifying it,” he said.
While the technology is still young, perhaps the best reason to not block ChatGPT is because your partners and customers are – or will be – asking for it. ‘We are starting to see some purposeful applications for it. While it’s still very hit or miss, we’re seeing asks from third parties and vendors and financial services [customers].”
Another reason to adopt ChatGPT is because CEOs are asking for it. According to Gartner, generative AI tops the list of business leaders’ priorities for 2023. In a recent survey by the research firm, 400 CEOs and senior executives listed AI is the technology that business leaders believe will most significantly impact their industry over the next three years.
So should you block ChatGPT? Your call. But regardless of your decision, you can count on it finding a way into your organization anyway.
Comments