
Compliance in the age of surveillance.
Dave Bittner: Hello everyone and welcome to "Caveat", N2K CyberWire's privacy surveillance law and policy podcast. I'm Dave Bittner, and joining me is my co-host Ben Yelin from the University of Maryland Center for Cyber Health and Hazard Strategies. Hey there, Ben.
Ben Yelin: Hello, Dave.
Dave Bittner: On today's show, Ben has the story of Immigration and Customs Enforcement and their extensive use of modern surveillance tools. I've got the Supreme Court's taking of a case involving Facebook tracking pixels and video store rentals. And later in the show, my conversation with Matt Hillary, Chief Information Security Officer at Drata. We're discussing how AI is reshaping the compliance landscape and what it takes to build trust at AI speed. While this show covers legal topics and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. [ Music ] All right, Ben, it's been a busy week, but I feel as though there's been one topic that's been dominating the news lately, and that's all the goings on with ICE. And you have a story related to that this week.
Ben Yelin: Yeah, so I think all of our eyes have been on the city of Minneapolis. As you know, there's been a surge of ICE and Customs and Border Patrol agents into that city. It's gotten controversial. There are raids that are going on. I think it's been very disruptive to the community. You've had these high-profile incidents of just terrible events, including homicides committed on the part of ICE agents. So, it's just something that's become very controversial. But of course, for our purposes, there is always a surveillance angle, right? Despite everything else that's going on. So, my article comes from the Electronic Frontier Foundation. And they cover just sort of the vast apparatus of surveillance tools that ICE has developed, largely over the past year. So, ICE has had a lot of surveillance capabilities going back to the beginning of its existence in the early 2000s. A lot of it was beefed up in the Obama era. They did a lot of interior immigration enforcement. So, this is not just a purely partisan thing. But the funding levels are stratospheric now compared to where they used to be. As part of last year's One Big Beautiful Bill, Congress appropriated something like $50 billion additional dollars to ICE for internal immigration enforcement. That's a lot of money. To give you some context, that is more money than the entire Israeli Defense apparatus spends.
Dave Bittner: Wow.
Ben Yelin: It's pretty astounding. And one of the things they are using that funding for, besides hiring many additional agents, is different types of surveillance. First question is, like, why should we care about this? Aren't they just surveilling undocumented immigrants? And I think that's a common and understandable view. If you set a dragnet as far as they've set it, it ends up almost by definition encapsulating a lot of communications of US persons. And we'll talk about the different types of surveillance that they're doing, but EFF estimates that they've, ICE itself has scanned driver's license photos of one out of every three adults in the United States, and that they have the capability of accessing three out of four adults in terms of their license plate data. They have tracked vehicle movements in cities where three out of every four Americans live, and they could locate approximately three out of every four adults in this country simply by surveying our utility records, which is just, like, not something you would think of as a tool of electronic surveillance that's going to be widely used.
Dave Bittner: Yeah.
Ben Yelin: So I guess I can go through kind of the full menu of surveillance tools they're using and then we can kind of talk about the broader implications.
Dave Bittner: Well, before we do, I mean, it's a lot of stats. And I guess my first question is, Are they acknowledging any requirement of a warrant for any of these accesses? Like, if they're accessing utility records, do they need a warrant?
Ben Yelin: They generally do not. So, people who are outside of the United States and are undocumented, under Supreme Court precedent you do not need a warrant to conduct that kind of surveillance. Obviously this is interior enforcement. This is happening within the United States. Undocumented immigrants themselves do have Fourth Amendment rights, although it's kind of circumstance dependent. And obviously US persons have Fourth Amendment rights. The summary basically is that a lot of the data they are just purchasing. So, it's not the case that they're going and collecting individual records from third-party vendors. And in that case, you'd think they would need something like a judicial warrant. Oftentimes they're just paying these big companies who have already put together these types of databases. And then when they search these databases after they've been acquired through private means, there is no need for a warrant or even any judicial supervision. In most circumstances. There are exceptions, but generally/ they're just purchasing platforms built by big tech companies, and it's the platforms themselves who have collected this data. And so it's kind of largely outside the purview of the judicial system until it gets to the point where there is a criminal prosecution of a US person. Then maybe you could challenge it in court. You know, the thing is, there are very few criminal cases that are going to come out of this against US persons, which means that, like, you're not going to have a lot of adversarial proceedings where somebody would have the opportunity to come up and say, Hey, like, what authority did you have to use all of these surveillance tools on a warrantless basis? Like, let's go through this. Let's go through discovery, etc., etc. I don't think that's really what's going on here. I think what's largely happening is this is behind the scenes. It's not being used to effectuate arrests. It's being used for a separate governmental purpose, which is interior immigration enforcement, deportation, etc. So that's a long-winded answer to your question that basically says this is not something that's really subject to our traditional Fourth Amendment process.
Dave Bittner: And just to clarify here, my understanding is that, for example, I'm looking around on the App Store because I need a flashlight app. And I download a flashlight app. And as part of the EULA, the flashlight app says, We're going to collect all this data about you, including, let's say, your location data.
Ben Yelin: Oh, yeah.
Dave Bittner: And then, like everybody, I don't read the EULA. I just need my flashlight.
Ben Yelin: I mean, you might. You, me, and Ben here might read the EULA, but most Americans are not nerds like you.
Dave Bittner: Yeah. So, you click through and now you've given them permission to collect and then ultimately sell your location data.
Ben Yelin: Right, it's all aggregated, yep, it's aggregated and sold.
Dave Bittner: Right, so the notion is because you granted them permission to do that, then when buying that information, the government does not need a warrant, nor do they need your permission because you've already granted that permission.
Ben Yelin: That is exactly right. So, yeah, I mean, even if there was a challenge at some type of criminal proceeding on this, that's what the government would argue, is that you don't actually have a reasonable expectation of privacy in this data. Because in a lot of it, you've agreed to that EULA. Now, that's only true in some of the circumstances here. When we're talking about certain types of social media monitoring and somebody has taken affirmative steps to make their posts private, and they've expressed that subjective expectation of privacy, it might get a little more complicated there. When we talk about --
Dave Bittner: What do you suppose if we, in other words, if I were standing in front of a judge, would a judge hold up the letter of the law with that EULA, or would a judge likely say, Come on, nobody --
Ben Yelin: Nobody reads these things. You know, it really depends on the perspective. Remember when we talked about that Orin Kerr article where he said that, like, we should not judge one's Fourth Amendment interest in a particular piece of evidence or data by whether there was an end-user license agreement, that that shouldn't have any relevance from a Fourth Amendment perspective. That is one scholar's view of it, and there are dissenting views, and actually judges, some judges have cited EULAs in stating that a person didn't have a reasonable expectation of privacy. If you ask me for my opinion, like, I don't think we should consider EULAs in that context just because I don't think people are meaningfully forfeiting their expectation of privacy because they're not reading the EULAs. These are, you know, extremely long documents full of technical jargon that most people don't understand, and you're just trying to open your flashlight app.
Dave Bittner: Right.
Ben Yelin: So, you know, maybe we'll eventually get to the point where people are more judicious and spend time actually reading these things, but it's just not something that happens right now.
Dave Bittner: Well, I mean, so what's the bigger problem here? You, let's talk about you, me, our families, our kids, our spouses. We're roaming around the country, minding our own business, and we're saying to ourselves, Well, ICE is doing what ICE is supposed to be doing, which is gathering information on people who may not be here legally. How does this affect me? Why should I care?
Ben Yelin: Well, let us count the ways. So they have facial recognition capability. They've purchased, and in many cases, simply scanned driver's license photos. And then there are mobile facial recognition apps, so they can point one of those apps at you, point their device at your face. And if you're caught up as part of a dragnet because your driver's license was in their relevant database, then they could recognize you simply for being on the street. You wouldn't even need to have your own device. And they could use that if you were part of some type of larger protest, for example, and they decided to arrest everybody who was part of the protest for impeding law enforcement. They could use facial recognition tools to, as evidence that you were at that protest. Social media monitoring, this is something where they're looking at people's online behavior. There is $300 million allocated in the ICE budget specifically for social media surveillance. ICE has hired 30 contractors to monitor platforms. So, if you're posting about, as a US person, about attending a protest, or even if it's something that's nonviolent, they could use this to intimidate people, to harass people. Or if you post something that they would interpret as interfering with their operation of internal immigration enforcement, they could use that against you. Now you could say, like, people just shouldn't use social media, which, sure. I wish I could abide by my own advice. Obviously you can make your posts private and that helps, but that does limit the reach of your posts, and I think that limits your ability to express yourself on these issues. They can do all different types of location tracking using license plate data. We talked about utility records, AI-assisted targeting and analysis platforms. One of those was developed by Palantir. It's a platform to identify, track, and deport suspected non-citizens, which, you know, me and you would sit here and say, Well, we're not suspected non-citizens, so, you know, why should we care? There are a lot of false positives. I think we've seen that in the news where people who are -- -
Dave Bittner: Well, and we've seen, what is it, ICE is saying that, one of their folks said on the record that they believe that their facial recognition software is superior to a printed document, to having your birth certificate on hand. Like, they trust the facial recognition software first.
Ben Yelin: Right.
Dave Bittner: Which, from our point of view, I'm speaking on your behalf, from our point of view, with all the stories we've covered, is bonkers, right?
Ben Yelin: It is absolutely bonkers.
Dave Bittner: Yeah, but here we are. And I guess what's, I think a lot of us struggle because we feel as though there should be backup from the government itself to protect us against these sorts of things. But we find ourselves in this place where, right now, ICE is labeling people domestic terrorists.
Ben Yelin: Right.
Dave Bittner: Willy nilly.
Ben Yelin: Right, and without any due process and sometimes applying that label to people just, you know, minutes after there's been some type of catastrophic event. So --
Dave Bittner: Or simply protesting, exercising their First Amendment rights, or videotaping officers. They're labeling them domestic terrorists, so that's the reality of where we are.
Ben Yelin: Right, not to mention there is a Supreme Court opinion, drafted, I guess the concurrence was drafted by Justice Kavanaugh, that talked about how somebody's nationality and language can be a pretext in internal immigration enforcement. So this will have a disparate impact on ethnic and racial minorities, obviously including those who are full citizens of the United States, like you and me. I think the emphasis point here is that this is not just, like, scaling up surveillance. This is building up an apparatus that has not existed in this context anywhere all over the world. I mean, it's truly a military-style surveillance network, as if we were going after Al-Qaeda, but we are using it to enforce immigration laws within US cities, US communities. And it's backed up by significant federal funding. So, this is just something that I think we're only starting to scratch the surface of how big of a deal this is going to be and how many lives it's going to impact. I think we've had these kind of smaller case studies where ICE has surged immigration enforcement in particular cities. It's been Minneapolis over the last month. And, you know, I have friends in Minneapolis, and it has really impacted their everyday lives. And there is sort of a sense of disunity and paranoia. And I think when this is scaled to go to other communities across the United States, I think everybody will start to feel the effects of this type of mass surveillance.
Dave Bittner: Yeah. So as we're recording this, there's talk that Democrats may try to hold up budgeting to push back against some of this stuff? Am I tracking that correct, that that's a possibility?
Ben Yelin: Yes. So as we're recording this at the end of this week, funding expires for about half of the government agencies in the absence of any new congressional funding authorization, and that includes the Department of Homeland Security, which includes ICE. So Democrats, especially after the incident that happened over the weekend, the homicide on the part of I believe it was Customs and Border Patrol agents in Minneapolis. There's been this outcry from Democratic lawmakers saying, We're not going to approve Homeland Security funding unless there are substantive significant changes. There's a problem there, which is that ICE, because funding for ICE was included in the One Big Beautiful Bill, that is mandatory spending. It's not subject to the discretionary appropriations process, which in English means ICE funding is on the books and approved through 2029, no matter what Congress does this week. Now, you could threaten to defund the rest of the Department of Homeland Security. Really, then you're only affecting things like FEMA, TSA, you know, and that's going to inconvenience people. So I don't think there's a great substantive political solution for the Democrats here. I think they're trying to extract demands from Republican senators and perhaps the administration. The president himself, I think, has really expressed willingness to walk back from the brink in terms of what's happened in Minneapolis. I think he does not like the optics on TV. He does not like the way some of his closest advisors have comported themselves in TV interviews. So, there might be some willingness kind of back off from the brink. I don't think he's going to agree to any Democratic demands for increased due process or warrants for surveillance or that type of thing.
Dave Bittner: But I guess the priority right now is getting an agreement to dial back the presence of these officers in Minneapolis. That's job one for the governor, right?
Ben Yelin: And I think that might end up being the demand from Democratic senators who do have the limited leverage here. So, you need 60 votes to advance appropriations legislation. Republicans have 53. You know, Rand Paul's not going to vote for it because he doesn't believe in bloated government funding bills. Fair enough. So that means you're going to need eight Democrats. I count one on my hand that's going to vote for this. So, you're going to have to win some type of concession, depending on how long Democrats are willing to hold out. And I think right now the demand is settling on some version of get out of Minneapolis, or at least end the surge that we've seen over the past several weeks.
Dave Bittner: Yeah, I don't know about you, Ben, but I just, I feel strongly about this whole idea that we are in this place where we have, you know, show me your papers, right? Prove your citizenship because you don't look a certain way. I just find that frightening and distasteful.
Ben Yelin: Yeah, yeah. It's a pretty dark place. It's something that I didn't think would happen in this country. And I think it's very abstract still for a lot of people. But it's very real for people who are living in Minneapolis who, even if it's not they themselves, it's their neighbors or it's kids who go to their children's schools where drop-off and pickup is delayed because ICE is conducting an operation at a public school, and it's disruptive to everyday life. And I think, you know, there was, people expressed in the 2024 election a preference for secure borders, and Trump ran on aggressive immigration enforcement and he won. And so I think there is a certain deference owed in that respect, but not to the degree that we're seeing. You know, I think really what people were angry about was the chaos of unchecked migration. Now we're replacing the chaos of unchecked migration with the chaos of ICE agents going into American cities. It's replacing chaos with chaos. And I think Trump himself recognizes the political backlash here. And I think it's incumbent on us to try and cover all the substantive implications of what's going on.
Dave Bittner: Yeah, for sure. All right, well, we will have a link to that story in the show notes. Again, working off of an article from the Electronic Frontier Foundation. Let's move on to my story this week. This comes from the folks over at The Record. And this is about the Supreme Court has agreed to take on a case about Facebook pixel tracking. But more important than that, Ben, more important than that, this has to do with the Video Privacy Protection Act.
Ben Yelin: Woo-hoo! Can we just say, you've been talking about the Video Privacy Protection Act.
Dave Bittner: Yes!
Ben Yelin: You've probably mentioned it at least 20 times on our show.
Dave Bittner: Yes, I feel vindicated.
Ben Yelin: Totally. For once, you might be the one tuning into oral arguments here.
Dave Bittner: That's right.
Ben Yelin: Because this has been a hobby horse of yours.
Dave Bittner: If they want to call me in as an expert witness, I'd be glad to do my civic duty. So, the Video Privacy Protection Act was a law that was enacted back in 1988, which, was that before you were born, Ben?
Ben Yelin: No, it was after. I'm old, just not that old.
Dave Bittner: So, in 1988, so --
Ben Yelin: I was 2, but just, we'll put that out there.
Dave Bittner: All right, all right. I was a teenager. And what happened was, Judge Robert Bork had his video rental history released to a newspaper. And he was in the midst of some confirmation hearings and ultimately he did not end up on the Supreme Court. But after this, I think folks in Congress said, Wait a minute, if they can do that to him, they can do that to us.
Ben Yelin: I've got to go look and see what movies I've been renting recently. Yeah.
Dave Bittner: Right. Right. Exactly. So, and so we got this Video Privacy Protection Act, which basically says that a place like a video rental store, which of course really doesn't exist anymore, can't share your rental history with anybody just for the sake of sharing it. Fast forward to today, and we have Facebook tracking pixels, which are put on websites to monitor the things that you're doing and report that stuff back to Facebook. So, it's monitoring where you go, what you click on, what you're watching, things like that.
Ben Yelin: As I go try and sever my Facebook account from all the things I do on the internet. Excuse me, Dave.
Dave Bittner: Yeah [laughter]. So in this case, the plaintiff is arguing that a online sports website was tracking the videos that he watched while he was logged into Facebook. Facebook used that information for targeted advertising. So the US Court of Appeals for the Sixth Circuit sided with the website, which is owned by Paramount, they sided with Paramount in 2023, saying that the plaintiff here didn't meet the definition of a consumer under the Video Privacy Protection Act because he was not a subscriber receiving audio-visual content. And the Supreme Court has agreed to take this on, and their decision's going to be how broadly can courts apply the video privacy law in today's age. What do you make of this, Ben?
Ben Yelin: It's so interesting because while there are a lot of different angles, substantive angles to this case, I think this is a statutory interpretation case, which is what makes it so interesting to me. So ultimately what it comes down to is when you subscribe to a website's general digital content, like sports news, recruiting information, etc., or their written content, does that make somebody a subscriber of audio-visual materials? In other words, does the subscription have to be tied only to video content, which is what the literal words in the statute say, or can it be applied more broadly to things people are perusing on the internet that might not meet that definition of video? And it really goes back to, like, how judges and justices do this type of statutory interpretation. Like, do you try to understand the term as it existed at the time the statute was drafted in 1998? Or should you interpret it in light of changes to modern technology? I think the person who believed in kind of the living constitution, or somebody who believed that statutes set the groundwork and that we should apply them broadly in similar circumstances, they would say, as the dissenting judge in the Sixth Circuit did, that all these terms should be interpreted more broadly. That if somebody pays to access a website that includes some video content, that should make the user a consumer under the VPPA. The majority justices take a more literal approach, and I think this is kind of an originalist conservative approach, that the subscription itself has to relate only to video, to audio-visual material. And that's kind of limiting the reach of the statute to cover only what was understood at the time to be video. So in that sense, it's really interesting to me.
Dave Bittner: What would happen if the Supreme Court ruled in favor of the plaintiff here and said that this sort of thing is under the Video Privacy Protection Act? What would that mean to companies like Facebook and their tracking pixels?
Ben Yelin: I mean, they might be concerned about liability, and I think it would force them to change their practices, whether that's a change in the EULA, where a person maybe is prompted to expressly agree to sharing those pixels, or if it's curtailing some of the services that connect Facebook with other websites, other digital subscriptions. I think that's something that they'd have to consider, because otherwise they could be sued under the statute by anybody who is a consumer of that content. Now, when we were talking about video stores in 1988, like, there was a limited universe. There were only so many customers.
Dave Bittner: Right.
Ben Yelin: You're talking about Facebook, like, we could get a class action lawsuit. Like, we could make quite a dent into this company if they continued these types of practices. So, there's a reason that Facebook is going to fight, or I guess it's Paramount Global who's taking the data from Facebook. There's a reason that they're going to fight this. They don't want any type of online platform to be subject to that level of legal liability. They want to make sure that the statute is construed narrowly for that purpose.
Dave Bittner: When the Supreme Court generally looks at something like this, to what degree are they looking at it clinically of, you know, this is what the law says, and to what degree are they looking at it with an eye toward the greater societal ramifications of how they rule?
Ben Yelin: You know, I think part of the trust we have in the legal system is that they are going to use the language of the law to make the decision. It's something that, I mean, you have to suspend your disbelief a little bit. These are human beings who have their own strong political opinions. But just as kind of a stylized example, there was a Supreme Court oral argument a couple of weeks ago on a couple of cases where a trans woman was participating in girls' sports. The argument I listened to was about an Ohio trans woman who had, you know, I don't really know the science of it, but had taken some type of puberty blocker that limited testosterone, so she was able, under the rule, to qualify for high school athletics or college athletics in Idaho, and then they passed a law to prohibit her from doing that. Anyway, what stood out to me at the Supreme Court oral argument is there was not a discussion on the substance of trans issues, which is what you see in a congressional hearing, or what you'd see kind of in the theater of public debate. They were talking about just, like, very technical legal doctrines. So, is this a case of sex-based discrimination, which is prohibited under our Constitution and our laws? When there is a case of sex discrimination, it's evaluated under a standard called intermediate scrutiny. And do the circumstances of this case satisfy that intermediate scrutiny test? And it's just striking to me that, like, I think we've taken a view that justices are just kind of partisans and rogues. And on my worst days, I believe that myself. But they really do try to find some justification in the language of the law and try to adhere to somewhat of a consistent judicial philosophy. And so I think, at least outwardly, they're going to be focusing on what the statute meant when it was enacted. Or, like, how do we go about statutory interpretation? Do we try and look at the definition of consumer under the statute as it was understood at the time? Or should we have a modernized definition that reflects the type of advanced technology that we're seeing here? I think it's going to be much more of that type of technical discussion where they're looking at dictionary definitions of consumer, or Black's Law dictionary definitions of consumer from 1988 to try and decipher, like, what that actually meant at the time.
Dave Bittner: Oh. Right. Right.
Ben Yelin: So maybe I'll be wrong. I just think, like, maybe out of a sense of shame, the Supreme Court justices want to portray to the public that they're not making these decisions on their own policy preferences, but on the details of the relevant statutes. And that's how I would expect this to be decided.
Dave Bittner: Okay. Well, stay tuned because we will revisit this one.
Ben Yelin: Oh, absolutely. Can't wait for the oral arguments for this one.
Dave Bittner: All right. Well, we will have a link to that story in the show notes. Tell you what, let's take a quick break to hear from our sponsors. We'll be right back after this message. [ Music ] And we are back. Ben, I recently had the pleasure of speaking with Matt Hillary. He is Chief Information Security Officer at Drata, and we're discussing how AI is reshaping the compliance landscape and what it takes to build trust at AI speed. Here's my conversation with Matt Hillary.
Matt Hillary: Looking in the last three years, I mean, even, like, the last five years where we have these GRC automation platforms that started and now have become fully fledged trust management platforms that we can utilize has already jump-started and accelerated a number of the things that we even hoped for 10, 15 years ago. Now with AI, I'm glad you started there. It's been fascinating to see how AI has just continued to propel our GRC team's capabilities forward. Like, for example, oh man, I'll get questionnaires, sometimes still hundreds of questions in those, and, you know, using an AI-capable questionnaire assistant capability has helped me, gosh, get up to, like, sometimes 75 to 80% accuracy on the first pass that AI is providing answers and populating those. And sometimes, like, 90-plus percent of the questions that are asked are being taken care of that, which is awesome. And so as a result, you know, questionnaires are now taking minutes instead of, oh man, counting up the questions and, you know, multiplying that by two to five minutes per question sometimes could be hours. And so that's one, but I have so many other examples, but it's just been fascinating to see this revelation, or evolution, over the last five years, and mostly, acutely, the last two to three.
Dave Bittner: Well, help me understand the time savings here. Because if you have to go and verify the response that the AI provides, which I think we all agree you do, you still yield significant time savings even with that verification layer?
Matt Hillary: Totally, totally agree. You are absolutely accurate in saying we still need to keep that human in the loop, and my team does exactly that. But I don't know if I talked about my role here at Drata, but I manage our security, IT, GRC, privacy, as well as a business apps team. And one of my favorite parts of this role is obviously spending time with incredible professionals like yourself that do this to kind of share experiences. But when I look at the time savings on the GRC team, you know, I'm a doer as well as a leader. And so I sit alongside my GRC team members and answering some of these. Like I mentioned the stats before, I'll get a questionnaire with 120 questions. And previously I would, you know, go question by question. Sometimes it would take anywhere between two to five minutes to answer. And that's so that I could just do it well, because I really want to make sure that customers are getting the answers they're looking for and kind of answering the questions they didn't ask and making sure they have that context. Again, it's all out of the essence and good faith efforts of building trust with those customers. And so, you know, multiply 120 questions by two to five minutes, and, you know, we've got a couple hours' worth of work there. Now with AI, one that's well populated with a strong knowledge base. And, you know, Dave, the garbage in, garbage out absolutely applies when it comes to the use of AI models. And so even the most capable models needs a good knowledge base to draw from. And so I spent time, you know, ahead of time, it ended up being a, what I would say an ounce of effort that has yielded a pound of result. Where, you know, we have, gosh, it would take that 120-question questionnaire and complete that within, you know, the first pass, sometimes within 5 to 10 minutes. I end up seeing just seconds taken to basically populate these questions. So, you know, you get that 120-question questionnaire. And this is actually my experience. A couple months ago, I got one of those. It was 5 o'clock. I was going to go up and help my spouse make dinner for our kiddos. And I was like, oh man, it's the end of quarter, end of month. We've got to get this done. So I got that 120-question questionnaire. And what it usually take me a couple hours and delay, you know, that customer asking for it, I was able to get that done, that first pass within five minutes. And then I think there was probably, you know, a good probably 10, 15 or so left over that I needed to go through and answer. They were largely related to AI and our model had not yet been updated to use some of our AI answers. So, that ended up saving that time. So it took me probably 5 to 10 minutes in addition. So we're talking 15 minutes to get this thing done. And then I was able to just make sure it's all good to go. There's capabilities where you can update the knowledge base with any questions that you had to manually answer. So, you continue to add good knowledge to your knowledge base. But, man, I got that thing back by, like, 5:20, 5:25, and I was able to jump upstairs and, you know, my spouse didn't even know the difference. Hey, like you're a little late or not. So that's a real-world example where we're able to still meet the needs of the business while still being able to live life and use our time wisely.
Dave Bittner: Well, help me understand how you can take advantage of those kinds of tools but still be in compliance in terms of not oversharing any company's or customer's information with an openly accessible AI model.
Matt Hillary: A hundred percent. I love this question because effectively what you're talking about here is data isolation. We don't want that data to spillage. So a couple of things that we have done, and when I talk about we, I talk about the GRC practitioner spaces, many of us will use, like, if you're using a public large language model on your own personal account, you know, you start having those concerns where their model is being trained with the information you're inputting and the reference source material. And that's an area where you want to stay away from. You definitely want to make sure you're using a provider where it has effectively turned off, you know, the retention of stuff that it has committed to not using anything you've inputted or referenced in their own training of the model so you don't get that resurfacing or spillage of data that may not be relevant here. So that's one. But the second one is using a provider that has made sure that you use tenant isolation when you create that vector database, that it is only putting in that database the elements that are specifically related to that customer, especially in a multitenant SAS environment like our own. And so we do that. We make sure that, again, that customer is only able to see data within their own instance, and the model is using data within the vector database that is honed into the guardrails, that kind of walled garden around their tenant. That's what's given us the confidence and demonstrable, like, ability to make sure that, Hey, these things really are isolated so that what is being surfaced is within the context of, you know, the question being asked. And so that's what we've done on our end to do that isolation. That's something we test, something we build for. It's built in by design. But that's an area where we want to make sure that we're not just using some random personal account, uploading all of your information and knowledge base and then saying, Hey, I have some questions here. And you're like, wait, you're starting to answer questions that aren't relevant here. And, wait, the memory and context window happens to have stuff from other customers? That would be really scary. So, you know, choosing a provider that has built that in is extremely important.
Dave Bittner: Well, as someone who is not in the compliance world on a daily basis, I can't imagine that there are many people in business who say to themselves, Oh, goody, I get to do compliance today. So, how do you, I know you all talk about this notion of continuous compliance versus, you know, an annual box checking exercise. Can you flesh that out for us? What's the difference and why does it matter?
Matt Hillary: Yeah, no, I, this is a good question because it highlights the essence of the GRC journey. And it's no different than the security journey, where many of us may feel like, hey, we seem to have this endless list of things we need to do. And we're never there. And I think that's the reality that as a CISO, I've had to learn, which is you can do everything but still have a percentage of things that are not yet complete. But from the GRC standpoint, you've got to start somewhere. And so just like on a security standpoint, you've got to start somewhere. And so with that, you know, many start at the very beginning with doing things as simple as having a list or checkbox of things to do that may seem checkbox-y in nature. But honestly, many of the things that are checkbox-y in the GRC space are still valuable to do. Many of them are around access control being appropriate. Many of them are around making sure changes are approved. But I think where the difference lies is many organizations will stop after all those boxes are checked and they don't progress and mature beyond that. And I think that's where we kind of have a bad rap when thinking about checkbox compliance. And so ultimately, organizations need to go beyond that. And I'm seeing that, especially when I talk to a number of my peers that are like, Matt, I no longer fear the auditor. Like, we've got that handled. What I fear are the true underlying risks, the things that we need to care about. I think that's the difference, is where an organization goes beyond just saying, Hey, here's a list of things that we need to do. All of them are good. All of them are things that we should do. But they need to go beyond by understanding the underlying risks that were used to create these controls in the first place. And then they need to be able to explain those risks and controls in simple terms so the internal team members can effectively understand the why behind it. And then it ends up maturing the organization. You ultimately become the great influencers with an organization to, like, expand on maturity and scalability and availability and, like, operational efficiency. And when compliance or GRC is done well, those are the natural outcomes. Sometimes you see it as, like, red tape that slows us down. The reality is, is when done right, I think it ends up really getting the machine into a very well-operating state. So I think it all comes back to just being extremely intentional about everything you're doing with security and GRC to really make that difference. I like this question again because it just, it talks about that desire to have a long -term trust between your organizations and that we really are on that journey of continuous improvement.
Dave Bittner: Are there any blind spots or specific challenges that you see in this modern world of compliance when dealing with things like shadow AI, accountability when AI systems make mistakes? Are there common errors that folks are making out there in your experience?
Matt Hillary: Yeah, a couple of blind spots come to mind. One is just using AI in ways that is slowing us down, which is kind of surprising. You're like, Man, every time I've used AI, it seems to have sped us up. But some folks are still using AI to generate what I'll call AI slop, where it ends up being stuff that ends up slowing down a number of team members having to read, you know, a Slack message that would have been a single, you know, direct message to a human, to being a long document full of stuff that's like, Now I need to use AI to summarize what you sent me. The same thing I think applies to the GRC space, where it's like, oh man, like, we've got to use AI intentionally. Some of the blind spots, you are right. You nailed it perfectly where you said shadow AI. In fact, I want to say in the last couple of weeks I've been losing sleep over this topic. There's so many different ways to use AI that we didn't even realize before. And those blind spots end up, you know, causing some anxiety around, you know, some of the things around bias, some of the things around, you know, the trust model that I have in these organizations that are providing these models and stacks. I think the reality is every AI security conference and conversation I've had with others is, in many ways, it's insecurable. There are these other ways that can be circumvented or jailbroken that have not yet been accounted for or may not be accounted for. And so there's a lot of known unknowns, and so those become quick blind spots. Some of the things that came to mind, I think is a recent quote that I came across. I think it's attributed to a guy named Jon Kabat-Zinn, where it's like, Hey, you can't stop these waves, but you can learn how to surf. And as security GRC professionals, we continue to see these waves of new technologies. They used to be cloud, and now we're at AI. And with those waves comes new waves around known and unknown risks. And so, you know, I definitely, we're not going to be able to propel our world to the future without adopting these technologies. But the reality is, is we've got to learn how to surf on those waves, you know, lurking beneath whatever may be. But the reality is that the same principles apply there, where it's like, okay, we've got to inventory and understand what we're using. We've got to understand what our people are using. Are they using the right things? I'm seeing some organizations adopt not only, you know, the typical acceptable use policy-level stuff, but also deploy technology to understand who's using what? Who signed up for what? Using some of our shadow IT capabilities to help with that, or even some are redirecting and effectively saying, hey, with some of these access capabilities to say, Hey, you're reaching out to an LLM. This is not the way the organization is defined. We're going to redirect you to the right one and we're going to redirect you to the right model, even in some cases. To really not sort of reinforce, but put in those nice guardrails to help make sure your people feel confident using AI in the way that it should be used. So that's one that came to mind. I'm happy to dig into any others.
Dave Bittner: Well, looking ahead, what do you think is going to separate the organizations that thrive in this environment from those who might find themselves falling behind?
Matt Hillary: Oh, I think that slider bar exists today, right? Those that are, that may fall behind are the ones that are kind of holding back, right? They have the very strong stance within their organization to say, No AI, right? And you're like, no, it's almost like saying, like, you can't use this technology until we feel okay with it. And I think there's a very harsh balance there that we have to do because every one of our organizations has a different risk appetite, right? I think of, you know, healthcare. I think of financial institutions like the government, you know, agencies where, you know, that kind of stance makes a little more sense, right? Because the risk appetite is so, so low in the sense that they want to make sure that we want to protect the sensitivity of data that we manage here. And so it kind of makes sense there. But also when it comes to those industries, those are traditionally the industries that are slow to adopt technology and they end up falling behind with, you know, their adoption of even cloud stuff. You know, 15, 20 years later after we've had this capability around and the costs associated with that, the feeling behind the inability to kind of scale their business in the way they'd hoped to. So, anyway, I call those out as examples, but I think the organizations that do fall behind are those that are really risk-averse to the point of inhibiting their growth. But those that are adopting it quickly and also in a really good and intentional way with awareness around, like, Hey, what are the risks? How do we mitigate those risks in a reasonable way? And kind of taking that risk, because it is a risk and we can't close all those out. But understanding there needs to be some level of appetite to adopt, to grow, and to use those. And so I think we're in that great, oh man, I would even call it, like, vibe selection. When you think of vibe coding, you're obviously using AI to generate code, but this vibe selection experience that we're in, where we're trying to identify, Hey, which one of these AI capabilities should we use within our organization? And so sometimes we have, like, three to five competing capabilities or providers now that are making it, you know, painful and saying how we have this sprawl of AI tools but I think the reality is we're trying to find which one or ones work for us so that we can propel into the future the way we want to. [ Music ]
Dave Bittner: Ben what do you think?
Ben Yelin: I think it's just we're in a new era, where there's this need for this continuous compliance, especially as the technology evolves and changes. And, you know, I don't think we've been at a place in the past where we've just had this accelerating capability, where within six months, the threat landscape completely changes and the use cases completely change. So, I thought it was a really interesting conversation.
Dave Bittner: Yeah, absolutely. All right. Well, again, our thanks to Matt Hillary from Drata for joining us. We do appreciate him taking the time. [ Music ] And that is "Caveat" brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to caveat@N2K.com. This episode is produced by Liz Stokes. Our executive producer is Jennifer Eiben. The show is mixed by Tre Hester. Peter Kilpe is our publisher. I'm Dave Bittner.
Ben Yelin: And I'm Ben Yelin.
Dave Bittner: Thanks for listening. [ Music ]

