AI: Trust but Verify

Alec Crawford

We interview leaders in the AI and finance space to talk about how they are using AI, what to trust, and what to verify. AI risk management and compliance are becoming way more important as AI does more complex tasks. Learn how to do it correctly on the show from experts!

  1. 23h ago

    When AI Goes Wrong in Banking: Trust and a Kill Switch, with Gagan Singh

    In the AI: Trust but Verify podcast, our host, Alec Crawford (@alec06830), Founder and CEO of Verapath (https://www.verapath.com), interviews guests about how they are using AI in business, where you can trust AI, and where you need to put up guard rails. About Our Guest This episode's guest is Gagan Singh, Head of Product and Strategy for Enterprise AI at one of the five largest banks in the U.S., who joined banking after years building and scaling products at big tech companies, including Google. Gagan has worked on AI since 2016, from early statistical and rule-based models to voice interfaces in the early days of Alexa, and today leads AI architecture at enterprise scale in a regulated industry. He and Alec discuss where banks are getting real ROI from agentic AI, how to make decades-old systems AI-ready, and why kill switches, traceability and humans in the loop are what will earn AI the trust it needs to scale. They also cover open-source versus frontier models, AI ethics after deployment, and Gagan's advice for tech professionals moving into banking. Top 5 Themes AI takes on back-office work and first-pass fraud review. Banks are getting the most value by automating middle- and back-office operations that already run on well-defined handbooks, such as tier-one review of potential fraud. AI can follow those processes faster and often more accurately, while people handle escalations and decisions.Making decades-old bank systems AI-ready. AI is only as good as the data and tools it can reach. Gagan breaks large legacy systems into smaller pieces, modernizes them, and builds a central data layer that AI can rely on, with different views for each line of business.The kill switch: governance in a regulated bank. AI use cases pass through cyber risk, model risk, first- and second-line risk and a risk committee that sets how much autonomy each one gets. Every pipeline needs points where a person can stop an outcome that can't be traced back to how the decision was made.Three layers of trustworthy AI. Traceability that satisfies risk and cyber stakeholders, clear rules and data definitions that keep models in bounds, and a human in the loop. Tool gates across the pipeline let teams stop a result the moment it drifts, rather than after it is finished.Open source vs. frontier models: competition is good for banks. The gap between open-source and frontier models has narrowed sharply. Simpler tasks can run on a cheaper open model, like Llama, inside the bank's own data center with extra guardrails, saving frontier models and their higher token costs for harder work. Resources Here are a few of the companies, products and resources mentioned during the episode: Verapath: Secure, private AI for banks and wealth managers. https://www.verapath.comClaude Cowork: The Anthropic tool Gagan cites for automating enterprise work such as redlining legal documents. https://claude.com/product/coworkGemini Live: Google's voice conversation mode for Gemini, which Gagan uses daily. https://gemini.google/overview/gemini-live/ChatGPT: The OpenAI chatbot that kicked off the current wave of AI adoption. https://chatgpt.comLlama: Meta's open-source model family, Gagan's example of a model a bank can run in its own data center. https://www.llama.comOpenClaw: The open-source, self-hosted AI agent discussed as a consumer example of autonomous agents. https://github.com/openclaw/openclawAll-In Podcast: One of Gagan's go-to sources for AI and tech commentary. https://allin.com Copyright (c) 2026 Artificial Intelligence Risk, Inc. All Rights Reserved

  2. Sep 29

    Deepfakes, Voice Clones and Forged IDs: Fighting AI-Powered Fraud, with Rachel Tobac

    In the AI: Trust but Verify podcast, our host, Alec Crawford (@alec06830), Founder and CEO of Verapath (https://www.verapath.com), interviews guests about how they are using AI in business, where you can trust AI, and where you need to put up guard rails. About Our Guest This episode's guest is Rachel Tobac, CEO of SocialProof Security and one of the best-known ethical hackers in the world. Rachel got her start hacking a real company live over the phone from a glass booth at DEF CON, and today enterprises, banks, government agencies and the military hire her to break in before criminals do. She and Alec dig into how AI is powering a new wave of fraud, from cloned voices and spoofed caller IDs to beating a large bank's deepfake detection with an iPad. They also cover the practical side: how bankers and advisors can safely use AI day to day, the governance mistakes that leak salaries and secrets, and why AI will create more cybersecurity jobs, not fewer. Top 5 Themes AI meeting prep for wealth advisors. An advisor asks the firm's approved AI assistant for a client summary before a quarterly review: portfolio changes, recent notes, open action items and life events to raise. An hour of prep becomes minutes, the assistant sees only that advisor's clients, and the advisor checks the summary before the meeting.AI reviews the loan file; a human makes the call. A community bank credit officer runs an application through an AI tool that flags missing documents, mismatched numbers and policy gaps. The officer goes back to the borrower for what's missing instead of taking shortcuts, and a person still makes the credit decision.Fraudsters call the help desk, and they sound just like you. Attackers skip email and phone the help desk or an executive's assistant, often with a cloned voice and a spoofed number. Date of birth, address and passcodes are easy to find, so verify identity through a separate channel, such as a callback or a push notification.AI governance and guardrails. Employees use AI tools the company never approved, and poorly governed AI can surface salaries or evidence of office romances. Limit what AI can see, red-team it before employees do, and add guardrails like "don't create fake IDs."AI will create more cybersecurity jobs, not fewer. AI is good at finding bugs when its access is limited. Rachel expects a flood of new vulnerabilities that people will need to review and fix. Resources Here are a few of the companies, organizations and resources mentioned during the episode: SocialProof Security: Rachel Tobac's social engineering testing and security awareness company. socialproofsecurity.comVerapath: Secure, private AI for banks and wealth managers. verapath.comDEF CON: The hacker conference where Rachel competed in the Social Engineering Capture the Flag. defcon.orgCNN: "We asked a hacker to try and steal a CNN tech reporter's data": Rachel's DEF CON hack of Donie O'Sullivan. cnn.comCISA advisory on Scattered Spider: The help-desk social engineering playbook Rachel describes. cisa.govInfluence by Robert Cialdini: The book behind the principles of persuasion scammers exploit. influenceatwork.comMicrosoft 365 Copilot: The AI assistant in Alec's data governance story. microsoft.comWells Fargo sales practices settlement: The fake-accounts scandal Alec references. justice.gov Copyright (c) 2026 Artificial Intelligence Risk, Inc. All Rights Reserved

  3. Sep 22

    Vibe Coding, Real Consequences: The Rise of the AI Architect, with Ran Aroussi

    In the AI: Trust but Verify podcast, our host, Alec Crawford (@alec06830), Founder and CEO of Verapath (https://www.verapath.com), interviews guests about how they are using AI in business, where you can trust AI, and where you need to put up guard rails. About Our GuestThis episode's guest is Ran Aroussi, a self-taught engineer who started coding at 13 and now leads MUXI, an open-source AI application server for deploying "agentic formations" at enterprise scale. Ran is also the creator of the widely used yfinance Python library for algorithmic trading, and the author of Production-Grade Agentic AI, a free book on building secure, production-ready agent systems. Based in London, Ran also runs a software development agency and writes regularly about the future of AI agents, memory systems, and software governance. 5 Big Takeaways"Vibe coding" is splitting engineers into two very different breeds. Ran sees one group (non-technical people who prompt an AI to build an app) as a dead end for production software, and a second group — the "architect," a hybrid of product manager, project manager, and senior engineer — as the role that will dominate going forward.AI is a force multiplier, not an equalizer. A non-technical builder gets more done with AI than without it, but a senior engineer using AI well pulls even further ahead — meaning the skill gap between strong and weak builders widens rather than shrinks.Offloading your mental model of the code has a real cost. Ran compares it to no longer remembering phone numbers once your phone stores them: if you hand all the reasoning to AI, you lose the ability to debug, maintain, or explain the system yourself.MUXI treats "deploying an agent" the way Docker treats deploying an app. Instead of hand-coding servers, interfaces, and orchestration for every agent project, MUXI lets you define agents in YAML and deploy a full multi-agent "formation" with built-in enterprise security, observability, and role-based access control.Memory is the unsolved problem behind good AI agents. Ran's approach layers interaction memory, session context, summarized "distilled" memory, a knowledge graph, and an opt-in ingestion pipeline (email, Slack, health data) — because an agent that doesn't know you well is fundamentally limited in what it can do for you. MentionedMUXI — open-source AI application server (GitHub)Production-Grade Agentic AI (free book)yfinance — Ran's open-source finance libraryRan Aroussi's websiteBrilliant Labs — open-source AI smart glassesProject Hail Mary by Andy Weir

  4. Sep 8

    AI Is Accelerating: How You Can Keep Up, with Frank Fitzgerald, Founder & CTO of Verapath

    In the AI: Trust but Verify podcast, our host, Alec Crawford (@alec06830), Founder and CEO of Verapath (https://www.verapath.com), interviews guests about how they are using AI in business, where you can trust AI, and where you need to put up guard rails. For the 100th episode, Alec is joined by Frank Fitzgerald, the other Founder and CTO of Verapath, for a wide-ranging conversation about the rapidly changing AI landscape. They explore the rise of autonomous agents, emerging cybersecurity risks, AI-powered software development, and why businesses can no longer afford to simply block AI. Frank also shares how Verapath is using secure enterprise AI to automate complex financial-services workflows while keeping humans firmly in control. AI Is Moving Faster Than Organizations Can Adapt — Models, tools, and development practices are advancing so quickly that even experienced technologists can fall behind after only a few months. Keeping pace with AI is becoming a competitive necessity.Autonomous Agents Need Strong Security and Control — Digital workers and AI agents introduce new risks around permissions, agent-to-agent communication, sensitive data, and unintended actions. Organizations need tight access controls, data segmentation, guardrails, and visibility into what agents are actually doing.Secure AI Adoption Beats Blocking AI — Employees increasingly expect to use AI, and simply prohibiting it can push them toward personal devices and unsanctioned tools. The better strategy is to provide secure, governed AI along with training on what is—and isn't—safe.AI Is Transforming Software Development — Developers are shifting from primarily writing code to directing AI, reviewing its output, understanding architecture, testing, and identifying what the AI missed. Deep technical judgment remains critical even as AI does more of the actual coding.Enterprise AI Is Moving From Productivity to Process Automation — The biggest opportunity goes beyond summarizing documents or writing emails. AI can redesign complex workflows such as commercial loan closing, potentially automating large portions of hundreds of steps while keeping humans in the loop for critical decisions and approvals. Copyright (c) 2026 Artificial Intelligence Risk, Inc. All Rights Reserved

  5. Jul 21

    AI Governance Begins with Transparency, with Jeremy Snyder

    In the AI: Trust but Verify podcast, our host, Alec Crawford (@alec06830), Founder and CEO of Verapath (https://www.verapath.com), interviews guests about how they are using AI in business, where you can trust AI, and where you need to put up guard rails. In this episode of AI: Trust but Verify, Alec Crawford sits down with Jeremy Snyder, co-founder and CEO of Firetale AI, to explore the rapidly evolving intersection of AI, cybersecurity, and enterprise governance. Jeremy traces his AI journey back to the early days of natural language processing, explains why most organizations already have "shadow AI" whether they realize it or not, and discusses the growing need for visibility into employee and AI agent activity. The conversation covers prompt injection attacks, AI security, open versus closed-source models, China's AI strategy, and why organizations must rethink vulnerability management as AI becomes embedded in critical business processes. Top 5 TakeawaysYou almost certainly have AI in your organization already. Even companies that believe they have banned AI often discover employees are using ChatGPT, Copilot, Gemini, or other public tools with sensitive business information.AI governance starts with visibility. Before organizations can manage AI risk, they need to know which models employees and AI agents are using, what data they're accessing, and whether their activity complies with company policies.The biggest AI security risks extend beyond prompt injection. Vulnerabilities increasingly exist in the surrounding cloud infrastructure, APIs, integrations, and AI marketplaces—not just inside the language models themselves.The next challenge is managing AI agents, not just AI users. As enterprises deploy autonomous AI agents to execute business processes, organizations will need continuous monitoring, telemetry, and governance to ensure those agents stay on task and operate safely.AI is becoming a strategic national security issue. The competition between the U.S. and China is driving rapid innovation, but organizations cannot ignore cybersecurity, patch management, and governance as AI becomes critical infrastructure across financial services and other regulated industries. ResourcesHere are a few of the companies, platforms, and frameworks mentioned during the episode that listeners may find helpful: Firetale AI – AI security and observability platform focused on visibility into employee AI usage and AI agents. https://firetale.aiCyber Risk Institute (CRI) AI Risk Management Framework – AI governance framework developed for financial institutions. https://cyberriskinstitute.orgNIST AI Risk Management Framework (AI RMF) – Widely adopted framework for managing AI risk. https://www.nist.gov/itl/ai-risk-management-frameworkNIST SP 800-53 – Security and privacy controls for information systems used across government and regulated industries. https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/finalISO/IEC 42001 – International standard for AI management systems. https://www.iso.org/standard/81230.html

  6. Jul 7

    Trust, Verify, Repeat: The Future of AI Governance with David Hardoon

    In the AI: Trust but Verify podcast, our host, Alec Crawford (@alec06830), Founder and CEO of Verapath (https://www.verapath.com), interviews guests about how they are using AI in business, where you can trust AI, and where you need to put up guard rails. In this episode of AI: Trust but Verify, Alec Crawford speaks with David Hardoon, former Global Head of AI at Standard Chartered Bank and the first Chief Data Officer of the Monetary Authority of Singapore. With more than two decades of experience spanning AI research, financial services, regulation, and enterprise transformation, David shares practical insights on what it takes to operationalize AI at scale. The conversation explores how AI is reshaping banking, cybersecurity, and regulation, why governance should accelerate rather than hinder innovation, and why organizations must move from static controls to continuous learning and verification as AI capabilities rapidly evolve. TakeawaysGovernance enables innovation. Principle-based, risk-based AI governance creates trust and accelerates adoption rather than slowing it down.Trust AI—but continuously verify it. AI systems should be monitored and validated continuously as models, risks, and business environments change.Banks need a new operating model. The era of "deploy and forget" is over; AI requires continuous adaptation, faster cybersecurity responses, and ongoing process improvement.AI is transforming cybersecurity. Frontier models are dramatically increasing both attackers' capabilities and defenders' tools, making resilience and rapid response more important than ever.The greatest value of AI is augmenting people. Beyond automation, AI empowers individuals and organizations to communicate better, solve harder problems, and unlock entirely new ways of working. Resources David Hardoon – https://www.davidroyhardoon.com/David Hardoon on LinkedIn – https://www.linkedin.com/in/davidhardoon/The AI Failure Handbook: The Ultimate Guide to Screwing Up Your AI Transformation (David Hardoon) – https://www.amazon.com/s?k=The+AI+Failure+Handbook+David+HardoonStandard Chartered – https://www.sc.com/Monetary Authority of Singapore (MAS) – FEAT Principles for Fairness, Ethics, Accountability and Transparency in AI – https://www.mas.gov.sg/

  7. Jun 23

    AI Guardrails > AI Models for Regulated Industries

    In the AI: Trust but Verify podcast, our host, Alec Crawford (@alec06830), Founder and CEO of Verapath (https://www.verapath.com), interviews guests about how they are using AI in business, where you can trust AI, and where you need to put up guard rails. In this episode of AI: Trust but Verify, Alec Crawford sits down with Omid Pakseresht, CEO of Goodfolio (renamed Sepanta), to discuss what it takes to build trustworthy AI systems in a world where organizations are rapidly adopting AI. The conversation explores why accuracy alone is not enough, the importance of governance and guardrails, and how AI often exposes weaknesses in existing business processes, data quality, and organizational controls. Alec and Omid also discuss AI's growing role in cybersecurity, the challenge of managing model costs, the future of AGI, and whether AI's greatest value will come from efficiency gains or entirely new opportunities for growth. While both acknowledge the risks associated with increasingly powerful AI systems, they remain optimistic that organizations can use AI responsibly if they focus on trust, verification, and human judgment. Top 3 TakeawaysDon't trust AI with high-impact decisions without guardrails. In areas like finance and healthcare, AI should support human decision-making, not replace it.Accuracy is less important than system design. Governance, controls, testing, and verification processes matter more than simply choosing the best model.AI's biggest opportunity may be growth, not cost reduction. The most transformative use cases will likely come from creating new capabilities and business models rather than simply making existing processes more efficient. MentionedGarry Kasparov Jimmy Stewart Elon Musk Books Risk Management in the AI Era (forthcoming) by Alec Crawford

  8. Jun 9

    Dominick Romano: Watch Out for Foreign Influence in Our AI

    In the AI: Trust but Verify podcast, our host, Alec Crawford (@alec06830), Founder and CEO of Verapath (www.verapath.com), interviews guests about how they are using AI in business, where you can trust AI, and where you need to put up guard rails. Podcast production and sound engineering by Troutman Street Audio. You can find them on LinkedIn. AI: Trust but Verify — with Dominick RomanoAbout the GuestDominick “Dom” Romano is the founder and CEO of Drainpipe.io, an AI company focused on making AI systems trustworthy enough for regulated, high-stakes environments. Dom’s background spans video game development, casino gaming, advertising, real-time routing for hazardous payloads, mainframe engineering for IBM z/OS and banking systems, real-time transactions, and observability. Today, Drainpipe.io works with major manufacturers in Germany across pharmaceuticals, automotive, and chemical manufacturing, helping them deploy AI systems where the inputs and outputs must be verifiable—especially when AI touches critical regulatory data such as pharmaceutical dossiers submitted to health authorities. Top 5 TakeawaysAI adoption in regulated industries requires trust, not just capability. Dom emphasizes that when AI touches critical workflows—especially in pharmaceuticals, compliance, or regulatory submissions—organizations need confidence that both the data going in and the AI-generated output are legitimate and trustworthy.AI can scale mistakes, bias, and discrimination. The conversation highlights how AI systems used in decisions such as lending or hiring can create large-scale harm if bias or unlawful discrimination goes undetected—particularly when companies cannot prove the model is not using impermissible factors.Cybersecurity has to come before “cool” AI features. Dom and Alec discuss how rapidly adopted AI tools can create serious security risks when they go viral without proper cybersecurity foundations. The OpenClaw example is used as a warning about software that provides value but fails to account for security from the start.AI is becoming a geopolitical and cultural force. Dom raises concerns about “digital colonialism,” where countries in the Global South may become increasingly shaped by Western AI models that do not represent their own cultures, languages, or values.The near-term AI risks may be more urgent than distant sci-fi scenarios. While existential risk is discussed, Dom argues that immediate threats—deepfakes, multimodal AI on devices, AI in armed conflict, and rapidly expanding cybersecurity vulnerabilities—deserve serious attention right now. People and Organizations MentionedDominick “Dom” Romano — Founder & CEO, Drainpipe.ioWebsite: https://drainpipe.ioLinkedIn: linkedin.com/in/domromanoX: https://x.com/dromanocpm Dom specifically points listeners to LinkedIn, X under the handle @drobmanocpm, andAlec Crawford — Founder & CEO, Verapath; host of the conversation linkedin.com/in/aleccrawfordVerapath — Secure AI platform for financial institutions https://verapath.comFull Sail University — Dom’s educational background in video game developmenthttps://www.fullsail.eduIBM z/OS — Mainframe platform referenced in Dom’s backgroundhttps://www.ibm.com/products/zosEU AI Act — European AI regulation discussed in the episode https://artificialintelligenceact.euJP Morgan / JPMorgan Chase — Mentioned in the discussion of AI, attrition, and jobshttps://www.jpmorganchase.comAnthropic — Mentioned in the discussion of AI existential risk https://www.anthropic.comRay Kurzweil — Mentioned as one of the people concerned about AI risk https://www.kurzweilai.netElon Musk — Mentioned in the discussion of AI risk https://x.com/elonmuskMarcus Hutter — AI superintelligence researcher mentioned by Alec https://www.hutter1.netDoraemon — Referenced as an example of Japan’s more positive cultural association with AIhttps://dora-world.comOpenClaw — Referenced as an example of a viral software/AI-adjacent tool with serious cybersecurity concernsMythos — Referenced in the discussion of emerging cybersecurity threats and online infrastructure risk

4.8
out of 5
16 Ratings

About

We interview leaders in the AI and finance space to talk about how they are using AI, what to trust, and what to verify. AI risk management and compliance are becoming way more important as AI does more complex tasks. Learn how to do it correctly on the show from experts!

You Might Also Like