Exclusive interview: Anekanta’s Pauline Norstrom – part 2

anekanta

 In this exclusive interview series, Anekanta‘s CEO, Pauline Norstrom, helps to demystify some of the issues around AI, and in this piece, discusses discusses adoption, implementation and trust. This is part two, of three.

Lots of companies in the security sector claim to offer AI-enhanced products or services, but what does this actually mean? Is there a uniform way of defining AI?

Pauline Norstrom: “For too long, the meaning of the term AI has been subject to interpretation, leading to market confusion. However, the globally accepted definition which originated with the OECD has been adopted almost verbatim across the regulatory landscape — from the Council of Europe’s AI treaty to the EU AI Act to UK government guidance and the international ISO standards. In the EU AI Act it reads:

“‘AI system’ means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments;

“The significance for a buyer is that “AI-enhanced” is not a marketing flourish; it has a legal meaning. If a system infers rather than simply following fixed rules, it may fall within scope of the Act — and the obligations that follow attach to how it is used, not to how it is described in a brochure. For an enterprise standardising technology across a large estate, that distinction determines which systems carry regulatory weight and which do not.

Have you seen any great case studies you can point to? And how far is this about companies making their own processes more efficient, rather than developing AI-enabled products and services that genuinely benefit their customers?

PN: “The two are not in opposition — done well, internal efficiency can produce a direct customer benefit. When AI processes volumes of information far beyond what a human team could review, and does so with consistent accuracy, the end customer gains earlier warning, fewer missed events and better-founded decisions. The condition is meaningful human oversight: appropriate human-in-the-loop review, supported by AI literacy training, so that automation bias does not allow AI-generated conclusions to pass through unchallenged. That safeguard is itself part of the customer benefit.

“So called AI-enabled products have been marketed for security applications for many years. The real intelligence, though, emerges at enterprise scale, where an organisation connects data sources that have historically resided in isolated legacy systems. This is where agentic AI becomes genuinely transformative: it can drive out inefficiency and inaccuracy in workflows that span multiple systems, improving both the speed and the accuracy of the information reaching human decision-makers.

“To capture that at scale, the sector must move on from a device-by-device mindset. Leveraging AI across an estate means embracing cloud and hybrid architecture and building the advanced AI skills needed to run it — the operational and safety gains are substantial, but they accrue to organisations willing to operate at infrastructure level rather than product level.”

Is part of trustworthy AI use ensuring that AI functionality really does benefit the customer? And if so, how can companies identify and assess the real-world benefits? Is this something Anekanta® can help them to do?

PN: “Yes, and it is central. An AI system that cannot be shown to reduce risk or improve an outcome is a cost and a liability, not an asset. The discipline is to define, before deployment, what benefit the system is expected to deliver and against what baseline — detection performance, decision quality, time to response, reduction in missed events — and then to demonstrate evidence of that benefit against real operating conditions across sites, populations and environments, rather than asserting it from a datasheet.

This is precisely where Anekanta® works. The firm helps enterprises evaluate AI use cases before investment, define what good looks like for their specific operation. Furthermore, through deep analysis of the system’s functionality and development origins, assess whether it is capable of delivering it, with the right risk, oversight and governance framework, such as ISO/IEC 42001, that keeps it delivering. The outcome is an organisation that can demonstrate the value of its AI to its board, its insurers and its customers — not merely claim it.”

How does one assess whether an AI system can be trusted?

PN: “Trust is not a property of the technology in the abstract; it is evidenced against a defined use, in a defined environment, for a defined population. Assessing it means asking a consistent set of contextual questions. What is the system’s intended purpose, and is it being used within it? What data was it built and tested on, and does that reflect the conditions it now operates in? How does it perform across different groups and edge cases, and how are errors detected and corrected? Where does the human sit in the decision, and do they have the authority and the information to overrule it? Is there a record that allows a decision to be reconstructed afterwards?

“At enterprise scale this cannot be answered system by system on an ad hoc basis. It requires a management framework — which is what ISO/IEC 42001 provides — so that trustworthiness is assured consistently across the whole estate rather than demonstrated occasionally for a single showcase deployment.”

Are there any companies in the security space implementing AI in a particularly advantageous or innovative way?

PN: “Anekanta® is independent, and that independence is what makes our assessments more valuable. The organisations doing this well are not the ones adding another analytic to a camera. They are the ones using generative AI and AI agents to communicate with previously disconnected systems — physical security, cyber, access control, HR and operational data — so that patterns invisible to any single system become visible. Agentic AI systems can orchestrate intelligence gathering and action across multiple sites, insider-risk signals that only emerge when several data sources are read together, threats that cross the physical and digital boundary.

“The innovation is architectural, not cosmetic. It lies in treating security as an enterprise-wide intelligence problem rather than a collection of sensors, and in building the data foundation and governance that lets AI operate across the whole picture safely. That is a capability large operators and their integrators are only beginning to develop, and it is where the real competitive advantage of the next few years will sit.”

Generative AI is moving from personal productivity tools to everyday infrastructure. What do organisations need to know about leveraging AI at scale?

PN: “The shift from a productivity tool used by an individual to infrastructure the whole organisation depends on changes everything about the level of rigour required. A tool that helps one analyst draft a report can be of low consequence. A system feeding decisions across a national or multinational security operation is critical infrastructure, and it has to be governed as such.

“Three things matter at that scale. Governance has to be designed in from the start, not retrofitted after deployment — which means knowing what AI systems are running, who is accountable for each system, and how each is controlled. The data foundation has to be sound, because AI systems operating across an estate are as trustworthy as the data feeding them. And the workforce has to be equipped, through AI literacy at every level from the board to the operational decision, so that people can exercise genuine oversight rather than deferring to the machine. Organisations that treat AI as infrastructure and govern it accordingly will capture the operational and commercial benefits at scale.”

To go back and read part one, click here

For more AI news, click here

Share this

Related News

In this exclusive piece, Tim Leehealey, Vice President of…

News

Over the past five to 10 years, the use…

News

Artificial intelligence is enabling 55% of reported cybercrimes across…

News

Scroll to Top