The Integrity Gap

What We're Seeing: AI Red Teams and Sneaky Sleuths

Recent examples from integrity work, from insider trading signals to AI red-teaming and risk communication.

The Integrity GapWhat We're Seeing: AI Red Teams and Sneaky Sleuths

Three things we’re seeing

  1. Geopolitical insider trading. In the 24 hours leading up to Israel’s recent strikes on Iran, a single user of the online betting service Polymarket bet around $20,000 that the attack was coming. When it did, that user, who had only set up an account the day before, made a profit of $134,000, then promptly closed the account. Not all of us will be privy to major governmental decisions, but there are indicators. For example, in the States during the same period, I heard some folks were monitoring the uptick in food deliveries to the Pentagon after hours, and the downturn in bar activity around a couple of popular haunts for Pentagon staff. For those of us trying to prevent insider threats within our own four walls, what information beyond obvious things like earnings reports, regulatory decisions, or M&A could affect value and performance? How might it be used for profit?
  2. AI red teaming. Beyond the obvious howlers, our newest team member, a fractional head of AI, has been giving me an AI masterclass. We are building models and agents using neural networks rather than simply plugging into large language models, and teaching the AI using reams of internal knowledge and experience. To do this well requires a lot of stress-testing. But we all have limits in terms of our own red-team thinking. Enter synths: personas we create in painstaking detail, based on real people, to view data and analyse it differently. When combined, they give us a sharper perspective. For example, much integrity-risk knowledge comes from the goodies: associations, fraud fighters, investigators, and regulators. What about the baddies? By training synths using material from criminal profiling, we are getting sobering results and identifying vulnerabilities very quickly.
  3. Less is more. A venture capital firm investing across five sectors set me the challenge of condensing the key risk considerations for each industry into one-page infographics. Why? No one reads policies, especially not three-person startup leadership teams. The VC firm wanted to communicate and educate in record time. It was one of the most challenging assignments this year, but the feedback from a hard-to-please CEO was effusive. Once again, less is more.

Case Study: Risk appetite’s deadly diet

A large development finance institution focused on Southern Africa asked us to look at their risk framework. The risk appetite statement is a good place to start, as it tells me what the Board cares about (and, therefore, will fund). Fraud, corruption, and money laundering were all absent. Why? Because no sane and publicly accountable organisation would publish that it accepts “a bit of corruption.” Risk appetite statements will quantify other things (supply chain disruption to health and safety incidents), but for “strict legislation” (i.e., all bribes are illegal), we box ourselves into the fallacy and fantasy that benighted “zero tolerance” is realistic.

The result: what doesn’t get measured doesn’t get managed. There are few checks on some of the most significant risks they face.

The lesson: pretending you don’t eat things will not lead to a healthy (corporate) body.

More Ethics Insight writing

Is it worth a conversation?

Tell us what you are trying to decide. We will listen, ask a few questions and tell you whether we can help.

Start a conversation