All Episodes

April 9, 2026 14 mins

In this episode of "Full Tech Ahead," Amanda Razani interviews Mery Zadeh, SVP of AI Governance and Risk Consulting at Lumenova AI. The conversation centers on the complexities of building AI governance teams and navigating the "three-language problem" where technical, regulatory, and business teams struggle to communicate. 

Zadeh advises companies to stop searching for "unicorn" candidates who possess all these skills and instead focus on cross-training and rotation programs. Furthermore, as AI evolves from Generative AI to Agentic AI (systems that take independent actions), she emphasizes the critical need to shift from annual audits to real-time, continuous monitoring. 

Ultimately, she notes that the most successful AI governance frameworks are practical ones that developers actually use, rather than theoretically perfect models.


Key Quotes

  • "We're turning AI risk to possibilities."
  • "We should stop looking for a Unicorn... start on career paths, start on education."
  • "You can't govern what you can't see."


Takeaways

  • Solve the "Three-Language Problem": Effective AI governance requires fluency in business, technology, and compliance. Instead of hunting for an impossible candidate who knows it all, organizations should implement rotation programs (e.g., auditors spending time with tech teams) to cross-train their current workforce.
  • Integrate Teams Across the AI Lifecycle: From the initial business intake and legal risk assessment to the developer build phase, cross-functional teams must collaborate continuously to ensure the AI system is technically sound, compliant, and fit for its intended use.
  • Shift to Continuous Monitoring: As the industry moves toward Agentic AI—where AI agents execute tasks like booking or canceling meetings—traditional annual audits are obsolete. Organizations must implement real-time monitoring and strict permission controls to catch and correct issues immediately. 
  • Prioritize Practical Governance: The most effective AI governance isn't a flawless, overly complex policy; it's a practical framework with clear controls and evaluations that developers understand, see value in, and actually follow.

Find Amanda Razani on LinkedIn.  https://www.linkedin.com/in/amanda-razani-990a7233/

Follow the FTA LinkedIn Page: https://www.linkedin.com/company/full-tech-ahead/

Visit the FTA website: https://fulltechahead.com/

Check out the Substack Channel: https://fulltechahead.substack.com/

Listen
Watch
Mark as Played
Transcript

Episode Transcript

Available transcripts are automatically generated. Complete accuracy is not guaranteed.
SPEAKER_01 (00:19):
Hello and welcome to Full Tech Ahead.
I am your host, Amanda Razzani,and I'm excited to have Mary
Zade here.
She is the Senior Vice Presidentof AI Governance and Risk
Assessment at or Risk Consultingrather at Luminova.ai.
How are you?
Hi, Amanda.

(00:40):
Nice to be here.
Happy to have you on the show.
Can you share a little bit abouta little bit about your
background and then what doesLuminova AI offer?

SPEAKER_00 (00:52):
Sure.
So I have a finance background.
I started with risk andcompliance.
I worked for KPMG for 10 years,was a director and head of risk
transformation in KPMG Norway.
And then started in Luminova asSVP of AI governance and risk
consulting.
So what we do is that we havethe unified AI governance, risk

(01:16):
and compliance platform.
We help organizations govern,monitor, and scale AI systems
safely.
So basically, we're turning AIrisk to possibilities.
I love that.
I love to say that.
So risk to possibilities,Amanda.

SPEAKER_01 (01:32):
Wonderful.
Well, I'd love to hear moreabout that.
And um, our topic today is aboutum all things AI.
And I'd love to hear more aboutbuilding AI governance teams and
from your experience, where aretheir issues with a lack of
skills and how can those beaddressed?

SPEAKER_00 (01:52):
It's a very interesting topic because uh,
you know, I love talking aboutAI governance, and I think it's
a very important topic to talkabout in 2026 because we see
that AI governance requires aunique blend of um technical,
regulatory, and businessfluency.
You know, it's you need peoplethat are able to speak these

(02:15):
languages fluently.
And the problem with that isthat we're not creating carrier
paths for these specialists.
We're just we're just lookingfor the unicorn that has all
these three um, you know,qualifications and um and skill
sets.
So I see it as a, you know, as Imentioned, a three language
problem because they are so thetechnical teams, um, they have

(02:38):
to understand regulation, whileyou know, compliance teams, they
have to understand the modelstructure, you know, data flows
and you know, the business,their perspective is like, what
is the risk tolerance?
What is the operational impact?
But they have to be able tocommunicate that to the
technical teams and to theregulatory teams in order to for

(03:00):
the teams to be able to functiontogether and work together.

SPEAKER_01 (03:04):
Well, so where you know communication is absolutely
key.
So, what tips do you have toimprove that communication
between departments soeveryone's on the same page?

SPEAKER_00 (03:18):
So I think we should stop as organizations.
We should stop as when we'rebuilding AI governance teams, we
should stop looking for, as Imentioned, a unicorn that has
all of it because usually wecome from different domains.
I come from you know riskcompliance and um internal
auditing, I'm a certifiedinternal auditor.
And even my path was startingthere, but I had to uh you know

(03:41):
start understanding thetechnical team's language,
right?
You we have to, so if you comefrom that domain, you have to
educate yourself on thetechnical aspects of AI, right?
You have to understand modelstructures, AI systems, why a
model drift, what is the traineddata, what is you know, why you
have to evaluate and why are youevaluating your AI systems on to

(04:06):
be able to communicate with thetechnical teams.
So, first don't look for theunicorn, start on career paths,
start on education.
So, for example, you can havedifferent rotation systems.
Like if you come from internalauditing and you know you have
to be auditing an AI system, youneed to be maybe rotated in a

(04:28):
technical team for a while tounderstand, to learn, you know,
to and then if you're if you'rea compliance person and you you
see frameworks, you seeregulations, and you just see a
set of set of regulations thatwe have to comply with, in order
to be able to translate that touh to the technical teams,
again, you have to understandwhat does it feel in in AI,

(04:51):
different AI systems.
So um we actually in Lumanova,we start building um training
programs because nothing existedfrom from before.
But rotation, education, and andinvest in career paths.

SPEAKER_01 (05:08):
Absolutely.
I think that I think morecompanies now than ever are
realizing that they need toprovide their own training in
order to get the the employeeswith the skill set that they
need.

SPEAKER_00 (05:21):
Definitely, definitely.
And it's not easy because the AIis uh evolving every day, this
the frontier models are evolvingevery day, the evaluation
criteria changes in the sensethat sometimes we just we don't
even know what regulation are wegoing to comply with.
So if you're going for NIST,this is a jet, this this is just

(05:42):
a guideline, right?
It's different than if you'relooking to um you know implement
I ISO 40 2001 or if you'relooking at EU AI Act.
And interesting problem goingforward as well, how like global
organizations are able to complywith the different regulation.
But going back to the topic,definitely invest in education

(06:06):
of um your your already existinguh you know resources and
people.

SPEAKER_01 (06:12):
What is your in having worked with so many
business leaders, what is thebest advice you can give them to
have success in this area?

SPEAKER_00 (06:21):
I think we're we're when we're talking about AI
implementing AI governance, Ihave a lot of um talking points.
But in terms of skill sets, Iwould say looking at different
um building different teams andmaking sure that these different
teams, technical, business, andcompliance, you know, framework,

(06:42):
um, legal people, build theteams cross-functional.
Because if you if you just let'ssay that you you are um you're
building AI internally, yeah,systems, it can be a chatbot,
right?
And you have to go through alife cycle.
This is like the best practice.
You have to go through a lifecycle, you start with an intake
process, a questionnaire tomaking sure which business

(07:05):
starts, right?
You have an intake process thatbusiness starts, and then you
you should have a riskassessment that legal and you
know risk people, the second umsecond line people should be
involved in.
And then be these two have tocommunicate together to make
sure the output is correct.
And then you get to the buildphase where the developers come

(07:26):
in and then, like, okay, so whyare we what are we building and
why are we building this?
So from you know, phase one towhich is intake to phase two,
which is build, even like in thebeginning of um building an AI
system, they have to be able tocommunicate.
And as an organization, we haveto build the life cycle of an AI

(07:49):
system because we know theoutcome will be best at the end
because they have communicatedand they have worked together,
making sure that it'stechnically correct, complying
with the right regulation andhave the audit-ready
documentation, and also it'sbuilt for the intended use.

SPEAKER_01 (08:06):
Absolutely.
Well, the other part of this isthat AI is constantly evolving,
and so are the regulations intune with that.
And so, what do you envision thefuture of AI and um regulations,
say a year from now?

SPEAKER_00 (08:22):
So we have the EU AI Act that is going to be uh
enforced in August 2026.
And then we have in the US, wehave you know, Colorado Act, we
have we have differentstate-level acts, and then we
have the guidelines like ISO42001 or NIST um risk management
frameworks.

(08:43):
I think we will have moreregulation.
Um, I mean, in Europe it'sdifferent.
They have they already have aregulation and they have to
comply with it and starting fromum, as I mentioned, 2026.
But in US, I think the way we'velooked at it in the US is a bit
different, right?
So we started um with lessregulation in order to make sure

(09:05):
that the innovators, it's anopen, like open road for the
innovation, right?
We didn't want the regulation tobe a showstopper.
But I think as we evolve, as theAI evolve, we need more
regulation on different parts,probably, because we we see that
it's it's not the AI of 2023.
It's not, we're not talkingabout, you know, even we're not

(09:29):
talking about traditional AI,we're not even talking about the
gen AI, where we were worriedabout the output, like uh right,
because um until now we werelike, okay, we're giving it a
prompt, we have a chat bot, weare worried if the output is
correct or not.
Is this output representable?
Is it uh hallucinated, right?

(09:50):
But in 2026, it would be morefocused on agent EGI, where we
would be worried about if it ifit has the right permission, if
it's within what we gave theagent to do.
For example, if you have anagent that is supposed to book
meetings for you and it does itperfectly by canceling your

(10:11):
other meetings to optimize yourcalendar, right?
So it's doing its job, but inorder for you to make sure that
it's actually doing the rightthing, you need to have right
controls in place.
You need to have continuousmonitoring.
And that's basically one of thekey learnings we've seen in
2025.
In general, you need to havecontinuous monitoring.

(10:35):
So the annual audit that workedperfectly for traditional AI and
maybe for Gen AI a little bit,it's not going to be doable
going forward.
You need definitely to be moreon real-time monitoring and
continuous observability goingforward.
Another thing is that, as Imentioned, it will require

(10:58):
frameworks that makes real-timeauthorization decisions, not
just postdoc um reviews.
We need to, again, as I'mmentioning, real-time monitoring
and having alert, havingdashboards that show you how
your model is performing, ifit's not hallucinating, if it's

(11:18):
actually doing what it wasintended to do in the right way
with the right risk.

SPEAKER_01 (11:23):
Yeah, that was so helpful.
Thank you for sharing yourinsights.
Well, if there was one keytakeaway that you could wrap it
all up with and share with ouraudience today, what would that
be?

SPEAKER_00 (11:34):
I think they have to start with, in general, what I
always say is that they have tostart with mapping of the AI
systems, because I always saythat you can't govern what you
can see.
So a simple way to start is thatyou start with an AI inventory,
making sure that you have anoverview of all your AI systems
in place.

(11:55):
Also, um, I would say invest ineducation, invest in
cross-functional teams in orderto make sure that they are
communicating.
Because if if you want tosucceed in this era, we need to
have humans, uh, the righthumans with the right education,
with the right um, you know,understanding of AI in order to

(12:17):
help it to be more reliable andum, you know, trustable.
Also, I would say theorganizations that will succeed
with AI governance in thefuture, they are not the ones
with the like perfect AIgovernance in place and perfect
policies, perfect structure, theperfect tool, but they are

(12:38):
actually the ones that areunderstanding what is required
to uh for the teams again to beable to work together.
Because we don't want AIgovernance, we don't want a
perfect AI governance.
We want something, we want wewant governance that
practitioners actually use.
So we want the control sets, wewant the evaluations, we want

(13:03):
the monitoring set up from youknow legal teams and compliance
and AI governance at you know,CI uh COI uh teams that the
developers actually use and theyfollow.
So it was a long, you know,closing, but what I would say is
that um make start with your AIsystems and then make AI

(13:26):
governance practical so thedevelopers would use it and see
the value in it, basically.

SPEAKER_01 (13:33):
Great.
Thank you so much for all thetips and advice for our
listeners.

SPEAKER_00 (13:38):
You're welcome.
I hope it's useful.

SPEAKER_01 (13:41):
Yes, and thank you to be here.
And thank you to our audience.
Uh please share any questions orcomments you have below in the
comment section, and I will belooking and try to respond.
And until the next podcast, havea wonderful day.
Advertise With Us

Popular Podcasts

Stuff You Should Know
Betrayal Weekly

Betrayal Weekly

Betrayal Weekly is back for a new season. Every Thursday, Betrayal Weekly shares first-hand accounts of broken trust, shocking deceptions, and the trail of destruction they leave behind. Hosted by Andrea Gunning, this weekly ongoing series digs into real-life stories of betrayal and the aftermath. From stories of double lives to dark discoveries, these are cautionary tales and accounts of resilience against all odds. From the producers of the critically acclaimed Betrayal series, Betrayal Weekly drops new episodes every Thursday. If you would like to share your story, you can reach out to the Betrayal Team by emailing them at betrayalpod@gmail.com and follow us on Instagram at @betrayalpod and @glasspodcasts. Please join our Substack for additional exclusive content, curated book recommendations, and community discussions. Sign up FREE by clicking this link Beyond Betrayal Substack. Join our community dedicated to truth, resilience, and healing. Your voice matters! Be a part of our Betrayal journey on Substack.

Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2026 iHeartMedia, Inc.

  • Help
  • Privacy Policy
  • Terms of Use
  • AdChoicesAd Choices