Write the AI Policy Before You Write the AI Feature

Episode Summary

Trust is where this conversation puts the difficulty, and Maher Hanafi, VP of engineering at Betterworks, manages it in two directions at once. Internally, the team, the leadership and the board have to be brought along, which means understanding the technology and its risks well enough to explain them and win backing. Externally, in HR technology, customers arrive with their own compliance and their own AI acts to satisfy, and adoption gets navigated close to tenant by tenant. His team spent more time on AI privacy policies, transparency and explanation than on building the AI itself, and shipped features small in scope and big on impact that customers could opt into at their own pace. On agents he holds the same line. Agents will reach further into the product, and the human stays in the driver’s seat rather than having decisions made on their behalf. His advice to executives is to learn enough to take part in the decision.

Key takeaways

  • He splits trust into two audiences, and that is the frame the whole episode runs on. The internal stakeholders are the team, the executive leadership team and the board, and they have to be on board with the journey into building generative AI features

  • What earning internal trust actually means is specific. Understand the concepts and how they work, then understand the risks involved in adopting AI and how it will disrupt the business either way, and build a plan and a framework the company can explain to its internal stakeholders

  • The external half is harder in his category, and he says why plainly. Betterworks sells enterprise performance management software into HR technology, which carries a lot of constraints and compliance, so pushback on AI runs higher, he thinks, than in other spaces or in direct-to-consumer products

  • The unit of negotiation is smaller than the market, and that is the operational point. Enterprise and global customers bring their own rules, policies and AI acts, so adoption gets navigated close to tenant by tenant or customer by customer

  • He allocates effort in a way that is unusual to hear stated out loud. His team worked on AI privacy policies and on transparency and explanation of how they build and use AI more than on building the AI itself, because they needed to arrive clear, transparent and responsible

  • The product tactic he runs alongside the policy work has a memorable shape. Ship early versions small in scope but big on impact, give customers early access, and let them opt in at their own pace, because even the best use case can meet an internal policy that says not now

  • He does not claim victory on adoption, which makes the rest more credible. Adoption is never 100 percent, because enterprise and global customers have a lot of moving pieces and their own processes for looking at AI

  • The reassessment his customers are running is bigger than the AI features. Long-standing customers have come back to say that because of this new era of AI they have to reassess the whole solution, not just the AI additions

  • His answer to that reassessment was to arrive before the conversation did. Building trust ahead of those early conversations meant putting together FAQs and use cases and answering questions in advance, as pre-read material customers could get comfortable with

  • He marks a change in where the resistance comes from, and it is a useful before and after. In the early days everyone said no because they did not know how it worked; now it is more understood and what is being navigated is internal policy and strategy

  • The pace of AI is a governance problem as much as a speed problem, and he says why. The frameworks built over years for software as a service and cloud are changing with AI, including role-based access controls, data pipelines and data governance

  • What customers ask about has moved on, and he is precise about the new question. Assessments still ask about data governance, infrastructure and cloud architecture, he says, and now they also ask what the AI will do, whether it makes decisions on behalf of people, and whether it affects performance, outcomes and scoring

  • On agents he answers both halves of the question rather than picking one. Internally the company will explore agents that give customers enhanced features, and externally customers will bring their own agents to its public APIs

  • His constraint on internal agents is stated plainly. Agents should not take decisions on behalf of human beings, they should make a complicated process easier, and the human stays in the driver’s seat with full control of what happens

  • He gives a reason why agents will be slower to arrive in his category than in others. A company cannot take the most sophisticated technology, bring agentic AI into HR technology and hand it all the access controls it needs, so the approach has to be more strategic and the adoption slower where the controls are heavier

  • The bring-your-own-agent path runs on plumbing that already exists. Customers have access to public APIs, which he says could in some way serve as tools for their agents, so they can build an internal agent that uses those APIs to create experiences outside the platform

  • His forecast about interfaces goes furthest of anything he says. Today an API exists for other software to consume and for an engineer to code an integration against, and he expects interfaces designed for agents instead, where an agent is told what tool is available and talks to it directly

  • Asked whether customers want to appraise agents as employees, he is careful to separate today from tomorrow. He is not aware of any conversations going that direction yet, and he can see a future where agents are part of the pool of resources alongside human resources

  • The future he does describe is specific about design, and he marks it as a future rather than a capability he has. He sees a future in which APIs are designed for agents, and experiences for something like an agent business analyst, which needs access to data under specific controls. He says they do not have that yet as far as he knows

  • His first piece of advice to executives is about their own preparation, and he is careful about how much he is asking. Executives should go as deep as their job and domain require into what AI is, what it can do and what the risks are, rather than delegating the work to others and to third-party contractors

  • His analogy for the executive learning curve is deliberately unglamorous. It is the same way people learned about the cloud coming from on-premise, and about the web coming from desktop applications, so he does not think he is asking too much

  • The structure he recommends is cross-disciplinary and, he says, cannot be owned by engineering alone. He describes a council with a framework that builds trust in the adoption, iterating on something like a flywheel so the organization learns, gains confidence and matures

  • His advice about what not to do first is aimed straight at agentic hype. Do not follow the most recent trends and start building an agentic flow on day one; the basic features have become affordable, easy and cost-efficient, and are still impactful, he says, for end users

  • The test he offers is a single question: what is the number one thing that will have a needle-mover impact for customers. Start there, he says, and pursue the sophisticated solutions once the framework and the confidence exist

  • His final word puts a boundary on the whole subject. He thinks responsible AI will get more attention as AI acts are written and revised, and what he asks of it is that it keeps the human at the center and gives people more power rather than replacing them

About Maher Hanafi

Maher Hanafi is VP of engineering at Betterworks, which builds enterprise performance management software as a service. He works on its generative AI features in HR technology, a category where customers arrive with heavy compliance requirements of their own. His argument on this episode is that trust is one of the pillars of adoption, and that it has to be earned in two directions at once: with the executives and board who fund the work, and with enterprise customers who are reassessing the whole solution they already buy, not just the AI added to it. What his team did about it was to put more work into AI privacy and transparency policies than into the features themselves, and to ship small, opt-in capabilities customers could adopt at their own pace.

 

In this episode

00:58 Welcome, and who Maher Hanafi is
01:30 The opening question: building trust in the era of AI
01:43 Why trust is key to adoption in a fast-moving field
02:05 Hype, noise, and the two sets of stakeholders
02:26 Everyone around the business on board with the journey
03:16 The other stakeholder: customers in HR technology
03:37 Compliance, AI acts, and negotiating tenant by tenant
04:05 Understanding a customer’s constraints and expectations
04:23 Policies, transparency and explanation, more than the AI itself
05:07 Small in scope, big on impact, and opting in at their own pace
05:38 Why trust is a pillar of adoption, not a nice to have
06:02 Are customers still reluctant?
06:18 Adoption is never 100 percent
06:25 Customers reassessing the whole solution, not just the AI
07:12 FAQs and use cases as pre-read material
07:41 From nobody understands it to navigating internal policy
07:58 The pace of change as its own problem
08:18 Why an enterprise should be concerned about a vendor moving fast
08:46 The frameworks that are changing: access controls, pipelines, governance
09:26 What the assessments ask about now
10:16 Getting familiar, and staying inside the boundaries of the system
10:50 Agents: yours, your customers’, or both?
11:29 Both scenarios, starting with agents inside the product
11:50 No decisions on behalf of people, and the human in the driver’s seat
12:18 Why agents take longer in a category with heavy controls
13:11 Bring your own agent, through the public API
13:37 Hit the API, get the data, do what you want with it
14:11 Interfaces designed for agents rather than for engineers
14:30 Tell the agent what tool is available and let it talk
15:16 Would customers want to appraise an agent employee?
15:55 Not a conversation he is aware of yet
16:40 Designing for the agent business analyst
17:11 Guidance for executives
17:53 Be educated, to the depth your job requires
18:17 Joining the cross-disciplinary conversation
18:59 The same learning curve as cloud, and as the web
19:21 The council, the framework and the flywheel
20:01 Do not start with an agentic flow on day one
20:49 Focus on impact, and the needle-mover question
21:06 What listeners should take away
21:24 Responsible AI, AI acts, and the human at the center
22:10 Close

In Maher’s words

“trust is key to the AI adoption in this very fast-paced AI evolution”

Maher Hanafi   (01:43)

“we have been working on our AI privacy policies, on our, the way we use AI in our transparency and explanation of building AI and using AI more than building the AI itself”

Maher Hanafi   (04:23)

“Early versions that are small in scope, but big on impact”

Maher Hanafi   (05:07)

“The adoption is never 100%”

Maher Hanafi   (06:18)

“all these kind of frameworks we built for years when it comes to SaaS and cloud are changing with AI”

Maher Hanafi   (08:46)

“we want to ensure that the human is still in the driver’s seat and taking full control of what’s happening”

Maher Hanafi   (11:50)

“I think in the future, we’ll be building interfaces that are for agents”

Maher Hanafi   (14:11)

“my biggest advice is not go directly following the most recent trends in AI and start to build an agentic flow day one”

Maher Hanafi   (20:01)

 

Resources

Ideas and terms discussed

  • Two sets of stakeholders: The split the conversation is organized around. Trust has to be earned inside the company, with the team, the executives and the board, and outside it with customers, and the work is different in each direction

  • Policies over features: His account of where the effort went: on AI privacy policies, transparency and explanation of how AI is built and used, more than on building the AI itself

  • Small in scope, big on impact: His shape for an early release. Enough of it to matter, offered as early access, so customers can opt in at their own pace rather than having it turned on for them

  • Tenant by tenant: How adoption gets negotiated in enterprise software as a service, because global customers arrive with a lot of rules, policies and AI acts of their own

  • The frameworks that are changing: His argument for why the pace of AI is a governance problem. Role-based access controls, data pipelines and data governance were built up over years for cloud software, and he says AI is changing all of them

  • The human in the driver’s seat: His design rule for agents inside the product. Agents handle processes more complicated than summarization or text generation, and he does not want them taking decisions on behalf of people

  • Bring your own agent: The other half of the agent answer. Customers already have access to public APIs, which he says could in some way serve as tools their own agents use to build experiences outside the vendor’s platform

  • Interfaces designed for agents: His forecast for what sits alongside the API written for engineers: an interface an agent is pointed at and talks to directly, which he expects to change how business software is built

  • Agent employees: Christina Ellwood’s framing, offered as a question about whether performance management will need to appraise agents. He is not aware of any such request yet, and describes the design it would require

  • The council and the flywheel: His structure for making adoption stick. A council, as he puts it, that cannot be owned by engineering alone, with a framework it iterates on, something like a flywheel, so the organization builds confidence and maturity as it goes

  • Responsible AI: The boundary he puts on all of it, and the note he ends on. Keeping the human at the center of the loop, and giving people more power rather than replacing them, as AI acts are written and revised

Related AI Realized episodes and events

 

Frequently Asked Questions

 
 
 
 
 
 
 
 
 
 
 
Previous
Previous

Treat the Agent as an Embedded Worker in the Ecosystem