/* ---- Google Analytics Code Below */
Showing posts with label risk. Show all posts
Showing posts with label risk. Show all posts

Saturday, July 22, 2023

A Nested Inventory for Software Security, Supply Chain Risk Management

 A Nested Inventory for Software Security, Supply Chain Risk Management

By Esther Shein, July 20, 2023

An SBOM is meant to provide visibility into risks and vulnerabilities. 

The Software Bill of Materials (SBOM) is comprised of all the components and libraries used to create a software application. It includes a description of all licenses, versions, authors, and patch status.

With high-profile data breaches like Kaseya and Apache Log4j still causing repercussions, securing the software supply chain is under scrutiny like never before. This prompted the Biden Administration's 2021 Executive Order on Improving the Nation's Cybersecurity, which requires developers to provide a Software Bill of Materials (SBOM).

Think of an SBOM like the ingredients in a recipe—it is comprised of all the components and libraries used to create a software application. It includes a description of all licenses, versions, authors, and patch status.

Many of these components are open source, and an SBOM is meant to provide visibility into risks and vulnerabilities. After all, if you don't know what code you're protecting, how can you maintain it?

The role of SBOMs

When organizations have this visibility, they are better able to identify known or emerging vulnerabilities and risks, enable security by design, and make informed choices about software supply chain logistics and acquisition issues. "And that is increasingly important because sophisticated threat actors now see supply chain attacks as a go-to tool for malicious cyber activity,'' according to Booz Allen Hamilton.  

By 2025, 60% of organizations building or procuring critical infrastructure software will mandate and standardize SBOMs in their software engineering practice, up from less than 20% in 2022, according to market research firm Gartner.

"Multiple factors are driving the need for SBOMs,'' says Manjunath Bhat, a research vice president at Gartner. Those factors include the increased use of third-party dependencies and open-source software, increased incidence of software supply chain attacks, and regulatory compliance mandates to secure the use of OSS, Bhat says.

 "The fine-grained visibility and transparency into the complete software supply chain is what makes SBOMs so valuable," he says.

SBOM elements

The National Telecommunications and Information Agency (NTIA) and the U.S. Department of Commerce were tasked with publishing the minimum elements for an SBOM, along with a description of use-cases for greater transparency in the supply chain.

They determined there should be data fields for a supplier, component name, and version, as well as the dependency relationship, among other areas, the NTIA and Department of Commerce said.

They also recommended there be automatic data generation and machine readability functionality to allow for scaling an SBOM across the software ecosystem. There are also three formats for generating SBOMs that are generally accepted: SPDX, CycloneDX, and SWID tags.

SBOMs are designed to be part of automation workflows, Bhat observes. "Therefore, standardization of data formats and interoperability between them is going to be paramount."  

The data fields within an SBOM "include elements that help uniquely and unambiguously identify software components and their relationships to one another,'' he says. "Therefore, the basic elements include component name, supplier name, component version, unique identifiers (most likely a digital signature or a cryptographic hash), and dependency relationships."

SBOM platforms that are automated and dynamic are ideal because they can be continuously updated to ensure software developers have an accurate view of the components and dependencies they use in their applications.  ... ' 

Wednesday, May 31, 2023

Statement on AI Risk

 Considerable statement and agreement,   Signed by many worldwide.  top academics in China. 

https://www.youtube.com/watch?v=f20wXjWHh2o

Statement on AI Risk

Hassabis, Altman and AGI Labs Unite - AI Extinction Risk Statement [ft. Sutskever, Hinton + Voyager]

54,971 views  May 30, 2023

The leaders of almost all of the world's top AGI Labs have united to put out a statement on AI Extinction Risk, and how mitigating it should be a global priority. This video covers not just the statement and the signatories, including names as diverse as Geoffrey Hinton, Ilya Sutskever, Sam Harris and Lex Fridman, but also goes deeper into the 8 Examples of AI Risk outlined at the same time by the Center for AI Safety.

Top academics from China join in, while Meta demurs, claiming autoregressive LLMs will 'never be given agency'. I briefly cover the Voyager paper, in which GPT 4 is given agency to play Minecraft, and does so at SOTA levels. 

Statement: https://www.safe.ai/statement-on-ai-risk

Further:  https://www.safe.ai/ai-risk   8 risk types

Natural Selection Paper: https://arxiv.org/pdf/2303.16200.pdf5

Yann LeCun on 20VC w/ Harry Stebbings:   

 • Yann LeCun: Meta’...  

Voyager Agency Paper: https://arxiv.org/pdf/2305.16291.pdf

Karpathy Tweet: https://twitter.com/karpathy/status/1...

Hassabis Benefit Speech:   


 • Fei-Fei Li & Demi...  

Stanislav Petrov: https://en.wikipedia.org/wiki/Stanisl...

Bengio Blog: https://yoshuabengio.org/2023/05/07/a...

https://www.patreon.com/AIExplained   .... ' 

Saturday, March 04, 2023

EU Digital Strategy

 So many directions to regulate.    Note considering the influence US Law

The EU digital strategy: The impact of data privacy on global business

McKinseu:  March 1, 2023 | Commentary

By  Daniel Mikkelsen, Sebastian Scheurle,   Henning Soller , and Malin Strandell-Jansson

New data regulations from the European Union require organizational attention, and three key steps can help navigate the data privacy landscape.

The data regulations in the European Union (EU) have recently received significant attention specifically due to the advent of the General Data Protection Regulation and the rulings around Schrems II—whereby the Court of Justice of the European Union found that the protection of personal data had limitations due to domestic law in the United States—as well as the access and use by US public authorities of personal data transferred from the EU, and recent developments such as e-privacy.

While these developments have led to major changes in data privacy, one of the other goals of the regulation—to establish a market for data and facilitate data exchange between companies—has not been reached to date.

This lack of action has led to the potential for further regulatory activity to define an agenda for how to uplift the data capabilities of European companies, create a market for data, and regulate activities around AI. These activities are typically summarized as the EU digital strategy. While regulation adds further requirements and obligations to any data-enabled business, it also creates an opportunity for competitive advantages for those that best derisk their data transformations.

The EU digital strategy offers organizations both challenges and opportunities, but these regulations will likely continue to evolve, so organizations should remain aligned with the regulatory process. ... ' 

Monday, February 20, 2023

Does it Pay to be a Whistlebower? and ChatGPTs General Answer.

In HBS Working Knowledge and Podcast ... 

Business Research for Business Leaders

Topics, Sections

14 FEB 2023 COLD CALL PODCAST follows ... 

Does It Pay to Be a Whistleblower?

In 2013, soon after the US Securities and Exchange Commission (SEC) had started a massive whistleblowing program with the potential for large monetary rewards, two employees of a US bank’s asset management business debated whether to blow the whistle on their employer after completing an internal review that revealed undisclosed conflicts of interest. The bank’s asset management business disproportionately invested clients’ money in its own mutual funds over funds managed by other banks, letting it collect additional fees—and the bank had not disclosed this conflict of interest to clients. Both employees agreed that failing to disclose the conflict was a problem, but beyond that, they saw the situation very differently. 

One employee, Neel, perceived the internal review as a good-faith effort by senior management to identify and address the problem. The other, Akash, thought that the entire business model was problematic, even with a disclosure, and believed that the bank may have even broken the law. Should they escalate the issue internally or report their findings to the US Securities and Exchange Commission? Harvard Business School associate professor Jonas Heese discusses the potential risks and rewards of whistleblowing in his case, “Conflicts of Interest at Uptown Bank.”  ...    '

Part II:

ChatGPT  answers, much more generally, 

Does it Pay to be a Whistleblower?

Being a whistleblower can come with significant risks and consequences, both personal and professional. However, it is important to note that there are also potential rewards and benefits to blowing the whistle on wrongdoing.

In some cases, whistleblowers may be eligible for financial rewards, such as a percentage of the amount recovered in a government investigation or qui tam lawsuit. Whistleblowers may also receive protection from retaliation, such as being fired, demoted, or harassed, under various whistleblower protection laws. These laws can protect whistleblowers from retaliation by their employers or colleagues, including by providing legal remedies, such as reinstatement, back pay, and compensatory damages.

Additionally, whistleblowers may also experience a sense of personal satisfaction and fulfillment from doing the right thing, and from knowing that they have helped to expose and prevent wrongdoing that may be harmful to others.

However, it's important to note that being a whistleblower can also come with significant personal and professional risks. Whistleblowers may experience retaliation, such as being ostracized, bullied, or harassed by their colleagues and superiors, and may face difficulty finding new employment in the same industry or field. The process of blowing the whistle can also be stressful and time-consuming, involving legal proceedings, investigations, and media attention.

Ultimately, the decision to blow the whistle on wrongdoing is a personal one, and depends on a variety of factors, including the severity of the wrongdoing, the potential risks and consequences, and the individual's personal and professional values and goals. It's important to weigh the potential benefits and risks carefully and seek the advice of a qualified attorney or whistleblower advocate before making a decision.   END

Compare,  Usefulness?  

Friday, September 09, 2022

GM Recalls RoboTaxi Code for Update after Crash

An example of how automotive complexity will increase in context. 

GM's Cruise Recalls, Updates Software in Robotaxis

By TechCrunch, September 9, 2022

A crash in June prompted General Motors' Cruise autonomous vehicle (AV) unit to recall 80 robotaxis and update their software.

In a regulatory filing with the National Highway Traffic Safety Administration, Cruise attributed the June collision to a "rare circumstance" in which the automated driving system caused the unmanned robotaxi to brake hard while making an unprotected left turn.

"The report explains how the Cruise AV responded to an oncoming vehicle speeding in the wrong lane, and how through our normal course of continuous improvements, Cruise AVs are even better equipped to prevent this singular, exceptional event," the unit said.

Cruise explained the automated driving system had chosen the risk scenario with the least potential for a serious crash, before the oncoming vehicle suddenly shifted direction.  .... 

Cruise said in a regulatory filing the software recall was issued because of a "rare circumstance" in which the automated driving system caused the driverless robotaxi to brake hard while making an unprotected left turn.... ' 

From TechCrunch  

View Full Article

Wednesday, August 10, 2022

Velocity of Response and Proactivity in Supply Chain Risk Management

 Good thoughts here,  make them work. 

Supply Chain Risk Management

August 10, 2022:   By    Russell W. Goodman, in SupplyChainBrain

Velocity of response and proactivity in risk management are key to meeting supply chain challenges and creating value, says Rajesh Kalidindi, founder and chief executive officer of LevaData.   (Talk) 

The unprecedented challenges of the last couple of years have presented opportunity for supply chain organizations to create value, Kalidindi says. Successful ones have managed to achieve resiliency and secure supply ahead of everyone. They have moved faster or figured out ways to lock down pricing to avoid significant inflation.

 There are three elements in successfully managing risk, Kalidindi says. One is rapid response. But “understanding” an event has occurred before competitors do doesn’t necessarily give advantage. “The real advantage comes in what you do post-understanding.” Some companies took weeks longer to respond to recent challenges.

Secondly, successful companies already understood where their top set of risks were, and were proactively managing those either at multiple sites or multiple nodes in their operation, he says. 

The last piece some companies have really done well has been in product design. “They're able to influence engineering proactively in terms of designing for supply chain risk, choosing the right parts, the right suppliers, the right sites to make the product.”

In Kalidindi’s view, companies can no longer have a cadence-based engagement with their supply base. “Gone are those days where you can decide when you need to act. In today's world, you better be ready for the rollercoaster at any point in time, whether it’s going up or down. And so having the team, the technology and the strategy in place to manage challenges becomes super critical for success.”

Kalidindi acknowledges that one may not be able to save cost when faced with a risk situation, but you’re likely to reduce the impact of a cost increase and do so better than the competition. .... '

Wednesday, June 29, 2022

TikTok a Dangerous Risk?

 Following up on this.   My guess it would be very hard now to get significant number of folks to delete it.

Is TikTok Seriously Dangerous—Do You Need To Delete It?

Zak Doffman, Contributor, I cover security and surveillance and co-host 'Straight Talking Cyber'

Follow this author to improve your content experience. 

Jul 11, 2020,05:07am EDT    in Forbes

FRANCE-CHINA-TIKTOK-INTERNET-APP

Reports on Friday that Amazon had asked employees to delete TikTok from their phones spread like wildfire—TikTok’s security woes have been the viral story of the month. Amazon quickly retracted the news—an internal memo had been released in error—but the implication that TikTok, an app installed by hundreds of millions, might be tapping into emails had resonated. That’s where we now find ourselves.

And while Amazon walked back from any ban, Wells Fargo has asked some employees to delete the app, citing “concerns about TikTok’s privacy and security controls and practices.” You’ll remember that the U.S. military has already banned TikTok from government-issued phones—and there is pressure to widen that significantly, all of which pales compared to India’s blanket ban and threats that Australia and—devastatingly for TikTok—the U.S. might follow suit.

I have reported on TikTok security concerns for more than a year—but we are now in uncharted territory. Whereas we have seen regulatory concerns and fines for data privacy violations and security vulnerabilities in the past, we have now seen TikTok caught up in the much wider U.S.-led backlash against Chinese tech. The question I’m now asked more than any other, unsurprisingly, is whether TikTok is seriously that dangerous and whether users should seriously delete the app.  ... .' 

Friday, June 24, 2022

Quantum Computing for Risk Aggregation

Looking at this further, in particular the aspect of supply chain risk use. 

Quantum Computing for Risk Aggregation    in BusinessWire

Early results lay the foundation for developing new solutions to manage risk exposure. Takeaways include:

IonQ and GE are able to use a large set of data to model predictability associated with future risk across up to four variables using their quantum computers.

This research can benefit finance, manufacturing, and supply chain management  .... ' 

Sunday, May 22, 2022

Risk, A Users Guide

 Finished reading.   Many of the examples are military, which is OK by me.  Success and Failure  looking back onto  actions.  Does a nice job of describing military risk and results analyses methods like  'After-action reviews' and results and failure analyses, of course by themselves a way to measure future risk in context. Would have liked more distinctly quantitative forecasting style analyses.   But worth the read.  

Risk: A User's Guide Hardcover – October 5, 2021   by Stanley McChrystal (Author), Anna Butrico (Author)

From the bestselling author of Team of Teams and My Share of the Task, an entirely new way to understand risk and master the unknown.

Retired four-star general Stan McChrystal has lived a life associated with the deadly risks of combat. From his first day at West Point, to his years in Afghanistan, to his efforts helping business leaders navigate a global pandemic, McChrystal has seen how individuals and organizations fail to mitigate risk. Why? Because they focus on the probability of something happening instead of the interface by which it can be managed.

In this new book, General McChrystal offers a battle-tested system for detecting and responding to risk. Instead of defining risk as a force to predict, McChrystal and coauthor Anna Butrico show that there are in fact ten dimensions of control we can adjust at any given time. By closely monitoring these controls, we can maintain a healthy Risk Immune System that allows us to effectively anticipate, identify, analyze, and act upon the ever-present possibility that things will not go as planned.

Drawing on examples ranging from military history to the business world, and offering practical exercises to improve preparedness, McChrystalillustrates how these ten factors are always in effect, and how by considering them, individuals and organizations can exert mastery over every conceivable sort of risk that they might face.

We may not be able to see the future, but with McChrystal’s hard-won guidance, we can improve our resistance and build a strong defense against what we know—and what we don't. .... ' 


Gen Z and Cryptocurrency and NFT

In a recent encounter also  discovered this, was surprised at the fluency seen in  these technologies.  But not the risk in their use.  

How Gen Z is hooked on cryptocurrency and NFTs

By Mariko Oi   in the BBC Technology, Asia business correspondent

The lure of making a quick buck has always attracted young people to invest in risky assets. For Generation Z, it is the volatility - and the decentralised nature - of digital assets such as cryptocurrency and NFTs which appeals. But they are unregulated, meaning there is little investor protection.

"All my friends were talking about [cryptocurrency] so one day I just decided why not just jump in and see if I can make some money," says 20-year-old Paxton See Tow.  All he needed was his phone and trading thousands of dollars' worth of assets was only a click away.

Generation Z - also known as Zoomers - are the age group born between the mid-1990s to early-2000s. They grew up online, playing games and meeting friends virtually, so the transition is natural., Cryptocurrencies are digital currencies while a "non-fungible token" (NFT) is a way of owning an original digital image, touted as the digital answer to collectables. .... '

Thursday, March 17, 2022

On Forthcoming Draft EU Rules About AI

Excerpt of EU regulation being considered, now in draft. 

The EU’s AI rules will likely take over a year to be agreed  By Ryan Daws | February 17, 2022  in AI News

Rules governing the use of artificial intelligence across the EU will likely take over a year to be agreed upon.

Last year, the European Commission drafted AI laws. While the US and China are set to dominate AI development with their vast resources, economic might, and light-touch regulation, European rivals – including the UK and EU members – believe they can lead in ethical standards.

In the draft of the EU regulations, companies that are found guilty of AI misuse face a fine of €30 million or six percent of their global turnover (whichever is greater). The risk of such fines has been criticised as driving investments away from Europe.

The EU’s draft AI regulation classifies systems into three risk categories:

Limited risk – includes systems like chatbots, inventory management, spam filters, and video games.

High risk – includes systems that make vital decisions like evaluating creditworthiness, recruitment, justice administration, and biometric identification in non-public spaces.

Unacceptable risk – includes systems that are manipulative or exploitative, create social scoring, or conduct real-time biometric authentication in public spaces for law enforcement.

Unacceptable risk systems will face a blanket ban from deployment in the EU while limited risk will require minimal oversight.

Organisations deploying high-risk AI systems would be required to have things like:

Human oversight.

A risk-management system.

Record keeping and logging.

Transparency to users.

Data governance and management.

Conformity assessment.

Government registration.

However, the cumbersome nature of the EU – requiring agreement from all member states, each with their own priorities – means that new regulations are often subject to more debate and delay than national lawmaking.  .... '

Thursday, March 10, 2022

Understanding High-Mutating Viruses

Tool Helps to Better Understand High-Mutating Viruses, Including COVID-19

Los Alamos Reporter, March 8, 2022

Scientists at the U.S. Department of Energy's Los Alamos National Laboratory (LANL) have developed FEVER, or Fast Evaluation of Viral Emerging Risks, a computational tool for detecting and investigating high-mutating viruses. Researchers use FEVER to design flexible measurement assays that concurrently identify whole classes of viruses for bio-surveillance, accurately diagnose an outbreak strain, and type mutations to find variants impacting public health. "We applied FEVER to COVID-19 and showed that we can indeed perform both highly specific SARS-CoV-2 diagnostics in 100 clinical samples while performing mutation typing for spike variants all at the same time," said LANL's Jessica Kubicek-Sutherland. ... '

Saturday, January 29, 2022

COVID-19: Implications for business

Lots, have been in particular following labor availability. 

COVID-19: Implications for business

Our latest perspectives on the coronavirus outbreak, the twin threats to lives and livelihoods, and how organizations can prepare for the next normal.  from McKinsey ....

Thursday, November 18, 2021

AI Risk and Coming Regulation

More needs to be done here  here, though though predicting it wil be hsrd.  Consider risk analyses under varying scenarios.

Assess AI Risk to Prepare for Coming AI Regulations  

September 30, 2021 

AI regulations are coming, with multiple acts being proposed in the US Congress, and AI experts are sharing advice on how to prepare.  (Credit: European Commission) 

By John P. Desmond, AI Trends Editor 

Since the European Commission in April proposed rules and a legal framework in its Artificial Intelligence Act (See AI Trends, April 22, 2021), the US Congress and the Biden Administration have followed with a range of proposals that set the direction for AI regulation.  

“The EC has set the tone for upcoming policy debates with this ambitious new proposal,” stated authors of an update on AI regulations from Gibson Dunn, a law firm headquartered in Los Angeles.  

Unlike the comprehensive legal framework proposed by the European Union, regulatory guidelines for AI in the US are being proposed on an agency-by-agency basis. Developments include the US Innovation and Competition Act of 2021, “sweeping bipartisan R&D and science-policy regulation,” as described by Gibson Dunn, moved rapidly through the Senate.

“While there has been no major shift away from the previous “hands off” regulatory approach at the federal level, we are closely monitoring efforts by the federal government and enforcers such as the FTC to make fairness and transparency central tenets of US AI policy,” the Gibson Dunn update stated.  

Many in the AI community are acknowledging the lead role being taken on AI regulation by the European Commission, and many see it as the inevitable path.  

European Commission’s AI Act Seen as “Reasonable” 

Johan den Haan, CTO, Mendix

“Right now, every forward-thinking enterprise in the world is trying to figure out how to use AI to its advantage. They can’t afford to miss the opportunities AI presents. But they also can’t afford to be on the wrong side of the moral equation or to make mistakes that could jeopardize their business or cause harm to others,” stated Johan den Haan, CTO at Mendix, a company offering a model-driven, low-code approach for building AI systems, writing recently in Forbes.  .... ' 

Tuesday, October 26, 2021

Risk Assessment Algorithms Can Unfairly Impact Court Decisions

 An aspect hat we examined for potential changes in court standings on regulations.  Well worth following. 

Risk Assessment Algorithms Can Unfairly Impact Court Decisions   By Government Technology,   September 29, 2021  in CACM

A study by the University of Michigan's Ben Green and Harvard University's Yiling Chen suggests pretrial risk assessment algorithms increase the likelihood that judges will change their priorities in making pretrial decisions.

The algorithms use data on previous defendants' outcomes to make forecasts on the given arrestee, presenting them either as a numerical score, or designating them high-, medium-, or low-risk for failure to appear in court, or being arrested again.

The researchers found viewing the algorithms' predictions caused participants to consider factors differently and to more highly prioritize the risk of defendants' failure to appear or getting re-arrested, with the result of more inequitable sentencing (since Blacks were more likely to be deemed higher-risk defendants, and to receive harsher decisions than Whites).

From Government Technology

View Full Article 

... Pretrial risk assessment algorithms are intended to help judges make more informed decisions. Researchers have raised concerns not only about the fairness and accuracy of the tools themselves, but also their influence on judges thinking.  ... 

Saturday, October 16, 2021

MIT and QCRI Deep Learning Predicts Traffic Accidents

And forecasting generalizes to multiple cities. 

Deep Learning Helps Predict Traffic Crashes Before They Happen

MIT News, Rachel Gordon, October 12, 2021

A deep learning model trained on historical traffic crash data, road maps, satellite imagery, and global positioning system trajectory patterns can generate high-resolution crash risk maps. Scientists at the Massachusetts Institute of Technology and the Qatar Computing Research Institute (QCRI) developed the model, which yields risk maps that can define the expected number of crashes over a future period, identifying high-risk areas and forecasting future collisions. The maps are composed of 5x5-meter grid cells, a resolution that shows highway roads, for example, have a greater risk for traffic accidents than nearby residential roads, while highway ramps have higher risk than other roads. QCRI's Amin Sadeghi said, "Our model can generalize from one city to another by combining multiple clues from seemingly unrelated data sources."

Friday, September 17, 2021

Visirule Business Risk Advisor

Have never stopped looking at simplified rule based systems to examine and  model decisions.  Some time ago we looked at some of Clive Spenser's work in this area.  Simplified and impressive.     Used similar methods in the 90s at P&G.

Storing and using complex knowledge does not have to be overly complex or too much like 'AI'.   Here it addresses risk, but can be aimed at other knowledge based applications.  Plan to test further, do take a look. Be glad to introduce you. 

Clive writes:   The BRAT initiative is based on work we have been doing for a major retail bank in the area of Testing Risk Assessment.

We simply recast it for demonstration purposes into the area of risk associated with various business activities.

The table of artifacts (Risk Areas and Risk Topics) which underpins both systems is represented using a flex frame hierarchy

The questions are standard VisiRule questions and there's a handful of statement boxes which look at the answers and determine which Risk Areas are relevant, set their initial priority levels and calculate some risk levels.

The calculated risk levels are used to calibrate the priority levels for each Risk Topic within a triggered Risk Area. Different Risk Areas are triggered by the various Business Activities.

You can play with the demo on:
So the whole thing is pretty configurable and runs on our VisiRule/Flex/Prolog AWS web server using IIS/CGI  ...   

Regards,     Clive Spenser,  LPA VisiRule,  www.visirule.co.uk,    www.lpa.co.uk   

Wednesday, July 21, 2021

AI and Media Buying

 Early on considered this option.  Key was to also include options available, risks in choices, knowledge from previous choices. 

How custom algorithms will shape the future of media buying

By John Wittesaele | July 14, 2021    Categories: Marketing,

John Wittesaele is EMEA CEO at Xaxis, a global provider of innovative AI technologies, data-driven creativity, and programmatic expertise.

The digital advertising industry ingests and processes millions of data signals per second, generating immense volumes of data. While the industry is hyper-focused on the cookie deprecation, the third-party cookie is actually only one marketing input, there are many other data signals, both on and offline, available to optimise media buying.

Algorithms based on artificial-intelligence (AI) can be tailored to brands’ unique goals, allowing marketers to find pockets of performance within vast amounts of data and optimise media buying to drive real business outcomes. By combining custom AI approaches that integrate a brand’s key performance indicators (KPIs), and shaking off our third-party cookie dependence, we can welcome a new era of transparent and effective programmatic media.

User matching via first-party data signals

One way AI and custom algorithms will shape media buying, is by matching converted consumers with prospects that have similar digital patterns. Rather than focussing on who consumers are – their age and gender, or where they live – AI looks beyond basic characteristics to focus on the most important behavioural signals of a likely customer. Two consumers can have completely different profiles but ultimately want the same thing. Where traditional audience targeting would miss this opportunity, algorithmic matching enables brands to identify and take advantage of these similar needs.

Algorithmic consumer matching is currently based on first-party data signals, from retailers, brands or publishers. Moving forward, an explosion in new types of data is expected from connected cars and homes, internet-of-things devices, virtual and augmented reality, and biometrics, which will all feed into this process. AI will be vital to manage this data, and there must always be an emphasis on balancing the relationship between AI and ethics to ensure advertising works better for everyone while individual identities are protected. .... '

Sunday, June 13, 2021

AI and Decisions

Good, colorful piece on the who idea of designing decisions.  I like the point made that 'most decisions are not binary',  noting that it is rarely just finding the best decision, at minimum such an endeavor should include a risk analysis for that decision, and typically more. 

AI Designs Decisions  in Towardsdatascience

Dissection of survey evidence on AI-powered decision-making

Ian Domowitz

Havelock Ellis said it is not the attainment of the goal that matters, it is the things met with by the way. He was speaking of philosophy. In business AI is all about goal attainment. The things met along the way are decisions.

Decisions constitute a focus of the recent survey by Signal AI of 1,000 C-suite executives in an attempt to estimate the impact of AI on the U.S. economy. According to the survey, 96 percent of business leaders believe AI will transform decision making and 92 percent agree companies should leverage AI to augment decision-making processes.

AI is not so sure.

Most decisions are not binary

Neither survey nor business directors are informative with respect to the types of decisions involved. Most respondents say they spend upwards of 40 hours a week on the process. No surprise: that is presumably why they are paid, but with 80 percent of leaders claiming there are too much data to evaluate, senior management is looking for relief. Where does AI fit in the picture?

AI aspires to set and achieve goals by motivating and guiding the organization through phases of decision making. Four kinds of decisions are relevant.

Policy decisions involve choosing what goals to pursue and how they will be attained. Proper adaptation of the technology to the company ought to define these objectives. AI risks failure at this step by falling in love with creative fire and failing to recognize practical guidelines.  .... 

Wednesday, June 02, 2021

Multiscale risk analysis with information entropy applied to portfolio optimization

Brought to my Attention.   Regards portfolio investment, Risk and entropy.    Authors are colleagues of mine.  Technical.

Multiscale risk analysis with information entropy applied to portfolio optimization By George G. Polak and David F. Rogers b,

Department of Information Systems and Supply Chain Management, Raj Soin College of Business, Wright State University, Dayton, OH, 45435-0001, United States. ORCID: 0000-0002-6222-7468 b Racers Consulting & Management, 30 Silver Avenue, Ft. Mitchell, KY, 41017-2909, United States.

ORCID: 0000-0002-3676-4075

* Corresponding author. E-mail: George.Polak@Wright.edu (G. G. Polak), RogersDavidF10@gmail.com (D. F. Rogers).

Abstract The overall risk assumed in making a decision or constructing a portfolio to maximize returns in a probabilistic setting includes both a return value-based component and a probabilistic information-

based component. Each is independent of the other, and each plays an important role in our approach to decision analysis and portfolio optimization. We introduce the concept of an information entropy profile for any discrete and finite probability distribution for the purpose of fully quantifying the information based component of risk. The profile is based on the partitioning of the state space into planning cells and is employed within the framework of Multiscale Risk Analysis to optimize decision-making across the full array of possibilities between the maximin and expected value approaches. We formulate mixed- integer nonlinear optimization models to find decisions without a priori enumeration of the partitions where the information-based risk as measured by entropy is expressed as both 1) an objective to be minimized subject to a constraint on expected returns and 2) an upper-bounded constraint coupled with an objective of maximizing expected return. We also present bounding models that are formulated without logarithmic functions. Although all the models are nonconvex, we demonstrate that realistically-sized instances can be solved to optimality by off-the-shelf global optimization software.

Keywords Risk analysis; Investment analysis; Integer programming; Nonlinear programming;

Global optimization.  Submitted: March 31, 2021

Declarations

Funding: The authors did not receive funding from any public, commercial, or not-for-profit agency.

Conflicts of interest/Competing interests: There are no conflicts of interest/competing interests involving funding; employment; financial or non-financial interests, directly or indirectly related to this work. Availability of data and material: Data used for this work is available in Polak et al. (2010). Code availability (software application or custom code): Custom GAMS code available from the authors.

1 Introduction

“Only those who will risk going too far can possibly find out how far one can go.” T. S. Eliot (1931)

 A fundamental goal of decision analysis is to determine a best strategy from among several alternatives for implementation in a risk-filled future. We consider an individual Decision Maker (DM) who is charged with constructing a financial portfolio from a discrete and finite set of possible investment opportunities actuated within a discrete and finite probabilistic state space for which alternative potential outcomes for the investments are defined. These outcomes may be posited according to particular economic circumstances during the planning period, e.g., 1) reflecting historical returns during previous time periods or 2) projected returns put forth by consultants. Winston (2008) refers to this as a scenario-based setting and how to best make decisions in this type of straightforward setting remains a pervasive issue for an individual DM as well as for corporations, banks, and governments.