7 min Analytics

SAS AI Navigator aims to make AI governance irresistible

SAS AI Navigator aims to make AI governance irresistible

If SAS has its way, governance need not be a brake on innovation at all. On the contrary, the right approach should make responsible AI use attractive and almost irresistible. That’s why SAS is about to launch the AI Navigator. We spoke with Reggie Townsend, Vice President of AI Ethics, Governance, and Social Impact, about the new tool.

As far as Townsend is concerned, a tool like the AI Navigator is sorely needed. This is evident from IDC research commissioned by SAS alone. As many as 46 percent of companies struggle with a lack of alignment between investments in responsible AI and actual trust in AI. Townsend refers to this as the “Trust Imperative”: without the right balance, AI initiatives have little chance of success, to put it mildly. This uncertainty means that roughly half of AI’s true potential within companies remains untapped.

At the same time, organizations are grappling with the growing threat of shadow AI. Similar to shadow IT, this refers to employees who use AI tools and models on their own initiative outside the organization’s official IT ecosystem. The result is an increased risk of data and IP leaks. “You’re simply expanding the risk surface for the entire organization,” says Townsend.

The use case as a fundamental anchor

A deliberate design choice in AI Navigator is to focus not on the underlying AI model but on the specific use case (the business application). Models, agents, and Large Language Models (LLMs) are grouped around this use case and directly linked to the corresponding internal or external policy.

Consider, for example, an open-source LLM compromised by data poisoning. The AI Navigator dashboard provides insight into which specific use cases are powered by the compromised model. These may include multiple applications, such as an internal tool for summarizing meetings and a broad enterprise tool for drafting Requests for Proposal (RFPs) and Requests for Information (RFIs).

At the use case level, the tool displays all assessments, the operational status, and the applicable policies, including policies for third-party vendors and the requirements of the EU AI Act. An enterprise use case requires significantly more due diligence than a simple internal tool, even if they are fundamentally based on the same model. “Each of these use cases carries a different risk, even if they’re linked to the exact same model,” says Townsend. That distinction must always be visible and traceable for organizations.

For example, an RFP application, as we just mentioned, can continue to function without issue because AI Navigator enables switching to an alternative agent in a flash. The new agent will then have the appropriate authorizations, no outstanding security alerts, and all documentation in order. For these types of agents, the platform defines detailed parameters, such as the level of autonomy, configured guardrails, specific skills, and known limitations. This is supplemented with compliance reports, a model card, and financial data.

Gaining control of the runaway AI economy

In addition to mitigating operational and ethical risks, Townsend emphasizes that the economic side of AI is just as important to the C-suite. The revenue model of foundation model providers is shifting from subsidized introductory rates to a consumption-based pay-to-use model. Many companies have not yet set aside an adequate budget to cover the massive quantities of “tokens” their departments consume daily.

When these rising, unpredictable costs are combined with the potential security risks of shadow AI, an organization’s operational expenses can skyrocket. That’s where the AI Navigator can prove its worth. “The key takeaway here is the Navigator’s ability to help organizations manage the business economics,” says Townsend.

By factoring in the use case, organizations can map the exact costs to specific business needs. This gives companies the flexibility to switch models easily if doing so is more financially or performance-wise attractive. For example, a less expensive challenger model might suddenly become the preferred choice. The user retains control over how much technical data engineering remains on an external platform and how much is directly linked to the AI Navigator governance layer. 

Accountability and a lightweight architecture

When it comes to AI governance, the question of who actually bears ultimate responsibility remains. Although designating a single point of contact seems obvious, Townsend warns against the pitfalls of excessive centralization. Appointing a centralized Chief AI Officer or a single, exclusive “AI team” can create the illusion that AI is an isolated department, when in fact it is a capability that cuts across all layers of an organization. SAS, for example, has deliberately opted for an internal cross-functional advisory committee.

To assist companies in this regard, AI Navigator works with predefined personas. This allows an organization to determine for itself who acts as the decision-maker and who acts as the implementer. Whether the person with ultimate responsibility must ultimately also bear legal liability remains a complex and difficult-to-predict issue. Townsend compares the adoption of AI in this context to the adoption of electricity. There, too, within a large company, no single individual is responsible for all possible drawbacks and risks.

To prevent the governance tool from becoming a bureaucratic obstacle, AI Navigator has been deliberately designed to be “nimble” and lightweight. Townsend explains that he wants to avoid unnecessary baggage. Too much functionality makes a product cumbersome and creates resistance. He draws a comparison with the iPhone. That device has enormous capabilities, but you can’t see everything at a glance. For executives, the landing page is sleek and functional, focusing on quick actions without endless clicking. The biggest challenge for the roadmap is finding the right balance. In other words, how much of the workflow should the tool take on versus simply facilitating it, without accidentally becoming a prescriptive workflow tool itself.

The broader governance strategy

Essentially, SAS has been focused for years on implementing governance in companies’ analytics approaches. Viya supports this as SAS’s data and AI platform, while AI Navigator is a separate, lightweight SaaS solution focused on AI governance, insights, and oversight. AI Navigator helps organizations inventory and manage AI models, agents, and use cases across the entire organization, including AI assets that may not run on Viya. The two solutions complement each other. Viya helps organizations build, deploy, and manage AI, while AI Navigator provides a centralized overview of AI usage, governance, and compliance within the broader AI ecosystem.

During the development of AI Navigator, SAS served as its own “customer zero.” While preparing internally for the EU AI Act, the company sought greater control over its own AI usage. It turned out there was little on the market that met its needs immediately. Existing solutions were often too cumbersome or fell short. The tool that SAS subsequently developed internally now serves as the blueprint for this new product.

Realizing the vision soon

Following a preview phase for a select group of companies, AI Navigator is nearly ready for a broad rollout via the Microsoft Azure Marketplace. According to Townsend, no surprising usage patterns emerged during the testing periods, though customer feedback already points to future updates for the roadmap.

Townsend succinctly summarizes the vision behind AI Navigator. AI systems are designed to scale human capacity, which carries the risk that they will gradually supplant human judgment. It is precisely that judgment that must be preserved. The platform is therefore not about slowing down innovation. “Governance is simply a way to scale sound judgment,” says Townsend. Blindly adopting technology is not the goal; responsible judgment is.

Tip: SAS analytics is becoming increasingly integrated with Snowflake, Databricks, and Fabric