IT Tech Pulse Exclusive Interview with Arti Raman, Chief Executive Officer at Portal26
Stay updated with us
Sign up for our newsletter
Arti Raman, Founder and CEO of Portal26, discusses how real-time AI visibility, continuous governance, and human oversight are helping enterprises manage AI risk while scaling adoption with confidence.
Arti, you’ve said the 2017 Equifax breach, which affected you personally, set yourpath toward Portal26. What did living through that incident teach you about data protection that later shaped how you think about governing AI?
Equifax was personal; I was one of the 147 million people whose data was exposed, and it changed how I thought about risk forever. What stuck with me wasn’t the breach itself; it was how long it took anyone to actually understand what had happened and who was affected. That’s the same failure I see with AI today: organizations move fast, but they don’t have a real-time way to see what’s happening with their data and models until something’s already gone wrong. Portal26 exists so no CIO or CISO has to learn that lesson the hard way.
Across years advising enterprises on generative AI adoption, what’s the assumption leadership teams keep making about their own AI usage that turns out to be wrong once they actually look at the evidence?
Almost every leadership team assumes they know how AI is being used in their business because they’ve approved a tool or signed a contract. Then they look at the evidence, actual usage, actual prompts, actual agent behavior, and it’s a completely different picture. Shadow AI, unsanctioned tools, agents touching systems no one scoped for. The gap between what leaders think is happening and what’s actually happening is usually the biggest risk in the room.
Portal26 has argued that knowing AI is being used isn’t the same as understanding its risk or value. What breaks down inside an organization that only tracks usage instead of continuously evaluating outcomes?
Usage tells you AI is happening. It doesn’t tell you whether it’s helping or hurting you. An organization that only tracks usage can say ‘we have visibility,’ but they can’t answer the questions that actually matter: is this reducing risk or creating it, is this driving ROI, are we compliant with what just changed in the regulation? Without continuous evaluation, visibility becomes a false sense of security.
Portal26 recently rolled out governance built specifically around enterprise Claude deployments rather than generic AI oversight. What changes about risk and control once governance has to track a specific model’s behavior in production?
Generic AI oversight treats every model and every deployment the same, and that’s not how risk actually works. Once you’re governing a live deployment, you need to understand how that specific model behaves in production, what it’s being asked, what it’s returning, where it’s creating exposure. That’s a different level of precision than a policy document sitting in a compliance folder. It’s the difference between having a governance program and having governance that actually catches something in time to matter.
As AI moves from answering questions to independently executing workflows and touching enterprise systems, what decision-making authority should never be delegated to an agent, no matter how reliable its track record becomes?
Judgment calls that carry legal, regulatory, or reputational consequences should never be fully delegated, no matter how good the track record looks. An agent can execute, recommend, even flag risk faster than any human team. But accountability doesn’t transfer. Organizations that get this right keep a human explicitly in the loop for anything that touches compliance exposure, customer trust, or irreversible action, and build governance that makes that checkpoint automatic rather than optional.
Give me two or three predictions about enterprise AI governance over the next three to five years that most CIOs would currently push back on and tell me what’s already convincing you you’re right.
First: AI governance is going to move from a quarterly review cycle to something closer to real time, CIOs who think an annual audit is sufficient are going to find that out the hard way. Second: the organizations that win with AI won’t be the ones with the most usage, they’ll be the ones with the clearest picture of what that usage is actually producing, risk, ROI, and everything in between. Third: Forward-Deployed Engineers are going to become a standard function inside enterprises, not just a model pioneered by a handful of companies, and most organizations don’t yet have the visibility structure to support them. What’s already convincing me I’m right is how fast the FDE model is spreading beyond the companies that pioneered it.
For CIOs, CISOs, and Chief AI Officers trying to move fast on AI without losing control of it, what’s the one operating principle you keep repeating that most organizations still aren’t following?
Move fast on adoption, move just as fast on visibility. Most organizations treat AI governance as something that catches up after adoption happens. Build it in from the first deployment. If you can’t see what your AI is doing right now, in plain language, you’re not moving fast, you’re moving blind.
Beyond avoiding fines or breaches, what does it actually look like when an organization has gotten AI governance right and not just controlled, but confidently and competitively using AI at scale?
It’s not a control function anymore, it’s a confidence function. Done right, governance means leadership can walk into a board meeting and answer any question about AI risk, spend, or performance without a week of digging first. It means CISOs aren’t chasing shadow AI after the fact. And it means the business can actually scale AI aggressively, because they trust what they can see. That’s the shift from AI governance as a brake to AI governance as what lets you press the accelerator with confidence.
Thank you, Arti Raman, for taking the time to share your insights with us.
Write to us [wasim.a@demandmediaagency.com] to learn more about our exclusive editorial packages and programmes.
Arti Raman is the founder and CEO of Portal26 (formerly Titaniam), an award-winning platform helping enterprises securely govern and adopt generative AI. Under her leadership, Portal26 gives CIOs, CISOs and business leaders visibility, policy control, and risk management over GenAI usage across Fortune 500 and mid-size organizations.
Before founding Portal26, Arti was an executive at Symantec, leading enterprise product strategy, heading UX, and founding the company’s competitive intelligence group. She earlier held product, marketing, and alliances roles at Modulo Security Solutions and Agiliance. She holds an MBA in Marketing and Entrepreneurship from the University of Rochester’s Simon Business School.
Arti’s leadership has earned wide recognition, including a nomination for 2023 Cyber Person of the Year, the 2022 TITAN Award for Female CEO of the Year, 2023 SVBJ Women of Influence, and a spot on CIO Influence’s Top 10 Women CEOs Shaping the Future of Tech (2024). She is a member of the Forbes Technology Council and a vocal advocate for women in security and STEM.
The Portal26 AI Adoption Management Platform provides enterprises full visibility and control of all Generative & Agentic AI to enable the buildout of a secure, trusted, and responsible AI program that lifts long-term organizational competitiveness and productivity. As the most mature & comprehensive AI governance offering, Portal26 is the only platform that uniquely provides full-life cycle management of AI consumption from security to ROI. Trusted by Fortune 500 companies, major utilities, and highly regulated sectors like finance, insurance, and healthcare, enterprises leveraging Portal26 have 24x more success in achieving ROI, detect 3x more Shadow AI, and have 10x more security coverage than legacy security providers. For more information, visit portal26.ai.