CX Today

Regal CEO says "The AI Regulation Patchwork Is Holding Innovation Back"

CXToday.com

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 12:53

California's new AI executive order is forcing a conversation every enterprise needs to have – but what does it actually mean for customer experience?  

In this episode of CX Today, Francesca Roche sits down with Alex Levin, CEO of Regal, to explore how organizations can build meaningful AI safety measures without waiting for regulators to mandate them. From system-level guardrails to agent-specific compliance by industry, Alex shares how Regal has been tackling this challenge for nearly six years — long before legislation caught up. 

The conversation digs into the growing problem of state-by-state AI regulation and why Alex believes a fragmented patchwork approach is slowing innovation and putting unnecessary strain on businesses operating at scale. With the EU AI Act adding another layer of complexity, we examine how enterprises can design internal governance structures that hold up across jurisdictions – and why some markets, like France and Italy, are seeing companies opt out of AI altogether as a result of overly restrictive rules. 

Alex also lays out three core principles he believes the industry must rally around if federal leadership doesn't emerge: always identify AI as AI, apply existing consumer protection rules like TCPA equally to automated interactions, and keep individual customer data out of LLM training pipelines. It's a candid, practical conversation about where AI governance stands today – and what it will take to build customer trust at scale.

SPEAKER_00

Hello everyone and welcome back to CX. Today, my name is Francesca Roche. I'm a technology journalist today discussing the impact of California's new AI executive order on customer experience and what it means for AI governance, compliance, and real-time customer interactions. Now, emerging regulation is starting to shape the way organizations design and deploy AI in customer experience. California's recent executive order on AI has added new expectations around transparency, risk management and accountability, particularly for systems that interact directly with customers, with ease of these developments raising practical questions for vendors and enterprises working at the intersection of automation and compliance. Today I'm joined by Alex Levin, the CEO of Regal. But before we get into this the discussion today, Alex, how are you doing today?

SPEAKER_01

Good. Thank you for having me.

SPEAKER_00

It's lovely to hear. Now, the California executive order has emphasized guardrails such as privacy, bias reduction, and accountability. Alex, how do you see companies implementing meaningful safety measures without waiting for regulation to mandate them?

SPEAKER_01

We've been in this space for almost six years now. And so long before the government caught up with what was actually happening, uh, we uh had a priority to make sure that our customers were safe and that their customers were safe. Uh, in our case, the incentives are very clear. We work for large enterprises where they want to make sure they're having a very uh premier experience with their customers, and that includes making sure there are uh no misunderstandings, there are no sort of bad experiences. And so it is actually clear that we are financially incentivized to make sure that we build safety into the product. So from our side, uh we couldn't count on the underlying model providers to do that because they have the opposite incentive. You know, they are much more like, let's say, Facebook in this metaphor, whose incentive is to get as many people using Facebook as possible, even if it means uh it's not exactly the best experience for everybody on Facebook. And so uh that was clear to us from the beginning that we would be responsible for it, not the model providers. And so from the beginning, we built in um we have system guardrails in the product as well as agent-specific guardrails, depending on the regulations necessary for that specific use case or industry. So, for instance, we work for lenders, and so we may have system prompts that you know prevent things like the agent going uh too far in one direction or hallucinations, and then that specific uh lending agent has to apply uh uh the regulations in the United States and in that specific state so that it's doing what it's allowed to do. So it can't be biased in the way it lends, for instance. So I think from the beginning that was our understanding. You know, this patchwork that's starting to develop state by state is really disappointing to us, actually.

SPEAKER_00

Absolutely. I think um even six years ago and also now, it's almost still on the companies to have that proactive responsibility rather than the states themselves. What incentives actually push companies to prioritize safety when speed and scale are those main competitive drivers?

SPEAKER_01

Yeah, so I'd make again the distinction I was just talking about. There are businesses like the AI models that are more similar to Facebook, where their incentive is scale and speed, and you know, anything that slows that down is seen as difficult internally. We are in a very different position, right? We're working with customers that are treating their end users, uh, and so it is in our you know interest to make sure that these are safe, good experiences. So that you know, if even a single one is a bad experience, that can create bad outcomes. So our incentives are very, very aligned with what is good for the end consumer. And that may not be the case for every industry, but you know, ours certainly are.

SPEAKER_00

Absolutely, I think it does come down to the very various companies. It's the factors of market pressure, leadership mindset, and that tension between the growth and risk management. What are the biggest operational risks for companies navigating multiple, you know, potentially conflicting AI laws?

SPEAKER_01

Yeah, to what I said, I'm very disappointed with the patchwork approach that's sort of evolving now. You know, it'd be nice if the federal government stepped in and clarified. So at the moment, the federal government is basically saying, you know, states, especially Republican states where they can lean on them more, you know, don't create AI laws because we're gonna do it eventually. Well, that's not very reassuring. You know, um, I I rather the federal government step in with, you know, at least a broad framework that everybody can understand across the United States, is the new standard. Because right now what's happening is each state is coming up with their own rules, which makes it very difficult for us as an organization to operate within the law because we're spending quite a lot of time paying attention to the nuances of each regulation rather than focusing on any innovation that's possible.

SPEAKER_00

Absolutely. I think obviously for companies operating multiple markets, not just within multiple states, but also globally, that creates challenges for companies operating in those areas. How should companies design internal governance structures for AI to ensure ongoing accountability as these systems scale?

SPEAKER_01

Yeah, so from the very beginning, one of the concepts that we introduced is we track on a user basis uh things like uh, you know, what is their zip code where they're living today, if they give it to the client, you know, uh what is the phone number they have, you know, what is that area code they've had? If we know it, you know, where are they when they're interacting with us? You know, if we happen to have location presence from the customer, um, if they've given us that permission, because that allows us to then make sure that we're applying the right state regulation depending on whether it's and it's complicated, right? What is it based on the state where they're originally from? Is it based on the state where they registered the phone number? Is it based on the state where they're currently calling? What if you don't know? So which one do you fall back to? And so um, you know, from the beginning, you know, we were very geospecific, and I think it's allowed us to serve customers well. Now, if I take the extreme, you know, I'm half French. Uh, you know, we're very careful uh, you know, about countries like France where regulation is much, much higher. Uh, you know, countries like Italy that have put in place huge barriers to entry. And you know, when we talk with our customers that are you know operating in those countries, basically their answer is, okay, let's not do AI in that country for now. And so those consumers are not getting the advantage of this new technology because the government has set up a set of regulations which are so prohibitive. And you know, I understand that the intention of the government was to do something positive, but the consequence is quite negative.

SPEAKER_00

Absolutely. I think as you mentioned earlier, there is a need for clear oversight in that level. But also, I think it's quite interesting you brought up uh France and Italy, especially with the EU AI Act um becoming a very popular topic at the moment. As voice and AI accelerate response times, customer expectations, for instance, services are increasing. So, how can companies meet those expectations without compromising compliance, accuracy, or customer trust?

SPEAKER_01

Yeah, you know, uh maybe starting 20 years ago, there was a gradual retrenchment by businesses that we all felt, where instead of being available to us, they constantly felt like they were taking things away from us to the point where you know a lot of consumers would describe their relationship with even brands they like as pretty fractious, as pretty uh, you know, not complimentary, you know, however you want to put it. And, you know, it's a shame. And finally, now with this technology, we're able to help businesses meet customers where they are and do it in a way that is uh you know cost neutral to the business or something that is really cost effective to the business because of the technology that we run. And so, you know, that's a huge opportunity. To the point we've been making, the the sort of entry uh ante is to be able to apply the regulations that are currently available to us. And so, you know, there's quite a lot of effort for the companies that are operating at scale like us, there's quite a lot of effort that goes into that piece. You know, what we'd ask is hopefully to see a shift in the way policy is being made to give the federal government the precedence here instead of state governments.

SPEAKER_00

Absolutely, I think it's very important that companies uh don't trade off the accuracy, that customer expectation for automation. You know, customer trust is still very much at the heart of experience, and enterprises do need to ensure that this is maintained in AI-driven interactions. And just before we close our discussion today, looking ahead, if regulation does remain inconsistent, do you expect industry-led standards to emerge? You know, what would those standards realistically look like?

SPEAKER_01

Yeah, I mean, what I've proposed in the past is sort of three main principles that I think we all can agree to. So one is the A should always be identified as AI. You know, whether you know it's an upfront disclosure, a verbal cue, uh, you know, there have been some uh talk about sort of a you know, invisible stamp, so to speak. We have to be transparent. The customer deserves to know that they're engaging with AI. You know, second, in the same way we have rules for how businesses should interact with humans, all those same rules have to apply to AI. So in the same way, you know, you can't just have some random business spam you forever, you know, the potential problem is even larger with AI. And so uh, you know, that's not innovation, that's harassment. And so you have to make sure that these rules, like TCPA, also apply to AI equally and provide consumers with control over how businesses are engaging with them. And then the third one is you know, we have to be really careful to not allow LLMs to store and train on individual customer data. So I understand that there will be use cases where consumers see that as a positive, especially like if you get used to interacting with uh you know one of these chatbots on the LLMs, you know, as they get to know you, they get more specific. But I think what we've seen is that they don't have consumers' interests at heart. Even the entropics of the world that are sort of staying there more on the privacy side in certain specific situations, are creating pretty dangerous situations. And so largely what we've seen is allow the LLMs to continue to be the generic uh language model. And then companies like us have created very specific, we call it a unified customer profile, so we'll call memory, and that is created in a you know SOC2, HIPAA compliant manner that uh obeys uh you know CCPA deletion requests, allows consumers to have full control of their data and understand what data is being used to personalize the interaction separate from the LLM. And so it still allows us to create the personalization that a customer would expect, um, including like remembering what you told us last time, so you don't have to repeat it again, which is nice, uh, and much better than with humans, but you know, without sort of sacrificing this risk that these AI models are gonna have everything. So, you know, obviously there's been a lot in the news recently that some of these more advanced LLMs can, you know, effectively hack any system. Yeah, they can also be used to uh shore up vulnerabilities in systems, which is nice, but you know, you don't want to be giving those LLMs all of your personal data. That's probably not the best idea.

SPEAKER_00

Absolutely. I think it goes back to that discussion of customer trust should and must be at the heart of um enterprises and that customer, um that customer goal. Now, unfortunately, that is all we have time for today, but I would like to thank Alex for being here. It's been really insightful to get an idea on how regulatory shifts and AI governance are influencing the future of customer experience and enterprise AI adoption. So thank you so much for joining me, Alex.

SPEAKER_01

Dang it.

SPEAKER_00

And from all of us at CX today, thanks for watching. Goodbye.