# Cillian Kieran, Founder and CEO of Ethyca – Interview Series

> Source: <https://www.unite.ai/cillian-kieran-founder-and-ceo-of-ethyca-interview-series/>
> Published: 2026-08-04 12:16:47+00:00

###
[
Interviews
](https://www.unite.ai/series/interviews/)

# Cillian Kieran, Founder and CEO of Ethyca – Interview Series

[Add Unite.AI to your preferred sources on Google](https://www.google.com/preferences/source?q=unite.ai)

[Cillian Kieran](https://www.linkedin.com/in/cilliankieran/), Founder and CEO of Ethyca, is a serial entrepreneur and privacy engineer with more than two decades of experience building data-intensive technology businesses. Before founding Ethyca in 2019, he led digital agency CKSK for a decade and subsequently founded BrandCommerce, drawing on his background in software engineering, user experience and large-scale enterprise data programmes. At Ethyca, Kieran has focused on transforming privacy and data governance from a largely manual compliance function into infrastructure that can be embedded directly within how organisations build and operate technology.

[Ethyca](https://www.ethyca.com/) develops trusted data infrastructure that helps enterprises discover sensitive information, manage consent, fulfil privacy requests and enforce rules governing how data is used across conventional applications and artificial intelligence systems. Its platform is built around Fides, an open-source governance language that creates a consistent framework for defining, auditing and enforcing permitted data uses across systems, APIs and AI pipelines. The company is now launching Astralis, an AI governance layer combining automated regulatory assessments with purpose-based access controls, enabling organisations to determine why models and agents are accessing particular data and enforce those permissions in real time. Ethyca says the platform can reduce assessments that traditionally require 40 to 60 hours of manual work to approximately 20 to 40 minutes, helping enterprises expand AI deployments without allowing governance processes to become a bottleneck.

**You founded multiple companies before launching Ethyca in 2019, including building CKSK into a global digital consultancy serving Fortune 500 organizations. What experiences during that journey convinced you that data governance, instead of AI models themselves, would become the defining bottleneck for enterprise AI adoption?**

I spent years building a digital consultancy servicing large enterprises like Heineken, Sony, and Pepsi during the digital advertising and social media gold rush. Time and again, I watched the same pattern play out. A powerful technology arrives, everyone races to adopt it, and only once it’s embedded in the business do regulators show up to put guardrails around it, leaving compliance teams to deal with the consequences. Take GDPR, the first real crackdown on how companies use personal data. Regulators only stepped in after martech and social media had already turned data collection into the backbone of their business models. It was obvious to me that the same pattern would occur with AI.

What solidified this hunch I had was the privacy compliance work I was doing at Ethyca. Building compliance systems for large enterprises, I realised you could put a layer around a company’s data that evaluated every request against three things: what the data is, what you’re permitted to do with it, and what the risk is if you do. Working on that made the real constraint obvious. Enterprises aren’t short on data. They’re short on a governance layer that dictates what data is permitted to be used for. That was the bet we made in 2019 and since the advent of AI, it’s only become more relevant.

**Over the past year, enterprise AI has shifted from simple chatbots to autonomous AI agents capable of making decisions and taking actions. How has that evolution changed the governance challenges organizations face, and why do traditional compliance approaches no longer scale?**

People talk about enterprise AI and its ROI as if the value comes from simply plugging an agent into your workflows. In reality, the value comes from connecting that agent to a wide breadth of systems, so it can synthesize data and produce outputs no human could pull together in the time. Access to data is the real bottleneck.

The catch is that the same thing making an agent valuable is what makes it risky. The more systems you connect it to, the more data starts flowing from one part of the organization to another, and every one of those flows becomes an opportunity for data to end up in the wrong place.

Every one of those flows needs to be checked: is this data allowed to be used this way, for this purpose, under privacy law and our own policy? When there are a handful of those decisions every day, a person can manually make each call. When there’s an AI agent firing thousands of requests per second, it becomes humanly impossible. That’s the point where traditional compliance breaks down.

For the frothy valuations of large AI companies to be realised, governance has to move to real time, at machine speed, at the moment the data is accessed.

**Ethyca is launching Astralis as a governance layer for enterprise AI. What specific customer challenges led to the creation of the platform, and why is now the right time to introduce it?**

The work of clearing data for AI still happens the way it did for privacy back in 2016, with people filling out questionnaires and running assessments by hand. That process was already too slow for ordinary privacy work, and against the volume of AI use cases, it stands no chance. Most of what’s being sold as AI governance right now is the same forms and workflows with an ‘AI’ label on it. Filling in a form is not governance. What’s missing is software that does the governance work itself, rather than producing a record of a person having done it by hand. That’s what we built Astralis to do.

The demand we’re responding to is coming from teams who have been told to ship AI fast and safely, and they currently can’t do both. Agents are going into production faster than any team can keep track of, and the question regulators ask has changed. It used to be whether you had a policy. Now it’s whether you can demonstrate that policy was followed on a specific piece of data, for a specific purpose. Most companies can answer the first question well. Very few can answer the second.

**Gartner projects that the average Fortune 500 company could be running 150,000 AI agents by 2028, up from just 15 in 2025. How should enterprise leaders rethink governance in a world where autonomous agents may outnumber human employees interacting with data?**

By 2028, the agents touching a company’s data will outnumber the employees who do. When the actors using your data are overwhelmingly machines, who is held accountable? The old model locates accountability in final human signoff but when the vast majority of those decisions are neither made nor reviewed by a human, accountability has to shift from people to systems.

Banking made this move a long time ago. We don’t trust a bank because a clerk is counting the notes by hand. We trust it because the controls are sound, and because there are people accountable for keeping them that way. Data governance has to do the same. The proof that a company handles data responsibly stops being that a person reviewed it, and becomes that the system enforces policy automatically on every use, and can provide evidence of this, so accountability is baked in. That will allow business leaders to focus on what they’re good at: applying judgement, setting the rules and standing behind the system.

**Astralis combines a Large Language Regulatory Model (LLRM) with Purpose-Based Access Control (PBAC). Can you explain how these two technologies work together to ensure AI systems understand not only who can access data, but also why they should be able to access it?**

Traditional access control checks who you are, and if your identity lets you touch specific data.

But privacy is different; it isn’t a question of who gets in. A person can be perfectly authorized to access a dataset and still use it for something they were never allowed to do. The question that becomes important is what the data is being used for, and whether that purpose is permitted. That’s what PBAC answers and enforces.

The hard part is that purpose isn’t a technical fact you can read off a database. It depends on what your business does, what you promised customers, and what the law allows. That’s what the LLRM is for. It learns how your specific business operates, then works through the regulations that apply to it. The output is a clear determination of what each kind of data can and can’t be used for. PBAC then enforces that determination at the point of access. LLRM reasons, PBAC acts.

**Your launch announcement states that AI assessments can be reduced from 40 to 60 hours of manual work to just 20 to 40 minutes. What portions of today’s governance process are most inefficient, and where does automation create the biggest gains?**

Most of those 40 to 60 hours aren’t spent on anything that needs human judgment. They’re spent on assembly. Someone maps the data by hand, keeps it in a spreadsheet, and then chases context across teams. By the time all of that is gathered, the actual assessment, the part that needs a person to think, is a small slice of the work. The rest is a professional acting as a collection agent for information the business already has, only it’s scattered across teams.

Frustratingly, it’s work that never stays done. An assessment is a one-time snapshot, but AI use cases don’t stop coming. New ones appear constantly, and each needs its own review. So the manual process isn’t just slow once, it’s permanently behind the pace the business wants to move at, and will become unmanageable as companies

The efficiency gains come from changing who does what. The system pulls the metadata itself, so no one is chasing context by hand. It only surfaces the questions a human can actually answer–the genuine judgment calls–instead of making a person grind through fields a machine can fill. And the audit trail builds itself as the assessment happens, rather than someone writing it up afterward from memory. That’s where 40 hours becomes 40 minutes.

**One of the more striking claims is that a major U.S. financial institution is processing roughly 6,000 governance requests per second through Astralis. What does operating at that scale teach you about the future infrastructure requirements for enterprise AI?**

The lesson is that governance can’t be a separate step anymore. At 6,000 decisions a second, it has to happen inside the data path itself, at the same speed as the queries and models it governs. For AI, governance has to be infrastructure: always on and always in line, not a report produced on the side. It has to be fast, because if governance is slow, it becomes the thing people skip to meet their deadline.

**AI regulation continues to evolve rapidly across both the United States and Europe. How do you build a governance platform that can adapt to changing legal frameworks without forcing enterprises into constant manual policy updates?**

The mistake most compliance tools make is baking the rules into the product, so when the law changes you’re stuck waiting on the vendor to re-engineer the tool. Astralis is built to work the opposite way. At its base is a common language for describing data and its uses, and it holds no rules at all. The rules sit separately, in a policy layer above it. The LLRM reads the regulation, works out what it means for your particular business, and writes the policy accordingly. PBAC then enforces whatever that policy says at the time–so a change to the rules leaves the enforcement mechanism entirely untouched.

When a new regulation lands, all of a company’s effort can go into working out what it means for their business; none of it goes into re-engineering their privacy systems.

**Many executives worry about rogue AI agents making unauthorized decisions or accessing sensitive information. How realistic is that concern today, and what practical safeguards should organizations implement before deploying AI agents at scale?**

It’s completely realistic, and it’s already happening. California fined Disney $2.75 million because its systems couldn’t reliably enforce something as basic as a customer’s opt-out. In their systems, a consumer who opted out on one device stayed opted in on the others, and browser-level opt-out instructions weren’t treated as valid requests at all. That incident wasn’t caused by an agent acting unpredictably, but was instead a pretty straightforward gap between what Disney told customers and what its systems were capable of enforcing.

The safeguards that actually prevent this are unglamorous: know what data you hold and what you’ve committed to about it, and hold it all in one place, because most of these failures come from one team’s promise never reaching another team’s database.

**Looking ahead three to five years, what do you believe will distinguish enterprises that successfully operationalize AI from those whose AI initiatives remain stuck in pilot projects, and what role will governance play in creating that competitive advantage?**

The difference will come down to whether a company has one system to govern all of its data, or if they choose to staple governance onto each database and team separately. Companies still governing their data department by department will keep hitting walls, because AI reaches across departments by design. Every enterprise is being told to ship AI quickly and not end up in a regulator’s letter, and until now those two have pulled against each other. Whoever solves both, instead of settling for one, will win the decade.

*Thank you for the great interview, readers who wish to learn more should visit Ethyca or Astralis*

**.**
