Kristin "Kris" Lovejoy has spent her career inside the systems the global economy runs on: banks, hospitals, energy grids, governments. Today she is Global Head of Strategy at Kyndryl, the world's largest IT infrastructure services provider, working with mission-critical enterprises across more than 60 countries. Before that she ran security businesses at EY and IBM, founded the AI security company BluVector (acquired by Comcast), and now sits on the board of Dominion Energy.
Her prediction: the first fully autonomous AI attack, where an AI takes down an enterprise network with no human driving it, lands within 18 months.
Conor and Kris dig into why 62% of enterprise AI initiatives are still stuck in pilots even as spend climbs 33% year over year, why attackers chaining low-risk vulnerabilities changes the patching math, and why she has a fraught relationship with policy as code.
We cover:
The electricity analogy: we can build the models, but the transmission lines for industrial AI don't exist yet
Productivity AI vs mission-critical AI, and why banks and healthcare systems aren't running agentic AI at production scale
Why deterministic policy as code clashes with autonomous systems, and "human on top" vs human in the loop
The 18-month prediction: chaining low-risk vulnerabilities, outcome-oriented agents that take systems down by accident, and insiders armed with AI attack tools
The data center build-out from a Dominion Energy board member: PJM load forecasts that miss by double digits every year, water use, density, and rack optimization
Privacy as a double-edged sword: data combinations that suddenly become PII and the shift to continuous compliance
What's next: open source everywhere, sovereignty as control, autonomous robotics, and quantum
Chapters:
(00:00) Meet Kris Lovejoy: Kyndryl, EY, IBM, and Dominion Energy
(02:09) Why 62% of AI initiatives are stuck in pilots
(03:07) The electricity analogy: models without transmission lines
(04:23) Productivity AI vs mission-critical AI
(06:53) Vintage systems, hybrid data, and the risk gap
(11:03) Policy as code and "human on top"
(16:25) Data centers, energy, and the grid build-out
(24:44) Data center design: density, cooling, rack optimization
(26:54) Privacy, continuous compliance, and sovereignty as control
(32:06) The first fully autonomous AI attack: 18 months away
(38:06) Predictions: open source, robotics, and quantum
(42:32) Control planes for agentic AI: closing thoughts
Connect with Kris Lovejoy:
LinkedIn: https://www.linkedin.com/in/klovejoy/
Kyndryl: https://www.kyndryl.com
Connect with Conor:
Newsletter: https://newsletter.chainofthought.show/
Twitter/X: https://x.com/ConorBronsdon
LinkedIn: https://www.linkedin.com/in/conorbronsdon/
YouTube: https://www.youtube.com/@ConorBronsdon
More episodes: https://chainofthought.show