top of page

|

16.png

Leading with Integrity in the Age of Agentic AI: lessons from inside Microsoft

7 Jul 2026

A recap of our Week of Integrity webinar with Susan Du Becker, Director Risk & Compliance at Microsoft.

Leading with Integrity in the Age of Agentic AI: lessons from inside Microsoft


A recap of our Week of Integrity webinar with Susan Du Becker, Director Risk & Compliance at Microsoft.


As part of the build-up to the Week of Integrity 2026, we hosted a webinar that many of us are still thinking about. “Leading with Integrity in the Age of Agentic AI” brought together an audience of compliance, legal, risk and governance professionals for an hour with Susan Du Becker, Director of Risk and Compliance for Microsoft’s Supply Chain Hardware team. The conversation was facilitated by Andrea Cardoso. Susan has spent years working on responsible technology inside one of the companies that helped build AI, and she brought a rare mix of hands-on experience and plain speaking. What follows is a recap of the ideas that stayed with us, and why they matter for the theme of this year’s edition, Leading with Integrity in a Digital Age.


Don’t be afraid, but don’t run before you can walk


Susan opened by describing her own journey into AI. Like many compliance professionals, she was focused on anti-bribery and corruption when AI arrived and, with it, a wave of enthusiasm about productivity and efficiency. She described the early feeling of trying to catch hold of “a wild beast.” Her advice to the audience was measured. “AI is a tool and AI is here to stay,” she said. “Don’t be afraid of it.” But she was equally clear that the danger is not caution, it is speed. Her recurring phrase throughout the hour was simple: don’t run before you can walk. Introduce AI, experiment with it, but keep your eyes where they need to be, and keep human oversight in place.


Security matters, but don’t forget people


One story captured the point better than any framework. A healthcare organisation, Susan recounted, built a staff scheduling app. It was, on paper, excellent. Staff could see their shifts at a glance. It was launched with fanfare and rolled out to everyone’s phones. And it immediately caused problems, because it had not taken account of a basic human reality: people have constraints. One person can only work certain days, another only certain shifts. The app ignored all of that. The result was real distress among staff, the app was withdrawn, and the organisation had to rebuild it. Even then, no one wanted to use it, and it took nine months to win people back. “There are ramifications for doing things too quickly without proper oversight,” Susan said. Security, she noted, is rightly a first concern, but “a lot of companies forget about people” in the rush for efficiency. Responsible AI, in her telling, is precisely the discipline of asking who and what a system affects before it goes live.


Agentic AI is not ready to be left alone


The conversation turned to the case many in the audience had read about: the Replit incident, in which an AI coding agent deleted a live production database during a public experiment, ignored explicit instructions, acted without permission, and then fabricated records to fill the gap. Susan was careful not to single out the company, which she respects, but she was direct about the lesson. “I don’t think we’re there with agentic yet,” she said. The appeal of agentic AI is that it can act on its own, build the thing and let you walk away. Her warning was blunt: no, you can’t. You can give AI room to move, “but you have to have oversight. I don’t care how good you are.” The Replit case matters, she added, because if it can happen to a company of experts, it raises the honest question every other organisation should ask: what about us?


Integrity belongs at the start, not the end


Asked where ethics and integrity fit into all of this, Susan gave perhaps her strongest answer of the hour. “Ethics and integrity should be there from the word go. I don’t think they come in anywhere.” Too often, she said, they are treated as an afterthought, something to check once the tool is built. In her view responsible AI is, at heart, about cause and effect: what does this do to you, to the business, to your neighbour? And it need not be complicated. Sometimes integrity is simply “spending time, five minutes, just thinking it through,” and taking the trouble to discuss a decision with the people it will affect. The scheduling app failed, she pointed out, not because of a technical fault but because no one paused to consider the human effect.


Governance beats gadgets, and no single function owns AI


Susan’s practical advice was refreshingly unglamorous. “One tool does not solve everything,” she said. Organisations chasing a single silver-bullet product, or boasting about thirty or forty AI programmes, worried her. “I’d rather deal with a company that had three or four really solid programmes with real integrity than somebody rattling out numbers left, right and centre.” Her own answer was structure rather than software: a small Centre of Excellence and an AI register, so the organisation can see what is being built, spot duplication, and catch gaps early. It was exactly such oversight, she said, that surfaced a security concern in her own team. And crucially, this is not a job for one department. “It’s not run by Fred from IT. It is a governance across all functions, because you all have a stake in it.” Every AI decision has a knock-on effect somewhere else, so the work has to be cross-functional by design.


Where regulation ends, culture begins


The webinar’s subtitle promised to explore where regulation ends and organisational culture begins, and Susan met it head on. She was honest, as a European, that current AI regulation is relatively weak, and that it will always lag behind business, which moves faster. But she refused to treat that as licence. “If we, as companies, do all the wrong things, the regulators will create more and more rules.” The responsibility to act well, she argued, sits with organisations themselves. She cautioned against over-pivoting on regulation and stifling business, while insisting that self-governance is “our destiny as well.” It was a fitting encapsulation of the theme: rules will only ever take you so far, and the rest is culture, judgement, and the willingness to stop and ask whether you are doing things the right way.


Bringing people with you


A thread ran through the audience’s questions: how do you bring people along? Susan’s answer was to explain the why rather than fall back on “because I said so,” which only sends people looking for a way around the rule. She spoke warmly about learning from younger colleagues while helping them understand why, for example, data privacy matters. Her test for making an abstract risk real was memorable. Ask someone for their bank balance, their savings, whether they have paid off their mortgage, and they recoil. Yet the same people hand over personal data without a second thought. “It’s just held a different way.” The job of anyone who understands AI, she said, is to help others understand it too, because “people can only move as quickly as the slowest person.”


A way of working


The conversation could easily have run another hour. What made it valuable was not a set of predictions but a way of working: curious, cautious in the right places, and unafraid to slow down. That is the spirit of the Week of Integrity 2026 and its theme, Leading with Integrity in a Digital Age. Thank you to Susan Du Becker for the time and the honest conversation, to Andrea Cardoso for guiding it, and to everyone who joined. The main week runs from 26 to 30 October, and we hope to see you there.


Watch the webinar:






bottom of page