
GRC AI Labs: What We Heard in Boston and Chicago
Two more stops on the tour, and the questions in the room keep getting better.
After our first GRC AI Labs in New York, we wrote that the power of AI has to be felt, not just talked about [link to NYC blog]. Two more Labs later, in Boston and Chicago, that conviction has only sharpened. The format was the same in both cities: Enterprise GRC leaders sitting down 1:1 with our team, co-building a custom AI Agent around a real problem, then watching it run. And once again, every session ran over.
What we kept hearing
Whatever the session was about - vendor risk, AI governance, risk visibility, audit preparation - the same refrain came through. The workload is increasing, and the AI tools teams have today aren't cutting it. Credit where it's due: they help teams get through some elements of the work more quickly. But there was a clear feeling in both cities that more should be possible. Attendees kept pointing at what's already happening in fields like LegalTech, where agents run whole pieces of work rather than speeding up fragments of it, and asking what the equivalent would look like for GRC. They weren't skeptical of the idea. They were hungry to see it.
In the rooms
That's what the sessions were for. Each attendee brought a real process, and together we built the Agent around it: their criteria, their thresholds, their guardrails. Then we set it live and watched it run, reasoning visible and every action traceable.
.jpg)
Somewhere in each build, the framing in the room shifted. Attendees arrived thinking about AI helping their team, another tool to speed things up. Watching an Agent complete a workflow end to end, they started talking about AI doing the work: for GRC teams and for the business owners they chase, carrying the repetitive load rather than packaging up information for a human to act on. Seeing the proof in front of them, on their own process, is what moved the conversation. No demo of someone else's data does that.
The question changed
By the end of each session, the conversations were somewhere new: not whether AI could help, but how much of the work it could take on, and where next. Attendees pushed into use case after use case. Nowhere was the appetite clearer than in vendor risk, where attendees wanted ongoing monitoring and evidence-based assessment over static, point-in-time questionnaires. The pattern underneath it all: let the Agents carry the repetitive work, on the team's own criteria, and give the team its time back for the judgment calls only they can make.
Where the tour goes next
That change of question is the real signal from the tour so far, and it's why we'll keep building in person, city by city. The format stays the same everywhere: come with a problem, leave with an Agent, and see first-hand what AI really changes for you. Boston and Chicago, thank you. Next stop: a city near you.
