Video summary
The video features a conversation at Workiva Amplify 2026 with Josh Robinson, the Chief Audit Executive of Vast Space, focusing on the integration of AI agents into the workplace and their implications for internal audit. Vast Space is an aerospace manufacturing company based in California dedicated to making human space travel commercially viable and safe. As AI agents increasingly take over tasks that were previously performed by humans, operating at greater speed and scale, a primary concern for auditors is maintaining control and understanding the probabilistic nature of these systems. Josh highlights that while AI effectively handles redundant, repetitive, and mind-numbing tasks, freeing up human brainpower for more strategic work, it introduces new risks related to opacity. The challenge lies in ensuring auditability when traditional evidence like handwritten notes or email chains is replaced by automated processes, requiring auditors to look deeper under the hood of these complex workflows.
To address these challenges and establish necessary assurance, Josh advocates for a return to foundational auditing principles centered on completeness and accuracy. He suggests breaking down multi-step AI workflows into individual components to validate each stage along the chain, thereby painting a comprehensive picture of the agent's actions. Furthermore, he emphasizes the importance of stress-testing Large Language Models (LLMs) with known data to verify their outputs before extrapolating results to broader audit tests. Despite these emerging methodologies, Josh notes that human judgment remains indispensable; auditors must not blindly rely on AI but should instead use technology to streamline evidence gathering and allow humans to focus on high-value analytical work. In the current early stages of this evolution, a hybrid approach is necessary where leadership conducts detailed reviews of both junior auditor and AI-generated work to ensure conclusions are sound before reaching a state of full reasonable assurance based solely on AI.
Accountability and governance emerge as critical themes, with Josh drawing an analogy to President Harry Truman's famous "the buck stops here" philosophy to define ownership of decisions made by AI systems. He asserts that while business users or IT teams may provide inputs, the ultimate responsibility for data integrity and decision accuracy rests with the audit leader who signs off on the workpapers. This stance implies a significant increase in scrutiny during the initial adoption phase, where organizations must double-check outputs to prevent errors caused by over-reliance on AI. However, Josh believes that internal auditors are uniquely suited for this task due to their inherent professional skepticism and holistic understanding of business operations. He argues that while this rigorous oversight may initially seem burdensome or costly, embedding strong governance early on acts as a facilitator for long-term business success, preventing safety incidents and ensuring resilience even if it takes two years to realize the full return on investment.
Finally, the discussion touches upon the specific high-stakes environment of the aerospace industry, where human lives are at stake, necessitating a conservative approach to risk management and safety protocols. Josh explains that while AI tools are used to enhance efficiency in building space stations and managing operations, there are deliberate pauses and controls to ensure astronaut safety is never compromised by algorithmic errors. The conversation also highlights Workiva's role as a potential solution provider that can connect disparate technology stacks and data sources to create unified, intelligent agents capable of solving complex business issues. By streamlining processes and integrating contextual knowledge from various applications, such platforms aim to help organizations navigate the complexities of AI adoption without sacrificing compliance or safety, ultimately enabling businesses to move faster with confidence while maintaining robust guardrails.
Read the full video transcript
Welcome back to WAKA Amplify 2026. We're
coming to you live from Las Vegas. I'm
Allison Caic alongside Christa Case and
we're about to get into a great
conversation about how AI agents,
they're moving into the workplace.
They're doing work that humans used to
do and it's kind of leaving the
question, are we going to lose control
here?
>> Absolutely, Allison. It's I think
something that's keeping a lot of people
up at night. Um and I think when it
comes to establishing that control um
you know auditability um is something
that's really important. I know we were
talking about that in our keynote
discussion um earlier this morning but
being able to make sure that again we
have that audit auditability especially
given that you know agents change the
game versus kind of when it's just
humans taking action agents can operate
much faster at much greater scale. And
so I think that has a lot of ripple um a
ripple effect on on their audit
processes.
>> Yeah. Yeah. All right. Well, let's get
into it. I want to introduce Josh
Robinson. He's the chief audit executive
of Vaspace. Welcome to the cube.
>> Hi, good morning. Thanks for having me.
I'm really happy to be here.
>> So, talk us through first what Vast
Space does.
>> Yeah. Yeah. Uh so, Vast
>> and your role with them.
>> Absolutely. So, um as you mentioned, I'm
the head of internal audit at Vast
Space. Uh it's an aerospace
manufacturing company that's based in
Long Beach, California. Um and we are uh
trying to make human space travel
relevant for the future. It you know the
future in this area is changing. It's
becoming more commercial and VAST is at
the forefront of making humans go back
into space. So it's a really really
exciting industry to be in right now.
>> Oh. So let's let's kind of start with
the big picture here. AI agents as I
said they're increasingly you know
making decisions and taking actions that
humans once did. I'm curious what
worries you the most from an audit and
from a risk perspective.
>> Yeah. So there's a couple of things. I
think first and foremost as you alluded
to AI agents are now doing the work that
humans really didn't want to do in the
past. So I want to start with the
positives in in so far that you now can
have you can have tasks that were
redundant, repetitive, mind-numbing or
boring that a computer is now doing. So
what I to answer your question what I
like to think how I like to phrase this
is mitigating the good with the bad. So
there is a lot of positivity because
we're re we're reallocating human brain
power to something that makes more sense
to to utilize that human brain power.
Now from a risk perspective and as an
audit executive as someone who's
reporting to boards who's dealing with
external audit firms what we're trying
to understand is how do we understand
the probabilistic nature of that AI and
making sure that okay with humans we
could understand they were using their
judgment they were exercising
probability but we could see it there
was either handwritten notes or there
were tick marks or or there was email
chain or slack messages that has all
been removed from the equation.
So for me the risk is in the unknown
what's happening underneath the covers
that we need to look into more and the
good news is particularly some of these
agents the workflow capability the audit
trails are becoming more and more robust
and complex over time that allows us to
look under the covers but to be clear
that risk still exists and and I think
the profession of full cander is still
trying to understand how to mitigate it
but like I said because of the ROI on
the human factor um it's an acceptable
risk and I think that's why companies
are leaning leing into it so much.
>> Yeah, absolutely, Josh. I'm hearing that
as well from both, you know, security
practitioners as well as risk
practitioners that the need for
enterprises to embrace AI has changed
the whole appetite for risk for the
business. But as you're alluding to,
Josh, you know, we still need that
observability and auditability. So if
you take a step back and think maybe
conceptually,
how do you think about you know laying
the groundwork to be able to have that
level of assurance given the fact that
with these AI agents we might not be
able to have that kind of you know that
that full observability and control over
every action that they're taking? Yeah,
that's a great question. And for me, I I
like to just go back to foundational
fundamental auditing. And one of the
things that's been we've been harping on
in our profession for a number of years
now is this concept of completeness and
accuracy. If you can demonstrate
completeness and accuracy as an auditor
generally that uh allows you to reach
conclusions about the assurance of data
sets or or audit tests you're doing. So
there are ways and again we're still
developing these in the profession to
demonstrate completeness and accuracy
around the work that agents are doing.
So for instance, if an agent is a
multi-step workflow, you're it is
potential there is excuse me, there's
possibility to chunk it out into let's
say there's five different steps and
validate the completeness and accuracy
of each one of those steps along the
chain that allows you to paint a bigger
picture as to okay the five things that
accomplished were indeed complete and
accurate representations that allows us
to reach a level of assurance.
Similarly, there are the concepts of
testing like LLMs to be like, okay,
let's let's stress test this or sanity
test it. And if we put in data and it
spits out what we'd expect it to, we can
then extrapolate that to a a more
traditional audit test. So, and again,
we're still testing the waters on these
things. But I do think these are
different ways for us to still reach
that level of comfort. And of course it
still takes time and effort but you're
just you're reallocating it in such a
way to still maximize how these agents
are able to maximize these processes.
Yeah, absolutely Josh. I think you know
to your point you know definitely we're
still early days and I think in
navigating you know all of these
challenges
one thing so as you're kind of talking
through this audit trail you know human
auditors are already strapped for time
right so how again conceptually how do
you think about beginning to you know
approach that problem can we maybe use
AI to start you know making taking some
actions on our behalf um and if so you
know what what are you looking for in
terms of you know trusting the AI to
potentially take some action?
>> Sure. Sure. Yeah.
>> So I think so going to the root of the
question auditors being strapped for
time and this is a big answer but in my
humble opinion you need to think about
the entire entire audit life cycle and
figure out where you can use technology
to remove redundancy or time syncs. And
so for for me and my current
organization, what we talk about is how
do we introduce AI into operational
processes that then have that trickle
down effect of making your audit
processes more simple because the
evidence is is easier to gather. The uh
information around the IP the
information provided by the entity is is
validated for completeness and accuracy.
That way auditors even if they're not
using AI spend more time doing you know
human you know brainpowered work rather
than oh I got to tick and tie and put
put evidence together. So that's one
thing. Now in the audit life cycle
itself and again still very much testing
the waters on these things. But for me
as an audit leader, what I'm what I will
be doing when we implement these
technologies is making sure that my
auditors are still exercising judgment
where it's necessary and not blindly
relying on AI or aentic AI to solve
problems for them. And then I think at
least in these early years and I'll say
years who knows how many years it'll be.
It'll be having leadership do detailed
reviews evaluations of audits work of
junior auditor's work of Agentic AI's
work to make sure that we would reach
the same type of conclusion before going
to that reasonable assurance model just
solely via the the AI. So I it's I think
it's a heavy-handed mix right now of
getting the entire life cycle in a
better place to make it more efficient,
but then making sure humans are still
inserting themselves appropriately until
such time we get that level of comfort
we'd expect.
>> Digging a little deeper into the
governance piece of this, one of the big
questions is AI accountability. You
know, if it makes the wrong decision,
you know, who owns the data? Is it the
technology team? Is it the business
unit? Or is it the person who is kind of
overseeing the process? Wow, that that's
a really loaded question, Allison, but
here here's the thing. As an audit
leader, I I love to use the analogy.
It's and I I say this to people and it
feels so old school, but it's the old
the buck stops here analogy. So Harry
Truman, when he was president of the
United States, had a big placard on his
desk and he's like, "Decisions come to
me. I own those decisions." That's what
I tell my team. So yes, there there are
going to be inputs whether it's a
business user, whether it's an IT user,
but if we're using data, I my team, you
need to make sure it's right, it is
complete, it's accurate, you've vetted
it, and the decisions that we're making,
the workpapers that we're initiing, you
know, digitally initially these days,
you stand behind that. So from my
perspective, and again, there's probably
a lot of conflicting thoughts about
this. As an audit leader, if it comes to
my desk and I'm going to put my
signature on it, I I it pretty darn well
better be the right answer. But and of
course it that would be a collaboration.
You know, we can still look to it like,
"Hey, by the way, this didn't solve
right." We can still look to the
business. You applied this agent wrong
or you didn't do diligence on the agent.
That's okay, but I'm going to own making
sure that happens.
>> Wait, so is that does does the AI factor
of this wind up creating more work for
you because if if others who are
creating this who are in the process in
the process of creating whatever that
document, they rely on AI too much.
you've trusted them and didn't and you
don't realize that they're relying on
AI, not checking, you know, dotting the
eyes and crossing the tees. Is this just
because it's causing you to to look over
everything more?
>> I think that's Alison, I think that's a
great question and I think it's a very
astute observation. I think in the early
days the answer to that is resoundingly
yes. However, I humbly believe that
internal auditors as a profession are
very well suited to take on that level
of effort because we've got the
professional skepticism built in. We've
got the the knowledge of companies at a
very holistic level built in. We've got
the relationships with people to help
solve for that built in where we can do
it. But, you know, at the end of the
day, if that were to happen, if if I was
to start billing a bunch of hours like,
"Oh my gosh, we're we're telling people
what they did wrong. We're
double-checking. We're we're blowing
budgets on audits." I think
fundamentally comes down to how are
organizations handling AI governance at
like their like entity level making sure
that's appropriate because again I think
the knock-on effect of that would reduce
the types of challenges you just said.
So again very complex answer in today's
like immature environment but I humbly
believe internal auditors are up to that
challenge that can make businesses
better as we solve for that. Yeah, and
kind of as I'm reflecting on what you
were just um you know talking about
Josh, I'm kind of thinking about the
role of audit in terms of actually with
time allowing the organization to move
faster in terms of adopting AI. So, you
know, would you agree with that in terms
of making sure that those kind of guard
rails and those audit capabilities are
in place up front? It might take a
little time to get it going, but again
with time
>> Yes. So couldn't agree with you anymore.
And and I think well-governed
organizations, AI governance has been
top of mind for them for for years now.
And to your point, and it's interesting,
as you might imagine, everyone who's in
an audit space has this battle. But good
governance is a facilitator of good
business. Whether that's business that
goes with high velocity, whether that's
business that treads with caution but
makes the right decision, it doesn't
matter. Good governance b is baked into
that. There's a lot of leaders who I've
dealt with over my career who would say
that's not true. I I respectfully
disagree with them, but exactly to your
point, you bake in good governance, it
facilitates success, even if it takes
time, and it does take time, even if the
the ROI is two years of of pain. I I do
think you can have very meaningful
conversations after that two-year period
to say, look what we built together and
how it's facilitating our strategic
success. Absolutely. Yeah.
>> Absolutely. And Josh to circle back, we
were talking a little bit about kind of,
you know, the context and and the
knowledge that humans bring to the
table. And you know, we heard at the
keynote here, we're obviously here at
Work Amplify. We heard at the keynote
this morning about kind of work even
knowledge and kind of what work is doing
to be able to, you know, connect some of
these different systems and applications
um and maybe help to facilitate some of
that contextual knowledge that AI will
um will need. My understanding is that
you've been aware customer for almost 10
years I think since 2017. Yeah. So I
guess maybe if you could comment a
little bit on um you know the role that
you see potentially playing in that
regard especially with announcements
like knowledge.
>> Yeah. So I have been a longtime customer
and obviously advocate for for the
platform. I'll tell you when I saw the
keynote both yesterday and then it was
continued this morning I I'm really
excited by what they're bringing to the
table and I'll let me tell you why
before I get into work specifically you
guys know this because you meet so many
folks every technology firm around the
planet is figuring out how they can in
implement or you know it bring inhouse
AI to help solution for create solutions
for their customers however in my
opinion I haven't seen any firm really
try to step outside of that box and say,
"Let me try to solve problems for you
that are created by having disperate
technology solutions with disperate AI
solutions." And I think what work has
demonstrated through their their
announcements from yesterday and today
is that they want to be a thought leader
in that space. So what I'm really
excited about is seeing how their
technology can take disperate data
inputs, it can interact with LLMs that
companies are using, no matter which one
it is, and then help create a gentic AI
that solves business issues drawing from
those various sources. So again, I
haven't had a chance to use it yet, but
I've had a chance to see it. And I think
I'm actually genuinely excited because I
think we're finally seeing a company
that's going to help solve. I can go to
my CFO and be like, okay, we use the
likes of a Netswuite and an HS and this
and this and and this is our data lake
and you know we're using Claude, but now
look at Worka who can connect to those
five different things, bring it in and
create agents simply that are is going
to solve XYZ problem for you. I think
he'd be just as excited as I am. So I
think it's a really cool thing that
they're they're introducing right now.
>> Yeah.
>> So streamlining certainly super
important.
>> Absolutely. Yeah. I think because look,
yeah, the best way we want humans to to
better utilize their brain power to make
strategic decision-m and the best way to
do that is to streamline these processes
or functions that simply don't require
that level of effort. And I think what
we're demonstrating is we're getting
there. We're we're we're finally getting
there. So, yeah.
>> So, Josh, I'm curious to kind of double
click on so obviously VAST, essentially
a commercial space station company like
you were talking about earlier. We've
been talking a lot about, you know,
audits and I think there's obviously
compliance implications there, but
especially in an industry such as, you
know, what you guys are in and what you
guys are doing, there's safety concerns
potentially. There's bigger risk beyond
just complaints. So, can you talk to,
you know, I guess some of those risks as
a result of potentially control gaps,
you know, in this process?
>> Yeah. Yeah, that's a great point. So,
you're exactly right. this industry that
that VAS operates in is highly regulated
and of course there are like and like
many industries there are human lives at
stake. So we take at our organization
risk management incredibly seriously. I
I think and one of the things is again
I'm newer head of internal audit this
organization is trying to bring together
disperate risk leaders to create more
holistic enterprise level risk
assessments and risk management programs
to help solve for what you're just
saying. But to your point, at least and
look, I can't speak for those risk
leaders cuz they're not here. But I
would say that particularly when it
comes to safety, occupational safety,
safety of astronauts that are eventually
going to be flying, the company takes a
more conservative approach. As you might
imagine, we are trying to we're trying
to win contracts. We're trying to get
humans back into space, but when it
comes to that aspect, it's very
conservative. So AI, agentic AI or or
LLM, it's part of the process to help us
build, but to be clear, there are very
much like let's let's hit pause and make
sure we're doing the right things to
keep our astronauts safe. So but to your
question, I think enterprise level risk
management programs help bring together
all the different players to make sure
we're addressing those things
holistically instead of something
getting missed or or you know
overrelying on AI and then all of a
sudden a safety concern does bubble up.
>> Yeah. Yeah.
>> Absolutely. And I think for all those
reasons, but also Josh, I would imagine
even in resilience for, you know, core
business functions, you know, like you
say, getting astronauts into space,
especially as, you know, AI agents are,
you know, taking action. So there's
things like we need to make sure that we
can reconstruct, you know, certain
decisions that were made, you know, we
make sure that we have the logs that are
founded in them. So again, it even has
kind of a resilience implication. At
least that's what we're saying.
>> No, I I think you're absolutely right.
And I would say that at my organization,
we're I think we're using AI tools to
help that. Now, I wouldn't consider it
agentic AI or probabilistic AI, but to
to your point, the technology is so
versatile, but but yes, absolutely. I do
think that's helping us be more
efficient in in keeping our astronauts
and our our team who's building a space
station safe. So, yeah, absolutely.
>> Wonderful conversation, Josh. Thank you
for stopping by the Cube. We appreciate
it.
>> Thank you. It's a pleasure to meet you
guys. Thanks so much.
>> And you're watching the Cube, the leader
in live tech coverage and in-depth tech
analysis. We'll be right back.