AI is already making its way into Managed File Transfer, but what can be achieved today, and where can it add real value?
In this episode of The Transfer Files, Steph and James continue the conversation around AI, following their discussion with Rob May, Founder & Executive Chairman of ramsac and Global AI Ambassador last month. This time, they’re honing in on integrating AI with Managed File Transfer. Joined by returning guest Richard Auger, they explore how artificial intelligence is being used across MFT technology, and where the biggest opportunities are emerging.
The discussion looks at some of the practical capabilities that can be achieved in MFT platforms today, from using AI for custom reporting and natural language queries to Data Loss Prevention, compliance, and workflow automation. The conversation also explores the relationship between AI and MFT automation, how enterprises should approach their AI in MFT strategy, and where AI can deliver real value alongside existing automation. Plus, find out the coolest thing Richard has seen AI do with Secure File Transfer.
Watch the episode to hear how AI is already being used with MFT. And if you want to explore what AI could do for your own MFT environment, get in touch with one of our AI Integration Specialists can help you identify practical opportunities, connect your AI technology stack with your existing file transfer workflows, and develop a long-term approach to AI integration.
-
Discover how to harness the power of AI today to get more from your MFT platform. Watch our on demand webinar.
Welcome back to another episode of The Transfer Files. In a previous episode, we were joined by Rob May from Ramsac where we explored the rapidly evolving world of AI. If you haven't listened or watched that one yet, it's definitely worth going back to and we will make sure to link it below as today's conversation builds on that discussion. Joining James and I is returning guest Richard Auger as we explore how AI can be applied specifically to MFT and what the future could look like as these technologies continue you to evolve. Let's get into it. Richard, welcome back to the podcast for a third time.
Third time, third time lucky.
Third time lucky. How are you doing?
Okay, thanks.
Good. And James, how are you?
I'm very good, thank you.
Ready for another episode?
Indeed, with my, I was going to say able assistant, but actually you're on the show. I'm not so sure I'm able. Let's carry on. Let's move on.
Happy to talk about today's episode, which is kind of a part 2 off the back of the conversation we had last time, which we had Rob on. We spoke to him about AI, more of a general view of AI, what he's doing with businesses and what he's seeing in that space and how businesses are adopting it, what risks they need to be aware of. What we didn't really go into detail on that conversation is AI in MFT and what we're seeing in that space because we know you have been experimenting a little bit and doing some research and you have some knowledge that you are keen to share today. We are keen to hear it.
Thank you.
But first, I think a good place to start because a lot of vendors in MFT, a lot of software vendors out there are doing their own thing when it comes to AI. There's a lot of noise going on about features that they're directly building within the platform themselves. And I don't know if we can talk a little bit about, from what you've seen, what's being built, how useful is it, and what are clients going to be seeing in the coming months, years?
The state of play at the moment is there are some vendors out there that have put AI into their platforms. There are some vendors who are planning on putting AI in their platforms. They're going through the testing phase. There's been over the last few months, there's been a number of queries from the different vendors saying, what sort of things would you like to see? And perhaps now we've got the results of those coming through. So predominantly, What I'm seeing is it tends to be they have made changes to the administrative platform that you run your MFT on. There are some things that have gone into workflows, but mostly speaking it's for the administrator, it's for the auditor, it's for the security officer, this kind of thing. So we're seeing The obvious one everybody seems to be jumping onto is custom reporting and putting that into the platform. And that's a really nice thing to have because it's running off of large language model. So you can speak natural language into your query and say, show me all the failures in the last week. And it can bring that back to you. But there's a cautionary tale in there as well. Because each time you run one of these LLMs to get your custom query that you're going to put in there, obviously there's a token cost that's going on there, but the query is going to be the same query that you ran the week before. So some of the vendors are allowing you to save those queries once you've generated it. So you're using AI to generate the query and then following that you can just use those results over and over again. Whilst others, you're just paying AI each time and doing the same thing. And it's a bit repetitive. So that's one of the first things.
That's just interesting. So you say some vendors are letting you use one token and then you can use that same query over.
Again. Yeah, I mean, it's a bit more than a single token whenever you do anything AI, but yes, you've got the gist there. So A one-time hit on your pricing and you save it, hey, I bought that now, I can use it again and again, rather than forcing you to pay every time.
Interesting.
And yeah, take it into context of not all of the vendors are letting you select your own AI. So, if they are forcing you down the route of having a specific AI, then the money is going through the vendor for that token cost. If you've got something local like Ollama, then that could be doing it for free for you and then you don't really care at that point, apart from general CPU costs, running a computer, the resources and so on. So there's a little bit of a cautionary tale of, don't perhaps jump in too deep without seeing what the long-term cost of these things are. There are some bits as well that are quite nice. Building of workflows. So whenever you want to do a new deployment, you want to start taking files from point A to point B, doing some stuff in the middle. Some of the vendors will let you now use LLMs to describe what you want to do. So I want to pick up a file from this folder. I want to encrypt the file. I want to send it out to this SFTP server. Being able to describe all of that in plain text is great. And I'll probably circle back to this later, but I can see that's going to be a way forward in the future. But you know what? You can already do that yourself without using the solution with the software. I can go to ChatGPT or Copilot and say, write me a workflow to do this, to work in this product. And it will give me the XML code or the JSON that I need to just import in. That works too. So that's, you know, again, do you really need to have that in the software? You're only really going to use it the first few times, then once you start to understand what's going on, maybe you wouldn't bother with it. It'll be useful, be interesting, but we'll wait and see how that pans out in the wrong term. Now, aside from that, everybody loves, we said custom reporting, but everybody also loves doing something with compliance. Okay, and your compliance could be, tell me if my system is configured to meet this regulation. So here in UK we're doing GDPR. It's open to interpretation. You can either get the AI to interpret this and tell you yes or do this, that, and the other, or some of our vendors already provide that information without going as far as the AI. But they'll put it into an AI model for you too so that you can really get like a second opinion on the thing. But again, it's a cost and it should be something that's everybody for. Most configuration on software is either held in a file or it's held in a database table, one of the two. And we can very quickly simply check, say, does it meet these criteria, blah, blah, blah. It's just if it meets the interpretation of the software vendor, all well and good. As well as that in compliance, though, and perhaps the best thing you can stick into a workflow is a DLP checker. So if we want to look for data loss prevention, rather than calling out to a DLP program or going via ICAP, you can call AI. It's straightforward. Some of the vendors are doing it, some of them haven't. So it's a bit of a mix. But if you've taken one of the vendors that doesn't provide it, you know, this is the sort of thing that you could be doing in a workflow on your own. And maybe we'll talk about that in a bit. Other things that vendors are currently doing is summarising data that's in a file. Don't know that I really like that one. I mean, I like it for, let's say, an ad hoc process. Somebody sends a big file through my secure transfer and it's a person-to-person type file. That might be nice to get a little e-mail summary of what the file is about. But in a batch world, it doesn't work, doesn't bring anything to it. And also I've seen in at least one of the vendors, the ability to pull fields out of a file so that you can make some decision about routing. I mean, that's nice to have into AI, but again, it's one of those things that you don't really need. It's been there forever and a day with the fact that I can just look at a header record and send a file this way or that way. So some of it, I think we're just seeing, we've got some AI, we're going to throw it at the wall and see what sticks. Some of these little features will stay and some will go.
It won't be used.
It's interesting. a lot of what you just mentioned there is native to the software in most instances. So not really getting a lot of bang for your buck other than paying some additional charges for something that it can already do on the proviso that you know how to configure it.
Yes. And that I think is probably what I'm going to come back to again and again today is Yes, you can use AI, but should you use AI? It's there just because it's there. We don't have to make use of it for absolutely every single thing. But there are a load of uses that aren't yet being explored and will be.
Yeah, that leads me on nicely to my next question. I know you've been going a step further in terms of looking at what's possible with AI right now and what clients can be doing without needing to wait for software vendors. I wonder if you can talk to us a little bit about what you've found and what can be done now without needing to wait.
So of course I don't have access to backend source code or to do anything with the actual applications, the various softwares that we work with. And as a consequence, I've been working inside the workflows themselves, where we're moving files from point A to point B. And I've been communicating with AI, in my case, OpenAI, using rest post calls to actually pass the information backwards and forwards. One of the first ones that I played with and took a stab at was writing my own DLP checker. And it's quite simple to do. So you're basically you're talking about passing a guardrail into the OpenAI, which is 1 big section of code, and then telling it the information that you want to look at. And if you can imagine, this is generative AI that we're talking about. So It's not too much of A risk if your guardrails aren't written well. It's not going to get wildly out of hand. It's not going to send the data off to somewhere. It's not going to make a decision based upon what you're doing. When you look at say ChatGPT on your phone and you just type in a question, tell me what this sentence means, and then you paste a bit of text in. It works just the same way when you're actually passing this information in, which means that you can get a workflow to pick up a file, read the content of the file, and then pass that in to OpenAI as your checkout. I use OpenAI in all my examples. It's really straightforward to put into a workflow. Then what you'll get back from that is a nice JSON format file, which tells you the results. It tells you the cost, which is most important thing. There's a whole bunch of old little bits that it puts in there. And you can pull this information apart and use it as you want in your workflow. So for me, the most simple thing that I could do was say, is there sensitive information inside this file and tell me clean or dirty and why. And I can just literally tell the LLM that and it gives me back the information. And I can then route my data accordingly, block it, send it. If you wanted to redact it, that's another thing entirely. You'd probably want to go to Agentic to do that. Again, circling back round, is it the best tool for the job? Probably not. There are dedicated DLP checkers which can probably give you a better result. They're more refined in what they do. They're more precise and granular. Other things that I've done. So I wanted to write my own custom query report. That's quite straightforward as well, but you need to have one of the various MFT applications that allows you to upload data in the form of a chunk of text. So if you've got some secure forms, some kind of a form input, and they all have some kind of a form input these days, you can just put that text into form input field, and then the workflow that is triggered after that form is executed, that goes away, does the same thing, brings you back to results afterwards. As I said earlier, when I was talking about what vendors have done so far, you might want to just take the opportunity to capture that query that you've generated each time. Use the original text as a description of what it's doing, but just capture the query itself. And then you can just replay it again and again and again as you want, because the data is going to change, but the actual query itself won't do. And probably the easiest one to get wrong to make a mistake with when you're talking about building your own AI integrations on a workflow is an error handler, so it's very great. You've got an error message that your workflow has produced, and you just pass it into OpenAI or whatever product you're using. and it will tell you the most likely cause of what the failure is. But let's say you've got a connection to an SFTP server, fails repeatedly, maybe four or five times a day. It's going to tell you the same solution each time, four or five times a day, seven days a week, and just keep counting up that cost. So really, I would suggest that in this case The better thing to do is to actually use the AI to build a knowledge module and just link out to the knowledge module instead. You can pass the error in there and maybe when the end user comes to have a look, your help desk or your operations team takes a look at that problem, they're looking at the old description rather than regenerating it and reworking every single time. It's not just the cost, the token cost, but each of these queries takes time. They're not instantaneous. So you have to wait for these things to complete. But yet again, that's very simple. And of course, you can set the guardrails to actually define how somebody should interpret these things. So you can say, I want this aimed at somebody who's not really got much AI, much MFT skill, somebody who's a real expert, somebody who's just looking after the help desk temporarily. So you can change the level of information and it will make it if you want to be like schoolboy rather than headmaster when it comes through. Those are options you can do. Now, I've not gone down this route, but what you can do from that, of course, is you can move this into an agentic workflow where it will trigger another action. But the way that Agentic works or Agentic AI works is you have an agent that has the capability of performing some action. And that might be to, I don't know, build a new workflow that does something else instead. Or it might be to I don't know, change the ports that you're connecting on or the username or a certificate or something like this. Sounds good in practice, but you'd have to be really, really careful with the guardrails that you put in there to make sure that it just doesn't try everything. And instead of sending it to bank ABC, sends it to bank DEF instead. I mean, that's a risk. And perhaps a better thing would be to do to stick with generative and actually make the decision in the workflow itself. Better error handling and troubleshooting inside the workflow based upon what the AI is suggesting.
Yeah. And all of these little things that you could be doing with AI, benefits wise, is the main benefit you're freeing up your team, you're becoming more efficient, you're introducing new levels of automation or is there other benefits that?
I think mostly it's automation. It can also be security. So if I give you an example, you go out to the shop every day to buy your lunch and you spend, I don't know, 5 pound on a meal deal every day, day in, day out. And then one day it comes through as 500 pound instead of your meal deal, big meal. So that's happened. you know what's going to come next. Your bank is going to contact you and say, is this a legitimate transaction? Recently I was looking at one of our own MFT systems and the blacklisting white listing mechanism was looking at so many failed logins from an address in a 5 minute period. And we had somebody trying to crack into our system by trying once a minute forever. just endlessly looping through. And honestly, the blacklisting was not working. It did not detect it because it was such a slow attempt. But if I ask AI to look at the transaction history and the login failure history, it will immediately say, here's a problem here. Let's address that one. So security could also be a strong point. The compliance bit could be coming in as well. Apart from that, Is it really time saving? Not in many cases, because these are bits of information you'll do one time. It might save you a couple of hours, maybe once a month, something like that. So a lot of these are not great time savers. It's more about, for me, security and functional changes.
It sounds to me largely that what you've just talked about, is or can or be delivered from the application going back to the point I made earlier that you've made. And hypothetically speaking, some of the additional capabilities that we, the benefits you might get from AI, it could be worthwhile actually building them out as standard functionality within the software rather than leveraging an additional tool and the complexities of that, the additional charges of that, the likelihood and potential of it to cause additional problems as well. It sounds to me like the functionality, the core functionality needs to be extended more over than necessarily leaning into AI so much.
Some of our MFT software that I personally worked with for 20 years, from 20 years ago, it's got a decent wizard, allows you to build a workflow step by step by step, everything you might want to do. Sure, you've got to put in details like where am I connecting to, what am I doing, which PGP key do I use, this kind of thing. But it's all there already as a wizard. I don't need AI to drive me through that. It's only if I'm getting into something really complicated, which might not be my everyday thing. Let's face it, most workflows tend to be really basic. They move a file from here and deliver it there. So yeah, there are a lot of occasions where We're just throwing AI at the wall and seeing what sticks.
I had a question on guardrails, but you've kind of touched upon guardrails already in terms of what organisations should be putting in place to as guardrails if they continue down this road of AI.
The guardrails themselves, as I said, they're more important when you're talking about the agentic side of things. For anything else, it's really just going to be on the generative side, I want you to respond in this manner. I want you to pretend you're an AI or you're an MFT expert when answering this question. So for the agentic ones, maybe we're looking at, okay, we're going to allow an agent to redirect a workflow on the fly, but we're going to force it to select from this group of 10 locations it can go to, can't go to anything else. That would be the kind of restriction that I would look to and making sure it's not manipulating source data. It's only ever creating data, updating not the source and sending it on.
Looking ahead five years, I won't go any further than that. I didn't go any further that with Rob. But where do you see AI? changing MFT.
We had this little almost mini revolution 15 or so years ago where we started doing ad hoc transfers inside our file transfer programs where we could say, dear business user, you no longer need to contact the IT admin. You can send this file yourself. Okay, we delegated that workflow out, sorry, that bit of the work out. But now what we can do is with with AI looking after our building of the workflows, it can perhaps do the whole job on a workflow too. Are we there yet? Not yet, but in five years I don't think we'll be anywhere else. It will be the sole thing.
Indeed, yeah. I'm going to come back to a point that Rob made and come back to the AI that's in the solution or solutions currently or what's coming down the pipe. I'll circle back to that point that Rob was making about the strategy of AI that an organisation needs to consider how they're going to use it rather than just using it for the sake of using it because it's something that they've heard and something that they feel that they necessarily need to implement inside their organisation. I've come to the point that I made to Rob, there's a crossover between what is AI and what's automation and largely a good majority of what we're talking about can be delivered by either standard automation within the technologies or some additional clever jiggery pokery and configuration within the app to get it to where you're talking about that AI will take it to anyway.
Well, I'm a big fan of the whole automation part, especially when it comes to administration, automating the creation of file system users. Even deploying some basic workflows, getting all of that done, host definitions, that kind of stuff, automate all of that, and you can do all that now already, but AI could maybe assist you in suggesting a better way to do it, or a cleaner way, or perhaps AI can just run in the background when it sees something happening, it can trigger that. would be more moving into the agentic side than the generative.
A lot of people listening or watching this episode right now are likely to be part of a team that's being pushed hard by their sort of leadership team in terms of, I know we've got clients that are being pushed to introduce AI into their systems. So if you were in their position and you were running an MFT environment on behalf of an organisation. What is 1 practical thing that you would take away from this episode and look to do as part of a long-term AI strategy?
I would suggest to people that they look where they're spending the most time at the moment. Just one area, just focus on one area. and then look at how much of that has to be, how much of it can be automated anyway without the use of AI and how much of AI can assist you to automate. Even if it's down as simple as something like creating the workflows, creating the reporting or just interpreting how a user should be defined in the system. I mean, AI can be looking after your security. It could be doing your your RBAC, your role-based access control on your system quite simply, and reapplying that every day. Once you've got that, your auditors, they save so much time, they don't need to be coming in and bothering you and rerunning the audit. It's a time saver. And it's the same across all the different aspects, really. Just pick one, focus on what can be automated, what AI can assist you automate. basically removing manual steps and compressing the whole workflow. You start off with a massive workflow and bring it down to something more manageable. And it allows you to move your steps around as well. They don't have to be in one place. You know, and stuff can run concurrently. Why not?
And my final question, and I ask this to Rob. and I can't let you leave in answering the same question, is what is the coolest thing you have seen or built when it comes to AI?
Well, everything that I build is cool anyway. I can't get away from that. But at least when I do it, it's cool. Then I get bored afterwards. No, the coolest thing that I've seen is actually it's multi-discipline. And the way that I've seen it is take a workflow, you've built your workflow, all right, we're happy with that and it's been running for a while. So then the AI agent looks at the workflow, the way it's designed and looks at all the history records that is generated, so it's log records, and looks at where improvements can be made inside your workflow based upon timings, based upon failures, based upon compliance. So you take all of the different things that I've mentioned already and throw them all into one place and not so much build something, but just, I don't know, it's like, think about the teacher giving you back your work, saying, yes, it's great, but you should have used this word here or that sentence. It's a really good way of just tuning what work you've already done, rather than redoing it, just tuning it.
So in effect you could. AI could help you to determine when to run the workflow so as to reduce the amount of failures.
Exactly.
Okay.
Yeah. If it always fails at 8 P.m. because the target server is down, it's not running at 8 P.m.
Yeah. Well, the cleaner's taking the network.
That's all my questions. James, do you have any more questions?
No, I don't think so. AI boggles my mind anyway.
I know, that's two episodes now around AI that have both been very fascinating and both mind-blowing.
One thing to bear in mind with AI is anything that you talk about now, the latest and greatest things in AI, three months will be.
Thank you for joining us for another insightful episode around AI. Thank you to our listeners. As mentioned at the beginning of this episode, if you'd like to revisit our earlier conversation with Rob May, we will leave a link in the show notes below. And if you'd like to get in touch with our team to discuss anything we've covered today, you can find our contact details there as well. If you enjoyed the episode, don't forget to hit subscribe and stay tuned for more conversations like this one. We will see you in the next episode.
