Netwrix 1Secure delivers unified visibility across data and identity - free for 14 days with full access. Start a free trial

Resource centerBlog

The AI challenge most companies don’t have

The AI challenge most companies don’t have

Aug 27, 2026

A few months ago, I attended a GC AI Summit hosted by Harvard Law School. As expected, there was plenty of discussion about AI tools, governance frameworks, emerging regulations, and the future of the legal profession.

One topic of discussion stood out above the others: Most organizations only need to think about how they deploy AI, whereas we have to think about how we deploy AI and how we develop AI.

Most companies are “AI deployers,” meaning they use AI internally to improve productivity, automate workflows, enhance decision-making, and create operational efficiencies. Their challenge is figuring out how to adopt AI responsibly while managing risk.

Technology companies increasingly face a different challenge in that they are also “AI developers,” meaning they build products that help customers leverage AI while navigating their own regulatory, security, and governance requirements.

We sit at the intersection of being both an AI deployer and an AI developer. We are deploying AI within our own organization while simultaneously helping customers understand, govern, secure, and comply with the rapidly evolving AI landscape. That creates a unique challenge, but also a unique opportunity.

Traditionally, legal teams have been responsible for understanding how external forces affect how the company operates:

  • Governments introduce new regulations
  • Industry standards evolve
  • Customer expectations shift

Legal’s role is to interpret those forces, assess risk, and help the business navigate them successfully. AI doesn’t change that responsibility, it expands it.

Today, Legal is increasingly expected to help answer questions that are not purely legal:

  • How should we govern AI internally?
  • What risks are acceptable?
  • What guardrails should exist?
  • How do we balance innovation with accountability?
  • How do we maintain trust with customers, employees, regulators, and investors?

Those questions often end up on a general counsel’s desk because Legal has visibility across the entire organization. Unlike most functions, we operate across departments, products, customers, regulators, and markets simultaneously.

The summit reinforced something I’ve observed and enforced with my team for some time: the role of Legal is evolving from advisor to orchestrator. Not because lawyers suddenly own every decision, but because someone needs to connect all of the moving pieces.

Three questions that will determine success

One of the most useful frameworks from the summit was that organizations navigating AI ultimately need to answer three questions.

1. How are we measuring gains from AI?

Most discussions about AI begin with excitement about what’s possible. Far fewer discussions focus on whether we’re actually creating value:

  • Are we reducing time spent on repetitive work?
  • Are we improving decision-making?
  • Are we helping employees focus on higher-value activities?
  • Are we creating better outcomes for customers?

The organizations seeing the greatest impact are not simply deploying AI because everyone else is doing it. They are identifying specific business problems and measuring whether AI helps solve them. Technology adoption alone is not the goal. Business outcomes matter more.

2. How are we thinking about efficiency and quality?

Historically, organizations have viewed speed, quality, and cost as competing forces:

  • Move faster and quality suffers
  • Improve quality and costs increase
  • Reduce costs and speed slows down

AI has the potential to reshape that equation, but only if organizations are intentional about how they use it.

The summit repeatedly returned to a question many organizations are still struggling to answer: How do we measure quality in an AI-enabled world? Efficiency is relatively easy to measure, but quality is much harder. For legal teams, this means asking whether AI is helping us make better decisions, identify issues earlier, improve consistency, and create better outcomes, not simply complete tasks faster. The future will not belong to organizations that maximize efficiency alone, but to those that improve both efficiency and quality simultaneously.

3. How does AI impact trust?

This may be the most important question of all. If employees don’t trust AI, they won’t use it. If customers don’t trust how you’re using AI, they won’t do business with you. If regulators don’t trust your governance, they will create governance for you. If boards don’t trust the outputs, they will continue looking to management for answers.

One speaker summarized it simply: “The board doesn’t trust AI. They trust you.” Technology can generate recommendations. Technology can accelerate workflows. Technology can surface insights. But accountability remains human. Trust remains human. Leadership remains human. As AI becomes more powerful, trust becomes more valuable.

What I heard from leaders at Microsoft, Workday, and beyond

While the summit spanned a range of sessions, from Harvard professors to in-house legal leaders to legal operations executives, a consistent set of themes emerged across very different perspectives.

A session led by Bjarne Tellman (FjordStream Advisors) framed the challenge as one of “structured velocity.” His point was that organizations are not simply adopting AI tools, but rather they are building systems that must scale intelligence safely. In his view, Legal’s role is not to slow innovation, but to create the governance and data structures that allow speed without fragility. He described this as the foundation for an “AI factory” model: a self-reinforcing system where data, governance, and learning continuously improve outputs over time.

From Microsoft’s leadership in Corporate, External, and Legal Affairs (CELA), the message was more operational and directive. The organization is actively re-architecting Legal as a consultative and development function that builds internal AI tools, regulatory intelligence systems, and agent-based workflows that reduce manual research and shift focus toward higher-value regulatory and policy engagement. The through-line was clear: legal teams are no longer just consumers of technology; they are becoming builders of it.

For Workday, the discussion centered on how organizations operationalize AI responsibly at scale. The model described moved from principles to practices to people, supported by a structured governance system where legal, privacy, and engineering jointly oversee AI development. A recurring theme was that successful adoption depends less on individual tools and more on whether organizations can design intake, risk classification, and accountability systems that allow AI to be used consistently and safely across the enterprise.

Across all the sessions, including examples from large enterprise legal and operations teams, the conversation consistently returned to a few practical challenges: how to structure enterprise data so AI systems can actually use it, how to move from matter and contract “drawers” to integrated knowledge systems, and how to embed quality assurance into AI-enabled workflows so that outputs can be trusted at scale.

The deployer-developer paradox

For companies like ours navigating the deployer-developer paradox, those questions become even more important because we’re answering them from two perspectives simultaneously. As an AI deployer, we need to understand how evolving laws, regulations, and public expectations impact our own organization. As an AI developer, we need to understand how those same developments impact our customers. That means we’re constantly looking in two directions at once:

  1. Inward. How do we use AI responsibly? How do we govern it? How do we manage risk while enabling innovation?
  2. Outward. How do we help customers navigate those same questions? What capabilities do they need? What controls matter? What evidence will they need to demonstrate compliance, security, and responsible governance?

The better we understand one side, the better positioned we are to solve the other. That creates an advantage that many organizations don’t have: We aren’t simply observing these challenges; we’re living them.

In many ways, that puts us in a unique position to shape how organizations think about AI governance, risk management, and trust.

Velocity requires structure

Another theme that surfaced repeatedly throughout the summit was the tension between innovation and governance. Organizations everywhere are racing to adopt AI. Some are moving carefully. Some are moving recklessly. Most are trying to find the right balance.

One speaker described the objective as creating “structured velocity.” I found that phrase particularly compelling. Businesses need to move quickly because customers expect innovation, and competitive advantages rarely wait for perfect certainty. At the same time, speed without structure creates risk.

One example shared during the summit involved an AI system that autonomously rerouted product shipments to avoid weather disruptions. The system optimized for speed and efficiency but failed to account for regulatory restrictions. It didn’t factor in whether the ports the shipments were rerouted to could actually accept them. The result was a costly operational problem that nobody intended to create. The lesson wasn’t that AI failed. It was that governance failed.

Technology can move faster than organizations can think if appropriate guardrails are not in place. The goal is not to slow innovation, but to create the structure that allows innovation to scale safely.

Another speaker used the German Autobahn as a metaphor. The reason large portions of the Autobahn can operate without speed limits isn’t because there are no rules. It’s because there is a strong culture of discipline, accountability, and enforcement surrounding the rules that do exist. If it’s raining, a speed limit is enforced, and there’s no tolerance for violations of that speed limit. “Structured velocity” works on the Autobahn because safety measures are understood and respected.

The same principle applies to AI. If organizations don’t create safe, approved paths for innovation, employees will find their own paths. The answer isn’t restriction for the sake of restriction. It’s creating frameworks that allow people to move quickly, responsibly, and confidently.

The future isn’t about replacing professionals

Whenever new technology emerges, predictions quickly follow about which professions will disappear. The legal profession, like many other professions, has heard them all countless times before:

  • The internet was going to change everything
  • Digital research was going to change everything
  • Contract workflow automation was going to change everything

Those predictions weren’t wrong. The profession changed, but it wasn’t replaced.

One speaker made an observation that stuck with me: Professionals often assume new technology will allow them to do what they already do faster and cheaper. Instead, technology usually changes what it means to be a professional in the first place.

AI will likely follow the same pattern. The highest-value work lawyers do has never been gathering information. Our most valuable assets are applying judgment, understanding context, balancing competing interests, building trust, and making decisions under uncertainty.

Those responsibilities remain profoundly human. What changes is how we spend our time. The most successful professionals (legal or not) will be the ones who learn how to combine technology, judgment, and expertise more effectively than anyone else.

Final thoughts

My biggest takeaway from the summit is that organizations now have an opportunity to help shape what responsible AI adoption looks like before someone else does it for them. For legal teams, that means helping create the frameworks that enable innovation. For technology companies, it means recognizing the unique position we occupy as both deployers and developers of AI. For all of us, it means understanding that the future will be defined by how thoughtfully we choose to use AI. The companies that get this right won’t simply adapt to the future. They will help create it.

Share on

Learn More

About the author

A woman in a grey jacket and white shirt smiles for the camera

Rachel Richart

General Counsel

Rachel Richart has guided Netwrix through legal strategy from our early startup stage to today's global scale. She brings her expertise in enterprise software contracts, global compliance, and M&A transactions and now serves as our trusted lead legal advisor. Rachel holds dual bachelor’s degrees in Business Administration and Political Science from The Ohio State University and a JD from Capital University Law School. She’s based in Columbus, Ohio.