Advertisement
Advertisement

Firms need playbook to ensure AI is fit for purpose, says specialist

Sarah Ward, Debbie Gregory and Vladimir Kravchenko in Brisbane for In-house Counsel Breakfast. Photos: Natalie Gauld

Law firm leaders need a playbook when it comes to managing the risks around artificial intelligence use rather than just focusing on the technology, advised Law Squared AI Practice Area specialist Vladimir Kravchenko on Tuesday.

The Senior Commercial and Corporate lawyer joined Attvest General Legal Counsel Debbie Gregory on the Queensland Law Society In-house Counsel Breakfast panel at Brisbane’s Customs House to discuss AI Governance and the Evolving Australian Regulatory Landscape.

The panel was chaired by Law Squared Head of Property and Projects Sarah Ward and the speakers covered risks, existing practices and shared corporate understanding.

Mr Kravchenko said leadership needed to work out what it actually wanted from AI and then ensure it was fit for purpose.

“In the context of AI, any technology implemented or any governance framework you build, it means something that reflects what’s happening on the ground in your business and that will be used by the people in your business,” he said.

“No one wants a system or a playbook that’s inaccessible or doesn’t reflect the reality.

“If you have that, as I’m sure everyone here has encountered, you end up either with something that is a handbrake or just theatre where people go through the bureaucracy for no real reason.”

Mr Kravchenko said three areas should be assessed: how AI is affecting the profession; how employees already use AI, including shadow AI; and how the organisation wants to use AI in the future.

“Firstly, and this is the least obvious one, you have to think about how AI is impacting your organisation, whether you use it or not, because AI is reshaping the world around us and sometimes in highly disruptive ways,” he said.

“For example, a friend of mine is a law firm founder and for many years a lot of the business came through her website.

“She got her lawyers to draft articles that were very popular among the sort of FinTech, FinReg community that they provided useful answers and so people clicked on the articles, traffic went to the website and she got new leads that way.

“With the advent of the AI search results, people stopped clicking. So the traffic sort of dried up overnight.”

In regard to how an organisation is already using AI, Mr Kravchenko said “whether you like it or not, most of your employees are probably using it and that’s shadow AI (use without approval and/or oversight)”.

“So at a very minimum that would need to be governed. But a great idea is to do a stocktake of what’s happening.

“We see many of our clients do an audit of their systems, and that can be done via questionnaires, interviews with the relevant people, and the broader the conversation the better.”

The third area relates directly to the strategic leadership of the firm – identifying how an organisation wants to use AI.

“Do you want to be a disruptor and innovator? Do you want to use it to remove routine tasks and improve efficiencies? Or do you sort of want to watch from the sidelines and not get too involved?” he asked.

“Wherever you land with that will inform your risk posture and ultimately what the governance looks like and whether the governance is fit for purpose.

“If you’re going to build your business around AI, where most things get driven by the machine, then you’ll need to have very robust risk frameworks with lots of checks and balances to make sure that it doesn’t destroy the business in the end.”

Ms Gregory, a member of the QLS In-house Counsel Committee, spoke about strategy in practice and said there had never been a better time to practise law with AI “coming our way”.

“The first thing that I encourage everybody to do is to start learning the language, make sure that the language that you’re using when you talk about AI is the same language that your IT team is using, and then teach your board the same language,” she said.

“Once you form the strategy and get an idea of where you’re headed, then the next step is to set the policies around what that’s going to look like.

“And then you move on from there and start, well asking, what are the problems that we need to solve? And how are we going to solve it? What kind of things are we going to use? Who’s going to be involved?”

Ms Gregory recommended setting up diverse working groups to set a firm’s strategy.

She also recommended that governance programs include a register of use to help reduce risks.

“I have my register, so every recognised use that we have of AI is recorded in the register,” she said.

“Anyone can access the register at a certain level and the register itself sets out whether there are guardrails around that particular AI use or whether it is available for all.”

Ms Gregory warned that the “most invisible” thing happening with AI in business and that “will continue for some time” is stealth AI.

“So products that you’re already using, that are already approved, everyone’s on board, been using for some time, and then that product itself introduces an AI element within its own product,” she said.

“It’s a big one to watch out for. It’s difficult for legal to always have eyes on that.”

Mr Kravchenko agreed with the risks posed by stealth AI – “that sort of silent revolution of traditional technology offerings, adding on an AI layer without really telling you.”

“And often times they rely on existing clauses in your MSA with them that allow them to modify the system so long as there’s no material detriment or some other clause to that effect.

“But with the possible risks that AI introduces, you really should be aware that’s changed. And often they add a legal addendum that no one reviews or signs that might govern AI use.

“I would highly recommend you scrutinise that.”

In the absence of clear guidance on governance, Mr Kravchenko also recommended reading the National AI Centre advice (AI6) which sets out the six principles or essential practices to consider.

“The basic gist of them is that you need to have someone responsible, you need to understand the risks and govern them,” he said.

“Having a register is good in that regard to have a stocktake of what’s there and before you introduce any new systems, it’s good to do an impact assessment.

“Then it’s very important to have someone appointed as the responsible person or sometimes several people, because where you don’t want to end up is with a responsibility vacuum, particularly where the AI can make consequential decisions or provide information that could lead to consequential decisions.”

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *

Search by keyword