On both the federal and state level, the focus on regulating AI has begun, and although many of these regulations are in the early phases, Legalweek panelists say organizations should begin sharpening their usage, privacy, and communication policies now
NEW YORK β At this point, itβs undeniable that generative artificial intelligence (Gen AI) will have some sort of impact on the legal profession. After all, according to the ³ΙΘΛVRΚΣΖ΅ Future of Professionals report, 70% of legal industry respondents believe the introduction of AI or Gen AI into their profession will have a transformative or high impact on the industryβs future within the next five years β more than any other trend.
However, particularly in legal, there remains two major sticking points to widespread adoption: ethics and regulation. While the technology itself is rapidly emerging, Gen AI is not likely to see widespread adoption in the legal industry if it can't be trusted, and many legal practitioners are waiting for additional guidance before using Gen AI to tackle more widespread tasks.
According to a panel, The Ethical and Regulatory Impacts of Using Your Data to Train AI, at the , that guidance is coming in the United States β albeit slowly, and in parts. However, the guidance that is available now is enough to get started on Gen AI risk mitigation planning, panelists said.
US Gen AI regulation today
Across most US jurisdictions, Gen AI regulation is extremely active but is still in the early stages. For example, the panelists noted that many US states are beginning to form councils and task forces to look into AI. βWeβre now seeing this over-arching focus on the risksβ¦ but that trickles down into the state legislatures themselves,β said panelist Garylene Javier, a Privacy & Cybersecurity Associate at Crowell & Moring.
In particular, a lot of the AI focus has been around the privacy rights of individuals, particularly around consumer protection and the right to opt out of AI systems. Javier explained that all states (except Utah) that have adopted privacy laws have done so with opt-out provisions as part of the legislation. βWhat weβre seeing is a shift of all of these different privacy laws with that particular focus, particularly when it comes to automated decision-making,β she explained.
Anyone in this space needs to be thinking through the scenarios.
On a federal level, President Bidenβs 2023 executive order on AI remains the most relevant guidance, particularly as the in early February that all executive agencies have completed the 90-day actions tasked by the order. Panelist Ignatius Grande, Director at Berkeley Research Group, cited the Federal Trade Commission (FTC) as one regulatory agency to watch, explaining it has been among the most proactive in the AI space.
βTheyβre coming out and saying, there are copyright issues with LLMs [large language models] and AI,β Grande said.
Of course, the upcoming 2024 presidential election could cause upheaval for AI regulation. As for exactly how, the panel did not speculate β only to say that it could have wide-reaching ramifications. Jason Winmill, Chair of legal industry organization Buying Legal Council, observed that the previous two presidential administrations viewed technology regulation very differently, and βanyone in this space needs to be thinking through the scenarios.β
Winmill drew an analogy to a pool table, where the pool balls are not independent, but interact with one another in seemingly endless varieties. What matters, however, is whoβs lining up the shot. βWe donβt know what that pool table is going to look like in 2 to 3 years.β
The legal industryβs response
Given the potentially transformative nature of Gen AI, itβs reasonable to expect that it will see widespread usage within the legal industry within the next 5 to 10 years; but the panel noted that in order to do Gen AI right, corporate legal departments and law firms will need to do their due diligence.
Grande told the story of Samsung, which ran into a problem last year with employees using ChatGPT. One employee uploaded source code to ChatGPT that was viewed externally, while another employee put a confidential recording into the tool to create a summary. Samsung ended up until it could put more controlled Gen AI systems in place.
Thereβs a lesson for the legal industry no matter where you sit, Grande added. βAs far as what law firms can be doing, part one is understanding and giving guidance to their employeesβ¦ and have in place acceptable ways of [using] generative AI. There are a lot of questions that you need to ask, and if youβre someone whoβs not experienced in the area, itβs really hard to know what questions to ask.β
Winmill agreed, noting that from the in-house legal perspective, AI use needs to be ethical but also should be βdriven by real business needs.β Answering the relevant AI questions starts with getting a number of different parties in the room: legal, for certain, but also procurement, IT experts, AI experts, and business advisors. Concerning the ethics risks, he added: βThe space is just moving way too fast, and youβre going to have to have outside counsel or advisors who can advise on a timely basis.β
There are a lot of questions that you need to ask, and if youβre someone whoβs not experienced in the area, itβs really hard to know what questions to ask.
Of course, that doesnβt mean throwing as many people as possible at the AI problem. The key is to be strategic, Winmill said, and bigger teams arenβt always better. βThe size of the table is growing, itβs growing faster, and that is also a concern,β he explained, noting that academic literature shows larger teams can have communication issues. βWeβre adding more resources in, but weβre also going to be encountering more problems.β
Communication is also a key when outside forces are involved, particularly when firms are dealing with outside regulators. Corporate legal departments and law firms need to demonstrate first that they have a plan, Javier said, and then demonstrate that they are doing everything they can to stick to that plan. This has been a particular point of emphasis when analyzing AI for potential bias, which has increasingly been the subject of US state legislation and lawsuits.
Organizations should be βmaking sure from an ethical standpoint, youβre demonstrating across the entire process [that] you did as an organization or a law firm take the time to step through and see how it affects certain demographics or customers,β Javier said, adding that as hard as legal departments or law firms may try, any Gen AI policy is βnot going to 100%β in terms of catching every problem.
βSomething will happen tomorrow where itβs going to be totally deficient,β she said. βThe best thing we can do is try β try really hard.β

