Evolving AI Compliance into Continuous Governance: Insights from Legal Experts, ETLegalWorld

WorkAI.TV Editorial Desk
4 Min Read

Share with your CISO

Legal and compliance leaders at the ETLegalWorld AI-Powered Legal Transformation Summit 2026 made a pointed case that AI governance cannot wait for a comprehensive regulatory framework that may never arrive. General counsels from HPE, IBM India, LTI Mindtree, GE Vernova, and Novo Nordisk converged on one position: compliance must be designed into AI architecture before deployment, not retrofitted after audit. The panel called out specific failure modes, including employees feeding confidential data into public AI tools, attrition models repurposed to deny promotions, and meeting apps transcribing conversations with no clear data handling policy.

What this means for your business

The enterprises represented on this panel are not startups experimenting with AI. They are regulated multinationals in life sciences, energy, and enterprise technology, and their general counsels are describing governance gaps that already exist inside live deployments. If your organization has AI pilots running in HR, legal, or procurement without a documented answer to who controls the infrastructure, where employee data travels, and who has authority to override an AI decision, you are in the same position these panelists are publicly describing as insufficient.

The sharpest idea from this panel, and the one most likely to get dismissed as philosophical, is the distinction between “human in the loop” and “human in command.” The loop framing, where a person nominally reviews AI output before it acts, has become a checkbox that organizations deploy to satisfy auditors without actually changing outcomes. LTI Mindtree’s Jagannath PV named the specific failure mode, a reviewer who advances a recruitment candidate because the AI scored them highly, without the authority or information to push back. That is not review. It is ratification. The command framing requires that reviewers have both the capability and the organizational standing to override AI decisions, which is a governance architecture question, not a training one.

The sovereignty point raised by IBM India’s Dinesh Vijayakumar deserves more weight than it typically gets in enterprise AI discussions. Vendor concentration risk, meaning dependence on a single platform operator who controls access, model behavior, and data handling across your AI stack, is not a geopolitical abstraction. It is a procurement decision with compounding consequences. Every time an enterprise deepens integration with a single AI platform without exit architecture or contractual data portability, it is trading short-term deployment speed for long-term leverage it no longer holds. The CISOs and CIOs who will be in the strongest position in three years are those who treated vendor access controls as a governance question starting now, not after a dependency became visible in a renewal negotiation.

Concept deep-dive: Compliance-by-design

Compliance-by-design means mapping regulatory obligations directly into an AI system’s architecture before it goes live, rather than auditing for compliance after deployment. The analogy is building fire exits into a structure’s blueprints instead of cutting holes in walls after occupancy. In practice, this means data routing, access controls, human override mechanisms, and audit logging are specified as requirements alongside model performance, not added when regulators ask. For enterprises running AI across multiple jurisdictions, it is the only approach that scales without constant retrofitting.

Based on reporting from Evolving AI Compliance into Continuous Governance: Insights from Legal Experts, ETLegalWorld, originally published 2026-08-07 07:45:00.

TAGGED:
Share This Article