Latest News

We are a young and creative company and we offer you fresh business ideas for your team and company.
bt_bb_section_bottom_section_coverage_image
Blog3 September 20240

Who Owns the Risk When AI Gets It Wrong?

Why the Best Legal Talent Isn’t on Job Boards

The accountability dilemma inside modern Legal & Compliance functions

AI is no longer at the edges of the Legal workflow – it’s in the middle of it.

From automated contract analysis to predictive compliance monitoring, algorithms are quietly rewriting how in-house teams create, review, and report. What started as a drive for efficiency has become something far more structural: an architectural shift in how risk itself is distributed.

The technology is getting smarter, but the lines of accountability are getting blurrier.

And that’s where the real tension sits.

When the Algorithm Becomes a Colleague

For decades, Legal risk was human risk. You could trace every decision to a named professional. Now, large language models can draft clauses, summarise discovery, and flag regulatory breaches faster than any associate – yet without context, conscience, or culpability.

If an AI-driven contract tool misses a key indemnity, who is responsible? If a regulatory monitoring engine fails to flag a sanction-listed entity, is that a Legal failure, a Compliance one, or an IT governance lapse?

Our recent LinkedIn poll reflected this uncertainty:

  • 21 % said ownership should sit with Legal.
  • 23 % pointed to IT / Data Governance.
  • 14 % nominated Compliance.
  • And 41 % favoured a joint risk committee model.

That near-majority for “shared accountability” tells its own story – nobody wants to own the risk alone.

The Case for a Joint Accountability Model

The most mature organisations are already converging these disciplines. Instead of arguing over ownership, they’re designing AI Governance Committees that include Legal, Compliance, IT, and Risk. These committees:

  • Define use-case thresholds: when human review is mandatory.
  • Approve data sources and prompt libraries for legal-tech tools.
  • Maintain an incident log for model errors or ethical breaches.
  • Report AI-related risk to the Audit or Risk Committee, not just IT.

This joint-ownership approach mirrors how cyber risk evolved a decade ago. Initially, data breaches were “IT issues.” Today, they’re board-level concerns with Legal, Compliance, and Risk all at the table. AI is following the same path – but faster.

Why GCs Still Sit in the Hot Seat

Even with shared structures, ultimate accountability often returns to the General Counsel. Why? Because AI risk, at its core, is legal risk – it affects liability, confidentiality, and contract enforceability. Boards and regulators still expect the GC to ensure the organisation’s technology choices are legally defensible.

That doesn’t mean Legal must become data scientists. It means building alliances with those who are – and insisting on visibility. The GC of tomorrow will need dashboards as much as dockets.

Practical Steps for Legal & Compliance Leaders

  1. Map AI Usage Catalogue every AI-enabled tool touching legal documents, client data, or regulatory reporting. You can’t govern what you don’t know exists.
  2. Define Risk Categories Classify tools by impact: low-risk (e.g. research summarisation), medium-risk (contract review), high-risk (automated advice). This prioritises oversight.
  3. Create an AI Policy Framework Establish approval processes, audit trails, and human-in-the-loop requirements. Include clear guidance on data privacy, bias testing, and prompt engineering.
  4. Train Your Teams Legal professionals don’t need to code but they must understand how models learn, where bias originates, and when to escalate anomalies.
  5. Engage Early with IT Treat technology selection like a legal procurement exercise. Get involved before implementation, not after a breach.
  6. Report Transparently Elevate AI governance to the board agenda. Regulators will increasingly expect evidence of control, not just policy statements.

The Human Element

The irony is that as machines automate more legal work, human judgment becomes more valuable, not less.

AI can accelerate analysis, but it cannot assign responsibility, interpret context, or balance ethics with enterprise goals. Those remain inherently human tasks and they’re precisely what clients, boards, and regulators will hold people accountable for.

So perhaps the better question isn’t who owns the risk, but how leadership distributes and manages it collectively.

Because when the algorithm gets it wrong, the headlines won’t name the model – they’ll name the company.

Final Thought

The integration of AI into Legal and Compliance is not a technology project; it’s a governance project. Ownership of risk can’t be outsourced to a tool, it must be embedded in the way functions collaborate.

The forward-thinking teams aren’t waiting for regulation to tell them what to do. They’re designing their own frameworks now – frameworks where Legal defines the guardrails, Compliance monitors integrity, IT ensures security, and the business moves faster because it’s safe to do so.

That’s the sweet spot: AI-enabled, ethically grounded, and strategically aligned.

OutsideCapital Strategic Legal & Compliance Recruitment — Our Business Is to Grow Yours📧 andrew@outsidecapital.co.za 🌐www.outsidecapital.co.za

Leave a Reply