As the use of artificial intelligence accelerates across financial services and other regulated industries, businesses are facing difficult questions about when AI outputs, chatbot exchanges, and agent activity become records that must be retained. In this episode of “Tech Law Talks,” Smarsh’s Robert Cruz joins Reed Smith lawyers Anthony Diana, Therese Craparo, and Michael Rubayo as they discuss emerging regulatory expectations, governance strategies, third-party risk, and the growing compliance challenges posed by agentic AI.
Transcript:
Anthony: Hello, this is Anthony Diana; welcome to Tech Law Talks. Today we're going to be addressing AI and regulatory obligations, the record-keeping debate as part of our AI compliance podcast series. Joining me today are Therese Craparo from Reed Smith, Michael Rubayo from Reed Smith, as well as Robert Cruz from Smarsh. Welcome guys. Robert, do you want to kick us off?
Robert: Sure. Thanks everyone. Appreciate you inviting me to today's session. Being in the regulatory governance and compliance space for quite a while, you know, these topics come up. And first of I need to say, I'm not providing legal advice or opinions. You must consult with your attorney regarding compliance with applicable regulations, so there you go. And the question from the last two years has been, you know, what are the record keeping obligations related to AI?
You know, what about the communications aspects? Is it different than a Google search? I mean, we've covered a lot of territory, and I guess the question still is on the table. I mean, what how do we see the regulators providing guidance here in terms of how firms should be dealing with AI outputs? Therese, what what have you learned, what are we what have we gathered from regulators as far as their obligations?
Therese: Yeah, I mean, I think from the regulatory perspective, what we're hearing from the regulators is what we always hear from the regulators, which is well, there are rules out there, and if the rules apply to, you know, the same rules that apply to other technology apply to AI. And so if you know you're using AI and the output is a record under the existing regulations, then you need to keep them. And I and look, I think this gets frustrating for a lot of, you know, our clients when you're trying to interpret it. The, The regulators, particularly with new technology, tend to be deliberately vague, right? In some perspectives, they don't want to stop innovation and they don't want to stop development. They're still feeling out what AI is and how it works and how it's being used in business. And they don't want to be overly prescriptive. They also don't want to be overly prescriptive with respect to particular kinds of technology because technology changes.
So a lot of what they like to say to our clients, and we've seen some guidance coming out from FINRA and the like that are essentially saying, look, AI is subject to the same regulations that we already have. You need to be mindful of that if you are using AI, all of the existing laws apply and you need to make sure that you're applying them. I think what gets challenging when you start talking about records from the legal perspective is the answer is "it depends," which is frustrating because some uses of AI are absolutely creating records. right? If you're using it within a very specific compliance process, and it's evidence of your compliance process, well, then it's maybe a record. If it's creating a draft that you're separately editing and saving somewhere else, it may not be a record, but it really depends on the usage. The other thing I would say is one of the areas where we have at least a little bit more guidance, but it's still incredibly difficult, is from a communications perspective. In the financial industry, we have obligations to retain communications, sometimes depending on the content and the like. And FINRA has come out with some guidance that said, look, if you're using chatbot, AI chatbots, and you're communicating with the public, right? It's gonna be considered a communication. Okay, but that gives the indication that look, AI tools can be communications.
Well then the question becomes, well, when is it a communication? When we talk about records outside of communications, you're talking about a final thing that is a representative, right? You're not talking about every version of it. We keep communications on topics that may not be the final. So you become it's a little bit different where you're saying, well, is this a communication? Do I need to keep it? that can be a really difficult challenge for our clients who are saying, well, when does it rise to the level of communication as opposed to as you're saying, a search?
Robert: Yeah, and that's that's very important considerations there, the multitude of use cases, some of which clearly intersect with regulations, market rule 2210, what have you. But Anthony, there's everything else. And you know, if you make the decision not to capture because of these other cases like meeting summaries and internal productivity tools being used and such, you run the risk of increasing shadow AI problems, people using unapproved tools or using the wrong data sources, or potentially leaking intellectual property. So how do you balance this? Where does firm, how are firms balancing both the regulatory obligation against the other risks that could arise if they don't have a strategy to be able to retain this data?
Anthony: Yeah. I mean, I think I think generally I would say most organizations are probably taking on, particularly finance institutions, are taking on more risks than you would normally take because they don't want to stand in the way. Like, legal and compliance are not standing in the way of AI. So it's often after the fact, let's figure this out. You know, should it be captured? Is it an e-com? All of those decisions. And because there's not strong guidance, it's hard for legal and compliance to say, no, you can't.
I mean, I think probably where you draw the line like Therese said is if you're saying the customer is going to be using, you know, an AI chat bot with us and all that, like I think that's pretty clear that it's hard not to argue that that has to be captured. and you could probably stop there. But when you start talking internally, you know, whether it's using AI agents or chatbots internally, it's a much harder argument for legal and compliance to say, no, no, no, you can't do that unless it may be a record, so therefore we have to capture it. So you know, we're seeing different people doing different things. I think one of the things that we're seeing, like with Copilot and stuff, we had some organizations say, well, let's just keep it in M365, we'll have a longer retention because we don't know how they're gonna react. And then, even if it's not captured in an archive under WORM and all that kind of stuff, at least we have it. So sort of no harm, no foul. I mean, that's one way to sort of mitigate the risk.
You know, obviously guidance and training and the like is also there so people understand it, but it is so hard because everything is moving so quickly within the businesses. It's really hard for legal and compliance to catch up, other than giving high-level guidance like, please come to us if you're doing anything with a client, right? Like a customer, please come to us. Everything else, you could sort of say, we'll take the risk. I think that's probably where most people are.
Therese: And I think this is where, from a legal and compliance perspective, so many organizations are struggling. Because I think frankly, everyone knows the shadow AI possibility is out there. They try to combat it by giving them better internal tools so they don't need to go to shadow AI. But, you know, they try to block those tools where you can block those tools. But I think they're struggling so much with just managing the approved AI within their organizations.
And how do we what controls do we apply to that data? And how do we have governance around it without you know stymieing business development? That from a legal and compliance perspective, a lot of our clients are still focused primarily on how do we manage the tools we have that we can use? And we know there's this possibility of shadow AI. We're telling people not to do it. We have policies and procedures, but frankly, I think resourcing is focused more on governing the tools they have that they know people are using for specific business purposes right now than they are on what am I doing about shadow AI? It's not to say they're ignoring it, but they're focusing more on governance of the many AI tools they have that are approved because as Anthony said, the development is so fast and there's so many tools, and it is so prolific in that it's not that IT is rolling these out.
Individual people are creating their own, right, AI functions built on these internal platforms that shadow AI, which I think will be a problem in the future and we will have enforcement actions around it, somewhere down the road. But right now, more of the focus is on managing the approved AI to make sure that is compliant as opposed to, you know, what is somebody doing, you know, behind the curtain.
Robert: Right. And I like to both the way both of you frame this. This is a governance call because ultimately the output and who can get access to it and what decision is it influencing and what could go wrong if it's misused? I mean, that's a governance play. And whether you choose to maintain it in a production system, you're mitigating some risk, you're creating others, because what happens if the production system doesn't work or their alerts are misfiring or what have you. So, you know, trade offs of cost and risk for sure. Michael, let me bring you in here. What additional guidance can we expect, if any, from the US regulators?
Michael: That's a tough one, Robert. As new technology comes out and as AI continues to develop and evolve, know, the regulators will provide guidance as they deem necessary. It'll be interesting to see with this new advent of watermarking in AI outputs, whether the FINRA or other, you know, regulators wanna provide additional guidance. Firms sort of have to predict and expect and sort of have to sit and wait for guidance to come out. There's nothing that that is on its way.
Robert: Right. hurry up and wait, I don't think, is the the optimal approach here anymore.
Anthony: Ha ha.
Therese: Yeah. And I think to your point, Robert, what this to me be happens is becomes a governance point. The regulators will provide additional guidance at some point in time. It is hard to predict when they will do that. We obviously are seeing less regulation now, so is it gonna be maybe further into the future? And I think what really is most important for our clients is to approach this from a governance perspective, to be able to justify the decisions that you make in the absence of guidance, in the absence of immediate guidance. It's not like we know next year something's coming out, right? Something will come out eventually. We don't really know what it's going to be or what form it's going to take. And I think the best thing to do is say, look, I've got a governance process. We considered the existing laws. We made decisions. These are the decisions that we made so that you can show you had controls in place. A reasoned decision was made in an effort to comply with the regulations.
And if it turns out the regulators come out with opposite guidance, at least you can say, look, we had a reasonable position at the time. When we got the additional guidance, we adjusted accordingly if you need to adjust. But the best way to handle it is to make reasoned decisions within a governance framework so that if you get guidance that is different, you still have a justifiable basis for the decisions you made at the time. And then you can, you know, If you need to adjust, you can adjust.
Robert: And that's a a good way to describe it is that, we're not going to see regulation by enforcement. That is not coming back. And so it's just operated with presumption of we have what we have at the US federal level. But Michael, a follow up to you, we also have a patchwork of US states that all have different obligations, and you've also got the EU AI Act. You mentioned the watermarking situation, which is a requirement as part of the transparency provision, which just took effect. So how are firms wrestling with that complexity where, you know, federal level's one set of guidelines, principles based, state level, some prescriptive, EU prescriptive. It's like you've got a a combination of extremes. How are how are firms reconciling these things?
Michael: Yeah, Robert, I I think what firms are doing is trying to, you know, comply with the law, obviously, but they're also trying to not stand in the way. So they they take sort of this, you know, highest common denominator approach when necessary, but you know, try and, you know, allow the company to continue to use and you know advance their business with AI.
Anthony: And I would probably be a little more blunt. They frankly are ignoring the EU AI Act. like look, there's principles there, but I don't think I as I said before, I don't think legal and compliance are stopping innovation, at least in US companies, right? They're moving forward very quickly. They're doing their best to mitigate risk, like Therese said, putting some type of governance around it. So at least they can say they thought about the issues of the EU AI Act, but the reality is is it's not gonna stop. That's the reality right now. And I think people are, you know, unlike I think GDPR, where GDPR sort of did have a huge impact on US and and people adopted similar, you know, California then did did privacy and other people followed. I don't think we're seeing that with the EU AI act. I think people are saying, look, we're not gonna stop innovation. And I think we've seen it both at the state and EU level where they came out with something and then backtracked because the businesses has said, you know, no, like we're not doing this. And everybody said, okay, well, then you're right. So it's a very much wait and see, even on that. So which again goes to the point which we keep saying with regulators and like it's we don't expect there's going to be like massive, you know, regulatory scrutiny on some of this. I mean, obviously everyone's sort of tiptoeing around AI governance. And I think it's going to be the same with the financial regulators. I don't think they're going be stamping on things and and being very prescriptive. I think we'll see, look, we're all expecting it. Something is going to go awry. There's going to be some big massive thing in the market that was caused by an AI agent or something like that. And everyone will be upset. And that's that's when we'll start seeing any type of movement in terms of guidance.
What happened, what is the fine? And everyone then will sort of recalibrate. But I think that's probably what people are waiting for. Not the not the regulators to say anything, but what's the big thing that happens that suddenly everyone now has to recalibrate the risk, right? In terms of how we're dealing with AI. So I think that's what we're all waiting for.
Robert: Exactly. And and just a couple of dimensions there I want to touch on. I mean, what's different in this patchwork of regulation is the thread here are thirds and fourth parties, the AI providers themselves. Do you guys see any change in the way that companies are approaching due diligence on the model providers themselves in terms of their data protection practices, where they're storing their data, how they're storing the data, what is your ability to retrieve it if you get a regulatory request, or litigation, if that's the if that's the location of where you're managing this data, how are firms approaching third-party risk management differently or or are they?
Therese: I think they are trying to manage third-party risk management. Look in the financial industry, whether it's AI or not, third-party risk management has been a huge focus, right? You're we're we're seeing more and more, you know, regulation and focus on how are you managing those third parties, the responsibility to manage those third parties. So I don't think that that's unique to AI, but we absolutely see our clients applying a scrutiny to third parties that are using AI tools as it's coming through their process. A lot of our clients have whether, you know, an AI council or an AI committee where they're reviewing the use of AI and is it appropriate and all the questions you're asking, Robert, where is it being stored? How is it being used? All of those kind of things. So we definitely see a lot of scrutiny about that. I think as we've talked about on this already, that, you know, legal and compliance are behind the business. And so they may not always review it in as timely a manner as we might like or they might like, but it there is a lot of scrutiny focused on that. What I think actually gets lost a lot of the time in that scrutiny is the focus is around ownership, appropriate use, IP, privacy. There's a lot of focus around that. What actually we see as a gap for a lot of our clients is records.
And that kind of piece of it is not, you know, yes, can the business retrieve it? Sure, but there is a lot less focus on, is it a record? How long are we retaining it? Should we be retaining it? Right? How would we get it if we needed it in a litigation or in response to a regulatory request? How would we demonstrate record keeping compliance with AI tools? A lot of the things, that is the gap, biggest gap probably we see, because we do see, you know, a lot of focus on the contractual pieces of it and all that, all of which are important, right?
We do see though these committees that are being formed, there is often a gap from the governance perspective and from the record keeping perspective that I think really organizations should be focusing on and making sure you have that representative in those groups. So you are taking that into consideration and doing your diligence as a factor in that process, but I I I do think that's one of the areas where there is a little bit lag behind and folks aren't realizing the record keeping piece of it as much.
Robert: Right. And so let's make this even more complex now as we kind of round through head for home. We've been talking about, you know, individual delivering communications via generative AI, what have you, but now we're we're getting into agents. Not as a future thing, it's it's here, it's now. You know, in some firms there are thousands of agents. And you know, we used to talk about the, you know, the common denominator here, human oversight, inspecting what these things are doing. But now, instead of human in the loop, we have human on the loop and still needing to provide oversight and still holding the responsibility.
Michael, wha what do you see the biggest changes that are that are happening here on these questions because of agentic? Where it's system interacting with system sometimes autonomously, sometimes, you know, without proper authorization or identification of who they are and what they should have access to. How how are firms wrestling with this new dimension?
Michael: Yeah, so I mean I think at a high level, right? You have to remember the firms still have a responsibility to identify and maintain and retain records, right? That has not changed with generative AI, with agentic AI, with anything. But like you highlighted, agentic AI is less human in the loop than generative AI is. And, you know, firms are being more cautious when it comes to agentic AI, right? They are trying to do human in the loop as much as possible. They are trying to, you know, have highly sort of predictive activities that these agentic AIs are taking and you know, have audit trails if possible of what actions are being taken. But, you know, they also don't want to stop in the way of innovation. And, you know, trying to find that balance is what firms are are battling with right now because, this is where the future of AI is going. This is where the future of business is going, but they need to stay compliant with the regulations. They need to retain these records.
Robert: Right. And I think we've seen some of these things play out with model risk management in the surveillance space, but how do how do firms apply that same sort of discipline and logic across every other agent, across the, you know, the multitude of things, some of which represent very high levels of risk and others are unknown. So any final thoughts, Anthony, Therese, on kind of how firms can be thinking about agenda from a risk management prioritization perspective?
Anthony: I think they're not thinking about it enough. But look, I think there's tremendous amount of risk here. I think I always talk about, you know, strategy, right? What is your strategy for AI agents? If your strategy is we're gonna use agents everywhere, including high risk, you know, trading, investment advice, all of that. And you're using agents for that. I think the reality is, and we'll see what the regulators do, but thinking about like making sure that you have good due diligence, good monitoring, audit trails, frankly, keeping some of that audit trails, whether it's a record or not, I think you probably need it to defend yourself when inevitably, particularly for a high risk area, the agent goes awry, right? Because you have to show, this goes back to what Therese said, you have to show governance around it, that you actually thought about, okay, it's a high risk area. We've done all this work. I think the reality is, which we keep talking about from a risk perspective, there's going to be agents doing stuff that isn't as risky. And I think there's going to be a lot less governance around that. And that's that's a choice people make. But I think it's it's triage, right? At this stage, I think legal compliance have to do triage. Focus on the areas that are the highest risk and make sure it's, you know, you're doing everything you can from a governance perspective, mitigating risk. And other than that, you hope for the best.
Therese: Yeah. And I think that again, we're gonna go back to echo this governance piece of this. You know, the the struggle one of the struggles with the gentic AI is when is it the difference between this is just a technology that's doing stuff? You know, because there's going to be so much of this and thousands of it, it's gonna be involved in every every application and every process you have. And when is it something that you need to have hands-on governance for?
We had a situation with a client where we were reviewing some of their their applications and we were looking at the users of an application, and fifty percent of the users in that application was a a a digital employee, which was, you know, agentic AI. And we said, Why are these agents in this application? What are they doing? And no one could answer the question. That's a problem, right? So I think a lot of this is gonna be, as Anthony said, one is gonna be give as much governance and rules to your people as you can to allow them to know what they are expected to do. It is unrealistic to expect that legal and compliance are going know every agent in your organization. But if you give your teams enough information to say, here's what our governance structure is for agents. Here's when you can use them, here's the guidelines, here's this, here's when it has to go through a higher level review.
Right? So that you are empowering your IT folks and your business folks to say they know what the rules are to some degree, as much as it may terrify the lawyers, you have to rely on your businesses to comply. You have right audit trails, you have monitoring of it, you have checks on that. And then put your resources where there is. What are the things that have to go through a higher level review? Because as they said, Anthony, it is higher risk. So I really think with this, you know, we keep saying it, but coming back to a reasonable governance structure.
That you can allow the business to move forward and to do what they need to do to comply with checks and balances on that, and then higher scrutiny on the things that are the highest risk. That's going to be the best model for I think compliance. It's really a matter, I think, of how do you get there and how do you structure it in a way that it can actually operate in a reasonable way?
Robert: And it sounds like we're doing all this in real time simultaneously, building the road, designing the guardrails, powering the vehicle and designing the braking system. So, know, s
Therese: Yeah.
Robert: in spite of all that, we're probably not too far away from agents with employee numbers and badges and treated like with the same rights and privileges as anyone else. Probably not too far away.
Anthony: Yep. I agree.
Therese: Yeah, true.
Robert: Hey, well, great discussion. Really appreciate you guys sharing your insights. Good to calibrate with you always. And thanks again for the invitation.
Anthony: Yep. And thanks everybody for listening to Tech Law Talks. Listen for new episodes coming soon.
Outro: Tech Law Talks is a Reed Smith production. Our producers are Shannon Ryan, Amanda Saunders, and Mason Kautz. For more information about Reed Smith's Emerging Technologies Practice, please email [email protected]. You can find our podcast on all streaming platforms, reedsmith.com and our social media accounts at Reed Smith LLP.
Disclaimer: This podcast is provided for educational purposes. It does not constitute legal advice and is not intended to establish an attorney-client relationship, nor is it intended to suggest or establish standards of care applicable to particular lawyers in any given situation. Prior results do not guarantee a similar outcome. Any views, opinions, or comments made by any external guest speaker are not to be attributed to Reed Smith LLP or its individual lawyers.
All rights reserved.
Transcript is auto-generated.