AI is moving quickly across organizations. Companies are scaling existing use cases, introducing new tools and giving more employees access to AI as they look for ways to improve efficiency and stay competitive.
That expansion is making AI governance a shared responsibility. CIOs are responsible for helping their organizations adopt the technology effectively and securely. Legal teams are increasingly focused on the litigation, regulatory, privacy and compliance risks associated with its use.
As AI reaches more parts of the business, these teams need to work closely together. Each has visibility and expertise the other needs, and both have an important role in helping the organization scale AI responsibly.
AI has changed the relationship between IT and legal
AI touches nearly every part of a business. It can involve company and customer data, influence decisions, interact directly with employees or customers, and perform work through agents.
Agents, in particular, have changed the governance equation over the past year. When companies were primarily piloting AI, much of that experimentation happened within IT. Those teams were accustomed to working within security, data and compliance requirements. Now organizations are under pressure to scale AI beyond those controlled environments.
That shift is already well underway. McKinsey’s 2025 State of AI survey found that 88% of respondents said their organizations regularly use AI in at least one business function, up from 78% the year before.
I see that pressure from both sides. As a CEO and a member of several boards, I push companies to use AI because I believe failing to adopt it effectively poses a serious competitive risk. But that same push for adoption makes governance more important, not less. CIOs are being asked to expand AI use while simultaneously managing risks that become harder to see as adoption spreads.
The strength of AI agents is that nontechnical employees can use them to build workflows and automate work. People in HR, finance, marketing, communications and other departments no longer need to wait for IT to develop every AI-enabled process. That accessibility creates enormous opportunity, but it also means AI can be deployed by employees who aren’t accustomed to evaluating security, compliance, privacy or legal risk.
Organizations therefore need to know what data an AI system is using, where that data came from, what decisions the system is making, and whether those uses align with company policies and legal requirements.
AI may also be embedded in third-party products an organization already uses. This creates shadow AI, where organizations may have AI operating without a complete understanding of where or how it is being used.
This is one of the biggest areas of risk we see. When we work with organizations that have five or 10 approved AI use cases, those applications usually aren’t where we find the most significant problems. The company already recognized those use cases as potentially risky, so someone evaluated them. The greater risk often comes from the AI the organization doesn’t realize is operating at all.
Understanding how AI is being used across the organization gives CIOs and legal teams a place to start.
AI requires closer collaboration
Legal teams are becoming increasingly aware of the exposure AI can create. There are new AI laws and regulations developing around the world, along with significant litigation happening under laws that already exist.
That concern is showing up among corporate legal leaders. In Norton Rose Fulbright’s 2025 Annual Litigation Trends Survey, 56% of respondents said managing the litigation and legal risks surrounding generative AI had been a challenge for their organization.
Many of those lawsuits involve familiar legal issues, including discrimination, consumer protection, privacy, wiretap laws and consent to use data. AI is simply the context in which those existing issues are now arising. There is no broad exemption from existing law simply because a decision or activity involves AI.
That legal risk isn’t always well understood throughout the rest of the organization. I recently met with a large retailer that had its CIO, COO, technical leaders, business leaders and an attorney in the room to discuss AI governance. When I raised litigation risk, much of the group wasn’t particularly concerned. The attorney was.
She explained that legal was deeply concerned about the company’s exposure and that the company had already faced an AI-related lawsuit. Several other people in the room didn’t know that had happened.
That type of disconnect matters as organizations scale AI. Legal may have information about litigation, regulation, contracts and privacy concerns that hasn’t reached the people making technology decisions. IT has visibility into systems, vendors, data, security and how AI is being deployed across the business.
Regular collaboration gives both groups a more complete understanding of what the organization is doing and where its risks are.
What CIOs and legal teams bring to AI governance
CIOs and technology leaders have an important role in creating visibility around AI. They can help organizations identify the systems and use cases already in place, including internally developed AI, third-party tools, vendor applications and shadow AI.
They also understand the organization’s technology environment. That includes its security requirements, data infrastructure, technical standards and the practical considerations involved in deploying AI at scale.
Legal teams bring a detailed understanding of the legal risks surrounding those same use cases. They can help determine which regulatory requirements apply, identify privacy or intellectual property concerns, review contractual obligations and evaluate whether the organization has the right to use particular data.
In large organizations, the attorney most familiar with AI risk may not be the chief legal officer. It may be a deputy counsel or another member of the department who has been following the issue closely. At smaller companies, it may be one attorney managing AI alongside dozens of other responsibilities. Making AI risk part of the broader conversation gives that legal expertise a way to reach the people responsible for adoption.
Building a partnership between CIOs and legal teams
A strong AI governance program brings these groups together as part of an ongoing process. Many organizations are doing this through an AI governance committee that includes IT, legal, compliance, security and representatives from business units using AI. The committee can review use cases, apply company policies, evaluate risks and determine what safeguards are appropriate.
That work starts with a comprehensive inventory of AI use across the organization. For each use case, the organization should understand what the technology does, what data it uses and what decisions it makes.
The use case itself matters because the same underlying technology can carry dramatically different levels of risk depending on how it is applied. Using generative AI to draft promotional copy about a city, for example, presents a very different risk profile than using it to prepare information that will be submitted to a federal regulator.
From there, the committee can evaluate the use case against company policies and identify areas that need to be addressed. If a resume-screening tool creates a risk of bias or discrimination, for example, the organization may decide to test it regularly or require human review. If an application uses sensitive data, the team needs to understand where that data came from and whether it can legally and securely be used.
The process also needs to be documented. Leaders often believe AI governance means documenting good intentions. Regulators and litigants will care about whether those intentions were operationalized, continuously enforced and supported by evidence.
Company policies are part of that documentation. If a policy requires a human in the loop for certain risk levels, the organization needs to follow that requirement and be able to demonstrate that it did.
Shared visibility makes this process easier. CIOs, legal teams, compliance, security and business leaders should be working from the same understanding of the organization’s AI systems, use cases, policies, risk assessments and approvals. This gives the governance committee the information it needs to make decisions as AI adoption continues to grow.
AI governance requires a shared approach
AI will continue reaching more systems, business functions, vendors and employees. That makes collaboration across the organization an increasingly important part of governing it well.
CIOs understand how the technology is being deployed and what it takes to scale it. Legal teams understand the laws, litigation and other areas of exposure surrounding that use. Bringing that knowledge together gives organizations a clearer view of their AI environment and a stronger process for evaluating new use cases as they emerge.
AI has enormous potential, and companies need to find ways to use it effectively. Scaling it safely requires safeguards and governance to be built into adoption from the beginning and maintained as AI use expands.
For companies expanding their AI usage, such a shared approach provides the structure needed to keep up with the technology and the risks that come with it.
Read More from This Article: The CIO-Legal partnership will define the future of enterprise AI
Source: News

