Learn

How Legal can lead AI culture in the workplace

Discover from Summize General Counsel Lexi Lutz how Legal can shape a responsible AI culture, enable adoption and help the business manage AI risk with confidence.

Published:

September 21, 2026

Navigate through the article
See Summize in action
Book a demo
Only got a minute? Here are the key takeaways
  • Legal is already at the center of governance – 80% of in-house legal professionals are involved in AI governance, putting Legal in a strong position to shape AI usage.
  • An AI policy isn’t enough – policies set boundaries, but an AI culture helps employees understand how to use AI responsibly in practice.
  • Legal can enable AI adoption, not just control it – clear guardrails, better questions and proportionate oversight can help the business experiment safely.
  • Visibility is more valuable than fear – when employees feel comfortable sharing how they use AI, Legal can identify risks, support useful use cases and shape adoption.

Research from Summize’s own AI Fluency Report found that almost 80% of in-house legal professionals say Legal leads or shares responsibility for AI governance.  

Legal has a unique role to play in AI adoption and development across the business – they’re high users of AI (some of the highest according to research by Harmonic Security) and they sit at the intersection of regulation, risk and commercial decision-making. This gives Legal an important role in helping the business adopt AI responsibly, not simply deciding which tools employees can use. But governance is only one part of that picture.

Policies can define what people should and shouldn’t do with AI. But they can’t fully determine what happens when employees start experimenting with AI in their day-to-day work. That’s where AI culture comes in.

Over half of businesses still don’t have an AI policy.

Source: Process Excellence Network

If you’re one of them, start with our article on how Legal can get involved in putting together an AI mandate.

So, we spoke to our General Counsel Lexi Lutz to find out how she’s leading on AI culture at Summize and how you can do it too.

What is AI culture and why does it matter?

There isn’t one universally accepted definition of AI culture, but at Summize, we define it as how people actually use AI when nobody is watching.

It embodies whether…

  • Employees feel comfortable asking questions about AI
  • They understand the risks associated with different use cases
  • They know where the boundaries are
  • They feel comfortable experimenting and sharing those experiments

A strong AI culture doesn’t mean you need to encourage everyone to use AI for everything. It means people understand when AI can help, how to use it responsibly and when they need to stop and ask for guidance.

Why isn’t an AI policy enough?

Individual AI experimentation is moving faster than policies can keep up with – according to cyber risk firm UpGuard, 81% of employees report using unapproved AI tools, showing how widespread the issue of shadow AI really is.

No one can eliminate experimentation completely, so we need make sure AI use is visible, more informed and safer. Culture helps bridge the gap between what our policies say about AI use and what people are actually doing with it.

There’s a big difference between just having an AI policy and creating an AI culture. This is how we see the stages in between:

Stage What it looks like
1. Policy-led AI policies are in place and employees are encouraged to use approved tools.
2. Supported adoption Teams receive practical guidance, training and examples of appropriate AI use.
3. Shared learning Employees actively share use cases, questions and lessons learned across teams.
4. AI-enabled culture AI champions, regular conversations and feedback loops help the organization continuously learn and adapt.

How Legal can become an enabler rather than a blocker

The instinct when dealing with new technology is often to focus on control: what are the risks? What could go wrong? What shouldn’t we allow?

Those questions are important, but they shouldn’t be the end of the conversation. Ultimately, we should aim to be a runway for the business to fly, rather than a roadblock pulling them back. This means moving from simply setting restrictions to getting involved early and helping the business understand how far it can go safely. Here are four ways I’ve done this at Summize and how it can work for your business:

Enablement over enforcement

An AI policy tells people what they can and can’t do. Enablement helps them understand why, and what they can do instead.

At Summize, I lead practical sessions on AI, provide examples of good and bad AI use cases and create clear guidance around the type of information employees can share with AI tools. The goal is to make existing guardrails understandable so that people can work confidently within them, rather than removing them altogether.

Questions over blanket rules

Not every AI use case creates the same level of risk.

Rather than hearing “are we allowed to use AI for this?”, help the business ask better questions as they use AI, for example:

  • What data is being entered?
  • What systems can the AI access?
  • Is the AI simply generating information, or can it take autonomous actions?
  • What happens if the output is wrong?
  • Does the use case involve confidential, sensitive or commercially important information?
  • How much human oversight is required?

Ask these questions to help everyone take a more nuanced approach to risk. A low-risk productivity use case may need very different controls from an AI agent with access to critical business systems.

Empowerment over bottlenecks

You shouldn’t need to approve every individual use of AI. Clear guardrails can give your business the confidence to experiment within defined boundaries, while allowing you to focus your attention on higher-risk use cases.

That might mean approving certain tools and environments, restricting access to sensitive data, requiring additional oversight for autonomous capabilities or preventing the use of particularly high-risk tools altogether.

Visibility over fear

Perhaps most importantly, get your business feeling comfortable to talk about how they’re using AI.

If your business is worried that admitting they’re experimenting with a tool will get them into trouble, they’re much more likely to experiment out of sight.

Creating a culture where people can ask questions, share new use cases and flag concerns gives legal visibility, which is arguably more valuable than control. At Summize, we run regular enablement sessions that create opportunities for people to learn from each other, rather than expecting everyone to work out the right way to use AI alone. Practical resources like saved prompts, skills and examples of how to apply business context also gives people something they can build on.

The visibility this creates means you can understand what people are actually doing, identify emerging risks and spot useful applications that you can champion more formally.

Who to involve when developing an AI culture strategy

Legal shouldn’t develop an AI strategy in isolation. Some of the most useful people to involve are those already experimenting with AI and the teams that will ultimately be using it.

This means involving a broader group of stakeholders, potentially from IT, security, HR, operations and other business teams, but also listening to the people closest to the work. I involve our Chief Technology Officer and Engineering Leads, but also stakeholders from across Sales, Marketing and Product – they all see different opportunities and risks, use AI in different ways and can help shape an approach that works for the wider business. The people experimenting with AI day to day can show you where the real use cases are, what support people need and where guidance is unclear.

This is especially important as AI moves towards systems that can access organizational data and take actions on a user’s behalf.

Legal’s next role in AI

The future of AI governance isn’t just about writing better policies, but about creating an environment where employees understand the boundaries, feel comfortable asking questions and know when to involve Legal. That elevates Legal role beyond the function that manages AI risk and towards one that helps the organization use AI safely and effectively.

For more insights into AI fluency among Legal and how Legal can lead the AI charge in your organization, read our full report into how in-house professionals view their own AI fluency.

About the author
Smiling woman with long wavy brown hair wearing a light blouse against a soft background.
Lexi Lutz
General Counsel
Lexi is Summize's General Counsel with over a decade of experience advising businesses across a broad range of legal disciplines, including data, privacy and technology. Having started her career in private practice before moving in-house, she's focused on delivering practical, business-minded legal advice that supports innovation while managing risk. A certified privacy and AI governance professional (CIPP/US, CIPP/E, AIGP, FIP), Lexi brings deep expertise in data protection, cybersecurity and emerging technologies. At Summize, she acts as a strategic advisor across product and customer teams, championing the use of technology while keeping the in-house legal perspective at the center. She helps ensure that innovation is grounded in real legal needs, translating complexity into practical, usable approaches for legal teams, and this balance between enabling progress and protecting legal integrity helps shape both product direction and how customers confidently adopt and scale Summize.
Connect on LinkedIn

Frequently Asked Questions

View all
  • What is Summize?
  • What makes Summize different from other CLM tools?
  • What are the three layers of the Summize product?
  • How long does the Summize implementation process take?
  • Where does Summize fit into my existing tech stack?
  • Is my contract data safe with Summize's AI?
  • The power behind every great legal team

    Book a demo