Research from Summize’s own AI Fluency Report found that almost 80% of in-house legal professionals say Legal leads or shares responsibility for AI governance.
Legal has a unique role to play in AI adoption and development across the business – they’re high users of AI (some of the highest according to research by Harmonic Security) and they sit at the intersection of regulation, risk and commercial decision-making. This gives Legal an important role in helping the business adopt AI responsibly, not simply deciding which tools employees can use. But governance is only one part of that picture.
Policies can define what people should and shouldn’t do with AI. But they can’t fully determine what happens when employees start experimenting with AI in their day-to-day work. That’s where AI culture comes in.
So, we spoke to our General Counsel Lexi Lutz to find out how she’s leading on AI culture at Summize and how you can do it too.
There isn’t one universally accepted definition of AI culture, but at Summize, we define it as how people actually use AI when nobody is watching.
It embodies whether…
A strong AI culture doesn’t mean you need to encourage everyone to use AI for everything. It means people understand when AI can help, how to use it responsibly and when they need to stop and ask for guidance.
Individual AI experimentation is moving faster than policies can keep up with – according to cyber risk firm UpGuard, 81% of employees report using unapproved AI tools, showing how widespread the issue of shadow AI really is.
No one can eliminate experimentation completely, so we need make sure AI use is visible, more informed and safer. Culture helps bridge the gap between what our policies say about AI use and what people are actually doing with it.
There’s a big difference between just having an AI policy and creating an AI culture. This is how we see the stages in between:
The instinct when dealing with new technology is often to focus on control: what are the risks? What could go wrong? What shouldn’t we allow?
Those questions are important, but they shouldn’t be the end of the conversation. Ultimately, we should aim to be a runway for the business to fly, rather than a roadblock pulling them back. This means moving from simply setting restrictions to getting involved early and helping the business understand how far it can go safely. Here are four ways I’ve done this at Summize and how it can work for your business:
An AI policy tells people what they can and can’t do. Enablement helps them understand why, and what they can do instead.
At Summize, I lead practical sessions on AI, provide examples of good and bad AI use cases and create clear guidance around the type of information employees can share with AI tools. The goal is to make existing guardrails understandable so that people can work confidently within them, rather than removing them altogether.
Not every AI use case creates the same level of risk.
Rather than hearing “are we allowed to use AI for this?”, help the business ask better questions as they use AI, for example:
Ask these questions to help everyone take a more nuanced approach to risk. A low-risk productivity use case may need very different controls from an AI agent with access to critical business systems.
You shouldn’t need to approve every individual use of AI. Clear guardrails can give your business the confidence to experiment within defined boundaries, while allowing you to focus your attention on higher-risk use cases.
That might mean approving certain tools and environments, restricting access to sensitive data, requiring additional oversight for autonomous capabilities or preventing the use of particularly high-risk tools altogether.
Perhaps most importantly, get your business feeling comfortable to talk about how they’re using AI.
If your business is worried that admitting they’re experimenting with a tool will get them into trouble, they’re much more likely to experiment out of sight.
Creating a culture where people can ask questions, share new use cases and flag concerns gives legal visibility, which is arguably more valuable than control. At Summize, we run regular enablement sessions that create opportunities for people to learn from each other, rather than expecting everyone to work out the right way to use AI alone. Practical resources like saved prompts, skills and examples of how to apply business context also gives people something they can build on.
The visibility this creates means you can understand what people are actually doing, identify emerging risks and spot useful applications that you can champion more formally.
Legal shouldn’t develop an AI strategy in isolation. Some of the most useful people to involve are those already experimenting with AI and the teams that will ultimately be using it.
This means involving a broader group of stakeholders, potentially from IT, security, HR, operations and other business teams, but also listening to the people closest to the work. I involve our Chief Technology Officer and Engineering Leads, but also stakeholders from across Sales, Marketing and Product – they all see different opportunities and risks, use AI in different ways and can help shape an approach that works for the wider business. The people experimenting with AI day to day can show you where the real use cases are, what support people need and where guidance is unclear.
This is especially important as AI moves towards systems that can access organizational data and take actions on a user’s behalf.
The future of AI governance isn’t just about writing better policies, but about creating an environment where employees understand the boundaries, feel comfortable asking questions and know when to involve Legal. That elevates Legal role beyond the function that manages AI risk and towards one that helps the organization use AI safely and effectively.
For more insights into AI fluency among Legal and how Legal can lead the AI charge in your organization, read our full report into how in-house professionals view their own AI fluency.
