The Privacy Filter: A Briefing on Privacy Law and Policy
The Privacy Filter: Barnes & Thornburg's Briefing on Privacy Law & Policy breaks down the legal and regulatory developments shaping data privacy, data security, and artificial intelligence. In each episode, the firm’s attorneys and guests translate emerging laws, enforcement actions, and technology trends into practical insights for business leaders and in-house counsel.
The Privacy Filter: A Briefing on Privacy Law and Policy
The AI Era Is Redefining the Role of the General Counsel
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode, Erica Sylvester, General Counsel at Authenticx, shares insights on how AI and privacy law are transforming the legal landscape, especially in healthcare. She discusses the evolving role of GCs, the importance of understanding product details, and strategies for legal professionals to stay ahead in the AI era.
Key Topics:
-The transformation of the GC role due to AI and privacy law
-Strategies for understanding and managing AI risks
-The importance of cross-functional collaboration in AI governance
-Legal considerations in healthcare AI and PHI
-Best practices for legal professionals entering AI roles
Welcome to the privacy filter, Barnes and Thornburg's briefing on privacy law and policy. Subscribe for the latest updates.
SPEAKER_01If you run a legal or privacy function, the job you train for is probably not the one you have anymore. AI moves super fast, as we all know, and the old model that we trained under couldn't really keep up with the pace. The one where the legal reviews at the contract at the end signs off and moves on, maybe hears about it the day before. We're past that. That model's breaking because by the time a product reaches your desk, the decisions that created the risk were already made by your teams weeks ago. The general counsel role has been rewritten over the last couple of years. Most GCs are still catching up, in my experience. But my guest today isn't catching up. She's living it and helping push it forward. Please meet Erica Sylvester, who's general counsel at Authentics, a healthcare AI company. And her role puts her at the intersection of voice data, protected health information, and machine learning, all difficult topics. That's the version of this job most in-house lawyers are about to have, whether or not you guys see it coming. I'm Brian McGinnis and welcome to the Privacy Filter. Erica, thanks for joining us. Really appreciate you taking time out of your day to do so. Before we get into how this job has changed for you, I want to give people a bit more of an idea about Authentics and what you guys are doing and how your seat looks as a GC there.
SPEAKER_00Thanks, Brian. I really appreciate you having me on this podcast and frankly for putting this podcast together because as you mentioned, we're all in it and all learning at the same time as things are changing. So I work at Authentics. We are headquartered in Indianapolis. We are a Series B company, about 140 employees. What we do is we are a healthcare technology company. We support patient services, pharmacovigilance, and other call center operations to review data at scale. We provide insights, themes, reportable events for FDA tracking and other topics to improve ROI and the patient experience. So how we do that is through our proprietary AI models. Our team of engineers has been building those models for the past eight years, has gone through, of course, as you'd imagine, several iterations to present date. But what we believe to be our strategic advantage is really our healthcare data and the data that we have utilized to build those models to ensure that we have accurate output for our clients who, as you can imagine, are in the healthcare industry and accuracy of information and privacy of information, including that PHI, that personal health information, is at the top of their minds. So that really kind of centers on both our models, our diligence, and how we are managing the data from the legal, compliance, and regulatory sides. So my role really is interwoven, interweaves with our engineering, our product teams, much more than even anticipated when I started about two and a half years ago. So it's been a really interesting journey. I've learned so much. I have so much more to learn, but I'm really excited to talk about all of the different things that I get to see on a day-to-day basis and that have changed, frankly, in the two and a half years that I've sat in this role.
SPEAKER_01Yeah, absolutely. And that's why we're excited to have you on. I think this conversation is going to be really relevant for a lot of people who are in your position. I mean, we're primarily covering privacy, uh, obviously on the privacy filter, but I'm sure you and many of your colleagues have learned pretty quickly that uh a lot of the people who came up doing privacy or just maybe getting a handle on what their company's doing with privacy are now also being taxed with being your global AI officer for a multinational company, things like that, right? So all this is coming at us extremely quickly, I think, in a lot of companies. Uh, that is the way that they're forced to handle it. They're sort of handling the governance and the AI development similar ways, uh, often with the similar people as they are on the privacy side. There's a lot of skills overlap requirements. I think regulators are bundling these things together as well. So even if your title only says privacy today, and honestly, across any uh legal practice area that you may have familiarity with or experience in, AI is going to drive into that area uh perhaps even more quickly than you think. So, Eric, I guess given all of that, when did you realize the role that maybe you thought you were taking uh when you joined Authentics needed to morph or has morphed uh a little bit since you got there?
SPEAKER_00Frankly, my background is I'm a litigator. So when I wanted to go in-house, it was because I wanted to have a more kind of general practice. I wanted to be more proactive than reactive on the litigation side. I wanted to help develop the processes to avoid the litigation. I wanted to help manage the contracts to avoid the blow-ups down the line and all of that. I wanted to be a part of a business. And I think while that still rings true, I did not realize how much a part of the business I was about to be. What do I mean by that? I mean that I um frankly have got the opportunity to sit in two seats that I didn't expect. One seat is on the commercial side, where I have been like deeply ingrained in our sales team at this point. I am sitting on customer calls regularly. I am talking with AI governance boards of prospects and of current clients. Those AI governance boards, as you can imagine, are comprised of privacy professionals, of lawyers, of business representatives, of IT, of security, um, of sometimes their engineering teams, um, all different folks from all different backgrounds that we are having to present our product, our services, and our compliance models to. So that is something that I really enjoyed doing, but was not something that was one in the job description or two, something I really anticipated at the time of taking the role. So that's kind of the commercial side and the aspect where I've really enjoyed getting to learn how to sell, but also be the moderate lawyer voice in the room, such that we are able to convey a trustworthy partner for our prospects and for our clients to continue to engage.
SPEAKER_01Yeah. So why do you think that is? I mean, you know, that's far beyond the traditional like, hey, in-house lawyer, do this contract, review this, tell us, you know, if we can or can't do this thing, you know, handle this dispute, uh, this piece of litigation with outside counsel. Why do you think it is that you're uh being part of those calls as much as you are?
SPEAKER_00Yeah, so I think one reason is the true commercial contracting aspect, right? So I am negotiating the terms that are included within our contracts. That includes the data privacy side, the data retention policies, the um the SLAs relating to uptime. Um, it also includes the data ownership and the data training and what you're gonna do with our data. How is that data managed? Is it fully redacted? What kind of PHI are you gonna have? So if I'm the one that is negotiating a lot of those terms within the contracts, then we also need to be able to speak to it to the different groups within our clients and prospects so that they understand where it's going also. It's not just a legal thing anymore, right? Because everybody is concerned about how their group is gonna be impacted by the use of this data. They may not think of it in the way that us lawyers think of it, in terms of, well, this is how we're going to agree to it. Instead, a lot of them, and you know, this is on my mind too, but a lot of them are thinking about what are our patients gonna feel about this? Like, how is this gonna look in the industry? Is this something that we're that we have consent for from our patients to do? Um, so all different things that are really kind of combining in this, you know, be it an AI governance review, be it a security review, this often comes up too. So it's kind of coming across the board from a cross-functional angle. So it's it's really interesting. I don't know that it has to be the lawyer, and I know we're gonna get to that in a little bit, that has to have all of these conversations, but it's certainly something that falls within the realm of what I'm doing at Authentics. Again, I mentioned we're about 140 people. I'm a solo GC. Maybe I should have mentioned that at the beginning, because that'll also color some of the comments that I'm making and some of the breadth of the duties that I'm taking on. Um, because I don't have another kind of partner seat uh with me to manage some of this. So that's also part of why I'm I'm the forefront of it, so to speak. But there's a lot of different factors that go in.
SPEAKER_01Are you seeing most often on those calls? Is there counsel on the other side as well, typically?
SPEAKER_00I would say that there is typically a lawyer involved, but not every time in the AI governance review. I would say more often than not, it's their privacy attorney that is involved and their compliance professionals that are involved. You know, now if they've got AI roles, certainly the whether it's their, you know, AI operations or chief AI officer or AI risk role, those are definitely coming up a lot more. Or this AI governance board is reporting it up to the chief AI officer such that that person has the final stamp of approval. Um, so there's a lot of new roles and a lot of different, um, a lot of nuances that are involved.
SPEAKER_01Okay. So a lot more involvement than you expected maybe going in. Are there places that you try and stay out of uh where you deliberately don't want to be in the room?
SPEAKER_00When we're talking on the commercial side with prospecting or my internal side.
SPEAKER_01Uh, I mean any of the meetings, right? You're getting called into, and we'll get into this, I think, maybe in even more detailed engineering meetings sometime internally. Um we covered the external piece, but are there places that you feel like your role should have boundaries and and uh try and intentionally keep out of?
SPEAKER_00I yeah, I do. And I I will say one thing on the external side. I still have to be very careful um because while this is not uh like a conflict-based approach, I do want to be sure that I'm not running afoul of my canons as a lawyer if the other side isn't represented by an attorney, even though we're not in, you know, an opposition standpoint. So I like to be really clear with that up front. And then sometimes that alone will then remove me from the conversation. And then I'm bringing in my chief privacy officer or someone else to handle the call. So I do want to note that that that has presented some challenges for me as the general counsel hat on, as opposed to just like a business person that's explaining our AI processes.
SPEAKER_01Yeah, great tip.
SPEAKER_00From the internal side, the spaces, and this kind of goes to part two where I didn't really expect to be as ingrained is with product and engineering. I mean, the biggest piece of advice that I got, this is my first time being a general counsel. The biggest piece of advice that I got from mentors that are general counsel, others that are in high-level roles at large public companies, general counsel and beyond, make sure you know your product, make sure you know what you're selling, understand what it is that you guys are doing in the industry. And so I really went in with that in mind, but I don't think that I understood the breadth to which I was going to need to understand the details, the nuances, and frankly the science behind what our project product is. So, to that end, like I have become, I have one-on-ones with our chief product officer bi-weekly, one-on-ones with our chief technology officer bi-weekly. We have leadership meetings weekly, which involves, of course, our CPO, our CTO, our CEO, all of our C-suite. Um, and so that we get to hear about all of these, oftentimes those meetings include where are we going with the product, so that I get to hear that on a weekly cadence in addition to my one-on-ones, um, and roadmap meetings. To answer your question, though, about where I don't want to plug in, I don't want to get in the way of the creativity of our teams, such that we are pre-limiting ourselves from an idea or a concept that they are developing that is going to be successful in the end, but that I may want to interject in before they go to full work mode on it. So there are tons of meetings that I am not a part of. And instead, there will be notes when I come into the next product or review map or um our SLT meetings or anything like that, our senior leadership team meetings, that are gonna be like, Erica, I wanted to talk to you about this because our team is thinking about going in this direction, but this starts to get into some data questions that we have. So can you come to our next meeting or can we schedule some time to talk about it? So I think that we've got a really good cadence right now in terms of like, I trust them to know when to bring me in in addition to these standing meetings, but I'm also giving them the creative capacity and space to develop and to perform their roles to make sure that our company can be successful and stay at the front of the line, so to speak, um, in our industry.
SPEAKER_01Yeah, that's some interesting insight into how you sort of think about that as your role and how you plug in and like you said, stay away in certain cases. I want to pick up a little bit more. You talked about heading into the role and preparing for it. Um, and then I think you covered well some of the things that you do now to sort of stay up on what the team is currently doing. Tell me a little bit more about the process leading into that job. Let's say somebody out there is looking for a new role, uh, they're going to a new company. Good chance that that's going to involve a heavy AI role these days. Let's say, how did you prepare any tips that you can give to people preparing to enter into a new company to help them get up to speed quickly?
SPEAKER_00So I started two and a half years ago. And at that time, frankly, it was before the AI boom. Like we were an AI company at that point in time. So what I did before starting and during the interview process, and when I was just kind of in initial phases, I was listening to podcasts like this. I was reading articles. I was like my LinkedIn um algorithm was starting to bring up all of the different posts, all of the different updates on AI, which was like probably one-tenth of what is out there at this point. So I was just kind of familiarizing myself with the terminology, with the language, with some of the risks that were coming to kind of set at the top of the list at that time. And I think that that's still what I would recommend for someone trying to go into a role like this today. I think there's a ton more information out there. I think there's a bunch more that you can plug into, be it IAPP that has like very specific AI tracks, there's an AI governance professional certification, um, there's all different kinds of things from that like general education standpoint, just from a familiarization aspect. But I would say that like using it on your own, AI, that is, and developing some mechanisms for yourself to show that you're going to be efficient and show that you want to learn in those ways. Because to me, it's more about the openness and like desire to engage in things that you don't understand, which is incredibly uncomfortable for us as lawyers. Like so often you want to have the answer and already know how to do it and say yes. But like this is a space where that's just like it's not the case for me.
SPEAKER_01Key point too. I mean, getting sort of your hands dirty and playing around with the tools and the technologies, especially as they change. I've had a number of conversations recently about the importance of that. And I find, you know, with myself, the more that I use these tools, the more that I use different tools and try different things, it inevitably makes you think of additional things that you can do that you can't really sort of unlock until you've got a certain base level. So uh absolutely encourage people, lawyers and otherwise, get in, start messing around with stuff, think of new ways that you can use these tools, which is only going to multiply and get you additional uh really benefits to sort of unlock the power of AI and what these tools can do currently.
SPEAKER_00Yeah, I completely agree. I think too, it has allowed me to identify some risks because I'm like, oh wow, okay, like I'm thinking about this and I know that I shouldn't input this document into a non-enterprise, you know, AI model or my own chat GPT versus my enterprise claude. But is everybody else thinking about that? Like, what do we need to do from a training perspective? How do we need to make sure that we're managing our internal controls? Like, we don't need maybe SharePoint to be connected in some ways because oh my gosh, what if we lose all this information? This is proprietary information. So it's like it also highlights things where you're like, oh my gosh, if I wasn't thinking about this, or somebody just didn't know yet, this could create a significant risk for our company. Um, so I think doing that play around technique also allows you to be like, whoa, there are some guardrails that we need to.
SPEAKER_01Yeah, let's dig in on that a little bit more. So um somebody has to control this, right? And a lot of times that ends up falling into the GC's office or compliance office and those kinds of things. We see a lot of questions and get a lot of questions from clients like, where does this live within an organization? Where does it sit on the org chart? Uh, I know you've got some thoughts. It could be lots of different things, but you know, basically AI risk oversight, AI risk governance. Is this legal? Is this compliance? Should this be somewhere else? Is there an internal sort of making sure that we're using AI right team lead, uh, making sure that people aren't going out and using the tools? Or does all that fall within the legal role as well? How do you guys structure it? What do you think a good way to handle those overlapping uh sort of considerations are?
SPEAKER_00I mean, it's hard. I don't think, to your point, I don't think that there's a clear answer as to what's best, so to speak. I think so much of it depends upon your company structure, what industry you're in, how you're gonna be like, is your product AI or are your is your company just using AI? I think those are two different things and probably would provide the two different answers to the question. I think from right now, how we are viewing it, it's a combination, right? Like when I think about compliance, I think about rules and laws that are developed such that we know what kind of operational techniques need to be implemented to ensure that our clients and our customers are compliant and that we're following the rules. Compliance oftentimes comes with it's kind of black and white, right? Like it's kind of like an audit. You're either gonna fail it and you're gonna get a finding on it of some level, minor, material, major, whatever, or you're not, you're gonna pass like you did it. And that might be too archaic of a perspective, but when I think about AI, it doesn't really align there for how we're managing it at this point. And instead, it requires a lot of gray area, risk assessment, business risk assessment for how much we want to lean in and how much we want to lean out, and also the evolution of the laws that are out there, right? Like the EU AI Act just gave us some more examples just a couple weeks ago of what high-risk AI really is. We've got Colorado repealing, reinserting, going kind of back and forth. We got several states that are trying to figure it out. And I think that really requires legal oversight, legal understanding, and some ability to fill in that gray so that we can be the advisors to the company on, you know, hey, here's some risk in this, but this may be worth it for our business to lean in. And here are some mechanisms that we can operationalize that may be applicable to each of these different legal regimes and approaches to how to manage AI. You know, this kind of harkens back to privacy, but I think privacy happened a little bit faster and was maybe a little bit clearer. Um, I and I don't want to say privacy happened faster. AI has been implemented faster than privacy has, but the law with AI has not taken place in terms of the speed for how much it's leaning forward and how much people are using it. So I guess from that perspective, I'm leaning toward legal owning it. Um, but also in saying all of that, from a legal perspective, we're not really operational owners. Like we're not great at implementing how to um for a whole business to set up a plan, to train on that plan, to implement that plan, to continue to monitor that plan. It's more like we then kind of step back as we get to that spot and hand it off to somebody that maybe that is an AI risk, you know, role or a chief AI officer role. Um, there's just so much to it that there's not like a full seat that's going to own it unless you have a full function, maybe underneath legal or maybe underneath compliance that could own it. So that's a pretty gray, gray answer to your question, but that's that's how I'm thinking about it at this point.
SPEAKER_01I think that's exactly where we are and where we see most clients too. And there's always that push-pull between like how big do we need to get before we start hiring non-legal people who serve this compliance or sort of chief trust officer, chief AI officer role who aren't lawyers but can be the doers in this space and get these policies and everything into place. Uh, but until then, there's like unless you and until you've assigned that role to somebody within the organization, chances are nobody's doing it. And it's one thing to have conversations about it, and that's great to sort of get everybody going in the same direction. But really, unless and until you start to formalize those things and reduce those into policy, into procedures, into what we would call a governance program overall, you're really not compliant. And that could be a moving target too. It's like, when's the right time to do that? I don't know, maybe from you, like, how do you guys think about you know, hey, we just had this great conversation about how staff should be using AI or this new tool? Uh, do you immediately get Go to policy on that? Does that just sort of carry forward in the business as sort of this is how we do things? Or like I guess, do you have any time left over in your day to think about how do we reduce this into uh I guess improving our governance program or written governance program?
SPEAKER_00Yeah, so we have gone straight to policy on those things. Um, partially because we needed something written because we were getting so many questions that it was taking more time to answer one-off questions and you don't know about the consistency. Exactly. Um, also, a lot of our clients require that we have these written policies from their quality management side. Like, how are you using AI internally? And should that impact how much we're paying you for your services? Um, I know law firms are kind of facing the same question. Um, so so the policy helps us in those kinds of ways. But I would say there is still a lot of gray space. We're utilizing Cloud Enterprise. We right now do not have it connected to our SharePoint or our emails. Um, we are hesitant because we've got you know PHI of clients when our our client-facing people are engaging with us at times based on what our clients are asking us to analyze. So we don't want that to go in. Um, so we're really just trying to manage and understand what our risk tolerance is, what our clients allow us to do. Um, and then also just like, what is our real use case here? How are we managing? What is the service that we want to provide? We obviously want to be as efficient as possible. We are a lean company. Um, but at the same time, what are we exchanging? So it's a continual discussion. Despite having policy and identifying different things we can and cannot do, there are still gaps that we need to fill in from our own leadership perspective and how we want it to go forward.
SPEAKER_01Yeah, to pick up on an earlier thought you had, which I thought was really insightful, was sort of the speed at which this is moving. And it seems as if we've sort of learned some lessons from the privacy rollout. Uh, where, you know, 20 plus individual state privacy laws at this point, we were heading down that path, uh, still potentially are on the AI side, but you've seen a lot more involvement, it seems, uh, in my view, to stop that kind of a rollout and try and handle it more from a federal level, if not through some sort of a law, hopefully, maybe someday, uh, than through executive orders. But even those have been sort of start and stop at this point too. So, you know, we work with a lot of clients. It's kind of like we want to be compliant, we want to do the right thing, we want to have a solid governance program, but like tell just tell me what to do right now, given where we are in this landscape and the build-out of all this stuff. And it's a difficult question, even to answer that, right? So um I think this is a thing that is really dependent upon each individual business trying to find the through lines and the trends and what these laws and policies and orders are uh trying to say about where they want us to put the needle in terms of thinking about risks of uh use of AI, uh effects of use of AI on individuals. Like is this a chat bot or is this something that has to do with uh making a financial decision or an employment decision about an individual and picking those things up and then finding the right spot for how that touches each individual business and then how each individual business wants to think about implementing that into their company. Um it's a really difficult task at this point to get it right. So I think, you know, in my view, movement towards that, uh towards those goals, continual improvement, continually building and making more sophisticated those programs is really the best answer that we can give at this point for the most part, given that things are moving so quickly underneath us. All right, I want to switch gears a little bit. Product teams, engineering teams versus legal. It's kind of the oldest fight in the book in this space. I know you to be an excellent GC, and I know you want to be an enabler of your business. How do you approach that? How do you build trust with those teams uh such that they do see you in a positive light and not as that uh sort of classic department of no?
SPEAKER_00It is like the classic conflict is not the word I want to use because partnership is so much nicer. But we do have like two very different purposes, right? Like GCs, lawyers, we got to protect the business. We need to protect our our bottom line in many ways. Like, you know, the board is very interested in how we are protecting our business, our longevity. Um, product engineering, they're very interested in how we can skyrocket. Me too, right? But uh, we don't want to blow up. So, anyway. Right, right. Re-enter that reactive state. So I I think really the way that I approached it, and and I mean, maybe this goes back to like my litigation days. Like, I just when I started, I asked a ton of questions. Um, I was not shy. I let them know I'm like, listen, I'm sorry. Like, please treat me like the novice that I am in this. Like, I just want to understand. So the more you can help me understand, the better. One, I can stay out of your way. Two, I can help solve challenges and work around potential roadblocks as they may be. And three, it's just gonna make both of our lives a lot easier. So it was really just kind of going in with the open mind, um, and frankly, like guard down and transparent perspective where I was asking them questions. I was trying to have them state it in a way that they would, you know, explain to their third grader. Um, and then me trying to explain it back to them and how I understood it until I caught up a bit more. Um, and as I caught up, I think that our conversations have gotten easier. They know when to bring me questions, I know when to butt in sometimes, as I may need to. And the cadence I think is kind of balanced out. I'm not gonna say it's all roses and that it's easy and that we've got it figured out because I don't think that that's true either. But I think by allowing that level of transparency about what I know as a lawyer and what I don't know has allowed them to feel good about what it is that they know and then come to me about what they don't know. Hey, Erica, we've got this data and I really want to try to make it into a different kind of a data set to grow this new uh function that we're looking at. Can we do that? I'm like, well, okay, well, what kind of data? Let's talk about the data. What are you gonna do to change it? Where did the data come from? What is the new function? Um, you know, is there PHI? Obviously, there shouldn't be. Different questions like that, that we can then just have more of a conversation instead of an inquisition. So I think that's been really my best tactic at it, though not easy oftentimes.
SPEAKER_01Yeah, it seems like you approach it with a sense of curiosity, though, and sort of a willingness or a desire to learn. I assume they're not having to tell you these things three different times, right? You're you're taking this in and each of those projects makes you better at the next one. But um, you had a line that stuck with me as part of our prep was you're looking to create solutions to their challenges, not roadblocks to their challenges. Um, and I'm sure that that approach allows you to get over some of those things that done another way might create more conflict than perhaps is necessary or or does end up creating something that stands in the way of those teams actually building what they need to build.
SPEAKER_00Completely. I don't know that there's anything that we've completely derailed. So I think that that helps too, although things may have been modified 98% of the way at different points in time, but still being able to cross some kind of end zone, I think gives satisfaction on both sides. So, you know, take the wins where you can and how you can. I think that's a good thing. That's interesting.
SPEAKER_01So we also we also talked about sort of like take those small wins where you can, be fast on the things you can be fast at. Don't ask as many questions where you don't need to ask questions, push things through, try and help them out and help them do their job when you need to. Seems like that's part of a process of buying and building trust from them so that, you know, when they maybe are getting a little bit too close to the line, you can you can uh reel them back in and have them listen to you as opposed to just say, oh, here she goes, saying no again, right?
SPEAKER_00Completely. I think a lot of it in and now where I've evolved to at least is when I understand what they're asking about and it's a pretty low-risk item, I'm not gonna put a roadblock in front of it. If it's not risky, why am I inserting myself in their process to develop something? Whether it works or not isn't my job. And whether it's something that's gonna be commercially, you know, really valuable, that's not my role. So, like, but I'm gonna butt out of those conversations so long as I'm good on the points that I need to be good on, or you know, mostly okay or low risk on several of the questions that um I generally would be asking. I'm getting out of their way because I do think it's easy sometimes when you're seeing all of these things from a high level to say, this isn't gonna work, like stop and find a way to stop it from the legal angle. But that just is not a partner and it is not the role that I need to take because there are other things that I'm going to need to kind of pull that card on down the road. So it's utilizing it judiciously, I guess. When you need them.
SPEAKER_01All right. Well, this has been fun. Let's uh maybe start to wind down a little bit. Uh, if uh general counsel or uh an associate general counsel wanting to be a GC, uh, or maybe somebody in a compliance officer wanting to build up into a chief AI officer, chief compliance officer type role, and wants to start doing this work, what are a couple two, three concrete moves that they can make or start thinking about making that'll help them get to uh having a role like yours?
SPEAKER_00Yeah, so in the the lead up to the role, I think it is absolutely engaging with AI, like we talked about earlier. I think that one thing that allowed me to grow within my role was creating kind of an AI FAQ. Um, Brian, I talked with you about this. You guys helped me with this. And it was really just identifying um, it can be an internal document, it can be an external document, but figuring out what your guardrails are internally and kind of putting it in a readable document. And maybe you don't know if you're applying for a job, but maybe it's something that you could create so you can speak to it in the interview process, such that you're like, I think this would be really valuable and really practical for our internal employees to utilize and to have a good understanding of the, you know, call it do's and don'ts and like the gray areas, the maybes. And then, you know, really kind of putting together a programming so you can have a perspective on how AI is used within your company. And then also on the customer-facing side, on the external side. Hey, we don't train on your data, we don't do all of these things, so that it's really clear up front what your position is, and you kind of jump over several hurdles and you gain that trust right away. And I think it's it shows that you're strategic, it shows that you understand what the nuances are, and that you understand the balance of the risk reward in utilizing AI and how it's going to be deployed. So that is one thing that I think is really important and that gains points, whether you're in a seat that could kind of take on the AI work or whether you're trying to get into a seat like that. Additionally, I would say understanding if you're in a role, understanding what AI is used internally. That could be a monumental task for large companies because AI is used in so many different areas. But I think just having a functional understanding of where AI is deployed in your company is really important. If no one else has that yet, that may already be done. Um, but I think that just shows some understanding of how what approach your company is taking to AI. Some other practical things I think are just, I mean, it's listening to these podcasts, it's getting different opinions. You may not agree with all the opinions you hear, may not agree with all of my opinions from today. But I think the more that you can stay abreast of what the industry is thinking, what others are thinking, and have your own perspective on it, that can be applied to different businesses, right? Different businesses have different risk tolerances based on the industry, based on the size, based on a number of things. So it's not static. My perspective on it at Authentics may not be the same if I'm in a different role at a larger company in a manufacturing setting. So I think that there are different ways to approach AI in that way that are both compliant and both appropriate, um, but applied differently. So just I think making sure that you keep your mind open to that perspective is going to be really important and applicable across the board.
SPEAKER_01Yeah. So I mean, it seems like your role is only like expanding, right? I mean, the traditional uh GC role uh I think is changed by the technology, but also the way that a lot of companies uh change this, right? And we I've seen it change recently. We have a lot more CLOs and we used to have, maybe fewer GCs, right? People moving to that chief legal officer, being seen more as part of the business team. I think the expectations, it sound like, that go along with that role have changed as well. You're on these business calls, you're talking with these product teams, helping them uh sort of wade through the legal component of driving the business forward. Uh that's a lot different than, you know, go sit in the office and review and draft contracts and make it cost less next year, uh role that I think traditionally has been there. So uh a huge challenge, but also one it's encouraging and I think really helpful for people to hear the way that you're handling this and hopefully they share those conversations of how they're handling it uh with other people. So um really valuable in that sense. I think I want to close, you know, the the main takeaway, at least for me, and and then please, you know, certainly give us your final takeaways, your final tips that you might have uh that we haven't quite gotten to. This isn't obviously a GC at an AI company problem. Uh AI is going to be baked into everybody's role going forward, every business going forward. It really already is, and that's only going to increase from what we've seen. Uh the lawyer, the privacy person, the compliance officer, the business operator, everybody is going to have to learn some version of what you're going through in your specific role, I think. Um, the job of staying close to that technology, asking the right questions, uh, perhaps approaching it the way that you do and in terms of being vulnerable and open to learning from those teams is really a critical part of doing your job, whatever that is, better. Uh for anyone who's out there who's listening, who sees this coming in their own roles, already experienced it, uh, that maybe is trying to work their own path through that. I guess what's your closing advice? Where do they start? What mindset do they need to bring to that approach to make sure that they're not only keeping up, but excelling uh given all the opportunity this change these changes are bringing as well?
SPEAKER_00It's a really great question. I think it's a summation really of a lot of the things that we talked about today, which are being comfortable in the uncomfortable. I mean, I've spent a lot, I've done a lot of tossing and turning because I haven't felt like the expert, or because I've had to learn as we're building the plane, so to speak. And I think that that is just going to become more a part of our everyday lives because speeds of businesses are increasing so much that we have to be more agile as lawyers, as compliance officers, as AI risk officers, you name it, that we have to be able to operate at that speed, which means there is going to be some discomfort to start. I think. I think I've gotten a bit more comfortable in it over the two and a half years. Um, but I think that that's really going to be part of the change in the industry and realizing that that's okay, that we don't have to know it all right away. And we don't have to know the answer right away. Figure it out pretty quickly, but not right away. You don't always have to know it. So and maybe that's applicable, you know, to the GC roles of the past too. But I just think it's so different now than what it was when I started as a lawyer, even. So, like it's being comfortable in the uncomfort discomfort, I think is really the best thing that I can say as we continue to face the challenges that we are, as ineloquent as that may sound.
SPEAKER_01You're exactly right and great insight. Erica, Sylvester, general counsel at Authentics. Can't thank you enough for taking the time to join us uh and have this conversation. Super insightful. I'm sure it'll be helpful to a lot of people. Thank you for your time and we appreciate it.
SPEAKER_00Sure. Thanks so much, Brian. I really appreciate it. Look forward to listening to the next couple of podcasts because I know I'll be learning more.
SPEAKER_01Hey, we'll keep them coming for you. And thanks everybody for hanging on and listening. We'll see you on the next one.