Skip to content

Key Takeaways from Loeb's AI Summit in Chicago: AI Governance

The AI Governance roundtable at Loeb’s AI Summit in Chicago on July 14, 2026, focused on the issues plaguing in-house counsel while executing and enforcing their AI policies. Most of the participants of the roundtable had an AI governance strategy, but some of them were more advanced than others depending on the urgency to use AI in their company. Therefore, most of the participants were now addressing enforcement. The two issues that garnered the most discussion were: (1) How to efficiently execute and enforce the policy without overburdening the legal department; and (2) How to deal with “shadow AI” or employee use of unauthorized AI tools. 

Many of the participants discussed being overwhelmed by the multiple different responsibilities related to AI that fall on the legal department. These responsibilities run the gamut from writing and updating the policy; reviewing AI tools and their licenses; training employees about the AI and the AI policies; and enforcement of the AI policy. The participants discussed different ways to potentially address these issues. One of the possible solutions included having a green/yellow/red policy for the approval of AI tools. Green tools would not require review and approval and the red tools would require the highest level of approval, including potential approval from the C-suite. Typically, the green tools would include productivity tools that would not use third-party information or share information with third parties; yellow tools may require sharing of information with outside parties; and red tools would require the use of sensitive personal information or highly regulated information (such as medical or financial information).  In addition to creating this risk matrix, the participants discussed the possibility of incorporating a federated governance structure as compared to the more unified structure many of the participants have today. Hopefully, including others in the governance structure would allow the legal department to push some of its responsibilities down to the different stakeholders. 

The second concern that many of the participants discussed was “shadow AI.” While many of the participants had instituted technical walls to stop employees from accessing unauthorized AI tools, all of the participants were concerned or knew that employees were using their personal devices to access these tools. In addition, many of the companies discussed having requirements that employees disclose the use of AI in their work product. However, again, it was assumed that many employees do not follow this policy even if the potential penalty is termination. The counsel had concerns that the undisclosed use of shadow AI not only potentially would lead to the leaking of confidential information through the AI tools, but also an invalidation of copyright registrations for failure to properly disclose the use of AI in the creation of the content. While we discussed many different possibilities on how to address shadow AI, we did not find a perfect solution.

Both of these concerns addressed during the roundtable illustrate not only the growth of the use of AI, but also the need for these governance structures to change and grow with AI.