Share
Facebook Facebook icon Twitter Twitter icon LinkedIn LinkedIn icon Email
AI Legal Hammer of Justice

Artificial Intelligence

AI and the Chief Legal Officer: Redefining legal leadership

Published October 5, 2026 in Artificial Intelligence • 12 min read

Once primarily the guardian of traditional and well-established legal systems, today the CLO is becoming the architect of enterprise artificial intelligence (AI) governance, helping to identify and manage AI risks and opportunities across the organization.

Rapid read:

  • Organizations have identified new legal needs, but execution lags.
  • CLOs should lead the business transformation, starting with an AI governance system.
  • The central legal challenge is building accountability into the organization without turning legal into a brake on innovation.

In 2026, the professional remit of the Chief Legal Officer (CLO) is widening into uncharted legal and compliance territory steering how the enterprise adopts AI legally and responsibly. The CLO is increasingly expected to shape corporate policy on algorithmic accountability, guide board-level conversations on regulation, and design the legal and operational frameworks that let innovation proceed without forfeiting trust. If being the architect of the unknown is not challenging enough, the CLO will need to perform under a deep AI disruption of the legal function itself, and at unprecedented speed. This article examines how the CLO role is transforming, the challenges outside and inside the legal function, and the steps legal leaders can take to thrive in this new pace and space.

Who owns AI-generated content?

Architect of AI governance

Traditionally, the CLO has protected the enterprise across a range of legal exposures, from regulation, litigation, contracts, and intellectual property to investigations, corporate governance, and board advice. Much of that guardianship has been based on a consolidated set of mature laws and legal precedents. AI renders that model outdated, raising both the complexity and the velocity of the legal questions companies face, many of them not fully settled. Among these are: Who owns AI-generated content? How is liability assigned when an automated system makes a consequential decision? And what obligations arise under incipient and scattered attempts at regulation? AI is changing the decisions being made across the enterprise, for example, around hiring algorithms, AI-enabled pricing, automated customer interactions, fraud detection, product recommendations, coding agents, and autonomous workflows. Each of these decisions creates legal consequences.

In this environment, the CLO must extend legal oversight into the design of enterprise-wide AI governance, setting the conditions and the processes to identify and manage new risks and opportunities created by AI. Legal should not own every AI decision, but should establish the rules by which those decisions are made, and answer such questions as: Who has authority to deploy a system? Which AI uses require additional scrutiny? What evidence must be retained? When is human intervention required? And who is accountable when an AI-enabled decision causes harm? The shift is from interpreting and ensuring compliance with clear rules to the creation of a legally safe new framework within which those decisions are made.

This new paradigm is of paramount strategic importance for the enterprise, and only the planning and execution of a smart AI architecture can future-proof the company. Gartner frames the evolution of the CLO role as a dual challenge: general counsel must assert strong AI governance leadership without stifling the innovation the business wants. The most effective CLOs meet that challenge by ensuring a legally safe environment to face the unknown without creating bureaucratic processes that undermine the potential of AI to become the most effective competitive advantage.

Organizations have identified new legal needs, but execution lags

Boards are ramping up briefings, training, and cross-functional engagement on AI, recognizing the urgency of understanding risks tied to data privacy, model hallucination, misuse of proprietary information, and shifting regulatory liability, and they look to the CLO to place those risks in the context of corporate strategy.

Models trained on biased data can produce discriminatory outcomes, exposing the organization to liability under employment and consumer-protection law. Confidentiality and privilege are at risk when generative systems ingest sensitive legal or commercial data. Accountability remains unsettled when an AI-driven tool fails. And the well-documented tendency of these systems to fabricate citations has already drawn judicial sanction, a reminder that human review is still required in most cases.

Despite the corporate expectation toward the expanded legal function, most organizations have not yet transformed to meet the need. A 2026 Plexus survey of general counsel found that only 8.7% own AI governance in their organization, compared with 28.7% who said it sat with IT or the CIO. Legal should not seize control of AI from technology or other parts of the business. Instead, the CLO’s opportunity is to design an accountability system in which AI ownership remains close to where AI creates value, while enterprise-wide standards architected by the CLO determine which risks are acceptable and how decisions can subsequently be defended. It is the responsibility of the CLO to proactively start developing this new mandate in the organization; no other function is qualified to do it.

AI and digital transformation programs

Build the skills to lead in a digital world

Transform your career and business with next-generation AI and digital skills

Explore programs
The EU AI Act stands out as the world’s first comprehensive AI law.

A new AI regulatory framework under construction

AI regulation is spreading quickly. And although it is uneven across jurisdictions, this will help the CLO. The EU AI Act stands out as the world’s first comprehensive AI law. It entered into force in 2024 and is applying in stages, imposing escalating obligations as potential harm increases. Prohibited practices have applied since February 2025, and in June 2026, EU lawmakers adopted changes under the Digital Omnibus that postponed key high-risk requirements until December 2027. In the United States, absent a federal statute, rules are emerging locally: New York City’s Local Law 144 requires employers to audit automated hiring and promotion tools for bias, publish the results, and notify candidates. Similar to the US, China does not have a single AI law, but has already issued a set of foundational statutes around cybersecurity, data security, and personal information protection. Those laws are then complemented with scenario-specific rules that are monitored and enforced by the Cyberspace Administration of China.

Beyond mandatory law, as is typically the case during the genesis of a new regulatory landscape, there are emerging self-regulatory standards that attempt to bring certainty and promote the right behaviors in a responsible use of AI. The Artificial Intelligence Risk Management Framework (AI RMF 1.0) and ISO/IEC 42001:2023 are the most salient examples of those voluntary efforts.

For multinational companies, clearly AI governance cannot be designed around a single model or compliance date. It needs to continuously absorb regulatory change that comes quickly and from many directions. For the CLO, the task is less to obsess over each rule than to build an operating model that can keep the organization compliant in all scenarios without halting the business or harming innovation. Since a clear and smart regulatory environment is proven to be much needed in this space, the CLO should not forget the strategic role of advocating for and promoting the appropriate policies and frameworks that will make the use of AI beneficial for all stakeholders.

Although the predictions of an effective loss of legal jobs have not yet materialized, it is already a reality that AI has moved from the periphery of legal work to its foundation.

The disruption at the CLO office: What AI is changing in legal work

While planning and executing a new AI governance in a fluid and fast-changing regulatory landscape, the CLO also faces massive disruption affecting the legal function itself. In one of the first studies of the impact of AI in organizations, the Goldman Sachs Generative AI 2023 Report indicated that 44% of legal industry tasks could be automated, replacing the equivalent of 40% of legal industry employment.

Although the predictions of an effective loss of legal jobs have not yet materialized, it is already a reality that AI has moved from the periphery of legal work to its foundation. Gartner, having evaluated 16 candidate applications, identified six use cases with the highest value and feasibility for corporate legal departments: extracting and classifying data from contracts, automated contract review and redlining, summarizing legal documents, intake and triage of legal requests, transcribing and summarizing meetings, and scoring contract risk. Together they turn slow, manual work into faster and more strategic workflows. The shift is now mainstream rather than experimental. The FTI Consulting and Relativity’s General Counsel Report finds that 87% of general counsel report their teams using generative AI, nearly double the 44% reported a year earlier and up from just 20% in 2023, while the Thomson Reuters Institute estimates that AI could free nearly 240 hours a year per legal professional, worth roughly $19,000 each. For the general counsel, the implication is a rebasing of what legal work costs and how it is delivered.

However, efficiencies and cost savings are only an initial part of the equation. The next frontier is AI that acts. A&O Shearman and Harvey, for example, are rolling out AI agents for complex, multi-step tasks such as antitrust filing analysis, cybersecurity obligations, fund formation, and loan review, deployed internally and sold to clients and other firms. As agents begin to draft, decide, and act with less direct human involvement, they make the CLO’s new challenge tangible: when an automated system causes a consequential outcome, how has responsibility been allocated among the vendor, the company, the business owner, and the executives who authorized its use?

This is where the CLO’s role converges with a governance discipline the whole enterprise is only beginning to build. Just as IT must learn to onboard, monitor, and retire AI agents with the rigor applied to human employees, the CLO must ensure the legal scaffolding keeps pace: clear allocation of liability, audit trails that hold up over long time horizons, and defined accountability for decisions made by automated systems. Getting ahead of agent governance now is far easier than retrofitting it after something has gone wrong.

Tools and technologies, but also skills and mindset

The legal technology market has developed rapidly. Purpose-built platforms such as Harvey, Thomson Reuters CoCounsel, Lexis+ AI, Legora, and Eudia are moving beyond search and drafting into increasingly complex legal workflows, while contract platforms apply AI to review, extraction, and risk identification. General-purpose systems are also entering legal work. Microsoft is embedding AI directly into productivity workflows, Anthropic is demonstrating Claude across activities including redlining, extraction, drafting, research, eDiscovery, and matter management, and OpenAI reports substantial adoption of Codex by its own legal team. The important shift is not the proliferation of products, but the movement from isolated assistance toward AI embedded directly into legal workflows, with features that allow legal advice that is consistent and adjusted to local laws and client profiles.

However, the key to success for the legal function in the AI space depends not so much on the technology chosen, but on the new mindset and capabilities necessary to embrace the change. Legal leaders can no longer rely on the old ways of working and must ensure that lawyers, particularly less experienced ones, are trained in the new skills necessary to adopt and adapt to the use of AI that necessarily will replace or complement their old activities. They need literacy in AI and algorithmic risk, must learn how to read context for effective prompting, a working grasp of digital ethics, and the ability to lead cross-functional efforts spanning technology, compliance, human resources, and risk. Anticipating regulatory change matters as much as reacting to it. The shift is cultural as well as technical, asking the CLO to hold legal rigor and strategic agility at once, and to build AI literacy across the legal team so that oversight of these tools is competent rather than nominal.

ai and legal council
The impact of AI in legal departments is already visible in operational models, not just in pilots

Real-world examples

The impact of AI in legal departments is already visible in operational models, not just in pilots. HSBC, working with Google, built an AI system it calls Dynamic Risk Assessment to screen more than a billion transactions a month for signs of financial crime; the bank reports finding two to four times more financial crime with greater accuracy, cutting false positives by 60%, and compressing the analysis of those transactions from several weeks to a few days. For a CLO, however, the interesting question is not simply whether the system performs better, but how the bank establishes accountability around a system operating at that scale: how performance is validated, how false positives and missed cases are handled, what oversight is retained, and what evidence can be produced if regulators subsequently challenge a decision. The larger the operational benefit, the more consequential the governance architecture around it becomes. In private practice, A&O Shearman’s deployment of Harvey cut contract-review time by around 30%, saving attorneys an estimated seven hours per review and freeing senior lawyers for higher-value work.

The CLO’s most valuable contribution is not to own every AI decision but to ensure the right people do.

What to prioritize now

Build an AI governance system in addition to AI policy. Start by knowing which significant AI systems and agents are operating across the enterprise and who owns each one. Establish risk-based approval thresholds, testing and monitoring requirements, incident escalation, minimum documentation standards, and scalable and audit-ready evidence to substantiate compliance. The test of governance is not whether the organization has published principles, but whether it can reconstruct who made a decision, using what system, under whose authority, when something goes wrong.

Lead the business AI transformation – do not just police it. The CLO’s most valuable contribution is not to own every AI decision but to ensure the right people do. Coach the board on the exposures that matter most, raise AI fluency across the legal team, and ensure accountability stays with the executives and functions creating the value. Legal should make responsible innovation easier, not innovation impossible.

Change starts at home. The CLO should make the legal department itself a model for responsible AI adoption, investing early in digital and AI-enabled tools, building the literacy and mindset needed to use them effectively, and redesigning workflows as automation and agentic models mature. Freed capacity should be deliberately reallocated toward higher-value strategic and governance work, while external counsel models should also evolve toward value-based arrangements that reflect the productivity gains AI will bring.

Govern AI agents as a new class of worker. Autonomous systems are already drafting, deciding, and acting inside the enterprise. Treat them accordingly: define onboarding standards, access controls, audit trails, and, above all, clear legal accountability for the decisions they make, so that responsibility never falls into a gap between vendor and company.

Advocate for the right AI regulatory environment. Mindful that we have a unique opportunity to shape regulation in the making, the CLO should proactively advocate and elevate a public voice for the smart and appropriate regulatory landscape that can secure a fair and sustainable use of AI. The adoption and promotion of the appropriate voluntary standards and the active participation of committed industry associations are concrete testimonies of CLO leadership in this space.

AI is not removing the CLO’s traditional responsibilities.

The CLO’s new mandate

AI is not removing the CLO’s traditional responsibilities. It is extending them into parts of the enterprise that legal functions have historically influenced but rarely helped design. As decisions become distributed across people, models, vendors, and increasingly autonomous systems, the central legal challenge is ensuring that accountability does not become equally distributed and ultimately disappear. The CLO who can build that accountability into the organization without turning legal into a brake on innovation will become an increasingly important strategic leader.

This article is part of a continuing series of insight articles on ‘AI and the CxO‘. 

Authors

Esteban-Mezzano_Headshot

Esteban Mezzano

Vice President, General Counsel Corporate Operations and Sustainability at Nestlé

Esteban Mezzano is Vice President, General Counsel Corporate Operations and Sustainability at Nestlé. As a member of the company’s global legal leadership team, he advises the business on operational, sustainability, and regulatory matters, with a particular focus on environmental, social, and governance (ESG) issues. His current interests include how digital technologies and artificial intelligence are reshaping the legal function into a more strategic, data-driven partner for responsible business adaptation and long-term value creation.

Konstantinos Trantopoulos

Konstantinos Trantopoulos

Advisor and Research Fellow at IMD

Konstantinos Trantopoulos is a Senior Advisor and Fellow at IMD. He works with C-level executives, boards, and private equity investors on the strategic, commercial, and operational levers that drive growth and enterprise value. His work focuses on investments, capital allocation, commercial diligence, market dynamics, and how new technologies and AI reshape value creation. His insights have been featured in Harvard Business Review, MIT Sloan Management Review, California Management Review, MIS Quarterly, Industry and Innovation, Το Βήμα, and Forbes.

Michael Wade - IMD Professor

Michael R. Wade

Professor of Strategy and Digital

Michael R Wade is Professor of Strategy and Digital at IMD and Director of the Global Center for Digital and AI Transformation. He directs a number of open programs such as Leading Digital and AI Transformation, Digital Transformation for Boards, Leading Digital Execution, Digital Transformation Sprint, Digital Transformation in Practice, Business Creativity and Innovation Sprint. He has written 10 books, hundreds of articles, and hosted popular management podcasts including Mike & Amit Talk Tech. In 2021, he was inducted into the Swiss Digital Shapers Hall of Fame.

Related

Learn Brain Circuits

Join us for daily exercises focusing on issues from team building to developing an actionable sustainability plan to personal development. Go on - they only take five minutes.
 
Read more 

Explore Leadership

What makes a great leader? Do you need charisma? How do you inspire your team? Our experts offer actionable insights through first-person narratives, behind-the-scenes interviews and The Help Desk.
 
Read more

Join Membership

Log in here to join in the conversation with the I by IMD community. Your subscription grants you access to the quarterly magazine plus daily articles, videos, podcasts and learning exercises.
 
Sign up

Log in or register to enjoy the full experience

Explore first person business intelligence from top minds curated for a global executive audience