Friday, August 7


Organisations embedding AI across operations cannot wait for one comprehensive AI law before building governance structures, legal and compliance leaders said at the panel “Managing AI Regulatory Complexity & AI-Enabled Compliance” at the ETLegalWorld AI-Powered Legal Transformation Summit 2026.

Moderated by Kirti Mahapatra, Partner, General Corporate & Policy and Regulatory Affairs Practice, Shardul Amarchand Mangaldas & Co., the panel included Lakshmi Menon (Director/General Counsel India, Hewlett Packard Enterprise), Jagannath PV (Global Data Privacy Officer, LTI Mindtree), Jay Maroli (General Counsel, GE Vernova Research), Dinesh Vijayakumar (General Counsel, IBM India), and Nitesh Bakshi (Director, Legal Compliance & Quality, Novo Nordisk India). Mahapatra noted that with no omnibus AI law in India, enterprises must navigate sectoral tech rules, global regulation and cybersecurity obligations simultaneously—making the real task of building a governance framework rather than meeting one auditable requirement.

Menon said surging AI infrastructure demand has exposed how technology adoption creates consequences beyond the tech function—affecting pricing, procurement and supply chains, and sometimes pushing companies into deployment before their compliance models mature.

Jagannath asked: do organisations know where employee data goes when they use AI? Boards are now probing which responsible-AI frameworks are used, who owns risk, and whether pilots deliver real outcomes. AI literacy is equally essential; the goal isn’t to stop using AI but to ensure accountability for its consequences.

Maroli warned about employees feeding confidential data into public AI tools or meeting apps that auto-transcribe conversations without clarity on data handling. Legal teams use AI for licence analysis and compliance research, but outputs need human review, especially where regulations are ambiguous, confident AI answers shouldn’t be taken at face value.

Bakshi highlighted life sciences, where AI can aid drug discovery but must be weighed against patient privacy and reliability risks; efficiency gains can’t be the sole adoption criterion.

Sovereignty as a Governance Question

Vijayakumar said the sovereignty debate has moved beyond data residency to who operates AI platforms, controls access, and how dependent an enterprise becomes on specific vendors, creating concentration risk that individual companies, not just governments, must manage.

Menon called for global principles, human intervention, transparency, fairness, bias mitigation, continuous testing, privacy, that flex for sectoral rules (finance, healthcare, telecom, defence) and local cultural context.

Assessing Impact, Not Just Output

Jagannath argued governance must track how AI outputs are used, not just what they produce. His example: an attrition-prediction model meant to prompt manager engagement becomes discriminatory if used to deny a promotion. “That is a misuse of AI,” he said. Accountability must span data controls (tech teams), contracts (legal), risk articulation (responsible AI functions) and decision ownership (business), sponsored by senior management.

Maroli said AI should stay out of decisions materially affecting individuals, since general-purpose models can miss essential legal principles despite polished answers. Human review is a substantive safeguard, not a formality.

Bakshi added that in life sciences, some AI use cases should simply be rejected if privacy risks can’t be controlled.

Vijayakumar noted governance must span hybrid environments (on-premise, cloud, multiple vendors) and be continuous, not a point-in-time audit, especially as AI systems act more autonomously.

Menon proposed compliance-by-design, mapping regulatory obligations into AI architecture before deployment, alongside infrastructure sovereignty and continuous testing, since models evolve over time.

Jagannath pushed further than “human in the loop,” advocating “human in command”: reviewers must have both ability and authority to challenge AI decisions, not just rubber-stamp them (e.g., blindly advancing a recruitment candidate an AI scores highly). He added monitorability, AI literacy and specialised testing, as core requirements. Maroli echoed this, framing AI as augmented intelligence supporting, not replacing, human judgment where context and consequences matter. Bakshi stressed pairing regulatory governance with technological capability to turn policy into practical controls.

The Shift to Continuous Governance

The panel’s broader message was that with AI deployed across jurisdictions and business processes faster than regulation evolves, enterprises need answers upfront—what problem AI solves, what data it uses, where that data goes, who controls infrastructure, what happens if outputs are wrong, who can challenge decisions, and who remains accountable.

For legal and compliance teams, this marks a shift from checking rule compliance to designing the environment for responsible AI adoption itself. The best-prepared organisations, panellists agreed, will be those embedding compliance, accountability, traceability and human command into AI architecture from the start—not bolting them on afterward.

The AI-Powered Legal Transformation Summit 2026 by ETLegalWorld is currently being held in Bengaluru. The summit has brought together general counsel, in-house legal leaders, and technology innovators, to chart the next phase of legal transformation in an AI-driven world.

  • Published On Aug 7, 2026 at 05:15 PM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETLegalWorld industry right on your smartphone!




Source link

Share.
Leave A Reply

Exit mobile version