Deep dive: How AI implementation teams navigate regulatory compliance

Applications that process customer data are often subject to stricter regulations than lower-risk software. When such applications use an AI model under the hood, the number of rules to which they must adhere grows even further. That creates additional work not only for companies adopting LLMs but also the consultancies helping them with the task.
Boardroom Insight recently got a chance to dig deeper into the topic with two tech industry insiders. Heather Wood is the senior director of data privacy and regulation at Outreach, a provider of AI-powered revenue orchestration software. Bernadette Bulacan is chief evangelist at Icertis, a provider of contract management software. Wood provided a technology buyer perspective on AI regulatory compliance, while Bulacan shared an industry-level view.
Boardroom Insight: AI projects tend to follow a phased rollout path from an initial pilot phase to a broader release. At what point does a firm’s legal team come into the picture, and what is its role?
Heather Wood: Legal gets involved first, during procurement. They look at what the vendor will actually be providing – in this case, to Outreach – and negotiate the right protections into the contract. At the same time, Privacy and Security are reviewing the deal to figure out what mitigations need to be in place.
Through all of this, it’s a joint effort with the business owner. Once we move into implementation, the compliance teams step in to help the business owner roll things out within the guardrails we set. In practice, legal is in before the pilot starts, and the work shifts from negotiation to oversight as the rollout widens.
Boardroom Insight: What about the legal teams of the partners involved in an AI project, like consulting firms and LLM providers?
Heather Wood: Ultimately, this would happen during procurement as well, since these vendors will likely need to integrate with or gain access to our – Outreach’s – systems. Engagements like this come with a number of control requirements that we work through.
Bernadette Bulacan: While the legal teams at AI vendors and consulting firms are not typically involved in the daily AI deployment decisions, they are instrumental in defining the contractual, privacy, security, intellectual property, and compliance frameworks that govern how their technologies and services can be used.
Boardroom Insight: What role do the software tools that legal teams use in their day-to-day work, like contract management systems, play in AI initiatives?
Bernadette Bulacan: They help legal teams centralize information, automate routine tasks, and gain visibility into obligations, risks, and commercial relationships. That not only improves efficiency and allows legal professionals to focus on more strategic work, but also creates the trusted, structured data that AI depends on.
An agent can reason and act much more effectively when it understands the rules and relationships that govern the business. CLM can provide that critical context and grounding – helping agents understand not just what they can do, but what they should do.
Boardroom Insight: How do data retention considerations factor into AI projects?
Heather Wood: Data retention is part of our Privacy Impact Assessment process right up front. We run this assessment for every procurement, triggered by responses to a conditional questionnaire. Whenever data is used for training, fine-tuning or simply passed in and out of an LLM, we’re evaluating both the retention requirements and what counts as acceptable use.
Bernadette Bulacan: Information that may seem low risk in one context can create compliance, privacy, or security concerns when it’s fed into AI systems. Complicating matters further, retention practices vary significantly across AI providers, making it important for organizations to establish governance policies rather than relying solely on vendor defaults.
Boardroom Insight: How do companies adapt to changes in the AI regulatory landscape?
Heather Wood: We adapt by staying ahead of things rather than reacting to them. Privacy and Legal keep a close eye on regulatory developments across the jurisdictions we operate in, and we build our vendor agreements and internal policies to flex with change rather than lock us into today’s rules.
Cross-functional collaboration matters a lot here too, since it lets Legal, Privacy, Security, and the business owners quickly assess new requirements and adjust our approach as regulations shift, instead of having to renegotiate every vendor relationship from the ground up. We’re also watching for trends and decisions gaining traction in other jurisdictions, so we can future-proof our agreements (as much as possible without a crystal ball) and approved use cases.
Bernadette Bulacan: Regulatory change is nothing new for most organizations. Many already have established playbooks for understanding what changed, determining where the rules apply, assessing risk, updating guidelines and processes, and monitoring compliance.
What makes AI different is that both the regulations and the technology are evolving simultaneously, and AI is testing these playbooks.
Photo courtesy of Unsplash