Tech Law Talks

Tech Law Talks

By Reed SmithTechnology
Download on the App Store

Tech Law Talks episodes

  • AI explained: AI in film and television

    Continuing our new series on artificial intelligence, Christian Simonds and Henry Birkbeck discuss the use of AI in film and television. AI features in every stage of production – from pre-production, through production, to post-production – and reliance on AI will continue to increase as it evolves. The discussion centers around the legalities that management in the industry should be aware of, as well as the recurring questions and issues raised by clients in both the UK and U.S.

    ----more----

    Transcript:

    Intro: Hello, and welcome to Tech Law Talks, a podcast brought to you by Reed Smith's Emerging Technologies group. In each episode of this podcast, we will discuss cutting edge issues on technology, data, and the law. We will provide practical observations on a wide variety of technology and data topics to give you quick and actionable tips to address the issues you are dealing with every day.

    Henry: Welcome to our new series on AI. Over the coming months, we will explore the key challenges and opportunities within the rapidly evolving AI landscape. Today, we will focus on AI in film and TV. My name is Henry Birkbeck. I'm a senior associate in the London office at Reed Smith, and I'm speaking today with Christian Simonds, who is a partner in the New York office. Christian and I have previously written an article on AI in the film and TV space, and there's probably quite a lot to mention and not a huge amount of time to cover it. But I guess I'll start maybe Christian just by asking, you know, have you seen recurring themes coming up with clients asking about AI in the film and TV space so far?

    Christian: Yeah, I think in terms of, you know, the film and TV industry as a whole, it's kind of always been kind of at the forefront of technology, particularly in terms of how to properly utilize it. Just not only from a budgetary perspective, but also from a creative perspective, right? And obviously, you know, AI has been such a hot topic, particularly with respect to the guilds during the strikes of 2023. So there is a lot to kind of unpack in terms of how it's being integrated into film and TV production. You know, I think the general consensus is that about two thirds of every budget for a AV project in the kind of the film and TV space is kind of made up of labor. Right. And particularly now in relation to kind of the economy and where it is, there's been a heightened scrutiny of, of each line item in a, in a particular budget. And, and, and as a result, it's kind of driven the need or reliance on AI as a potential solution to mitigating certain costs, labor costs. And again, I know it's not ideal from an individual employment perspective, but from an overall budget perspective, it is something that I see the studios and production companies on the independent level embracing as it relates to trying to drive down costs of a particular budget it kind of, AI kind of plays into each stage of production on, it plays into development, pre-production, production, and post. And when you're navigating that as it relates to the legalities of how it's used, yeah, there are certain issues that come into play vis-a-vis what the guilds have agreed to kind of in their most recent ratification at the end of the strikes. And how to ensure that you're adhering to what those requirements are, at least aware of what they are. In addition to that, just from a copyright perspective and other considerations in terms of how AI is used in that kind of development stage. So there's kind of a lot to unpack within kind of the lifespan of a production as it relates to AI and how it's been used. And the reality is it's going to be used and it's going to continue to evolve and be, be relied on to a greater degree, particularly with respect to certain elements of the production process on the, on, on the VFX side in particular, obviously certainly in, in, in the development stage and, and, and the editing stage. And there's, there's certain things that, that it really has a, a, a tremendous value from a timing perspective, a cut down and production timing and, and, and, and other elements that I think will, will benefit the production as a whole. But yeah in terms of legalities yeah there's a lot to kind of unpack there I'm happy to touch on each of those in the time that we have.

    Henry: Well I think the first one which you did touch on obviously is that the guild strikes of 2023 and clients and and those those people in the industry in the US were probably a lot closer to it but for the benefit of those of us that weren't in the US do you do you want to give a very quick recap of kind of where where they ended up?

    Christian: Absolutely. Yeah. In terms of the Screen Actors Guild, SAG, there are really four main components to how they regulate artificial intelligence. So you've got your employment-based digital replica, which is basically a replication of a performer's employment or participation in the production. So it's literally taking the performer himself and portraying him in a scene that they didn't actually shoot or a performance that they didn't actually shoot. A good example is if you see in a movie someone talking to themselves. That second digital replication is employment-based digital replica. Right. What does that mean in terms of what you need to do vis-a-vis SAG? It means you need to get mandatory consent from the performers when you're going to do that. So it needs to be disclosed at the outset, either from the performer himself or if the performer is no longer around, you need to get consent from an authorized representative from his estate or the union itself. The contracts need to be reasonably specific as to the description of how it's going to be used. And if you're going to use it outside of the project, i.e. kind of that beyond a kind of one picture license, you're going to need additional consent to do that. And, you know, they need to be, the performers will need to be compensated, you know, for that digital creation as though it was themselves, right? So you need to take into consideration that residuals obviously Obviously, we'll need to be paid on whatever amounts are paid in connection with that. And then you've got independently created digital replica, which is basically using digital replicas created kind of using materials that the performer has provided in a scene that they didn't actually shoot. Right. So you're not actually using a previous performance in the movie itself, but you're like literally digitally replicating the performer in a scene that he didn't otherwise participate in. So again, you need to consent from the performer when you do that. You need to be reasonably specific in terms of how you're describing that use in the contract. Again, obviously, he's entitled to compensation for that use. And obviously, that compensation is entitled to payment of fringes.

    Henry: Has this kind of been met with or met positively, I guess, in the industry since? Because I know that in 2023, you know, there was a big kind of reputational issue around AI and there was a lot of speculation about whether these, you know, protecting the performer's rights, was this being overblown a little bit? Or do you think, you know, are people comfortable with where they landed?

    Christian: I think with respect to those two elements, I think yes, right? I think that the general consensus is they do adequately protect the actors when you're exploring those types of digital replica usages. I think the real wildcard here or the area of real concern is around generative AI, right? So basically, taking data, materials, prior performances, facial expressions, their image likeness, and actually creating new content from that material from an actor. I think that's really where we start to enter into an area where people aren't necessarily comfortable, particularly on the talent side. And again, the guild is clear that if you're going to do that, you need to get consent from the actor, right? So if you're going to use his image or likeness or prior performances to kind of feed a gen AI tool to create a new piece of content from those materials, you're going to need consent from that actor. You got to notify the union when you're going to do such a thing, you know, and the compensation around that usage is usually specifically negotiated with the talent themselves. And you basically need to continue to keep that talent informed how those materials are being used vis-a-vis the gen AI. So that really is a touchy area. I mean, I think a lot of people are familiar with what happened with Scarlett Johansson when she basically said that her voice was being utilized for purposes of chat GPT. Recently, they claimed that they had used an actress's voice that they had brought in that sounds similar to hers, but it wasn't her voice. I mean, so it just shows you the heightened sensitivity on the talent side in terms of of how their, you know, image like this voice is being used within the gen AI space. So yeah, there is, there's a lot of sensitivities around that usage.

    Henry: Okay. So it's interesting that there's an ongoing obligation as well, which I guess makes sense, but you know, it's a burden, I guess, on the production company. And the other question I had relating to guilds was, was the writers guild. And I think the other thing that seemed to make the headlines internationally was about how particularly large language models and generative AI tools can be used for screenwriting and at what point. There's always a question with AI and copyright and ownership. And I was wondering if you could speak a little bit on where they landed in terms of who, if anyone, can own a script that has been written by an AI tool.

    Christian: You know, within the US, the copyright law is clear in the sense of, you know, anything that's gen AI created is not copyrightable, right? And if you are utilizing elements of materials that were gen AI created in your copyrightable material, you have to disclose what those materials are, and those materials will not be protected within the overall piece of IP, right? So you could copyright the script, but if certain elements of it were pulled from gen AI sources, those elements of your script will not be protectable. So the copyright law is fairly clear on that. In terms of the WGA and how they're trying to protect their writers from being replaced by AI, it's saying, hey, obviously with respect to signatory companies, you have to be clear that... gen AI produced material will not be considered kind of literary material under the WGA, right? So what does that mean? So if you can't give an AI generated screenplay to a writer and say, hey, go rewrite this, and you potentially won't be entitled to separate rights because you're writing something that's based on underlying materials, WGA says absolutely not. We're basically going to exclude that gen AI-created screenplay or treatment or Bible from the kind of separated rights discussion and say, Hey, that writer that contributes those first writing services, you know, for purposes of taking that gen AI material and, you know, either polishing or rewriting it or, or, or developing further into the screenplay, that will be considered the first step of the writing process. And that writer will be the writer that will be entitled to the writing credits around the material moving forward. So yeah it's almost like it's fine for studios to to provide gen AI materials for purposes of writers developing a screenplay or or assisting them with their writing services and again if they're going to do that they need to fully disclose that to the writer when they're doing it but those materials will basically be excluded from kind of the chain right when the WGA is considering what makes up the overall literary material that's going to be considered for purposes of writing credits residuals before etc. And I think again you know it's it's a good place to land for writers it doesn't necessarily solve the AI issue as a whole because it's still going to be utilized for purposes of coming up with ideas potentially on the studio side because it's it's something that they can quickly do and and also it has added benefits in terms of saying, hey. It can analyze a screenplay or it can analyze an idea and say, hey, here's the likelihood of the success of this idea or screenplay based on, you know, historics of screenplays like it in the past. Or, hey, I think the second chapter of this story should be changed this way because it's going to be better received because of X, Y, or Z, right? I think that tool will be beneficial. So it's not totally carving out the usage of AI as it relates to the development of a literary material. And I think it could be utilized in a positive way, which is great. I just don't think it will ever be able to fully remove physical writers from the process. I think the WGA did a sufficient job ensuring that.

    Henry: Yeah. It's interesting because obviously we're talking mostly about the US here, but I think most other markets in the film and TV industry were watching very closely what happened in 2023. And certainly in the UK, there's kind of been largely a following suit. You know, we haven't had the same kind of high profile developments, but PACT, which is the Producers Alliance in the UK, has since issued guidance on AI and the use of AI in film and TV productions. And, you know, they don't. They kind of stop short of taking a hard stance on anything, but they do talk about being very mindful and aware of the protection of the rights of all the various people that might be involved and how to integrate AI into production. So I think, I think the US position is, is really the kind of the market leader for this. And, you know, there's, there's a slight nuance in the copyright law is slightly different in the US and the UK and, you know, how AI relates to that. And, and lots of other jurisdictions, of course, there's implications there. But I think so far, the UK market seems to be broadly following what's happening in the states.

    Christian: It's interesting, too, because the states here are starting to take a position on AI. And there's, at least in New York, there's a few bills that are being considered currently. There's three bills, one of which I think probably has a likelihood of getting passed, which deals with contracts around the creation of digital replicas. And it kind of tracks what SAG has already said. But basically, any contract between an individual and an entity or individual for performance of personal or professional services as it relates to a new performance by digital replication basically is contrary to public policy and will be deemed null and void unless it satisfies three conditions, one of which is the reasonably specific description of the intended use of the digital replica. But it adds like an interesting element, which is that the person who is on the other side, whose performance is potentially being digitally replicated, needs to have been represented by council or a member of a guild, which is interesting, right? So it kind of adds a little, an extra level of protection. And again, this is going to be state specific. So it'll be interesting how this kind of impacts other states or what other states are potentially considering. And then there's two other bills that are currently in place. One is on the advertising side, you know, in connection with disclosing synthetic media as it relates to advertising. But the other one that's interesting, just from a film financing perspective, is that they're taking a position that, you know, productions that spend money on AI digital replication or AI usage might not qualify for the New York tax rebate, which is very interesting.

    Henry: Oh, really? Wow.

    Christian: They think that that one won't necessarily pass. Certainly the first one will because it's kind of already in line with what SAG has said. But yeah, that second one, I think, will probably get shelved. But just an interesting one to consider.

    Henry: Yeah, and it's really kind of, I guess, both of them showing that there is this protection element being added in and trying to... It's almost like holding these AI devices slightly at a distance to stop them kind of... Becoming a source of, I don't want to say evil in the industry, but kind of going too far overstepping the mark.

    Christian: Absolutely. And it's interesting too, because it's almost like, obviously you've got your defined protections within SAG and copyright law, and now obviously what's being considered by legislation. But the reality is a lot of this is being driven just by public policy in terms of the public's rejection of AI to a degree, right? I think people are generally like scared of it right so the knee-jerk reaction is to say no let's continue to promote you know the employment of real people right?

    Henry: Yeah.

    Christian: I think you know and and I think this also plays into how AI is used you know in films and again you know i think it's going to evolve to a point where it'll be tough to distinguish between AI and real right but you know, a good example being Irishman or some other films that have used significant AI to basically de-age people, you know, and people see it and like, that looks ridiculous, right? Like, I think there's a general knee-jerk reaction to doing it, right? And whether that changes over time based on how the AI technology evolves. Particularly from a visual perspective is TBD. But but yeah I think a lot of it is driven by public perception of AI right.

    Henry: Yeah yeah and I think you know it is interesting what you were saying before and we've seen this in the UK as well is that initially it was like okay well how is this gonna affect producers and you know and there's kind of efficiencies there but actually we're seeing studios and commissioners really embrace it and and look for ways to cut the cost of production as well and and you know i think it's It's just going to, like you say, it's going to touch basically every aspect of film and TV production and streamline things.

    Christian: Yeah, I think there are, I mean, I think there are real positives in terms of how it can be integrated into the production process. I know we touched on a few, but, you know, also like dubbing, right, localization of content and, you know, basically extending the reach of a piece of AV IP, right? So if you can do it in a way where it looks natural, because I know there's always kind of been a visceral reaction to seeing something that is dubbed really poorly, but if it can evolve to a point where it's almost seamless, it may have a better impact in terms of the breach of content. Again, I think there are different schools there in terms of whether investing in that makes sense in certain places or if it's just easier just to dub it and release it and how much of an impact it's actually having. But I do think in certain jurisdictions or certain areas, a seamless localization could have value to the reach of a particular piece of AV IP.

    Henry: Yeah, yeah, absolutely. And it could kind of move things geographically as well. I know, in the UK, we have this a lot where, you know, the cost of post production is a lot cheaper in countries close to the UK. And so as a result of that, you quite often see productions that will be, you know, 80% of it will be of the money will be spent in the UK. And actually, the final 20%, which, you know, often doesn't qualify for the tax credit over here anyway, gets outsourced to somewhere in Europe, where it is much cheaper to have the post production be carried out remotely, or even to Canada, or somewhere where there's a kind of better incentive package. And actually, if you could streamline that whole process, and you've got, you know, a company that or an AI tool that can, you know, do all the grading and all this kind of stuff that was cutting and these previously quite labor intensive activities, then there's no reason why you couldn't bring a lot of that production cost back on shore and reduce it. So it may kind of move where people are located in the market as well.

    Christian: Yeah, I think, you know, and it's not necessarily, you know, solely issue for, you know, scripted projects. You know, I think also in the US, it's even kind of led into the doc space, right? So I know, you know, the APA in the US, which is the Archival Producers Alliance, which basically is a document variance, you know, basically said as well, like, hey, just be careful how you use AI in this space, even though it's not, you know, governed by a auild necessarily, right? Like still, or how it's used in the non-scripted space, you know, it doesn't really have guild coverage depending on what it is. They're at least saying, hey, like, just be careful how you use it because, you know, what we're doing, particularly in terms of how we're depicting history or events, historical events or things that have happened, you know, AI, you don't want to, you don't want to change it to a point where you're basically changing the perception of history, right? Or generating things that are so AI oblivious to the realities of what actually happened, right? Like you might potentially, it might have a negative effect. And it's funny, it's more of like an ethical line that documentarians are trying just to be mindful of as it's kind of integrated into that space as well. Because look, when you don't have kind of primary source material to utilize for purposes of trying to depict something in a documentary, Yeah, it may be easy to duplicate it using AI, right? Generated by AI. But at the same time, that may have implications that you might not have thought about, which is, you know, how is this telling a story that might not actually be accurate to the underlying facts?

    Henry: I mean, I think that's a pretty good kind of starting point. Obviously, these are issues and discussion points that have a lot of depth to them and have been discussed a lot in the industry internationally already. And we're kind of in a point now where it's like, let's wait and see how this stuff shakes out in practice. And certainly, as we've discussed, the US has kind in a lot of areas that there is now a bit of a direction. So it'll be interesting to see how things unfold. And I know for the most part in the UK, the production industry sort of follows what's happening in the states. And in respect of international productions, they have to kind of be aligned to a degree. So it will be really interesting to see how this develops in the coming months and years.

    Christian: Yeah, for sure. And like Luke said in the beginning, there is no question that it is a part of the filmmaking process and will continue to be so at an ever-increasing degree. So it's kind of unavoidable. And I truly think it could be utilized in a way that's beneficial to filmmaking, both from a budgetary perspective, but also like, hey, if you can reallocate a bunch of the spend from what otherwise was labor-intensive, time-consuming elements of production, re-allocate that to talent or other things, elements of the process that can compensate certain individuals in a way that they weren't before. I think that can be beneficial as well. And I think, you know, there will be a point where, you know, it'll really help independent filmmaking in particular, right? Because that always is, budgetary constraints are always paramount in that space. And if you can do things that otherwise cost a ton of money previously for cents on the dollar using AI, moving forward to the extent it kind of evolves quality wise, I think you'll see an uptick in really quality, you know, independent filmmaking.. Again, there's never going to be a universe, in my opinion, that totally circumvents the utilization of real people, but AI can certainly be utilized in a beneficial way to help the process.

    Henry: Great. Thanks very much, Christian. And thanks everyone for listening. Tune in for the next episode on our series on AI.

    Outro: Tech Law Talks is a Reed Smith production. Our producers are Ali McCardell and Shannon Ryan. For more information about Reed Smith’s Emerging Technologies practice, please email [email protected]. You can find our podcasts on Spotify, Apple Podcasts, Google Podcasts, reedsmith.com, and our social media accounts.

    Disclaimer: This podcast is provided for educational purposes. It does not constitute legal advice and is not intended to establish an attorney-client relationship, nor is it intended to suggest or establish standards of care applicable to particular lawyers in any given situation. Prior results do not guarantee a similar outcome. Any views, opinions, or comments made by any external guest speaker are not to be attributed to Reed Smith LLP or its individual lawyers.

    All rights reserved.

    Transcript is auto-generated.

    26 min
  • AI explained: AI in the workplace

    As part of our new series on artificial intelligence, in the coming months, we explore the key challenges and opportunities in this rapidly evolving landscape. In this episode, our labor and employment lawyers, Mark Goldstein and Carl de Cicco, discuss what employers need to know about the use of AI in the workplace and the key differences and implications between the UK and the U.S.

    ----more----

    Transcript:

    Intro: Hello, and welcome to Tech Law Talks, a podcast brought to you by Reed Smith's Emerging Technologies group. In each episode of this podcast, we will discuss cutting edge issues on technology, data, and the law. We will provide practical observations on a wide variety of technology and data topics to give you quick and actionable tips to address the issues you are dealing with every day. 

    Mark: Hi, everyone. Welcome to Tech Law Talks podcast. We're starting a new series on artificial intelligence or AI, where the coming months we'll explore the key challenges and opportunities within the rapidly evolving AI landscape. Today, we will focus on AI in the U.S. and U.K. workplaces. My name is Mark Goldstein. I'm a partner in Reed Smith’s Labor and Employment Group, resident in our New York office. And I'm here joined today by my colleague, Carl De Cicco from our London office. And we're going to talk today about some of the U.S. and U.K. Implications for AI as it relates to the workplace. So, Carl, let me kick it over to you. And if you can tell us, you know, from a high level, what do employers in the UK need to know when it comes to AI related issues in the workplace? 

    Carl: Thank you, Mark. So, yes, my name is Carl. I'm a partner here in the London Employment Group of Reed Smith. And essentially, I think the AI issues to be concerned about in the UK are twofold. The first is how it pertains to day to day activities. And the second is how it relates to kind of management side of things. So look on the type of day-to-day activities point that's hopefully the things that people are starting to see themselves in their own workplace starting to come in so use of particular generative AI programs or models to help generate content and that's obviously increasing the amount of output individuals can have and so on the one hand it's quite good on the other hand thinking about it there might be some issues to look at so for example are people being overly reliant on their AI are they simply putting the request in and whatever is churned out by the AI system is that being submitted as the work product and if so that could be quite concerning because, AI is obviously a very useful tool and is sure to continue improving as time goes on but where we stand right now AI is far from perfect and you can get what are known as hallucinations and this seems to be quite a nice term of art for effectively what are errors so things that are conclusions that are drawn on the basis of information that doesn't exist, or quotations of things that do not exist either. So really, the content that's produced by AI should be seen as something that's collaborative with the worker that's involved in the matter rather than something which AI should be totally responsible for. So see it as a first pass rather than the finished product. You should be checking the product that comes out, not just the things like making sure that sources stack up and the conclusions draw back to the data underneath, but to make sure also that you're not getting to a stage where there might be plagiarization. So AI takes what is available on the internet and that can lead to circumstances where actually somebody somebody's very good work is already out there is simply being reproduced if not word for word substantially that can obviously lead to issues not just for the person who's submitting the work but for the employer who might use that particular piece of generated work for something that they're doing. Other benefits could be things like work allocation so one of the issues that people look at in the DEI space is our opportunities for work being fairly and equally distributed, people getting enough of a looking at work, both in terms of amount and quality. And obviously, if you have a programme which is blind to who the work is going to, there's potential for that work to be more fairly distributed so that those who don't often get the opportunity to work on particular matters are actually finding themselves onto the kind of work they weren't previously dealing with and they would like to be able to get and experience of. Now, that's the positive side of it. The potential negative there is that there might be some bias in the AI that underpins that resourcing program. So, for example, it might not pick all the individuals who are less occupied than others in a way which a business might have in a view to what's coming up over the next week or two. It might not even pick up quite how the quality of work should be viewed through all particular lenses. It might have a particular skew on how quality of work is viewed. And that could lead perhaps to an individual being even more pigeonholed than before. So all of these things are potentially positive but need to be underpinned by essentially a second human checker so whilst there are many many positives it shouldn't be seen as a panacea. So well how's that holding up for what you're seeing in the states particularly new york? 

    Mark: I think that that's absolutely right Carl similar principles apply here in the US i think it's by way of background to go through kind of where I've seen AI kind of infiltrate the workplace, if you will. And I'll distinguish between AI, traditional AI, and then generative AI. So I've seen, you know, we've seen AI be used by employers in the U.S. and a whole host of fronts from headhunting, screening job applicants, running background checks, inducting job interviews coming up with a slate of questions. Also to things like performance management for employees and even selection criteria and deciding which employees to select for a reduction in force or mass layoff. I've also seen employers use AI in the context of simple administrative tasks like guiding employees to policy documents or benefits materials and then creating employee and workplace-related agreements and implementing document retention and creation policies and protocols. In terms of generative AI, which is more, as you noted, on the content creation front, I've certainly seen that by employees being used to translate messages or documents. And to perform certain other tasks, including creating responses from manager inquiries to more substantive documents. But as you rightly note, just as in the UK, there are a number of potential pitfalls in the US. The first is that there's a risk, as you noted, of AI plagiarizing or using a third party's intellectual property, especially if the generative AI is going to be used in a document that's going to be outward facing or external, you run substantial risk. So absolutely review and auditing any materials that are created by generative AI, among other things, to ensure that there's no plagiarism or copying, especially when, again, that material is going externally, is incredibly important. Simply reviewing the content as well, just beyond plagiarism, simply to ensure general accuracy. There was a story out of, you know, New York Federal Court last summer about an attorney who had ChatGPT help write a legal brief and asked ChatGPT to, you know, run some legal research and find some cases. And ultimately, the case sites that were provided were fictional, were not actual cases that had truly been decided. So a good reminder that, as Carl said, while generative AI can be useful, it is not, you know, an absolute panacea and needs to be reviewed and conducted, you know, reviewed thoroughly. And then, you know, similarly, you run a risk if employees are using certain generative AI platforms that the employee may be disclosing confidential company information or intellectual property on that third party platform. So we want to make sure that, you know, even when generative AI is used, that employees are doing so within the appropriate confines of company policy and their agreements, of course, things like confidential information and trade secrets and intellectual property. You know, so I think it's important that employers, you know, look to adopt some sort of AI and generative AI policy so that employees know what the expectations are in terms of, you know, what they can and equally, if not more importantly, what they cannot do in the workplace as it relates to AI and generative AI. And certainly we've been helping our clients put together those sorts of policies so employees can understand the expectations. Carl you know we talked we've talked so far kind of generally about you know implications for the workplace is there any specific legislation or regulations from the UK side of things that you all have been monitoring or that have come out? 

    Carl: The approach of the UK government to date has been to not legislate in this area in a in what I think is an attempt to achieve a balance between regulation and growth the plan I think so far has been to to at some point introduce a voluntary self-regulatory scheme, which bodies sign up to. But we're recording this in June 2024, less than one month away from a UK general election. So matters of AI regulation and legislation are currently on the back burner, not to be revived perhaps for at least another two to three months. But what we can, there is still, of course, a lot of interest in this area. And the UK TUC, which is a federation of trade unions in the UK, has published sort of a framework proposal for what the law might look like. This is far from being a legislation and obviously many hurdles to pass before this might even come before Parliament and whether or not if it is passed, put before Parliament, whether it's approved by all there. But this looks at things very similar to what the EU are looking at, that is to the risks-based approach to legislation in this area. And they draw a distinction between regular decision-making and what they call high-risk decision-making. And the high-risk decision-making is really shorthand for decisions which might affect the employment of an individual, whether that's recruitment. Whether it's a decision, disciplinary decisions, termination decision. Essentially all the major employment related decisions are to go through essentially a system of checking so you couldn't rely purely for example in the framework on a decision made purely by AI. It'd be required that an individual sits alongside that or at least only uses the AI tangentially to decision that they're making. Things like no emotion recognition software would be allowed so that's for example if you were to have a disciplinary hearing and that's to be recorded you could use software which is designed to pick up on things like inflection word pattern things that might infer a particular motive or meaning behind what's been said and what this framework proposal does is say that kind of material could have that kind of software or programming couldn't be used in that kind of setting. So what happens in the UK remains to be seen but i think you guys are a bit further ahead than us and actually have some law and statute. How are things working out for you? 

    Mark: We've seen a lot of government agencies, as well as state legislatures, put an emphasis on this issue in terms of potential regulatory guidance or proposed legislation. To date, there has not been a huge amount of legislation passed specifically relating to AI in the workplace. We're still at the phase where most jurisdictions are still considering legislation. That said, there was an extremely broad law passed by New York City a few years ago, which finally went into effect last July. And in a nutshell, we can have an entirely separate podcast just on the nuances of the New York City law. But essentially what the New York City law does is it stops employers or bars employers from using an automated employment decision tool or an AEDT to screen job candidates when making employment decisions unless three criteria have been satisfied. First, the tool has been subjected to an independent bias audit within the year prior to the use. A summary of the most recent bias audit results are posted on the employer's website, and the employer has provided prior written notice regarding use of the AEDT to any job applicants and employees who will be subject to screening by it. If any one or more of these three criteria aren't satisfied, then an employer's use of that AEDT with respect to any employment decisions would violate the New York City Human Rights Law, which is one of the most employee-friendly anti-discrimination statutes in America. And other jurisdictions have used the New York City law as somewhat of a model for potential of the legislation. We've also seen the Equal Employment Opportunity Commission or the EEOC weigh in and issue some guidance, though not binding necessarily strongly cautions employers with regards to the use of AI and the potential for disparate impact on certain protected classes of job applicants and employees, and generally cautioning and recommending that employers conduct periodic audits of their tools to ensure no bias occurs. Carl, do you have any final thoughts? 

    Carl: So whilst we're still a long way from legislation in the UK, there are things employers can be thinking about and doing now to prepare themselves for I think what will inevitably be coming down the road. So just a few suggestions on that front. Establish an AI committee. So take ownership of how AI is used in the business, whether that's in the performance of day-to-day tasks and content generation and such. As Mark said earlier on, setting up things like what can be done what checks should be carried out ensuring that there is a level of quality control and also in terms of decision making ensuring that there is a policy that employers can look to to make sure that they are not going to one fall foul of something in the act and also have something so that if any decisions are challenged in future not just can they look back on the measures they've taken but show that it's consistent with a policy that they've adopted and applied on an equal basis for all individuals going through any particular process may give rise to complaints. And they might also, for example, conduct a risk assessment and audit of their systems. I mean, one of the things that will be key is not just saying that I had AI and that was used in a particular process, but knowing how that AI actually worked and how it filtered or made decisions that it did. So, for example, if you want to be able to guard against an allegation of bias, it would be good to have a good understanding of how the AI system in question that gave rise to decision that's in dispute had made its determination as over one individual than the other that will help the employer to be able to demonstrate first of all that they are an equal opportunities employer in the event of real challenge the discrimination didn't occur, so look those kind of things are things employers can be thinking about and doing. Now what kind of things do you think people on your side of the pond might be thinking about? 

    Mark: Yeah so I think you know similar similar considerations for U.S. employers. I think among them, considering the pros and cons, if you're going to use an AI tool, building your own, which some employers have opted for versus purchasing from a third party. If purchasing from a third party, particularly given the EEOC and other agencies' stated interest in scrutinizing how tools potentially might create some sort of discriminatory impact, consider including an indemnification provision in any contracts that you're negotiating. And in jurisdictions like New York City, where you're required to conduct an annual audit, but even outside New York City, especially given that it's been recommended by the EEOC, consider periodic auditing of any employee and company AI use to ensure, for instance, that tools aren't skewing a paper of or against a particular protected class during the hiring process. And again, I strongly recommend developing and adopting some sort of workplace AI and generative AI policy. Thank you all for your time today. We greatly appreciate it. Thank you, Carl. And stay tuned for the next installment in this series. 

    Outro: Tech Law Talks is a Reed Smith production. Our producers are Ali McCardell and Shannon Ryan. For more information about Reed Smith’s Emerging Technologies practice, please email [email protected]. You can find our podcasts on Spotify, Apple Podcasts, Google Podcasts, reedsmith.com, and our social media accounts. 

    Disclaimer: This podcast is provided for educational purposes. It does not constitute legal advice and is not intended to establish an attorney-client relationship, nor is it intended to suggest or establish standards of care applicable to particular lawyers in any given situation. Prior results do not guarantee a similar outcome. Any views, opinions, or comments made by any external guest speaker are not to be attributed to Reed Smith LLP or its individual lawyers. 

    All rights reserved.

    Transcript is auto-generated.

    17 min
  • AI for legal departments: Managing e-discovery and data retention risks with Microsoft Copilot

    Anthony Diana and Therese Craparo are joined by John Collins from Lighthouse to provide an overview of some of the challenges and strategies around data retention and e-discovery with Microsoft’s AI tool, Copilot. This episode explores Copilot’s functionality within M365 applications and the complexities of preserving, collecting and producing Copilot data for legal purposes. The panelists cover practical tips on managing Copilot data, including considerations for a defensible legal hold process and the potential relevance of Copilot interactions in litigation.

    ----more----

    Transcript:

    Intro: Hello, and welcome to Tech Law Talks, a podcast brought to you by Reed Smith's Emerging Technologies Group. In each episode of this podcast, we will discuss cutting-edge issues on technology, data, and the law. We will provide practical observations on a wide variety of technology and data topics to give you quick and actionable tips to address the issues you are dealing with every day. 

    Anthony: Hello, this is Anthony Diana, a partner in the Emerging Technologies Group at Reed Smith, and welcome to the latest Tech Law Talks podcast. As part of our ongoing podcast series with Lighthouse on Microsoft M365 Copilot and what legal departments should know about this generative AI tool in M365. Today, we'll be focused on data retention and e-discovery issues and risks with Copilot. I am joined today with Therese Craprro at Reed Smith and John Collins of Lighthouse. Welcome, guys. So, John, before we start, let's get some background on Copilot. We've done a few podcasts already introducing everyone to Copilot. So if you could just give a background on what is Copilot generally in M365. 

    John: Sure. So the Copilot we're talking about today is Copilot for Microsoft 365. It's the experience that's built into tools like Word, Excel. PowerPoint, Teams, Teams meetings. And basically what it is, is Microsoft's running a proprietary version of ChatGPT and they provide that to each one of their subscribers that gets Copilot. And then as the business people are using these different tools, they can use Copilot to help generate new content, summarize meetings, create PowerPoints. And it's generating a lot of information as we're going to be talking about. 

    Anthony: And I think one of the interesting things that we've emphasized in the other podcasts is that each M365 application is slightly different. So, you know, Copilot for Word is different from Copilot for Exchange, and they act differently, and you really have to understand the differences, which we talked about generally. So, okay, so let's just talk generally about the issue, which is retention and storage. So, John, why don't you give us a primer on where is the data generally stored when you're doing a prompt and response and getting information from Copilot? 

    John: So the kind of good news here is that the prompts and responses, so when you're asking Copilot to do something or if you're chatting with Copilot in one of the areas that you can chat with it, it's putting the back and forth into a hidden folder in the user's mailbox. So the user doesn't see it in their outlook. The prompts and responses are there, and that's where Microsoft is storing them. So there's also files that get referenced that are stored in OneDrive and SharePoint, which we may talk about further. But in terms of the back and forth, those are stored in the Exchange mailbox. 

    Anthony: That's helpful. So, Therese, I know we've been working with some clients on trying to figure this out and doing testing and validation, and we've come across some exceptions. You want to talk about that process, I'll say. 

    Therese: I think that's one of the most important things when we're talking about really any aspect of Copilot or frankly, new technology, right? It's constantly developing and changing. And so you need to be testing and validating and make sure you're understanding how it's working. So as you said, Anthony, you know, we found early on when Copilot, our clients first started using Copilot, that the prompts and the responses for Outlook were not being retained in that hidden folder, right? And then Microsoft has since continued to develop the product. And now, in most cases, at least we're seeing they are, you know, similarly, for those of you who are using transcriptionless Copilot, so it's Copilot that doesn't can give you meeting summaries and answer questions during the meeting, but doesn't retain the transcript, because people had some concerns about retaining transcripts, we're seeing that those Copilot artifacts, so the prompt and the response are now currently not being retained in the hidden folder. So a lot of this is you need to understand how Copilot is working, but understand that it's also a dynamic product that's constantly changing. So you need to test it to make sure you're understanding what's happening in your environment with your organization's use of Copilot. 

    Anthony: Yeah. And I think it's critical that it has to constantly be tested and validated. Like any technology, you have to constantly test it because the way it's happening now, maybe even if it's being retained now, could change, right? If they revise the product or whatever. And we've seen this with Microsoft before where they may not always, you know, they change where it's stored because for whatever reason, they decided to change the storage. So if you have an e-discovery process and like, you just have to be aware of it. Or if you're trying to retain things and you're trying to govern retention, you just have to make sure you understand where things are stored. Okay, so John, if you could explain presently sort of how retention works with Copilot data that's stored in the hidden folder of Exchange. 

    John: So what Microsoft has done so far is they've made it possible for the prompts and responses that we were talking about. So when you're in Word or Excel or PowerPoint, or if you're using the chat function inside of the Teams or in general, those are the subject to the same retention that you've set for your one-to-one in your group chats. So if you have a 30-day auto-delete policy for your one-to-one in group chats, that's going to be applied to these Copilot interactions. So I've heard, and I think you guys may have heard this as well, that Microsoft is going to split those off, but it's not on the roadmap that we've seen, but we've heard that they are going to make them two separate things. But right now they're the one in the same. 

    Therese: Yeah, and I think it's the good and the bad news, right, for people who are looking at Copilot and how do I best manage it. The good news is that you can control retention. You can set a retention on it that's within the organization's control and you can make the decision that's right for your organization. The bad news is that it has to be the same as whatever right now is for whatever you're setting for Teams chat, which may or may not be how long you would like to retain the Copilot data. So there are some features that are good, that gives you a little bit control to make decisions that are right for the organization. But right now, they're only partially controllable in that sense. So you have to make some decisions about, you know, how long do you need Teams chat? How long do you need Copilot? And where's the right place in the middle to meet business needs, right? And also to take into consideration how long this data should exist in your organization. 

    Anthony: Yeah. And John, we've heard the same thing and heard from Microsoft that they're working on it, but I haven't heard if there's a roadmap and when that's happening. But we have several clients who are monitoring this and are constantly in contact with Microsoft saying, when are we going to get that split? Because at least for a lot of our clients, they don't want the same retention. And I think, Therese, we could talk a little bit about it in terms of what people are thinking about, what to consider. Once we get to a place where we can actually apply a separate retention for Copilot, what are the factors to consider when you start thinking about what is the appropriate retention for this Copilot data? 

    John: And Therese, do you want them to be ephemeral where you could have a setting where they just go, they aren't captured anywhere? I'd be curious if you guys think that's something that you would want clients to consider as an option. 

    Therese: Well, look, I mean, the first thing all of our clients are looking at is business needs, right? Is this with anything, right? Do the artifacts from Copilot need to exist for a longer period of time for a business use? And in general, the answer has been no. There's no real reason to go back to that. There's no real reason to keep that data sitting in that folder. There's no use of it. The users don't go, like John, as you said, you can't see it. Users aren't going back to that data. So from a business perspective, you know, number one thing that we always consider, the answer has been no, we don't need to retain these Copilot artifacts for any business reason. The next thing we always look to is record retention, right? Is there a legal regulatory obligation to retain this Copilot artifacts that are coming out? And in most cases, when our clients look at it, the answer is no, it's not a record. It's not relied on for running the company. It doesn't currently fall under any of the regulations in terms of what a record is. It's convenience information or transitory information that may exist in the organization. So typically, again, that next component is records. And typically, at least with Copilot, we're seeing that the initial output from Copilot, the question and the response, are not considered records. And so once you get to that point, the question is, why do I need to keep it at all? Which is, John, to what you're alluding to, you know, today for all data types, whether it's Copilot or otherwise, right, over-retention presents risks. It presents privacy risks and security risks, all kinds of risks to the company. So the preference is to retain data only for as long as you need it. And if you don't need it, the question arises, do you need to keep it at all? Do you need it even for a day? Could you make it ephemeral so that it can just disappear when it's gone because it has served its useful life and there's no other reason to keep it? Now, we always have to consider legal holds whenever we have these conversations, because if you have a legal hold and you need to retain data going forward, you need to have a means of doing that. You need to be aware of how to retain that data, how to preserve that data for a legal hold purpose if you deem it to be relevant. of it. So that's always the caveat. But typically when we're seeing people look at this, when they actually sit down and think about it, there hasn't been to date really a business or records reason to retain that data in the ordinary course of business. 

    Anthony: And so it's a matter of how do you enforce that? And whether, John, I mean, when we talk about ephemeral, it is retained. So ephemeral would be probably like one day, right? So it would basically be kept for one day, which raises all kinds of issues because they're there for one day. And as we've seen with other, whether it's team chats or any type of instant messaging, once it's there, and we're gonna talk a little bit about preservation, it's there, right? So for one day it's there. So let's talk a little bit about sort of the e-discovery issues and particularly preservation, which I think is the issue that a lot of people are thinking about now as they're rolling this out is, can I preserve this? So John, how do you preserve Copilot data? 

    John: So that's pretty straightforward, at least in one respect, which is if you're preserving a user's Exchange Online mailbox, unless you put in some kind of condition explicitly to exclude the Copilot prompts and responses, et cetera, they're going to be preserved. So they will be part of what's being preserved along with email and chats and that type of thing. So the only The only question is, and if we're going to get into this, Anthony and Therese, but the reference files, the version shared and all that. But as far as the prompts and responses, those are part of the mailbox. They're going to be preserved. 

    Anthony: So you're talking about a potential gap here then. So let's just talk about that. When you're doing prompts and responses, oftentimes you're referencing a specific document, right? It could be a Word document. You're asking for a summary, for example, of a Word document. it's going to refer to that document in the prompt and response. So what is or isn't preserved when you preserve the mailbox in that situation? 

    John: Well, I know we were talking about this before, but there's really, the question is, do you have the version shared feature enabled? Because the Microsoft documentation says if you want referenced files to be preserved as part of your Copilot implementation, you have to enable version shared. But in our testing, we're seeing inconsistent results. So in one of our tenants, we have version shared, and that's exactly what it's doing is if you say, summarize this document or use this document to create a PowerPoint, it is treating it almost like a cloud attachment. And it's it, but that's not, but that's not for preservation purposes. That's at the collection stage. It goes back to the topic that I know you guys, we talk about this a lot is, well, do I have to preserve every SharePoint and OneDrive where something might live that somebody referenced, right? And that's kind of the question there with the reference files. 

    Anthony: Got it. So you're not preserving it necessarily because like a modern attachment, which we've talked about in the past, it's not preserving it. Although if they're looking at a document from their OneDrive and you have the OneDrive on hold, that document should be there. So when you go to collect it, you can. Assuming that there's this setting, you have to have the version shared. So it's actually linking that attachment to this Copilot data. So a lot to digest there, but it's complicated. And again, I think you point out, this is a work in progress you have to test, right? You cannot assume that based on what we're saying, it's actually going to work that way because we've seen the same thing. You have to test and it often changes because this is a work in progress and it's constantly being changed. But that's an interesting point to think through. And again, I think from a preservation standpoint, Therese, is it required to preserve it if you have Copilot data and they're referring to a document? Is it similar to like an e-comms where we say, generally in the e-comms front where we talk about a Team's message, we always said, well, you need it because it's the complete electronic communication. So therefore to get completeness, we generally say you should be producing it in the like Copilot data, do we think it's going to be any different? 

    Therese: Look, I mean, I think it depends is the answer. And if you look out there, even when we're talking about e-discovery, when you look at the cases that are out there talking about links, right, links to attachments or links to something that's in an email or in an e-comm, it's mixed, right? Right. The courts have not necessarily said in every case you have to preserve every single document for every single link. Right. You need to preserve what is relevant, even with production. Courts have said I'm not going to make them go back and find every single link necessarily. But if there's something that is deemed relevant and they need that link, you may have an obligation to go back and find it and make sure that you can find that document. So I don't think it's as clear cut as you must, you know, turn on version shared to make sure that you can, you are, quote, preserving every single referenced file and every single Copilot, you know, document. We certainly don't preserve every single document that's referenced in a memo, right? Or in a document that it refers to. There's a reference to it and maybe you have to go find that. So I think that it's not really clean cut. It's really a matter of looking at your Copilot setup. And making some strategic decisions about how you are going to approach it and what makes the most sense and making sure you're communicating that, right? That the structure and the setup of Copilot is coordinated with legal and the people who need to explain this to courts or to regulators and the like. And that you're educating your outside counsel so that they can make sure that they are representing it correctly when they're representing you in any particular case that says, this is how our Copilot works. These are the steps that we take to preserve. This is why. And this is how we handle that data. And I think really that's the most important thing. We're sort of, this is a new technology. It's, we're still figuring out what the best practices are and how it should be. I think the most important thing is to be thoughtful. Understand how it functions. Understand what steps you're taking and why. So that those can be adequately communicated. I think most of the time when we see these problems popping up, it's because someone hasn't thought about it or hasn't explained it correctly. Right? And that's the most important thing is understanding the technology and then understanding your approach to that technology from a litigation perspective. 

    Anthony: Yeah. And I think one of the challenges, right? And I think this is both a risk and a challenge. And we've heard this from a lot of litigation teams as this Copilot is being launched is it's not always accurate, right? Like it's, and I think you maybe make the argument that it's not relevant because if I'm a user and I'm asking a question, and it comes back, and it's just answering a question, and it's wrong, but you don't know that. I mean, it's Copilot. It's just giving you an answer. Is it really relevant? What makes it relevant? I may be asking the question of Copilot relating to the case. Let's assume that it's relating to the case in some way, underlying matter. You ask a question, you get a response back. Do you really need to preserve that? I've heard from litigators saying, well, if they go to Google, and they do a Google search on that topic, we're not preserving that necessarily. So what do we think that the arguments are that it's relevant or not relevant to a particular matter? 

    Therese: I mean, look, relevance is always relative, right, to the matter. And I think that it's difficult with any technology to say it's never relevant, right? Because relevance is a subject matter and a substantive determination. Just to say a particular technology is not relevant is a really hard, I think, position to take in any litigation, frankly. It's also very difficult to say, well, it's not reliable, so it's not relevant. Because I can tell you, I've seen a lot of emails that are not reliable, and they are nonetheless very relevant, right? The fact that somebody asked a certain type of prompt in certain litigations could be quite relevant in terms of what they were doing and how they were doing it. But I think it's also true that they're not always going to be relevant. And there's a reliability aspect that often comes in, I think, probably less so at the preservation stage and more so at the production stage. Right, in terms of how reliable is it, is this information? Again, this is about understanding the technology. Does your outside counsel know that if you are one, are you going to take the position that we're not going to produce it because it's not reliable, right? And be upfront about that and take that position and see if that's something that you can sustain in that particular case. Can you can explain that they would not be relevant here and it's not going to be reliable in any case, right? Are you going to take that position or not? Or at the very least, if you are going to produce it, that you understand that it is inherently unreliable, right? A computer gave an answer to a question that may or may not be right, and depends on a user reviewing that. You know, if the user used it and sent it out, you can review, that's when it becomes important or valuable. But understanding the value of the data, so you take appropriate positions in litigation, so that if for some reason Copilot artifacts are relevant, you can say, well, sure, that may be on a topic that is relevant to this case. But the substance of that is unreliable and meaningless, right, in this context. So I think, I mean, one of the funny things that I always think is, right, we say email is relevant, but not all email is relevant. We preserve all email because we don't have a way at the preservation stage to make a determination as to which email is relevant and which email is not, right? But I think that's true, right, with Copilot. I mean, at the end of the day, unless you are being upfront that I'm not preserving this, or you can say this type of data, there are cases where email is not relevant, right, at all for the case, unless you could take that position. You preserve that data because you don't know which of those Copilot interactions are on the topic that could matter or could be relevant. But you're thoughtful again down the road about your strategic positioning about whether or not it should be produced or whether or not it has any value in evidentiary value in that litigation given the nature of the data itself. 

    Anthony: And John, you talked a little bit about this. I know you're doing some testing. Everyone's doing some testing now on collecting and reviewing this data, this Copilot data. What can you tell us about? You got prompts and responses. Are they connected in any way? Is there a thread if you're doing a bunch of them? How does it all work based on what you're seeing so far? 

    John: Right. Well, like a lot of Microsoft, when it comes to e-discovery, some of it's going to depend on your licensing. So if you have premium eDiscovery, then for the most part, what we've been seeing in our testing is that when you collect the chats or when you collect the Copilot information, what it's going to do is if you select the threading option and the cloud attachment option, it's going to treat the Copilot back and forth largely like it's a Teams chat. So you'll see a conversation, it'll present as an HTML, it'll show you, it'll actually collect as cloud attachments, the files that are referenced, if you've got that set up. So to a large degree, in terms of determining if things are relevant and that type of thing, you can do keyword searches against them and all of that. So at this point, what we're seeing with our testing is that for the most part, it's treating the back and forth as these chat conversations similar to what you see with Teams. 

    Anthony: And I'm sure there'll be lots of testing and validation around that and disputes as we go forward. But that's good to know. Okay, well, I think that that covers everything. Obviously, a lot more to come on this. And I suspect we'll be learning a lot more about Copilot and retention and discovery over the next six months or so, as it becomes more and more prevalent, and then starts coming up in litigation. So thank you, John and Therese, and hopefully you all enjoyed this and certainly welcome back. We're going to have plenty more of these podcasts on this topic in the future. Thanks. 

    Outro: Tech Law Talks is a Reed Smith production. Our producers are Ali McCardell and Shannon Ryan. For more information about Reed Smith's Emerging Technologies practice, please email [email protected]. You can find our podcasts on Spotify, Apple Podcasts, Google Podcasts, reedsmith.com, and our social media accounts. 

    Disclaimer: This podcast is provided for educational purposes. It does not constitute legal advice and is not intended to establish an attorney-client relationship, nor is it intended to suggest or establish standards of care applicable to particular lawyers in any given situation. Prior results do not guarantee a similar outcome. Any views, opinions, or comments made by any external guest speaker are not to be attributed to Reed Smith LLP or its individual lawyers. 

    All rights reserved.

    Transcript is auto-generated.

    24 min
  • AI for legal departments: Managing legal and regulatory risks within Copilot

    Anthony Diana and Samantha Walsh are joined by Lighthouse’s Chris Baird as part of our series on what legal teams need to know about Microsoft 365 AI-driven productivity tool, Copilot.

    This episode presents an overview of the risks relating to Copilot’s access to and use of privileged and sensitive data and how businesses can mitigate these risks, including using Microsoft 365's access control tools and user training. 

    In particular, the episode provides in-depth information about Microsoft 365's sensitivity labels and how they can be used to refine a business’s approach to managing risk associated with privileged and sensitive data stored in Microsoft 365.

    ----more----

    Transcript:

    Intro: Hello, and welcome to Tech Law Talks, a podcast brought to you by Reed Smith's Emerging Technologies Group. In each episode of this podcast, we will discuss cutting edge issues on technology, data, and the law. We will provide practical observations on a wide variety of technology and data topics to give you quick and actionable tips to address the issues you are dealing with every day. 

    Anthony: Hello, this is Anthony Diana, a partner here in Reed Smith's Emerging Technologies group, and welcome to Tech Law Talks and our podcast series on AI for legal departments with a focus on managing legal and regulatory risks with Microsoft Copilot that Reed Smith is presenting with Lighthouse. With me today are Sam Walsh from Reed Smith's Emerging Technologies Group and Chris Baird from Lighthouse. Welcome, guys. Just to level set, Copilot is sort of the AI tool that Microsoft has launched relatively recently to improve productivity within the Microsoft environment. There are a number of risks that we went through in a previous podcast that you have to consider, particularly legal departments, when you're launching Copilot within your organization. And let me just start to level set with Chris, if you could give a little bit of a technical background on how Copilot works. 

    Chris: Absolutely, Anthony. So thanks Thanks for having me. So I guess a couple of key points, because as we go through this conversation, things are going to come up around how Copilot is used. And you touched on it there. The key objective is to increase, improve data quality, increase productivity. So we want really good data in, want to maximize the data that we've got at our disposal and make the most of that data, make it available to Copilot. But we want to do so in a way that we're not oversharing data. We're not getting bad legacy data in, you know, stale data. And we're not getting data from departments that maybe we shouldn't have pulled it in, right? So that's one of the key things. We all know what Copilot does. In terms of its architecture, so think about it. You're in your Canvas, whatever your favorite Canvas is. It's Microsoft Word, it's Teams, it's PowerPoint. You're going to ask Copilot to give you some information to help you with a task, right? And the first piece of the architecture is you're going to make that request. Copilot's going to send a request into your Microsoft 365 tenant. Where is your data? It's going to use APIs. It's going to hit the Graph API. There's a whole semantic layer around that. And it's going to say, hey, I've got this guy, Chris. He wants to get access to this data. He's asking me this question. Have you got his data? And the first thing, really, there's this important term Microsoft use. They call it grounding. When you make your request into Copilot, whatever you request, you're going to get data back that's grounded to you. So you're not going to get data back from an open AI model, from Bing AI. You're only going to get data that's available to you. The issue with that is if you've got access to data you didn't know you had, you know, through poor governance. Maybe somebody shared a link with you two years ago. That data is going to be available to you as well. But what's going to happen, a few clever things happen from an architecture perspective. The graph gives a response. It says, hey, I've got Chris's data. It looks like this. That's going to go into the large language model. That's going to make it look beautiful and pass you all that data back in a way you can understand it. There's a final check that Copilot does at that point. It goes back to the graph and it says, I've got this response. I need to give it to the user. user, are there any compliance actions I need to perform on this response before I give it? And I think that's what we're going to focus on a lot today, Anthony, right? But the important thing is thinking about that grounding. And the one message I want to give to people listening is really, you know, don't be immediately scared and worried of Copilot. It respects a lot of the controls that are in there already. The challenge is if you have poor access control and governance, there are things that you need to work on. 

    Anthony: Yeah. And I think that's one of the challenges. I think a lot of legal departments don't know what access controls and what controls that the IT department has put in place into M365. And I think that's one of the things that you have to understand, right? I think that's one of the things we'll be talking about today is the importance of that. out. So Sam, just talking about what we're our focus today, which is on the risks associated with privileged information, highly confidential information, sensitive information. So can you just give a just a brief description of what those risks are? 

    Samantha: Sure. So I think one of the risks Chris just alluded to that Copilot is going to have access to information that you have access to, whether you know it or not. And so if you have privileged information that is sort of protected by just being in a spot maybe where people don't know it's there, but it's not necessarily controlled in terms of access, that could be coming up when people are using Copilot. I think another thing is Copilot returning information to people, you lose a bit of context for the information. And when you're talking about privilege and other types of sensitivity, sometimes you need some clues to alert you to the privilege or to the sensitive nature of the information. And if you're just getting a document sort of from the ether, and you don't know, you know, where it came from, and who put it there, you know, you're obscuring that sort of sensitive nature of the document potentially. 

    Anthony: Yeah. And then I guess the fear there is that you don't realize that it's privileged or highly confidential and you start sharing it, which causes all kinds of issues. And I think just generally for everyone is the regulators. And I think both on the privacy side, where there's a lot of concern about where you're using AI against personal information or highly sensitive personal information, as well as the SEC, which is very focused on material, not public information and how you're using AI against it. I think one of the things that people are going to be asking, the regulators are going to be saying, what controls do you have in place to make sure that it's not being used inappropriately? So again, I think that sets the groundwork for why we think this is important and you start setting things up. So one of the first things you do, let's talk about how you can manage the risk. I think one of the things you can do, right, which is pretty simple, is training, right? Like the users have to know how to do it. So Sam, what should they be thinking about in terms of training for this? 

    Samantha: I think you can sort of train users both on the inputs and maybe on what they're doing with the outputs from Copilot. I think there are certainly ways to prompt Copilot that maybe would reduce the risk that you're going to get just this information flooding in from parts unknown. known. And I think having clear rules about vetting of co-pilot responses or limitations on sort of just indiscriminately sharing co-pilot responses, you know, these are all kinds of things that you can train users in to try to sort of mitigate some of the data risk. 

    Anthony: Yeah, no, absolutely. And I think we're also seeing people just so in doing this and launching it, having user agreements that sort of say the same thing, right? What are the key risks? The user agreement says, make sure you're aware of these risks, including the risks that we've been talking about with sensitive information and how to use it. Okay, so now let's switch to more sort of from a technical perspective, some things you can do within the M365 environment to sort of protect this highly confidential information or sensitive information. Information so let's start with Chris sort of this concept of which i know is in there when you have a SharePoint online site or a team site that has a SharePoint online site i think one of the one of the things you can do is basically exclude those sites from co-pilot so if you give us a little a brief description of what that means and then a little bit about the pros and cons. 

    Chris: Yeah of course Anthony so that that control by the way that's that's nothing new. So for anybody that's administered SharePoint, you've always had the ability to control whether a site appears in search results or not. So it is that control, right? It's excluding sites from being available via search and via Copilot. You would do that at the SharePoint site level. So, you know, Microsoft makes that available. There's a couple of other controls, maybe one I'll mention in a second as well. These are kind of, I don't want to call it knee-jerk reaction, I guess I just did, but it's what are the quick things you can do if you want to get access to Copilot quickly and you're worried about some really sensitive information. And it is a knee-jerk, right? It's a sledgehammer to crack a door. You're going to turn off entire access to that whole site. But in reality, that site may have some real gems of data in that you want it to make accessible to Copilot. And you're going to miss that. The other quick win that's similar to that one, there's a product called Double Key Encryption. A lot of the products I'm going to talk about today are part of the Microsoft Purview stack. And as part of MIP, which is Microsoft Information Protection, we're definitely going to cover that, Anthony, shortly about labels. One thing you can do with the label is you can apply something called Double Key Encryption. And you would use your own encryption key. And that means Microsoft cannot see your data. So if you know you've got pockets of data that are really secret, really sensitive, but you want to activate Copilot quickly, you've got these options. You can disable a site from being available at search level. That's option one. The other option is at a data level. You can label it all as secret. That data is not going to be accessible at all to Copilot. But like I say, these are kind of really quick things that you can do that don't really fix the problem in the long term. don't help you get the best out of Copilot. The reason you're investing in Copilot is to get access to good quality data and hiding that data is a problem. 

    Anthony: Yeah. And I think one of the things that, and Microsoft has basically said, even though it's available, they've been pretty open about saying, this is not the way you should be managing the risks that we're talking about here. Because you do lose some functionality in that SharePoint site if you take it out of search. So it's an option if you're rushing. And that's basically why they said, If you frankly aren't comfortable and you haven't have all the controls in place and you really have certain data that you want excluded, it's an option. But I think, as you said, it's a sort of a knee-jerk short-term option if you really have to launch, but it's not a long-term solution. So, now let's focus a little bit on what they think is the right way to do it, which is, and first let's talk about the site level. I think you talked a little bit about this, is putting in this concept of a sensitivity label on a site. Now, before you do that, which we could talk about, is first you have to identify the site. So, Chris, why don't you talk a little bit about that, and then let's talk a little bit about the technical. 

    Chris: No, absolutely. So a couple of terminology things. When I talk about data classification, I'm talking about something different to applying a label. When I often say to a lot of my clients, data classification, they think, oh, that's confidential, highly confidential secret. What I mean when I talk about data classification is what is the data in its business context? What does it mean to the organization? Let's understand who the data owner is, what the risk of that data is if it falls into the wrong hands. What are the obligations around processing and handling and storing that data? How do we lifecycle it? So simple things would be, really simple things would be social security numbers, names, addresses, right? We're identifying data types. We can then build that up. We can move on from those simple things and we can do some really clever things to identify documents by their overall type, their shape, their structure. We can use machine learning models to train, to look for specific documents, case files, legal files, customer files, client files, right? We can train these machine learning classifiers. But the great thing is if you get a good handle on your classification, you will be able to discover and understand your data risk across your enterprise. So you'll see there are tools within Microsoft 365 Purview, Content Explorer, data classification. These tools will give you insights into SharePoint sites that you have in your organization that have high amounts of social security numbers, high amounts of case files, legal affairs documents, right? It's going to come back and tell you, these are the sites that have this type of information. And you can do that analysis. You don't have to go out and say, guys, you've got to put your hand up and tell us if you've got a SharePoint site with this information. The administrators, the guys that are running Purview, they can do that discovery and reach out to the business and go and discuss that SharePoint site. But Anthony, what you're talking about there is once you've identified that SharePoint site, you know, if we know we've got a SharePoint site that contains specific case files that are highly confidential, we can apply a highly confidential label to that site. And the label does a number of things. It visually marks the file, right? And what I mean by that, at a file level from a metadata perspective, anybody interacting with that file electronically will receive a pop-up dialogue on a ribbon or a pop-up. It's going to be front and center to say this file is labeled as highly confidential. I've also got options, which I'm sure we've all done before in the day-to-day work. You can mark the document itself across. You can put a watermark across the document to say it's highly confidential. You can put headers and footers on. So the label isn't just this little concept, but it takes it a step further even more. And this is where it really, really works with Copilot is you can define custom permissions at a label level. So we can say for highly confidential labels, we might have a label for a particular case, a particular project. And if it is a case label, then we could give permissions to only the people involved in that case. So only those people can open that file and that means only those people can talk about that file to copilot you know if you're not in that case Anthony if you're not part of that case and me and Sam are and i use that label you're going to ask copilot to give you all the information it can about that case you're not going to get any information back because you don't have the permissions that's on that source file so that's that's one of the first things that we can do is we can take that label and apply it to a sharepoint site and that's going to apply a default label across all the documents that are in that site. What we're really talking about here, by the way, when we talk about labels, is we're trying to plug a hole in access control and governance. So think about SharePoint management and hygiene. The issue is SharePoint has just grown exponentially for many organizations. You know, there's organic growth, you've got SharePoint migrations, but then you have this explosion of use once you're on SharePoint online. There's going to be public sites. There's going to be SharePoint sites that are public, that are available to everybody in your organization. There'll be poor JML processes, join and move and leave processes, where people who move departments, their access isn't revoked from a SharePoint site. The issue with Copilot is if the site access control isn't strict, if it's open and the file doesn't have permissions on the file, Copilot is going to be able to see that file. If it's public, it's going to be able to see that file, right? So with the label, where that differs to the permissions is it puts the access controls on the files that are in that SharePoint site directly. So if you lift those files from that site, if it is a public site and I take those files, I put it in another SharePoint site or I put it on my laptop, it carries the access control with it. And that's what's really important. That means that wherever that file goes, it's going to be hidden from Copilot if I don't have that access. That's the important thing. So, you know, sensitivity labels are a huge part of ensuring compliance for co-pilot, probably the biggest first step organizations can take, And I think you touch on the first step quite nicely, Anthony. A lot of our clients say, well, we're scared of labeling everything in the organization, going out immediately, doing all that discovery, labeling everything, right? Maybe just knock off the top SharePoint sites, the ones that you know contain the most sensitive data. Start there. Start applying those labels there. 

    Anthony: Yeah, and Sam, we've talked with some clients about using their provisioning process or attestation process, process lifecycle management to start gathering this information because it's a big project, right? If you have thousands of sites, the concept of figuring out which ones have that. Obviously, Chris talked about, so the technical way you could do it, which would be fantastic because that obviously, but there are other ways of low-tech ways of doing this. 

    Samantha: Right. Just kind of relying on your human resources to maybe take a little bit more of a manual approach to speaking up about what kind of sensitive data they have and where they're putting it. 

    Anthony: Which they may be doing already, right? I think that's one of the things that you have to track is like they may, an organization, you know, a specific business line may know where their data is. They just haven't told, they haven't told IT to do something with it. So I think it's just getting that information, gathering it through, you know, whether it's the provisioning process, you could do an attestation or survey or whatever, just to start. And then as Chris said, once you have an idea of what the highly confidential information sites are, then you start doing the work. And again, I think it's applying the labels. One of the things that I think, just to emphasize, and I want to make sure people understand this, is in the sensitivity labels, it's not an all or nothing. At least what I've seen, Chris, is that for each sensitivity label, right, and you could have different types of highly confidential information. Maybe it's sensitive personal information, maybe a material non-public information. Whatever it is, privileged information, you can have different settings. So, for example, you can have it where the site is in essence like a read-only, right, where nobody can touch it, nobody can transfer the data, you can't copy it. That's the most extreme. But then you can have others where it's a little bit more permissive. And as you said, you can tailor it so it could be, you know, certain people have it, certain groups or security groups or whatever, how you want to play. But there is some flexibility there. And I think that's where the legal departments have to get, you know, really talk to the IT folks and really look and figure out what are the options for just not just applying the sensitivity label, but what restrictions do we want to have in place for this? 

    Chris: Anthony as well like you know you you're touching on the really important thing there and I'm going to go back to what Sam had talked about earlier with training as well about culture but I guess you know the the important thing is finding the balance right so with a sensitivity label you are able as an administrator as an IT administrator you can define the permissions for that label so like I say you could have a high level and by the way you can have sub labels as well so let's go with a common scheme that we see, public, internal, confidential, highly confidential. We've got four labels. Highly confidential could be a parent label. And when we click on that, we get a number of sub labels and we could have sub labels for cases. We could have sub labels for departments. And at an administrative level, each of those labels can carry its own predefined permission. So the administrator defines those permissions. And exactly as you say, Anthony, you know, one of the great things about it, it's not just who can access it, it's what can they do with it. Do not forward, block reply to all. You can block screen share screen copy all of those kind of things save and edit it can block all of those things where i say you need to find a balance is that's going to become onerous for the administrator if every time there's a case you're going back for a new label for each case and you're going to end up with thousands of labels right so what microsoft gives you is an option to allow the users to define the permissions themselves and this is where it really works well for copilot but before i talk about what that option is i want to go back to what Sam said and talking about the training. One of the important things for me is really fostering a culture of data protection across the organization, making people realize the risk around their data, having frequent training, make that training fun, make it interactive if you can. At Lighthouse, our training is, it's kind of a Netflix style. There's some great coffee shop things where it's fun. We get to watch these little clips. But if you make people want to protect their data, when they realize data is going to be available to co-pilot now, they'll be invested in it, right? They'll want to work with you. So then when you come to do the training, Sam, you need to say, right, we're not going to use the administrative defined labels. It's too much burden on the admin. We're going to publish this label for highly confidential that allows the users to define the permissions themselves. And that's going to pop up in Word. If you're in your favorite canvas, you're in Word, you click highly confidential, it's going to pop up and say, what permissions do you want to set on this file? If you haven't trained, if you haven't fostered that culture of information protection amongst the user community, people are going to hate it, right? People aren't going to like that. So it's so important to start to engage and discuss and train and coach and just develop that culture. But when it's developed, people love it. People want to define the permissions. They want to be prescriptive. They want to make sure that information cannot be copied and extracted and so on. And anything you do at that level, again, it protects that data from being read in by Copilot. That's bringing that back to the whole purpose of it. 

    Anthony: And I would just say, again, that this all goes about prioritization because people are like, I have 50,000 people in my organization. There's no way I'm going to train everybody. You don't. I mean, obviously some, but there's only certain people who should have access to certain of this information, right? So you may want to train your HR people because they have a lot of the personal sensitive information, the benefits folks or whatever, because you have to break it down because I think a lot of people get caught up into, I'm never going to have 50,000 people do this, but you don't. Everyone has different things that come across their desk based on the business process that you're working on. So again, it's just thinking logically about this and prioritizing because I think people think training and, oh my God, I'm relying on the user and this is going to be too much. I think to your point is if you do it in chunks and say, okay, here's a business line that we think is really high risk, just train them on that. And like you said, it's part of their job, right? HR is not going to have like compensation. They're not throwing that everywhere in the organization. They shouldn't be right. But if they do, they know they're sensitive about it. And now you're just giving a tool, right? We know you want to protect this. Here's the tool to do it. So again, I think this is really important. Before we end I know, Chris, I think you had one more thing that you want to add, which was on the monitor monitoring side, which I had not heard of, but could you just talk a little bit about that? 

    Chris: You know, this is sort of really key information that you can think of going up to your leaders in your organization to say, look, we've got a roadmap for co-pilot adoption. It's X many months or however long it's going to take, but now we can implement some quick wins that really give us visibility. So there's a product, there's two products. Many of the listeners will probably know the second product that I'm about to talk about, but the first one might be new. There's a product called Communication Compliance. It's part of the Microsoft E5 or E5 Compliance or IP and Governance Suite. It's in Purview. Technically speaking, it's a digital surveillance product that looks at communications through Teams and throughout Look and through Viva. But what Microsoft has introduced, and this is a stroke of genius, it really is, they've introduced co-pilot monitoring. So the prompt and the responses for co-pilot can now be monitored by communication compliance. And what that means is we can create simple policies that say, if personal information, client information, case information. Is passed through a prompt or a response in Copilot. Let us know about it. We can take it a step further. If we get the sensitivity labels in, we can use the sensitivity labels as the condition on the policy as well. So now if we start to see highly confidential information spilling over in a Copilot response, we can get an alert on that as well. And that I think is just for many of the listeners, it's a quick win. You can go, cause you're going to be your CIO or, or, you know, your VP is going to be saying, we need Copilot. We want to use Copilot. that your CISO and your IT guys are saying, slow down. You can go to the CISOs and say, we've got some controls, guys. It's okay. Now, the other tool, which a lot of the listeners will know about is eDiscovery Premium. What you can do with communication compliance once you're alerted is you can raise a case in eDiscovery Premium to say, go and investigate that particular alert. And what that means is we can use the eDiscovery tools to do a search, a collection. We can export and download. We can look at a forensic level. What information came back in the response? And if it was data spillage, if that data came from a repository that we thought was secure, specific to some case or legal information, and now it's in the hands of a public-facing team in the organization, you can use the tools. You can use eDiscovery through the Graph API to go and delete that data, that newly created data. So two real quick wins there to think about is deploying communication compliance with eDiscovery. 

    Anthony: That's fantastic. Well, thanks, everybody. This was really helpful. We're going to have additional podcasts. We'll probably talk about e-discovery and retention alike in our next one. But thank you, Chris and Sam. This was highly informative. And thanks to our listeners. Welcome back. We hope you keep listening to our podcast. Thanks. 

    Outro: Tech Law Talks is a Reed Smith production. Our producers are Ali McCardell and Shannon Ryan. For more information about Reed Smith's Emerging Technologies practice, please email [email protected]. You can find our podcasts on Spotify, Apple Podcasts, Google Podcasts, reedsmith.com, and our social media accounts. 

    Disclaimer: This podcast is provided for educational purposes. It does not constitute legal advice and is not intended to establish an attorney-client relationship, nor is it intended to suggest or establish standards of care applicable to particular lawyers in any given situation.

    All rights reserved.

    Transcript is auto-generated.

    27 min
  • AI for legal departments: Introduction to M365 Copilot

    Anthony Diana and Karim Alhassan are joined by Lighthouse’s John Collins to discuss Microsoft's AI-driven productivity tool, Copilot.

    This episode presents an overview of Copilot and its various use cases, the technical nuances and details differentiating it from other generative AI tools, the identified compliance gaps and challenges currently seen in production, and the various risks legal departments should be aware of and accounting for.

    This episode also provides a high-level overview of best practices that legal and business teams should consider as they continue to explore, pilot and roll out Copilot, including enhanced access controls, testing and user-training, which our speakers will further expand upon in future episodes.

    ----more----

    Transcript:

    Intro: Hello and welcome to Tech Law Talks, a podcast brought to you by Reed Smith's Emerging Technologies Group. In each episode of this podcast, we will discuss cutting edge issues on technology, data, and the law. We will provide practical observations on a wide variety of technology and data topics to give you quick and actionable tips to address the issues you are dealing with every day. 

    Anthony: Hello, this is Anthony Diana, a partner here in the Emerging Technologies Group at Reed Smith. Welcome to Tech Law Talks. Today will be the first part of a series with Lighthouse focusing on what legal departments need to know about Copilot, Microsoft's new artificial intelligence tool. With me today are John Collins from Lighthouse and Karim Alhassan from Reed Smith. Thanks guys for joining. So today, we really just want to give legal departments sort of at a very high level what they need to know about Copilot. As we know Copilot was just introduced, I guess like last fall, maybe November of last year by Microsoft. It has been in preview and the like and then a lot of a lot of organizations are at least contemplating the use of Copilot or some of them, I've, I've heard have already launched Copilot without the legal departments knowing which is an issue in of itself. So today, we just want to give a high level view of what Copilot is, what it does at a really high level. And then what are the things that legal department should be thinking about in terms of risks that they have to manage when launching Copilot? This will be of a high level of additional series, which will be a little bit more practical in terms of what legal department should actually be doing. So today is just sort of highlighting what the risks are and what you should be thinking about. So with that John, I'll start with you. Can you just give a very high level preview of what, what is Copilot that's being launched? 

    John: Sure, thanks Anthony for having me. So Copilot for M365 which is what we're talking about is Microsoft's flagship Generative AI product. And the best way to think about it is it's Microsoft which has a partnership with open AI is taken the ubiquitous ChatGPT and they've brought it into the Microsoft ecosystem. They've integrated it with all the different Microsoft applications that business people use like Word Excel, powerpoint and teams. And you can ask Copilot to draft a document for you to summarize a document for you. So again, the best way, think about it is that it's taking that generative AI technology that everyone is familiar with, with ChatGPT and bringing it into the Microsoft ecosystem and leveraging a number of other Microsoft technologies within the Microsoft environment to make this kind of a platform available to the business people. 

    Anthony: Yeah. And I think, you know, I think from at least from what Microsoft is saying and I think a lot of our clients are saying that this is, this is groundbreaking, this is going to be and frankly, it's probably going to be the largest and most influential AI tool Enterprise has because Microsoft is ubiquitous, right? Like all your data is flowing through there. So using AI in this way, should provide tons of productivity. Obviously, that's the big sell. But it is obviously everyone, if they get licenses for everybody, this is something that's going to impact I think most organizations pretty highly just because it is, you know, if you're using Microsoft M365 you're going to be dealing with AI and you know, sort of on a personal level, large scale and the like, and I think that's one of the challenges we'll see. So Karim could you just give a little bit? I mean, John gave a very nice overview just in terms of a few things that he said in terms of we've got this ChatGPT, what is it that's unique about Microsoft in terms of how it works from a from a technology perspective because I know a lot of people are saying I don't want people using ChatGPT for work. 

    Karim: Sure, thanks Anthony. You know, as opposed to kind of these publicly web based ChatGPT tools, the I think the big sell and what makes Copilot unique is that it's grounded in, you know, your enterprise data, right? And so essentially it integrates with the Microsoft graph, you know, so which allows, you know, users within the enterprise to leverage their M365 data, which adds context. And so rather than just going to, you know, GPT-4, which is, you know, as everyone knows, trained on publicly available data and has its own issues, you know, hallucinations and whatnot. You know, having this unique enterprise specific data kind of adding context to inputs and outputs, you know, leads to more efficiency. You know, another big thing and, and a big issue that legal departments are, you know, obviously thinking about is that having this data input into the tool, you know, one of the problems is that you're worried that it can, you know, train the underlying models. With Copilot, you know, that's not happening, you know, the instance of the LLM in which the tool is relying on is within your surface boundary. And so, you know, that kind of gives protections that you wouldn't necessarily have when you know, people are kind of just using these publicly available tools and So, you know, that's, I think that the big differentiating factor with Copilot as opposed to, you know, GPT-4,  ChatGPT and, you know, kind of these other public tools. 

    Anthony: And I think that's critical and John, obviously I'll let you sort of expand on that too, but I do think that's a critical piece because I know a lot of people are uncomfortable using these large language models, like you said, they're public. The way Microsoft built this product is you get your, in essence your own version. So if you get a license, you're getting your own version of it and it's inside your tenant. So it doesn't go outside sort of your firewalls, not technically a firewall, but it's in your tenant. Um And I think that's critical and I think that gives a lot of people comfort. Um And at least that's what Microsoft is saying. 

    John: Yeah, just a, just a couple of things to point out is some folks might be familiar with or heard about that their Microsoft has this responsible AI framework where if you are using Azure Open AI tools and you're building your own custom uh ChatGPT but using the Microsoft or the Azure Open AI version of ChatGPT, this responsible AI framework. There is, Microsoft is actually retaining prompts and responses and a human being is monitoring those prompts and responses. But that's in the context of a custom development that an organization might do. Copilot for M365 actually opted out of that. And so to Karim and Anthony's point, Microsoft's not retaining the prompts for Copilot, the responses, they're not using the data to retrain the model. So there's that whole thing. The second thing I just want to point out is that you do have the ability with Copilot from 365 to have plugins and one of the plugins is that when you're chatting in Microsoft teams using the chat application, you have the option to actually send prompts out to the internet to further ground. Karim talked about grounding information in your organization's data. So there are some considerations around configuration. Do you want to allow that to happen? You know, there's still data protection there. But those are a couple of things that come to mind on this topic. 

    Anthony: Yeah, and look, and I think this is critical and I, I agree with you. I think that's one of the, there is a lot of, I don't say dangers, but there's a lot of risks associated with Copilot. And I think as you said, you really have to go through the settings to make sure that is one that I think we've been advising clients at least to turn off for now just because, and, and just to give, we give clarity here, I think we, we're talking about prompts and responses. A prompt is in essence, a, a question, right? It could be summarized the document or you can type in, you know, give me a recipe for blueberry muffins, right? You can type anything. It's a question through Copilot. So it's an app, you make that question. When we talk about grounding, right? I think this is an important concept for people to understand when you're grounding on a document. So for example, if you want to summarize a a document, right? We have a or a transcript of a meeting, right? Like OK, I want to summarize it. My understanding of the way it works is when you press summarize a document, what you're really doing is telling the tool to look at the document, use the language in that document to create, I'll call it a better prompt or question that has more context. Then that goes to the large language model which is again inside the tenant and then that will basically give you an answer. But it's really just saying the answer is this is the likely next word is the best way to describe it. It's about probability and the like so it doesn't know anything. It is just when you're grounding it in a document or your own enterprise data, all you're doing is basically asking better questions of this large language model. That's my understanding of it. I know people have different types of descriptions, but that's the way I think the best way to think about it. Um And then and again, this is where we start talking about confidentiality. Like why people are a little concerned about it going public, you know, to the public part is that those questions, right are gonna take potentially confidential information, whatever and send it to this outside model if it wasn't Copilot, be out there. And this is true with a lot of a a tools and you may not have control like John that of who's looking at it. Are they storing it there? How long? And they're storing it? You know, is it, is it secure all that stuff? That's the type of stuff that we normally worry about. However, here, because the way Copilot is, you know, built, some of those concerns are are less. Although as you pointed out John, there are features that you can go to the internet which could cause those same concerns any other flavor, Karim or John that you want to give again. That's my description of how it works. 

    John: But yeah, no, the thing I was gonna say, no, I think you gave a great description of the grounding. Um Karim had brought up the the graph. So the graph is something which is underlies your Microsoft 365 tenant. And Karim alluded to this earlier and essentially when the business people in your organization are communicating back and forth, sharing documents as links, they're chatting in Microsoft teams sending emails. This graph is a database that essentially collects all of that activity, you know, it, it knows that you're sharing documents with. So and so and that becomes one of the ways that Microsoft surfaces information for the grounding that Anthony alluded to. So how does it, how does Copilot know to look at a particular document or know that a document exists on a particular topic about blueberry muffins or whatever, you know, in part that's based on the graph and that's something that can scare a lot of people because it it tends to show that documents are being overshared or people are sharing information in a way that they shouldn't be. So that's another issue. I think Anthony, Karim that we're seeing people talk about. 

    Anthony: Yeah. And that is that is a key point. I mean, the way that Microsoft explains it is copilot is very individualistic, I'll say so if it's it's based and when you're talking about all the information could be grounded and it's based on the information that someone has access to. And this is, and I think John, this is the point you were saying as we start going through these risk, one of the big challenges, I think a lot of organizations are now seeing is Copilot’s exposing, as you noted, bad access controls is the best way to describe it, right? Like in a lot of people M365 there's not a focus on it. So because people may have more access than they need when you're using Copilot it really does expose that. I think that's probably one of the biggest risks that we're seeing and big, the biggest challenges um that we're talking to our clients about because, because it, it is limited to the access that the person has. There's a presumption that that person only has access to what they should have. And I think we all know now that's not the case. Um And I think that's one of the big dangers and we'll talk about this and she episodes about how do you deal with that specific risk. Um But again, I think as we talked about it, that is one of the big risks that legal departments have to think about is, you know, you should be talking to your IT folks and saying what access controls do we have in place. And the like, because that is one of the big issues that um people have so to give you, you know, highlight it, you have highly confidential information within your organization. You know, if people are using Copilot, that could be a bad thing because suddenly they can ask questions and get answers based on highly confidential information that they shouldn't be getting. So it, it is one of the, the big challenge that we have. One thing I want to talk about, Karim, before we get into a little bit more on the risks is sort of the product level differences. And we talk about copilot as if it's one product, but I think as we've heard and seen there's sort of different flavors, I guess of Copilot. 

    Karim: Sure. Uh Yeah, so as Anthony noted, um, you know, Copilot is an embedded tool within the, you know, 365 suite. And so, you know, you're gonna have Copilot for word Copilot for Powerpoint. And so there are different, you know, tools and, and there's different functionality within, you know, whatever product you're working within. And that of course, is going to affect, you know, one the artifacts that are created uh some of the prompts that you're able to use and leverage. And so it's not as simple as just thinking as Copilot as this unified, you know, product because there are going to be different configurations. And I'm sure Anthony will, will speak to this, you know, we've kind of noted that even some of the configurations around where these things are stored, you know, there are certain gaps depending on whether you're using Outlook for example. And so, you know, you really have to dig into these product specific configurations because it, you know, the risks do vary. And just to, to kind of add and uh John kind of point to this, there is, you know, one version of Copilot, which is 365 Chat I believe is what it's called. And that is the probably the most efficient uh from a product perspective because it can leverage data across the user um you know, personal graph. And so again, bigger risks may be there than if you were looking at just kind of Excel. So, you know, definitely product specific functionalities change. And so food for thought on that point. 

    Anthony: And John, I don't know if you've done lighthouse has done testing on each of these different applications, but what we've seen our clients do is actually test each application, you know, so we have Copilot for word Copilot for Excel. Copilot for teams and stuff because as Karim said, we have seen issues with each, I don't know if you've seen anything specific that you want to raise. 

    John: Yeah, well, I think you guys bring up some really good points. I think um the like for example, Outlook, the prompts actually don't get captured as, as an artifact versus in Word and Excel and Powerpoint. But then we're also seeing some interesting things in our testing. So we're, we're ongoing, we're doing ongoing testing. But when it comes to meeting summaries and the difference between recapping a meeting that only has a transcript versus a meeting that has a full recording and the artifacts that get generated between the different types of meeting summaries, whether it's a recap or a full what they call AI notes. So that we're seeing some, some, some the meeting recaps aren't being captured 100% verbatim. So there's a lot of variability there. I think the key thing is that you pointed out, Anthony is you got to do testing, you've got to test, you've got to get comfortable that, you know, what artifacts are being generated and, and where they stored and whether you can preserve, collect all of those things. 

    Anthony: Yeah. And, and I think one of the things that um I'm gonna talk a little bit about this generally and John, I'm sure you're saying the same thing is prompts and responses, or at least Microsoft is saying prompts and responses are generally stored in all these applications in a hidden folder in your um in a person's outlook, right? So their their mailbox, as we noted and Karim noted for whatever reason, outlooks prompts and responses aren't being saved there. Although I'm told that that fix is coming in may have been even this week so that there was a gap, obviously, it came out in November. So there's still gaps and I think, you know, as is true, everyone's doing testing, John's doing like Lighthouse is doing testing. I'm sure you're talking to Microsoft note these gaps, they're filling in the gaps. So it is a new product. So that's one of the risks that everyone has to deal with is if anybody telling you this is the way it works may not be absolutely correct because you have to test and certainly you can't really rely on the the documentation that Microsoft has because they're improving the product probably faster than their updating their documentation. So that's another challenge that we've seen. So, test, test test is really important. Um So I just think some things to think about. Okay, we're almost out of time. So we're getting too much in the risk. But I think we've already talked about at a high level, some of the risks as we've talked about, there's the confidentiality and access issues that you should be thinking about retention and over retention we'll get into later. But there is obviously a risk. A lot of litigation teams are saying I don't want to keep this around. People are asking these questions, getting responses, they not be accurate. From a litigation perspective, they don't want it around. There's not business case for it, business use for it. Um because usually when you're doing this and like, you know, you're asking to help draft an email or whatever, you're probably doing something with that data, even meeting transcripts. If you get, you know, a recap, some people are copying and pasting it somewhere just to keep it. But generally the idea is the the output of Copilot is usually sort of short term. So that's generally been the approach I think most people are taking um and to get rid of it, but it's not easy to do because it's Microsoft. And so that's, that's one of the risks. And I think as we talked about, there's going to be the discovery risks, John, right? Like we're talking about, can we preserve it. There may be instances you can or can't. And that's where the outlook thing becomes an issue. As I think Karim noted hallucinations or accuracy is a huge risk. It should be better. Right. As I think Karim said, because it's grounded in your data, it should be better than just sort of general. Um, but there's still risks, right and there's a reputational risk associated with it if, if someone's relying on a summary of a meeting and they don't look at it carefully, that's obviously gonna be a risk, particularly if they circulate that this was said. So a lot of things to think about. At a high level, you know, Karim and John, let, let's conclude, what are one of the risks that you're seeing that? Do you think legal department should be thinking about other than what I just said? 

    John: Yeah. Well, I think that um one of the things that legal departments seem to be struggling with, I'm sure you guys are hearing this, is that what about the content itself being tagged or labeled as created by generative AI? There, there's actually some areas in M365 like meeting summaries will say generated by AI. But then there's other areas like a word document was completely, you know, the person creates a document. They do, they do a very light touch review of it. The documents essentially 99% generative AI, you know, a lot of companies are asking, well, can we get metadata or some kind of way to mark something is having been created by? So that's one of the things that in addition to all the issues that you highlighted Anthony that we're hearing companies bring up. 

    Anthony: Yeah, Karim, anything anything else from, from your perspective? 

    Karim: Sure. Yeah, I think one big issue that, you know, and I'm sure we'll talk about this in future uh episodes is, you know, with this kind of emergence of, you know, this AI functionality, there's a tendency on behalf of users, you know, to, to heavily rely on the outputs. And I know a lot of people kind of talk about human in the loop. And so, you know, I heard somebody say, uh you know, these are called Copilots for a reason and not autopilot. And so the training aspect, you know, really needs to be ingrained because when people do sit and rely on these outputs as if they're, you know, foolproof, you know, you can run into operational reputational, um you know, risks. And so I think that's, that's one thing we're seeing that, you know, the training is going to, you know, be integral. 

    Anthony: Yeah, and I think the other thing that I'll finalize this just to think about and this is really important for legal departments, think about privilege, right? If you're using Copilot for and it's using privileged information, I know I've heard a number of GCs say my biggest concern is waiver of privilege because you may not know that you're using Copilot against privileged information. That's summarizing an answer which is basically privilege, but you don't know it and then it circulated broadly and stuff. So again, there's a lot to consider, I think as we've talked about, it's really about training and access controls and really understanding the issues. And like I said, in future episodes, uh with Lighthouse, we'll be talking about some of the risks more specifically and then what can you do to mitigate those risks? Because I think that's really what this is gonna be about is mitigating risks and understand the issues. So well thanks to John and Karim. I hope this was helpful. Like I said, we'll have future podcasts, but thanks everyone for joining and hopefully we'll listen soon. 

    Outro: Tech Law Talks is a Reed Smith production. Our producers are Ali McCardell and Shannon Ryan. For more information about Reed Smith's Emerging Technologies practice, please email [email protected]. You can find our podcast on Spotify, Apple Podcasts, Google podcasts, reedsmith.com, and our social media accounts. 

    Disclaimer: This podcast is provided for educational purposes. It does not constitute legal advice and is not intended to establish an attorney-client relationship, nor is it intended to suggest or establish standards of care applicable to particular lawyers in any given situation. Prior results do not guarantee a similar outcome. Any views, opinions, or comments made by any external guest speaker are not to be attributed to Reed Smith LLP or its individual lawyers. 

    All rights reserved.

    Transcript is auto-generated.

    23 min
  • EU update: Data processing agreements for cloud services

    Partners Andy Splittgerber, and Christian Leuthner shed light on recent developments in the use of cloud services and EU data protection issues. This includes a summary of and comments on recent publications by the DSK (the German data protection authorities) as well as recent perspectives on data processors’ reuse of data. Andy and Christian conclude by giving some practical tips for both providers and customers.

    18 min
  • Tokenization Nation: Putting real-world assets on the blockchain

    2023 has been the year for the tokenization of real-world assets. The theme has been all-pervasive, with businesses across the world seeking to tokenize a whole spectrum of assets ranging from real estate to music, film, art, loans, invoices and credit. In this episode, Reed Smith’s Hagen Rooke (Singapore) and Soham Panchamiya (Dubai) are joined by Wayne Tan, general counsel at OpenEden, a platform that has become known for pioneering the tokenization of Treasury Bills. The conversation seeks to unpack the concept of tokenization and growing interest in this area, surveys some of the key activities in the real-world assets space, and contemplates the attendant legal and regulatory challenges.

    This episode was recorded on 23 October 2023.

    37 min
  • Artificial intelligence for legal departments

    Anthony Diana joins Daniel Broderick, co-founder and CEO of BlackBoiler, to discuss how AI is already being used by legal departments to manage contracts, the requirements for making the use of AI for contract management, and how future developments in AI will impact contract management.

    23 min
  • Leveling up legally: Regulating Web3 gaming

    Does your game have a token and an NFT marketplace? What about a DAO for your hard-core players? It doesn’t matter if you’re AAA or casual mobile gaming – a token component or staking functionality is likely to involve regulation of some sort. Join Reed Smith’s Hagen Rooke (Singapore) and Soham Panchamiya (Dubai) and Victoria Wells, general counsel of Illuvium DAO (Australia’s largest Web3 gaming DAO), to understand what the regulations say about gaming, play-to-earn, NFT marketplaces, and some unrelated musings we’ve managed to pack into this podcast.

    Link referenced at 28:30 can be found at polygon.com.

    This episode was recorded on 23 October 2023.

    43 min
  • Coin control: Understanding stablecoin regulations

    Reed Smith’s Hagen Rooke (Singapore) and Soham Panchamiya (Dubai) are joined by Samson Leo, co-founder and Chief Legal Officer of Fazz, to discuss stablecoin regulation in various jurisdictions, including Singapore and the UAE. How will these regulations affect stablecoin issuers and projects? What do they signal about the state of play for stablecoins in the future? Also, there is general debate around the regulatory framework affecting crypto in this increasingly maturing landscape.

    This episode was recorded on 9 October 2023.

    31 min

About Tech Law Talks

From the publisher's feed

Listen to Tech Law Talks for practical observations on technology and data legal trends, from product and technology development to operational and compliance issues that practitioners encounter every…

More shows like Tech Law Talks

On The Merits by Bloomberg Law

On The Merits

32 Listeners