AI's Effect on Legal Governance
From Simple's AI for Family Offices Gathering in Copenhagen May 2026
Rene Thornfeldt, who works at the intersection of law and technology, joins Simple's head of research for a fireside conversation on AI and legal liability. They examine where defects in AI systems create structural exposure, why high-frequency uses such as banking chatbots concentrate risk, and what that means for governance.
Transcript
The next one is not going to disappoint you and it will also be moderated by uh our head of research who uh does a lot of work for us in for over many years and I think it's going to be very good conversation. So yeah, David and Rene Hi. Um, it's nice to be here. It's quite an honor and I've been with Simple for a number of years now and these environments are the reason why I continue to stay and and yeah, enjoy Simple so much. I'm going to introduce Rene.
Um, he's at Aura. He has a background in international business and law and he's worked in the intersection of law and IT for a number of years now. And so, please welcome Rene. So mic check. So I was just asked to to sort of set the scene before the the talk which is going to be a fireside going to be an interview rather than a presentation.
Speak up. Is this better? Yes. yeah. So the point is we'll go this a little bit interactive in the sense of we'll do an an interview based dialogue uh rather than a presentation.
Um but just setting the scene, my background obviously is uh is economics and law. Uh I've done this for 25 years. Um so I come from a law firm that does a large volume of M&A activities. Uh have has the largest transaction volume for 5 years in a row in the Nordics. Uh so that's the one leg and the other leg is the the ITO the IT and outsourcing.
Uh which is the practice that I had. Um that means we do most of the infrastructure deals for banks and pension funds uh large companies but also do a lot of for startups. Um so basically my angle in this is both that of understanding um uh the numbers if you will where's the value at uh but also where's the risk at. Uh so what I'll try to bring to the table obviously is some of the dos and don'ts from the deals that we see. Um it's AI so it's very much obviously focused on uh the angle of your perspective uh being company owners and investors uh what to look for uh in terms of where the value at and and and and what to avoid in terms of of risk that's basically setting the table.
So I'll try to bring in as much as I can a practical angle but al also obviously also bringing in uh the legal context. Yeah. Right. Thanks. Um so my first question is this.
It seems that many organizations treat AI tools as productivity software similar to document management and research. Um from a legal perspective, do you see any problems with this? Yeah. So so first of all that's a good question. Um uh obviously it's a it's a tool that drives tremendous uh value in terms of automation and in terms of value creation.
Uh but it's a little bit like looking at a fast car. Uh it's great if you're a good driver and it's a a terrible dangerous place to be if if you're not a good driver. Um and the risks that that associated with this particular tool is very much that of knowing the legal context of what it does. It's a tool. it automatically tends to drive over automation but the company you yourselves and as owners uh remain liable.
Um that's the one risk obviously knowing that risk and what it entails and then the other risk that we can talk about is very much that of retention of organizational knowledge. That's the value that's the asset if you will in any company. This tool can deteriorate that value or it can enhance the value. Uh that's the other risk. uh that we can talk about.
Yeah. Could you expand on that a little bit? of the legal risk, if you will, I think it's critical to to recognize that a lot of you are are following the AI act and and and and thinking that that probably is the uh the rules to know uh and be aware of. Uh obviously that is somehow uh true in the sense that that is a specific regulation. uh most of the regulation without going too much into it is very much about focusing on on legal risk management and most of the the really significant parts of that has not come into effect yet and in fact has just been uh uh delayed itself.
The significance uh that you need to be aware is that all the other rules already applies. That means in terms of uh GDPR, IPR, uh um all the other rules in terms of confidentiality, all those rules apply and and and and AI is basically just a tool. So you're liable as if carried out by yourself. So doing the automation that drives the activity here is on behalf of the company although driven by the AI and and that's the reality you need to be aware of. So so it's like fasttracking your legal exposure.
Uh so if you're not in control uh then obviously that's a dangerous thing and the fact that AI in itself is inherently driving automation what you want to avoid is over auto automation and thereby loss of control. So if you if you lose control on something that drives exponentially legal exposure then obviously it becomes a dangerous thing. Okay. I want to dig down on that a little bit. So if tools like Harvey and Lora sit on top of foundational models like cloud um does that mean the real legal power in legal AI is shifting from the specialized legal packages to the underlying AI infrastructure?
So that's a really interesting question and that's where you have to look into the crystal ball a little bit but but bear with me. The from my perspective the IT stack sort of have four layers if you will. you have the foundational basis, your large language models in in in the bottom. Those are substitutable. Uh changing from one to another doesn't take that long.
Uh as long as you agnostic in your tool choice, uh then you can choose between the two. That's the that's the basis. Then you have the legal tech uh uh on top. Um those obviously are are very much uh driving the activity these days because they are commoditizing the legal knowledge and thereby building concentration in in the market. Uh so it's a good investment opportunity obviously on top of that then you have the integration into sort of your your standard layers your office package and your will that needs to be kept separately and then you have the real asset on top and that's the driver for the second risk identified that's the making or breaking that's the company data layer that's where you take your organizational knowledge and keep that separable you do not put that into the other layers if you do that you either lose the data or it becomes commodity and thereby not worth anything because competition will have the same knowledge.
So keeping that layer separable is what's going to drive the value in the separate companies. So in terms of where's the value at obviously it will be everywhere. Uh the more we use our AI the foundational model obviously will continue to to to to rise in value. The integration layer obviously uh will drive a lot of value. Uh the concentration risk if you will is not being agnostic in your choices.
not being able to substitute uh if the value of one uh increases and changes over time if you lock yourself into that. So you don't are not able to do the substitution without losing the data that's really the the inherent danger here in the layering. Okay. Can you give me the specific examples of companies making mistakes um with compliance workflows? Yeah.
Yeah. So starting out in in some of the known cases obviously many of you will have seen um you can start by saying what is AI inherently at these at this stage really good at it's really good at driving out information of large pools of data they're really good at comparing data doing any sort of of illustration of data that's where the real strength is right now where they're not that strong right now is any kind of abstract conclusions that that is driving out conclusions based on non-definite data points. What that means is that any legal assessment is based on judgments on legal schooling that are non non-specific criteria. That's not where it's really good. So what does that mean?
That means your answer to your question in terms of where where we're seeing the risk right now in terms of legal and compliance sex, two things. Chat bots. Um, at a lot of companies that we work with, banks, pension funds, those kind of companies, they're using obviously uh the AI technology for chatbots. People don't want to talk to their uh salesman anymore. They want to do it themselves.
They want to be able to model right in the app itself, which is great and you and it's certainly driving down uh a lot of cost, driving user experiences up, but the risk there is that the chatbots um limitation is the categorization. So that basically means if it has to explain what yellow is or red is or blue is it's excellent. But if it has to make a depiction of whether it's one color or the other and it's an assessment that based on a categorization then we see a lot of defects. So where do we see a lot of these defects? Certainly in chatbots but it's not because of the use of chatbots uh itself.
It's because of this specific use. So it has to be tailored specifically to drive information but it has to not be judgmental in the sense that it's making decisions. That's one. Another place where we've seen it a lot and that has been in the media uh obviously is in litigation. We've seen all these cases itself hallucinations driven where it basically comes up with it its own references and own rules.
If it's not there it'll find it called hallucinations. Um obviously we saw the uh the deoid case uh in Australia example for that as well. Um so Deoid came up with this report to the Australian government. Um and they basically asked AI to do most of the report it turns out. Uh so the base conclusion in the report was based on a hallucination.
So the Australian government asked Deote to to fix the report and put in the right citations and they could do that. But since the base condition derived in the report was a hallucination that could not be found in the real world. So the result of the report was basically erroneous and could not be fixed and obviously now there's a liability case in Australia. So the point based on this as I said before is make sure that you have QA processes to verify not itself the data finding or the building of the report which is excellent no but the conclusions themselves the abstract assessments those are the ones you want to verify. Um so that's certainly where we are are seeing it in the media uh uh where the defects are made but where we see them every day is very much in these chatbots with the banks which what we call uh cyclical risks and concentration risks and and those are hyperfrequent so it means even small defects on a large scale obviously become structurally large exposures and thereby also large liabilities.
Okay. Yeah. you mentioned that um liability case but is is that a governance blind spot or is that is that something else? Good question. Yeah.
So again there are many many different paths here but we can we can try to break it down. Obviously what the AI act will will will will will will will will bring is a governance of how to work in managing risks because what's going to happen is you will the legal world will transcend from being people like me into very much being machine-driven to a large extent maybe 85% to be popular in the sense that knowing the rules and being a able to present those rules and use those rules will be driven by machines. That basically means that that many of of uh of the changes here will be administrating these kinds of systems rather than using transitional cases and then you will have strategic legal advice on top. So the assessments will be made by people. Everything else will be run by machines and and that is happening extremely fast.
Um I just come from a meeting I'm doing obviously these meetings uh with a with a high frequency uh but I'm I'm I'm amazed what these uh systems can do already. So, so, so that is not if that is a a guaranteed will happen. Uh, but it's also very very important to remember that the outcome of these systems, the decisions if you will, those will remain with the boards and and the CEO obviously on the one side and then the lawyers in terms of liability on the other side. And my point here being that we need to be able to uh recognize and work against the what we call the automation bias which is a human psychology tendency to rely and trust machines over human judgments. So here's a contradiction of terms because if the machines cannot do the assessment that people can do then we need to be aware what which is which.
So we need to be able to have these support board decisions, CEO decisions, legal decisions. um but certainly not make them them ourselves. And the bias here is they're able to do this themselves and we cannot see what it's based on. So if we have this bias, we do not recognize the fact that it's not really good at this part since it's so dramatically good at the other parts. And that is an inherent danger for anybody making a decision.
So So how do we work with this? We work with them in terms of building up data tracing any decision. Where does the the information come from? What's the source? document the source.
If we're building something new, if we're making new decision process, where did this come from? Who made this idea? How do we trace the data so we can go back for litigation purposes and uh compliance purposes? You need to be able to trace your decisions and document your decisions. That's one um that's in the act itself.
We need to teach our people. So, we build this organizational knowledge. That's a requirement in the AI act. And then we obviously need to have liability with the people making the decisions, incentivizing them to do the right thing. And that's what the AI act does as well.
So we basically just need to read the rules, understand that this is about risk management. It is not about knowing because there is no traceability in an AI. So it's about verifying your process of making decisions being able to trace back if errors are made because the AI itself does not allow for that. All right. If I can ask you a question.
what um what's the most common misunderstanding organizations have today about legal responsibility when using AI tools? Yeah. So, so the first one is that we just wait for the AI act. Uh and then until then we sort of have a freeze trial if you will. That's not the case.
So, so, so obviously today even a lot of the the actual applications that we see are in areas like HR. Um HR is what we call the critical area. That's where the AI act not has not come into to to uh to to to to effect yet. But that's where fines will be up to 7% of the global turnover. So obviously this is real money.
It's something that the companies be will become increasingly aware of. Um you have GDPR itself carrying up to 4% of global turnover. Uh so every time we use personal data um it's basically in a GDPR context a processing. So while the uh you may not be doing it or the organization may not be doing the process, the AI is doing the process. And in terms of the law, it does not distinguish between one or the other.
Uh so you need to see the AI as an email. It's basically just a tool. Uh so if you're not accountable for the use of data, uh the information obligations, uh the capability to take out my data, withdrawal, consents, things like that, then obviously those will be breach of a of of of a of a of GDPR. And if you do that in a high frequency and AI automatically entails that, then you're in the higher end of the uh of the fines. So, so that's just GDPR, but it also means anything like a breach of confidentiality clauses.
If you put your contracts in there, obviously it's for a different purpose. It's been shared for a different purpose. Obviously, that will be breach of contract. Um things like uh marketing purposes, um anything like that, that applies today. uh IPR infringements uh obviously information that that you get from from contextual and that's the whole purpose of the AI right is gathering all this information making use in a new context driving an asset that wasn't there before but all of that unless you extract the data and do it right all constituting breach of contracts of employee relations of GDPR and things like that so you basically just fasttrack legal exposure for family offices and investors um looking at this as a as a potential investing space.
What's the real strategic value likely to sit specialized legal AI companies underlying AI infrastructure that a lot of the other speakers have talked about today? Yeah. So, so let me try. Obviously the underlying infrastructure is there to stay and uh and since the application is is being driven then all the uh all the underlying uh uh data centers infrastructure investments those will be good safe uh investments but those are also highly commoditized. Um so if you want to something interesting then obviously you need to go up in this in the layer.
I normally sort of compare this with what happened in the mobile industry. You have the iOS in the bottom, but that's not really driving the the value. The the apps are the equivalent to the apps here would be your legal tech. It would be all sorts of uh specific applications uh specific in there. Those obviously would be the value drivers, but that's also where you risk not making any investment at all.
Obviously, there's a parody there in terms of risk and and and payoff. But the real value and point here in terms of of of looking at value, that's what I do for a living, is looking into organizations and making sure that they're the ones being aware from a risk perspective and procedural uh aspect that they're driving the value in their separate data layer. So everything over time will become a commodity in terms of of legal all the apps if you will of of of this world will be commodity. The only thing that will not be commodity is the separate data layer in the separate company. So whatever make them unique and thereby also drives the value.
If they are good at investing in that they will be able to reduce employees and thereby their relative cost of the asset and thereby increasing the value of the asset. So that's one thing. Are they working actively to drive that value? And the other side of that is are they by way of of making sure there's no shadow numbers with employees using AI, private AIS, and thereby taking uh data from the the company's specific layer into non-proprietary data layers or for instance having leaks or anything like that. Are they deteriorating the value of the organizational knowledge in the companies?
So are they driving that value and are they protecting that value for any due diligence we'll do in the future in terms of of AI and that will be mostly any company that is a key thing to look at whether you're looking at the value of a of a startup or whether you're looking at the value of a bank absolutely the same thing I have one last question for you look a few years ahead what's generally going to be changed by legal governance of AI with AI and what's what's going to be the So what's definitely going to be a change is we're going to see a lot of turn in the legal industry for sure. So so the challenge that we're seeing and and I come from a law firm with 650 people obviously I learned what I know today by starting off on the on the base floor doing simple things. All of that will not be there for the future generations. So how's that going to change things? It's certainly going to reduce the concentration of knowledge.
It's going to commoditize a lot of jobs. Uh so that's going to change. um then you will have certain people that are able to do this assessment on top that the AI will ultimately never in my view be the best at and and and those individual will be you know highly valuable in in a society like that obviously um uh so so those are the changes in terms of what will change in the law we will see we will go from have in my view now we in the in the far future obviously uh we won't have the same kind of litigation all of that will be done by machines uh all assessments chat bots, anything like that will be 85% automated. Um, so so so fewer people will be doing a lot more and a lot of what all the companies are doing today and the value of that will be commoditized. Um, that's the future we're looking into and it's it's it's exciting, but it's also really scary.
Well, um, join me in thanking Rene for the insight.
