Ted Theodoropoulos

Writing an AI policy is the easiest part of AI governance.

It's also the least important.

Amy Swaner, JD AIGP wrote a solid piece on why every firm needs one. She's right.

But a document doesn't fix the problems she describes. Process and infrastructure do.

If your DMS has 17 iterations of an unexecuted SPA and no data hygiene, your AI policy won't save you from hallucinated outputs.

If your integration layer can't enforce access controls at the data level, your confidentiality provisions are aspirational.

The policy is the starting line, not the finish line.

Most firms treat governance like a compliance checkbox. Write a document, circulate it, file it. Done.

That's theater.

Real governance requires infrastructure. Clean data. Security-trimmed access. A stack that makes it difficult to use data incorrectly.

Real governance requires culture. Embedded accountability. Champions who model the behavior daily.

Swaner nails it when she recommends "champions, not mandates." Adoption is a culture problem, not a document problem.

Process before technology. Infrastructure before policy. Culture before compliance.

If you're starting and ending with the document, you're very unlikely to be successful.

Image from the original LinkedIn post

First published on LinkedIn. Read the thread and replies.

Ted Theodoropoulos is CEO and co-founder of Infodash and hosts the Legal Innovation Spotlight podcast. He writes about legal AI strategy, law firm technology, and the economics of the law firm business model.