Menu

Finding your edge: Leading with AI

Posted on 27 August 2026

Watching time 12 minutes
Read the full transcript

Ashley Williams, Partner, Head of the Technology Group

As soon as you as you start thinking about AI governance as a one key stakeholder problem, you’ve failed straight away.

Dan Sinclair, Partner, Strategy & Growth

Most people feel like their AI programmes are visible but not necessarily valuable.

Nina O’Sullivan, Client Engagement Partner

Hesitation without a plan that’s where it becomes problematic.

WHAT QUESTIONS SHOULD EVERY BOARD BE ASKING ABOUT AI?

Dan Sinclair, Partner, Strategy & Growth

So AI is now everywhere, it’s ubiquitous certainly in everyone’s personal life. What are the key questions the board should be considering when thinking about incorporating AI into their organisations?

Ashley Williams, Partner, Head of the Technology Group

The first main question is, what is the problem we’re trying to solve and then part 2 of that is, is AI the right answer to solving that question. I think quite often we jump straight away to solving a problem that might be a nice to have not a must have and we need to maintain that distinction at the beginning. So that would be my first one. I mean the second question I would ask is then, what are the risks of implementing AI but also equally as important, what are the risks of not implementing AI. And I think lastly maybe which specific AI solution is right for our business and that’s probably the hardest question for a lot of corporations because there are so many AI companies offering a lot of things at the moment. Do we need a tool that is a Swiss army knife, everything for everyone. Or do we have a problem which is a bit more bespoke and more specific that we can get a bit more of a bespoke AI solution for that piece.

Nina O’Sullivan, Client Engagement Partner

Is AI governance falling into a gap, so a gap between legal, IT and the C Suite and if it is, what should we do about it?

Ashley Williams, Partner, Head of the Technology Group

I think as soon as you start thinking about AI governance as a one key stakeholder problem, you’ve failed straight away. For me an AI governance framework is successful if it does 2 things. One, if it brings everyone in the organisation along for the journey and then the other is most importantly, it helps people make decisions and go no go decisions confidently and quickly.

WHAT SHOULD BE IN AN AI VENDOR CONTRACT THAT MOST COMPANIES OVERLOOK?

Ashley Williams, Partner, Head of the Technology Group

I think maybe the top one that we still see a lot of contracts be silent on is the use of customer data. So what can AI vendors use my data for? The key to me is contractually what are we saying the vendor can do with our data and that probably is the one that I think is still dealt with quite badly in vendor contracts. Before you even get into the contract piece, do you as a lawyer understand what the use case is for this AI solution you’re buying because if we don’t know what that use case is, we don’t understand our risk and we don’t know what additional terms we should be putting in that AI vendor contract.

Nina O’Sullivan, Client Engagement Partner

Yeah I mean I think the challenge often isn’t it is that there is this commercial imperative to move fast and so that means that sometimes you don’t interrogate the vendor terms with perhaps the same level of assessment that perhaps you might do otherwise. I think it is worth spending time on those provisions around data use restrictions, um, indemnities, intellectual property ownership because those are the provisions that you are going to be looking at if there is a problem and you need to work out where the liability sits.

Ashley Williams, Partner, Head of the Technology Group

Yeah.

WHEN AI ACTS OUT, WHO IS RESPONSIBLE?

Dan Sinclair, Partner, Strategy & Growth

I’m curious how this all changes in the agentic era. I think I read that 79% of UK CEO’s are concerned about risk exposure liability as a result of use of agents within their organisations. If you are talking to the GC or you are the GC, what are the key things you should be flagging as we head into this agentic era.

Nina O’Sullivan, Client Engagement Partner

Liability for agentic decisions and transactions is an emerging area and I do think it is one where our laws are going to be tested sooner rather than later. I think the starting point is that we do have a framework of very flexible, very adaptable laws that can meet technological developments and we’ve seen that throughout history. Contractual allocation of responsibility, negligence liability, product liability, availability of insurance. But having said that and having said that those laws were still created and developed in an era when you had a human that was making the decision that ultimately had the responsibility. When you have an agent that is, um, negotiating or entering into transactions, taking decisions, making hiring decisions, that changes the dynamic entirely and it gets even more complicated when you start thinking about multiple agents. And that raises I guess really quite difficult evidential questions. What has happened? Why has it happened? How has it gone wrong? Who is responsible? And I think until we get the Courts and given their views on some of these issues, it’s going to be really quite difficult for businesses to assess what the risk appetite is but what they do need to do is think about well where does our deployment sit on that spectrum because the risks involved in getting AI to create a document that a human is going to review is very different to the risk profile of an AI agent executing a transaction on the company’s behalf.

Dan Sinclair, Partner, Strategy & Growth

So there are still some guard rails, this isn’t a hall pass moment where everyone can do what they want in, in terms of their agents until the Courts figure themselves out?

Nina O’Sullivan, Client Engagement Partner

No and we, the UK Jurisdiction Task Force produced a paper in which they said, look yes we think that existing laws are sufficiently flexible to adapt to these questions. It is going to be the usual questions that we as lawyers know and understand and apply but even in that paper, there was a recognition that as these tools become more autonomous that is going to make the assessment more complex.

Ashley Williams, Partner, Head of the Technology Group

That’s 2 areas that I see of risk here. One is, internals, so we say it’s only going to do these decisions but actually we get further and further away from what we originally approved and then the second is a technical one which is, we’ve already seen high profile examples of where the AI agent is a law to its own.

Nina O’Sullivan, Client Engagement Partner

Yes.

Ashley Williams, Partner, Head of the Technology Group

And it’s been outside the guard rails. So for me those are the 2 areas the scope creep and AI agentic autonomy going beyond the guard rails.

Nina O’Sullivan, Client Engagement Partner

Yes. And it’s working out where the liability responsibility for that sits because is the problem in the model? Is it in the way it’s been implemented in the system? Is it the way it’s been used by the deployer? And it’s working out where that has happened in terms of where the ultimate allocation of responsibility might sit.

HOW ARE ORGANISATIONS MOVING FROM AI PROMISE TO IMPACT?

Dan Sinclair, Partner, Strategy & Growth

I think most people feel like their AI programmes are visible but not necessarily valuable. Enterprises have rightly been focussed on experimenting first to learn more about the technology, to learn more about the potential application but then I think people feel or sometimes run the risk of thinking that the job is done. I think the breakaway organisations are one that manage their AI programmes like they do any other capital investment and so it really starts with the strategy around what they are trying to achieve with the use of AI for the business perspective. I think the second thing is then having really clear KPI’s which are well articulated and well communicated to the business in terms of what the AI programme is looking to achieve. And then that third thing is that ongoing active management. So regular check-ins, how are we tracking against each of those KPI’s? What do we need to be escalating and having that really senior buy-in effectively throughout the programme to make sure that it is something the business is taking seriously. I think those are the characteristics that you’re seeing from the organisations that are really kind of moving faster.

WHAT ARE THE HIDDEN PITFALLS THAT PREVENT PROGRESS?

Ashley Williams, Partner, Head of the Technology Group

At the beginning the likelihood is you’re going to need more effort to get the benefit of the AI solution. Quite often when I go in to do a digital transformation, AI transformation project the first piece that large corporates actually struggle with is data, data, like how do we get data in a format that can actually be digested to make the most of this AI solution? And to some extent that is process manual part that you just have to get over before you start reaping the benefits of the AI solution that you actually want.

WHAT’S REALLY STOPPING ORGANISATIONS FROM GETTING AI RIGHT?

Dan Sinclair, Partner, Strategy & Growth

I think there are 3 really key areas. The first is strategically. Being upfront, here’s the strategy, here’s what we’re trying to achieve across the organisation and why. The second is around tech and products. AI is not something that can be outsourced and it will require ongoing senior kind of input, leadership, steering through both business model pricing but also just technical product questions the organisation will face. And the third which I actually think is the most important and probably not spoken about, is on the people side. This is a changed management problem ultimately, not just a technology problem and I think senior leadership need to be there to bang the drum to empower their people and their workforce to really capitalise on the opportunity of AI.

Can we talk about decision paralysis a little bit. 51% of CEO’s have said that they are delaying rolling out their AI programmes because of risk and concerns about risk. What better kind of waiting or acting, what’s, you know, what’s the cost of action versus inaction and waiting for everything to sort itself out?

Nina O’Sullivan, Client Engagement Partner

Hesitation in the face of regulatory uncertainty, that’s understandable. There has to be an element of caution but hesitation without a plan, um, that’s where it becomes problematic and if you hesitate and by that you don’t take any action, what that can lead to is that your competitors are going to gain advantage over you. If you go to the other extreme of moving too fast, that can also present problems. That could be a failed deployment, it could be that you sign contracts too quickly without proper review of the terms and all of that can lead to reputational risk. I think the thing to do is to recognise that there is regulatory uncertainty and think about how you are adapting and deploying your framework, your governance framework in the face of that uncertainty. UNESCO has recently published a report in which they say that globally there are 9 emerging different types of regulatory approach to AI. I think actually I think the figure may be a bit lower than that.

Ashley Williams, Partner, Head of the Technology Group

I think 9 is too many. If it was me I would bucketise them into 3. One I think is an unregulated approach. Let AI go and let’s see what happens and we may regulate in the future. The second approach is a principles base approach accepting that if we try and do rules they are going to be outstripped by technology very quickly.

Nina O’Sullivan, Client Engagement Partner

Is that the UK current approach currently?

Ashley Williams, Partner, Head of the Technology Group

That’s the UK currently. Yeah we’re sat in that bucket. And then the third is that we think a rules based approach will provide the right level of safety for the deployment of AI and that is unapologetically the EU right now. And perhaps maybe, not quite as far as unregulated but we could probably put the US more so on the left side of that line. The executive orders under the Trump Administration is clear that there will be no regulatory hurdles for AI advancements. So when you know what that looks like you kind of know where you’re high water mark is. I typically tell clients that if you’re compliant with this high water mark threshold the EU had, you get a kind of 80-20% passport in effect into other countries which means that if I know that I’m compliant with this level, when I move across different countries my level of compliance is going to be pretty good.

Nina O’Sullivan, Client Engagement Partner

But also you can adapt so even though you have that as your baseline for the programme and the framework that you have in place. If it’s not relevant in particular if you’re in the US for example, you can adapt the processes so that you are not necessarily complying to that particular EU standard.

Ashley Williams, Partner, Head of the Technology Group

Yeah and for some companies that is how they are thinking about it. I think once you’ve got to that level though, interestingly and this is what we saw with GDPR, is people kind of just passport that level across and that is absolutely what the EU wants.

Nina O’Sullivan, Client Engagement Partner

I guess the story doesn’t end with the fine but it’s the other stuff as well. If there is a breach it’s thinking about the impact on trust and your relationships and that can last a lot longer than the financial consequences of the heavy fine.

MISHCON DE REYA

In this conversation, Mishcon de Reya experts explore how businesses can move from AI experimentation to strategic, value-driven deployment. They examine the key questions boards and leadership teams should be asking, from governance and vendor contracts to risk appetite, accountability and change management. 

The discussion covers: 

  • Identifying the right AI use cases and business problems to solve 
  • Building governance frameworks that bring legal, IT and the C-suite together 
  • Reviewing AI vendor contracts, data use, indemnities and IP ownership 
  • Understanding liability and responsibility in the agentic AI era 
  • Turning visible AI programmes into valuable, measurable business investments 
  • Balancing speed, risk and regulatory uncertainty without falling into decision paralysis 

With practical insight into governance, regulation and implementation, the speakers highlight why AI success depends on more than adopting new tools. From clear strategy and senior leadership to robust controls and prepared data, this video offers guidance for organisations looking to harness AI responsibly while protecting their position. 

Featuring Ashley Williams (Partner, Head of the Technology Group), Dan Sinclair (Partner, Strategy & Growth) and Nina O’Sullivan (Client Engagement Partner). 

To learn more, read our supporting article, From AI ambition to accountability: five priorities for boards and leadership teams or visit our AI resource centre. You can also explore our Corporates hub, offering more insights for multinational organisations.

How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

Crisis Hotline

I'm a client

I'm looking for advice

Something else