Go Back
On-demand

Data Management for eDiscovery and Regulatory Compliance in 2023: Everything You Need to Know

In the rapidly evolving landscape of data management, industry names are changing but the keys to success remain the same: You need to know where your data is and how it’s being maintained.

Whether working in a legal or compliance department, you need to know how data management, eDiscovery, and digital communications compliance all intersect.

In this webinar, our experts discuss the latest Gartner report, strategic technologies, and best practices that organizations must embrace to navigate the challenges of data retention, legal discovery, and regulatory compliance challenges. 

Legal expert, Ari Kaplan, will lead our panel of experts including Anthony Diana, Reed Smith, along with Courtney Kern, KLDiscovery, and David Aaronson, Shield, in a discussion on 

  • Gartner’s introduction of the Digital Communications Governance category
  • eDiscovery essentials 
  • Data lifecycle management 
  • Technology adoption 

Speakers

Ari Kaplan

Legal Industry Analyst

Anthony Diana

Partner and Co-Chair of the IP, Tech & Data Practice Group, Reed Smith

Courtney Kern

Director of Compliance, Information Governance & Archiving Solutions, KLDiscovery

David Aaronson

Sr. Product Marketing, Shield

  • Transcript

    Data Management for eDiscovery and Regulatory Compliance in 2023: Everything You Need to Know

    A collaboration between KLDiscovery and Shield
    Speakers

    • Ari Kaplan, Legal Industry Analyst (Moderator)
    • Courtney Kern, Director of Compliance, Information Governance & Archiving Solutions, KLDiscovery
    • David Aaronson, Senior Product Marketing Manager, Shield
    • Anthony Diana, Partner and Co-Chair of the IP, Tech & Data Practice Group, Reed Smith

     

    Introduction and Research Data Points

    Ari:Welcome, everyone, to Data Management for eDiscovery and Regulatory Compliance in 2023: Everything You Need to Know, which is a collaboration between KLDiscovery and Shield. I’m Ari Kaplan, an analyst who covers the legal industry, and I’m honored to be joined today by Courtney Kern, the Director of Compliance, Information Governance and Archiving Solutions at KLDiscovery; David Aaronson, a Senior Product Marketing Manager at Shield; and Anthony Diana, a Partner and Co-Chair of the IP, Tech and Data Practice Group at Reed Smith. Courtney, David, Anthony — great to see you.
    As you all know, and as listeners may know, I’ve recently released the ninth edition of my eDiscovery Unfiltered report, and I want to set the framework for our discussion today with some data points. I interviewed thirty leaders who are making eDiscovery buying decisions across the corporate and law firm spectrum. I’ll share that 87% said they were using some form of artificial intelligence in their document review processes; 83% noted that the amount of data in a typical eDiscovery matter has increased over the past year; and 80% use analytics across the majority of their matters. Almost three-quarters have seen an increase in the workload for eDiscovery. And to give a sense of where they fall on a scale of one to ten, ten being the highest, 63% of in-house participants rate the level of difficulty of integrating their data from various sources into eDiscovery at a seven or above, and 71% of law firm participants rate it at a six or above. So there are lots of challenges here. When I talk about communication data types, it’s just overwhelming — the feeling is one of overwhelm. I see Anthony nodding. So let’s set a foundation for this discussion. Courtney, how should today’s listeners define digital communications?

    Defining Digital Communications

    Courtney:Very good question, Ari. Digital communications is very broad today, and it will continue to expand. Digital communications really is anything where you’re putting your thoughts into some kind of digital platform — whether that’s texting, any type of video content, anything that can be captured and used for collections and any type of litigation or compliance review. That needs to be deemed digital communication. The use of mobile devices is just expanding it, and it’ll continue to expand. So we need to be very aware of how we’re using these digital communication applications and platforms. Anything that can be captured can be deemed digital communications.
    Ari:Anthony, I’ve had the privilege of learning from you for many years and have seen you speak at various events. When I started researching for the eDiscovery Unfiltered report nine years ago, very few of these were issues. As professionals move away from email — which was the fundamental core of eDiscovery years ago — to more short-form, encrypted, or ephemeral messaging formats, what are the risk management and litigation implications?

    Moving Beyond Email: Risk and Litigation Implications

    Anthony:Ari, I’ll mention we’ve known each other probably for two decades. We started working together about nine years ago, but we’ve known each other a long time, so I appreciate that. The reality is, for almost twenty years, email was king. While everyone was communicating differently in their personal lives, business communications were really email. That has changed, and is changing tremendously, and there are lots of implications. We’ve seen all these large fines in the financial services world, and I know lots of clients even outside financial services look at those fines with trepidation, saying the DOJ or the SEC is going to come after me too. There may not be the same regulatory record-keeping requirements, but for certain types of litigation they know they’re going to be asked to produce text messaging, WhatsApp, WeChat, and the like. People have been using this for a while — it just hasn’t been front and center, but it has been used.
    The other thing to keep in mind — and I agree with Courtney — is that the decentralization of electronic communications has been wildly dramatic, particularly in the past two or three years. Part of it is everyone’s going to the cloud, and one of the reasons to go to the cloud is there’s always innovation. So a lot of even standard structured databases — a financial database, a trading database, a research database — now have chat components in them. As a litigator, you have to be aware of that. One of the challenges for every outside counsel, and in-house counsel too, is you can never say now, “I am preserving all communications for these custodians,” or “I am collecting all communications with these custodians,” because that’s not possible — there are just too many ways they’re communicating. It’s going to have to come back to relevance. It’s probably healthy for everybody, but we really have to start moving toward talking about what is relevant and what is really required. That’s hard, because the easiest way used to be, “Well, it’s email; I’m collecting email, I’m fine.” That’s not true anymore. It’s much more upfront thinking. Compliance has to think, “Do I really have to capture?” Litigators have to say, “What am I really preserving? What am I really collecting?” And it’s not objective criteria — it’s going to be somewhat subjective, which is what scares everyone.
    Ari:David, a key element of my research, especially this year but over the years, is this incredible trend of legal no longer being an isolated discipline — legal is now supplemented by compliance, records, information, and of course advanced technology. Where’s the intersection between compliance and communications?

    The Intersection of Compliance and Communications

    David:Both Courtney and Anthony spoke to where this starts at its most basic level. The way I like to tell it: if you asked me the same question a hundred years ago, I’d say we’re probably all looking at the same documents and letters, going downtown to some archive warehouse that doesn’t have any air conditioning, because no one had air conditioning back then. If you asked me ten years ago, the answer would probably be email. Now you have to consider emojis, personal communications like WhatsApp and SMS, complex data sources, massive volumes of data — and of course it’s just growing. So the intersection between compliance and communications has become much bigger and much more complicated. We’re talking about data volumes and complexities, use cases and analytics, reporting, search and collections, and surveillance work.
    A while ago, as Anthony said, different people were doing different things on different data, everyone in their own spots. Now the intersection is so big and complex that everyone has, or should have, a seat at the table in terms of understanding how we’re going to build a strategy on a united front. And the cloud is bringing innovation like never before, with modern platforms that cover these end-to-end use cases. This is where compliance and legal are really starting to see that we can shift from how we used to do things to a new way that isn’t just some middle ground we haven’t wanted to commit to — something that works more holistically, more completely.
    Ari:It’s funny, because when I picture the complexity, I imagine a random intersection — Madison and 34th or something — that’s turned into some crazy highway situation in Houston where the road leads to nine different places. That’s where we are with communications compliance. So Courtney, to spark a discussion on aligning these things: what are the challenges specifically that corporate leaders are facing with communications compliance at this stage?

    Policy vs. Strategy: Corporate Compliance Challenges

    Courtney:Companies are developing their policies, which are very good to have — it sets the framework for employees to follow. However, with mobile devices and communications, the challenge I’m seeing very regularly is that even when a company has a policy in place stating you’re allowed to use these business communication platforms, other platforms are being used. The biggest issue in terms of compliance is that even when a company has a policy — say, “You are not allowed to use WhatsApp; these are our business apps” — if they are aware that some employees or even contractors are using apps outside the policy, that company is still liable. Awareness is a key component in any type of compliance and any litigation arena. So when you have employees using their personal devices and apps outside that policy, you still have an accountability factor that companies are working hard to mitigate. That’s the biggest challenge I’m seeing repeatedly.
    Ari:Anthony, I’ve probably conducted four hundred interviews in the first three quarters of 2023, and Courtney’s point is so well taken. One of the issues with bring-your-own-device or using a personal device is that in a post-pandemic world, all these compliance issues are in so many different places. How do you see organizations, particularly highly regulated ones, maintaining and disposing of all these new forms of correspondence?
    Anthony:It’s a huge challenge, and it goes back to your point about who should be at the table. I agree with Courtney — a policy is helpful, but there needs to be a strategy: a technology strategy that’s communicated to employees. I hear this from IT professionals all the time: they don’t want to disrupt the business. The business is dictating it, because their clients are using a certain app. When the organization says you can’t use that app, that means “I can’t communicate with that client.” So there has to be some structure — whether it’s an approval structure, or something that really gets into “here’s our strategy, here’s what we want to use.” It’s not just having an approved app, but a process for approving apps. I’ve had situations where regulators are using a certain app. If you say you can’t use WhatsApp or WeChat, and then you find out that in China they only communicate with WeChat, you have to use WeChat. Then it becomes: do you make an exception to the policy? So it’s not as easy as saying “this is what we’re doing.” It’s the process that matters — what’s the approval process, who’s involved, and there are costs associated with it. Every time, particularly in highly regulated industries, when you approve an app and determine it has to be captured, there’s a cost: someone has to monitor it, you have to have auditing procedures. Regulators always say it’s not enough to have a policy — you have to enforce it, and that means some type of audit. That’s a huge amount of infrastructure, and I don’t think most organizations have that yet.
    And we’ve seen in some of the fines that oftentimes senior management are the violators. You can’t have a policy where senior management is the exception — it’s top-down. That’s one of the things the SEC, CFTC, and FINRA have always said: they want to see a culture of compliance, and that starts with senior executives actually following the policy. It’s also resources — a lot of resources need to be put in place to actually be compliant, because it’s not an easy undertaking. I have a client where we’ve gone through hundreds of applications in the past year and a half; there are thousands they have. They have an onboarding process where someone has to click a button and say, “Do I think this may have electronic communications?” and then an investigation happens. But that’s a lot of work.
    Ari:David, in many of my conversations that include the words audit, process, or implement, the word automation always comes into play, because it’s so difficult for a human being or a team to navigate this. How can listeners balance automation with human talent in capturing their communications?

    Balancing Automation and Human Judgment

    David:It’s a really important question. Human talent is typically the judgment that’s involved — the kind of thing where, if I hand it to someone else, I may not get the same result I’d get myself. Those are always the hardest tasks to pass off to anything automated, because how can you trust you’ll get consistent results? So when it comes to automation in a world of human decision-making, we need to think not just about what we can automate, but whether our data is available to make these judgments. Can I deliver a user experience that allows humans to make the best judgments and be the most focused on the right risk questions? There are only so many resources and so much time, so what are you going to spend your time on? Really, that means getting your data management under control — which is always the “oh man, do we have to do that?” hard thing.
    And on the capture side: how do you know you’ve captured everything? Say at the end of the day you did your collections and want to say, “Everything’s in, full confidence.” Do you have everything you need? Going back to the banning policy, we did a report last year where 73% of respondents were not confident in their ability to ban. So if you’re not banning, and you don’t know what you are capturing, you don’t know if you’re getting 100%. Then the data comes in different types, pulled in from third parties, and all the band-aids go on top of the other band-aids from the legacy band-aids — we’re talking like a mummy — and you somehow have to get a picture of what’s happening.
    So the job of data management — and the people involved with it — is to ask what we can do to shift from a fragmented approach to data, and how we actually empower our data to give us the insights we need. Some quick examples: think about powerful search tools that even less experienced analysts can use for early case assessment; good data tools should lower the threshold for that. Data completeness — what if you can automatically reconcile some of these issues, diagnose them much faster? These things can take weeks or months to notice. GDPR is another big one: if you have people working out of Europe and Canada, you have to think about global regulations, and how you handle that if you have one thing on-prem and another in the cloud. The cloud isn’t the answer to everything — that’s the problem. We’d love to just throw it in the cloud and everyone’s happy, but it doesn’t always work, because the strategies have to be strongly knitted with the use cases. We want to empower decision-making through automation — as funny as that sounds to say — but that is the job of a data platform in 2023.

    What’s Driving the Shift in Communication

    Ari:You’ve given me yet another image of somebody driving on a really complicated freeway wrapped in band-aids. As we get through this, it’s really starting to take shape in terms of the complexity. I want to think about the communication story. Courtney, what ultimately is driving the shift in the way we’re communicating? Anthony made a great point — you can ban a tool all you want, but if it’s the necessary tool in an entire country, that ban is useless. And David mentioned you sometimes can’t even prevent that usage. So what’s driving this shift?
    Courtney:I think there are three areas. One is the use of mobile devices and the technology behind them, which is just so enticing. Then you have the two human components of convenience and comfort. It’s very convenient to use a mobile device, and then there’s the comfort of knowing perhaps this app provides more security — WhatsApp has end-to-end encryption, which promotes feeling comfortable putting your thoughts into that app. You want to picture it as a data flow where it’s a person — we have to bring this back to the person using the technology, not just the technology. There’s a person who has feelings and thoughts, and those thoughts are going into the technology. So people want to feel secure in where they’re putting their thoughts.
    It’s very important now, more than ever, for everyone to be cognizant that if you put it into an app or on the internet, it’s not going away — it is discoverable. Mobile devices are a little more challenging, because you have to have a signal for capture; if you turn a device off, you can’t reach it remotely. But there’s increasingly more technology equipping entities that do this type of capturing and collection to reach that mobile device. So there are ways for companies to employ an action plan to capture and collect what they need. But ultimately, this drive is about what’s available, the convenience factor, and the human feeling of comfort and security.
    Ari:Anthony, Courtney makes a good point about the emotion in communications and the array of tools. The challenge is they’re popping up so often — so many different ways to communicate, so many chat applications, so many countries with different applications. Why do lawyers need to understand this full range of communications applicable in so many legal matters?

    Collaboration, Not Just Communication: Why Lawyers Must Adapt

    Anthony:There are a number of reasons. Number one — and we’re seeing this already, where the DOJ, SEC, and the like are really focused on it — is the pandemic. The pandemic accelerated something that was already happening: another way we communicate differently is we’re all on Zoom now. It’s Zoom, Teams — so much business is conducted by video. Even though everyone’s back at work, we’re still on Teams, still on Zoom. Even in an office, I spend most of my time on these applications. That’s a sea change. From a litigator’s perspective, if you’re spending all day on a Teams or Zoom call, so is the business. So when there’s a litigation, what are the DOJ and SEC going to focus on? “I want to know about those calls. I want the relevant calls and all the artifacts associated with them.” In the end, they’re trying to put together a narrative. Before, it was easier because you had email — I remember when email happened, everybody said we don’t have to do depositions anymore because everything’s in email. Now it’s even more, but the technology isn’t necessarily litigation-friendly. Finding all the artifacts associated with a meeting or a call isn’t easy, because the pieces are everywhere — Zoom chats, Teams, who participated, when they participated. It’s in a meeting note or an attendance note; it’s not easily found.
    It’s different from litigators saying, “IT, just give me everything, give me all the data for this custodian.” That’s only a piece of the puzzle now. I think we’re going to see a ton of recordings and transcripts — that’s going to be the new wave. A lot of people said, “We’re not doing it, we don’t want video recordings because of all kinds of issues.” But now, with Microsoft Copilot and Teams Premium, you can get summaries of meetings. That sounds like a great business efficiency — at the end of a meeting, someone who couldn’t attend wants a summary, and AI can do that for you. The problem is the only way to do that is if you record; you have to have a recording or transcript. That means there’s going to be an explosion of recordings and transcripts. Realistically, I don’t care about email — give me the meeting. If you have the AI summary, I want the summary. It’s a complete change in the way people look at things.
    In some ways, as litigators, we’re still thinking about communication, not collaboration. These are all collaboration tools. It may matter that you want to see the video, because you want to see somebody shaking their head — if you have a transcript, you won’t see that. So one of the things that’s going to change is all the operations litigators, and particularly in-house people, have set up for eDiscovery, which is based on custodian and search terms: “I get email, I collect it, I’m done.” That’s going to completely change, and people frankly aren’t prepared, because to find the relevant meetings, you have to do the custodial interviews — talk to them about their important meetings, see their calendar, find all the meetings, then get all the artifacts associated with that. That’s a sea change. And one of the challenges is always people, process, technology — many people forget about the people. They say “I want to do this” and don’t have the resources in terms of people to do it. We have to redo all our processes; a lot of them have been around for twenty years and have to be rewritten. Lawyers and anybody associated with this are very resistant to change, so the idea of completely changing your process is scary. They choose to avoid it — stick their head in the sand and say, “I’m not going to worry about it unless the other side asks me.” But almost every standard request now is asking for this type of information.
    Even thinking about what apps they may have used for doing a deal: you say, “I have this deal,” and you look at your emails, and the person says, “Oh, I didn’t negotiate the deal there. We had an application where I marked up the document and sent responses back and forth. That’s where the negotiation happened — we had no negotiations in email.” You wouldn’t know that; you have to ask somebody. It makes complete sense to negotiate an agreement on an application where you can literally mark it up together. Everyone here knows you get three hundred emails a day — there’s no way I can read them all. I prefer Teams now because I can do a chat and know the content. That’s where people are heading: there’s so much information, it has to be organized by content.
    Anthony:And legal can’t stand in the way and say, “I know this is better, more efficient, and more productive, but you have to do it through email because that’s the way I can collect it,” or compliance saying “it has to go into my compliance archive.” That’s the big challenge — but that’s why legal and compliance have to be ahead, and be a partner to the business and to technology to figure out the strategy. The strategy of “no, it’s banned, you can’t do it” isn’t going to work. People want efficiency, and frankly that’s coming from the top down. Everybody wants to use cloud AI apps. Particularly when dealing with clients, it’s going to be very technology-driven, and that includes communications. It’s not just communication — it’s collaboration, whether it’s video or working on a document together.

    The Consequences of Poor Visibility

    Ari:It’s interesting how the first reaction is often no — don’t use generative AI, don’t use cloud, don’t use predictive coding — but then there’s some acceptance. The point about context is a powerful one. David, in terms of consequences: what happens if you don’t have full visibility the way Anthony’s describing, with relevant data centralized in one place for a given matter?
    David:I’m a big North American football fan, and October is a great sports month in the US and Canada. So what are we really talking about? Playing from behind — that’s where we’re heading if we’re not careful. Everything’s changing and moving. The pace of change from regulations and from what’s going on with legal — we know it’s coming; the question is when, how, why, in what order, and what’s the best approach. So you want to get ahead of risk and play offense, and that starts with a proactive perspective on risk. We used to have time to respond to the slow pace of things, especially in the legal world, where we like to take a step back and say, “Hold on, let’s understand this.” But it’s happening so fast that the longer we wait, the pile of risk debt builds higher and higher. That’s a different way than we’re used to operating, and it can be uncomfortable. It’s up to the KLDiscoverys, the Reed Smiths, and the Shields of the world to help make this shift easier for people.
    What do we mean by proactive? Getting better at defining relevant data for collection matters, analyzing that data, and decision-making on that data, so you can get to know your potential exposure faster instead of waiting. Where is your data being stored geographically? Do you have the right retention periods? Are you on top of GDPR policies in different countries? Are there gaps in your data? Did stuff stop coming into the system and you don’t know why? What about new data sources that pop up? We do not know what people will be using a year from now. What was Meta’s new Threads? I don’t know if people are still using Threads — it was a big subject for a while. Look how fast they brought new users in, and now it’s just another social media platform. What’s coming next? Guaranteed there’s going to be another opportunity, because that’s how this works now.
    Just for an example: voice. We have much better capabilities for accurate transcriptions and audio remediation tools. At some point the question will be asked, “We now know we can do this — why aren’t we?” And either we’re going to ask ourselves that internally to get ahead, or we’re going to find out from someone else. That’s what we want to get away from. The name of this game is not playing from behind. Not having visibility into relevant data means someone else will probably find out eventually, and you’ll be caught with your pants down — an unpleasant place to be. So getting proactive is the way to go.

    Best Practices for Deploying Compliance Technology

    Ari:Big-ticket litigation and eDiscovery itself have become mainstream — you see it in major newspapers. Your point about “it’s available, why aren’t you deploying it?” is a challenge. Courtney, what are some best practices attendees can apply to deploying communications compliance technology?
    Courtney:The first thing companies need to understand is their data mapping. They need to know where their data sits, what it is, and how it flows. That data-mapping exercise is huge in preparation. We have three areas — policy, protocol, and processes — that are evaluated in understanding the implementation, what it’ll look like, and the timing involved in deployment. You want to know the users and the data size — that’s really important, and it’s part of the data mapping. So understand the ins and outs of your data, where it sits, your infrastructure as a whole, and your policies, protocols, and processes.
    Next is having a reliable and experienced partner. You have to do your due diligence to find a company that’s not going to hold your data hostage. Make sure that in the contractual process, before it’s executed, it’s read with a fine-tooth comb so you understand the agreement with the partner you choose. I’m seeing very frequently that it’s costing companies so much money when they decide they want to exit for whatever reason — companies are holding data hostage. So have that conversation when choosing a technology partner. Choose a company that has not only the professional services component that comes with the software, but also advisory services. That’s where KLDiscovery comes in with Shield — we have our Nebula Intelligent Archive solution, powered by Shield technology, which includes various modules that help companies with the strategy of implementing their compliance technology. So do your research and due diligence in choosing the best technology partner.
    Ari:Courtney’s point is so important — it came up several times in my research, the framework of this process completely changing and the freedom of your data. I saw Peter posted something in the Q&A section — Peter, whom Anthony and I know, we appreciate that, and we’d love to see others. Anthony, speaking of Q&A, what questions do clients usually ask when considering their options for the type of technology Courtney is talking about?

    Questions to Ask Vendors: Trust, Retention, and Identity

    Anthony:Courtney hit on a lot of them. First, I want to comment on one thing David said, which is probably the most important: if you’re comfortable, you’re not doing it right. This is the point about just ignoring it — everyone should be uncomfortable. If anybody’s comfortable in this day and age saying, “Oh, I have an eDiscovery process I’m comfortable with,” you’re wrong. If you think, “Oh, I’m compliant,” you’re wrong. And if you’re uncomfortable, that’s where you should be. That goes back to what questions you should ask. You shouldn’t be comfortable saying, “Oh, I’m just going to go with this new vendor.” For onboarding any type of technology, trust is the most important thing. As a lawyer, you trust but verify, and you put it in a contract — good contractual language is really important.
    If they’re going to have your data, there are privacy and security considerations, absolutely, but also record-retention obligations. Who owns the data? Can I get rid of it? How quickly? Can I apply a retention period? If it’s a type of application that could have legal holds, can I place legal holds? I can tell you that probably 90% of the applications we look at have no ability to apply a retention period or place legal holds — the developers haven’t thought about that. And I’m not hitting on any bad vendor; even Microsoft comes out with a product and then figures out if it’s compliant from a retention and eDiscovery standpoint afterward. That’s one of the challenges of the cloud: they bring out new technology based on productivity, and then decide what the legal requirements are. Then you start thinking, “Can I delete things? GDPR — if we get a request, can I delete that person’s data?” Sometimes you don’t even know, because there’s no way of doing it in the technology.
    So as a lawyer looking at technology, think about governance. You have a governance structure within your organization about how you manage data. Just because it’s going to the cloud or to a vendor, that structure should still apply. That includes collection: what is the data type? Say you decide this communication has to be captured by a Shield compliance archive — can you get the data out, and what does it look like when you do? They’ll say, “Oh yeah, you can export it,” but then it has no identity information. Identity is key for these electronic communications, and it’s one of the big challenges we have — David can speak to it. Identity within an organization is probably one of the most important things in managing electronic communications, because you’d like it to be consistent. There’s some data point — whether an internal identity marker or an email address — that has to tie things together. If you have someone with seventeen different aliases across all these communications and their Bloomberg or whatever, it’s really hard to capture and understand all of it. That’s another area where some of these applications don’t think about identity, because it’s not a concept for them — they may have a name, “Anthony,” and that’s how it’s saved.
    So think about it as a governance structure. Every application is your enterprise; think about all the things you’d ask if it were an email system. Can I delete stuff? Is it backed up? What happens if it goes down? All those questions apply to any vendor who has your data. Because of decentralization, it’s not centralized in a data center on-prem anymore — it’s now with hundreds of different organizations, and they should all be held to the same standard for data management, legal holds, data privacy, and data security. That’s where the trust factor is really important, because you can’t possibly trust hundreds of people. It goes back to strategy: should I be applying to seventeen different tools? I see this all the time in large organizations where everyone wants their own little toy, instead of someone saying, “Here’s the toy we’re all going to use.” Having multiple applications doing the same business process is probably not the best solution. So even asking “Why are we doing this? What’s the business need?” is one of the biggest questions I ask.

    Where Generative AI Is Headed

    Ari:David, now I have a more complete description: a neurotically uncomfortable character with no identity, wrapped in band-aids, on some complicated American freeway. Where are we headed? And — I’ve intentionally waited to get to this point — given all the enthusiasm around generative AI, where are the advancements headed to accommodate this situation?
    David:That visualization is strong now. Before I answer, I want to address what Anthony just said, and give some important points from Courtney around trust — and I promise it segues to generative AI, because one has very much to do with the other. The word is trust, and what are we trusting in? We need to trust the vendors holding our data, we need to trust the integrity of the data itself, and we need to trust that we understand what’s coming — which we don’t necessarily know, but we have a good indication for now. Some of the old-school approaches to selecting a vendor have been “Well, how long have they been around?” as if that tells you the whole story.
    What I found interesting in our work with our Gartner analysts is that they just published a new market category in a couple of their Hype Cycles: Digital Communications Governance. That was a pivot from the really old-school Enterprise Information Archiving, which has been around forever. What I learned from the analysts — and what helped us at Shield better relate to our own customers — comes down to this: can you do the things with the data that you need to do when you don’t know what you don’t know? That’s a hard position to be in. That’s where Enterprise Information Archiving started to lose its touch, because it’s not about having a bucket to dump your information into just to get it and then buy it back later from a vendor. That’s not the job of an archive today; it used to be. A lot of vendors are still trying to sell that, because we’re at an inflection point: are we ready to say we’re ready for a new future or not?
    So that idea of trust — vendors have to decide what they’re ready to trust in terms of the capabilities technology can bring. Technology can do lots of stuff; the question is whether it’s going to help us, and whether we can trust this new process and capability. That identity use case is a great example. Can I get into my data to get the real answers I need? Or is it just data sitting in an archive doing nothing other than fulfilling the initial requirement we’ve been so used to fulfilling that we just revert back?
    So let’s talk about generative AI. People ask a lot of “what if” questions: “Now that I see what you can do with ChatGPT, what if we can do this and that?” It’s an adorable conversation, but we’re not there yet as a community in understanding what generative AI can do for us in compliance, because there are too many questions of trust. Can we use this tool compliantly? Do we even understand the level of exposure we have when using it? So there are challenges. But there’s a lot we can do today to leverage these technologies to take out some of the grunt work in data management, collections, or assessment. We may not be able to rely on generative AI to make decisions or use its judgment for us, but we can use it as a tool. For example, analysis and recommendations on data management — Courtney mentioned that one of the first conversations with clients is “What’s up with your retention policies, how’s that all working?” and everyone says, “Ah, I was hoping you wouldn’t ask.” But we can actually use generative AI to look at this and bring us recommendations, because there’s no such thing in compliance as being perfect — it’s about continuing to improve and gathering more information to make judgments or start investigations. Maybe we have a whole bunch of data in the wrong place, or that can be deleted, or that we want in different storage to save money. We can broaden what you can ask your own structured data, automate some workflows using AI recommendations, and surface analysis for new user experiences.
    So the enthusiasm is warranted, and there’s a lot of potential for meaningful use — but we’ve got to watch out for the gotchas. Those cute use cases we sometimes see, like “we’re going to run all of our surveillance analysis through ChatGPT” even though we have zero control over where that data is going and who can access it — that’s more on the gimmicky side, and it distracts from what generative AI can really do. Imagine building a query just by talking to your machine when you’re new at this — that’s realistic, though not simple, and you don’t want to launch it without knowing what usage will look like. These are real things we can do, and we’re moving in that direction, but trust is always going to be the center of it. Are we ready for it as a community, and are we ready to say we’re good with it? Generative AI has to earn that trust. ChatGPT did a great job earning trust based on use case alone for a lot of people — and when the 4.0 model started to shift, everyone said, “Wait a second, I thought this was amazing.” If the use case is there, we can repeat it and learn to trust it, but new stuff is going to keep coming.

    The Regulatory Landscape

    Ari:Courtney, as we wind down and summarize this topic — Anthony has mentioned the SEC a few times, David has mentioned GDPR. What should legal professionals understand about the extent of regulatory activity in the current climate?
    Courtney:The regulatory landscape is doubling down right now — they are not messing around. Companies absolutely need to be prepared before litigation is knocking on their door; that is imperative. Judges are not going to find favor with anyone not being prepared. So it’s a matter of being proactive and ensuring you’re in a state of compliance — not only for the litigation side, but just for being in compliance, because so many companies in recent months have been fined millions and billions of dollars just because they weren’t prepared, weren’t compliant, and were hit in an area where there was a gap. Companies and their legal professionals need to ensure they’re ready, their gaps are closed, and they understand exactly what it means to be compliant. What are the regulations they’re subject to? Every company is different, so make sure you have the personnel and employees who are knowledgeable and have the expertise to understand the regulations you’re subject to, then ensure your data and operations are compliant. You don’t have room for even the smallest bit of non-compliance. So operationalize your processes, protocols, and policies. Be prepared, be thorough, make sure there aren’t major gaps, and understand that no one is exempt — every single employee, even up to the CEO, needs to be treated as subject to the highest level of compliance.
    Ari:Anthony, given that call to action, where can lawyers and law firms gain a competitive advantage, taking into account this intersection between eDiscovery and regulatory compliance?

    Gaining a Competitive Advantage: Be Brave, Ask Questions

    Anthony:This is my opinion, not the firm’s, but I think the legal industry as a whole is failing to address this massive technological change. There aren’t nearly enough lawyers who have the technical capability — they all can, though. I’m not a technical person at all. I started eDiscovery because I was told I had to, twenty-five years ago on a big case, and once I learned, I kept learning. That’s like every litigator: you have to be the expert in the subject matter. I go back to people, process, technology — people are as important as the technology. You can talk about generative AI, but if you don’t have people and process, it’s just a tool, and it’s probably going to create more risk, as David mentioned.
    Lawyers are good at asking questions, and that’s how they can make the most of their capabilities. Nobody knows about generative AI, so if you’re in a meeting, ask the question — be brave, and make yourself look foolish. Everyone in that room will be quiet, thinking, “Thank God they asked that, because I don’t understand it either.” People are talking nonsense right now about generative AI. So ask the questions. The most important thing when dealing with technology is asking the questions. If you don’t understand it, your role is to understand it, so ask another question — not because you’re not technical, but because the person on the other side doesn’t know how to explain it. I’m with IT people all the time: if they can’t explain it to me, then it’s not happening. Explain the process — I’m smart, I can learn. I won’t know all the technical details, but I should know enough to understand the legal and regulatory risks. So be brave, ask questions. There’s no stupid question, because no one understands technology. It’s hard. It’s really hard.

    Closing: Where This Is Going

    Ari:David, I wanted to give you the last word on where this is going.
    David:I’ll try to keep it short. Number one, I think we’re going to continue to see silos coming down — both on the data side, in terms of where data is stored, and among teams themselves. Siloed teams are surfacing more risk data that can be leveraged for analysis by other teams. From the surveillance side, we’re seeing blurring lines between first and second lines of defense, where insights from one place can be shared with another. Expect voice and other complex digital communications data types to become more accessible and analyzable. Expect data science and user experience to continue converging for better insights and decisions — that’s here, and it’s continuing. And remember, all these use cases need to be built on the right data strategies; you have to start there. There’s a lot of gimmicky stuff out there, and you can sniff out the limitations by poking around into the strength of the platform. Poke into the strengths of your own platform and understand: is it ready for today? Is it ready for tomorrow? Ask the tough questions, because someone will ask you at some point — and hopefully not because something bad already happened. To bring it down: expect modern, containerized, end-to-end platforms built for excellence, data integrity, and fidelity to give you the proactive edge you need for this new age of data.
    Ari:David Aaronson, Courtney Kern, and Anthony Diana — I’m Ari Kaplan. It’s been a privilege to join you for this collaboration between KLDiscovery and Shield. Thanks, everyone.
    David:Thank you so much, Ari.

Q&A

We have a communications policy, doesn’t that protect us?

Not on its own. Awareness is a key liability factor: if a company knows employees or even contractors are using off-policy apps, it’s still on the hook, policy or not. A policy needs a strategy behind it — an app-approval process, monitoring, audit trails, and consequences. And it has to be top-down; regulators like the SEC and FINRA want a culture of compliance where senior executives aren’t the exception.

Can we still just collect email for eDiscovery?

No. Business has moved from email to chat, collaboration tools, and even chat features inside trading and research databases, so you can no longer credibly claim you’ve preserved “all communications” for a custodian. The panel’s advice is to shift from collect-everything to relevance — deciding what’s genuinely required. It’s more subjective and more upfront work, but it’s the only realistic approach now.

Why are meeting recordings and transcripts suddenly an eDiscovery issue?

Because collaboration has replaced communication. So much business now happens on Zoom and Teams, and tools like Microsoft Copilot and Teams Premium only generate their handy meeting summaries if the session is recorded or transcribed. That’s driving an explosion of recordings and transcripts — and regulators want the relevant calls and their artifacts, which breaks the old custodian-plus-search-term eDiscovery model.

What should we ask a vendor before trusting them with our data?

Treat it like governance for your own enterprise. Ask who owns the data, whether you can apply retention periods and legal holds, and how cleanly you can export it with identity intact. The panel noted that roughly 90% of the applications they review can’t apply retention or place legal holds. And confirm the exit terms, because some vendors effectively hold data hostage on the way out.

Where do we even start with communications compliance technology?

Start with data mapping — know where your data sits, what it is, and how it flows, plus your users and data size. From there, evaluate across policy, protocol, and process to scope the implementation and timeline. Then choose an experienced partner offering both professional services and advisory support, and read the contract with a fine-tooth comb before signing.

Can we use generative AI or ChatGPT for compliance and surveillance?

As a tool for grunt work, yes — data-management analysis, retention recommendations, broader search, workflow suggestions. Not yet for judgment or decisions. The big caveat is trust and exposure: running surveillance data through a public tool with no control over where it goes is a gimmick that creates risk. Use it to assist your people, not to replace their judgment.

How much have data volume and complexity actually grown?

Sharply. In the research underlying this panel, 87% of eDiscovery decision-makers now use AI in document review, 83% say the data in a typical matter has grown over the past year, and 63% of in-house teams rate the difficulty of integrating data from various sources at seven or higher out of ten. Volumes and source types keep expanding.

Is banning risky apps enough to stay compliant?

No. You can ban an app all you want, but if it’s the required channel in an entire country — WeChat in China, for example — the ban is useless, and sometimes you can’t even prevent usage. In a prior survey, 73% of firms weren’t confident in their ability to ban. Bans mostly push communication into unmonitored channels and raise your risk.