Welcome everyone to Data Management for eDiscovery and Regulatory Compliance in twenty twenty three. Everything You Need to Know, which is a collaboration between KL Discovery and Shield. I’m Ari Kaplan, an analyst who covers the legal industry, and I am honored to be joined today by Courtney Kern, the director of compliance information governance and Archiving Solutions at KL Discovery David Aronson, a Senior Product Marketing Manager at Shield and Anthony Diana, a Partner and the Co Chair of the IP Tech and Data Practice Group at Reed Smith. Courtney, David, Anthony, great to see you. Thanks, Eric. Thanks, I’m looking forward to this. As you all know, and as listeners may know, I have recently released the ninth edition of my eDiscovery unfiltered report. And I wanna just sort of set the framework for our discussion today with some data points. I interviewed thirty leaders who are making eDiscovery buying decisions across the corporate and the law firm kind of spectrum. I just wanna sort of share that eighty seven percent said they were using some form of artificial intelligence in their document review processes, eighty three percent. Note that the amount of data in a typical eDiscovery matter has increased over the past year. Eighty percent use analytics across the majority of their matters. Almost three quarters have seen an increase in the workload for eDiscovery. And just to give a kind of a sense of where they fall on a scale of one to ten, with ten being the highest, sixty three percent of in house participants rate the level of difficulty in terms of integrating their data from various sources into e discovery at a seven or above. And seventy one percent of law firm participants are rating it at a six or above. So there are lots of challenges here. When I talk about communication data types, it’s just overwhelming. The sort of the feeling is just one, a sense of overwhelm. I see Anthony nodding. And so I wanna start and kind of set a foundation for this discussion. Courtney, how should today’s listeners define digital communications? Very good question, Ari. So digital communications is very broad today and it will continue to expand. Digital communications really is anything where you’re putting your thoughts into some kind of digital platform, whether that be texting, any type of video content, anything that can be captured and used for collections and any type of litigation or compliance review, that needs to be deemed as digital communication. So it’s very broad. The use of mobile devices is just expanding it. It’ll continue to expand. So really, we need to be very aware of how we are using these digital communication applications and platforms. Anything that can be captured again, be deemed as digital communications. Anthony, I’ve had the privilege of learning from you for so many years now and have seen you speak at various events. When I started researching for the eDiscovery Unfiltered Report nine years ago, very few of these were issues in terms of communication. As professionals move away from email, which was sort of the fundamental core of eDiscovery years ago, to more short form encrypted or ephemeral messaging type formats, what are the risk management and litigation implications? Yeah, look, I think, Ari, I will mention we’ve known each other probably for two decades. Obviously, we started working together about nine years ago, but we’ve been known each other for a long time. So I appreciate appreciate that. But look, the reality is, for almost twenty years, email was king, right? It was while everyone was communicating differently in their personal lives, business communications was really email. That has changed, and that is changing tremendously, and I think there’s lots of implications to that, which we’re seeing, right? We’ve seen all these large fines by the financial services world. And I know lots of clients, even outside of the financial services world, look at those fines with trepidation and saying, the DOJ, the SEC is going to come after me as well. There may not be the same regulatory record keeping requirements, but there are still issues of, you know, for particularly for certain types of litigations. They know that they’re gonna be asked to get, you know, text messaging. They’re gonna get asked for WhatsApp, WeChat, and like. And the reality is, and I’ve talked to clients for years, people have been using this for a while. It just hasn’t been WarFront, but it has been being used. I think the other thing to keep in mind, and I agree with Courtney, the decentralization of electronic communications has been wildly dramatic, particularly in the past two or three years. Part of it is everyone’s going to the cloud, right? So if you’re going to the cloud, one of the reasons to go to the cloud is there’s always innovation. So a lot of even standard structured databases, a financial database, a trading database, whatever research database, now have chat components in it, right? As a litigator, you have to be aware of that, right? I think one of the things that I see as a challenge for every outside counsel and it’s in house counsel too, is you can never say now, I am preserving all communications for these custodians, or I am collecting all communication with these custodians, because that’s not possible, because there’s just too many ways they’re communicating. It is going to have to come back to relevance. It’s probably healthy for everybody, but I think we really have to start moving towards, even in terms of communicating or talking with about communications and discovery and compliance, is really talking about what is relevant, what is really required. And that’s hard because it was the easiest way to do was, well, it’s email that’s being captured, email, I’m collecting that, I’m fine. That’s not true anymore, right? It is much more, you know, upfront people have to start thinking about these. I think compliance has to think about it and saying, do I really have to capture? I think litigators have to say, what do I really preserving? What am I really collecting? And that’s, you know, it’s not an objective criteria. It’s going to be somewhat subjective, which is what scares everywhere. David, what are the key elements of my research, especially this year, but over the years, you’ve seen this incredible trend of legal being no longer an isolated discipline, that legal is now supplemented by compliance or records or information, and of course, advanced technology. Where’s the intersection between compliance and communications? So I think both Courtney and Anthony spoke directly to like, where does that start from its most basic level? The way I like to tell it is that like, you ask me the same question one hundred years ago, I would say, well, we’re probably all looking at the same documents and letters going downtown to some archive like warehouse somewhere that doesn’t have any air conditioning because no one had air conditioning back then. But if you asked me ten years ago, the answer would probably be email. Now you have to consider like emojis, personal communications like WhatsApp, SMS, complex data sources, massive volumes of data, and of course, it’s just growing. So I don’t think like the intersection between compliance and communications has become Well, I think it’s become much bigger intersection and much more complicated intersection at best. So we’re talking like the data volumes and complexities, the use cases and analytics, reporting, search and collections, and surveillance work. So we’re, I think, a while ago, like Anthony was talking about different people were kind of doing different things on different data and everyone was kind of like in their own spots. Like the intersection is so big and so complex. Everyone has a seat at or should have a seat at the table in terms of understanding how we’re going to build the strategy for all of us, you know, on united fronts that can’t really be fully united or maybe it can be fully united and people come from different perspectives. So that intersection is a big one. And I think it’s only expanding even more. I mean, you know, is that the market driver to implement new data strategies, we’re seeing a lot of that today in our partnership with our friends at Kale Discovery. And the last thing I just want to mention is, to your point, Anthony, the cloud. I mean, the cloud is just bringing innovation like never before and modern platforms that really cover these end to end use cases. This is where I think compliance and legal are really starting to see, like, this is where we can start to make a shift from how we were used to do things to maybe a new way that isn’t just some middle ground. We haven’t wanted to commit yet to something that actually works a little bit more. I hate to use the word, but holistically, completely. David, it’s funny because when I think of a visual of this and the complexity, I’m just imagining just a random intersection, Madison and thirty fourth or something that has turned into some crazy highway situation in Houston where the road leads to nine different places. And it sounds like that’s where we are in terms of communications, compliance. And so Courtney, just spark a discussion on aligning these things, what are the challenges specifically that corporate leaders are facing with respect to communications compliance at this stage? Right, so companies are developing their policies, which are very good to have. It sets the framework for employees to follow. However, with mobile devices and communications, the challenges that I am seeing very regularly right now is that even when companies have a policy in place that state, you are allowed to use these business communication platforms that other platforms are being used. And the biggest issue right now in terms of compliance in regards to this is that even when a company has a policy in place, if they are in states, you are not allowed to use WhatsApp. These are our business apps. These are the ones we are to use. If they are aware that there are some clients, even if it’s or I’m sorry, employees, if there are employees or even contractors using these apps that are outside of the policy, if there’s any awareness to that, that company is still liable because and it kind of, you know, just takes the policy and pushes it to the side a little bit because awareness is a key component in any type of compliance and any type of litigation arena. And so when you have employees using their personal devices and apps that are outside of that policy, you still have an accountability factor that companies are trying and working hard just to mitigate the risk in that. So I’d say that that’s the biggest challenge that I am seeing repeatedly. Anthony, I’ve probably conducted four hundred interviews in the first three quarters of twenty twenty three. And Courtney’s point is so well taken. Like one of the issues in terms of bringing your own device or using a personal device is this idea that in a post pandemic world, all of these compliance issues are just in so many different places. How do you see organizations, particularly those that are highly regulated, maintaining and disposing of all of these new forms of correspondence? Yeah, and look, I think it’s a huge challenge. And I think one of the, you know, one of the one of the challenges is, this goes back to your point about who should be at the table is, and I agree with Courtney, a policy is helpful, but there needs to be a strategy, right? There needs to be a technology strategy that is communicated to the employees. Because I hear this from IT professionals all the time in these organizations, which is they don’t want to disrupt the business, right? So the business is dictating it because their clients are using a certain app, right? When the organization says you can’t use that app, that means I can’t communicate with that client. So, it’s hard, but there has to be some type of structure, right? Whether it’s an approval structure, or something that really gets into here’s our strategy, here’s what we want to use. It’s not just having an approved app, but a process for approving apps, right? So when someone says, I’ve got a client. I mean, I’ve had situations where regulators are using a certain app. So if you say you can’t use WhatsApp or WeChat, and then you find out that in China, they only communicate with WeChat, you have to use WeChat, right? And then it becomes, do you make an exception to the policy because you don’t want them doing it? So it’s not as easy as saying, know, this is what we’re doing. It’s the process that matters. And I think it’s that’s, I think, the challenge that people are having is what is the approval process? Who’s involved in that approval process? And there’s costs associated with it, right? Like every time, particularly in highly regulated industries, when you prove an app and say, Okay, we’re going use this, and you make a determination it has to be captured, there’s a cost associated with that, right? Someone has to monitor it. You have to have auditing procedures. It’s one of the things that the regulators always talk about. It’s not enough to have a policy, you have to enforce it. And that means some type of audit. That’s a huge amount of basically infrastructure within these organizations to build up. And I don’t think most organizations have that yet. And that’s what they’re trying to build up. They’re trying to build up the defensible process that allows them to do it. Basically implementing the policy, having an audit trail, I think you have to have consequences if people are violating the policy. All of that has to be come in, but it’s not easy. And I think we’ve seen this in some of the fines we’ve seen that oftentimes senior management are the violators. And you can’t have a policy where senior management is the exception. It’s top down. And that’s one of the things that the SEC, CFTC, FINRA, they’ve always said is they want to see a culture of compliance. And that starts with senior executives actually following the policy. And if they get exceptions, then people are going to say it’s not really true. So and I think it’s also resources, right? I think one of the big challenges is that there’s a lot of resources that need to have to be put in place in these organizations to actually be compliant to really manage this because it’s not an easy undertaking. As you said, it’s completely decentralized with, you know, I have a client, we’ve gone through hundreds of applications in the past year and a half. There’s thousands that they have. These are the ones that we think may have eComps. Not all of them do, but it’s, you know, they have a, you know, onboarding process where someone has to click a button and say, do I think it may have an electronic communication? And then there’s an investigation that has to happen. But that’s that’s a lot of work. David, in many of my conversations that include the words audit or process or implement a compliance regulatory, whatever, the word automation always comes into play. Because as Anthony just mentioned, it’s so difficult for a human being or a team to navigate this very difficult sort of set of circumstances. How can listeners balance automation with human talent in terms of capturing their communications? So it’s a really important question. I mean, we talk about what is human talent, you know, in comparison to automation, human talent is typically the judgment that’s involved. It’s the kind of thing that if I were to hand this to someone else, I may not get the same result that would happen if I did it myself. And those are always going to be the hardest tasks as an organization to be able to pass off to anything that’s automated because how can you trust you’ll get consistent results? That’s going be across the board. And I think when it comes to automation in a world of human being decision making, what we need to kind of start to think of is not just like what can we automate, but is our data available to make these judgments? And I think that’s where the question of automation comes in. It’s a question of can I deliver a user experience that allows humans to make the best judgments to be the most focused on the right risk questions? There’s only so many resources, only so much time. So what are you gonna spend your time on? Really like zooming out. That means like getting your data management a little bit under control, which is always like, oh man, do we have to do that? That’s such a hard thing. We talk about being so decentralized. And I think that just coming from the vendor side of things, something that’s changed over the many years, it’s not just the challenges involved with centralizing things, but also the ability to look at data management completely differently actually. And like you talk about the capture side of it. How do you know that you’ve captured everything? So let’s say at the end of the day you did collections. You want to say, okay yeah, everything’s in full confidence. Do you have confidence? Do you have everything that you need? I mean we saw just to go back to the banning policy also, did a report last year, seventy three percent of the respondents that we talked to were not confident in their ability to ban. So if you’re not banning and what aren’t and what you are capturing, you don’t know if you’re getting one hundred percent of, and then the data comes with different data types, just kind of pulled in from a third party. And then like all the band aids that go on top of the other band aids from the legacy band aids, like we’re talking like a mummy and then you just have to somehow like get a picture of what’s happening. So to bring it back, the job of a data management, let’s call it system, but really the people involved with data management is to really ask the questions of what can we do to kind of like shift this from a fragmented, not even system, but just a fragmented like approach to data and how do we actually empower our data to give us the insights that we need from it? How do we put ourselves in the best position to look at this data? And just I’ll give some quick examples. Let’s talk about search. So maybe think about powerful search tools that even less experienced analysts can use for early case assessment, right? If you have good data tools, should be able to lower the threshold for that kind of stuff. I would talk about data completeness. What if you can automatically reconciliate some of these issues that come up? What if you can diagnose them much faster and get to the issue? I mean, these things can take weeks to notice. They can take months to figure out. Things are disasters obviously. Getting ahead of that, I think is really important. GDPR is another really big one. If you’re talking about, okay, so like we have a firm and we have some people working out of Europe and some people working out of Canada. So now we have to think of global regulations and how do we fit for that if we have this thing on prem and that thing in the cloud? The cloud isn’t the answer to everything. That’s the problem. We would love to just throw a cloud and everyone will be happy, But it doesn’t always work. That’s because the strategies have to be strongly knitted with the use cases that we’re going to get out of that. We want to empower decision making through automation as much as that sounds like a funny thing to say. But actually that is the job of data platform in twenty twenty three. I love it. You’ve given me yet another image of somebody driving on a really complicated freeway wrapped in band aids. And I think, I mean, I feel like as we’re getting through this process, it really is starting to take shape in terms of the complexity. And Reed Smith, KL, Discovery Shield, all very sophisticated organizations, very sophisticated teams that are applying some of these strategies. I also wanna just take a moment to encourage the participants who are listening, feel free to ask us questions. I always try to encourage engagement. But I wanna think about the communication story. And so Courtney, what ultimately is driving the shift in the way we’re communicating? Anthony made a great point. You can ban a particular tool all you want, but if it’s the necessary tool in an entire country, that ban is completely useless. And then David even mentioned that sometimes you can’t even factor in preventing that usage. So what’s driving this shift? Well, I think that there are three areas. One is the use of mobile devices and the technology behind that. I think that what is to us is just so enticing. And then you have the two human components of convenience and comfort. So it is very convenient to use a mobile device. And then the comfort of knowing that perhaps this app provides me more security. WhatsApp has end to end encryption that promotes the feeling of feeling comfortable in using that app and putting your thoughts into that app. So you want to picture it as a data flow where it’s a person, right? We have to take this back to the person using the technology. It’s just not the technology. There’s a person using it who has feelings, who has thoughts. And those thoughts are going into the technology. And so basically people wanna feel secure in where they’re putting their thoughts. It’s very important now more than ever for everyone to be cognizant of the fact that if you put it into an app, if you put it on the internet, it’s not going away. It is discoverable. Mobile devices are a little more challenging because you do have to have a signal for capture. If you turn a device off, you can’t reach it remotely. But there are increasingly more tech There’s more technology coming about that is equipping certain entities that are doing this type of capturing and collection to reach that mobile device. So there are ways for companies to employ an action plan that will help them to go into a mobile device and capture and collect what they need. But ultimately, I just think this drive is just what’s available. And then again, the convenience factor as well as the human feeling of comfort and feeling comfortable and that they’re secure in what they’re doing. Anthony, Courtney makes a very good point about the sort of the emotion in communications and the array of tools. So the challenge is they’re popping up so often. There are just so many different ways that you can communicate so many different chat applications, so many different countries in which different applications you use. Why do lawyers need to understand this full range of communications that are applicable in so many different legal matters? Yeah, look, I think there’s a number of reasons. Number one, and again, I think this goes to, you know, as a litigator, investigator, and we’re seeing this already where, you know, the DOJ and SEC and the like are really focused on this, is because of the pandemic. And I think the pandemic was something that it really accelerated something that was already happening, but really accelerated it is, you know, another way we communicate differently is we’re all on Zoom now, right? Like it’s Zoom teams, So much business is being conducted by video. Right? Even though everyone’s back at work, we’re just still on Teams. You’re still on Zoom. Right? Like, even I’m in an office and I spend still most of my time in the office on these applications, that’s a sea change. And just even thinking about that, I think from a litigator’s perspective, and I think all the lawyers on the phone can imagine this. If you’re spending all your day on a Teams or Zoom call, so is the business, right? So when there’s a litigation, what is the DOJ and SEC going to focus on? I want to know about those calls. I want to know the relevant calls and I want all the artifacts associated with that, right? And because in the end they’re trying to put together, it’s a narrative, They’re trying to put the pieces together. And again, before it was a lot easier because you had email. And I remember when email happened, everybody said, don’t have to do depositions anymore because everything’s an email. So now I can put it all together, you know the story, what was happening, and that was somewhat true. Now it’s even more, right? There’s so much technology there where but it’s not necessarily litigation friendly, right? It’s not finding all the artifacts associated with a meeting or a phone call or whatever. It’s not easy because it’s pieces everywhere. There you have Zoom chats, you have this and Teams. You can find information about who actually participated, when they participated. It’s just not easily found, right? It’s in a meeting note or whatever it is, an attendance note, all of these things you have to find. It’s not And again, it’s different from saying, you know, litigators used to say, IT, just give me everything. Give me all the data for this custodian. That’s not available anymore. Right? You can get that, but that’s only a piece of the puzzle. And I think most of these the the plaintiffs, DOJ or otherwise, all the regulators realize that they want something that’s relevant. I mean, I think we’re going to see a ton of recordings and transcripts. I think that’s going to be the new wave. A lot of people have said, we’re not doing it. We don’t want the video recordings because of all kinds of issues. But we’re seeing, and this goes back to what technology happens. Now with Microsoft and Copilot and Teams Premium, where you can now get summaries of meetings, right? That sounds like a great business efficiency. I can have a meeting, like at the end of this meeting, we could press a button and someone could say, I couldn’t attend, but I want a summary. AI could do that for you. Fantastic. The problem is the only way to do that is if you record. You have to have a recording or transcript, but that’s the way that at least Microsoft’s doing it. That means there’s going to be an explosion of recordings and transcripts. Just think about it realistically. I don’t care about email, right? Give me the meeting, right? I don’t need to know what the email that was. All I want is that meeting. If you have the AI, I want the summary. So again, it’s a complete change in the way people look at things. You know, it’s in some ways I always talk about it, we are still as a litigator still thinking about communication, not collaboration, right? These are all collaboration tools. So it’s not the same, right? It may matter, you want to see the video because you want to see somebody shaking their head, right? If you got a transcript of it, you’re not going to see the shaking of the head. I want to see the video, right? So that is, I think, one of the things that’s gonna be changing is all of the operations that litigators and particularly in house people like have set up for eDiscovery, right? Which is based on custodian search terms. I get email, I collect it and I’m done. That’s going to completely change. And people frankly aren’t, I think, prepared for it because in order to find out the relevant meetings, you got to do the custodial interviews. You got to talk to them about where their important meetings, let me see your calendar, let me find all the meetings. Now I have to get all the artifacts associated with that. I think that’s going to be a sea change in terms of what’s happening. And again, one of the challenges, which we always talk about, it’s always like people process technology, right? People, many people forget about the people, right? They say, okay, I wanna do this, and they don’t have the resources in terms of people in order to do it. And again, we have to redo all of our processes. We’ve got standard processes. A lot of them have been around for twenty years. They all have to be rewritten. You know, to rip it up and start over again. And I don’t think most people, you know, I think lawyers and anybody associated with this are very resistant to change. So the idea of completely changing your process, completely changing what I talk about and meet confer is scary to most people. So they choose to avoid it’s human nature. You avoid it, right? Stick your head in the sand and say, I’m not gonna worry about it unless the other side asks me. But I’ve seen it almost every standard request now is asking for this type of information. And it’s not easy, right? Again, it’s even in terms of thinking about, you know, what apps they may have been using for doing a deal, right? You have a deal and you say, oh, I have this deal, I have the deal, What’s this? I look at my emails. I saw I collect your emails. And they can say, oh, I didn’t negotiate the deal there. We had an we had an application that I did. There was a document and it’s great. I love I love this application because I can mark up the document and I can send responses back and forth. And that’s all that’s where the negotiation happened. We had no negotiations in email, right? You wouldn’t know that. You have to ask somebody that, right? And that’s that is gonna be the big challenge. And again, that’s where it’s going. I mean, think this goes back to what’s approved and not approved. It makes complete sense if you’re negotiating an agreement to have it on an application where you’re literally negotiating the agreement. It’s there. You can mark it up together. You can correspond together, and you don’t have to look at your email. I I think everyone here knows you got three hundred emails a day or something like that. I can’t read all my emails. Like, there’s no way I can get through them all. I prefer Teams now because it’s not as bad and I can do a chat box, whatever, and I know sort of the content. That’s where people are heading. There’s so much information. It has to be organized by content. And again, those applications know the same thing. That’s how they’re gonna make that application, that business process so much more efficient. And legal can’t stand in the way and say, I know this is better, it’s more efficient, it’s more productive, but you have to do it through email because that’s the way I can collect it. Or compliance saying, you have to do it through email because it has to go into my compliance archive. So that is going to be the big challenge, but that’s why legal and compliance have to be ahead, right? And be a partner to the business, to technology, to figure out the strategy. And again, I think the strategy of no, you know, it’s banned, you can’t do it, isn’t going to work, right? People want efficiency. And frankly, that’s coming from the top down. Everybody wants to use cloud AI apps, all that kind of fun stuff. Particularly when they’re dealing with their clients, right? Or their customers, it’s gonna be very technology driven that includes communications. And again, it’s not communications, it’s collaboration. It’s not just a communication, it’s gonna be whether it’s video, whether that you’re working on a document together, whatever it is, it’s all gonna be about collaboration. Although it’s interesting how the first reaction is often no. Know, don’t use generative AI, don’t use cloud, don’t use whatever predictive coding. Just no, no, but then wait, I think there’s some acceptance here. But the point about context is a powerful one. It like really brings us into a whole nother section of this discussion. But David, I just wanna get back to you for a second. In terms of the consequences, I think it makes a really important point there context really matters. And we’re just piecing together a story that started with Courtney’s point about the shift in communication. What are the consequences if you don’t have full visibility the way that Anthony’s talking about and have it all centralized in one place in terms of relevant data for a given matter? So I’m a big North American football fan, right? And this is like October is like a great sports month in the United States, right? So and Canada. So when we talk about what are we talking about? We talk about playing from That’s what we’re really saying is that’s where we’re heading. We’re heading Everything’s changing. Everything’s moving. The pace of change from regulations and from what’s going on with legal. Okay. We know that it’s coming. The question is when and how and why and then what order and what’s the best approach, but it’s happening. So you want to get ahead of risk and you want to play offense. And like I said before, that starts with having a proactive perspective on risk in general. And we used to have time, and this is where I think this is all coming from, just our culture is we used to have time to respond to the slow pace of things. And especially in the legal world, we want to just take a step back and say like, hold on, hold on, what are we looking at? Let’s understand this. Let’s get in front of but it’s happening. It’s happening so fast, you know, and that pace is just completely blown up. So I think that’s why the longer we wait, the pile of risk debt just builds higher and higher, and that’s a different way than we’re used to kind of operating. And it can be uncomfortable for a lot of people to make this adjustments. And it’s on, I think, the KLD’s of the world, NREED’s of the world, the shields of the world. It’s up to us to really help change this and really make this easier for people to make this shift. So what do we mean by proactive? So I’ll give some clear examples hopefully. Getting better at defining relevant data for collections matters, getting better analyzing that data, getting better at decision making on that data, and so you can really get to know your potential exposure faster as opposed to waiting and then emails and meetings and like you don’t have time and there’s so much more and like just we need a way to do this better. Where is your data being stored? Geographically we talked about. Do you have the right retention periods? Are you on top of the GDPR policies in different countries? Are you really on top of it? Do you have all the data? Are there gaps in your data? Is everything being collected? Did stuff stop coming into the system and you don’t know why and how and what to do next about that? What about new data sources they pop up? I mean, who knows what’s gonna be out there in a year from now? And and let’s be honest, we do not know what people will be using in a year from now. I I I mean, what was met is new new threads. Right? I I don’t know if people are using threads that I don’t know what’s going on with that one. That was a big subject for a while, and maybe for some people it still is. But look how fast they brought new users. Now it’s just another social media platform. What’s gonna come next? Guaranteed there’s gonna be another opportunity because of course there is. That’s just how this works nowadays. So if we’re gonna continue this pace of change, we’re gonna be in a lot of trouble. So, okay, obviously there’s like to create some urgency, but at the same time, there is some urgency and there is what to do about it. And just for an example, this is I think like voice. We have much better capabilities for accurate transcriptions and audio remediation tools. And at some point, the question is going be asked, we now know that we can do this. Why aren’t we doing this? And either we’re going to be asking ourselves that internally to get ahead, or we’re we’re probably gonna find out from someone else. And ultimately, that’s where we wanna get away from. That’s really the name of this game is not playing from behind. Not having visibility into relevant data on any given subject means someone else will probably find out eventually. And you’ll be caught with your pants down, which is just like an unpleasant place to be for everyone. So I think just getting proactive is the way to go. And the question now is, what does it look like and how do we make that switch? Also litigation, very big ticket litigation, e discovery itself has become kind of mainstream. There’s lots of mainstream news. You see it in major newspapers of litigation and e discovery and your point about it’s available, why aren’t you deploying it? Why aren’t you using it is a challenge. So Courtney, what are some best practices that attendees who are listening can apply to deploying communications compliance technology? Sure. So the first thing I really think companies need to understand is their data mapping. They need to know where their data sits, it is, how it flows. That data mapping exercise is huge in preparation. So companies need to be prepared for that implementation of that compliance technology. We have three areas. We have policy, protocol, and processes that are going to be evaluated in understanding the implementation and what that’ll look like, the timing that will be involved in that implementation and deployment. We want to think of just knowing the users, the data size, huge. That’s really important to understand, but that’s also part of the data mapping. So really understanding the ins and outs of your data, where it sits, and then your infrastructure as a whole, and in addition to the policies, protocols, and processes. Next is having a reliable and experienced partner. So you have to do your due diligence in making sure that you’re finding a company that is not going to hold your data stock hostage. You want to make sure that in that contractual process before it’s executed, that it is really red with a fine tune comb and understanding on what the agreement is with the partner that you choose. I am seeing very frequently that it is costing companies so much money when they decide they want to exit for whatever reason. Companies are holding data hostage. So you want to have that conversation in choosing that technology partner. You want to choose a company who has not only that professional services component that comes with the software that you’re deploying and implementing, you also want to make sure that you have advisory services. That’s where Cale Discovery comes in with Shield. We have our Nebula Intelligent Archive solution where it’s powered by the Shield technology, which is state of the art, includes various modules that help companies with this strategy of implementing their compliance technology. And so you wanna make sure that you’re doing your research and your due diligence in choosing the best technology partner. Wow, Courtney’s point is so important. It came up several times in my research just in terms of the framework of this process completely changing and the freedom of your data. It just, and I’m happy to share, I have some data points on that. I’m happy to share it as a courtesy for listening from KL Discovery and Shield. But I think that, Courtney, what a great point, Sue. And also, I wanna encourage, I saw that Peter posted something in the Q and A section, Peter, who, Anthony, and I know, and we appreciate that. We’d love to see others. But Anthony, speaking of Q and A, what are the questions that clients usually ask when considering their options for the type of technology that Courtney is talking about? Yeah, look, I think, and I, Courtney, I hit on a lot of them. I think it is, well, one, I want to comment on one thing that David said, which I think is probably the most important. If you’re comfortable, you’re not doing it right, right? Like I, this is sort of the point I was making where you’re just ignoring it. Everyone should be uncomfortable. If anybody’s comfortable in this day and age with, Oh, I have any discovery process that I’m comfortable with, you’re wrong. So if you think, Oh, I’m compliant, you’re wrong. You’re not. And if you’re uncomfortable, that’s where you should be. And I think that goes back to what questions should you be asked, right? So you shouldn’t be comfortable saying, Oh, I’m just gonna go and go with this new vendor, right? Whatever it is, whatever. And again, this is for onboarding any type of technology. Trust is the most important thing. And again, it’s hard to As a lawyer, you trust but verify and you put it in a contract. It is really important to have good contractual language. To the point that David and Courtney were making, like even thinking of things like, and I do this all the time, if they’re gonna have your data, right, there’s privacy and security considerations, absolutely. There’s also record retention or retention obligations that you may have, right? Who owns the data? Can I get rid of it? How quickly can I get rid of it? Can I apply a retention period? If you think it’s a type of application that have legal holes, can I place legal holes? I can tell you that probably ninety percent of the applications that we look at has no ability to apply a retention period or place legal goals. Right? The developers haven’t thought about that. And frankly, you know, and I’m not hitting on any bad vendor because even people like Microsoft, they come out with a product, then they figure out if it’s compliant from a retention, any discovery standpoint. It’s one of the challenges of dealing with the cloud, right? They’re gonna bring out new technology based on productivity. And then once it’s out there, then they decide, oh, what are the legal requirements? And then you start thinking about, can I delete things? You know, as David said, GDPR, can I delete if we get a request, can I delete that person’s data? Sometimes you don’t even know because there’s no way of doing it in this technology. So, as a lawyer looking at technology whenever you’re doing it, just think about governance, right? You have a governance structure probably within your organization about how you manage data. Just because it’s going to the cloud or just because it’s going to be in the vendor, it should apply. So all the things that you have, you should have. And that includes collection, right? We talked about collection, like what is the data type? Say you decide, okay, this communication has to be captured by a Shield compliance archive. Well, can you get the data out? Okay, if I get it out, what does it look like when I put it in there? Because they’ll say, oh yeah, you can export it. But then it has no identity information, right? Identity is key for these electronic communications. It’s one of the big challenges we have, and David can speak to it. Identity within an organization is probably one of the most important things in managing electronic communications, because you would like it to be consistent, right? There’s some some data point, whether it’s, you know, an internal identity marker, or it could be your email address, it doesn’t really matter, but it has to be tied together. Because if you have someone with seventeen different aliases and there’s all these different communications and they’ve got their Bloomberg or whatever it is, it is really hard to capture all of that and understand it. And I think that’s another area where when you’re dealing with some of these other applications, they don’t think about identity, because they’re not thinking about that as a concept. They may have a name, right? They’re happy with Anthony, and that’s how it’s saved in the system. So thinking about it just as a governance structure, every application you can think about as your enterprise. And you should be thinking about all the things if it was an email system, what are all the things you would ask about? So as a lawyer, you have to think about, okay, well, how about this? Can I delete stuff? And is it backed up? Or what happens if it goes down? I mean, there’s so many questions you have. Again, one of the challenges is all of those questions apply to any vendor who has your data, right? And again, it goes back to the decentralization point I said is, in this day and age, because of people who are going to cloud, it’s not centralized in a data center, on prem, it’s now with hundreds of different organizations, and they should all be set to the same standard in terms of what you’re doing, right? In terms of data management, in terms of legal holds and data privacy, data security. Again, that’s where it’s hard because I think Courtney sort of said it, the trust factor is really important because you can’t possibly trust hundreds of people. And this goes back to the strategy of, should I be applying to seventeen? I see this all the time, particularly in large organizations where everyone wants their own little toy, instead of someone saying, Here’s the toy that we’re all going to use. And again, there could always be back and forth, but even things like HR databases or whatever, where people say, Well, I like this certain This business likes this one, and this business likes that one. That’s a choice you’re making, but it makes management so much harder. So I think that’s where even the asking the question, which is often the case, why are we doing this? I mean, it’s one of the biggest questions I ask is, okay, what is the business need for this? When you’re asking, what does the business need? And then when you say, but don’t we have this other application that does that? And the answer is, yeah, but I don’t like it as much. Well, maybe we shift everything to this new application, but having multiple applications doing the same business process is probably not the best solution. So David, now I have a little bit more of a description here. I have a neurotically uncomfortable character with no identity that is wrapped in band aids on on a some sort of complicated American freeway. Where are where are we headed then? What are the advancements? You know, given the enthusiasm and and just for the record, I’ve intentionally sort of waited to get to this point, but around generative AI. Given all this enthusiasm, where are the advancements headed to try to accommodate this particular situation? Yeah, thanks. That visualization is strong now. Before I answer this question, I will answer it. Wanted to actually address what Anthony just said, just very well said and give some very important points also from Courtney around trust. And I promise I will segue to the generated vibe because actually it is very much one has to do very much with the other real fast with that. Word is trust and what are we trusting in? So we need to trust obviously vendors who are holding our data. We need to trust and then to integrate in the integrity of the data itself. We need to trust that we understand what’s coming, which we don’t necessarily know what’s coming, but we have a good indication at least for now. I think what we’ve also kind of learned is that, where I think some of the old school approaches to selecting a vendor has been around, well how long have they been around for? That basically tells you the whole story because then we can trust it. What I thought was very interesting with our work with our Gartner analysts and they just published a new market category in a couple of their hype cycles of digital communications governance. And that was a pivot from the old, I mean, the really old school enterprise information archiving, which has been around since forever. And I think part of what I learned from the analysts and what I think really, really helped us at Shield also better relate to our own customers and understand what it is that they’re how to translate what they’re saying to us from the challenges that they have around data. It it really comes down to this. You know? Can you do the things with the data that you need to be able to do with it when you don’t know what you don’t know? That is such a hard thing and a hard position to be in, know. And that’s where this idea of the enterprise information archive world started to lose its touch because it is not about having a bucket to dump your information into just to get it, you know, having to buy it back later from a vendor. Like that’s not the job of an archive today. It used to be that. And a lot of vendors are still trying to pelt this because we’re still at this inflection point. Are we ready to say that we’re ready for a new future or not? So I think that idea of trust does have to, vendors have to make decisions of like what are we ready to trust in terms of the different capabilities that technology can bring? Because technology can do lots of stuff. Question is, is that going to help us? Can we trust in this new process and this new capability? So that really, I think tells us what generational, sorry, what generative ID, Generative AI. All these worldly buzzwords buzzing around my head. But that identity use case is a great example of this. Can I get into my data to get the real answers I need? Or is it just data sitting in an archive doing absolutely nothing other than fulfilling the the initial requirement which we’ve been so used to fulfilling for so long we just reverted back. And how many people just revert back and revert back and it’s not going to get you where you need to go. So let’s talk about the generative AI. People ask a lot of what if questions. Oh, now that I see what you could do with chat GPT, what if we can do this and what if we can do that and what if And it’s an adorable conversation. I love having it with some people because we’re not a community, we’re not there yet in terms of understanding what generative AI can do for us in compliance because there’s too many questions that come with it in trust. Can we use this tool compliantly? Do we even understand the level of exposure that we have when using it? So clearly some challenges there, but there actually is a lot we can do today to leverage these technologies to take out maybe some of the grunt work in data managing collections or assessment. Because there is a lot of that grunt work stuff that we may not be able to rely on generative AI to give us to just like choose things for us and make decisions for us and use its judgment on things, but we can use it as a tool. And some of these things are like, okay, so maybe we’re thinking about analysis and recommendations on data management because as we just said, data management is extremely complex. But modeling today can actually help us untangle. Courtney, you mentioned like some of the first conversations you’ll have with the customers like, so like, or the client is like, what’s up with your with your retention policies? And then they how’s that all working? And everyone’s like, ah, I was so hoping you were not gonna ask me that question, but it turns out it’s an important place to start and but who wants to do? But but the reality is, like, we can actually use generative AI to take a look at this stuff and actually bring us more recommendations because there’s no such thing in compliance not being perfect. It’s just about continuing to improve and continuing to gather more information that we can make judgments based on or at least start investigations on to say, hey, you know what? Maybe we actually have a whole bunch of data that is just totally in the wrong place or that can be deleted. Maybe we want it to be deleted or maybe we want to put in different kinds of storage so we can save money on this stuff. There’s a lot of ways to do this. I think we talk about search criteria. So like broaden what you can ask your own structured data. Maybe we can automate some workflows using suggestions from AI recommendations, surface analysis for new user experiences. This is what I think we’re talking about. So I think the enthusiasm, just to wrap that one up with a little bow, the enthusiasm on the one hand is warranted and there’s a lot of potential for real meaningful use. And we got to kind of watch out for those gotchas. So those like, you know, cute use cases we sometimes see of like, yes, we’re gonna run all of our surveillance analysis through ChatGPT even though we have zero control over where that data is going and who can access it because we just have no idea what’s going on there quite yet. That to me is like a little bit more on the gimmicky side and it distracts I think from some of the things that Generator Guide can do. I mean imagine building with like, I don’t know where to start. I’m new at this or I haven’t done this for so long and I haven’t seen this kind of thing. What if I can build a query just by talking to my machine? I don’t know. That’s realistic. It’s not so simple and you definitely don’t want to land it and know what’s usage is going to look like. Okay, yeah. But these are real things that we can do and we’re definitely moving in that direction but trust is always gonna be the center of that. Are we ready for this? Not from a technology standpoint, are we ready for it from as a community? Are we ready to say we’re good with this? And we’re gonna need to earn that trust. Generative AI has to earn that trust. TragicPT did a great job at earning that trust based on use case alone for lots of people. And when model four point zero started to shift back, everyone’s like, wait a second, I thought this was amazing. And then all of us, like if the use case is there, we can repeat it and we can learn how to trust those things, but new stuff is gonna come. Courtney, we’re winding and sort of summarizing this topic, Anthony has mentioned the SEC a few times, David has mentioned the GDPR. What should legal professionals understand about the extent of regulatory activity in the current climate? Sure. So the regulatory landscape is doubling down right now. They are not messing around. Companies absolutely need to be prepared. They need to be prepared before that litigation is knocking on their door. That is absolutely imperative. Judges are not going to they’re not gonna find favor with any judge not being prepared. So it’s a matter of being proactive and ensuring that you are in a state of compliance. So not only for the litigation side, but also for just being in compliance because so many companies right now, and in recent months even, have been fined millions and billions of dollars just because they were not prepared. They were not compliant. And they were hit in an area that there was a gap in their organization. So ultimately, companies and legal professional clients, they need to ensure that they are ready, they are prepared, that their gaps are closed, and that they understand exactly what it means to be compliant. What are the regulations that they are subject to? Because every company is different. So making sure they have that list the personnel and the employees who are knowledgeable and have the expertise in place to understand the regulations that they are subject to, then going and ensuring that their data and their operations are in place and compliant. You don’t have any room for even the smallest bit of non compliance. So, you want to make sure that you are operationalizing processes and protocols and policies again. I always bring that up because it’s so imperative. You need to be prepared. You need to be thorough. You need to make sure there aren’t any major gaps. And you need to just understand that no one is exempt from being compliant. You need to look at every single employee. Companies need to understand every single employee, even up to their CEO needs to be treated as though they are subject to the highest level of compliance. So I would say in the interest of time, companies really need to be prepared. Anthony, given that call to action, where can lawyers and law firms gain some type of competitive advantage taking into account this intersection between e discovery and regulatory compliance? Yeah, look, I think, I mean, I mean, this is my opinion, not the firm’s, but I think the legal industry as a whole is failing to address this massive technological change. I don’t think there’s nearly enough lawyers who have the technical capability. I mean, they all can, right? Every lawyer, I’m not a technical person at all. I started e discovery because I was told that I had to do that, right? It was a big case twenty years ago, twenty five years ago, there was e discovery and I had to learn how to do it. Once I learned, I keep learning, right? It’s like every litigator. When you’re a litigator, you have to learn, you have to be the expert in the subject matter. I think there’s a deficit of lawyers who actually understand this. Again, I go back to people process technology. People is as important as the technology. You can talk about generative AI, if you don’t have people and process, it’s just a tool and it’s probably going to create more risk, as David mentioned. So it’s the people matter. And I think that’s probably lawyers can do the best, you know, make the most of their own capabilities is lawyers are good at asking questions. And I tell every lawyer, nobody knows about generative AI. For example, if you’re in a meeting, ask the question, be brave, and make yourself look foolish. And I will tell you, everyone in that room is quiet, is saying, thank god they asked that question because no one understands it. Right? As David said, like, it was adorable. Like, that’s exactly it. It’s people are talking nonsense right now about gender of AI. It’s ask the questions. Like, you know the questions to ask. It’s no different than anything else. So I think the thing that from a legal perspective, the most important thing when dealing with technology is asking the questions. If you don’t understand it, your role is to understand it. If you don’t understand it, ask another question. And it’s not because you’re stupid, and it’s not because you don’t understand, you know, you’re not technical. It’s because the person on the other side doesn’t know how to explain it. I tell this all the time. I’m with IT people. If If they can’t explain it to me, then it’s not happening. You got to explain it to me, explain the process. I’m smart. I can learn. I’m not gonna know all the technical details, but I should know enough to understand what the legal and regulatory risks are. So, I mean, again, be brave. I tell that all the time. If you’re a lawyer, be brave, ask questions. There’s no stupid question because no one understands technology, right? It’s just the reality. It’s hard. It’s really hard. David, I wanted to give you the last word on where this is going. You have to, you know, Let’s do it. I’ll try to keep it short. Number one, I think we’re gonna continue to see silos coming down and that’s both from the data side of it, like where data is stored and what’s what, but also teams themselves. I think silo teams are surfacing more risk data that can be leveraged for more analysis by other teams. So like think of like from the surveillance side, blurring lines between first and second lines of defense, where insights from one place can be shared with another. Expect voice and other complex digital communications data types to become more accessible and analyzable. Expect to see data science and user experience continuing to converge for better insights and better decisions. That’s here and it’s just continuing. And remember what we’ve said before, all these use cases need to be built on the right data strategies. You have to really start there. There’s a lot of gimmicky stuff out there and you can sort of already sniff out some of those limitations by poking around into the strength of the platform and really do that. That’s very important. Poke into the strengths of your own platform and understand, is it gonna be ready? Is it ready for today? Is it ready for tomorrow? Ask the tough questions because someone will ask you at some point and hopefully that won’t be because something bad already happened. That’s really, I think to really bring it down, expect modern containerized end to end platforms that are built for excellence and data integrity on Fidelity to give you the proactive edge you need for this new age of data. David Aronson, Courtney Kern, and for Anthony Diana, I’m Ari Kaplan. It’s been a privilege to join you for this collaboration between KL Discovery and Shield. Thanks everyone. Thank you so much, Ari.