TCDI Talks | Episode 26

How Bringing GenAI Behind the Firewall Changes the Conversation

About TCDI Talks: Episode 26

For legal teams exploring GenAI, where the data lives can be just as important as what the technology can do. In this episode of TCDI Talks, host Michael Gibeault sits down with TCDI’s Chief Client Officer, Dave York, to discuss his recent article, Your Data Never Left the Building: How Behind-the-Firewall Options Change the GenAI Conversation.

In this 11-minute episode, they explore how bringing GenAI into a controlled environment can help legal teams address concerns around security, privilege, access, and defensibility. They also discuss the role of validation and human oversight, along with practical considerations for moving GenAI from experimentation into real-world legal workflows.

Episode 26 Transcript

0:05 – Michael Gibeault

Welcome to TCDI Talks, where we highlight the people and ideas driving innovation in legal services and technology. I’m your host, Michael Gibeault, and today, we’re talking about a question that comes up in nearly every GenAI conversation: What happens to the data?

Legal teams are under pressure to move quickly and take advantage of new technology, but they’re still required to protect sensitive information and preserve privilege, all while managing cost and defensibility.

Joining me to discuss how using AI behind the firewall can help is my colleague, Dave York, TCDI’s Chief Client Officer. Dave is a co-leader of our Tech Lab and oversees our Litigation Services Team. He brings valuable experience from the law firm, corporate, and service provider sides of the industry. Dave, thanks for joining us.

1:03 – Dave York

Great to talk with you, Michael.

1:05 – Michael Gibeault

So, Dave, let’s start with one of the central ideas from your article that you just wrote. You write that GenAI has changed the conversation, but it hasn’t changed the obligations. What do you mean by that?

1:19 – Dave York

Yeah, certainly. You know, GenAI creates new opportunities for us to move faster, to gain better information. But legal teams and everybody that’s working with this data, we still have obligations to manage risk, security, confidentiality, defensibility, and certainly ensure that we have client confidence, and counsel confidence, throughout the entire process.

So, you know, years ago, a few years ago, it seemed like the question was, you know, “Can we use GenAI?” But instead, we have to assume the answer to that is “yes,” and switch the question to “How do we protect the data, preserve privilege, control access, and costs associated with it? And keep the workflows defensible, just like we would any other workflow.”

Certainly, the technology has changed, but our responsibilities have not.

2:20 – Michael Gibeault

So, Dave, when corporate legal teams evaluate GenAI for a matter, what questions should they be asking beyond whether the technology can perform the task?

2:30 – Dave York

Great question Michael. So, you know, certainly having an understanding of where’s the data processed. Is the data retained or being used to train a larger model when we’re talking about GenAI?

And going all the way back to how data has been managed and hosted over the years, can access be restricted? Can it be audited? Are there appropriate access controls around it? Are the outputs logged? You know, and certainly, with any solution, you want to make sure whether or not a process can be repeated and explained later on down the road.

You know, asking these questions are certainly not obstacles to innovating and using emerging technology. They’re just guardrails to help make the emerging technology and GenAI reusable.

3:32 – Michael Gibeault

So, Dave, why does the location where legal data is processed matter so much when teams are working with GenAI?

3:40 – Dave York

I think you have to look at the data itself. I mean, the client data can include:

  • Privileged communications
  • Trade secrets
  • Employee information
  • Financial data and records
  • Regulatory material
  • Source code
  • Investigations

You know, highly sensitive data and information. And, you know, once that leaves a controlled environment, or environment the client is used to kind of maintaining and accessing that data, certainly the risk analysis with it changes. Keeping the data within a secured, monitored environment provides a strong starting point for controlling that access, applying operational procedures, and maintaining quality practices.

Certainly, it changes the conversation from trust in a tool to just validating a controlled process and the environment itself. So, not just focusing in on the data, but the processes and the environments for which the data live in and are managed.

4:51 – Michael Gibeault

So, Dave, what does “behind the firewall” actually mean in practice, and how is that different from using a typical cloud-based GenAI platform?

5:01 – Dave York

For different clients it can mean different things. For some clients, that can mean behind their firewall. At TCDI, you know, with our own data centers and our hardware, we’re typically talking about behind the TCDI firewall.

And, you know, we work in a variety of environments: cloud-based, behind the firewall. And so, for us, bringing GenAI “behind the firewall” really means bringing that technology into a secured, controlled environment that a lot of our clients are already used to and are familiar with when it comes to how their data is managed. And certainly, that’s the same or similar infrastructure that has the established access controls, operating procedures, and quality procedures that are tied to it.

And a lot of times when there’s emerging technology or innovation, there’s this idea that the data needs to go to the technology. And instead, you know, we believe that you’ve got to have the flexibility not just to default to that every time. Sometimes you’ve got to bring the innovation and emerging technology to the data where it lives.

And so, for a lot of our clients, that means behind the TCDI firewall.

6:27 – Michael Gibeault

How does keeping data within a controlled environment affect privilege, confidentiality, access controls, and of course, the ability to audit a workflow?

6:37 – Dave York

Obviously the less you move data around, it reduces the need to move highly sensitive information outside of an environment.

You know, if you’re able to do more where the data lives, or where it is consistently maintained, then that can lead to easier and better management of the data. And again, it goes back to applying some of those same access controls that the clients have been used to over the years.

Prompts, workflows, permissions, outputs, review protocols, other documentation can be managed within that controlled process. And at the end of the day, it just helps to create more transparent, repeatable, and explainable processes for an environment that is familiar to a lot of our clients.

7:35 – Michael Gibeault

Well, Dave, we always look at defensibility. So, what kinds of validation, documentation, even human oversight should be built into the process?

7:46 – Dave York

Yeah. Trust but verify on everything. On outputs, no matter what the solution, GenAI or otherwise, should always be validated rather than accepted every time.

So, many of us are used to dealing with that. And it’s not a new concept in the industry, but certainly, with the speed and the level of work product that you get out of GenAI tools, you know, it does tend to have folks letting their guard down a little bit when it comes to the validation side. It can be very convincing of the outputs that you get.

But being able to have that human-in-the-loop validation built in and workflows and documentation, so that your processes are not just defensible and repeatable, but they can be explained as well. So, you have those protocols and quality checks in play that can be explained and understood, not just today when you’re doing it, but six months, a year, or two years down the road when you might have to go back and explain what it is that you did.

But the process should definitely be structured around and a logical validation workflow and making sure that whether it’s using other solutions to assist with that validation, but also ensuring that you have humans-in-the-loop for that validation process.

So, you know, we live by the trust but validate, and certainly, GenAI and all solutions fall under that umbrella.

9:36 – Michael Gibeault

So, Dave, for a legal team that wants to move beyond experimentation, where is the most practical place to begin?

9:43 – Dave York

Yeah, I think clearly defining the use case or problem that you’re trying to solve. There are a lot of different use cases when it comes to GenAI. A lot of different applications and solutions that are out there. Understanding what the problems are that you’re looking to solve and understanding the use cases that you’re focusing in on, is going to help you align with the right solution and the right technology.

And, you know, once you have a handle on what it is you’re trying to solve for, you know, making sure that you’re taking the other holistic approach and values into consideration. So, that’s the security side of it, understanding, you know, everything about where the data is going and how it’s being used, understanding how it fits into a process and making sure that you’re not just fixing one piece of the process, but you’re not creating more work or breaking things before or after that piece that you fixed.

And then also how the humans and teams are going to interact with it. So, you know, it really starts with the problem that you’re trying to solve. But then when you get into the actual implementation of those tools, jumping back to the data, the process, the tools and the people, to ensure you’re solving them the right way.

11:19 – Michael Gibeault

Well, Dave, thank you so much for sharing your insights today.

11:25 – Dave York

Thank you, Michael.

11:26 – Micheal Gibeault

Absolutely. It’s clear that GenAI can create meaningful opportunities for legal teams. And as Dave explained, behind the firewall, technology gives organizations another option when sensitive data or higher-risk workflows call for greater control.

The goal isn’t to choose one model for every situation. It’s to use the right technology within a process that can be secured and validated. If you like to read Dave’s article or keep up with what’s next at TCDI, visit tcdi.com or connect with us on LinkedIn.

Thank you again for joining us and we’ll see you next time on TCDI Talks.

Meet the Expert Behind the Topic

David York | Chief Client Officer | TCDI

David York oversees TCDI’s Litigation Services team involved in projects and data relating to eDiscovery, litigation management, incident response, investigations and special data projects. Since his start in the industry in 1998, Dave has made the rounds working on the law firm, client, and now provider side of the industry, successfully supporting, executing and managing all phases of diverse legal and technical projects and solutions.

During his career he has been a NC State Bar Certified Paralegal, holds a certification in Records Management, is a Certified eDiscovery Specialist (ACEDS), and has completed Black Belt Lean Six Sigma training.

Meet Our Host

Michael Gibeault | Senior Vice President, Legal Services | TCDI

As Senior VP, Legal Services, Michael Gibeault works closely with corporate legal and law firm clients alike, providing forensics, eDiscovery, and managed document review solutions while managing a team of Legal Services Directors.

Michael’s tenured career has focused on supporting law firms and corporate legal departments with creative and cost-effective solutions that rely on cutting-edge technology and highly skilled legal professionals. Prior to joining TCDI in 2017, he served in executive positions at DTI Global, Epiq, Robert Half International, LexisNexis, and Martindale Hubbell.

In Case You Missed It