Building Trust with AI Governance Across Global Retail Brands

AI and IP: The Legal Frontier - Season 2, Episode 2

23 min

AI & IP: The Legal Frontier

Host Justin Pierce talks to Ethan Cohen, global head of Privacy and AI Compliance at Gap Inc., and Meaghan Kent, Venable partner and head of Venable’s AI Solutions Hub, about how to build principled, trust-centered AI programs that can move at the speed of technology without sacrificing rigor.

 

Host: Justin Pierce

Guests: Ethan CohenMeaghan Kent

 

About AI and IP: The Legal Frontier

Venable's AI and IP: The Legal Frontier is a podcast to help your company use AI and IP law to gain a competitive edge. This season's episodes examine topics from AI and copyright to data licensing, trade secrets, and confidentiality.

 


Transcript

Read the transcript for AI and IP: The Legal Frontier - Season 2, Episode 2
Justin Pierce: 00:13

If you're a business leader or general counsel, you already know AI isn't just another tech trend. It's the next frontier reimagining and reshaping how companies operate and compete. With that transformation comes complexity around intellectual property, data rights, regulatory oversight, litigation exposure, and brand integrity. This podcast is designed to give you clarity. I'm Justin Pierce, cochair of Venable's intellectual property division.

Justin Pierce: 00:43

In this season, I'll talk with colleagues and industry leaders about how AI is reshaping business, ecommerce platforms, toy companies, industrial automation, luxury brands, beyond, and the legal strategies companies need to protect innovation while moving fast. Our goal is simple, to help you turn our legal insight into your competitive advantage. Welcome to season two of AI and IP, The Legal Frontier. This week, we're talking about AI governance and retail brands. Hi, I'm Justin Pierce, a partner at Venable and co chair of the firm's Intellectual Property Division.

Justin Pierce: 01:29

As organizations race to harness generative AI, the real challenge isn't just innovation, it's governance. From aligning terminology across jurisdictions to embedding compliance directly into business processes, companies are rethinking how privacy, security, and AI oversight work together at scale. In this episode, we sit down with Gap Incorporated's Global Head of Privacy and AI Compliance and Venable's AI Solution Hub leader to explore how to build principled, trust centered AI programs that move at the speed of technology without sacrificing rigor. We'll unpack practical strategies for managing risk and improving data quality and turning AI governance into a strategic advantage rather than a regulatory afterthought. We're talking today with Gap's Ethan Cohen and my colleague, Meaghan Kent, a partner at Venable and a seasoned IP litigator.

Justin Pierce: 02:28

Hello, Ethan. Thanks for joining us. This is gonna be a great conversation. Looking forward to speaking with you and hearing all the insights you have for us today. Let me start by asking you, what's your role at The Gap?

Ethan Cohen: 02:42

Thanks for having me Justin. I serve as our global head of privacy and AI compliance for Gap Inc. We cover every brand, every jurisdiction.

Justin Pierce: 02:52

And how long have you been at Gap?

Ethan Cohen: 02:54

About five years. I started in private practice and spent about fifteen years defending regulatory enforcement matters in financial services and fintech and kind of developed organically a focus on privacy, data protection through audits and investigations. It really became powerful evidence, real credible evidence, and that developed into a subject matter focus on privacy and security. I'll tell you, left private practice, I became the first full time privacy lawyer at Charles Schwab. And then after Schwab moved over here to Gap and it's been a great transition.

Justin Pierce: 03:38

That's a great background. Thanks for going through that with us. What does your team cover now if you had to describe some of the different areas, subject matter, types of tasks that you and the team you're responsible for cover to Gap?

Ethan Cohen: 03:51

We cover a lot. I mean, we cover privacy, we cover AI compliance, records management, corporate records management, not just personal information and data. And of course, we support incident response with our security teams.

Justin Pierce: 04:05

Okay. It's a pretty wide ambit. I'm joined today as well by Meaghan Kent, who at Venable is a partner and colleague of mine. She's also the lead attorney running the AI solutions hub within Venable. I've got some similar questions for her.

Justin Pierce: 04:23

Meaghan, first of all, how long have you been in this position? It's relatively new as I understand.

Meaghan Kent: 04:27

Yeah. Justin, thanks for having me. As chair of the AI Solutions Hub, it's been, gosh, about six months.

Justin Pierce: 04:35

Great. Very recent. And what do you do in your role?

Meaghan Kent: 04:39

So as day to day practice, as you know, I'm an intellectual property attorney doing a lot of work in the copyright and AI space. As chair of the AI Solutions Hub, we are looking at AI governance across the firm, what tools we should be selecting, how we should set use guidelines for those tools, and then working with our clients to talk through what tools we might be using and what their considerations are if we're using those tools as part of our work.

Justin Pierce: 05:06

Excellent. So sort of an internal look, but also external in its application and and perspective as well.

Meaghan Kent: 05:12

That's right.

Justin Pierce: 05:13

Alright. Thank you. So now I wanna move to the area of AI adoption and the fact that governance is something that's being built in as companies and entities and organizations adopt AI. One of the biggest aspects though to adopt AI because it's moving so fast, we've all talked about this before and we deal with it in our regular lives, is terminology. There's so many different new terms.

Justin Pierce: 05:36

There's a new aspect of AI technology every day, every week, and just getting everybody on the same sheet of music to have a good conversation about it is a big deal. Ethan, I'd love to hear your thoughts on AI terminology.

Ethan Cohen: 05:51

It's a good setup. A quick public service announcement. Let me say that these opinions are my own and do not necessarily reflect those of Gap Inc. Or its officers. So thanks for letting me do that.

Ethan Cohen: 06:02

The language issue, it typically comes up at the beginning of any new relationship or engagement. And we've had some time with privacy to work through terminology and ultimately aligning best examples could be processor controller distinctions. Is that similar to a service provider third party distinction or role? And ultimately, I think we lean into picking one and using kind of commonalities across laws to be able to use a consistent set of terminology that our business partners help inform.

Ethan Cohen: 06:40

Use processors and controllers as one example, but that same discipline that comes out of trying to parse through different jurisdictional terms that functionally have the same meaning just gives us kind of a we take a step back, take a holistic view and say, hey, we can use some standard terms and not really get hung up in a lot of the jurisdictional distinctions that ultimately have the same functional use.

Justin Pierce: 07:09

Great point. Meaghan, your thoughts?

Meaghan Kent: 07:12

Yeah. I agree. It absolutely helps to simplify the terms and the terminology, especially with technology that's moving so quickly and many people do not understand yet. Even developers do not necessarily understand how it's all working. Being able to simplify the terms allows us to simplify sort of what we're talking about, not overcomplicate it.

Justin Pierce: 07:34

You bring up in your answer this, concept of how quickly things are moving in speed. All of us, because we're in this field, are seeing change maybe faster and at a faster rate than we've ever seen before. That speed really is a feature of what you have to deal with. And I'd love to hear your thoughts, Ethan, on that aspect of how speed plays a part in trying to get to the right place in compliance and AI governance.

Ethan Cohen: 07:59

You know, one key point here, AI hasn't disrupted privacy. I I think it's validated privacy. And what I mean by that is we talk about speed, ways to move faster, and ways to build what we've been working on with privacy assessments really into business ways of working. So you can have speed and rigor in the same motion and what AI does to validate this is we've been talking and working on risk assessments for a while. And changing the narrative a bit, the compliance isn't a gate.

Ethan Cohen: 08:35

It's more of building it into the infrastructure. And when you embed it from the start, that's the real velocity layer, I'd say, and doesn't become invisible, but is really baked into the process. And I like to lean into it that way. I think it really has validated a lot of what the privacy profession has been promoting for a long time and AI really is a good a proof of that as any.

Justin Pierce: 09:02

Embedding AI compliance from the start gives you the speed or enables the speed. Meaghan, your thoughts?

Meaghan Kent: 09:08

Totally agree again. I love the term rigor that Ethan used, but I agree guardrails and compliance are critical from the beginning in terms of managing risk and setting the guardrails that will ultimately save time. So for example, you know, setting the rule that only enterprise level GenAI tools could be used is a guardrail. It's perhaps a gate, but it's gonna ultimately save us so much time from an evaluation perspective and eliminate so much risk that we would otherwise be facing.

Justin Pierce: 09:40

So one thing that's interesting, I think that we've all noted is that organizations that are working with AI governance and trying to build AI tools often have to work down two different tracks. One track being what are the use cases, what are the things we might use that fit our business strategy with respect to AI as they look at tools to fit their business objective or mission. But on another track, what can be done safely? What can be done that is ethical? What can be done that complies with certain rules?

Justin Pierce: 10:08

And you've got those two tracks that are always going on. Your thoughts on how best to deal with that duality, Ethan?

Ethan Cohen: 10:15

Well, I think you set it up perfectly. I mean, that you've got a first track where you were looking at use cases. Does the use case meet the company's strategy? Does it duplicate a tool we may already be using? Is it something that's gonna be durable? Do we have the information layer to support it? And there's a function of pure business risk consideration. There's a compliance layer in that first track. And then as you mentioned, the second track is really doing that assessment of vendors. And I think a lot of attention is focused on those vendor assessments for delivering speed and process at scale.

Ethan Cohen: 10:59

And really the counterpart to that is building in the same kind of speed and scale for those use case assessments really to get kind of the full life cycle. So you're not running into rework or raising questions that ultimately come back to the same source material that you could collect upfront.

Justin Pierce: 11:20

Meaghan, your thoughts?

Meaghan Kent: 11:22

Yeah. I agree that we've got the process of do we need the tool? Do we already have a tool that does that? And then evaluating if we decide we need the tool, evaluating that vendor. I think a third consideration that we're seeing more and more from clients is, can we develop our own tool? Can we create a custom GPT? Can we use, GenAI coding to develop our own tool? Especially when you weigh the security concerns potentially from a vendor and then the cost associated with many of the tools that are being offered. We're seeing more and more clients go down that sort of third pathway of developing their own tools.

Justin Pierce: 12:03

Right. This is a question on the fly here. Not asking for a scientific answer, but when you think of those three tracks, what percentage of clients in this current snapshot in time are you seeing considering developing their own tools?

Meaghan Kent: 12:18

I don't know that I have a percent, but we have, as you know, a lot of nonprofit clients, and a lot of them have been evaluating developing their own tools given the cost concerns.

Justin Pierce: 12:29

Interesting trend.

Meaghan Kent: 12:30

Yeah. And our our for profit clients, we're hearing more and more the security concerns of vendors and that it's easier from a data perspective to develop it in house. I would say I probably heard this from maybe half of our clients.

Justin Pierce: 12:42

Okay. I think this is gonna continue to evolve.

Ethan Cohen: 12:45

Yeah. And I could layer on what what Megan was saying, the opportunity I think with development of tools and we're talking about tracks, the same opportunity to really get a unified look across domains. You have privacy, AI, security. Holistically, those all have a shared relationship. So as we're looking at and seeing tools being built, there's an opportunity really to try to develop them in a way that combines those domains for a unified look ultimately of both use case and vendor assessments.

Ethan Cohen: 13:23

And that's where we're trying to leverage tools that are very focused on our particular pain points or areas of need. And they can be very effective, I think that way.

Justin Pierce: 13:36

Yeah. And it's actually that viewpoint gives us a sense of just how many layers there are to this. It's a good segue to to my last question on this particular topic. Ethan, you and I have talked about this before. So what is this sort of built in AI governance and AI adoption?

Justin Pierce: 13:52

What does that produce? What's sort of the end state that you'd like to see or the end state that you're aiming for?

Ethan Cohen: 13:59

Well, I I I think you can't let the perfect be the enemy of the good, but the end state we're looking for is to have a credible inventory. If things can come through a front end, we're able to track it, we see it obviously. And in addition to an inventory, it provides a form of a risk register. And at the end of the day, you can deliver credible KPIs. If you're putting things through a consistent path and process, at the end of the day, we did a 100 risk assessments, for example.

Ethan Cohen: 14:36

Of those 100, 25 are red, green, or yellow. And that's a really powerful, not only performance metric, but view for leadership on what their overall portfolio looks like. And these tools are now giving us, I think, better informed way of delivering that kind of performance and and risk view.

Justin Pierce: 14:59

Right. Thank you. So another topic to cover today and probably one of our biggest ones are what are some of the challenges that are out there and what has worked in dealing with those challenges and what are some of the answers to deal with the challenges that companies and various entities face that are trying to integrate AI. One aspect of that, quite honestly, because things are moving so quickly, that I think is a challenge, is trying to understand just the scope and scale of AI use that's happening within a company or organization at any moment in time. So some thoughts from you, Ethan, on just the challenge of dealing with visibility as an organization.

Ethan Cohen: 15:40

I think visibility is an issue for everyone. And employees are already using AI technologies. I I don't think that's a crisis. Think the questions become what is customized with company data? Where are you building persistent memory within the tools that could reflect a company standard and ethic.

Ethan Cohen: 16:05

And then ultimately, what are the retention periods here? So visibility is in the first instance, are we aware of it? And then of course, what is going into it? And what are we retaining? And who is that information being shared with?

Ethan Cohen: 16:19

That visibility is a full line of sight. And there's a lot of commentary out there that I think ends up assessing an imagined risk surface in a way. This kind of esoteric or existential risk, instead of really what's in front of us. And that visibility really has to be more than we've identified a tool or product that teams are using. It's the next layer, the next levels of how data is being leveraged to do it.

Justin Pierce: 16:51

Okay. Given that's the case, what are some things that you've seen at an organizational level and perhaps even in your industry that have worked to deal with that challenge, whether it's visibility or some of the others that we've touched on.

Ethan Cohen: 17:04

One other aspect of visibility I would offer is making AI personal and getting engagements with teams where maybe you don't have a hard agenda and or maybe you don't have a PowerPoint slide with with a graphic of of the complexity of AI, but you can get people talking about it, how they're using it, and what's successful, what isn't. And I think that dialogue is part of breaking down some barriers or any resistance that may be out there for using the tools or seeing them as reliable. And that dialogue really becomes one, an early warning system and an enablement mechanism. You're able to see where areas are you need to focus for consistency. And we all use these things at home too.

Ethan Cohen: 17:57

So you're using tools you're doing at work at home. There's a lot more ultimately you can you can learn about how you can leverage them at work.

Justin Pierce: 18:07

I like that. So no agenda meetings, make it personal. That's great.

Ethan Cohen: 18:11

That's not I may not go over well with everyone no agenda meetings, but I I I think some no agenda meetings may save you a dozen or so emails trying to connect the dots on a few things when you can get on the same page. That's true.

Meaghan Kent: 18:27

Yeah. I I mean, I love that idea. I also agree that we really need to be using the tools, especially when we're advising clients. We need to see what the capabilities are, get to know these tools. And to that end, it's really important for us as a law firm and having so many, client considerations and client confidentiality considerations that we make tools available to our people that are enterprise tools that we know that they're security.

Meaghan Kent: 18:54

If we're going to be encouraging use, we need to make sure that we have really secure enterprise level tools available, and then encourage that use in in baby steps. Right? Just just try it out.

Justin Pierce: 19:05

Right. Right. I think that's a key aspect, particularly for any organizational use, obviously, law firm. And I would say this goes to any business organization that focusing on using enterprise tools, for instance, versus public AI chatbots is a good rule of thumb.

Ethan Cohen: 19:20

You know, Justin, I I make one plug there. You know, those that are curious about it are more likely to bring use cases forward. Something that's working or isn't working. To Megan's point, if we're all using the tools that familiarity really creates that curiosity and greater transparency because you can anticipate what to expect or really how the tools are working in a way that needs to be addressed.

Justin Pierce: 19:46

Ethan, in some of our earlier talks, you had a number of profound statements, but one that really struck me was some of your recommendations about a multilayered compliance architecture. And I'd love to give you some time just to explain your thoughts and what you recommend and how that might be operationalized.

Ethan Cohen: 20:07

Maybe to set this up, I'll I'll I'll start it with this concept. You can't defend the hallucination. And what I mean by that is how are you architecting your use of AI in a way that builds in, let's call them compliance standards, that builds in company standards, culture, known constraints. So there's you can look at it in three layers. You have a generative layer.

Ethan Cohen: 20:36

Consider that maybe your policy layer. I wanna generate rules based on a particular type of policy with a particular result in mind. And then I think the key is the second layer that I refer to as a constitutional layer. How are you training the technology, the models that shape the output? What I mean by that is you want to try to shape the behavior before those outputs are delivered.

Ethan Cohen: 21:08

Some may refer to that as a inference time control, for example. That's the part of the technology that we can control from larger or major AI system developers. And then of course, once those outputs are received, there's a deterministic layer. That's the human in loop where you're validating what the outputs are and you can get comfort that you're seeing reliable results. So when I say you can't defend a hallucination, if you apply some layered architecture where you are training the tools based on what your internal principles or standards are, you're doing more than just using it as a web search tool.

Justin Pierce: 21:49

Right.

Ethan Cohen: 21:50

And I think that becomes very effective and you really see the benefits of the technology specific to your company needs.

Justin Pierce: 21:58

This is thoughtful in a sense that it's realistic and you're trying to move with this framework organizations away from just having a policy, but no real implementation. So, I think that's well thought out. One other aspect, before we leave this point that I think is worth talking about, much that we've seen so far in AI, its effectiveness often relies on something that has nothing to do initially with AI and it's the quality of the data that the AI is relying on. Some thoughts for us in our audience on that, Ethan?

Ethan Cohen: 22:31

Data quality has been around for a while, of course. And from the privacy side of things, a big component of that is data mapping and lineage. I think businesses that are making that investment upfront in understanding their data architecture, mapping it, generates data quality. You identified the highest quality data. I think what's changing in the moment, and this is what I meant earlier on saying AI is really validating privacy.

Ethan Cohen: 23:05

If you didn't have quality data, that would typically be identified maybe in an internal spreadsheet or an internal document. And what generative AI does now is it has the potential for putting that less quality data immediately in front of the user. And it presents it in an articulate way and in a confident way, but it may be relying on less reliable data. And I think that is what generative AI is accelerating and it makes our work more urgent than ever before to have a reliable data foundation. And companies that have been working on that, I think are maybe better positioned for deploying AI that is durable and reliable.

Justin Pierce: 23:53

We've covered a good bit today. And as we move towards the end of our conversation, I wanna make sure that we have distilled a few takeaways and insights for the audience. And in that regard, I'd like to ask you and then I'll turn to Meaghan. But Ethan, your thoughts on what ought to be a lesson or insight from today's discussion that in house counsel or any member of our audience could take away, use, implement, or at least they should remember as they tackle AI issues in their organization.

Ethan Cohen: 24:26

I think the regulatory landscape is complex and privacy laws, whether or not the term artificial intelligence may be used explicitly or not, capture that type of data processing. It's a processing mechanism. And the call out here is we all keep our eyes on the regulatory landscape, what laws are changing, are they fractured, are they consistent? And there's a way to look at this that we don't really need a regulation to dictate what we should be assessing. There are some things that are deemed high risk, but a lot of the issues with AI, generative AI in particular, are good business issues to be considering.

Ethan Cohen: 25:09

It doesn't have to be codified in a regulation. So we don't wait for that. We don't wait for a regulation really to dictate what you should be assessing for business risk. And the result of that too is you're doing that same kind of risk assessment, I think regulations would expect on principles of transparency and explainability. And we would lean into it that way because I think the laws that are developing have that same common theme, those common principles we need to be assessing.

Ethan Cohen: 25:39

So I I would offer, we don't need to wait for regulation and we can change the narrative a little bit talking about from compliance and gates and regulation to using trust as a rallying point. And that's something everybody can get around.

Justin Pierce: 25:55

Thank you. Meaghan, your thoughts on this point and a takeaway as well?

Meaghan Kent: 25:59

Yeah. Playing off of what Ethan just said, the trust. And I think it's important what he was saying is just going back to the basic and he referred to as the business obligations or or thoughts, and for us as attorneys, our ethical obligations. If you go back to that, even without the laws or regulations in place, we can set the guardrails for ourselves and for our organizations for the use of these tools. And I love just go back to trust, and that's so important with us and our clients.

Meaghan Kent: 26:27

So that's a it's a great term for us to continue to go back to.

Justin Pierce: 26:32

That's great. Well, I'll conclude with this. I think this is a fascinating conversation. It's one that we will continue to have as things move on in this new field. A takeaway for me here that I thought is really important, and it comes out as a theme is that there is so much going on with the speed of technology in AI, so much going on with terminology that if we kind of focus in on principle based standards and focus in on what are the ethical goals and minimal guardrails that we're trying to hit, Deal with that first.

Justin Pierce: 27:05

Whatever applications, whatever technology you're building will move fast, and it'll meet the purposes that your business organization has set for you. So great insights. Thank you.

Meaghan Kent: 27:16

Thank you.

Ethan Cohen: 27:17

Great to be part of this discussion.

Justin Pierce: 27:20

Okay. That's all we have time for today. I want to thank Ethan Cohen and Meaghan Kent for helping us better understand how organizations can embed privacy, data quality, and trust into their AI governance programs while still moving at the speed of innovation. You can read more about how Venable's privacy and cybersecurity teams are helping businesses navigate the AI frontier by visiting venable.com/ai. Please join us next week when I talk to my Venable colleagues, Calvin Nelson and David Levy, about how generative AI is creating a new and fast moving set of questions about discoverability and attorney client privilege.

Justin Pierce: 28:01

I'm Justin Pierce. Thanks for listening to AI and IP, the Legal Frontier. Hi.