Skip to main content

Articles

How to Ensure AI Governance and Risk Management Keeps Pace With AI Adoption

Date

August 19, 2026

Read Time

2 minutes

Share


As companies across sectors continue to add AI tools to their workflows both internally and externally — granting AI agents access to critical internal systems and allowing them to interact with customers — data security and privacy risks are growing.

Implementing Best Practices for Oversight

In the family office context, organizations are using AI tools for research, reporting, risk analysis, manager selection, forecasting, and other operational tasks. While they are eager to realize gains in efficiency, cybersecurity remains a chief concern. Kathryn (Katie) Nadro was quoted in a recent “Chief Investment Officer” article about how family offices can manage these risks and create processes for oversight and accountability around the use of AI. 

“At a minimum, the office should document the data inputted into an AI tool, keep a human in the loop with authority to override AI decisions, test the tool against known outcomes before relying on it, perform strong vendor diligence on security and data use, and maintain an audit trail showing what the model recommended and what the human decided,” Katie said. “You should always be able to reconstruct the human reasoning behind a decision.” Read the full “Chief Investment Officer” article here.

Assessing AI Liability Exposure

Just like humans, AI agents can make mistakes. But these tools can repeat that mistake thousands of times in seconds, potentially causing real harm to customers. When that happens, who is liable? A recent “Techtarget” article advising chief information officers on AI liability concerns pointed to a July 2026 incident, in which Open AI’s models escaped a controlled testing environment and hacked into another company’s systems, as an object lesson in the risks of prioritizing speed over governance.

While the parties in this particular situation treated the incident as a collaborative security matter, it’s easy to see how similar scenarios could spawn disputes, raising questions about who is responsible. Katie explained that these legal questions about AI systems will be evaluated through established areas of law.

“If you talk to lawyers or regulators in the space, they’re using existing law to evaluate these kinds of risks. You’re talking about product liability law, consumer protection laws, data privacy and security laws, and negligence,” Katie said. But because existing laws may not address every risk associated with increasingly capable AI systems, she said, new regulations could be needed for frontier AI systems, particularly around safety requirements and accountability measures.

Reducing AI liability exposure requires careful planning and proactive engineering measures, including vetting vendors, fully understanding contracts, carefully reviewing insurance coverage, limiting what AI systems can access, and continuously monitoring these models after they go live.  

Read the full “Techtarget” article here.

Questions about managing the risks associated with AI tools and agents in your company? Reach out to Katie Nadro or another member of LP’s Corporate Group.


Filed under: Cybersecurity, Corporate

October 22, 2025

Cyberattack and the Risk to Wire Transfers

Read More