AI x Midsized

Legal AI

ILTACON 2026: Compliance Teams Use AUPs and NIST Frameworks to Hold Shadow AI at Bay

BY INSIDE PRACTICE · SEPTEMBER 1, 2026 · 1 MIN READ

ILTACON's August 26 session "Beyond the Charter: AI Governance Frameworks That Actually Work" surfaced the legal industry's belatedly accelerating effort to align governance structures with the pace of AI tool deployment. GRC and IT leaders described written authorized use policies (AUPs), NIST frameworks, and ISO standards as the primary instruments for creating enforceable leverage with attorneys and vendors — not because the policies themselves stop bad behavior, but because they create documented accountability that malpractice carriers and vendors can be held to. For mid-sized firms where the compliance function is typically a part-time responsibility rather than a dedicated team, the takeaway is that written documents are both the minimum viable governance structure and the most actionable starting point — more durable than standing committees and more enforceable than informal norms.

Read the full story