Plain-English Explanation
What this episode is about
This episode explains why organizations—especially law firms—need strong information governance before they can safely and effectively use artificial intelligence (AI).
Information governance means knowing:
•What information the organization owns
•Where that information is stored
•Who is responsible for it
•How long it should be kept
•When it should be securely deleted
•Who is allowed to access or change it
The central message is simple: AI can only be as reliable as the data it uses. If an organization’s data is outdated, duplicated, badly classified, or stored without clear rules, AI will amplify those problems.
The guest, Chris, describes Legal RM’s 2026 priorities:
1. Preparing data so it is suitable for AI
2. Deleting unnecessary information in a controlled and provable way
3. Connecting governance across many systems, including email, document platforms, file shares, cloud storage, chat, and physical records
Main ideas in simple terms
1. Good AI starts with organized information
AI is not a magic solution. It finds patterns and produces answers based on existing information.
If the underlying information is inaccurate or poorly organized, AI may:
•Give incorrect answers
•Use outdated documents
•Reveal information to the wrong people
•Treat duplicate or irrelevant files as important
•Miss the correct version of a document
This is why the episode describes AI as an “echo chamber” or “amplifier.” It can magnify both good practices and bad ones.
2. Organizations should first understand what they have
Before launching a governance program, an organization should create a basic map of its information:
•What documents and records exist?
•Are they in a document management system, email, SharePoint, OneDrive, file shares, chat, or storage boxes?
•Which client, case, department, or employee is responsible?
•Are the records confidential, obsolete, duplicated, or subject to legal requirements?
Without this visibility, decisions about retention, deletion, security, or AI use are mostly guesswork.
Chris also advises organizations not to wait for a perfect inventory. A useful first step is better than endless planning.
3. Data preparation is becoming an AI requirement
Many organizations are adopting AI while their information remains poorly managed. Common problems include:
•Over-retention: keeping information much longer than necessary
•Misclassification: labeling information incorrectly or not labeling it at all
•Under-governance: having too few rules or controls over information
•Unstructured data: information stored in places where it is difficult to categorize, such as email or ordinary file shares
The proposed solution is an AI-ready data foundation: information that is clean, correctly classified, access-controlled, and governed by clear policies.
4. Deleting unnecessary information can save money
Law firms often keep huge amounts of old information. Some of it may be legally necessary, but much of it may no longer have business value.
Chris focuses on defensible disposal: deleting information according to documented rules, approvals, and evidence.
For example, if a client matter is closed and the responsible partner approves deletion, thousands of documents might be removed in one controlled process.
This can reduce:
•Storage costs
•Charges for exceeding document-system limits
•Physical storage and destruction fees
•The risk of exposing old sensitive information
•The amount of irrelevant material AI must search through
5. Governance must work across many systems
Information is rarely stored in one place. A firm may use:
•A document management system
•Microsoft SharePoint
•OneDrive
•Email
•Microsoft Teams
•File shares
•Box or other cloud services
•Physical filing rooms
•Off-site storage vendors
A governance program that covers only one system leaves gaps. The episode argues for a shared governance framework that can apply consistent rules across different repositories.
Sometimes a full technical integration is unnecessary. A simple reference or reminder may be enough to record where information exists and when it should be reviewed or deleted.
6. A successful first 90 days should create visibility and action
The value achieved in 90 days depends on the organization’s size, data quality, mergers, and existing classification practices.
A realistic first phase should aim to:
1. Identify information across major repositories
2. Define and apply retention policies
3. Find the first group of records eligible for disposal
4. Obtain the necessary approvals
5. Complete an initial deletion or cleanup
6. Measure the time, risk, and money saved
The first result does not need to transform the entire organization. It should demonstrate that governance can produce practical benefits.
7. Compliance requires evidence, not just policies
Having a written policy is not enough. An organization must be able to show that the policy was actually followed.
A reliable system should record:
•Which policy applied
•Which documents or records were affected
•When the policy was triggered
•Who reviewed or approved the action
•Any exceptions or overrides
•Whether a legal hold stopped deletion
•When the information was ultimately destroyed
This creates an audit trail, which is a chronological record of decisions and actions.
The system may delete the original records but retain evidence showing what existed, why it was deleted, who approved it, and when the deletion occurred.
8. Safe deletion often happens in stages
The system described does not immediately erase everything permanently. It first uses a soft deletion, meaning the material is moved to a recycling or holding area.
This gives the organization time to review the proposed deletion before permanent removal. The episode mentions recycling periods of roughly 20 to 28 days.
This approach reduces fear and makes deletion easier to control.
9. Governance can become a source of savings
Information governance is often viewed as a compliance expense. The episode argues that it can also become a financial benefit.
Organizations can calculate savings from:
•Fewer storage charges
•Fewer physical records
•Lower vendor fees
•Reduced data-management work
•Less time spent searching through irrelevant information
Measuring these savings helps show that governance is not merely administrative overhead. It can directly improve the organization’s finances.
10. The next step should be small and practical
The recommended action for the next 30 days is to choose one manageable target, such as:
•The oldest overdue records
•A large closed client matter
•One attorney’s files
•One department’s storage area
•One clearly obsolete category of data
Then obtain approval, dispose of the information properly, record the result, and celebrate the success.
Visible early wins can encourage other people across the organization to participate.
Technical terms explained
•Artificial intelligence (AI): Computer systems that perform tasks such as finding patterns, summarizing text, answering questions, or generating content.
•Information governance (IG): The rules, responsibilities, and technologies used to manage information throughout its life—from creation to storage, use, archiving, and deletion.
•Governed intelligence: The idea that AI should operate on information that is organized, controlled, accurate, and used according to clear rules.
•AI-ready data foundation: A trustworthy base of information that has been cleaned, classified, secured, and prepared for use by AI systems.
•Data: Recorded information, such as documents, emails, messages, spreadsheets, photographs, or database entries.
•Information asset: A particular piece or collection of information that has value or requires management, such as a contract, email, client file, or physical folder.
•Structured data: Information organized in a predictable format, often with labels or fields that make it easy to search and categorize.
•Unstructured data: Information without a consistent format or organization, such as ordinary emails, chat messages, scattered file-share documents, or handwritten notes.
•Data classification: Assigning labels or categories to information, such as client matter, confidential, financial, personal, or eligible for deletion.
•Metadata: Information about information. For example, a document’s author, creation date, client, matter number, file type, or security level.
•Retention policy: A rule explaining how long a type of information must be kept and what should happen when that period ends.
•Disposition: The final action taken on information, such as deleting it, destroying it, transferring it, or preserving it permanently.
•Defensible disposal: Deleting information in a way that follows documented rules and approvals, so the organization can explain and defend the decision later.
•ROT data: Redundant, Obsolete, and Trivial information. Redundant data is duplicated, obsolete data is no longer useful, and trivial data has little or no business value.
•Over-retention: Keeping information longer than necessary or legally required.
•Under-governed information: Information that is not properly controlled, classified, secured, or assigned an owner.
•Document management system (DMS): Software used to store, organize, search, secure, and manage documents. Examples mentioned include iManage and NetDocuments.
•Repository: Any place where information is stored, such as a DMS, email system, cloud drive, file share, chat platform, or physical warehouse.
•File share: A shared digital folder or storage location that multiple people can access, often through a company network or cloud service.
•SharePoint: Microsoft’s platform for storing, sharing, and collaborating on documents and other business information.
•OneDrive: Microsoft’s cloud storage service for individual users and shared files.
•Application programming interface (API): A controlled way for one software system to communicate with another. APIs allow governance tools to read, classify, or manage information in other platforms.
•API throttling: Limiting how many requests a system can receive through its API during a period of time.
•API acceptable use: Rules that determine how an organization is allowed to use another company’s API, including limits, permissions, and prohibited activities.
•Policy engine: Software that applies governance rules automatically based on conditions such as client, matter, document type, department, or date.
•Granular policy: A very specific rule that can apply to a narrow category, down to an individual document, person, case, or record.
•Legal hold: An instruction to preserve information because it may be relevant to a lawsuit, investigation, audit, or regulatory matter. Information under a legal hold must not be deleted even if its normal retention period has ended.
•Exception handling: The process for managing cases where the normal policy cannot be followed, such as a legal hold, special client requirement, or partner override.
•Audit trail: A time-ordered record showing what actions occurred, when they occurred, and who performed or approved them.
•Auditability: The ability to prove what happened by producing reliable records of decisions, approvals, changes, and deletions.
•Disposition certificate: A formal record confirming that specified information was destroyed or otherwise disposed of according to policy.
•Soft deletion: Moving information into a temporary recycling or holding area instead of permanently erasing it immediately.
•Hard deletion: Permanent removal of information so that it cannot normally be recovered.
•Return on investment (ROI): A comparison between the value gained from a project and the cost of carrying it out.
•Overage charge: An additional fee charged when an organization exceeds the storage or usage limits in a software contract.
•Dark data: Information an organization possesses but does not properly understand, classify, use, or manage.
•Single tenancy: A software arrangement in which one organization has its own separate application environment.
•On-premise: Software or infrastructure operated on the organization’s own computers or servers rather than entirely through a cloud provider.
•Cloud-based system: Software and storage operated on remote servers and accessed through the internet.
•Integration: A connection that allows separate software systems to exchange information or trigger actions.
•Ad hoc integration: A limited, purpose-built connection created for a specific need rather than a complete, permanent integration with every feature.
•Information lifecycle: The stages information passes through, including creation, use, storage, review, archiving, and destruction.
•Information governance framework: The organization-wide structure of policies, responsibilities, procedures, technologies, and controls used to manage information.
Why this matters
Organizations are increasingly using AI to search documents, answer questions, summarize matters, and support business decisions. That makes information quality and control more important than ever.
Poor governance can lead to:
•Incorrect AI answers
•Confidentiality breaches
•Accidental disclosure of privileged information
•Higher storage costs
•Difficult audits
•Inability to explain why records were deleted
•Legal and regulatory risk
Strong governance creates the opposite outcome. It helps an organization know what it owns, protect sensitive information, remove unnecessary material, reduce costs, and give AI better-quality inputs.
The episode’s practical lesson is to start with one visible, manageable improvement. Clean up a defined set of information, obtain proper approval, document the process, measure the benefit, and use that success to expand governance across the organization.