Plain-English Explanation
What this episode is about
This episode discusses how organizations—especially law firms and other regulated businesses—should manage information in 2026.
The main focus is information governance: deciding what information an organization has, who can access it, how long it must be kept, and when it should be safely deleted.
The speakers emphasize starting with small, practical projects instead of waiting for a perfect, organization-wide solution. They also discuss managing paper records, cloud systems, Microsoft 365, collaboration tools, audits, and the difficult new question of how artificial intelligence should be governed.
Main ideas in simple terms
1. Safe deletion does not have to happen all at once
Defensible disposal means deleting information in a way the organization can reasonably justify if challenged by a regulator, court, client, or auditor.
Many organizations mistakenly believe they must organize and delete everything at once. The episode argues that a better approach is to:
•Start with an area that is easier to manage.
•Test the process through a pilot.
•Document the rules and decisions.
•Learn from mistakes.
•Expand gradually.
For example, a law firm might begin by reviewing one category of closed matters rather than trying to clean up every document in every system.
The goal is not instant perfection. The goal is to show a sensible, good-faith process that steadily improves compliance.
2. Poorly handled projects can damage trust
Information disposal can be politically sensitive. People may fear that important records will be deleted, or that their work will be disrupted.
If an organization launches an overly broad project without preparing stakeholders, the project may fail. Future attempts will then be harder because employees may no longer trust the initiative.
The practical lesson is that communication and adoption are as important as the software itself.
3. Large-scale transfers are becoming more important
Law firms increasingly move large amounts of information when:
•A lawyer changes firms.
•A practice group moves.
•Firms merge or split.
•A client relationship changes.
•Paper and electronic records are transferred between offices.
This is more complicated than moving one person’s files. Organizations need workflows that identify what can be moved, what must stay behind, who approved the transfer, and whether confidential or restricted information is included.
4. Paper records still matter
Although much work is digital, organizations continue to create and store physical records.
The episode highlights the value of identifying when an entire box of paper records is eligible for destruction. That sounds simple, but it requires checking the records inside the box, applying retention rules, and handling exceptions correctly.
Physical records may also be stored with external providers such as Iron Mountain, so digital systems need to connect with off-site storage workflows.
5. Governance tools should fit into existing work
Employees often ignore governance systems if they have to leave their normal applications to use them.
The speakers therefore support “meeting people where they work”—for example, integrating governance functions into Microsoft 365, document-management systems, email, Teams, and other tools employees already use.
This can make compliance more natural and reduce the burden on users.
6. Audits require evidence, not just promises
Organizations may need to prove that their information policies are being followed.
A useful governance system should record:
•What action occurred.
•Which record it affected.
•Which rule was applied.
•Who approved or changed something.
•What the previous policy was.
•What the new policy is.
•Whether the action was automatic or performed by a person.
•Which exceptions were made.
This creates an evidence trail that can be shown to auditors, regulators, clients, or courts.
7. Chat and collaboration tools create messy information
Tools such as Microsoft Teams make it easy for people to create chats, channels, shared files, and informal discussions. But they are often created without a consistent structure.
A conversation may contain important business information, but it may be unclear:
•Who owns it.
•How long it should be kept.
•Whether it is an official business record.
•Whether it belongs in a document-management system.
•How it should be found later.
The speakers suggest that artificial intelligence may eventually help identify where important information is located. However, the underlying governance rules still need to be established.
8. AI should support human controls, not replace them
The episode presents AI governance as an area still under development.
The preferred approach is “governance first”: establish rules about access, retention, privacy, and classification before adding AI capabilities.
AI might help identify sensitive information, but people should still be able to review and correct the results. For example, an AI system might estimate whether a document contains personal information, while a human confirms the decision when confidence is low.
9. Prompts and AI outputs raise new ownership questions
A prompt is the instruction or question given to an AI system. An output is the response produced by that system.
Organizations are still deciding whether prompts and outputs should be saved. The answer may depend on:
•Whether the material is needed for legal or regulatory reasons.
•Whether a client requires it to be preserved.
•Whether it contains personal or confidential information.
•Whether it records an important business decision.
•How long the related matter or project must be retained.
•Where the data is stored and which country’s rules apply.
Law firms also face an ownership question when lawyers move between firms: are their prompts and AI-generated work personal materials, firm property, or client-related records?
There is no universal answer yet. Organizations need to evaluate the purpose, risks, and benefits of retaining this information.
10. The practical advice is to start small
The clearest recommendation is to begin a controlled pilot within the next 30 days.
A pilot might involve:
•One retention category.
•One business unit.
•One type of physical record.
•One Microsoft 365 repository.
•One notification and approval process.
The organization should decide who needs to be involved, what communications should say, what exceptions might arise, and how success will be measured.
Technical terms explained
•Information governance (IG): The system of rules and processes used to manage information throughout its life—from creation to deletion.
•Defensible disposal: Deleting information in a consistent, documented, legally reasonable way so the organization can explain and defend the decision later.
•Disposition: The final action taken on information, usually either preserving it or destroying it.
•Retention: Keeping information for a defined period because it may be legally required, commercially useful, or needed for historical reasons.
•Retention schedule: A documented list explaining how long different categories of information should be kept and what should happen afterward.
•Good faith: Acting honestly, reasonably, and with a genuine effort to follow applicable rules, even when the organization cannot achieve perfection immediately.
•Stakeholder: A person or group affected by a decision, such as lawyers, clients, records managers, IT staff, compliance teams, or executives.
•Adoption: The extent to which people actually use and follow a new system or process.
•Disposition pilot: A limited test of a deletion or records-management process before applying it more broadly.
•Auditability: The ability to demonstrate what happened, when it happened, who was involved, and which rules were used.
•Audit log: A time-stamped record of actions taken in a system.
•Exception: A case that does not follow the normal rule, such as a document that must be kept longer because of litigation or a client requirement.
•Override: A deliberate change that replaces the normal retention or access rule.
•Client rule: A requirement imposed by a client about how its information must be handled.
•Matter-based rule: A rule tied to a particular legal case, project, or engagement.
•Media-type rule: A rule that applies differently depending on the format or type of information, such as email, paper, video, or chat.
•Records management: The organized control of business records, including their classification, storage, access, retention, and disposal.
•Repository: A system or location where information is stored, such as a document-management platform, file share, email system, or Teams site.
•DMS: Document Management System—software used to store, organize, search, secure, and manage documents.
•File share: A shared folder or storage location that multiple people or departments can access.
•Regex: Short for regular expression, a pattern used to find specific text formats. For example, it can help identify client or matter numbers in file paths.
•API: Application Programming Interface—a structured way for software systems to communicate with each other.
•REST API: A widely used style of API that lets applications request or exchange information over the web using standardized methods.
•Workflow: A defined sequence of steps, such as requesting approval, checking records, notifying users, and completing destruction.
•Microsoft 365: Microsoft’s collection of cloud-based workplace tools, including Outlook, OneDrive, SharePoint, Teams, and Office applications.
•Provisioning: Setting up users, teams, permissions, storage locations, and other system features in a controlled way.
•AI governance: The policies, controls, and oversight used to ensure artificial intelligence is used safely, lawfully, fairly, and consistently.
•Data minimization: Collecting, using, or retaining only the information that is genuinely needed.
•Permissioning: Controlling who can view, edit, share, or delete information.
•Sensitivity label: A classification attached to information to show how confidential or restricted it is.
•PII: Personally Identifiable Information—information that can identify a person, such as a name, address, phone number, or identification number.
•PHI: Protected Health Information—health-related information connected to an identifiable person and protected by privacy laws.
•Confidence threshold: A level of certainty required before an AI system’s classification or recommendation is accepted automatically.
•Model: The AI system that analyzes information and produces predictions, classifications, or responses.
•Prompt: The question, instruction, or material supplied to an AI system.
•AI output: The text, summary, classification, recommendation, or other result produced by an AI system.
•Black box: A system whose internal reasoning is difficult for users to see or understand.
•ISO certification: Certification showing that an organization follows a recognized international standard, often relating to security or management practices.
•SOC 2: A widely used auditing framework that evaluates how a service provider protects data and manages controls relating to security, availability, confidentiality, processing integrity, or privacy.
•Lateral partner: A lawyer who moves from one law firm to another, usually bringing clients, cases, and related work with them.
Why this matters
Organizations now store information across paper files, email, cloud drives, document systems, chat, collaboration platforms, and AI tools. That makes it harder to know what exists, who controls it, and when it should be deleted.
Poor information governance can lead to:
•Unnecessary storage costs.
•Privacy breaches.
•Conflicting or outdated information.
•Inability to respond to audits or lawsuits.
•Accidental deletion of important records.
•Retaining sensitive data longer than necessary.
•Confusion over ownership of AI-generated material.
The episode’s central message is practical: organizations should not wait for a perfect solution. They should establish clear rules, test them on a manageable scale, document what happens, involve the people affected, and improve over time.
In short, good governance is not only about buying sophisticated software. It is about building trustworthy habits around information—especially as AI makes it easier to create, copy, search, and recombine vast amounts of data.