Working With Legal and Security
Both will be involved, both have legitimate concerns, and both can stall the programme. How to make them useful.
Governance · Procedure
Legal and security are the functions most able to stop this programme and the ones whose support makes it workable. The relationship is worth designing.
The recommendations in “Working With Legal and Security” become easier to sustain when implementation work has visible owners, dates and review time. Teams evaluating automatic time tracking can use it to coordinate the operational side of AI adoption and identify where governance tasks are being missed, without treating activity data as evidence of misconduct or as a substitute for asking people why they chose a tool.
For an independent benchmark, compare the local approach with OWASP GenAI Security Project; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.
What legal needs from you
A small number of decisions rather than a stream of individual questions.
A pre-agreed position on the standard clauses: what is acceptable, what escalates.
Classification of the data involved, which they cannot determine themselves.
And honest sizing, because a risk presented as larger than it is produces a response calibrated to the overstatement.
What you need from legal
A view on the seven clauses, once, as a template.
Positions on the hard constraints: regulated data, client contracts, cross-border.
And a fast path for low-risk assessments, which the procurement note argues is the single biggest unblocking change available.
What security needs
Visibility of what is in use, which discovery provides.
Involvement in monitoring decisions, which is their domain.
And confidence that enabling is not abandoning control, which is a real concern and deserves a real answer.
The argument that works with security
Shadow use is invisible use.
A programme that provides a good approved option converts unmonitored personal-account activity into enterprise-tier activity with logging and a contract.
That is a security improvement, stated in their terms, and it is the framing that turns an obstacle into a sponsor.
Where they will disagree with each other
Legal wants fewer tools, assessed thoroughly.
Security wants visibility and control.
The business wants capability now.
Those tensions are real and the standing group exists to resolve them case by case, which the ownership note covers.
The monitoring conversation specifically
Security will propose content inspection because the tooling offers it.
Legal may have consultation obligations that make it harder than it looks.
Settle this early, jointly, rather than discovering the disagreement after procurement.
Keeping both informed
Short regular updates: what discovery found, what was approved, what incidents occurred.
Surprises are what damage these relationships.
And bring them problems before they are decisions, which costs nothing and changes how the advice arrives.
What to check
Is there a pre-agreed legal position on the standard clauses?
Has security been given the discovery findings?
Have monitoring decisions been settled jointly?
And do both get regular updates, or only requests?
The point
Shadow use is invisible use.
A good approved option converts unmonitored personal-account activity into enterprise activity with logging and a contract.
Underlying all of this
Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.
The recurring pattern
The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.