Why do AI and information governance have to be discussed together?

SHALAKA NATU
“People often don’t know what they have access to, because they’re usually not going poking around every possible information source — they’re trying to do their job and access what they need,” Natu says. “Versus AI, which is going to find everything — and that’s by design. You want AI to find information and present it to you, but the flip side is that AI will find anything and everything it has access to, so you have to be very aware of how your data is permissioned.”
What did the mix of perspectives on the panel surface?

SHALAKA NATU
The roundtable drew voices from governance advising, law firm technology operations, legal data infrastructure, and AI and software solutions providers. Natu says that mix mattered.
“Law firm IT leaders consider factors like business justification, budget, and which projects they should be investing in,” she says. “Whereas a strategic advisor, who advises multiple clients and is very aware of what challenges those clients are facing — that’s a very different lens.”
The firm IT leader perspective also shed light on what organizational change looks like at a firm actively managing AI transformation, while the software and service providers were able to provide insights on how that’s happening across clients and industries.
“We work with clients across hundreds of firms in legal, but we also work with clients in accounting and financial services,” says Natu. “Practitioners don’t always have as much visibility into what their peers are doing.”
What’s the most common mistake firms make when they try deploying AI on top of their knowledge systems?

SHALAKA NATU
Natu identifies data governance, data quality, and clarity on objectives as the biggest blockers.
“Historically, firms have not had to deal with AI agents sitting above systems of record and trying to reach across all of them,” says Natu. “They’re starting to realize that governance is non-negotiable now.”
“AI can only be as good as your data, and it’s not easy to go back and fix it. There are so many competing priorities, and this one almost always gets deprioritized.”
The third failure pattern is the one she finds most consistent across pilots: the inability to answer what she calls the three W’s. “You have to answer: For whom are you building this agent, what will they be working on, and why is this important? We’ve seen that almost 80 to 85% of pilots never reach the deployment stage. That’s because they don’t have clear answers to those three W’s.”
AI can only be as good as your data, and it’s not easy to go back and fix it. There are so many competing priorities, and this one almost always gets deprioritized.
Shalaka Natu, Senior Director, Product Management Intapp
How does the gap between what firms think their knowledge systems contain, and what’s actually there, show up in practice?

SHALAKA NATU
“As they’re piloting their agents, that’s when a lot of those gaps get exposed,” Natu says. “That’s when they come to realize: I have to have my data foundation robust before I can even expose this to my professionals. There are so many systems at play, so many integrations at play, and unless they go back and invest in fixing their architecture, they don’t have a path forward.”
In Intapp’s experience, most firms are still in the early stages of that work.
What does “secure AI integration” mean in this context?

SHALAKA NATU
All of the technical controls matter — data access, client confidentiality, model behavior — but Natu frames the question at a higher level of ambition than most firms are working toward.
“We’re not just talking about automation through AI, or integrating systems so that AI can present more holistic data,” she says. “We’re looking at providing a coworker — an agent that’s taking actions on your behalf while you’re not actively working in the system.” If a conflicts analyst can get through 15 searches a day, adding AI coworkers means getting through 150. The throughput ceiling on the operation itself moves, not just the speed of any single task.
What that looks like in the compliance space: A new business intake coworker takes the email thread from a client conversation, populates the intake form based on that correspondence and historical form data, identifies the right lawyer and matter type, and submits the form to the conflicts team — with the professional reviewing at the end rather than at every step. A conflicts coworker builds a search strategy, runs the search, and brings the analyst in to review rather than to build from scratch. An AML coworker researches negative news, sanctions, and bankruptcy data for every party on a new matter and compiles the report.
The governance principle runs through all of it. AI agents must inherit the firm’s security model, not bypass it. Intapp expects agents to start showing up on ethical walls, subject to the same set of policies as their human counterparts. And security and defensibility aren’t the same thing. Security prevents improper access; defensibility proves responsible use after the fact — to a client, court, regulator, insurer, or opposing party.
“AI by default is non-deterministic,” Natu says. “It’s very difficult to prove after the fact because it could produce a different result when you run the agent the next time. So you want to log every single action the agent takes, in case you need to prove why you made a certain decision at a certain point in time.”
Where did the panel perspectives diverge?

SHALAKA NATU
One point of difference was how to think about agents relative to people — and whether the governance model for one maps onto the other.
“Humans and agents are different, and we need to treat them differently,” Natu says. “Humans inherently have conscience and consequences. When we bring on a lateral, they’re trained and told not to use competitor clients’ information — and they inherently know that, and they also know there are consequences. Agents don’t have consciences, and they don’t pay any penalties. So you have to figure out how to instruct your agent to do certain things or not, and how to hold them accountable.”
A fellow panelist took a different stance. “His view was essentially, ‘I can’t make the assumption that people will do the right thing, and I come from business applications where I’m trying to make sure people behave and not expose the firm to risk.’”
Natu found the challenge clarifying. “There are always 2% that don’t, and firms need to have the right guardrails in place to account for those instances.”
Humans inherently have conscience and consequences. When we bring on a lateral, they’re trained and told not to use competitor clients’ information — and they inherently know that, and they also know there are consequences. Agents don’t have consciences, and they don’t pay any penalties. So you have to figure out how to instruct your agent to do certain things or not, and how to hold them accountable.
Shalaka Natu, Senior Director, Product Management Intapp
For a firm that’s early in its AI journey, what are the most practical takeaways?

SHALAKA NATU
Natu identifies three starting points.
First: Be clear on the problem you’re solving. “Where is the biggest ROI for you, and where do you want to spend it? That has to be answered before anything else.”
Second: Understand your regulatory exposure. “If you’re deploying agents, you need to make sure you’re tracking their every single action so you can prove to regulators after the fact what the agent did and why. That is not optional.”
Third: Start mapping your data and permissions. “Data governance is foundational. If you’re not doing that work in parallel, you won’t have a path to the deployment you actually want.”
The through line of the session: AI integration with knowledge systems isn’t a new set of obligations for firms. It’s the same obligations firms have always carried — extended to a new kind of actor, and provable after the fact.
For more on how professional firms can scale AI without compromising compliance, read our conversation with Chris Wada, SVP and GM of Compliance Solutions at Intapp: How to scale AI without scaling risk.
About The Back Channel
The Back Channel is an ongoing Q&A series where Intapp leaders and industry voices speak candidly about the forces reshaping professional services firms, and the role Firm AI will play in that reshaping. Each conversation goes beyond the headline trends to explore what’s actually working — and what’s at stake. No fluff, no talking points: just direct dialogue on the issues that matter most to firm leaders today.
Firm AI, built on Intapp
See what AI built for the firm looks like
Explore how Intapp gives your firm the governed data foundation that AI depends on — before you scale a single agent.