When Legal Sets the Policy and Comms Inherits the Crisis

How the gap between legal and communications is becoming one of the most expensive problems in AI governance.

AI Governance Gap: When Legal and Comms Don't Align
Image by iStock/dem10
Justin Joffe

Justin Joffe

July 29, 2026 07:00 AM

In February 2026, a federal judge in the Southern District of New York issued a landmark ruling that was immediately understood by most corporate legal teams. The trouble is, most communications teams never heard about it.

Ruling on United States v. Heppner, Judge Jed Rakoff found that a defendant's prompts to public AI tool Claude were discoverable in court because the platform's privacy policy permitted data collection and third-party sharing, including with government authorities. The decision didn't create new law, but it did apply longstanding privilege principles to determine that the individual entered information into a public AI platform under terms that did not support a reasonable expectation of confidentiality. That means sending the material to counsel afterward could not retroactively make it privileged.

The decision creates significant exposure for organizations whose employees use consumer AI tools without understanding their privacy implications, Ogletree Deakins noted in its post-ruling analysis.

While most legal teams read Heppner and started asking questions about tool governance, employees at most organizations continued to prompt away, unaware that anything had changed.

That gap between what legal knows and what the workforce understands is where some of the greatest AI risk now lives. At its core, this is a communications problem.

Summary prepared by
  • A federal judge ruled AI prompts entered into public platforms may be discoverable in court, putting companies at risk when employees use consumer AI tools without understanding privacy policies or confidentiality limits.
  • More than half of workers surveyed globally received no recent AI training, even as AI use climbed to 45%, exposing a major gap between legal governance and employee behavior.
  • The article shows how poor AI messaging fueled backlash at major companies, while IKEA turned AI adoption into workforce reskilling that generated about 1.3 billion euros in new revenue.
  • For law firm leaders and corporate counsel, the takeaway is urgent: AI governance succeeds only when legal, IT and communications align early enough to build employee trust and reduce reputational risk.

The Room Where It Doesn't Happen

Most organizations don't follow that order of operations.

According to ManpowerGroup's 2026 Global Talent Barometer, which surveyed nearly 14,000 workers across 19 countries, more than half of the global workforce reported receiving no recent AI training, even as regular AI usage jumped 13% to 45% of workers. Worker confidence in technology fell by 18% over the same period. Workers are being asked to use more AI while trusting it less.

"If you are not in the room for the calibration of the tool, you should not be responsible for the communication of its impact," says Aaron Kwittken, global head of AI and Innovation at FGS Global. Kwittken sees this as a sequencing problem: AI is deployed as an operational pilot, then the communications function is brought in to announce the outcomes. By then, the window for building genuine understanding has already closed.

Shawn Helms, a partner at McDermott Will & Schulte who co-founded the firm's AI Cross-Practice Group, sees the same dynamic from the legal side. "Too often, communications is treated as the final distribution channel for a policy developed elsewhere," Helms says. "That is a mistake."

In a mature AI governance program, he continues, communications should be involved before the policy is finalized, because communications professionals understand how employees receive information, where ambiguity will cause confusion, and which messages are likely to change behavior.

This disconnect is a function of organizational structure, says George Haj, founder of Haj Media and a crisis communications advisor who has counseled law firms through high-stakes reputation matters. "In the organizations that manage reputation risk and crisis well, communications executives are part of the executive leadership team," Haj says. "They're not a service department."

When the Announcement Is the Crisis

The cost of that misalignment has been on public display all year. Three cases illustrate what happens when legal sets the parameters and communications inherits the fallout.

In February, Baker McKenzie explicitly cited AI in a public statement announcing the elimination of between 600 and 1,000 roles, according to the Global Legal Post. The statement was legally defensible, but it was also a communications failure: employees felt blindsided, and the narrative that followed focused on displacement instead of transformation.

This is one of the defining reputational risks of the current moment, Kwittken says. "We are seeing a wave of AI-washed layoffs where leadership masks poor quarterly performance with a technological restructuring narrative," he says. The damage happens on both sides: external credibility suffers when the rationale doesn't hold up to scrutiny, and internal trust erodes among remaining employees.

Standard Chartered offered a starker example in May when CEO Bill Winters told an investor event in Hong Kong that the bank planned to cut close to 8,000 support roles by 2030, explaining the bank would replace "lower-value human capital" with AI investment, The Wall Street Journal reported. The Remarks sparked immediate backlash, prompting Winters to issue a public apology on LinkedIn days later. Whatever legal review Winters' messaging received, it didn't consider a communications lens that anticipated how his words would land.

"Disparity between internal workforce messaging, external PR, and SEC filings is often what creates legal exposure," Stephen Reynolds, a partner at McDermott Will & Schulte who advises publicly traded companies on SEC cybersecurity disclosure obligations, says. "Early alignment mitigates risk."

What Right Looks Like

IKEA offers a positive example of how successful legal-comms coordination boosts employer brand.

When IKEA's largest franchisee, Ingka Group, deployed its AI customer service tool "Billie," the chatbot resolved roughly 47% of all incoming inquiries and affected about 8,500 employees. But rather than reduce headcount proportionally, Ingka examined the 53% of queries Billie could not resolve. Customers were calling for interior design help that required human judgment. The company built a reskilling program around that signal, retraining the workforce as remote design consultants before any announcement was made. The reskilled program generated approximately 1.3 billion euros in its first full year, reported CIO—representing 3.3% of Ingka's total revenue.

Comms wasn't tasked with sugercoating a layoff announcement. Instead, it was handed a genuine workforce investment and asked to explain it.

Haj frames this question around storytelling. "Are we talking about reskilling? Are we talking about how teams have used AI to reduce workload and build efficiencies in ways that make lives better for most employees?" Those are communications decisions to be made before the legal language is finalized, not after.

Kwittken frames the structural fix in terms of a partnership between the CCO, GC, and IT leader. He calls it an "AI Amnesty Window"—a defined period where employees can disclose how they are using AI tools without penalty. The GC gets a risk map, the CCO gets a narrative, and the organization gets an accurate picture of its own exposure before a court or regulator finds it first.

The Interpretive Layer

There's a reason this is harder than it sounds. Legal and communications report to different executives, optimize for different outcomes, and operate on different timelines. When those functions are not in the room together from the beginning, they tend to pull in opposite directions at the precise moment when alignment matters most.

"I love my friends in legal, but they don't always have the best understanding of how things really work day-to-day in an organization: the actual workflow, the pressures on employees, the need to find efficiencies, whether they're authorized or not," Haj says.

Reynolds puts it in operational terms. "The real communication breakdown occurs when converting complex legal requirements into daily employee workflows," he says. Closing that gap requires breaking down internal silos so that corporate AI policy aligns with how people actually work. "AI policies work best when they are written to embrace positive use cases while setting reasonable guardrails against higher risk uses."

"An AI chatbot is a third-party service, not a private notebook and not a substitute for communicating with counsel." says Helms. He believes that sentence should be in every organization's AI onboarding materials. Most aren't there yet.

As Best Law Firms reported, confidentiality and data privacy concerns remain among the top barriers to AI adoption in the legal industry. The question the Heppner ruling raises isn't whether attorneys trust AI tools, but whether the employees in their client organizations understand what using those tools means from a risk management lens. In most organizations, the answer is no. And that answer is a communications failure.

"Your governance is only any good if your employee base understands it," Haj says. Building governance frameworks that employees can't navigate is not risk management. It's risk deferral.

Scaling AI at the Speed of Trust

"AI adoption scales at the speed of excitement, understanding, and trust," says Kwittken. "If the workforce believes efficiency is a euphemism for unemployment, they will sabotage the tools."

The organizations that move fastest on AI are not the ones with the most sophisticated legal frameworks. They're the ones where employees understand what the tools are, what the guardrails mean, and what the plan is if their role changes. That understanding doesn't come in a memo from the General Counsel. It comes from a communications function in the room when the strategy is built, one that has the standing to translate legal constraint into human language.

For law firms and the clients they advise, the practical question is not whether to build that partnership. It's whether communications gets to shape governance before the next announcement, or after it.

Frequently Asked Questions

  • What did the United States v. Heppner ruling decide about AI and privilege? Judge Jed Rakoff ruled that a defendant's prompts to a public AI tool were discoverable in court, because the platform's privacy policy allowed data collection and third-party sharing. Sending that same material to a lawyer afterward did not retroactively make it privileged.
  • Why is AI governance considered a communications problem, not just a legal one? Because most organizations' legal teams update AI policy or respond to new rulings without looping in communications until after decisions are made—leaving employees unaware of new risks or expectations. Experts interviewed say this sequencing, not the policy language itself, is where the biggest exposure comes from.
  • What is an "AI Amnesty Window"? A concept proposed by FGS Global's Aaron Kwittken: a defined period in which employees can disclose their actual AI tool usage without penalty, giving the general counsel a real risk map and the communications team an accurate narrative to work from.
  • How much AI training are employees actually receiving? According to ManpowerGroup's 2026 Global Talent Barometer, more than half of the global workforce reported no recent AI training, even as regular AI usage rose to 45% of workers and worker confidence in the technology fell 18%.