Is Legal Still the "Department of No"?: Legal’s New Role in AI - Future of Work Podcast
30m 4s
In this podcast interview, Vanessa Candela, Chief Legal and Trust Officer at Celonis, discusses the evolving role of legal leaders in the age of AI and the importance of building trust. Celonis is a process intelligence company that uses AI to create digital twins of business operations, enabling companies to gain insights, fix inefficiencies, and drive transformation. Candela explains how her role expanded beyond traditional legal functions to include information security, IT, and sustainability, reflecting a broader industry trend where legal officers are becoming trusted partners who enable business growth while managing risk.
A central theme is the responsible adoption of AI. Candela highlights that for AI to be effective and trusted in enterprises, it must be grounded in clean data and process intelligence (summarized as "no AI without PI"). Celonis has established a cross-functional AI governance council and a business transformation office to oversee AI use, ensuring a balance between innovation and risk management. This involves practical guardrails addressing security, bias, and data integrity, anticipating regulatory trends like the EU AI Act.
Finally, Candela emphasizes that successful AI integration depends on people. Through initiatives like AI activation weeks and designated "AI champions," Celonis focuses on change management, skill development, and dispelling fears to foster adoption. She analogizes AI agents to junior colleagues, requiring clear governance, human oversight, and accountability to build trust and realize their full potential in enhancing, not replacing, human work.
(upbeat music) - Hi everyone and welcome to the Future of Work podcast. Today we're welcoming a very special guest and somebody who is uniquely qualified to talk about trust, AI and the future of business transformation. And that is Vanessa Candela, chief legal and trust officer at Salonus. And her work sits right at the center of how people, process and technology move forward together in the age of AI. So welcome Vanessa and so thrilled to have you here. Thank you for taking the time to speak with us. And I wanted to start by sharing with our listeners a little bit about your journey, what Salonus does in terms of business value to its customers. And then about how your role evolved. You started as in a way having responsibility for the traditional things that a chief legal officer owns within an enterprise. But over time that expanded to some really interesting areas of the business. And it really demonstrates how much trust you managed to build with your business partners. So we'd love to hear a little bit about that during Vanessa. - Absolutely. So first off, thank you so much for having me. I'm excited about this conversation today. So a little bit about Salonus for those of you that don't know, we are leading process intelligence software company. So what does that mean? Effectively, we're able to enable companies to understand how their businesses actually run, right? We use process mining in the AI to create what we call a living digital twin of their business operations. And this serves as a basis allows them to transform their business, get insights in see how the company's actually operating versus how they think it's operating. Fix bottlenecks improve efficiencies and boosting sustainability in the meantime. So that's a little bit about Salonus about me. So yes, you're right. I'm the chief legal and trust officer at Salonus. When I first started at Salonus a little over four years ago, I came on board as the chief legal officer to run legal compliance and ethics in a more traditional role. I think about two years in, they asked me to take on their responsibility for information security, which I embraced wholeheartedly. I had some experience at a prior company in InfoSec and I was excited to get back into it. And then about six months later, they asked me if I would lead the team's supporting IT and business systems and also sustainability. So my scope broadened pretty remarkably over the course of the first few years of my time here. And that's impressive because, you know, I think it was a couple of years ago, the financial times and the economists, they do these reports on predicting the future of chief legal officers remits and they predicted that more CLOs would be asked to take on these non-traditional legal functions. And that means you're sort of wearing two hats on the one hand, you're advising on the risks and how to calibrate risk for the business and on the other hand, you're also looking at technology to bring into the company. And when you think about Vanessa, you know, legal's role, I think in the past, legal might have been seen as somewhat of a department of know and we've made that shift, I think, as an industry to being much more trusted business partners. But when AI has presented itself, I think that has swung the pendulum again. We've got new risks to think about. And how have you been navigating that uncertainty in these new risks? - Yeah, great question. So I do think that legal departments used to be seen as the department of know. I think particularly in high tech, that has moved out of necessity, to be honest with you. I think you, as I or myself, I will say, as a chief legal officer, responsible not just for legal, but what I call the trust organization. So I've flipped the dialogue a little bit from risk to trust and we can talk about that. But it is our responsibility to enable the business in a way that mitigates risk for sure. But more importantly, that builds trust for our customers and our stakeholders. And I think CLOs have unique skill sets. And that's why you're seeing us get more and more responsibility across the organization because we can build credibility with all of the stakeholders, the organization. Because when we do that, we gain the trust of our CEOs and our boards so that they are comfortable giving us that broad remit. And I think it frankly makes sense. I have seen the benefits of bringing together all of my organizations really tightly to cross-functionally align and ensure the best outcome for the company. - Yeah, and I think that is really what CEOs are looking for. Because I think when we were preparing for this podcast, we were talking about many CEOs. And I think your co-seos are looking to really adopt AI and use it as a business differentiator. And at the same time, do that in a really responsible way. And there's that tension between the two. How do you look at legal's role in guiding the business through that adoption in a responsible way and also governing within the organization? How do you govern looking at new vendors to bring in what AI is to use? What sort of frameworks have you been putting in place or thinking through? - Yeah, absolutely. So a great question around AI. And I think AI for me, we're so business focused in driving forward and AI is moving at such a breath-taking speed that we have to keep up with it. And so the interesting thing for me is because we're so business focused and business-enabled, AI has been something that has made me and with my legal hat on have to take a step back and say, okay, what do we need to do here? How can we enable the business to move as fast as humanly possible, embracing this technology while also being smart about it and not losing credibility, not losing the trust of our customers and our stakeholders or partners, et cetera. So I think from that perspective, we of course have put in a governance framework around the adoption of AI, both internally and how we're implementing it within our product. And because that's critically important, especially for us in the space that we're in. And so we have this AI governance council that governs and looks at every time we adopt AI internally or how we're using it in our product and it is a cross-functional team. So we bring in engineering, product, legal, infosec, compliance, ethics, et cetera. We all look at whatever it is in front of us and make a smart decision based on our sort of risk profile that we're willing to move forward with. And it's a tough balance. I will say, I know I talk to a lot of CLOs out there and everyone is really struggling with keeping up with it. So I think we're all doing the best we can to implement. I will say we're doing a lot around embracing AI and we can talk about that a little bit if that makes sense. So as part of my role, I formed the, what's called, what we call the business transformation office within the trust organization. And one of the first remits for that organization is to ensure that we are AI first so that we're activating AI internally for internal use. And that is not as easy of a task as you would think, right? I think a lot of companies make mistake, the mistake of thinking tool first and then we'll figure it out the rest later. Let's pick our tool and then everybody will just embrace and move forward and that's just not the reality of AI or any technology. So we really have been very thoughtful and pragmatic about how we roll this out, right? Yes, we have chosen a key tool. There are a lot of tools being used across the organization, but it's really about change management and about getting people to embrace AI and embrace AI in a responsible way so that we can get all of the benefits from it. And yes, of course, there's always risk with technology but mitigate that risk as much as possible given the space that we're in. So we have done things like we have, everyone is gold on using AI of course, but really we focused on enablement, right? Helping people no matter where they are in the journey of AI, whether they've never put a prompt into Gemini or ChatGPT or their experts and their engineers and they're using AI tools to code. Everyone's at a different place in their journey and so we kicked off an AI activation week where there were 14 sessions covering all different aspects depending on where you are. Really enabling, we have what we call AI champions in every organization that are responsible for rolling out AI usage and bringing back to us when they need tools, when they need training and enablement. So really trying to embed it into the organization so people get comfortable with it and are using it every day in a way that is responsible. So I think you have to be very thoughtful about it, but it's here, it is moving fast even in the last six to 12 months since people really started embracing. I would say that the technology has come so far. Tools are frog leaping each other, leapfrogging each other and it's really an incredible thing to watch. But my responsibility within the legal and trust organization is to ensure one that we have the tools we need, that we're rolling them out, that we're enabling people around it, but we're doing it in a responsible way. And I actually think, back to your original question on this, I actually think that having my role across the legal and trust organization helps that in an incredible way because we're so tightly aligned on what we're doing and I talk to my leadership team every day about how are we aligning what do we need to do better and I think it makes it easier and faster being all under one umbrella. And I love what you said about people still being at the center of how you think about adoption because it is as amazing as the tools are, you won't realize the ROI unless you do have that adoption that we both talked about and resonates a lot with the values that we have at work day where we're doing a lot around skills. I love your activation week idea, but we're skilling people because trust is also about dispelling fear and we had talked about that because people are quite fearful about AI taking their roles and I think this work you're doing to bring everybody with you and not leave anybody behind and get people ready for this new world that they're going to have to operate in and learn how to leverage AI to elevate a work they do is so important and impressive and I think setting up that transformation office really put kind of people and change management at the core of what you're doing. When we were prepping, you said something that really resonated with me around like delivering an ROI and how hard that is. If you could share a little bit your thoughts on the one hand we've got people's fear around can AI take their jobs then we have the tools themselves which still have some gaps and then there's the pressure for us to really use AI and differentiate ourselves, but there's also a lot of readiness to get the ROI in terms of data readiness and ensuring the AI has the context and that your adage at Solonus that no AI without PI maybe you can talk a little bit to that. Yeah, absolutely. Yeah, it's really interesting because everyone's so focused on the AI tools, but in order for AI to work, right? Number one, you need access to good clean data, like anything else. And two, you need the context, especially for enterprise AI. You need the context that feeds around the AI in order to do what it needs to do for enterprise. So we say there's no AI without PI meaning there's no AI without process intelligence. And so what does that mean? Well, assuming you have the foundation of your data, right? You need the context of your unique business in order to feed the AI what it needs. Otherwise AI spits out generic information. We've all seen it. You put a prompt into one of the tools. It spits out some generic thing that doesn't really make sense for you and then you end up going around and doing the work anyway. But if prompted right and combined with process intelligence that is actually injected right into the workflows, the power of that is really truly incredible. And we obviously see it internally. It's alone as we see it with our customers. And it really enhances that AI. So yes, I think you need good data. You need to ensure that your data is clean. You need the right tooling around AI, but you also need process intelligence for enterprise AI to actually work. And I think that plays into the trust equation too, right? I recently moderated a panel which was called AI+PI equals trust. And what that really means is what I was just talking about, which is to trust the output from AI in the enterprise, you need the process intelligence to ensure that it has the proper context. So it gives you confidence in the output and therefore you end up trusting the output of the tool itself. And I think that's really important especially in the enterprise space where companies are wanting to embrace, wanting to use and leverage the power of AI to really scale and grow their businesses. But there's some fear there that it's not smart enough yet or it doesn't have the right context in order to do that. And I think process intelligence helps that tremendously. Vanessa, everybody is talking about the non-human colleague and we did some research to work day and 82% of our customers and organizations are expanding their use of agents. And it's our job as legal teams and as CLOs to be thinking about how we enable those agents and ensure that they're trusted. And I know you shared with me sort of a way that you think about how to train and have oversight around agents and you had a great analogy that I'd love you to share. Yeah, sure. So I do, I think when we think about agents, you have to think about them the same way you think about sort of junior people on your team in many ways, right? Just like we're training AI models, we are adding process intelligence to give the context to the AI in order to give people trust in the output of AI. Agents I view in a very similar way, right? And all of the things that we're doing around governance help with that. So clearly defined policies on the use of AI controls to ensure that models only train on and access the data they're supposed to train on, monitoring, reviewing, human accountability for the output of the agent. That's really, really important, right? The agents honestly need to earn our trust just like a new human colleague needs to earn our trust. And I do think that they're going to get smarter and smarter than more people use them and build and the as technology changes. But I think it will never go away that you have to ensure that there is oversight of these agents and that there is a human that is accountable for the output. Because if mistakes are made in nobody's accountable, I think that's a very dangerous place to be. But we're embracing agents all over the place. I think that's one thing that we are really focused on. And I am super excited about what I'm seeing. I'm seeing my team build agents, you know, people that are not necessarily super technical. We own a company called Make.com. So that combined, their internal technologies really has been incredible to see. And, you know, my goal is to get every single person that's alone is ultimately building an agent for themselves. And it sounds scary if you've never done it before. But I think as people get more and more comfortable with the technology, the beauty of the agent and the beauty of some of this technology is it is actually pretty user-friendly. For the simple use cases. And so as long as there continues to be somebody accountable, you continually enforce those governance models. It's a pretty exciting place to be in technology today. Now that's music to our ears. As it worked out, we've launched many new agents and internally as well, really thinking even within the legal team about how we can leverage agents to really help us do our jobs better, not necessarily replace tasks. But there are many, I think, quite, you know, mundane tasks, like contract review and things like that, Vanessa, that no lawyer will ever regret having to read a 200-page contract again. So that's our ever-sort tool. We fully embraced within legal for that reason. I want to go back to what you said about, you know, the speed at which AI is moving and the technology is moving. And I think regulation can't even keep pace with the technology. And I know we've got the EUAI Act coming. But it is what you talked about, I believe, the putting in the right frameworks and very practical approach that you've adopted to thinking through how to make it safe and take a risk-based view of each of the different types of AI that you're using. Can you talk a little bit more about that? And in higher-risk situations, you know, you talked about human oversight, which is so important. But I think companies like yours, where you've been putting these frameworks in place long before the regulation is even in place, means that you're better set up to really meet those requirements. But I'd love your thoughts on regulation and also these risk-based frameworks and principles that you've adopted, because I think a lot of companies are thinking through that right now. Yeah, I mean, it's not easy, right? The law is always behind technology. It always has been and it always will be. It just takes a little bit of time to catch up. We can't sit around and wait for the regulators to sort of figure it out, because our businesses want to use the technology. And so I do take a very common sense risk-based approach. We all know the issues that that governments are thinking about and what they're concerned with are the same things that we're concerned with from a business perspective, right? So if I think about, what do I worry about? I worry about security, 100%. Probably my from number one priority, given my remit. I worry about hallucinations. I worry about the integrity of data. I worry about IP leakage, another huge risk. I worry about bias. So we think about all these things and these are the exact things that governments are regulating. And so we really try to put in place a framework that addresses that. So super-sensitive or high-risk data we stay away from. But the majority of things we absolutely leverage AI for. And so as long as you have that sort of common sense risk-based approach, I think when the regulations catch up, there may be some adjusting to do. But you will be 80% of the way there, 90% of the way there. And again, at the end of the day, of course, I always worry about compliance with law and regulation. But I worry more about protecting all of those things that those laws are going to be put in place for. So we try and get ahead of it as much as we possibly can. It's hard. It's very reminiscent of GDPR, if you think about that. Everybody went into a full-blown panic and how do we do this? And then every country came up with their own version of that. And how do you comply as a global organization? We are all over the world. And so you have to sort of take a step back and think practically about, OK, how do I do this? What's the lowest common denominator when it comes to the regulation? And that's what you roll out. And so I think about AI in the same way. I think we have to-- I'm in a company that is moving so fast that I have to embrace this, whether I want to or not. I love it. It's super exciting. I love seeing what my team's doing with AI. So we're embracing it. We're putting common sense guardrails around it and just pushing forward. Very, very much, I think, forward thinking on your part and I totally resonates what you're saying around putting policies, principles, work day. We built a responsible AI program many, many years ago and built that risk-based approach into how we build our products. And then bias testing, testing at the end of the process as well before we release monitoring, third party reviews. And that transparency, I think, and explainability to customers does build a lot of trust. And I think that's really key. Because you're also in a position, Vanessa, where you're looking at tech vendors to bring into the company, to bring into Salonas, how do you think about vendors and what you're looking in trusted vendors that you will-- is there a bar now that has changed because of AI with them? I know you asked your law firms, which I thought was super interesting. What is their AI strategy, which I'm been ashamedly steel, that idea? But yeah, how do you think, because when you're wearing that head of also leading the IT organization and security, how do you think about that in terms of trusted vendors? Yeah, I mean, look, we expect our vendors to set the bar where we set our own bar. And so we do ask those questions. And we do any time that our AI governance council is reviewing some tool that somebody wants to bring in, we look at it from all of those ankles. They're not as advanced or they don't have the security implemented that we would expect to that we expect of ourselves. Then they're not a good vendor for us. But everybody's on the journey, so we do try to work with our vendors. And sometimes we can bring them in and put parameters around it to allow that to happen. But look, I think we all have to. And especially, I think for us, my number one priority from a security and legal perspective is our customers. And so if we're bringing in a tool that in any way could potentially touch customer data or get implemented into our product flow, I need to be incredibly confident that that tool is at the same level as we are. Otherwise, obviously, from a pure legal perspective, you create liability. But more importantly, I don't want to risk our credibility with our customers. And I don't want to risk their data or anything to happen. And so I do hold them to a high bar, as I would expect our customers to hold us too. So I think it's fair going both ways. That's also a great synergy of your roles. Yeah, where you're bringing the flip side of everything that you're doing as the advantage and then also kind of the building trust and innovating with integrity, I think, with your customers in mind, is really the right way to think about it and to embrace AI, but to do so responsibly, I think, is your message. I love that, integrating with, oh, sorry, innovating with integrity. That's a great, I love that. Those are two of our workday values. So we talk about that a lot and try to connect our values. And customers are really important to-- and people, one of our other values are the people that work at our company. And I mean, have you any advice to people who are at all different stages of their level of openness and adoption of AI? And there's a lot of talk about lawyers of the future, what they should be thinking about in this new age. Have you any advice for people who are perhaps reticent or not fully there yet? I think we're all starting to test and learn how to prompt. But do you think it's a key skill that we learn this to be relevant in the future? Oh, my gosh, 100%. If you aren't learning how to use this to enhance what you do, you are going to be left behind. And this is what I tell my team. And that's not from a people perspective in terms of you're going to lose your job. But you're going to miss out on this opportunity to be better at your job. It's like any technology if you don't embrace it. You're going to be left behind. And I think that there are so many ways to embrace it and so many levels of embracing. So you can meet the tool where you're at. And really, or meet AI where you're at is really what I mean. And I think, you know, this is why I ask my law firm, you know, how are you leveraging AI and things like e-discovery? How are we doing things more efficiently? I mean, you and I are in-house. One of my, you know, one of the things I have to think about all the time is budget and how much we're spending money with our law firms. And, you know, I might, we, I work with incredible lawyers at, at incredible law firms that I'm very grateful for. But I need them embracing this as well because there are areas where they need to engage and you leverage this to be more efficient, be more cost effective. And if they're not, I think they're going to get left behind to be honest. So obviously, always responsibly. But my lawyers are using it. They're gold to use it every day. We have a company goal that every single person embraces and uses at least our key tool. And then there's a, you know, we have KPIs around it. We want people not just using it every once in a while, but using it a certain number of times of week. And we have a target to hit across the company. I've targeted the legal and trust organization to hit 10% above that because I think we need to be leaders on this, which is not usually the way things work, but interesting that's the way things are working out. Because I think you have to embrace it, right? And so I think, you know, again, we have to do this in a responsible way. We have to do this in a way that our customers and our internal customers continue to trust what we're doing. But I think if you are not embracing technology and right now it's AI, you're missing out on an opportunity to really enhance your skill set. It's funny. I talked to, I think we chatted about this last night, but I talked, I presented, I spoke to my daughter's high school business national honor society last night. And I was talking all about AI, you know, right now, the same is true for the high school student, the college student, the young professional. And those of us that have been doing this for a long time is how do we embrace AI in a way that the controls are permitted? You know, I said to them, you know, your teachers are in a position right now where they are between encouraging it and banning it. And they're not sure where on the spectrum they are because they're not comfortable with it plus they're trying to teach you how to do these things on your own before you leverage AI. But at the same time, these kids are going into a world, they're in a world where AI is just table stakes for them. And so, you know, I wish my daughters would go into AI engineering. That's not where they're interested, but, you know, you don't have to be an AI engineer, but you do have to embrace it. It's sort of like, you know, you have to embrace the smartphone when that came out. You have to embrace the laptop when that came out. I mean, I don't want to date myself, but when I was in college, we were using word processors, right? So, like, we couldn't wait for the desktop and then it was the laptop and stuff just moved so fast. Imagine if I was still using a word processor. Like, I would have been, you know, I would have been unemployed. So, I do think it's really important and this is just the next gen of that. I'd still be using a blackberry if people had allowed me. But I had to make the transition. And I think that's, you know, really your message is, you know, it's time for us to make the transition to this technology and not to be afraid of it, that in the right environments and used properly, it can really enhance what we do as professionals. And I think as companies, you want to leverage it as a differentiator, but in a very responsible way that is going to really help. People be more efficient at their jobs, not replace, but really elevate what they do. It really just, it really encourages, right? I like to say, like, when I talk to people in their afraid, that it's going to replace them, I say it's not going to replace you. It's just going to supercharge you like anything else. It's going to, you can leverage these tools to move, to be more efficient in what you're doing, so that you can focus on other work that might be more interesting for you, or you can just deeper dive on the things that are important to you. Obviously, the tools are going to get better and better. You need to keep checking. You need to click on those sources and make sure they're real, because they're not all real. All of that, but I think if you do that, it's just so powerful. So young people need to really embrace it, learn it deeply, and then come into these companies and teach us all more about what you know. And I think as lawyers, if we don't understand it, it's really hard to credibly talk about the risks and help people move from risk to trust. And that's ultimately our goal is, how do we create a trusted environment and the frameworks where we can use AI effectively? - Yeah, absolutely. - Vanessa, it's been such a pleasure having you in this conversation. Thank you for sharing your perspectives, your lessons learned and experiences. And thanks to everybody for joining us today. Be sure to subscribe to the Future of Work podcasts, so you don't miss out on future conversations with thought leaders like Vanessa. - Thank you so much. It's been a pleasure. [BLANK_AUDIO]
Podcast Summary
Key Points:
Vanessa Candela's role at Celonis evolved from Chief Legal Officer to Chief Legal and Trust Officer, expanding to oversee information security, IT, business systems, and sustainability, reflecting a shift from a traditional "department of no" to a trusted business enabler.
Celonis uses process intelligence and AI to create a "living digital twin" of business operations, helping companies understand, optimize, and transform their processes for efficiency and sustainability.
A key principle at Celonis is "no AI without PI" (Process Intelligence), emphasizing that AI needs clean data and business context to be effective and trustworthy in enterprise settings.
The company adopts a proactive, risk-based governance framework for AI, including a cross-functional AI governance council, to enable rapid and responsible adoption while managing risks like security, bias, and IP leakage.
Successful AI integration requires focusing on people and change management, such as through training programs and "AI champions," to build trust, dispel fear, and ensure widespread, responsible use across the organization.
Summary:
In this podcast interview, Vanessa Candela, Chief Legal and Trust Officer at Celonis, discusses the evolving role of legal leaders in the age of AI and the importance of building trust. Celonis is a process intelligence company that uses AI to create digital twins of business operations, enabling companies to gain insights, fix inefficiencies, and drive transformation. Candela explains how her role expanded beyond traditional legal functions to include information security, IT, and sustainability, reflecting a broader industry trend where legal officers are becoming trusted partners who enable business growth while managing risk.
A central theme is the responsible adoption of AI. Candela highlights that for AI to be effective and trusted in enterprises, it must be grounded in clean data and process intelligence (summarized as "no AI without PI"). Celonis has established a cross-functional AI governance council and a business transformation office to oversee AI use, ensuring a balance between innovation and risk management. This involves practical guardrails addressing security, bias, and data integrity, anticipating regulatory trends like the EU AI Act.
Finally, Candela emphasizes that successful AI integration depends on people. Through initiatives like AI activation weeks and designated "AI champions," Celonis focuses on change management, skill development, and dispelling fears to foster adoption. She analogizes AI agents to junior colleagues, requiring clear governance, human oversight, and accountability to build trust and realize their full potential in enhancing, not replacing, human work.
FAQs
Salonus is a leading process intelligence software company that uses process mining and AI to create a digital twin of business operations, helping companies understand and improve their processes, fix bottlenecks, and boost efficiency and sustainability.
She started as Chief Legal Officer, then expanded her responsibilities to include information security, IT, business systems, and sustainability, becoming the Chief Legal and Trust Officer as her role broadened to build trust across the organization.
Salonus uses an AI governance council with cross-functional teams to review AI adoption internally and in products, focusing on enabling business while managing risks responsibly through frameworks and change management.
It means AI needs process intelligence (PI) to provide context and clean data for effective enterprise use, ensuring AI outputs are trusted and relevant rather than generic.
They take a common sense, risk-based approach by avoiding high-risk data, implementing guardrails, and focusing on security, data integrity, IP protection, and bias mitigation to align with regulatory concerns.
They run initiatives like AI activation weeks with tailored sessions, appoint AI champions in each department, and emphasize enablement and change management to help employees use AI responsibly at their own pace.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.