The Gap Between Using AI and Actually Being Ready for It
Eighty-eight percent of businesses are using AI. Only eight percent have the frameworks in place to use it ethically, legally, and operationally. That staggering gap is exactly what Episode 266 of the Localization Fireside Chat digs into, with Robin Ayoub welcoming back Sukhi Dhillon Alberga, co-founder and legal strategist at BLS Consulting. Sukhi is a lawyer who has spent years watching businesses rush headlong into AI adoption without stopping to ask the most basic questions: where is my data going, who is accountable for it, and what happens when something goes wrong? The conversation started as a preview of a bigger roundtable planned for September 10th with colleague Andrew Terrett, but it quickly became a standalone masterclass in why governance cannot be an afterthought.
Sukhi draws on her work chairing the Canadian Legal Innovation Subcommittee and building a Law Society of Ontario approved legal tech platform to explain why the marketplace has already shifted. Early adopters who jumped in two years ago are now feeling the pitfalls. Companies that spent months on the fence are now in implementation mode, but without the change management or oversight structures to back it up. As she put it during the conversation, the question is no longer whether generative AI is going to be used in your organization. That ship has sailed. The real question is whether you are equipped to handle what comes with it.
Shadow AI, Data Sovereignty, and the Risks Nobody Is Talking About
One of the most valuable stretches of the episode is the discussion around shadow AI and data sovereignty, two concepts that most business owners have not put on their radar yet. Shadow AI refers to the ways employees inadvertently or otherwise feed sensitive company information into public-facing AI tools, even when IT policies try to restrict access. Robin makes the point bluntly: close the tool on the company laptop and your staff will use it on their phone. The genie is out of the bottle. What that means practically is that client data, internal IP, and employee records can end up training models or sitting in data centers in jurisdictions with very different legal protections than your own.
Sukhi connects this to data sovereignty and the US Cloud Act, explaining that if a business uses a US-based AI provider, the American government can potentially compel that provider to hand over data, including yours. For Canadian businesses, PIPEDA and the Privacy Commissioner’s enforcement powers make this more than a theoretical concern. Violations can cost up to one hundred thousand dollars per incident. And as Robin points out, legacy companies with existing contracts face an additional exposure that often goes completely unnoticed: if those contracts define how data is stored, transmitted, or protected, deploying AI across your operations without revisiting those agreements could already constitute a breach of contract right now.
What Good AI Governance Actually Looks Like in Practice
BLS Consulting was built precisely to close this gap. Sukhi is clear that having a legal department is not the same as having AI governance. A legal team can draft a policy, but governance means understanding where AI is actually being used inside your organization, whether it is generating real ROI or just creating the appearance of efficiency, who inside the business is accountable when something goes wrong, and what the incident recovery plan looks like before you ever need it. That last piece connects directly to the insurance conversation Robin raises, where general liability coverage has to be revisited in light of AI exposure.
The human factor runs through everything Sukhi says in this episode. Technology can drive efficiency. It can help a business take on more clients, compress timelines, and surface insights from data at a scale no team could match manually. But the relationship between people, the integrity of how a business treats its clients and its employees, and the accountability structures that sit above any AI system, those are not things a model can substitute for. As Sukhi closes the episode, her message to business owners is to be curious rather than afraid, get informed, assess your own needs honestly, and if the blind spots feel overwhelming, bring in people who can help you see them clearly.
If this conversation prompted you to think differently about how your organization is handling AI risk, the full episode is worth your time in whatever format works best for you. Watch on YouTube if you want the full back-and-forth energy of this impromptu recording, or Listen on Simplecast if you prefer audio on the go. And keep an eye out for the follow-up episode with Sukhi and Andrew Terrett, where the conversation expands even further into practical AI governance for businesses of every size.
Leave a comment