Keeping AI under control by balancing innovation, compliance and legal risk
- Press
- Posted 22.09.2026
In an article published in Inflight, Gary Cywie, Partner & General Counsel, Tiago Nogueira, Partner and Iren Butrakova, Counsel, share their insights on the legal and regulatory challenges surrounding Al adoption.
With ever more AI tools being developed, both regulated and non-regulated entities are eager to take advantage of them, but how can they mitigate legal and regulatory risk while not falling behind the competition? The team at law firm Elvinger Hoss weighs in.
What are the biggest missteps you're seeing as organisations rush to adopt AI?
Gary Cywie: Teams want to stay competitive, so they quickly roll out or use an external AI tool, before legal, compliance and IT put up guardrails. This can lead to a loss of control over confidential and personal data. Governance is key.
Mr Cywie, you specialise in technology law. When a client comes to you about a new AI tool, what do you ask first?
Gary Cywie: Before discussing regulation, we usually take a step back to clarify the use case. Who will get access? What kind of data will be fed into it? Will it support a critical function, a client-facing activity or an internal process? And practically, will the tool be running on internal systems, or will it be outsourced, and to what extent? The answers help us to determine notably whether personal data, confidential information or client data are involved, the type of legislation we will deal with and whether the AI Act is even engaged.
The more automated, integrated, and intelligent a tool is, the more difficult it is to pull apart and say, give us back our data. It is in fine a battle between efficiency and regulatory compliance/accountability.
![]()
Tiago Nogueira
Partner
Ms Butrakova, you’re on the asset management regulatory team. How do you start the conversation with a client?
Iren Butrakova: We first work on figuring out the legal, compliance, risk impact of the implementation of an AI tool is going to require, and then we determine which processes need to be adapted or built around it. A lot of what we see involves automating internal processes that are already compliance-heavy. KYC is a good example. And the deeper you get into it, the more you tend to discover things you didn't expect at the outset. The AI landscape itself doesn't sit still either. It changes almost daily, and tools are becoming more deeply integrated with each other, such as to create entire silos or environments, which means the compliance checklist keeps moving too.
Beyond legal advice, what value do you bring to these conversations?
Iren Butrakova: In a lot of cases, we're acting as an intermediary, almost like a translator, between the legal and regulatory side and the technical teams or providers. We're listening to both sides and making sure everyone's actually on the same page, because those two groups don't always speak the same language. That's not traditional legal work, but that’s one way we bring added value – as legal advisors, we need to understand the technical context, to bridge those different perspectives, and to tailor our advice to an increasingly complex intersection between Law and Tech.
How is signing a contract with an AI provider different from a normal IT deal?
Tiago Nogueira: Various particularities may be highlighted. One is surely, that exiting a contract with an AI provider is much harder than with conventional ICT. The more automated and integrated the tool is, the harder it is to say "give us our data back" and actually walk away cleanly. Entities need to think about vendor lock-in upfront, and have an explicit exit plan for what happens if the service goes down, or the provider goes bankrupt. Regulators will also want to see that plan explained very clearly. That's really where concentration risk comes into it, and it's not something you can work out after the fact.
Can a single AI query end up involving several parts of the firm at once?
Tiago Nogueira: Yes, this is even generally the case. A client will come in with what looks like a simple services agreement project or professional secrecy question. Let’s say, they want to roll out a new AI tool to staff, and they’ll need to share employee data to set up the accounts. Once we dig in, though, we sometimes find they never asked the provider the right questions about how that data will actually be used. What started as straight forward project can turn into a complex file touching several areas such as banking, funds, labour law, or whatever the sector calls for.
How is the firm keeping pace with all of this?
Gary Cywie: We recently set up an internal AI Think Tank. Champions from each practice group— regulatory banking, investment funds , technology and IP law, litigation, and so on track market trends to identify recurring client needs, structure practical solutions and develop multidisciplinary services that reflect how clients actually deploy AI in business. It's part of how we shape the firm's overall AI strategy, rather than reacting case by case, not just reacting to the AI Act or the latest tool. We'll also be addressing these topics at our Annual Fintech Conference on 16 September in Luxembourg City. Panellists from across the sector will take a deep dive into how AI and automation are reshaping finance, and how digital operations are scaling up across the asset management industry.