AI, Cybersecurity & Critical Thinking: Inside a Law Firm’s Real AI Strategy

Posted on September 10, 2026 in AI

 


You know AI is moving fast. But do you know how fast your business needs to move with it?

In this episode, Marco Nicosia sits down with Robyna May, CIO of McInnes Wilson Lawyers, and REDD CEO Bryan Rogers, to unpack what it really takes to keep pace with AI without losing control.

You’ll hear why having Co-Pilot switched on isn’t the same as having an AI strategy, why zero-day vulnerabilities are becoming exponentially harder to manage, and why quantum computing could turn today’s encrypted data into tomorrow’s liability.

You’ll also get a candid look at governance, tool sprawl, and the very human question sitting underneath it all: how do you protect critical thinking, in your team and in the next generation coming up behind them, when the answer is always one prompt away?

If you’re leading a business through this shift, this conversation will challenge how you’re thinking about AI, security and accountability.

 

#REDDTechnologyPodcast #CyberSecurity #BusinessLeadership #DataSecurity #AIStrategy

 

00:00 – Welcome & Guest Introduction
00:51 – The Pace of AI: Can Businesses Keep Up?
02:00 – Claude’s Delayed Release & the Zero-Day Threat, Explained
05:19 – Legal Data, Quantum Computing & the PII Time Bomb
07:14 – Is Microsoft Co-Pilot a False Sense of Security?
09:58 – Their AI Toolkit — and Policing How It’s Used
15:24 – What Excites Them: Agentic Workflows & Claude Designer
17:03 – Finding the Human-AI Balance (Avoiding “Brain Fry”)
19:11 – Leading AI Change: Strategy, Sprawl & Protecting Junior Skills
28:04 – Fast-Forward 7 Years: Critical Thinking, Education & Accountability

 

If you would like to discuss any of the topics discussed in this episode further with a REDD expert or if you would like to be a guest on the show, please get in touch either via our website, [email protected], or through any of the links below. https://redd.com.au

https://www.linkedin.com/company/redd-digital/
https://www.linkedin.com/in/nicosiamarco/
https://www.linkedin.com/in/bryan-rogers-171423104/
https://www.linkedin.com/in/robynamay/


 

READ THE FULL TRANSCRIPT HERE

1
00;00;06;03 – 00;00;07;15
Speaker 1
Well, thank you for joining us.

00;00;07;18 – 00;00;33;26
Speaker 2
Thanks, Marco. It’s absolutely lovely to be here. Great, great. Thank you for making time. So today we have Robyna May. Well, I introduce yourself? Sure. So. Yes, my name is Robyna. I’m the CIO over at McInnis Wilson Lawyers. So basically, look after the IT team over there, as well as our strategy as a law firm regarding what we’re doing with our technology and knowledge space, and have been working with the red guys since late last year in terms of our cybersecurity piece.

00;00;33;27 – 00;00;35;09
Speaker 2
Yes, amazing. And cybersecurity.

00;00;35;09 – 00;00;54;09
Speaker 3
Is what we’re going to be talking about today, as well as AI. And also joined by Bryan, CEO of REDD. Hello and myself. So we do have a few questions for you. Great. If you don’t mind, the first thing is the pace of AI, right? And in a world where AI develops so quickly and it’s getting more and more autonomous.

00;00;54;11 – 00;00;58;15
Speaker 3
Do you feel like businesses are ready to keep up with the space?

00;00;58;16 – 00;01;16;28
Speaker 2
I think that’s a mean. It is a difficult thing to keep up with. I think even if you’re very, very interested in it and keeping it very close eye on it, it’s still feels quite overwhelming. So I think potentially, particularly for business owners, and when you’re reporting to a board there, obviously the scope of what they’re worried about is quite broad.

00;01;17;04 – 00;01;41;15
Speaker 2
So I feel very privileged to work within an IT team that is really interested in all of this stuff. AI from a productivity perspective, but also AI from a cyber perspective. And so they very much do keep an eye on everything that’s going on, as well as being supported by you guys and Arctic Wolf. And I think what that allows you to do then is to surface the things that really do need some attention to the people that need to worry about it.

00;01;41;16 – 00;01;57;24
Speaker 2
So I do feel like potentially people are just feeling really overwhelmed due to the amount of information. And if you can have a team in play that allows you to filter that information to what’s really relevant and critical to that business owner audience, then I think you’re in a much better position.

00;01;57;26 – 00;02;07;22
Speaker 3
Okay. Thank you. And did you releases like clause less release latest release which they’ve held back for security reasons. Does that worry you in the business?

00;02;08;00 – 00;02;12;24
Speaker 2
Oh, absolutely. So the whole we’re all a bit obsessed by the whole mythos project class when.

00;02;12;25 – 00;02;15;01
Speaker 4
We could sort of. Yeah.

00;02;15;03 – 00;02;15;17
Speaker 2
It’s.

00;02;15;21 – 00;02;17;13
Speaker 4
It’s it’s terrifying.

00;02;17;14 – 00;02;17;19
Speaker 2
And.

00;02;17;19 – 00;02;18;25
Speaker 4
It’s super interesting.

00;02;18;25 – 00;02;39;16
Speaker 2
At the same time. So, you know, this idea that for a long time and now my original background. The first thing that I did in law was actually in software development. And as a software developer, I can’t say I was terribly concerned about cybersecurity. And I dare say this is probably a feature of a feature, not a bag of many software developers.

00;02;39;17 – 00;03;03;19
Speaker 2
And when you think now that we have a tool that’s going to be able to discover those zero day vulnerabilities in code that has existed potentially decades, that others just have not been able to surface, I mean, the attack factor just becomes exponentially so much larger. And then when you have the other side of AI, which allows you to generate those attacks at a much larger scale in terms of the agents doing the work for you.

00;03;03;20 – 00;03;23;13
Speaker 2
Yeah. I mean, it is quite terrifying. And while I think we’re all quite relieved that anthropic made that decision to launch project last week so that they are incorporating those bigger players so that they do have that first access to be able to patch those zero day vulnerabilities. It won’t be long before the other AI players catch up because it never is.

00;03;23;17 – 00;03;34;25
Speaker 2
Yep. So if we’re seeing anthropic being able to do this. It’s not going to be terribly long before others do. So. Yes, a long answer and then a short answer. Does it worry me? Yes it does.

00;03;34;27 – 00;03;45;19
Speaker 3
Yeah, of course it does. A good point there, which is day vulnerabilities. Brian, you might explain. And then our world what zero the ability is or your best guess as zero the vulnerability.

00;03;45;20 – 00;04;05;06
Speaker 5
Okay. Essentially it’s a type of vulnerability that you only find out about for the first time what is being used actively until you find out about it on day zero. When it’s happening, you don’t have any warning about it. No one else has seen it before. No one knows anything about it. It’s it’s life that’s happening from my perspective, very, very similar.

00;04;05;09 – 00;04;41;17
Speaker 5
There’s a lot of a lot of risk and fear and uncertainty around what it can bring and what it can bring is a concept. But even more generally, the older models, so to speak, still had the same the same fears for a lot of business owners and a lot of our lot of our clients as well, around the readiness moving so quickly, like you said, and it’s exposing so much you didn’t realise was necessarily a problem that if you just dive right in, you’re finding out about those like like zero day run, if you’re zero day problems that you didn’t realise were gaps that you need to think about in advance.

00;04;41;19 – 00;04;56;19
Speaker 5
But on the flip side, if things like Project Glass Wing can surface those issues before others can find them and you can find your own kind of zero day improvements, that’s that’s a super powerful tool to have access to.

00;04;56;20 – 00;05;01;23
Speaker 2
Yeah. It’s just how long can you keep that cool so that it’s the good guys versus the bad guys.

00;05;01;26 – 00;05;04;02
Speaker 5
Zero days. Yeah, yeah, yeah.

00;05;04;04 – 00;05;27;04
Speaker 3
I was seeing the action movie where somebody tries to burn it in a dock and he’s like, we’ve never seen something like this before. And that’s that’s becoming reality. Right. So and comparing that to working in the legal sector, private information is everything. Does what scares you more these tools of AI or how users are using AI within a company or business?

00;05;27;06 – 00;05;48;22
Speaker 2
Yeah, it’s it’s a little bit of both to be honest. So we are incumbent with our with our clients to keep the data onshore for one thing. So, you know, as soon as someone puts something into an external AI tool, we’re really breaching what we’ve said we’re going to do with our clients. So we are doing a lot of education in that space.

00;05;48;24 – 00;06;17;06
Speaker 2
We’re looking at DLP and all the rest of the technical tools we can put around that to try and protect ourselves. At the end of the day, I think education plays such a huge piece there. Then in terms of sort of the tools themselves, we’ve talked a little bit sort of about that. One of the things that I’m currently really interested in going down a bit of a rabbit hole is the whole idea of quantum computing and coming to when a lot of the encryption that we have come to rely on is going to be able to be decrypted.

00;06;17;06 – 00;06;44;05
Speaker 2
And, you know, if that’s 15 years in the future. And Google recently said it might be less of a time frame than that. If you think about the data that we are holding as a law firm, we need to hold that for some period of time, minimum seven years and sometimes more. So we’re now moving into a world where the encryption we’re relying on at the moment is fine for now, but if we get to a point of quantum computing where we’re able to decrypt and we need to encrypt things in different ways, we need to kind of think about that now because of the whole harvest now, decrypt later.

00;06;44;05 – 00;07;03;25
Speaker 2
So I think the pressure on our PII, and particularly as law firms, as we’re going into a year where we need to implement AML and we are potentially holding even more PII. Yeah, yeah, that’s definitely a concern. And then just augmenting all of that with the AI that can sit on top of that, which allows the the bad guys to kind of attack at scale.

00;07;03;25 – 00;07;08;11
Speaker 2
So yeah, yeah, yeah. All of its are concerned. All of it would keep you up at night if you let it.

00;07;08;13 – 00;07;31;00
Speaker 3
Yeah. Yeah. Let’s yeah. We’ll talk about something positive in a second. But listen there is good I and Betty if you want to put it that way there’s AI that makes your whatever you put in public and I that depending on your level of enterprise can keep your information safe. Microsoft Co-Pilot has been used, for example, in a lot of enterprises and go like this is the safe AI.

00;07;31;02 – 00;07;33;00
Speaker 3
Is that a false sense of security?

00;07;33;01 – 00;07;56;16
Speaker 2
I think there elements where it is a bit of a false sense of security. So I mean, you do have the reassurance that your data is staying within your perimeters, but you also need to look at, well, how am I securing my data? How am I making sure that things within my environment aren’t visible to those that that don’t necessarily need to see someone’s salary or someone’s complaint about something, etc., etc..

00;07;56;16 – 00;08;15;07
Speaker 2
So I think there’s that element of it in terms of just being sure about your own, both your data security and I think also your data quality. So within a law firm and typically within a law firm, to be fair, our documents are residing inside a DMs. It’s highly unlikely it’s within the Microsoft environment as the, you know, the actual record.

00;08;15;09 – 00;08;36;28
Speaker 2
But if you think about the fact that you were wanting to leverage AI to surface the best possible, you then need to have a good quality data set that represents that. So I think there is that element of co-pilot feeling safe without investing that time in sharing data set. I think the flip side of Co-Pilot is it feels like this really, really easy answer.

00;08;37;02 – 00;08;53;26
Speaker 2
It’s really difficult to turn it off. You kind of just you are getting it. You’re inheriting it. It’s not, you know, you’re not making a purchasing decision. Really. Microsoft has just decided this is the way of the future. We’re going to roll this out as a feature within our products. So it’s part of the infrastructure. It’s not a tool you’ve decided to buy.

00;08;53;28 – 00;09;14;14
Speaker 2
So part of that I think feels comfortable because you can tick your AI box. You can say, yeah, we’ve got on our environment, we’re doing really well, but you’re not making any of those strategic decisions that would have ordinarily come along with when you’re actually thinking about a purchase. So just because you have AI available in your environment through Co-Pilot doesn’t mean you have an AI strategy.

00;09;14;14 – 00;09;26;21
Speaker 2
It doesn’t mean you have an AI policy. It doesn’t mean that you’ve really thought very critically about how you’re going to leverage that AI. So I think for those reasons, it can feel a little too safe. Yeah, yeah, yeah.

00;09;26;22 – 00;09;42;29
Speaker 3
And those policies we’ve seen are a lot of companies have policies which is used with AI within moderation or something, which is usually I safely. And that’s end of policy. Right, right. What what do you think. You know, given this this breakfast.

00;09;43;01 – 00;09;55;08
Speaker 5
Room there. Yeah, sure. In the legal world they love, love that kind of talk. Yeah, yeah, yeah. Yeah. Look, have you guys got a flavour that you’ve kind of picked in the AI space? You said this is the one we’re going to.

00;09;55;08 – 00;10;13;05
Speaker 2
Work with. Yeah, so we use a bit of a combination. So we use co-pilot chat and co-pilot co-pilot chats a bit of an interesting beast at the moment. So that’s basically the one that you get for free. And they keep adding things to it. So it it starts to appear more and more like three, six, five version you do pay for.

00;10;13;06 – 00;10;14;22
Speaker 5
Yeah. I don’t know how to tell the difference.

00;10;14;29 – 00;10;34;08
Speaker 2
Yeah. It is a little difficult to tell the difference between the two and we. That’s fine. People can use that for you know basically admin casks is what we encourage people to use. For that we’ve implemented the document management system. Net documents with its AI capabilities. So we’re in NDI Max customer, which means that we can leverage AI within.

00;10;34;08 – 00;10;53;03
Speaker 2
Net documents itself, which means that we inherit the security within our DMs. So that’s where we want people to operate when they’re dealing with their documents. And then we’ve also invested in Lexus A+, which is basically where we want people to leverage AI for their research. So we’ve we’ve sort of tried to align tools with various purposes. Yeah.

00;10;53;09 – 00;11;11;08
Speaker 2
So we’ve sort of settled on kind of that that stack for the moment, and we’re definitely open to to other things is obviously a lot within the legal market. Harvey and Laura, obviously a lot of people have implemented those and are talking about those tools, but at the moment we’re just wanting to explore what we have really and just try and understand it, see where the gaps are.

00;11;11;10 – 00;11;29;07
Speaker 2
Obviously, we’re still in a space where there’s an awful lot of Venn diagrams and overlapping in terms of capability. So we also are we’re not wanting to be too much of a late mover, but we are also a little cautious of point solutions that might get gobbled up, you know, within the near future.

00;11;29;08 – 00;11;49;15
Speaker 5
Yeah, yeah. Because one of the, one of the challenges with is a very loose segue from Marco’s question around the policies that don’t really dictate how use AI, but kind of guide, you know, safely within reason, avoid sensitive information that don’t actually tell people what they need to do. One of the challenges is, how do you police that?

00;11;49;20 – 00;12;13;03
Speaker 5
And when and how do you know that people aren’t using it safely or aren’t using the right kind of manner? And the more tools you have, the harder it comes to gather all that information and say, what kind of governance can we put in place to actually learn from what’s happening, and then apply retrospectives to say, right now we can teach people what is and isn’t safe using empirical examples.

00;12;13;06 – 00;12;37;17
Speaker 5
So I think that’s one of the challenges that people face and one that we face as well. In a similar vein, co-pilot is kind of a preferred mechanism for people do administrative tasks, but again, somewhat relies on people not to put the wrong thing in there because there isn’t a technical limitation that would stop them, you know, offloading something they shouldn’t or saying, can you interpret this and putting in a document that they shouldn’t?

00;12;37;19 – 00;12;55;20
Speaker 5
Again, as you said, comes back to the LP piece. It comes back to the tagging and having the right data structures and quality and governance in your data itself. But that’s not something that many organisations have or have the time to or need to have invested in previously. And now it’s really becoming obvious that they do.

00;12;55;21 – 00;13;12;20
Speaker 2
Yeah, we have having a lot of projects kind of all hit at once because of this. Yeah. So yeah, the data classification DLP, you know, all of that is front of mind for us as well. Yeah, there’s a lot more impetus to get those things done in the context of AI than there used to be before.

00;13;12;21 – 00;13;30;06
Speaker 5
Yeah, because that gives you a mechanism to essentially a technical mechanism to stop wrong data flowing to the wrong place. But short of that, how do people, you know, how do you keep an eye on how people are using AI within your organisation? Are there other mechanisms you’ve seen work or try?

00;13;30;09 – 00;13;37;27
Speaker 2
So we often get asked, yeah. Someone wants to present us some work and go, do you think they used AI for this?

00;13;37;28 – 00;13;39;01
Speaker 5
That’s true. Is it a long.

00;13;39;09 – 00;13;40;24
Speaker 1
Dash there?

00;13;40;26 – 00;13;41;25
Speaker 2
Use some Zs.

00;13;41;26 – 00;13;43;11
Speaker 3
And some bold in the wrong place.

00;13;43;12 – 00;14;04;05
Speaker 2
It is. Yeah, it is not this, but it is that, you know. Let’s choose. Yeah, yeah. Divide us. Yeah. All of those tells one thing that we’re actually finding interesting and we don’t delve into what in great detail because there’s an element of privacy there as well. So obviously within Co-Pilot you can actually see the prompts that people are using.

00;14;04;05 – 00;14;29;22
Speaker 2
So you can sort of go through those and try and understand, you know, what are we seeing people using things for? But that level of transparency and visibility doesn’t obviously exist within all of the AI tools that you’re using. And DLP is obviously really important in this space. But at the same time, it’s always just kind of introducing frictions so that people, you know, pause and it gets really hard to do what they want to do.

00;14;29;22 – 00;14;58;08
Speaker 2
But if someone desperately wants to cut and paste something, or if someone desperately wants to just voice to text something, you know, there’s there’s always those bits around the edge. So I think, again, it just really does come back to that education piece. And I think getting those people in your firm who are really enthusiastic about it and have found in great use cases and are using it really well to try and spread their word more across the firm, because you will get those people who’ll use it and then say, oh, this isn’t for me.

00;14;58;08 – 00;15;07;28
Speaker 2
This doesn’t really work. This has given me entirely the wrong answer. Or, you know, they’ve given it, you know, a one sentence prompt and expected it to do their work for the day.

00;15;08;00 – 00;15;11;05
Speaker 1
Yeah. Well my job. Yeah, yeah. Pretty much.

00;15;11;07 – 00;15;27;19
Speaker 3
I live to read the answer. Right. And some people just got to give the prompt and copy and paste an email. Right. But let’s talk about something exciting and it’s all, all doom and gloom. Right? I can bring a lot of things that are positive. Is there anything particularly that excite you about how AI can help you in your business or business in general?

00;15;27;25 – 00;16;00;04
Speaker 2
Yeah, I think where we are at the moment, I think a lot of people are probably here. It’s very much a personal productivity tool right now. Like I think that’s the way people are tending to use it. So those that are leveraging it are leveraging it quite well. They’re finding it’s helpful within their work day. But what I’m probably more excited about is when we get to a point where it’s actually integrated properly within workflows, potentially where we are using agents between points and securely passing off the control in that way, and just thinking about how we might be able to reorganise businesses utilising that.

00;16;00;04 – 00;16;24;19
Speaker 2
I think that cultural change that can be supported through AI is quite interesting. I think we’re still away from that. In terms of the tools themselves. I was playing with Claude Designer yesterday and that’s that was that was pretty cool. Yeah, there’s a number of just sort of little bits of software that would be helpful in firms. You know, calculators are a big one.

00;16;24;22 – 00;16;46;02
Speaker 2
Lawyers sometimes make a blanket statement, but a lot of them don’t love math, and a lot of them don’t love Excel. But if you can create something that helps calculate, you know, basic settlements and 5050 rules and things like that, and tools like Claude Designer and which is a lot more accessible than Claude code. You don’t have to set up GitHub repository or anything for it.

00;16;46;03 – 00;16;59;27
Speaker 2
You know, things like that I think will be quite exciting once people understand. Oh, I can develop this little piece of software that I’ve always wanted to help me in my work for this thing that I hate doing, and then just being able to create those without sort of any friction.

00;16;59;29 – 00;17;22;05
Speaker 3
Yeah, that’s super interesting. So how do you control that in a way that’s human, right. Because the AI, you know, it can run 24 hours a day. 365 for years on end, we get exhausted after a while, right? So how do you leverage the human side in terms of I’m not falling behind with my AI, I’m using it the right way.

00;17;22;06 – 00;17;27;22
Speaker 3
You know, I’m going to implement this tomorrow. Something else is going to come out. What’s the balance? Is there a magic trick.

00;17;27;22 – 00;17;28;05
Speaker 1
For it?

00;17;28;07 – 00;17;32;18
Speaker 2
Oh, I don’t think there is. If there was.

00;17;32;20 – 00;17;34;27
Speaker 1
A very level of.

00;17;35;00 – 00;17;57;15
Speaker 2
I think this whole idea of brain fry where because you’re able to pass so much of the low hanging fruit and the low level work over to AI, and if you do that constantly, and then all you’re kind of left with is orchestrating that AI and then investing your brain just in the really, really hard stuff and that, you know, this has already come up as a thing that that’s not great for our brains.

00;17;57;15 – 00;18;22;12
Speaker 2
We almost need that rest of that dumb work. So there’s an argument for not necessarily outsourcing all of that into AI. But I do think there are definitely elements of any job that could benefit from the use of AI. And then it’s just a matter of monitoring that for yourself. So I know we talk about AI policies in the context of our firms.

00;18;22;12 – 00;18;46;15
Speaker 2
I think it’s actually quite useful to just reflect for yourself and think, well, what’s. Where are my boundaries? Where are my hard lines with AI? So if you’re someone who really, really enjoys writing and a lot of lawyers do, obviously it’s a huge part of the job. You might say to yourself, you know what, I’m going to limit the amount that I use AI to generate text for me because I really want to keep in control of those skills, and it’s something that I really enjoy in my job.

00;18;46;17 – 00;19;08;25
Speaker 2
So I think that balance might be quite individual. There might be other people who say, you know what, I hate writing. I love putting that into AI. But don’t tell me about this calculator because Excel’s my jam and I love doing it that way. So I think it is helpful to think about it in the context of the stuff that you personally really love doing, so that you hold on to those skills and then thinking about it in the context of, well, what wouldn’t I mind giving to someone else.

00;19;08;25 – 00;19;09;25
Speaker 1
To do? Yeah.

00;19;09;26 – 00;19;33;15
Speaker 3
And how does this translate to an executive role like yours? CIO? You have to think of the strategy and not only the technology. Brand new piece of art coming in, brand new piece of technology coming in. I bet bombarded by everything that’s coming in. Is it gone from, you know, data ingestion to data filtration and actually trying instead of receiving a lot of information, trying to just push away a lot of information, just keeping the one that.

00;19;33;17 – 00;19;58;27
Speaker 2
Does it. Yeah, I think the role has always been a little bit like that to be honoured, to be honest. You’ve always had to filter a little bit of the wheat from the chaff. I think from my perspective, what I’m seeing is it is the kind of technology that is so pervasive and everyone’s talking about it and it’s in the media, so there’s a lot of interest in it from like a board perspective, which is not necessarily the case around a lot of technology.

00;19;59;01 – 00;20;38;10
Speaker 2
So for me, in this particular role, it’s probably quite interesting in terms of leveraging that interest in technology, because it does mean that you get to have probably, maybe a little bit more of a say than maybe you did previously. So in terms then of kind of everything coming all at once. As I said before, probably our project load has uplifted, not because of AI or necessarily implementing a lot of AI projects all at once, but because of that, those security projects that sit around it to make it feel safe, as well as just trying to ensure that the whole the business is engaged in this, because AI obviously has a technical component, but it’s

00;20;38;10 – 00;20;51;18
Speaker 2
something that touches everyone in such a profound way that it cannot just rely on the technology department to be able to push it out, or to encourage people to use it does need to be a whole firm project.

00;20;51;20 – 00;21;01;12
Speaker 3
Of course, and it’s a whole change management side of things and cultural impact on, you know, a tool is only as good as its users in a way. And the same goes for it, doesn’t it?

00;21;01;14 – 00;21;33;16
Speaker 5
Yeah. So for us and the type of one of the core things that we do in the managed services side, it is very process driven and procedural in that you can have a particular type of problem, and all of the technicians should ideally follow a similar triage and initial troubleshooting and support process with what you’re describing before around people finding the right balance between what they like doing within their jobs and what they need to achieve within their roles.

00;21;33;17 – 00;21;50;25
Speaker 5
There is a level there of a level of nuance to how people, what people will be developing, right? If things like or design to make it easy for you to build your own agent that works in a certain a certain way, you can end up having a lot of different but somewhat similar types of tools to do the same thing.

00;21;50;25 – 00;22;23;14
Speaker 5
And then the type of work that that your firm does is that does that align with how people do their work? I’d imagine there’s a level of subjectivity to any of the the lawyers, the clerks, even the early people earlier in their career around how they would tackle a particular problem. We don’t necessarily have that on our side, but that does behove the type of model that you’re talking about there where someone might have their own kind of personalised co-pilot or agent that works with them, and that does that align with how most of the lawyers and most of your team do work?

00;22;23;15 – 00;22;54;29
Speaker 2
I think so, so we do have some areas that are highly process driven. Yeah. And so I think for them the benefits of AI might be a little more collaborative within their teams. We do want to avoid just having huge amounts of sprawl obviously, because that’s difficult for everyone to manage. But even when you talk to a group of lawyers about how they’re leveraging the tools at the moment, which are mostly within still within that chatbot interface, they are very much, as I said before, that personal productivity tool.

00;22;55;04 – 00;23;16;21
Speaker 2
Some will lean more heavily into the research space, some will lean more heavily into the I more user just for my admin. And because, you know, I find it very because I get a huge volume of emails, maybe the other person doesn’t get a huge volume of emails. So I think even now there is that element of I’m going to use it for the bit that really fits in with my pain point.

00;23;16;21 – 00;23;38;14
Speaker 2
And whereas I do think we obviously need to be conscious of sprawl, where people are then creating applications and agents, that’s probably a kind of a different layer to just using a chatbot, but I think it will probably get to a point where it’s not so different from just the applications you use. So you might be a person who’s heavily in Excel, but that doesn’t mean the person next to you is using Excel at all.

00;23;38;15 – 00;23;46;04
Speaker 2
So I think it’ll probably just align with what people’s jobs are in the in the way that we currently have with applications.

00;23;46;05 – 00;23;46;12
Speaker 1
Yeah.

00;23;46;12 – 00;24;12;25
Speaker 5
I find that quite interesting to reflect on a little bit, thinking about how AI changes, not not the need for different types of roles, but in, in that sense, how those roles are structured and what what what that type of role is needed for in our space. I think that can be quite scary for people, especially people who are starting an IT career and potentially need that training in their coaching.

00;24;12;25 – 00;24;42;01
Speaker 5
They’re coming straight out of high school, maybe, or they’re coming with very little experience in that space. And part of what we’ve needed to do over time is build the right frameworks, onboarding tools, processes, training to teach someone okay. When you get a problem that looks and smells like this, these are the steps you work through. These are your first principle troubleshooting, triage, basic approach and having that very regimented, very procedural and very repeatable, it’s kind of necessary for them to learn.

00;24;42;04 – 00;25;02;10
Speaker 5
So from my perspective, I wouldn’t be as comfortable having people build these tools themselves to start with. I think I would want that level of control initially to say, right, it is getting pushed out from a central place. This tool is for this purpose, and it aligns with what we’re trying to achieve from a learning, coaching and development perspective.

00;25;02;11 – 00;25;09;22
Speaker 5
I think that might just be something like different types of businesses, different different organisations, because I don’t think that would really work in your scenario.

00;25;09;23 – 00;25;10;15
Speaker 1
As well.

00;25;10;22 – 00;25;34;27
Speaker 2
Yeah, I guess for us where we’re concerned is so as a lawyer, particularly, particularly in the drafting space. So, you know, even as I was first emerging, this idea of generating text was kind of where it started. And that’s starts to get quite terrifying to lawyers. If a, if an AI can generate a brief or whatever, in the same way that a lawyer might be able to, and I don’t think it’s there.

00;25;34;29 – 00;25;56;25
Speaker 2
Not at all. And particularly not within an Australian jurisdiction where it doesn’t have a lot of its grounding. But I think what I know the lawyers that I’m talking to in this space are concerned about is just making sure that early years lawyers still have those skills, still able to, you know, look through a document and understand what should catch their eye, where they should be finding the issues.

00;25;56;26 – 00;26;18;27
Speaker 2
They still need to have those skills. They still need to be able to put together a cogent argument. And I think there is a bit of a fear that if you come in as an early lawyer and you pass all that over to AI, that you’re just going to lose something. Yeah. So I know part of what we have in our AI strategy is trying to protect that human element and that human skill.

00;26;18;27 – 00;26;40;24
Speaker 2
So yeah, I also think in terms of developing tools, it’s one of those it’s sort of getting into that citizen development kind of programs where you do want to see what everyone’s using and everyone’s doing because, you know, if it’s working for team A, it might work for team B, or if, you know team has already done it, you don’t want team B to replicate that effort, even if it might be a significantly reduced effort.

00;26;40;26 – 00;26;49;09
Speaker 2
So I still think you need some level of governance around it, even as this sort of technology democratises the ability to build software.

00;26;49;11 – 00;27;15;14
Speaker 5
Yeah, it’s something we definitely encourage here. We want people to think about how could these tools augment what you’re doing? How can they support what you’re doing? How can they validate what you’re doing? We’re not we’re definitely not at a point where they’re doing any of those actions, but they’re suggesting the prompting that they’re supporting. So yeah, reflecting on what what you’ve said there, I think one of the challenges we might see over the next couple of years is how do we manage that sprawl?

00;27;15;15 – 00;27;45;19
Speaker 5
How do we encourage that innovation and encourage people to leverage these tools so that we can remain efficient and remain on that leading edge, but not end up creating 50 different ways, the same thing that really should be done in 1 or 2 from the most efficient perspective, and to give that foundational consistency, because from each of those that then escalate to the next level, and if they’ve got 50 different ways of doing that, and it might have come from 50 different sources, we start getting exponentially large in terms of the the many, many different ways to skin a cat.

00;27;45;20 – 00;27;46;08
Speaker 1
Yeah.

00;27;46;09 – 00;28;02;20
Speaker 2
And we’ve done this before. Right. We’ve done it with document management. Like we do manage things. We just probably haven’t thought about managing developed applications in the same way, because it’s been such a small sort of set and controlled things. But I think we can take things we’ve learned from from other places.

00;28;02;21 – 00;28;04;09
Speaker 1
So let’s fast forward, right?

00;28;04;11 – 00;28;40;23
Speaker 3
Let’s fast forward from a person he or she might be in school now and finishing the last couple of years doing a little degree, which takes whatever time it takes at least five, I would say. Yeah, if you’re good at it. And then so let’s fast forward seven years, something like that. And assuming AI is gonna develop more or less constantly, although from what we know is probably going to accelerate and touching into what you said in theory of keeping those skills, how are you going to balance, generally speaking honestly, personally, how are you going to balance as a business AI versus loss of control?

00;28;40;24 – 00;29;04;23
Speaker 3
How much do you give to your iris? How much? How much are you going to lose control of your own ways of working? And more importantly, are we at risk of losing critical thinking and becoming more impulsive? Because as soon as we have a question, we feed at UI, we get the response and that’s it. We lose that ability of, you know, questioning literature and questioning how things work.

00;29;04;24 – 00;29;30;06
Speaker 2
Yeah, I think this is I, I have a 17 year old, so I’m concerned about how he uses AI and his assignments already for that reason, because they’re not asking you to just ask an AI and regurgitate an answer. That’s not what they’re trying to teach you. They’re trying to teach you how to critically think. And so just keeping the analogy with my teenager, he had to write a book report in the character, taking on the persona of one of the characters in this book.

00;29;30;08 – 00;29;54;06
Speaker 2
And obviously, I knows about this book. It’s a text that high schoolers use. And I said to him, well, why don’t rather than do that? Why don’t ask the AI to be the persona of another character in the book, and you’ll take on the persona that you’re meant to be writing in, and just have a conversation with the AI in that kind of context about the themes of the book, which is kind of a fun way that still preserves some element of critical thinking.

00;29;54;12 – 00;30;13;14
Speaker 2
So I think we need to look at the ways that we’re using AI. And I’m really hoping they’re doing this within the education space, because what will be very difficult in that situation you’ve just described, if we get law students who come to us who haven’t been challenged to critically think within their education, because that’s part of why you go to university.

00;30;13;15 – 00;30;48;09
Speaker 2
We were just talking before about our own IT degrees and saying that what you learn there technically is probably outdated by the time you graduate, but the basics of what you’re learning and that ability to critically think, that ability to understand the building blocks of knowledge that’s always useful. So we need to make sure I think and I do think as law firms, we should be working more closely with the universities in this space so that we are preserving that and that ability and that we’re using AI to make that stronger rather than weaker in terms of them when we get to the workplace.

00;30;48;10 – 00;31;22;17
Speaker 2
Again, I know a lot of this has come back to this idea of education, but I do think it’s a really, really important piece in this whole thing. And I do think we need to think really critically about what we are providing, if it can just be provided by II, if what we are doing can be replicated in terms of quality, just using AI, maybe we need to look at procedurally, whatever those bits of our business are, and maybe it’s right to put that now that the technology can fit that model.

00;31;22;17 – 00;31;34;10
Speaker 2
And let’s have a look really critically at what can’t be replaced by that because because obviously that’s where the the future is. And, you know, I mean, who knows what’s going to happen in seven years.

00;31;34;10 – 00;31;34;29
Speaker 1
So I.

00;31;34;29 – 00;31;36;02
Speaker 2
Am not putting my hand in.

00;31;36;02 – 00;31;38;07
Speaker 1
The fire there. Yeah.

00;31;38;09 – 00;31;54;28
Speaker 3
But it doesn’t worry me in terms of how you know, that ability critically thing and losing patience. You were no longer willing to put in the hard work because you don’t get that immediate, immediate reward. How that would have, you know, create a society of impatient, impulsive.

00;31;55;01 – 00;32;23;12
Speaker 2
So we we already have this problem. People’s attention spans are not where they should be. You know, we have the tick tock generation where everything’s consumed, in short, you know, amounts of time. So I think this is a technical problem we’ve had for a while now that AI can, I think, potentially maybe draw us back from a little bit if we can have more engaging kind of experiences online, or it could entirely just keep.

00;32;23;12 – 00;32;23;28
Speaker 1
Us.

00;32;23;29 – 00;32;30;10
Speaker 2
Throwing us in the other direction. But I think a little bit of that is how we are choosing to use the technology.

00;32;30;12 – 00;32;32;04
Speaker 1
That’s very interesting. Yeah.

00;32;32;06 – 00;32;35;10
Speaker 5
I’ve got a two year old, so I’ve got I don’t.

00;32;35;10 – 00;32;37;05
Speaker 1
Know what he’s.

00;32;37;05 – 00;33;06;26
Speaker 5
Going to grow up in, but I mean, I don’t see a scenario from here where it isn’t heavily integrated and everything they’re doing, you know, it’s being taught from day one. Almost. And I think the importance of teaching people how to use AI, how to think about the different tools, how to manage it, just like another tool in any toolbox is going to be the critical piece rather than, you know, mandating how they use it or or potentially teaching them how to interact with a particular tool.

00;33;06;29 – 00;33;25;13
Speaker 5
I think it’s going to have to be a much more holistic approach around using it, like like another source of information. But I think in practice it’s going to be quite difficult to to break that when you’ve got an easy way to find the answer to something you want. Yeah. How do you teach people to consciously stop and not use that?

00;33;25;14 – 00;33;26;09
Speaker 1
Yeah, and it does.

00;33;26;11 – 00;33;33;02
Speaker 5
It’s like the calculator. Yeah. How do you teach people how to do mental maths when the calculator there.

00;33;33;04 – 00;33;38;06
Speaker 2
Yeah. And you know, whenever we bring this up someone then says, well, why do I need to do basic arithmetic.

00;33;38;08 – 00;33;39;17
Speaker 1
Like what benefit.

00;33;39;18 – 00;34;02;17
Speaker 2
What benefit does that give me? I do think that we’re entering into a world that will will work for some people and might not work for how others innately are. So if you’re someone who just loves knowledge and you’re going to consume knowledge for the sake of knowledge, or if you’re someone who just loves reading and you’re always going to read because you’re in it for the joy of reading, not the necessarily the outcome.

00;34;02;19 – 00;34;09;20
Speaker 2
You know, I is obviously not going to take that away. But if you are the kind of person and I think teenage boys often are this kind.

00;34;09;20 – 00;34;10;11
Speaker 1
Of person.

00;34;10;12 – 00;34;26;01
Speaker 2
Who just yet literally, I just want to try and get to where I need to go real quick because this is not interesting to me. I want to go out and play football with my mates. Yeah, that’s difficult and I really am worried. For teachers, this seems like a really difficult problem for them to solve.

00;34;26;03 – 00;34;32;09
Speaker 3
Well, there might be legislation that you can help introduce soon in terms of when you ask something to I say.

00;34;32;09 – 00;34;36;18
Speaker 1
No, go and research it yourself. Maybe.

00;34;36;18 – 00;34;39;18
Speaker 2
Maybe better age restrictions than the social media companies have.

00;34;39;18 – 00;34;41;20
Speaker 1
Put in place. Yeah, yeah.

00;34;41;24 – 00;35;02;03
Speaker 5
Can be interesting to see what kind of what kind of controls they can put in place, what kind of novel ideas that we can’t think of or conceive of now that they’ll, they’ll have to incorporate into those different education or even training facilities like us. Sometimes people are coming straight out of high school or not even, and going into roles where they have critical impacts.

00;35;02;10 – 00;35;17;06
Speaker 5
And we’ve got our responsibility as the leaders of businesses to teach people the right things. So we’ll need to learn those same lessons that educators and teachers are and how they apply it. I think that’s going to be a big piece of kind of our role as business leaders over the next couple of years.

00;35;17;07 – 00;35;37;07
Speaker 2
And I think in, you know, both in law and the services that you guys provide, at the end of the day, the accountability does live with the person. It’s not no one’s going to be terribly impressed by you pointing at the AI tool and saying, well, it told me to do it, you know, and to be able to take on that accountability obviously need to have a fairly deep level of understanding.

Posted By
Bryan Rogers
Bryan Rogers
Chief Executive Officer
Bryan brings a grounded, business‑first perspective to complex risk and decision‑making — not as abstract technical problems, but as leadership issues that require clarity, judgement and pragmatism. His work centres on helping CEOs and senior leaders understand what truly matters, where real exposure exists, and which decisions deserve attention. With a career spanning digital consulting, software delivery and technical analysis, Bryan is comfortable operating between strategy and execution. He has a strong track record of translating complexity into clear, commercially grounded conversations that leaders can act on with confidence. Known for listening before advising, Bryan focuses on understanding the realities leaders face — competing priorities, constraints and risk appetite — and helping teams align on a sensible path forward. Through REDD, his aim is to cut through noise and jargon to provide an honest, practical view of organisational risk and readiness, without theatrics or box‑ticking. Bryan works closely with CEOs, COOs, CTOs and business owners, and welcomes open, thoughtful conversations about navigating risk and complexity in the real world.
Reach out!

If anything in this post interests you, or you'd like to have a chat with someone about your technology challenges, we would love to hear from you!