10 Simulação de Papéis

Governança de IA Policy Drafting Session — Role Simulation

The breach story published this morning. The ordem de advogados estadual called at noon. The largest client wants a governança plan by Friday. Five people in a room with 90 minutes to build — from nothing — the governança de IA framework the firm needs to survive.

Duração

60-90 minutos

Participantes

4-6 participantes

← Voltar ao Currículo

Cenário da Simulação

It is Thursday, February 13 — one day after the CyberLaw Report published its story on the Hartwell, Sinclair & Pratt violação de dados. The firm's sócio-gerente has convened an emergency governança policy drafting session. The ordem de advogados estadual's ética committee has requested a written description of the firm's governança de IA measures by the end of next week. Crawford Pharmaceutical's board has given the firm until Friday to present a credible governança framework or face termination of the legal relationship. The room contains five people with very different perspectives on what went wrong, who is responsible, and what the governança framework should look like. They have 90 minutes to produce a working draft that satisfies clients, regulators, and the partnership.

Partes Interessadas e Papéis

modules.m10.simulation.stakeholdersSubtitle

1

Margaret Sinclair — Sócio-Gerente

Perfil

Chairs the meeting and must synthesize competing views into a workable framework. Her priority is speed and credibility — the firm needs a presentable governança document before the Friday client deadline and the ordem de advogados estadual deadline next week.

Objetivos

  • Produce a governança framework that is comprehensive enough to satisfy regulators and clients but concise enough to be implementable within 30 days
  • Navigate the internal politics — balancing responsabilização for Ashworth with the need to retain her revenue and expertise
  • Estabelecer a autoridade de Osei como CISO sem alienar os sócios cujo apoio é necessário

Restrições

Sinclair knows that the insurance exclusion for unauthorized third-party applications means the firm may face uninsured liability. She must ensure the governança framework addresses this gap going forward.

Informação Exclusiva

Sinclair has received a private call from the sócio sênior at Crawford Pharmaceutical's alternative assessoria jurídica externa firm, offering to 'take the matter off her hands gracefully.' She has not told anyone about this call. She also knows that two additional partners have been using unapproved ferramenta de IAs and that the governança framework must address their situations before those become public as well.

2

Daniel Osei — Diretor de Segurança da Informação

Perfil

Three days into the job, working with incomplete knowledge of the firm's systems. Brings deep cibersegurança expertise from financial services but limited understanding of escritório de advocacia culture, partnership dynamics, and legal obrigações profissionais.

Objetivos

  • Establish a governança framework with teeth — mandatory tool vetting, classificação de dados, monitoring, and enforcement mechanisms that meet enterprise security standards
  • Secure budget and authority commitments from the partnership for the infrastructure upgrades needed to support the governança framework
  • Create an resposta a incidentes protocol so the firm is prepared if another breach occurs

Restrições

Osei's infrastructure assessment reveals that implementing enterprise-grade governança controls will cost $800,000-$1.2 million in the first year. The firm's current IT budget is $340,000 annually. He must propose a framework that is aspirationally robust but pragmatically phased.

Informação Exclusiva

Osei has discovered during his infrastructure review that the firm's document management system has a logging gap — there is no complete record of which documents Ashworth uploaded to LegalMind Analytics. The 4,200-page figure reported publicly is the fornecedor's estimate, but the actual exposure could be larger. He has not shared this finding with anyone yet because he wants to verify it before creating additional panic.

3

Victoria Ashworth — Senior Litígio Partner

Perfil

The partner whose use of LegalMind Analytics caused the breach. She is present because Sinclair believes that excluding her would be both unfair and counterproductive — the governança framework needs input from practitioners who understand why attorneys adopt unauthorized tools.

Objetivos

  • Ensure the governança framework addresses the root cause — the gap between attorneys' technology needs and the firm's approved tool offerings — rather than just punishing unauthorized adoption
  • Protect her team of three associates who used LegalMind Analytics at her direction from individual ação disciplinar
  • Demonstrate responsabilização and constructive engagement to rebuild credibility with the partnership and clients

Restrições

Ashworth's continued presence at the firm is politically contentious. Some partners want her suspended or expelled. She must contribute meaningfully to the governança discussion without appearing to be deflecting blame or minimizing the harm her actions caused.

Informação Exclusiva

Ashworth has conducted her own review and discovered that LegalMind Analytics' termos de serviço — which she never read — included a clause granting the fornecedor a royalty-free license to use uploaded documents for AI treinamento de modelo purposes. This means the exposed documents may have been incorporated into the fornecedor's dados de treinamento, creating a broader and potentially irremediable exposure beyond the violação de dados itself. She has not disclosed this to anyone.

4

Kevin Park — Representante dos Associados, Comitê de Tecnologia do Escritório

Perfil

A fifth-year associate elected to the firm's technology committee by the associate class. Represents the perspective of junior lawyers who use ferramenta de IAs daily and are most directly affected by governança policies they had no role in creating.

Objetivos

  • Ensure the governança framework does not eliminate ferramenta de IA access that associates rely on for competitive efficiency and workload management
  • Defender um processo de aprovação de ferramentas simplificado — o atual processo de aprovação de 3 meses inviabiliza a inovação
  • Pressionar por recursos de treinamento e suporte em vez de aplicação punitiva

Restrições

Park knows that associates are the heaviest users of ferramenta de IAs in the firm and that many are using unapproved tools for tasks ranging from research drafting to time entry. A restrictive governança framework will face immediate nonconformidade from the associate class.

Informação Exclusiva

Park has been quietly running an anonymous survey of associates about ferramenta de IA use. The preliminary results show that 67% of associates have used at least one unapproved ferramenta de IA for firm work in the past six months. The most common reason cited is 'the approved tools are inadequate for my needs.' 23% report that a partner specifically asked them to use an ferramenta de IA that was not approved. He has not shared these results with firm leadership.

5

Eleanor Vance — Ética Committee Chair

Perfil

Senior counsel who chairs the firm's responsabilidade profissional committee. A former ordem de advogados estadual disciplinary counsel, she understands the regulatory exposure better than anyone in the room and has strong views on the ético obligations that the governança framework must address.

Objetivos

  • Ensure the governança framework satisfies the ordem de advogados estadual's expected requirements and positions the firm favorably in any procedimentos disciplinares
  • Establish clear ético guidelines for uso de IA that go beyond technical security to address duties of competência, confidencialidade, and supervisão
  • Create a reporting and escalation mechanism for AI-related ético concerns that protects attorneys who raise issues in good faith

Restrições

Vance has been contacted by the ordem de advogados estadual's ética committee chair, who indicated informally that the bar is considering using this case as the basis for a new formal ética opinion on governança de IA in escritório de advocacias. The governança framework the firm produces may influence statewide standards.

Informação Exclusiva

Vance has reviewed the disciplinary history and discovered that the firm received an informal ética inquiry 18 months ago from a different partner about whether using a baseado em nuvem AI summarization tool for client documents required client consent. The inquiry was routed to the firm's general counsel, who provided an informal 'green light' without conducting a formal analysis. This prior inquiry — never documented in a formal opinion — suggests the firm had notice of the governança de IA gap well before the breach.

Regras

Duração

45 minutos

Comunicação

Sessão de elaboração de política facilitada por Diana Caldwell; todos os papéis contribuem para o rascunho final.

Método de Decisão

The session must produce a governança framework outline with specific provisions on: tool approval, classificação de dados, training, monitoring, enforcement, and resposta a incidentes. Sinclair has final authority on unresolved disputes, but consensus is strongly preferred.

Fases

Fase 1

Avaliação do Estado Atual (15 minutos)

Each participant presents their view of what the governança framework must achieve and their non-negotiable requirements. Osei presents the technical reality. Ashworth presents the practitioner's perspective. Park presents the associate viewpoint. Vance presents the ético obligations. Sinclair synthesizes the priorities and identifies areas of agreement and conflict. By the end of this phase, the group should have agreed on the framework's guiding principles.

Fase 2

Elaboração de Política (20 minutos)

The group works through the six core sections of the governança framework: (1) Tool Approval Process, (2) Data Classification and Handling, (3) Training and Certification, (4) Monitoring and Conformidade, (5) Enforcement and Consequences, (6) Resposta a Incidentes. For each section, participants propose specific provisions, debate alternatives, and work toward consensus. Exclusive information may be revealed as it becomes relevant. This is where the hardest negotiations occur.

Fase 3

Implementação & Responsabilização (30 minutes)

The group finalizes the framework and addresses implementação: Who owns each section? What is the timeline? What resources are required? How will success be measured? Each participant makes a commitment statement — what they will do to support implementação and what they need from others. The session concludes with each participant rating their confidence in the framework's effectiveness and identifying the single biggest risk to successful implementação.

modules.m10.simulation.simVariationsTitle

  • What if the ordem de advogados estadual accelerates? During Phase 2, Vance receives a call and announces that the ordem de advogados estadual has moved up its deadline — they want the governança framework description by Monday, not the end of next week. How does this compressed timeline affect the quality and scope of what the group can produce?
  • What if Park reveals the survey results? At any point during the simulation, Park may choose to share the anonymous associate survey showing 67% unauthorized ferramenta de IA use. How do these numbers change the group's approach to enforcement and the perceived urgency of the governança challenge?
  • What if a second breach is discovered? During Phase 3, Osei receives an alert and announces that his infrastructure review has uncovered evidence of a second unauthorized ferramenta de IA — used by a different partner — that may have exposed a smaller set of client documents. How does a second incident, discovered during the governança drafting session itself, affect the framework and the group dynamics?

Debriefing

modules.m10.simulation.debriefSubtitle

Processo de Decisão

  • Review the governança framework your group produced. Does it address all six core sections? Which section was the strongest? Which needs the most additional work?
  • Compare your framework with the governança policies of real escritório de advocacias (if available). What gaps exist? What did your group include that others might miss?
  • O framework que você produziu é realista? Um escritório de 180 advogados poderia implementá-lo sem contratar uma equipe de conformidade dedicada?
  • Does the framework balance security with usability? Would attorneys at this firm actually follow it, or would it drive more shadow uso de IA?

Informação e Perspectivas

  • Which parte interessada had the most influence over the final framework? Was that influence proportional to their expertise, their authority, or their emotional leverage?
  • Que mecanismos de aplicação são mais provavelmente eficazes?
  • Houve momentos em que interesses pessoais entraram em conflito com obrigações institucionais?

Governança Design Principles

  • Como você obteria adesão de toda a firma para a nova política de IA?
  • How should a governança framework handle the tension between partner autonomy and institutional conformidade? Is the traditional partnership model compatible with enterprise-grade governança?
  • Should the governança framework be developed internally or should the firm engage external experts? What are the tradeoffs?
  • How often should the governança framework be reviewed and updated? What triggers should prompt an immediate review outside the regular cycle?

Aplicação no Mundo Real

  • Does your own organization have an governança de IA policy? After this simulation, what would you add or change?
  • If you were asked to lead governança de IA at your organization, what is the first thing you would do? What is the biggest obstacle you would face?
  • Reflect on Ashworth's situation: a talented attorney who adopted a tool to do better work, without malicious intent, and caused a catastrophe. How does your governança framework prevent this without stifling innovation?
  • Name one specific action you will take within the next 30 days to improve governança de IA in your professional environment.

Referências e Fontes

Padrões Profissionais

  • ABA Regra Modelos of Conduta Profissional, Rules 1.6(c), 5.1, and 5.3 — Confidencialidade and supervisory duties
  • ABA Opinião Formals 477R (2017) and 483 (2018) — Technology security and post-breach obligations
  • State bar ética opinions on governança de IA requirements for escritório de advocacias

Governança Frameworks & Resources

  • NIST AI Gestão de Riscos Framework (AI RMF 1.0) — Comprehensive governança de IA guidance adaptable to legal practice
  • ISO/IEC 42001:2023 — AI Management System standard for organizational governança de IA
  • ACC (Association of Corporate Counsel) — Políticas Modelo para Uso de IA por Advogados Externos

Pronto para Executar Esta Simulação?

This role simulation is designed for guided facilitation as part of the Lawra Learning Program. Request a personalized program that includes expert moderation, governança framework templates, and structured debriefing.

Comentários

Carregando comentários...

0/2000 Os comentários são moderados antes de serem exibidos.