The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Customer Success/The Customer Success Playbook
The Customer Success Playbook artwork

Customer Success Playbook S3 E67 - Gayle Gorvett - AI Governance Essentials

The Customer Success Playbook · 2025-07-07 · 9 min

0:00--:--

Key moments - from our scoring

Substance score

45 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality8 / 20
Guest Caliber12 / 20
Specificity & Evidence7 / 20
Conversational Craft8 / 20

Gayle Gorvett brings 26 years of technology law experience to discuss how organizations should approach AI governance before diving into adoption. Drawing parallels to the blockchain hype cycle of a decade ago, she emphasizes that companies must first identify specific business use cases for AI rather than implementing it as a strategic initiative without clear purpose. Her work with Duke Center on Law and Technology's AI guardrails working groups - focused on end users and legal professionals - has produced practical frameworks for ethical compliance. Gorvett advocates for multidisciplinary governance involving business functions, technical teams, in-house counsel, and fractional legal advisors. She recommends two key resources: the NIST AI Risk Framework for general U.S. adoption and the Duke AI Risk Framework specifically designed for legal teams to conduct comprehensive AI risk assessments tailored to their industry, sector, and specific use cases. For customer success teams, this translates to understanding how AI tools handle customer data, protect company information, and align with customer preferences around AI usage.

Key takeaways

  • →Identify specific business use cases for AI before making strategic investments or building AI into core business processes, rather than adopting the technology for its own sake.
  • →Approach AI governance through a multidisciplinary lens involving business functions, technical teams, legal counsel, and potentially fractional general counsel if in-house expertise isn't available.
  • →Use established frameworks like NIST AI Risk Framework or Duke AI Risk Framework to conduct comprehensive AI risk assessments appropriate to your industry, sector, and specific use case.
  • →Ensure transparency with customers about how your company uses AI and seek to understand how customers want to be informed of AI implementation in your products or services.
  • →The absence of federal AI regulation in the U.S. makes self-imposed ethical and governance guidelines essential for responsible AI adoption in enterprise contexts.

In this episode

  1. 1Introduction to Gayle Gorvett and AI Governance Background
  2. 2Duke Center Working Groups on AI Guardrails
  3. 3Development and Goals of AI Guidelines
  4. 4Top Tips for Establishing Ethical AI Guidelines
  5. 5Multidisciplinary Approach to AI Governance
  6. 6Recommended AI Risk Frameworks and Resources

Mentioned

Gayle GorvettKevin MetzkerDuke Center on Law and TechnologyNIST AI Risk FrameworkDuke AI Risk FrameworkGovett ConsultingStanfordMITMicrosoftGooglemonster.comBrinks

Guests

Gayle Gorvett

Topics in this episode

AI governanceDuke UniversityCross-border transactionsNIST AI frameworkNIST AI Risk FrameworkDuke AI Risk FrameworkDuke Center on Law and TechnologyFractional general counselSaaS legal complianceAI risk assessmentEthical AI guidelinesFederal AI regulationcustomer success playbooklegal frameworks

Questions this episode answers

What's the first step a company should take before implementing AI?

Identify the specific business use case for AI before investing financial resources or making it part of strategic planning, rather than adopting it as a trendy technology without clear purpose.

What frameworks does Gayle recommend for building AI governance policies?

For U.S. companies, the NIST AI Risk Framework provides general guidance, while the Duke AI Risk Framework (developed through Duke Center on Law and Technology) is specifically designed for legal teams to conduct comprehensive AI risk assessments tailored to their business, industry, and use case.

Who should be involved in developing an AI governance policy?

AI governance requires a multidisciplinary approach involving business functions, technical teams, in-house counsel if available, or fractional general counsel for smaller organizations.

Why is customer awareness about AI use important?

Companies need to consider how they inform customers about AI usage and understand customer preferences regarding AI implementation, as this affects both customer trust and compliance considerations.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

The episode provides some useful frameworks (NIST AI Risk Framework, Duke AI Risk Framework) and mentions a multidisciplinary approach to AI governance, but much of the content is introductory background and lacks depth. The advice to 'think about your use case' and 'involve stakeholders' is practical but fairly standard governance thinking, not densely packed with novel insights for an operator.

think about the use case, the specific use case for your business, um, before, you know, potentially investing, uh, financial resources or making AI a really big part of your
make sure that you are involving the business function, the the tech people in your team. If you do have in-house counsel involved, the them

Originality

8 / 20

The comparison of AI hype to blockchain hype a decade ago is a reasonable observation, but the core governance recommendations (multidisciplinary teams, risk frameworks, stakeholder input) are standard practice in compliance and risk management. No genuinely contrarian or first-principles thinking emerges; the guest largely reiterates established governance best practices.

I see a lot of the, the hype in this space as similar to what we saw when blockchain was. Everywhere about 10 years ago
approach it from a multidisciplinary way. Um, make sure that you are involving the business function, the the tech people in your team

Guest Caliber

12 / 20

Gayle Gorvett has legitimate credentials as a former in-house counsel at public companies (Alcatel spinoff, Brinks EMEA) and now runs her own consulting practice with AI governance focus. However, she is primarily a fractional counsel and academic working-group participant rather than an operator who has scaled AI governance within a major organization. Her experience is advisory rather than hands-on operational.

Before forming my company, I was an associate at a large law firm in New York, and I was in-house counsel at two public companies
I've been a, a technology for, uh, going on 26 years now, and, you know, I've been working with, um, companies in this space since, you know. The beginning with like monster.com

Specificity & Evidence

7 / 20

The episode lacks concrete examples, data points, or case studies. References to NIST and Duke frameworks are named but not explained with specifics. There are no numbers, timelines, dollar figures, or real-world failure stories to ground the governance advice. The mention of past tech work (monster.com, blockchain) is vague and not tied to specific lessons learned.

I would recommend to people in the US is the nis NIST AI risk framework. That's NIST. And the other one for legal teams is the one that we've developed through Duke, which is the, the Duke AI risk Framework
I've been working with, um, companies in this space since, you know. The beginning with like monster.com and, um, you know, the, the battle between, uh, Microsoft and um, and, and Google

Conversational Craft

8 / 20

The host asks reasonable opening questions ('Can you get into that a little bit more?') but rarely probes deeper or challenges claims. When Gayle mentions the Duke framework and NIST, the host does not ask for specifics, implementation examples, or how they differ. The conversation ends abruptly with a teaser for a Wednesday episode rather than drilling into substance. The host is pleasant but passive.

Can you get into kind of how those guidelines are getting developed? What, what can you get into around that?
I think we're gonna probably get into more detail on some of these in our show on Wednesday

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

governance9groups6customer5show5counsel5duke5guidelines5success4general4lawyers4help4ethical4risk4welcome3today3gail3

Episode notes

Send us Fan Mail Ready to navigate the complex world of AI governance without getting lost in legal jargon? This episode delivers a masterclass in building ethical AI frameworks that actually work for your business. Global tech lawyer and fractional general counsel Gayle Gorvett breaks down the essential guardrails every company needs before diving headfirst into AI implementation. From her work with Duke University's AI working groups to real-world enterprise applications, Gayle reveals why treating AI like the "shiny new toy" without proper governance is a recipe for disaster. Whether you're protecting customer data or safeguarding your company's future, this customer success playbook episode provides the foundational knowledge to approach AI adoption with confidence and compliance. Detailed Analysis The AI revolution isn't just changing how we work - it's fundamentally reshaping the legal and ethical landscape of business operations. Gayle Gorvett's expertise in AI governance comes at a crucial time when companies are rushing to implement AI solutions without adequate safeguards.

Full transcript

9 min

Transcribed and scored by The B2B Podcast Index.

Customer success. Hello everyone and welcome to the Customer Success Playbook podcast, where we bring you actionable insights for the customer success team of today and tomorrow. I'm your host, Kevin Metzker. Unfortunately, Roman is unable to join us this week, but we are thrilled to welcome Gail Vete to the show.

Gail's a seasoned global tech lawyer and fractional general counsel with deep expertise in SaaS, cross-border transactions and AI governance. She's helped companies expand into markets from China to Istanbul. And currently leads g Govett Consulting. Gail, welcome to the show.

Would you like to share a little bit more about your background? Thank you. Um, yes, I would. Before forming my company, I was an associate at a large law firm in New York, and I was in-house counsel at two public companies, um, in France, nal, which is an Altel spinoff, and Brinks, EMEA.

Where I was international corporate counsel for the BGS business division and responsible for EMEA and Asia Pacific. And now in addition to helping clients with their day-to-day, um, legal matters, I do quite a lot of AI governance work. Which is a very interesting area to be in. Yeah, and I'm, I'm super excited about that because that's really what the topic of today's show is.

It is kind of getting into what you're doing in AI governance and how it kind of applies. And, you know, we do look at this from a customer success perspective, but quite frankly, this is whole company type stuff, right? So how, how people are using AI and what's happening. And how the governance structures are coming in.

It's important to understand that information and how to structure a governance program within a company because you're. Working on your customer's data. You're working on protecting your company's data. This new AI scenario, this new AI workflow is something that we need to consider all of these, these priorities.

And so with that said, like I said, I'm super excited to kind of talk to you about this and I think you're working or you're working with a program for governance structure. Can you kind of get into that a little bit more? Yes, I've been a member of two, um, AI guardrails working groups with the Duke Center on Law and Technology for, I guess it's a little more than a year now. And, um, duke is actually in, you know, similar to a lot of big universities like Stanford and MIT.

Um, creating a lot of working groups in this area. They have five. Um, the, the two I'm working with are focused on two different user groups. One is end users of ai, you know, just the general population, and the other is users.

So lawyers that are either in law firms or in-house who would be using ai. And we've been focusing on producing, um, AI guardrails for those two user groups. In the working groups that I'm part of. Can you get into kind of how those guidelines are getting developed?

What, what can you get into around that? Yeah. Um, so Duke basically, you know, put out a call to have volunteers to anyone who was really interested in participating in, of course got a, a pretty, um, large response. Um, and a lot of.

The people who volunteered for the user group. Um, the working groups that I'm part of are, um, lawyers or people who work in, um, different, uh, nonprofit organizations. Some, some are professors, um, and they're interested in making sure that we have, um. Guidelines and, and, um, documentation for the general population and also especially for lawyers to help clients and other lawyers, um, to really provide ethical and compliance guardrails for ai, especially in the United States where we have a, a real lack of federal regulation in this space.

Uh, to make sure that people use ai, but that they have some ethical and governance guidelines to help them do that. Thank you for the background. And if we get into the, what's your number one SH tip, which, so first show always is about what's your number one tip for ensuring that we kind of like the foundational rule for ensuring you have those ethical guidelines in place. You know, I've been a, a technology for, uh, going on 26 years now, and, you know, I've been working with, um, companies in this space since, you know.

The beginning with like monster.com and, um, you know, the, the battle between, uh, Microsoft and um, and, and Google in the old days. And, um, and I, I think AI has a lot of promise. It's very innovating.

It's a kind of the, the shiny new toy right now. But I, I see a lot of the, the hype in this space as similar to what we saw when blockchain was. Everywhere about 10 years ago. And, and, um, people who are, you know, thinking about using this in a, in an enterprise context.

I would say two things. I would say yes. It, it definitely, it has a lot of promise. It, it shows a lot of, um, you know.

Um, innovation in terms of helping, uh, in, in a lot of administrative tasks, a lot of potential productivity tools. But think about the use case, the specific use case for your business, um, before, you know, potentially investing, uh, financial resources or making AI a really big part of your. Uh, you know, planning in, in any strategic way on a business level. Then when you think about AI and how to, um, look at a, a governance policy or an ethical, uh, use of ai, you always have to think about how you're using it.

Of course, think about your customers and how they want to be, um, informed of your use of ai. And then you have to approach it from a multidisciplinary way. Um, make sure that you are involving the business function, the the tech people in your team. If you do have in-house counsel involved, the them.

If you, if you're not big enough to do that, maybe think of someone you know, like me, who's a fractional, um, general counsel to help you. Um, come up with those kind of guidelines. You know, there are resources out there, um, to help you go go through this process and think about the considerations and the risk that you might be, uh, facing in your company, um, as you're going through that. So, one that I would recommend to people in the US is the nis NIST AI risk framework.

That's NIST. And the other one for legal teams is the one that we've developed through Duke, which is the, the Duke AI risk Framework, through which we've, we've developed, you know, a comprehensive, um, AI risk assessment, which allows legal teams to develop their own governance policies that are. Um, really app appropriate to their business, their industry, their sector, and the use case that they're using it for. Fantastic for, and thank you for helping kick off today.

I think we're gonna probably get into more detail on some of these in our show on Wednesday. Um, kind of what happens on when you go deep and who's responsible or accountable. When AI goes wrong, don't miss it. Like, share, subscribe, and until then, keep on playing.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How to Implement AI in Your Business: From AI Use Cases to Real ROI | Dr. Markus SchmidbergerUsing AI at Work · on AI governance92 / 100
  • #291 Why Most AI Projects Fail to Deliver ROI Sinohe Terrero CFO and COO, EnvoyGrowCFO Show · on AI governance91 / 100
  • Who Owns What Your AI Does?The Pre-Read · on AI governance85 / 100
  • The USB Problem for AI: Phil Stafford on Agents, Governance, and MCP RiskAI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop · on AI governance84 / 100
  • Navigating AI Risks with Trevor Horwitz from TrustNetB2B Automation Spotlight · on AI governance79 / 100
  • S4 Eps 18: Leigh Lewis InterviewThe Dirty Verdict · on Duke University76 / 100

More from The Customer Success Playbook

All episodes →
  • Customer Success Playbook - Final Episode with Kevin and Roman31 / 100
  • Customer Success Playbook Podcast S3 E72 - Adrian Swinscoe - Enhancing Customer Experience with AI55 / 100
  • Customer Success Playbook Podcast S3 E71 - Adrian Swinscoe - Unlocking Value in Customer Journeys48 / 100
  • Customer Success Playbook Podcast S3 E70 - Adrian Swinscoe - Data and Customer Storytelling74 / 100
  • Customer Success Playbook S3 E69 - Gayle Gorvett - Scaling AI Governance Without Killing Innovation65 / 100
Explore the best B2B Customer Success podcasts →
All The Customer Success Playbook episodes →