The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Customer Success/The Customer Success Playbook
The Customer Success Playbook artwork

Customer Success Playbook S3 E68 - Gayle Gorvett - Who's Liable When AI Goes Wrong?

The Customer Success Playbook · 2025-07-16 · 12 min

0:00--:--

Key moments - from our scoring

Substance score

36 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality7 / 20
Guest Caliber10 / 20
Specificity & Evidence6 / 20
Conversational Craft5 / 20

The regulatory landscape for AI remains unsettled, with the US lacking comprehensive federal rules despite recent proposals to pause state-level AI laws for up to 10 years. Gayle Gorvett emphasizes that without clear legal frameworks, companies must implement private regulation through careful vendor contracts, terms of service review, and governance policies. The EU AI Act attempts to establish guardrails for high-risk uses like biometric data and mass scraping, though it faces potential modifications due to complexity. In regulated industries like law (governed by the American Bar Association), professional bodies are already mandating AI disclosure and technical proficiency requirements. Gorvett argues that organizations should treat governance policies as both legal protection and competitive advantage - establishing written policies, training employees, and transparently communicating AI use to customers provides an affirmative defense if incidents occur and builds customer trust. The key insight: rather than waiting for regulation to force compliance, early adopters can differentiate by being responsible stewards of customer data and establishing themselves as trustworthy AI users.

Key takeaways

  • →Without comprehensive federal AI regulation, companies must create their own governance policies through vendor contracts and terms review to protect customer data from unauthorized reuse or training purposes.
  • →Having written AI policies and documented employee training can provide an affirmative defense in legal disputes and puts your organization in better standing than competitors relying on undefined practices.
  • →In regulated industries like law, professional bodies like the ABA are establishing disclosure requirements and technical proficiency standards for AI use ahead of federal regulation, signaling future compliance requirements.
  • →Transparent communication of AI governance to customers - published alongside privacy policies - builds trust and competitive advantage by positioning your company as a responsible steward of data.
  • →The EU AI Act focuses guardrails on high-risk categories like biometric data and mass scraping, but remains incomplete and subject to modification, making private governance policies essential regardless of geography.

In this episode

  1. 1Introduction to Gayle Gorvett and Her Background
  2. 2AI Accountability and Liability When Systems Fail
  3. 3Current Regulatory Landscape in the US and EU
  4. 4Private Regulation Through Contracts and Vendor Terms
  5. 5AI Governance Policies as Business Protection and Customer Trust

Mentioned

Kevin MetzgerGayle GorvettAmerican Bar AssociationEU AI ActNISTCISA

Guests

Gayle Gorvett

Topics in this episode

AI governance policiesEU AI ActAmerican Bar Association (ABA)Biometric regulationVendor contracts and terms of serviceCalifornia AI regulationIllinois biometric regulationNew York AI regulationFederal AI legislationAffirmative defensecustomer success playbookAI accountabilityliability frameworkprivate regulation

Questions this episode answers

Who is liable when an AI system causes harm or fails?

Liability determination is still being figured out, but organizations can protect themselves by implementing written governance policies, training employees on them, and documenting compliance - this creates an affirmative defense and shifts responsibility to companies rather than leaving it undefined.

Do I need to tell customers if I'm using AI in my business?

Yes, in regulated industries like law (per the American Bar Association), disclosure is required; but Gorvett recommends all companies proactively communicate AI use alongside privacy policies to build trust and potentially gain competitive advantage, rather than waiting for regulation to force disclosure.

What's the difference between US and EU AI regulation?

The EU AI Act establishes specific guardrails for high-risk uses like biometric data and mass scraping, whereas the US lacks comprehensive federal regulation and relies on fragmented state laws (California, Illinois, New York); the federal government has proposed pausing state laws for 10 years to develop federal standards.

Does having an AI governance policy actually protect my company legally?

Yes, having a written policy, training employees on it, and demonstrating regular compliance can provide an affirmative defense if something goes wrong, putting your organization in better legal standing than competitors without documented governance.

What should my company's AI governance policy cover?

At minimum, review vendor contracts and service terms to ensure data isn't reused for training, avoid putting sensitive data into systems without clear data protection commitments, and communicate your AI practices to customers through published governance policies.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode contains some relevant content on AI governance (regulatory landscape, contract review, disclosure duties) but is heavily diluted by 4+ minutes of personal biographical filler (Paris, languages, books, Harry Potter) that adds zero value to a B2B operator learning about AI liability. The substantive content on AI accountability, EU AI Act, and affirmative defenses is present but surface-level and not densely packed with novel claims.

You may have a legal requirement to inform your customers of your use of ai
If you have a policy, you have a written policy and you train your employees on that policy, and you can show that you're doing all of that on a regular basis, and then something happens and you can say, well, we've been doing this in good faith and we've been complying with it. You know, you can put yourself in a much better situation

Originality

7 / 20

The regulatory overview (EU AI Act, state-level variation, federal pause proposals) is accurate but represents standard legal analysis widely available in AI governance discussions. The affirmative defense concept and contract review guidance are conventional legal risk mitigation playbooks, not contrarian or first-principles thinking. No counterintuitive claims or fresh frameworks are offered.

Legislation to pause state laws in AI for up to 10 years to give the federal government the time to enact comprehensive federal AI regulation
engaging in, uh, a good contract with a vendor or making, making sure that you read the terms and conditions of the service

Guest Caliber

10 / 20

Gail Vete is positioned as a fractional legal counsel and AI governance expert with relevant credentials (ABA references, EU AI Act knowledge), but the transcript provides no detail on her actual track record, clients served, or scale of implementation experience. She appears credible but is primarily positioned as a legal advisor rather than a B2B operator who has shipped products or scaled businesses with AI governance.

fractional, uh, legal counsel and leading expert on AI governance
in in the legal profession, the A BA, which is interesting because they're not. Um, the coercive ability over, um, lawyers, they have a sort of, you know, it's kind of like NIST or CISA on the federal level for security

Specificity & Evidence

6 / 20

The episode lacks concrete examples, named companies, specific case studies, or quantified impacts of AI failures. Regulatory references (EU AI Act, state biometric laws, ABA guidelines) are mentioned but not detailed with specifics. No metrics, timelines, or dollar figures are provided, and claims remain largely abstract and general.

California. We have some biometric regulation in Illinois and New York, um, and some other states have coming online with AI regulation
There is, um, talk of modification of the act and the act being, um, put paused because it's. Too complex and too burdensome

Conversational Craft

5 / 20

The host devotes most of the episode to softball personal questions (Paris retirement plans, language proficiency, favorite books) that waste air time and demonstrate minimal preparation for a 12-minute window on AI liability. When substantive questions do emerge, follow-ups are thin and the host does not probe claims or push back on vague statements like 'doing all of that on a regular basis,' nor does he clarify what specific governance looks like in practice.

That maybe I wanna live in again? That's, yeah. I've lived a lot of places, so, um, I just got back from Paris
Do you speak French and Japanese? I believe I speak French fluently

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

legal7policy7regulation7back5japanese5read5states5federal5governance4better4sure4french4studying4makes4example4making4

Episode notes

Send us Fan Mail When AI systems fail spectacularly, who pays the price? Part two of our conversation with global tech lawyer Gayle Gorvett tackles the million-dollar question every business leader is afraid to ask. With federal AI regulation potentially paused for a decade while technology races ahead at breakneck speed, companies are left creating their own rules in an accountability vacuum. Gayle reveals why waiting for government guidance could be a costly mistake and how smart businesses are turning governance policies into competitive advantages. From the EU AI Act's complexity challenges to state-by-state regulatory patchwork, this customer success playbook episode exposes the legal landmines hiding in your AI implementation - and shows you how to navigate them before they explode. Detailed Analysis The accountability crisis in AI represents one of the most pressing challenges facing modern businesses, yet most organizations remain dangerously unprepared.

Full transcript

12 min

Transcribed and scored by The B2B Podcast Index.

All right. Welcome back to the Customer Success Playbook podcast. I'm Kevin Metzger again. Robin is unable to join us, but we are continuing our conversation with Gail Vete, uh, fractional, uh, legal counsel and leading expert on AI governance.

Gail, before we dive in. Let's let our audience get to know you a little bit better. You up for that? Sure.

What's one city, uh, you could see yourself living in that maybe you've lived in in the past or somewhere you'd wanna live in in the future? That maybe I wanna live in again? That's, yeah. I've lived a lot of places, so, um, I just got back from Paris and lived there for a long time and I don't know if I want to live there full time again.

I. But I've thought about the idea of maybe getting a little kind of, um, pie there, um, for retirement to be able to go back and forth. Nice. Yeah.

Do you speak French and Japanese? I believe I speak French fluently. Um, Japanese not so fluently. Um, at one point I knew 500 kanji.

I cannot say that I know the 500 kanji anymore. Um, I, their Japanese has three different written alphabets, and I know the two that are used to translate foreign words, but my kanji has really slipped. How did you get into that? I mean, I, I went to a school in Virginia when I was young that taught French very early, and I started going there at a later age, but I started studying French.

At that at 12 and I continued and then I went to Europe to study a couple of times in high school and college. And I just became then very interested in, um, international business and studying languages. And while I was in college, the European Union was just really. Getting delayed in their, you know, unionizing, let's say.

Um, so I thought, I think I need a different language if I really wanna do this international business. I decided to start studying Japanese 'cause they seem to be the ones kind of pushing the, the economic ball forward in international business. So I started studying Japanese and then I went to work in Japan after I graduated. On the JET program, what's a favorite book, uh, that you have?

Oh, yeah. You know what? That's a great question. I love to read.

I have not had a lot of time to read for pleasure lately. I, I will say, when I was really busy in New York and I needed to try to relax to calm down, after working a lot of hours, I read all the Harry Potters like. In a row, but that, I wouldn't say those are my F they're good, but those are not my favorite books. I love historical fiction and I love books like Memoirs of a Geisha.

I recently read, oh, I'm trying to remember the name of the book. They made it into a mini series and now I can't remember the name of it. Oh, A Gentleman in Moscow. Oh, cool.

That was a really good book. Very cool. I like historical fictions as well. I tend to, I, I actually like a lot of the legal thrillers as well.

Oh, do you like John GREs stuff and all that? Yeah. Yeah. But I, I gotta imagine that probably isn't very relaxing for you.

Well, it's kind of funny, you know, 'cause it's so unrealistic. Well, let's get back into the, uh, the realm of ai, which is, uh, where we're focusing these days. And when an AI system fails or causes unintended harm, how do we determine who's really accountable? What are the rules around that now?

And now? How are you seeing that from a Well, I think we're still kind of figuring out what the rules around that are, and that's one of the reasons why. Having a good governance policy is so important and why it's a good idea to using innovations like AI is, is of course, you know, great, um, to help you in your work and to help you, you know, kind of, uh, do research and things like that, but also. If you're using this kind of technology to do something sensitive or to advance your business in an area that's of strategic importance, the question that you ask, it makes, uh, all the difference in terms of look before you leap because this is an area where in some, especially in the US for example, we don't have.

Um, comprehensive regulation around this. Um, and there are states that do have AI regulation. California. We have some biometric regulation in Illinois and New York, um, and some other states have coming online with AI regulation.

But in the past few weeks, the federal government has put forth. Legislation to pause state laws in AI for up to 10 years to give the federal government the time to enact comprehensive federal AI regulation. 10 years, huh? Yes.

Yeah. To, we'll all have chips in our head and it will be completely irrelevant, so it makes it even more important to kind of, um, as much as you. As much as you can within the realm of possibility, do what we call, you know, sort of private, uh, regulation, which is obviously engaging in, uh, a good contract with a vendor or making, making sure that you read the terms and conditions of the service that you're using and making sure that you're comfortable with what they say.

Um, so that, you know. Um, that you're not, um, putting data into an LLM that you know, is then going to be, become the, the of that, um, entity or being reused for training purposes, for example, or, you know, those types of things. Because right now, um, in the United States in particular, a lot of the, um, power is going to a lot of these companies as opposed to, um, the users of their technology. Um, you know, in the EU they've introduced E EU AI Act, um, which puts some guardrails around the use of ai, especially in the high risk, um, categories, which are biometric.

Mass or mass use of areas where, um, they would automate gathering or scraping of data or personal data in a large way. Um, things like that. But they haven't fully rolled out the, um, EU AI act yet. And there is, um, talk of modification of the act and the act being, um, put paused because it's.

Too complex and too burdensome. Um, so we're even seeing some, some, um, in other jurisdictions that already have regulation. Yeah, I mean, it's interesting. Stuff is moving so fast.

I have a question too, if I have, um, you know, a set of guidelines in place for my company. Yeah. Does that provide any actual protection for me? Because I can show I'm using within the guidelines that we set, or is like, um, something goes sideways.

Is it not necessarily provide protection? Well, I would say a couple things. If you're in a regulated industry. Unlike mine, for example, um, you may have a legal requirement to have guidelines.

You may have a legal requirement to inform your customers of your use of ai. For example, in in the legal profession, the A BA, which is interesting because they're not. Um, the coercive ability over, um, lawyers, they have a sort of, you know, it's kind of like NIST or CISA on the federal level for security. They put out guidelines that become very strong suggestions, and the a BA, um, the American Bar Association is a federal, you know, bar association, but.

Uh, the legal profession is regulated by the states, so they put out these sort of blanket, you know, statements that are not coercive, but then they become adopted in, in different forms by individual states. And what they've said is. You know, lawyers who are using ai, um, have a duty to disclose that to their clients and they have a duty to become technically proficient in ai. Um, and, uh, you know, I would say you should use it as an opportunity to communicate with your customers and instead of waiting for there to be a law to that compels you.

To create a, a guideline or, or a governance policy. Use it as a way to be the first adopter in your industry Having a governance policy. It is good business. It's also, you know, good common sense because you don't want your, your, your employees doing whatever they want, right?

You want to be the one who sets the tone. For your employees, you wanna be the one who sets the rules. And then you also want your customers to know that you're responsible with their information. You want them to know that you care about their information.

And so in some circumstances, yes, it can, you know, put you in a better legal footing. It can provide you what's called an affirmative defense. If you have a policy, you have a written policy and you train your employees on that policy, and you can show that you're doing all of that on a regular basis, and then something happens and you can say, well, we've been doing this, we've been doing this in good faith and we've been complying with it. You know, you can put yourself in a much better.

Um, situation, but then also with your customers, if you, you adopt kinds of policies, you also then put that on your website along with your privacy policy. Then it, it makes feel better about you as. Uh, a service provider makes sense. And really, I mean, basically the responsibility for this isn't just, it's the technical, it's organizational, it's making sure you're getting back to everybody so that they understand how you're intentionally using AI at this point.

Thank you. Thanks for helping us tackle in this, this talk. It's a tough one. It's not, it's, we're not with all the details yet.

We don't know where it's going. I mean, but. Thank for sharing your knowledge with us on this. Our next show we explore how to without stifling innovation.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Why Enterprise Software Deals Now Include a Vendor AI Model Explainability MandateB2B SaaS Talks with Fexingo · on EU AI Act94 / 100
  • How Fortune 500s Use Procurement to Manage Vendor AI Training Data RightsEnterprise Tech with Fexingo · on EU AI Act90 / 100
  • AI You Can Trust, Audit and Keep with Russell Moore, Co-Founder & CEO of Amotivv | Episode 494Leaders In Payments · on EU AI Act85 / 100
  • AI in Financial Modeling: Better Than Ever, Still Not There, and the Fatigue FactorThe FP&A Guy Network · on AI governance policies77 / 100
  • Trustworthy AI For Real Telco ImpactWhat's Up with Tech? · on EU AI Act77 / 100
  • The Trust Gap in AI: Why Agents Need a New Certification Model ft Rajiv Dattani & David Meyer @ AIUCSecurity & GRC Decoded · on EU AI Act76 / 100

More from The Customer Success Playbook

All episodes →
  • Customer Success Playbook - Final Episode with Kevin and Roman31 / 100
  • Customer Success Playbook Podcast S3 E72 - Adrian Swinscoe - Enhancing Customer Experience with AI55 / 100
  • Customer Success Playbook Podcast S3 E71 - Adrian Swinscoe - Unlocking Value in Customer Journeys48 / 100
  • Customer Success Playbook Podcast S3 E70 - Adrian Swinscoe - Data and Customer Storytelling74 / 100
  • Customer Success Playbook S3 E69 - Gayle Gorvett - Scaling AI Governance Without Killing Innovation65 / 100
Explore the best B2B Customer Success podcasts →
All The Customer Success Playbook episodes →