Global AI Regulations & Compliance with Stan Shepard | Atlassian Team 25 EU Barcelona
AI regulations are taking shape across the globe — with Europe leading the way and the U.S. working toward a more unified approach. In this session from Atlassian Team 25 EU in Barcelona, Stan Shepard breaks down how governments, organizations, and legal experts can collaborate to ensure responsible AI adoption. The discussion explores evolving compliance frameworks like NIST and ISO, how lawmakers are learning to adapt to rapid innovation, and the balance between AI-driven efficiency and the enduring importance of human judgment in the legal field.
Transcript
Hey, welcome back to Atlassian, Europe, and we're gonna have a little chat now about AI regulations ethical use with my new friend Stan, how you doing? Hey, Mike. Great to meet you.
Thanks for having me on my online. My, my pleasure. Um, there are regulations all over the world, and you're the general counsel, and I'm sure you're keeping track of all this stuff, but different countries, different regions seem to have different attitudes.
So what's the current state of AI regulation? 'cause I know in the US we're kind of maybe anti-regulation, and in Europe they're pretty far ahead. So yeah.
How do I navigate all this stuff? Yeah, it's a tricky world. Uh, it reminds me a little bit about where we were eight years ago with GDPR and privacy.
Uh, so some analogies and some, some, some things that we can talk about that are different. Um, what I would say is that we hear at Atlassian believe in smart regulation of ai. Um, we believe that it's really a partnership between industry and lawmakers to, uh, I think create a regime that doesn't stifle growth, only encourages, um, you know, the development of technology and new technologies like ai, but also creates guardrails that, um, will produce AI that, um, is technology we all wanna live with.
It creates more of a utopia rather than a a, a dystopia. Um, specifically when it comes to the geo geographic differences that you've talked about, Mike, um, right now Europe is definitely leading the PACT with the EU AI Act. Um, Atlassian signed on early to something called the EU Pact, um, which was sort of a, a a, a lightweight regime that, um, we comply with today.
And it's something we can offer our customers here, say in Barcelona. Um, and then what I would say is that we're building towards that high watermark really sort of saying, okay, if the EU is leading the pack, let's go where the puck is moving. Um, and then in the meantime, you know, if the US decides that it wants to move in a a different direction, then I think we'll remain agile and we can pivot, um, when it decides where it wants to go.
The US is, uh, the United States of America and the various states have different attitudes towards AI as well. We'll see. Correct.
Things in California and New York, Colorado. Yep. And Texas.
Colorado, yep. Um, is there some sort of baseline standard that I can get to if I'm using AI that might be applicable to a broad number of these states and countries? Yeah, It's a great question.
Um, you know, what I would say is that, uh, in the US there's actually a government standard. It's called nist. Um, and that's something that if you want to sell technology to the US government, um, you have to go through that checklist.
And so for us, that's sort of been the, the closest industry proxy. There's also some, um, other industry standards that our customers are asking for in the United States, um, and elsewhere, it's an ISO standard, um, that's specific to ai. And so that's something that we're also, uh, having our roadmap to, to build towards.
Um, but as far as anything that is necessarily required, um, you know, that is a, a much more of a matrixed, um, approach. And so what we're trying to do is really build for scale since we have customers globally, rather than try and get too specific, um, build again towards that high watermark that we see, um, you know, sort of the industry moving towards. Uh, but this conversation in a couple years could be very different, Mike, And there are other regulations that still apply We'll, so say HIPAA and healthcare.
Oh, yeah. If I have an AI agent, it still has to comply with the HIPAA regulations. Yep.
And there's all kinds of other regulations. Yep. So, um, do those need to be tweaked or can they just be applied as is to AI agents and we'll just treat them like any other end user?
Yeah. So not only are there new laws, there's the existing laws that maybe have been around for, for, for many decades, privacy laws, data security laws, all like you just mentioned. Um, and so absolutely those, um, I think are, are, are, are the laws today.
And yes, they, they, they can apply to use cases. Um, specific to ai, my sense is that they will also need to evolve, um, that lawmakers will need to keep up with the development of technology and make sure that those are rightly, you know, adjusted and applicable to, um, new, new use cases. Um, so all to say that this is something that takes a full legal team like mine to really stay out ahead of and make sure, um, that not only are we complying, but we're also leading and influencing.
Um, and for example, we recently sent a team to Brussels here in Europe to help influence, um, the evolution of the law. 'cause again, this has to be this partnership between industry and lawmakers. Do you get the sense that the lawmakers are AI literate at this point, or are they, or is that still very much a work in progress?
Yeah, well, I mean, most of them are not technologists by trade. Uh, some of them are, um, and they have a, a series, uh, and you know, a a bench of experts that they rely on. Um, but I think that's the opportunity that we feel at Atlassian.
And, you know, being tech lawyers on my team, we really can help bridge the two sides technology and law and really I think help influence the, the outcome. So I've been very pleased, um, in talking to lawmakers and their ability to be fast learners, to be able to understand, um, you know, new areas of, uh, technology and be open to, uh, curiosity and learning. Yeah.
Are you also working with other vendor partners who are also have similar interest in AI regulations? I mean, can the industry kind of speak with one voice or is that always gonna be a hundred different voices? Yeah.
Um, so for me, you know, a simple, uh, I would say, um, you know, sort of model to look at within AI specifically are the fundamental LLM providers. So you're, you know, sort of anthropic, you're OpenAI, uh, your Gemini, um, and then you also have the deployers, which is more where Atlassian is, right? We're, we're taking the LLMs from the developers given all the, you know, incredible compute, um, infrastructure that it takes to stand up an LLM.
Um, and so maybe there, you know, I wouldn't say there's a, a schism or a divide, but I feel like when it comes to compliance and regulation, the laws today are looking a little bit more closely at the fundamental LLM providers saying, you know, do they have a kill switch? You know, are there things that are more consequential when you're actually developing the model than say, Atlassian, that's deploying the model for the end user. And so that's maybe where I see a little bit of the industry sort of, um, again, not a schism, but just sort of two different industry, uh, camps, um, and sort of how they're at least, um, looking at compliance and also what's the lift, um, in, in actually standing up a regime that that can comply.
Um, last time I checked, I don't think you can indict an AI agent, so we're, we're still responsible for what happens with this AI thing, but I don't know, do people really get that? I think are they gonna sit around and say, you know, well the AI did it, it's not my fault. Yeah, It's, it's great.
I mean, it's absolutely a, a partnership between humans and ai, and at the end of the day, the humans have to be responsible, uh, for the actions that that, that are taken. I, I do think it will be interesting to see, uh, maybe as, uh, some litigation works its way through the courts, um, where the liability truly lies for an agent's behavior. You know, was it the creator of the agent?
Was it the, the user who, you know, gave, gave the command? Um, I, I, I think it's still too, too soon to tell. Um, but at the end of the day, this really comes down to trust.
And the only way that AI is really gonna be successful and is gonna be something that we want to use, um, and really fulfill, I think the full capability and the full potential of AI will be if, if it is transparent. We know we're talking to ai, we're not talking to a human. Um, do we understand how the models trained, how the biases were either accounted for or not accounted for.
All of that I think is gonna be super, super important. And that's something that we here at Atlassian take very seriously. You probably know we have a company value of, um, open company, um, no b******t.
And so that transparency comes very naturally to us. Yeah. So you guys have been using AI agents within your own practice, right?
Yeah. So tell us a little bit about that. How are you using these things and what surprised you?
Yeah. I like to think, Mike, that we have the most innovative legal team, um, in, in any company out there. We are not afraid to embrace new technology.
We're curious, we like to experiment. Uh, we work for a company that is agile. Um, and so very much that is in, in keeping with our, our legal brand as well.
Um, we have, uh, identified two, we call them hero use cases for ai. They're both related to ro uh, the Atlassian, uh, product. Um, and so the first one is about, uh, our service management.
So we have a whole bunch of stakeholders internally within Atlassian who reach out to legal with questions, um, rather than get a whole bunch of emails and slacks, what we do is we funnel them in through what we call the legal one front door. So we use Jira service management as that front door portal with ro o powering, uh, all of the, the first line questions. So you might have a question and say, I wanna hire this new employee in this geo.
Um, I wanna make some changes to the employment agreement. You know, where should I go? Rather than have to have a human go in there and sort of point you, okay, here's the template and here's the page that tells you, you know, what changes are acceptable and which ones are not.
Ro o can actually do the first line of defense on that. Um, yes, you need a human behind the scenes, giving them the playbook, giving them, you know, doing the quality assurance to make sure that they're pointing, um, you know, the knowledge seeker in, in the right direction. But that's a really great example of how we can do more efficiency, um, and more throughput and not necessarily, um, you know, sort of have a, a, a human have to do that first pass.
The second hero use case that we have, uh, using AI in, in, in the legal team that Atlassian, um, is around, um, knowledge extraction. So think about, you know, in the old days you bought a company and they, uh, had a bunch of contracts and you had to hire a team of lawyers to go in and read those contracts. What are we buying?
Vendor contracts, employment contracts, sales contracts, maybe some leases. Well, rather than pay a law firm or have a team of, you know, five people, 10 people having to pour over these photocopies, you can feed those PDFs into vo ROA will extract a summary, a high level accurate summary of all those documents and give you a readout, say in a confluence page that you can then sort and go through and sort of say, well, here's the ones that, uh, are highest risk. Here are the ones that we don't care about.
Let those go through. That's all the power of ro o. Um, and so those are the two things that I'm really excited about that we've said though, if, if we can focus on those and standing those up with my legal team, we can then focus on the more high value things that are really attorney work.
Mm-hmm. Are you at all worried that AI's gonna replace lawyers at some point? It's Been, I've, I've, I've had some, I've had some friends reach out to me and, uh, and, and ask me about that.
You know, I think there's always going to be a need for judgment that that's the one thing that I think, um, the legal craft, um, needs humans to do, uh, and that AI cannot replace, is that there's always gonna be these, uh, I think very, uh, discrete edge cases that are gonna require really understanding the totality of facts precedent, um, being able to see shades of gray. And I, I, I think maybe AI can get us 50, 60, 70% of the way there, but it's that last 30% that takes human judgment, human discretion, um, a lot of, I think just experience that perhaps, um, AI can, can simulate. So maybe the legal craft evolves, um, but I don't think it ever replaces us.
Mm-hmm. Can we accelerate the legal process? I think if you ask most people who've ever been involved in the legal process than one impression they got, it was, it takes a long time.
Yep. Can we like reduce this down to something that's more manageable? Absolutely.
I think we can go much faster. Um, and I think, you know, the business can run that much more efficiently, um, with, uh, AI helping, uh, lawyers, um, and part of what I was just describing of getting a box of 600 pages of photocopies that used to take, you know, a team of 10 people 24 hours overnight, pulling an all-nighter in a conference room to read, you can feed that into VO and you probably can get the readout in about 20 minutes. Right?
And just think about that. And there was some great examples in the, the keynote, uh, yesterday from Rajiv around software coding. Same thing.
What used to take code review three days and a team of developers. I think you can do that now in a couple minutes. So it's just gonna free us up to do better things with our time.
That's, that's where I think the unlock is. One more question related to that. Yeah.
So when you take the bar exam, you're supposed to memorize all this stuff. Yeah. Do I really need to memorize all that stuff if I have AI agents going forward?
Good question. I, I feel like that comes back down to like the calculator of like, back in the, you know, we used to have to learn algebra, but now we have comp, you know, calculators and computers to do that for us. Um, I think that there probably still will be some benefit in testing for knowledge and standardized testing.
It's just gonna have to evolve. And maybe the things that we're testing for today are not the things we should be testing for in the future. Maybe the test will be on how does the legal craft use ai, that that could be more of a skills-based test.
There you go. Something to think about. All right, folks, you heard it here.
AI use it responsibly, but it can't do great things. Hey buddy, thanks for coming by. Thanks, Mike.
All right. Thanks for a great conversation and We'll be back in a minute.