TrenchOps 🐎

Insights from the tech trenches

Legal

Cover Image

The AI Not-To-Do List

Ten Things Your Company Should Never Delegate to a Machine, Ranked by Blast Radius

Classic scenario: an executive pasted an entire acquisition contract into a free public chatbot. He wanted a summary because reading twelve pages was, quote, "not a good use of his time." He got a lovely summary. He also got a confidential M&A document uploaded to a third-party server, which - depending on how you read the NDA he had personally signed - was somewhere between "career-limiting" and "please forward all future correspondence to my lawyer."

The best part: the deal was so straightforward that his own legal counsel could have summarized it in the elevator. He didn't save time. He converted a five-minute conversation into a compliance incident.

Everyone asks what AI can do for their company. Almost nobody asks the more profitable question: what should it never do? So let's invert the problem. If I wanted to guarantee an AI disaster, what would I deploy? Here's the list. Count how many your org is already doing. Two or fewer is excellent. Five or more - well, it was nice knowing you.

The hard no's: where lawyers get involved

1. Feeding confidential or regulated data into unvetted tools. GDPR data, health records, trade secrets, customer contracts. Pasting them into a public chatbot is publishing with extra steps. There's no attorney-client privilege for your chat history - it can be subpoenaed, and courts have already gone fishing in exactly those waters. The chatbot will never sit in the deposition. You will. That's the whole test right there: never delegate a decision to something (or someone) that can't be fired, fined, or sued for it. The AI has no skin in the game. Yours is the only skin available.

Read more
Cover Image

The Employee You Cannot Sue

A friend told me this story about a Company that hired a remote support engineer from a country with beautiful beaches and terrible rule-of-law. They worked European hours, had full access to the CRM, and handled tickets for enterprise customers across Germany, France, and the UK. On paper, it was a perfect hire: talented, responsive, and cheap.

After a few months, they noticed an odd pattern. Customer churn was increasing in a way that correlated with this engineer's shift. No obvious cause in the tickets themselves. But an elaborate security audit revealed that a competitor had started approaching their customers with suspiciously accurate knowledge of their infrastructure, decision-makers, and contract terms.

That engineer had been quietly exporting customer data from the CRM during his shift for three months. He just looked into the account data, wrote it in a notepad, typed it back into his personal computer, and then sold it to a shady data broker who resold it to the competitor. The total payout to the engineer was probably a few thousand dollars (or the equivalent in Bitcoin). A fraction of their annual salary.

The company found out. They fired the engineer. They contacted local law enforcement. And then they hit a wall.

Read more