Ken Priore

Deputy General Counsel, Docusign · I help companies build AI they can actually answer for · Applied legal: product counsel for products that act
Most of it comes down to timing. Today's rules are the easy part. The harder part is what a team will have to answer for in two years, while the architecture is still changing. So I get legal into the room while the design is being made.
I call the work applied legal: product counsel for products that act. Products used to recommend. Now they send, charge, and call other systems, and the job includes deciding what a feature may do, who may approve it, and what proves the approval happened. We are teaching models to do legal work. I work with that and the other end of the pipeline: what the lawyer must still do, and how anyone will know it was done.
Beyond the Bio
High standards only matter if people can meet them. That takes trust, credit for good ideas wherever they come from, and cover when someone takes a smart risk.
What follows is mostly me in rooms with people who know things I don't: engineers, regulators, academics, other lawyers. I keep showing up because the useful problems sit in the gaps between what each room knows, and somebody has to stand in the middle and translate.
You can reach me at ken@kenpriore.com
ICML 2026 · AI for Law Workshop, Seoul

Taking the accountability argument to machine learning's home field
In July 2026 I presented my peer-reviewed paper, Certificate of Action: A Trust Primitive for Verifiable Autonomous Legal AI Agent Workflows, at the AI for Law workshop at ICML in Seoul, one of the first workshops the machine learning community has dedicated to law.
The room ran from PhD students hanging their first poster to researchers who have led their fields for decades, and nearly all of them were circling the same problem from different angles: how to measure legal work, verify an agent's conduct, and prove what happened after the fact. Law has no answer key, and watching computer scientists reach for social science methods to build one was the most instructive thing I saw all year.
My paper made the practitioner's case: agent capability is outrunning proof, and the missing artifact is a portable, verifiable record of what an agent did and on whose authority. The paper, poster, and research live at ai4law.kenpriore.ai.
NYU School of Law's Information Law Institute

In June 2026 I presented at "Fiduciary Duties and AI," a two-day workshop convened by NYU School of Law's Information Law Institute and the GliaNet Alliance. My talk, The Fiduciary Gap in Agentic AI, made the practitioner's case: a lawyer's duties of loyalty and care don't transfer to the software that now does much of the work, so the open question is how a professional proves those duties were honored when an agent acted. My discussion draft, The Fiduciary's Footprint: How Legal AI Agents Can Prove They Were Loyal, circulated to the workshop, works through what that proof would have to look like.
MIT FutureTech · AI Risk Initiative
The people most exposed to AI risk aren't the ones who can fix it
I contributed to MIT FutureTech's AI Risk Initiative study, Prioritizing the Risks from Artificial Intelligence, a Delphi study in which 272 experts across 37 countries ranked 24 AI risks by severity, by who is most exposed, and by who is responsible for doing something about them.
The people most vulnerable to AI risk (users, the public, whole sectors like finance and national security) are not the ones positioned to reduce it. That responsibility sits upstream, with frontier developers and governance actors. Aviation and pharma built liability, testing, and oversight to bridge exactly that kind of gap. For AI, those mechanisms are mostly still missing.
That is the work I keep coming back to: closing the distance between who carries the risk and who answers for it, and building governance into the architecture instead of bolting it on at the end.
Read the study at airisk.mit.edu/priorities
AI Engineer World's Fair: San Francisco
Why I'm at AI Engineer World's Fair

I'm a lawyer who builds things. In most rooms that gets a polite nod. Here it's just what everyone does.
For the last year or so I've been writing about a fairly narrow problem: how you take a big pile of contracts and turn it into something a negotiator would actually rely on in the middle of a deal. Not a chatbot that summarizes. Something with a record of where each answer came from, a pipeline you can version and inspect, and a way to pull in the context that never makes it into the contract itself (the CRM notes, the account history, what happened last time with this counterparty).
It turns out that's an AI engineering problem more than a legal one. Every hard part of it maps to a track on this schedule. The MCP workshop, the context engineering sessions, the evals talks, the memory stuff. I keep reading the descriptions and thinking, yes, that's the thing I've been stuck on, described by someone who's shipped it.
So I'm here to learn from people who've already solved this for software, and to bring the legal-side problems they probably haven't run into yet. The consent posture on training data, what survives anonymization, why a lineage trail matters more to a general counsel than a better model does.
If you're working anywhere near contracts and agents, come say hi. I'd rather have that conversation than sit through another keynote.
FPF Advisory Board Meeting
Advisory Board Meeting in Washington, D.C.
In June, I shared a stage at the Future of Privacy Forum's 17th Annual Advisory Board Meeting in Washington, D.C., on a panel called "Lessons from Leaders: AI Legal Policy & Governance Power Users." The room included senior counsel from IBM, Anthropic, Meta, and Medidata, moderated by Stacey Gray, FPF's Senior Director for AI. The brief was practical: what are we doing with these tools right now.
So instead of a slide, I showed a build: a Certificate of Action, a signed record of what an agent was permitted to do, what it did, and the proof that ties the two together.
When an agent moves money, signs a document, or runs a step in a workflow, a policy layer tells you what should have happened. The agreement and execution layer is where intent becomes a record of what did happen, and that record is the part that has to hold up in an audit, a dispute, or a regulator's inbox.
Sharing that stage with IBM and Anthropic on this question says something on its own. The companies building the models and the companies running them in production are converging on the same gap: governance is easy to write down and hard to prove.
The agenda made the same point from a different angle. One working session asked how teams are folding agentic workflows into existing risk assessments, and whether legacy privacy assessments should absorb new AI requirements or stay separate. Chatbot and agent governance came up in nearly every breakout, and in most of those rooms the answer was that the policy is still being written. The question underneath it, who holds the receipt when the agent acts, is the one this work is built to answer.
Frameworks describe accountability. Receipts prove it.
BSA | The Software Alliance Panel
Governing Agents Before the Rules Are Written

IIn May 2026, I spent a day in San Francisco with AI, legal, and policy leads from across the enterprise software industry, convened by BSA | The Software Alliance. We came at one problem from a dozen angles: how do you govern agents that act autonomously when our assurance models still assume a human reviewing a system at a single point in time?
The Gaps? Provenance and audit trails that don't survive an agent handing work to another agent. Identity and authorization questions that have no clean answer when the thing acting is a piece of software. And a speed mismatch nobody could wave away: agents operate in seconds, while the certification and assurance cycles we rely on move in quarters.
Security, privacy, and AI ethics walked into that room as three disciplines and left looking like one. The teams furthest along were building toward a single accountability layer that all three could share.
The day reinforced a thesis I have been building toward: governance has to live at the level of action authority, meaning what an agent is permitted to do, on whose behalf, and how that is proven after the fact. Policy on paper doesn't reach that far. That is the work I care about most, building the accountability infrastructure before the rules are settled, so teams can keep moving without flying blind.
NOVA School of Law · Lisbon

Consent Was Built for a Moment. Agents Don't Have One.
In April 2026, I gave 2 lectures the at NOVA School of Law in Lisbon: once for Graça Canto Moniz's master's course on EU data protection, and once for Vera Lúcia Raposo's cohort. I called it "When Consent Has No Moment."
The argument starts from something simple. Consent was built for a moment in time. A user reads a screen, decides, and clicks. Agents have trajectories. One click can set off forty-seven actions across four systems over three days, and the question of whose consent governs step forty-seven has no good answer inside the frameworks we have built. Underneath the GDPR sit four assumptions: that consent happens at a discrete point in time, that purposes stay stable once declared, that decisions are discrete events, and that a human can review what happened. Agentic systems break all four at once.
I spent most of the session on nondeterminism, because I think it is the problem everything else rests on, and it is still treated as an engineering nuisance instead of a governance one. It shows up in three layers. At the output layer, the same prompt can produce a different answer twice in a row. At the reasoning layer, confidence and correctness come apart, and the wrong answer tends to get more persuasive as the model improves. At the trajectory layer, the path an agent takes differs on every run, so an audit log records one roll of the dice and nothing more general than that. Software is deterministic. Agents are not. Every compliance framework I know of still assumes otherwise.
That leads to the practical half of the talk. Governance lives in the harness built around the model: the permission scopes, the escalation logic, what gets surfaced to a human and when. Those are design decisions, and if lawyers don't make them, engineers will, because someone has to. I walked the students through the three-tier framework I use day to day: automated for reversible, non-production actions; supervised, where an agent proposes and a person approves after reading it; and lawyer in the loop for anything customer-facing, irreversible, or regulatory. I also pushed back on a common confusion. The business requirement is the specification. The contract is the code that runs against the world.
I closed with something I built in a week to pressure-test the idea: a tamper-evident, hash-chained record of what an agent did, under what policy, with what reasoning attached. A working proof. The note I left the students with is that the lawyers who can build systems like that, or who can talk fluently with the engineers who do, are the ones whose skills will matter over the next ten years.
UC Law San Francisco's Law & Artificial Intelligence Program
In March 2026, I completed UC Law San Francisco's Law and Artificial Intelligence Certificate Program, hosted by LexLab. A week with practitioners, technologists, and legal scholars all grappling with the same pressure: the law is being asked to govern systems it doesn't yet fully understand.
The program ended with a fitting exclamation point. One of the last speakers was Dean Ball, former senior AI policy adviser to the Trump White House and primary staff writer of their AI Action Plan. Sharp, and thoughtful about both the technology and the policy tensions underneath it.
I walked out of the building, opened my podcast app, and there he was: Dean Ball on The Ezra Klein Show, discussing why the Pentagon was moving to declare Anthropic a supply chain risk. The same person. The same week. Two very different rooms having the same argument about who controls AI and why it matters.
That's the meta-moment of this field right now. The policy conversations happening in law schools, the White House, and the New York Times opinion section are converging, fast, because the stakes are real and the rules aren't settled.
Grateful to Drew Amerson and the LexLab team for putting together a program that took both sides of that gap seriously.
In Conversation
Exploring AI, law, and innovation through podcasts, panels and interviews
PLI : AI and Intellectual Property

The Convergence of AI and IP: Policy Frameworks That Actually Work
For the second year, I participated in PLI California's program on AI and intellectual property in San Francisco.
The conversation centered on the gap between having AI policies and actually implementing them. We walked through IP risks that often get missed—not just copyright infringement from training data, but ownership questions when outputs blend human and machine work, trade secret exposure when employees input sensitive information into public models, and patent implications when AI contributes to inventions without meeting the "significant human contribution" standard.
We spent time on agentic AI governance, which raises different questions than prompt-based systems. When AI acts autonomously rather than responding to inputs, the decision points shift. Where do humans intervene? How do you map data provenance when agents collect and use information dynamically? What standards apply when multiple AI systems hand tasks between each other?
The session reinforced something I see across organizations: governance frameworks work when they're built into existing structures rather than layered on top. IP committees, invention disclosure processes, vendor approval workflows—these already exist. The question is how to extend them to handle AI-specific risks without creating parallel bureaucracy that teams ignore.
My takeaway: companies don't need more policies on paper. They need governance that maps to actual decisions teams make—which models to approve, which use cases to greenlight, which data sets carry acceptable risk. That's where IP protection and innovation can move forward together.
IAPP Privacy. Security. Risk

AI Governance as a Driver of Innovation
In October 2025, I presented "AI Governance as a Driver of Innovation Amidst Regulatory Flux" at IAPP Privacy. Security. Risk in San Diego alongside Bret Cohen (Hogan Lovells) and Saima Fancy (Data Governance Product Manager, Adobe).
The session focused on a practical challenge: how to build AI accountability structures that match the speed at which teams are shipping. We presented a three-pillar framework that treats trust as infrastructure: cross-functional governance with real authority, existing privacy and security controls extended to AI in place of parallel structures, and trust impact measured alongside technical risk.
The conference reinforced a pattern I've been tracking: the EU AI Act, Colorado's AI law, and California's CCPA regulations are converging on the same operational demands. Companies must risk-assess, test, and monitor high-risk systems. They must explain why systems reach certain results. They must show that someone is responsible for what their AI does.
The most valuable conversations happened in the hallways, with practitioners admitting what is broken in their governance frameworks and sharing what's working. Those conversations shaped a series of posts I published afterward on California's privacy infrastructure, the developer-deployer divide, making governance frameworks teams want to use, and how privacy principles struggle when applied to autonomous agents..
ABA Artificial Intelligence and Robotics National Institute

We're not just regulating tools anymore—we're governing systems that make autonomous decisions.
In October 2025, I joined a panel at the American Bar Association's Artificial Intelligence and Robotics National Institute titled "In-House Insights: Managing AI Challenges and Change." Cynthia Cwik (JAMS) moderated a conversation with Matt Samuels (Anthropic), Roy Wang (Eightfold AI), Belinda Luu (Kaiser Permanente), and me that cut straight to what in-house teams are wrestling with right now.
Cynthia's opening question, what we really want from outside counsel, set the tone for a conversation that moved past platitudes. Matt and I explored how AI agents are creating an entirely new surface for governance: we're moving from systems that assist to systems that decide. Roy brought us back to fundamentals: build what customers need before building what the technology makes possible. And Belinda and I kept circling back to the same principle: trust is the foundation for any AI guidance people will follow.
The through-line: the best AI solutions emerge when legal thinking is woven in from the start. That's where innovation and responsibility meet.
Stanford Law: Agentic AI

Where AI Autonomy Meets Legal Reality
In September 2025 I spent a day at Stanford Law School's panel on agentic AI, on one of the most pressing questions facing organizations today: how do you deploy AI systems that make independent decisions when your legal frameworks assume humans are always in control?
The room was filled with legal and product leaders from major corporations, all grappling with the same challenge. Their engineering teams are building agents that can interpret goals, plan multi-step actions, and execute transactions autonomously. Their organizational structures, contracts, and risk frameworks were designed for software that waits to be told.
The gap that mattered was between technical capability and deployment readiness. Companies have impressive demonstrations of autonomous AI, and they're stuck in pilot phases because they haven't solved the attribution problem: when an agent makes a decision you didn't directly program, who is accountable for the outcome.
This is the kind of challenge I work on: helping teams build AI systems that are both innovative and responsibly deployed. The discussions at Stanford reinforced what I see in my practice. The organizations succeeding with agentic AI are building new frameworks for governance, accountability, and risk management alongside the technical work, frameworks that adapt as AI capabilities change.
The technology is moving faster than the legal and organizational frameworks designed to govern it. My work sits at that intersection, translating technical capabilities into legal and business strategies teams can implement.
“AI is getting very good at acting like a lawyer. It isn’t one.”
JJessica Nguyen asked me on the In-House podcast the question many legal professionals are wrestling with: is AI going to take our jobs?
My view is that AI is reshaping nearly every role inside the legal function without replacing the lawyers in it. I put it this way on the episode: "I'm not worried about it taking my job — I'm worried about how it will fundamentally change almost every job in the legal function."
The conversation with Jessica and Jenny Hamilton (CLO, Exterro) circled around this idea of change. We drew comparisons to the early years of eDiscovery, when the shift from paper binders to searchable databases felt daunting. Those tools changed how lawyers worked, saved time, and created new kinds of work. The same pattern is now playing out in contracting, risk review, and other workflows with AI.
AI is good at acting like a lawyer, and that is why the human role matters. As I said, "For folks who want to stay in the same exact spot where they are, that's going to be really difficult." Lawyers will need to stay in the loop to review, correct, and redirect outputs. That oversight prevents malpractice, protects clients, and keeps efficiency from costing judgment.
Adoption has to be tied to real problems. Lawyers and teams have limited time, and new technology needs to show why it matters quickly. Curiosity is a good start; durability comes from solving specific needs and making people's work easier.
AI in legal is a story of adjustment, new skills, and lawyers stepping into the role of translators between powerful tools and human judgment.
AI and the future of the legal department
Back to co-hosting the "In-House" podcast with Jessica Nguyen! We had a fantastic chat with DocuSign's legal leaders, Sandy MacDonnell and Krysta Johnson, about the future of the legal department.
Three threads ran through it. Legal ops has moved past cost-saving; it now shapes company goals and brings in revenue, and the job is running the legal department like a business. AI is already handling everyday tasks, which frees lawyers for the work that needs one. And adoption works when the technology solves the right problem and people stay in the loop, which means involving the people affected early and managing the change.
My take: the line between "legal ops" and "legal" is dissolving. Operational thinking is becoming part of everyone's job, and the tools are making that possible. The full episode is above.
Who Owns the Call? Building Clarity, Speed, and Trust in Legal Decisions
I joined Jessica Nguyen on the In-House podcast for an episode on "The Art of Decision Ownership": how legal leaders move out of review-and-approve mode and into the role of trusted advisor, by sharing ownership of risk, getting into the conversations where direction gets set, and building a culture where people can take informed risks. In large companies, you need early agreement on who is the directly responsible decision maker; without it you get decision paralysis. Legal's job is to surface the concern, invite the dialogue, and get teams thinking differently about the problem. Saying no is the smallest part of it.
Decision ownership is as much about process and relationships as about the decisions themselves. Clarity on ownership has to come early, before hard calls arise. Legal belongs upstream in strategy; the final-approval seat is the wrong place to first meet a problem. Framing issues as "how do we solve this together" gets further than "legal says no," and documenting the thinking behind major decisions protects the company when a regulator asks. Psychological safety does the rest: teams take informed risks and treat mistakes as things to learn from, and nobody spends the meeting assigning blame.
PLI : AI and Intellectual Property

Structuring AI Governance for Real-World Impact
In this Practicing Law Institute program, I walked through the building blocks of an AI governance framework that works in practice: how to define an AI-specific mission, vision, and plan; set measurable KPIs; and establish governing committees that blend C-suite leadership, legal, data science, IT, marketing, and other voices. I made the case for formal policies and guidance backed by clear internal controls, including approved-use lists for AI technologies, applications, data sets, and vendors. We covered policies governing public AI use, vendor oversight, and organizational messaging, and the role of checklists and approval workflows in keeping governance embedded in daily operations. Strong governance manages risk. Done well, it also lets AI work go forward inside clear, transparent guardrails.
Developing an AI Use Strategy & Policy | Part 1
I kick off this series by digging into why AI policies matter now, and how to move from lofty principles to guardrails teams can use. We cover the risks companies tend to overlook, the building blocks of a policy that holds up, and the cross-functional muscle it takes to make governance stick. My takeaway: good AI governance creates the conditions where innovation and responsibility move forward together
AI Use Policies: Involving the Whole Business | Part 2
For the second installment, I focus on one of the toughest challenges: making governance real across the entire organization. Policy has to be a shared framework that everyone, from engineers to marketers to leadership, can understand and apply, and it dies in a siloed document owned by legal. Real governance means a common language, clarity for teams without stifling creativity, and principles turned into everyday practice. The goal is trust and alignment that let people move fast and responsibly.
So You Have an AI Policy. Now What? | Part 3 | Briefly
In this segment with Briefly, we move past drafting and into the harder part, bringing an AI policy to life. Too often, policies exist only on paper, disconnected from the people making day-to-day decisions. Here we work through how to close that gap: educating teams, reinforcing accountability, and weaving governance into daily workflows until it becomes second nature. My core message: the value of an AI policy is in how it shapes behavior and builds trust across the organization.
Tulane Law, Privacy Lecture: September 2022

In September 2022, I returned to Tulane Law School as a guest lecturer for Amy Gajda's privacy law concentration. Amy Gajda held the Class of 1937 Professorship, and her course gives students a practical grounding in privacy that goes beyond theory.
What I talked about that day was how my career, from financial services through venture capital, mobile dating, and enterprise applications, kept circling back to the same questions. How do you build technology that people can trust? What does privacy mean when the systems get more complex but the people using them stay the same?
Those aren't abstract questions for me. In mobile dating, you're handling some of the most sensitive data people share. In enterprise software, you're building tools that touch millions of users who never consented to be in your system. Each shift taught me something about where privacy protections break down and what it takes to build them in from the start.
Teaching at Tulane crystallized something I'd been learning across those different contexts: privacy is about understanding how systems work, what can go wrong, and what you need to build to prevent that. A compliance checkbox doesn't get you there. First-principles thinking means asking "why does this rule exist?" before you decide how to apply it.
That's what I bring to teams building AI systems now: an understanding of why the regulations exist and how to translate that into architecture that protects people without grinding development to a halt.