Skip to main content

Robert Cruz

Robert Cruz is Vice President of Regulatory & Information Governance at Smarsh, a regtech firm, and a regular podcast guest on AI, e-discovery, and communications compliance.

Sep 30, 2026

0:32
Robert, why don't
0:33
you take it over? Awesome.
0:34
Thanks again for the invitation.
0:36
Hey, so there's a lot to talk about regarding AI and both e-discovery as well as investigation.
0:42
And I think that as we approach some of these topics on the regulatory side, some of them are fairly novel, but it feels like we've got a little bit more underfoot within discovery as far as how firms are using advanced technologies, machine learning and the like, In the e-discovery process, court decisions to lean upon, plenty of writings and speeches from Judge Peck.
1:05
But Anthony, what are some of the key things that have already been established as far as the use of AI because of what we've been through with predictive analytics and TAR? Where do we stand right now? Yeah, look, I think,

18 MINS LATER

18:56
You need to focus your resources on what is important to litigation, not on boiling the ocean.
19:02
Right.
1:01
So Robert, we'll start with you and what seems like a basic question, but is it? But what does reasonable supervision mean when applied to it?
1:09
It's a great question.
1:11
And in the case of supervision, the act of a compliance staff reviewing communications of individuals to look for policy infractions, AI or machine-based approaches aren't new.
1:22
We've had large language models and natural language processing.
1:25
So it's not an entirely new concept.
1:27
But key thing to note here, reasonable supervision, at least in the case of U.S. regulators, is very simple.
1:33
It's have a policy and demonstrate you're following it.

12 MINS LATER

13:14
So I want to take a step back, Robert, and go back to something that you had brought up earlier about the idea of moving from lexicons to models, right? With this proliferation of AI, are we seeing firms move away from the usage of lexicons and moving towards models?
0:33
Robert, do you want to kick
0:34
us off? Sure.
0:36
Thanks, everyone.
0:36
Appreciate you inviting me to today's session.
0:39
Being in the regulatory governance and compliance space for quite a while, you know, these topics come up.
0:44
And first of all, I need to say I'm not providing legal advice or opinions.
0:46
You must consult with your attorney regarding compliance with applicable regulations.

15 MINS LATER

16:15
But I do think that's one of the areas where there is a little bit lag behind and folks aren't realizing the record-keeping piece of it as much.
27:11
So are you seeing agencies, especially in this case where AI is moving so fast, adopting advanced AI models without the governance mechanism that goes, should go alongside of them, and what kind of risk does that present to the organization?
27:27
Well, we have a history, um, a recent history with something called off-channel communications, which not many firms wanna think back on.
27:35
It was not an easy time where, you know, the regulators really cracked down on the use of tools that were not approved.
27:41
So that whole process and what we learned and the infrastructure we built are things that governance executives are now trying to apply in the way that AI is being used so that, again, you're giving people the right tools to do their jobs, and you're making it clear, what are the, what are the consequences of using tools or using the use cases or using the wrong model, maybe a public model, where my intellectual property may be disclosed or made vulnerable.
28:06
Firms have to be thinking through that holistic picture of risk.
28:11
So your question and the premise is terrific 'cause that governance as overhead, I think what we're seeing now is firms are putting these programs together, and they're also bringing intellectual or the IP leakage group, the people that look a- after their intellectual property, the data privacy and infosec people, as well as the folks that look after regulatory.
28:32
'Cause the ri- the issues that could arise could be anywhere on that risk spectrum.
28:52
Does that make them better positioned to implement trustworthy AI, or does it just now expose weaknesses in how they've been doing that kind of information management?

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.