CZ and Friends

S1E7

AI Governance and Why Legal Bottlenecks Start Upstream With Suzy GC Rachel Harris

AI Governance and Why Legal Bottlenecks Start Upstream With Suzy GC Rachel Harris

Released

45 minutes

Photo of Cecilia Ziniti

Rachel Harris

Rachel Harris

GC and AI Governance and Privacy Officer, Suzy

GC and AI Governance and Privacy Officer, Suzy

Dive Deeper

Transcript

Episode Overview

Episode length: 46 minutes | Released April 8, 2026

When in-house legal becomes a bottleneck, the fix is rarely inside the legal department. Rachel Harris, who runs legal, privacy, and AI governance at Suzy, the consumer insights platform, traces bottlenecks upstream: a sales team never trained on the business model, a security questionnaire nobody audited, a handoff between legal and engineering that AI can now remove entirely.

In this episode of CZ and Friends, Harris and GC AI co-founder and CEO Cecilia Ziniti map out AI governance for in-house legal teams, the cure for compliance theater, and the markdown file Harris used to hand her brain directly to engineering.

The night before recording, Harris built that file herself. It was a plain-language spec describing how consent should work across jurisdictions, age thresholds, and regulatory contexts.

Suzy's heads of product and engineering dropped it into their AI agents and started building a prototype the same morning. The legal spec became the product spec.

About Rachel Harris

Rachel Harris is the General Counsel and AI Governance and Privacy Officer at Suzy, an AI-driven market research firm. She began her career litigating multidistrict pharmaceutical cases on the plaintiff's side, where a federal judge appointed her to a national steering committee.

When GDPR took effect in 2018, she pivoted toward privacy, building privacy and governance programs from scratch for companies that had never had them. After a stint at the law firm Thompson Coburn, she joined Suzy, where she built the privacy program from the ground up and now also oversees security, privacy, and the legal side of procurement.

Key Takeaways

If legal is a bottleneck, look upstream first. Harris's diagnostic test, asking whether the team integrated into a department's workflow before the work reached legal, traced one sales-cycle bottleneck to account executives who had never been trained on Suzy's SaaS business model.

Meet your clients where they already work, not where legal wants them. Sales lives in Salesforce, engineers live in GitHub, and product lives in Jira, so Harris places legal guidance inside those tools instead of routing teams into legal's own queue.

A homegrown CLM built inside Salesforce cut contract turns in half. With no budget for a contract lifecycle management platform, Harris's team built a central reference sellers already used, taking negotiations from three turns down to two max.

The markdown file is replacing the product counsel handoff. Harris wrote a consent-requirements spec as a plain-language MD file and handed it to Suzy's product and engineering leads, who dropped it into their AI agents and had a prototype running the next morning.

Compliance theater starts where questionnaires go unaudited. Harris tests every security-review question against three checks, what it captures, why it's there, and whether it can be asked more clearly, and applies the same scrutiny before paying for certifications like SOC 2 or ISO 42001.

Why Is Plaintiff-Side Litigation Good Training for a Startup GC?

Plaintiff-side litigation teaches the founder's mentality a startup GC needs. It means making big bets under ambiguity, financing long timelines with no guaranteed payoff, and moving at the speed of owners who have their own money on the line. Harris started her career litigating pharmaceutical MDLs, and she considers that experience better preparation for a high-growth startup than any big law defense role.

Harris did not plan to end up in private practice. She said as much out loud in law school, to anyone who would listen.

The universe, as she puts it, tends to manifest the opposite of whatever she declares. Her first job out of law school was litigating pharma MDLs, work she describes with a baking analogy. A class action is many plaintiffs eating from one pie, while an MDL is a hundred plaintiffs with a hundred different pies, all baked in the same kitchen.

That first job taught her what it means to do hard, unglamorous, intellectually demanding work in service of a bet that might pay off in a decade or never.

One week in New York, she and a partner with a nursing background combed through 3,000 FDA MedWatch reports on a testosterone medication case, hunting for a needle in a haystack. They found it.

Rachel Harris, GC and AI Governance and Privacy Officer at Suzy, said:

"I think back to what if anything could have prepared me for life in a very high-growth startup, and it wasn't working at a big law defense-side firm. It was hands down working at the plaintiff's firm. There are so many analogies between the vibe and the speed at which you have to work and make decisions in the ambiguity and take big, bold bets."

The deepest analogy is financial. Plaintiff-firm partners sometimes take first, second, and third lines of credit on their own homes to finance litigation that might not pay out for ten years.

Harris calls it her first exposure to founder mentality, and it translated directly to working with a VC-backed CEO making the same kind of bets.

How Do You Move In-House Without In-House Experience?

Harris's path in-house ran through generalist corporate work, the GDPR scramble of 2018, and a predecessor willing to take a chance on a litigator from Missouri with no in-house or tech background. Her advice for anyone making a similar pivot is to spend the first 30 days talking to the teams you serve, give yourself permission to learn the company's tech stack, and skip the search for a perfect playbook.

After the MDL years, Harris deliberately un-niched herself, moving to a small firm for general corporate exposure. Then GDPR took effect in 2018 and she found herself building privacy programs from scratch for businesses that had never had one.

A stint at Thompson Coburn cemented a lingering feeling. Litigation was too reactive for her. She wanted to help companies before problems reached the courtroom.

Her predecessor at Suzy took a gamble on her and handed over one critical piece of advice. Your clients are the product and engineering teams, so go become best friends with them. Harris took it.

Harris said:

"There's no great playbook. The best playbook is: don't doubt yourself and make friends."

Why Does Legal Become a Bottleneck, and How Do You Fix It Upstream?

Legal becomes a bottleneck when it sits outside the workflows it serves. Harris's diagnostic is that legal is never its own end-to-end workstream in-house; it always sits inside someone else's flow, whether sales, procurement, or product.

So when the "legal is slow" feedback arrives, the question is where the process broke before the work reached legal.

The Department of No is a trap in-house legal knows well. Cecilia Ziniti opens the episode with the line that captures Harris's philosophy. If legal is a bottleneck, something upstream is broken.

Harris gets at the same idea in her own words later in the conversation:

"The real question becomes, have we not integrated ourselves into this workflow appropriately, to where once it gets to us, it feels like a bottleneck?"

Contracts counsel at Suzy was burning turns going back and forth with sales on agreements that did not match the product being sold. Prospects kept sending professional services agreements to a SaaS company.

Digging in, Harris found the upstream gap. Account executives had never been trained on the company's fundamental business model, so every mismatched contract at the finish line was a downstream symptom of a conversation that went wrong at the first sales call.

How Do You Build a CLM Without a CLM Budget?

Build the contract workflow into the system your sellers already use. Suzy had no budget for a contract lifecycle management platform and no appetite to buy one, so Harris's team built a homegrown version directly into Salesforce, where sales lived end to end.

Every salesperson gained a central source of truth. It showed them how to have the right conversations earlier, which issues to flag before they reach legal, and notes on each customer relationship's quirks.

Harris said:

"It has almost completely removed the notions of bottleneck or why are we taking three turns. We've got it down to two turns max."

Now, anytime legal feels like friction, Harris and her team re-evaluate the process and how early legal should be involved, so there are no bottlenecks at the finish line.

The same principle scales. Meet your clients where they live. Sales lives in Salesforce, engineers live in GitHub, and product lives in Jira.

Harris caveats that at 500 or 1,000 employees legal starts to operate as a more independent function. At a 100-person startup, embedded beats independent.

What Is Compliance Theater, and How Do You Avoid It?

Compliance theater is what happens when you put words in a questionnaire for the sake of having words in the questionnaire, or pursue a certification for the badge rather than because a customer requires it.

Harris's cure is a three-question audit of every line in your security review: What is this question capturing? Why is it included? Can it be asked more clearly?

A question that fails all three is probably theater.

Harris sits on both sides of the questionnaire. She reviews legal and data processing terms on Suzy's procurement tickets, which means she sends security questionnaires as well as answers them.

When vendor responses started dragging, her team locked themselves in a room and went through their own questionnaire line by line under a microscope, cutting what had no purpose and making the rest dynamic, so answering one question a certain way collapses the questions that no longer apply. The result was a faster, clearer experience for vendors and a more accurate picture of what happens with the data.

This is the same discipline in-house teams apply to AI governance and legal accountability more broadly. Start from what the regulation intends to capture, then build the process around that intent.

Which Security Certifications Are Worth the Money?

The certification question follows the same logic as the questionnaire audit. SOC 2, ISO 42001, and the other audit frameworks serve a genuine commercial purpose, but only when a customer requires them or they replace questionnaires.

Harris advises mapping each certification to a contractual requirement before spending, because audits cost real money and real headcount time. A SOC audit can run 45 days; overlapping ISOs can keep a team in audits for six months.

Harris said:

"Has a customer contractually required that \[certification\]? Or informally, is there just a lot of interest in us having that? Because if not, we're just jumping through the hoops for the sake of jumping through the hoops. And so you have to be very strategic in where you're investing those dollars, because those audits are not cheap."

Cecilia has seen the same tension from the GC seat. At one of her previous companies, a governance, risk, and compliance manager made the point that a certification only serves a commercial purpose if it replaces the questionnaires.

The rub, as Harris notes, is that even with four audits on the wall, the 500-question questionnaires keep coming from the verticals you would expect: financial services, healthcare, and insurance.

Her pragmatic response is to build knowledge bases that help her team get through the remaining questionnaires faster, a solution that respects the well-intentioned GRC person on the other side while the industry catches up to itself. For a deeper look at what those buyers are checking for, see the guide to data security in legal AI.

How Can a GC Hand Legal Requirements Directly to Engineering?

Write the legal requirements as a markdown file and let engineering's AI agents consume it directly.

The night before recording, Harris built an MD file describing how consent capture should work across jurisdictions, age thresholds, and regulatory contexts, the detailed nuances lawyers geek out about and product managers used to have to translate. Suzy's heads of product and engineering downloaded it, dropped it into their agents, and had a prototype underway by morning.

The traditional product counsel loop worked like this. Product asks legal about a launch, legal answers in legal language, and a product manager repackages the answer into specs engineers can build.

Harris's markdown file collapsed that loop. The legal spec became the product spec, and the translation layer disappeared.

Harris said:

"Can you infuse the brain of Rachel into the thing that you've built? So rather than marketing having to come to me and be like, hey, review this new go-to-market collateral for marketing law review. Instead, boom, you've already got an MD file from me. Put it where you already are."

The pattern extends past engineering. Marketing builds its own custom GPTs and skills; instead of routing collateral through legal review, Harris hands them a versioned MD file that carries her judgment inside the tools they already use.

Version two replaces version one, and nobody opens a Jira ticket.

Harris shared a related favorite AI moment in the episode. She recounts signing up for GC AI once it announced its Word integration, and using AI to apply redlines and generate commentary to the opposing party in real time inside Word. As she puts it, "it seems so not sexy now in hindsight, but at the moment, that is crazy."

Is the Modern GC Already a Product Manager?

Yes, whether she knows it or not. Harris's CFO tells her she should have been a product manager almost daily, and she can see it, but she argues the modern GC already wears that hat. She is product manager, project manager, and increasingly a direct contributor to engineering workflows, handing work product straight into the repository.

Harris said:

"The modern-age GC is that. It's one of the hats we wear. We are a product manager, whether we know it or not. We're product manager, project manager, all of the things."

Why Harris Says This Is the Best Time to Be a GC

Harris is already through the door on AI. She was jealous of the lawyers who got to navigate the advent of the internet.

Her message to lawyers at every stage, whether new to practice or 30 years in: the same window is open right now, and the lawyers who get in early and build their AI skills will define what comes next.

Harris said:

"I sure as heck wouldn't change getting to be a GC right now in the age of AI and how fun and crazy things are. ... We get to navigate the murky, messy, but also fun and exciting world of AI."

Her lightning-round answers land the same way. The book that shaped her thinking is The Simple Path to Wealth.

The advice she would give her younger self is to be kind and make friends. Her parting word for listeners is to experiment and have fun.

Harris embedded her legal judgment directly into the tools her business already uses. Ready to try that with your own team?

Recommended Reading

About CZ and Friends

GC AI CEO Cecilia Ziniti talks with the legal leaders rewriting how in-house teams work with AI.

Listen to the full episode

New to Legal AI?

GC AI runs free legal AI classes for in-house teams, from prompting basics to building playbooks, rolling out AI across a legal department, and working with agents.

Get started today.

Get started today.

Get started today.

See how in-house teams run that review — start with a free class, or try the platform on your own work.