THE BIG IDEA
AI is changing the role of corporate legal departments from reviewing products to helping design them. ADP argues that responsible AI begins long before a product reaches the legal team. By embedding lawyers alongside engineers, product managers and data scientists from the start, companies can make governance part of the product’s architecture rather than a last-minute compliance exercise. The approach offers a blueprint for building AI systems that are both innovative and trustworthy.
Generative AI is changing how corporate legal departments function, requiring them to move deeper into product development – and turning lawyers from final-stage reviewers into participants in decisions about how AI systems are designed, tested and used.
At payroll giant ADP, that means legal staff work alongside product managers, data scientists, privacy specialists, security teams and user experience designers from the earliest stages of an AI project, according to Helena Almeida, assistant general counsel and chief AI legal officer at ADP.
“We are sitting side by side with the people who are coming up with the ideas for the products, designing the early models of the products, testing, iterating, developing the products – the entire time,” said Almeida, in an interview with The AI Innovator.
Need more clues? Ask the Sherlock chatbot in the lower right corner to summarize this story, explain technical concepts or answer other questions.
ADP calls the approach “compliance by design.” Instead of presenting lawyers with a finished product and asking for approval, the company brings legal and other governance functions into discussions before the system has been built.
While the approach predates generative AI as ADP has long handled sensitive workforce and payroll information, the number and variety of generative AI proposals have required the company to formalize and expand its review processes.
“We’ve had to update that and tweak it and modify it to deal with the volume that generative AI use cases have brought,” Almeida said.
Legal questions become product decisions
When an ADP team has a product idea, they approach Almeida to ask about the legal considerations. Then they go into a discussion of the business problem the product would be solving, the data they would use, how that data would be protected, how its output would be used and whether the product could affect individuals, according to Almeida.
“What is the impact to actual people from this product? And how are we going to test and monitor it?” Almeida said. “We’re thinking about that from the beginning.”
Those questions can change the design of the product rather than merely producing legal disclosures or contractual protections.
“I think the most useful legal advice ends up being a design decision,” Almeida said. “These conversations that we’re having at the beginning end up being influential in how we design our products.”
To be sure, the entire process is supported by ADP’s governance group, which includes representatives from legal, privacy, security, product and data teams. The company also has an AI and Data Ethics Council with internal and external specialists, including experts in ethics and AI systems.
But Almeida said formal committees are only part of the solution. Most governance happens through continuous conversations among the people designing, operating and reviewing the product.
“That’s how you end up with the best output. If you try to bolt legal onto the end of a process, you’re not going to get the best outcome,” she said.
Rethinking the process before adding AI
Almeida said one of the most common mistakes enterprises make is placing AI on top of an existing workflow without first determining whether the workflow itself should be changed.
She compared the practice to installing a faster conveyor belt in a factory that is already producing defective goods.
“You’re just using AI to speed up faulty output,” she said.
ADP applied that thinking to a payroll product that identifies variances between a company’s current payroll and previous payrolls. Instead of automating a process that generated reports few people read, the company studied the steps payroll professionals actually followed when reviewing discrepancies.
That analysis allowed the team to eliminate unnecessary steps and focus the product on information practitioners could use to identify potential problems.
“If you bolted AI on top of that to produce reports that nobody cared about, nobody read, you’re not really getting any value out of that,” she said. “But if you took the time to think, ‘wait a minute, what are those reports actually useful for? Who’s looking at them? Why do we need them?’ You might cut out some steps … and get to a better output faster.”
Guardrails vary by use case risk
ADP is not only using generative AI, but it has been using traditional AI for a long time. All those years of experience helped the company understand how to apply nuances of governance to different use cases, Almeida said.
“As we learned more about AI, we were able to provide different levels of governance to it – to right-size the governance based on the use case,” she said.
A back-office tool that tallies numbers or automates an administrative task may not require the same review as a system that influences a hiring process or provides information used in workforce decisions, she said.
Applying the strictest possible controls to every use case could slow relatively low-risk projects without providing meaningful additional protection, Almeida said. The company instead assigns different levels of risk to AI applications and adjusts the governance process accordingly.
That risk assessment is becoming more important as companies experiment with AI agents that can complete multiple steps with less direct supervision.
ADP is exploring agentic systems, but Almeida said the company is not designing AI to make critical workforce decisions for its clients. Its goal is to give human decision-makers better information while allowing automation to handle appropriate sequences of routine tasks.
An agent, for example, might carry out six steps after a person instructs it to complete a defined process. The user would not have to approve each individual step, but would retain control over important decisions.
“One of the things that I spend a lot of time doing is thinking about where the human oversight needs to be,” Almeida said. “Friction is … not something that you want to totally get rid of because you want somebody to have to take that pause to review what the AI output is.”
Responsible AI must live in the workflow
But policies alone are not sufficient to govern AI, Almeida said.
The requirements established by ADP’s cross-functional governance group must be reflected in the user experience, documentation, testing process and operation of the product.
“Responsible AI has to actually live in the workflow,” she said. “It can’t just be a policy.”
The review also continues after a system is introduced. Teams must monitor how the product performs and update the controls as the technology, use case and regulatory environment change.
“None of this is going to be – you get it right the first time and you stop looking at it,” Almeida said. “It has to be a constant evolution.”
As for complying with global AI regulations, ADP applies a common group of principles across markets rather than building an entirely separate governance program for each jurisdiction.
Although AI laws differ, Almeida said many are converging around transparency, explainability, fairness, human oversight, security and data protection.
The company’s objective is to design products that meet a consistent standard wherever they are offered, including in locations without comprehensive AI laws.










