AI adoption in law firms may be happening faster than many leadership teams realise.
It doesn't necessarily begin with an organisation-wide AI strategy or a major technology implementation. Sometimes it begins much more simply: a lawyer opens an AI tool in their browser and discovers that something which previously took 30 minutes can now take five.
They might use it to summarise a document, improve an email, structure some notes, brainstorm questions or analyse information. From the lawyer's perspective, the attraction is obvious.
But there is another question law firm leaders need to consider: What information are people giving AI in order to get those results? That question is becoming increasingly important because AI adoption and governed AI adoption are not necessarily the same thing.
AI Adoption Doesn't Always Wait for an AI Strategy
Generative AI is remarkably easy to access. Employees don't necessarily need new software installed, a company licence or assistance from IT to start experimenting.
That means AI adoption can begin at an individual level long before leadership has formally decided how the firm intends to use it. This is sometimes referred to as Shadow AI — employees using AI applications without the organisation necessarily having visibility or governance around that activity.
It doesn't automatically mean employees are behaving recklessly. In many cases, people are simply trying to work more efficiently. But it creates an important visibility gap for leadership.
Which tools are being used? What are they being used for? Are personal or consumer accounts involved? And, crucially for a law firm, what client or firm information might be entered into them?
The Productivity Opportunity Is Real
It's important not to lose sight of why lawyers are interested in AI in the first place. Legal work involves enormous amounts of information. Documents need to be reviewed, correspondence drafted, meetings summarised, ideas researched and complex information organised.
AI can potentially assist with many of these tasks. A lawyer might reasonably wonder whether AI could help them:
- summarise a lengthy document;
- structure notes from a meeting;
- improve the clarity of correspondence;
- extract information from a contract;
- brainstorm questions or arguments;
- organise information relating to a matter; or
- reduce time spent on repetitive administrative work.
The business case for exploring those opportunities can be compelling. The problem isn't that lawyers want to use AI. The challenge is making sure the firm's approach to AI keeps pace with the way people are actually using it.
Client Information Changes the Conversation
Consider two AI prompts. The first asks an AI assistant to suggest an agenda for an internal team meeting. The second asks it to summarise a document containing confidential information about a client matter.
Both involve AI. But they don't necessarily involve the same level of risk. For law firms, that distinction matters enormously. Depending on the work being undertaken, information could include confidential client material, personal information, commercially sensitive information, privileged communications, contracts, matter documents or internal firm information.
That means a useful AI governance framework needs to go beyond a simple question of whether the firm allows AI. Leadership needs to be able to answer a more practical question: Which information can our people use with which AI tools, and under what circumstances?
If the answer isn't clear to leadership, it is unlikely to be clear to every lawyer in the firm.
Not Every AI Tool Is the Same
Another potential trap is talking about “AI” as though every platform carries the same risks. They don't. A freely available consumer AI service may handle information differently from an enterprise platform deployed and configured specifically for organisational use.
Different tools may have different approaches to data retention, model training, security, privacy, administrative control and auditability. Some may integrate deeply with information already held by the firm. Others may operate largely independently of the firm's existing environment.
So a policy that simply says “AI is permitted” or “AI is prohibited” may not provide enough guidance. A more useful approach is to establish which tools the firm has assessed and approved, which use cases are appropriate, and what information can be used with them.
That gives lawyers something more practical than a list of restrictions. It gives them an approved path.
Banning AI Isn't the Same as Governing It
Faced with uncertainty, a blanket ban can feel like the safest option. But there is an important difference between prohibiting AI and controlling AI. If employees can access generative AI from almost any web browser or personal device, a policy alone does not guarantee that experimentation stops.
In some cases, overly restrictive approaches can simply push AI adoption further out of sight. That creates an uncomfortable situation: the organisation may believe it has eliminated the risk because AI isn't officially approved, while employees continue experimenting through tools the firm cannot easily see or govern.
The better objective is not necessarily to stop people exploring AI. It is to create an environment where they have less reason to work around the organisation's controls in the first place.
Good Governance Can Enable AI Adoption
The word governance can make AI sound like it requires an enormous committee, dozens of policies and months of planning before anybody can begin. It doesn't have to. A practical starting point can be agreeing on some relatively straightforward questions:
- Which AI platforms has the firm approved?
- What information can and cannot be entered into them?
- Which AI use cases are acceptable?
- Who is responsible for assessing new tools?
- When is human review of AI-generated output required?
- How should employees raise new AI ideas or applications?
- How will the firm educate people about responsible AI use?
- How will the approach be reviewed as the technology changes?
These questions don't answer every possible AI risk. They do, however, give the organisation a framework for making deliberate decisions rather than allowing AI adoption to develop entirely by accident. And importantly, governance doesn't have to exist purely to restrict AI. Good governance can give leadership the confidence to approve more AI use, not less.
Make the Rules Relevant to Legal Work
AI guidance also needs to make sense to the people expected to follow it. A long policy filled with abstract statements about confidential information may technically cover the issue, but it doesn't necessarily help a lawyer make a decision in the middle of their working day.
Practical guidance should address the questions people are actually likely to encounter.
-
Can I upload this contract for summarisation?
-
Can I ask AI to rewrite this client email?
-
Can I enter notes from a client meeting?
-
Can I use my personal AI account for work?
-
Can I use an AI tool to research an issue relating to a matter?
-
What should I do if I find a new AI application that could save our team time?
Those are much easier questions for people to apply to their day-to-day work. The goal should be for employees to understand not only what the rules are, but why they exist.
Leadership Doesn't Need to Become the AI Department
Managing Partners, COOs and other firm leaders don't need to understand every technical detail behind generative AI. But AI adoption can't sit entirely with IT either. There are decisions here that are fundamentally business decisions.
What level of risk is acceptable? Which use cases genuinely benefit the firm? What obligations do we have around client information? Who is accountable for responsible adoption? Where should human judgement remain essential? What kind of AI use would our clients reasonably expect us to disclose or control?
IT can provide critical guidance around security, platforms, identity, access and data protection. But leadership provides the organisational direction. The strongest AI strategies are therefore likely to involve both.
Ask What People Are Already Doing
One of the most useful starting points for leadership may be surprisingly simple: Ask people how they're already using AI. Not as an investigation. Not as an attempt to catch somebody breaking a rule. Treat it as discovery.
Which tools are people experimenting with? Which tasks are they trying to improve? Where are they seeing genuine productivity gains? What concerns do they have? Where are they unsure about what is permitted?
The answers can reveal both risk and opportunity. If several lawyers are independently trying to solve the same problem with AI, that may tell the firm something important about where a supported AI use case could deliver value.
If employees are unsure whether client information can be used with a particular platform, that tells leadership where clearer guidance is needed. Visibility creates the opportunity to make better decisions.
Client Trust Needs to Extend to AI
Clients already trust law firms with highly sensitive information. As AI becomes part of legal work, that trust increasingly extends to how firms use emerging technology around that information.
Clients may reasonably expect their information to be handled deliberately rather than entered into whatever application happens to be convenient. That doesn't mean law firms should avoid AI. Quite the opposite. Firms that can demonstrate a thoughtful approach to AI may be better positioned to adopt the technology confidently while maintaining the standards clients expect.
The aim isn't to choose between innovation and confidentiality. It is to create the governance that allows the firm to pursue both.
One Question Worth Asking
There is a simple question leadership teams can use to test where they currently stand: If one of your lawyers wanted to use AI with client information tomorrow, would they know exactly what they were allowed to do?
-
Would they know which platform to use?
-
Would they know which information was appropriate?
-
Would they know when human review was required?
-
Would they know who to ask if they were unsure?
If the answer to those questions isn't clear, the firm doesn't necessarily need to stop using AI. It may simply mean the governance needs to catch up with the adoption.
Because the objective shouldn't be to prevent lawyers from finding better ways to work. It should be to make sure innovation happens in a way that protects the client information and trust the firm has been given.
Tags:
Legal Services
2 September 2026, 14:22:35 GMT+09:30
Comments