Key takeaways
- The tasks worth automating in a law firm are the ones nobody bills proudly for, not the ones that demonstrate well.
- The account tier is the confidentiality decision. A personal consumer account with matter content in it is the actual risk, not the model.
- Verification is not optional. Every legal proposition an AI tool produces needs a lawyer standing behind it before it leaves the building.
- The billable hour tension is real and should be resolved deliberately, before adoption, not discovered afterwards.
Law firms have a harder version of the AI question than most businesses, and it is not the one usually discussed. The confidentiality issue is real but tractable. The verification issue is real and permanent. The genuinely awkward one is that a firm billing by the hour has just been handed a tool whose entire value proposition is taking less time.
All three are solvable. None of them are solved by buying a licence and hoping.
Start with the work, not the technology
The mistake most firms make is beginning with a question about legal research, because legal research is the most visible thing lawyers do that looks like something AI might handle. It is close to the worst place to start. Research carries the highest verification burden, the highest cost of being wrong, and the smallest margin over the specialist tools your firm may already pay for.
The better place to start is the unglamorous middle of the working day. Look at what associates and paralegals do that is time consuming, low judgement, and already reviewed by someone before it goes anywhere. That is where the hours are, and it is where the risk of an AI error is contained by a process that already exists.
| Task | Fit | Why | Who verifies |
|---|---|---|---|
| Summarising a long document set you already have | Strong | Source material is in front of you, so errors are checkable in minutes | Reviewing associate |
| First drafts of routine correspondence | Strong | Already reviewed before sending, format is repetitive | Supervising lawyer |
| Deposition and transcript summaries with citations to page and line | Strong | Every claim points at a source you can open | Whoever uses the summary |
| Comparing a contract against your firm's standard positions | Good | Flags differences for a human to judge, does not decide | Matter lawyer |
| Turning a partner's dictated notes into a structured memo | Good | All substance comes from the partner | The partner |
| Plain-English explanation of a clause for a client | Good | Lawyer checks accuracy before it is sent | Matter lawyer |
| Case law research | Poor | Fabricated or superseded authority is the classic failure and the verification cost eats the saving | Not suitable without specialist tooling |
| Conflicts checking | Unsuitable | Needs completeness and an audit trail, not plausible output | Existing system |
| Final filings and signed advice | Unsuitable | No margin for an unverified sentence | Not suitable |
The pattern across the strong rows is that the source material is already in the room. When a lawyer can check the output against a document sitting on the desk, the verification cost is small and the time saving survives. When the tool has to supply the underlying facts from its own knowledge, the verification cost is large and the saving disappears.
The rule that covers most of it: use AI to reorganise information you already have, not to supply information you do not have. Nearly every reliable use in a law firm sits on the first side of that line, and nearly every embarrassment sits on the second.
The verification problem does not go away
By now most lawyers have heard about the sanctioned filings containing citations to cases that did not exist. Those incidents are instructive not because the technology was uniquely bad, but because of how the failure presented itself. The fabricated citations were correctly formatted, plausibly named, attributed to real courts, and confidently described. Nothing about them looked wrong. That is the failure mode, and no amount of model improvement removes the need for the check.
Firms that handle this well tend to do two things. They write down, in one page, which categories of output require what level of checking, and they make that document part of how new lawyers are trained rather than a policy nobody opens. And they insist on a simple habit: if an AI tool asserts a legal proposition, the lawyer opens the primary source before relying on it. Not a search for the case name to confirm it exists. The actual authority, read.
The second habit is what separates a firm using AI responsibly from a firm that has not had its incident yet.
Confidentiality is an account tier decision
The concern lawyers raise first is whether client information put into an AI tool becomes training data or otherwise escapes. It is a legitimate concern and it has a specific answer that depends almost entirely on which account the material was typed into.
A personal consumer account is a personal arrangement between an individual and a vendor. Your firm has no visibility into it, no administrative control over it, no ability to configure retention, and no contractual position of its own. If an associate is pasting matter documents into their own account, the firm has an undisclosed subprocessor and does not know it.
A business or enterprise tier changes that. Inputs are excluded from model training by contract, retention is configurable, administrators can see who has access, and there is a commercial agreement your firm is party to. At that point the analysis resembles any other cloud vendor decision your firm has already made about practice management, document storage or email. Firms comfortable with those are usually comfortable here once they see the terms side by side.
Which means the practical confidentiality task is not a philosophical one. It is: find out who is using personal accounts, get them onto the firm account, turn off the settings that need turning off, and write down what you did so you can answer a client question about it later.
Professional responsibility and disclosure
The American Bar Association addressed generative AI in Formal Opinion 512 in 2024, and a number of state bars have issued their own guidance since. The themes are consistent: competence includes understanding the tool well enough to supervise it, confidentiality obligations follow the client's information wherever it goes, and fees should reflect the time actually spent rather than the time a task historically took.
Disclosure practice varies. Many firms handle it with a short provision in the engagement letter describing the use of technology tools including AI, with client information kept confidential and all work supervised by lawyers. Others make no general disclosure and address it per matter where a client asks or where a client's own policy requires it. Some institutional clients now specify their position in outside counsel guidelines, in which case the question is answered for you. Check your own jurisdiction and your own client obligations rather than adopting a general practice you read somewhere.
Worth doing early: read your three largest clients' outside counsel guidelines for anything about AI or technology subprocessors. It takes an afternoon and it occasionally changes the answer entirely. Finding out during a billing dispute is the expensive way to learn it.
The billable hour question, addressed honestly
If a task took an associate three hours and now takes forty minutes, the firm has a decision to make, and pretending otherwise produces the worst outcome: quiet non-adoption. Lawyers are not slow to work out that efficiency on an hourly matter reduces their own recorded time, and if nobody has told them how the firm views that, they will resolve the ambiguity in the direction that protects them.
Three positions firms actually take, all defensible:
Bill the time actually spent and take the capacity gain. The realisation rate on that matter drops, but the same lawyers handle more matters. This works when the firm has demand it is turning away or work sitting in a queue. It does not work when the constraint is client volume rather than lawyer hours.
Move the affected work to fixed fees. The efficiency accrues to the firm rather than being competed away, and clients get price certainty they generally prefer. This is the direction of travel for document-heavy, repeatable matter types, and AI makes it more attractive rather than causing it.
Reinvest the time in matter quality. More thorough review, better client communication, work that previously got the version the budget allowed. Harder to measure, but it is what many good lawyers do with the time anyway.
The position matters less than making one and saying it out loud. A firm that adopts AI without addressing this will find that adoption stalls among exactly the fee earners whose time is most valuable, and the partners will conclude the technology does not work rather than that the incentives do not.
What to configure before anyone starts
The setup that makes the rest of this workable is not large, but it needs to exist before the first matter document goes anywhere near a chat window.
- One firm account on a business tier, with every lawyer and paralegal on it, so nobody has a reason to keep using a personal one.
- Training on inputs disabled and retention set deliberately, with the settings screenshotted and filed for the day a client asks.
- A spending ceiling at the provider, so the finance partner has a number rather than an exposure.
- Single sign-on where your firm already runs it, so a departing associate loses access the same day they lose their email.
- A one-page verification standard naming which outputs need what checking, kept short enough that people read it.
- An answer to the billing question, communicated by a partner rather than circulated by email.
- Task guidance by role, because the useful tasks for a litigation paralegal and a transactional associate are not the same, and generic training produces generic non-use.
Firms that complete that list before rollout tend to see steady use within a few weeks. Firms that hand out licences and schedule a lunchtime demonstration tend to see a spike in curiosity, a fortnight of experimentation, and a quiet return to how things were.
A realistic view of the return
The honest version is that AI does not change what a law firm sells. It changes how long some of the inputs take. In a mid-size firm the recoverable time tends to concentrate in document review and summarisation, routine correspondence, internal knowledge work, and the administrative layer around matters rather than in the legal reasoning itself.
That is a meaningful gain and it is worth having. It is not a restructuring of the practice, and firms that expect the latter are usually disappointed by something that was in fact working perfectly well.
Frequently asked questions
Is it safe for a law firm to use ChatGPT or Claude?
Not on personal consumer accounts with client matter content. On a business or enterprise tier with training on your inputs disabled, retention configured and administrative control in place, it becomes a normal vendor decision comparable to your practice management system. The account tier changes the risk profile far more than the choice of model does.
What should AI never be used for in a law firm?
Anything where an unverified statement reaches a court, a client or the other side. Case law research without checking primary sources, final filings, advice sent unread, and conflicts checking all sit outside the boundary. Drafting a first pass that a lawyer then verifies sits comfortably inside it.
Do we have to tell clients we use AI?
It depends on your engagement terms, your state bar guidance and your clients' outside counsel guidelines. Many firms use a short clause in the engagement letter rather than per-matter disclosure. Check your own jurisdiction and your largest clients' requirements before settling on an approach.
Will this reduce our billable hours?
On hourly matters, yes, for the tasks it touches. Firms respond by taking the capacity gain, moving affected work to fixed fees, or reinvesting the time in quality. The important thing is choosing a position and telling fee earners what it is, because unresolved ambiguity here is the most common reason adoption quietly fails in law firms.
Get AI working in your firm without the guesswork
We pick the provider that fits how your firm actually works, configure the confidentiality settings, cap the spend, set up single sign-on and write task guidance for litigation, transactional and support staff separately. Your practice manager runs it afterwards. Fixed price, live in 30 days or less.