AI Governance for Law Firms Needs Matter-Level Decision Rights
AI governance for law firms needs matter-level approval instead of one firm-wide permission for a named model. The operating record should connect each legal use to the responsible lawyer, client terms, permitted information, model route, review duty, and retained evidence. Request controls support that program for authenticated HTTP calls routed through an enforcement point.

A litigation associate opens an internal assistant beside a red-welled case file and asks it to compare witness statements. When a corporate lawyer later uses that assistant to draft a public closing checklist, AI governance for law firms has to distinguish those requests before either one reaches a model. The firm needs matter identity and an approved purpose, plus client restrictions and a review owner. I would reject a firm-wide "approved AI" badge because a vendor name says almost nothing about the legal work being performed.
TL;DR
- Approve legal AI by matter and use case. Record the responsible lawyer, permitted information, client terms, model route, and required review.
- Separate public research and administrative drafting from work involving privileged material or advice delivered to a client.
- Preserve the prompt decision and source review, plus the lawyer's final disposition, as connected evidence under the active policy version.
- HTTP controls cover authenticated LLM calls deliberately routed through them. Professional judgment and court filings remain with lawyers, while vendor-managed AI needs separate oversight.
AI governance for law firms starts with the matter
A law firm already organizes authority around matters. Conflicts checks and ethical walls use that unit, as do engagement letters and outside counsel guidelines, followed by staffing permissions and retention schedules. The AI register should use the same identifier rather than creating a detached technology catalog.
Each approved use record needs a responsible lawyer and a defined legal task. It should identify the client or internal function, approved information classes, and available model route. The record also states the required review and evidence location, with an expiration or reassessment event. A merger matter under a client prohibition on generative AI receives a different policy result from public regulatory research for the firm's knowledge team.
The existing law-firm confidentiality architecture explains the Rule 1.6 data boundary. This governance decision sits one level above it. The management committee decides which matter uses may enter production and who accepts the residual risk. Practice leaders can approve work inside their delegated threshold. Information security operates the technical route, while the responsible lawyer owns the legal service.
Ethics duties become approval fields and tests
The District of Columbia Bar's Ethics Opinion 388 applies existing duties to generative AI. It addresses competence and client confidentiality, along with candor to tribunals and supervision, while its discussion also reaches client files and fees. Those duties produce concrete fields in the governance record.
Competence starts with the specific product and function. The approving lawyer should understand how the tool generates an answer and where its data travels. Testing should cover fabricated authority and incomplete retrieval, as well as behavior after a model update. Confidentiality review records the provider terms and retention setting, then connects them to the matter's information classes before communication review determines when the client needs disclosure or consent under applicable rules and engagement terms.
Supervision needs evidence from tests that actually ran under the approved policy. Preserve an allowed test using public authority and a denied test containing a matter restriction. Record who reviewed generated analysis before it entered advice or a filing. For agents that can select sources or prepare a document, approval should also define the permitted actions and the point where a lawyer must intervene.
Agentic legal work requires an explicit authority ceiling
The State Bar of California's Practical Guidance for Generative AI was updated to address agentic AI. It warns against allowing a system to make substantive legal determinations or communicate legal advice without meaningful lawyer supervision and review. The guidance asks lawyers to understand the system's autonomy and the circumstances in which it acts.
Translate that into a short authority statement for every agentic use. A research agent may query an approved legal database and assemble authorities for a named lawyer, while its policy excludes client communications and filing a pleading. A contract agent may compare clauses inside one authorized repository and draft proposed language, while execution and counterparty delivery stay behind human approval.
The identity chain matters for every agentic request. The application should carry the originating lawyer or staff identity into each HTTP model call and retain the agent identity as a separate field. Matter context and delegated action should travel with the request. Legal discovery AI security covers the narrower privilege and protective-order mechanics for litigation systems. The firm-wide program sets the authority ceiling that applies before those controls execute.
Output review needs source and disposition evidence
Generated prose can sound finished while resting on a citation that leads to the wrong page. A useful review packet places the cited authority beside the generated passage and the lawyer's correction, showing the filing lawyer's final disposition under applicable tribunal rules when the output enters a court filing. For client advice, the packet connects the answer to the responsible lawyer and matter.
Build the packet around four records. The intake record captures purpose and approval. A request record identifies the caller and model route, with content classification and policy outcome. The source record preserves the authorities or client documents used. A disposition record shows the lawyer's corrections and final action. Four linked artifacts make later supervision review far more credible than a chat export with no matter identifier.
This is also where retention becomes a legal records decision. Full prompt storage can create another repository of privileged material. A firm may retain a fingerprint and source-system reference for lower-risk workflows, while a litigation hold or client guideline requires fuller preservation. The records team and responsible lawyer should set that choice in the use record before production begins.
Governance architecture needs named exclusions
An external policy point can govern authenticated HTTP traffic that a firm-controlled application deliberately routes to an LLM. It can evaluate identity and matter context, classify request content, constrain the model destination, and preserve its policy decision. That boundary supports enforcement of an approved-use matrix.
Several legal and technical controls sit elsewhere in the firm's architecture. Native AI inside a document platform or legal research service may follow a vendor-managed inference route, while personal browser sessions require endpoint and egress controls. IAM establishes workforce identity and access before a model call. Conflicts systems remain the source of truth for matter access. Lawyers retain responsibility for factual verification and legal judgment, including client communication and tribunal filings.
Put those owners on the diagram. The HTTP policy point should appear on the customer-controlled model route rather than around the whole practice. Vendor due diligence and contract terms cover opaque services. Training and supervision cover lawyer conduct. The engagement process handles client consent and billing. An honest boundary lets the management committee see which evidence comes from technology and which evidence must come from professional practice.
DeepInspect
DeepInspect supports the customer-controlled HTTP portion of law-firm AI governance. It is a stateless proxy between authenticated users or agents and HTTP-based LLM endpoints. The calling application supplies lawyer or staff identity and matter purpose. DeepInspect evaluates that context with content classification and destination, along with the active role and policy version, before forwarding an allowed request.
Each routed decision produces a signed, tamper-evident record. DeepInspect leaves conflicts administration and identity proofing with the firm's source systems. It also leaves source verification and legal judgment with lawyers. Vendor-managed embedded AI and local execution sit outside the proxy path. For applications deliberately routed through it, the firm gains an enforceable request point and independent evidence tied to the matter-level approval. Book a demo today.
Frequently asked questions
- Should a law firm approve one generative AI vendor for every matter?
A vendor approval can establish baseline security and contract terms. Matter approval still needs the intended task and client restrictions, plus the information involved and responsible lawyer. One client may prohibit generative AI in its outside counsel guidelines. Another may permit research under named enterprise terms. Litigation work can carry protective-order limits absent from a corporate knowledge task. The AI register should connect the vendor review to each permitted use rather than treating procurement as blanket legal authorization.
- What belongs in a law firm's AI use record?
Record the matter or internal function and the accountable lawyer. Add the intended task and affected work product, along with approved information classes and the model route. Include client terms and applicable jurisdictional guidance, then state the review step and retention choice. The entry should identify test evidence and the next review event. For an agent, add its identity and delegated actions, with the human approval point and source access scope.
- Can a law firm use an LLM for public legal research?
A firm can create a lower-risk lane for research using public sources. The approval should name accepted databases or source types and prohibit matter-confidential input on that route. Lawyers still need to open the cited authority and verify that it supports the proposition. The District of Columbia Bar's Opinion 388 grounds that review in competence and candor duties. Save the selected source and reviewer disposition when the result enters client advice or a tribunal submission.
- Do request logs prove compliance with professional conduct rules?
Request logs prove a bounded technical event. They can show that a supplied identity sent classified content to a named model under a particular policy and received an allow or block result. Professional compliance also depends on the lawyer's competence and supervision, with client communication and fee handling governed by the facts. A connected review packet combines request evidence with source verification and lawyer disposition. The disciplinary authority or court makes the final assessment.
- How should firms govern AI built into legal software?
Start with the vendor's actual architecture. A firm-controlled API route can pass through an external policy point. An opaque managed feature requires contract review and administrative configuration, plus vendor evidence and application logs. The use record should identify which path applies. It should also state data use and retention terms, available audit events, matter access behavior, and the lawyer review point. Reassess the entry when the vendor changes its model or adds an agentic action.