General Counsel AI Risk Checklist: The Legal Approval Gate
This General Counsel AI risk checklist defines a legal approval gate for a specific AI use and material change. It covers product and public claims, contractual risk allocation, privilege, regulatory posture, litigation holds, exceptions, and a signed legal disposition while keeping recurring executive reporting in a separate process.

A legal review tied only to a vendor name expires as soon as the application changes its purpose or data. A change to its model route or public claim also invalidates the review. The same applies when its authority changes. The General Counsel AI risk checklist below creates a legal approval gate for one defined use and its material changes. It ends with a signed disposition that preserves counsel's conditions and management's exceptions, along with the evidence reviewed. Ongoing trends and open actions belong in AI risk reporting for General Counsel. This gate decides whether a specific use may proceed.
TL;DR
- Define the exact AI use and release. Name the owners and people affected. Record the data and model routes. Identify outputs and downstream actions under legal review.
- Reconcile product and public claims with production evidence. Review contract allocation and privilege handling against actual data flows.
- Record regulatory posture, preservation requirements, exceptions, and advice in separate dated artifacts.
- End with one of three signed outcomes. Two are approve and hold. The third is approve with conditions. The authorized legal decision-maker signs the outcome, and the gate reopens after material change.
Check 1: freeze the legal review boundary
The product owner should identify the service and release. Record its purpose and users, including affected non-users. Document input data and retrieval sources. Name model providers and regions. Define outputs and human review, along with downstream actions. Legal needs the system that will run, not a category label such as "customer assistant."
The record should define material-change triggers. New claims or data categories reopen the gate. The same applies to new jurisdictions or providers. New fallbacks and retrieval sources also trigger review. So do new agent powers or decision effects. NIST's AI Risk Management Framework calls for documented legal requirements and inventory. It also calls for accountability and context, plus third-party risk. Those outcomes structure the file without assigning legal authority to NIST.
Check 2: reconcile product and public claims with evidence
Create a claims ledger with the statement and audience. Record the channel and owner. Add the approved scope and evidence link, along with the review date. Include website copy and sales answers. Add tender responses and contract schedules. Include regulator submissions and board material, plus investor statements. Each claim should resolve to current system behavior.
If a questionnaire says prompts are inspected before provider transmission, the evidence should show the route and policy result. It should also show the deployment version. If a product description promises human review, name the workflow and proof. Put the approved sentence beside the production artifact. One empty evidence cell should stop publication.
Check 3: assign contractual risk before approval
Procurement and Legal should map each provider and subprocessor to its terms. Do the same for every model host and retrieval source, plus each integration partner. Record data-use restrictions and confidentiality. Document intellectual-property allocation and warranties. Add indemnities and liability caps. Include audit rights and incident notice. Record deletion and termination assistance.
Compare the contract with the planned flow. A broad provider permission or low liability cap may leave exposure the business assumed had transferred. The AI vendor risk review for law firms gives a sector example. Also identify customer promises that depend on the supplier's performance.
Check 4: protect privilege and legal confidentiality
Counsel should identify workflows likely to contain privileged communications or attorney work product. Include investigation material and settlement positions, along with legal strategy. Define approved systems and recipients. Record access roles and retention. Document provider terms and review procedures. Generic confidential-data labels may miss legal status and distribution limits.
Test with synthetic matter names and canary passages. Confirm approved routes and matter access, then verify unauthorized users receive no context or answer. Record any human override. The AI audit trail requirements guide explains how operational evidence can support review while the organization governs access and retention.
Check 5: state the regulatory posture and unresolved interpretation
The legal memo should list jurisdictions and regulated activities. Record legal classifications and notices. Identify prohibited uses and licensing. Document record duties and human oversight. Add complaint routes and regulator commitments. Separate conclusions from assumptions. Keep open questions distinct so product owners know which facts would change the analysis.
Where personal data is involved, the official GDPR text can create design and records obligations depending on the processing. It can also create DPIA and DPO obligations. Rights and security obligations may apply as well. Other regimes may govern employment and credit. Consumer protection and sector records may also apply, as may cybersecurity. The gate should cite each primary authority used rather than treating "AI law" as one universal category.
Check 6: preserve evidence and litigation holds
Legal operations should identify repositories holding prompts and responses. Include retrieved-source references and route records. Preserve policy decisions and evaluation results. Add approvals and tickets, along with incident communications. Define normal retention and a tested hold procedure. The hold must reach derived stores that custodians may overlook.
Run a tabletop using one synthetic matter. Issue the hold and identify custodians. Suspend eligible deletion and export a bounded record set. Then verify chain-of-custody metadata. Record limitations and privileged access. Counsel needs proof that a named event can be preserved without opening unrelated user content.
Check 7: document exceptions and escalation rights
List each unresolved legal issue and contract gap. Include every unsupported claim and control limitation, along with each evidence gap. Give it an owner and affected scope. Record the consequence and compensating measure. Add a due date and expiry, plus a closure test. Keep technical exceptions separate from legal acceptance so responsibility remains visible.
I would hold a release over a public claim with no owner or production proof, even when the underlying feature appears to work. Unowned language spreads across sales decks and contracts. It also reaches customer answers faster than Legal can retract it. A condition should expire automatically, and missed deadlines should return the use to the gate.
Check 8: sign the legal disposition
The final page should identify the reviewed release and evidence package. Record the assumptions and conditions. Add the exceptions and decision. Use one of three outcomes. Two are approve and hold. The third is approve with conditions. Name the legal signer and date. Record the review trigger and executive accepting business risk.
The NIST AI RMF Playbook provides voluntary suggested actions under Govern, Map, Measure, and Manage through its official resource. One useful discipline is explicit responsibility paired with documented monitoring and change review. The organization still defines who may give legal approval. A later material change invalidates the old disposition.
DeepInspect
DeepInspect supplies operating evidence for authenticated HTTP traffic routed between enterprise users or agents and LLM endpoints. It evaluates application-supplied context and classifies the assembled request. It applies content and destination policy, then creates a signed record for each decision before traffic reaches the provider.
Those records can support claims reconciliation and approved-route tests. They can also support privilege-policy checks and exception investigations, plus preservation for managed traffic. DeepInspect does not provide legal advice or interpret contracts. It does not establish privilege or issue litigation holds. It also does not sign the disposition. Those responsibilities remain with counsel and the organization's named owners. Book a demo today.
Frequently asked questions
- Does General Counsel need to approve every AI tool?
The organization should define risk-based authority. Low-risk uses may follow pre-approved conditions. Uses involving regulated decisions or sensitive data warrant direct legal review. The same applies to material public claims and privileged material. Customer commitments and autonomous actions also warrant direct review. The inventory should preserve the assigned approval path and trigger escalation when the use changes.
- How is this gate different from General Counsel reporting?
Reporting summarizes the portfolio and incidents. It also covers claims mismatches and vendor gaps, along with open actions on a cadence. The gate examines one defined use or material change and produces a dated legal disposition. The report can reference that disposition later. It should never substitute a green dashboard status for the underlying approval file.
- Can gateway records prove the legal conclusion?
Gateway records can prove facts about managed HTTP requests, such as supplied identity and destination. They can also show classification and policy version. Treatment and time are recorded as well. Legal conclusions also depend on scope and law. Contract and notice matter too. Human conduct and local activity may affect the conclusion, along with evidence outside that route. Counsel should use traffic records as part of the factual file and state their coverage limits.