How to Prepare Your Firm for Legal AI

How to Prepare Your Firm for Legal AI
If you’re figuring out how to prepare your firm for legal AI, you’re not alone. 

In fact, a lot of law firms are in the same boat: “We know we should do something about this, but don’t know where to start. Our employees use AI tools, but that’s about it.”

Recent industry reports have also discovered a clear divide between ‘individual AI usage’ and ‘firm-level readiness.’ For example, the 8am Legal Industry Report (2026) found that 69% of legal practitioners use AI, but only 9% of law firms have implemented an AI usage policy. 

This ‘AI adoption gap’ between employees and firms isn’t uncommon – but it isn’t safe either. Left unchecked, it can pose serious risks to your organisation, like it happened last month with Pinsent Masons LLP,  in the Cork v Smith (2026) case. 

An AI-savvy junior associate used an LLM that cited a non-existent insolvency rule, leading to great public embarrassment. Since there were no firm-wide AI usage guidelines, he turned in the draft without double checking it. Then, the firm’s senior partners also signed off on the court letter– without verifying the details. When the judge caught the fake text, the firm used the AI to draft a second letter, attempting to explain away the hallucination as a mere summary conclusion.

In the end, the judge publicly admonished the firm and gave them an SRA referral, calling their incompetence “troubling.”  

"I find their conduct, as it appears from the documents that I have, very troubling. [...] Much of it could have been avoided had [they] simply checked any of the statutory provisions that the AI referred to in an authoritative source."
— ICC Judge Mullen, Cork v Smith [2026] EWHC 1199 (Ch)

How did Pinsent Masons LLP end up here? 

They failed to implement the urgent framework of AI training, AI usage policy, and risk management required to protect their practice. 

This is the key lesson law firms need to learn as they prepare themselves for legal AI. 

This article is your map to adopting responsible and efficient legal AI. It talks about the state of AI adoption, explains the four stages every firm moves through when using AI in legal work, and what each stage requires. 

Let us help you understand where your firm is right now with AI, and what your next step should be. 


Key Takeaways:

  • AI adoption among employees greatly outpaces AI readiness among firms. This means a lot of firms are dealing with unchecked, unsecured AI use.
  • Every firm moves through 4 stages of AI maturity: 1. Exploring, 2. Testing in Real Work, 3. Building Consistent Practices, and 4. Running AI as Part of the Business

  • To know which stage your firm is, ask yourself: Can I tell my clients how I use AI? Is my answer clear, confident, and backed by official firm policy

  • Every stage needs a different process to start (or continue) using AI responsibly. 

  • While stages 1 and 2 require clarity and security, stages 3 and 4 require constant monitoring of their workflow. 

  • To build client trust, be upfront about AI use, and emphasize human oversight.



Where Are Most Firms Right Now, With AI?

As of 2026, all available data points in the same direction: AI adoption generally outpaces AI readiness. 

Most employees are already using AI in some way. Many are using general-purpose tools to research faster, generate first drafts, meet deadlines, and review documents. However, they are doing so in a compliance vacuum, without any training or governance from their firms. 


What numbers tells us about firms (and employees)  

AI adoption among law practitioners is growing steadily. The 8am Legal Industry Report (2026) found that 69% of legal professionals now use AI tools for work. This number has doubled from their 2025 report. Similarly, The Wolters Kluwer Future Ready Lawyer Report (2026) found that 92% of respondents reported using at least one AI tool in their workflow. 52% of professionals are seeing noticeable revenue growth tied directly to their personal AI usage. 

While lawyers are keen on using AI, the numbers about firm-level adoption tell a different story. 

The 2026 AI in Professional Services Report by Thomson Reuters found that 54% of law firms believe they should use AI more. Yet, less than 20% of them have any guidelines about AI usage. Surprisingly, 82% of firms do not even collect any ROI metrics regarding their AI software usage, and only 40% have integrated generative AI at an enterprise-wide level. Furthermore, 43% law firms do not have any AI policy or any plans to create one.

The 8am Legal Industry Report presents similar, bleak numbers on AI preparedness. 54% of law firms have provided no training to their staff on the responsible use of AI – and have no plans to do so. Only 9% of law firms have a written AI policy that is actively monitored and enforced.

Employees are adopting AI
Firms are lagging behind
69%
92%
>20%
82% 
54%
9%
40%
Legal professionals use AI for work
Legal professionals report using at least one AI tool in their workflow 
law firms have any guidelines about AI usage 
law firms do not collect ROI metrics about AI usage
Law firms provide no AI-related training to their employees
Have a written AI policy that is actively monitored and enforced
law firms have integrated gen AI at an enterprise level

The message is clear: employees are aggressively adopting these tools while firms are failing to catch up.


I Want to Be Prepared for Legal AI. Where Do I Begin?

The process is simple: see where your firm falls on the AI Maturity Ladder. The Maturity Ladder  is a list of four stages every AI firm moves through when adopting AI. 

Once you’ve figured that out, you are one step closer to being prepared for legal AI. 


1. The AI Maturity Ladder: the four stages every firm moves through

Stage
What It Looks Like
What You Need
Signal You Are Ready to Move Forward
Stage 1 — Exploring
Curious about AI, some informal use happening, no shared expectations.
A clear conversation about which tools are acceptable and a basic expectation that outputs get a human read.
The firm can name which AI tools are in use and for what.
Stage 2 — Testing in Real Work
Trying AI on lower-risk tasks, people forming views on what works.
A shared decision about which tasks AI should not handle yet and who reviews outputs.
The firm consistently reviews outputs before using them professionally.
Stage 3 — Building Consistent Practices
Moving from individual experimentation to shared expectations.
Clear internal guidelines on tasks, roles, and review process. 

Written down, not just understood.
The firm can explain its AI process clearly to a client if asked.
Stage 4 — Running AI as Part of the Business
AI embedded in specific workflows with clear roles and expectations.
Periodic review of which tools are used and how practices are holding up as AI changes.
The firm treats AI governance as ongoing maintenance, not a one-time setup.


2. The litmus test: How to know which stage you’re at

If you want to know exactly where your firm stands with AI adoption, it all boils down to a simple test. 

Imagine a major institutional client sits you down today and asks two simple questions:

“How exactly is your firm using AI on our files? And how are you verifying that the output is 100% accurate?”

Can you give a clear, confident answer backed by official firm policy?

If you answered YES: Congratulations, you are structurally sound. Your firm has crossed the threshold into Stage 3 or 4 maturity. You have secure enterprise tools, a written policy, and enforceable "human-in-the-loop" workflows.

If you hesitated or said NO: You are still at Stage 1 or 2 (and that isn’t a bad thing, the next section will tell you what to do.) 


What Does Each Stage Need To Ensure Responsible AI Use


No matter which stage you’re at, simple and specific guidelines are the way to go. Let us break these down into three sections. 

The first section is for Stages 1 and 2 – the firms who are rather new to AI use. The second section is for Stage 3, and the third section is for Stage 4 – the firms who have been using AI consistently.  


1. Stage 1 and 2 – What you actually need right now

At these two stages, you do not need enterprise governance. You need 3 things:
  1. A clear conversation: Develop a shared understanding within your firm about which AI tools are acceptable and which are not. This doesn’t have to be a formal policy, but a very honest conversation. 

  1. A consistent ‘human review’ habit: Set a basic shared expectation that AI outputs always get a ‘human read’ before they go to a client or into a document. This need not be a complex review process. 
  1. A firm boundary: Make a clear decision about which types of work should not involve AI at all for now. (For example, anything involving sensitive client information that you would not want leaving the firm's systems.)

That is it for Stage 1 and 2. It is simple, achievable, and enough to move forward without creating unnecessary exposure.


2. Stage 3 – What moving forward looks like for you

If you are at Stage 3, you are very close to understanding “how” AI works within your firm. Here’s your to-do list – 

  • Delegation: Decide who in the firm should use AI for which tasks. (Not because junior staff cannot be trusted, but because different tasks carry different levels of responsibility.)
  • Escalation: Create a clear process for what staff should do when AI outputs feel uncertain. (Who to escalate to, what to double-check, when to rely on traditional research.)
  • Explainability: Keep a simple record of which AI tools the firm uses and what they are used for. (If a client ever asks, the firm should be able to explain this calmly and clearly.)


3. Stage 4 — what sustainable AI use looks like

At Stage 4, AI is part of how the firm works rather than a new addition. If your firm is at stage 4, you have made deliberate choices about where AI adds value and where it does not. Moreover, those choices are written down, reviewed periodically, and understood by the whole team. 

But wait, this isn’t final. Even at Stage 4, your AI workflow requires ongoing attention as AI tools change.

The ultimate trap of this stage is complacency. Since AI models are not static software, they can drift without warning. For example, say your AI vendor pushes a routine weekend update to the AI’s core engine to increase processing speed. The updated model begins subtly misinterpreting the interaction between specific liability limits and indemnity clauses. Because your team trusts a system running on autopilot, automation bias kicks in. They drop their guards, and a flawed output slips through to the client. 

If you have to remain steady at Stage 4, you need regular auditing, proactive testing against model drift, and a work culture that never fully relies on the AI. 



Okay, But What Happens if AI Gets Something Wrong?


If your AI produces work that ends up causing a problem for a client, the responsibility sits with your firm—not with the AI tool. (The vendor's terms of service will make this clear.) 

Now, this isn’t a reason to avoid AI. It is a reason to thoroughly review AI outputs rather than simply accepting them.


1. How to review AI outputs at each stage

  • At Stage 1 and 2: A human lawyer reads and flags every AI output before it is used. (Not deeply, but attentively—checking whether there is anything that needs verifying.)
  • At Stage 3 and 4: At this stage, the review needs to be more structured. Certain outputs—contracts, compliance documents, anything with significant consequences—must get a more careful check against the source material. The question evolves from "does this look right?" to "is this actually right for this specific situation?"

Task Type
Stage 1 and 2
Stage 3
Stage 4
Drafting first-pass documents
With human review
With structured review
With defined review process
Legal research and summarisation
With verification
With source checks
With documented validation
Client-facing documents
Approach with caution
With attorney sign-off
With formal approval process
Sensitive client information
Avoid until tool governance is clear
Only in approved tools with clear data handling
Within documented data handling policy
High-stakes legal decisions
AI support only, human decides
AI support only, attorney decides
AI support only, attorney decides



How Are Other Law Firms Handling This?

Most managing partners have this question, but are too afraid to ask. However, this question is worth asking so that you can get a clear picture of where you stand in the era of AI-everything. 

1. The honest picture

In 2026, the vast majority of firms remain clustered between Stage 1 and Stage 3 of maturity. 
As of now, only a small fraction of the market has established formal, audited AI governance programs. The rest of the law firms operate in a state of ‘rolling experimentation.’ They rely on ad-hoc adjustments when it comes to using AI for legal work. And when their AI approach clashes with their existing workflows, they perform course-corrections. 

This approach isn’t necessarily bad – given that AI is a relatively new and complex phenomenon, this iterative method works. However, the firms at Stage 4 do things differently. 


2. The firms who get it right – what do they have in common? 

The firms at Stage 4 aren’t necessarily the most technologically sophisticated firms. They are the ones that made deliberate choices early. They decided which tasks AI is appropriate for and what review means in practice. 

This clarity about AI usage looks like a simple thing. It isn’t even legally required in many jurisdictions. Nevertheless, it gives you a major advantage: It allows you to explain what you did with AI, how you did it, and why. 


Do We Need Formal Policies Already?

Having an AI policy is an excellent way to move forward, but putting it into action takes time. If you’re in the early stages and feeling a rush of ‘compliance anxiety’, don’t fret. First, separate what really protects your business from what is just empty paperwork. 

Law firms often stress themselves out trying to follow long checklists that do not reduce their real-world risk. For example, instead of forcing your employees to read a boring 50-page rulebook (that they will immediately forget), build automatic safety warnings right into your workflow. By doing this you will prevent mistakes without slowing people down. 

Then, once your team is better equipped to use AI responsibly, you can begin creating formal policies. 

1. Your AI policy depends on which stage you are at 

If you are at Stage 1 or Stage 2, your priority isn’t having a well-drafted AI policy. Instead, you must focus on having a clear shared understanding. Why? At this stage, your employees are using AI on the go, there isn’t any clarity on AI usage on a firm-wide level, and everyone is on a different page. So, just putting out a formal policy (that nobody reads) will create the impression of management without the reality of it.


2. When a formal policy becomes important

If you are at Stage 3 and 4, a written internal policy becomes genuinely useful. Since your firm is using AI for enough tasks, having clear written expectations protects both the firm and the staff. It is also easier to explain how you use AI in your workflow, if a client raises a question. 

Stage 4 Done Right: How A&O Sherman Prepared for Legal AI

One shining example of a Stage 4 firm is A&O Shearman

Here’s how they designed their blueprint for firm-wide AI integration:

  • Secure AI access: First, they ditched passive, high-level policy memos and embedded automated compliance triggers directly into the daily desktop workflow. They teamed up with Harvey AI to give their 4,000 lawyers a safe, private space to use AI. By doing so, they reduced friction and ensured responsible AI adoption.
  • Structural defensibility: To legally protect attorney-client privilege and eliminate the risk of data leakage, the firm established absolute data isolation with zero-retention parameters. Furthermore, they neutralized the Hallucination Haze by utilizing Retrieval-Augmented Generation (RAG)—forcing the underlying model to reference only verified, internal corporate precedents rather than public web data.
  • Change in training programs: The firm understood that using AI fundamentally changed their associate pipeline, so they redefined traditional legal training. Instead of teaching junior lawyers to spend hours on manual data aggregation and boilerplate drafting, they now focus heavily on strategic review, risk validation, and the critical mechanics of “human-in-the-loop” oversight.


How to Earn Client Confidence in the Age of AI?

Being concerned about your reputation is valid (and completely natural for any professional practice.) When you introduce new technology into client work, the fear of losing client trust can feel like a major hurdle. However, you don’t build client trust by pretending technology doesn't exist; you develop it by clearly communicating that you use it responsibly. 

1. Here’s What Your Clients Actually Care About

Clients demand diligence, oversight, and transparency. They want to know that their data is safe and that they are paying for your legal expertise – not just a machine's automated output.

Today, a firm that uses AI within a structured, secure framework is actually in a much stronger position than its competitors. How? First, they can leverage AI efficiency and save billable hours. By having guardrails in place, they protect client data, reduce the risk of AI hallucinations, and pass the efficiency savings onto the client. In contrast, firms that completely refuse to engage with AI risk falling behind. Those who use it without structure or neglect responsible usage risk massive data leaks and errors.


2. How do We Communicate AI Use to Clients?

Most clients don’t want a highly technical lecture on algorithms, LLMs, or data science. They simply need confidence that a lawyer is in complete control of the final judgement.
The Golden Rule of the “AI Talk” With Your Clients: Be upfront, keep it simple, and emphasize human oversight.
When talking to clients about your AI usage, focus on these three core messages:
  • Data security first: Assure them that their sensitive information is kept in a private, isolated environment that never shares their data with the outside world.
  • The "Human-in-the-Loop" principle: Explicitly state that AI is used only as an internal assistant for initial research, brainstorming, or drafting. Clarify that every single deliverable, advice note, or document is heavily reviewed, edited, and approved by a qualified professional before it ever reaches them.
  • Showcase AI’s value add: Frame AI as a tool that cuts out the tedious, time-consuming grunt work. This allows your team to spend more time focusing on high-level strategy and deeply analyzing the client's unique problems.


Are We Exposing Ourselves Legally?

Adopting a new technology brings immediate anxiety about malpractice, negligence, and data breaches. 
However, these challenges are easy to mitigate once you understand where you are liable and where you aren’t. Using a secure and robust legal AI tool like Evatt AI also takes the burden off your shoulders by reducing hallucinations, providing verifiable and clickable citations, and ensuring all your data is deleted after use. 

1. The real exposure risk isn’t in the AI tools

Every tool can make a mistake, and AI is no different. In fact, AI vendors explicitly state their tools can make mistakes and recommend double-checking the outputs. So, the true risk lies in the lack of a process for catching those mistakes before they end up in a court document. 

Further, this AI risk scales depending on a firm's operational maturity:

  • Structured use (defensible): A firm that reviews AI outputs consistently, uses secure environments, and keeps simple records of how AI is deployed is in a legally defensible position. If an error occurs, the firm can demonstrate a standard of care—proving they treated AI outputs as drafts requiring rigorous human oversight.

  • Unstructured use (exposed): A firm where employees use public, consumer-grade AI tools secretly or without shared expectations is highly exposed. The vulnerability here is that the firm has no visibility, data security controls, or standardized process to intercept errors before they reach a client or a courtroom.

2. The Simplest Protective Steps at Any Stage

You do not need a 50-page compliance manual to drastically reduce your legal exposure. Just implement these 3 non-negotiable rules: 

  • Maintain a "Human-in-the-Loop" Mandate: You must treat AI like a brilliant (but occasionally unreliable) intern: its work must always be supervised. A qualified professional must read, verify, and sign off on every single piece of AI output before it is used professionally, filed, or sent to a client. This single practice eliminates the vast majority of professional liability concerns.
  • Enforce Data Quarantine Rules: Never share sensitive client data, proprietary information, and trade secrets with free, public AI models (where the data is often used to train the public algorithm). Any AI tool you use for client work should operate within a secure, private enterprise environment where data privacy is legally guaranteed and explicitly locked down.
  • Prioritize Operational Transparency: You must be able to clearly explain which AI tools you use for what tasks, and how those tasks are supervised. True transparency and a clear audit trail protect your firm far better than a rigid, overly complex formal policy.


Move Forward With Confidence

There is no single ‘right’ way to introduce AI into a legal practice. 

But, there is a sensible way, one that:

  • Moves at a pace your firm can manage
  • Builds confidence before expanding
  • Keeps human judgment in the loop at every step that matters

If you are a growing firm at Stage 1 or Stage 2, encourage your team to clearly communicate and document how they use AI. Set one non-negotiable rule: a human must thoroughly review everything it produces. You can also curate your own “private AI sandbox”, and decide which tools are okay to use for which tasks. This way, you stop employees from secretly using risky public tools that leak confidential data. Not only does this move protect your client information, it also allows your team to use AI safely and confidently. 

If your firm is already at Stage 3 or Stage 4, Evatt AI is built for you. It is designed to work within professional standards, with source-traceable outputs and human review built into every workflow. 

If you are ready to move from Testing in Real Work to Building Consistent Practices, this is where to start. Sign up for your free trial today.