AI Governance for Law Firms
Your clients are starting to add AI terms to their outside counsel guidelines. Your malpractice carrier is starting to ask at renewal. Most firms can't answer either question — because nobody has ever asked their own people what they use.
No credit card. No software to install. Nothing to monitor.
§1 AI SYSTEMS IN USE · 24
| ChatGPT | Elevated |
| Otter.ai | High |
| Harvey | Moderate |
| Microsoft Copilot | Moderate |
| “Scheduling bot” | Pending review |
§3 POLICY
§7 OUTSTANDING

The problem
Ask your partners which AI tools the firm uses and you'll get a short list. Ask your paralegals and you'll get a longer one.
Not the tools you bought — the tools people use. Personal ChatGPT accounts, the transcription bot in the video call, the AI built into software you already pay for.
Which matters, which data, whose accounts. This is a Rule 1.6 question before it is a technology question.
Not say it. Show it — with dates, versions, and names.
How it works
Send every person in the firm a one-click link. No login, no account. They tell you what they use, what they put into it, and whether it touches client matters. The survey opens with an amnesty note, because people who fear discipline don't tell you the truth.
Answers resolve against a catalogue of hundreds of known tools, so “ChatGPT”, “Chat GPT” and “GPT-4” become one record instead of three. Anything unrecognised goes to a review queue — never discarded.
Every tool is scored on what data goes in, whether it influences decisions, whether clients see it, whose account it runs on, and whether a human reviews the output. The formula is fixed and explainable. No black box, no AI guessing.
Publish an AI policy from a law-firm template, assign it, and collect acknowledgments with timestamps. Assign training and record completions with renewal dates. Approve tools, restrict others, and give everyone a list of what they're actually allowed to use.
Generate a governance report covering your AI estate, your risk distribution, who acknowledged what, who's trained, your vendor reviews, and your open issues. Save it as a PDF and send it.
Watch a two-minute overview
The difference
Most governance tools can tell you that somebody uses ChatGPT.
This one can tell you that ChatGPT is being used for contract drafting — a workflow you've already scored as requiring partner sign-off, worth $42,800 a month in recovered time — by three people on personal accounts, with no documented human review.
That's the difference between an inventory and a decision. Because the platform started as a workflow audit, every AI tool connects to the actual process it runs, with the value and the risk already attached.
Privacy by design
No browser extension. No prompt capture. No reading anyone's screen, inbox, or keystrokes.
Surveillance makes people hide what they're doing, which destroys the only thing that makes this work: an honest answer. So we ask instead, and we tell people up front that declaring something won't get them in trouble.
Everything in the system is a record someone created on purpose.

Professional responsibility
Model Rules 5.1 and 5.3 make partners and supervising lawyers responsible for the conduct of the lawyers and nonlawyers they supervise. ABA Formal Opinion 512 applies that squarely to generative AI, alongside confidentiality under Rule 1.6, competence under Rule 1.1, and candour about fees under Rule 1.5.
Supervising something you haven't inventoried is difficult to evidence.
This platform produces the record: what the firm uses, what it decided, who was told, who acknowledged it, and when.
We're a tool vendor, not your ethics counsel. The platform documents what your firm does — it doesn't certify compliance with any rule, and it isn't legal advice. Have your policy reviewed by whoever handles your firm's professional obligations.
The evidence
When a client's outside counsel guidelines ask about AI. When your carrier asks at renewal. When a partner asks what the firm's exposure is. When something goes wrong and you need to show what was in place beforehand.
| §1 | Every AI system in use, with its risk tier and who uses it |
| §2 | Your employee declaration results and response rate |
| §3 | Policy versions, who acknowledged which, and when |
| §4 | Training completion and renewal dates |
| §5 | Vendor assessments and review dates |
| §6 | Incidents raised, investigated, and closed |
| §7 | A prioritised list of what's still outstanding |
§1 AI SYSTEMS IN USE · 24
| ChatGPT | Elevated |
| Otter.ai | High |
| Harvey | Moderate |
| Microsoft Copilot | Moderate |
| “Scheduling bot” | Pending review |
§3 POLICY
§7 OUTSTANDING
Built for firms from 3 to 300. If you have more people than you can poll by walking around, this is faster.
FAQ

Find out what your firm is actually using. Everything else follows from that.