← AI for lawyers

Before Your Firm Adopts an AI Tool: A Task-by-Task Risk Test

A practical framework for deciding which legal tasks an AI tool may assist with, what evidence its output needs, and where human review must remain decisive.

Asking whether an AI product is “safe for legal work” is too broad to produce a useful answer. The same tool may be low-risk when it generates interview questions and unacceptable when it supplies an unverified filing deadline.

A better evaluation starts with the task, the information involved, and the consequence of an error.

The ABA takes a similar task-sensitive approach in Formal Opinion 512: the amount of independent verification required depends on the tool and the legal task it performs. That means a firm needs more than a general “AI approved” label. It needs conditions for particular uses.

First, classify the task

Place a proposed use into one of four working categories.

1. Administrative assistance

Examples include reformatting nonconfidential text, generating a meeting agenda, proposing folder names, or turning an approved checklist into a template.

The legal consequence of a mistake is usually limited, but confidentiality and accuracy still matter. A quick human review may be proportionate.

2. Discovery and organization

Examples include suggesting research terms, grouping documents by issue, extracting dates from supplied material, or identifying questions for a witness interview.

These uses can save substantial time. The output should be treated as a lead or organizational aid, not as a verified statement. Omissions matter: a system may classify most documents correctly while missing the one that changes the case.

3. Analysis and drafting

Examples include summarizing authority, comparing contracts, drafting an argument, or proposing advice for a client.

Here, human review must test both the sources and the reasoning. A polished draft is not evidence that the analysis is complete, current, or correct.

4. Consequential decisions and representations

Examples include choosing a filing position, communicating final advice, submitting a document to a tribunal, calculating a deadline, or deciding that a conflict does not exist.

AI may assist with preparation, but the responsible lawyer must make and defend the decision. The system should never become the unexamined final authority.

Then score the actual risk

For each proposed use, ask six questions.

What information goes in? Determine whether the prompt or attached materials include client information, personal data, privileged communications, trade secrets, health information, financial records, or material subject to a protective order.

Where does that information go? Identify retention periods, training practices, subprocessors, employee access, storage locations, deletion procedures, and what happens when legal process is served on the provider.

What happens if the output is wrong? Compare an awkward internal summary with a missed deadline, false quotation, incorrect trust-account calculation, or bad advice. Higher consequences require stronger controls.

Can the answer be independently checked? A draft grounded in a closed set of identified documents is easier to review than an answer based on unspecified model knowledge. If the source cannot be inspected, confidence should fall.

Will a qualified person actually review it? “Human in the loop” means little unless the reviewer has the time, source access, subject knowledge, and authority to reject the output.

Can the work be reconstructed? For important work, preserve the relevant source set, material instructions, generated result, and final human-approved version.

Match controls to the task

A firm can turn the answers into a simple approval table:

Risk level Typical use Minimum control
Lower Formatting or brainstorming without client information Quick human review
Moderate Organizing approved source material Approved tool, defined source set, sampling and omission checks
Higher Legal analysis or matter-specific drafting Confidentiality review, proposition-level sources, qualified substantive review
Critical Filing, deadline, client advice, conflict or funds decision Independent primary-source verification and lawyer approval; prohibit automation of the final decision

The classification should be revisited when the tool, provider terms, model, integration, or task changes.

Questions to put to the vendor

  • Are customer inputs or outputs used to train any model?
  • How long are prompts, uploaded files, outputs, and logs retained?
  • Which employees and subprocessors can access them?
  • Can retention and training be disabled by contract and configuration?
  • Does the tool identify the exact source supporting each material proposition?
  • Can the firm limit retrieval to an approved source collection?
  • What audit history can the firm retain?
  • How are security incidents and legal demands communicated?
  • What happens to all copies of firm data when the relationship ends?

Marketing claims such as “legal-grade AI” or “enterprise security” do not answer these questions.

The policy should enable good uses

A blanket prohibition often drives experimentation into personal accounts and unapproved tools. Blanket approval creates the opposite problem. A task-based policy gives lawyers a usable path: approved tools, approved information types, defined review, and a clear escalation point for unfamiliar work.

No policy can make every use risk-free. It can make the expected care visible and proportionate before an AI-generated answer reaches a client, a court, or a business decision.

Primary reference

This article is general information for legal professionals, not legal advice or an ethics opinion. Rules of professional conduct vary by jurisdiction—consult yours.

Usus founders program

Help shape legal AI that shows its work

Tell us a little about you and the legal work you want technology to handle more rigorously. Lu Jin will review every submission.

By submitting, you agree that Usus may contact you about the founders program and related product updates. Read our privacy notice.