AI in Legal and Professional Services
Law firms, accounting firms, and professional services organizations are adopting AI for document review, contract analysis, legal research, due diligence, and client-facing work. These deployments raise distinct governance obligations around client confidentiality, accuracy, professional liability, and the unauthorized practice of law. Regulatory bodies and bar associations are beginning to issue specific guidance, while the EU AI Act classifies certain legal AI applications as high-risk.
Key board-level questions
- 1.How do we ensure AI-assisted legal work meets professional accuracy and confidentiality obligations?
- 2.Are we disclosing to clients when AI systems are used in their matters, and is that disclosure adequate?
- 3.What liability framework applies when AI-generated advice or documents contain errors?
- 4.Do our AI tools expose client data to third-party model providers in ways that violate privilege or confidentiality?
Regulatory frameworks
EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act is the European Union's law on artificial intelligence. It sorts AI systems by risk, bans a short list of practices, and sets duties for high-risk systems and general-purpose AI models. It applies to any organization that builds, sells, or uses AI in the EU, wherever that organization is based. Obligations phase in between February 2025 and August 2028.
NIST AI Risk Management Framework (AI RMF 1.0) and Playbook
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary US framework for managing the risks of AI systems. It organizes the work into four functions: Govern, Map, Measure, and Manage. Its companion Playbook suggests concrete actions for each part. Any organization that builds or uses AI can adopt it, and some laws and contracts point to it.
ISO/IEC 42001:2023 - Artificial Intelligence Management System
ISO and IEC published ISO/IEC 42001:2023 in December 2023 as the first international AI management system standard. It sets requirements for establishing, maintaining, and improving an AI Management System. Organizations developing or using AI products and services can seek independent certification.
Playbook guidance
What does meaningful human oversight look like for high-risk AI decisions?
What is our explainability standard for AI decisions?
How do we maintain data privacy compliance when using AI?
How do we ensure third-party AI vendors meet our standards?
What does audit-ready AI documentation look like in practice?
