Sep 30, 2026

Clients are Writing the New Rules for Legal AI

As AI enters daily legal work, outside counsel guidelines are defining acceptable use and requiring firms to demonstrate value without compromising control.

By Joel Wirchin

The Real AI Challenge in Legal Is Trust, Not Technology

For the past several years, legal industry conversations about artificial intelligence have largely focused on technology. The questions were familiar: Which platforms should firms adopt? Which tools are secure? Which applications will drive productivity gains?

Those questions remain important. But they no longer represent the industry’s biggest challenge. At a recent gathering of legal leaders discussing AI and Outside Counsel Guidelines, a different theme emerged repeatedly: the future of AI in legal will be determined less by technology itself and more by governance, trust, and accountability. That shift has a practical consequence. Legal leaders now need an operating model that can answer four much broader questions:

  • Where does AI belong in the workflow? 

  • What information can it access? 

  • Who has authority to approve and oversee its use? 

  • How will value be measured? 

The rapid pace of change matters because expectations being written today may look different within months.

The Conversation Has Changed

In the early stages of generative AI adoption, many clients sought to prohibit its use entirely. As understanding improved, those restrictions often evolved into requirements for disclosure and consent. Today, many organizations are asking a different question altogether: How are you using AI to create value? 

That shift represents a significant maturation of the market. The debate is no longer centered on whether AI belongs to legal services. Increasingly, clients assume it does. The focus now is on how it is governed and how its benefits are measured. OCGs are where this shift from permission to performance is becoming operational.

Outside Counsel Guidelines Enter a New Era

Historically, Outside Counsel Guidelines were primarily administrative documents focused on billing practices, conflicts, staffing requirements, and engagement terms. Today’s guidelines are considerably more expansive. They increasingly address cybersecurity, privacy obligations, vendor oversight, information governance, data-handling procedures, audit rights, and AI usage policies. In many ways, OCGs are evolving into enterprise governance frameworks.

That evolution reflects a broader concern shared by clients across industries: data stewardship. Throughout the discussion, the most consistent concern was not AI itself. It was what AI might mean for confidential information. Questions around data ownership, data access, information security, and data sprawl repeatedly surfaced. Organizations want confidence that their information remains protected regardless of the technology being used. As a result, firms are finding that discussions surrounding AI often become discussions about governance.

At some point during the panel discussion, I put the risk plainly: The best way to make faster mistakes is by not employing governance. That warning becomes practical when legal leaders test whether they can answer six questions before a tool or use case scales:

  • What client and matter data can the system access? 

  • Can information cross client, matter, or ethical-wall boundaries? 

  • How are prompts, outputs, and interaction histories stored, retained, and deleted? 

  • Who owns AI-created workflows, agents, and the decision trace behind the final work product? 

  • Can the organization audit how information moved through the system? 

  • Do vendor terms and technical controls match the confidentiality obligations the firm has accepted? 

Answering those questions requires more than policy language. It requires clear ownership and decision rights. It requires cross-functional models involving the general counsel’s office, technology, information security, finance, executive management, knowledge management, and relevant practice or business leaders. Working groups may sit beneath that structure, but the number of committees is less important than the authority they carry.

The governance body needs clear decision rights: which tools and use cases are approved, who can accept risk on behalf of the organization, how exceptions are handled, and which outcomes will be measured. Strategy also requires deciding what the organization will not do. But governance defines the boundaries. It does not redesign the work inside them.

Success Requires More Than Technology

If OCGs are becoming operational governance frameworks, firms need an operating model capable of delivering against them. Many organizations initially approached AI as a technology deployment challenge. Firms moving beyond experimentation are taking a different approach. Rather than simply layering AI onto existing workflows, they are reexamining how work is performed in the first place.

Process design, knowledge management, training, operating models, data architecture, and change management are increasingly becoming prerequisites for successful AI adoption. The work can be organized into five steps:

  • Step 1: Map how the work moves today. 

  • Step 2: Identify repetitive steps, bottlenecks, handoffs, and areas of avoidable risk. 

  • Step 3: Establish a baseline for time, cost, quality, and capacity. 

  • Step 4: Decide where AI can improve the workflow rather than simply accelerate an existing weakness. 

  • Step 5: Assign owners, controls, and review requirements, then pilot and measure before scaling. 

Even a well-designed workflow can fail if predictable operating risks remain unresolved. Shadow AI can move work into unapproved consumer tools. Blanket restrictions can inadvertently capture AI already embedded in ordinary software. AI transcription in client meetings can create confidentiality concerns, while model outputs can change over time. Each use case therefore needs defined testing, human review, and exception handling.

The Challenge of Measuring Value

As clients move from asking for consent to asking for value, firms need evidence at the workflow level. Clients understandably want evidence that AI investments are generating meaningful returns. Yet there is little consensus regarding the appropriate metric. Should value be measured through lower costs, reduced hours, faster turnaround, better quality, improved outcomes, or some combination of them?

The reality is that all may play a role. The most useful measurement starts with a defined workflow, not an enterprise-wide ROI claim. Compare the historical inputs for a specific task or phase with the same work after AI is introduced. Track what changes in cycle time, cost, quality, capacity, and risk.

For many matters, the greatest benefit of AI may not be lower cost. It may be faster delivery, deeper analysis, broader coverage, improved consistency, greater capacity, or the ability to make better-informed decisions. Those advantages can create substantial value even when they do not translate neatly into traditional billing metrics. Efficiency does not automatically equal cost reduction. The metric should reflect the client outcome the work is intended to improve, not the number of licenses issued or prompts entered.

What Legal Leaders Should Do Now

The legal profession is moving from experimentation to execution. Conversations about tools are giving way to more substantive questions about governance, accountability, client expectations, and trust. These conversations may lack the novelty of technology demonstrations, but they are far more consequential. For legal leaders, that shift points to five immediate actions:

  • Redesign the workflow before selecting the AI intervention. Map the work and identify where AI can change it, not simply speed it up. 

  • Put AI decision-making within one cross-functional governance model. Assign authority over tools, use cases, risk, and exceptions. 

  • Define the data boundaries before scaling. Set rules for access, separation, prompts, outputs, retention, ownership, vendor use, and auditability. 

  • Plan for predictable operational traps. Address shadow AI, blanket restrictions, client-side meeting tools, changing model behavior, and the level of human review each use case requires. 

  • Measure outcomes, not adoption. Track time, cost, quality, capacity, and risk at the workflow level.

Taken together, these actions create conditions for trust. The next phase of AI adoption will not be defined by access to sophisticated tools alone, but by the ability to turn governance and operational discipline into a better way of working. As I challenged attendees:

“Think bigger. Ask a different, bigger question about how work happens.”

– Joel Wirchin is Senior Director, Legal Strategy at Williams Lea.

Insights

The Think Space

See All Insights
Sep 30, 2026

Paving the Path to Operational AI: What the Firms Making Progress are Doing Differently

7 Min Read
Sep 30, 2026

Clients are Writing the New Rules for Legal AI

7 Min Read
Sep 11, 2026

Why Creative Operating Models will Matter More than Creative Tools in 2026

6 Min Read
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.