Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Enterprise studies show legal AI agents are live before oversight exists. Here's the governance gap costing your firm six figures in risk and rework.

Law Firms Are Deploying AI Faster Than Governance
Insight ai

Law Firms Are Deploying AI Faster Than Governance

Sam McKay

A partner at a mid-sized litigation firm told me last month that their junior associates had been using ChatGPT for legal research for six weeks before anyone in leadership knew. No policy. No review protocol. No audit trail. When the managing partner found out, the firm spent three days reconstructing which client matters had been touched and whether any privileged information had left the building.

That’s the governance gap. AI agents are being deployed in law firms faster than the frameworks to manage them. VentureBeat’s recent enterprise research confirms what we’re seeing across our network: agents are live in production, handling client intake, document review, and legal research while governance protocols lag months behind. For firms billing $1M to $25M annually, this gap isn’t just a compliance headache. It’s a six-figure risk sitting in your workflow right now.

The speed problem isn’t going away

Law firms face a unique pressure. Clients expect instant responses. After-hours intake calls go straight to voicemail, and 30 to 40 percent of those callers never leave a message or try again. They call the next firm. That’s $80K to $250K in annual leakage for a typical practice, and it’s why partners are reaching for AI voice agents that can answer every call, run conflict checks, and book consultations without human intervention.

The technology works. Our Intake Voice Agent handles after-hours calls with the same protocol a paralegal would follow: capture the matter, check for conflicts, qualify the lead, and slot a consultation into the calendar. It’s live in a dozen firms right now, and the conversion lift is measurable. But here’s the problem: most firms turned it on without writing down who reviews the transcripts, how often, or what happens when the agent makes a mistake.

That’s not a technology failure. It’s a governance failure. And it’s happening because the deployment cycle for AI agents is now faster than the policy-writing cycle inside most firms.

What governance actually means in a law firm context

Governance isn’t a 40-page manual. It’s three things: who decides, who reviews, and what gets logged. When an AI agent touches a client matter, you need to know what data it accessed, what output it produced, and who signed off before that output went into a brief or onto a client call.

Most firms we work with don’t have that protocol written down. They have agents running in Slack, drafting intake summaries, pulling case law, and generating first-pass contract reviews. The output is good enough that associates use it. But there’s no review step, no version control, and no audit trail linking the agent’s work to the final deliverable.

Here’s what that looks like in practice. A junior associate uses a Document Review Agent to summarise a 200-page discovery batch. The agent flags three clauses, writes a two-page memo, and the associate forwards it to the partner. The partner edits two sentences and sends it to the client. Six weeks later, opposing counsel challenges a factual claim in the memo. The partner asks the associate where the claim came from. The associate says the agent flagged it. No one kept the agent’s raw output. No one logged which version of the model was used. The firm can’t reconstruct the chain of reasoning, and the claim gets withdrawn.

That scenario has happened twice in our network in the past four months. Both times, the firm had deployed the agent without a review protocol. Both times, the cost to fix it was higher than the time saved.

The three gaps we see in every unmanaged deployment

The first gap is access control. Agents need data to work. An Intake Voice Agent needs access to your conflict-check database and your calendar. A Matter Triage Agent needs access to client emails and intake forms. A Document Review Agent needs access to matter files. Most firms grant that access without documenting it, and without setting retention or deletion rules.

We worked with a family law practice last year that had given their intake agent read access to every client record in their CRM. The agent only needed access to active matters, but the firm’s IT contractor had granted full access because it was faster. When the firm ran an internal audit six months later, they discovered the agent had logged 14,000 client records it never needed to touch. No breach occurred, but the exposure window was six months wide.

The second gap is output review. Agents produce work product. That work product goes into client deliverables. Most firms don’t have a written rule about who reviews agent output before it leaves the building. The assumption is that the associate or paralegal using the agent will review it, but that assumption isn’t documented, and it’s not enforced.

Here’s the test: ask your associates right now whether they’re required to review every line of agent-generated text before using it in a client memo. Half will say yes. Half will say they thought it was optional. That’s a governance gap, and it’s costing you billable hours in rework when mistakes slip through.

The third gap is logging. When an agent performs a task, you need a record. What input did it receive? What output did it produce? What version of the model was running? Most firms don’t log any of this. The agent runs, the output appears in Slack or email, and the record disappears when someone deletes the thread.

That’s fine until you need to reconstruct what happened. A client disputes a bill. A regulator asks how you handled a conflict check. Opposing counsel challenges the accuracy of a document summary. If you can’t produce the agent’s log, you’re defending the output with no evidence of how it was created.

What a governance protocol actually looks like

A working governance protocol for AI agents in a law firm fits on two pages. It covers five things: who can deploy an agent, what data the agent can access, who reviews the output, how long logs are retained, and who’s responsible when something goes wrong.

Here’s a real example from a commercial litigation firm we work with. They deployed our Matter Triage Agent to handle intake form submissions. The agent reads the form, classifies the practice area, scores the lead, and routes it to the right partner with a summary attached. Before they turned it on, they wrote a one-page protocol:

  • Only the managing partner can authorise a new agent or change its data access.
  • The agent has read-only access to intake forms and the conflict-check database. No access to client matter files.
  • Every agent-generated summary is reviewed by a paralegal before it’s forwarded to a partner. The paralegal’s initials go in the subject line.
  • Agent logs are retained for three years and stored in the same document management system as client files.
  • If the agent makes a factual error, the paralegal who reviewed the output is responsible for the correction, and the incident is logged in a shared spreadsheet.

That protocol took 90 minutes to write. It’s been in place for eight months. The firm has logged three agent errors in that time, all caught by the paralegal review step, and none reached a client. The protocol works because it’s specific, it’s short, and it’s enforced.

If you don’t have something like this written down, you’re running agents without governance. That’s the gap VentureBeat is describing, and it’s the gap that’s costing firms six figures in risk exposure and rework.

How the Omni Audit surfaces governance gaps in 60 minutes

We built the Omni Audit to find these gaps before they cost you money. It’s a 60-minute working session, not a sales call. We map three workflows in your firm where agents could be deployed or are already running. We identify the data access points, the review steps, and the logging gaps. You walk out with three outputs: a workflow map, a risk scorecard, and a two-page governance template tailored to your practice.

Most firms we audit discover at least one agent running without oversight. Sometimes it’s a junior associate using a third-party research tool. Sometimes it’s a paralegal using an AI summariser for discovery. Sometimes it’s a voice agent the firm deployed six months ago and forgot to document. The audit surfaces it, and we write the protocol to fix it.

The download we’ve built for this, the AI Client Intake Checklist for Law Firms, walks you through the intake-specific governance questions: what data your intake agent needs, who reviews its output, and how you log the interaction. It’s a practical worksheet, and it’s a good starting point if intake is your first deployment. But the audit covers all three agent types we build, intake, triage, and document review, and it’s the fastest way to get a complete picture of your governance posture.

You can see the full scope of the AI audit for law firms on our vertical page, or book a 60-min Omni Audit directly. We run these every week, and the output is yours whether you work with us or not.

Why this matters more for law firms than other verticals

Law firms face a higher governance bar than most businesses. You’re handling privileged information. You’re bound by ethics rules. You’re subject to discovery in litigation. When an AI agent touches client data, you’re responsible for what it does with that data, and you’re responsible for the accuracy of its output.

That’s not true in every industry. A trades business can deploy a scheduling agent with minimal oversight because the downside of a mistake is a missed appointment, not a malpractice claim. A law firm can’t take that risk. The cost of a governance failure in a legal practice is higher, and the regulatory exposure is broader.

We’ve written about this dynamic in more detail across our insights library and in the technical breakdowns on Omni Ops, where we cover how document review agents handle privileged material. The short version is that law firms need tighter protocols, better logging, and more frequent audits than most verticals. That’s not a limitation. It’s a design constraint, and it’s one we build for.

The three agents that need governance first

If you’re running AI agents in your firm right now, or you’re planning to deploy them in the next quarter, start with these three.

The Intake Voice Agent is the highest-risk deployment because it’s client-facing and it handles conflict checks. If the agent books a consultation with a conflicted party, you’ve created an ethics problem before the client walks in the door. The governance protocol for this agent needs to specify how often a human reviews the conflict-check logic, who’s responsible for monitoring the call transcripts, and what happens when the agent misclassifies a matter. We cover this in detail on the Omni Voice page, and it’s the first agent we audit in every law firm engagement.

The Matter Triage Agent is the second priority because it routes high-value leads to partners. If the agent misroutes a case, you’ve lost the client before anyone knows they existed. The governance protocol here needs to specify who reviews the agent’s classification logic, how often the routing rules are updated, and what happens when a partner reports a bad lead. This agent typically saves 4 to 6 hours per week of partner time, but only if the routing is accurate.

The Document Review Agent is the third priority because it produces work product that goes into client deliverables. If the agent misreads a clause or misses a key fact, the error propagates into briefs, memos, and court filings. The governance protocol for this agent needs to specify who reviews the agent’s output before it’s used, how the review is documented, and how long the agent’s raw output is retained. This is the agent that most often runs without oversight, and it’s the one that creates the biggest malpractice exposure when it fails.

All three agents are live in firms we work with right now. All three have governance protocols in place. If you’re running any of these agents without a protocol, you’re in the gap VentureBeat is describing, and you’re carrying more risk than you need to.

What happens when you don’t govern

The cost of ungoverned AI in a law firm isn’t abstract. It shows up in three places: rework, risk exposure, and client trust.

Rework happens when an agent produces output that isn’t reviewed, gets used in a client deliverable, and turns out to be wrong. The associate has to redo the work. The partner has to review it again. The client gets a revised memo. That’s 3 to 5 billable hours lost, and it’s a direct result of skipping the review step in your governance protocol.

Risk exposure happens when you can’t reconstruct what an agent did. A regulator asks how you handled a conflict check. You can’t produce the log. A client disputes a bill. You can’t show the work the agent performed. Opposing counsel challenges a factual claim. You can’t trace it back to the source document. In every case, you’re defending your work with no evidence, and that’s a governance failure.

Client trust is harder to quantify, but it’s the biggest cost. When a client discovers you’re using AI agents without oversight, they start asking questions. Are you logging my data? Who’s reviewing the output? What happens if the agent makes a mistake? If you don’t have good answers, the client starts looking for a firm that does.

We’ve seen this play out twice in the past year. Both times, the firm lost the client not because the agent made a mistake, but because the firm couldn’t explain how the agent was governed. That’s a $50K to $150K annual client walking out the door because you didn’t spend 90 minutes writing a protocol.

The path forward is shorter than you think

The governance gap isn’t a six-month project. It’s a two-week sprint. You write the protocol, you train the team, and you start logging. Most firms we work with have a working governance framework in place within 10 business days of the audit.

The hard part isn’t writing the protocol. The hard part is knowing where the gaps are. That’s what the Omni Audit does. We map your workflows, we identify the agents you’re running or should be running, and we write the governance template. You implement it, and you’re covered.

If you’re ready to close the gap, book my Omni Audit now. If you want to see the full scope of what we build for law firms, visit Omni for law firms and read the case breakdowns. And if you want to start with the intake-specific checklist, download the AI Client Intake Checklist and work through it with your team.

The agents are already running. The question is whether you’re governing them or just hoping they don’t break. Most firms are hoping. The ones that aren’t are the ones that will still be here in five years.