AI Agents in Your Firm, Who Carries the Risk
A Forbes Technology Council piece this month made a point that’s been rattling around boardrooms for a year now: agentic AI is moving faster than the resilience planning around it. Enterprises are deploying agents that act, decide, and execute with less human review at every step, and the governance, insurance, and oversight structures haven’t caught up.
Law firms are not exempt from this. If anything, you’re more exposed. When a retail company’s AI agent makes a bad call, it’s a customer service complaint. When your firm’s AI agent misreads a contract clause, mischaracterizes a discovery document, or drafts a memo with a hallucinated case citation that an associate doesn’t catch, that’s a malpractice exposure with your name on the engagement letter.
The tools are already in your building. The question is whether your oversight and your insurance coverage know it.
Where AI is already doing legal work at your firm, unofficially
Most managing partners we talk to think their firm’s AI use is limited to one associate’s ChatGPT habit. It rarely is. Attorneys use AI tools for first drafts, research summaries, and contract redlines because the alternative is 4-6 unbilled hours a week of document grinding that nobody wants to do manually anymore. That’s a typical range for firms of your size, and it’s exactly why the shortcuts happen quietly.
The problem isn’t that attorneys are using AI. It’s that most firms have no consistent procedure for how AI output gets checked before it becomes part of a client file, a filing, or an opinion letter. There’s no sign-off step. No log of which matters had AI involvement. No standard for what “reviewed” actually means. If a claim ever comes in, you’ll be asked to produce that record, and most firms currently can’t.
This is the gap the Forbes piece is pointing at from the enterprise side. For law firms specifically, it shows up in three places.
The three failure points nobody’s insuring against yet
Document review and discovery. Junior associates spend days on first-pass review at $200-400 an hour of billed or written-off time, and firms are increasingly using AI tools to speed that up. Good. But if the AI agent misses a privileged document, misclassifies a hot document as irrelevant, or summarizes a deposition transcript incorrectly and nobody catches it before it goes to the partner, that’s not a technology problem anymore. That’s a malpractice fact pattern.
Research and drafting. AI-generated case citations that don’t exist are well documented at this point, and courts have already sanctioned attorneys for filing them. Your malpractice carrier wants to know what your review procedure is before every filing that touched AI. Most firms don’t have an answer beyond “we look it over.”
Intake and conflict screening. This one’s less obvious but just as real. If you’re using any automated intake tool and it misses a conflict, or captures a matter detail incorrectly that later affects a deadline, that’s a liability event traced back to a process with no human checkpoint.
None of this means don’t use AI. It means the oversight procedure has to be as deliberate as the tool itself, and your coverage has to reflect what you’re actually doing, not what your policy assumed three years ago.
What oversight actually looks like, not a policy binder
Most firms respond to this risk by writing a policy document nobody reads. That’s not oversight, that’s paper. Real oversight has three components.
First, a defined checkpoint. Every AI-touched work product needs a named human who signs off before it moves forward, and that sign-off needs to be logged somewhere retrievable. Not a verbal “looks fine,” an actual record.
Second, a scope boundary. AI agents should have a clearly defined job (first-pass review, intake capture, triage) and a clearly defined stop point where the matter goes to a person. The Forbes piece calls this the core resilience gap in agentic AI generally: agents that keep acting past the point where a human should have stepped in.
Third, a coverage conversation with your carrier that names the actual tools and workflows you’re running, not a generic tech rider. Ask your broker directly whether your current malpractice policy addresses AI-assisted work product, and get the answer in writing. If they can’t answer clearly, that’s information too.
This is also where a structured intake process pays off twice, once for conversion and once for risk. If you want a working reference for what a defensible intake checkpoint looks like, our AI Client Intake Checklist for Law Firms walks through the specific fields and sign-off points firms in our network use to keep intake both fast and reviewable. It’s built as a practical worksheet, not a theory document, and you can grab the checklist here if you want a starting point before your next carrier conversation.
What a properly built agent looks like end-to-end
The fix isn’t fewer agents. It’s agents built with the checkpoint baked into the workflow instead of bolted on after the fact. Here’s what that looks like for the three workflows we build most often for firms your size.
The Intake Voice Agent answers every call, after-hours, lunch, weekends, and runs a conflict check on the caller before anything else happens. It captures the matter details in a structured format, not a loose voicemail transcript, and books the consultation directly into the right partner’s calendar. Every call is logged with a timestamp and a transcript, which is exactly the kind of record a carrier or a bar complaint process wants to see. Nothing about this agent decides legal strategy. It captures, screens, and routes, and it stops there.
The Matter Triage Agent picks up incoming form submissions and emails, classifies the practice area, scores fit against your firm’s actual criteria, and routes the matter to the right partner with a one-paragraph brief attached. The partner still makes the call on whether to take the matter. The agent’s job is to make sure nothing sits in an inbox for six hours while a competitor firm answers first, which is the reality for 30-40% of after-hours intake at firms without this in place.
The Document Review Agent performs first-pass review on contracts, discovery batches, and matter files. It flags clauses, summarizes positions, and produces an associate-grade memo. Critically, it doesn’t file anything, doesn’t finalize anything, and doesn’t skip the human review step. It compresses the days of first-pass grinding into a memo an associate can verify in an hour instead of writing from scratch across three days. The checkpoint is built into the deliverable format itself, because a memo demands a sign-off in a way a buried inbox doesn’t.
This is the actual answer to the Forbes piece’s concern. Agentic AI outpaces resilience when agents are deployed to just go faster with no defined stopping point. Agents built with a stopping point baked into the design don’t create that gap. You can see how we structure this specifically for legal workflows on the Omni ops page, and how the voice-side intake work fits alongside it on the Omni voice page.
The dollar math on getting this wrong, or right
Firms in the $1M-25M range typically carry somewhere in the range of $80,000 to $250,000 a year in leakage tied to exactly these workflows: unbilled attorney hours on admin and review, missed after-hours intake that goes to a competitor, and associate time burned on first-pass discovery that could be compressed.
That’s the leakage side. The liability side is harder to put a number on because it’s contingent, but it’s not smaller. One malpractice claim tied to an AI-assisted filing or a missed conflict can run well past your annual leakage number in defense costs alone, before you even get to the reputational cost of a bar inquiry. Carriers are already adjusting how they underwrite firms with undisclosed or unstructured AI use, and that trend moves in one direction from here.
The firms getting ahead of this aren’t the ones avoiding AI. They’re the ones building the oversight and the coverage conversation at the same time they deploy the tools, so the two things track together instead of one running years ahead of the other.
The Omni Audit, 60 minutes, three outputs
We don’t start with a deck and we don’t start with a sales pitch. We start with a 60-minute audit of your actual intake, triage, and review workflows. You walk out with three things: a map of where hours and dollars are leaking right now, a specific list of where an AI agent could take over with a defined human checkpoint, and a plain-language estimate of what that’s worth annually to a firm your size.
This is also where the liability conversation gets concrete instead of theoretical, because we’re looking at your actual workflows, not a generic risk framework. If you’re already using AI tools informally across intake or review, the audit is the fastest way to find out where the oversight gap actually sits before a carrier or a claim finds it for you.
You can see Omni for law firms to get a sense of what the audit covers before you book, or head straight to the AI audit for law firms page if you’d rather skip ahead. Either way, the next step is the same conversation, just at a different point in your thinking.
For a broader look at how firms in adjacent professional services are approaching agentic AI governance, our insights hub tracks this across verticals, and the guides section has more detail on how we scope oversight checkpoints inside agent builds generally.
Where to start this week
Pull your current malpractice policy and find the AI-related language, or the absence of it. Ask your broker directly what “AI-assisted work product” means under your current terms. Then look at your intake and review workflows and ask a simpler question: if a claim came in tomorrow tied to an AI-touched matter, could you produce a clean record of who reviewed what and when.
If the answer is no, that’s not a reason to panic. It’s a reason to fix the workflow before it becomes a claim instead of after. Book a 60-min Omni Audit and we’ll walk through your actual intake and review process, no deck, no generic framework, just your numbers and your risk exposure mapped against what an agent with a real checkpoint would look like at your firm.
The agentic AI race isn’t slowing down, and neither is the exposure it creates for firms that adopt it without the oversight to match. The firms that get this right in the next year will be the ones who treated the checkpoint and the coverage as part of the build, not an afterthought. Book your Omni Audit and let’s find out where your firm actually stands.