Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Law firms running multiple AI tools need a record of what each agent touches and who approved it. Here's how to build that discipline.

AI Governance for Law Firms Is Now a Board Issue
Insight ai

AI Governance for Law Firms Is Now a Board Issue

Sam McKay

A recent piece from SAP’s news desk made a point that’s been sitting in the back of my mind for a few months now. AI agent sprawl, the quiet accumulation of tools that each touch a slice of company data, has moved from an IT problem to a board-level one. The reasoning is simple. Once you have five or six agents running inside your operation, each with its own access to systems and data, nobody at the top can actually say who approved what, or what any given tool can see.

For a law firm, that’s not a minor governance gap. That’s the same category of risk as a missed conflict check.

If you run a firm doing $1M to $25M in revenue, you’ve probably added AI tools faster than you’ve documented them. A research assistant here. A drafting tool there. Maybe an intake bot bolted onto your website last year. Each one seemed like a small decision at the time. Add them up and you’ve got a patchwork of systems touching client files, matter details, and privileged communications, with no single list of who can see what.

What Agent Sprawl Looks Like Inside a Law Firm

Walk through a typical mid-size firm and you’ll usually find AI showing up in three places without anyone quite deciding to put it there.

Research tools get adopted by individual associates because they save hours on case law summaries. Drafting assistants get added by a managing partner who wanted faster first drafts on standard agreements. Intake gets automated by whoever handles marketing, usually a chatbot plugged into the website that nobody outside marketing has actually reviewed for what it stores or who sees the transcripts.

None of this is reckless. It’s just how tools get adopted in a busy practice. But when a client asks, as they increasingly do, “what AI touches my file and who signed off on it,” most firms don’t have an answer. That’s the exact question a conflict check answers for representation. It should be asked the same way for data access.

The SAP piece frames this as an enterprise IT concern, and for a Fortune 500 company it is. For a law firm, it’s sharper than that. You’re bound by confidentiality obligations that don’t bend for convenience. A client data breach through an ungoverned AI tool isn’t just a reputational hit. It’s a bar complaint waiting to happen.

Treat It Like a Conflict Check, Not a Software Audit

Most firms run conflict checks with real rigor. Every new matter gets checked against every current and former client relationship before anyone touches the file. Nobody skips this because it’s slow. It’s slow on purpose.

AI governance needs the same posture. Before any new tool touches client data, someone should be answering three questions in writing. What data does this tool access. Who approved it. What happens to that data after the tool processes it.

That’s not a compliance checkbox. It’s the same discipline you already apply to matter intake, just pointed at your tech stack instead of your client roster. Firms that build this habit now, while they’ve got three or four tools rather than fifteen, save themselves a much harder cleanup later. Firms that wait usually only fix it after an incident forces the conversation.

If you want a structured way to think through this for your own intake process specifically, our AI Client Intake Checklist for Law Firms walks through the exact questions to ask before a new tool touches a client file. It’s built as a working document, not a lecture. You can grab the checklist here and start applying it to whatever you’ve already got running.

Where the Manual Work and the Governance Gap Overlap

Here’s the part most governance conversations miss. The places where AI oversight is weakest are usually the same places where manual work is quietly draining the firm’s margin.

Take intake. Most firms still route after-hours calls and form submissions to voicemail or a shared inbox that gets checked in the morning. Industry data on legal intake consistently shows that a meaningful share of after-hours inquiries never convert once the caller’s had a few hours to call the next firm on their list. That’s lost revenue sitting right next to an ungoverned process, because whoever built the after-hours answering system probably wasn’t thinking about data access controls when they set it up.

Take document review. Junior associates spend days on first-pass review of contracts and discovery batches. At $200 to $400 an hour of associate time, that’s an expensive way to do work that’s largely pattern recognition. Firms that have started using AI to accelerate this step often did it fast, without a clear record of what document sets the tool ingested or where that data lives now.

Take billable-hour leakage generally. We typically see attorneys losing 4 to 6 hours a week to admin and intake tasks that never make it onto an invoice. That’s real money walking out the door every week, and it’s also exactly the kind of work firms are tempted to hand to whatever AI tool is fastest to set up, without pausing to document the handoff.

The point isn’t that AI is risky. It’s that speed without a paper trail creates two problems at once, an efficiency gap and a governance gap, and they compound.

What a Properly Governed Agent Actually Looks Like

This is where the distinction matters. An AI agent built with governance in mind isn’t slower or more limited. It’s just documented, scoped, and accountable in the same way a new associate would be before you hand them a client file.

Our Intake Voice Agent answers every call, after-hours, during lunch, on weekends, and runs a conflict check on the caller before it ever discusses matter details. It captures the intake information and books a consultation directly into the firm’s calendar. Every interaction is logged, every data touchpoint is scoped to exactly what intake needs and nothing more. You can see the full mechanics on the Omni voice page.

Our Matter Triage Agent reviews incoming form submissions and emails, classifies the practice area, scores fit against your firm’s actual capacity, and routes it to the right partner with a one-paragraph brief attached. It doesn’t touch anything outside the intake pipeline. What it accesses is defined once, reviewed periodically, and visible to whoever’s responsible for oversight.

Our Document Review Agent performs first-pass review on contracts, discovery batches, and matter files. It flags clauses, summarizes positions, and produces an associate-grade memo, but it operates inside a scoped environment where the firm controls exactly which matter files it can see and for how long. That’s the difference between “we use an AI tool for document review” and “we can tell you precisely what that tool accessed on any given matter.” One of those answers satisfies a client audit. The other doesn’t. Both agents run through the Omni ops framework, which is built around this exact accountability structure.

None of this requires slowing the firm down. It requires deciding, in advance, who approves a new agent and what it’s allowed to touch. That’s a fifteen-minute conversation per tool. Most firms have just never had it.

The Dollar Reality for a Firm Your Size

For a firm doing $1M to $25M in revenue, the manual work sitting behind ungoverned or absent AI tooling typically runs $80,000 to $250,000 a year in lost billable time, missed intake conversion, and associate hours spent on first-pass review that could run faster and cheaper. That range holds up across firms of very different practice mixes, because the underlying pattern is consistent. Intake delays cost new business. Document review eats associate capacity. Admin work displaces billable hours.

The governance question doesn’t add cost to fixing this. It changes how you fix it. Instead of bolting on tools ad hoc and hoping nobody asks hard questions later, you build the same tools with a documented access map from day one. It costs you almost nothing extra at build time and saves you the entire cleanup cost later.

Firms of this size typically see 4 to 6 hours of unbilled attorney time per week and 30 to 40 percent of after-hours intake going unconverted, a combination that lands most firms in the $80K to $250K range in annual leakage.

What an Omni Audit Actually Shows You

We built the Omni Audit specifically to answer the two questions sitting behind everything in this article. Where is your manual work costing you money, and where is your current AI usage, if you have any, missing the documentation a client or a regulator would expect to see.

It runs 60 minutes. No deck, no sales pitch buried in slides. You walk away with three concrete outputs. A map of where your intake, triage, and document review work is currently handled, and by whom or what. A dollar estimate of what that work is costing you annually, based on your actual call volume and matter mix rather than industry averages. And a governance snapshot, a plain-language list of what any existing AI tools in your stack can currently access and where the accountability gaps sit.

If you’re already running one or two AI tools and aren’t entirely sure what they can see, this is the fastest way to find out before a client asks you first. See Omni for law firms for the full breakdown of what we look at during the session.

Book a 60-min Omni Audit and we’ll walk through your intake pipeline, your document review load, and whatever AI tools you’ve already got running, in one sitting.

Building the Habit Before You Need It

The firms that handle this well aren’t the ones with the most sophisticated AI stack. They’re the ones who decided early that every new tool gets the same scrutiny as a new client matter. Who approved it, what does it touch, and who’s accountable if something goes wrong. That habit costs almost nothing to build now and becomes very expensive to retrofit once you’ve got a dozen tools running with no record of any of it.

Start with the checklist if you want a structured first pass at your own intake process. If you want a clearer read on where the dollars are actually going and what your current setup can and can’t account for, that’s exactly what the audit is for. For more on how firms in your position are approaching this, our insights section covers the operational side in more depth, and the guides library has practical breakdowns if you want to see how other practice areas are structuring their own AI rollouts.

Either way, the board-level question isn’t going away. It’s better to have the answer ready than to build one under pressure. Book my Omni Audit and let’s get you a clear picture of what you’re running and what it’s costing you, one way or the other. And if you want the full detail on what we look at specifically for legal practices, the AI audit for law firms page has the exact framework we use.