Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Law firms using multi-day AI agents need approval gates, audit logs, and policy checks to protect confidentiality and reduce costly leakage.

Long-Running Legal Agents Need Compliance Gates
Insight ai

Long-Running Legal Agents Need Compliance Gates

Sam McKay

A larger context window is not a compliance control

Law firms are starting to use AI agents for work that lasts longer than one prompt or one phone call. An agent might monitor an intake queue through the weekend, collect documents over three days, prepare an initial case file, or coordinate first-pass discovery review across a large matter.

That is useful. It is also where the risk changes.

A one-off AI task is relatively contained. Someone gives the system a contract, asks for a clause summary, reviews the answer, and closes the task. A long-running agent keeps acting. It receives new messages, stores or retrieves matter details, makes routing decisions, follows workflows, and can trigger downstream actions.

The problem is not simply that an agent might make a bad call. The more serious issue is that it can quietly stop applying a rule it was expected to follow.

It may initially screen for conflicts, then process a follow-up message without rerunning the check. It may be told not to share sensitive matter details outside a defined workspace, then include too much context in a partner brief. It may know an escalation rule on Monday and fail to apply it after several days of activity, new instructions, and changing matter context.

The recent reporting on long-running agents makes an important point. Bigger context windows do not guarantee ongoing policy adherence. More history can help an agent recall facts, but it does not create reliable governance. A law firm should not assume that an AI system will preserve confidentiality rules, engagement restrictions, ethical walls, or approval requirements merely because those rules appeared in its earlier instructions.

For firms doing $1 million to $25 million in revenue, this is not a theoretical enterprise problem. You need practical automation because intake, matter administration, and document review consume expensive time. You also need controls that a managing partner can explain to clients, insurers, staff, and regulators.

The right question is not, “Can the agent run for several days?”

It is, “What must the agent prove, who must approve it, and what record will we have when something matters?”

That is the standard behind the AI audit for law firms.

Where long-running agents create real exposure

Consider a typical new client inquiry.

A prospective client calls after hours. They explain a dispute, name the opposing party, upload a demand letter, and ask for an urgent consultation. The next morning, they send another email with documents. A staff member forwards the inquiry to a partner. The partner responds later that day, assuming conflict screening happened somewhere in the process.

This workflow often contains handoffs, inbox searches, copied notes, and implicit assumptions. AI can reduce the friction. But if an agent runs this workflow without checkpoints, it can make the existing ambiguity faster.

An Intake Voice Agent (Omni voice) can answer calls after hours, over lunch, and on weekends. It can capture the matter, collect opposing-party information, ask approved qualification questions, and book a consultation. That gives a firm a better chance of responding before the prospect contacts another practice. Firms commonly see 30% to 40% of after-hours intake fail to convert when no one responds promptly.

Yet the agent should not be allowed to represent that the firm has accepted the matter. It should not disclose existing client relationships. It should not provide legal advice beyond an approved intake script. It should not send an engagement letter after hearing a name that appears to be clear.

Those are approval and policy questions, not conversational quality questions.

The same applies to an Matter Triage Agent (Omni ops). It can read incoming forms and emails, classify a likely practice area, score fit, route the inquiry to the right partner, and attach a one-paragraph brief. That saves time for staff and creates a cleaner first review.

But routing a matter involving a current client, a former client, a restricted industry, or a sensitive litigation opponent needs a policy gate. The agent can identify the situation and collect information. A designated human must decide whether the workflow may advance.

Document work brings a second form of risk. A Document Review Agent (Omni ops) can process a discovery batch, compare contract language to a playbook, flag clauses, summarise positions, and prepare an associate-grade memo. It can take away much of the repetitive first-pass work that otherwise sits with associates billing $200 to $400 per hour.

Still, an agent that runs over days should not quietly alter its confidentiality classification, apply an outdated playbook, or deliver a privileged document summary into the wrong workspace. First-pass review is a strong AI use case. Unsupervised final legal judgment is not.

The three controls every long-running agent needs

There are three controls I would insist on before allowing an agent to operate across days, multiple touchpoints, or sensitive matter files.

1. Human approval gates for consequential actions

An approval gate is a hard stop. The agent can prepare the work, but it cannot take the next consequential action until an authorised person reviews and approves it.

For a law firm, consequential actions usually include:

  • Moving an inquiry from prospective lead to active client
  • Confirming that a conflict check is clear
  • Sending an engagement letter or fee agreement
  • Sharing a summary that includes sensitive client facts
  • Routing a matter into a restricted practice group or ethical-wall workspace
  • Marking document production material as ready for delivery
  • Sending a substantive response that could be treated as legal advice
  • Closing an intake based on a lack of fit or conflict result

The key is to define the gate in the workflow itself. “Someone should review it” is not a control. The system must know that it cannot send, route, publish, or close the matter until the named reviewer approves.

A good approval screen is short. It should show the source materials, the agent’s summary, the policy reason for escalation, the proposed action, and an approve or reject decision. If approval requires reading ten screens of agent output, people will skip it.

For example, an intake agent can draft a consultation confirmation but hold it in a pending queue when the caller names an opposing party or gives information that matches an existing matter. The conflicts coordinator gets the exact details required for review. The agent does nothing further until that person records a decision.

That is how you keep speed without pretending that a workflow engine can carry professional responsibility.

2. Immutable audit logs that show what happened

If a partner asks, “Why did this inquiry get routed to me?” you need more than a chat transcript.

You need an immutable audit trail that records:

  • The source of each item of information
  • The time an event occurred
  • The policy version active at that time
  • The agent’s classification or recommendation
  • Any retrieval sources used by the agent
  • The action the agent attempted to take
  • The person who approved, rejected, or overrode it
  • The final action taken
  • Changes to rules, permissions, prompts, or matter access

“Immutable” does not mean nobody can correct a record. It means corrections are added as new entries. You do not overwrite the previous record and lose the sequence of events.

This matters for operational reasons before it ever becomes a dispute. Without logs, your team cannot diagnose why an agent treated a personal injury intake differently from a commercial dispute. You cannot see whether a failure came from incomplete intake data, a misconfigured rule, a stale knowledge source, or a human override.

It also matters when client confidentiality is involved. A firm should be able to establish who accessed what information, why that access occurred, and which workflow state permitted it. That expectation should shape the system from the beginning.

If your firm is considering a workflow that handles calls, email, forms, calendars, and matter documents, review Omni voice and Omni ops as separate operating layers. Voice intake and document workflows have different triggers, permissions, and risks. They should not be treated as one generic bot.

3. Recurring policy checks, not one-time instructions

Most firms begin with a policy document or a carefully written set of agent instructions. That is a useful start, but it cannot be the finish.

Long-running agents need recurring checks because the environment changes while the work is in progress.

A new email may introduce an opposing party. A client may add an affiliate that changes a conflicts analysis. A staff member may update a practice-area policy. A document batch may include a privileged attachment. A new matter status may restrict who can see the file.

The agent should re-evaluate relevant rules at defined triggers, including:

  • Every new party name, entity, or related matter identifier
  • Every upload or external document link
  • Every change in matter status
  • Every handoff from intake to consultation or engagement
  • Every outbound communication
  • Every scheduled interval during a multi-day workflow
  • Every update to the firm’s policy, playbook, or permissions

This is not just a reminder injected into an agent conversation. It is a policy evaluation outside the model’s memory. The workflow should call a current rules source, check the matter state, and decide whether the action is allowed, blocked, or sent for review.

That distinction is important. You do not want the agent to “remember” it should avoid sharing confidential information. You want the system to verify permissions before it can share anything.

What a controlled agent workflow looks like

Here is a practical example for a law firm handling new litigation inquiries.

At 8:40 p.m., a caller reaches the Intake Voice Agent. The agent identifies the caller, obtains contact details, captures a high-level issue description, asks for relevant entities and opposing parties, and explains that the firm has not agreed to representation.

The agent creates a provisional intake record. It does not create a client matter.

A conflict-check workflow compares the supplied names against approved sources. If the result is clear and the inquiry matches the firm’s criteria, the agent can offer available consultation times. If there is a potential match, missing information, or a high-sensitivity marker, the workflow stops and routes the record to a conflicts reviewer.

At 9:15 a.m. the next day, the Matter Triage Agent reviews the caller’s web submission and follow-up email. It detects that a newly named company was not part of the original call. That triggers a recurring policy check. The system reruns the conflicts screening rather than relying on last night’s result.

The agent creates a brief for the assigned partner, but it does not send a matter summary to a broad internal channel. Access is limited to the people named in the workflow.

After the consultation, a partner approves the engagement path. Only then can the agent prepare approved next steps, initiate the correct matter workspace, and request documents through the firm’s authorised process.

Later, the Document Review Agent receives the first document batch. It classifies the files, flags items requiring privilege review, produces a draft memo, and identifies missing materials. It cannot mark production-ready items as final. An associate or supervising attorney reviews the output, records the disposition, and the audit log preserves the chain.

That is not slower automation. It is automation designed for the way legal work actually carries risk.

The financial case is bigger than intake speed

Compliance controls can sound like overhead until you look at the work they protect.

Many firms see 4 to 6 hours per attorney each week disappear into non-billable document review setup, intake follow-up, matter admin, and internal status chasing. Some of that time should remain human work. A meaningful portion comes from repetitive collection, categorisation, scheduling, summarisation, and routing that can be automated with the right controls.

For a small firm, the result may be fewer missed calls and a cleaner intake process. For a growing practice, it can mean partners spend less time sorting leads and associates spend fewer hours on first-pass file organisation. Across the law-firm vertical, we often see annual operational leakage in the $80K to $250K range once unbilled staff time, lost after-hours inquiries, rework, and slow document processing are included.

The wrong response is to deploy a long-running agent without guardrails to chase savings. One confidentiality failure, missed conflict, or untraceable client communication can erase the value of months of automation.

The better response is to identify workflows where the agent can do the preparation work, then build approval points around the decisions that carry legal, ethical, or client-service consequences.

If you want a useful starting point for your front door, use the AI Client Intake Checklist for Law Firms. It is a practical worksheet for mapping call handling, conflict questions, escalation rules, follow-up ownership, and the information your team needs before an intake can move forward. You can also access the direct intake checklist download for your operations lead.

Start with the workflow, not the model

You do not need to turn every legal process into an autonomous system.

Start with one workflow that has enough volume to matter and enough structure to control. After-hours intake is often a good first choice. Incoming email triage is another. First-pass document review can work well where your firm has clear playbooks and a defined attorney review step.

Map the workflow from trigger to outcome. Identify every point where confidential information enters, where a conflict question arises, where the system communicates externally, and where a professional judgment is required. Then define:

  1. What the agent can do without approval
  2. What it can draft but not send
  3. What must stop for human review
  4. What information must be logged
  5. Which rule set must be checked again when the matter changes
  6. Who owns exceptions and workflow changes

That exercise tends to reveal issues before technology does. You may find that conflict data is incomplete, partner calendars are inconsistent, practice-area routing rules live in people’s heads, or staff have different definitions of a qualified lead. Those are fixable operating problems. AI makes them visible.

For ideas on designing the operating layer around the technology, our AI advisory work focuses on workflow ownership, risk controls, and the practical adoption decisions firms need to make.

Make the audit trail part of the value

A well-built long-running agent should make your firm more accountable, not less.

It should give staff faster first responses. It should prepare better briefs for partners. It should reduce repetitive associate work. It should also show when a rule was checked, when a person approved an action, and why the system behaved the way it did.

That is the difference between a useful legal workflow and a black box running in the background.

If you are testing multi-day agents for intake, matter coordination, or document work, Book a 60-min Omni Audit. In 60 minutes, we will identify the highest-value workflow, map the current leakage, and outline the controls required before automation goes live. No deck. Just three practical outputs your firm can use.

You can also see Omni for law firms to understand how we assess intake, operations, and document workflows before recommending an agent build.

The aim is not to trust an agent with more than it can safely handle. The aim is to give it bounded work, current policy checks, clear human gates, and a record that stands up when someone asks what happened.

When you are ready to turn that into an implementation plan, Book my Omni Audit.