Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

AI agents don't hallucinate as often as they overstep. Here's how law firms define decision authority before deployment, not after a malpractice scare.

Set Authority Limits Before You Deploy Legal AI Agents
Insight ai

Set Authority Limits Before You Deploy Legal AI Agents

Sam McKay

A recent piece in VentureBeat made a point that a lot of firms are learning the hard way: when an AI agent goes wrong, it’s rarely because it made something up. It’s because nobody told it where its job ends. The agent didn’t hallucinate a fact. It exceeded its authority. It made a call it was never supposed to make on its own.

For a law firm, that distinction is the whole ballgame. A hallucinated case citation is embarrassing and fixable. An agent that quietly approves a contract clause, tells a prospective client something about their case, or reschedules a filing deadline without a partner ever seeing it, that’s a malpractice conversation. The technology isn’t the risk. The scope is.

If you’re a partner or GM at a firm doing $1M-$25M in revenue and you’re looking at AI agents for intake or document review, this is the piece you need to read before you sign anything, not after.

The manual work nobody has time for anyway

Most firms this size aren’t drowning because of one big problem. They’re bleeding out through a dozen small ones.

Attorneys lose somewhere in the range of 4 to 6 hours a week to work that never turns into a billable line. Reviewing intake forms. Chasing down conflict checks. Summarizing a discovery batch before deciding whether it’s worth a second look. None of it bills. All of it has to happen.

Then there’s intake itself. A call comes in at 7:40pm from someone who just got served papers or just had an accident. Nobody picks up. By the time someone calls back the next morning, that person has already talked to two other firms. Industry data on after-hours intake generally lands in the 30-40% range for conversions lost simply because nobody answered fast enough. That’s not a lead-generation problem. That’s a staffing-hours problem dressed up as a marketing problem.

And then discovery. A junior associate spends two or three days on first-pass review of a contract batch or a discovery set, at a fully loaded cost of $200-$400 an hour. It’s expensive, it’s slow, and it doesn’t scale when volume spikes. Every firm we talk to has some version of this bottleneck sitting in their matter management system right now.

None of this is new. What’s new is that AI agents can now touch all three of these workflows directly. Which is exactly why the authority question matters more than it did a year ago.

Why “the AI works” isn’t the question anymore

We’ve stopped fielding the question “does AI actually work for this?” Firms have seen enough demos and read enough about legal AI to know the underlying technology is solid. Contract review agents catch clauses reliably. Voice agents hold a coherent conversation and capture accurate details. The models are good enough.

The question we get now is sharper: what happens when the agent is right about the task but wrong about whether it should have acted at all?

That’s a governance question, not a technology question. And it’s the one most vendors skip past because it’s less fun to sell than “our AI can review 500 pages in ten minutes.”

Here’s what scope creep actually looks like in a law firm setting:

An intake agent doesn’t just capture a caller’s information. It starts answering questions about whether they have a case. That’s legal advice, from a system with no bar license, on a recorded line.

A document review agent doesn’t just flag a problematic indemnification clause. It marks the batch “cleared” because none of the flagged issues crossed its confidence threshold. Nobody attorney-reviews the ones it didn’t flag.

A triage agent doesn’t just route a new matter to the right partner. It quietly declines to route a borderline conflict-of-interest case because its classifier scored it low-priority.

None of these are hallucinations. The agent did exactly what it was built to do, faster and cheaper than a human. The problem is nobody drew the line for what it was and wasn’t allowed to decide on its own.

What authority limits actually look like in practice

This is where firms need to get concrete before deployment, not during a post-mortem. The exercise is simpler than it sounds. For every workflow you’re automating, you write down three tiers:

What the agent can decide alone. Scheduling a consultation. Classifying a practice area. Extracting dates, parties, and dollar figures from a contract. Flagging a clause for review. Low-stakes, reversible, no legal judgment involved.

What the agent can draft or recommend, but a human signs off. A summary memo on a discovery batch. A proposed response to a routine intake question. A suggested matter assignment for a complex or high-value case.

What the agent should never touch. Anything that constitutes legal advice. Anything that closes out a matter, waives a right, or commits the firm to a position. Anything involving a conflict determination that isn’t unambiguous.

Most firms we work with get the first tier right instinctively. They struggle with the second and third because nobody’s written it down. It lives in the head of whichever partner set up the workflow, and it doesn’t survive them going on vacation or the vendor pushing an update that changes default behavior.

This is also why a generic AI tool bought off the shelf is a different risk profile than an agent built for your firm’s specific matter types and intake criteria. Off-the-shelf tools ship with broad defaults because they’re built for every firm at once. You want narrower authority than the default, and you want it documented somewhere your managing partner can actually point to if a client or the bar ever asks how a decision got made.

If you want a structured way to think through this before you build anything, our guides section has more detail on how firms are sequencing agent rollouts by risk tier, and the insights library covers where other firms have drawn these lines in practice.

What this looks like end to end, with named agents

We build three agents most often for firms in this range, and each one has an authority boundary built into it from day one, not bolted on after.

The Intake Voice Agent answers every call, including the 9pm ones and the Saturday ones. It runs a conflict check against your existing client list in real time, captures the matter details, and books a consultation directly into the firm’s calendar. What it does not do: give any opinion on case merit, quote a fee, or answer a legal question. It’s scripted to redirect those to “an attorney will cover that on your call” every time. That boundary isn’t a limitation, it’s the thing that keeps the tool inside the lines of what a non-attorney intake process is legally allowed to do.

The Matter Triage Agent reviews every incoming form submission and email, classifies the practice area, scores the fit against your firm’s ideal client profile, and routes it to the right partner with a one-paragraph brief attached. It can decide routing on clear-cut cases. Anything ambiguous, anything touching a possible conflict, anything outside your normal practice mix, it flags for a human to route instead of guessing. That’s the tier-two boundary in action.

The Document Review Agent does first-pass review on contracts, discovery batches, and matter files. It flags clauses, summarizes positions, and produces an associate-grade memo. It doesn’t clear a document as final. It doesn’t decide what’s “immaterial.” Every batch gets a memo, and every memo gets an associate’s eyes before it moves. The agent compresses days of first-pass work into hours. It doesn’t compress out the review step itself, because that step is where your malpractice exposure actually lives.

You can see the fuller picture of how these fit together, along with the Omni voice and Omni ops products behind them, on our main Omni page. The point isn’t the tooling. It’s that each agent has a written authority boundary that a managing partner reviewed before go-live, not one that got decided by default settings in a vendor dashboard.

The dollar reality

For a firm doing $1M-$25M in revenue, we typically see $80,000 to $250,000 a year in leakage from this combination of unbilled attorney hours, missed after-hours intake, and slow first-pass document review. That’s not a hypothetical, it’s the range we see consistently once we walk through a firm’s actual intake logs, timekeeping data, and matter throughput.

Firms in the $1M-$25M range typically leak $80K-$250K a year across unbilled attorney hours, missed after-hours intake, and slow first-pass review, based on patterns we see across our law firm client base.

The fix isn’t “add more AI.” It’s knowing exactly which of those dollars come from a task an agent can safely own outright, and which come from a task an agent can only accelerate while a human still signs off. Firms that skip that distinction end up either under-deploying, leaving money on the table because they’re scared to automate anything, or over-deploying, which is how you end up in the VentureBeat scenario where the agent did exactly what it was told and that’s the problem.

Where the audit fits

This is exactly what an Omni Audit is built to sort out. It’s a 60-minute session, no slide deck, no sales pitch dressed up as a “strategy session.” We walk through your actual intake volume, your current document review process, and your matter mix, and we come out the other side with three concrete outputs: where the dollars are leaking, which workflows are safe for full agent authority versus draft-and-review authority, and what a phased rollout looks like for your firm specifically.

If you want to see how this plays out for firms like yours, see Omni for law firms has more detail on the process and what other practices have found in their first session. It’s also where we walk through the specific authority-tier framework for your intake and document workflows before anything gets built.

If you’re earlier in the process and just want a working document to bring to a partner meeting, we put together an AI Client Intake Checklist for Law Firms that walks through the intake decisions worth automating versus the ones that need to stay with a human, and you can grab the checklist directly if you want to start there before booking anything.

But the audit is the faster path if you’re serious about moving this quarter. Book a 60-min Omni Audit and we’ll go through your intake logs and matter data together, live, and tell you where the authority lines should sit for your firm before you deploy anything.

The takeaway

The firms getting this right aren’t the ones with the most sophisticated AI. They’re the ones who sat down before deployment and wrote out, in plain language, what the agent can decide, what it can recommend, and what it can never touch. That document is short. It takes an afternoon to write. And it’s the difference between an agent that saves your associates 15 hours a week and one that quietly makes a decision on your letterhead that you find out about from opposing counsel.

Set the boundary first. The agent will do exactly what you tell it to. Make sure that’s actually what you meant.

If you want a second set of eyes on where those boundaries should sit for your specific practice mix, the AI audit for law firms is the place to start, and it’s free to book. You can also browse our broader blog for more on how other firms are sequencing their rollouts, or check Omni advisory if you want ongoing guidance rather than a one-time build.