AI agents for law firms and legal teams.
Gaper builds and deploys supervised agents for legal operations, intake, document review, contract analysis, and matter management, grounded in your documents with a lawyer in the loop on every judgment call.
$ gaper deploy agent --to production ✓ plan ……………… 4 steps ✓ retrieve …… 1,240 docs grounded ✓ tool ………… salesforce.update_record ✓ eval ………… 12/12 checks passed ● live · p95 1.2s · 0 errors
An AI agent for legal is software that reads and reasons over legal documents, drafts and reviews, surfaces risk and citations, and routes to a lawyer for judgment, grounded in your matter data with strict access controls.
Legal work is high-stakes and document-dense. Generic tools cannot be trusted with privilege, citations, or policy, so the work needs grounding, access control, and oversight.
- Does it touch real systems?
- Can the outcome be measured?
- Where does human approval stay?
- Who owns it after launch?
Book a free assessment. We will identify one high-leverage workflow, make the build-vs-buy call, and scope the smallest production release.
From strategy to production, owned by your team.
- 01
Map the workflow
We start from the documents, systems, and edge cases your team handles today, then turn the repeatable path into an agent workflow map.
- 02
Build the supervised agent
We build on the right model for the job, with retrieval, evals, guardrails, and human approval gates where the work carries risk.
- 03
Connect your systems
The agent gets the data, APIs, and write-backs it needs to finish work inside your systems of record, not beside them.
- 04
Sandbox, verify, go live
We launch in a sandbox, verify every run, then move into supervised production with traces, rollback, and an owner.
Agents wired into the systems you already run.
Intake & triage
Classify matters, capture the facts, and route to the right team.
Contract review
Compare against your playbook, flag deviations, and propose redlines for review.
Clause & risk flagging
Surface risky clauses and obligations with citations to the source.
Document summarization
Summarize long documents and discovery with references back to the text.
Matter management
Keep matters, deadlines, and tasks current across your systems.
Research support
Assemble grounded research with citations, for a lawyer to verify.
Policy Q&A
Answer questions from your policies and precedents, grounded and cited.
Compliance
Check work against policy with an access trail on every document.
Grounded in your documents, not the open web
Answers and drafts are sourced from your matter documents and playbooks with citations, so a lawyer can verify every claim. No invented case law, no ungrounded advice.
- Cited from your documents
- No invented citations
- A lawyer verifies the output
Privilege and access, protected
The agent runs inside your environment with strict access controls, so privileged material stays privileged and every document touch is logged.
- Deployed in your cloud
- Matter-level access controls
- Full access audit trail
Where legal point solutions stop
Point tools handle one task on one data set; the firm-specific workflows and integrations are where they leave you. We build and deploy custom into your stack, and call build-vs-buy honestly.
- Custom where products fall short
- Wired into your DMS and matters
- Honest build-vs-buy call
Use a product when the workflow is standard and the data path is simple.
Fast startLess controlBuild when integration, compliance, or differentiation decide the outcome.
Your stackYour codeIf we put client documents into a model, have we waived privilege?
No court has held that AI use waives privilege as a general matter. One federal trial court has held that a client's own unsupervised use of a publicly available AI platform produced documents that were never privileged to begin with.
In United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y. Feb. 17, 2026), Judge Rakoff granted the government's motion for a ruling that a defendant's written exchanges with Claude were protected by neither the attorney-client privilege nor the work product doctrine. He called it "a question of first impression nationwide" and noted that neither the court nor the parties had identified any earlier case presenting it. There were three grounds. "Claude is not an attorney," and that "alone disposes of Heppner's claim of privilege." The exchanges were not confidential, because the privacy policy users of Claude consent to provides that Anthropic collects data on "inputs" and "outputs," uses it to "train" Claude, and reserves the right to disclose it to "third parties," including "governmental regulatory authorities." And the defendant did not communicate with the tool for the purpose of obtaining legal advice.
The waiver point is footnote 3, and it is narrower than the headlines. Even if some of what the defendant typed in had been privileged when counsel told it to him, "he waived the privilege by sharing that information with Claude and Anthropic, just as if he had shared it with any other third party."
Read the facts before you read the rule. The defendant acted on his own volition on a publicly available platform, and his counsel conceded they "did not direct [Heppner] to run Claude searches." This is one district court memorandum, which binds no other court, and whether a firm controlled deployment comes out the same way has not been decided anywhere.
Does it change anything if the model runs in our own cloud tenant?
It changes the facts a court would be looking at. It does not give you a ruling, because no court has decided that configuration yet.
The confidentiality ground in Heppner rested on the privacy policy of a publicly available platform, which permitted training on inputs and disclosure to third parties. A deployment where inputs are never used for training, retention is contractually zero, and no third party may read the content takes away the specific fact the court relied on there. It does not touch the court's other two grounds.
Ethics regulators draw a similar line. Florida Bar Ethics Opinion 24-1 states that "confidentiality concerns may be mitigated by use of an inhouse generative AI rather than an outside generative AI where the data is hosted and stored by a third-party," and that if the use of the program "does not involve the disclosure of confidential information to a third-party, a lawyer is not required to obtain a client's informed consent pursuant to Rule 4-1.6."
Be honest about the limit. That is an advisory ethics opinion construing Florida's own rule, not a privilege ruling, and it binds no court. Rakoff also floated, without deciding, that had counsel directed the use, the tool "might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer's agent." Architecture improves the argument you would make. It does not settle it.
What does Model Rule 1.6 actually require before client data goes into a tool?
Start with what binds you. The ABA Model Rules are a template rather than law, they govern only where a state has adopted them, and states edit the text, so the citation that decides your question is your own state's rule.
As written, Rule 1.6 is broader than privilege, and that is the part firms get wrong. Comment 3 says the rule "applies not only to matters communicated in confidence by the client but also to all information relating to the representation, whatever its source." Rule 1.6(a) bars revealing that information unless the client gives informed consent, disclosure is impliedly authorized in order to carry out the representation, or an exception in paragraph (b) applies. Rule 1.6(c) adds a duty to make "reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of the client."
The safe harbor is in Comment 18. Unauthorized access or inadvertent disclosure "does not constitute a violation of paragraph (c) if the lawyer has made reasonable efforts to prevent the access or disclosure." The factors listed are the sensitivity of the information, the likelihood of disclosure if additional safeguards are not employed, the cost of employing additional safeguards, the difficulty of implementing them, and "the extent to which the safeguards adversely affect the lawyer's ability to represent clients." The same comment lets a client "require the lawyer to implement special security measures not required by this Rule."
So the question is never whether AI is permitted. It is whether your safeguards were reasonable for this data, and whether you can show the work afterwards.
Do we have to tell clients we are using AI?
There is no single national answer, and pages that give one are wrong somewhere. Bar opinions are advisory, so what binds a firm is the rule its own state adopted.
ABA Formal Opinion 512, issued July 2024, says "the facts of each case will determine whether Model Rule 1.4 requires lawyers to disclose their GAI practices to clients or obtain their informed consent to use a particular GAI tool," and that "depending on the circumstances, client disclosure may be unnecessary." It then names when disclosure is required anyway: if the client asks how the work was done, if the engagement agreement or the client's outside counsel guidelines require it, if the use is relevant to the basis or reasonableness of the fee, or when the output "will influence a significant decision in the representation."
Confidentiality is the harder trigger. For self learning tools, the same opinion says "a client's informed consent is required prior to inputting information relating to the representation into such a GAI tool," and that "merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use GAI is not sufficient."
States then diverge. Texas Opinion 705, from February 2025, says a lawyer "should consider informing clients about the associated risks and may need to secure client consent," and notes that opinions from the ABA and the Florida Bar "go a step further and suggest that lawyers should obtain informed consent before using these tools." California's 2026 Practical Guidance, which replaced its 2023 version, says a lawyer "must not input any confidential information of the client into a generative AI solution that may present material risks to confidentiality or security, absent informed client consent." A New York City Bar task force survey of the opinions, dated May 2025, reported that most "conclude that client disclosure is not needed provided the attorney is otherwise complying with the attorney's ethical responsibilities when using generative artificial intelligence," with West Virginia the exception.
What has to be in the vendor contract before privileged material touches a model?
Start with the diligence list ABA Formal Opinion 512 carried over from the earlier cloud computing and outsourcing opinions. Ensure the tool "is configured to preserve the confidentiality and security of information, that the obligation is enforceable, and that the lawyer will be notified in the event of a breach or service of process regarding production of client information." Investigate its "reliability, security measures, and policies, including limitations on the [tool's] liability." Determine whether it "retains information submitted by the lawyer before and after the discontinuation of services or asserts proprietary rights to the information."
New York City Bar Formal Opinion 2024-5 adds the training term. A lawyer who intends to use confidential information in such a product "should ensure that the provider does not share inputted information with third parties or use the information for its own use in any manner, including to train or improve its product," absent informed client consent. D.C. Bar Opinion 388, from April 2024, describes one such term plainly, "a zero data retention policy in which the provider of the GAI retains neither the inputs nor the outputs of the GAI's interaction with a particular user."
These are advisory opinions, not contract law, and none of them drafts the clause for you. Read the terms yourself. California's guidance is blunt about the standard: "Reasonable efforts require more than reliance on generalized marketing assurances."
Will an agent that searches across all our matters break our ethical walls?
It can, and the risk is named in the guidance rather than hypothetical. The control has to be enforced inside retrieval rather than in a policy document.
ABA Formal Opinion 512 names the failure. A tool may disclose information relating to the representation to persons in the firm "who either are prohibited from access to said information because of an ethical wall" or "who could inadvertently use the information from one client to help another client, not understanding that the lawyer is revealing client confidences."
New York City Bar Formal Opinion 2024-5 closes the obvious escape hatch: "Even with closed systems, a lawyer must take care that confidential information is not improperly shared with other persons at or clients of the same law firm, including persons who are prohibited access to the information because of an ethical wall."
California's 2026 Practical Guidance speaks directly to agents given standing access to firm systems. It notes that such systems "may have persistent or automated access to large volumes of confidential client information, raising acute confidentiality considerations," that "lawyers must carefully evaluate and limit the scope of such access," and that unrestricted or poorly configured agents "may unintentionally disclose confidential information (including across different matters) and even expose privileged material."
In practice that means the wall is checked against the requesting user at query time, on every retrieval, or it is not a wall.
Are our prompts discoverable, and does work product cover them?
It depends on who wrote them, at whose direction, and what ended up in a filing. Both reported decisions here are about testing and self help rather than about a firm's client files, so treat them as thin analogy.
In Tremblay v. OpenAI, No. 23-cv-03223-AMO (N.D. Cal. Aug. 8, 2024), the district judge held that a magistrate had misapplied the law by treating pre suit testing material as "more in the nature of bare facts," because "the ChatGPT prompts were queries crafted by counsel and contain counsel's mental impressions and opinions about how to interrogate ChatGPT." Opinion work product "is virtually undiscoverable," and is discoverable by waiver only where "mental impressions are at issue in a case and the need for the material is compelling." The court denied the request to compel the negative testing results and the documentation of the testing process, and still ordered production of the prompts, outputs and account settings behind the positive results disclosed in the complaint.
Heppner shows the other end. The work product claim failed there because the documents "were not prepared at the behest of counsel and did not disclose counsel's strategy."
This is thin ground. Tremblay is an unreported order reviewing a magistrate's ruling under a deferential standard, and two judicial officers classified the same material in opposite ways. Plan on the assumption that prompts and outputs are records you may have to preserve, log and explain.
A judge wants us to certify that our AI use did not disclose privileged information. Can we sign that?
Read the qualifier, because it is narrower than it first appears, and whether you can sign it is a judgment for your own counsel on your own facts. Standing Order MC-11, signed by Judge Marcia A. Crone of the Eastern District of Texas, Beaumont Division, on 20 July 2026, applies when a party uses AI to draft or assist in drafting a pleading. The certificate must then disclose the use, certify that the party independently verified the accuracy of any AI drafted or AI assisted portion, and "certify that the use of AI has not resulted in the disclosure of confidential or privileged information to an unauthorized party." On its face that asks who received the data and what your contract permitted, and it does not by its terms bar hosted models.
Other orders reach further into the client relationship. Judge Nina Y. Wang of the District of Colorado requires an AI certification on every filing, effective 1 December 2025, and the sample language her order offers for illustration reads "I/we further certify that [Party] was/were advised of and consented to such use." Filings that do not comply "may be stricken without substantive consideration and with leave to re-file a compliant document."
The trend is not universal. The Fifth Circuit considered a proposed rule and decided not to adopt one, declining "to adopt a special rule regarding the use of artificial intelligence in drafting briefs at this time" and reminding counsel that "'I used AI' will not be an excuse for an otherwise sanctionable offense." Requirements are set judge by judge, so clearing a district's rule is necessary and not sufficient.
What actually leaves your tenant
The privilege question above is, in practice, an architecture question. Documents, retrieval and the audit trail sit inside your own cloud. A lawyer reviews before anything is filed, sent or relied on, and that review is a gate rather than a suggestion.
- Docs, agent and logs stay inside your boundary
- A lawyer approves anything that leaves it
- Every document touch is logged and attributable
Does every lawyer have a duty of technology competence, and does it force us to use AI?
Most US lawyers have a duty to keep abreast of relevant technology, but it sits in a comment rather than in the rule itself, and it does not require you to adopt AI. Comment 8 to ABA Model Rule 1.1 says a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology.
The Model Rules are a model. They bind nobody until a state adopts them, so the operative text is always your own state's version. The long running LawSites tracker counts 40 states plus the District of Columbia and Puerto Rico as having adopted that comment, which leaves ten states that have not, and North Carolina adopted modified wording. Check your own jurisdiction before telling partners this is a national duty.
Competence also is not expertise. ABA Formal Opinion 512 says lawyers need not become generative AI experts, only that they must have a reasonable understanding of the capabilities and limitations of the tools they use, and that the required level of competence can ordinarily be reached by self study, by associating with a competent lawyer, or by consulting someone with sufficient expertise. Texas Opinion 705 adds that Rule 1.01 almost certainly does not require the use of generative AI for any particular purpose. Both are ethics opinions, which are advisory rather than binding.
Does Rule 5.3 actually cover software, or is that an interpretation nobody has tested?
It is an interpretation, a well supported one, but the operative text speaks about people rather than systems. Model Rule 5.3, retitled Responsibilities Regarding Nonlawyer Assistance in 2012, applies with respect to a nonlawyer employed or retained by or associated with a lawyer, and refers throughout to the person's conduct. Like the rest of the Model Rules it binds only through the version your state has adopted. Florida Ethics Opinion 24-1, an advisory opinion issued in January 2024, is candid about the gap, noting that its Rule 4-5.3(a) defines a nonlawyer assistant as a person, while concluding that many of the standards applicable to nonlawyer assistants still provide useful guidance for generative AI.
The strongest textual hook is Comment 3 to Rule 5.3, which already contemplates using an internet based service to store client information, and sizes the duty to the circumstances, including the nature of the services involved and the terms of any arrangements concerning the protection of client information. ABA Formal Opinion 512 adopts that reading, applies Rule 5.3(b) to work done outside the firm, and says the outsourcing concepts also apply to generative AI providers and tools.
So treat it as the operative framework, because your regulator does. Treat it as settled law and you will be overstating it. We found no court decision testing whether Rule 5.3 reaches a model rather than a person, and we are not aware of one.
What does reasonable supervision of an AI agent actually look like in practice?
A written policy, trained people, tested outputs, and a human release point before anything leaves the firm. ABA Formal Opinion 512 says managerial lawyers must establish clear policies regarding the firm's permissible use of generative AI, and that supervisory obligations include ensuring subordinate lawyers and nonlawyers are trained in the ethical and practical use of the tools relevant to their work.
It does not mean reviewing everything twice. Opinion 512 gives a worked example: a lawyer who had previously tested a summarizing tool against a manually reviewed subset of documents, and found the summaries accurate, would not necessarily have to manually review the whole set. The hard floor is that lawyers may not leave it to generative AI tools alone to offer legal advice to clients, negotiate clients' claims, or perform other functions that require a lawyer's personal judgment or participation.
California goes furthest on autonomy. The State Bar of California's 2026 Practical Guidance, which replaced the 2023 version and was revised at the California Supreme Court's request to address agentic AI, says lawyers must not deploy agentic systems in a manner that allows the system to make substantive legal determinations, communicate legal advice, prepare and file pleadings, or otherwise act in a representative capacity without meaningful lawyer supervision and review, and that the greater the level of system autonomy, the greater the lawyer's obligation to implement oversight. It also says reasonable efforts to protect client confidences require more than reliance on generalized marketing assurances. That is guidance for California licensees, so read it as a direction of travel rather than a rule that binds your firm.
If the agent does in two hours what took an associate twenty, what can we bill?
Your actual time, and no more, if you bill hourly. ABA Formal Opinion 512, following Formal Opinion 93-379, says a lawyer who has agreed to bill on hours expended does not fulfill her ethical duty by billing for more time than she has actually expended. Its example is concrete: fifteen minutes spent inputting the relevant information, plus the time actually spent reviewing the resulting draft for accuracy and completeness. Texas Opinion 705 puts it flatly, a lawyer may not charge hourly fees for the time that was saved by using the generative AI program.
You cannot bill the learning curve either. Opinion 512 says a lawyer may not charge a client to learn how to use a tool the lawyer will regularly use for clients. Flat fees are not a way round it: 512 also says it may be unreasonable under Rule 1.5 to charge the same flat fee for work the tool makes much quicker.
Costs split by what the tool is. General purpose subscriptions are overhead, while per-use charges tied to a specific matter can ordinarily be billed as an expense at actual cost with advance disclosure, which is the common line across the state opinions, though that Illinois State Bar review flags North Carolina and the New York State Bar as allowing more. California adds that no markup or profit element may be added without the client's informed written consent.
Do we have to disclose AI use in our court filings?
That depends on the individual judge, not just the district, and mandatory disclosure is still the minority position. The Ropes and Gray AI court order tracker tagged 174 items as requiring disclosure or verification, 451 as suggesting cautious use, and 5 as prohibiting AI, when we read it in September 2026. Those are counts of orders, local rules and decisions across state and federal courts, not counts of judges, so do not convert them into a percentage of the bench, and the tracker keeps growing.
Some courts have declined to impose anything. The Fifth Circuit proposed a certification rule and then decided not to adopt one, reminding parties and counsel that filings must be carefully checked for truthfulness and accuracy as the rules already require, and that saying you used AI will not be an excuse for an otherwise sanctionable offense.
Where orders do exist they differ in detail. Judge Leslie Kobayashi in the District of Hawaii requires disclosure that AI was used and the specific AI tool, plus certification that the filer has checked the accuracy of any AI drafted portion, including all citations and legal authority. Clearing a district rule is necessary, not sufficient. Check the judge before each filing.
What actually happened in the fake citation sanctions cases, and what does it mean for us?
The lawyers were sanctioned for not checking, not for using AI. In Mata v. Avianca, 678 F. Supp. 3d 443 (S.D.N.Y. 2023), the lawyers were fined $5,000, ordered to notify their client in writing, and ordered to send a letter to each judge falsely named as the author of a fabricated opinion, as set out by the D.C. Bar in Opinion 388. That opinion quotes the lawyer's testimony that he had falsely assumed ChatGPT was like a super search engine. Florida's ethics guidance quotes the other half of the same ruling, that technological advances are commonplace and there is nothing inherently improper about using a reliable artificial intelligence tool for assistance.
The volume is real and it is not mostly law firms. Damien Charlotin's hallucination case database listed 2,095 matters worldwide when we read it in late September 2026, with 1,208 attributed to pro se litigants against 829 attributed to lawyers. The count moves constantly, so check it rather than quoting a number.
Courts have closed the excuse route. Judge Crone's standing order states that the fact AI was used to create the offending document will not excuse or absolve ethical infractions.
Can an AI agent do client intake and run our conflicts check?
Yes for the clerical half, no for the judgment half. An agent can take a web or phone intake, normalise party and entity names, search your document management and accounting systems for prior and adverse parties, and hand a lawyer a ranked conflicts candidate list with the source documents behind every hit. It cannot clear a conflict, and it must not answer the legal question the caller is asking.
Two published constraints shape the build, and both are jurisdiction specific rather than national law. Florida's Opinion 24-1, which carries the Bar's own note that advisory ethics opinions are not binding, says a lawyer must inform prospective clients that they are communicating with an AI program and not with a lawyer or law firm employee, warns that an overly welcoming chatbot can create a prospective client or even a lawyer client relationship without the lawyer's knowledge, and suggests screening questions that limit the chatbot's communications when a person is already represented by another lawyer (Opinion 24-1). The State Bar of California's 2026 practical guidance, revised at the request of the California Supreme Court, names autonomously facilitating client intake as an example of agentic AI and says lawyers must not deploy agentic systems in a manner that allows them to make substantive legal determinations or communicate legal advice without meaningful lawyer supervision and review (COPRAC guidance).
Control gate: a lawyer clears every conflict and signs the engagement. The agent writes to a conflicts queue, never to the prospective client.
What does an AI agent actually do in document review, and where does it stop?
It ranks and proposes, a human confirms what matters. The agent reads the collection, applies your issue codes with a confidence score, clusters near duplicates, surfaces documents that look responsive or hot, and writes a reviewable record of what it did to each file. Privilege calls and hot document judgment stay with people.
The ceiling is set by verification, not by model quality. ABA Formal Opinion 512 interprets the ABA Model Rules, which bind only in the states that have adopted them, and it says the amount of independent review required depends on the tool and the specific task. Its own example is a lawyer who uses a tool to review and summarise numerous lengthy contracts, and who would not necessarily have to read the entire set manually if the accuracy of the tool had first been tested on a smaller subset by reviewing those documents by hand and finding the summaries accurate (Opinion 512). So the defensible position is sampling you can show, not trust.
Log what the agent did, because the method may be discoverable. In Conservation Law Foundation v. Shell Oil, in the District of Connecticut, a magistrate judge treated the process used to cull a document set as part of the expert's methodology and therefore fair ground for discovery under Rule 26(b), and ordered any further prompts disclosed or their absence formally confirmed after a diligent search. That order was stayed while the district judge considered an objection, so this is a live question rather than a settled rule (report).
Control gate: the reviewing lawyer approves the coding protocol and signs a validation sample before anything is produced.
Can an agent review contracts against our playbook without a lawyer reading them?
No. It produces a first pass redline and an exceptions list, and a lawyer approves every deviation. In practice the build reads the agreement against your own playbook, marks each clause on standard, off standard or missing, cites the playbook rule it applied, and drafts fallback language for a lawyer to accept or reject.
Three constraints are explicit in the published guidance. ABA Formal Opinion 512, which interprets the Model Rules and binds only through the states that have adopted them, says lawyers may not leave it to generative AI tools alone to offer legal advice to clients, negotiate clients' claims, or perform other functions that require a lawyer's personal judgment or participation (Opinion 512). Florida's advisory Opinion 24-1 says a lawyer should not instruct or encourage a client to rely solely on the work product of generative AI, such as a due diligence report, without the lawyer's own personal review (Opinion 24-1). California's 2026 guidance says a lawyer must not deploy an agentic system in a manner that permits autonomous external transmission of client information without appropriate safeguards and human review, which means the agent does not send the markup (COPRAC guidance).
The failure mode we design around is cross document context. A clause read in isolation, without the amendment that changed it, produces a confident wrong answer.
Control gate: the responsible lawyer signs the redline and every playbook exception.
How reliable is AI legal research, and who checks the citations?
Not reliable enough to file unchecked, and the check cannot be delegated to the tool. In a preregistered Stanford evaluation published in the Journal of Empirical Legal Studies, accepted in March 2025, the AI research tools made by LexisNexis (Lexis+ AI) and Thomson Reuters (Westlaw AI-Assisted Research and Ask Practical Law AI) each hallucinated between 17 and 33 percent of the time on the versions tested (study).
Read the definition before the number. The study treats a response as hallucinated if it is either incorrect or misgrounded, so the number covers more than invented cases. A real case cited for a proposition it does not support counts too, and that is the failure a citator does not catch: the citator finds the case that does not exist, it does not tell you the case that exists says something else.
The consequences are documented. A public database of decisions in which courts dealt with hallucinated AI content lists more than 2,000 worldwide and was updated in late September 2026 (tracker). In the District of Hawaii, Judge Kobayashi directs anyone who uses a generative AI tool in preparing a filing to disclose that AI was used and the specific tool, and to certify that they have checked the accuracy of any portion drafted by generative AI, including all citations and legal authority (standing order).
Control gate: the signing lawyer pulls and reads every authority. The agent produces a verification worksheet, not a certification.
Can we trust an agent to summarise a deposition or a client call?
For orientation yes, for anything a decision rests on the lawyer reads the source. The risk is omission rather than invention, which is why a summary feels safe when it is not. A summary that is right about everything except the indemnity carve out is worse than no summary.
The New York City Bar addressed this for AI tools that record, transcribe and summarise conversations with clients. Attorneys should independently review any recording, transcript or summary to ensure it accurately reflects the conversation, should not simply rely on work products prepared by AI tools without independently verifying their accuracy, and where the tool has generated a legal analysis or a recommended course of action should independently confirm that the analysis and recommendations are sound (Formal Opinion 2025-6). The same opinion flags what firms miss: these records may be relied on sometimes even years later, and a client later involved in litigation may be able to use the evidence as part of an advice of counsel defense, so retention is a decision to make before deployment rather than after.
ABA Opinion 512 supplies a calibration method rather than a rule, test the tool against a hand reviewed subset first (Opinion 512).
Control gate: the lawyer who will rely on the summary reads the underlying record and signs it.
Can an agent draft a filing, and do we have to tell the court we used it?
It can draft, it cannot file, and disclosure turns on the individual judge rather than on the district. The requirements genuinely conflict. In the District of Hawaii, Judge Kobayashi directs a filer to disclose that AI was used and the specific tool, and to certify the accuracy of any portion drafted by generative AI, including all citations and legal authority (standing order). In the Eastern District of Texas, Judge Crone requires a Certificate of Generative Artificial Intelligence Usage that discloses the use, certifies independent verification of accuracy, and further certifies that the use of AI "has not resulted in the disclosure of confidential or privileged information to an unauthorized party" (Standing Order MC-11). The Fifth Circuit considered a proposed rule and decided not to adopt one, reminding parties that filings must be carefully checked for truthfulness and accuracy as the rules already require, and that "I used AI" will not be an excuse for an otherwise sanctionable offense (decision). California's 2026 guidance takes the filing itself out of the agent's hands, saying lawyers must not permit AI systems to autonomously file documents, communicate with the court, or make representations on the lawyer's behalf (COPRAC guidance).
Read the Texas certification closely. It asks about unauthorized parties, so it turns on who your vendor is and what your contract permits. Whether routing a privileged document through a hosted model is itself a disclosure that affects privilege is unsettled, and we are not aware of a court that has resolved it.
Control gate: the Rule 11 signature.
Can an agent review our prebills and time entries?
It can flag, it cannot rewrite time upward, and the larger point is that using AI changes what you may bill. What follows is ethics guidance interpreting each jurisdiction's own rules, and the ABA Model Rules bind only where a state has adopted them. On hourly work ABA Opinion 512 permits charging for the time actually spent, for example the minutes spent putting the relevant information into the tool and the time spent reviewing the resulting draft for accuracy and completeness, while repeating the older rule that a lawyer may not bill for more hours than were actually expended (Opinion 512). Texas Opinion 705 says it directly, a lawyer may not charge hourly fees for the time that was saved by using the generative AI program (Opinion 705). Florida's Opinion 24-1 adds that use of generative AI does not permit improper billing practices such as double billing (Opinion 24-1). California's 2026 guidance treats subscriptions for general office functionality as overhead to be absorbed in the fee, allows costs incurred specifically for a matter to be billed where the fee agreement discloses it, requires those charges to reasonably reflect the lawyer's actual cost, and prohibits a markup or profit element without the client's informed written consent (COPRAC guidance).
So the agent does mechanical work: flag block billing, missing time, narratives that reveal privileged detail, and entries that breach outside counsel guidelines. Write off decisions and narrative rewrites stay with a person.
Control gate: the billing partner approves every proposed change. The agent writes to a review queue, never to the invoice.
Can an agent run our docketing and deadline calendar?
It can read docket entries and propose computed dates. It should not commit them, and it should not file. Date computation turns on the governing rule plus whatever the assigned judge has ordered in that case, and how far those judge level requirements can diverge is visible in the AI orders themselves: one judge requires the specific tool to be named, another requires a confidentiality certification, and the Fifth Circuit declined to adopt any special rule at all (Hawaii, Texas, Fifth Circuit). An agent that learns one set of requirements and generalises will be confidently wrong.
California's 2026 guidance is the closest published constraint. It contemplates agentic systems configured to reach internal firm systems including calendaring, says lawyers must carefully evaluate and limit the scope of that access because unrestricted or poorly configured systems may unintentionally disclose confidential information across different matters, and says a lawyer must not deploy a system that permits autonomous external transmission of client information, including automated filings, without appropriate safeguards and human review (COPRAC guidance).
We are not aware of bar guidance that approves unattended calendaring, and a blown deadline is not a recoverable error, so this stays human committed.
Control gate: a docket clerk or paralegal confirms each computed date against the governing rule and the docket entry before it enters the calendar of record.
Should we build a custom AI agent or just buy Harvey or CoCounsel?
Buy first when the work lives inside a product's own content and workflow. That is where the commercial tools are hardest to beat, and we will say so rather than quote you a project.
Thomson Reuters describes CoCounsel as an assistant for research, analysis and drafting that reasons from Westlaw content, Practical Law guidance and your organization's own knowledge. Harvey sells purpose built agents for law firms and in house legal teams, with its own document store and shared workspaces. Relativity documents aiR for Review as generative AI and large language models examining extracted document text against your prompt instructions, returning document citations with associated rationale, inside the review platform your litigation team may already license.
If your question is first pass document review, citation checked research, or anything else already sitting in a platform you pay for, start with the product. Nobody can tell you what a build would cost against that before they have seen your systems, and that includes us.
When does a custom build actually pay off for a firm our size?
When the work crosses systems no single vendor owns, and when your own access rules have to travel with it.
Three patterns tend to justify a build. First, a workflow that touches the document management system, practice management, email and billing in one pass, because no product spans all four. Second, anything where retrieval has to honor need to know security and information barriers per user at query time. ABA Formal Opinion 512 treats that as a live confidentiality risk, warning that a tool may disclose information relating to the representation to persons in the firm who are prohibited from access because of an ethical wall. Third, work built on your own precedent, where the asset is your drafting history rather than a public corpus.
Opinion 512 interprets the ABA Model Rules, and those are a model only. They bind lawyers in a state only where that state has adopted them, and ABA ethics opinions are advisory rather than binding anywhere, so read your own jurisdiction's rules and opinions before relying on any of this. If none of the three patterns applies, a build is the expensive answer to a solved problem. The honest test is whether the thing you need is missing from every product, or only from the one you happen to have bought.
What does running the model in our own cloud actually change for confidentiality?
It changes who holds the data and what the terms permit. It does not make the cloud provider disappear, and it does not settle privilege.
Microsoft states that for models sold by Azure your prompts, completions, embeddings and training data are not available to OpenAI or other model providers and are not used by those providers to improve their models or services, and that data stored for service features sits at rest in the Foundry resource in your own Azure tenant, within your chosen geography, deletable by you at any time. The same page adds a limit worth reading: unless you are approved for modified abuse monitoring, a sample of prompts and completions may be stored and reviewed, including by authorized Microsoft employees. AWS states that because model providers have no access to the model deployment accounts, they do not have access to Amazon Bedrock logs or to customer prompts and completions.
That is a narrower claim than it first sounds. Your own tenant still means a cloud provider holds the data, so the question is which third party and on what terms, not whether there is one. Florida Ethics Opinion 24-1 notes that confidentiality concerns may be mitigated by use of an in house generative AI rather than an outside one where the data is hosted and stored by a third party, and that where use of the program does not involve disclosure of confidential information to a third party, informed consent is not required under Rule 4-1.6. Whether a tenant hosted by a cloud provider counts as in house for that purpose is not spelled out, and Florida states on the face of the opinion that advisory ethics opinions are not binding.
Privilege is less settled still. In United States v. Heppner, No. 1:25-cr-00503-JSR (S.D.N.Y. 2026), the court held that documents a defendant produced by prompting a consumer chatbot on his own initiative were neither privileged nor work product, reasoning in part from the consumer product's published privacy terms. A law firm summary of the split reports that another court, in Warner v. Gilbarco in the Eastern District of Michigan, reached the opposite result on work product for a self represented litigant's chatbot drafts. Neither decision binds any other court, and we found no decision addressing an enterprise deployment inside an organization's own tenant.
Will an agent respect our ethical walls in iManage or NetDocuments, or does it just read everything?
Only if the permission check sits inside retrieval, per user, on every query. Nothing about a model does this for you.
Firms already run this logic outside the AI stack. iManage Security Policy Manager exists to deliver need to know security, ethical walls and information barriers across a range of systems, iManage systems such as Work and Records Manager and non iManage systems including time and billing and conflict management, enforced through agents configured to talk to each target system. NetDocuments exposes access rights and ACLs through its API, with view, edit, share, administer and no access flags at cabinet and group level, and an operation that searches a cabinet and modifies ACLs, as catalogued in Microsoft's connector reference.
A build can inherit those decisions by resolving the requesting lawyer's entitlements at query time, instead of indexing the whole corpus once under a service account. The State Bar of California's 2026 COPRAC practical guidance names the failure mode: lawyers must carefully evaluate and limit the scope of such access, because unrestricted or poorly configured agentic systems may unintentionally disclose confidential information, including across different matters, and even expose privileged material. That guidance addresses California lawyers under the California Rules of Professional Conduct, so treat it as a checklist rather than a rule that reaches your state automatically. Then ask any vendor, including us, to show you where that check happens in the request path.
Can it connect to Clio, iManage, NetDocuments, SharePoint and Relativity?
Yes, all five publish developer interfaces, and the connector is the easy part.
Clio documents two routes, the Clio Platform for Clio Grow APIs and a separate Clio Manage developer portal. Relativity publishes a REST API for building web, mobile and cross platform applications against its resources. SharePoint, OneDrive, Outlook and Teams are all reachable through a single endpoint, graph.microsoft.com, per Microsoft Graph. iManage and NetDocuments both document administrative and API surfaces of their own.
The time goes elsewhere. It goes on deciding which system is authoritative when three of them hold a version of the same matter, on reconciling client and matter identifiers that were never designed to line up, and on carrying each user's entitlements through every hop. Being able to read a system is not the same as being allowed to read it. Opinion 512 says lawyers should read and understand the terms of use, privacy policy and related contractual terms and policies of any tool they use, to learn who has access to what the lawyer inputs, or consult a colleague or external expert who has read and analyzed those terms. That review belongs at the start of an integration, not after go live.
What does a sensible first AI project look like at a law firm?
One workflow, one practice group, and an output that a human releases.
A first scope that survives contact with a firm names five things: the single task, the systems it reads, the people it serves, what it is forbidden to do, and how you will know it worked before anyone relies on it. Keep the first output reversible, a draft, a summary, a flagged issues list that a lawyer sends or does not send.
The 2026 COPRAC guidance draws the boundary. Lawyers must not deploy agentic systems in a manner that allows the system to make substantive legal determinations, communicate legal advice, prepare and file pleadings, or otherwise act in a representative capacity without meaningful lawyer supervision and review, and a lawyer must not deploy an agentic system in a manner that permits autonomous external transmission of client information, including automated communications, filings or data transfers, without appropriate safeguards and human review. Opinion 512 supplies the governance half: managerial lawyers must establish clear policies regarding the firm's permissible use of generative AI, and supervisory lawyers must make reasonable efforts to ensure that the firm's lawyers are trained. Read both through your own state's rules, since the ABA Model Rules bind only where a state has adopted them and the COPRAC guidance speaks to California lawyers. Intake, conflicts triage and internal document summarization are reasonable first picks because all three produce output a lawyer can reject before it goes anywhere.
How do we measure whether the agent actually worked?
Against a sample your own lawyers coded before the agent saw it, and before anyone relies on the output.
Relativity's best practices for aiR for Review describe a method you can copy: have human reviewers code the documents in advance, run the prompt criteria on a saved search of 50 to 100 test documents that contains a diverse range of documents, compare the results to the human coding, look for documents the application coded differently than the humans did and investigate possible reasons, then repeat until the application produces results that reasonably align with the coding decisions for the test documents. ABA Formal Opinion 512 accepts the same logic for verification, saying a lawyer who relies on a tool to review and summarize numerous lengthy contracts would not necessarily have to manually review the entire set if the lawyer had previously tested the tool's accuracy on a smaller subset by manually reviewing those documents, comparing them to the summaries and finding the summaries accurate.
Measure the money separately. Texas Opinion 705 states that a lawyer may not charge hourly fees for the time that was saved by using the generative AI program, so on hourly matters a working agent shrinks the invoice rather than the hour. That is the number partners will ask for, and it is the one nobody can supply for you before your own pilot runs.
If we build it, what do we actually own, and what can we take with us?
You own the deployment, the integrations, the prompt and evaluation library, the logs and the code. You do not own the frontier model, and a firm should be suspicious of anyone who says otherwise.
What is portable is the part that took the work: the retrieval layer, the permission mapping, the evaluation sets that show how the thing performs, the audit trail, all running inside your own subscription. Microsoft states that fine tuned models sold by Azure are available exclusively for your use, that data stored for service features sits at rest in the Foundry resource in your own Azure tenant, and that you can delete it at any time, per its data privacy documentation.
Treat exit as a contract question rather than a trust question. List the artifacts you get back and in what format, because a general promise to return data is not a migration plan. Settle the billing side at the same time. The 2026 COPRAC guidance treats subscription fees for tools that provide general office functionality as overhead that should be absorbed within the lawyer's fee, while costs incurred specifically for a client's matter and beyond general office operations, such as custom AI implementations developed for a particular matter, may be charged to the client where the fee agreement clearly discloses it, the charge reasonably reflects actual cost, and no markup is added without the client's informed written consent.
Questions buyers ask us.
What is an AI agent for legal?+
Can it be trusted with privileged material?+
Does it invent case law or citations?+
What legal workflows can you automate?+
Does it work with our document system?+
Who owns it after launch?+
Ready to deploy your first agent?
Book a free 30-minute assessment. We'll map the highest-leverage workflow and scope the smallest thing worth shipping, live in as little as 24 hours.