Law firms and corporate legal departments should deploy legal AI agents only when the agent inherits the same client, matter, document, conflict, and professional-review boundaries that govern the lawyers using it. A permission-aware connector or legal-specific model can help enforce that design, but it does not decide whether a disclosure is authorized, preserve privilege automatically, verify a citation, or replace the lawyer's independent judgment.
The production gate is this: begin with one bounded read-and-propose workflow; keep client data inside a matter-isolated environment; prove that permissions and ethical walls survive every connector, index, cache, memory, skill, and log; prohibit bulk exports; verify provider terms; require traceable sources and adversarial testing; and place a qualified attorney between the agent and every filing, advice, negotiation, execution, or disclosure. If any part cannot be demonstrated with evidence, the workflow remains a sandbox or a manual process.
This article provides an operational readiness framework, not legal advice. Privilege, professional-conduct, court, privacy, employment, discovery, and client-notification duties vary by jurisdiction, matter, engagement terms, protective order, and facts. The responsible lawyers should apply the rules adopted in their jurisdictions and involve ethics, privacy, security, and insurance counsel where appropriate.
Three sources—and three different kinds of authority
Google Cloud's August 25, 2026 Gemini Enterprise for Legal announcement is a product launch and vendor statement. Google describes reusable legal skills, MCP connectors that inherit source-system access controls, centralized governance, private data isolation, traceable citations, and example workflows including contract review, regulatory scanning, research, DSAR fulfillment, redaction, and drafting. It also says the product is in preview. Preview availability is not evidence that every feature, connector, region, term, or control is production-ready for a particular firm.
The American Bar Association's Formal Opinion 512, issued July 29, 2024, interprets the ABA Model Rules for lawyers using generative AI. It addresses competence, confidentiality, client communication and informed consent, candor to tribunals, supervisory responsibilities, vendor diligence, and reasonable fees. ABA model rules and formal opinions are influential guidance; they are not a substitute for the professional rules, ethics opinions, court orders, and law that actually bind a lawyer in a given jurisdiction.
The Solicitors Regulation Authority's August 17, 2026 Misuse of AI warning is regulatory guidance for firms and individuals the SRA regulates in England and Wales. The SRA says it will have regard to the notice when exercising its regulatory functions. It focuses on inaccurate legal work, hallucinated authorities, supervision, client confidentiality, legal professional privilege, and the continuing accountability of regulated people. Its specific duties apply in its regulatory context; organizations elsewhere should not present it as a universal rule.
These authorities converge on a practical point: legal AI is not governed by a platform label. It is governed by the lawyer's duties, the client's instructions, the matter's restrictions, the system's actual data path, the action being proposed, and the quality of the professional review.
Privilege, confidentiality, and ethical walls are not interchangeable
Attorney-client privilege is generally an evidentiary protection for qualifying confidential communications made for legal advice, and it is typically held by the client. Work-product protection is a separate doctrine with its own requirements and waiver rules. The ethical duty of confidentiality is broader. ABA Model Rule 1.6 covers information relating to a representation regardless of its source and requires reasonable efforts against unauthorized access or disclosure. A record can therefore be nonprivileged yet still confidential under the applicable professional rules.
Ethical walls, conflict screens, need-to-know restrictions, protective orders, insider lists, clean teams, and client-imposed access terms add further boundaries. An employee's general right to use an enterprise AI service does not authorize access to every legal matter. The agent must not use a shared index, cache, memory, prompt history, evaluation set, or log to reveal information from a screened matter to a person who could not open the source document.
Avoid categorical statements that uploading material to any AI service always waives privilege or that an enterprise contract always preserves it. The SRA warns that entering client letters into an open-source tool will likely breach confidentiality and may permanently waive legal professional privilege. Current ABA Law Practice analysis of three 2026 federal decisions reports divergent treatment of consumer AI, attorney-client privilege, and work product. The safer operating rule is to prevent unauthorized disclosure, document counsel's direction and purpose, and obtain case-specific advice rather than test an unsettled boundary with client data.
The legal-agent readiness contract
Use this matrix as an acceptance contract for each workflow, not as a claim of compliance. Replace role labels with named owners, attach the underlying evidence, and map each control to the rules, engagement terms, client outside-counsel guidelines, protective orders, and information-governance requirements that apply to the matter. A vendor control can support the decision; it cannot make the professional judgment for the responsible lawyer.
| Control | Minimum design | Acceptance evidence | Stop condition |
|---|---|---|---|
| 1. Bounded workflow | One named matter workflow, such as clause review or regulatory scanning, limited to read and propose | Owner, matter type, allowed inputs, prohibited actions, output schema, reviewer, and success criteria | The task expands into advice, negotiation, filing, disclosure, or another matter without a new approval |
| 2. Matter permissions | Connector queries run as the authorized user and preserve repository, workspace, document, and field permissions | Positive and negative identity tests across active, closed, transferred, and newly restricted matters | The agent returns a document, citation, snippet, or metadata that the requesting user cannot open at the source |
| 3. Ethical walls | Conflict screens apply to retrieval, memory, caches, embeddings, logs, evaluations, and generated work product | Wall membership, restricted groups, deny tests, alert routing, and periodic access recertification | Any cross-wall retrieval, inference, recommendation, or undisclosed restricted-matter reference occurs |
| 4. No bulk exports | Process records in their governed source or retrieve only the minimum authorized documents for the task | Export prohibition, query and result caps, controlled temporary storage, deletion proof, and egress policy | A connector, user, or agent attempts a corpus export, unrestricted synchronization, or undeclared destination |
| 5. Client-data isolation | Separate tenants, projects, indexes, keys, memory, evaluation sets, logs, and support access according to risk | Data-flow map, processor list, residency, encryption, backup, support, retention, deletion, and recovery settings | Client data can enter shared memory, cross-client training, an unapproved region, or an unowned store |
| 6. Provider terms | Verify training, fine-tuning, human review, abuse monitoring, retention, deletion, ownership, and breach-notice terms | Executed agreement, edition and feature inventory, configuration export, exceptions, and contract review date | The actual edition, feature, connector, subprocessor, or setting falls outside the reviewed terms |
| 7. Traceable citations | Every material legal assertion links to an authorized source with jurisdiction, date, document, and location | Citation schema, source snapshot or version, quote boundary, retrieval time, and attorney verification result | The source is missing, inaccessible, stale, outside the jurisdiction, or does not support the proposition |
| 8. Accuracy and redaction | Test hallucinations, omitted authority, quotation fidelity, document boundaries, PII, privilege, and layered redactions | Versioned gold set, adversarial cases, false-positive and false-negative thresholds, and regression history | A fabricated authority, material omission, failed redaction, or unsupported factual claim reaches review |
| 9. Attorney approval | A qualified lawyer reviews the exact artifact before advice, filing, negotiation, execution, or disclosure | Named reviewer, approval scope, artifact hash, source check, exceptions, timestamp, and final disposition | The output changes after approval or the reviewer cannot reproduce its controlling sources and assumptions |
| 10. Access and action logs | Record identity, client and matter reference, model, skill, connector, sources, actions, denials, approvals, and result | Complete, time-synchronized, access-controlled logs that avoid duplicating confidential payloads | An access, action, denial, or downstream handoff cannot be traced to its task and accountable owner |
| 11. Incident and notice | Contain access, preserve evidence, assess privilege and confidentiality impact, reconcile outputs, and decide notifications | Incident owner, legal and ethics counsel, insurer and vendor contacts, notice criteria, deadlines, and tested tabletop | The team cannot identify affected clients, matters, data, jurisdictions, recipients, or downstream artifacts |
| 12. Change revalidation | Treat model, skill, prompt, connector, permission, source, policy, region, and provider-term changes as controlled releases | Version diff, renewed risk decision, targeted regression tests, canary, monitoring window, and rollback target | An unreviewed change alters access, retention, citations, redaction, side effects, or professional-review behavior |
1. Start with one bounded legal workflow
Choose a recurring task with defined inputs, observable outputs, and reversible consequences. Contract-clause extraction against an approved playbook and regulatory horizon scanning against named official sources are sensible pilot candidates. They let the agent find, compare, and propose while a lawyer decides what the result means. A first pilot should not autonomously file with a court, send advice, accept negotiated language, disclose client information, issue a litigation hold, answer a regulator, or communicate a legal position to another party.
Write a run contract before configuration: client and matter, jurisdiction, task purpose, eligible users, allowed repositories, document types, time range, model and skill, connector, permitted tool actions, prohibited actions, retention, output schema, citation requirements, attorney reviewer, deadline, stopping conditions, and final system of record. Define whether the agent may read, summarize, compare, draft, propose a redline, or create a task. Do not let the prompt infer authority from the verb “review.”
Separate research from advice, advice from approval, and approval from communication. A regulatory-scanning agent may identify a new rule and draft an impact note, but the responsible lawyer should determine applicability, resolve ambiguity, approve the legal position, and decide who may receive it. A contract agent may flag a nonstandard indemnity clause, but it should not accept fallback language or transmit a counterproposal without the designated lawyer's approval.
Set a representative pilot corpus and an explicit exclusion list. Exclude matters under a special protective order, criminal or internal investigations, whistleblower reports, board advice, sanctions-sensitive records, personal legal matters, sealed material, highly restricted transactions, and any client that has prohibited or conditioned AI use until counsel approves a separate control design.
2. Preserve matter and document permissions across every connector
Google says Gemini Enterprise for Legal connects to legal systems through permission-aware MCP connectors and that access can remain bound to role-based and document-level controls. That is a useful design goal, not an acceptance test. For each connector, determine whether it federates a query to the source or ingests a copy; which service identity performs synchronization; how end-user identity is mapped; whether groups, nested groups, document ACLs, field restrictions, and matter changes are preserved; and how quickly revocations take effect.
The effective permission should be the intersection of the user, client, matter, document, field, task, and agent policy—not the broad entitlement of a connector service account. Search results, snippets, citation titles, counts, inferred topics, and “no result” differences can all disclose information. The agent should not reveal even the existence of a restricted matter when the source system would not.
Test with identities that should succeed and identities that should fail. Include a newly added user, a departed user, a lawyer removed from a matter, a lateral hire behind a screen, a temporary contract lawyer, a legal-operations administrator, a business executive, an external co-counsel account, and a service account. Change access while a session is active and confirm retrieval, cached results, conversation history, and future answers reflect the revocation on the required clock.
For custom data stores, current Google Cloud access-control documentation explains that administrators must enable access control and provide the appropriate ACL metadata. That reinforces a larger point: permission inheritance is a configuration and data-quality obligation. The phrase “supports ACLs” does not prove that the imported identities, groups, and documents are complete or correct.
3. Make the ethical wall a system boundary
Represent each ethical wall in an authoritative access and policy service, then enforce it before retrieval, after retrieval, during tool calls, and before output. Do not rely on the model to remember a wall written in a system prompt. A model can follow an instruction imperfectly; a policy enforcement point should deny the request regardless of the wording used.
Extend the wall beyond original documents. Isolate derived summaries, embeddings, vector indexes, search caches, model memory, conversation history, prompt templates that contain matter facts, legal playbooks built from restricted work, evaluation examples, logs, screenshots, exports, and generated drafts. A cross-matter answer assembled from derived data still crosses the wall even if the original file is never displayed.
Define how conflicts and restrictions propagate when clients merge, parties change, a matter becomes adverse, a lawyer changes teams, a new protective order arrives, or a regulator imposes a hold. The wall owner should be able to stop affected agents and purge or re-permission derived artifacts without waiting for every user to delete a chat.
Monitor denied attempts without exposing the restricted matter in the alert. A useful event can say that policy blocked cross-boundary access for a task and route the protected detail only to authorized conflicts, security, and legal personnel. General administrators should not gain matter knowledge merely because they operate the AI platform.
4. Prohibit bulk exports and process data in place
Google's launch describes permission-bound access to iManage without bulk exports and says NetDocuments source documents remain in the governed environment. Whether a particular connector truly processes in place, indexes content elsewhere, or creates temporary copies must be verified. The firm should prohibit users and agents from exporting an entire client workspace, mailbox, deal room, discovery database, or document-management corpus merely to make AI access convenient.
Prefer federated retrieval or minimum-necessary, task-scoped access. Cap the number, size, age, and classification of records an agent may retrieve. Restrict copy, download, print, email, external sharing, clipboard, local storage, and unsanctioned synchronization according to the matter. If temporary processing is unavoidable, record where the copy exists, who can access it, how it is encrypted, when it expires, how deletion is verified, and whether backups, logs, or support systems retain another copy.
Bulk export also increases discovery, retention, breach, and deletion complexity. The legal team may know how to govern the system of record but lose that control when an AI project creates a shadow repository with different holds and access. The ITECS Data & AI Readiness Audit maps these source, copy, identity, and retention paths before the agent receives production access.
5. Isolate client data and verify every provider term
Isolate data at the level justified by risk: organization or tenant, client, matter, project, repository, index, encryption key, region, workload identity, memory, evaluation set, log, backup, support role, and incident queue. Confirm that product administrators cannot browse privileged content by default and that support access is time-bound, approved, logged, and covered by the agreement. Test tenant and matter separation with canary documents that must never appear outside their authorized context.
Review the executed terms and actual edition, not only a launch post or sales answer. Cover input, output, prompts, files, embeddings, memory, feedback, logs, safety and abuse monitoring, human review, fine-tuning, provider improvement, subprocessors, data residency, cross-border transfers, encryption, customer-managed keys, retention, deletion, backup expiration, service termination, legal process, breach notification, ownership, confidentiality, indemnity, liability, audit rights, and exit assistance.
Google's launch says client data, firm playbooks, custom agents, and outputs stay private to the organization and are not used to train or fine-tune Google's foundation models. The current Gemini Enterprise app FAQ makes training and ownership statements for identified editions. Treat those as inputs to diligence. Confirm that the purchased edition, preview feature, connector, partner agent, grounding source, feedback setting, support path, and contract all receive the same treatment, and record any exception.
ABA Formal Opinion 512 says lawyers should understand a generative AI tool's terms, privacy policies, access, retention, reliability, security, proprietary-rights claims, conflicts process, breach notification, and failure risks, consulting technology or security expertise where needed. It also concludes that informed consent is required before entering representation information into certain self-learning tools that create disclosure risk, and that general boilerplate is not enough. The facts and applicable jurisdiction determine the required disclosure or consent; do not turn one engagement clause into universal permission.
6. Require citations that an attorney can reproduce
A legal-agent output should distinguish source text, extracted facts, rules, quotations, analysis, assumptions, uncertainty, and recommendations. For every material legal proposition, retain the jurisdiction, authority type, court or issuing body, title, citation, date, version or effective date, document identifier, page or paragraph, retrieval time, and stable link or approved source reference. For a contract finding, point to the exact agreement, version, clause, page, and playbook rule.
The reviewer must be able to open the source through their own authorized identity. A citation to a document the lawyer cannot access is not traceability; it may be evidence of a permission failure. Preserve the source version used so a later change to a webpage, regulation, filing, or contract does not make the prior conclusion impossible to reconstruct.
Citations improve verification but do not prove correctness. An agent may cite a real case for a proposition the case does not support, omit controlling adverse authority, quote a dissent as a holding, use an outdated regulation, mix jurisdictions, or retrieve a later-amended contract. The lawyer should check primary authority, quoted language, procedural posture, current validity, jurisdiction, and the application to the client's facts.
When the system lacks an authorized, current source, it should say that the proposition was not verified and route the gap to a person. It should not create a plausible citation or silently broaden to an unapproved web source. Google describes traceable grounding in its preview; the firm still needs an acceptance test for each source, skill, and workflow.
7. Test hallucinations, omissions, and redactions
Build a versioned legal evaluation set with lawyers who know the practice area and the relevant matter types. Include genuine and fabricated case names, similar citations, superseded statutes, conflicting authorities, negative treatment, unpublished decisions, foreign jurisdictions, defined terms that change meaning, cross-references, scanned exhibits, handwritten annotations, tables, footnotes, attachments, and documents with missing pages. Reward the system for stopping and escalating, not for answering every prompt.
Measure more than citation presence. Test whether the authority exists, supports the proposition, remains good law, applies in the jurisdiction, and includes controlling contrary authority. For contract review, test clause boundaries, amendments, hierarchy, incorporation by reference, dates, parties, defined terms, exceptions, and playbook fallbacks. Record false positives, false negatives, material omissions, unsupported assertions, and the attorney correction rate by version.
Redaction requires its own destructive test. Seed names, account numbers, personal identifiers, trade secrets, privileged annotations, hidden text, comments, tracked changes, document properties, layers, embedded files, OCR text, images, and filenames. Confirm that the released artifact—not merely the visual preview—contains no recoverable restricted content and that the original remains preserved under the proper hold and matter controls.
The SRA warning highlights false cases, misleading submissions, confidentiality failures, and the continuing responsibility of the regulated lawyer. ABA Formal Opinion 512 likewise says lawyers must review generative AI output for accuracy and carefully verify material submitted to a court. A passing model benchmark does not satisfy those duties for a real filing.
8. Put attorney review before consequential legal action
Require a qualified lawyer to review the exact final artifact before it becomes advice, a filing, a representation to a tribunal or regulator, a negotiation position, an executed agreement, a waiver, a disclosure, a response to a data request, a communication to another party, or a change to the legal system of record. Nonlawyer review can support quality and process, but it does not replace the professional judgment and supervisory responsibility assigned to a lawyer.
Bind approval to the task, client, matter, artifact hash, sources, model and skill versions, connector state, intended recipient, action, and expiration. If the content changes after review, the approval expires. A generic “looks good” click should not authorize a later agent to add new language, switch a citation, attach another document, or send the result to a different recipient.
The reviewer should see what the agent did, what it could not verify, which sources it used, what data it accessed, and whether any policy was denied or overridden. Require a second lawyer or specialist for the same high-risk decisions that receive dual review in the manual process. Do not lower an existing client or court approval requirement because AI produced the first draft faster.
For corporate legal departments, preserve the distinction between business preference and legal judgment. A business executive may own the commercial decision, but the lawyer should own the legal advice and privilege analysis within the scope of their role. The SRA specifically cautions in-house solicitors that enterprise AI tools built for the wider business may not be designed for legal work and that business pressure to adopt AI can conflict with professional duties.
9. Log access and actions without building a second disclosure problem
Record the task and parent task, client and matter reference, user and agent identity, authorization result, source systems, document identifiers and classifications, retrieval time, model, prompt, skill, connector and policy versions, tool calls, citations, redaction result, output artifact, attorney review, approval, recipient, side effect, error, retry, denial, and final disposition. Synchronize time and prevent the agent from altering its audit trail.
Use protected references, hashes, classifications, counts, and field names instead of copying full privileged communications into a broadly accessible monitoring platform. Restrict logs by matter and role, apply retention and legal holds deliberately, and document which administrators or vendors can see payloads. Logging designed without confidentiality boundaries can recreate the same cross-matter exposure it was meant to investigate.
Alert on first access to a sensitive matter, cross-wall denials, unusual document counts, bulk queries, new data destinations, missing citations, changed redaction behavior, repeated policy overrides, output sent without approval, and a user or agent acting outside its normal matter set. Route the alert to authorized responders without exposing the restricted matter to a general operations channel.
Make the evidence understandable without requiring private model reasoning. The team needs the observable inputs, permissions, sources, actions, output, and approvals—not a claim that the system can faithfully reveal an internal chain of thought. The ITECS AI DevOps model connects those versions and events to controlled releases, incidents, and rollback.
10. Define incident and client-notification procedures before launch
Define reportable events and near misses: cross-matter access, use of an unauthorized tool, disclosure to a provider or recipient, bulk export, lost privilege or work-product concern, fabricated authority in a released artifact, failed redaction, unapproved advice or filing, changed provider term, missing audit evidence, or a model, skill, or connector acting outside its approved boundary.
The first response is to stop new access and side effects, quarantine the affected agent and connectors, revoke task and service credentials, preserve prompts, files, versions, tool calls, permissions, logs, approvals, recipients, and timestamps, and protect the original evidence. Determine which clients, matters, jurisdictions, data types, users, providers, external parties, filings, negotiations, and downstream systems were affected. Separate confirmed facts from hypotheses.
Preassign the incident commander, responsible partner or general counsel, ethics counsel, privacy, security, conflicts, records, insurer or broker, provider, communications, and business owner. Create decision paths for notifying the client, court, counterparty, regulator, data-protection authority, insurer, law enforcement, and affected individual. The trigger and clock may come from professional rules, law, a protective order, an engagement, outside-counsel guidelines, insurance, or contract; one generic breach template will not cover every matter.
ABA Formal Opinion 483 says a lawyer has duties to notify current clients and take other reasonable steps when an electronic breach involves, or is substantially likely to involve, material client information. Apply the adopted rules and current law to the facts. The SRA warning makes clear that AI does not diminish accountability. Rehearse an agent-specific tabletop so the team can make these decisions without learning the system during a live disclosure.
The ITECS AI agent incident-reporting playbook provides a broader evidence, containment, escalation, and corrective-control structure. Legal teams should adapt it to their professional duties, privilege strategy, client instructions, and reporting regimes.
11. Revalidate every model, skill, connector, and policy change
A legal agent is a versioned system, not a one-time vendor approval. Treat changes to the model, system prompt, legal skill, playbook, retrieval configuration, connector, identity mapping, ACL import, source corpus, citation format, redaction engine, memory, tool, output schema, approval rule, logging, region, subprocessor, provider term, and support process as controlled releases.
For each change, identify which risks and matters are affected, compare the prior and proposed versions, rerun the relevant permission, wall, citation, hallucination, redaction, retention, action, and incident tests, then release to a canary group. Monitor acceptance rate, attorney corrections, unsupported claims, source failures, access denials, restricted-data alerts, redaction failures, latency, cost, and time saved without treating speed as a quality substitute.
A model update that improves general reasoning can still alter citation selection or refusal behavior. A connector update can change scopes or synchronization. A skill update can introduce new instructions or tools. Apply the supply-chain controls in the ITECS guide to AI agent tool poisoning: pin and verify what can be pinned, review semantic metadata, test in isolation, monitor behavioral drift, and retain a rapid quarantine path.
Set update triggers for this governance program too. Reopen the decision when Google moves the legal product out of preview or changes editions, connectors, data treatment, or terms; when the ABA, an applicable bar, court, or jurisdiction issues new AI guidance; when the SRA changes its warning; when a client changes outside-counsel rules; when privilege case law develops; or when an internal incident or evaluation reveals a new failure path.
Illustrative scenario: the cross-matter contract cache
Consider a contract-review agent approved to compare vendor agreements against a corporate playbook. Its connector correctly denies a lawyer access to a restricted acquisition matter, but an optimization stores clause summaries from all reviewed agreements in one shared semantic cache. A later query on an unrelated vendor contract returns a distinctive fallback position derived from the acquisition. No source document appears, yet confidential strategy has crossed the wall. This is an illustrative control test, not an ITECS client incident.
A mature design prevents the shared cache, assigns client and matter labels to every derived artifact, evaluates retrieval under the requesting identity, and denies content without revealing that a restricted matter exists. Canary text demonstrates the isolation failure before production. If the signal appears later, the team can quarantine the skill, identify every task that touched the cache, preserve evidence, purge or re-permission derived data, assess privilege and client impact, and restore only after a lawyer and security owner accept the corrective controls.
The scenario shows why source-system permissions are necessary but insufficient. The complete data path includes what the agent derives, remembers, logs, tests, and shares after retrieval.
A four-week legal-agent pilot
In week one, select one bounded workflow and matter class, assign a responsible lawyer and technical owner, collect applicable client and jurisdiction requirements, map the data flow, and exclude sensitive matters. In week two, configure identities, connector ACLs, ethical walls, no-export controls, isolated storage, provider terms, retention, and the attorney approval record.
In week three, build the citation, hallucination, omission, privilege, redaction, access, and incident test sets. Use synthetic and approved data, negative identities, restricted canary documents, changed permissions, and realistic source failures. Rehearse quarantine, credential revocation, evidence preservation, client-impact assessment, correction of downstream work, and the notification decision path.
In week four, release to a small trained group and review every task, source, denial, output, correction, and action. Expand only when the responsible lawyer can show that permissions were preserved, restricted content stayed isolated, citations were reproducible, redactions were irreversible, outputs met the legal acceptance criteria, and the human-review burden is understood.
Measure dependable legal work completed, not prompts or documents processed. Useful signals include accepted findings per reviewed contract, time to verify sources, material attorney correction rate, unsupported-authority rate, missed-clause rate, redaction escape rate, cross-wall denial accuracy, percentage of calls with complete evidence, unapproved action count, time to revoke access, and time to determine incident scope. Zero alerts are meaningful only if the negative controls are tested and the telemetry is complete.
The leadership decision
Gemini Enterprise for Legal shows where the market is moving: legal-specific skills, connectors into governed systems, agents that perform multi-step work, and a common control plane. Those capabilities can reduce copy-and-paste workflows and preserve context. They do not convert product availability into permission to expose a client matter or delegate professional responsibility.
The defensible unit of adoption is one legal workflow with one accountable lawyer, one enforceable matter boundary, one reviewed data path, one reproducible source trail, one human approval point, and one tested incident response. When that unit works, the organization can expand deliberately. When it does not, the legal team should stop the agent before speed turns a confidential mistake into advice, a filing, a negotiation, or a disclosure.
