Ask a legal team whether it governs its use of AI and you will usually be handed a policy. It reads well enough, listing approved tools, warning against pasting client data into public chatbots, and telling everyone to review the output before relying on it. Then it lands in a shared drive and the firm moves on. The box is checked, and almost nothing about how people use AI has changed.
That gap is the problem. A policy describes what people are permitted to do. Governance concerns what they do, and whether anyone can see it, correct it, or account for it later. Firms treat the two as the same thing, which is how they end up confident and exposed at once.
The distance between them keeps growing, partly because of how AI reaches a practice now. Few teams sit down to evaluate and approve a new tool. The capability arrives inside a platform they already license, switched on by a routine update or a renewal. Lawyers start using it, and the question of whether they should comes up afterward, if at all. A document written last year was never going to keep pace with that.
So, what does governance involve? It starts with someone owning it. A policy can sit unsigned for a year, and nothing breaks; an owner is a named person who answers for AI use, vets new capabilities before they reach client work, and can refuse one and make the refusal stick. Without that person, enforcement falls to whichever lawyer happens to be paying attention, which is to say no one.
It also means deciding what a review is worth. Most policies require a human to check AI-generated work but never say what checking involves or who carries the result when it turns out wrong. A summary of an internal memo and a brief headed to court do not warrant the same scrutiny, and someone must draw that line in advance. “Review the output” is not a standard. It is an instruction to worry, and it leaves the burden with whoever ran the tool.
Closely related is the problem of knowing what a firm has. No team can supervise tools it cannot see, and because AI now hides inside larger platforms, many do not know which ones touch privileged material or shape a given piece of work. A list maintained by hand falls out of date the moment a lawyer opens a free chatbot in a personal browser. This is what has pushed firms toward dedicated tooling: products such as CounselGuard capture AI sessions across firm and personal devices and tag each tool with a status, keeping the inventory live. The category matters more than any single vendor. An accurate picture of where AI operates is simply not something a quarterly spreadsheet can produce.
Configuration is the next concern, and the one policies reach least. AI tools make quiet design choices that influence legal judgment without announcing themselves. A system might fill a gap in a document instead of flagging it or present an inference as established fact. Consider a contract review tool asked to extract the indemnification terms from an agreement that has none. A well-built system reports that the clause is absent; a poorly configured one drafts a plausible clause and presents it as found. The output looks complete precisely where it is wrong, and the lawyer who trusts it never learns the difference. Reaching that level requires that the tools a team depends on keep records, surface their assumptions, and submit to an audit. Logging prompts, responses, and the rule that applied to a matter is what turns oversight from a stated intention into something a partner can examine.
Governance also must outlast the tools themselves. A decision shaped by AI may need explaining years after the software behind it has been retired or the vendor has folded. That means settling now on how records are kept, so a choice made this quarter can still be defended when a client, regulator, or insurer asks about it long after the fact. A policy written for present conditions has nothing to say about the past.
None of these things is paperwork. Ownership, review standards, inventory, auditability, and retention are ongoing practices, and they decay when no one tends them. As the technology and the regulation around it keep moving, a framework that stands still stops doing its job. Writing a policy takes an afternoon; sustaining the practices behind it is part of running the function, and the work does not end.
A long acceptable-use document proves nothing on its own. What counts is whether a firm can say, on any given day, where AI is touching its work, who is responsible for it, and how it would prove the answer.
Colin S. Levy is a lawyer, legal technology strategist, and author who has spent more than a decade working at the intersection of legal practice and innovation. He serves as General Counsel and Evangelist at Malbek, a contract lifecycle management platform, and teaches Technology & Law Practice Management as an adjunct professor at Albany Law School. He also sits on the Board of Directors of the Corporate Legal Operations Consortium (CLOC). He has a forthcoming book on AI coming out this fall.






