Governing Legal AI Before Someone Does It for You
- Admin ILTN
- Aug 3
- 6 min read
AI is already changing how legal work is researched, drafted, reviewed, and delivered. But the rules governing its use in the legal profession are still taking shape.
That gap was at the centre of Governing Legal AI Before Someone Does It for You, an evening jointly hosted by the International Legal Technology Association (ILTA) and the Indian LegalTech Network (ILTN), in collaboration with Aarna Law.
Moderated by Shreya Raman, the conversation brought together Leah Verghese and Shreyas Jayasimha for a practical discussion on what responsible AI governance should look like in the legal sector and why the profession cannot afford to wait for regulation before developing its own standards.
The discussion moved beyond abstract principles. It examined the immediate questions confronting lawyers and law firms: How should AI-generated work be verified? What information should never be entered into a general-purpose AI tool? Who should develop professional standards? And will responsible AI adoption widen the divide between large firms and smaller practices?

The absence of regulation is not an absence of responsibility
One of the clearest themes from the discussion was that legal AI is advancing faster than the professional rules surrounding it.
In India, lawyers do not yet have a detailed, profession-wide framework governing the use of generative AI. Questions around confidentiality, disclosure, supervision, verification, and accountability therefore often remain with individual lawyers, chambers, and law firms.
But the absence of formal regulation does not mean that the profession should operate without guardrails.
Leah Verghese emphasised the need for institutions such as the Bar Council of India to take the lead in developing clear standards for lawyers. Other jurisdictions have already begun issuing guidance on the professional use of AI, and the Indian legal profession will eventually need rules that reflect its own institutional realities.
Until those rules emerge, responsibility cannot simply be deferred. Legal organisations must create internal protocols that determine which tools may be used, what information may be shared with them, how their outputs must be checked, and who remains accountable for the final work.
The core principle remains familiar: a lawyer cannot outsource professional responsibility to a machine.
Verification must become a professional habit
The risk of fabricated cases and citations has become one of the most visible problems associated with generative AI in legal practice.
An AI system can produce an answer that appears authoritative while containing inaccurate propositions, invented authorities, or citations that do not support the claim being made. The fluency of the response can make these errors especially difficult to detect.
The panel stressed that every AI-generated output must therefore be independently verified.
This does not make AI unusable. It means that AI must be incorporated into legal workflows with appropriate supervision. Lawyers already review the work produced by teams, external vendors, databases, and other information sources. AI requires a similar but technologically informed layer of scrutiny.
Verification should not depend solely on whether an individual lawyer remembers to double-check an answer. Law offices and chambers need repeatable processes for confirming citations, reviewing underlying sources, recording how AI was used, and ensuring that a qualified professional approves the final output.
Human oversight cannot be a slogan placed at the end of an AI policy. It must be built into the workflow.
Confidentiality begins with knowing where the data goes
The discussion also addressed a less visible but equally serious concern: the information lawyers enter into AI tools.
A prompt may contain far more than a simple question. It can include client names, facts of a dispute, contractual terms, negotiation positions, internal strategies, personal information, or unpublished documents. Entering such information into a general-purpose tool without understanding how the data is stored or processed may create significant confidentiality and privacy risks.
The practical advice was straightforward: lawyers should not share confidential client information with general AI tools unless the organisation has carefully evaluated the product and established appropriate safeguards.
Responsible tool selection requires more than choosing the most popular platform. Legal teams must consider its data-retention practices, security controls, contractual protections, access permissions, training policies, and suitability for the proposed task.
Client expectations will also increasingly shape these decisions. Sophisticated clients may impose their own requirements concerning approved tools, data handling, disclosure, or compliance with frameworks such as the EU AI Act. AI governance will therefore become part of the relationship between law firms and their clients—not merely an internal technology issue.
Should courts or professional bodies make the rules?
An important question raised during the session was whether courts should lead the governance of legal AI.
Courts will inevitably influence standards through procedural directions, judicial decisions, and responses to the misuse of AI in proceedings. However, the panel suggested that professional bodies are better placed to develop broader standards for lawyers.
A court generally responds to disputes and failures that have already occurred. A professional regulator can act earlier by establishing duties, providing guidance, and helping lawyers understand what responsible use looks like before misconduct reaches the courtroom.
Bar Councils and Bar associations could begin with basic orientation programmes explaining how generative AI works, where it can fail, what information should not be shared, and how lawyers should verify its outputs.
This initial training need not turn every lawyer into a technologist. Its purpose would be to give legal professionals enough understanding to use AI critically and recognise when a tool creates professional risk.
Governance cannot be designed in silos
Shreyas Jayasimha approached the current regulatory gap not only as a risk, but also as an opportunity.
Instead of waiting for a complete framework to arrive from the top, the legal and techno-legal community can begin developing shared standards from the ground up. Law firm partners, general counsel, litigators, judges, technologists, entrepreneurs, researchers, clients, and professional bodies all encounter different aspects of AI adoption. Any workable governance model will need to account for those perspectives.
This requires systems thinking.
An AI tool cannot be evaluated only according to whether it produces a useful draft. Its wider effects must also be considered: who provides the underlying data, who reviews the result, how errors travel through the workflow, which incentives influence deployment, and who bears the consequences when the system fails.
Collaboration is particularly important because many governance failures begin with groups working separately. Technologists may develop solutions without fully understanding legal duties. Lawyers may impose controls without understanding the technology. Organisations may introduce tools without consulting the people expected to use them.
Responsible adoption begins with empathy for users and stakeholders. It asks not only whether a system works, but whether it fits the environment in which people will actually use it.
The risk of a new digital divide
The panel also considered whether AI adoption could deepen existing inequalities within the profession.
Large firms may be able to purchase secure enterprise tools, build internal technology teams, obtain specialist advice, and create sophisticated compliance frameworks. Smaller firms, chambers, and independent practitioners may not have access to the same resources.
If responsible AI becomes synonymous with expensive AI, the profession risks creating a system in which only larger organisations can benefit safely from the technology.
Yet the future need not follow that path. Automation is becoming more accessible, and smaller practices may be able to adopt targeted tools without recreating the infrastructure of a large firm. Community-developed guidance, shared training, transparent products, and affordable legal AI systems could help reduce the divide.
Governance must therefore address access as well as risk.
The goal should not be to restrict useful technology to institutions capable of building the most elaborate compliance systems. It should be to make responsible adoption understandable and achievable across the profession.
India will need its own approach
International frameworks provide valuable reference points, but India’s approach to legal AI governance cannot simply be copied from another jurisdiction.
The structure of the legal profession, differences in digital access, the role of courts and Bar Councils, the range of legal practices, and the availability of Indian legal data all shape how AI will be adopted here.
AI systems trained on or designed around Indian legal materials may create significant opportunities. They may also raise difficult questions about data quality, linguistic coverage, accuracy, transparency, and the representation of Indian legal reasoning.
India’s governance framework is likely to develop gradually, through a combination of professional guidance, organisational policies, client requirements, judicial intervention, and community-led standards.
That process may not begin with a single law or major triggering event. It has, in many ways, already begun.
Self-governance must come before crisis
The strongest takeaway from the evening was that the legal profession should not wait for a fabricated citation, confidentiality breach, or high-profile failure to force the conversation.
Lawyers and legal organisations can begin immediately by establishing approved-tool lists, confidentiality safeguards, verification procedures, human review requirements, internal training, and clear accountability for AI-assisted work.
But internal policies are only the beginning. The wider legal community must also participate in shaping common expectations for responsible use.
AI governance will not be solved by regulators, courts, law firms, or technology companies acting alone. It will require shared responsibility across the ecosystem and a willingness to revise standards as both the technology and our understanding of its risks develop.
The choice is not between adopting AI and resisting it. The more important choice is whether the legal profession will shape how AI is used or wait until failures, clients, courts, or regulators make that decision for it.



Comments