All posts
AI
July 31, 2026

Why Legal Teams Don't Have a Choice About AI Anymore. Only How They Use It

Why Legal Teams Don't Have a Choice About AI Anymore. Only How They Use It

The debate is over. Legal teams are using AI. The only question left is whether they’re doing it safely.

That’s the conclusion Pritesh Patel, Director of Artificial Intelligence at Fisher Phillips, has reached after leading the firm’s AI strategy from the inside. And it’s backed by hard data.

According to Law360’s most recent Pulse Survey, the percentage of attorneys using AI three or more times per week jumped from 27% to 47% in a single year. Not over a decade. One year.

For anyone still asking “should we allow AI on our legal team?” that ship has sailed. The real conversation is: now that it’s happening, how do we make sure we’re not the ones left exposed?

The Tension Is Real, But the Tradeoff Isn’t

Legal work operates under conditions that almost no other industry faces. Attorney-client privilege. Confidentiality obligations. ABA ethical rules. Fiduciary duty. The stakes of being wrong are not just financial: they’re reputational, regulatory, and in some cases criminal.

So when AI tools promise speed, efficiency, and scale, the natural instinct in a law firm is caution. And that caution isn’t wrong. What’s wrong is the conclusion most firms draw from it.

“The wrong question is: should we use it right now? The right question is: how do we use it without increasing our risk?” (Pritesh Patel, Director of AI, Fisher Phillips)

The moment you frame it that way, the conversation changes entirely. You’re not choosing between speed and safety. You’re designing for both.

The Shadow AI Problem Nobody Wants to Admit

Here’s an uncomfortable truth: the AI inventory most organizations believe they have is fiction.

Research consistently shows that organizations underestimate actual AI usage by 2x to 4x. That gap isn’t theoretical, it’s already sitting inside your firm, in the form of attorneys using consumer AI tools to draft correspondence, summarize documents, and research case law. Without governance. Without logging. Without oversight.

The instinct when you discover this is to build a “naughty list.” Don’t.

When you find more AI usage than you expected, read it as a demand signal. Your people want to work this way. Your job isn’t to shut it down, it’s to build an environment where they can do so safely.

This is what governance frameworks like NIST AI RMF and ISO 42001 are telling you when they emphasize continuous monitoring. An inventory isn’t something you build once and put on a shelf. It’s a living, actively maintained picture of what’s happening in your environment right now.

Governance by Design, Not Governance by Announcement

The old model looks like this: IT controls access. Employees submit requests. Requests get reviewed and approved. Governance happens at the end of the process, after value has already been created, which means governance is always negotiating.

The new model flips this entirely.

Governance happens in the building layer, not the review layer. Enforcement happens where agents actually operate, not after the fact. The result is that your people can move at speed without ever touching something they shouldn’t.

A useful analogy: a commercial kitchen is not made safe by telling everyone to be careful. You don’t start every meal with a speech about caution. Instead, you put guards on the slicer, you color-code the cutting boards, you set the fryer to a maximum temperature. Safety is designed into the environment, not announced to the people working in it.

The same principle applies to AI governance in legal.

What This Looks Like in Practice

At Fisher Phillips, the philosophy is simple: the people who understand the work best should be the ones building the AI tools that support it.

“The best thing you can do is educate and train your people who are running these workloads. They are the most equipped to figure out what the efficiencies are.” (Pritesh Patel)

This means non-technical operations staff (paralegals, billing coordinators, matter intake teams) are given the ability to build their own AI agents inside a pre-governed environment. Policies are already set. Guardrails are already in place. The environment itself prevents unsafe actions, not policy memos or training sessions.

The result is a paralegal who builds a summarization agent, wired only to the documents related to her matter, running on the model approved for that data classification, with every run automatically logged. She never had to read a governance policy. She never violated anything. The design of the environment led her down the right road.

This is what governance by design actually means.

The Agent Rule of Two

As agentic AI becomes more common in legal workflows, a new risk framework becomes essential.

An AI agent can, in principle, do three things: access sensitive data, change the state of a system, and reach out over the web. Any one of these capabilities alone is manageable. Two together require careful design. All three at once, without controls, is a danger zone.

This framework, sometimes called the Agent Rule of Two, was formalized in AI safety research and is now being applied as an enforceable policy at Fisher Phillips. No agent is permitted to do all three simultaneously. When the evidence layer of your AI platform can detect this pattern and block it automatically, the rule has teeth.

On Data Privacy: The Agreement Is Not Enough

One of the most common questions legal technology leaders face is: how is client data protected from being absorbed into an LLM?

The short answer is that the agreement matters, but the environment matters more.

At Fisher Phillips, client data is only connected to AI systems when explicit agreements are in place under ABA guidelines. But beyond that, the architecture itself provides the protection. Sensitive workloads run on open-source models deployed on-premises, inside the firm’s own servers. That data never touches a public API. It never leaves the environment.

Critically: when a model provider updates its terms (as has happened with major providers shifting retention policies) an agreement alone won’t protect you. You need to stay actively on top of what your providers are doing. Governance is not a document you sign once.

Speed and Safety Are Not Opposites

The loudest objection to AI governance is always the same: it will slow us down.

But consider what “slow” actually costs. Legal teams that refuse to adopt AI governance frameworks aren’t choosing safety over speed. They’re choosing to be slow AND exposed, because the AI usage is already happening, just without controls.

“If you really are determined about how to design this, and you have the right platform behind you, it is actually an advantage. And not a lot of people are doing that.” (Pritesh Patel)

We’re in the first inning and a half of AI in legal. The decisions made right now, about how agents are built, what data they can touch, how actions are logged, and where enforcement lives, are the decisions that will determine which firms lead and which firms clean up messes.

The window to get this right is still open. But it won’t be forever.

Andrew Clearwater is Chief Trust Officer at Airia, an enterprise AI control plane that helps organizations govern, monitor, and enforce AI usage at scale. Pritesh Patel is Director of Artificial Intelligence at Fisher Phillips.

This article is based on a live webinar conversation. Watch the full recording here.

Put these ideas to work.

Schedule a 30-minute walkthrough with our team.

Talk through your use case