Read the report HERE
Legal IT Insider today (16 June) publishes its Gen AI and the Practice of Law 3 Report, which at over 100 pages, following over 35 hours of interviews with legal tech leaders, is not a light read, and nor is it intended be.
The first two reports in this series were descriptive: they asked what was happening as generative AI entered legal practice. Report 3 is different. The descriptive phase is closing. After three years of deployment, judicial scrutiny, client pressure and vendor consolidation, the question is no longer what the technology can do, but what a firm can defend, to whom, and on what evidence. That is a question of accountability rather than tooling, and it changes what governance is for. Governance is no longer a brake on the work; it has become the infrastructure that makes the work possible.
Written by our lead analyst, leading technology consultant, Neil Cameron, the report can be used as both a benchmark and a manual. The overriding finding, if it were possible to distil it, is that governance is the key, not the lock.
One problem in four parts
At the core of the report is a deceptively simple model: a four-part governance chain spanning strategy, process, forensic validation, and client acceptance. These are not parallel workstreams. They are interdependent layers, where failure upstream cannot easily be corrected downstream.
This framing is one of the report’s most important contributions. Much of the market discussion to date has treated governance as a policy exercise or a compliance overlay. The report argues instead that AI governance in legal work is inherently cross-system, and no single vendor today owns cross-system enforcement. That missing layer is the governance spine, and it organises everything that follows.
Section 2 – Strategic governance: why AI strategy has it backwards
Most firms started with the tools and worked backwards towards a business case, when every principle of strategic IT planning demands the reverse: business objectives first, then the technology that serves them. A firm that cannot say what each of its AI tools is for, measured against a prioritised objective, does not have an AI strategy. It has procurement history. The two are routinely confused. The Autologyx argument frames the way out as a governance spine rather than another tool bolted onto the patchwork.
Section 3 – Process governance: the orchestration layer
An orchestration spine sequences AI tasks, human checkpoints and system-of-record updates into one auditable pipeline. The market building it sorts into five positions: dedicated middleware, consolidated legal-AI platform, productivity-platform horizontal, agentic operating system, and vertical professional-services platform.
Two harder questions sit underneath: where the line falls between the content layer and the orchestration layer, and, once agents can act, why a client pays the firm rather than the agent’s operator. Every contender claims a different share of the spine; none yet owns the cross-system enforcement layer.
Inside Section 3 we examine Microsoft Agent Framework: the third attempt; Claude for Legal: the foundation layer moves up the stack; and a note on LexisNexis Protégé as the stable layer beneath a multi-model market.
Section 4 – Forensic governance: the validation gap
The profession spent two decades making technology-assisted review defensible, then carried almost none of that experience across to generative AI. The forensic problem is evidential rather than a matter of accuracy: an output that cannot be shown to have come through a documented, validated method is a problem in court whether or not it happens to be right. And the validation problem HAR raises is different in kind from TAR’s, not merely larger – interpretive synthesis across drifting context needs a methodology that does not yet exist. Who builds it, and how the courts come to accept it, is the open question of the next few years.
Inside Section 4 we examine The Heppner ruling: what it says and what it does not; and The MCP integration that returned the partners’ compensation.
Section 5 – Client-driven governance: clients as co-regulators
Formal regulators have been slow; sophisticated clients have not. AI procurement questionnaires from major buyers now demand more than the SRA, ABA or Law Society has produced, and function as de facto regulation. The exception is AML and source-of-funds, the one territory where the regulator itself is the most demanding buyer in the room. The sharpest case comes when contradictory client demands meet a firm with no cross-system way to enforce either.
Section 6 – Taking control
The economic argument beneath the chain: model capability commoditises; governed workflow does not. Governance lowers the marginal cost of supervised AI deployment at the firms that have it, and turns into a moat that deepens as the models improve. Increasingly it is the substance of the work rather than an overhead on it. The precondition almost everyone is deferring is the unglamorous one, data architecture, and it is the part most likely to surface later as the explanation for an expensive forensic failure.
Why this report matters
Legal IT Insider’s third Gen AI report lands at a moment when the industry’s centre of gravity is shifting.
The early phase of excitement, experimentation and vendor proliferation is giving way to something more exacting: proof, accountability and control.
For firms, the implication is clear. The question is no longer whether to use AI. It is whether they can govern it, end-to-end, and under scrutiny. Capability, without control, is a liability.
To read the report in full, please click HERE









