The lawyers getting real time back from AI are not the ones who paste a whole matter file into a consumer chatbot and ask for a brief. They are the ones who split work into "first draft / triage" vs. "judgment / filing" and keep a hard stop between the two.
The risk is not that the model types slowly. The risk is a hallucinated citation, a confidential fact in a non-compliant tool, or a partner signing off on language nobody verified.
Safe vs. not-safe by task type
| Task | Safe AI use (with human review) | Not safe to fully delegate |
|---|---|---|
| Research triage (what to read first) | Summarize public opinions or statutes you already retrieved; rank issues | Inventing case law or "the leading case is…" without a primary source open |
| First draft of internal memo structure | Outline issues, headings, questions to research | Final advice to client without attorney edit |
| Contract redline first pass | Flag missing clauses against your checklist | Binding negotiation position sent to opposing counsel |
| Discovery document sorting | Bucket by theme, date, party (on approved tool) | Privilege calls and production decisions without attorney review |
| Client email polish | Tone and clarity on non-confidential drafts | Anything with strategy, settlement numbers, or privileged facts in an unapproved system |
| Citation formatting | Convert known good cites to house style | Generating cites from memory |
If a task changes legal rights, costs money, or goes to a court or opposing party, AI can draft - a human still owns the decision.
The confidentiality rule that prevents most disasters
Before any paste:
1. Is this tool under a firm-approved DPA / enterprise agreement with training disabled?
2. Can I strip client identifiers and still get a useful draft?
3. Would I be comfortable if this prompt appeared in discovery?
If the answer to 1 is no, use only public, non-sensitive examples or an approved offline/enterprise product. The [AI for Lawyers Playbook](https://auth.mane.dev?site=aiagentstudio&template=ai-for-lawyers) on aiagentstudio.pro is designed around practice-area tasks and tool constraints so the first plan already separates safe drafting work from judgment work.
A concrete safe workflow: first-draft issue list
Bad: "Here is the full client email and all attachments. Write a motion to dismiss."
Better (public facts + structure only):
"You are a litigation associate. Practice area: commercial contract dispute under [state] law. Known public facts: [3 bullets with no client name]. Opposing theory appears to be X. Produce: (1) issue list ranked by strength, (2) for each issue, 3 questions I should answer with primary sources, (3) a memo outline with headings only - no fabricated case names. Flag any area where you are uncertain."
Then the attorney pulls real cases from Westlaw/Lexis/etc., plugs them in, and writes the argument. The model saved the blank-page hour. It did not invent authority.
Hallucinated citations: the non-negotiable check
Every citation the model produces is guilty until proven innocent. Open the case. Confirm the holding supports the sentence. Confirm the pinpoint if you include one.
A useful prompt add-on: "If you are not certain a case exists or stands for this proposition, write UNKNOWN instead of a citation." Models still sometimes ignore that, so the human check remains mandatory.
What good looks like after two weeks of use
- Associates spend less time on first outlines and more time on source-verified analysis.
- Partners see fewer "confident but empty" drafts because the prompt requires an uncertainty flag.
- No client names or strategy emails go into consumer free tiers.
- The firm has a one-page policy: approved tools, banned tasks, citation verification rule.
Pair tools with the right job
Use the [AI for Lawyers](https://auth.mane.dev?site=aiagentstudio&template=ai-for-lawyers) playbook to map your practice area to a short list of high-ROI, low-risk tasks (research triage, checklist-driven redlines, internal outline generation).
For long public PDFs or opinions you already have permission to process, a structured [Summarizer](https://auth.mane.dev?site=aiagentstudio&template=summarizer) workflow with "decisions / open questions / action items" format beats "summarize this" every time - still with human verification of anything that will be cited.
The one-sentence policy
AI drafts; lawyers decide; no citation ships unopened; no confidential matter data enters an unapproved tool.
That is not anti-AI. It is how you keep the time savings without buying a malpractice fact pattern.
Practice-area notes (still human-owned)
Litigation: strong use for deposition outline scaffolding and issue lists from *public* pleadings you already have. Weak use for predicting how a specific judge will rule based on vibes.
Transactional: strong use for checklist-driven first-pass redlines against your playbook clauses. Weak use for deciding whether a non-standard indemnity is "acceptable business risk."
Employment / counseling: strong use for internal FAQ drafts from your existing policy PDFs. Weak use for advising on a fact-specific termination without attorney review.
Whatever the practice area, the pattern is the same: AI accelerates assembly and first structure; licensed judgment stays with the lawyer.
A 30-minute onboarding for a new associate
1. Share the firm one-pager: approved tools, banned data, citation rule.
2. Run one safe exercise: outline-only memo from a public opinion PDF.
3. Require the associate to attach primary sources for every cite before partner review.
4. Only then expand to checklist redlines on a non-client training agreement.
Skipping step 1 is how firms get headline risk. Skipping step 3 is how they get quiet quality risk.