A 40-attorney litigation firm in Chicago handed an associate a due diligence project last spring: review 1,200 vendor contracts from an acquisition target and find every change-of-control clause, every auto-renewal, and every assignment restriction. Two weeks of billable time, most of it after 9 PM. When the deal closed, everyone was relieved and nobody could tell you with confidence that clause 14.3 in contract number 700-something had actually been read.
That is the real state of AI in legal work. The question is not whether machines can read contracts faster than a tired associate at midnight. They obviously can. The question is whether you can trust what they tell you, and whether using them puts privilege or client confidentiality at risk. Get those two things right and AI in legal is transformative. Get them wrong and it is malpractice with better formatting.
Two Places AI Earns Its Keep in Law
Set aside the hype and there are two workflows where AI in legal is already doing serious, defensible work: contract review and discovery. Both are document-heavy, deadline-driven, and expensive precisely because they consume senior human attention on tasks that are 80 percent pattern-matching.
Contract Review
Reviewing a contract is, mechanically, a search-and-compare exercise. You are hunting for specific provisions, comparing them to a standard or a playbook, and flagging deviations. AI does the first pass extremely well:
- Extraction - pulling every indemnification clause, termination right, liability cap, governing-law provision, and renewal term across a stack of agreements
- Comparison - measuring each clause against your firm's preferred positions and flagging where a counterparty's draft strays
- Summarization - producing a clause-by-clause abstract of a 60-page master services agreement in the time it takes to get coffee
The Chicago firm now runs its due diligence sets through an extraction pass first. The associate does not start from 1,200 blank contracts. They start from a structured grid showing every change-of-control clause already located and quoted, and they spend their expensive hours verifying and judging rather than hunting. The same 1,200-contract review that ate two weeks now takes about three days, and every clause has a traceable source.
Discovery
Discovery is where document volume becomes absurd. A mid-sized litigation matter can involve hundreds of thousands of documents. Technology-assisted review has been accepted by courts for years, but modern AI goes further - it can cluster documents by concept, surface the ones most likely to be responsive or privileged, and draft summaries of what a custodian's email trove actually contains. That turns a linear slog into a prioritized one, and prioritization is most of the game when the clock and the budget are both running.
A related and underrated use is privilege review. In a large production set, missing a single privileged document is a nightmare - inadvertent waiver, a clawback fight, a very uncomfortable call to the client. AI that flags likely-privileged material by spotting the markers of legal advice, attorney involvement, and litigation context gives the review team a second pass that a human alone, at volume and under deadline, simply cannot match. It does not replace the privilege log; it makes sure fewer things fall off it.
The Hallucination Problem, Stated Plainly
Here is the part the industry learned the hard way. In 2023 two New York lawyers were sanctioned after they filed a brief citing cases that did not exist. A general-purpose chatbot had invented them - plausible names, plausible citations, entirely fictional. It has happened repeatedly since, in multiple jurisdictions, to lawyers who should have known better.
This is the defining risk of AI in legal, and it comes from a basic property of language models: they generate text that is statistically likely, not text that is verified true. Ask one for a supporting case and it will happily produce one that *sounds* exactly right, because sounding right is literally what it optimizes for.
The fix is not "be careful" or "double-check." The fix is architectural.
Cited, Grounded Output Is the Only Acceptable Standard
A legal AI system fit for real work must not answer from its own memory. It must answer from a defined corpus - your documents, your matter files, an authorized case-law database - and every assertion it makes must link back to the specific source passage it came from. This is usually called retrieval-augmented generation, but the operational rule is simpler: no citation, no claim.
When a system quotes clause 14.3 and links to the exact page of the exact contract, you can verify it in seconds. When a system tells you "case law generally supports this position," you have learned nothing and possibly been lied to. The difference between those two behaviors is the difference between a tool a firm can rely on and one that gets people sanctioned. Our AI for legal approach is built on grounded, cited output for exactly this reason - the human lawyer verifies the source, but the source is always there to verify.
That verification step is not optional and it does not disappear. The lawyer remains responsible for every filing. AI compresses the work of finding and organizing; it does not transfer accountability.
Privilege and Confidentiality: Do Not Feed the Public Model
The second landmine is confidentiality. When a lawyer pastes a client document into a consumer AI tool, that content may be transmitted to and retained by a third party, and in some configurations used to improve their models. For privileged material, that is a potential waiver of privilege and a breach of your duty of confidentiality in one keystroke.
The requirements for AI in legal that touches client matter:
- A closed, contractual environment where client data is never used to train shared models and is not retained beyond your control
- Segregation by matter and client, so one client's data cannot surface in another's workspace
- Clear data-handling terms you can actually show a client or a court if asked
- Encryption and access logging as a baseline, not a premium feature
The same document-heavy capability that powers extraction is described on our AI document processing page, but for legal use the confidentiality architecture around it is what matters most. And because every firm's document types, playbook, and matter structure differ, this is frequently a case for custom AI software rather than a generic subscription that was never designed for privileged material.
What This Actually Changes for a Firm
The firms getting real value are not replacing lawyers. They are removing the least valuable use of a lawyer's time - the initial hunt through documents - and preserving the most valuable - judgment, strategy, and the decision about what a clause actually means for a client.
The economics follow. If a review that billed 80 hours now takes 20 hours of higher-value work, the firm either wins more work at a better margin or delivers faster at a price clients prefer. Either way the associate stops living at the office at midnight, and clause 14.3 actually gets read.
There is a professional-responsibility angle worth naming too. Bar associations across jurisdictions have started issuing guidance on generative AI, and the throughline is consistent: a lawyer's duties of competence, confidentiality, and candor to the court apply exactly as they always have, regardless of the tool used. That means using AI competently now includes understanding its limits well enough not to file its unverified output. A firm that adopts AI thoughtfully - cited output, closed environment, human verification - is on far safer ethical ground than one whose associates are quietly pasting privileged drafts into whatever free tool is open in another tab. The choice is not really whether AI enters your practice. It is whether it enters through a governed door or a back window.
The discipline that makes it safe is boring and non-negotiable: grounded output with citations, a closed environment that protects privilege, and a human lawyer who verifies before anything is filed. AI in legal rewards firms that treat those three rules as sacred and punishes the ones that treat AI like a smart intern who never lies.
Frequently Asked Questions
Can AI actually be trusted to review contracts?
For extraction, comparison, and summarization, yes - provided the output is grounded in the actual documents and cites its sources. The reliable model does not answer from memory; it quotes the specific clause and links to it so a lawyer can verify in seconds. Trust comes from verifiability, not from the model being infallible.
What is the hallucination problem?
Language models generate text that is statistically plausible, not necessarily true. Asked for a supporting case, a general-purpose model may invent one that looks completely real. Lawyers have been sanctioned for filing such fabricated citations. The safeguard is a system that only asserts what it can cite from an authorized source.
Does using AI risk waiving attorney-client privilege?
It can, if you use the wrong tool. Pasting privileged material into a consumer chatbot may transmit it to a third party and retain it. A legal-grade system uses a closed environment where client data is never used to train shared models, is segregated by matter, and stays under your control.
Will AI replace lawyers?
No. It removes the low-value document hunt and preserves the high-value judgment. Lawyers remain accountable for every filing and every interpretation. The change is in how their time is spent, not whether they are needed.
How do we start safely?
Begin with one contained, high-volume task such as contract extraction or discovery prioritization, inside a confidential environment with cited output, and keep a lawyer verifying results. Measure the time saved and the accuracy, then expand once the safeguards have proven themselves.