July 2026 · AI governance

AI governance for in-house legal teams: five minimum controls

The adoption numbers no longer leave room for a wait-and-see posture. In the Association of Corporate Counsel's 2025 survey, US in-house respondents using generative AI rose from 23 to 52 percent in a year. Thomson Reuters' 2025 professional services report found, separately, that across industries 52 percent had no policy on generative AI at work. The same number, two different populations: US in-house adoption and cross-industry policy absence, together a tool outrunning its guardrails.

Before I let a team scale, I ask for five controls on one page.

First, data handling. Write down what may enter a prompt: client identities, personal data and privileged material each need a rule, set before anyone opens a chat window.

Second, accountability. Every AI-assisted output has a named owner. The model drafts; a lawyer signs and answers for it.

Third, human review. Tie review depth to the impact and reversibility of the output, not only to whether it leaves the team. High-impact or hard-to-reverse work passes a qualified reader who can reject it. A later spot check does not meet that bar.

Fourth, logging and records. Log the metadata and review trail: which tool, which version, who approved. Set a retention period and a deletion rule rather than storing full prompts by default. Memory is not a record when a regulator asks how a document was produced.

Fifth, error handling. Agree in advance what happens when the model is wrong: who gets told, how the correction is documented, what changes in the workflow.

These five are the floor for a pilot, not the finished house. The next layer adds a use-case inventory, access controls, and training. None of it needs a new platform or a committee, just one page, the starting document that links out to each control, signed first by the general counsel.

Sources

Related: Legal tech and AI workflow automation

Next: KVKK-compliant generative AI workflows for legal teams →