In many law firms, the adoption of artificial intelligence (AI) hasn't been the result of a formal leadership decision. It has occurred organically, driven by individual attorneys selecting tools, developing workflows and applying their own judgment about what to verify, what to disclose and what to trust.

That is not a technology policy. It's the absence of one. And the consequences of that absence sit with firm leadership, regardless of whether leadership was directly involved in the decisions that created it.

The companion article in this series examined where AI creates professional liability exposure, including hallucinations, supervision gaps, confidentiality risk and evolving disclosure obligations. This article addresses the structural issue beneath those risks: what happens when AI governance is treated as an individual attorney decision rather than a leadership mandate and why that approach introduces material and often underappreciated exposure.

What decentralized AI use looks like in practice

In firms without formal AI governance, the reality is often uneven and largely invisible at the institutional level.

A litigation partner may rely on one AI tool for drafting and deposition preparation, with a self-developed verification process. In another practice group, an associate may use a different tool, potentially one not designed for legal work, and may input client-specific details to improve results. In other areas of the firm, adoption may be extensive or nonexistent, with little awareness across practice groups.

In many cases:

  • No centralized inventory of tools exists
  • No formal evaluation of how tools handle client data has been conducted
  • No defined supervision standards govern AI-assisted work
  • No consistent approach to disclosure has been established

Individual attorneys make decisions independently, based on their own risk tolerance and familiarity with technology. The firm lacks visibility into how AI is being used and cannot demonstrate to clients, courts or insurers what standards apply. This isn't an outlier scenario. It reflects the current state at many firms.

Our 2026 AI Adoption and Risk Survey found that fewer than half of organizations have implemented formal AI risk management frameworks, even as 63% have operationalized AI in some capacity. The gap between adoption and governance is not peripheral. It's central.

Why decentralized AI use creates compounding risk

The issue isn't simply the potential for individual mistakes. It's the structural impact on how the firm manages and defends its risk.

Why this is a leadership issue

Treating AI governance as an attorney-level decision introduces a set of leadership risks.

What an effective AI governance framework requires

AI governance doesn't require deep technical expertise. It requires disciplined risk management aligned with professional responsibility.

A well-structured framework typically includes:

  • A clear inventory and approval process for AI tools. The firm should understand which tools are in use, where they are applied and whether they meet confidentiality and security expectations. Approved tools should be defined, along with a process for evaluating new ones.
  • Defined supervision standards. The firm should establish consistent expectations for reviewing AI-assisted work product before it's delivered to clients or submitted to courts.
  • Explicitly prohibited uses. Certain activities should be clearly restricted, including the use of unsecured tools for client information or the use of AI-generated content without attorney review.
  • Firm-wide training and communication. Attorneys and staff should understand how AI use intersects with duties of competence, confidentiality and supervision.
  • Consistent disclosure protocols. Practices for disclosing AI use should reflect current bar guidance and be updated as standards evolve.
  • Ongoing monitoring and ownership. Governance should have a defined owner responsible for maintaining and updating the framework as technology and regulatory expectations change.

The governance-insurance connection

AI governance and professional liability insurance are increasingly connected. Underwriters are beginning to evaluate how firms govern AI use as part of the renewal process. While approaches vary, the direction is consistent. Insurers are assessing whether firms have formal policies, supervision standards and training in place. Firms that can demonstrate structured governance present a more stable and predictable risk profile.

Governance also plays a role in claims defense. When a claim involves AI-assisted work, the existence of a documented and applied governance framework supports the firm's ability to demonstrate appropriate standard of care. This is not only a risk management issue. It's also a coverage and insurability consideration.

Strategic implications for law firm AI governance and risk management

The way firms approach AI governance today will shape both their risk profile and their competitive position.

  1. A lack of governance is an active decision with measurable consequences. Firms that have not implemented governance frameworks have, in effect, delegated decision-making authority to individual attorneys. This doesn't transfer liability. It concentrates it.
  1. Decentralized AI use produces an unstructured and difficult-to-defend risk profile. Without clearly defined and consistently applied standards, firms cannot demonstrate how AI is governed. This creates challenges in client conversations, regulatory scrutiny and claims scenarios.
  1. Governance must be operational, not theoretical. Policies alone are insufficient. Effective governance requires implementation, communication and ongoing monitoring. The relevant question is not whether a policy exists, but whether it's actively followed.
  1. Clear ownership is essential. AI governance requires accountability. While multiple stakeholders may contribute, responsibility for maintaining and evolving the framework must be clearly assigned.
  1. The opportunity for proactive governance is finite. Firms that act before a significant AI-related issue arises are establishing credibility and control. Firms that wait may find themselves reacting under pressure.
  1. AI governance is a leadership responsibility. It sits at the intersection of professional responsibility, client expectations and insurance risk. As such, it belongs within firm leadership discussions, not solely within technology or innovation functions.

The competitive dimension

AI governance is often framed as a compliance requirement. While that is accurate, it's not the full picture.

Firms with strong governance frameworks are also better positioned competitively. They can respond to client inquiries with clarity, demonstrate consistent standards and engage more confidently with insurers. They are also able to capture the efficiency benefits of AI while maintaining accountability and control.

Firms that treat governance as a leadership priority, rather than a downstream operational issue, will be better positioned to realize both outcomes.

Closing perspective

This article is the second in a two-part series on AI risk in law firms. The first article, "The Efficiency Tool That Became a Liability," examines the specific professional liability exposures created by AI adoption.

Read together, the two pieces provide a comprehensive view of both the risks and the governance structures required to manage them effectively.

View Now


Disclaimer

The information contained herein is offered as insurance Industry guidance and provided as an overview of current market risks and available coverages and is intended for discussion purposes only. This publication is not intended to offer financial, tax, legal or client-specific insurance or risk management advice. General insurance descriptions contained herein do not include complete Insurance policy definitions, terms, and/or conditions, and should not be relied on for coverage interpretation. Actual insurance policies must always be consulted for full coverage details and analysis. Insurance brokerage and related services provided by Arthur J. Gallagher Risk Management Services, LLC License Nos. IL 100292093 / CA 0D69293 © 2026 Arthur J. Gallagher & Co., and affiliates & subsidiaries | PRODUS202822