In many law firms, the adoption of artificial intelligence (AI) hasn't been the result of a formal leadership decision. It has occurred organically, driven by individual attorneys selecting tools, developing workflows and applying their own judgment about what to verify, what to disclose and what to trust.
That is not a technology policy. It's the absence of one. And the consequences of that absence sit with firm leadership, regardless of whether leadership was directly involved in the decisions that created it.
The companion article in this series examined where AI creates professional liability exposure, including hallucinations, supervision gaps, confidentiality risk and evolving disclosure obligations. This article addresses the structural issue beneath those risks: what happens when AI governance is treated as an individual attorney decision rather than a leadership mandate and why that approach introduces material and often underappreciated exposure.
What decentralized AI use looks like in practice
In firms without formal AI governance, the reality is often uneven and largely invisible at the institutional level.
A litigation partner may rely on one AI tool for drafting and deposition preparation, with a self-developed verification process. In another practice group, an associate may use a different tool, potentially one not designed for legal work, and may input client-specific details to improve results. In other areas of the firm, adoption may be extensive or nonexistent, with little awareness across practice groups.
In many cases:
- No centralized inventory of tools exists
- No formal evaluation of how tools handle client data has been conducted
- No defined supervision standards govern AI-assisted work
- No consistent approach to disclosure has been established
Individual attorneys make decisions independently, based on their own risk tolerance and familiarity with technology. The firm lacks visibility into how AI is being used and cannot demonstrate to clients, courts or insurers what standards apply. This isn't an outlier scenario. It reflects the current state at many firms.
Our 2026 AI Adoption and Risk Survey found that fewer than half of organizations have implemented formal AI risk management frameworks, even as 63% have operationalized AI in some capacity. The gap between adoption and governance is not peripheral. It's central.
Why decentralized AI use creates compounding risk
The issue isn't simply the potential for individual mistakes. It's the structural impact on how the firm manages and defends its risk.
