GOVERNANCE RISK

The Most Common Gaps in Law Firm AI Governance

Most lists of governance gaps describe the gap. This one gives you the test, because the useful question is not what a gap is but whether your firm has it, and the answer is usually one conversation away.
CounselRisk AI Governance Framework

Author

CounselRisk Editorial
Executive Summary
Each gap below carries a test with a checkable answer and a note on who is likely to find it first. That second part is the uncomfortable one. On our reading only three of the fourteen are ones a firm is likely to find by looking. The rest tend to surface through a client, a court, opposing counsel, a carrier, or an incident, which means they are found on someone else’s schedule rather than at the cheapest moment.

A word on “most common”

Nobody has published frequency data on which AI governance gaps law firms actually have. Any article claiming a ranking is guessing, and a ranking would not help much anyway, because the gap that matters at your firm is the one you have.

So this is not a ranking, and the four groupings below are an organizing choice rather than a finding. What the list is organized around is the duties ABA Formal Opinion 512 actually addresses, plus the operational conditions those duties depend on. The value is in the tests.

Two caveats that apply throughout. Opinion 512 is advisory and the ABA Model Rules bind no lawyer until a jurisdiction adopts them. Three places tell you what actually governs your firm: your own state’s rules of professional conduct, your state or city bar’s ethics opinions, and the individual rules and standing orders of the courts you appear in. Opinion 512 itself draws on several state opinions worth reading if they are yours, among them Florida’s Opinion 24-1, the Pennsylvania and Philadelphia joint opinion 2024-200, West Virginia’s Opinion 24-01, California’s Opinion 2023-208 and DC Bar Opinion 388.

And several tests below presuppose that you can identify which tools are in use. If you cannot, that inability is itself the finding, and it is Gap 1.

Cluster one: what the firm does not know

These four are prerequisites. A firm with any of them open cannot close the others, because the later work has no object.

Gap 1: No one can name the tools in use

A firm generally knows about the tool it bought. Under Rule 1.1, Opinion 512 says lawyers “must have a reasonable understanding of the capabilities and limitations of the specific GAI technology that the lawyer might use.” That standard attaches to a specific product, so it cannot be assessed until the products are known.

It is also a more modest standard than it first appears, and the modest version is the one worth knowing. The opinion says plainly that “lawyers need not become GAI experts,” and that they should “either acquire a reasonable understanding of the benefits and risks of the GAI tools that they employ in their practices or draw on the expertise of others who can provide guidance about the relevant GAI tool’s capabilities and limitations.” The understanding can be concentrated in a competent person. The not-knowing cannot be delegated to anyone.

The test. Ask three practice group leaders, separately, to list by task every place AI was used in their group last month. Not which tools they use, which produces only the products with recognizable names. Compare the lists to each other and to what IT believes is in use.

Who finds it first. The firm, if it looks. Otherwise a client questionnaire, which asks the same question in writing and expects a complete answer.

What closing it takes. An inventory taken by task, and a decision made in advance about how the firm will treat what it finds. The discrepancy between the three lists is the floor of the gap, not its size, since the tools nobody named are by definition not in the discrepancy.

Gap 2: The AI already inside purchased software is uncounted

The tools easiest to miss are the ones nobody bought separately: the summarize function in the meeting platform, the drafting assistance in the word processor, the AI features added to the research subscription. There was no procurement decision, so nothing triggered a review, and the feature arrived under a license signed before the feature existed.

The test. List the firm’s five largest software subscriptions. For each, have someone check the vendor’s release notes and the admin console for AI features added since the contract was signed, and whether they are enabled by default. Release notes and tenant settings are the authoritative record here; a sales contact’s recollection is not.

Who finds it first. Often nobody, until a client asks whether client data has been processed by an AI system and the accurate answer turns out to be yes.

What closing it takes. Treating feature releases as governance events, and a register entry per feature rather than per vendor.

Gap 3: Nobody has read the vendor terms

A firm can have an approved tools list where no one has established what the vendors do with the inputs. In its discussion of supervisory responsibilities, Opinion 512 notes that ethics opinions developed for cloud computing and outsourcing, principally Florida Bar Advisory Opinion 12-3 and Iowa Ethics Opinion 11-01, “suggest that lawyers should” do four things. In the opinion’s order: “ensure that the [GAI tool] is configured to preserve the confidentiality and security of information, that the obligation is enforceable, and that the lawyer will be notified in the event of a breach or service of process regarding production of client information”; “investigate the [GAI tool’s] reliability, security measures, and policies, including limitations on the [the tool’s] liability”; “determine whether the [GAI tool] retains information submitted by the lawyer before and after the discontinuation of services or asserts proprietary rights to the information”; and understand that provider servers “are subject to their own failures and may be an attractive target of cyber-attacks.”

The test. Pick the tool your firm uses most. Ask whoever owns it four questions: does it train on our inputs, what happens to our data if we leave, does the vendor have to tell us if it is served with process for our material, and what is the liability cap. The failure condition is not whether the answers come from memory. It is whether they can be produced from the contract within one business day.

Who finds it first. A client audit under outside counsel guidelines, or the day a vendor is served.

What closing it takes. One competent reader per contract. Opinion 512 says that “[a]s a baseline, all lawyers should read and understand the Terms of Use, privacy policy, and related contractual terms and policies of any GAI tool they use to learn who has access to the information that the lawyer inputs into the tool or consult with a colleague or external expert who has read and analyzed those terms and policies.” The reading can be delegated. Knowing the answer cannot.

Gap 4: Personal accounts are outside everything

A partner using a personal subscription on a personal device sits outside the firm’s enterprise agreement, which means the vendor terms the firm negotiated and recorded do not govern that use, and outside every control built on top of them.

The test. Pull ninety days of expense reimbursements and firm card statements and search for AI vendor names. Separately, ask IT for the list of unmanaged software-as-a-service domains seen on the firm network. The count that comes back is a floor, not a total, and a floor above zero is the finding.

Who finds it first. Typically an incident, because this is the route with the least visibility.

What closing it takes. Firm-provided access good enough that the personal account is not the more convenient option, which is a procurement decision before it is a policy one, plus a rule that names the practice rather than implying it.

Cluster two: who is not deciding

Gap 5: Ownership is assumed rather than assigned

Opinion 512 reads Rules 5.1 and 5.3 to mean that “[m]anagerial lawyers must establish clear policies regarding the law firm’s permissible use of GAI, and supervisory lawyers must make reasonable efforts to ensure that the firm’s lawyers and nonlawyers comply with their professional obligations when using GAI tools.” Model Rule 5.1(a) reaches a partner in a law firm, and a lawyer who individually or together with other lawyers possesses comparable managerial authority. In many firms the responsibility is understood to sit somewhere between leadership, IT, operations and risk, which means it sits nowhere.

Worth reading alongside 5.1(a) is Rule 5.1(c), which is the provision that makes this personal rather than administrative. It makes a lawyer responsible for another lawyer’s violation where the lawyer ordered or ratified the conduct, or where the lawyer is a partner or has comparable managerial or direct supervisory authority and knows of the conduct at a time when its consequences could be avoided or mitigated and fails to take reasonable remedial action. Knowing about ungoverned use and not acting is the exposure, not the ungoverned use itself.

The test. Ask three people, chosen from different functions, who owns AI governance at the firm. If you get three answers, or a committee name with no individual attached, that is the gap.

Who finds it first. The firm, but only at the moment of the first real request, when nobody moves. That is discovery by stall rather than by audit.

What closing it takes. Three names: one lawyer accountable, one person who maintains the register, and named reviewers for the technical and the confidentiality questions. Rule 5.1(a) does contemplate managerial authority held jointly, so a committee is not wrong as a matter of the rule, and a firm that governs by committee can keep doing so provided one named person can answer between meetings. The practical problem is only that a committee meeting quarterly cannot answer a request that arrives in week two.

Gap 6: There is no approval route, so people approve themselves

Where there is no practical way to ask, the decision still gets made, privately and inconsistently. Different lawyers reach different conclusions about the same tool, and the firm cannot state which tools are approved, restricted, or under review.

The test. Name the last new AI tool your firm started using. Who approved it, on what date, against what criteria, and where is that recorded? If you cannot identify a last new tool at all, that is Gap 1 rather than this one.

Who finds it first. A client asking how the firm evaluates AI tools. Corporate legal departments now have a published question list for evaluating outside counsel’s AI use, covering policies, accountability, data handling, quality control and billing.

What closing it takes. A short form and a named approver, with a lighter lane for uses that involve no information relating to a representation. If the same heavyweight process governs both an experiment and a client-data workflow, the design gives people a reason not to report the experiment.

Gap 7: Conflicts and ethical walls are not part of the analysis

This one is specific to self-learning tools. Opinion 512 warns that such a tool may disclose information to people in the firm “who either are prohibited from access to said information because of an ethical wall” or who “could inadvertently use the information from one client to help another client, not understanding that the lawyer is revealing client confidences.” A screen that holds in the document management system does not necessarily hold inside a tool that learns from what everyone puts into it.

The conflicts authority sits in the opinion’s footnotes rather than its text. Footnote 4 cites the Pennsylvania and Philadelphia joint opinion for the proposition that because large language models continue to develop, “some without safeguards similar to those already in use in law offices, such as ethical walls, they may run afoul of Rules 1.7 and 1.9 by using the information developed from one representation to inform another.”

The test. Take a matter currently behind an ethical wall. Ask two questions: is any AI tool touching that matter also available to lawyers on the other side of the wall, and does that tool retain and reuse inputs across users. The second is a vendor architecture question, which means it routes to Gap 3 rather than to a colleague. If the firm has no screened matter right now, run this on the next one and treat it as a precondition of the screen rather than a review of it.

Who finds it first. Opposing counsel, in a disqualification motion.

What closing it takes. A conflicts question on the approval form, and treating screened matters as their own category rather than as ordinary work with a note attached.

Cluster three: what the rules do not say clearly enough

Gap 8: The confidentiality rule is too general to apply

A common formulation is that confidential information should not be entered into unapproved tools. That sentence does not say whether matter facts may be summarized, whether client names may be used, whether a draft with identifying content may be processed, or what changes when a tool has contractual protections.

It is also usually pitched at the wrong standard. Opinion 512 describes the Rule 1.6 duty as covering all information relating to the representation of a client, “regardless of its source, unless the client gives informed consent, disclosure is impliedly authorized to carry out the representation, or disclosure is permitted by an exception.” That is broader than “confidential” and broader than “client identifying.” Note that implied authorization is fact-specific rather than a category a policy can simply claim, and that for self-learning tools the opinion routes to informed consent instead, which is Gap 9.

The same passage carries a sentence that is easy to miss: “Model Rules 1.9(c) and 1.18(b) require lawyers to extend similar protections to former and prospective clients’ information.” An intake chatbot may be within it, depending on whether the exchange amounts to a consultation under Rule 1.18(a) rather than a unilateral communication, which is a live question rather than a settled one.

The test. Take your written rule to two associates in different practice groups and give each the same three realistic scenarios. The failure condition is divergence: if they reach different answers, the rule is a principle rather than a control. Escalating to supervision is correct behavior and is not the failure. If there is no written rule to test, that is the gap and the test does not need to run.

Who finds it first. Often nobody, until an incident, which is what makes this gap expensive rather than untidy.

What closing it takes. Categories of information mapped to actual tools, at a level of specificity a person can apply alone, with the no-input uses named so people know what is freely available to them.

Gap 9: There is no consent position for self-learning tools

Opinion 512 states that “because many of today’s self-learning GAI tools are designed so that their output could lead directly or indirectly to the disclosure of information relating to the representation of a client, a client’s informed consent is required prior to inputting information relating to the representation into such a GAI tool.” It then closes the shortcut most firms reach for: “merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use GAI is not sufficient.”

Two things determine whether the duty attaches at all, and both are answerable. Whether the tool trains on inputs is a contract and configuration question, which is Gap 3’s territory; the answer can differ between tiers of the same product and can change with a release, so it is a fact about your agreement rather than about the product name. And whether information relating to the representation is going in at all. The opinion is explicit that consent is not required where it is not: “Today, there are uses of self-learning GAI tools in connection with a legal representation when client informed consent is not required because the lawyer will not be inputting information relating to the representation,” with idea generation as its example, expressly qualified as being “in a manner that does not require inputting information relating to the representation.”

The test. List every tool on your approved list. For each, state whether it is self-learning and whether information relating to a representation goes into it. Where both are true, ask to see the consent script. Then check it against what the opinion requires: the lawyer’s best judgment about why the tool is used, “the extent of and specific information about the risk, including particulars about the kinds of client information that will be disclosed, the ways in which others might use the information against the client’s interests, and a clear explanation of the GAI tool’s benefits to the representation,” plus the element specific to these tools, “the extent of the risk that later users or beneficiaries of the GAI tool will have access to information relating to the representation.” A missing element means the consent is not informed.

Who finds it first. A sophisticated client, or the firm’s own lawyer improvising the conversation and later being unable to evidence what was said.

What closing it takes. A drafted position per self-learning tool, and a named set of uses that fall inside the no-input carve-out so that people have somewhere legitimate to go. Note that the carve-out removes the consent requirement only; competence, verification, supervision and the vendor-terms questions all still apply.

One qualification the opinion attaches to this holding and almost nobody quotes. Footnote 34, appended to the consent conclusion itself, begins: “This conclusion is based on the risks and capabilities of GAI tools as of the publication of this opinion. As the technology develops, the risks may change in ways that would alter our conclusion.” The duty this gap describes is expressly provisional, which is a reason to build a way of re-asking rather than a settled answer. That mechanism is Gap 14.

Gap 10: Verification is a principle, not a standard

“Lawyers remain responsible for their work” is true, and it is not a control. Opinion 512 is explicit that the required amount of review “will necessarily depend on the GAI tool and the specific task that it performs as part of the lawyer’s representation of a client,” and it works an example: a lawyer using a tool to summarize numerous lengthy contracts “would not necessarily have to manually review the entire set of documents to verify the results if the lawyer had previously tested the accuracy of the tool on a smaller subset of documents by manually reviewing those documents,” comparing them to the summaries and finding them accurate.

The review it describes is broader than citation checking. Before materials go to a court, duties to the tribunal require lawyers to “review these outputs, including analysis and citations to authority, and to correct errors, including misstatements of law and fact, a failure to include controlling legal authority, and misleading arguments.” The opinion also states that “[e]ven an unintentional misstatement to a court can involve a misrepresentation under Rule 8.4(c).” That is a broad reading, and the opinion does not say how far 8.4(c) reaches without a showing of intent, which is a reason to have a verification standard rather than to rely on the argument.

The test. Pick a filing from the last quarter that involved AI assistance. Ask what verification standard applied, who applied it, and where that is recorded. If you cannot identify such a filing, that is Gap 1. If the answer is that the lawyer reviewed it, ask how the firm would establish that eighteen months from now.

Who finds it first. A court, after a filing, publicly.

What closing it takes. A standard set by task type, with the sample testing recorded where sample testing is what justifies the level of review.

Gap 11: There is no written position on billing

Lists like this one tend to skip billing, and it is the gap with a direct line to the invoice. Opinion 512 addresses fees at length.

Hourly billing must reflect time actually spent. Flat and contingent arrangements are not a way around it: “if using a GAI tool enables a lawyer to complete tasks much more quickly than without the tool, it may be unreasonable under Rule 1.5 for the lawyer to charge the same flat fee when using the GAI tool as when not using it.”

On learning time the rule has an exception firms should know about. A lawyer “may not charge a client to learn about how to use a GAI tool or service that the lawyer will regularly use for clients because lawyers must maintain competence in the tools they use, including but not limited to GAI technology.” But the opinion continues: “However, if a client explicitly requests that a specific GAI tool be used in furtherance of the matter and the lawyer is not knowledgeable in using that tool, it may be appropriate for the lawyer to bill the client to gain the knowledge to use the tool effectively.” It adds that before billing, the lawyer and the client should agree on any new billing practices or terms and, preferably, memorialize the new agreement.

On cost, the opinion draws a workable boundary rather than leaving it abstract. Where a tool “functions similarly to equipping and maintaining a legal practice,” its cost should be treated as overhead and not charged absent contrary disclosure in advance. Its own worked contrast: an AI grammar checker embedded in the firm’s word processing software is overhead, whereas a third-party provider’s service charged per use to review thousands of contracts for one client is one where “it would ordinarily be reasonable for the lawyer to bill the client as an expense for the actual out-of-pocket expense incurred for using that tool.” Procedurally: “before charging the client for the use of the GAI tools or services, the lawyer must explain the basis for the charge, preferably in writing.”

The test. Ask four partners, from different practice groups and including at least one who does alternative fee work, how AI-assisted time is billed, whether tool cost is overhead or an expense, and what happens on a flat fee matter where a tool compressed the work. Four answers means no position.

Who finds it first. A client’s legal operations group, because billing is where AI use becomes visible to someone reading an invoice.

What closing it takes. A written position covering time, alternative fee arrangements, learning time and cost classification, agreed at the partnership level rather than left to each partner.

Gap 12: Client communication triggers are undefined

Rule 1.4 governs here, and Opinion 512 imposes no blanket duty to disclose AI use, which is sometimes read as no duty at all. It identifies situations instead: if the client asks, if the engagement agreement or the client’s outside counsel guidelines require it, if the lawyer proposes to input information relating to the representation, if the use is relevant to the basis or reasonableness of the fee, and where output “will influence a significant decision in the representation,” such as reliance on the tool to evaluate potential litigation outcomes or jury selection. It adds a further case where a client retained the lawyer for particular skill and judgment and undisclosed use would defeat the engagement terms or the client’s reasonable expectations.

The list is expressly open. The opinion says: “It is not possible to catalogue every situation in which lawyers must inform clients about their use of GAI,” and directs lawyers to weigh the client’s needs and expectations, the scope of the representation, and the sensitivity of the information involved.

The test. Ask two partners what they would say if a client asked tomorrow whether AI was used on their matter. If the answers differ, the firm has delegated a client-communication decision to whoever picks up the phone.

Who finds it first. The client, by asking.

What closing it takes. A decision on each identified trigger, written down and known to the people who answer client calls, plus a route for the situations the list does not cover, since the opinion says there will be some.

Cluster four: what the firm could not show

Gap 13: Training is generic, and there is no record of it

A single all-hands session is an announcement. Different roles face different decisions: attorneys need the input rules and the verification standard, practice group leaders need the supervisory expectations, staff need tool boundaries, and approvers need the criteria. Opinion 512 treats training as part of the supervisory duty and says it “could include the basics of GAI technology, the capabilities and limitations of the tools, ethical issues in use of GAI and best practices for secure data handling, privacy, and confidentiality.”

The test. Ask who at the firm has been trained on AI use, when, and on what. If there is no list, the firm cannot demonstrate the supervisory effort it may later need to describe.

Who finds it first. A carrier, or a client. AI governance is increasingly part of professional-risk and insurer conversations.

What closing it takes. Role-differentiated content and an acknowledgment record. Also worth adopting: the convention Opinion 512 suggests in a footnote, that material produced by these tools be marked as such “when stored in any client or firm file so future users understand potential fallibility of the work.”

Gap 14: The register is stale, and nobody owns it

A register is accurate the day it is written. Without a named owner and a review trigger it drifts, and people keep relying on it while it does. Opinion 512 built the same logic into its own conclusion. Footnote 34, attached to the informed-consent holding, begins: “This conclusion is based on the risks and capabilities of GAI tools as of the publication of this opinion. As the technology develops, the risks may change in ways that would alter our conclusion.”

The Committee treated its own answer as provisional. A firm’s answers are provisional too.

The test. Open the register. When was each entry last verified, and by whom? If entries carry no date, or the most recent verification predates updates the tools have shipped since, the register describes a firm that no longer exists. If there is no register, this gap is not yet reachable and the work is in cluster one.

Who finds it first. The firm, if it audits its own entries. Otherwise whoever relies on it, meaning a lawyer making a decision on a fact that stopped being true.

What closing it takes. A named owner and event triggers rather than calendar reviews: a vendor changes terms or ships a feature, someone requests a tool not on the register, a court the firm appears in adopts an AI rule, or a client sends a questionnaire.

Who is likely to find each of these

Likely first discovererGapsTiming
The firm, if it looks1, 5, 14On its own schedule, but only Gap 1 without a prompt
A client, or their outside counsel guidelines2, 3, 6, 9, 11, 12On their schedule, in writing, with a deadline
A carrier13At renewal
A court10After a filing, publicly
Opposing counsel7In a motion
An incident4, 8Without warning

This is our reading rather than an observed distribution, and reasonable people would move some rows. What is hard to move is the shape: most of these are found by someone with their own timetable. That is the argument for looking on purpose.

If you only run three tests

Gap 1, because most of the other tests presuppose you can identify the tools in use. Specifically, Gaps 3, 6, 7, 8, 9, 10 and 14 all take the tool list as their starting point, which is why cluster one comes first. Gap 3 on your single most-used tool, because whether it trains on inputs is the switch that turns on the consent obligation in Gap 9 and much of the confidentiality analysis in Gap 8. And Gap 11, because it is the one a client’s legal operations group reaches first and the one most likely to be a partnership conversation rather than an administrative fix.

The gap underneath the others

Where a firm has addressed AI at all, it has usually done so with a policy document. That is a reasonable start and a different thing from a governance system, which is an approval route, a register, a classification method, defined ownership, role-based training, review expectations, and a process for updates and exceptions. A policy states positions; a governance system produces records, and every test above asks for a record. An AI policy is not AI governance.

If you want a structured version of these tests scored against your own firm, the AI Governance Readiness Assessment takes about three minutes.


CounselRisk builds and operates governance machinery for law firms. This article is general information and not legal advice. Formal Opinion 512 is advisory, and the ABA Model Rules are not binding until adopted by a jurisdiction, so jurisdiction-specific conclusions belong to the firm and its counsel. CounselRisk is operated by QbitBrains LLC.

Key Takeaway
On our reading, eleven of these fourteen are more likely to surface through a client, a court, opposing counsel, a carrier or an incident than through the firm itself. Which is an argument for looking on purpose.
COUNSELRISK GOVERNANCE FRAMEWORK

Governance you can show, not a policy you can circulate

The tools register, the approval route, the input and consent positions, the verification standard and the billing position, in a form a client or a court can be shown. 16 policy sections and 12 operational appendices, delivered immediately in PDF and editable Word. Structured around the ABA Model Rules and Formal Opinion 512.

RECENT INSIGHTS

ABA Guidance

What ABA Formal Opinion 512 Means for Law Firm AI Governance

ABA Formal Opinion 512 clarifies how existing professional responsibility rules apply to generative AI. This article explains what the opinion requires in practice and why firms need documented governance controls.

GOVERNANCE IMPLEMENTATION

How to Roll Out an AI Governance Policy in a Midsize Firm

Recognizing the need for AI governance is only the first step. This guide outlines a practical rollout structure for midsize firms, including approval workflows, tool registers, and internal oversight controls.

GOVERNANCE RISK

The Most Common Gaps in Law Firm AI Governance

Many firms adopt AI tools informally without clear governance controls. This article examines the most common structural gaps and explains how those gaps create professional responsibility and operational risk.