Professional services

AI for law, accounting and advisory firms

Your people are already using AI on client work. The question is not whether to allow it — that decision was made for you — but whether you can evidence how it is being used when a client, a regulator or your insurer asks.

The day-to-day

What we see when we sit with your team

  • Fee earners are drafting with public AI tools, often on client matters, with no policy governing it.
  • Client engagement letters and confidentiality obligations were not written with AI in mind.
  • Nobody can produce a list of which tools are in use, let alone what has been entered into them.
  • The firm is simultaneously worried about the risk and worried about falling behind on efficiency.

Where the money goes

Four leaks, and the mechanism behind each

  1. Confidentiality exposure you cannot quantify

    Client-privileged material pasted into a consumer AI tool is a disclosure. The firm's difficulty is not usually the exposure itself — it is being unable to say what has been exposed, which makes every question unanswerable.

  2. Inconsistent output quality reaching clients

    Without a review standard, AI-assisted work varies enormously by who produced it. The failure mode is not obviously wrong output; it is plausible output that nobody checked.

  3. Client and insurer questions you cannot answer

    Client due diligence questionnaires and PI insurers now ask about AI governance directly. "We are looking into it" is an increasingly expensive answer.

  4. Efficiency gains that never reach the P&L

    Individuals get faster; the firm does not. Without changing how work is scoped, reviewed and billed, personal productivity gains stay personal.

What we would build

Specific to your operation, not a template

AI usage policy that fee earners will actually follow

Short, specific and written for practitioners rather than for a compliance file: what may be used, on what matters, with what data, and what must never leave the firm.

Approved tooling and data boundaries

A reviewed shortlist of tools with acceptable data handling, configured with the right retention and training settings, and least-privilege access to matter data.

Review and quality standards

A defined review step for AI-assisted work product, proportionate to matter risk, so the firm can evidence human oversight rather than assert it.

Client-facing position

Language for engagement letters, DDQ responses and insurer questionnaires that describes your controls accurately — which is only possible once the controls exist.

What we design around

The constraints specific to your sector

These are the things that make a generic build fail here. We treat them as hard requirements from day one, not as issues discovered in testing.

  1. Privilege is the binding constraint

    Every design decision starts from what may cross the firm boundary. Where a use case cannot be made safe, the answer is no, and we will say so rather than engineer around it.

  2. Policy without enablement fails

    A prohibition with no approved alternative produces shadow usage, which is worse than the original problem. Every restriction we recommend comes with a sanctioned route to do the same work.

  3. It has to survive partner scrutiny

    Policies that were not built with the people who will be governed by them do not last. We run this with partners in the room, not as a document delivered to them.

A realistic first quarter

What the first 90 days actually look like

Indicative, and it changes with your systems — but this is the shape, and the ordering is deliberate: lowest risk first, so the evidence arrives before the exposure does.

  1. Weeks 1–2

    Discover what is actually in use. Anonymous, non-punitive, and consistently more extensive than management expects.

  2. Weeks 3–4

    Draft the policy and the approved-tool list with a working group of partners and senior associates.

  3. Weeks 5–6

    Configure the approved tools properly — retention, training opt-out, access scope — and roll out with practical training.

  4. Weeks 7–13

    Add the review standard, then look at where AI genuinely changes the economics of a matter type.

FAQ

Professional services: your questions

Will you tell us to ban AI?

No. Bans do not work; they produce undocumented usage on personal devices. The objective is a sanctioned route that is good enough that nobody needs the unsanctioned one.

How do we handle what has already been exposed?

Honestly. We help you establish scope, assess materiality, and decide what needs disclosing. Most firms find the exposure is narrower than feared but broader than assumed.

Do you understand our regulatory obligations?

We work to your regulator's requirements and your professional obligations as the constraints on the design. We are technologists, not your legal advisers — where a question is legal rather than technical, we will say so and work alongside whoever advises you.

How long before this is defensible?

A firm with nothing in place today can have a written policy, a reviewed tool list and configured access inside four weeks. The harder part — changing habits — takes a quarter.