Organizations are introducing generative AI into legal, compliance, and regulatory workflows—for contract drafting, policy summarization, regulatory research, and review of complex filings—without the governance those applications require. This creates confidentiality breaches, privilege waivers, inaccurate advice treated as legal opinion, and exposure to claims of unauthorized practice of law. The question for general counsel and compliance officers is not whether to use these tools, but what must be in place before they are used for work that carries legal or regulatory consequence.
Why This Matters Now
Legal and compliance functions are under pressure to move faster and do more with fewer resources. Generative AI offers speed, but it operates on principles incompatible with how legal work is governed. Large language models do not preserve attorney-client privilege, cannot assess whether output is legally accurate, and have no mechanism to prevent confidential information from entering training data or being disclosed in other contexts. When business units or even legal operations staff adopt these tools without governance, the consequences land on general counsel: privilege is lost, regulatory filings contain fabricated citations, contracts include terms no lawyer reviewed, and the organization has no record of who approved what or on what basis.
This is not a theoretical risk. It is a gap in executive accountability that becomes visible when regulators ask how a filing was prepared, when opposing counsel seeks discovery of AI-assisted work product, or when an inaccurate summary is relied upon to make a compliance decision.
The Specific Risks Generative AI Introduces to Legal and Compliance Work
Confidentiality and Data Leakage
When a user submits a contract, regulatory filing, or internal legal memorandum to a generative AI tool, that content typically leaves the organization's control. Many commercial AI services retain input data for model improvement, quality assurance, or other purposes. Even where vendors assert they do not use customer data for training, their terms often permit human review, logging, or storage in ways that are incompatible with confidentiality obligations. If the tool is accessed via a public interface or a consumer-grade account, the risk is higher. Confidential business terms, merger details, unreported violations, and privileged legal analysis can all be exposed.
The obligation to protect this information does not disappear because a user found a faster way to work. General counsel remains accountable for ensuring confidential and privileged material is not disclosed to unauthorized parties, including AI vendors.
Attorney-Client Privilege and Work Product Waiver
Attorney-client privilege protects confidential communications made for the purpose of obtaining or providing legal advice. Sharing privileged communications with a third party can waive that protection. When a lawyer or legal team member submits privileged material—such as a draft legal opinion, an internal investigation memorandum, or litigation strategy notes—to a generative AI service operated by a vendor, that disclosure may constitute a waiver unless the vendor is acting as an agent of the legal team under strict conditions. Most AI service agreements do not establish that relationship. Privilege, once waived, cannot be reclaimed. This exposes the organization to compelled discovery of material that was previously protected.
Similarly, work product doctrine protects materials prepared in anticipation of litigation. If those materials are shared with an AI tool that stores, logs, or reviews them outside the litigation team's control, work product protection may also be lost.
Accuracy, Hallucination, and Legal Reliability
Generative AI produces output that is statistically plausible but not verified for legal accuracy. The tools generate text that can include fabricated case citations, incorrect interpretations of statutes, or contract terms that sound reasonable but create unintended obligations. This is commonly called hallucination. When that output is incorporated into a contract, filing, or compliance policy without independent legal review, the organization is relying on material that has not been checked for correctness. If a regulator questions the basis for a compliance position, or if a contract dispute turns on language drafted by AI, the organization cannot defend the work by saying it was generated by a tool.
The business consequences include regulatory penalties, failed audits, contract disputes, and loss of credibility with regulators or counterparties.
Unauthorized Practice of Law
Legal work must be performed or supervised by licensed attorneys. When non-lawyers use generative AI to draft contracts, render compliance opinions, or interpret regulations, and that output is used without lawyer review, the organization may be engaged in the unauthorized practice of law. This creates liability for the organization and for individuals who rely on or distribute the output. It also undermines the legal function's ability to maintain quality control over the advice the organization relies upon.
The risk is highest when business units or compliance staff treat AI output as legal advice and act on it without involving counsel.
Regulatory and Third-Party Contractual Obligations
Organizations subject to privacy regulations—including HIPAA, GLBA, COPPA, state privacy laws, and international frameworks—have specific obligations regarding how personal information is processed and disclosed. Using a generative AI tool that transmits personal data to a vendor without appropriate agreements, safeguards, or disclosures may violate those regulations. The Federal Trade Commission enforces obligations around privacy promises and data security under Section 5 of the FTC Act, and has issued guidance emphasizing that companies must honor their privacy commitments and maintain appropriate security for the data they hold, as described in the FTC's privacy and security resources. NIST's Privacy Framework offers a structured approach for organizations to identify and manage privacy risk, which becomes essential when introducing AI tools that process personal information.
Similarly, contractual confidentiality obligations to clients, customers, or partners may prohibit sharing their information with third-party AI services without consent. Breaching those terms creates liability and damages commercial relationships.
What Must Be in Place Before Deployment
Using generative AI responsibly in legal or compliance contexts requires governance that addresses confidentiality, privilege, accuracy, and regulatory obligations before the first document is submitted. The following controls are necessary, not optional.
Vendor and Data Handling Assessment
Before any legal or compliance content is shared with a generative AI service, legal and information security leadership must jointly assess the vendor's data handling practices. This assessment must answer:
- Where does input data go, and who has access to it?
- Is input data used for model training, quality review, or other purposes?
- Can the vendor guarantee that submitted content will not be disclosed, logged in a way accessible to other customers, or retained beyond the session?
- What contractual terms govern confidentiality and privilege? Does the vendor agreement establish the vendor as an agent of the legal department for purposes of privilege?
- Does the service comply with applicable privacy regulations (HIPAA, GLBA, state laws, GDPR where relevant)?
- What security controls protect data in transit and at rest?
If the vendor cannot provide satisfactory answers, the tool cannot be used for privileged, confidential, or regulated information. Consumer-grade AI services and free-tier accounts are presumptively unsuitable for legal work.
Defined Acceptable Use Policy
The organization must document, in writing, what uses of generative AI are permitted, prohibited, and conditionally allowed for legal and compliance work. This policy should specify:
- Which tools are approved for which purposes (drafting, summarization, research, review)
- What types of content may never be submitted (privileged communications, unreported violations, confidential third-party information, personal data subject to regulatory protection)
- What review and approval process applies before any AI-generated output is finalized or relied upon
- Who is authorized to use these tools and under what supervision
- How outputs must be documented and retained
The policy must be approved by general counsel and communicated clearly to all legal, compliance, and business staff who might use these tools.
Mandatory Lawyer Review of All Output
No AI-generated contract, legal memorandum, compliance policy, regulatory interpretation, or other legal work product may be finalized, distributed, or relied upon without independent review by a licensed attorney. The reviewing lawyer must verify accuracy, check citations, assess legal risk, and take responsibility for the final work product. This review cannot be cursory. The lawyer must apply the same standard of care as if they had drafted the document themselves.
Organizations should implement workflow controls that prevent AI outputs from bypassing legal review, such as requiring drafts to be routed through the legal department before distribution.
Documentation and Audit Trail
When AI is used to assist in preparing legal or compliance documentation, the organization must maintain a record of:
- What tool was used and for what purpose
- What content was submitted to the tool
- What output was generated
- Who reviewed the output and what changes were made
- Who approved the final document and on what date
This audit trail supports privilege claims, responds to regulator inquiries, and establishes that appropriate review occurred. It also enables the organization to assess whether its controls are working.
Privacy Impact and Regulatory Compliance Assessment
If the legal or compliance work involves personal information, protected health information, financial data, or other regulated content, a privacy and regulatory compliance assessment is required before using AI tools. This assessment should reference frameworks such as the NIST Privacy Framework to systematically identify privacy risks and determine what safeguards are necessary. The assessment must confirm that the planned use complies with HIPAA, GLBA, COPPA, state privacy laws, FTC Act requirements, and any contractual data protection obligations. Where the assessment identifies risks that cannot be mitigated, the use case must be rejected.
Training and Awareness
Lawyers, compliance staff, and any business personnel with access to generative AI tools must receive training on:
- The risks these tools pose to confidentiality, privilege, and accuracy
- The organization's acceptable use policy and approval workflows
- How to recognize when output requires legal review
- How to document AI-assisted work appropriately
Training must be repeated when new tools are introduced or when policies change. The goal is to ensure that every potential user understands the stakes and knows when to stop and seek guidance.
Who Owns This and What Adequate Ownership Looks Like
Accountability for AI governance in legal and compliance contexts cannot be delegated to IT, to individual lawyers, or to business units. This is an executive responsibility that requires coordination across general counsel, the chief information security officer, compliance leadership, and enterprise risk management. The work includes strategy, policy development, vendor negotiation, regulatory interpretation, and ongoing oversight. It is the kind of cross-functional, risk-focused leadership that [a virtual CISO (vCISO) engagement](/vciso/) is designed to provide: an executive who owns the governance framework, aligns it with legal and regulatory requirements, reports to leadership on progress and risk, and ensures accountability is clear.
Adequate ownership means one named executive is responsible for:
- Approving the AI governance policy and acceptable use standards
- Overseeing vendor assessments and contract negotiations for AI tools used in legal or compliance work
- Ensuring that privacy, confidentiality, and privilege risks are assessed before new use cases are approved
- Establishing and enforcing the mandatory legal review process
- Reporting to the board or executive leadership on AI use, risk exposure, and control effectiveness
- Coordinating with general counsel on regulatory obligations and with information security on technical safeguards
Without this level of ownership, the organization will have policies that are not followed, tools deployed without oversight, and risk exposure that becomes visible only when something goes wrong.
How This Relates to AI and Emerging Technology Governance
The controls described here are a specific application of broader AI and emerging technology governance principles. Organizations that have already established governance for AI—covering risk assessment, acceptable use, data handling, human oversight, and accountability—are better positioned to extend those controls to legal and compliance use cases. Organizations that have not yet built that governance foundation will find it difficult to address AI in legal contexts in isolation.
The NIST Cybersecurity Framework, updated in version 2.0, provides a structure for managing cybersecurity risks at the enterprise level and can support the technical and organizational controls required for AI governance. While the Cybersecurity Framework does not prescribe AI-specific policies, its outcomes-based approach to risk management, asset management, and governance aligns with the need to treat AI tools as material enterprise risks requiring executive oversight.
Effective AI governance integrates legal, technical, privacy, and operational perspectives. It requires leadership that can translate regulatory requirements into practical controls, negotiate with vendors on behalf of the organization's risk posture, and report to boards and executives on what is in place and where gaps remain.
Practical Next Steps for General Counsel and Compliance Leadership
If your organization is considering or already using generative AI for legal or compliance work, the following steps should be taken immediately:
- Conduct an inventory of all generative AI tools currently in use or under consideration by legal, compliance, or business staff for work involving contracts, policies, filings, or legal research
- Assess each tool's data handling practices and contractual terms, with particular attention to confidentiality, privilege, and regulatory compliance
- Draft and approve an acceptable use policy that clearly defines what is permitted, prohibited, and conditionally allowed, and communicate it to all relevant staff
- Establish a mandatory legal review workflow that prevents AI-generated legal or compliance documentation from being finalized or relied upon without attorney oversight
- Assign clear executive accountability for AI governance, with authority to approve use cases, oversee vendor relationships, and report on risk
- If privacy-sensitive or regulated data is involved, conduct a privacy impact assessment referencing the NIST Privacy Framework before proceeding
- Implement documentation requirements so that AI-assisted work can be audited and defended if questioned by regulators or opposing counsel
- Provide training to legal, compliance, and business staff on the risks, policies, and procedures that govern AI use
This work requires coordination, judgment, and sustained attention. If your organization does not have the internal capacity or executive ownership to establish and enforce these controls, a confidential consultation can clarify what is required, what the regulatory and legal risks are, and how to close the governance gap. Heights Consulting Group offers a single consultation to general counsel and compliance leadership who need an independent assessment of their AI governance posture and a roadmap for responsible use. That consultation is available once, at the point where leadership is ready to act. To explore whether it would be useful, contact Heights directly.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: AI and Emerging Technology Governance
Governance for how your organization adopts artificial intelligence: approved uses, data handling boundaries, review before deployment, and accountability for the output.