← All guides

Compliance and AI

Using AI in a law firm or regulated practice without taking on the liability

The question is not whether AI is useful to a regulated practice. It plainly is. The question is whether you can explain, defend and stand behind what it produced — and with a general-purpose chatbot, usually you cannot.

Law firms, immigration practices, clinics, financial advisers and public bodies share a problem: their work carries professional and legal obligations that do not disappear because a machine drafted the first version. This guide sets out the risks plainly, then the controls that address them.

The real risks

Invented authorities. Language models can produce confident text citing cases, sections or policies that do not exist, or that say something different from what is claimed. In legal and regulatory work this is the risk that does the most damage.

Confidentiality. Staff pasting client material into public AI tools may be sending it to a third party under terms the practice has never reviewed. Often this is already happening, because there is no approved alternative.

Decisions nobody can explain. If an eligibility assessment, a risk rating or a recommendation came from a model, can you say why it came out the way it did? Regulators and clients increasingly expect you to.

Stale information. Models know what they were trained on. Rules, thresholds and programme criteria change; an answer that was right last year may be wrong today.

Manipulated inputs. Documents and messages can contain instructions designed to steer an AI system — a risk whenever a model reads material from outside the firm.

What “governed” means in practice

The controls below are what we mean by governed AI. None of them is exotic; together they turn a liability into a tool.

  1. Answers grounded in your own sources. The system retrieves from material you have approved — legislation, policies, precedents — rather than answering from the model’s memory.
  2. Citations checked before they are shown. Every authority the model cites is verified against the source corpus, and an answer citing something that cannot be verified is withheld.
  3. Decisions in code, not in the model. Calculations, eligibility rules and thresholds run as deterministic rules. The model explains and drafts; the code decides.
  4. A person approves what matters. Anything leaving the practice passes through a review and approval step that cannot be skipped.
  5. A record of every call. What went in, what came out, which sources were used and who approved it — so any output can be traced and defended.
  6. Data kept to the minimum. Client identifiers and personal information stay out of the AI layer unless the task genuinely needs them.
  7. Freshness tracked. Time-sensitive sources carry a last-updated date, and answers that depend on them say so.

Where AI helps today

  • Research over your own precedents, templates and knowledge base.
  • First drafts from approved templates, reviewed before they go anywhere.
  • Intake triage — sorting enquiries and extracting key facts for a person to review.
  • Document classification and extraction.
  • Checking outgoing material against advertising, anti-spam or conduct rules before it is published.

Where it should not decide

Eligibility, advice, deadlines, anything that commits the practice. AI can prepare the material for those decisions; a qualified person should make them.

Questions to ask any AI vendor

  1. Where do the answers come from — the model’s memory, or our sources?
  2. How are citations verified, and what happens when one cannot be?
  3. Which parts of the decision are rules in code, and which are model output?
  4. Where is our data processed and stored, and is it used to train anyone’s model?
  5. What is recorded for each output, and can we export it?
  6. How does a person approve output before it leaves the practice?

These are the questions our governed AI systems are built to answer — and the privacy side is covered in our guide on privacy by design under Canadian law.

Where Elarion fits

Governed AI systems

Retrieval, drafting and classification — with governance attached. Approval state, provenance back to a source, and a human in the loop where the cost of being wrong is real.

30 minutes, free. Bring the problem, or the document you already have.

Related guides