Can law help build ethical AI systems by design, or does ethics resist formalization? In earlier posts, I argued that ethics is about reasoned judgement under uncertainty, and that regulation can create clarity where organizations otherwise struggle. With today’s post I want to connect law and ethics to technical implementation; specifically, the role that law can play in facilitating ethical data practices by design. Privacy professionals are well familiar with this concept, as epitomized by Art. 25 GDPR which requires organizations to implement data protection by design and default. But as Prof. Christian Djeffal outlines in a recent article, law by design has since become a fixture of EU law: Law by design translates legal and ethical goals into technical and organizational obligations. At the same time, it deliberately leaves discretion as to implementation. ➡️ What law can do well Frameworks like the GDPR and the AI Act show how law can meaningfully support ethical data practices by design: ✅ They shape how organizations structure the lifecycle of data processing, starting with an initial assessment of the necessity and proportionality of processing. ✅ They require organizations to clearly define roles and responsibilities from the beginning, and document any relevant risks. ✅ They encourage organizations to seek diverse perspectives when developing and deploying new technologies, thus reflecting the inherently interdisciplinary nature of sociotechnical design. ➡️ What this means for ethical AI Ethics is no longer a nice-to-have when it is hardcoded into legal requirements. As I argued in my master's thesis, the AI Act, for instance, translates ethical obligations into technical requirements, specifically mandating: ✅ Respect for human autonomy by requiring human oversight of the development and deployment of AI systems. ✅ The prevention of harm through accuracy, robustness, and security. ✅ Fairness and explainability through robust data governance and record-keeping. ➡️ Where law reaches its limits At the same time, law by design does not resolve any dilemmas or trade-offs. Ethical behavior is not a technological fact, but the result of human deliberation. Procedure matters just as much as outcome, and legal requirements alone do not tell organizations how to weigh competing priorities in practice. ➡️ What this means for leaders on ethical AI Law by design is not a shortcut to ethical AI. But it can create the right incentives. Leaders should: ✅ Leverage law by design requirements as a foundation for responsible data processing. ✅ Facilitate ethical deliberation to translate law by design requirements into concrete deliverables. ✅ Open up the room for innovation by, in Djeffal's words, "prompting the development of solutions where none yet exist." Link to Djeffal's article: https://bit.ly/45Sj76P. #ResponsibleAI #AIGovernance #DataEthics #Leadership
Legal Technology Consulting
Explore top LinkedIn content from expert professionals.
-
-
If you use GenAI… I want to hold you… accountable. As AI becomes a key tool in legal practice, ensuring ethical use is critical. This condensed framework is based on ABA guidelines and other regulatory standards, balancing efficiency with accountability. 1. Competence Lawyers must understand AI’s capabilities and risks, such as inaccuracies or biases. Regular training is crucial for staying updated. 2. Confidentiality Client data must be protected when using AI tools. Anonymize sensitive data and ensure AI systems are secure. 3. Transparency Lawyers must inform clients about AI use, particularly when it impacts legal services or fees, fostering transparency and trust. 4. Verification of Outputs AI-generated outputs must be reviewed for accuracy to avoid errors like false citations, ensuring the integrity of legal work. 5. Reasonable Fees Fees must be reasonable and reflect the actual work performed. When using AI, this means that lawyers can charge for tasks like inputting data into AI tools and verifying the AI-generated results. However, lawyers should not bill clients for time saved due to AI’s efficiency, unless the client has specifically agreed to this arrangement in advance. This ensures transparency and fairness in billing practices. 6. Addressing Bias Firms should actively mitigate AI biases that could lead to unfair outcomes, particularly in sensitive legal areas . 7. Supervision Supervisory lawyers must ensure that AI use complies with ethical standards, implementing policies and training to manage AI responsibly.
-
We have been deploying RLM-style architectures for enterprise clients over the past months, and the implementation lessons are significant. The use cases driving adoption include:- - Regulatory compliance:- Organizations are analyzing thousands of pages across evolving frameworks such as GDPR, AI Act, and NIST AI RMF. Traditional approaches often hit context limits or hallucinate. Recursive patterns allow us to trace every conclusion back to source clauses. - Enterprise knowledge work:- Teams are overwhelmed by documentation, codebases, and institutional knowledge. RLMs effectively handle what RAG systems struggle with: multi-hop reasoning across massive, heterogeneous datasets. - Security audits:- Analyzing entire codebases for vulnerabilities is now possible. The ability to recursively decompose and reason over 100K+ line repositories transforms automated review capabilities. Key lessons learned from implementing these systems include:- - Architecture beats brute force:- Using larger context windows can be costly and often ineffective. Teaching systems to intelligently decompose problems is more efficient and effective. - Observability is crucial:- When an AI makes multiple sub-queries to answer a single question, serious instrumentation is needed. We have developed custom tracing to understand decision flows, which is essential for governance and debugging. - The prompt evolves into a framework:- Instead of simple prompts, we are creating meta-cognitive frameworks that guide the system's exploration. This requires a different skill set. - Cost dynamics change:- Initial implementation may be heavier than basic LLM calls, but at scale, selective context loading can reduce costs by 3-5 times compared to naive long-context approaches. The governance aspect is vital:- Recursive systems with code execution create auditable reasoning chains. When AI decisions impact compliance, procurement, or risk assessment, the ability to trace the logic and criteria used is essential. However, there are hard truths to acknowledge:- - Not every problem requires recursion; some tasks genuinely need dense attention across the full context. - Failure modes are different. A single bad sub-query can cascade. Error handling and validation become critical. - Latency can be an issue. Synchronous recursive calls add up. We're exploring async patterns. Where this is heading:- The shift from LLMs as 'smart text generators' to 'cognitive orchestrators' is accelerating. The research from Massachusetts Institute of Technology MIT Computer Science and Artificial Intelligence Laboratory (CSAIL) validates what we're seeing in production, the next wave of AI systems won't just process information; they'll actively manage computational workflows. What patterns are you finding for orchestrating multi-step AI reasoning? Are you seeing similar cost/performance tradeoffs? #AgenticAI #AIArchitecture #AIGovernance #EnterpriseAI #BuildingAI
-
Your most experienced lawyer just gave notice. Suddenly, nobody knows where anything is. The panic that follows: "Where did she keep the template agreements?" "How do we handle IP assignments for contractors?" "What was our position on that regulatory issue?" "Who has the login for the trademark filing system?" This scenario happens at every company. Senior legal talent leaves, and institutional knowledge walks out the door with them. The real cost: junior lawyers spending weeks recreating work that already existed, making mistakes that were already solved, and reinventing processes that were already optimized. Most legal teams store knowledge in three places: -- Individual lawyers' heads -- Email threads from 2019 -- Folders buried in shared drives When knowledge is trapped in people instead of systems, every departure is a crisis. Here's how winning legal teams prevent this: → Document standard processes and decision trees → Create searchable templates and clause libraries → Maintain decision logs for recurring issues → Build internal playbooks for common scenarios → Record the "why" behind policies, not just the "what" The goal: any lawyer should be able to handle any issue with access to the right information. Knowledge management feels like busy work when you're overwhelmed. But losing a key team member without proper documentation feels much worse. Start small: document one process this week. Your future self (and your team) will thank you. How does your legal team capture and share institutional knowledge? What happens when someone leaves?
-
State Bar of California approves guidance on use of generative AI in the practice of law. Key points: 🔹 A lawyer must not input any confidential information of the client into any generative AI solution that lacks adequate confidentiality and security protections. A lawyer must anonymize client information and avoid entering details that can be used to identify the client. (Duty of confidentiality) 🔹 AI-generated outputs can be used as a starting point but must be carefully scrutinized. They should be critically analyzed for accuracy and bias, supplemented, and improved, if necessary. (Duty of competence and diligence) 🔹 A lawyer must comply with the law (e.g. IP, privacy, cybersecurity) and cannot counsel a client to engage, or assist a client in conduct that the lawyer knows is a violation of any law, rule, or ruling of a tribunal when using generative AI tools. (Duty to comply with the law) 🔹 Managerial and supervisory lawyers should establish clear policies regarding the permissible uses of generative AI and make reasonable efforts to ensure that the firm adopts measures that give reasonable assurance that the firm’s lawyers and non lawyers’ conduct complies with their professional obligations when using generative AI. This includes providing training on the ethical and practical aspects, and pitfalls, of any generative AI use. (Duty to Supervise) 🔹 The lawyer should consider disclosure to their client that they intend to use generative AI in the representation, including how the technology will be used, and the benefits and risks of such use. A lawyer should review any applicable client instructions or guidelines that may restrict or limit the use of generative AI (Duty to communicate) 🔹 A lawyer may use generative AI to more efficiently create work product and may charge for actual time spent (e.g., crafting or refining generative AI inputs and prompts, or reviewing and editing generative AI outputs). A lawyer must not charge hourly fees for the time saved by using generative AI. (Charging for work produced by AI) 🔹 A lawyer must review all generative AI outputs, including, but not limited to, analysis and citations to authority for accuracy before submission to the court, and correct any errors or misleading statements made to the court. (Duty of candor to tribunal) 🔹 Some generative AI is trained on biased information, and a lawyer should be aware of possible biases and the risks they may create when using generative AI (e.g., to screen potential clients or employees). (Prohibition on discrimination) 🔹 A lawyer should analyze the relevant laws and regulations of each jurisdiction in which a lawyer is licensed to ensure compliance with such rules. (Duties in other jurisdictions) #dataprivacy #dataprotection #AIprivacy #AIgovernance #privacyFOMO Image by vectorjuice on Freepik https://lnkd.in/dDUuFfes
-
In 2023, a lawyer used ChatGPT to cite six federal cases in Mata v. Avianca Airlines. None of them were real. The judge wasn’t amused. A huge amount of legal labor is pattern recognition… → spotting risk in contracts → flagging clauses → checking compliance → classifying documents All of which AI is surprisingly good at. 1. Contract Review = AI’s current stronghold Startups like Kira Systems, Luminance, and Evisort are already being used by major firms and in-house legal teams to review thousands of contracts in minutes. How it works: - NLP models are trained on millions of legal documents - They extract entities (parties, dates, obligations) - Flag unusual clauses or missing terms - Compare contracts to templates and playbooks - Suggest standardized language These systems don’t “understand” law like a human, but they do spot patterns with superhuman speed and consistency. Some use cases: M&A due diligence, lease abstraction, procurement review, NDAs and vendor agreements. 2. AI legal assistants Companies like Harvey (built on GPT-4 and backed by OpenAI and Sequoia) are building “AI co-counsel” tools for major law firms like Allen & Overy and PwC Legal. These tools can: - Draft memos, emails, and summaries - Translate legal language into plain English - Review case law and generate first-pass legal research - Answer questions about internal policies or past cases using retrieval-augmented generation Some corporate legal departments are now using LLM-powered chatbots to field internal questions like “Can we onboard a contractor in France?” Most firms still keep a human in the loop, but the productivity gains (especially for junior attorneys) are real. 3. Legal research Instead of spending hours on Westlaw or LexisNexis, LLMs like CoCounsel (by Casetext) and Ask Sage let lawyers type queries in natural language: “Find cases where a noncompete was struck down in California after 2021” They return relevant cases, key excerpts, and links to full decisions. But… what about ethics, bias, and accountability? Hallucinations: LLMs can still generate fake cases, made-up statutes, or misquote real ones Bias: training data often reflects real-world legal inequities so models might encode racial, gender, or class bias in sentencing, surveillance, or risk scoring Black-box risk: if you can’t explain why the model flagged something, can you trust it? Confidentiality: uploading sensitive legal docs to a public API? Probably not compliant. That’s why most law firms are either building private in-house models, using vetted APIs with strict data policies, or restricting LLM use to low-risk, client-facing tasks. Basically, AI in law isn’t about robots arguing in court (yet?). It’s about freeing lawyers from boilerplate and speeding up research and review. 👉 I’ve given myself 30 days to learn about AI. Follow Justine Juillard to keep up with me. 17 days to go.
-
Singapore’s Ministry of Law has published a sector-specific Draft Guide for Using Generative AI in the Legal Sector, a timely blueprint that seeks to reconcile the productivity gains of GenAI with the enduring professional obligations of legal practice. Released for public consultation (1–30 September 2025), the guidelines aligns the IMDA’s Model AI Governance Framework with the Courts’ guidance for court users and sets out practical, non-binding standards for responsible adoption. At the conceptual core the Guide foregrounds three interdependent principles: professional ethics (insisting on a “lawyer-in-the-loop” and preserving ultimate professional responsibility), confidentiality (data classification, preference for enterprise or on-premises solutions where client confidentiality is material, and contractual assurances against use of inputs for model training), and transparency (client disclosure, opt-out rights, and readiness to explain verification steps in court). The text is frank about GenAI limitations, notably hallucination and bias, and prescribes concrete mitigants such as grounding, retrieval-augmented generation (RAG), and robust vendor due diligence. Operationally, the Guide prescribes a five-step implementation pathway: develop an AI adoption framework; diagnose and priorities needs; identify and evaluate tools against data-security and performance criteria; implement with staged pilots and structured training; and institute continuous review. A copy of the draft guidelines is enclosed for reference. P.S. This is for academic discussion only. #GenerativeAI #LegalTech #ResponsibleAI #LegalEthics #DataPrivacy #AIinLaw #SingaporeLaw #AIRegulation #LawFirmInnovation #LegalAI #ProfessionalResponsibility
-
Everyone keeps asking: "Should Legal AI use SLM or RAG?" The better question is: Why are we choosing when enterprise legal teams need both? Here's the reality. A lawyer doesn't make decisions from memory alone. They: ✅ Review the contract. ✅ Check internal policies. ✅ Verify regulations. ✅ Compare similar cases. ✅ Ask for a second opinion when the stakes are high. That's exactly how trustworthy Legal AI should work. 🧠 SLM (Small Language Models) are excellent at structured, repetitive legal tasks. Think: • Contract metadata extraction • NDA review • Clause classification • Legal request routing • Playbook-based contract review • Document summarization They're fast, private, affordable, and predictable. But here's the catch. Fast doesn't always mean trustworthy. That's where RAG (Retrieval-Augmented Generation) changes everything. Instead of relying only on what the model learned during training, RAG grounds every response in the organization's latest approved knowledge. 📂 Contracts 📑 Legal playbooks 📘 Company policies ⚖️ Regulations 📚 Previous legal matters 📝 Templates Every answer becomes evidence-backed not just AI-generated. But even that isn't enough. The best enterprise legal systems add another layer: 🔍 Verify every response. • Is the source current? • Is it the correct jurisdiction? • Are there conflicting policies? • Does the evidence actually support the conclusion? • If confidence is low, the AI should say "I don't know" instead of pretending it does. And one thing should never change. Lawyers stay in control. AI shouldn't replace legal judgment. It should eliminate repetitive work, surface reliable evidence, and help legal teams make better decisions faster. The future of Legal AI isn't about building a smarter chatbot. It's about building AI that legal teams can confidently defend in the boardroom, the audit, and the courtroom. Because in enterprise AI, Trust isn't a feature. It's the product. If you're building AI for regulated industries, start by designing for trust—not just intelligence. 🔁 Repost if you believe trustworthy AI will outperform flashy AI. 💬 Would you trust an AI that gives fast answers, or one that shows its evidence before answering? 🌐 Learn more about LuMay AI: https://www.lumay.ai 📅 Book a demo: https://booknow.lumay.ai Follow Reshma for practical AI insights, enterprise AI strategies, and real-world Agentic AI use cases that businesses can implement today. #LegalAI #EnterpriseAI #LegalTech #AgenticAI #RAG #SLM #TrustworthyAI #LegalOps #AIArchitecture #GenerativeAI
-
🔍 NEW ARTICLE: Navigating AI Ethics in Legal Practice: A Cross-Jurisdictional Guide As AI tools become increasingly integrated into legal work, understanding our ethical obligations has never been more crucial. In this article, I examine the emerging regulatory landscape across Australia, New Zealand, the UK, US, and Canada. Key insights include: - Client confidentiality remains paramount - Professional competence includes understanding AI tools' capabilities and limitations - The necessity of human oversight and verification of all AI-generated content - Transparency requirements regarding AI use The regulatory approaches share consistency in emphasising these core principles while enabling innovation. What ethical challenges have you encountered when implementing AI in your legal practice? What safeguards have you found effective? #LegalTech #AIEthics #LegalInnovation #LegalProfession #AIRegulation #LegalEducation #ProfessionalResponsibility