A small firm should never let AI make the final call on anything a client, court or counterparty relies on: signed advice, filings with unchecked authorities, limitation and filing deadlines, conflict decisions, client-money and payment instructions, identity checks, and capacity or vulnerability judgements. AI can draft, sort and summarise around all of these. A named lawyer decides.
The dividing line isn't really the type of task. It's two things: whether a mistake can reach the client or the court before a qualified person has read it, and whether the mistake can be undone once it does. The risk is not theoretical. Damien Charlotin's public AI Hallucination Cases database listed 2,086 decisions by 27 September 2026 in which a court or tribunal found that a party had relied on AI-invented material, and in 828 of them the party responsible was a lawyer.
A four-question test before any legal task goes near AI
Run every proposed use through these four questions. They take a minute and they sort almost everything a small firm does.
- Will the output reach a client, court, counterparty or regulator before a lawyer has read all of it? If yes, redesign the step so it can't.
- Does the output commit anyone? A signature, a filing, a payment, a deadline entered in the diary, an undertaking. Commitments are human decisions.
- If it's wrong, can you undo it before harm is done? A clumsy first draft can be rewritten. A missed limitation date or money sent to a fraudster usually can't.
- Would you have to put confidential or privileged material into a tool whose terms you haven't checked? If yes, stop until the tool is approved.
A yes to question 2 or 3 puts the task on the never list: AI may prepare the ground, but a person makes the decision and records it. A yes to question 1 or 4 means the task can use AI only after you change the process. Here is how the test plays out on a real-looking week.
One week of tasks, sorted
Picture a four-lawyer practice doing residential conveyancing, wills and probate, with two support staff. A practice manager lists 40 tasks from an ordinary week and runs the test on each. The result: 15 tasks are fine for AI with a light read (tidying file notes, first drafts of routine chasers, summarising a lease for internal use), 18 are amber (AI drafts, a lawyer checks every line against the source), and 7 are red. The red ones were telling:
| Task that week | Question that failed | What AI may still do |
|---|---|---|
| Confirm completion funds and seller's bank details | 2 and 3: a payment, irreversible | Nothing that touches the bank details |
| Diary the deadline for a probate claim response | 2 and 3: a deadline | Pull the relevant dates from the letter for the lawyer to check |
| Decide whether a new client conflicts with an existing one | 2: commits the firm to act | Draft the search terms for the conflict system |
| Sign off a will for an elderly client with a new carer present | 3: capacity and undue influence | Draft the attendance note template |
| Verify the identity of a remote buyer | 3: fraud risk | Nothing in the decision itself |
| Send the advice letter on a boundary dispute | 1 and 2: advice relied on | First draft, then a full lawyer rewrite |
| Respond to the other side's offer | 2: negotiating position | Summarise the offer and options internally |
Seven out of 40 is roughly what most small firms find. The red list is short, which is why it's realistic to hold firmly.
Seven jobs that stay with a qualified person
1. Advice the client will act on
AI can produce a fluent answer to "can my landlord keep my deposit?" in seconds, often applying the wrong jurisdiction's rules or a version of the law that has since changed. The danger is fluency: a draft that reads well gets skimmed. Let AI structure the letter and simplify the language, then have the lawyer check every statement of law and fact against a source they trust before it goes out. If the lawyer couldn't defend a sentence to a regulator, it comes out.
2. Anything filed with a court or tribunal
This is where the invented citations in that database come from. A general chatbot asked for supporting authorities will sometimes return cases that don't exist, or real cases that don't say what it claims. The routine that works is simple and slow: open every authority in a trusted legal database, read the passage relied on, and initial a citation log. The small-firm checking routine for invented case law sets that out step by step. Court rules in many places also expect a witness statement to be in the witness's own words, so an AI-polished statement can create a problem even when every fact is true.
The log only needs five columns, and the most useful entries are the partial ones. An illustrative line:
Authority: [case name and citation]
Found in: [firm's legal database]
Passage relied on: paras 31-34
Says what the draft claims? Partly. The point is an aside, not
the reason for the decision. Draft reworded to say so.
Checked by / date: [initials], 12 Oct
A real case that doesn't quite say what the draft claims is harder to spot than an invented one, because it survives a quick search. It only shows up when someone reads the passage.
3. Deadlines and limitation dates
Ask a chatbot for the limitation period on a claim and it will give a confident number, sometimes for the wrong kind of claim, the wrong place or a rule that has been amended. Worse, deadline errors are silent until they're fatal. Keep the calculation and the diary entry with a person using your practice-management system, and use AI only to extract the dates from correspondence so the lawyer can check them against the letter itself.
Here's how a plain extraction goes wrong. A letter dated 3 September, received on 8 September, says the recipient must respond "within 21 days of service of this notice". Asked to "extract the deadline", an assistant returned (illustrative): "Response deadline: 24 September." It had counted from the date on the letter, ignored when the notice counts as served, and assumed calendar days without saying so. Any of those could be wrong under the rules that apply. The safer instruction: "Quote the exact words setting any time limit, the date of the letter and the date we received it. Do not calculate a deadline." The lawyer does the sum in the practice-management system, and the diary entry shows who did it.
4. Conflict checks
A conflict decision depends on your full client and matter history, which a chat assistant doesn't hold and shouldn't be given wholesale. AI can suggest name variants to search ("J. Smith Ltd", "Smith Holdings"), but the search runs in your own system and the decision to act is signed by a lawyer.
5. Client money and payment instructions
Payment-diversion fraud targets conveyancing completions, and AI makes the fake emails more convincing. No AI tool should draft, send or "confirm" bank details, and no automation should be allowed to change payee details. Verify by phone on a number you already hold, every time. The newer risk is cloned voices, covered in the tutorial on spotting deepfake voice and video scams.
AI that sorts your inbox needs the same rule. In an illustrative near miss, an email arrives two days before completion from an address one letter different from the seller's solicitors: "Please note our client account details have changed; use the details below for completion funds." The firm's AI triage files it as "Seller's solicitors: updated completion details" in the routine pile, with the new account number helpfully copied into its summary, and a fee earner nearly updates the completion statement from that summary. Give the triage one hard rule: any email that mentions bank, account or payment details is labelled "STOP: verify by phone", its details are never copied into a summary, and it goes to the fee earner unsorted.
6. Identity and anti-money-laundering decisions
AI can help assemble an ID-check file, but it can't tell you a passport photo or a video call is genuine, and generated documents are now good enough to fool a tired eye. The decision that a client is who they say they are, and that the source of funds makes sense, stays with the person whose name goes on the check.
7. Capacity, vulnerability and safeguarding calls
Whether a will-maker understands what they're signing, whether a family client is at risk, whether a caller sounds coerced: these rest on what a trained person sees and hears in the room. No transcript summary captures the pause before an answer or the relative who keeps interrupting. AI can prepare the attendance note template. It shouldn't be anywhere near the conclusion.
Transcript summaries fail here in a particular way: they tidy hesitation into agreement. Suppose an AI note taker summarises a will meeting as "Client confirmed she understood the effect of leaving the house to her nephew." The recording shows she said, "I suppose so. Whatever he thinks is best," after the nephew had answered the previous two questions for her. The summary isn't false, but it records the opposite of what an experienced lawyer would have noticed. If you record will meetings at all, the lawyer writes the attendance note on capacity and influence from their own observation, and the AI summary is never pasted into it.
Where the line sits in three kinds of small practice
A conveyancing-heavy firm. The red zone is money and searches. AI summarising a 40-page lease for the fee earner is fine with a check. AI writing the report on title that the buyer relies on is amber at best, with every point traced to the document. AI anywhere near completion funds is red. One firm-wide rule helps: the word "bank" in an AI-drafted email triggers a manual check before sending.
A family practice. Here the sensitive data is the problem as much as the advice. Financial disclosure, allegations of abuse and children's details should never go into a consumer chatbot, and even on a business plan the use should be limited to drafting and summarising. Safeguarding judgements and anything said to a vulnerable client stay human.
A wills and probate practice. AI is useful for estate account first drafts and chasing letters to banks. It is red for capacity decisions, for interpreting an ambiguous will clause that the executors will act on, and for deciding who inherits under intestacy rules, where one wrong assumption about a family tree sends money to the wrong person.
The amber list: AI drafts, a named lawyer signs
Most of the value sits in amber. The point of the list is that each task has a named check and a record that the check happened.
| Task | AI's job | The human check | Record kept |
|---|---|---|---|
| Research memo | Find leads, summarise arguments | Open every authority; confirm the passage says what's claimed | Initialled citation log |
| Contract review | Flag clauses against your playbook | Read the whole contract; AI misses what isn't there | Checklist on file |
| Bundle chronology | Build a dated timeline with page references | Spot-check a sample of entries against the pages | Note of entries checked |
| Client letter | Plain-English draft | Every statement of law and fact | "Reviewed by" file note |
| Enquiry triage | Sort enquiries by type and urgency | No enquiry declined without a person reading it | Weekly sample review |
Contract review deserves its own caution: tools catch the clauses they're told to look for and miss the protection that should be there but isn't. The tutorial on what AI contract review catches and misses goes into that gap, and summarising bundles and transcripts safely covers the chronology work.
A near miss with invented cases, and the prompt that prevents it
Near misses rarely look dramatic. Here is a typical one, invented for illustration. A trainee asks a general assistant for support on a point about easements:
Prompt: Give me three cases supporting the argument that a right of way
can be acquired by long use even where the owner gave occasional
permission. Include citations.
Illustrative output (the cases below are invented for this example):
1. Harlow v Pennington (2019) - held that occasional permission does not
defeat a claim where use was otherwise as of right...
2. Marsh Estates v Doyle (2011) - ...
3. ...
The names sound right, the reasoning sounds right, and the trainee pastes them into a draft skeleton argument. What catches it is the citation log: the supervising lawyer can't find either case in the firm's legal database. The fix isn't to ban the tool. It's to change the prompt to ask for search terms rather than cases, and to make the log mandatory before any authority reaches a document. A better prompt looks like this:
I am researching whether occasional permission defeats a claim to a
right of way acquired by long use. Do not name cases. Instead give me:
(1) the legal concepts and terms I should search for,
(2) the questions a court would ask,
(3) what facts I should gather from the client.
I will find and check the authorities myself.
The second leak is quieter. The confidentiality risk from pasting a client's file into a consumer chatbot is real, and a widely reported court ruling in February 2026 found that documents a defendant had produced with a consumer AI chatbot, on his own initiative, were not protected by privilege. If your fee earners use personal accounts, read whether solicitors can use ChatGPT without breaching confidentiality before anything else.
Wording for the never clause in your firm's AI policy
Put the red list into your AI policy in plain words, so no one has to interpret a principle at five o'clock on a Friday. Adapt this:
AI tools may help prepare work, but they must never be used to:
1. Send, file or give advice to a client, court, tribunal, counterparty
or regulator without a qualified lawyer reading all of it first.
2. Calculate, enter or change any limitation date or deadline.
3. Decide a conflict of interest or whether we can act.
4. Draft, send, confirm or change bank details or payment instructions.
5. Decide whether a client's identity or source of funds is verified.
6. Reach any conclusion about capacity, vulnerability or safeguarding.
7. Respond to an offer or state a negotiating position.
Confidential or privileged material may only be used in tools on the
approved list. Personal AI accounts are not approved for client work.
Report any near miss to [name] the same day. No blame for reporting.
The last line matters more than it looks. A firm only learns where its line is leaking if people report the near misses, and they only report if doing so doesn't cost them.
Checking the line holds after three months
Three signs tell you the never list is working. First, the citation log has entries every week; if it's empty, people have either stopped using AI for research or stopped logging. Second, near misses are being reported; a firm with no reports in a quarter usually has unreported ones. Third, when you sample five files a month, the "reviewed by" note matches work that visibly changed between the AI draft and the version sent. An AI draft sent unchanged with a review note on it is the pattern to look for, because it means the review was a signature, not a read.
The same test works beyond advice and filings. The AI client intake tutorial for law firms applies it to out-of-hours enquiries, where the red line is never letting a bot decline a potential client on its own, and the AI hub collects the rest of the series.
Follow-up questions from partners and practice managers
Can a paralegal or trainee check AI work instead of a qualified lawyer?
For amber tasks like chronologies or first-draft letters, a trained paralegal can do the first check, but the lawyer who signs or sends the work still owns it. Regulators and courts treat the supervising lawyer as responsible for what leaves the firm, so the final read of anything a client or court relies on should be by the person accountable for it.
Is a legal-specific AI tool safe for the tasks on the never list?
A legal tool with a proper contract, no training on your data and a citation database behind it lowers the confidentiality and invented-case risks. It does not change who decides. Deadlines, conflicts, payment instructions and capacity calls stay with a person because the cost of an error is high and often irreversible, whichever tool produced the draft.
Do we have to tell clients we use AI on their matter?
It depends on your regulator's guidance, your engagement terms and what the tool does with client information. Many firms add a short line to their client care letter explaining that AI tools may help with drafting and summarising under lawyer supervision, on business-grade services that don't train on client data. Check your professional body's current guidance before settling the wording.
How often should we revisit the never list?
Review it when you adopt a new tool, when a near miss happens, and at least twice a year. Tools gain features quickly, such as sending emails or filing on your behalf, and a feature that acts rather than drafts can quietly move a task from amber to red without anyone deciding it should.
Further reads
- AI for Small Law Firms: What to Automate First — The other side of this list: what a small firm can safely automate first.
- ChatGPT or a Legal AI Tool: Which Should a Small Firm Use? — Whether a general assistant or a legal-specific tool suits your amber tasks.
- Can Lawyers Use AI Note Takers in Client Meetings? — When AI note takers are acceptable in client meetings.
- AI Implementation Plan for a Small Law Firm: The First 90 Days — A 90-day plan that builds these limits in from the start.
- AI Acceptable Use Policy for a Small Professional Firm — A full acceptable-use policy to hold the never clause.
- Per-Seat or Pay-As-You-Go? Legal AI Pricing for Small Firms — What legal AI tools cost a small firm, per seat or pay-as-you-go.
- What an AI Consultant Does for a Law Firm, and What It Costs — The five phases of a law-firm AI engagement, what each should hand over, how fees are built from consultant days, and proposal red flags.
- How Small Law Firms Use AI to Draft Letters and Routine Documents — A precedent-first way to draft routine legal letters with AI: risk bands, a cleaned precedent pack, a fill-and-flag prompt and a fee-earner checklist.
- How HR Consultants Use AI for Policies, Letters and Cases — Three workflows for HR consultants, with a client fact sheet, letter before-and-after, a grievance chronology prompt and the lines AI must never cross.
- AI Marketing for Small Law Firms: Content, Reviews and the Rules — How a small law firm can use AI for guides, posts and review replies while staying inside platform, consumer-law and professional conduct rules.
- Which Pharmacy Tasks Should Never Be Handed to AI? — The pharmacy tasks that must stay with a pharmacist, why each one fails with AI, and the admin work around them that AI can safely support.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Damien Charlotin's AI Hallucination Cases database (case count and party breakdown, checked 27 September 2026); published commentary on the February 2026 court ruling on privilege and consumer AI chats; professional-body guidance on lawyers' duties when using generative AI.