Legal automation has spent three years promising that the firm will run itself, and it still hasn't happened. What has happened, fairly quietly, is that a handful of specific tasks — checking clauses against a house position, organising a case file, drafting a first version of a routine filing, pulling data out of rulings — have gone from a three-hour junior job to a twenty-minute review job. That's the real shift, and it's enough to move the P&L of a mid-sized firm.
This article separates what works safely today — with review, traceability and clear accountability — from what remains human and will probably stay that way for a long time. No autonomous-firm promises, and none of the "this doesn't apply to law" excuse either.
What is legal automation, and how is it different from traditional legal software?
Classic legal software — case management, deadline diaries, billing — automates the record of the work. It knows a matter exists, who owns it and when the deadline falls. What it doesn't do is read anything.
Today's legal automation adds a different layer: systems that can read, classify, compare and draft over legal documents. That changes the nature of what can be delegated. It isn't that the system knows law; it's that it can process five hundred pages in minutes and flag where a lawyer needs to look.
The practical distinction that matters:
- Workflow automation: moving a matter between states, flagging a deadline, generating the engagement letter with the client's details. Deterministic, verifiable, no surprises. It's the first thing to build and almost nobody has it working properly.
- Content automation: reviewing a contract against the firm's position, summarising a thousand-page file, producing a first draft. Probabilistic. It requires review, always, and the review has to be designed rather than improvised.
Mixing the two into a single project is the most common mistake. The first can be rolled out in weeks and pays off immediately. The second needs judgement, samples and a measurement phase before it touches a live matter.
If your firm still hunts for documents across shared folders and file names, the generative-AI conversation is premature. Fix what can be fixed without models first.
Which law firm processes can be safely automated today?
These are the cases where the technology is mature, the saving is measurable and the risk is contained by a sensible review process.
Contract review against your own position. The strongest case by far. The system compares an incoming contract against the firm's standard stance — clauses always rejected, acceptable liability caps, jurisdiction, notice periods — and returns a list of deviations ordered by severity. The lawyer doesn't read the whole contract hunting for traps: they read the fifteen flagged deviations and decide. In recurring commercial contracting volumes, this is where most hours come back.
Data extraction from documents. Deeds, rulings, payslips, expert reports, court notifications. Pulling out the dates, the parties, the amounts and the key terms and pushing them into the case management system without typing. The technology here is reliable, and errors, when they show up, are visible.
First drafts of repetitive filings. Debt claims, responses to formal notices, standard contracts, engagement letters, termination notices. The key word is first. The draft doesn't get sent — it gets corrected. Even so, starting from something 70% written with the matter's data already inserted removes the most mechanical and least valuable part of the job.
Intake classification and routing. Everything arriving at the firm — email, electronic notifications, client documentation — classified by area, matter and urgency, then routed to the right person. Unglamorous automation, and among the best at removing daily friction.
Search across your own document archive. Being able to ask "what have we argued before in a case with these facts" and get back the three relevant internal filings with the exact citation. The most underused asset in any firm older than ten years is its own archive.
Deadline and contractual obligation monitoring. Detecting expiry dates, automatic renewals and notice windows across the contract portfolio, and flagging them early. Pure client value, and it doesn't require the system to "understand" anything difficult.
| Process | What the system does | What the lawyer reviews | Typical saving | |---|---|---|---| | Contract review | Flags deviations vs. house position | The flagged deviations and negotiation stance | High | | Document extraction | Pushes data into the matter | Sampled quality control | High | | Repetitive drafts | Writes the initial version | The entire text before it goes out | Medium-high | | Intake classification | Routes and tags | Exceptions and edge cases | Medium | | Internal search | Finds your own precedents | Whether the results are on point | Medium | | Deadline monitoring | Alerts in advance | The decision on each alert | Medium |
What can't be delegated to a machine?
This list matters more than the previous one, because it's the one that prevents the accident.
Legal judgement. Deciding the strategy for a matter, choosing between two procedural routes, assessing whether a risk is acceptable for this client. A model can lay out options; it can't be accountable for the choice.
Anything that gets signed. The filing that goes to court, the opinion that gets delivered, the contract that gets closed. A system can prepare it; whoever signs has read all of it. There's no shortcut here and none should be looked for.
Client relationships at critical moments. Delivering bad news, negotiating fees, managing a misaligned expectation. An automated assistant replying to an angry client's email is an expensive way to lose them.
Unverified case-law citations. Models generate references that look right and don't exist. Every citation coming out of a system gets checked against the source before it's used. No exceptions, no "I was in a rush".
Anything where the volume doesn't justify it. Automating a process performed three times a year costs more than it saves. Profitable legal automation lives in repetition, not in exceptions.
How do you roll it out without breaking the firm?
The sequence that works in firms of 5 to 60 people, which is where we see most projects:
Phase 1 — Count before you buy (2-3 weeks). Measure where the time actually goes. Not by partner intuition: from the time records, or if there aren't any, from one week of honest logging. It nearly always turns out that 40% of non-billable time sits in three specific tasks, and they aren't the ones people assumed.
Phase 2 — Fix the substrate (4-6 weeks). Matter naming, where each document lives, who can access what. Any system that reads documents needs to know where they are and how they're structured. This is the work nobody wants to budget for and the work that determines whether everything else functions. We cover it in data before AI.
Phase 3 — One use case, with a metric (4-8 weeks). A single process — the highest-volume one from phase 1. Decide in advance what gets measured: minutes per document, error rate caught at review, share of cases the system can't handle. Run it in parallel with the current method for a few weeks and compare. Yes, it's more work up front; it's also what separates a pilot from a bet.
Phase 4 — Production, then the second task. Only once the first is in real use, with its review procedure written down and someone accountable for it. Then the next one, which also reuses all the infrastructure built for the first.
Firms that skip phase 2 are the ones that six months later say "AI didn't work". It worked fine — it just couldn't find anything.
What do professional privilege and the GDPR require?
A law firm isn't just any company feeding data into a system. It handles third-party data under professional privilege, and often special category data. Three decisions to put in writing before starting:
- Where it's processed and what's retained. If the vendor can't state in writing where the model runs, how long the input is kept and whether it's used for retraining, it isn't a vendor for a law firm. This is an Article 28 processor contract, not a matter of trust.
- What leaves the perimeter and what doesn't. By document category, decided by the partnership and not by each lawyer at eleven at night. Some matters simply shouldn't leave, and it's worth having that written down before someone decides it alone.
- Minimise before sending. Plenty of use cases don't need the client's name to work. Filtering at source is cheaper and more robust than any contractual clause. The specific techniques are in the data anonymization guide.
Add to that an up-to-date record of processing activities, a client notice if the processing changes materially, and traceability: who asked the system what, and what came back. If someone has to explain tomorrow how a document was produced, that trail is the difference between an answer and a problem.
For the detail on how this fits regulatorily in firms and practices, it's developed in the AI for accounting firms guide.
What does it cost, and how do you actually measure the return?
The cost has three lines and only one gets discussed. The software licence is the small one. The other two: integration with the case management system and email, and the internal time spent defining the house position and reviewing output during the first weeks. In smaller firms that third line is usually the biggest, and budgeting it at zero is the number one reason projects stall halfway.
Return shows up in three different places:
- Non-billable hours recovered. The most direct saving and the easiest to measure if time is recorded.
- Capacity without hiring. Taking on 20% more matters with the same team is worth more than the hourly saving, and it's what actually moves the P&L.
- Risk avoided. A deadline caught in time, a clause that didn't slip through. Hard to quantify, impossible to ignore when the opposite happens.
A simple test for whether a process deserves automating: multiply how many times a year it happens by the minutes it costs each time. If it doesn't clear a hundred hours a year, park it and find another one.
Frequently asked questions
Can an AI system draft a filing that goes to court? It can draft the first version, but the filing that gets submitted has been read and signed by a lawyer, in full. Professional responsibility isn't delegated to a tool, and case-law citations must be verified one by one against the source before use.
Is it safe to upload client documents to an AI system? It depends on three specific things: where it's processed, how long it's retained, and whether it's used for retraining. With a processor agreement that answers all three in writing and a policy on which categories may leave the perimeter, it's manageable. Without that, no.
What size of firm justifies automating? It isn't about size, it's about repetition. A five-person firm with high volumes of standard contracting has more upside than a thirty-person firm doing bespoke matters. Count how many times the same process repeats per year before you count headcount.
Where do I start if nothing is in place? By measuring where non-billable time goes for one week, and by fixing matter and document naming. Neither costs a licence, both take under a month, and together they determine whether any tool you buy later will be worth anything.
The honest summary
The legal automation that works today doesn't replace the lawyer: it takes away the part of the work that never required being one. Cross-checking, extracting, organising, preparing the first draft, flagging an expiry. That's a lot of hours, and it isn't where a firm's value sits. What stays with the lawyer — judgement, the signature, the client relationship — isn't at risk, and anyone selling the opposite hasn't worked in a firm.
If you want to know which three processes in your firm have enough volume to justify the effort, and which ones don't even though they look like they do, the audit is exactly that: the real workflow gets measured and prioritised by recoverable hours, not by what's fashionable. And if you already have a clear case in mind and just want to test it against someone who has implemented one before, let's talk.
Shall we apply it to your case?
The 360° AI Audit turns these ideas into a concrete plan for your company: three weeks, fixed price and the full picture of your AI before spending a euro.
See the 360° Audit→ Let's talk↗