• Legal
  • Intapp Celeste
  • Intapp Walls

AI adoption is climbing. Confidence in law firm AI governance hasn’t. Here’s the gap.

The governed AI series | Part 1 of 3

Firms using AI firmwide nearly doubled this year, from 17% to 33%, and 90% of professionals grade their firm’s AI rollout an A or a B, according to Intapp’s 2026 Technology Perceptions Survey [1]. But 76% of professionals are using AI tools their firm never approved. Firms think they’ve solved this. Their own people are quietly proving otherwise.

That gap points to something deeper. According to MD Communications’ What Lies Ahead 2026 [2] survey, 95% of law firm leaders say they’re concerned about AI governance, and only 5% trust their current controls. Firms think they’ve solved this. The gap isn’t between having governance and not having it. It’s between believing you have it and actually verifying it works.

Most firms have a governance policy. Most have an IT team that believes the AI deployment is covered. The problem is that a policy describes what’s permitted, and an IT configuration governs one system at a time. Neither travels automatically to every AI tool a lawyer opens. That’s a sequencing problem. The firms that have scaled AI confidently built Governed AI first, which is why firm-wide deployment didn’t require a separate compliance negotiation every time a new tool went live.

What governance actually means in a law firm

At a law firm, governance means the firm’s professional responsibility obligations have to travel with every AI interaction. Lateral hire screens. Matter-level confidentiality. Waiver-driven walls. OCG requirements from clients who have specified how their data can and cannot be processed. An audit trail that can demonstrate, at the matter level, that privileged information was handled consistently with those obligations.

A GC who approves firm-wide AI deployment is implicitly certifying that those controls hold inside every tool lawyers use, not just inside the DMS, but inside Copilot, inside any AI research tool, and inside whatever comes next. That certification is only credible if the controls extend there. Most firms that have scaled AI quickly are operating on the assumption that they do. Most haven’t verified it.

Approving firm-wide AI deployment is a compliance certification. The question is whether the infrastructure underneath it supports that claim.

Three scenarios where ungoverned AI creates real exposure

The lateral hire scenario is the most recognizable. A partner joins from opposing counsel. The screen goes up immediately, correctly. Three months later, the firm deploys an AI research tool firm-wide. That tool has access to matter history the firm hasn’t explicitly restricted for that user. The screen that governs the lateral hire’s document access in the DMS does not extend to the AI tool’s access, because the AI tool was deployed after the screen was configured, in a different system, by a different team. The lateral hire never touches a restricted document directly. The AI tool they use might.

The OCG scenario is less visible but arriving faster. Clients are starting to write AI into outside counsel guidelines directly. The Association of Corporate Counsel published sample AI guidelines for outside counsel use [3] in June 2025, the clearest signal yet that this is moving from informal expectation to formal requirement, specifying that no client matter data may be processed by a third-party AI tool without explicit approval, and requiring documented evidence of controls on request. A firm that cannot produce that documentation within days is not just at risk of an OCG violation. It is at risk of losing the client.

The policy propagation scenario is the most operationally costly. A new conflict is identified on an active matter. The wall change needs to propagate across the DMS, Microsoft 365, and every AI platform in use at the firm. At a firm doing this manually, reaching out to each system administrator separately, that propagation takes days. During that window, the wall exists on paper but not in the systems lawyers are using.

A wall that exists in policy but not in the AI tools your lawyers use every day is not a wall. It’s a liability with documentation attached.

Diagram showing how lateral hire screens apply to DMS but not ungoverned AI tools

What Governed AI deployment actually looks like

The firms that have moved from AI pilots to firm-wide deployment without a compliance hold resolved the governance question before the rollout decision. When a wall changes, it changes across every connected system. The GC doesn’t have to ask whether the AI tool is covered. The answer is built into the deployment.

That structure also changes the conversation when a client or auditor asks for evidence. Instead of pulling records across four systems and reconstructing a timeline, the compliance team runs a report. Every user request and policy change was enforced and recorded at the moment it happened. The difference between a defensible record and a scramble is whether that log exists before the question arrives.

The time to build governance infrastructure is before partners are attached to tools that aren’t governed. Retrofitting controls onto a firm-wide AI deployment that already has adoption, embedded workflows, and partner expectations is operationally difficult and politically harder. The longer a firm waits, the more partners and workflows get attached to tools that were never brought under governance, and the harder retrofitting becomes.

The pilot-to-production question

The question for any firm managing an AI pilot is whether the governance infrastructure is ready to support firm-wide deployment, or whether scaling now means inheriting the compliance debt later.

But before you can answer that question, you need to know where you actually stand. Part 2 of this series walks through what happens when firms audit their current AI workspace access—and what they consistently find. Part 3 addresses the infrastructure gap that audit typically reveals, particularly for firms on on-premises governance systems.

For firms ready to assess their readiness, Intapp Walls for AI is designed to serve as a governance foundation for the legal compliance environment, with information barriers that span the firm’s AI infrastructure. Request a demo to see what Governed AI deployment looks like in practice.

Sources
[1] Intapp’s 2026 Technology Perceptions Survey, firms using AI firmwide grew from 17% in 2025 to 33% in 2026, 90% of professionals grade their firm’s AI rollout an A or B, and 76% report using AI tools not approved by their firm.
[2] MD Communications’ What Lies Ahead 2026 report, 95% of law firm leaders report concern about AI governance, while only 5% trust their current controls.
[3] Association of Corporate Counsel, Sample Artificial Intelligence (AI) Guidelines for Outside Counsel (June 2025)