Building an AI Governance Framework for In-House Legal Departments
Legal departments need governance structures, not just policies, to actually enforce AI rules.

AI adoption inside legal departments has stopped being a pilot program and started being infrastructure. That shift happened fast, and mostly without permission: the ACC/Everlaw GenAI Survey found corporate legal AI adoption jumped from 23% to 52% in a single year, with 64% of in-house teams now expecting to lean less on outside counsel as a direct result. Gallup found something similar at the workforce level: U.S. employees reporting AI use at least a few times a year rose from 27% in late 2024 to 46% by the fourth quarter of 2025, a climb that owes nothing to formal policy and everything to people finding tools that make their jobs faster. Steve Hasker has framed 2026 as the year a real divide opens up, between companies with an actual AI strategy and companies without one. For legal departments, the department that builds real governance now, rather than a policy binder nobody opens, is the one that becomes the function the rest of the organization turns to for AI judgment.
What governance means, and why a policy document is not enough
Most legal departments have written an AI policy by now. Fewer have built AI governance, and that gap explains why so many of those policies sit unused on a shared drive.
DISCO's framing captures the distinction well: governance is the city's legal and governmental system, while policy is the traffic laws and building codes that operate inside it. A traffic law only works because there's a police department to enforce it, a court system to adjudicate disputes, and a licensing body that decides who gets to drive. A policy document, on its own, does none of that. It can't say who owns the risk when an AI tool produces a bad outcome. It can't describe how the department will evaluate the next generation of tools as the technology shifts under its feet. It creates no cross-functional accountability, and it gives no one a way to check whether the rules are actually being followed day to day.
Governance builds the structures that make a policy enforceable. Skipping that step turns an AI policy into a document employees skim once, forget, and route around the moment a faster tool shows up.
The three foundational steps before any governance framework can function
Departments that jump straight to a governance framework, without first laying groundwork, produce frameworks that fail at the one thing they're supposed to do: get followed. Three steps have to happen first, in order, and skipping any of them causes a blind spot that becomes visible later.
Form a Center of Excellence first. It needs to be cross-functional from day one, typically pulling in the CISO, General Counsel, CHRO, CIO, and Chief Data Officer, and its first job is building a RACI matrix that spells out who's responsible and who's accountable for AI outcomes across every function that touches the technology. Legal's seat at that table isn't a courtesy invite. Legal is the function positioned to lead the structure, because it already sits at the intersection of every risk category the matrix has to cover.
Adopt a recognized risk framework next. The NIST AI Risk Management Framework and ISO 42001 hand a governance program a shared vocabulary instead of forcing it to invent one from scratch. ISO 42001 certification is starting to work the way SOC 2 Type 2 or ISO 27001 already do: clients will soon expect it as proof of external validation.
Map the AI landscape last, including the parts nobody approved. You can't govern what you can't see. AI use in professional settings climbed from 22% in 2025 to 40% in 2026, and roughly a third of professionals admit to using tools their employer never signed off on. That mapping exercise corresponds directly to the MAP function inside the NIST RMF, and it isn't optional. Eighty-five percent of legal departments now have a dedicated resource or committee for AI, but a committee is not visibility. A department can staff a governance committee for a year and still have no idea that half its paralegals are running contracts through a free browser-based chatbot after hours.
The core components of a working legal AI governance framework
Once the groundwork is in place, the framework itself needs a handful of core pieces, and each one has to do real work rather than sit on a shelf.
Data governance comes first, because AI risk is, in large part, data risk. Before anyone can govern how AI gets used, the department needs to know what data it holds, where that data lives, and how it's classified. Departments with mature data governance already in place start several steps ahead of everyone else, and the ones without it are rebuilding the plane mid-flight.
The next fork in the road is internal versus external use, and this distinction should drive almost every downstream decision. Internal tools, the kind used for drafting or research inside the department, carry one risk profile. Customer-facing AI, the kind embedded in products or client-facing platforms, triggers a different set of questions entirely, around disclosure, trust, and how data gets used downstream.
From there, risk-tiered approval does more day-to-day governance work than any paragraph of policy language ever could. A tiered classification lets lower-risk work move through a lighter approval process, while high-stakes uses like hiring decisions, consumer data handling, or anything involving autonomous action get real scrutiny before they go live. The oversight level matches the actual risk level, so the framework doesn't become the bottleneck it was built to prevent.
Vendor protections round things out, and they belong in procurement, not in a one-off negotiation every time a new tool shows up. A standardized AI addendum should cover a prohibition on using customer data to train models, clear deletion requirements once a vendor relationship ends, data isolation from other customers on the platform, and solid liability and indemnification language. A template ready to go, instead of language drafted fresh each time, speeds adoption and builds security into the process rather than bolting it on after the fact.
The regulatory landscape legal AI governance must account for right now
None of this gets built in a vacuum. The regulatory floor under legal AI is rising fast, on several fronts at once, and departments waiting for a single clear standard to emerge are going to wait past their own compliance deadlines.
The EU AI Act's full application to high-risk systems under Annex III now arrives in December 2027, following the AI Omnibus amendment that adjusted the original timeline. AI used in legal services is squarely inside the high-risk category. Conformity assessments, risk management systems, and human oversight mechanisms all need to be operational, not aspirational, and the penalties back that up: 35 million euros or 7% of global revenue, whichever is larger.
There's no federal AI law in the country in question, but the state-by-state patchwork is real and already binding. Colorado's AI Act takes effect in June 2026, requiring risk management policies, impact assessments, and transparency around high-risk AI systems. Illinois's AI in Employment Law kicks in January 1, 2026, mandating disclosure whenever AI plays a role in an employment decision. The Trump Administration's December 2025 executive order tried to preempt state AI laws outright, but it's running into constitutional challenges and bipartisan pushback, so the federal-state standoff remains unresolved. In practice, the most restrictive state law sets the floor for any employer operating nationally, even if that employer has no presence in that state.
Professional ethics obligations are already in force, too, and they predate most of this legislation. ABA Formal Opinion 512 requires lawyers to have a "reasonable understanding" of what AI tools can and can't do, the first national bar guidance addressing generative AI use directly. California, New York, Florida, and DC have all issued their own opinions since, and none contradict the ABA's framework. Forty states have already built a duty of technological competence into their ethics rules, so attorneys are on the hook for understanding the tools they use as well as the law they practice. Dozens of federal and state judges have gone further still, issuing standing orders that require AI disclosure and verification in filings.
The hallucination cases making headlines drive home why none of this can get delegated away. Courts have sanctioned counsel regardless of which department picked the tool or how convincing the vendor's marketing was. Handing the technology decision off to IT or legal ops does not hold up as a defense, because a license to practice law comes with no exception for outsourced judgment.
The shadow AI and measurement problems that make governance fail in practice
Two problems sink governance frameworks in practice more than any regulatory gap does, and both are underrated compared to how much attention gets paid to policy language.
Shadow AI is the first, and it's not a fringe issue. A large share of professionals use AI tools several times a week, and roughly a third admit to using tools their organization never approved. The instinct after an incident is to slam the door shut, and that instinct is almost always the wrong call. After engineers at one organization exposed sensitive code through a public LLM, a blanket ban followed, when a well-designed governance framework would have let teams keep working under clear guardrails instead. Prohibition without guardrails pushes the behavior underground, where nobody can see it or manage it. It just pushes it underground, where nobody can see it or manage it.
The measurement challenge runs even deeper, and it's structural rather than a matter of picking the right tool. Eighty-one percent of Chief Legal Officers feel the productivity lift AI is delivering, but can't prove it. The technology is working; the department just never instrumented itself before adoption started, so there's no before-and-after to point to. Nobody measured cycle time going in, so nobody can demonstrate a change in it now. A baseline has to exist before the AI does, and for most departments, it simply doesn't. AI won't replace legal judgment, but it will demand that legal departments state when judgment is being applied and how, and measurement is what makes that statement visible instead of assumed.
There's a financial edge to all this now, too. The cyber insurance market has begun incorporating AI-specific underwriting questions into renewal cycles, and AI governance attestations are becoming a standard input in that process. None of this is theoretical risk dressed up for effect. Stanford's AI Index Report counted 362 AI-related incidents in 2025, a 56.4% jump from the year before.
How legal earns the role of AI governance authority
Legal has structural advantages here that other functions simply don't. Legal ops already runs on the exact muscles AI governance requires: evaluating new technology, managing vendors, monitoring compliance against defined standards. That's the same discipline pointed at a new problem. Legal also sits across contracts, procurement, employment, and product in a way almost no other function does, which puts it in a rare position to hold the whole governance architecture together instead of owning one slice of it.
The rise of agentic AI raises the stakes considerably, and it's the single biggest technical shift of the year. The move from AI as an assistant to AI as an agent, one that executes multi-step tasks on its own with no human clicking "approve" at each stage, changes what governance even has to cover. The profession is already treating it as its own category: the ACC Artificial Intelligence Toolkit for In-house Lawyers added a checklist specifically for Developing Governance for Agentic AI, alongside seven other new resources built for exactly this moment. Gartner projects that 40% of enterprise applications will carry task-specific AI agents by 2026, up from under 5% before. The surface area governance has to cover is growing faster than most frameworks were designed to handle, and departments that treat agentic AI as an extension of existing policy rather than a new category are going to find that out the hard way.
None of this makes legal-led governance a brake on the business, and treating it as one gets the incentive backwards. Organizations with a defined AI strategy are twice as likely to see revenue growth and three-and-a-half times more likely to actually realize the AI benefits they set out chasing. The 64% of in-house teams expecting to lean less on outside counsel only get there if the internal capability they're building is governed properly. Skipping that makes AI adoption add risk instead of building an edge. Twenty-nine percent of legal departments have already shifted to value-based budgeting and performance measurement, and AI governance is one of the levers that makes that shift legible to the rest of the business, turning "legal is doing more with less" from a slogan into a number someone can actually defend.
Holding this position long-term means setting the rules that govern AI risk across the whole portfolio, rather than re-litigating every tool one at a time. It means building measurement infrastructure now, before the next capability shift arrives, so there's a baseline in place to defend when someone asks what changed. And it means treating vendor selection itself as a governance act: any AI platform brought in for legal work has to meet the standards the framework sets, on data isolation, on a hard prohibition against training on customer contract data, on documented auditability that holds up under scrutiny. Contract intelligence platforms built specifically for legal workflows, designed to apply legal judgment at scale across a portfolio rather than generate generic output, are exactly the category governance frameworks should be measuring against that bar.


