Skip to main content
How Can Our Firm Use AI Agents and Keep Client Data Under Our Control?

How Can Our Firm Use AI Agents and Keep Client Data Under Our Control?

Fusion Legal & Tax · August 23, 2026Thought leadership9 min read

Law firms do not have to choose between useful AI and responsible stewardship of client information. The more empowering path is to define what an AI agent may access, what it may do and where a person must remain in control.

One signal worth attention in Law360 Pulse legal-tech expert analysis (subscription required) is a change in how the legal industry may be expected to evaluate AI risk. Based on the article’s publicly available teaser/summary, in May 2026 Camilo Artiga-Purcell of Kiteworks advanced the position in “Public AI Disclosures Raise Stakes for AI Agent Oversight” that two recent reports alter the legal posture of organizations deploying AI agents because they make an agent’s weaponization for data exfiltration foreseeable for negligence purposes.

That is a commentator’s legal thesis—not a reported holding, a universal negligence standard or a substitute for jurisdiction-specific analysis. Artiga-Purcell writes from Kiteworks, an affiliation readers should consider when evaluating the analysis. The publicly available teaser also does not identify the two underlying reports, so this article does not rely on or characterize their findings.

The thesis nevertheless raises a useful operational question for law firms:

Once a category of AI-enabled harm is documented and visible, what controls can the organization show that it considered, implemented and tested?

That question should not stop firms from adopting useful technology. It can help them adopt it with clearer boundaries, stronger evidence and greater confidence.

What your AI agent can reach—and who decides

Lawyers should be able to explore useful technology while knowing where its authority begins and ends.

Traditional generative-AI governance often concentrates on output: Is the answer accurate? Are the authorities real? Did a lawyer review the draft?

Those controls remain important. But an AI agent can present a broader governance problem than a stand-alone drafting tool because it may search across connected repositories, pass information between tools and initiate steps in a workflow.

The market is openly moving in that direction. Legora describes its platform as supporting workflows from intake through delivery, with an agent that can generate lists from documents and connect outputs to legal work. That is the vendor’s description of its own product, not an independent assessment of performance or risk.

Product descriptions do not establish that a particular system is unsafe. They illustrate why firms should assess more than answer quality. Relevant questions can include:

  • What repositories can the agent reach?
  • Which matters and client workspaces can it enter?
  • Can it retrieve, transform or transmit information?
  • Which external tools or platforms can receive information from it?
  • What actions require human approval?
  • How are credentials, sessions and permissions limited?
  • Can the firm reconstruct what occurred afterward?

The protective objective is straightforward: help lawyers benefit from automation while keeping authority, confidentiality and accountability clear.

Foreseeability is not the same as liability

The purpose is not documentation for its own sake. It is to give people a practical way to make thoughtful choices as the technology changes.

The distinction matters. A published report or industry article may contribute to awareness of a risk category, but awareness alone does not resolve duty, breach, causation, damages or defenses. Those questions depend on governing law and specific facts.

In Fusion Legal & Tax’s view, firms gain more practical value by developing governance alongside adoption rather than waiting for legal doctrine to answer every operational question. A contemporaneous record may show how a firm:

  1. identified the relevant use case;
  2. classified the information and systems involved;
  3. evaluated credible failure and misuse paths;
  4. selected controls suited to the workflow;
  5. tested those controls;
  6. trained the people responsible for the workflow; and
  7. revisited the assessment when the product, model or integration changed.

This seven-step outline is illustrative, not a compliance standard. Appropriate measures may vary by jurisdiction, practice setting, professional-conduct rules, insurer requirements, client agreements and the technology involved.

A consistent record can support institutional memory, help teams manage a fast-changing technology stack and can help the firm explain its choices accurately if a client, insurer, auditor, court or regulator later asks.

Are AI prompts discoverable? What to decide before you deploy

A clear plan for prompts and responses can help teams use AI with greater confidence from the start.

Firms should not wait for an incident or discovery request to decide how prompts, responses and agent activity fit into information governance. Before broad deployment, teams can address questions such as:

  • Are prompts and responses retained?
  • Where are they stored?
  • Do matter numbers and retention rules attach?
  • Who can retrieve them?
  • How is privileged or confidential material identified?
  • Do agent actions receive a separate audit trail?
  • How can legal holds reach relevant records?

A prompt log may help document supervision and validation, but it may also contain client facts, attorney thinking or unnecessary sensitive data. The answer is not automatically indiscriminate retention or deletion. It is a documented, consistently applied and matter-aware policy coordinated among legal, privacy, security, records and litigation teams.

Put meaningful human review inside the workflow

People remain the source of professional judgment, and the workflow should make it easy for them to exercise it at the right moment.

“Human in the loop” is too imprecise to function as a control description. A workflow is more useful when it identifies the person responsible, the intervention point and the standard that person applies.

That means distinguishing among at least four activities:

  • Review: reading an output before use.
  • Verification: checking propositions against authoritative material.
  • Approval: authorizing an external communication, filing or system action.
  • Escalation: stopping the workflow when defined conditions arise.

These distinctions matter because courts were not taking one uniform procedural approach in June 2024. At that time, Law360 reported that the U.S. District Court for the Western District of North Carolina had issued a standing order requiring counsel to certify with every brief that AI was not used (subscription required), while Law360 reported that the Fifth Circuit declined to adopt a proposed verification/certification rule for AI-drafted filings (subscription required). As of June 2024, Law360 Pulse reported—citing its tracker of federal judges’ AI orders (subscription required) that 28 standing orders had come from about 2% of more than 1,600 U.S. district and magistrate judges, with some orders signed by more than one judge, and that most permitted AI use subject to disclosure and an accuracy certification. That is a June 2024 snapshot rather than a current count. Scholars quoted by Law360 Pulse in June 2024 supported the Fifth Circuit’s decision (subscription required) and expressed hope that it would influence other courts. The standing-order landscape also moved within 2024; for example, at the 2024 ABA annual meeting in Chicago, Law360 Pulse reported that Illinois Magistrate Judge Gabriel Fuentes had pulled back his AI order as no longer necessary and slightly burdensome (subscription required).

Rather than treating one AI-specific certification as a complete governance model, firms can tie review, verification, approval and escalation to the actual professional task.

Write AI policies that survive changing vendors

Teams should not have to rebuild their governance approach every time a product name or feature changes.

Legal-AI products and integrations continue to change. Policies written around one product name may age quickly, while controls tied to capabilities and workflows can remain useful across vendor changes.

Workflow characteristicGovernance question
Drafts text onlyWho verifies facts, quotations and authorities before use?
Retrieves internal documentsWhich repositories, matters and document classes are permitted?
Uses external sourcesHow are provenance and authoritative status checked?
Connects to another platformWhat data crosses the boundary, under which credentials and logs?
Communicates externallyWhat requires express human approval?
Executes or changes recordsCan the action be limited, reversed and reconstructed?
Learns from user interactionWhat contractual and technical rules govern retention and reuse?

A product may perform well in one row and call for additional controls in another. Firms can therefore learn more by evaluating representative workflows with controlled test data than by depending only on a sales demonstration.

Make summer-associate training a governance opportunity

Summer-associate programs offer firms a supportive place to build good AI habits early.

AI competence is becoming a professional-development question as well as a technology question.

Effective training can move beyond prompt-writing tips. A useful exercise gives participants a realistic assignment and asks them to document:

  • whether AI use is permitted for that task;
  • what information may be entered;
  • which sources must be checked independently;
  • how the output should be revised and attributed;
  • what must be preserved in the matter record; and
  • when the associate should stop and ask a supervising lawyer.

The exercise can then introduce an unsafe instruction, an unsupported proposition or an attempted transfer of information outside the approved workspace. The goal is not to make new lawyers fearful of AI. It is to help them recognize boundaries early and use the tools with professional judgment.

Law schools including Columbia, Catholic University, Berkeley Law and GW Law are setting boundaries that vary in strictness. In August 2026, Law360 Pulse summarized (subscription required) Columbia Law School’s policy as permitting AI to “support learning” and “perform specific functions” while restricting its role in written work, original arguments and legal analysis, with some decisions about AI use left to faculty discretion. Law firms need their own task-specific rules, but the underlying design principle is useful: define permitted assistance by function while also making clear who has discretion to set task-specific limits, rather than relying on a vague instruction to “use AI responsibly.”

An illustrative agent-governance file

A concise, usable record can help everyone responsible for an AI workflow understand the same boundaries.

For a material agentic workflow, a concise internal governance file could include:

  1. Use-case statement: the business and legal task the workflow supports.
  2. Data map: the information the tool can receive, retrieve, create and transmit.
  3. Authority map: the systems and actions available to the agent.
  4. Risk scenarios: potential mistakes, misuse and attempts to redirect the workflow.
  5. Control map: measures assigned to each scenario.
  6. Validation record: representative test cases, expected results and identified limitations.
  7. Human checkpoints: named roles and approval thresholds.
  8. Vendor record: relevant contractual commitments, technical settings and change notices.
  9. Evidence plan: logging, retention, legal-hold and investigation procedures.
  10. Review trigger: events that prompt reassessment, such as a new model, integration, capability or incident report.

This list is an educational framework, not a compliance program or assurance that a firm has addressed every form of exposure. Its relevance will vary by jurisdiction, practice area, professional obligations, insurer expectations, client terms and system design.

Teams still need to consider the information involved, the consequences of error and the authority given to the system.

Moving fast and staying in control

At Fusion Legal & Tax, we see one durable posture for law firms: controlled acceleration. That means permitting useful experimentation while classifying workflows by capability, limiting authority by default, verifying legal output, preserving appropriate evidence and making escalation easy.

The emerging foreseeability discussion should not be framed as a reason to freeze. It is an invitation to make AI adoption more mature. Firms that can explain what their agents may access, what they may do, where people intervene and how the organization evaluates its controls can be better positioned to innovate with clarity as products, professional expectations and legal doctrine continue to develop.


This article provides general educational information for legal-industry audiences. It is not legal advice, does not establish an attorney-client relationship and should not be treated as a compliance standard. Organizations should evaluate AI governance in light of their own jurisdictions, professional obligations, client agreements, insurer requirements and technology environments.

Have Questions?
Chat with Margot