Somewhere this week, a lawyer will paste an AI answer into a client email without reading it twice.
A public database maintained by legal researcher Damien Charlotin counts, at the time of writing, 1.751 court decisions worldwide involving fabricated or distorted AI-generated material. Every one of those decisions had to answer the same question: when the machine gets it wrong, who answers for it?
Several candidates, one signature
In a law firm, when an AI error reaches a client, three parties stand in the frame: the lawyer who used the tool, the firm that lawyer works for, and the provider that built it.
In a company, the frame is wider and messier. The error can be born anywhere an AI licence sits: in the legal department, but just as easily in sales, finance or customer care, quoting terms and giving assurances nobody reviewed. Towards the outside, nothing changes, because the company answers for whatever leaves in its name. Inside, the question splits in two: the function that produced the error owns the mistake, and the general counsel inherits a new kind of exposure, responsibility for legal risk generated by people who never thought they were doing legal work.
The mistake can also happen on the way in. Client data pasted into a public tool, a privileged document used as a prompt, a name that a thin anonymisation does not really hide: data privacy and professional secrecy can be breached before the machine writes a single word. Same question, one step earlier: who let the data in?
The provider, in both worlds, sits furthest from the consequence, by design. Contracts and terms of service say it plainly: the model can be wrong, and verification belongs to the user. The allocation looks tidy until it is tested: the error surfaces months later, inside work that passed through many hands, and by then the question has moved from what the licence said to who signed.
The insurance question
Bar associations, institutions, conferences, continuing education requirements and regulation are all converging on the same point: the responsible party remains human. The next question arrives on its own: is insurance necessary?
The question itself reveals the difficulty: this is a risk underwriters struggle to assess and to price.
A cyber or IT policy cannot simply be stretched to cover it, and from the outside an insurer cannot tell whether an organisation runs autonomous agents or a supervised drafting tool, how the work is structured, or where human review actually sits. They are being asked to put a premium on a black box working inside another black box.
As of spring 2026, no major American legal malpractice carrier has publicly filed an AI exclusion on its lawyers’ policies: more than a dozen have published guidance on how to use the tools instead, and only scattered manuscript exclusions are reported in smaller programmes. Coverage lawyers point to a sharper risk than any exclusion: when an unverified output reaches a client, the insurer can recast the loss as a technology failure rather than a lawyer’s judgment, and push the claim outside the policy.
Reflections
Clients and customers are learning to ask the same questions back: how is AI used on my matter, by whom, under whose supervision, explained in plain, complete language. And one more, still asked too rarely: is it insured?
For this reason, every organisation that lets AI touch its legal work, law firm or company, should be able to answer five questions without opening a drawer:
- Deployment. Which tools run, for which workflows, inside which limits, with which logs. If nobody can produce the list, the list is being written by employees, one personal subscription at a time.
- Literacy. Who has been trained, on what, how recently. Tools change every quarter; last year’s training session is archaeology.
- Policies. What exists in writing, and when it was last touched. A policy that lives in a drawer regulates the drawer.
- Confidentiality. What goes into the tools, and what never should: personal data, privileged documents, clients recognisable from the facts alone.
- Output. Who reads and verifies what goes out, whatever produced the first draft. In a law firm, that person has a signature. In a company, that person often does not exist.
On the other hand, there is no standardisation. Every client asks the same questions in a different format and every firm rebuilds answers client by client, matter by matter. Until a common standard emerges, one governance file, written once and updated often, separates answering from re-answering.
Our take
Professional services have always had one honest answer to the accountability question: the person whose name is on the work. However, AI multiplies the tools, the intermediaries and the paperwork. Will that answer survive?
Who answers for the machine in your firm? At Better Ipsum, we help law firms and legal teams deal with AI governance and strategy. Contact us if you want to know more