AInora

AI training · Legal

AI training for law firms

A practical session for a legal team: assistance with drafting and review, summaries of long files, the limits of research assistance, and confidentiality. One failure mode gets a section of its own, because in this profession it is the costliest: the source that does not exist.

Published

Definition

What is AI training for law firms?

AI training for law firms is a practical programme for a legal team that teaches the use of AI tools in drafting, review and summarising, and at the same time establishes the routine by which every output is checked before it is used. It differs from a general AI course in two ways: the work is done on your own templates, and most of the time goes on source checking and confidentiality.

The reason is specific to the profession. In legal work an output rests on a source, and the form of a legal citation is exceptionally regular. A language model reproduces form very well, so it can produce a reference that looks immaculate from every angle and corresponds to no real document. This is the one area where we recommend a team have a written rule before its first working day with the tool. This programme is part of AI training for companies, adapted to legal teams. The Lithuanian edition is at DI mokymai teisininkams, and the systems side for practices is on AI for law firms.

Context

The same tool works in both directions

The strongest argument for training is not a productivity figure. It is that the same instrument, in the same team, helps or harms depending on the type of task and on whether the person can see the difference.

+12.2%
more tasks completed with AI where the task sat inside the model’s capability frontier (pre-registered experiment, 758 consultants)
Source: Dell’Acqua et al., HBS WP 24-013
19 pp
less likely to produce a correct solution, in the same experiment, on a task selected to be outside that frontier
Source: Dell’Acqua et al., HBS WP 24-013
20%
of studied organisations experienced breaches linked to shadow AI, meaning unsanctioned tools adopted without IT or security oversight
Source: IBM, Cost of a Data Breach 2025
97%
of breached organisations that had an AI-related security incident say they lacked proper AI access controls
Source: IBM, Cost of a Data Breach 2025

What the evidence behind this page actually is

SourceYearSampleKey findingConfidence
Dell’Acqua et al., HBS WP 24-013Source: Dell’Acqua et al., HBS Working Paper 24-0132023758 consultants, pre-registered field experiment, three randomised conditionsInside the frontier: 12.2% more tasks, 25.1% faster. Outside it: 19 percentage points less likely to be correctHigh for the causal direction, because of randomisation. It is a working paper, and the tasks are consulting tasks rather than legal ones
IBM, Cost of a Data Breach Report 2025Source: IBM, Cost of a Data Breach Report 20252025600 breached organisations in 17 industries worldwide, researched by the Ponemon Institute20% of studied organisations had breaches linked to shadow AI, adding as much as USD 670K to the average breach costMedium. Vendor-published, based on interviews with breached organisations, so it describes those organisations rather than a general population
Mata v. Avianca, Inc., S.D.N.Y.Source: Mata v. Avianca, Inc., S.D.N.Y., 22-cv-1461 (PKC), 22 June 20232023One case, 22-cv-1461 (PKC), opinion and order on sanctions of 22 June 2023A penalty of USD 5,000 imposed jointly and severally on two attorneys and their firm over non-existent opinions with fake quotes and citationsHigh as to what the court decided, because it is the primary record. It is a single United States case and establishes no EU or UK precedent

None of these sources measured AI use in a European law firm. We publish them as evidence about a mechanism, not as a claim about your practice.

Application

Where AI helps in legal work

The session works through four groups of task. They are chosen on the same criterion as in our other programmes: it must be possible to check the result more cheaply than doing the work again. Tasks that fail that test do not go into the programme.

1. Assistance with drafting

A first draft against the firm’s template, alternative formulations of a clause, a version of a letter to a client, the structure of an internal memo. The model is strong here because the task is linguistic. In the session we work on your templates, so a draft matches the firm’s style straight away rather than a generic internet standard that then has to be rewritten.

2. Review and comparing two versions

Finding missing clauses against a checklist, spotting inconsistent terms and definitions, collecting the differences between two versions into one table. The boundary we repeat throughout the session: the model says where to look, and the lawyer decides whether a clause is acceptable. Review assistance is attention direction, not an opinion.

3. Summaries of long documents

A summary of case material, correspondence or an expert report with references to specific pages. The only method we teach: ask for exact quotations from the uploaded document in a separate block first, and only then for the summary. A fabricated quotation is found by searching the document in seconds; a fabricated conclusion would have to be checked in full.

4. Research assistance

Explaining a concept in plain words, listing the arguments on both sides, drawing up questions before a client meeting, forming hypotheses about where to look. This is help with thinking, not a source. The gap between this group and the previous three is the widest on the page, which is why it gets a section of its own below. The layer of enquiries that arrives by phone is covered separately on AI for law firms.

What is not in this programme: legal advice, a view on any particular matter, and promises that AI will replace a lawyer’s judgement. We are an AI implementation company, so we teach people to work with the tool and leave legal decisions to the people accountable for them. If you are still working out which processes in the practice are worth changing, the sensible first step is scoping, and how we work sets out that sequence.

The core of it

Fabricated citations: the error that costs most in this profession

A language model holds no register of sources. It reproduces the form of text, and the form of a legal citation is among the most regular anybody could invent: party names, case number, year, court, page. So it can produce a reference that looks tidy from every side and simply does not exist. The same is true of an article number, a judgment date and a direct quotation from a text.

The second half of the error is the half that does the damage: when doubt arises, the person asks the same model whether the reference is real. The model confirms it and adds detail, because it is reproducing form again. So the training states the rule strictly and without exception: a reference counts as checked only when a person has opened it in the primary source and read it. Confirmation from inside the same chat window is not a check.

The documented case the training is built on

On 22 June 2023 the United States District Court for the Southern District of New York, in Mata v. Avianca, Inc., imposed a penalty of USD 5,000 jointly and severally on two attorneys and their law firm. The opinion records that they submitted non-existent judicial opinions with fake quotes and citations, and then continued to stand by the fake opinions after judicial orders called their existence into question. The court was careful about the tool itself: “Technological advances are commonplace and there is nothing inherently improper about using a reliable artificial intelligence tool for assistance. But existing rules impose a gatekeeping role on attorneys to ensure the accuracy of their filings.” This is a United States case, not an EU or UK precedent, and we do not present it as one. Its value is that the mechanism of the error, and the professional duty it collides with, are set down in a public primary record.

Source: Mata v. Avianca, Inc., S.D.N.Y., 22-cv-1461 (PKC), 22 June 2023

One exercise follows from that, and we never skip it. Participants are handed a summary containing several references, some real and some correctly formed but non-existent, and asked to separate them inside a set time and then write down what allowed them to tell. After that exercise nobody needs to be told why checking is a separate step in the work rather than a formality at the end.

Limits

Research assistance and where it ends

This table is filled in during the session with your team’s own tasks. The aim is that the line between “help with thinking” and “a source” becomes automatic.

TaskWhere AI fitsWhat must be checked
Explaining a concept in plain wordsFits as a starting point, especially in a new area or when something has to be put simply for a clientEvery definition is compared against the text in force before it is used in a document
Setting out both sides of an argumentFits for preparation: the model produces the opposing logic and the weak points quicklyWhether each argument rests on a real rule; an invented rule inside an argument looks exactly as tidy as a real one
A reference to a judgmentDoes not fit as a source; fits only as a hint about what to look for in the primary databaseThe reference is opened in the source and read; confirmation from the same model does not count as a check
A direct quotation from a documentFits only where the document has been uploaded and the quotation is asked for from its textThe quotation is found in the document character by character; a quotation not found is removed
A question about the version currently in forceDoes not fit without an uploaded text: the model answers from training data and does not change its toneThe version is checked in the official source, and the model’s answer is used only to summarise the uploaded text
An overview of foreign lawFits for initial orientation, when the point is to understand which questions arise at allEvery statement is checked in a local source or with a practitioner in that jurisdiction
Calculating a time limitDoes not fit: calculating in a chat window is one of the most unnecessary causes of error there isThe limit is calculated by hand or in the system and reconciled against the procedural document

Confidentiality

What never goes into a consumer tool

A legal team’s confidentiality perimeter is wider than data protection: it covers client identity, case material, negotiating positions and internal assessments, even where none of it contains personal data. So the decision about what may go into an external tool is the firm’s decision, and in the training we help you write it down rather than take it for you.

During the session we write down four things: what goes up only anonymised, what is handled only in a company environment with agreed data retention terms, what nobody uploads, and who is told if too much went through by accident. In practice the last point is the most important, because without it a member of staff simply says nothing about a mistake. We recommend reviewing the boundary every six months, since tool terms change faster than internal procedures do. The technical side is on the security page, the vendor-by-vendor picture in does your AI vendor train on your data, and the full document structure on the internal AI use policy.

Why “do not upload sensitive documents” is not enough on its own

In IBM’s Cost of a Data Breach Report 2025, which analysed 600 breached organisations in 17 industries around the world, one in five studied organisations experienced breaches linked to shadow AI, meaning unsanctioned AI tools adopted by employees without IT or security oversight, and those incidents added as much as USD 670,000 to the average breach cost while disproportionately exposing customer personal data and intellectual property. Among breached organisations that experienced an AI-related security incident, 97 percent say they lacked proper AI access controls, and 63 percent of the organisations researched had no AI governance policies at all. A prohibition with no alternative works badly: where there is no convenient approved tool, the work moves into personal accounts that nobody can see.

Source: IBM, Cost of a Data Breach Report 2025

Routine

A checking routine a legal team remembers

1

Upload the source rather than trusting memory

A task starts from a document or an official text. A question with no uploaded source is a question put to the model’s memory, and in legal work that is the wrong source.

2

Quotations first, conclusion second

Ask for exact quotations from the uploaded text in a separate block first, and only then for the summary or the proposal. You will check a quotation by searching the document; a conclusion would have to be checked in full.

3

Allow the answer “not found”

State in the task that a missing clause must be marked as not found rather than guessed. Without that sentence the model fills the gap with plausible text that reads like everything around it.

4

Every reference is opened in the source

Case number, article, date and page are checked in the primary database. This step is not skipped even when the reference looks familiar, and particularly then.

5

Do not check by asking the same model

Asked whether a reference is real, the model is inclined to confirm it and add detail. Checking means an external source, not a second question in the same conversation.

6

Write down what went wrong

Every error anybody notices goes onto a shared team list. After a few weeks that list becomes the firm’s internal guidance, and it is more useful than any generic instruction.

Who is responsible for the output

DigComp 3.0, the fifth edition of the European Digital Competence Framework published by the European Commission’s Joint Research Centre in 2025, states it directly in competence statement CS1.2.10: “Recognise that AI systems may produce output which is inaccurate, even if it may seem plausible, and that the human using the AI system is responsible for checking the quality and validity of information and content generated.” It is an EU institution assigning responsibility to the person using the tool rather than to the tool.

Source: European Commission JRC, DigComp 3.0

Programme

The session programme for a legal team

A basic session runs three to four hours; an extended one splits into two parts with a week in between, so the team works on its own in the gap.

Why the model invents a source

Enough theory for a lawyer to understand the mechanism and stop treating it as a random glitch. No neural network architecture.

Work on your own templates

Everyone works with anonymised firm documents and their own real tasks, rather than watching a demonstration on a screen.

The source-separation exercise

Real references and correctly formed but non-existent ones inside one document. This exercise replaces an hour of theory about reliability.

The confidentiality boundary in writing

During the session we write down what goes up, what does not, and who is told about a mistake. Without a reporting route the team just stays quiet.

Scenarios for the next working day

Each participant leaves with three to five scenarios they will use immediately, and one they have deliberately decided not to use.

A return session

After four to six weeks we come back to the same processes and look at which scenarios stuck, and where the obstacle turned out to be the process rather than the person.

The decision layer for managing partners is covered separately on AI training for executives. The sibling programme for finance teams is AI training for accountants. Terms are explained in the AI glossary, and what Article 4 of the EU AI Act actually says is in our explainer. Scope and price are agreed per engagement on a call.

FAQ

Frequently asked questions.

It is a hands-on session for a legal team, worked on that team’s own documents: drafts of contracts and procedural documents, review, summaries of long files, and internal memos. Most of the programme is not about writing prompts but about source checking and confidentiality, because that is where the expensive mistakes are in legal work.
It can prepare a draft, not a document you can file. A language model produces the most probable continuation, not a verified legal source, so every reference, every quotation and every statement about a rule in force has to be checked in the primary source. Accountability for the content of a filed document stays with the lawyer. DigComp 3.0, the European Commission’s digital competence framework, states that the human using the AI system is responsible for checking the quality and validity of information and content generated.Source: European Commission JRC, DigComp 3.0
The model learns the shape of text, and the shape of a legal citation is exceptionally regular: party names, case number, year, court, page. So it can produce a reference that matches the form perfectly and matches no real document, and deliver it in the same tone as a real one. The practical training rule is simple: a reference counts as checked only when a person has opened it in the primary source and read it.
Yes, and at least one instance is documented in a public court record. On 22 June 2023 the United States District Court for the Southern District of New York, in Mata v. Avianca, Inc., imposed a penalty of USD 5,000 jointly and severally on two attorneys and their law firm, after they submitted non-existent judicial opinions with fake quotes and citations and then continued to stand by them once judicial orders called their existence into question. That is a United States case, not an EU or UK precedent, and we do not present it as one. Its value is that the mechanism of the error is recorded precisely in a public document.Source: Mata v. Avianca, Inc., S.D.N.Y., 22 June 2023
The firm sets that boundary itself, and in the training we help you write it down rather than take the decision for you. The starting position we suggest: client identity, case material, negotiating positions and internal assessments do not go into a consumer account, and where a document is needed for the work it is either anonymised or handled in a company environment with agreed data retention terms.
For review assistance yes, for the decision no. The model is good at finding places worth looking at: missing clauses, inconsistent defined terms, repetitions, differences between two versions. The assessment of whether a clause is acceptable is made by the lawyer. In the session we practise that boundary on your own templates, so it stays a habit rather than a principle.
A basic session runs three to four hours; an extended programme splits into two parts with a week in between. In BCG’s 2025 survey of 10,635 respondents, the share of employees who are regular AI users rose from 18 percent with no training to 89 percent among those with more than ten hours, so a one-off presentation builds no habit.Source: BCG, AI at Work 2025
Not in the form the market usually claims, though an obligation does exist. Article 4 requires providers and deployers of AI systems to take measures to support the development of AI literacy of their staff; it binds and has applied since 2 February 2025. Article 4 is not listed in Article 99(4), so it carries no EU-level fine ceiling of EUR 15 million or 3 percent of turnover, and any consequence runs instead through national law under Article 99(1), a paragraph the 2026 amendment widened rather than narrowed. The European Commission adds that no strict requirements or mandatory trainings are imposed and that there is no need for a certificate, and answers separately that employees using a general assistant should be informed about the specific risks, giving hallucination as the example. For a legal team that specific risk has a name, and it is the subject of half this page. This is general information, not legal advice.Source: European Commission, AI literacy Q&A
JB
Justas Butkus

Founder & CEO, AInora

Building AI digital administrators that replace front-desk overhead for service businesses across Europe. Previously built voice AI systems for dental clinics, hotels, and restaurants.

View all articles

Start with your own documents.

An hour on a call to look at which of your legal team’s tasks suit AI, which do not, and what the checking routine will look like. No obligation.