AI training · Legal
AI training for law firms
A practical session for a legal team: assistance with drafting and review, summaries of long files, the limits of research assistance, and confidentiality. One failure mode gets a section of its own, because in this profession it is the costliest: the source that does not exist.
Definition
What is AI training for law firms?
AI training for law firms is a practical programme for a legal team that teaches the use of AI tools in drafting, review and summarising, and at the same time establishes the routine by which every output is checked before it is used. It differs from a general AI course in two ways: the work is done on your own templates, and most of the time goes on source checking and confidentiality.
The reason is specific to the profession. In legal work an output rests on a source, and the form of a legal citation is exceptionally regular. A language model reproduces form very well, so it can produce a reference that looks immaculate from every angle and corresponds to no real document. This is the one area where we recommend a team have a written rule before its first working day with the tool. This programme is part of AI training for companies, adapted to legal teams. The Lithuanian edition is at DI mokymai teisininkams, and the systems side for practices is on AI for law firms.
Context
The same tool works in both directions
The strongest argument for training is not a productivity figure. It is that the same instrument, in the same team, helps or harms depending on the type of task and on whether the person can see the difference.
What the evidence behind this page actually is
| Source | Year | Sample | Key finding | Confidence |
|---|---|---|---|---|
| Dell’Acqua et al., HBS WP 24-013Source: Dell’Acqua et al., HBS Working Paper 24-013 | 2023 | 758 consultants, pre-registered field experiment, three randomised conditions | Inside the frontier: 12.2% more tasks, 25.1% faster. Outside it: 19 percentage points less likely to be correct | High for the causal direction, because of randomisation. It is a working paper, and the tasks are consulting tasks rather than legal ones |
| IBM, Cost of a Data Breach Report 2025Source: IBM, Cost of a Data Breach Report 2025 | 2025 | 600 breached organisations in 17 industries worldwide, researched by the Ponemon Institute | 20% of studied organisations had breaches linked to shadow AI, adding as much as USD 670K to the average breach cost | Medium. Vendor-published, based on interviews with breached organisations, so it describes those organisations rather than a general population |
| Mata v. Avianca, Inc., S.D.N.Y.Source: Mata v. Avianca, Inc., S.D.N.Y., 22-cv-1461 (PKC), 22 June 2023 | 2023 | One case, 22-cv-1461 (PKC), opinion and order on sanctions of 22 June 2023 | A penalty of USD 5,000 imposed jointly and severally on two attorneys and their firm over non-existent opinions with fake quotes and citations | High as to what the court decided, because it is the primary record. It is a single United States case and establishes no EU or UK precedent |
None of these sources measured AI use in a European law firm. We publish them as evidence about a mechanism, not as a claim about your practice.
Application
Where AI helps in legal work
The session works through four groups of task. They are chosen on the same criterion as in our other programmes: it must be possible to check the result more cheaply than doing the work again. Tasks that fail that test do not go into the programme.
1. Assistance with drafting
A first draft against the firm’s template, alternative formulations of a clause, a version of a letter to a client, the structure of an internal memo. The model is strong here because the task is linguistic. In the session we work on your templates, so a draft matches the firm’s style straight away rather than a generic internet standard that then has to be rewritten.
2. Review and comparing two versions
Finding missing clauses against a checklist, spotting inconsistent terms and definitions, collecting the differences between two versions into one table. The boundary we repeat throughout the session: the model says where to look, and the lawyer decides whether a clause is acceptable. Review assistance is attention direction, not an opinion.
3. Summaries of long documents
A summary of case material, correspondence or an expert report with references to specific pages. The only method we teach: ask for exact quotations from the uploaded document in a separate block first, and only then for the summary. A fabricated quotation is found by searching the document in seconds; a fabricated conclusion would have to be checked in full.
4. Research assistance
Explaining a concept in plain words, listing the arguments on both sides, drawing up questions before a client meeting, forming hypotheses about where to look. This is help with thinking, not a source. The gap between this group and the previous three is the widest on the page, which is why it gets a section of its own below. The layer of enquiries that arrives by phone is covered separately on AI for law firms.
What is not in this programme: legal advice, a view on any particular matter, and promises that AI will replace a lawyer’s judgement. We are an AI implementation company, so we teach people to work with the tool and leave legal decisions to the people accountable for them. If you are still working out which processes in the practice are worth changing, the sensible first step is scoping, and how we work sets out that sequence.
The core of it
Fabricated citations: the error that costs most in this profession
A language model holds no register of sources. It reproduces the form of text, and the form of a legal citation is among the most regular anybody could invent: party names, case number, year, court, page. So it can produce a reference that looks tidy from every side and simply does not exist. The same is true of an article number, a judgment date and a direct quotation from a text.
The second half of the error is the half that does the damage: when doubt arises, the person asks the same model whether the reference is real. The model confirms it and adds detail, because it is reproducing form again. So the training states the rule strictly and without exception: a reference counts as checked only when a person has opened it in the primary source and read it. Confirmation from inside the same chat window is not a check.
The documented case the training is built on
On 22 June 2023 the United States District Court for the Southern District of New York, in Mata v. Avianca, Inc., imposed a penalty of USD 5,000 jointly and severally on two attorneys and their law firm. The opinion records that they submitted non-existent judicial opinions with fake quotes and citations, and then continued to stand by the fake opinions after judicial orders called their existence into question. The court was careful about the tool itself: “Technological advances are commonplace and there is nothing inherently improper about using a reliable artificial intelligence tool for assistance. But existing rules impose a gatekeeping role on attorneys to ensure the accuracy of their filings.” This is a United States case, not an EU or UK precedent, and we do not present it as one. Its value is that the mechanism of the error, and the professional duty it collides with, are set down in a public primary record.
One exercise follows from that, and we never skip it. Participants are handed a summary containing several references, some real and some correctly formed but non-existent, and asked to separate them inside a set time and then write down what allowed them to tell. After that exercise nobody needs to be told why checking is a separate step in the work rather than a formality at the end.
Limits
Research assistance and where it ends
This table is filled in during the session with your team’s own tasks. The aim is that the line between “help with thinking” and “a source” becomes automatic.
| Task | Where AI fits | What must be checked |
|---|---|---|
| Explaining a concept in plain words | Fits as a starting point, especially in a new area or when something has to be put simply for a client | Every definition is compared against the text in force before it is used in a document |
| Setting out both sides of an argument | Fits for preparation: the model produces the opposing logic and the weak points quickly | Whether each argument rests on a real rule; an invented rule inside an argument looks exactly as tidy as a real one |
| A reference to a judgment | Does not fit as a source; fits only as a hint about what to look for in the primary database | The reference is opened in the source and read; confirmation from the same model does not count as a check |
| A direct quotation from a document | Fits only where the document has been uploaded and the quotation is asked for from its text | The quotation is found in the document character by character; a quotation not found is removed |
| A question about the version currently in force | Does not fit without an uploaded text: the model answers from training data and does not change its tone | The version is checked in the official source, and the model’s answer is used only to summarise the uploaded text |
| An overview of foreign law | Fits for initial orientation, when the point is to understand which questions arise at all | Every statement is checked in a local source or with a practitioner in that jurisdiction |
| Calculating a time limit | Does not fit: calculating in a chat window is one of the most unnecessary causes of error there is | The limit is calculated by hand or in the system and reconciled against the procedural document |
Confidentiality
What never goes into a consumer tool
A legal team’s confidentiality perimeter is wider than data protection: it covers client identity, case material, negotiating positions and internal assessments, even where none of it contains personal data. So the decision about what may go into an external tool is the firm’s decision, and in the training we help you write it down rather than take it for you.
During the session we write down four things: what goes up only anonymised, what is handled only in a company environment with agreed data retention terms, what nobody uploads, and who is told if too much went through by accident. In practice the last point is the most important, because without it a member of staff simply says nothing about a mistake. We recommend reviewing the boundary every six months, since tool terms change faster than internal procedures do. The technical side is on the security page, the vendor-by-vendor picture in does your AI vendor train on your data, and the full document structure on the internal AI use policy.
Why “do not upload sensitive documents” is not enough on its own
In IBM’s Cost of a Data Breach Report 2025, which analysed 600 breached organisations in 17 industries around the world, one in five studied organisations experienced breaches linked to shadow AI, meaning unsanctioned AI tools adopted by employees without IT or security oversight, and those incidents added as much as USD 670,000 to the average breach cost while disproportionately exposing customer personal data and intellectual property. Among breached organisations that experienced an AI-related security incident, 97 percent say they lacked proper AI access controls, and 63 percent of the organisations researched had no AI governance policies at all. A prohibition with no alternative works badly: where there is no convenient approved tool, the work moves into personal accounts that nobody can see.
Routine
A checking routine a legal team remembers
Upload the source rather than trusting memory
A task starts from a document or an official text. A question with no uploaded source is a question put to the model’s memory, and in legal work that is the wrong source.
Quotations first, conclusion second
Ask for exact quotations from the uploaded text in a separate block first, and only then for the summary or the proposal. You will check a quotation by searching the document; a conclusion would have to be checked in full.
Allow the answer “not found”
State in the task that a missing clause must be marked as not found rather than guessed. Without that sentence the model fills the gap with plausible text that reads like everything around it.
Every reference is opened in the source
Case number, article, date and page are checked in the primary database. This step is not skipped even when the reference looks familiar, and particularly then.
Do not check by asking the same model
Asked whether a reference is real, the model is inclined to confirm it and add detail. Checking means an external source, not a second question in the same conversation.
Write down what went wrong
Every error anybody notices goes onto a shared team list. After a few weeks that list becomes the firm’s internal guidance, and it is more useful than any generic instruction.
Who is responsible for the output
DigComp 3.0, the fifth edition of the European Digital Competence Framework published by the European Commission’s Joint Research Centre in 2025, states it directly in competence statement CS1.2.10: “Recognise that AI systems may produce output which is inaccurate, even if it may seem plausible, and that the human using the AI system is responsible for checking the quality and validity of information and content generated.” It is an EU institution assigning responsibility to the person using the tool rather than to the tool.
Programme
The session programme for a legal team
A basic session runs three to four hours; an extended one splits into two parts with a week in between, so the team works on its own in the gap.
Why the model invents a source
Enough theory for a lawyer to understand the mechanism and stop treating it as a random glitch. No neural network architecture.
Work on your own templates
Everyone works with anonymised firm documents and their own real tasks, rather than watching a demonstration on a screen.
The source-separation exercise
Real references and correctly formed but non-existent ones inside one document. This exercise replaces an hour of theory about reliability.
The confidentiality boundary in writing
During the session we write down what goes up, what does not, and who is told about a mistake. Without a reporting route the team just stays quiet.
Scenarios for the next working day
Each participant leaves with three to five scenarios they will use immediately, and one they have deliberately decided not to use.
A return session
After four to six weeks we come back to the same processes and look at which scenarios stuck, and where the obstacle turned out to be the process rather than the person.
The decision layer for managing partners is covered separately on AI training for executives. The sibling programme for finance teams is AI training for accountants. Terms are explained in the AI glossary, and what Article 4 of the EU AI Act actually says is in our explainer. Scope and price are agreed per engagement on a call.
FAQ
Frequently asked questions.
Founder & CEO, AInora
Building AI digital administrators that replace front-desk overhead for service businesses across Europe. Previously built voice AI systems for dental clinics, hotels, and restaurants.
View all articlesStart with your own documents.
An hour on a call to look at which of your legal team’s tasks suit AI, which do not, and what the checking routine will look like. No obligation.