5–7 minutes
1,170 words

Artificial intelligence is no longer something that exists on the edge of legal practice.It is already becoming part of everyday work.Lawyers are using AI to draft contracts, summarise case files, conduct legal research, review documents, communicate with clients, and automate administrative workflows.

But there is a question many firms still struggle to answer:

Do you actually know where AI is being used across your firm?

For many organisations, the honest answer is no.And that creates a governance problem before it creates a technology problem.

The Shadow AI Problem

AI adoption inside a law firm rarely happens through one central decision.One team starts using ChatGPT.Another adopts Microsoft Copilot.Someone experiments with Claude.Another department begins using Gemini.A practice group purchases a specialised Legal AI platform.

An individual lawyer discovers an AI-powered research tool and starts using it independently.None of these decisions may appear particularly significant in isolation.But collectively, they can create an AI ecosystem that the firm’s leadership cannot see.That is where the risk begins.

You Can’t Govern What You Can’t See

Imagine asking your firm’s management team:

How many AI systems are currently being used by our lawyers and staff?

Then ask:

Who is using them?

What information are they entering?

Which systems process client information?

Which vendors retain data?

Which systems are being used for high-risk activities?

Which tools have been formally approved?

Which have never been reviewed?

If nobody can provide a reliable answer, the firm does not yet have an AI governance problem.It has something more fundamental:

a visibility problem.

What Is an AI Inventory?

An AI Inventory is essentially a structured record of the AI systems being used across an organisation.For a law firm, it should help establish a clear picture of the firm’s AI landscape.

At minimum, firms should be able to identify:

The AI system

What tool or platform is being used?

The users

Which lawyers, teams, or departments use it?

The purpose

What is the system being used to accomplish?

The data

What firm, client, personal, or confidential information is processed?

The risk

What potential legal, ethical, operational, confidentiality, or regulatory risks does the use create?

The controls

What policies, safeguards, human oversight, and contractual protections are already in place?This turns an invisible collection of AI experiments into something the organisation can actually govern.

Why This Matters for Law Firms

Law firms operate in an environment where information is exceptionally sensitive.

AI systems may interact with:

  • client communications;
  • personal data;
  • confidential documents;
  • litigation materials;
  • commercially sensitive information;
  • privileged information;
  • internal knowledge;
  • and legal research.

Without visibility, firms cannot reliably determine whether their existing controls are appropriate.That can create several problems.

Client confidentiality risks

Employees may unintentionally provide sensitive information to tools that have not been approved.

Data governance gaps

The firm may not know where information is being processed, stored, or transferred.

Inconsistent outputs

Different teams may use different systems with different capabilities, configurations, and reliability.

Regulatory challenges

The firm may struggle to demonstrate that AI use is being appropriately managed.

Operational risk

AI may become embedded in important workflows without anyone formally owning the associated risk.

An Inventory Is Not Just a Spreadsheet

This distinction matters.An AI inventory should not become another compliance document that gets created once and forgotten.AI tools change.Employees change.Vendors change their terms.Models change.Use cases expand.A system originally used for summarising internal documents may eventually be used for client-facing work.That means the inventory needs to be treated as a living governance mechanism.

The question is not simply:

“What AI tools do we have?”

It is:

“How is AI actually being used today?”

Start With Discovery, Not Policy

Many organisations approach AI governance in the wrong order.They begin by writing a policy.But how can you write an effective policy if you don’t understand the technology already being used?

A more logical sequence is:

Discover → Inventory → Assess → Control → Monitor

First, identify the systems.Then understand their use cases.Then assess their risks.Then establish appropriate controls.Finally, monitor the landscape as it changes.This is much more practical than creating a generic AI policy and hoping employees follow it.

What Should a Law Firm’s AI Inventory Capture?

A useful inventory could include fields such as:

CategoryKey question
AI ToolWhat system is being used?
OwnerWho is responsible for it?
UsersWhich teams use it?
PurposeWhat is it used for?
DataWhat information does it process?
Client DataIs confidential/client information involved?
Risk LevelWhat could go wrong?
VendorWho provides the system?
Human OversightWho reviews the output?
ApprovalHas the firm authorised its use?
ControlsWhat safeguards exist?
Review DateWhen should the system be reassessed?

The precise structure will vary between firms.

The important thing is that the inventory creates visibility and accountability.

The AI Inventory Also Changes How Firms Think About Risk

Once the firm can see its AI landscape, another important question becomes possible:Where is AI actually creating risk?

Not every AI use case deserves the same level of scrutiny.Using AI to improve the formatting of an internal document is obviously different from using AI to analyse confidential litigation material.Likewise, an internal brainstorming tool is different from an AI system communicating directly with prospective clients.The inventory therefore becomes the foundation for risk-based governance.The firm can concentrate its strongest controls where they matter most.

The 2027 Question

The EU AI Act’s implementation timeline continues to develop, including changes affecting the timing of certain obligations.That makes preparation more important, not less.

Firms that wait until every obligation becomes immediately applicable may find themselves trying to understand their AI environment, classify systems, assess vendors, create policies, train staff, and establish controls simultaneously.That is an unnecessarily difficult position.

A firm that starts with an inventory has already completed one of the most important steps:It knows what it needs to govern.

AI Governance Begins With Visibility

There is a simple principle behind all of this:

You cannot manage what you cannot see.

A law firm cannot meaningfully govern AI if AI use is happening invisibly across departments, devices, applications, and individual workflows.The first step is not necessarily buying another AI governance platform.It may simply be asking the right questions.

Where is AI being used?

Who is using it?

What information is going into it?

What decisions depend on it?

Who is accountable for the result?

Once those questions can be answered, meaningful governance can begin.

Conclusion

The AI challenge facing law firms is not simply that AI is becoming more powerful.It is that AI is becoming distributed.It is moving into everyday workflows, often faster than formal governance structures can keep up.That makes an AI Inventory one of the most practical foundations for responsible AI adoption.Because before a firm can establish meaningful policies, assess risk, train its people, or demonstrate responsible use, it needs to know what it is actually dealing with.AI governance doesn’t begin with policies.It begins with visibility.And the firms that understand their AI landscape before they are forced to will be in a far stronger position to govern it responsibly.You can’t manage what you can’t see.