EU AI Act transparency duties apply now; high-risk duties from December 2027. Check your exposure
Insights About us Careers
Contact us
Solutions

AI Services for Legal and Compliance

More than two thousand court decisions now involve fabricated AI content, and almost all of them share the same missing step.

Risk
Function group
2,022 cases
As at 5 Sept 2026
Provenance
On every claim

Legal work has the most documented AI failure record of any function, which is unusually useful, because the failure mode is known precisely and it is avoidable by design.

In one paragraph

AI services for legal and compliance cover contract and obligation extraction, retrieval across prior advice and precedent with provenance, policy and playbook checking, regulatory change monitoring, matter and spend analytics, and the verification workflow required where output is relied on.

What the failure record actually shows

The AI Hallucination Cases database recorded 2,022 decisions worldwide as at 5 September 2026 in which a court found a party had relied on fabricated AI content. Read carefully it is a study of process failure rather than a case against the technology.

  • The distribution is wide. 1,379 in the United States, 217 in Canada, 110 in Australia and 69 in the United Kingdom, with entries from more than forty other jurisdictions.
  • Fabricated authority dominates. Around 1,677 instances of invented citations, 845 of misrepresented content and 547 of false quotation, all failures of generation with nothing to ground it.
  • Self represented litigants outnumber lawyers. 1,163 against 805, which identifies the real variable as whether anyone checked.
  • Sanctions are mostly procedural. Warnings, fines recorded between one dollar and 14,500 dollars, referrals, struck filings and adverse costs. The reputational cost exceeds the financial one.
  • The duty to verify is unchanged. Courts have been consistent that the obligation to check what you file does not change because a machine drafted it.
Worth knowing

Constrain the generation and the failure mode largely disappears

Every one of these failures involves a model asked to produce authority it was not given. A system that drafts only from documents you supplied, cites only sources it can point to in your own corpus, and marks anything it cannot support does not invent authority, because it has nowhere to invent it from. Add a verification step that a person actually performs and you have the productivity without the exposure. That is a design decision, made before tool selection rather than after an incident.

Contracts, which is where in house teams get the most back

Nobody can query the obligations they have signed

Most organisations hold their contractual commitments as documents in a repository, which means questions about notice periods, liability caps, change of control, audit rights and termination triggers become manual reviews every time they are asked.

Notice and deadline obligations have asymmetric cost

A missed notice can extinguish an entitlement worth more than the contract's margin. Extracting notice requirements into a structured register with dates that surface before they expire is unglamorous work with a very high payoff.

Playbook checking is the reliable review application

Comparing an incoming contract against your standard positions and flagging deviations for a lawyer is well posed, checkable, and it lets the team spend time on the deviations rather than the whole document.

Extraction needs deterministic checks

Dates must be internally consistent, values must match the commercial schedule, and anything uncertain must be flagged rather than averaged into a report that reads as authoritative. See contract analysis.

Advice retrieval, and the boundary that matters

ApplicationFitDesign requirement
Contract and obligation extractionStrongDeterministic checks; uncertain fields flagged
Obligation and notice registerStrongDates surfaced before they expire
Playbook and deviation checkingStrongDeviations flagged for a lawyer, not resolved automatically
Retrieval over your own prior adviceStrongProvenance and date on every result; superseded marked
Policy and guidance search for the businessStrongReduces routine questions reaching the legal team
Regulatory change monitoringGoodFiltered to your operations; a person assesses relevance
Matter and spend analyticsGoodWhere external spend goes and what it buys
Legal research into authorityCarefulOnly over a verified corpus, and never as the final check
Worth knowing

Date awareness is a specific risk in a legal corpus

Law changes, positions are superseded and advice given under a previous regime can be actively wrong today. A retrieval system over prior advice that cannot tell the user which period a position related to will confidently supply obsolete guidance, and the person relying on it carries the consequence. Every result should carry its date and the regime it applied to, and superseded material should be marked rather than merely ranked lower.

Process

How an engagement runs

Verification designed in, then the contract portfolio.

Weeks 1 to 2

Scope and verification design

Where the checking step sits and who performs it, before any build.

Weeks 3 to 6

Corpus assessment

Contract formats and volumes, advice archive currency, and confidentiality boundaries.

Weeks 7 to 12

Build

Obligation extraction with deterministic checks, or provenance carrying retrieval over prior advice.

Weeks 13 to 16

Trial

On live matters against lawyer judgement, with missed obligations measured specifically.

Ongoing

Operation

New contracts extracted on signature, superseded advice marked, verification audited.

Deliverables

What you receive

The obligations you have signed, queryable, and generation that cannot invent authority.

01

Contract obligation extraction

Notice periods, liability caps, change of control and termination triggers, structured.

02

Obligation and deadline register

Dates surfaced before they expire rather than discovered afterwards.

03

Playbook deviation checking

Incoming contracts compared to your standard positions, deviations flagged.

04

Advice retrieval

Provenance and date on every result, with superseded positions marked.

05

Business self service

Routine policy and process questions answered without reaching the legal team.

06

Verification workflow

A checking step built into the process with an audit trail rather than an assumption.

Fit check

Is this the right starting point?

Worth being direct. There are situations in legal and compliance where custom AI work is the wrong spend, and those are listed rather than buried.

Worth doing if

  • Questions about contractual obligations require manual document review every time.
  • Notice deadlines are tracked in a spreadsheet and some have been missed.
  • Contract review capacity is the constraint on commercial velocity.
  • Prior advice exists and only the author can find the right version.
  • Routine policy questions consume a large share of legal team time.

Do something else if

  • You want generated advice relied on without a lawyer verifying it.
  • Contracts are not available in digital form and there is no route to scanning them.
  • Superseded and current advice cannot be distinguished in the archive.
  • Confidentiality boundaries across matters cannot be represented in an index.
Questions

Frequently asked questions

Marked up with FAQPage schema so these answers can surface directly in search results and inside AI assistant responses.

How do we use generative AI without ending up in the sanctions record?

Constrain what it can draw on. Every one of the 2,022 recorded cases involves a model asked to produce authority it was never given, which is exactly what a system restricted to your own corpus cannot do. Require provenance on every factual claim, mark anything the system cannot support, and put a verification step into the workflow rather than into a training slide. It is worth knowing that self represented litigants account for more of those cases than lawyers do, 1,163 against 805, which shows the variable is whether anyone checked.

What is the highest value project for an in house team?

Contract obligation extraction. Most organisations hold their commitments as documents in a repository, so every question about notice periods, liability caps, change of control or audit rights becomes a manual review. Structuring those obligations makes the portfolio queryable, and the notice register alone has an asymmetric payoff, because a missed notice can extinguish an entitlement worth more than the contract's margin. It is checkable against the source, which makes it one of the safest applications available.

Is legal research a good application?

Only over a verified corpus and never as the final check. Research is precisely where open ended generation invents authority, because the task is to produce citations and a model will produce them whether or not they exist. Retrieval over a licensed database with citation to the source is a different and defensible thing. What no configuration removes is the professional obligation to verify before relying, and courts have been unambiguous that this duty does not change because a machine drafted the document.

Can we index all our prior advice?

Yes, and two design requirements decide whether it helps or harms. The first is date awareness: law changes, positions are superseded, and advice given under a previous regime can be actively wrong today, so every result must carry its date and the regime it applied to with superseded material marked. The second is confidentiality boundaries, which in a group with multiple entities or in a regulated business need enforcing in the index rather than stated in a policy.

How do we reduce routine questions reaching the team?

Give the business a way to find the answer. A large share of in house legal contact is people asking what the policy says, whether something needs approval, or which template to use, and that is a retrieval problem rather than a legal one. A well built self service layer over your policies and playbooks removes a substantial volume of interruption, and the questions it fails to answer are a precise list of what your policies do not currently cover.

Tell us what the problem looks like.

Thirty minutes, no charge, no deck. We will tell you whether this is an AI problem, a data problem, or a process problem, and we will say when the honest answer is to buy something rather than build it.