For many law firms, the conversation about artificial intelligence begins with a simple inventory question: Which AI tools have we approved? That is a useful question, but it is no longer a complete one.

A firm can have meaningful AI exposure even when it has never signed a contract for a dedicated legal AI platform. AI capabilities may already exist inside software the firm has used for years. Vendors may add them through ordinary product updates. Employees may experiment with public tools. Client portals, research platforms, document systems, meeting software, email products, and productivity suites may all introduce AI into the flow of firm information.

Key Concept

AI exposure is the total set of meaningful ways a firm's people, information, systems, vendors, and workflows interact with AI—not merely the list of AI products the firm knowingly purchased.

01 · The Old Model The approved-tools list is necessary. It is not enough.

Traditional technology governance often starts with procurement. A product is selected, reviewed, contracted, configured, and then approved for use. That process creates a relatively clear decision point.

AI does not always arrive that way. It may appear as a new button inside an existing platform, a model change behind a familiar interface, an automated feature activated by default, or a vendor integration that routes information through an AI service the firm never directly selected.

This means a firm can truthfully say it has approved only two AI tools while still having dozens of AI-enabled touchpoints across its operations. The gap between those two realities is where governance blind spots develop.

The question is no longer only, “Which AI tools did we buy?” It is, “Where can our information encounter AI?”

02 · A Broader View What AI exposure actually includes

AI exposure is broader than Shadow AI, although Shadow AI is one important part of it. Shadow AI usually refers to unapproved or undisclosed employee use. AI exposure also includes systems and capabilities the organization may be using openly but has not fully evaluated as AI-related governance decisions.

01

Embedded AI

AI features added to email, document management, research, billing, transcription, productivity, or collaboration platforms.

02

Vendor-Enabled AI

AI used by outside providers, subprocessors, support tools, or service platforms that handle firm or client information.

03

Employee Experimentation

Public chatbots, browser extensions, writing assistants, research tools, and other capabilities adopted without formal review.

04

Workflow Integrations

Automations, APIs, plug-ins, model routing, and connected systems that move information into or through AI services.

05

Client-Facing Systems

Intake tools, portals, communications platforms, support systems, or analytics used in delivering legal services.

06

Configuration Changes

Retention settings, model selection, training permissions, data sharing, access controls, and feature activation.

The important point is not that every exposure carries the same risk. It does not. The point is that firms cannot make reasoned decisions about exposures they do not know exist.

03 · Blind Spots Why firms often underestimate their exposure

AI is increasingly delivered as a feature, not a product

A dedicated AI purchase is obvious. An AI capability embedded in an existing system may not be. When technology providers market AI as an ordinary feature improvement, the governance significance can be easy to miss.

Procurement records rarely show the full picture

Contracts and approved-vendor lists tell a firm what it deliberately bought. They may not reveal what vendors later enabled, which models are used behind the scenes, or how information flows through connected services.

Employees do not always recognize a tool as AI

Many capabilities are framed as summarization, drafting, search, transcription, automation, assistance, or recommendations. Employees may use them without thinking of the activity as an AI use case requiring attention.

Configuration can matter as much as product selection

The same platform may present very different risk depending on whether data is retained, used for model improvement, accessible to third parties, routed to different models, or controlled through enterprise settings.

Governance Principle

A tool should not be considered fully approved without understanding the relevant capability, use case, model, data handling, and configuration.

04 · Why It Matters Invisible exposure creates visible consequences

The purpose of identifying AI exposure is not to create a catalog of every minor technical detail. It is to ensure that the firm can recognize and govern meaningful decisions before they become incidents, client concerns, or difficult questions the firm is unprepared to answer.

A limited view of AI can create several practical problems:

  • Confidential information may reach systems the firm has never evaluated.
  • Employees may receive inconsistent guidance about tools already present in their work.
  • Client questionnaire responses may be incomplete or overly confident.
  • Vendor risk reviews may focus on contract language while missing real system behavior.
  • Firm policies may prohibit conduct that embedded products quietly encourage.
  • Leadership may believe AI use is minimal because formal procurement is minimal.

None of this means firms should stop adopting AI. The opposite is true. Better visibility allows firms to approve valuable capabilities with greater confidence, define appropriate boundaries, and reduce unnecessary fear around responsible use.

The goal is not to eliminate AI exposure. The goal is to understand it, govern it, and make deliberate decisions about it.

05 · Practical Response How a firm can begin managing AI exposure

Firms do not need to document every prompt or require employees to report every individual AI interaction. That would create administrative burden without necessarily improving governance.

A better approach is to govern the significant organizational capabilities, configurations, workflows, and expectations that shape responsible use.

Starting Point

Five practical steps

01

Discover meaningful AI touchpoints

Review existing platforms, vendor relationships, integrations, employee practices, and recent software changes.

02

Prioritize by information and use case

Focus first on capabilities involving confidential information, legal analysis, client work, automated outputs, or consequential decisions.

03

Approve tools and configurations together

Record the approved capability, permitted uses, prohibited uses, safeguards, model or plan, and relevant settings.

04

Educate employees around practical boundaries

Explain what is approved, what information may be used, when human review is required, and when escalation is necessary.

05

Revisit exposure as systems change

Treat major feature releases, vendor changes, integrations, and new workflows as governance events—not merely technical updates.

Conclusion Visibility is the beginning of responsible governance

A law firm cannot responsibly govern AI by looking only at the products it knowingly purchased. AI is becoming part of the broader technology environment through which legal work is performed.

The firms that manage this well will not be the firms that prohibit everything or attempt to record every employee interaction. They will be the firms that develop visibility into meaningful AI exposure, make deliberate decisions, communicate those decisions clearly, and maintain evidence that the program is real.

That is the shift from an approved-tools list to an AI governance program.