Law firm AI policies often include a sensible requirement: AI-generated work must be reviewed by a lawyer before it is used. That is an important starting point. But “human review required” does not explain what the reviewer should examine, what level of scrutiny is appropriate, or how the firm knows that meaningful review actually occurred.

As AI becomes embedded in research, drafting, document analysis, discovery, intake, knowledge systems, and other legal workflows, supervision must become more operational. A firm should be able to show not only that human review was required, but also that responsible oversight was built into the way AI-assisted work was performed.

Key Concept

AI may assist with the work. It does not assume responsibility for the result.

01 · Professional ResponsibilityThe lawyer remains responsible

Generative AI does not replace the lawyer’s professional responsibility for the final work. ABA Formal Opinion 512 explains that lawyers using generative AI must consider existing duties involving competence, confidentiality, communication, supervision, candor, meritorious claims, and reasonable fees. It also emphasizes the need to understand the capabilities and limitations of the tools used and to review their output appropriately.

The Florida Bar has similarly stated that lawyers remain responsible for their work product and professional judgment. Its guidance calls for policies and practices that verify whether generative AI use is consistent with the lawyer’s ethical obligations.

Human review is not a transfer of responsibility. It is the process through which the lawyer retains responsibility.

02 · The Operating Gap“Human review” is too vague

A policy may say that a lawyer must review all AI-generated content. But that instruction leaves several questions unanswered:

  • What must be reviewed?
  • How thoroughly must it be reviewed?
  • Does the required review change according to the task?
  • Must sources and citations be independently confirmed?
  • Who is responsible when one person generates the work and another approves it?
  • What happens when the reviewer finds a material problem?
  • Is there any record that the review occurred?

A quick reading of a draft is not necessarily meaningful supervision. The appropriate review should reflect the nature of the work, the risks involved, the AI capability used, the information provided to the system, and the consequences of an error.

A short internal summary may not require the same process as a court filing, client opinion, transaction document, or analysis containing confidential information. The obligation to exercise professional judgment remains, but the depth and form of review should be proportionate to the risk.

03 · A Practical StandardSupervision is a process, not a policy sentence

01

Verify

Confirm factual statements, legal authorities, quotations, citations, calculations, names, dates, and other material details against reliable sources.

02

Evaluate

Assess whether the output is appropriate for the matter, jurisdiction, task, approved capability, client requirements, and confidentiality obligations.

03

Exercise Judgment

Decide whether to accept, modify, reject, or supplement the AI-assisted work based on the lawyer’s independent professional judgment.

04

Document When Appropriate

Preserve a concise supervisory record for higher-risk work, new capabilities, material issues, or situations where evidence of oversight may later matter.

Not every AI-assisted action needs its own formal record. Requiring employees to document every prompt or minor use would create unnecessary work and discourage responsible adoption. Documentation becomes more valuable when the use is higher-risk, when the firm is testing a new capability, when an issue is discovered, or when the firm needs evidence that its governance requirements are functioning.

Practical Principle

The goal is not surveillance or exhaustive prompt logging. It is evidence of reasonable oversight where the risk justifies it.

04 · Proportionate OversightSupervision should be risk-based

Routine internal assistance

Brainstorming, reformatting nonconfidential material, or generating an initial internal outline may justify informal review, provided the tool and use are permitted and the lawyer remains responsible for the result.

Substantive legal work

Research summaries, contract analysis, drafting, discovery support, and client-facing communications require closer review. The lawyer should verify material facts and authorities, evaluate completeness, and make independent decisions about the final work.

High-consequence work

Court filings, formal opinions, sensitive investigations, major transaction documents, or work involving significant confidential information may justify a more structured review and a preserved supervisory record. The firm may also require partner approval, confirmation of specific checks, or documentation of the AI capability and approved configuration used.

The distinction should be based on risk, not merely on whether AI was involved.

05 · Closing the LoopReview findings should lead somewhere

A supervisory review is most valuable when it connects to the rest of the firm’s governance program. Suppose a reviewer discovers that an AI-assisted research memorandum contains nonexistent authorities. Correcting the memorandum addresses the immediate problem, but the firm should also consider whether the finding points to a broader need.

The appropriate follow-up might include:

  • refresher education for the employee;
  • a targeted knowledge check;
  • clarification of the AI policy;
  • a change to an approved capability or configuration;
  • additional review requirements for certain work;
  • confirmation that other employees understand the same risk; or
  • a scheduled recheck to determine whether the corrective action worked.
Without follow-up, the firm has documented an issue. With follow-up, it has demonstrated improvement.

Policies, acknowledgements, attestations, and supervisory reviews serve different purposes

An AI policy defines the firm’s expectations. An acknowledgement shows that an employee received and accepted those expectations. An attestation asks the employee to confirm current conduct or disclose concerns. A supervisory review examines whether responsible practices are actually visible in the work.

These records are related, but they are not interchangeable. A signed acknowledgement does not establish that every AI-assisted document was properly reviewed. An employee attestation does not independently evaluate the quality of completed work. A supervisory review gives the firm a separate form of operational evidence.

06 · Governance EvidenceEvidence matters when someone asks

Clients, insurers, auditors, courts, and other stakeholders may ask how a firm governs AI. A policy may answer part of that question. It can describe permitted and prohibited uses, confidentiality requirements, approved tools and configurations, and human-review expectations.

A stronger response can also show that the firm:

  • educates its people;
  • records participation;
  • monitors relevant developments;
  • reviews AI-assisted work where appropriate;
  • follows up when concerns are identified; and
  • preserves evidence of its decisions and improvements.

That does not require documenting every AI interaction. It requires maintaining enough connected evidence to demonstrate that the firm’s governance process is real and ongoing.

Supervisory Review Standard

Four practical actions

01

Verify the material details

Check facts, authorities, quotations, citations, calculations, names, dates, and other consequential information.

02

Evaluate the work in context

Consider completeness, jurisdiction, confidentiality, client instructions, approved use, and the consequences of error.

03

Exercise independent professional judgment

Accept, revise, reject, or supplement the work based on the lawyer’s own analysis and responsibility.

04

Document meaningful supervision when appropriate

Create a concise record for higher-risk work, material findings, corrective action, and scheduled follow-up.

ConclusionThe question is not whether a human looked at the output

The more useful question is whether the firm can reasonably demonstrate that a qualified person evaluated the work, exercised judgment, addressed material concerns, and preserved appropriate evidence of responsible oversight.

That is the difference between requiring human review and operating a system of AI supervision.

SourcesProfessional guidance referenced