Home The model Function Diagnostic Project and Change AI in legal About Get in touch
AI in legal and compliance

Practical AI adoption. Not theory.

Early adopter, hands-on builder, and governance practitioner. The AI work below has been done in production legal environments, not in a lab.

Hands-on experience

What has actually been built and run

Most AI commentary in legal is advisory. This is what working with Legal AI looks like when you are the one accountable for the outcome.

Early adoption
First Legal associate licensed for Microsoft Copilot
Led the Legal AI adoption programme at Novartis, including AI-driven contract analytics RFI-RFPs. Piloted Harvey, Wordsmith, and Leah in real legal workflows. Understanding what tools actually do versus what they claim to do takes time in the seat.
Build
Copilot Studio proof-of-concepts
Built a Legal chatbot, contract generator, and contract extractor using Copilot Studio. Also built the Mind Frame diagnostic tool and this website with significant AI assistance practical experience of AI-augmented delivery from the inside.
Training and governance
Internal training, workshops, and conference sessions
Delivered training and workshops on practical Legal AI adoption and governance at Novartis and externally at CLOC and Alternative In-House Europe. Governance is not a separate workstream it is what makes adoption sustainable.
Strategy
AI strategy for Legal and Compliance functions
Developed a full AI strategy framework covering use case identification, tool landscape, governance frameworks, vendor evaluation, and adoption roadmaps. The framework is grounded in what legal functions at pharma and medtech multinationals can realistically do, not what is theoretically possible.
The landscape

A strategy across seven layers

AI does not enter a legal function through a single decision. It arrives through seven distinct channels, each with different risk, different procurement requirements, and different governance needs. An effective AI strategy takes a clear position on each layer what to adopt, what to defer, and what to govern before it governs itself.

01
Open GenAI
ChatGPT, Claude, and similar tools used directly by lawyers. The highest governance risk and the lowest barrier to entry. Already in use whether you have a policy or not.
Requires: usage policy, data handling guardrails, output validation.
02
Enterprise productivity AI
M365 Copilot, Google Gemini AI embedded in daily tools. Faster to deploy than standalone tools and lower perceived risk, but governance requirements are the same.
Microsoft Copilot, Google Gemini for Workspace.
03
Internal AI builds
Custom tools built on enterprise AI platforms, leveraging internal data. Highest potential value, highest build cost, longest timeline.
Copilot Studio, Gemini Gems, custom GPT workflows.
04
Broad legal AI tools
Multi-use AI built for legal contracts, research, drafting, Q&A. Fast to deploy, wide coverage, strong vendor support. The most active part of the market right now.
Harvey, Legora, CoCounsel.
05
Specialist legal AI tools
Narrowly focused on one domain or workflow. Deeper capability than broad tools in their area, but point solutions that require careful integration into the wider stack.
Spellbook, Relativity, Compliance.ai.
06
Legal tech vendor AI
AI capabilities embedded in CLM, matter management, eBilling, and other platforms already in your stack. Often underused. Ask vendors what is in their roadmap before buying new tools.
Icertis AI, Legal Tracker intelligence features.
07
AI-enabled firms and ALSPs
Outside counsel and alternative providers offering AI-powered services. Access capabilities you cannot yet build internally, but understand what they are doing with your data and require explicit guardrails in engagement letters.
Requires: AI acceptable use standards in outside counsel guidelines.
Governance

The non-negotiable foundation

AI governance in legal is not a compliance checkbox. It is the difference between a function that can scale AI adoption confidently and one that is exposed every time a lawyer uses a personal account on a client matter.

The governance question is not whether to use AI. That decision has already been made by the lawyers in your function. The question is whether the function has a framework for managing it or whether it is finding out about the exposure after the fact.

In the Mind Frame maturity model, AI governance sits in the Operating Governance pillar. It is assessed alongside privilege and confidentiality controls, external firm guardrails, and the function's mandate to operate. The score for this pillar is frequently the one that surprises GCs most not because the risk is theoretical, but because the gap between what is happening and what is governed is already real.

Usage policy
What tools are permitted, on what types of matter, with what data. Needs to exist before adoption, not after the first incident.
Risk framework
How AI-generated output is validated. Human-in-the-loop requirements. What decisions AI can inform versus what it cannot make.
External firm guardrails
Acceptable use standards for outside counsel and ALSPs using AI on your matters. Needs to be in engagement letters, not assumed.
Incident response
What happens when AI produces a wrong output, a hallucination, or a confidentiality breach. Most functions do not have an answer.
Responsible AI
Bias, transparency, and accountability in AI-assisted decisions. Increasingly relevant for compliance and HR-adjacent legal work.
Where to start

A pragmatic approach

The functions that get the most from AI are not the ones with the biggest budgets. They are the ones that start with a clear picture of where they are, a governance framework that is proportionate to the risk, and a sequenced roadmap that does not try to do everything at once.

1
Understand what is already happening
Lawyers are already using AI. Find out what, on what types of matter, with what data. The gap between what is happening and what is governed is your starting risk.
2
Set an interim policy
An interim policy does not need to be comprehensive. It needs to set clear boundaries on what is permitted while the full governance framework is built. Done in days, not months.
3
Identify two or three use cases
High volume, low risk, clear value. Contract review, first draft, research. Pick the ones where AI failure is recoverable and the time saving is visible.
4
Build the roadmap from evidence
Use the pilot results to sequence the next investments. AI adoption that is driven by evidence rather than vendor pressure is more likely to deliver and more likely to hold.

AI is a capability, not a destination.

Powerful when it is directed. Expensive when it is not. The functions that get the most from AI are those that treat it as a capability to be built deliberately governed, sequenced, and grounded in what the function actually needs to do better.

Start with the Function Diagnostic