Blog

Using AI Safely: A Practical Guide for Lawyers

Hananeh Shahteimoori 8 min read
Using AI Safely: A Practical Guide for Lawyers

Mira had been a junior associate for four months when her supervising partner asked her to run a batch of NDAs through the firm’s new AI tool before their call that afternoon. She opened it and typed the first prompt that came to mind: “Summarize this NDA.” The output looked polished: clean paragraphs, confident language, a summary that read like it knew exactly what it was talking about. She almost sent it straight to the partner.

Then she noticed one clause referenced a governing law the NDA never mentioned. Nothing in her training had told her to expect that, or to check for it. She caught it this time. She was not sure she would catch it next time.

That gap, between having the tool and knowing how to use it safely, is where most legal AI mistakes happen.

Why AI literacy matters

Three things are at stake, and they are not the same problem.

  • Risk: AI tools produce fluent, confident output that is sometimes wrong. A fabricated citation or an invented clause reads exactly like a real one, which is what makes unsupervised AI use a real risk. Mata v. Avianca is the case everyone in legal tech now cites for a reason: a lawyer submitted a court brief built on cases a chatbot had invented, then defended those citations before a judge caught the fabrication and sanctioned the lawyers involved.
  • Ethics: Competence, diligence, and confidentiality do not pause because a tool did the first draft. If a lawyer cannot explain why a model produced a given answer or where a client’s data went after it was submitted, they are not in a position to rely on that answer in front of a client or a court.
  • Efficiency: This is the one people underestimate. Without literacy, a team either avoids AI entirely, losing the time savings it could offer, or trusts it blindly, which creates more rework than it saves once someone has to catch and fix the errors downstream. Literacy is what makes the efficiency gain real instead of borrowed against future cleanup.

Key terms in practice

Knowing what a term actually means is the first step toward using AI well, and that knowledge pays off the moment it meets a real document, a tight deadline, and a partner waiting on an answer. The three ideas below are the ones that come up constantly in day-to-day legal AI use, shown the way they actually play out in a workflow. The better you understand them, the more precisely you can direct the tool instead of just hoping it gets things right.

  • Prompt engineering, applied to contract review: A vague prompt gets a vague, unreliable answer. “Summarize this NDA,” the prompt Mira typed in the opening story, invites the tool to guess what matters. “List every clause in this NDA that references a governing law other than German law, and flag any clause with an undefined term” gives it a specific task with a checkable answer. The second prompt is not more clever. It is just precise enough that a wrong answer would be obvious.
  • Hallucinations, explained with an example: Ask an AI tool to summarize recent case law on non-compete clauses in a specific jurisdiction, and it may return a paragraph citing a court decision, complete with a plausible-looking file number, that does not exist. Nothing about the sentence looks wrong. That is the actual risk: hallucinated output is not garbled or obviously broken, it is fluent, which is exactly why it needs to be checked against a real source every time.
  • Confidentiality, do’s and don’ts: Do not paste unredacted client data (deal terms, case facts, names) into a public consumer chatbot; it may store or train on what you submit, and that data has now left the firm’s control. Do use a tool with a data-processing agreement and clear hosting terms, and redact what you can before anything goes in. Picture an associate about to paste a client’s term sheet into a public AI tool to speed up a summary, catching it, and running the same task through the firm’s vetted tool instead. That one habit is most of the difference between safe and unsafe AI use.
AI Glossary for Legal Professionals Free download Keep the full glossary on hand The three terms above are a preview. The download covers 40+, with the same practical, example-driven explanations, so you have a precise answer ready the next time a vendor call or a meeting outruns your vocabulary. Download the free glossary

Common mistakes

  • Over-relying on AI summaries. Reading the summary instead of the document it summarizes, then acting on the summary as if it were the source.
  • Not verifying outputs. Forwarding AI-drafted text to a client or court without checking citations, figures, or clauses against a primary source.
  • Treating vendor claims as guarantees. “Enterprise-grade” or “hallucination-free” is marketing language, not a specification. Ask what the claim actually means and how it is tested.
  • Skipping confidentiality checks because a tool feels secure. A clean interface says nothing about where data is hosted or whether it is used for training.

Practical steps for law firms

  • Set guardrails before anyone starts. Write down which tools are approved, what categories of data can and cannot go into them, and when a human review checkpoint is mandatory before output reaches a client. Name one person as the point of contact for AI questions, so the team has somewhere to go instead of guessing individually.
  • Vet the tool itself first. Confirm a data-processing agreement, hosting location, and what happens to submitted data before anyone is allowed to use it for client work. This is the confidentiality check from above, done once at the firm level instead of left to each person’s judgment.
  • Run structured training, not a one-off briefing. A single slide deck does not build the instinct to catch a hallucinated clause. A hands-on session, with real documents and real failure cases, does.
  • Start with low-risk, verifiable tasks. First-pass review or routine drafting, where a wrong answer is easy to catch, builds trust in the tool and in the process before it touches anything higher-stakes.

None of these steps require a technical background, and none of them happen overnight. What they build, together, is the instinct Mira was missing in the opening story: the pause before sending something out, and the specific knowledge to know what to check first. That instinct is what turns AI from a shortcut a firm hopes works into a tool it can actually rely on.

FAQ

What does AI literacy mean in practice for a lawyer?

It means enough working knowledge to use AI tools without breaching professional duties: writing a specific prompt instead of a vague one, recognizing when output might be hallucinated, knowing what data is safe to paste into a tool, and verifying anything before it reaches a client or court.

What is a hallucination in AI output, with an example?

A hallucination is confident, fluent output that is factually wrong. Ask a tool to summarize case law on a narrow topic and it may return a paragraph citing a court decision, complete with a plausible-looking file number, that does not exist. It reads exactly like a real citation until someone checks.

What should never be pasted into a public AI chatbot?

Unredacted client data: names, deal terms, case facts, anything covered by confidentiality or privilege. Public consumer tools may store or train on what is submitted, sending client information outside the firm’s control. Use a tool with a data-processing agreement and clear hosting terms instead.

Over-relying on an AI-generated summary without reading the underlying document, or forwarding AI output without verifying it against a primary source. Fluent output is not the same as correct output, and responsibility for the final work product stays with the person who sent it.

What safeguards should a law firm put in place before rolling out AI tools?

Written guardrails on which tools are approved and what data can go into them, due diligence on the tool’s data-processing agreement and hosting before anyone uses it for client work, structured training rather than a one-off briefing, and a mandatory human review checkpoint before AI output reaches a client.

Ready to automate your legal workflows?

Discover how e! can transform your legal operations with no-code automation.

Related Articles