What is collaborative AI for legal and compliance review?
Collaborative legal review is a quoted clause, a named playbook version, and a lawyer who can refuse — on a shared job, not in a private chatbot. A guide to starting with one clause type.
Collaborative AI for legal and compliance review is a shared artefact: the clause as written, the playbook version, a named lawyer who can refuse, and a log that would still make sense if someone asked how that language left the company. It is not a copilot that paraphrases a contract in a private window. The model may propose a rewrite next to the quote. A person compares quote to rewrite.
You should care if sales already pastes “legal is comfortable” into a thread, or if a website bot can state terms. This is a how-to for one clause type. A private drafting aid for a lawyer who still works alone can be useful. It is not shared review.
The Use cases hub is the series. What auditors are asking for is the evidence cut. What write-back governance is is the rule that a model may not change a live system, or send a binding message, until a person has signed the exact change. Product governance is where that rule has to live as behaviour.
What is collaborative AI for legal and compliance review?
At minimum the shared job holds:
- The language under review as the words that will be signed or sent — quoted, not only summarised.
- The playbook, grid, or clause list that applied, with a version or a date.
- A named lawyer or named delegate who can refuse the send.
- A stored refusal so the next draft cannot pretend the first one was approved.
- A log a later reader can open without the people who were there.
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689, 2024) is the Union text on placing AI systems on the market and putting them into service. It is not a clause-review playbook. It is a reminder that generated systems used in the Union carry duties that chat etiquette does not satisfy. You do not need to map every article to need a reconstructable log.
Write-back here includes customer messages and contract files, not only CRM fields. When AI changes a live system, or when it sends language that binds, the lawyer’s stop has to be in the path. Fail-closed means if nobody approves, nothing happens. The payload is the exact text, not “we tightened it.”
Collaborative AI for finance and planning is the sibling gate: the journal that must not auto-post is the same idea as the clause that must not auto-send.
Why should legal care?
Because fluency is not review, and late addition is the usual pattern.
Legal is often asked to “sanity-check this email” after the commercial conversation has already happened. If the email went out, it is already a write to the relationship. Multiplayer work puts legal on the job before the send is possible.
In February 2024 the Civil Resolution Tribunal of British Columbia held Air Canada to a bereavement fare its chatbot had invented — Moffatt v. Air Canada. No CRM write was required. The message was the write. In June 2023 lawyers were sanctioned for filing ChatGPT-invented cases — Mata v. Avianca, as reported by Reuters. Both are sequence-and-custody stories as much as model-quality stories.
A perfectly accurate discount sent without finance is still an incident. A well-drafted clause legal never saw still binds the company. Accuracy is about whether a sentence is true. The roster is about whether anyone with a duty to refuse it had the chance.
How do you keep review shared without putting everything in a chatbot?
Keep the matter on the job. Keep the bot from being the vault.
Practical rules:
- Attach the source PDF. Do not trust a retrieval snippet as the clause — snippets miss the proviso on the next page.
- Diff the proposal against the quote. If the product only stores “legal OK,” you have neither review nor a record.
- Name the playbook version. “Follow the playbook” with a folder of PDFs is an instruction to guess.
- Confirm retrieval cannot prefer an obsolete PDF because it ranked well.
- List the channels this job can emit on. Each has a signer class, or it is disabled. Draft-only is the default.
If you have no official playbook, stop asking the model to “sound like legal.” You are generating tone. Write the fallback you actually use, date it, and put that dated artefact on the job before the next draft.
A personal assistant can still help a lawyer rephrase in private. The shared job starts when sales, operations, or compliance must stand on the same words. Do not put the whole contract corpus into a chatbot “so everyone can ask.” That is reach without a matter.
The harness — the tools, stops, and checks around the model — includes which playbook version the model may retrieve. Harness engineering is the guide to that environment.
NIST’s AI Risk Management Framework (2023) is a voluntary map for governing AI systems. It does not replace a named rejector on Tuesday’s concession. It is a useful reminder that the system, not only the paragraph, is what you manage.
What does a shared review job look like?
A concession matter might hold: the quoted clause, the playbook version dated this quarter, finance’s commercial exception still visible, a lawyer named as rejector, a draft customer message that cannot send while a reject is in force, and a guest seat for outside counsel who cannot turn on a CRM write.
Sales can propose. Sales cannot emoji-approve as “legal.” A Slack group is an audience. If any member of a large channel can approve, you have named whoever was online.
Internal messages that commit a BU — “your new discount is approved” — are writes too when they would be quoted later.
The log a regulator or general counsel needs is not a token trace of agent steps. Engineers need traces. The company needs who proposed, what the quoted clause was, which playbook version, who signed or rejected, when, and whether the send landed. Retention on that log should match how long you must explain the language, not how long the chat tool keeps messages.
RBAC — who is allowed to do what — is how outside counsel sees the matter and not every connector. See RBAC for enterprise AI.
How do you start with one clause type?
Pick one type that will leave the company this month: limitation of liability fallback, data-processing sentence, discount that changes terms, website bot copy that states a fare-like rule.
On that matter:
- Print five checks: quoted text, version, named rejector, send gate, reconstructable log.
- Mark pass or fail with a date. Fix the first fail you cannot live with before you add a second matter.
- Run the checks once with sales, legal, and compliance in the same sitting if they would mark differently. The disagreement is information.
Do not roll out “legal AI” as a seat count. A seat is a private window. Nimbus workstreams hold the matter next to the roster. You can start with a matter folder and a written send stop if that is what you have.
If you cannot pass the checks, the model is a drafting aid for a lawyer who still works alone. That can be the right tool for that week. Shared review begins when the quote, the version, and the name sit on one job.
Quoted clauses and a named refusal
Is a chatbot summary the same as legal review?
No. Review needs the clause as quoted, the playbook version, and a named lawyer who can refuse. A paraphrase can drop a defined term. Comfort in chat is not a clause.
Are customer emails “only messages”?
If a customer could rely on the sentence, treat it as a write. Air Canada was held to a chatbot fare in 2024 with no CRM write required. The message was the write.
Do we need the EU AI Act to care about a log?
No. The 2024 Act is one reason Union operators will be asked about systems. Reconstruction — who proposed, what was quoted, who signed — is useful even without mapping every article.
Related guides
See what governed AI looks like on your stack.
Connect your tools, run a workstream, and keep every decision on your ledger - free for 7 days.