Artificial Intelligence and the Law: Navigating AI in the Legal Industry

Download This Article as a PDF pdf download
Loading ...
Artificial Intelligence and the Law

Contents: AI for Law Firms: A Comprehensive Guide

Clio Work free trial for Clio customers

Practice the future of law today

Discover Clio Work

Artificial intelligence is already reshaping both legal practice and the law itself. Lawyers use AI to research legal issues, analyze matters, draft documents, review evidence, and manage routine work. At the same time, legislators and regulators are developing rules governing automated decisions, data use, discrimination, transparency, and accountability.

This guide explains the impact of artificial intelligence in the legal sector, the artificial intelligence legal questions lawyers should ask when evaluating tools, the main US and international regulatory frameworks, and how lawyers can stay current as the rules change.

Key takeaways

  • AI supports legal research, matter analysis, drafting, document review, scheduling, client communication, and other work across a legal practice.
  • AI use is already widespread. Clio’s 2026 Legal Trends for Solo and Small Law Firms report found that 71% of solo firms and 75% of small firms use AI. Adoption rises to 86% among mid-sized firms, according to Clio’s 2026 Legal Trends for Mid-Sized Law Firms.
  • Lawyers remain responsible for checking AI-generated work, protecting confidential information, and complying with their professional obligations.
  • The United States regulates AI through a mixture of federal agencies, state laws, courts, and sector-specific rules rather than one comprehensive federal AI statute.
  • The EU AI Act follows a comprehensive, risk-based approach and can affect US organizations with sufficient connections to the EU.
  • Lawyers should assess what an AI system does, what data supports it, and who develops, deploys, or relies on it.

How is artificial intelligence changing the legal sector?

Artificial intelligence is changing the legal sector by accelerating substantive legal work, automating practice-management tasks, and helping firms handle a greater volume of work.

Adoption is already broad. Clio’s 2026 Legal Trends for Solo and Small Law Firms report found that 71% of solo firms and 75% of small firms use AI, while Clio’s 2026 Legal Trends for Mid-Sized Law Firms report found that 86% of mid-sized firms have adopted it.

Legal analysis, research, and strategy

Legal AI can review case or transaction files, identify relevant facts, build chronologies, surface gaps, and help lawyers test possible arguments. It can also support legal research by identifying relevant authorities and connecting them to the facts of a matter.

Lawyers must still verify the result. General-purpose AI systems may generate plausible but incorrect statements, misstate legal authorities, or rely on outdated information. Legal professionals remain responsible for the work they submit and the advice they provide.

Clio Work brings matter analysis, legal research, strategy, and drafting into one AI workspace built for legal professionals. It reads across matter documents to organize key facts, claims, risks, and timelines. It also connects its conclusions to jurisdiction-specific authority and provides source-linked results lawyers can verify.

For larger firms and legal departments, Vincent by Clio supports enterprise-scale research, litigation, transactional, and regulatory work. It provides cited answers grounded in curated legal sources, including case law, dockets, administrative materials, and court rules. It can also produce 50-state surveys, compare jurisdictions, review documents at scale, and connect with enterprise document-management systems.

Drafting and document review

AI can help lawyers create first drafts, summarize long documents, compare contractual terms, identify unusual clauses, and organize evidence for review. These uses can reduce the time spent locating information or producing routine drafts.

However, AI output should be treated as a starting point rather than finished legal work. A lawyer should review the underlying source material, confirm every authority, and ensure the result reflects the client’s facts and jurisdiction.

Tools designed specifically for legal work can make this process easier to supervise. For example, Clio Work creates drafts using the context of the matter and relevant legal authority, while allowing lawyers to trace results back to their sources.

Clio Draft supports a different type of legal drafting. It uses AI to convert existing Word documents into reusable templates, populate sets of related documents, gather client information through dynamic questionnaires, and complete current court forms. This makes it best suited to repeatable, form-based document workflows rather than open-ended legal analysis.

Matter and firm operations

AI supports the operational work surrounding a legal matter. It can help organize calendars, prepare client updates, record work, create billing entries, and turn unstructured matter information into actionable tasks.

Among mid-sized firms that have adopted AI, 65% say it has enabled them to handle a higher volume of work, according to Clio’s 2026 Legal Trends for Mid-Sized Law Firms.

Clio Manage brings cases, documents, calendars, communications, billing, and firm operations into one legal practice-management platform. It’s AI works across these workflows to turn routine activity into review-ready work. For example, it can convert court documents into calendar events, surface matter activity for client updates, and turn recorded time and expenses into invoices ready for approval.

AI and automation can also improve work before a matter formally begins. Clio Grow, for example, helps firms collect prospective-client information, automate intake steps, run conflict checks, generate engagement documents, and transfer new-client information into Clio Manage when a lead converts.

What legal issues does artificial intelligence create?

Most legal issues involving artificial intelligence can be evaluated by asking three questions:

  1. What the system does
  2. What data it uses
  3. Who develops, deploys, or relies on it

1. What decision or action does the AI perform?

AI systems create greater legal risk when they make or materially influence decisions affecting a person’s rights, employment, health, finances, education, immigration status, or access to essential services.

Lawyers should identify whether the system merely supports a human decision or effectively determines the outcome. They should also examine whether the affected person receives notice, an explanation, a meaningful opportunity to challenge the result, and human review where required.

2. What data was used to build or operate the AI?

AI systems depend on data used for training, testing, and generating outputs. That raises questions about:

  1. Whether the data was collected and used lawfully
  2. Whether copyrighted material was included
  3. Whether personal or confidential information is protected
  4. Whether the dataset contains discriminatory patterns

Lawyers should distinguish between the data used to train a model and the information a user enters when operating it. A firm may have little control over the original training data, but it can control which tools its employees use and whether confidential client information may be entered.

Structured workflows can also reduce the need to re-enter client information into separate systems. For example, intake forms in Clio Grow can populate automatically into the matter in Clio Manage.

3. Who is developing, deploying, or using the AI?

Responsibility may be divided between the organization that developed the model, the company that supplied it, the organization that deployed it, and the person who relied on its output.

Government agencies and regulated businesses may face stricter obligations than private actors. The applicable rules may also differ according to the industry, jurisdiction, purpose, and effect of the system.

Lawyers should identify every party in the chain and determine who controls the data, configures the system, makes the final decision, and owes a duty to the person affected.

Artificial Intelligence and the Law

What professional duties apply when lawyers use AI?

Lawyers remain responsible for competence, confidentiality, supervision, communication, candor, and the accuracy of work completed with the help of a legal AI assistant. AI does not transfer professional responsibility from the lawyer to the technology provider.

Firms should decide which AI tools employees may use, what information may be entered, how outputs must be checked, and who must approve AI-assisted work before it reaches a client, court, regulator, or opposing party.

Keeping AI-assisted work within the same system used to manage matters can also reduce unnecessary transfers between disconnected tools. Clio Manage centralizes case information, documents, client communications, deadlines, and billing, while keeping AI-assisted actions within the firm’s existing workflows.

Despite widespread adoption, many firms lack formal governance. Clio’s 2026 Legal Trends for Solo and Small Law Firms found that 57% of solo firms and 55% of small firms have no AI policy in place.

A written law firm AI policy can define approved tools, confidentiality restrictions, verification procedures, human-oversight requirements, and the firm’s approach to informing clients.

Who regulates artificial intelligence in the United States and globally?

Artificial intelligence is regulated through a combination of binding legislation, existing sector-specific laws, agency enforcement, court decisions, and voluntary technical standards. The structure differs significantly between the United States and other jurisdictions.

Which US agencies regulate artificial intelligence?

The United States does not have one comprehensive federal AI law or a single regulator responsible for every use of artificial intelligence. Existing consumer-protection, competition, communications, healthcare, transportation, employment, privacy, and civil-rights laws may apply alongside state legislation.

Lawyers should monitor the agencies most relevant to their clients’ industries and AI use cases:

  • Federal Trade Commission: The FTC applies its consumer-protection and competition authority to companies that develop, market, or use AI. Its work includes enforcement against misleading claims about AI products and potentially unfair or deceptive AI practices.
  • Food and Drug Administration: The FDA regulates AI when it forms part of a product within the agency’s jurisdiction, including certain medical devices and software functions.
  • Department of Transportation: The DOT oversees AI applications within its transport-safety responsibilities, including automated driving, aviation, unmanned aircraft, and traffic-management systems.
  • Federal Communications Commission: In February 2024, the FCC ruled that AI-generated voices count as “artificial” voices under the Telephone Consumer Protection Act. Covered calls are therefore subject to the same consent and disclosure requirements as other artificial or prerecorded voice calls. The ruling did not impose a blanket ban on every call containing an AI-generated voice.
  • National Institute of Standards and Technology: NIST publishes voluntary technical guidance rather than binding AI regulations. Its AI Risk Management Framework helps organizations identify and manage risks associated with artificial intelligence.
  • State governments: States continue to introduce and enact measures addressing automated decisions, discrimination, employment, healthcare, consumer disclosures, deepfakes, elections, and government use of AI.

Lawyers should check the rules governing the client’s industry and every state or jurisdiction in which the client develops, supplies, deploys, or uses the system.

How is artificial intelligence regulated outside the United States?

AI regulation outside the United States combines binding regional and national laws, international policy frameworks, and voluntary technical standards.

  • European Union: The EU AI Act creates a comprehensive, risk-based framework that can also apply to organizations established outside the EU.
  • National governments: Countries have developed different approaches to AI safety, automated decision-making, data protection, online content, transparency, and model governance.
  • International organizations: Bodies such as the OECD and United Nations publish principles and policy frameworks that can influence national laws. These documents do not automatically create directly enforceable obligations for private organizations.
  • Standards bodies: Organizations such as ISO and IEC publish technical standards that may remain voluntary unless legislation, regulators, procurement requirements, or contracts incorporate them.

Organizations operating across borders must assess each jurisdiction separately rather than treating international AI policy as a single global rulebook.

To regulate AI usage at your firm, it will be important to draft an AI policy—discover our AI template here.

What role do standards bodies and industry groups play?

Standards bodies and industry groups influence how organizations assess and document AI risk, even when their recommendations are not legally binding.

Frameworks such as NIST’s AI Risk Management Framework and technical standards developed by ISO can help organizations establish governance processes, evaluate vendors, document risks, and demonstrate reasonable controls. Their legal effect depends on whether a regulator, statute, contract, or court incorporates or relies on them.

Law firms should distinguish voluntary guidance from binding law and confirm which rules apply in their jurisdiction.

Artificial Intelligence and the Law

Are there laws for artificial intelligence?

Yes. Existing privacy, consumer-protection, employment, intellectual-property, product-safety, anti-discrimination, communications, and sector-specific laws may apply to AI even when they do not mention the technology by name.

Some jurisdictions have also enacted legislation specifically addressing artificial intelligence. The EU AI Act is the most comprehensive cross-sector framework currently enacted, while the US continues to rely mainly on federal agency authority, state legislation, and laws governing particular sectors or harms.

How does the EU AI Act regulate artificial intelligence?

The EU AI Act regulates artificial intelligence according to the level of risk created by the system and its intended use. It establishes rules for prohibited practices, high-risk systems, general-purpose AI models, and certain uses requiring transparency.

Who does the EU AI Act apply to?

The Act can apply to organizations established outside the EU. Its scope includes providers that place AI systems or general-purpose AI models on the EU market and providers or deployers outside the EU when an AI system’s output is used within the EU.

US law firms advising multinational businesses may therefore need to assess the Act when a client develops, supplies, or uses AI connected to the European market.

Which AI systems does the Act classify as high risk?

The Act classifies some AI systems as high risk because they are safety components of regulated products or because they are used for specified purposes listed in the legislation.

These purposes include certain uses involving:

  • Critical infrastructure
  • Education and vocational training
  • Employment and worker management
  • Access to essential private or public services
  • Law enforcement
  • Migration, asylum, and border management
  • The administration of justice and democratic processes

The high-risk categories intersect most directly with employment, education, financial-services, healthcare, immigration, criminal-justice, litigation, and public-law practices.

However, every AI use within these industries is not automatically high risk. The analysis depends on the particular system, its intended purpose, and whether it falls within the Act’s defined categories and exceptions.

High-risk systems may be subject to requirements involving risk management, data governance, technical documentation, record keeping, transparency, human oversight, accuracy, robustness, and cybersecurity.

What rules apply to general-purpose AI models?

Providers of general-purpose AI models must meet obligations involving technical documentation, information for downstream providers, EU copyright-law legal compliance policies, and summaries of the content used to train the model.

Providers of general-purpose AI models presenting systemic risk face additional obligations involving evaluation, systemic-risk assessment and mitigation, incident reporting, and cybersecurity.

What transparency rules apply to AI-generated content?

The Act introduces transparency duties for specified AI-generated or manipulated content. These include disclosure requirements for certain deepfakes and some AI-generated text published to inform the public about matters of public interest, subject to the legislation’s definitions and exceptions.

The Act also allows affected people to lodge complaints with the relevant market-surveillance authority. In specified circumstances, people affected by decisions based on high-risk AI systems may request meaningful explanations.

When does the EU AI Act apply?

The EU AI Act entered into force on August 1, 2024, and its requirements apply in stages.

  • Rules covering prohibited AI practices and AI literacy began applying on February 2, 2025.
  • Governance provisions and obligations for providers of general-purpose AI models began applying on August 2, 2025.
  • Transparency duties for specified AI-generated content are scheduled to apply from August 2, 2026.
  • Obligations for high-risk systems were pushed back by a package of amendments known as the Digital Omnibus, agreed in June 2026. Most high-risk requirements now apply from December 2, 2027, and those covering AI built into already-regulated products from August 2, 2028.
  • Because parts of this timetable were amended recently and further changes are possible, lawyers should confirm the current dates against the final legislation and European Commission guidance before advising a client on a deadline.

Lawyers should check the final legislation, applicable harmonized standards, and current European Commission guidance before advising a client on an implementation deadline.

How does US AI regulation differ from the EU approach?

The United States primarily regulates AI through existing sector-specific laws, agency authority, state legislation, and rules addressing particular harms. The applicable requirements depend on factors such as the client’s industry, state, data practices, and use of automated decisions.

The European Union uses a single cross-sector framework built around defined roles, risk classifications, and obligations. It can also apply to some organizations established outside the EU.

Lawyers advising on cross-border AI compliance should therefore conduct separate assessments: a sector-and-state analysis for the US and a scope, role, and risk-classification analysis for the EU.

Practice the future of law today

With Clio Work, you go beyond generic chatbots and use AI that understands the context of your matters and delivers precise, cited legal research, analysis, and drafting that moves your cases forward.

Discover Clio Work

How can lawyers track changes to AI laws and regulations?

Lawyers should monitor the regulators responsible for their clients’ industries and use separate trackers for international, federal, and state developments.

No third-party tracker is guaranteed to be comprehensive or continuously current. Before advising a client, confirm the wording and status of any relevant bill, law, regulatory action, or guidance through the official legislative or regulatory source.

AI regulation trackers for lawyers

IAPP Global AI Law and Policy Tracker

Best for: Comparing national and international approaches to AI governance.

The IAPP Global AI Law and Policy Tracker follows legislative and policy developments across jurisdictions on six continents. It covers comprehensive legislation, sector-specific laws, national strategies, and voluntary frameworks.

Brennan Center Artificial Intelligence Legislation Tracker

Best for: Identifying qualifying AI bills introduced in the US Congress.

The Brennan Center Artificial Intelligence Legislation Tracker records bills addressing subjects such as high-risk AI, testing, transparency, regulatory authority, liability, and government studies.

Its public tracker may not reflect every recent development. Lawyers should verify the status, text, and legislative history of individual bills through Congress.gov before relying on them.

NCSL Artificial Intelligence Legislation Database

Best for: Broad state-level legislative research.

The NCSL Artificial Intelligence Legislation Database tracks identified state and territorial AI bills introduced from 2025 onwards. It includes pending and enacted measures and can be filtered by state, bill status, and policy topic.

Because state legislative activity changes quickly, lawyers should use the live database rather than relying on a static national bill count.

BCLP US State-by-State AI Legislation Snapshot

Best for: A visual overview of state laws affecting private-sector AI development and deployment.

BCLP’s US State-by-State AI Legislation Snapshot maps proposed, failed, and enacted measures that may directly affect organizations developing or deploying AI.

Its methodology omits some laws involving biometrics, facial recognition, and sector-specific administration. Lawyers should use it alongside a broader source such as NCSL’s database.

Free AI Course: Build your legal AI expertise with our free Legal AI Fundamentals Certification where you’ll learn from real AI experts how to write better prompts, identify the best AI tools, and how to introduce AI into your daily work.

Build your legal AI expertise with Clio’s free Legal AI Fundamentals Certification. The course covers how to evaluate AI tools, write effective prompts, and introduce AI into legal workflows responsibly.

Free AI Course: Build your legal AI expertise with our free Legal AI Fundamentals Certification where you’ll learn from real AI experts how to write better prompts, identify the best AI tools, and how to introduce AI into your daily work.

How should law firms prepare for the future of AI and law?

Law firms should prepare for AI by creating clear governance rules, selecting tools appropriate for legal work, protecting client information, and requiring lawyers to verify every substantive output.

The regulatory landscape will continue to change. Firms should monitor the authorities governing their practice areas, use legislation trackers to identify developments, and verify every rule through its official source before advising a client.

Clio brings AI and automation into the full lifecycle of legal work. Clio Work supports matter analysis, research, strategy, and substantive drafting. Vincent by Clio extends authoritative legal AI across enterprise research and complex workflows. Clio Draft automates repeatable document work, while Clio Manage connects cases, communications, deadlines, billing, and firm operations in one platform.

Together, these products make AI part of how legal work gets completed, not a separate tool lawyers must bolt onto disconnected processes.

Use AI that understands the context of your matters, connects its conclusions to legal authority, and helps turn analysis into work you can review and defend.

Book a demo to try Clio today.

Which federal agencies should lawyers monitor for AI regulations relevant to their practice?

Lawyers should monitor the agencies responsible for their clients’ industries and AI use cases. Consumer-protection and competition lawyers should follow the FTC. Healthcare and medical-device lawyers should monitor the FDA, while transportation and telecommunications lawyers should follow the DOT and FCC respectively.

NIST is also important, although it is not an AI regulator. It publishes voluntary technical standards and risk-management guidance that organizations, regulators, and courts may consider when evaluating AI governance.

Lawyers should also monitor relevant state authorities because the United States does not have one comprehensive federal AI law.

How does the EU AI Act affect US law firms and their clients?

Yes, the EU AI Act can affect US firms and clients with sufficient connections to the European Union. It applies to providers outside the EU that place AI systems or general-purpose AI models on the EU market. It can also apply to providers and deployers outside the EU when an AI system’s output is used within the EU.

US lawyers advising multinational clients may therefore need to evaluate the Act when a client develops, sells, or uses AI affecting the EU market. The precise obligations depend on the client’s role, the system’s risk classification, and how the system is used.

Which legal practice areas are most affected by the EU AI Act’s high-risk categories?

The EU AI Act’s high-risk categories most directly affect employment, education, financial-services, healthcare, immigration, criminal-justice, litigation, and public-law practices.

The Act identifies specified AI uses involving employment decisions, educational access, essential services, law enforcement, migration, border control, and the administration of justice as potentially high risk.

However, an entire industry or practice area is not automatically high risk. Lawyers must assess the particular AI system, what it does, and whether it falls within the Act’s defined categories.

What questions should lawyers ask when evaluating an AI legal issue?

Lawyers should ask three questions: what the AI does, what data it uses, and who develops, deploys, or relies on it.

First, identify whether the system makes or materially influences decisions affecting a person’s rights, employment, health, finances, or access to services. Next, examine where its data came from, whether it was obtained lawfully, and whether it could produce discriminatory or unreliable results. Finally, identify every responsible party, including the developer, provider, deployer, and organization relying on the output.

How can lawyers stay current on AI regulations affecting their clients?

Lawyers should combine specialist trackers with official legislative and regulatory sources. IAPP provides an international overview. The Brennan Center tracks qualifying AI bills introduced in Congress, while NCSL covers introduced and enacted state measures. BCLP provides a narrower visual overview of laws affecting private-sector AI.

Trackers can be incomplete or outdated. Lawyers should verify the status and wording of any relevant bill, law, or regulatory action through the responsible legislature, agency, or official journal before advising a client.

When does the EU AI Act take effect, and what should lawyers prepare clients for?

The EU AI Act is already in force, but its requirements apply in stages. It entered into force on August 1, 2024. Rules covering prohibited AI practices and AI literacy began applying on February 2, 2025. Governance provisions and obligations for general-purpose AI models followed on August 2, 2025. Transparency duties for specified AI-generated content are scheduled for August 2, 2026. Obligations for high-risk systems were deferred by amendments agreed in June 2026 and now apply from December 2, 2027, with a later date of August 2, 2028 for AI built into already-regulated products.

Lawyers should help affected clients classify their systems, identify whether they act as providers or deployers, document risk-management measures, and prepare for applicable transparency, human-oversight, record-keeping, and governance duties.

Because the timetable was amended recently and may change again, they should confirm current dates against the final legislation before advising on a deadline.

How does US AI regulation differ from the EU for lawyers advising on AI compliance?

The United States primarily regulates AI through existing sector-specific and state laws, while the European Union uses a comprehensive, risk-based framework.

In the US, the applicable rules depend on factors such as the client’s industry, location, data practices, and use of automated decisions. Several agencies may have overlapping authority, and state requirements differ.

The EU AI Act creates common categories and obligations across the bloc and can apply to some organizations established outside the EU. Cross-border compliance advice should therefore use separate assessments: a sector-and-state analysis for the US and a role, scope, and risk-classification analysis for the EU.

Practice the future of law today

With Clio Work, you go beyond generic chatbots and use AI that understands the context of your matters and delivers precise, cited legal research, analysis, and drafting that moves your cases forward.

Discover Clio Work