Sector: Law
Harvey, Lexis+ and the new wave of legal AI apps do the work brilliantly — but each governs only itself. Firm-wide oversight of AI is a separate job, and it's the one the SRA actually asks about.
7 July 2026 · 8 min read
There is a comforting thought doing the rounds in law firm management meetings: we bought a proper legal AI tool, so the AI question is handled. It is an understandable conclusion and a costly one, because it confuses two different things — a tool that does legal work with the oversight that governs how AI is used across the firm.
Harvey, LexisNexis Protégé, contract-review tools, eDiscovery platforms, intake assistants, transcription services — these are genuinely good at what they do. They draft, they research, they review, and the serious ones run in a secure, firm-scoped environment. But every one of them governs exactly one thing: itself. None of them can see, record or control the AI use happening everywhere else in your firm. And "everywhere else" is where your regulatory and privilege exposure actually lives.
Ask what your legal AI platform protects and the honest answer is: the data that flows through that platform. That is a real and valuable thing. It is not the same as knowing how AI is used across the firm.
On any given day your people are also inside Microsoft 365 Copilot, which reads across mailboxes, documents and Teams. They are in ChatGPT, Gemini or Claude in a browser tab. A trainee is trying a new summarisation app a friend recommended. Someone is dictating attendance notes into a transcription tool the firm has never assessed. Your sanctioned legal AI tool sees none of this — and cannot, by design. It was built to do legal work well, not to be the firm's control plane for every model your staff can reach.
The tool you bought is one sanctioned island. The regulator is asking about the whole map.
The Solicitors Regulation Authority has deliberately not written AI-specific rules. Its position is that the existing Standards and Regulations already apply and that the solicitor remains personally responsible for the work. What it expects, set out in its guidance and risk material, is governance: a senior individual with oversight of AI use, documented policies, risk assessments, staff training, and — the part that catches firms out — ongoing monitoring and audit. The COLP carries responsibility for compliance when new technology is introduced.
Read that list again with a single legal AI subscription in mind. A drafting assistant does not give you oversight of AI across the firm. It does not monitor the tools you did not buy. It cannot produce an audit of what your people did in Copilot last quarter. It answers "are we using AI well inside this product?" — not "can we show the regulator how AI is governed across the practice?"
The reason this matters is not tidiness. It is that the sharpest risks sit precisely in the uncontrolled space.
Your legal AI platform reduces exposure for the work that runs through it. It does nothing about the associate who, under deadline, drops a bundle into a free tool because the sanctioned one was two clicks further away.
Worth saying plainly, because it is where firms underestimate the problem: the legal-specific AI market is now dozens of point tools, not two big names. Contract analysis, due diligence, legal research, client intake, deposition and hearing transcription, knowledge search over your DMS — each is its own vendor, its own login, its own data path, and its own island of self-governance. Buying three of them does not add up to firm-wide oversight. It adds up to three more places AI touches client data that your COLP now has to account for, separately.
This is the layer Evaident is built to be — and it is deliberately not another tool that does legal work. It sits above the tools and does four things a point solution cannot:
Two honest caveats, because overclaiming here helps no one. First, capture depth depends on what each tool exposes: a vendor with an audit API or gateway routing gives rich evidence; a closed tool still shows up in shadow-AI discovery, but the deep detail stays in its own logs. Second, metadata is the default — full-content capture is a deliberate, approval-gated choice, precisely because retaining the text of a live matter can itself raise privilege questions.
Your legal AI tool is a tool to be governed. It is not the governance. Keep buying the ones that make your lawyers faster — that is a good decision. Just don't let the subscription convince the partnership that the oversight question is answered, because the SRA, your PI insurer and your clients' procurement teams are all asking the firm-wide version of it.
See where your firm stands today with a free exposure check, and how Evaident is set up for the obligations of legal practice on the law firm page.
The free AI Exposure Check gives you an instant score across visibility, shadow AI, evidence, governance and data-leak risk — no data connection needed.