Task assistance
An output
A person supplies the context, asks the question, checks the answer and carries it into the organisation. The tool stops when the text is produced.
Framework Published
For boards, shareholders, general counsel and legal teams assessing where agents belong in an enterprise.
The relevant question is not whether a model can produce a legal answer. It is whether the organisation can notice what requires attention, assemble authoritative context, test possible courses, allocate responsibility and carry an approved decision into the business.
01 / System
Here, a legal agent is software that receives a defined task or event, retrieves permitted context and produces a bounded work product or proposed action. An agentic legal function governs how those outputs lead from a material change or question to evidence, challenge, an authorised decision and verified implementation.
Many legal AI deployments are attached to a task: search, summarise, compare or draft. That can improve an individual task without changing how legal work moves through an organisation.
An organisational system can begin before a request, remain active between human interactions and extend beyond an answer. Within defined coverage and permissions, it receives external and internal events, tests their relevance against current company facts, opens or updates a decision record, initiates research and independent challenge, routes the matter to its accountable owner and keeps it under review until an evidenced disposition is recorded. It brings an issue to judgment; it does not assume authority to decide it. Model output is an intermediate work product.
Model capability is only one constraint. The organisation must also redesign its sources of truth, handoffs, decision rights, incentives, review duties and ownership of exceptions. Technical readiness can therefore precede organisational readiness. If the operating path remains unchanged, automation adds another output to it.
Task assistance
A person supplies the context, asks the question, checks the answer and carries it into the organisation. The tool stops when the text is produced.
Decision system
The trigger, sources, decision rights, challenge, approval, resulting actions and evidence of closure are part of one governed record.
01.01 / Decision object
01 / Trigger
The event, affected entity, product, market or matter; the owner; the deadline; and the decision requested.
02 / Record
Facts and exact sources; applicable authority and company policy; temporal scope; assumptions; contradictions; and unresolved questions.
03 / Judgment
Available courses, relevant trade-offs, the proposed position, the strongest contrary case and the uncertainty that remains.
04 / Authority
The authority basis, required approvals, dissent, the decision and any conditions attached to it.
05 / Action
Tasks, controls, contract positions, disclosures or system changes; their owners and due dates; and the evidence required for closure.
06 / Outcome
The result, assumptions that proved wrong, conditions that should reopen the decision and any proposed change to policy.
02 / Loop
The operating loop connects changes in law and business to an owned decision. Implementation, express rejection, deliberate deferral and monitored non-action can each be valid dispositions. Each requires a rationale, owner, durable record and, where applicable, conditions, a review date or a reopen trigger.
02.01
Receive a material external development or internal business event from the systems in which it occurred.
Required recordThe original event, source, time, status and affected perimeter.
02.02
Assess materiality, urgency, uncertainty, reversibility and the authority required. Suppress duplicates without concealing severe outliers.
Required recordWhy the signal matters, who owns it, when action is due and which decision is requested.
02.03
Retrieve authorised internal facts and external law. Separate evidence, inference, company policy and prediction.
Required recordA proposition–evidence map, contrary authority, temporal cutoff and material gaps.
02.04
Test the principal case independently against facts, authority, alternative interpretation, evidence, operational feasibility and the likely adversary.
Required recordA challenge ledger showing the attack made, result, residual uncertainty and stop condition.
02.05
Present distinct courses, assumptions, consequences and the strongest case against the proposed position to the authorised person.
Required recordThe decision, authority basis, rationale, dissent, conditions and residual risk.
02.06
Translate an approved course into changes in the systems where the business works, or record the approved basis and conditions for deferral, rejection or monitoring. Consequential writes remain subject to the relevant approval.
Required recordAction owner, due date, target system, approval, execution receipt and reversal route; or review owner, review date and reopen trigger.
02.07
Compare the outcome with the assumptions and capture corrections. A repeated exception may justify a proposed policy change; it does not become policy by repetition alone.
Required recordOutcome, correction cause, reopen trigger and any authorised promotion into institutional knowledge.
03 / Architecture
A business system remains authoritative for its own internal facts; official or otherwise legally recognised sources remain authoritative for external law. Agents assemble the minimum context required for a defined purpose through permissioned interfaces. They do not receive undifferentiated access to the enterprise.
03.01 / Capabilities
01 / Memory
Matter history, approved decisions, policy, external law and observed outcomes remain separate. A draft, conversation or negotiated exception does not become organisational policy merely because it was stored.
02 / Attention
Attention begins with a coverage register: jurisdictions, authorities, courts, standards, markets, products, sources, known blind spots and review cadence. Within that perimeter, developments in external sources and events from internal systems are compared with the entities, products, contracts, controls and prior decisions they may affect. The resulting assessment is not a news summary. It states the cited change, applicability hypothesis, affected perimeter, evidence, owner, deadline and decision requested. Anything less adds queue volume without establishing control.
03 / Research
External authority and internal company facts are researched together. A legally sound proposition applied to the wrong entity, product, data flow or contract remains a wrong answer.
04 / Red team
The challenger uses an independent path where the consequences justify it. Independence may require different retrieval, assumptions, model, evaluator or human review. Asking the producing model to reconsider its own answer is not independent assurance. The task is to find defects capable of changing the decision, approval level, evidence required or implementation plan.
05 / Interfaces
Departmental systems publish defined facts and events through purpose-bound interfaces. Permissions apply to the user, agent, matter, purpose and time; not merely to a broad role.
06 / Actions
Agents propose commands through an action gateway. Consequential changes require validation, appropriate approval, an execution receipt and a way to reverse or remediate failure.
03.02 / Business context
Counterparty, value, proposed products, markets, commercial thresholds and approval state.
Exact text, versions, deviations, executed commitments, obligations, source locations and classifications.
Features, intended uses, user groups, models, vendors, data flows, jurisdictions and release changes.
Incidents, affected assets, control status, evidence and notification-clock inputs.
Employment locations, roles, material transactions, spend and exposure thresholds, limited to the purpose at hand.
Delegations, reserved matters, approved conditions, owners, review dates and evidence of completion.
03.03 / Responsibility
Management
The business owner is responsible for the accuracy of operational facts, the choice within delegated authority, resources for implementation, accepted residual risk and evidence of completion. Decision ownership does not transfer to Legal or to an agent.
Legal team
Matters assembled from their sources; propositions linked to evidence; legal analysis reviewed; standard work routed under policy; conflicts and deviations escalated; actions tracked to disposition. The legal team owns the quality of its work, not the underlying business decision.
General Counsel
Material decisions and their owners; unresolved factual and legal uncertainty; competing courses; unresolved disagreements; concentrations of exposure; conditions awaiting implementation; patterns that may require a policy or risk-appetite decision.
Board
Material developments, affected decisions, authority exercised, evidence relied on, dissent and uncertainty, conditions imposed, implementation status and residual risk. The board should not receive a stream of operational alerts. An aggregate score is insufficient; material assumptions, dissent and uncertainty must remain visible.
03.04 / Deliberation
Agents can prepare a pre-mortem, the strongest contrary case, a list of missing evidence, conflicts with precedent or policy, and second-order operational consequences. For the General Counsel, this tests the legal position and whether it can be implemented. For the board, it tests management’s framing, alternatives, control evidence and residual uncertainty. It does not set risk appetite, exercise a vote or replace independent advice.
03.05 / Example
The product system records a material change.
Affected entities, markets, data, contracts and controls are identified.
Internal facts and external authority are assembled; gaps are requested.
The proposed position is tested independently.
The authorised person proceeds, pauses or imposes conditions.
Approved conditions enter the release workflow.
Implementation evidence is checked and the decision record is updated.
04 / Authority
An agent has technical permissions, not corporate office, professional responsibility or judgment authority. Each permission must trace to a human owner, a lawful basis and a revocable delegation. Accountability does not move to the system. Reading, analysing, recommending, communicating and acting require separate permissions.
04.01 / Deterministic
An agent may verify parties, dates, approvals, clause presence, numerical consistency or other defined conditions after the checks and exception routes have been tested. People remain responsible for the specification and thresholds.
04.02 / Bounded
An agent may operate within an approved, versioned playbook and explicit delegation. Missing facts, novelty, conflicting sources or a threshold breach require escalation.
04.03 / Consequential
An agent may frame the decision, develop courses, surface assumptions and argue the contrary case. Materiality, acceptable risk, fairness, reputation, negotiation posture and novel interpretation remain human judgments.
04.04 / Reserved
An agent may prepare a formal act, but it may not exercise a director’s vote, choose to waive privilege, settle a matter or make an external legal commitment. Filing, signature or communication may be automated only where law and professional rules permit, the responsible authorised person has approved that specific class of act, and approval and execution are recorded.
04.05 / Controls
Each agent has a workload identity, human sponsor, defined purpose, permitted matter and expiry.
No standing enterprise superuser. Access is granted to the minimum fields and actions required.
Material claims retain source, jurisdiction, effective date, version, access scope and currentness.
Drafts, conversations and exceptions enter institutional policy only after authorised review.
Privilege, confidentiality, conflicts, supervision, retention and legal hold are designed into retrieval and logging.
The system that produced the preferred answer is not the sole evaluator of its own work.
Retrieved documents and user content are untrusted inputs. They cannot alter permissions, routing rules, approval state or governing system instructions.
Source, connector and model failure modes are defined. Consequential actions fail safely, degraded operation is visible and a manual fallback is tested.
Models, prompts, sources, policies, connectors and routing rules run against a versioned regression set before release.
Agents have owners, logs, health checks, expiry, a kill mechanism and retirement criteria. Dormant access is removed.
05 / Maturity
A company can procure software designed for Stage 7 while its daily work remains at Stage 1. Buying orchestration does not create authoritative context, a tested harness, process ownership or operational continuity.
Stage 4 is the hinge for a workflow intended to operate continuously. Before it, the workflow depends on a person to start it and keep it running. At Stage 4, it becomes an organisational service: triggered by an event or schedule, operated under its own identity, monitored, logged and supported by defined failure and continuity procedures.
Stage 4 depends on the context and harness established at Stages 2 and 3. The stages describe the dominant mode of operation; they do not permit basic controls to be deferred. Privacy, security, professional duties, ownership and human authority apply from Stage 1. Not every workflow should advance to headless or multi-agent operation.
Stage 01
Individuals use AI for discrete tasks and remain responsible for initiating, supplying and checking each one.
Evidence before proceedingNamed owner, permitted use, data boundary and a method for checking output.
Stage 02
Authoritative knowledge is available through bounded, permissioned interfaces. Domains remain separated.
Evidence before proceedingSource registry, authority by field, access policy, freshness and provenance.
Stage 03
Evaluation criteria, routing, abstention, escalation and quality gates are defined independently of the chosen model. The durable investment is the system around the model: rules for context, the evaluation set, routing, permissions and the decision record. A replacement model must meet the same release criteria without weakening authority controls or auditability.
Evidence before proceedingAdjudicated test cases, severity-weighted failure classes, regression results and release criteria.
Stage 04
Stable, recurring and observable workflows run from business events, conditions or schedules rather than from a person’s laptop. The service no longer depends on one person being present.
Evidence before proceedingService identity, logs, retries, failure routing, monitoring, continuity testing and an accountable operator.
Stage 05
Access, delegation, retention, agent lifecycle, audit, incident response and retirement are managed systematically across the portfolio. Permissions are suspended on expiry, loss of sponsorship, policy-defined inactivity or regression below an approved evaluation threshold.
Evidence before proceedingControl ownership, review cadence, access recertification, automatic suspension, kill mechanism and retained decision records.
Stage 06
Specialist agents exchange defined work products within a value chain. Before a handoff is accepted, the work product is checked for required structure, source provenance, completeness, the authority to send and receive it, and known failure modes. That check may be rule-based, performed by an independent model or assigned to a person. Agent coordination is justified only where it improves performance or controls risk better than a simpler pipeline.
Evidence before proceedingVersioned interface contracts, acceptance checks at each handoff, comparative evaluation, named failure ownership and end-to-end traceability.
Stage 07
Within the declared coverage perimeter, routine cases proceed through governed workflows. Open obligations, conditions and decisions return to attention when a relevant fact, deadline or threshold changes. People concentrate on exceptions, contested facts, strategy and accountable judgment.
Continuing evidenceDecision time, senior attention, critical escapes, escalation quality, action closure, incidents and outcomes.
05.01 / Implementation
The implementation model determines who carries the work of changing systems and behaviour. It does not remove that work.
Internal redesign
The organisation builds and operates the capability itself. This preserves control and institutional learning, but requires sustained executive authority and cross-functional ownership to change roles, incentives, handoffs and systems.
Embedded implementation
A specialist works inside the organisation to connect systems and tune the harness. That can solve the technical integration. It cannot by itself establish decision rights, align incentives or secure adoption. An accountable internal process owner remains necessary.
Managed outcome
A provider operates a defined process to an agreed outcome and carries the continuing work of maintaining the workflow and adapting it as models change. This reduces the internal change burden only where the work can properly be outsourced, quality can be specified and audited, and authority boundaries, data arrangements, knowledge transfer and exit are explicit.
No implementation model fits every process; a hybrid arrangement may be appropriate. In every case, adaptation remains an operating function because sources, AI models, law, policy and business processes change on different cadences. Accountability for corporate decisions remains within the organisation.
05.02 / Measurement
Seats activated, token volume and documents generated show adoption. They do not establish value or control. Measures should be defined for each workflow, compared with an appropriate baseline, segmented by risk class and tested through adjudicated samples.
Defined monitoring perimeter; relevant events detected; known blind spots; source outages; false dismissals and precision by attention tier.
Severity-weighted errors; unsupported propositions; source validity and currentness; and correct abstention, escalation and routing.
Material facts, alternatives, contrary authority and second-order effects omitted when the decision was made.
Time from event to decision and from decision to closure; overdue conditions; failed or reversed writes; and reopened decisions.
Senior legal time, net external spend and the full cost of integration, evaluation, supervision, incidents and maintenance.
Unauthorised access or action, cross-matter leakage, privilege events, malicious-input failures and incidents during degraded operation.
Governed-workflow coverage; manual bypasses; regression results after changes; source and connector availability; time to contain a failure; and tested manual fallback.
Corrections, disputes, losses and control failures against the assumptions recorded at the time. Outcomes are lagging and confounded; alone, they do not prove decision quality.
05.03 / Oversight
Conclusion
It is a legal function that maintains defined coverage, tests relevant changes against current company facts and keeps open matters under review. Routine execution is systematic, institutional knowledge is available at the point of decision and judgment is independently challenged. Authority remains explicit, and approved decisions are followed into business action and evidenced closure.