The governing question is not “did a lawyer click approve?” It is whether the lawyer and firm exercised meaningful, informed and reconstructable supervision.
Competence
Competence in an AI-native firm includes understanding the system's intended use, material limits, sources, error modes and escalation rules. A superficial review of fluent output is not substantive verification. For high-impact work, the reviewer must be able to test both authority and reasoning.
Confidentiality
A lawyer must know where client information travels, who can access it, whether it is retained, whether subprocessors are involved and whether prompts or outputs are reused. Contractual language stating that data is not used for training is only one control; it does not answer transfer, access, deletion or incident questions.
Supervision and delegation
Traditional supervision assumes a person can explain what was delegated. Agentic systems may generate sub-tasks, invoke tools and alter records dynamically. The firm therefore needs machine-readable limits: actions the agent may take, actions requiring approval, mandatory evidence and termination conditions.
Client disclosure
Disclosure should be risk-based. Routine spellchecking does not justify the same notice as AI-led issue classification or strategy ranking. Material use should be disclosed when it affects confidentiality, price, the method of service, explainability or the client's ability to contest an outcome. Kazakhstan's AI law adds an express transparency dimension by requiring users to be informed when services are produced using AI systems.
Accountability
Responsibility should attach to named roles: matter partner, system owner, data owner, vendor owner and incident lead. “The model made a mistake” is not an accountability model. Neither is a generic policy disconnected from actual workflows.
| Duty | Minimum evidence |
|---|---|
| Competence | Approved use case, reviewer standard, training and validation results |
| Confidentiality | Data-flow map, vendor terms, access controls, retention schedule |
| Supervision | Human checkpoints, escalation triggers, action logs |
| Accuracy | Source verification, citation checks, sampled quality review |
| Client interest | Conflict checks, bias analysis, method and fee transparency where material |