AI agents for law firms: what lawyers can delegate—and what they must control

An AI agent can move beyond answering a prompt: it may plan a sequence, choose tools, consult several sources and take action in another system. That can remove repetitive work from a legal process. It also changes the risk. A weak draft waits to be corrected; an agent with permission to send, file, amend or delete can turn an error into an external event before a lawyer sees it.

Why AI agents are the legal technology question of 2026

This is more than a new label for familiar software. The MIT-led 2025 AI Agent Index, published for FAccT 2026, recorded a sharp rise in new agent-related search terms. It also found that papers mentioning “AI agent” or “agentic AI” in 2025 exceeded the combined 2020–2024 total by more than twofold (1). The study examined 30 widely deployed agents and found substantial gaps in public information about safety, evaluation and societal impact.

Legal buyers are moving at the same time. A Deloitte Legal survey of 121 senior legal leaders, conducted in April and May 2026, found that 61% of their departments were experimenting with or piloting agentic AI (2). A broader Thomson Reuters survey of more than 1,500 professionals found 15% reporting current organizational use, another 53% planning or considering it, and 77% expecting agentic AI to become central to their workflow by 2030 (3). These samples do not measure the whole market, but together they show active demand rather than a distant forecast.

Start by testing the word “agent”

Suppliers use “assistant”, “copilot”, “agent” and “agentic” inconsistently. The Law Society found widespread confusion and warned that vendor narratives can outpace actual capability (4). A product name therefore tells a firm very little. Ask what the system can actually observe, decide and do.

The last two categories deserve the closest attention. “Agent washing” is best answered with a demonstration: show the permissions, the approval points, the complete action history and what happens when the system encounters uncertainty.

The delegation ladder: from research help to legal consequence

Autonomy is not a yes-or-no property. A useful firm policy can set five levels and attach a review rule to each.

  1. Retrieve and organize. Find public authorities, group documents, extract dates or prepare a chronology. The lawyer checks coverage, provenance and access boundaries.
  2. Analyse and recommend. Compare clauses, flag issues or propose research paths. A lawyer tests both the supporting material and what may be missing.
  3. Prepare a draft. Produce an internal memo, client-letter draft or pleading outline. Nothing leaves the working environment without substantive review.
  4. Change an internal record. Update a task, calendar, knowledge item or matter field. Permission is narrow, changes are visible and reversal is practical.
  5. Act externally. Send a client or counterparty message, make a filing, accept a term, transfer data, incur cost or delete material. Express human approval is the default, not an optional setting.

The ladder prevents a common mistake: treating a source-search agent and an email-sending agent as the same risk merely because both use the same underlying model.

Four legal workflows, four different boundaries

Source-grounded legal research

An agent may expand search terms, retrieve decisions, cluster arguments and draft an issue map. It should not decide that research is complete. The reviewing lawyer must inspect the authorities, confirm jurisdiction and date, test whether cited passages support the proposition and look for contrary material. This is where a source-grounded legal research environment is more useful than a fluent, untraceable answer.

Contract review against an approved playbook

Extraction, comparison and first-pass issue spotting can be delegated within a defined playbook. Commercial judgment cannot. An agent should not silently accept a fallback, waive a deviation or send revised terms. The lawyer needs the original clause, the playbook position, the proposed change and unresolved uncertainty together. For repeatable work, the value lies in a reviewable AI contract review, not autonomous negotiation.

Client intake, conflicts and identity checks

An agent can collect information and identify missing fields, but should not make the final conflicts, eligibility or client-acceptance decision. Names can match imperfectly; relationships can be indirect; adverse interests require legal context. Access should also be designed so an intake workflow cannot browse unrelated client material merely because it is technically available.

Pleadings, advice and settlement communications

These are red-line actions. A lawyer should approve the legal position, facts, authorities, recipient and final text before transmission or filing. The California State Bar's 2026 practical guidance is jurisdiction-specific, but its comparative warning is useful: agentic systems should not make substantive legal determinations, communicate advice, prepare and file pleadings or otherwise act on a client's behalf without meaningful lawyer supervision and review (9).

Professional autonomy cannot be delegated

The technology may be autonomous in an engineering sense; it is not an autonomous legal professional. The SRA's July 2026 discussion of agentic legal services states that AI use does not transfer responsibility and that authorized individuals remain accountable for review and supervision (5). CCBE guidance likewise places competence, confidentiality, independence and appropriate verification with the lawyer (6).

Confidentiality becomes harder when an agent has persistent access to email, a document store, a calendar and matter data. The question is no longer only what a lawyer pasted into a prompt. It is what the agent can reach, combine and transmit. Grant the minimum access for one defined purpose; separate matters; place approval before external transfer; and remove access when the task ends. See also our guide to secure AI use for lawyers and LexVera's public security approach.

How the EU AI Act treats agents

“AI agent” is not a separate category in the EU AI Act. The Commission's AI Act Service Desk explains that an agent will typically constitute an AI system and may incorporate a general-purpose AI model; the applicable rules follow from its role and intended purpose (7). An agent is not automatically high-risk simply because it performs several steps.

From 2 August 2026, Article 50 transparency duties can apply where an agent interacts directly with natural persons or generates content. The Digital Omnibus—Regulation (EU) 2026/1744, in force since 27 July 2026—softened but did not remove Article 4. Providers and deployers must take measures that support the development of AI literacy among staff and other people operating their systems, taking account of their knowledge, training and the context of use; they need not guarantee that any individual reaches a specified level. The same Regulation moved Sections 1–3 of Chapter III to 2 December 2027 for high-risk AI systems classified under Article 6(2) and Annex III, and to 2 August 2028 for systems classified under Article 6(1) and Annex I. It did not create a regulatory holiday for agent deployment (8).

Nine controls before an agent receives access

  1. One defined purpose: describe the task, users, matter type, permitted inputs and prohibited outcomes.
  2. Minimum access: expose only the sources and systems required for that task.
  3. Approved sources: distinguish authoritative law, matter documents, firm knowledge and open-web material.
  4. Named lawyer checkpoints: state exactly which steps require approval and who may give it.
  5. Proposition-level verification: test citations, facts and material inferences rather than approving polished prose as a block.
  6. Visible action history: retain enough context to reconstruct tools used, material changes, approvals and external actions.
  7. Stop and recovery: make suspension immediate and reversal possible wherever the underlying action allows it.
  8. Change review: reassess after material supplier, model, permission or workflow updates.
  9. Incident route: define escalation for wrong recipients, confidentiality exposure, missed deadlines, false authorities and unauthorised acts.

A defensible 30-day pilot

Choose one bounded, reversible workflow—public-source monitoring or an internal chronology is usually easier to test than client communication. In week one, document the baseline, task boundary and prohibited actions. In week two, run a closed set of representative matters with full lawyer review. In week three, examine false positives, missed issues, access attempts and review time. In week four, decide whether to narrow, expand or stop.

Measure quality-adjusted time, not demonstrations completed. Useful indicators include source-support rate, material corrections per output, inappropriate access attempts, interventions before action and time spent on final review. A pilot succeeds only if the resulting legal work is both better controlled and worth repeating.

What to ask before buying an AI agent

Where LexVera draws the line

LexVera is built to support legal work while keeping responsibility with the lawyer. The useful outcome is not a system that appears independent; it is a legal AI assistant that keeps relevant sources, matter context, review points and professional judgment close to the work.

That approach reflects a wider principle: legal technology should make careful work easier to inspect and supervise. It should help a lawyer reach the source, understand what changed and decide whether the result is fit for the client or court. Our editorial policy applies the same discipline to public analysis: separate sourced fact, professional interpretation and product context.

Frequently asked questions

What is an AI agent in legal practice?

An AI agent can plan and carry out several connected steps, often by using tools or other systems, with less instruction between steps than a conventional chatbot. The important facts are its access, decision space and authority—not its product label.

Does the EU AI Act apply to AI agents?

Yes, where the relevant definitions are met. Agents are not a separate legal category. The rules for AI systems and general-purpose AI models apply according to role, intended purpose and use.

May an AI agent communicate with a client?

It may support preparation or clearly bounded administrative exchanges, but substantive advice, strategic representations and sensitive disclosures should require meaningful lawyer review and approval before sending.

May an AI agent file court documents?

A firm should not permit autonomous filing. The responsible lawyer should verify the facts, law, citations, procedural requirements and final document, then expressly approve the filing.

Who is responsible when an AI agent makes a mistake?

Technical autonomy does not displace professional responsibility. The responsible lawyer and firm remain accountable for the legal service and need controls proportionate to the agent's permissions and potential consequences.

Sources and methodology

This guide reflects public materials available on 29 July 2026. Survey figures are presented with their stated samples and describe different populations; they are evidence of momentum, not a single market-size estimate. The article provides general professional information, not advice on a particular firm's regulatory or ethical duties.

  1. Staufer et al., 2025 AI Agent Index, FAccT 2026
  2. Deloitte Legal, The AI Imperative survey, 9 July 2026
  3. Thomson Reuters Institute, 2026 AI in Professional Services Report
  4. The Law Society, The future of agentic AI in legal practice, 14 April 2026
  5. Solicitors Regulation Authority, Agentic AI in legal services, 2 July 2026
  6. CCBE guide on the use of generative AI by lawyers, 2 October 2025
  7. European Commission AI Act Service Desk, How are AI agents addressed within the AI Act?
  8. Regulation (EU) 2026/1744 (Digital Omnibus on AI), 8 July 2026
  9. State Bar of California, Practical Guidance for the Use of Generative AI in the Practice of Law, approved 14 May 2026
  10. CCBE technical guide on the use of AI tools and models by lawyers, 27 March 2026