All articles

2026-08-03 · lawyers

AI for Law Firms Without Practicing Law: A Responsibility Matrix

Use this responsibility matrix to give an AI employee law firm intake and admin work without handing it legal judgment or client strategy.

AI for Law Firms Without Practicing Law: A Responsibility Matrix

AI for law firms can handle intake, scheduling, document collection, status follow-up, billing reminders, and record updates without practicing law. The line is straightforward in principle: the AI employee can own a defined administrative outcome, while an authorized lawyer owns legal advice, legal conclusions, strategy, and representation.

The hard part is turning that principle into daily operating rules.

A small firm may have twenty potential-client inquiries in different places, three consultation calendars, documents arriving by email, and clients asking for updates. Staff know that some work is routine. They also know one careless message can create a confidentiality problem, an inaccurate promise, or an answer that sounds like legal advice.

The usual response is one of two bad systems. The firm either lets a generic tool answer too much or makes a lawyer approve every harmless administrative action. The first creates risk; the second creates another inbox for the lawyer.

A useful AI employee needs a written responsibility matrix, access to the right systems, and a narrow but complete job to own.

The operating boundary

The American Bar Association's Formal Opinion 512 on generative artificial intelligence tools applies existing professional duties to lawyers' use of generative AI. It addresses competence, confidentiality, communication, candor, supervision, and fees. It does not make the software responsible for the lawyer's work.

That matters when a firm designs an AI employee. The firm still needs an accountable lawyer, current policies, appropriate supervision, and a way to inspect what the system did.

The ABA Model Rules are a useful starting point, but they are not a substitute for the rules that govern a particular firm. Before launch, check the professional-conduct rules, ethics opinions, privacy requirements, court rules, client terms, and other laws that apply in each jurisdiction where the firm operates.

Three Model Rules frame the basic boundary:

Firms can delegate the process while keeping professional judgment with authorized lawyers.

Why routine legal operations still get stuck

Law firms rarely lose administrative work because nobody cares. The work gets lost because the process crosses too many places and has no single owner.

A potential client submits a form. The form sends an email. A receptionist copies some details into practice-management software. A lawyer checks conflicts later. Someone sends a scheduling link. The prospect replies to the original email instead. A document arrives as an attachment. Nobody can tell whether the consultation was confirmed.

The same pattern appears after engagement:

  • clients ask for status updates in separate email threads;
  • staff chase missing documents without a consistent cadence;
  • matter records do not match the latest conversation;
  • routine invoice reminders wait until someone checks aging;
  • a lawyer is interrupted to answer a scheduling or process question;
  • an actual legal question sits beside routine requests in one queue.

An automation may move data at one step. A chatbot may answer a question. Neither automatically owns the result.

An AI employee should have a definition of done. For new-client intake, that might be: collect the approved facts, run the firm's preliminary routing and conflict-input procedure, schedule an appropriate consultation when allowed, send the required confirmation, update the system of record, and route any true exception with a decision-ready brief.

That is the ownership distinction described in what an AI employee is. The goal is finished administrative work, not another stream of suggestions for staff to process.

A responsibility matrix the firm can use

Start with three categories. Do not build the workflow until every action has a category and a named owner.

Work the AI employee can own

These actions are administrative when the firm supplies the rules, approved language, and system access:

  • acknowledge a new inquiry without evaluating the legal merits;
  • collect contact details and the prospect's own description of the issue;
  • ask approved factual intake questions;
  • identify missing fields and request them;
  • create or update a contact and matter-intake record;
  • detect likely duplicate records;
  • check calendars and offer approved consultation slots;
  • send scheduling confirmations and routine reminders;
  • collect approved documents through the firm's designated channel;
  • label, route, and log incoming files without interpreting their legal effect;
  • answer approved questions about office hours, location, process, and document-submission steps;
  • send factual status messages based on an attorney-approved matter status;
  • send approved invoice reminders and record the response;
  • stop a follow-up sequence when the person replies, declines, retains other counsel, or asks not to be contacted;
  • produce a daily exception report with timestamps and source links.

The AI employee should communicate directly and update the firm's systems as it works. Staff should not have to copy its answer into the practice-management system or send every approved message themselves.

Work the AI employee can prepare but not decide

Some work is useful to assemble, but the decision belongs to an authorized person:

  • prepare a conflict-check packet from collected names and entities;
  • summarize the facts supplied by a prospect without adding a legal conclusion;
  • flag a deadline mentioned by the prospect for immediate lawyer review;
  • draft a status update from an attorney-approved matter note;
  • assemble documents against a lawyer-approved checklist;
  • identify a missing signature, field, or attachment;
  • prepare a settlement, filing, research, or strategy packet for lawyer review;
  • draft a response that touches legal rights or options;
  • prepare a fee or scope change that requires lawyer approval;
  • flag a request that may involve a complaint, privilege issue, adverse party, court communication, or ethical duty.

The AI employee can do the collection and packaging. It should pause only the affected action, preserve the source material, and send the designated lawyer a short brief with the exact decision needed.

Work that stays with an authorized lawyer

The following category should never be disguised as routine administration:

  • telling a person what legal rights or remedies they have;
  • applying law to facts and giving a legal conclusion;
  • evaluating the merits or likely outcome of a matter;
  • choosing legal strategy;
  • establishing or changing the scope of representation;
  • making a final conflict or disqualification decision;
  • accepting or declining a representation when legal judgment is required;
  • advising on deadlines, limitation periods, filings, or procedural rights;
  • negotiating or communicating a legal position unless an authorized lawyer directs and supervises it under applicable rules;
  • signing, filing, certifying, or representing anything that requires a lawyer;
  • making a fact-specific confidentiality, privilege, waiver, disclosure, or candor decision.

A category label alone is not enough. The firm needs examples drawn from its own work. "Status update" could mean "Your consultation is Tuesday at 2:00 p.m.," which is administrative. It could also mean "The court will probably grant the motion," which is a legal assessment. The matrix must define the difference in the language the firm actually receives.

What end-to-end intake can look like

Suppose a potential client submits a website form at 7:40 p.m. The person provides a name, phone number, opposing-party name, a short description, and a preferred consultation day.

A well-scoped AI employee can:

  1. Create the intake record with the original timestamp and source.
  2. Preserve the prospect's wording rather than rewriting it as a legal conclusion.
  3. Acknowledge receipt using approved language that does not imply representation.
  4. Ask only for missing facts on the firm's approved intake list.
  5. Check whether the inquiry fits an administrative routing rule, such as practice area, geography, and consultation type.
  6. Prepare the required names and entities for the firm's conflict procedure.
  7. Offer an approved consultation time only after the required gate has cleared.
  8. Send the confirmation, document instructions, and firm-approved disclosures.
  9. Update the intake stage and set the next action.
  10. Record every message, field change, and timestamp.

If the prospect asks, "Do I have a case?" the AI employee should not improvise. It should preserve the exact question, continue collecting any routine missing information, and route the legal question to the authorized lawyer.

If a possible deadline appears, the AI employee should not calculate or assure the prospect about it. It should flag the source language immediately under the firm's urgent-review policy.

The system does not need to freeze the entire intake because one question is outside its authority. It pauses that action, routes it correctly, and continues the administrative work that remains safe and useful.

Build the workflow in seven steps

1. Name one outcome

Do not start with "use AI in the firm." Pick one result that currently consumes time or fails unpredictably.

A workable first outcome might be:

"Every website inquiry receives an approved acknowledgement, a complete intake record, the next allowed scheduling action, and a documented final status. Legal questions and policy exceptions reach the intake lawyer with the facts and decision needed."

That statement tells the team where the job starts, where it ends, and what does not belong in the routine path.

2. Map the data before the messages

List every field the workflow can read, create, or change. Mark which fields may contain information relating to a representation, sensitive personal data, payment information, health information, or court-protected material.

For each system and vendor, document:

  • what data enters;
  • why the workflow needs it;
  • where it is stored;
  • who can access it;
  • whether it is retained or used to improve a model;
  • which security and contractual controls apply;
  • how access is removed;
  • how an incident is investigated.

Formal Opinion 512 discusses the need to evaluate disclosure risk before putting representation information into a generative AI tool. The safest design is not to send every record to every model. Give the workflow the minimum data and permissions needed for its assigned job.

3. Turn the responsibility matrix into rules

Write examples for each allowed action, conditional action, and lawyer-only decision. Include the firm's approved disclosures and prohibited statements.

Avoid vague instructions such as "do not give legal advice." Add examples:

  • Allowed: "Your consultation is scheduled for August 6 at 10:00 a.m."
  • Not allowed: "You should file before August 6."
  • Allowed: "I recorded your question for the attorney."
  • Not allowed: "Based on what you described, the firm can win this."

Examples make testing possible.

4. Connect the system of record

The workflow needs the same operational context a capable employee would use: approved intake questions, matter types, office locations, calendars, status definitions, communication templates, stop conditions, and current routing rules.

Use the least privilege needed. An intake workflow may need to create a potential-client record and schedule a consultation. It probably does not need permission to delete matters, release trust funds, change billing rates, or access every document in the firm.

5. Design decision-ready exceptions

A raw transcript is not an exception brief. Use this format:

  • Record: prospect or matter ID and direct link.
  • Trigger: the exact rule that stopped the affected action.
  • Source facts: the person's exact words and relevant submitted fields.
  • Work completed: records, questions, messages, and documents already handled.
  • Available options: only options permitted by firm policy.
  • Decision needed: one specific question for the authorized person.
  • Deadline: when the decision is needed and why.

The lawyer should be able to decide without hunting through three systems.

6. Test paths, not sample prompts

A good answer in a chat window proves very little. Test the full path with controlled records.

Include:

  • a routine inquiry with complete information;
  • missing contact information;
  • a possible duplicate;
  • a possible urgent deadline;
  • a direct request for legal advice;
  • a conflict-input issue;
  • an unsupported matter type;
  • a prospect who stops responding;
  • an opt-out request;
  • a failed message or unavailable calendar;
  • a prompt-injection attempt inside an uploaded document;
  • an incorrect or stale status in the source system.

Check the message, the record update, the next action, the exception route, and the audit log. A test fails when the reply looks polished but the underlying record is wrong.

7. Review failures and expand slowly

The NIST Generative AI Profile is a voluntary companion to AI RMF 1.0 for managing generative-AI risks across the system lifecycle. Its governance approach is useful here: document the intended use, identify the risks, test the system, manage third parties, and monitor what happens in operation.

Start with limited data, permissions, and matter paths. Review actual exceptions and failures. Expand authority only after the current path works and the firm's responsible lawyers are satisfied with the evidence.

A copyable launch checklist

Scope and authority

  • [ ] Name one administrative outcome the AI employee owns.
  • [ ] Identify the accountable lawyer and operational owner.
  • [ ] Classify every action as AI-owned, conditional, or lawyer-only.
  • [ ] Add examples of allowed and prohibited language.
  • [ ] Check the rules and requirements for every jurisdiction involved.

Data and systems

  • [ ] Inventory every source, destination, vendor, and model in the workflow.
  • [ ] Identify confidential and sensitive fields.
  • [ ] Record retention, model-training, access, deletion, and incident terms.
  • [ ] Give each integration the least privilege needed.
  • [ ] Keep one authoritative record for intake or matter status.
  • [ ] Log messages, field changes, actions, errors, and timestamps.

Customer and client communication

  • [ ] Use approved language that does not imply representation before engagement.
  • [ ] Separate process information from legal advice.
  • [ ] Preserve the person's own words when routing legal questions.
  • [ ] Define consent, channel, recording, quiet-hour, and opt-out rules.
  • [ ] Stop follow-up when the terminal condition is reached.

Testing and oversight

  • [ ] Test routine, missing-data, legal-question, conflict, deadline, failure, and adversarial paths.
  • [ ] Verify system updates, not just message quality.
  • [ ] Confirm that one exception does not stop unrelated safe work.
  • [ ] Review a sample of completed records and every high-risk exception.
  • [ ] Set a schedule for policy, vendor, permissions, and failure review.

Measure whether the job gets finished

Do not judge the AI employee by the number of messages it generates. Measure the assigned outcome.

For an intake workflow, track:

  • inquiries received by source;
  • records created without missing required administrative fields;
  • median time to approved acknowledgement;
  • consultations scheduled under firm policy;
  • inquiries with a documented terminal status;
  • legal or policy exceptions by reason;
  • exceptions that lacked decision-ready information;
  • duplicate records;
  • failed sends and failed system writes;
  • follow-ups that continued after a stop condition;
  • sampled records that match the communication and audit log.

Set a baseline from the firm's current process before launch. Then compare the same fields after the workflow is active. Do not borrow a benchmark from another firm and call it proof.

Common mistakes

Treating the tool's disclaimer as the boundary

A footer that says "not legal advice" does not fix a message that applies law to a person's facts. The workflow, permissions, examples, and escalation rules need to enforce the boundary.

Sending all firm data to one model

Map the minimum information needed for each action and review the provider's actual terms and controls before sending firm data to a model.

Making a lawyer approve every routine action

If the lawyer must approve acknowledgements, scheduling, document requests, reminders, and record updates one by one, the firm has built a draft generator. The responsibility matrix should give the AI employee enough authority to finish routine administrative work.

Hiding legal judgment inside a label

"Lead scoring," "case assessment," and "status update" can contain legal conclusions depending on how the firm defines them. Inspect the decision, not the label.

Testing language without testing systems

A message can be accurate while the calendar booking fails, the matter status remains stale, or the opt-out is ignored. Test the completed record and the evidence trail.

Assuming one policy fits every jurisdiction

The ABA Model Rules are not the final word for every firm. Adopted rules, state ethics opinions, court rules, privacy requirements, and firm obligations can differ. The workflow needs jurisdiction-specific review before live use.

Give the administrative work a real owner

A useful design gives the AI employee enough authority to complete routine legal operations while reserving professional judgment for authorized lawyers.

ComfortGrowth AI builds AI employees for law firms around the firm's intake rules, systems, permissions, and exception paths. The result should remove scheduling, collection, follow-up, and recordkeeping work from the team while keeping legal decisions with authorized lawyers.

Request a free business audit and we will map one law-firm workflow from trigger to completed administrative outcome. You will leave with a responsibility matrix showing what the AI employee can own, what needs a decision brief, and what stays with a lawyer.

Next step

Want this running in your business?

We implement AI employees that do the work—follow-ups, inbox, invoices, scheduling—with your approval before anything goes out.