In May 2023, two New York attorneys submitted a legal brief citing six precedent cases. The legal AI tool they used to research the brief generated all six cases. None of them existed. The court issued an order requiring the attorneys to explain why they should not be sanctioned.
That incident shaped how legal teams think about AI legal research for the next two years: avoid it. That overcorrection is now costing legal teams measurable productivity on tasks where legalai performs accurately andrepeatably at a fraction of the manual effort. The risk is real and concentrated in specific tasks. The opportunity is also real and concentrated in different specific tasks. This is a task-by-task risk map.
The Legal AI Risk Framework
Legal AI risk concentrates around two dimensions: whether the output will be relied upon without human review, and whether an error in the output creates professional liability or harms a client.
High-risk tasks are those where AI errors go undetected (no human reviews the output before it reaches the client or court) or where an error has severe consequences (wrong clause in a contract, missed deadline, incorrect case citation). Low-risk tasks are those with mandatory human review before any output is used, or where an error is easily caught and low-stakes.
The framework below rates each task by risk level and states what human oversight is required. GenAI Protos provides a detailed breakdown of implementations for law firms and in-house teams across these use cases.

Task Risk Map
AI Legal Research
Risk level: High if output is not verified. Medium with mandatory verification.
Legalai tools trained on case law databases (Westlaw, LexisNexis,Casetext) perform significantly better on legal research than general-purpose LLMs. They are grounded in actual case law, not trained associations. They hallucinate at lower rates and include citation links that can be verified.
General-purpose LLMs hallucinate case citations at significantly higher rates than purpose-built ai legal research tools grounded in verified legal databases. The risk scales with query specificity and jurisdictional obscurity. This is the failure mode from the 2023 incident.
What works: Research using a legal-specific AI tool, with the attorney verifying every citation before inclusion in a filing. The ai legal research step reduces time materially compared to fully manual research. The verification step is non-negotiable. Risk: lower when mandatory verification is built into the workflow.
What does not work: Using a general-purpose LLM for case law research, relying on AI-generated citations without verification, or using AI research tools for jurisdictions or practice areas they are not trained on.
Explore our industry approach: GenAI Protos designs Legal AI with retrieval grounding, verification and mandatory lawyer review.

Contract AI: Review and Analysis
Risk level: Medium with human review on key clauses.
Contractai performs reliably on three tasks:identifying whether standard clauses are present or absent (indemnification, limitation of liability, IP ownership, termination rights), comparing contract terms against a standard playbook, and flagging unusual or non-standard language for attorney review.
It underperforms on: jurisdiction-specific enforceability questions, novel clause types without training precedent, and multi-party agreements with complex dependency structures.
The Legal AI Assistant handles contract review for standard commercial agreements: NDAs, MSAs, vendor agreements, and employment contracts. The workflow is: AI reviews the contract and produces a structured analysis of present/absent clauses, deviations from the standard playbook, and flagged unusual terms. A lawyer reviews the flagged items and makes the final assessment. The AI handles the structural and repetitive portions of contractai review, freeing attorney timefor the judgment-dependent work. The enterprise results of this workflow at scale are detailed in the AI-Powered Contract Intelligence case study.
Risk boundary: Contract AI generates analysis. A qualified attorney makes all decisions about whether contract terms are acceptable, what changes to request, and whether to sign.

Legal Document AI: Drafting
Risk level: Medium-high for first draft, Low with revision by qualified attorney.
Legal documentai for first draft generation reduces drafting time meaningfully on standard document types: NDAs, employment agreements, standard vendor terms, court filings with standard sections, and demand letters. The actual time saving depends on document complexity, organizational templates, and the level of customization required. The first draft is a starting point that requires attorney review and revision, not a finished document.
The risk is treating AI-generated legal documents as ready to use without revision. Every AI-drafted legal document must be reviewed by a qualified attorney before it is sent to any party. This is not a suggestion. In most jurisdictions, submitting an AI-generated document without attorney review may violate professional responsibility rules.
For regulated documents that require specific language (regulatory filings, securities disclosures, patent claims), legal document AI produces a structural draft but cannot substitute for the domain expertise required to get the regulated language exactly right.
Compliance Monitoring and Regulatory Research
Risk level: Low with appropriate grounding.
The RAG Compliance Assistant GenAI Protos builds handles a specific, high-value use case: monitoring a defined regulatory corpus (GDPR, HIPAA, EU AI Act, specific industry regulations) and answering compliance questions grounded in that corpus. The AI retrieves the relevant regulatory text, cites the specific provision, and generates a structured answer.
This use case has lower hallucination risk than open-ended generation because the AI is grounded in retrieved regulatory text. Retrieval grounding significantly reduces the risk of fabricated citations or invented regulatory provisions, but does not eliminate it entirely; the model can still misinterpret, selectively quote, or draw unsupported conclusions from real documents. The primary risk is corpus completeness: if a relevant regulation is not in the indexed corpus, the AI will not find it, and cannot flag its absence.
What works: Compliance question-answering on a defined, indexed regulatory corpus with citation to source documents. Regulatory change monitoring that alerts when indexed documents are updated.
What does not work: Compliance advice on regulations not in the corpus, jurisdiction-specific advice on interactions between regulations, or compliance decisions that require professional judgment about regulatory intent.
E-Discovery and Document Review
Risk level: Low for prioritization and classification. High if used as the final review.
AI-assisted e-discovery classifies documents by relevance, privilege, and category at a scale and speed human reviewers cannot match. The AI classification determines which documents are prioritized for human review. Attorneys review the flagged documents. Attorneys make the final privilege determination.
The risk in e-discovery is using AI classification as the final review rather than as prioritization. Documents classified as non-responsive by AI should have a sample reviewed by human attorneys to assess classification accuracy. Even a small error rate on a large document set can mean a significant number of responsive documents potentially withheld. Courts have sanctioned parties for inadequate review processes. Human sampling of AI classifications is a necessary control, with the sample size determined by the risk level of the matter and the AI tool's validated accuracy for that document type.
Relevant case study: AI-Powered Contract Intelligence demonstrates how GenAI Protos applies AI to document review while retaining human oversight.
What AI for Lawyers Cannot Do
Provide legal advice to clients. Legal advice requires attorney-client relationship, jurisdiction-specific knowledge, and professional liability. No AI system establishes this relationship.
Represent clients in proceedings. Courtroom representation, depositions, and negotiations require a licensed attorney.
Make final decisions on legal strategy. Case strategy, settlement decisions, trial preparation, and plea decisions require attorney judgment and accountability that AI cannot provide.
Sign documents or filings on behalf of a party.
Key Takeaways
- Legal AI risk concentrates in two conditions: no human review of AI output before use, and high consequences for errors in the specific task.
- AI legal research with citation verification is medium-risk. Mandatory citation verification by a qualified attorney is what makes it usable. Without verification, it is high-risk.
- Contract AI performs well on clause presence/absence analysis and playbook comparison. It requires attorney review before any term is accepted or rejected.
- Compliance RAG assistants grounded in a defined regulatory corpus have reduced hallucination risk compared to ungrounded generation. Corpus completeness and accurate interpretation of retrieved text are both constraints.
- E-discovery AI works as prioritization. Human sampling of AI classifications is required before any set is finalized as non-responsive.
Conclusion
Legal AI delivers value when task boundaries, source verification and attorney accountability are explicit. GenAI Protos builds legal workflows that automate repeatable analysis and drafting while keeping professional judgment, client responsibility and final approval with qualified legal teams.



