Guest Essay
Vendors are proving their tools are safe to use. That is not the same as proving your firm used them safely, and the difference is where malpractice exposure lives.
Hema Dey, Advisor, AI Trust CouncilSeptember 18, 20266 min read
The question every managing partner should be able to answer, matter by matter.
A litigation associate files a brief on a Friday afternoon. The research was fast, the citations looked clean, and the partner signed off before the 5 p.m. deadline. Three weeks later, opposing counsel raises a simple question in a reply brief: which of these cases actually exists.
That scenario is no longer rare enough to dismiss. It is becoming a pattern courts recognize, and it points to a problem most firms have not solved, including the ones who believe they have.
The problem is not that lawyers are using AI. Every serious firm is, whether that use is sanctioned or quietly happening on an associate’s own laptop. The problem is that almost no firm can answer a simple question about any piece of AI-assisted work product: who or what touched this, in what order, and who verified it before it reached the client or the court.
That question is exactly what the Trust Identity Protocol, or TIP, is designed to answer.
The industry is solving the wrong layer of the problem #
Watch what the major AI vendors have been building this year, and a pattern emerges. OpenAI’s Astra for Law, announced this month, leans heavily on data retention controls and human review exclusions for eligible firms. Vendors are racing to prove their tools are safe to use in principle.
That is a meaningful step, and firms should expect it from any vendor they work with. But it solves the vendor’s liability, not the firm’s. A tool being safe to use does not tell you whether it was used safely, by whom, on which matter, with what verification step before the output reached a client file or a court filing.
That gap, the space between a safe tool and a defensible process, is where malpractice exposure actually lives. It is also where TIP operates.
What TIP actually does #
TIP is not another AI tool competing with the research assistants and drafting copilots already in your stack. It sits underneath them. Where a research tool answers a legal question and a drafting tool produces language, TIP is concerned with a different question entirely: can the firm establish, after the fact, exactly what happened at each point AI touched a matter.
In practice, TIP is built around three core functions.
- Establishing identity at each touchpoint , so a firm can distinguish AI-generated content from attorney-authored content, and distinguish one AI system’s output from another’s when multiple tools touch the same matter.
- Creating a verification checkpoint , so there is a documented moment where a human reviewer confirmed an AI output before it moved downstream, rather than an assumption that review happened because a partner’s name is on the final document.
- Building an audit trail across the life of a matter , so that if a question is ever raised, in a malpractice claim, a bar inquiry, or under cross-examination, the firm has an actual record instead of a reconstructed memory of what probably happened.
None of that replaces a firm’s judgment, its supervision structure, or its existing case management system. TIP is not a substitute for attorney oversight. It is the layer that makes attorney oversight provable, which is a different and in some ways harder problem than most firms have thought to solve.
Why SB 574 makes this urgent instead of optional #
California’s SB 574, which cleared the Legislature this year, pushes firms past the old standard of “use good judgment with AI” toward something closer to what firms already do for conflicts checks and trust accounting: a documented, repeatable process.
That shift changes what a managing partner needs to be able to produce. It is no longer enough to say the firm has a policy. A firm increasingly needs to show, matter by matter, what happened. Without a structure like TIP running underneath a firm’s AI use, that documentation does not exist. It has to be reconstructed after the fact, which is exactly the position no attorney wants to be in when a judge or a client is asking the question.
The malpractice exposure attorneys are not yet watching for #
Most malpractice conversations about AI still focus on the most visible failure: a hallucinated citation making it into a filing. That is real, and it is happening in courtrooms with increasing frequency. But it is only the most visible version of a broader exposure.
The bigger risk is a firm that cannot reconstruct its own process. A client who loses a matter where AI touched the file is going to ask a specific question. Did the firm have a process, or did it improvise? An attorney who can point to a documented chain, this tool was used, this output was reviewed by this person on this date, is in a fundamentally different position than one explaining, after the fact, what probably happened.
That distinction, between a firm that can show its work and one that cannot, is the line malpractice carriers and bar associations are moving toward. TIP exists to put a firm on the right side of it before the question is ever asked.
This is not a tool decision. It is a firm decision. #
In “The Reimagined Law Firm,” I wrote about the pattern I see across firms that outsource AI governance to a fractional executive or a single well-meaning associate: nobody owns the full picture. The managing partner signs a vendor contract without fully understanding what the vendor’s controls do and do not cover. The associate who is comfortable with AI becomes the de facto governance function, with no visibility for anyone above them.
TIP does not work as a bolt-on decision made by whoever is closest to the technology. It works as firm infrastructure, decided and owned by firm leadership, the same way a firm decides how conflicts checks work or how client trust accounts are reconciled. That parallel is deliberate. Those processes are not optional because a firm trusts its people. They are structural, because trust without a verifiable process is not something a firm can stand behind when it matters most.
The firms getting AI governance right are not the ones with the most sophisticated tools. They are the ones who decided, at the leadership level, that every AI touchpoint needs an answer to a simple question: if someone asked us to prove what happened here, could we?
That is the DNA TIP is built to provide. Not a replacement for legal judgment, but the structure that makes a firm’s judgment defensible, matter after matter, long before anyone thinks to ask.
If your firm cannot answer that question with confidence today, that is not a technology gap. It is a governance decision sitting in front of you, and it is one worth making before a client, a judge, or a bar investigator makes you answer it under pressure. Hema Dey is a Forbes Top 5 AI Leader, Founder and Chief Executive Officer of Iffel International Inc., and the #1 Amazon bestselling author of The AI Translator. She serves as an Advisor to the AI Trust Council of The AI Lab. Understand your law firm's malpractice risks at iffelinternational.com.
Read how the Trust Identity Protocol works, or start at vp.theailab.org.