Turning firm approval into a defensible use decision
A Romanian law firm is preparing a competition-law submission for a client. The matter file contains the agreement under review, internal correspondence, personal data, and commercially confidential records. The firm has just purchased a legal-AI tool, and the team wants to use it to organise documents and prepare a preliminary memorandum. The useful question is not whether the tool has been approved in the abstract. It is whether the tool may be used for this particular assignment, with these records, for this client, and under the applicable handling restrictions. A workable matter-use gate must be able to produce three outcomes: acceptable use, prohibited use, or use subject to stated conditions.
Firm-wide approval answers only part of that question. It may establish that procurement, security, or legal teams reviewed selected characteristics of the vendor and product. It does not make every subsequent use suitable. A tool accepted for research across public materials may be unsuitable for confidential contract schedules. A feature permitted for internal issue spotting may require a different assessment when its output informs a notice submitted to a competition authority. The EU AI Act adds pressure to examine intended purpose, roles, and actual deployment, while professional secrecy, data protection, information security, and the client’s instructions continue to operate alongside it.
Define the deployment
Assess the precise legal task, document set, affected people, enabled feature, client restrictions, and destination of the output.
Choose one outcome
A matter-use gate should classify the proposal as acceptable, conditional, or prohibited for the specific file.
Reopen when facts change
New records, features, vendor terms, client instructions, or regulatory classifications can require a fresh assessment.
Define the intended use and map roles
Step one is to describe the intended use narrowly enough to evaluate it. Record the legal task, document set, affected people, jurisdiction, intended users, and destination of the output. “Use AI on the matter” is not an assessable description. A better entry would say: extract exclusivity clauses from 25 distribution agreements to populate an internal table checked by the legal team, without generating the final authority submission. That wording distinguishes internal document analysis from the production of an external legal deliverable. It also reveals whose data may be processed, which contractual restrictions matter, and whether the assignment could expand after approval.
Step two is to map roles before assuming which AI Act duties apply. The vendor may be the provider of the AI system, while the firm may act as a deployer when it uses that system under its authority. Those labels should not be assigned mechanically. Material modification, a changed intended purpose, or incorporation into another system may alter the analysis. A separate role map is required for data protection: the firm might act as controller or processor depending on the engagement, and the vendor’s position must also be established. AI Act roles, GDPR roles, the client relationship, and the lawyer’s professional obligations answer different questions; one label cannot substitute for another.
Test marketed purpose through an information screen
The team should then separate the product’s marketed purpose from its proposed deployment. “AI for professionals” does not establish suitability for every file or legal deliverable. The relevant facts include the vendor’s instructions, the enabled feature, the firm’s configuration, and any changes made to the workflow. The team should also ask whether the proposed use affects people in a way that differs from the reason the product was acquired. Summarising clauses for an internal memorandum is materially different from relying on an automatically generated score to recommend terminating an agreement or to characterise the conduct of an employee whose communications appear in the file.
Step three is an information screen conducted at document-category level. Identify confidential client information, personal data, special-category data, privileged material, trade secrets, and records covered by client-imposed handling rules. The engagement agreement, the client’s security policy, or instructions for the competition matter may prohibit uploading records to an external service or require prior consent. The firm should obtain clear answers about storage location and duration, authorised access, relevant subprocessors, deletion, and whether submitted material is used to develop models. If an answer cannot be verified, that gap belongs in the decision record rather than being converted into an assumption of safety.
Set operating conditions and issue the matter-use record
The screen should lead to concrete boundaries, not a generic approval tick. The firm might allow only redacted documents, exclude specified annexes, or restrict use to clause extraction without permitting generation of the memorandum. Conditions may require an authorised workspace, named users, activity logging, and a prohibition on entering records from a sensitive part of the file. Conversely, if the client forbids external processing, the proposed data flow conflicts with the agreement, or the vendor cannot explain material handling practices, the correct outcome may be “prohibited for this matter.” That does not mean the product is rejected for all work; it means suitability is use-specific.
Step four defines operating conditions and escalation triggers before work starts. The record should state who may intervene, who receives an incident report, and which events suspend the approval. Triggers might include unintended disclosure, an unexplained output, a change in vendor terms, activation of a new feature, or expansion from an internal table to a client memorandum or regulatory notice. Logging should be sufficient to reconstruct why the use was permitted: tool version, important settings, document categories, approval conditions, and intended output destination. Output retention also needs an explicit rule. Keeping everything indefinitely is not automatically responsible, while deleting all evidence may prevent later reconstruction.
Step five is to issue a short, revisitable matter-use record. It should identify the use, mapped roles, information categories, client restrictions, operating conditions, approver, and one of three outcomes: acceptable, conditional, or prohibited. It should also specify what reopens the decision. New client instructions, additional sensitive documents, revised vendor terms, a changed system version, or a different regulatory classification may all justify reassessment. This creates a practical control without pretending that the original decision is timeless. It also enables the firm to show how an abstract governance policy was applied to a particular agreement, document collection, legal task, and external deliverable.
Wisanna and the pre-adoption inquiry
Wisanna is a private and secure legal-AI workspace built for lawyers. Its public product surfaces include AI Chat, a Microsoft Word add-in, and Wisanna Draft for editable legal documents. Those facts can form part of a proposed-use assessment, but they do not replace examination of the matter, the contract, the client’s instructions, or the records involved. AI outputs are not automatically correct or final. The firm still needs to decide what information may enter the workspace, which feature is appropriate for the defined task, and whether the intended destination of the output remains within the conditions recorded for that use.
Before legal AI enters client work, Wisanna can support the pre-adoption inquiry by helping legal professionals formulate and organise the questions they need to ask about a proposed use. The gate becomes useful when those questions are specific: which clause, from which agreement, for which memorandum, concerning which people, and under which client restrictions? A product demonstration can clarify the available surfaces, but it cannot determine whether a particular file is eligible on the firm’s behalf. A disciplined matter-use decision therefore avoids two weak assumptions: that purchasing a tool authorises every deployment, and that a single general policy can anticipate every combination of documents, people, purposes, and legal deliverables.
Structure the inquiry before legal AI enters the matter
Wisanna can help legal professionals organise specific questions about the task, records, people, restrictions, and intended legal output.
See Wisanna's lawyer-controlled workflow