Module 6.3 · Topic 5
Advising on AI Compliance in Legal Contexts
Bottom Line Up Front: AI governance is emerging as a professional responsibility for lawyers. ABA Formal Opinion 512 requires competence and supervision of AI use. State-level AI acts (Colorado SB 24-205, effective June…
5.1 Regulatory Landscape for AI in Legal Practice
Sample prompts to explore compliance issues and approaches with different use cases
Use Case 1: Legal Research and Due Diligence with AI
Use Case 2: Contract Drafting with Generative AI
Use Case 3: Multi-Jurisdictional AI Governance
5.2 Client Guidance on AI Governance and Risk
Lawyers advising clients on AI governance must assess multiple use cases, identify applicable regulations, prioritize implementation, and estimate resources. This skill demonstrates competence under ABA Formal Opinion 512 and state AI acts.
| Know the Law | Build the Policy | Make it Real | |
| What | Map AI use cases to applicable frameworks | Draft governance around documented risks | Implement — don't just write |
| Key References | NIST AI RMF 1.0; FTC Act §5; Colorado SB 24-205; EU AI Act | EEOC AI guidance; OCC/Fed SR 11-7 (model risk) | FTC & EEOC enforcement actions |
| Client Must Do | Identify which rules apply before drafting | Include vendor oversight, human review, incident response | Create audit trails that match the written policy |
| Risk if Ignored | Non-compliant policy creates liability, not protection | Vague language signals no real governance | Discovery gap between policy and practice is a plaintiff's gift |
5.3 Cross-Border Compliance Considerations
Cross-border AI governance creates conflicts between jurisdictions' rules. Lawyers must identify conflicts, understand enforcement priorities, and design governance that satisfies the strictest rule. This skill is critical for multinational organizations.
Scenario:
Pharmaceutical company uses AI for clinical trials across US, EU, China, and India. Different jurisdictions have different rules: GDPR right-to-erasure conflicts with US litigation holds; China requires data residency; India requires localized training. Lawyer must identify conflicts and design governance satisfying strictest rules.
Sample prompt:
What to expect in reply:
Response may identify GDPR, HIPAA, China cybersecurity law, India data localization rules. Recognizes conflicts (erasure vs. holds, residency requirements). Recommends applying strictest rule globally for consistency, updating compliance matrix quarterly. Notes pharmaceutical AI is high-risk per EU AI Act requiring impact assessment, bias testing. Strong responses link governance to insurance, litigation risk, and enforcement priorities.
5.4 Building AI Governance Expertise as a Professional Differentiator
Building governance expertise positions lawyers as trusted advisors on emerging risk. Clients increasingly ask: "How do we comply with AI regulations?" Lawyers who answer that question win work and earn differentiation.
- Build competence: Take structured AI course, read ABA Formal Opinion 512 and state bar guidance, track regulatory developments, maintain practice-area checklist
- Audit internally: Document current AI use in your firm, create risk register, identify governance gaps, assess compliance
- Develop services: Offer clients governance assessments, policy templates, training, ongoing compliance advising. Market as risk management and liability mitigation.
- Track regulations: Join regulatory tracking services, understand reasoning behind rules to advise clients effectively and anticipate future requirements
- Link to insurance: Position governance as insurance risk mitigation. Firms without governance face uninsurable gaps; insurance carriers increasingly demand it.