Two. That is the number of legal departments, of 452 surveyed for LegalOn’s Inhouse Pulse in August 2026, reporting full workflow support from AI. Ninety-two per cent used AI; 54.9% were still “experimenting”. Artificial Lawyer called it “a large, very shallow lake of activity” under the headline “Culture Still Eats AI For Breakfast”.

That is the honest state of AI for in-house counsel in September 2026: adoption near-universal, workflows rare, numbers rarer. What follows: four workflows with named-company evidence, the Copilot tiers most departments confuse, February’s privilege ruling, and metrics a CFO will not laugh at.

The shallow lake: 87% use, 7% at scale, 83% cannot measure

The figures come from surveys with different denominators; here they are side by side.

Finding Figure Source
GCs reporting GenAI use in their teams (44% in 2025, 20% in 2023) 87% FTI / Relativity, March 2026
Top use cases: summarisation / clause identification 83% / 63% same
Teams that have scaled AI beyond pilots 7% Axiom, July 2026
Cannot demonstrate ROI on last year’s AI spend 83% same
Expect AI-related rate cuts from outside counsel 92% same
Do not know whether their firms use GenAI on their matters 59% ACC / Everlaw, October 2025

Two Axiom details explain the rest: two-thirds of teams run a general-purpose tool in its default configuration, and tool selection often happens outside legal. A lawyer with a chat window and no playbook is what a shallow lake looks like.

Why in-house adoption is structurally faster: capacity, not revenue

A law firm that finishes a five-hour task in one hour has a pricing problem. A legal department does not.

“When an in-house team uses AI to finish a five-hour task in one hour, that time does not disappear from a revenue line. It becomes capacity.” — Daniel Lewis, CEO, LegalOn, Artificial Lawyer, May 2026

The ACC/Everlaw survey found 64% of in-house counsel expecting to reduce reliance on outside counsel, with drafting (78%), contract management (71%) and research (62%) the likeliest work to be pulled back; Axiom found 80% planning to move significant law-firm work in-house or to alternative providers within 24 months.

The second motive is political. Thomson Reuters’ 2026 State of the Corporate Law Department report found 86% of GCs believe legal contributes significantly to business success; 17% of C-suite executives agree. A department that can show turnaround falling has an argument. One that cannot has a cost centre.

Workflow 1: NDA and MSA review against a playbook

NDA review works because the standard is yours, not the model’s. Alexis Palmer, Senior Managing Counsel at Snyk, calls it “the kind of review a lean team runs a hundred times a quarter”, and adds: “Having saved prompts means anyone on my team can run the same review I would” (GC AI, vendor page). The prerequisite is a playbook with Preferred, Fallback and Walk-away positions per clause; LegalOn found 34% of legal teams have none, so build one from five signed agreements first. The contract review guide covers the GREEN / YELLOW / RED method; this prompt is the in-house front door.

NDA triage against your standard
Triage the attached NDA against our standard mutual NDA <standard>[paste]</standard> and these triage rules <rules>[e.g. one-way in counterparty's favour = FULL REVIEW; term over 5 years = COUNSEL REVIEW; residuals clause = FULL REVIEW; governing law outside [list] = COUNSEL REVIEW]</rules>. Read the whole document, including exhibits, before flagging anything.

Output: TRIAGE RESULT: [STANDARD APPROVAL / COUNSEL REVIEW / FULL REVIEW]; the rule(s) triggered with the clause quoted; a five-line summary of deviations from our standard with clause numbers; and a two-sentence reply I can send to the business requester. If the document is not an NDA, say so and stop. Cite no law.

Models are better at deciding whether an issue exists than at locating it (Onit’s “Better Call GPT” study: F-score 0.871 versus 0.686), so demand quoted words in every row and read every STANDARD APPROVAL result for the first thirty documents.

Workflow 2: DPA review against GDPR Article 28 (with the full prompt)

Data processing agreements are, in GC AI’s words, “some of the most repeatable work an in-house privacy team does: the same GDPR Article 28 terms, the same negotiation points, agreement after agreement.” DataGrail’s Daniel Barber published a full GPT-5 prompt in October 2025: the model acts as senior privacy counsel, asks for the DPA and any areas of concern, and reviews it across ten dimensions.

# DataGrail dimension # DataGrail dimension
1 Roles and scope of processing 6 Data retention and deletion
2 Subprocessors 7 Audit rights and cooperation
3 International transfers 8 Indemnity and liability
4 Security and breach notification 9 Regulatory compliance (GDPR, CCPA/CPRA, HIPAA)
5 Data subject rights 10 Emerging risk trends

The prompt asks for a four-part report: Executive Summary, Findings by Clause or Topic, Compliance Matrix, Suggested Redlines and Questions. The version below keeps the dimensions but forces the Article 28(3) checklist into a gap table, because a matrix you can spot-check beats prose you read twice.

DPA review against our controller-side standard
You are reviewing a vendor's data processing agreement on behalf of the customer (controller). Compare <dpa>[paste]</dpa> against our standard positions <standard>[paste]</standard> across: the Art. 28(3) mandatory terms (subject matter, duration, nature and purpose, data types, documented instructions, confidentiality, Art. 32 security, sub-processor authorisation and flow-down, data-subject-rights assistance, breach notification, audit rights, deletion or return); international transfers (mechanism, SCC module, UK Addendum, transfer impact assessment); liability carve-outs that override the MSA; and the vendor's AI or model-training use of our data.

Output a table: Clause | Our position | Their text (quoted, or MISSING) | Gap | Proposed redline. Then the five points to negotiate first and the two we would accept as-is. Where the DPA is silent, write MISSING; never infer.

Workflow 3: AI-governance intake in one afternoon

GC AI’s intake design is deliberately unglamorous: “A form, a routing table, four named owners, and a log will do it, and a spreadsheet version you stand up this quarter beats a platform you buy next year” (GC AI). The seven questions:

  1. What is the tool or vendor, and is anyone using it already?
  2. What will it be used for, in one sentence you would say out loud?
  3. What data goes in: customer personal data, employee data, special-category data, confidential business data, or none?
  4. Where is it processed and stored, and which sub-processors touch it?
  5. Does the output influence a decision about a person (hiring, pay, credit, benefits, discipline)?
  6. Does it interact directly with customers or the public?
  7. Who owns it on the business side, and when is go-live?

The routing table maps answers to assessments: personal data to an Article 28 DPA and an Article 30 record; high-risk processing to an Article 35 DPIA; a non-adequate destination to a transfer impact assessment; customer-facing AI to an EU AI Act Article 50 review (in force since 2 August 2026); consequential automated decisions to the Colorado and California rules, both from 1 January 2027.

Route an AI-governance request
Here are the business team's answers to our seven-question AI intake form: <answers>[paste]</answers>. Using our routing table <routing>[paste]</routing>, list every assessment triggered (DPA, ROPA entry, DPIA, transfer impact assessment, AI vendor diligence, Article 50 review, ADMT notice) with the answer that triggered it, the named owner and our first-response target. Then draft three follow-up questions the answers left open: one for the requester, two for the vendor. Mark any legal threshold you relied on [VERIFY]. Do not approve or reject; that decision is mine.

Ali Hartley, Chief Legal Officer at SimplePractice, on the security team’s own prompt: “it used to take over like between three to six hours per vendor review. And now it’s down to less than 30 minutes” (GC AI, vendor page). A self-report, but consistent with every other account.

Workflow 4: outside-counsel invoice review

“Why do we have three law firms involved?” was one of the first questions Chuck Kable, GC at Innovative Renal Care, asked on arrival. Invoice review is a natural first automated workflow: the standard is written down and the input arrives monthly.

Invoice review against outside-counsel guidelines
Review the attached invoice against our outside-counsel guidelines <ocg>[paste]</ocg> and the agreed budget <budget>[paste]</budget>. Flag: block billing; vague descriptions such as "attention to file"; rate overages; timekeepers not on the approved list; duplicate entries; travel or admin time we do not pay for; entries that look like AI-assisted tasks billed at pre-AI durations; and any AI-related disbursement without prior approval.

Output a table: Line | Issue | OCG clause | Suggested adjustment. Then draft a courteous email to the billing partner listing the adjustments and asking two questions. Do not total the hours; I will do that in a spreadsheet.

Models miscount, so total in Excel. Upstream, your guidelines need an AI clause first: Poppy Legal’s sample provision bars billing for “hypothetical time saved” and suggests the notation “AI-assisted; attorney reviewed”. The outside-counsel guidelines guide walks through all eight provisions. Remember the 59%: the clause only works if you ask.

Copilot inside the department: three tiers, three gaps

“Can I use the thing already inside Word?” is the question GC AI reports hearing most from in-house lawyers. It depends which Copilot you mean.

Tier What it is Training on your data Client work?
Consumer Copilot (personal account) Free assistant on a personal Microsoft account On unless “Training on conversation activity” is switched off No
Copilot Chat (work account, no licence) Web-grounded chat in the M365 shell; the tier most often confused with the licensed product Depends on tenant settings; confirm enterprise data protection is on Low-risk drafting only
Licensed Microsoft 365 Copilot ($30/user/month) Copilot in Word, Outlook, Teams and Excel, grounded in your tenant “Prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs” Yes, with caveats

On the licensed tier Microsoft’s own page says responses “aren’t guaranteed to be 100% factual” (Microsoft Learn). Three gaps follow. No persistent legal context: it does not know your fallback positions unless you paste them. Citations need verification. And oversharing: “Permissions set years ago and never revisited now define what an AI tool will surface on demand”, as the ABA’s Law Technology Today put it, so the SharePoint review comes before the licence. EU departments should note that Anthropic models inside Copilot sit outside the EU Data Boundary. The Copilot guide has the admin checklist.

Microsoft’s own legal department proves the two-layer pattern: CELA, roughly 2,000 people, runs Copilot for the productivity layer and, since July 2026, Harvey for the legal layer. Note what CELA needed: a “CELA Copilot skilling series” run through an internal “CELA Academy” plus an “AI catalysts” community, which lifted Copilot usage by 50%. Licences did not drive adoption. Training did.

The Heppner test: counsel-directed use on a contractually confidential tool

The three grounds are the test. The tool is not a lawyer, so “Because Claude is not an attorney, that alone disposes of Heppner’s claim of privilege.” There was no reasonable expectation of confidentiality: Anthropic’s consumer policy says inputs and outputs are collected, used for training and may be disclosed to third parties. And Heppner used the tool of his own volition; the documents were “not prepared by or at the behest of counsel”, so work product failed too.

Then the opening: “Had counsel directed Heppner to use Claude, Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege.” Add Morgan v. V2X (D. Colo., 30 March 2026), where a protective order barred AI platforms unless the provider is contractually prohibited from storing or using inputs to train its model and from disclosing them to third parties, and the policy writes itself:

  • Client and privileged material goes only into tools with a written no-training clause and enterprise retention terms.
  • Counsel directs the use, visibly and in writing, rather than the business running its own analysis.
  • The direction is documented, so the agency argument exists if it is ever needed.

Anything a colleague pastes into a free chatbot about a live dispute should be treated as discoverable; put that in your Upjohn script. The privilege guide covers the diverging rulings.

Measuring: the ten metrics your CFO will accept

The ACC found 12% of departments track technology ROI. Corporate Counsel Business Journal’s line on the Axiom report belongs in every board paper: “A tool that cannot be measured is not a transformation strategy. It is a line item.”

The fix is boring: baseline before the pilot. Define time per review, hours per research task and turnaround first, pilot with three to five curious lawyers, and do not start with the most ambitious use case. Swiftwater’s tool-selection test is the best sentence on the subject: “Run five contracts you know well through any tool you are seriously evaluating.”

GC AI’s ten metrics: contract turnaround time; matter cycle time; outside-counsel spend as a share of total legal spend; the insourced-versus-outsourced mix by category; matter throughput per lawyer; first-response time on business requests; hours saved per lawyer per week (self-reported, so pair it with a harder number); repeat-issue rate; internal NPS; legal-tech ROI. Alexandra Sepulveda, AGC at Trust & Will (GC AI, vendor page): “you can literally see the time saved … and if you report to a CFO, that lands.”

The insourcing playbook and the 20-to-5-hours story

David Morris, formerly GC at Snyk, described insourcing better than any survey:

“We’re doing a lot of that work ourselves. We can get 75% of the way to a good answer. And then we’re going to the firm and saying, hey, listen, I have this project, I think I have a lot of the answers, but can you check this? That 20 hours comes to five hours.” — David Morris, formerly GC, Snyk (GC AI, vendor page)

The firm was not fired. It moved from drafting to checking, a cheaper and arguably higher-value instruction. GC AI’s in-housing loop formalises it: catalogue what went out last year; identify the routine categories; build playbooks for NDAs, DPAs, MSAs, employment documents and vendor onboarding; train the team and the AI on them; set an escalation rule keyed to complexity, deal size, novelty and regulatory exposure; measure quarterly. Start by pulling “last quarter’s outside counsel invoices” and identifying “the three categories with the highest volume and the lowest variance”.

That is why in-house teams tend to come to AI Lab for Lawyers as a group through Maven for Teams: four live sessions in which a department builds one standardised NDA or DPA workflow in the tools it already has, rather than five private prompts.

Where to go next: the practice-area hub covers the specialist work departments still send out, starting with employment law for the HR policies you are about to insource; the implementation playbook covers pilots, policies and the 90-day rollout; and the prompt library has the full in-house set.

Frequently asked questions

How are legal departments using generative AI?

Mostly for summarisation and contract work. The FTI/Relativity General Counsel Report for 2026 found 87% of GCs reporting GenAI use in their teams, with summarisation (83%) and contract clause identification (63%) the leading use cases. Depth is another matter: Axiom's July 2026 report on 528 in-house leaders found only 7% had scaled AI beyond pilots, and LegalOn's Inhouse Pulse found just 2% with full workflow support.

Can in-house counsel use Microsoft Copilot for legal work?

Yes, on a licensed work tenant with enterprise data protection, where Microsoft states that prompts, responses and Graph data are not used to train foundation models. It suits first-pass drafts, summarising a 40-message Outlook thread and meeting recaps. It has no persistent playbook memory, its citations need checking, and it surfaces whatever your SharePoint permissions allow, so run an oversharing review before switching it on.

How should a legal department measure AI ROI?

Pick baselines before the pilot, not after. The ACC found only 12% of departments track technology ROI, and Axiom found 83% cannot show whether last year's AI spend paid off. Usable metrics include contract turnaround time, matter cycle time, outside-counsel spend as a share of total legal spend, the insourced-versus-outsourced mix, first-response time on business requests and hours saved per lawyer per week. Measure the categories you insourced separately so the saving is visible.

Does using ChatGPT in-house waive privilege?

It can. In United States v. Heppner (S.D.N.Y., February 2026) Judge Rakoff held that a represented defendant's roughly 31 exchanges with consumer Claude were protected by neither privilege nor work product, because the tool is not a lawyer, the consumer terms gave no reasonable expectation of confidentiality, and counsel had not directed the use. The court left open protection for counsel-directed use, so keep client work on enterprise terms and make the direction explicit.

What should an in-house team automate first?

The highest-volume, lowest-variance category. GC AI's advice is to pull last quarter's outside-counsel invoices, sort by matter type and pick the three categories with the most volume and least variation, which usually means NDAs, DPAs and routine vendor MSAs. Build a playbook, save the prompt so anyone can run the same review, calibrate on the first thirty documents, and only then measure quarterly.

Written by

Dr. Niklas Schmidt, Partner at Wolf Theiss

Partner at Wolf Theiss Attorneys-at-Law, where he heads the firm-wide tax team; lawyer, author, TEDx speaker and technologist. He has spent well over 1,000 hours testing practical AI applications for legal work, runs a toolkit of roughly 80 AI tools in daily practice, founded the WT Crypto Academy (1,000+ participating lawyers) and has given around 450 talks over 20 years. He teaches the live course AI Lab for Lawyers on Maven.