The most useful thing a language model can do with your draft is hate it. Left to itself it will not: chat models are tuned on human approval, and in April 2025 OpenAI rolled back a GPT-4o update within days because it had become “overly flattering or agreeable”. Ask “is this clause good?” and you get a compliment. Ask “you are supplier’s counsel and your client’s business depends on breaking this clause” and you get every word you should have tightened. That switch, from pleasing you to defeating you, is adversarial prompting for legal work, and it is the closest thing to a second pair of eyes at 11pm that a solo or a small deal team can get.
Why a single “draft and critique” prompt degrades both
Justia’s prompting guide for lawyers states the rule and the reason: “If you ask it to draft, critique, and rewrite simultaneously, the model’s performance degrades. It will often rush the initial draft just to get to the critique.” Its cure is three personas in three turns: drafter, adversary, refiner. The principle behind all of prompt engineering for lawyers is the same: one task per prompt.
| Works | Fails |
|---|---|
| Draft in turn one, attack in turn two, rewrite in turn three | “Draft the clause, critique it and rewrite it, all in one answer” |
| A named adversary with a stake (“supplier’s counsel, aggressive”) | “Improve this” or “is this good?” |
| A second model attacking the first model’s reasoning | A second model asked whether the first model’s cases are real |
The three-turn workflow: draft, adversarial review, rewrite
Justia’s second step is the one to copy word for word: “Analyze the draft you just created from the perspective of a [Strict Judge / Aggressive Opposing Counsel] looking for vulnerabilities. Identify any phrases that are ambiguous, weak, or unfavorable to [Your Client]. List these vulnerabilities as bullet points.” The third step rewrites, remedying each vulnerability.
Now act as [opposing counsel / supplier's counsel / a strict judge] with a strong incentive to defeat the draft you just wrote for [my client]. List, as bullet points: every phrase that is ambiguous, weak, overstated or unfavourable to [my client]; every place the draft claims more than the materials support; and the argument you would lead with. Do not rewrite yet. Do not soften the critique.Persona chains: cautious counsel, confident expert, synthesis
Nico Kuhlmann of Hogan Lovells, writing in LTO, calls his version “temperature simulation”, a chain of personas with different risk appetites: “Zuerst analysiert eine vorsichtige Juristin, die gerne zu viel erklärt, das Thema im Detail. Danach gibt eine selbstbewusste Expertin eine prägnante Einschätzung. Abschließend werden beide Perspektiven zusammengeführt und hervorgehoben, wo noch Unsicherheit besteht.”
The third step is the point: a cautious analysis and a confident one disagree exactly where the law is unsettled or the facts are thin, and the synthesis makes that visible instead of averaging it away.
Analyse [the enforceability of the restrictive covenant in clause 12 under [jurisdiction] law] in three passes.
Pass 1: as a cautious lawyer who prefers to explain too much, set out every issue in detail.
Pass 2: as a confident specialist, give the answer and the one or two points that decide it.
Pass 3: reconcile the two. Where they differ, say why, label the point UNCERTAIN, and name the fact or authority that would resolve it. Tag every authority [VERIFY].The verification loop: name three weaknesses in your own analysis
Kuhlmann’s second technique: “Analysiere diesen Vertrag und nenne die drei wichtigsten Risiken. Identifiziere anschließend drei mögliche Schwächen deiner eigenen Analyse und überprüfe, ob sie berechtigt sind.” Analyse, find three weaknesses in your own analysis, check whether they hold.
Thomson Reuters’ CoCounsel team showed the English equivalent, “Double-check your answer and fix any problems you find”, correcting a wrong GPT-4 answer. That line is now model-dependent: Anthropic’s guidance for Claude Opus 5 says the model “verifies its own work without being told to” and that re-check instructions “cause over-verification”. On those models keep the adversarial turn and drop the “double-check” line; prompting reasoning models has the table.
Analyse the attached agreement for [my client, the licensee] and name the three most important risks, each with the clause quoted.
Then identify three possible weaknesses in your own analysis: an issue you may have overrated, one you may have missed, and an assumption that, if wrong, changes your ranking. For each, say whether the weakness is justified and what I should check.Two limits. The loop audits reasoning, not sources; the Swiss bar warns that one cannot simply ask an AI system whether its output is true. And r/legaltech user folderit_dms adds a design rule for every loop here: “do not start with two models debating each other. Start with a checklist the model must fill: issue, jurisdiction, source relied on, uncertainty, recommended human review point. That gives you something you can audit later instead of just a nice sounding answer.”
The opposing-counsel and strict-judge prompts
The adversarial role is most valuable before you commit to a position. Katten’s Weston Love describes the partner-level prompt in an M&A workflow as “synthesize the diligence findings into a concise risk summary and pressure test our key negotiating positions for the weaknesses that opposing counsel is most likely to exploit” (National Law Review).
Here is my position and the authorities I rely on: <position>[paste]</position>. Act as opposing counsel with a strong incentive to defeat it. Produce: the three best counter-arguments in order of danger; for each, the fact or authority from my own materials that most helps you; the question a sceptical judge would ask that I would least want to answer; and any assumption that, if false, collapses my position. Then say which of my points you would concede because fighting them is hopeless. Treat any authority you name as [VERIFY].The last instruction is a calibration check: an adversary that concedes nothing is performing; one that concedes the right points is reasoning. For oral argument, Justia’s strict-judge prompt asks “one challenging question at a time” until you say “Time Out”; the moot-court guide builds the full bench.
Two-model adversarial research (Claude vs ChatGPT)
An r/legaltech user posting as Faktafabriken described the loop on 1 September 2026: ask Claude, ask ChatGPT, then “Feed Claudes answer to chat gtp sol telling it to review it with scepticism and make an independent assessment (important!)”, then feed that back to Claude with the same instruction and a request to “combine the most accurate insights to a final answer”. The same thread has a moot-court set-up from another user: “spin up two agents, one for each side then make arguments to a third judge agent who makes a ruling between the two”, with an audit trail and a citator run on every cited case.
The loop works for reasoning because different tools fail differently: Stanford found Lexis+ AI’s errors were mostly retrieval and applicability failures (47% naive retrieval, 38% inapplicable authority), while 61% of Westlaw AI-Assisted Research’s were reasoning errors made with the correct documents in hand. It does not work for existence. A second model asked whether a case is real is the Mata v. Avianca error with an extra step, and the lawyer in Noland v. Land of the Free ran his briefs through several AI tools and still filed 21 fabricated quotations. The line that keeps the loop honest: “Do not add citations of your own, and do not tell me whether the cited cases exist; I will check that in a database.”
Deliberate over-instruction: forcing the deep dive
Kuhlmann’s third technique explains why adversarial prompts sometimes come back thin. Models are optimised for speed, so they “antworten das erste, was ihnen ‘in den Sinn’ kommt”, the first plausible answer. His fix is deliberate over-instruction: demand exhaustiveness and say that completeness matters more than brevity. In the adversarial turn that means “list every phrase”, not “list the weaknesses”. Harvey’s benchmark team found the same bias in research agents: “Their bias is to search efficiently, not completely.”
Harvey’s authority check for brief sections
The narrowest adversarial prompt is Harvey’s, aimed at a single brief section: “Review this draft brief section. Identify unsupported propositions, missing authority, overstatements, and arguments that need stronger factual support.” It attacks the join between assertion and support, where briefs fail and a reviewer’s eye tires.
Review this draft brief section: <draft>[paste]</draft>. For every sentence asserting a legal proposition, mark it SUPPORTED (name the authority in the draft), OVERSTATED (say how far the authority actually goes), UNSUPPORTED, or FACTUAL CLAIM NEEDING RECORD CITE. Then describe, without naming, the counter-authority a diligent opponent would cite. Do not verify whether any cited case exists; I will.Limits: sycophancy still leaks through
The adversarial role counteracts the model’s drift toward agreement; it does not remove it. Damien Charlotin, who maintains the database of court decisions involving hallucinated material, describes the pull: “The harder your legal argument is to make, the more the model will tend to hallucinate, because they will try to please you.”
So read the critique as sceptically as the draft: a soft attack means the model is still pleasing you, so say “You conceded too easily; try again as if your client’s business depended on winning”. Name the stakes; a concrete incentive leaves less room for flattery. And prefer critiques that must fill a structure, because a structure is harder to flatter through. The guide to AI sycophancy covers the mechanism in full.
None of this needs a legal platform, only the discipline to run three turns instead of one. We run these loops on participants’ own drafts in AI Lab for Lawyers, because the difference between a model that flatters and one that attacks is a single instruction most lawyers have never typed.
Where to go next: the contract drafting guide shows what the adversarial turn catches in a clause; the prompt collection and prompt library have the full set of critique prompts; the other prompting guides cover the techniques this page assumes.
Frequently asked questions
How do I get AI to critique my own brief?
In a separate turn from the drafting, with a hostile role. Justia's wording: 'Analyze the draft you just created from the perspective of a [Strict Judge / Aggressive Opposing Counsel] looking for vulnerabilities. Identify any phrases that are ambiguous, weak, or unfavorable to [Your Client]. List these vulnerabilities as bullet points.' Then rewrite in a third turn and diff the two drafts, because a rewrite can quietly drop an argument to fix a weakness.
What is a verification loop prompt?
An instruction that makes the model audit its own answer as a second step. Nico Kuhlmann of Hogan Lovells gives the German form: analyse the contract and name the three biggest risks, then identify three possible weaknesses in your own analysis and check whether they are justified. It catches overstatement and missed issues. It does not catch invented citations, because the model checks its reasoning against itself, not against a database.
Can two AI models check each other's work?
For reasoning and gaps, yes; for citations, no. One r/legaltech user feeds Claude's answer to ChatGPT 'telling it to review it with scepticism and make an independent assessment', then back again. Different tools fail differently, so the second model finds overstatements the first missed. But asking any model whether a case exists is the Mata v. Avianca error; Victoria's Supreme Court says one AI tool cannot confirm another's content.
Should I ask the AI to draft and critique in one prompt?
No. Justia's guidance is blunt: 'If you ask it to draft, critique, and rewrite simultaneously, the model's performance degrades. It will often rush the initial draft just to get to the critique.' Give each turn one job: draft, then attack from a named adversarial perspective, then rewrite. The exception is Claude Opus 5, which Anthropic says 'verifies its own work without being told to'; even there, the adversarial turn adds a perspective the model would not take unprompted.
Does adversarial prompting stop hallucinations?
It reduces overstatement and exposes weak arguments; it does not stop fabricated authority. The critic is the same model under the same incentives, and it has no database. Use the loop for logic, structure and vulnerability, then run every citation through Westlaw, Lexis or the official reports yourself. A lawyer in Noland v. Land of the Free ran his briefs through several AI tools to check them and still filed 21 fabricated quotations.