AI Controls Become Practice Rules, Firmwide Adoption Accelerates, and Taiwan Advances AI Governance
The gist
Legal teams are moving from AI experimentation to enforceable workflow, verification, and governance duties that reshape daily judgment, supervision, and accountability.
This week’s developments
California and the IRS Turn AI Controls into Practice Rules
California’s SB 574 would make AI use a controlled workflow requirement: lawyers and arbitrators could not place confidential, personally identifying, or other nonpublic client data into public generative AI tools, must take reasonable steps to verify outputs and remove hallucinated citations or harmful content, and remain responsible for AI-assisted work as if they produced it themselves. The enforcement signal is already real. In State v. Coleman, 2026-Ohio-965, an Ohio attorney who filed an AI-drafted brief with fabricated facts and citations was sanctioned $2,000 and referred to disciplinary counsel, showing courts are treating failed AI review as a pleading and conduct problem, not a tech glitch.
That pressure is now spreading beyond general ethics guidance. ABA Formal Opinion 512 already tied generative AI to competence, confidentiality, candor, and supervision duties, and the IRS has now extended that logic to tax advisors under Circular 230, allowing drafting support but not blind reliance on AI for authority or calculations. The market response is a shift toward auditable platforms that preserve traceability.
For lawyers, the career edge is moving to those who can document review, protect client data, and build defensible sign-off processes. AI is no longer just a productivity boost; it is becoming a supervised production system.
How should we update AI review workflows and accountability now?
If you're an individual contributor
- AI speed won't save you; your review discipline will.
- Learn to verify AI output, strip bad citations, and protect client data—your value is now in defensible judgment.
Sources
- Accelerating PM Workflows and Elevating Customer Value with AI | ProductTank London — Mind the Product, July 23, 2026
Shows how to validate AI summaries against original sources and use AI safely in product workflows.
- How I Turned Codex Into My AI Life Coach in 13 Minutes (5-Step Tutorial) — Peter Yang, June 17, 2026
A 5-step workflow for checking context, tailoring advice, and forcing concrete next steps before trusting AI output.
- How to Use AI to Get Smarter (Not Just Work Faster) — Artificial Corner, July 5, 2026
Prompts and habits for making AI test assumptions, expose blind spots, and improve decision quality.
If you manage a team
Sources
- Start With AI Literacy: Why Most Leaders Are Missing the Point — Gartner ThinkCast, July 23, 2026
Frameworks for teaching leaders to spot AI errors, improve prompting, and embed AI learning into daily workflows.
- TBM 432: Bundling & Unbundling Capabilities (and AI) — The Beautiful Mess, July 26, 2026
Framework for redesigning tasks, preserving critical skills, and coaching teams through AI-driven workflow change.
If you lead the organization
Sources
- AI Governance Isn't Optional Anymore: Enabler or Blocker? | HackerNoon — HackerNoon, July 25, 2026
Framework for inventorying AI, assigning ownership, integrating GRC, and monitoring risk without slowing deployment.
- Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226 — Security Weekly - A CRA Resource, July 13, 2026
Shows how leaders split AI oversight across teams, use cases, and platforms to manage risk at scale.
- AI governance in practice: moving from policy to live controls (via Passle) — Bristows, July 22, 2026
Shows how to inventory AI use, assign ownership, and embed risk-based controls into procurement and deployment.
Firmwide Adoption and Custom Builds Signal the Next AI Arms Race
Barnes & Thornburg reported nearly 90% attorney usage, 1,000+ users, and more than 150,000 prompts across Harvey, CoCounsel, and ChatBT in 30 days, while BDO Abogados said its eight-month Legora rollout reached 90%+ adoption and Hanson Bridgett adopted Anthropic’s Claude firmwide for 200+ attorneys and staff. Those disclosures show firms are standardizing on platforms that combine matter context, research, and authority checks in one interface, not just tools that draft faster.
The adoption is also moving into specific workflows: Kirkland & Ellis is planning a $500 million tailored AI build, NKF moved to a firmwide Legora partnership after internal evaluation, and BKL is using Harvey for cross-border M&A, international disputes, and multi-jurisdictional regulatory work with Korean-language support. The competitive edge is shifting from isolated drafting assistance to control of the full matter environment plus verified legal authority inside the same workspace.
For practitioners, this is the next step beyond the workflow and supervision layers already taking hold: less time stitching together research, drafts, and matter data across systems, and more responsibility for supervising matter-aware AI, checking jurisdiction-specific authority, and becoming fluent in the platform your firm standardizes on.
How should firms govern AI adoption across all seniority levels?
If you're an individual contributor
- Your edge is shifting from drafting fast to supervising AI well.
- Learn your firm’s platform deeply and get sharp at checking authority, jurisdiction, and matter context—those errors will define your value.
Sources
- 126. Where Legal Quality Assurance Fails: Lessons from a Real Appellate Case (AI ROI Part 2) — The Agile Attorney Podcast, June 30, 2026
Shows how to embed verification steps and audit trails so AI-generated legal work meets consistent standards.
- Legal Research for Everyone: Inside the CourtListener - Claude Partnership — LawNext, July 1, 2026
Shows how citation-matching connectors reduce hallucinations and require manual verification of court authority.
If you manage a team
- Your team’s leverage now comes from AI fluency, not just output speed.
- Coach lawyers on review discipline and workflow judgment, and reallocate time toward exception handling, not repetitive drafting.
Sources
- AI Is Shifting the Bottleneck: Actionstep’s Triona Buckley on Building Smarter Mid-Market Law Firms — The Geek In Review, July 20, 2026
How AI can standardize associate training, reinforce firm knowledge, and reduce reliance on inconsistent partner-led coaching.
- The Legal AI Advantage Won’t Come From the Model Alone — Artificial Lawyer, July 6, 2026
Shows how to embed AI in workflows, approved language, and institutional knowledge for consistent legal output.
If you lead the organization
- The AI race is now about firmwide control, not isolated tools.
- Invest in one governed platform, custom matter workflows, and talent who can run AI-enabled legal work across jurisdictions.
Sources
- OpenAI's five-step framework for managing agentic AI spend — MarketScale, July 14, 2026
Five-step guide to measure, govern, and scale enterprise AI investments across teams, models, and workflows.
- AI Governance Platform Requirements Checklist 2026 | Govern365.ai — AI Governance Platform Requirements Checklist 2026, June 4, 2026
Checklist for selecting AI governance platforms with model registries, risk controls, compliance mapping, and audit-ready workflows.
- Cloud Security Meets AI: What CISOs Need to Govern Before They Scale - Brent Neal - CSP #226 — Security Weekly - A CRA Resource, July 13, 2026
Framework for dividing AI oversight across legal, privacy, security, finance, and platform owners as adoption scales.
Taiwan Sets the Next Layer of AI Governance
Taiwan’s Artificial Intelligence Basic Act, promulgated on 14 January 2026, is now pushing the next layer of AI governance into place. The Act makes the National Science and Technology Council the central AI policy authority, creates a National AI Strategy/Governance Committee under the Executive Yuan chaired by the premier, and requires agencies to implement AI risk assessments, internal control and usage guidelines, labor-right safeguards, and privacy-by-design/data governance measures by July 2026. Sector regulators then have until 14 January 2028 to issue AI risk-management rules and fill gaps through delegated rules.
The enforcement burden is still being built. The Basic Act is principles-based, with no clear penalty regime or private right of action, so the real compliance load will come through secondary rules, audits, and sector-specific implementation. That makes Taiwan closer to Japan and Singapore than the EU AI Act’s harmonized, risk-tiered model, even as China tightens controls and U.S. state laws keep fragmenting the baseline.
For Legal teams, this is the next step after inventories and incident workflows: keeping live obligation maps current across regimes that diverge in timing, structure, and enforcement. The value now sits in regulatory intelligence, local ownership, and fast evidence retrieval when secondary rules move.
How should we adapt our AI governance operating model now?
If you're an individual contributor
- Taiwan’s AI rules will reward lawyers who can track fast-moving gaps.
- Keep your obligation map live and learn to pull evidence fast; that’s how you stay useful as secondary rules land.
Sources
- AI governance checklist: 10 practical actions every legal team should take now — Lexology, July 24, 2026
A tactical checklist for implementing AI governance, risk awareness, and compliance workflows now.
- AI Governance Isn't Optional Anymore: Enabler or Blocker? | HackerNoon — HackerNoon, July 25, 2026
Shows how to inventory AI systems, map ownership, assess risks, and monitor controls within existing GRC processes.
- AI governance in practice: moving from policy to live controls (via Passle) — Bristows, July 22, 2026
Shows how to inventory AI use cases, tailor controls by risk, and embed monitoring into procurement and deployment.
If you manage a team
- Your team’s edge shifts from drafting to monitoring fragmented AI rules.
- Coach for regulatory intel, local ownership, and rapid issue-spotting; inventories alone won’t carry the workload.
Sources
- How regulators are using old rules to catch AI firms out — FinTech Global, June 4, 2026
Shows how to embed AI approvals, training, and accountability into existing compliance and business workflows.
If you lead the organization
- Your operating model must absorb AI governance before sector rules hit.
- Invest in a central obligation-tracking spine and local execution now, or you’ll pay later in audit friction and missed gaps.
Sources
- AI Governance Platform Requirements Checklist 2026 | Govern365.ai — AI Governance Platform Requirements Checklist 2026, June 4, 2026
Ten requirements for choosing platforms that map AI risks, controls, suppliers, and audit-ready compliance workflows.
- Boards want answers about AI at energy firms | Grant Thornton — Grant Thornton, June 19, 2026
Shows how to centralize AI use-case oversight, decision rights, and risk-tiered monitoring for board accountability.
- From Governance to Results: Building Enterprise AI in 90 Days — FedTech Magazine, July 24, 2026
A 90-day framework for central intake, policy alignment, monitoring, and accountable AI deployment.