Home/ Guides/ Answering Client AI Questions in Outside Counsel RFPs

Answering client AI questions in outside counsel RFPs.

Answer an outside counsel RFP's AI section with four documented items: the named tools your firm has approved, the governance that controls them, the data boundary those tools operate inside, and the human review step before anything reaches the client. Clients now score evidence, not intent. A firm running one governed workflow answers better than a firm claiming none.

Written for managing partners, operating partners, and firm administrators holding an RFP or panel renewal packet with a new AI section and roughly ten days to respond.

For20 to 150 attorneys
TriggerRFP or panel renewal
Fee band$45K to $180K fixed
Last updatedAugust 2026

The short answer.

The AI section is not a technology question. It is a supervision question wearing a technology costume, and the client's procurement team is scoring whether your firm can account for its own work product. That is why it asks for records rather than capability. Nobody doubts a model can summarize a deposition. What a client cannot verify from outside is whether the summary was checked by a lawyer, whether their matter content sat inside an environment their guidelines permit, and whether anyone could reconstruct either fact a year later.

The gap is documented. Thomson Reuters Institute's 2026 AI in Professional Services Report, published in February 2026, found that fewer than one third of corporate legal professionals knew whether their outside firms were using AI at all, and that roughly three quarters of respondents on both sides thought the firm should be the party opening that conversation. The RFP is where the silence ends, because procurement can force an answer in writing that a relationship partner has avoided over lunch for two years.

The pressure also runs in one direction, and it is not toward catching you out. The ACC and Everlaw survey of 657 in-house legal professionals across 30 countries, published in October 2025, found active generative AI use inside legal departments jumped to 52 percent from 23 percent a year earlier, while only about a quarter were satisfied with how their outside firms were adopting it to deliver more cost-effective services. The people writing the AI section use these tools daily.

So the answer that wins is narrow and dull: named tools, written governance, a stated data boundary, and a human review step, each with an artifact a stranger could audit. Everything else in the section is decoration.

What the questions are

The four clusters general counsel are being told to ask.

01Disclosure.Will you tell us when AI touches our matters, on which task categories, and through what mechanism. Who at your firm is accountable for that decision on our account.

Any firm willing to commit in writing can answer this today. It is also the cluster most firms fudge, because a general assurance is easier to write than a named partner.
Answer nowCommitment, not capability
02Data handling.Where does our matter content go when a tool processes it. Can vendor personnel reach it. Is it used to train, fine-tune, or evaluate a model.

A wrong answer here is a liability rather than a lost bid, and the true answer lives in contracts your firm signed, not in what a sales engineer said in a demo.
Answer with contractsRead your own vendor terms
03Accuracy and supervision.What verification applies before AI-assisted output enters a filing. How are hallucinations detected and reported. What is the supervisory structure under Model Rule 5.3.

The Stanford RegLab study published in May 2024 found the Lexis research tool produced incorrect information more than 17 percent of the time and the Westlaw AI-assisted research tool hallucinated more than 34 percent of the time across 202 preregistered queries. Purpose-built tools do not remove the review step.
Answer with a workflowA checkpoint, not a habit
04Governance.Do you hold a documented firm-wide AI policy current as of this year. Is training mandatory before an attorney touches a tool. Will you report annually on AI use across our matters.

Annual reporting is the quiet trap. A firm can promise it and discover at the first reporting date that no system in the building can produce the number.
Answer, then verifyDo not promise a report you cannot run
The response, block by block

The four-block answer template, and what goes in each.

Block one. The named tools, and the prohibited list.

List the specific products your firm has approved, the practice areas cleared to use each, and the work categories each is approved for. Name the tool, not the category. A response saying the firm uses generative AI for research and drafting gives a procurement analyst nothing to check. One naming the document management assistant, the research platform, and the two models cleared for internal use gives them something to map against their own vendor list.

Then name what is not approved: consumer accounts, personal subscriptions, browser plugins, anything that skipped intake. Publishing the prohibited list says the approved list has a boundary and that someone enforces it.

Block two. Governance, with a version number and a date.

Attach the policy with a version and an effective date, because an undated policy reads as one written for this response. State who owns it, how often it is reviewed, the intake process for a new tool, and what training an attorney completes before access. If you can report the training completion rate, report it, unflattering or not.

Point the policy at recognised frameworks rather than your own vocabulary. Procurement teams outside legal already score vendors against the NIST AI Risk Management Framework and ISO/IEC 42001, and vendor-side guidance published in 2026 describes 42001 moving from a differentiator to a baseline expectation. That mapping moves your answer into a review process that already has a rubric.

Block three. The data boundary, in one verifiable paragraph.

State where matter content sits while a tool processes it, whether it leaves your tenancy, whether any provider retains inputs, and whether any provider trains on them. Then state the contractual basis, because the client is not asking your belief about a vendor's practice. They are asking which agreement makes it enforceable. If your terms carry a zero-retention commitment, name the agreement. If they do not, that is a finding you need now.

Then add the client-specific layer. Guidelines from financial services, healthcare, and government clients increasingly require pre-approval before client data reaches any AI tool. The ACC publishes sample AI guidelines for outside counsel covering disclosure, data security, accuracy, and performance, and a department that adopted that template wants its own clauses answered.

Block four. Human review, named as a checkpoint.

Describe the point where a licensed attorney reviews AI-assisted output, who that attorney is by role, and what they attest to. Guidance published in June 2026 on drafting outside counsel guidelines for AI-assisted work puts it simply: any AI-generated content going to the client is reviewed and approved by a qualified lawyer before it is sent.

Handle citations separately, because that is the failure the client has already read about. In Johnson v. Dunn, decided in the Northern District of Alabama in July 2025, three attorneys at a firm of more than 350 lawyers were sanctioned over filings containing fabricated citations produced with ChatGPT, removed from the case, and referred to the state bar. Name the step that would have caught it: every authority checked against the primary source by a person, logged, before signature.

The uncomfortable part

Why a firm running no AI now has the worse answer.

The abstinence answer is now a scoring risk.

There is a version of this response partners still reach for: our firm does not use artificial intelligence in the delivery of legal services. In a 2026 evaluation it reads as either untrue or uncompetitive, and the evaluator decides which. Untrue, because your associates have phones. Uncompetitive, because more than half of the corporate legal professionals in Thomson Reuters Institute's 2026 report said their outside firms should be using AI on their matters, and 61 percent of in-house respondents in the ACC and Everlaw survey intend to push for change in how legal services are delivered and priced.

The stronger position, available to a firm that has done almost nothing, is one governed workflow described in full. One task category, one approved tool, one written data boundary, one review checkpoint, one log. Narrow and true beats broad and unverifiable in every procurement process ever run.

Policy is not proof, and clients have started saying so.

The most common defect is a category error. The client asks for an auditable record and the firm sends a policy. Intapp's July 2026 write-up names the gap: clients in financial services, healthcare, and government ask which tool was used, what data it processed, who reviewed the output, and whether client-specific restrictions applied, while most firms cannot produce matter-level logs tying AI activity to a matter.

That is the larger exposure. A firm that cannot see which client restrictions apply to a live file can breach a guideline without anyone noticing until the client audits. The billing question rides in on the same section, and ABA Formal Opinion 512 is the fixed point: fees must be reasonable and consistent with the time actually spent, so a tool that absorbs an hour does not entitle anyone to bill it.

The ten-day version, in order.

Days one and two. Read the client's outside counsel guidelines and any AI supplement in the packet. Answer their clauses, in their order, in their terms. Most firms write a generic section, which is visible instantly to whoever drafted the guidelines.

Days three and four. Establish what is actually true. Which tools are in the building, including the ones nobody approved. What the vendor contracts say about retention. Whether any log ties a tool to a matter. This usually produces one unwelcome discovery, which is the point of doing it first.

Days five through seven. Write or date the policy, name the accountable partner, publish the approved and prohibited tool lists, define the review checkpoint.

Days eight through ten. Draft the four blocks, attach only artifacts that exist, and mark anything not yet in place as a commitment with a date. A dated commitment is credible. A present-tense description of a capability you do not have ends a relationship rather than a bid.

What we would commission to make the answer true.

Everything above is written work a firm does itself inside the deadline. The part that is not writing is the matter-level record, and that is engineering against systems you already run: a logging layer between your attorneys and the approved tools, recording every AI-assisted action against a matter number, loading that client's restrictions from the guidelines rather than from memory, capturing the reviewing attorney and a timestamp, and producing the report on demand when a client exercises an audit right. In a mid-market firm that means integrating with iManage, NetDocuments, Clio, or Litify.

What we have actually shipped, because this category is full of claims nobody can check. Our nameable law reference is Jim Glaser Law, where we built five channel-specific voice agents covering PPC, Organic, TV, Meta, and LSA; they have handled 3,787 calls across 5,514 minutes, and Jimmy takes reference calls. Across clients our systems have handled more than 6,000 live calls, and our own AI receptionist answers at (617) 675-9067. Closest to this problem is an engagement we can describe but not name: a 47-attorney litigation firm whose matter, invoice, and IOLTA trust accounting platform we commissioned, carrying 13,296 matters, 4,396 clients, and 5,684 invoices, with a trust ledger that reconciles byte-identical.

What we have not shipped is a completed AI governance logging layer at a law firm, and we are not going to describe one that does not exist. What we would commission is the build above, at the bands published on the pricing page: $45,000 to $180,000 against a written scope, a prototype on your real data in 7 to 10 days before any fee is owed, four to seven weeks to production, inside your own cloud tenant under NDA, with source code owned by the firm at handoff. An audit log you rent is one whose terms can change.

Ready when you are

Book the 45-minute diagnosis.

Bring the RFP and the client's outside counsel guidelines. We read the AI section against what your firm can currently evidence, tell you which answers are already true, and name what would have to be built to make the rest true by the renewal. If nothing needs building, we say so.

Frequently Asked Questions

What are clients asking about AI in outside counsel RFPs?

Litera's July 2026 guidance to general counsel, also carried by Law.com, groups the questions into four clusters: disclosure, data handling, accuracy and supervision, and governance. Will you tell us when you use AI, where does our matter content go, who verifies output before a filing, and do you hold a current policy.

Do we have to disclose AI use to clients?

Increasingly the client requires it by contract rather than the rules requiring it in every case. ABA Formal Opinion 512 cautions that boilerplate consent in an engagement letter is not adequate where consent is needed, and guidelines from financial services, healthcare, and government clients now often require pre-approval before client data touches an AI tool.

What if our firm does not use AI at all?

That is the weakest answer available, not the safe one. Thomson Reuters Institute's 2026 report found more than half of corporate legal professionals believe their outside firms should be using AI on their matters, and the ACC and Everlaw survey of 657 in-house professionals found 64 percent expect to rely less on outside counsel.

Can we answer the AI section with our firm-wide AI policy?

A policy answers the governance cluster and nothing else. Intapp's July 2026 write-up names the failure: firms submit a firm-wide policy when the client asked for an auditable record of AI activity on their matters. The client is buying proof, meaning matter-level records. If you cannot produce them, give a date.

Who at the firm should own the AI section of an RFP response?

One named partner with authority over both technology and client relationships, supported by the firm administrator or director of practice technology who holds the records. The RFP asks who is accountable for AI disclosure decisions on the account, so it needs a name and a title, not a committee.

Does using AI mean we have to discount our rates?

Half of the in-house respondents in the ACC and Everlaw survey expect reduced outside counsel costs, so the pressure arrives whether or not you raise it. ABA Formal Opinion 512 is the fixed point: fees must be reasonable and consistent with the time actually spent. Price the categories that got faster differently.

What evidence should we attach to the AI section?

Vendor-side procurement guidance published in 2026 lists what buyers score: a documented AI risk management process, an inventory of the models and tools in use, data governance covering training and inference, human oversight controls, incident response, and audit trails. Attach what exists, with dates.

How long does it take to build the systems behind a credible answer?

A written policy, an approved tool list, and a named accountable partner fit inside the ten days most RFPs allow. Matter-level logging is engineering work against your document management and practice systems, and it does not. Our fixed-fee commissions run $45,000 to $180,000 with a prototype in 7 to 10 days.

Where to look next.

If governance is the piece to settle first, AI governance for a mid-market firm without the enterprise theater covers what a real policy contains at this size, and the security questions to ask before an AI build is the list to run against any vendor. The ownership argument is in why code handoff matters.

For the firm-level view, the law firm practice page lists the workflows most often commissioned, what we would commission first at a $30M law firm works through sequencing, and AI for mid-market law firms covers where these projects stall. On choosing a builder, how to choose an AI consultant for a law firm is the checklist and the ranked guide is the comparison.

If the build is against a specific system, the playbooks go deeper: iManage, NetDocuments, Clio, and Litify on Salesforce. If a product is on the shortlist: Harvey against a commissioned build, CoCounsel versus Harvey, Clio Duo versus a custom build. Also: build, buy, or commission, AI consulting cost for law firms, the commission process, and what we do not build.