Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

AI maturity assessment5 min read

Law firm AI assessment: a 5-level maturity framework

A practical five-level method to assess AI uses, data, security, skills and oversight in a law firm.

A law firm AI assessment must answer three questions: which uses produce verifiable value, which risks must be controlled, and what next step can the firm actually carry out? Maturity is therefore measured neither by the number of accounts opened nor by the sophistication of the chosen model. It is assessed across five dimensions: use cases, data, risk control, skills and oversight.

The framework below rates the firm from 1 to 5, from individual experimentation to measured oversight of augmented processes. It can be used for self-assessment, then explored further in a law firm AI maturity assessment. Its purpose is not to award a flattering score, but to reveal gaps between actual practice and the required level of control.

What an AI assessment should examine

Start by inventorying actual practices, including those never formally authorized. For each tool, record users, account type, enabled features, document categories processed, connectors, purpose and how results are validated. Distinguish simple rephrasing assistance from processing involving a matter, legal research, document analysis or output intended for communication.

This distinction matters: applicable conditions depend, among other things, on the offering purchased. For example, the Anthropic commercial terms consulted state that customers retain rights to inputs and own outputs within applicable-law limits, that commercial-service customer content cannot be used to train models, and that generated factual assertions must be independently verified. These provisions do not remove the need to examine the exact offering, DPA, retention, subprocessors, transfers, connectors and account configuration.

The assessment must then compare uses against data protection principles. The CNIL factsheet on AI and GDPR organizes the analysis around concrete points: purpose, lawful basis, minimization, retention period, information, exercise of rights, system evaluation and prevention of discrimination. For a firm, these topics must become observable evidence: a written purpose, authorized data categories, a retention rule and a review procedure.

The 5-level AI maturity framework

LevelObservable situationMain riskPriority for the next 90 days
1 — Spontaneous useA few people use consumer tools without an inventory or shared instructions. Usage depends on individual initiative.Uncontrolled information transmission, lack of verification and personal accounts that are difficult to administer.Map usage, suspend the most sensitive processing and publish simple interim rules.
2 — Controlled experimentationThe firm has selected a small number of tools and use cases. A pilot group works with fictitious, public, anonymized or strictly minimized data.Confusing a promising pilot with a deployment-ready solution.Formalize tests, validation criteria, data categories and responsibilities.
3 — Controlled deploymentAccounts are managed, access is individual, rules are documented and human review is built into the process.Applying a single policy to use cases with very different impacts.Create a brief for each use case and train each user group according to its role.
4 — Integrated processAI operates within defined workflows, with sources, instruction templates, checks, useful logging and an incident procedure.Automating a poorly designed or insufficiently supervised process.Measure quality, rework time, errors and exceptions before expanding scope.
5 — Adaptive oversightThe use-case portfolio is governed, reassessed and connected to firm objectives. Tools can be replaced without losing rules or operational knowledge.Technical dependency, relaxed controls or indicators focused solely on speed.Organize periodic reviews, test exit/portability and decide investments on evidence.

A firm may be at level 4 for summarizing internal documents and level 1 for unrestricted use of a conversational tool. Assign a level to each dimension and use case rather than a single overall score. The target level also depends on context: a reversible task involving public content does not need the same safeguards as analysis of confidential documents or an automated action.

The PREUVE method for conducting the assessment

To avoid a purely self-reported audit, Initial proposes a six-step sequence, remembered through the acronym PREUVE:

  1. P — Practices: inventory official tools and informal uses through interviews, questionnaires, configurations and redacted examples.
  2. R — Risks: classify data, confidentiality, access rights, potential errors, dependencies and the effects of a poor output.
  3. E — Economics of the process: break down the current work, its trigger, rework, controls and deliverable. Theoretical time savings are insufficient if verification increases.
  4. U — Use-case priorities: select two or three cases according to frequency, value, feasibility and reversibility. High-volume litigation automation, for example, must be broken into controllable operations rather than conceived as wholesale delegation.
  5. V — Verification: define authorized sources, human review, tests, rejection thresholds and what to do when an output is incomplete or uncertain.
  6. E — Execution: assign an owner, deadline, indicator and evidence of completion to every action in the roadmap.

The “skills” dimension must not be reduced to an awareness session. Article 4 of the European AI Regulation, applicable since 2 February 2025, requires providers and deployers, to the greatest extent possible, to take measures ensuring a sufficient level of AI literacy, taking account of knowledge, experience, training and context of use. As of 22 July 2026, the general application date for many other provisions remains 2 August 2026, with specific schedules under Article 113. The assessment must therefore document who uses what, in which context and with what preparation.

How to rate the firm without producing a misleading average

Assess five areas separately: uses, data, security, skills and governance. For each, assign a level only if three elements are present: a written rule, observed practice and retained evidence. If the policy claims level 4 but accounts remain personal, the operational score stays at the level of observed practice.

  • Uses: is there an inventory and an owner for every case?
  • Data: are authorized categories, minimization and retention defined?
  • Security: are access, connectors, logs, incidents and departures managed?
  • Skills: can users formulate instructions, verify, cite sources and identify limitations?
  • Governance: can a decision-making body authorize, suspend or modify a use?

The Conseil national des barreaux resource on generative AI emphasizes controlled integration respecting professional ethics, confidentiality and responsibility. It also provides the profession with a practical guide and assessment grid highlighting sovereignty, confidentiality, security and possible data reuse. This supports an approach in which software selection follows classification of the use and requirements.

Technical comparison remains useful, but only within this framework. The LLM comparison for legal professionals can clarify model capabilities and limitations, while selection of AI tools for lawyers must be tested against contractual conditions and settings actually available. For a complex document process, the analysis of AI and legal due diligence also illustrates the importance of traceability and output review.

Turning the assessment into a roadmap

The findings should cover three horizons. At thirty days: inventory, secure accounts, set temporary prohibitions and appoint an owner. At sixty days: train the pilot group, test two use cases on a controlled corpus and document checks. At ninety days: decide on deployment, abandonment or further testing based on observed errors, rework time, quality and incidents.

The final deliverable ideally includes a process map, tool register, detailed scores, value-risk matrix, priority use-case briefs and an action plan with owners and deadlines. A good result does not necessarily mean reaching level 5 everywhere. It means achieving a level of control that is proportionate, demonstrable and compatible with how the firm actually works.

Further reading

Related resources

Frequently asked questions

FAQ

How long does a law firm AI assessment take?

Duration depends on the number of teams, tools and processes examined. At a minimum, the scope must allow verification of reported practices, configurations, data categories, controls and responsibilities, followed by a prioritized roadmap.

Should AI be prohibited until the assessment is complete?

A blanket prohibition is not always the most practical response. The firm can immediately set interim rules, exclude the most sensitive data or uses and organize a controlled pilot environment during the assessment.

What maturity level should a firm aim for?

The target depends on the risk and value of each use case. Not every process needs to reach level 5. The priority is applied rules, verifiable controls and proportionate oversight.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles