# How to Audit AI Use Across Your Whole Law Firm in 2026

> A clear step-by-step way to audit every AI tool your firm actually uses and keep a tamper-evident record that your insurer and any court will accept later.

[Home](https://rankshieldlegal.com/) / [Blog](https://rankshieldlegal.com/blog/) / Firm Security Governance
# How to Audit AI Use Across Your Law Firm With a Tamper-Evident Record
You cannot govern AI use you cannot see, and most firms cannot list every AI tool their people already use. Staff sign up for research assistants, drafting tools, and browser extensions on their own, and that shadow AI is where privilege and supervision risk hides. This guide gives you a repeatable way to find every AI tool actually in use across the firm and to keep a tamper-evident record of it that an insurer or a court will accept.

By [Jamie Kloncz](https://rankshieldlegal.com/about/), Founder, RankShield ** 15 min read ** Published August 22, 2026

Knowing how to audit AI use across a law firm starts with accepting that the official list of approved tools is not the real list. In the American Bar Association's 2024 survey, 30.2 percent of respondents said their offices were using AI tools, up from 11 percent a year earlier, and that count reflects only sanctioned use; the unsanctioned use running alongside it rarely shows up in any inventory [[1]](#ref-1). Shadow AI, tools adopted by staff without firm approval, is creating hidden legal exposure precisely because no one is tracking what data goes into it [[3]](#ref-3).
The reason a record matters as much as the audit is that your duties are ongoing and provable. ABA Formal Opinion 512 ties the duty of supervision to AI, meaning partners answer for how the firm's people use these tools, and an insurer or a court may later ask what the firm knew and controlled [[2]](#ref-2). A one-time spreadsheet does not answer that. A tamper-evident record, one that cannot be quietly edited after the fact, does.
This guide is written from the perspective of a verification vendor, not a law firm, and it is informational rather than legal advice. It walks through finding the AI tools already in use, deciding what to log about each interaction, why a tamper-evident record matters to insurers and courts, how long to keep the records, and how to turn the one-time audit into a control that keeps working.

## Finding the AI tools already in use at your firm
Find shadow AI through four sources, not a survey alone. Pull single sign-on and OAuth grants to see which AI apps staff connected to firm accounts, review expense and card statements for AI subscriptions, inventory browser extensions on firm devices, and then run an anonymous survey to catch consumer tools used on personal accounts. The technical signals find what people will not self-report [[3]](#ref-3).
Start with the systems that already know. Your identity provider logs every application staff have signed into with a firm account, so an export of single sign-on and OAuth grants surfaces the AI tools connected to firm data. Expense reports and corporate card statements reveal paid subscriptions that never went through procurement. Managed-device inventories show which AI browser extensions are installed, which matter because an extension can read page contents including client documents.
Then close the gap those signals miss. Consumer tools used on personal accounts and personal devices leave no trace in firm systems, so an anonymous survey, framed as amnesty rather than enforcement, is the only way to see them. Ask what tools people use, for what tasks, and whether any client information has gone into them.
The output is a real inventory: tool, who uses it, on what account, for what work, and whether client data is involved. That inventory is the thing every later control depends on, and it is what our guide on [finding shadow AI accounts](https://rankshieldlegal.com/blog/shadow-ai-small-law-firm) goes into in more depth.

## What to log about each AI interaction
Log six fields per AI interaction: the tool used, the person, the matter or client, the data classification involved, the purpose, and whether a required verification step was completed. This is enough to answer the two questions that matter later: did privileged data reach a third-party tool, and did a lawyer verify any output that went into a filing. Anything less cannot answer either.
The log is not surveillance; it is the evidence layer for a duty you already hold. The goal is to be able to reconstruct, for any matter, what AI touched it and whether the firm's controls were followed.
Field Why it matters
Tool and version Identifies the vendor and its data terms
User Ties the action to a supervised person (Rule 5.1/5.3) [2]
Matter or client Lets you answer "what AI touched this matter"
Data classification Flags whether privileged or confidential data was involved
Purpose Distinguishes research from client-data processing
Verification completed Records whether a lawyer reviewed AI output before use

Source: ABA AI TechReport; ABA Formal Opinion 512; ISO/IEC 42001:2023 Download SVG

## Why a tamper-evident record matters to insurers and courts
A record only helps if no one can quietly change it after an incident. A tamper-evident log is append-only and cryptographically chained, so any later edit or deletion is detectable, which is what lets an insurer or a court trust that the record reflects what actually happened rather than what the firm wishes had happened. An editable spreadsheet proves intent to track; a tamper-evident log proves the facts.
The difference between a spreadsheet and a tamper-evident record is the difference between a claim and evidence. Anyone can produce a clean log after the fact. What an insurer assessing a claim, or a court examining a firm's conduct, wants to know is whether the record could have been edited to look better than reality.
A tamper-evident log solves that by making entries append-only and chaining them cryptographically, so removing or altering any entry breaks the chain and is detectable. RankShield Legal's platform records verification and privilege-isolation events to exactly this kind of tamper-evident transparency log, signed and sealed so the firm can show, not just assert, what happened and when. That capability is live for the citation and privilege primitives it produces.
For a firm, the payoff is at the worst moment. When a client alleges its data was mishandled or a court asks how a filing's citations were verified, an append-only record answers the question with evidence, which is a far stronger position than a supervisor's recollection.

## How long to keep AI usage records
Tie AI usage-record retention to your matter-file retention, not a shorter technical default. Because the AI log may be the evidence that privileged data was handled correctly or that citations were verified, it should survive as long as the matter it documents could be questioned, which usually means the firm's standard file-retention period plus any malpractice limitations tail. Set the schedule deliberately rather than accepting a vendor's default.
Retention is a decision, not a default. Many tools keep logs for a short operational window and then purge them, which is fine for uptime monitoring and useless for professional-responsibility evidence.
Match the AI usage record to the life of the matter it documents. If a malpractice claim or a fee dispute could arise years later, the record that shows the firm followed its AI controls needs to still exist then. Align the schedule with your existing file-retention policy and your jurisdiction's limitations periods, and confirm the retention rules where they vary, since records requirements differ by state and by matter type.

## Turning the audit into an ongoing control
A one-time audit is stale within a quarter, because staff adopt new tools continuously. Make it continuous: schedule the identity and expense pulls to repeat, require new AI tools to be logged before first use on client work, and review the inventory at a set cadence. The aim is a living inventory and record, not an annual snapshot that is wrong by the time it is filed.
The audit you run once tells you where you stood on one day. Given how fast staff adopt tools, that picture decays quickly, so the value is in making the audit repeat on its own.
Automate the parts that can repeat: schedule the single sign-on and expense reviews, and wire new-tool logging into the firm's intake so a tool used on client work is recorded before, not after. Then review the living inventory at a set cadence, treating governance as a managed process, the posture standards like ISO/IEC 42001 describe for AI management [[5]](#ref-5) and a [realistic firm AI policy](https://rankshieldlegal.com/blog/law-firm-ai-policy) operationalizes [[4]](#ref-4). A continuous inventory feeding a tamper-evident record is the operational goal; a firm-wide dashboard that aggregates it across every tool is the direction RankShield Legal is building toward, and that broader dashboard is on the roadmap rather than shipped today.

## Why the tool inventory is always incomplete the first time
A first-pass AI inventory is a snapshot of what the firm knows about, which is reliably a subset of what it uses. Shadow AI enters through personal accounts, browser extensions, and features quietly added to software the firm already licenses. The third route is the one that defeats a procurement-based inventory entirely, because nothing was ever procured.
Firms usually build the first inventory from procurement records and a survey. Both methods share a blind spot: they capture tools the firm decided to adopt, and shadow AI is defined by the absence of that decision.
Personal accounts are the obvious route and the one most policies address. A lawyer using a consumer AI account on a personal device to summarise a document leaves no trace in firm systems, which is precisely why prohibition alone does not solve it. If the approved tool is harder to reach than the unapproved one, use migrates to the easier tool regardless of policy.
Browser extensions are the underestimated route. An extension with permission to read page content can see whatever the lawyer sees, including matter data in a document management system, and it installs without any procurement event.
The third route is the one that breaks inventories built from purchase records: AI features added to software the firm already licenses. Nothing was bought, no approval was sought, and a product the firm has used for years acquires a summarisation or drafting capability in an update. The inventory says the firm uses that product, which is true and now materially incomplete.
The practical consequence is to treat the inventory as a recurring process rather than a project with an end. Re-run discovery on a cadence, add a check for newly enabled AI features in existing products, and treat every finding as information about the gap between what people need and what the firm has approved, rather than purely as a compliance failure. A tool that keeps reappearing after being blocked is telling you about an unmet need.

## What the log proves, and what it does not
A usage log establishes that an interaction occurred, when, and by whom. It does not establish that the output was correct or that anyone verified it. Those are different records, and conflating them produces a firm that can show extensive AI activity and nothing about whether it was checked.
The value of a log is bounded and worth stating precisely, because a firm that misunderstands what it has will rely on it for a question it cannot answer.
What a usage log does establish is real and useful. That a specific person used a specific tool at a specific time. What category of material was involved. Whether use was inside approved boundaries. In aggregate, which tools are actually used, which is what makes the next inventory better than the last.
What it does not establish is whether the output was accurate, whether a human reviewed it before it was relied upon, or who that human was. A log showing that a drafting tool produced a document tells you nothing about whether the citations in that document were checked.
This distinction has a sharp edge in litigation. A log that records extensive AI use, with no corresponding verification record, is not neutral evidence; it documents the volume of unverified reliance. The firm has proved the exposure and none of the diligence.
So build both records and keep them linked. The usage log answers what happened. A verification record answers whether it was checked, by whom, and when, which is the question a court or an insurer actually asks. Our guide on [proving verification to a court](https://rankshieldlegal.com/blog/prove-you-verified-ai-citations-to-court) covers the second record; this article covers the first. Neither substitutes for the other.
2 records a usage log proves what happened; a verification record proves it was checked, by whom, and when

Test yourself
## Test yourself on auditing AI use
Five questions on finding what the firm actually uses, and what the record proves.

- 1 Why is a first-pass AI inventory reliably incomplete? Surveys are usually ignored It captures tools the firm decided to adopt, and shadow AI is defined by the absence of that decision Vendors withhold usage data **Answer:** It captures tools the firm decided to adopt, and shadow AI is defined by the absence of that decision Procurement records and surveys share a blind spot. They document adoption events, and the tools of greatest concern arrived without one.
- 2 Which shadow AI route most completely defeats a procurement-based inventory? Personal consumer accounts AI features added to software the firm already licenses Trial subscriptions **Answer:** AI features added to software the firm already licenses Nothing was bought and no approval was sought. A product the firm has used for years acquires a drafting or summarisation capability in an update, and the inventory entry remains technically true while becoming materially incomplete.
- 3 What does a usage log establish? That the output was accurate That a specific person used a specific tool at a specific time That a human verified the result **Answer:** That a specific person used a specific tool at a specific time The log answers what happened and when. Accuracy and verification are different records entirely, and a log showing a drafting tool produced a document says nothing about whether its citations were checked.
- 4 Why can a usage log alone be harmful in litigation? It is inadmissible Without a verification record it documents the volume of unverified reliance It waives privilege automatically **Answer:** Without a verification record it documents the volume of unverified reliance Extensive logged AI use with no corresponding verification record is not neutral. The firm has proved its exposure and none of its diligence, which is why both records need to exist and stay linked.
- 5 What does a tool that keeps reappearing after being blocked indicate? Deliberate policy violation only An unmet need the approved toolset is not covering A technical failure in the block **Answer:** An unmet need the approved toolset is not covering If the approved tool is harder to reach than the unapproved one, use migrates to the easier tool regardless of policy. Recurring findings are information about the gap between what people need and what the firm has approved.
Honest self-check. There is no sign-up, and nothing is stored.

Questions answered
## Straight answers to the common questions
The questions readers ask about this topic, answered directly. **No forms, no sales pitch.**

JAMIE KLONCZ · SEO AGENCY NAPLES ************** ONLINE
Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

← PREV NEXT → [REQUEST ACCESS →](https://rankshieldlegal.com/contact/)

- **How do I audit AI use across my law firm?** Combine technical discovery with an honest survey. Export single sign-on and OAuth grants from your identity provider to see which AI applications staff connected to firm accounts, review expense reports and corporate card statements for AI subscriptions that bypassed procurement, and inventory browser extensions on managed devices, since extensions can read client documents on a page. Then run an anonymous, amnesty-framed survey to surface consumer tools used on personal accounts that leave no trace in firm systems. The result is a real inventory: each tool, who uses it, on what account, for what work, and whether client data is involved. That inventory is the foundation for logging, retention, and every control that follows, and it should be refreshed on a schedule rather than done once.
- **What is shadow AI in a law firm?** Shadow AI is any AI tool that staff adopt without the firm's approval or oversight, such as a personal ChatGPT account, an unapproved drafting assistant, or an AI browser extension installed without IT's knowledge. It creates hidden legal exposure because the firm cannot supervise what it does not know about, and privileged or confidential client data may be flowing into tools whose data terms no one has reviewed. Under ABA Formal Opinion 512, the duty of supervision extends to how the firm's people use AI, so unsanctioned use is a professional-responsibility gap, not just an IT problem. The first step in closing it is an audit that finds the tools already in use, including the ones no one will volunteer in a meeting.
- **Why does a law firm need a tamper-evident record of AI use?** Because the value of the record depends on whether it can be trusted, and an ordinary spreadsheet can be edited after an incident to look better than reality. A tamper-evident record is append-only and cryptographically chained, so any later alteration or deletion is detectable. That is what lets an insurer assessing a claim, or a court examining the firm's conduct, rely on the record as evidence of what actually happened rather than a reconstruction. When a client alleges its data was mishandled, or a court asks how a filing's citations were verified, an append-only log answers with facts. It is the difference between showing your controls worked and asking someone to take your word for it.
- **What should a law firm log about each AI interaction?** Log six fields: the tool and version used, the person who used it, the matter or client involved, the classification of the data, the purpose of the use, and whether any required verification step was completed. Those fields let you answer the two questions that actually matter after an incident: did privileged or confidential data reach a third-party AI tool, and did a lawyer verify any AI-generated output before it went into a filing. Logging less than this leaves you unable to reconstruct what AI touched a given matter or whether the firm's own controls were followed. The log is not surveillance of your lawyers; it is the evidence layer for the supervision and confidentiality duties the firm already carries.
- **How long should a law firm keep AI usage records?** Tie the retention to your matter-file retention rather than a vendor's short operational default. The AI usage record may be the evidence that privileged data was handled correctly or that citations were verified, so it should survive as long as the underlying matter could be questioned. In practice that means aligning the schedule with your standard file-retention policy and your jurisdiction's malpractice limitations period, so the record still exists if a claim or fee dispute arises years later. Many AI tools purge their own logs quickly, which is adequate for operational monitoring but not for professional-responsibility evidence, so set the retention deliberately and confirm the requirements in your jurisdiction, since records rules vary by state and matter type.
- **How do I find AI tools nobody told the firm about?** Assume three routes and check each, because procurement records and surveys only capture tools the firm decided to adopt. Personal accounts are the most discussed: a lawyer using a consumer AI account on a personal device leaves no trace in firm systems, which is why prohibition alone does not work, and if the approved tool is harder to reach than the unapproved one, use migrates to the easier option regardless of policy. Browser extensions are underestimated, because an extension with permission to read page content can see whatever the lawyer sees, including matter data in a document management system, and it installs with no procurement event. The third route defeats purchase-record inventories entirely: AI features added to software the firm already licenses, where nothing was bought and no approval was sought. Re-run discovery on a cadence and include a check for newly enabled AI features in existing products.
- **Is a usage log enough to satisfy a court or an insurer?** No, and relying on it for that purpose is a common mistake. A usage log establishes that a specific person used a specific tool at a specific time, what category of material was involved, and whether the use fell inside approved boundaries. It does not establish that the output was accurate, that anyone reviewed it before it was relied on, or who that person was. The distinction has a sharp edge: a log recording extensive AI use with no corresponding verification record is not neutral evidence, because it documents the volume of unverified reliance while proving none of the diligence. Build both records and keep them linked. The usage log answers what happened; a verification record answers whether it was checked, by whom, and when, which is the question actually asked.

## References

- American Bar Association. 2024 Artificial Intelligence TechReport (Legal Technology Survey Report). 2025. [https://www.americanbar.org/groups/law_practice/resources/tech-report/2024/2024-artificial-intelligence-techreport/](https://www.americanbar.org/groups/law_practice/resources/tech-report/2024/2024-artificial-intelligence-techreport/)
- American Bar Association. Formal Opinion 512: Generative Artificial Intelligence Tools. July 2024. [https://www.americanbar.org/news/abanews/aba-news-archives/2024/07/aba-issues-first-ethics-guidance-ai-tools/](https://www.americanbar.org/news/abanews/aba-news-archives/2024/07/aba-issues-first-ethics-guidance-ai-tools/)
- Falcon Rappaport & Berkman LLP. Why Shadow AI Use by Employees is Creating Hidden Legal Exposure. 2026. [https://frblaw.com/why-shadow-ai-use-by-employees-is-creating-hidden-legal-exposure/](https://frblaw.com/why-shadow-ai-use-by-employees-is-creating-hidden-legal-exposure/)
- North Carolina Bar Association. Beyond the Ban: Why Your Law Firm Needs a Realistic AI Policy in 2026. January 2026. [https://www.ncbar.org/2026/01/13/beyond-the-ban-why-your-law-firm-needs-a-realistic-ai-policy-in-2026/](https://www.ncbar.org/2026/01/13/beyond-the-ban-why-your-law-firm-needs-a-realistic-ai-policy-in-2026/)
- International Organization for Standardization. ISO/IEC 42001:2023 Artificial Intelligence Management System. December 2023. [https://www.iso.org/standard/81230.html](https://www.iso.org/standard/81230.html)

Written by
## [Jamie Kloncz](https://rankshieldlegal.com/about/)
Founder, RankShield
Jamie Kloncz is the founder of RankShield, the verifiable AI and quantum security platform behind RankShield Legal. An engineer by training, he built RankShield after his own devices and business were attacked, including an AI voice-cloning scam that targeted his family, on one conviction: unverifiable security is the real danger, so every consequential action should leave a receipt anyone can independently check.
[More about Jamie →](https://rankshieldlegal.com/about/)

Try it · Free
## Check a citation against live case-law
Paste a citation from an AI-drafted brief and see whether the case actually exists, resolved against live case-law. Free, no sign-up. Then request early access to certify a full filing.
[Try the citation checker](https://rankshieldlegal.com/ai-legal-citation-checker/)

Keep reading
## Related guides
[Firm Security Shadow AI in a Small Firm: Finding the AI Accounts Your Staff Already Opened Read guide →](https://rankshieldlegal.com/blog/shadow-ai-small-law-firm/)[Legal AI Building a Defensible Law Firm AI Policy Read guide →](https://rankshieldlegal.com/blog/law-firm-ai-policy/)[Legal AI When Your AI Stops Drafting and Starts Acting: The Agentic AI Governance Gap in Law Firms Read guide →](https://rankshieldlegal.com/blog/agentic-ai-governance-gap-law-firms/)
