RankShield Legal
Citation checker Request access
Governance

How to Audit AI Use Across Your Law Firm With a Tamper-Evident Record

You cannot govern AI use you cannot see, and most firms cannot list every AI tool their people already use. Staff sign up for research assistants, drafting tools, and browser extensions on their own, and that shadow AI is where privilege and supervision risk hides. This guide gives you a repeatable way to find every AI tool actually in use across the firm and to keep a tamper-evident record of it that an insurer or a court will accept.

By Jamie Kloncz, Founder, RankShield 15 min read Published

Knowing how to audit AI use across a law firm starts with accepting that the official list of approved tools is not the real list. In the American Bar Association's 2024 survey, 30.2 percent of respondents said their offices were using AI tools, up from 11 percent a year earlier, and that count reflects only sanctioned use; the unsanctioned use running alongside it rarely shows up in any inventory [1]. Shadow AI, tools adopted by staff without firm approval, is creating hidden legal exposure precisely because no one is tracking what data goes into it [3].

The reason a record matters as much as the audit is that your duties are ongoing and provable. ABA Formal Opinion 512 ties the duty of supervision to AI, meaning partners answer for how the firm's people use these tools, and an insurer or a court may later ask what the firm knew and controlled [2]. A one-time spreadsheet does not answer that. A tamper-evident record, one that cannot be quietly edited after the fact, does.

This guide is written from the perspective of a verification vendor, not a law firm, and it is informational rather than legal advice. It walks through finding the AI tools already in use, deciding what to log about each interaction, why a tamper-evident record matters to insurers and courts, how long to keep the records, and how to turn the one-time audit into a control that keeps working.

Finding the AI tools already in use at your firm

Find shadow AI through four sources, not a survey alone. Pull single sign-on and OAuth grants to see which AI apps staff connected to firm accounts, review expense and card statements for AI subscriptions, inventory browser extensions on firm devices, and then run an anonymous survey to catch consumer tools used on personal accounts. The technical signals find what people will not self-report [3].

Start with the systems that already know. Your identity provider logs every application staff have signed into with a firm account, so an export of single sign-on and OAuth grants surfaces the AI tools connected to firm data. Expense reports and corporate card statements reveal paid subscriptions that never went through procurement. Managed-device inventories show which AI browser extensions are installed, which matter because an extension can read page contents including client documents.

Then close the gap those signals miss. Consumer tools used on personal accounts and personal devices leave no trace in firm systems, so an anonymous survey, framed as amnesty rather than enforcement, is the only way to see them. Ask what tools people use, for what tasks, and whether any client information has gone into them.

The output is a real inventory: tool, who uses it, on what account, for what work, and whether client data is involved. That inventory is the thing every later control depends on, and it is what our guide on finding shadow AI accounts goes into in more depth.

What to log about each AI interaction

Log six fields per AI interaction: the tool used, the person, the matter or client, the data classification involved, the purpose, and whether a required verification step was completed. This is enough to answer the two questions that matter later: did privileged data reach a third-party tool, and did a lawyer verify any output that went into a filing. Anything less cannot answer either.

The log is not surveillance; it is the evidence layer for a duty you already hold. The goal is to be able to reconstruct, for any matter, what AI touched it and whether the firm's controls were followed.

FieldWhy it matters
Tool and versionIdentifies the vendor and its data terms
UserTies the action to a supervised person (Rule 5.1/5.3) [2]
Matter or clientLets you answer "what AI touched this matter"
Data classificationFlags whether privileged or confidential data was involved
PurposeDistinguishes research from client-data processing
Verification completedRecords whether a lawyer reviewed AI output before use
RANKSHIELD LEGAL Auditing firm AI use: what the inventory misses A first-pass inventory captures what was adopted. Shadow AI is defined by the absence of adoption. 3 routes Shadow AI arrives via personal accounts, browser extensions, and features added to licensed software Extensions An extension that reads page content sees matter data, with no procurement event No purchase AI features added to existing products defeat any inventory built from purchase records Recurring Treat discovery as a cadence, not a project with an end 2 records A usage log proves what happened; only a verification record proves it was checked Unmet need A tool that reappears after being blocked is telling you what people actually need RankShield Legal rankshieldlegal.com
Source: ABA AI TechReport; ABA Formal Opinion 512; ISO/IEC 42001:2023

Why a tamper-evident record matters to insurers and courts

A record only helps if no one can quietly change it after an incident. A tamper-evident log is append-only and cryptographically chained, so any later edit or deletion is detectable, which is what lets an insurer or a court trust that the record reflects what actually happened rather than what the firm wishes had happened. An editable spreadsheet proves intent to track; a tamper-evident log proves the facts.

The difference between a spreadsheet and a tamper-evident record is the difference between a claim and evidence. Anyone can produce a clean log after the fact. What an insurer assessing a claim, or a court examining a firm's conduct, wants to know is whether the record could have been edited to look better than reality.

A tamper-evident log solves that by making entries append-only and chaining them cryptographically, so removing or altering any entry breaks the chain and is detectable. RankShield Legal's platform records verification and privilege-isolation events to exactly this kind of tamper-evident transparency log, signed and sealed so the firm can show, not just assert, what happened and when. That capability is live for the citation and privilege primitives it produces.

For a firm, the payoff is at the worst moment. When a client alleges its data was mishandled or a court asks how a filing's citations were verified, an append-only record answers the question with evidence, which is a far stronger position than a supervisor's recollection.

How long to keep AI usage records

Tie AI usage-record retention to your matter-file retention, not a shorter technical default. Because the AI log may be the evidence that privileged data was handled correctly or that citations were verified, it should survive as long as the matter it documents could be questioned, which usually means the firm's standard file-retention period plus any malpractice limitations tail. Set the schedule deliberately rather than accepting a vendor's default.

Retention is a decision, not a default. Many tools keep logs for a short operational window and then purge them, which is fine for uptime monitoring and useless for professional-responsibility evidence.

Match the AI usage record to the life of the matter it documents. If a malpractice claim or a fee dispute could arise years later, the record that shows the firm followed its AI controls needs to still exist then. Align the schedule with your existing file-retention policy and your jurisdiction's limitations periods, and confirm the retention rules where they vary, since records requirements differ by state and by matter type.

Turning the audit into an ongoing control

A one-time audit is stale within a quarter, because staff adopt new tools continuously. Make it continuous: schedule the identity and expense pulls to repeat, require new AI tools to be logged before first use on client work, and review the inventory at a set cadence. The aim is a living inventory and record, not an annual snapshot that is wrong by the time it is filed.

The audit you run once tells you where you stood on one day. Given how fast staff adopt tools, that picture decays quickly, so the value is in making the audit repeat on its own.

Automate the parts that can repeat: schedule the single sign-on and expense reviews, and wire new-tool logging into the firm's intake so a tool used on client work is recorded before, not after. Then review the living inventory at a set cadence, treating governance as a managed process, the posture standards like ISO/IEC 42001 describe for AI management [5] and a realistic firm AI policy operationalizes [4]. A continuous inventory feeding a tamper-evident record is the operational goal; a firm-wide dashboard that aggregates it across every tool is the direction RankShield Legal is building toward, and that broader dashboard is on the roadmap rather than shipped today.

Why the tool inventory is always incomplete the first time

A first-pass AI inventory is a snapshot of what the firm knows about, which is reliably a subset of what it uses. Shadow AI enters through personal accounts, browser extensions, and features quietly added to software the firm already licenses. The third route is the one that defeats a procurement-based inventory entirely, because nothing was ever procured.

Firms usually build the first inventory from procurement records and a survey. Both methods share a blind spot: they capture tools the firm decided to adopt, and shadow AI is defined by the absence of that decision.

Personal accounts are the obvious route and the one most policies address. A lawyer using a consumer AI account on a personal device to summarise a document leaves no trace in firm systems, which is precisely why prohibition alone does not solve it. If the approved tool is harder to reach than the unapproved one, use migrates to the easier tool regardless of policy.

Browser extensions are the underestimated route. An extension with permission to read page content can see whatever the lawyer sees, including matter data in a document management system, and it installs without any procurement event.

The third route is the one that breaks inventories built from purchase records: AI features added to software the firm already licenses. Nothing was bought, no approval was sought, and a product the firm has used for years acquires a summarisation or drafting capability in an update. The inventory says the firm uses that product, which is true and now materially incomplete.

The practical consequence is to treat the inventory as a recurring process rather than a project with an end. Re-run discovery on a cadence, add a check for newly enabled AI features in existing products, and treat every finding as information about the gap between what people need and what the firm has approved, rather than purely as a compliance failure. A tool that keeps reappearing after being blocked is telling you about an unmet need.

What the log proves, and what it does not

A usage log establishes that an interaction occurred, when, and by whom. It does not establish that the output was correct or that anyone verified it. Those are different records, and conflating them produces a firm that can show extensive AI activity and nothing about whether it was checked.

The value of a log is bounded and worth stating precisely, because a firm that misunderstands what it has will rely on it for a question it cannot answer.

What a usage log does establish is real and useful. That a specific person used a specific tool at a specific time. What category of material was involved. Whether use was inside approved boundaries. In aggregate, which tools are actually used, which is what makes the next inventory better than the last.

What it does not establish is whether the output was accurate, whether a human reviewed it before it was relied upon, or who that human was. A log showing that a drafting tool produced a document tells you nothing about whether the citations in that document were checked.

This distinction has a sharp edge in litigation. A log that records extensive AI use, with no corresponding verification record, is not neutral evidence; it documents the volume of unverified reliance. The firm has proved the exposure and none of the diligence.

So build both records and keep them linked. The usage log answers what happened. A verification record answers whether it was checked, by whom, and when, which is the question a court or an insurer actually asks. Our guide on proving verification to a court covers the second record; this article covers the first. Neither substitutes for the other.

2 records a usage log proves what happened; a verification record proves it was checked, by whom, and when
Test yourself

Test yourself on auditing AI use

Five questions on finding what the firm actually uses, and what the record proves.

  1. 1Why is a first-pass AI inventory reliably incomplete?

    Answer: It captures tools the firm decided to adopt, and shadow AI is defined by the absence of that decision

    Procurement records and surveys share a blind spot. They document adoption events, and the tools of greatest concern arrived without one.

  2. 2Which shadow AI route most completely defeats a procurement-based inventory?

    Answer: AI features added to software the firm already licenses

    Nothing was bought and no approval was sought. A product the firm has used for years acquires a drafting or summarisation capability in an update, and the inventory entry remains technically true while becoming materially incomplete.

  3. 3What does a usage log establish?

    Answer: That a specific person used a specific tool at a specific time

    The log answers what happened and when. Accuracy and verification are different records entirely, and a log showing a drafting tool produced a document says nothing about whether its citations were checked.

  4. 4Why can a usage log alone be harmful in litigation?

    Answer: Without a verification record it documents the volume of unverified reliance

    Extensive logged AI use with no corresponding verification record is not neutral. The firm has proved its exposure and none of its diligence, which is why both records need to exist and stay linked.

  5. 5What does a tool that keeps reappearing after being blocked indicate?

    Answer: An unmet need the approved toolset is not covering

    If the approved tool is harder to reach than the unapproved one, use migrates to the easier tool regardless of policy. Recurring findings are information about the gap between what people need and what the firm has approved.

Honest self-check. There is no sign-up, and nothing is stored.

Questions answered

Straight answers to the common questions

The questions readers ask about this topic, answered directly. No forms, no sales pitch.

JAMIE KLONCZ · SEO AGENCY NAPLES ONLINE

Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.

REQUEST ACCESS →

References

  1. American Bar Association. 2024 Artificial Intelligence TechReport (Legal Technology Survey Report). 2025. https://www.americanbar.org/groups/law_practice/resources/tech-report/2024/2024-artificial-intelligence-techreport/
  2. American Bar Association. Formal Opinion 512: Generative Artificial Intelligence Tools. July 2024. https://www.americanbar.org/news/abanews/aba-news-archives/2024/07/aba-issues-first-ethics-guidance-ai-tools/
  3. Falcon Rappaport & Berkman LLP. Why Shadow AI Use by Employees is Creating Hidden Legal Exposure. 2026. https://frblaw.com/why-shadow-ai-use-by-employees-is-creating-hidden-legal-exposure/
  4. North Carolina Bar Association. Beyond the Ban: Why Your Law Firm Needs a Realistic AI Policy in 2026. January 2026. https://www.ncbar.org/2026/01/13/beyond-the-ban-why-your-law-firm-needs-a-realistic-ai-policy-in-2026/
  5. International Organization for Standardization. ISO/IEC 42001:2023 Artificial Intelligence Management System. December 2023. https://www.iso.org/standard/81230.html
Written by

Jamie Kloncz

Founder, RankShield

Jamie Kloncz is the founder of RankShield, the verifiable AI and quantum security platform behind RankShield Legal. An engineer by training, he built RankShield after his own devices and business were attacked, including an AI voice-cloning scam that targeted his family, on one conviction: unverifiable security is the real danger, so every consequential action should leave a receipt anyone can independently check.

More about Jamie →
Try it · Free

Check a citation against live case-law

Paste a citation from an AI-drafted brief and see whether the case actually exists, resolved against live case-law. Free, no sign-up. Then request early access to certify a full filing.

Try the citation checker