Guide
AI contract review: what to automate and where a lawyer still signs
AI contract review uses a language model to do the first pass a lawyer or contract manager would otherwise do by hand: find and extract clauses, compare them with the company’s playbook, flag departures and missing terms, summarise, and draft a first redline. That pass is fast, and it can be confidently wrong, so nothing it produces should reach a counterparty or bind the company until a person has checked it. The American Bar Association’s Formal Opinion 512, issued on 29 July 2024, says generative AI cannot replace the judgement a lawyer needs to advise a client, and that the lawyer is fully responsible for the work whatever level of review they choose. The decisions that matter are which steps the tool owns, how it is tested on your own contracts before anyone relies on it, what it is allowed to see, and where a lawyer signs.
AI contract review. The use of AI models to find, extract, compare and summarise contract terms and to draft first-pass markups, with a lawyer reviewing and approving anything that is relied on or sent.
Checked . The bar guidance and court rulings on this page were read in the documents the American Bar Association, the State Bar of California and the courts issued. The rulings are early trial-court decisions and the guidance is being revised as the tools change, so check what applies in the states where your lawyers are licensed. This page is not legal advice.
What AI does reliably in contract review, and what it cannot own
A model can only flag a clause as off-standard if somebody has written the standard down. So the first piece of work in an AI contract review project is legal work: turning the playbook your lawyers carry in their heads into positions, fallbacks and deal-breakers for each clause. Once that exists, the table below is how I would split the rest. The numbers in brackets point to the sources at the foot of the page.
| Dimension | What the AI does | Check before relying on it | Who signs |
|---|---|---|---|
| Finding and extracting clauses | Pulls out term and renewal dates, notice periods, liability caps, governing law, assignment and similar clauses across a whole contract set | Every extraction quotes the clause and says where it sits, and code confirms the quote is really in the document | Nobody signs on an extraction alone; a contract manager samples them |
| Comparing against your playbook | Flags each clause that departs from your standard position or an accepted fallback, and names the playbook rule it breaks | Tested first on signed contracts where your lawyers already know the answer | A lawyer, for every flagged departure |
| Spotting what is missing | Lists the clauses your playbook expects that the contract does not contain | Checked against the whole document, including schedules, exhibits and terms incorporated by reference | A lawyer |
| Summaries for the business | Writes a plain summary of the key terms for the person who owns the contract | Each point links back to the clause it came from | The contract owner reads it; a lawyer approves it where it will inform a decision |
| First-draft redlines | Drafts changes and negotiation language from the playbook’s fallback positions | A lawyer reads every change before it goes to the other side | A lawyer, always |
| Searching a whole portfolio | Finds, for example, every contract with a change-of-control or exclusivity clause, for diligence or after a change in the law | A lawyer checks a sample by hand against the tool’s answers before the rest is trusted [1] | A lawyer, on the conclusions drawn |
| Advice: sign, push back or walk away | Nothing it should own. It can lay out the options and the clauses behind them | Not a step to automate | A lawyer |
The split follows the ABA’s own line. A lawyer may use AI output as a springboard, an analysis to base advice on or a draft to work from, but may not leave it to the tool alone to advise a client, negotiate a client’s claims or do other work that needs a lawyer’s personal judgement [1]. The opinion is just as clear about why the middle column exists. Generative tools can produce unreliable or incomplete results, can combine accurate information in ways that turn out false, and some are prone to plausible answers with no basis in fact [1].
Where a lawyer signs: tier by contract
Whether a contract needs a lawyer at all is a decision for your general counsel. What AI changes is how quickly you can tell which tier a contract is in. I would set three tiers and let the tool sort contracts into them. Sorting is as far as it goes: it never approves.
| Dimension | What the AI does | What a lawyer does | Who approves |
|---|---|---|---|
| Your own template, signed unchanged | Nothing that matters. Whether the text is unchanged is a comparison against the template, done by ordinary code | Nothing further, once legal has approved the template and who may sign it | The business, under its existing signing authority |
| Counterparty paper, or edits inside approved fallbacks | Extracts the terms, compares them with the playbook and flags every departure | Reviews each flag and the full clause behind it | A lawyer, for anything flagged |
| Non-standard, high value, or regulated data in scope | Summarises, extracts and lists what looks unusual, to speed up the reading | Reads the whole agreement | A lawyer, on the whole document |
Two rules hold in every tier. Nothing the tool writes goes to a counterparty until a named person has approved it, and the approval is recorded. The State Bar of California’s 2026 guidance says a lawyer must not deploy an agentic system in a way that lets it send client information out, through automated communications, filings or data transfers, without appropriate safeguards and human review. It adds that the more autonomy a system has, the more oversight the lawyer owes [2].
If contract managers or procurement staff use the tool, they do so under the legal team’s rules. ABA 512 says managerial lawyers must set clear policies on the permissible use of generative AI, that supervisory lawyers must make reasonable efforts to see that lawyers and nonlawyers comply, and that supervision includes training people on the tools they use [1].
Test it on contracts you have already signed
ABA 512 describes the test itself, using contracts as the example. A lawyer relying on a tool to review and summarise many long contracts would not necessarily have to check every document by hand, if they had first tested the tool on a smaller set, compared its summaries with their own review and found them accurate [1]. That is an evaluation, and it is the step I would never let a project skip.
Build the test set from contracts you have already negotiated and signed, where your lawyers know what each clause says and what they accepted. Score the tool clause type by clause type, because a tool that handles governing law well can still be poor on limitation of liability. Count three things separately: clauses it missed, clauses it got wrong, and false alarms. Misses are the expensive error, because nobody goes looking for a problem the tool said was not there.
Set the pass mark before the pilot starts, and run the same test whenever the model, the prompts or the playbook change. The California guidance makes the same point: AI systems change through updates and model changes, so competence includes reassessing a system’s capabilities and risks from time to time, and when it is put to new legal tasks [2].
A vendor’s accuracy figure was measured on somebody else’s contracts. ABA 512 cites a June 2024 Stanford study that found the generative AI systems of established legal research providers hallucinate between 17% and 33% of the time [1]. That study measured research tools, not contract review, but it shows why a published figure cannot stand in for your own test. Public datasets help with the plumbing. The Atticus Project’s CUAD holds more than 13,000 labels across 510 commercial contracts, marked up under the supervision of experienced lawyers for 41 clause types [3].
Confidentiality: what the tool may see, and who else can
Before anyone pastes a contract into a tool, somebody needs to know where the text goes. ABA 512 says that before lawyers put information relating to a client’s representation into a generative AI tool, they must evaluate the risk that it will be disclosed to or accessed by others, both outside the firm and inside it [1]. For self-learning tools, which can surface one client’s information in answers on another matter, it says the client’s informed consent is required first, and that general, boiler-plate provisions in an engagement letter are not enough [1].
Contracts carry a second layer: the other side’s information, often under a confidentiality clause of its own. Read that clause before the contract goes into any tool a third party runs.
The opinion’s baseline is to read the tool’s terms of use, privacy policy and related contractual terms, or to consult someone who has [1]. Drawing on earlier opinions about cloud computing and outsourcing, it lists what to establish about any tool that stores client information [1].
- Confidentiality that holds
- The tool is configured to preserve confidentiality and security, that obligation is enforceable, and you will be told of a breach or of legal process seeking your information.
- Reliability and security
- How reliable it is, its security measures and policies, and any limits on the provider’s liability.
- Retention and ownership
- Whether it keeps what you submit, before and after the service ends, and whether the provider claims rights in it.
- Exposure
- The provider’s servers can fail, and can be an attractive target for attackers.
Walls inside the company matter as much as the vendor’s terms. A shared index across every contract lets a question on one matter pull text from another, which is the cross-matter disclosure both ABA 512 and the California guidance warn about [1, 2]. Give the tool each person’s existing document permissions, matter by matter, rather than one account that can read everything.
Privilege: two early court rulings that point different ways
The privilege question has started to reach the courts, and the first answers do not agree.
In United States v. Heppner, the Southern District of New York held in February 2026 that a criminal defendant’s written exchanges with a publicly available AI platform were protected by neither attorney-client privilege nor the work product doctrine [4]. He had used the platform on his own, not at his lawyers’ direction. The court found that the platform was not an attorney, and that the exchanges were not confidential, because its privacy policy let the provider use inputs for training and disclose data to third parties, including governmental regulatory authorities. Sharing the outputs with his lawyers later did not make them privileged. The court left one door open: had counsel directed the use, the tool might arguably have acted like an agent of the lawyer [4].
On 10 February 2026, the day the Heppner ruling was first given from the bench, a magistrate judge in the Eastern District of Michigan reached a different result in Warner v. Gilbarco, a civil case in which the plaintiff was representing herself. The court refused to order production of her AI material and said that, even if it were discoverable, it would be protected as work product. It added that generative AI programs are tools, not persons, and that waiving work product protection takes disclosure to an adversary or in a way likely to reach one [5].
The facts differ: who used the tool, whether a lawyer was involved, and a criminal prosecution against a civil claim. Both are early trial-court rulings, and neither settles the law. What I take from them for a legal team is practical. Run legal AI work in tools the company controls, under terms that rule out training on your inputs and limit disclosure, at the direction of counsel, and keep personal accounts on public AI tools away from legal work. Whether that protects privilege in your jurisdiction is a question for your own lawyers.
This section describes the guidance and rulings as published on 29 September 2026. It is not legal advice.
The US bar guidance this page relies on
The guidance is written for lawyers, but it sets the standard any contract review system will be judged against, so it is worth reading even when the buyer is legal operations or procurement.
- ABA Formal Opinion 512 (29 July 2024)
- The ABA ethics committee’s opinion on generative AI tools. It covers competence, confidentiality, communication with clients, candour to courts, supervision and fees, and it is based on the ABA Model Rules of Professional Conduct as amended through August 2023. It expects the committee and state and local bar ethics committees to update their guidance as the tools develop [1].
- State Bar of California, Practical Guidance (2026)
- Replaces the 2023 version and, at the California Supreme Court’s request, covers agentic AI. It says a lawyer’s professional judgement cannot be delegated to AI, that reasonable efforts on confidentiality take more than a vendor’s marketing assurances, and that subscriptions to general AI tools are typically overhead to absorb in the fee rather than a separate charge [2].
- Other bars and courts
- The State Bar of California’s resource page lists AI opinions and guidance from more than a dozen other bars and courts, among them Florida, New York City, North Carolina, Oregon and Pennsylvania [6]. Read the guidance for the states where your lawyers are licensed.
What to ask a contract review vendor, or whoever builds it
Whether you buy a product or have one built, the questions are the same, and several come straight from what the bar guidance asks lawyers to establish.
- Where does the text go?
- Which provider processes it, in which region, how long it is kept, and whether anything you send is used to train a model.
- Who can see what?
- Whether the tool uses each person’s existing document permissions, matter by matter, or one account that can read everything.
- Can every finding be traced?
- Whether each flag quotes the clause and its location, and names the playbook rule it applied.
- Will you test on our contracts before we sign?
- A supplier confident in its tool will run it on a sample of your signed contracts and show you the misses as well as the hits.
- What happens when the model changes?
- How you are told, and whether the evaluation runs again before the new version reaches your team.
- What is recorded?
- Who reviewed each finding, what they decided and when, kept for a period you set.
- What do we keep if we leave?
- Your playbook, your test set and your review history, in a format you can take elsewhere.
- What happens on a breach or a subpoena?
- Whether the contract obliges the provider to tell you, which is one of the things ABA 512 expects a lawyer to establish [1].
Where 1AYM fits
1AYM builds the system around your lawyers, and the legal judgement stays with them. For a contracts team that means three pieces of work: encoding the playbook your lawyers set as rules a machine can check against, building the review pipeline in your own environment so every finding quotes its clause and every outgoing change waits for a named approver, and building the test set from your signed contracts so you know the error rates before anyone relies on them. That is our AI governance implementation work, scoped as a fixed statement of work.
Copyright in what we build, the playbook encoding and the test set included, is assigned to you where the contract needs it. US clients can contract through our US entity, and a fixed-scope build can start within a day of the scope being signed. The next step is a 30-minute call.
For engineers: pipeline, evaluation and access controls
The same design in engineering terms. Each point is something a reviewer can check in configuration, code or logs.
- Grounded extraction
- The model returns structured output per clause type, each item carrying a verbatim quote and its location. A deterministic check confirms the quote exists in the source text after whitespace normalisation. A failure goes to review; it is not retried until it happens to pass.
- Document preparation
- Scans go through OCR with a quality check before any model reads them. Schedules, exhibits and amendments are joined to the parent agreement, and each version under review is identified by a content hash, so a finding always points at the text it was made on.
- Playbook as data
- Positions, fallbacks and deal-breakers per clause type live in version control, owned by legal and changed through review. Every flag cites the rule id it applied.
- Evaluation in CI
- A labelled set drawn from signed contracts, scored per clause type for misses, wrong extractions and false alarms, with misses weighted heaviest. It runs on every change to the model version, prompt or playbook, and a score under threshold blocks the release. CUAD is a useful public set for testing the pipeline itself [3, 7].
- Access
- Retrieval inherits permissions from the document management system, per user and per matter. No shared index across matters unless it enforces the same walls [1, 2].
- Untrusted input
- A counterparty’s document is untrusted input. OWASP lists indirect prompt injection, where content in external sources such as files alters a model’s behaviour, as a risk [8]. So the model holds no tools that act: it proposes findings, and code decides what reaches a person.
- No autonomous sending
- The pipeline has no path to email, e-signature or a counterparty portal. A person sends outgoing redlines after approval [2].
- Audit record
- Per finding: document hash, model and prompt version, playbook version, output, reviewer, decision and timestamp, stored append-only. Mark AI-generated material as such in the file, which ABA 512 suggests so that later readers understand it may be fallible [1].
Sources
- [1]American Bar Association, Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512: Generative Artificial Intelligence Tools (29 July 2024), read 29 September 2026
- [2]State Bar of California, Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law (2026), read 29 September 2026
- [3]The Atticus Project, Contract Understanding Atticus Dataset (CUAD), read 29 September 2026
- [4]United States v. Heppner, No. 25 Cr. 503 (JSR) (S.D.N.Y.), memorandum filed 17 February 2026, read 29 September 2026
- [5]Warner v. Gilbarco, Inc., No. 2:24-cv-12333 (E.D. Mich.), order filed 10 February 2026 (ECF No. 94), read 29 September 2026
- [6]State Bar of California, Ethics and technology resources: Artificial Intelligence, read 29 September 2026
- [7]Hendrycks, Burns, Chen and Ball, CUAD: An Expert-Annotated NLP Dataset for Legal Contract Review (arXiv 2103.06268), read 29 September 2026
- [8]OWASP GenAI Security Project, LLM01:2025 Prompt Injection, read 29 September 2026
Frequently asked questions
Can AI review contracts without a lawyer?
It can do the first read: extraction, comparison with a playbook, summaries and draft markups. It should not decide whether to sign, or send changes to the other side, on its own. ABA Formal Opinion 512 says lawyers may not leave it to AI alone to advise clients or negotiate their claims, and that the lawyer is fully responsible for the work [1]. A contract on your own template, signed unchanged, may not need a lawyer at all, but that is your general counsel’s policy, and checking that the text is unchanged is a job for ordinary code.
Does using AI on a contract waive attorney-client privilege?
Courts have only started to answer this, and the early rulings differ. In United States v. Heppner (S.D.N.Y., February 2026), a defendant’s own exchanges with a public AI platform were not privileged [4]. In Warner v. Gilbarco (E.D. Mich., February 2026), the court said a self-represented plaintiff’s AI material would be protected work product even if it were discoverable [5]. Keep legal AI work in tools the company controls, under counsel’s direction, and ask your own lawyers how the rulings apply to you. This is not legal advice.
Do lawyers need client consent to use AI on contracts?
ABA 512 says informed consent is required before a lawyer puts information relating to a representation into a self-learning tool, and that boiler-plate provisions in an engagement letter do not satisfy it [1]. Beyond that, it treats disclosure case by case: lawyers must tell a client who asks, must follow any disclosure terms in the engagement agreement or the client’s outside counsel guidelines, and must consult the client when the tool’s output will influence a significant decision [1].
How accurate is AI contract review?
No single figure transfers to your contracts. Accuracy varies by clause type, by document quality and by how clearly your playbook is written. Measure it on a set of your own signed contracts before relying on it, which is the test ABA 512 describes for contract summaries [1], and measure again whenever the model or the prompts change.
Should we buy a contract review product or build our own?
Buy when your contracts fit the product’s clause library, its terms answer the questions on this page and it passes a test on your own contracts. Build, or have one built, when your playbook, your document systems or your data rules do not fit a product. The evaluation, access and approval controls on this page apply either way.
Further
- AI governance implementation · The engagement that builds approval gates, access rules and an audit trail like these into your estate.
- Production AI systems · AI systems that run against real documents day after day, with human sign-off where it matters.
- Agent proposes, verifier gates · The pattern behind the quote check: the model proposes, and deterministic code decides.
- Private LLM · Where the model runs, and what each deployment keeps private, when contracts cannot leave your control.
- AI governance framework · A copyable AI policy, each clause mapped to the control, owner and evidence behind it.
We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.
Last reviewed · 1AYM