What is the demand for AI governance advice actually for?
For the operational artifacts a client needs and does not have: an AI use policy, a vendor diligence process, training, an approved-tools list, disclosure practices and an incident playbook for when a tool does something unexpected. Those are concrete deliverables rather than an abstract compliance posture.
The obligations driving it span several regimes at once — sectoral rules, state statutes, contractual commitments to customers, and internal governance expectations from boards and insurers. Clients are not usually asking what the law is. They are asking somebody to turn a pile of overlapping obligations into something their staff can follow.
Why is a law firm well placed to sell this?
Because the work is substantially about obligations, evidence and defensibility, which is what firms already do. A policy that will survive a regulator or a plaintiff is a different artifact from one that satisfies an internal checklist, and firms are better positioned than most consultancies to know the difference.
There is also an unusual opening on the standards side. The legal industry has produced no AI control framework of its own — no bar-body standard, no legal-specific vendor questionnaire — so firms are borrowing ISO/IEC 42001 and NIST material designed for other contexts. That vacuum is an opportunity for whoever publishes the missing artifact, and it is currently unclaimed.
What does Model Rule 5.7 have to do with it?
It governs law-related services, and it is the structural question sitting under this entire service line. Where a firm provides services that are related to but not themselves the practice of law, the question is whether the client reasonably believes those services carry the protections of a lawyer-client relationship — including confidentiality and conflicts obligations.
Governance consulting is close to the boundary by nature. It is sold to the same client, often by the same partners, frequently in the same engagement letter as legal advice, and it produces deliverables a client will treat as authoritative. The practical questions are whether the engagement is scoped to make the distinction clear, whether the consulting sits inside the firm or in a separate entity, and how conflicts are run across both.
Conduct rules are adopted state by state and diverge, and this is exactly the kind of question where the divergence matters. This is a framework to reason with, not a conclusion about any particular jurisdiction.
What is the credibility problem?
That a large share of firms selling AI governance do not have AI governance. Estimates put the proportion of firms with no AI policy at roughly 43 to 50 percent, and Clio’s 2025 Legal Trends Report found 53% of legal professionals saying their firm had no AI policy or that they did not know of one.
That is an awkward position to sell from and a straightforward one to fix, which is the useful part. The internal policy is short work — approved tools only, no client-confidential or matter-identifying inputs, named attorney verification of every factual and legal assertion, no claims without objective substantiation, hybrid personal and professional accounts treated as advertising, archived copies retained per state rule, and a standing disclaimer.
A firm that has run its own adoption has something to sell that a consultancy does not: the experience of having done it, including the parts that failed.
How do firms structure the offering?
Most commonly as a fixed-fee ladder, because the deliverables are definable and clients buying governance work want a number rather than an estimate. A typical shape runs from an assessment, to a policy and approved-tools list, to vendor diligence and contract review, to training, to a retained advisory arrangement covering changes in the regulatory picture.
Fixed fees fit this work unusually well for a reason worth noting: the firm’s own AI leverage lands directly on its margin instead of reducing billable hours. This is one of the clearer cases where the efficiency gain has somewhere to go.
Where does this go wrong?
In three predictable places. Scope creep across the Rule 5.7 line, where a consulting engagement quietly starts producing legal conclusions the engagement letter does not cover. Standing behind a vendor’s claims — a firm that recommends a tool and does not document why has taken on a position it cannot defend if the tool fails. And staleness, because a policy written against one period’s regulatory picture is a liability once it is out of date and still carries the firm’s name.
The third is the one that argues for a retained model rather than a one-off deliverable, and it is also the honest reason a client should want one.
The Institute’s New Revenue & Service Lines area covers the product ladder, and Governance & Policy covers the underlying artifacts. The Institute does not rank tools or vendors, and its founder advises firms on AI adoption.