home  /  insights  /  can-a-law-firm-sell-ai-governance-advice
New Revenue & Service Lines

Can a law firm sell AI governance as a service line?

Clients need AI policies, vendor diligence and incident playbooks, and roughly half of firms do not have a policy of their own. The structural constraint is Rule 5.7 and what happens when legal advice and consulting share an engagement.

September 4, 2026 · 5 min read

The short answer

Many firms are, and the two real constraints are credibility and Rule 5.7. The demand is genuine because clients face overlapping obligations across jurisdictions and need policies, vendor diligence, training and incident playbooks — work that is adjacent to legal advice and often sold beside it. Model Rule 5.7 governs law-related services and is the structural question: where consulting work sits alongside legal advice in one engagement, the client may reasonably believe the whole engagement carries the protections of the lawyer-client relationship. The credibility problem is more immediate and easier to fix — estimates put the share of firms with no AI policy of their own at roughly 43 to 50 percent.

What this article establishes

  • Demand is real: clients need AI policies, vendor diligence, training and incident response, and the obligations span multiple overlapping regimes.
  • Model Rule 5.7 on law-related services is the structural constraint when consulting and legal advice sit in the same engagement.
  • Roughly 43 to 50 percent of firms have no AI policy of their own, and a 2025 survey found 53% of legal professionals said their firm had no policy or did not know of one.
  • The legal industry has produced no AI control framework of its own — no bar or industry-body standard, no legal-specific vendor questionnaire — so firms are borrowing ISO/IEC 42001 and NIST material.

What is the demand for AI governance advice actually for?

For the operational artifacts a client needs and does not have: an AI use policy, a vendor diligence process, training, an approved-tools list, disclosure practices and an incident playbook for when a tool does something unexpected. Those are concrete deliverables rather than an abstract compliance posture.

The obligations driving it span several regimes at once — sectoral rules, state statutes, contractual commitments to customers, and internal governance expectations from boards and insurers. Clients are not usually asking what the law is. They are asking somebody to turn a pile of overlapping obligations into something their staff can follow.

Why is a law firm well placed to sell this?

Because the work is substantially about obligations, evidence and defensibility, which is what firms already do. A policy that will survive a regulator or a plaintiff is a different artifact from one that satisfies an internal checklist, and firms are better positioned than most consultancies to know the difference.

There is also an unusual opening on the standards side. The legal industry has produced no AI control framework of its own — no bar-body standard, no legal-specific vendor questionnaire — so firms are borrowing ISO/IEC 42001 and NIST material designed for other contexts. That vacuum is an opportunity for whoever publishes the missing artifact, and it is currently unclaimed.

What does Model Rule 5.7 have to do with it?

It governs law-related services, and it is the structural question sitting under this entire service line. Where a firm provides services that are related to but not themselves the practice of law, the question is whether the client reasonably believes those services carry the protections of a lawyer-client relationship — including confidentiality and conflicts obligations.

Governance consulting is close to the boundary by nature. It is sold to the same client, often by the same partners, frequently in the same engagement letter as legal advice, and it produces deliverables a client will treat as authoritative. The practical questions are whether the engagement is scoped to make the distinction clear, whether the consulting sits inside the firm or in a separate entity, and how conflicts are run across both.

Conduct rules are adopted state by state and diverge, and this is exactly the kind of question where the divergence matters. This is a framework to reason with, not a conclusion about any particular jurisdiction.

What is the credibility problem?

That a large share of firms selling AI governance do not have AI governance. Estimates put the proportion of firms with no AI policy at roughly 43 to 50 percent, and Clio’s 2025 Legal Trends Report found 53% of legal professionals saying their firm had no AI policy or that they did not know of one.

That is an awkward position to sell from and a straightforward one to fix, which is the useful part. The internal policy is short work — approved tools only, no client-confidential or matter-identifying inputs, named attorney verification of every factual and legal assertion, no claims without objective substantiation, hybrid personal and professional accounts treated as advertising, archived copies retained per state rule, and a standing disclaimer.

A firm that has run its own adoption has something to sell that a consultancy does not: the experience of having done it, including the parts that failed.

How do firms structure the offering?

Most commonly as a fixed-fee ladder, because the deliverables are definable and clients buying governance work want a number rather than an estimate. A typical shape runs from an assessment, to a policy and approved-tools list, to vendor diligence and contract review, to training, to a retained advisory arrangement covering changes in the regulatory picture.

Fixed fees fit this work unusually well for a reason worth noting: the firm’s own AI leverage lands directly on its margin instead of reducing billable hours. This is one of the clearer cases where the efficiency gain has somewhere to go.

Where does this go wrong?

In three predictable places. Scope creep across the Rule 5.7 line, where a consulting engagement quietly starts producing legal conclusions the engagement letter does not cover. Standing behind a vendor’s claims — a firm that recommends a tool and does not document why has taken on a position it cannot defend if the tool fails. And staleness, because a policy written against one period’s regulatory picture is a liability once it is out of date and still carries the firm’s name.

The third is the one that argues for a retained model rather than a one-off deliverable, and it is also the honest reason a client should want one.

The Institute’s New Revenue & Service Lines area covers the product ladder, and Governance & Policy covers the underlying artifacts. The Institute does not rank tools or vendors, and its founder advises firms on AI adoption.

For informational purposes only. Not legal advice and not ethics advice. Professional conduct rules are adopted state by state and diverge, and this record changes monthly. Anything here that reads as a holding should be checked against your own jurisdiction before it is relied on.

Related

The practice area

AI adoption conciergeorientation · not legal or ethics advice
Happy to. Tell me roughly how big the firm is and what it already pays for — Microsoft 365, Google Workspace, a practice-management system — because the honest answer to most AI questions at a firm your size starts with what you have already bought rather than what you should go and buy.