AI for law firm knowledge management: sources and access
Build an internal law-firm AI assistant around approved policies, current versions and matter permissions, with source checking and unanswered-question handling.

A useful internal assistant helps staff find an approved answer and inspect the source behind it. Start with a defined collection, such as current operational policies. Connecting every matter file at once creates a much harder permission, confidentiality and maintenance problem.
The first task might be locating an approved procedure and explaining where it appears. Legal advice, precedent selection and application to a live matter require an appropriately scoped professional workflow.
Give every source an owner and a version
- 01Approved collection
- 02User permissions applied
- 03Relevant source retrieved
- 04Answer linked to version
- 05Person checks application
- 06Owner maintains the source
Record the document owner, status, effective date where relevant, review date and permitted audience. Keep withdrawn material out of the current-answer collection unless the user is explicitly researching historical versions.
| Source state | Proposed assistant behaviour |
|---|---|
| Current and approved | Answer with the relevant source and version |
| Conflicting approved documents | Show the conflict and route it to the owner |
| Withdrawn or superseded | Avoid presenting it as current guidance |
| Outside the user's permissions | Do not retrieve or disclose its content |
| No suitable source | Say the collection does not establish an answer |
These are proposed operating rules. A source citation helps checking; it does not prove the answer interprets the document correctly.
Separate internal knowledge from legal research
Law firm knowledge management organises the firm's approved information so staff can find and use it. An internal AI assistant adds a question-and-answer interface over a defined collection. A current operational policy and a legal precedent need different approval, currency and application checks.
Begin with a source inventory: document, owner, status, permitted audience and next review. Ask the assistant to retrieve a passage before asking it to draft an answer. That makes a missing or conflicting source easier to spot.
For external legal authority, assess the relevant research product through the legal AI tools comparison. For Ampliflow's wider internal-knowledge service, see Company Cortex; any legal implementation still needs a scoped source and permission model.
The employment evidence guide illustrates why policy versions and effective dates matter. A knowledge assistant should identify the version it retrieved; the professional reviewer decides whether it applies to the matter.
Enforce access outside the model
The application should restrict which documents a user may retrieve before those documents reach the model. Do not rely on a written instruction asking the model to keep inaccessible material secret after it has already received it.
Check search results, previews, generated answers, exports and logs. Removing access to a source should trigger a defined response for related cached material. Previously exported copies also need an understood handling policy.
Treat retrieved text as content to inspect
Prompt injection occurs when material supplied to an AI system tries to redirect its behaviour. The NCSC explains that language models do not enforce a reliable boundary between instructions and data in a prompt. This makes the permissions and actions around the model important, even when instructions tell it to ignore malicious content. NCSC: prompt injection.
For the first version, keep the assistant's role limited to retrieval and proposed answers. Do not give a document the power to trigger external messages, change permissions or modify matter records through the assistant.
Test withdrawal and uncertainty
Create fictional policies with one current version, one retired version, a contradiction and an instruction embedded in a source asking the assistant to ignore its task. Ask questions the collection can and cannot answer.
Then remove a test user's access and repeat the relevant queries. Record wrong-version answers, unsupported statements, permission failures and the reviewer's correction time. The synthetic evaluation guide explains how to keep expected answers separate from model inputs.
Maintain the collection as an operating responsibility
A fictional source check makes the expected behaviour concrete. Suppose an approved procedure, OPS-07 version 3, says failed document imports go to the operations queue. A withdrawn version 2 names an individual. Asked where to report a failure, the assistant should identify the queue and link to the relevant passage in version 3. It should not combine the two instructions into a new procedure.
If the collection says nothing about out-of-hours cover, the assistant should state that the approved sources do not establish the answer and direct the question to the named document owner. It should not invent a rota. Record these as separate evaluation outcomes: correct current source, correct passage, no unsupported addition and an appropriate unanswered-question route. This is a fictional test case, not a deployed assistant's result.
Name the person who approves updates and resolves conflicting sources. Record unanswered questions as candidates for improving the collection, without assuming every question needs another document.
The SRA retains professional responsibility and appropriate human scrutiny for AI-assisted legal services; an internal assistant does not remove that boundary. SRA supervision guidance.
The supplier review addresses data handling, while the legal hub connects internal knowledge with the firm's wider workflows. Success is a checked answer from the right source, available to the right person.