Corporate legal departments are now the largest AI users in enterprise, raising oversight stakes for general counsel
Corporate legal departments have become the biggest users of artificial intelligence within enterprises, adopting company-approved AI tools more aggressively than any other business function, according to analysis published by Law.com. The finding raises significant questions about governance: when the legal team is the heaviest user of AI, the general counsel (GC), the senior lawyer responsible for a company's legal affairs, sits simultaneously in the role of the organisation's primary AI user and its primary AI overseer. That dual position creates a tension between driving efficiency and maintaining independent governance of the risks that AI use generates, including data protection exposure, confidentiality risks when sensitive legal information is processed by AI systems, and the professional responsibility implications of AI-generated work product. Separately, guidance published for law firms emphasises that it is incumbent on firms to create policies, set usage scenarios, and implement training and support so that all members understand the strengths and weaknesses of AI tools. Firms that invest in governance, training, and change management from the outset are positioned to manage these risks more effectively. The convergence of these two data points, in-house legal as the leading AI adopter and firms being urged to invest in governance, points to a market in which clients and their advisers are both racing to embed AI while the regulatory framework around it remains incomplete.
Why this matters
Legal departments being the heaviest enterprise AI users creates a direct tension with the GC's governance function. Under data protection frameworks such as the UK GDPR (the UK's retained version of the EU General Data Protection Regulation), processing client or employee data through AI systems requires a lawful basis and a data protection impact assessment (DPIA). If the legal team is the biggest user, the GC must ensure those obligations are met for their own function while also advising the rest of the business. For law firms, the guidance to invest in governance and training from the outset reflects a maturing understanding that AI deployment without structured oversight creates professional liability risk. The EU AI Act, which classifies AI systems by risk level and imposes obligations on providers and deployers, will directly affect how law firms and in-house teams in the EU document and govern their AI tool use.
On the Ground
A trainee supporting an AI governance project would assist with drafting AI governance policy documents, marking up data processing agreements with AI vendors, and preparing regulatory impact assessment memos identifying which AI use cases may require a DPIA under UK GDPR or comply with obligations under the EU AI Act.
Interview prep
Question you might get
“What governance framework would you recommend for a corporate legal department that has become the largest user of AI tools within its enterprise, and what are the key legal risks it needs to manage?”
Sign up free to see the full answer
A model answer you can lift into an interview — how to frame this story for a partner.
Sign up freeSources
My notes
saved