Abacus AI
Hub
AI regulatory intelligence, curated resources, governance templates, and practical use cases for member firms navigating the AI transformation across legal, tax, audit, and accounting practice.
[BRACKETED] fields with your firm details. These templates reference the regulations and guidance tracked in the Regulatory tab.
[FIRM NAME] — AI ACCEPTABLE USE POLICY Effective Date: [DATE] Approved by: [MANAGING PARTNER / BOARD] Review Cycle: Quarterly, or upon material regulatory change 1. PURPOSE AND SCOPE This policy governs the use of artificial intelligence tools and services by all personnel of [Firm Name], including partners, associates, staff, contractors, and secondees. It applies to all AI tools whether provided by the firm, accessed via personal accounts, or embedded within other software. 2. APPROVED AI TOOLS The following tools are approved for use with firm and client data, subject to the conditions specified: Category A — Approved for client-identifiable data: [List tools with enterprise agreements, e.g. Microsoft 365 Copilot, firm-deployed Harvey instance, etc.] Category B — Approved for anonymised/non-client data only: [List tools approved for internal use only, e.g. ChatGPT Enterprise for internal drafting, Claude for research on public information] Category C — Prohibited: All consumer/free-tier AI tools (free ChatGPT, free Claude, free Gemini, etc.) are prohibited for any firm or client-related work. Personal use outside firm matters is not governed by this policy. Any tool not listed above requires written approval from [AI Governance Lead / Managing Partner] before use. 3. DATA CLASSIFICATION AND INPUT RULES Before inputting any information into an AI tool, personnel must classify the data: Confidential client data: May only be input into Category A tools. This includes client names, matter details, financial information, legal positions, and any information subject to legal privilege or professional confidentiality. Internal firm data: May be input into Category A or B tools. This includes firm policies, general know-how, and de-identified precedents. Public information: May be input into any approved tool. When in doubt, treat data as confidential. Anonymisation must remove all identifiers that could reasonably be used to identify a client, matter, or individual. 4. PROHIBITED USES AI tools must not be used to: — Make final decisions on client matters without professional review — Submit AI-generated content to courts, regulators, or clients without verification against primary sources — Process personal data in a manner inconsistent with applicable data protection law — Generate content that will be presented as the professional judgment of the firm without review by a qualified professional — Circumvent the approved tools list by using personal accounts, VPNs, or alternative access methods — Input information subject to legal professional privilege into any tool without confirming the tool data processing terms preserve privilege 5. SUPERVISION AND REVIEW REQUIREMENTS All AI-generated work product must be reviewed before use in client-facing work: Partner/Director review required: Court filings, audit opinions, tax returns, formal legal opinions, regulatory submissions Manager/Senior review sufficient: Research memos, internal analysis, first-draft client communications Self-review sufficient: Internal administrative tasks, meeting summaries, formatting The reviewing professional is responsible for the accuracy of the final work product regardless of whether it was AI-assisted. AI-generated content must be verified against primary sources where it contains citations, legal authorities, regulatory references, or factual claims. 6. DOCUMENTATION Where AI tools are used in client work, the following should be documented in the matter file: — Which AI tool was used — What task it was used for — What human review was conducted — Any limitations or caveats identified This documentation supports quality management obligations under [ISQM 1 / SRA requirements / applicable professional standards]. 7. CLIENT DISCLOSURE [Option A — Proactive disclosure]: The firm discloses in engagement letters that AI tools may be used as part of its service delivery, subject to this policy and applicable professional standards. [Option B — On-request disclosure]: The firm will disclose AI use to clients upon request. Specific client instructions regarding AI use will be documented and honoured. [Select the approach that aligns with your jurisdiction professional conduct requirements and client expectations.] 8. TRAINING All personnel must complete AI awareness training within [30/60/90] days of this policy taking effect and annually thereafter. Training covers: approved tools, data classification, verification requirements, and professional conduct obligations. Completion is tracked and reported to [Managing Partner / HR]. 9. INCIDENT REPORTING Any actual or suspected breach of this policy — including inadvertent input of confidential data into a non-approved tool — must be reported to [AI Governance Lead / Managing Partner] within 24 hours. Incidents will be assessed, documented, and remediated. Client notification will be made where required by professional conduct rules or data protection law. 10. REVIEW AND UPDATES This policy is reviewed quarterly by [AI Governance Lead / Management Committee] and updated as required to reflect changes in regulatory requirements, approved tools, and firm practice. Material updates are communicated to all personnel and require acknowledgement. Acknowledged by: _________________________ Name: _________________________ Date: _________________________
[FIRM NAME] — AI VENDOR ASSESSMENT CHECKLIST Vendor Name: _______________ Product/Service: _______________ Assessment Date: _______________ Assessed By: _______________ SECTION 1: DATA HANDLING AND CONFIDENTIALITY [ ] Does the vendor confirm that client data input by users is NOT used to train, fine-tune, or improve their AI models? [ ] Does the vendor provide a clear data processing agreement (DPA) compliant with [UK GDPR / GDPR / PIPEDA / applicable law]? [ ] Where is data processed and stored? Jurisdictions: _______________ [ ] Is data encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent)? [ ] Can client data be deleted on request? What is the deletion timeline? _______________ [ ] Does the vendor provide sub-processor lists and notify of changes? [ ] Is legal professional privilege / attorney-client privilege preserved under the vendor terms? [ ] Does the vendor have SOC 2 Type II certification (or equivalent)? SECTION 2: AI MODEL AND OUTPUT QUALITY [ ] What underlying model(s) does the product use? _______________ [ ] Does the vendor disclose accuracy rates or error benchmarks for the relevant use case? [ ] Are outputs traceable to source material (RAG with citations)? [ ] Does the product include confidence scoring or uncertainty indicators? [ ] What is the training data cutoff date? _______________ [ ] Does the vendor provide documentation on known limitations and failure modes? SECTION 3: REGULATORY COMPLIANCE [ ] Has the vendor conducted an EU AI Act risk classification assessment (if EU market exposure)? [ ] Does the product meet the transparency requirements of applicable AI regulations? [ ] Can the vendor provide conformity documentation if the product qualifies as high-risk AI? [ ] Does the vendor maintain audit logs of AI system inputs and outputs? [ ] Does the vendor have a bias testing and monitoring programme? SECTION 4: CONTRACTUAL PROTECTIONS [ ] Does the contract include a limitation on vendor use of firm/client data? [ ] Are there clear liability provisions for AI-generated errors? [ ] Does the contract include indemnification for intellectual property infringement claims? [ ] Is there a termination right with data portability/deletion within a defined period? [ ] Does the contract include SLA commitments for uptime and response times? [ ] Are price escalation terms capped or predictable? SECTION 5: OPERATIONAL FIT [ ] Does the product integrate with existing firm systems? (DMS, PMS, accounting software) [ ] What training and onboarding support is provided? [ ] Is there a dedicated account manager or support team for professional services clients? [ ] What is the implementation timeline? _______________ [ ] Are there reference clients in the legal/accounting sector? ASSESSMENT OUTCOME Overall Risk Rating: [ ] Low [ ] Medium [ ] High Recommendation: [ ] Approve [ ] Approve with conditions [ ] Reject Conditions (if applicable): _______________ Approved by: _______________ Date: _______________
[FIRM NAME] — AI DISCLOSURE CLAUSES FOR ENGAGEMENT LETTERS Select the clause(s) appropriate for your jurisdiction, client relationship, and professional conduct requirements. These are starting points — adapt to your specific engagement terms. ————————————————— CLAUSE A: PROACTIVE DISCLOSURE (RECOMMENDED FOR MOST ENGAGEMENTS) Technology and AI Tools In delivering the services described in this letter, our firm may utilise artificial intelligence and other technology tools as part of our professional workflow. Any such use is subject to our internal AI governance policies, which require human professional review and oversight of all AI-assisted work product. All advice and deliverables provided under this engagement represent the professional judgment of the qualified professionals assigned to your matter. Our use of technology tools does not alter the scope, quality, or professional responsibility standards applicable to our services. Client data is processed only through approved tools that meet our data security and confidentiality standards. ————————————————— CLAUSE B: ON-REQUEST DISCLOSURE Technology in Service Delivery Our firm employs a range of professional tools and technologies in delivering services. We are happy to discuss our technology practices, including the use of AI-assisted tools, upon request. All services are delivered under the supervision of qualified professionals in accordance with applicable professional standards. ————————————————— CLAUSE C: CLIENT OPT-OUT PROVISION (WHERE REQUIRED OR APPROPRIATE) AI Tools — Client Instructions Unless you instruct us otherwise in writing, our firm may use AI-assisted tools as part of our workflow for this engagement, subject to professional review and our data security policies. If you prefer that AI tools not be used in connection with your matter, please notify [contact] and we will accommodate your instructions. [Note: accommodating an opt-out may affect timelines and fees — consider whether to address this.] ————————————————— CLAUSE D: SPECIFIC TOOL DISCLOSURE (HIGH-SENSITIVITY ENGAGEMENTS) Technology Disclosure For this engagement, we may use the following technology tools: [list specific tools, e.g., Microsoft 365 Copilot for document drafting, Bloomberg Tax AI for tax research]. Each tool operates under enterprise licence terms that [prohibit use of client data for model training / maintain data within our jurisdiction / are subject to our DPA]. All AI-assisted output is reviewed by [Partner name / a qualified professional] before inclusion in deliverables. ————————————————— GUIDANCE NOTES Jurisdiction considerations: — US (ABA FO512): Competence requires understanding AI tools used. Disclosure is recommended but not universally mandated at federal level. Check state bar opinions. — UK (SRA): The SRA expects firms to be transparent about technology use where it is material to service delivery. — Canada (CBA): Guidance recommends disclosure where AI materially affects how services are delivered. — EU: The EU AI Act imposes transparency obligations on deployers of certain AI systems — assess whether your use case triggers these. — Australia: No specific disclosure requirement yet, but professional bodies recommend transparency as best practice ahead of mandatory AI obligations. For accounting engagements specifically: — Audit: Consider whether ISQM 1 documentation requirements necessitate disclosure of AI-assisted audit procedures. — Tax: AICPA SSTS 1.4 requires assessment of technology tools relied upon — engagement letter language should be consistent with this. — CAS/Advisory: Standard disclosure language is generally sufficient.
[FIRM NAME] — AI INCIDENT RESPONSE PROTOCOL 1. INCIDENT CATEGORIES Category 1 — CRITICAL (respond within 2 hours): — Confidential client data input into unapproved/consumer AI tool — AI-generated content with material errors submitted to court, regulator, or client — Data breach involving AI vendor systems — Privileged information potentially exposed through AI tool Category 2 — SERIOUS (respond within 24 hours): — AI-generated work product used without required review — Discovery of systematic AI output errors affecting multiple matters — Client complaint regarding AI use in their matter — AI vendor terms change materially affecting data handling Category 3 — REPORTABLE (respond within 5 business days): — Near-miss incidents (error caught before reaching client) — Staff non-compliance with AI policy (first occurrence, no client impact) — AI tool performance degradation affecting work quality 2. IMMEDIATE RESPONSE STEPS Step 1: Contain — Stop the AI tool/process that caused the incident — If data was input into wrong tool: contact vendor immediately to request deletion and confirm retention — If erroneous content was sent externally: begin correction process — Preserve all evidence (screenshots, logs, matter files) Step 2: Assess — What data or content was affected? — Which clients or matters are impacted? — What is the potential harm (legal, financial, reputational)? — Are there regulatory notification obligations? (72 hours under GDPR) — Are there professional conduct reporting obligations? Step 3: Escalate — Category 1: Managing Partner + [AI Governance Lead] + [Data Protection Officer/Privacy Counsel] immediately — Category 2: [AI Governance Lead] + relevant practice group head within 24 hours — Category 3: [AI Governance Lead] within 5 business days 3. CLIENT NOTIFICATION Notify the client when: — Their confidential data was exposed or potentially exposed to an unauthorised party — AI-generated errors were included in deliverables sent to them — The incident may affect the advice or work product they relied upon — Professional conduct rules in the applicable jurisdiction require disclosure Client notification should be made by the responsible partner, with support from [AI Governance Lead / risk counsel], and should include: what happened, what data or work was affected, what remediation steps have been taken, and what the client should do (if anything). 4. REGULATORY NOTIFICATION Assess notification obligations to: — Data protection authority (72 hours under GDPR, varying timelines under other regimes) — Professional conduct regulator (SRA, state bar, CPA board — per applicable rules) — Clients (per professional conduct and contractual obligations) — Cyber insurance carrier (per policy terms — often required within 48-72 hours) 5. REMEDIATION — Correct any erroneous work product and reissue to affected parties — Update AI policy if the incident reveals a gap — Provide additional training if the incident resulted from staff error — Review vendor relationship if the incident involves vendor failure — Update approved tools list if warranted 6. DOCUMENTATION Document in the incident register: — Date and time of incident and discovery — Category and description — Data, clients, and matters affected — Root cause analysis — Immediate actions taken — Client and regulatory notifications made — Remediation steps and timeline — Lessons learned and policy updates 7. POST-INCIDENT REVIEW Within 14 days of resolution, conduct a post-incident review: — Was the response timely and effective? — Did the escalation process work? — What policy or procedural changes are needed? — Is additional training required? — Report findings to [Management Committee / Board]
[FIRM NAME] — AI SUPERVISION AND REVIEW POLICY (LAW FIRM) 1. PROFESSIONAL CONDUCT FOUNDATION This policy implements the supervision obligations arising from [applicable rules]: — Duty of competence: requires understanding the AI tools used and their limitations — Duty of supervision: AI-assisted work must be supervised with the same rigour as work by a junior lawyer — Duty of confidentiality: AI tool use must not compromise client confidentiality or privilege — Duty of candour: AI-generated content submitted to courts must be verified; AI use must be disclosed where required 2. REVIEW TIERS Tier 1 — Partner review mandatory: — Court filings, pleadings, and submissions — Formal legal opinions — Regulatory submissions — Client advice letters on material matters — Any document where the firm assumes professional liability Timeline: Before submission/delivery. No exceptions. Tier 2 — Senior associate / manager review: — Research memoranda — Due diligence reports and issue logs — First-draft client communications on routine matters — Internal case assessments Timeline: Before circulation to partner or client. Tier 3 — Self-review sufficient: — Internal meeting summaries and notes — Administrative correspondence — Document formatting and organisation — Initial research scoping (not final research) Timeline: Before use. Practitioner remains responsible. 3. VERIFICATION REQUIREMENTS FOR AI-ASSISTED LEGAL RESEARCH Given documented error rates in leading legal AI research tools (17-34% per Stanford HAI 2025 research), the following verification steps are mandatory: Every case citation must be verified: — Confirm the case exists in the primary law report — Confirm the citation is correct (court, year, page/paragraph) — Confirm the legal proposition attributed to the case is accurately stated — Confirm the case has not been overruled, distinguished, or superseded Every statutory reference must be verified: — Confirm the section number and title are correct — Confirm the provision is in force and has not been amended — Confirm the interpretation stated is consistent with the statutory text Every regulatory reference must be verified: — Confirm the guidance/rule exists and is current — Confirm the summary is accurate Verification must be documented: The reviewing lawyer should note in the matter file that AI-assisted research was verified against primary sources. A simple file note stating "AI-assisted research verified against [source] on [date] by [name]" is sufficient. 4. AI-ASSISTED COURT FILINGS Before any document containing AI-assisted content is filed with a court or tribunal: — All citations verified per Section 3 above — All factual assertions verified against matter file — Document reviewed by the responsible partner — Consider court-specific AI disclosure requirements (an increasing number of courts require or request disclosure of AI use) — File note documenting AI use and verification steps 5. ESCALATION If AI-generated content is discovered to contain errors after delivery to a client or submission to a court: — Invoke the AI Incident Response Protocol immediately — Responsible partner must assess materiality and determine corrective action — Client notification and court correction as required by professional conduct rules
[FIRM NAME] — AI IN AUDIT ENGAGEMENTS — DOCUMENTATION AND QUALITY POLICY 1. SCOPE This policy applies to all audit and assurance engagements where AI tools are used as part of audit procedures, including: data analytics and anomaly detection, journal entry testing, population analysis, predictive risk assessment, and document review. 2. QUALITY MANAGEMENT FRAMEWORK (ISQM 1 ALIGNMENT) AI tools used in audit are part of the firm quality management system and must be: — Assessed for fitness for purpose before deployment on engagements — Subject to periodic performance evaluation — Documented in the firm quality management policies — Included in the monitoring and remediation process The engagement partner retains responsibility for the overall quality of the engagement regardless of AI tool use. 3. DOCUMENTATION REQUIREMENTS For each engagement where AI tools are used, the audit file must include: Engagement-level documentation: — Which AI tools were used and for which procedures — The nature of the data input to the AI tool — The parameters and settings applied — How AI outputs were evaluated and by whom — The conclusions drawn from AI-assisted procedures — Any limitations identified in the AI tool output Procedure-level documentation: — The audit assertion(s) addressed by the AI-assisted procedure — The population tested and how completeness was established — Anomalies or exceptions identified by the AI tool — How each anomaly was investigated and resolved — The auditor professional judgment applied to AI-identified items 4. PROFESSIONAL SKEPTICISM AI outputs must be evaluated with the same professional skepticism applied to any other audit evidence: — AI-identified anomalies are starting points for investigation, not conclusions — The absence of AI-flagged anomalies does not constitute sufficient audit evidence on its own — The engagement team must understand what the AI tool is measuring and what it might miss — Known AI tool limitations must be factored into the assessment of audit risk AI tools do not replace the auditor professional judgment. The auditor must be able to explain and defend the conclusions drawn from AI-assisted procedures. 5. DATA INTEGRITY Before relying on AI-generated analytics: — Verify the completeness and accuracy of the data input — Confirm the data was extracted from the client system correctly — Assess whether the data format and structure are appropriate for the AI tool — Document any data transformations or cleaning performed 6. REVIEW AND SIGN-OFF AI-assisted audit procedures require the same review structure as manual procedures: — Prepared by: The team member who ran the AI tool and evaluated outputs — Reviewed by: Manager/senior with sufficient understanding of the AI tool methodology — Approved by: Engagement partner, confirming procedures are sufficient and conclusions are supported 7. SSTS 1.4 COMPLIANCE (TAX ENGAGEMENTS) Where AI tools are used for tax research or position support: — Document which AI tool was used and the query submitted — Verify all authorities cited by the AI tool against primary sources — Assess whether reliance on the AI tool output meets the reasonable basis standard — Document the assessment of the AI tool suitability per SSTS 1.4 requirements
[FIRM NAME] — AI TRAINING AND COMPETENCY POLICY 1. MANDATORY TRAINING REQUIREMENTS All personnel: — Complete AI Awareness module within [30/60/90] days of policy effective date or hire date — Complete annual AI refresher training — Acknowledge updated AI Acceptable Use Policy upon each revision Module content: — Firm AI Acceptable Use Policy (approved tools, data classification, prohibited uses) — What AI is and how it works (sufficient for their role) — Key risks: hallucination, confidentiality, bias, over-reliance — Professional conduct obligations relevant to their role — How to report an AI incident 2. ROLE-SPECIFIC COMPETENCY TARGETS Partners / Directors: — Understand AI capabilities and limitations at strategic level — Know regulatory and professional conduct landscape for AI in their practice area — Able to evaluate AI vendor claims and assess firm AI strategy — Able to supervise AI-assisted work effectively Assessment: Annual self-assessment against competency framework reviewed by [Managing Partner] Managers / Senior Associates: — Proficient in at least one approved AI tool for their practice area — Can write effective prompts and evaluate AI output quality — Understand verification requirements and can supervise junior staff AI use — Know professional conduct obligations for AI use in their jurisdiction Assessment: Practical assessment — demonstrate use of approved tool on a sample task Associates / Junior Staff: — Daily proficiency with approved tools for their role — Strong verification habits — every output checked before use — Know approved tools list, data classification rules, and escalation procedures — Can identify hallucinations and plausible-but-wrong outputs Assessment: Practical assessment plus verification exercise (AI output with planted errors) Business Services / Support Staff: — Proficient in AI features within tools they use (M365 Copilot, etc.) — Know firm AI policy and data classification rules — Can use AI for approved administrative tasks Assessment: Complete training module and pass knowledge check 3. TRAINING DELIVERY — AI Awareness module: Online, self-paced, available via [LMS / firm intranet]. 60-90 minutes. — Role-specific training: Delivered by [internal AI champion / external trainer] in group sessions. Quarterly. — Tool-specific training: Provided when new tools are added to the approved list or when significant updates occur. — Practical workshops: Quarterly hands-on sessions where staff practice with approved tools on non-client scenarios. 4. TRACKING AND REPORTING — Training completion tracked in [HR system / LMS] — Quarterly compliance report to [Managing Partner / Management Committee] — Non-completion escalated to practice group heads at 30 days past deadline — Training completion is a factor in annual performance reviews 5. STAYING CURRENT The AI landscape moves fast. This policy supports ongoing learning through: — Monthly AI digest: curated summary of relevant developments (managed by [AI Governance Lead]) — Peer learning: staff encouraged to share useful AI techniques in team meetings — External resources: firm subscription to [Abacus AI Hub / relevant CPE provider] — Conference attendance: budget allocated for AI-relevant professional development
[FIRM NAME] — AI OUTPUT VERIFICATION PROTOCOL BEFORE USING ANY AI-GENERATED CONTENT IN CLIENT WORK: STEP 1: SOURCE CHECK [ ] Every case, statute, or regulatory citation — verified against primary source [ ] Every named authority (person, body, organisation) — confirmed to exist and be correctly described [ ] Every date, deadline, or timeline — verified against official source [ ] Every numerical figure or statistic — confirmed against original data STEP 2: ACCURACY CHECK [ ] Legal propositions accurately reflect the cited authority [ ] Tax positions are consistent with current law and guidance [ ] Financial figures are arithmetically correct and contextually appropriate [ ] No fabricated or hallucinated content (read critically — does this sound right?) STEP 3: CURRENCY CHECK [ ] Authorities cited are current and have not been superseded, amended, or overruled [ ] Regulatory guidance reflects the most recent version [ ] Tax rates and thresholds are for the correct period [ ] Any time-sensitive information is current as of the date of the work product STEP 4: JURISDICTIONAL CHECK [ ] Correct jurisdiction — AI tools can mix jurisdictions without flagging the switch [ ] Applicable law is correctly identified for the client situation [ ] Cross-border matters: each jurisdiction position verified independently [ ] Professional body guidance is from the correct jurisdiction STEP 5: COMPLETENESS CHECK [ ] Are there material issues the AI output missed? [ ] Has the AI addressed all aspects of the question asked? [ ] Are there obvious counterarguments or risks not mentioned? [ ] Would you be comfortable signing this as your own work? STEP 6: SIGN-OFF [ ] Verified by: _______________ Date: _______________ [ ] Review tier (per AI Supervision Policy): [ ] Tier 1 (Partner) [ ] Tier 2 (Senior) [ ] Tier 3 (Self) [ ] File note: AI-assisted content verified against primary sources REMEMBER: If an AI output passes all checks, it is good evidence that was efficiently produced. If it fails any check, it is not a shortcut that went slightly wrong — it is an error that would have damaged your client and your reputation. The five minutes spent verifying is always worth it.
[FIRM NAME] — AI INDEPENDENCE CONSIDERATIONS FOR ASSURANCE ENGAGEMENTS
Engagement: _______________
Client: _______________
Assessed by: _______________ Date: _______________
SELF-REVIEW THREAT ASSESSMENT
[ ] Is the AI tool used in both advisory and assurance services for the same client?
If yes: Assess whether reliance on AI-generated advisory work in the audit creates a self-review threat.
[ ] Was the AI tool used to prepare financial information that is now subject to audit?
If yes: This may create a self-review threat equivalent to preparing and auditing the same information.
[ ] Does the AI tool automate any judgment that should remain with the audit team?
If yes: Ensure the engagement team exercises independent professional judgment — AI output is evidence, not a conclusion.
VENDOR RELATIONSHIP ASSESSMENT
[ ] Does the firm have a financial relationship with the AI vendor beyond a standard licence?
(E.g., revenue sharing, equity stake, board membership, exclusive partnership)
If yes: Assess whether the relationship creates a business relationship threat to independence.
[ ] Does the AI vendor also provide services to the audit client?
If yes: Assess potential conflicts and document the assessment.
[ ] Is the AI tool marketed to clients through the firm?
If yes: Consider whether this creates an advocacy or self-interest threat.
DATA AND CONFIDENTIALITY
[ ] Does the AI tool process data from the audit client alongside data from other clients?
If yes: Confirm data segregation measures are adequate.
[ ] Could AI tool outputs from the advisory engagement inadvertently inform the audit engagement?
If yes: Implement information barriers or separate tool instances.
DOCUMENTATION
[ ] Independence assessment documented in the engagement file
[ ] Assessment reviewed by the engagement quality reviewer (where applicable)
[ ] Any identified threats and safeguards documented
[ ] Conclusion: Independence maintained / Safeguards applied / Matter escalated
Reviewed by: _______________ Date: _______________When people say "AI" in 2026 they almost always mean large language models (LLMs) -- software trained on enormous amounts of text to predict the next word in a sequence. That is literally all they do. The remarkable thing is that doing this at sufficient scale and with enough data produces a system that can reason, write, summarise, translate, and code at a level that is genuinely useful for professional work.
LLMs do not search the internet in real time (unless a tool is specifically built that way). They do not remember your previous conversations (unless your tool stores them). They do not "know" things the way a person does -- they generate statistically likely continuations of text. This is why they can produce fluent, confident, completely wrong answers. Understanding this is the single most important thing any professional needs to know before using these tools.
Key terms you will encounter:
- Model -- the underlying AI system (GPT-4o, Claude 3.5, Gemini 1.5). Different models have different strengths, training data, and pricing.
- Context window -- the amount of text the model can "see" at once. Larger context windows let you feed in longer documents. Current leading models handle 100,000 to 1,000,000+ tokens (roughly 75,000 to 750,000 words).
- Prompt -- your instruction to the model. The quality of the output depends heavily on the quality of the prompt.
- Token -- the unit models process text in. Roughly 1 token = 0.75 words. Pricing is typically per thousand tokens.
- Temperature -- a setting controlling how creative vs. predictable the output is. Low temperature = more consistent, high temperature = more varied. Most professional tools set this for you.
- Fine-tuning -- training a model further on specific data to specialise it for a domain. Harvey and Casetext, for example, are fine-tuned on legal text.
- RAG (Retrieval-Augmented Generation) -- a technique where the model retrieves relevant documents before generating a response. This is how legal research tools serve current case law rather than relying on training data.
- Agent / Agentic AI -- AI that can take actions autonomously: run searches, draft documents, send emails, execute multi-step workflows. 2025-26 is the year agentic AI moved from concept to deployment in professional services tools.
- Hallucination -- when a model generates something plausible-sounding but factually wrong. This is not a bug that will be fixed -- it is a structural feature of how LLMs work. All AI output that will be used professionally must be verified.
The market is moving fast. Here is an honest assessment of the main platforms as of early 2026:
| Service | Best for | Strengths | Watch out for |
|---|---|---|---|
| ChatGPT OpenAI |
General drafting, research, coding, brainstorming | Widest tool ecosystem, strong reasoning, large context window, image/voice support. GPT-4o is the flagship model. | Free version uses older model. Data sent to OpenAI unless you have Enterprise. Check your terms before inputting client data. |
| Claude Anthropic |
Long-document analysis, careful drafting, nuanced reasoning | Best-in-class for reading and analysing long documents (200K+ token context). Tends to be more cautious and less likely to fabricate. Strong for professional tone. | Less third-party tool integrations than ChatGPT. Enterprise plan needed for data privacy in professional use. |
| Microsoft Copilot Microsoft / OpenAI |
In-workflow use inside Word, Outlook, Excel, Teams | Integrated directly into M365. For firms already on Microsoft 365, lowest friction adoption. Data stays within your Microsoft tenancy under M365 Copilot terms. | Requires M365 Copilot licence (significant cost per seat). Quality varies by application. Best in Word and Outlook, more limited in complex Excel scenarios. |
| Gemini |
Google Workspace integration, multimodal tasks | Deeply integrated with Google Docs, Gmail, Drive. Strong multimodal capability (text, images, audio). Competitive reasoning on latest models. | Gemini for Workspace requires separate licensing. Data governance terms matter if you use free consumer version. |
| Harvey Harvey AI |
Law firm-specific workflows | Purpose-built for legal work. Trained on legal data. Integrates with document management systems. Strong on contract review, due diligence, legal research within its trained domains. | Significant licensing cost. Best ROI at higher usage volumes. Quality still varies by practice area and jurisdiction. |
| Thomson Reuters CoCounsel / Westlaw AI Thomson Reuters |
Legal research, brief analysis | RAG-based -- retrieves from Westlaw database before generating. Reduces (but does not eliminate) hallucination risk on case law. Workflow integration with existing TR subscriptions. | Stanford research (2025) found 17% error rate on legal-specific tasks. Still requires verification. Premium pricing on top of existing Westlaw subscription. |
| Lexis+ AI / Protege LexisNexis |
Legal research, multi-agent workflows | Multi-agent architecture (orchestrator + research + web + document agents). Good for complex research workflows. RAG from LexisNexis database. | Stanford research found 34% error rate -- higher than Westlaw AI. Verification workflow is essential. Complex to configure effectively. |
| Bloomberg Tax / Checkpoint AI Bloomberg / Thomson Reuters |
Tax research | Tax-specific training. RAG from primary tax sources. Integrated into existing research workflows for firms already subscribed. | Cross-border accuracy varies. Novel positions require senior review. AICPA SSTS 1.4 (2025) requires documentation of technology tool assessment. |
Error rate data from Stanford HAI research (2025). Figures represent task accuracy on legal-specific benchmarks -- general performance may differ. All figures should be treated as directional, not definitive.
Not everyone in a professional services firm needs the same AI capability. Trying to train everyone to the same level wastes time and misses what different roles actually need. Here is a practical framework:
- Understand what AI can and cannot do at a conceptual level -- enough to evaluate vendor claims critically
- Know the regulatory and professional conduct obligations relevant to your jurisdiction and role
- Understand the AI strategy divide: firms without a defined strategy are already falling behind
- Know how to evaluate ROI claims from AI vendors -- what metrics actually matter
- Understand data privacy and confidentiality obligations when staff use AI tools
- Be able to set policy on approved tools, supervision requirements, and client disclosure
- Proficient in at least one approved AI tool for their practice area
- Understand hallucination risk and know how to verify AI-generated outputs
- Can write effective prompts for their common tasks (see Prompting section)
- Know what client data can and cannot be input into which tools
- Can supervise junior staff AI use and catch errors before they reach partners or clients
- Understand the professional conduct implications -- ABA FO512, SRA guidance, or their national equivalent
- Can identify when AI output is plausible but wrong (this is the hard skill)
- Proficient in approved tools for their role -- should be using AI daily for routine tasks
- Strong prompting skills -- know how to iterate, refine, and get useful output
- Non-negotiable: every AI output must be verified before use in client work
- Know which tools are approved for which types of data
- Can identify hallucinations, fabricated citations, and plausible-but-wrong output
- Understand they cannot delegate professional judgment to AI -- the responsibility remains theirs
- Know when to escalate: novel fact patterns, high-stakes positions, unfamiliar jurisdictions
- Proficient in AI features within the tools they already use (M365 Copilot, document management AI)
- Know firm policy on what data can be input into AI tools
- Can use AI for drafting routine communications, summarising meeting notes, formatting documents
- Understand that AI output is a starting point, not a finished product
The single highest-leverage skill for anyone using AI in professional work is learning to write better prompts. The difference between a useless AI output and a genuinely useful one is usually the prompt, not the model.
Understanding AI limitations is as important as understanding its capabilities. These are not temporary limitations that will be fixed soon -- most are structural features of how the technology works.
Based on professional conduct cases, regulatory guidance, and court sanctions across jurisdictions, these are the risks that materialise most often in law and accounting firm AI use: