Govern the estate

Every AI tool in the firm, on the record.

Ask a managing partner which AI tools their firm uses, who approved each one, and under what policy. In most firms that answer lives in nobody's head. The register makes it a living record instead, with usage flowing in automatically where a vendor exposes it and by attestation where none exists.

app.legalaispace.com/admin/ai-register

AI register

5 tools registered · 1 pending review · AI use policy in force

LegalAI Space agents

Approved

Governed risk · COLP · Native evidence

Harvey

Approved

High risk · COLP · Usage API

Microsoft Copilot

Approved

Medium risk · IT director · Audit-log ingest

ChatGPT, personal accounts

Not permitted

Shadow risk · Unassigned · Attestation only

A practice-area tool under evaluation

Under review

High risk · Head of KM · Manual, quarterly

Register a toolEdit the AI use policySend attestation roundExport register

Illustrative. Note the fourth row: the register is built to hold the tools a firm has not approved as readily as the ones it has.

Honesty by design

The register states what each entry rests on.

A governance record that implies telemetry the vendor does not have is worse than no record, because someone will rely on it. Every row carries its evidence depth on the face of it.

01

Native evidence

Work run through our own agents or through Check this. We hold the full record: what ran, what was verified, who signed it off.

02

Usage API

Where a vendor exposes usage or query history, we ingest it. We know a tool was used, by whom and when, but not what we did not run.

03

Audit-log ingest

Where an enterprise platform exposes compliance logs, we consume those. Coverage is whatever the platform chooses to log.

04

Attestation only

No feed exists. The entry rests on what a named person declared, and the register says so on the face of it.

We do not put agents on endpoints and we do not intercept traffic. Where a vendor exposes a usage feed we consume it. Where none exists, the register says the entry is attested, and the exported report states the basis of every figure in it.

The first two weeks

What a COLP actually does.

Finite, ordered, and mostly not technical. The point at which the register stops needing you is step five.

1

Run the readiness check

Ten minutes against 70 controls. You get a gap report that tells you which of the following steps your firm actually needs.

2

Take the policy pack

An SRA-aligned AI use policy, templated in. One call to tailor the interpretations to how your firm works.

3

Declare the estate

List the tools. Connect the feeds where the vendor exposes one. Record the rest honestly as attested.

4

Ask staff to attest

Fee-earners acknowledge the policy and confirm what they use. Training is tracked against the same record.

5

Let evidence accumulate

From that point the register fills itself. Checks, sign-offs and usage populate the COLP dashboard without anyone maintaining a spreadsheet.

Questions

The AI register, answered.

What a register is for, what it can honestly show, and what we deliberately do not do.

Still have questions? Talk to the founder
There is no rule that names one. The SRA regulates outcomes rather than tools, so the obligations that apply are the ones a firm already has: effective governance and systems and controls, records that demonstrate compliance, and identifying and managing material risks. A register is simply the practical way most firms satisfy those when several AI tools are in use. Its updated compliance guidance of 9 February 2026 also states that the SRA would expect, as a minimum, the COLP to be responsible for regulatory compliance when new technology is introduced.

From the blog

Getting the estate onto paper

What belongs in a register, what belongs in a policy, and why the two are not the same thing.

Find out what your register would say today.

The readiness check covers the register alongside eleven other governance domains, and tells you which gaps to close first.