Look at the AI stack of a firm that has been buying enthusiastically for two years and you will usually find four or five logins. One tool for research. Another for contract review. Something for document analysis. Maybe a separate enterprise product the risk team bought to keep an eye on all of it. Each was chosen well, on its own merits, to solve one clear problem.
Then a single matter comes in and needs three of them, and the seams show. The research tool does not know what the drafting tool produced. The compliance product sits to one side, governing in the abstract, unaware of the specific output either tool just generated. And the question of who holds the unified record of what the AI did across the whole matter has no owner, because no single tool was built to hold it.
That is the pattern worth naming. Most AI tools for law firms are narrow, single-scope products. They are very good at one job in the workflow and were never designed to do the other jobs, least of all the governance. So a firm stacks them and stitches the gaps by hand, which means the hardest half of the problem, proving the work was done safely, is left to a spreadsheet and good intentions.
The market splits into two camps, and neither is the whole answer
Step back from individual products and the legal AI market resolves into two broad camps, built around opposite priorities.
On one side are the tools built around doing the work. Products in the mould of Harvey, Legora, or Luminance are optimised for productivity: drafting, research, contract and document review, getting the legal output produced faster. This is the visible, exciting half of legal AI, and these tools are genuinely capable at it.
On the other side are the tools built around governing at scale. Products in the mould of OneTrust or Norm Ai come from the compliance and risk world. They are enterprise-scale governance and policy tooling, and they are not built to perform legal work at all. They watch, they document, they manage policy, but they do not draft the memo or review the contract.
Practical rule: The productivity tools do the work but do not govern it. The enterprise compliance tools govern but do not do the work. A firm that wants both, which is every firm using AI on live matters, ends up buying from both camps and becoming the integrator itself.
That integration is the unglamorous, unpriced job that falls on the firm. The market optimised each product for one part of the workflow, and left the connective tissue, and the accountability, as the customer's problem.
| Productivity tools | Enterprise compliance tools | Governance built in | |
|---|---|---|---|
| Built to | Do the legal work | Manage policy and risk | Do the work and govern it |
| Does the legal work | Yes | No | Yes |
| Governs the AI output | No | At policy level, after the fact | Before and after every action |
| Unified audit trail per matter | No | Partial, external | Yes, as a by-product |
| Who does the integration | The firm | The firm | Built in |
What fragmentation actually costs a firm
The cost of a stacked, stitched-together approach is not mainly the licence fees. It is four quieter things that compound.
Different tools cover different scopes, with gaps between them. Each product draws its own boundary. The matter does not respect those boundaries, so work falls through the seams and no tool owns the whole of it.
Governance gets bolted on after the fact. When the compliance layer is a separate product from the tools doing the work, governance happens after the output already exists. The tool produces; then, separately, something tries to check. That is the wrong order, and we made the fuller argument in why an AI policy is not AI governance.
Every additional vendor is another relationship a COLP has to assess. This one is underrated. Each AI tool that touches client data is a data-handling relationship the firm has to justify. Under UK GDPR Article 28, a firm using a processor has to have the right contractual terms and has to satisfy itself the processor offers sufficient guarantees. The COLP carries the regulatory weight of that assessment. Five tools is five due-diligence exercises, five sets of terms, five places client data can sit. Fragmentation is not just an IT cost. It is a compliance surface area.
There is no single, unified audit trail. This is the heart of it. When five tools each keep their own partial log in their own format, there is no one place that shows what the AI did across a matter, what it relied on, and who checked it. The record a supervising partner, an insurer, or the SRA would want to read does not exist as a single artefact. It has to be assembled by hand, after the fact, if it can be assembled at all.
Productivity or governance is a false choice
The stacked approach quietly forces a choice no firm should have to make: move fast with the productivity tools, or be safe with the compliance tools, and reconcile the two yourself.
Most firms, under pressure to show AI is delivering, pick productivity and promise themselves the governance will follow. So the tool produces the output first, and verification comes later, if it comes. That order is exactly backwards for a regulated profession. The whole value of governance is that it happens before the work is relied on, not after a problem surfaces.
Field note: The tell is the sequence. Ask a firm how its AI is governed and if the honest answer is "the tool produces the draft, then someone is supposed to check it," governance is a hope bolted onto the end. The firms that have actually solved this describe governance as something that happens before and around the work, not a review step someone might skip when busy.
The false choice only exists because the market sold the two halves separately. It disappears the moment the work and the governance are the same system.
Built in versus bolted on
That is the real distinction, and it is not a slogan. It is an architecture.
Bolted on means governance is a separate layer added to tools that were designed without it. The check comes after the output, in a different product, in a different format, run by a different team. It can be skipped, it can lag, and it never sees the moment the work was actually made.
Built in means the governance runs inside the work itself. The checks happen before an agent acts and after it produces, as part of the same pipeline, so there is no version of the output that exists ungoverned. The audit trail is not assembled later from five logs; it is a by-product of the work, generated as the work happens.
The difference shows up on the day it matters. A firm with bolted-on governance, asked to show what its AI did on a matter, starts a reconstruction project. A firm with built-in governance opens the record, because the record produced itself.
Where LegalAI Space sits
We built LegalAI Space on the other side of that line. The agents do the legal work, research, contract review, due diligence, matter management, and every one of them runs inside a single governance layer, not beside one. The checks run before each agent acts and verify after it produces, and every output is tied back to its source and captured in one audit trail across the whole matter. Governance first, in the same system as the work, rather than a compliance product bought to watch a productivity product from the outside.
That does not make the productivity tools bad at what they do. It makes them half of an answer. The firm using them still has to be the integrator, still has to bolt the governance on, still has to assemble the record by hand. Built in removes that job, because the record and the work are never two things.
Which situation are you in
If you have one AI tool and no governance layer, your gap is the most urgent: you have productivity and no proof. Close the governance side before you buy more capability, or you are just scaling unverifiable output.
If you have a stack of specialist tools already, your problem is the seams and the audit trail. Before adding a sixth product, ask where the single, unified record of what your AI did actually lives. If the answer is "nowhere, we'd have to pull it together," that is the half you have not solved. We compared the specialist options in the best legal AI tools for lawyers and the governance-side options in the best AI governance tools for law firms.
And if you are choosing your first serious AI platform now, the question to lead with is not "which does the work best?" Every capable tool does the work well. It is "does the governance come built in, or will I be bolting it on for the next three years?" That question decides whether you have bought half the answer or all of it.
LegalAI Space builds AI agents for legal teams with a governance layer that makes every output verifiable, compliant, and audit-ready. Sign up for early access or book a pilot call with Founder Daman Kaur.
FAQ
Why do most AI tools for law firms only solve half the problem? Because they are single-scope. Productivity tools do the legal work but do not govern it; enterprise compliance tools govern but do not do the work. A firm using AI on live matters needs both, so it ends up stacking products and stitching the governance and the audit trail together by hand.
What does a fragmented AI stack actually cost a firm? Four compounding costs: gaps between tools that each cover a different scope; governance bolted on after the output already exists; a separate data-handling relationship for the COLP to assess for every vendor; and no single, unified audit trail of what the AI did across a matter.
What is the difference between built-in and bolted-on governance? Bolted-on governance is a separate layer added to tools designed without it, so the check comes after the output, in another product. Built-in governance runs inside the work itself, before and after each action, so no ungoverned version of the output ever exists and the audit trail is a by-product of the work.
Do I have to choose between productivity and governance? No, and the choice only appears because the market sells the two halves separately. When the work and the governance are the same system, the output is governed as it is produced, so you get speed and proof together rather than trading one for the other.
Where does LegalAI Space fit against tools like Harvey or OneTrust? Productivity tools do the work without governing it; enterprise compliance tools govern without doing the work. LegalAI Space does the legal work and governs it in one system, so governance is built into the workflow and the audit trail spans the whole matter rather than living in five separate logs.
Sources
-
SRA, Standards and Regulations, Code of Conduct for Firms, Rule 2.1 (effective governance, systems and controls) and Rule 2.2 (records to demonstrate compliance), which the firm, not any single tool, is accountable for.
-
Information Commissioner's Office, Contracts and liabilities between controllers and processors under UK GDPR. Article 28 requires appropriate contractual terms and that a processor offers sufficient guarantees, the assessment every additional AI vendor adds.
Related reading
- The best legal AI tools for lawyers: the productivity side of the market, compared.
- The best AI governance tools for law firms: the governance side, compared.
- Why an AI policy is not AI governance: why bolted-on governance is the wrong order.