Governance Core

The firm's AI supervision record, in one place.

A register of every AI tool, a policy engine that runs on every governed task, a COLP dashboard over the whole estate, and a tamper-evident evidence chain underneath. Not a pilot. Compliance infrastructure, with a renewal date.

Grounded inBAILIIlegislation.gov.ukEUR-LexHUDOCCURIACourts.ie

What it is

Four parts, one record.

Each part is useful on its own. What makes it a system of record is that they all write to the same evidence chain.

01

The register

Every AI tool in the firm, who approved it, at what risk tier, under what policy, and how each entry is actually substantiated. Shadow tools included.

Inside the register
02

The policy engine

Your AI use policy, running as code rather than sitting in a document. 19 checks on every governed task: 13 protocols and 6 deterministic gates, mapped to the SRA duties they answer.

03

The COLP dashboard

One worklist and one set of numbers across the whole estate, with per-tool provenance on every figure. Failing signals rank first, and every flagged item carries an action.

04

The evidence chain

Every governed event hashed, linked to the one before it and immutable at the database level, with exports shaped for a regulator, an insurer or a client.

Inside the evidence chain

The COLP dashboard

Risk before vanity metrics.

A supervision screen that opens on what needs a decision, with per-tool provenance on every number. Amber says a closer look is needed, never panic.

app.legalaispace.com/admin/governance

COLP dashboard

All tools

AI outputs governed

312

last 30 days

Citation pass rate

94%

up 3 points

Fabrications caught

17

4 from external tools

Open flags

3

1 blocking

Worklist, needs a decision

Fabricated authority in an external tool's output

BlockingReview

Information-barrier warning on a draft

Needs a closer lookReview

Three citations we could not auto-confirm

Needs a closer lookAssign

Data protection review due on a register item

TaskOpen

By tool, pass rate and volume

LegalAI Space agents

97%184

An AI assistant

91%76

A general-purpose copilot

88%39

Unattributed

not measured13
Export audit reportInspection bundle

The COLP

The whole estate, worklist first. Which tools are producing work, what proportion of citations pass, what was caught, who signed off, and what still needs a decision today.

A supervising partner

Their team's matters and their own sign-offs, without the firm-wide noise. Oversight scoped to what they are actually accountable for.

A fee-earner

Their own record and nothing else. Framed as protection rather than surveillance, because a supervision tool that reads as monitoring gets routed around.

The guardrails

Two protocols. One before the work, one after.

Governance is not a setting a fee earner can switch off. Named guardrails run automatically on every agent. One protocol clears the matter before any work begins; the other checks the output before a lawyer ever sees it. Nothing skips them.

19 named protocols and gates ship with the platform, 6 of them deterministic Layer-3 gates enforced in code, not by a model. Each agent implements them through its own protocol stack. Nothing skips them.

Pre-run protocolsCleared before anything happens

Conflict Check

SRA 6.1 / 6.2

Screens the matter against connected CRM and practice-management data before a single keystroke of work. A conflicted matter never starts.

Jurisdiction Gatekeeper

Blocks work that mixes jurisdictions the matter is not configured for. A Scottish authority cannot reach an English matter.

PII Redaction

Detects and redacts personal data from agent inputs before processing: confidentiality enforced at the door, not audited after.

Planning Protocol

Writes a step-by-step plan before execution, jurisdictions, authorities, privilege concerns, and holds it for approval. The run is deliberate, not improvised.

In-run & post-run protocolsChecked before a lawyer sees it

Legal Citation Verifier

BAILII · legislation.gov.uk · EUR-Lex

Independently re-fetches and verifies every citation against the primary source: format, existence, current status. We do not trust the model's recall: we re-check its homework.

Regulatory Compliance Check

SRA · FCA · ICO · EU AI Act

Evaluates the output against the SRA Code, FCA rules, ICO guidance and the EU AI Act: rule by rule, with a severity on every finding.

Output gate: draft, never advice

Every output is marked a draft for a qualified lawyer. Send-gated agents (pre-action, cease-and-desist, DSAR) never deliver on their own. A person sends them.

The guardrails named above are not the whole set. 19 protocols and gates ship in the catalogue. The rest run on the same automatic basis, none of them optional.

Human approval gateSource provenanceCase treatment signalsHallucination SentinelSource Freshness CheckPrivilege ReviewQuote-Verbatim GateConfidence Floor GateCitation Match-Set GatePrivilege Drop GateProvenance Label GateQuality Gate
LIVEapp.legalaispace.com/library: the governance catalogue
The live governance library: 19 named protocol and gate cards, Citation Verification, Hallucination Sentinel, deterministic Layer-3 gates and more, each tagged Pre-Run, Post-Run or On Demand and active on the platform

The register

Including the tools nobody approved.

The entries that matter most are the ones a firm would rather not write down. The register states the evidence depth behind each row, so nobody mistakes an attestation for telemetry.

app.legalaispace.com/admin/ai-register

AI register

5 tools registered · 1 pending review · AI use policy in force

LegalAI Space agents

Approved

Governed risk · COLP · Native evidence

Harvey

Approved

High risk · COLP · Usage API

Microsoft Copilot

Approved

Medium risk · IT director · Audit-log ingest

ChatGPT, personal accounts

Not permitted

Shadow risk · Unassigned · Attestation only

A practice-area tool under evaluation

Under review

High risk · Head of KM · Manual, quarterly

Register a toolEdit the AI use policySend attestation roundExport register

The evidence chain

What comes out at the end.

Each governed event is hashed and linked to the one before it. Change an earlier link and every hash after it stops matching.

run_started

hash 9f41…c2

citations_verified

prev 9f41…c2

policies_evaluated

12 linked verdicts

human_review

named reviewer

certificate_issued

insurer pack

report_exported

sha256 anchored

The exports are shaped for whoever is asking: an SRA-aligned period audit report, a per-run evidence pack, a PI insurer pack, a client AI-use disclosure, an EU AI Act oversight attestation, or a frozen inspection bundle.

Regulatory landscape

The obligation is already here.

01In force now

The SRA Standards and Regulations

The SRA already requires proper governance, competence and a record of how work was produced. Every one applies to AI-assisted work today, because the regulator does not wait for new rules.

022025 to 2026

Courts sanctioning unverified AI

In Ayinde v London Borough of Haringey and Al-Haroun v Qatar National Bank, handed down 6 June 2025, the Divisional Court addressed fabricated authorities in court filings and referred individuals to their regulators. An unverified output is a professional risk, not a convenience.

032 December 2027

EU AI Act, high-risk obligations

The AI Omnibus, in force 27 July 2026, moved the high-risk application date from 2 August 2026 to 2 December 2027 for standalone systems, and to 2 August 2028 where the AI is embedded in a product. Transparency duties and the record-keeping expectation are unchanged, and most off-the-shelf tools still cannot export the record.

04Ongoing

The record is the deliverable

When an inspection comes, the question is the same: can you prove this output was governed? A signed, reproducible audit record is the answer, written as the work happens rather than assembled the night before.

From the blog

Governance, built in

Why a policy document is not a control, what a governance framework has to cover, and what an SRA-ready audit report must prove.

Questions

Governance Core, answered.

What it covers, how it differs from generic compliance tooling, and what it takes to stand up.

Still have questions? Talk to the founder
The firm's record of how AI was actually used: a register of the tools, a policy engine that runs on every governed task, a COLP dashboard over the whole estate, and a tamper-evident evidence chain underneath the lot. It is compliance infrastructure with a renewal date, not a pilot.

Governance, before the regulator asks for it.

Start with the free readiness check, or tell us what your firm is running and we will show you what the record would look like.