Skip to content
    HAQQ
    • Precios
    Comenzar Gratis
    Comenzar GratisReservar una demo
    Iniciar sesión
    1. Inicio
    2. Blog
    3. Comprar la herramienta es la parte fácil: la brecha de implementación de la IA legal
    Guías y Tutoriales

    Comprar la herramienta es la parte fácil: la brecha de implementación de la IA legal

    Los despachos compran IA legal más rápido de lo que forman a su gente. Cuatro políticas, un hábito de verificación y un despliegue que mida algo cierran la brecha que la herramienta no cierra.

    24 de septiembre de 2026
    10 min de lectura
    |
    HAQQ Team
    Comprar la herramienta es la parte fácil: la brecha de implementación de la IA legal

    In short: law firms are buying legal AI faster than they are training for it. Sixty-one percent of legal professionals in one survey say AI saves them time every week, and fewer than half of their firms provide training on responsible use. The tool was never the hard part. Four written policies, one verification habit and a rollout that measures something are, and the firms that skip them end up among the 83% who cannot tell whether the money worked.

    The numbers, dated

    The 8am 2026 Legal Industry Report was fielded between September and October 2025 with more than 1,300 legal professionals. It puts the problem in one sentence:

    Sixty-one percent say AI saves time each week, yet fewer than half of firms provide training on responsible use.

    Usage is running ahead of training, and nothing in the report suggests the gap closes by itself.

    Thomson Reuters's 2025 Generative AI in Professional Services Report, released in April 2025, surveyed close to 1,800 professionals across legal, tax, accounting, corporate risk and government. Among the corporate professionals in that sample, 64% had not been trained to use generative AI for their work. It is a wider population than law firms, so treat it as a second reading on the same dial.

    Axiom's 2026 Legal AI Survey, published on 29 June 2026, surveyed 528 in-house legal leaders across six countries. Only 7% had scaled AI across their organisation, and 83% could not measure whether their AI spending was working.

    Read together, the three describe a deployment problem, not a capability problem. The licence arrives before the process does.

    An earlier draft of this post carried a fourth statistic, on the share of firms that train nobody. We could not trace it to the report it was attributed to, so it is gone, and the three that stayed are dated for that reason.

    Two waves at once

    Most industries digitised first and automated second. Records went into databases, the databases became searchable, and only then did anyone try to automate the work on top. Legal, in much of the world, skipped the first step. Matters still live in scanned PDFs, email threads and a numbering scheme inherited from the filing cabinet. Then AI arrived and asked for both steps at once.

    You can see the result in a pattern we keep meeting. A paper case-numbering system gets reproduced one for one as folders on a shared drive. The folders are then dragged wholesale into a chat tool, because that is where the documents are and the tool accepts uploads. Nobody decided to transfer client files to a third party. The upload did not feel like a transfer. It felt like opening a folder.

    That one gesture contains both mistakes this post is about. The tool was handed the wrong unit of work: a folder, when it needed a question and the two documents the question depends on. And the confidentiality and data residency questions were never asked, because nobody in the chain experienced the drag as a decision. A firm that never structured its records has no policy about them either, and it is now being asked to write one under time pressure while the licences are already running.

    The two duties nobody separates

    Two obligations sit underneath every "can I upload this?" question, and most firms collapse them into one.

    Confidentiality is owed to the client. It comes from the professional conduct rules and, in most systems, from the engagement itself. It is the reason a lawyer hesitates before pasting a term sheet into a chat window. Its remedies are disciplinary and contractual: a complaint, a claim, and in litigation the loss of privilege, the rule that keeps a client's communications with their lawyer out of the other side's hands.

    Data protection and data residency are owed to the law. They constrain where personal data may physically sit, which entity may process it, and what has to be documented before processing starts. The remedies belong to a commissioner, not a client. In the region, the DIFC and the ADGM each run their own data protection regime, and the DIFC's Regulation 10 speaks directly to personal data processed through autonomous and semi-autonomous systems. It was enacted on 1 September 2023 and has been in full enforcement since 1 January 2026.

    Conflating the two produces both failure modes at once. One lawyer uploads nothing, gets no value, and keeps paying for the licence. Another uploads everything and has no idea which duty they just breached, or whether it was both.

    Here is the sentence that costs us something to write, because HAQQ sells anonymization. A vendor's anonymization answers part of the first duty. Strip the client's name, the counterparty, the amounts and the dates before the document leaves your machine, and you have reduced what the client can complain about. It cannot answer the second duty. Anonymization does not move the provider's servers, does not decide which commissioner has jurisdiction, and does not tell you whether processing through that system is permitted for the matter in front of you. Redaction is half of a compliance answer, and the half it covers is the client's half. How to do that half properly, and why [CLIENT] is the wrong placeholder, is in our post on anonymizing a document before you give it to AI.

    The verification gate, in one paragraph

    Courts are not asking the AI to be right. They are asking the lawyer to have read what they filed. In Arabyads v Gulrez Alam, decided in the ADGM Court of First Instance on 18 December 2025, a defence pleading cited authorities that did not exist or did not say what they were cited for. Justice Paul Heath KC found that the firm's failure to verify its AI-assisted research was a deliberate choice, that the checks made on the output were superficial, and that the conduct was reckless. The firm, not the client, was ordered to pay the other side's costs of the wasted costs application, AED 282,508, assessed on the indemnity basis, which is the higher scale a court uses when it wants the order to sting. There is a growing list of these, in the region and elsewhere, and we keep it current in our AI hallucination sanctions tracker; why the most dangerous fabricated citation is the one that looks real is a separate post. We will not restate a count here, because it changes weekly.

    The four policies

    Four documents, each short enough to read in ten minutes, each with an owner and a signature. A firm with a tool and none of these has a licence, not a rollout.

    1. Confidentiality policy

    What may be shared with a third party system, at what level of redaction, and who decides when the answer is not obvious. The anchor is US v. Heppner: in February 2026 a federal court in New York held that documents a defendant produced with a free consumer AI tool were neither privileged nor work product, and left an opening for AI use directed by counsel. A written policy is how a firm shows that the direction existed before the dispute did; we covered the ruling in our post on why AI conversations are not privileged. The partner responsible for professional conduct owns it and the managing partner signs it. Skip it and you lose a privilege argument, and a client learns from a filing what you did with their file.

    Prueba HAQQ AI gratis

    Experimenta la redacción e investigación legal con IA

    2. Data policy

    Where client and personal data may sit, in which jurisdictions, with which vendors, and what happens to it when a contract ends. In the DIFC, Regulation 10 has been in full enforcement since 1 January 2026, and the policy is where you record that you checked what it requires of your entity before the processing started, not after a complaint. The data protection officer owns it if the firm has one; otherwise it belongs to whoever would answer the commissioner's letter, which is the managing partner by default. Skip it and the first question from a commissioner is one you cannot answer, about a vendor contract that says nothing about deletion.

    3. Verification policy

    This is the load-bearing one. Every citation personally read, in the source, not in the summary. Every quotation checked against the document it came from. A named person who signs off before anything is filed or sent, and a record that they did. The practice group heads own it and each supervising partner signs it matter by matter. Skip it and the cost has a figure attached: AED 282,508, and a published judgment with your firm's name in it.

    4. AI use policy

    Which tools are approved, for which tasks, on which accounts, and what gets logged. This is the policy that ends shadow AI: staff using personal consumer accounts for client work because the firm never said what it did want them to use. Whoever runs the firm's systems owns it together with one practising partner, and the managing partner signs it. Skip it and the first two duties get breached at once, on an account you cannot see, with no log to show a court or a commissioner.

    What a real rollout looks like

    Start with a pilot group rather than a licence for the whole firm: eight to twelve people across seniority and practice areas, including at least one sceptic, because the enthusiasts will make any tool look good and the sceptic will find the workflow it breaks.

    Test on a live matter. Every tool passes the demo NDA; that is what the demo is for. A live matter forces the questions the demo hides: what has to be redacted first, where the data goes, who verifies the output and how long that takes. If the verification step takes longer than the drafting step, you have learned something the vendor's deck did not tell you.

    Define the number before the purchase. Axiom found 83% cannot measure whether their AI spend is working. A number nobody defined before signing is a number nobody can measure afterwards. Pick two things you can count today, such as hours to a first draft on a recurring document type, or citation errors caught at review per filing. Measure them for a month without the tool, then for a month with it.

    Put training on the calendar as time with a real document. "Fewer than half of firms provide training on responsible use" is the 8am finding, and the phrase to notice is "responsible use". The session that matters is the one where someone opens a real document, redacts it in front of the group, runs the prompt, and reads the output against the source. That is the whole skill. It takes an afternoon, and it is the afternoon almost nobody schedules.

    Nobody handed you the manual

    The vendors have noticed. On 9 December 2025, a large legal AI vendor and a legal technology consultancy announced an expanded partnership whose entire content is what this post is about: customised training and adoption programmes, onboarding workshops, firm playbooks, change management. The software is sold by one company and the ability to use it by another. Neither is wrong to do it. The market is saying out loud that buying the tool was the easy part.

    Our part in this is small and specific. HAQQ's anonymization runs before a document reaches a model, which answers the part of the confidentiality duty a vendor can answer; the data duty stays yours, and we would rather say so here than have you learn it from a commissioner. Our academy course teaches verification as a habit, with the reading against the source done in the open, and a chapter on rolling AI into a firm without breaking privilege is on its way, as is a free tool for redacting a document on your own machine before you paste it anywhere. The four policies still have to exist. These make them cheaper to follow.

    Write the verification policy this week. It is the one a court will ask about, and the one nobody sells.

    Key takeaways

    • Usage is ahead of training. Sixty-one percent of legal professionals say AI saves them time each week, and fewer than half of firms provide training on responsible use (8am, fielded September to October 2025).
    • Confidentiality is owed to the client. Data protection and residency are owed to the law. Anonymization helps with the first and cannot help with the second.
    • Courts sanction the failure to verify, not the tool. Arabyads v Gulrez Alam, ADGM, 18 December 2025: AED 282,508 on the indemnity basis, ordered against the law firm.
    • Four policies with named owners: confidentiality, data, verification, AI use. The verification policy is the one a court asks about.
    • Pilot on a live matter, define the number before you buy, and put training on the calendar as an afternoon with a real document.
    • 8am, 2026 Legal Industry Report (fielded September to October 2025, more than 1,300 legal professionals)
    • Thomson Reuters, 2025 Generative AI in Professional Services Report, press release, 15 April 2025
    • Axiom, 2026 Legal AI Survey Report, 29 June 2026
    • ADGM Courts, Arabyads Holding Limited v Gulrez Alam Marghoob Alam [2025] ADGMCFI 0032, judgment of Justice Paul Heath KC, 18 December 2025 (PDF)
    • HSF Kramer, AI hallucinations: ADGM Court takes firm stance against misuse of AI in drafting pleadings, 2026
    • DIFC Commissioner of Data Protection, Regulation 10
    • Mayer Brown, AI regulation in the DIFC: personal data processed through autonomous and semi-autonomous systems, January 2026
    H

    HAQQ Team

    Editorial

    Recursos relacionados

    Stop writing [CLIENT]: how to anonymize a document before you give it to AIAre AI Chats Privileged? A Federal Court Says NoAI Hallucination Cases: The Sanctions TrackerHow to Become an AI-Native Law Firm: The Operating Model, Not the Tool List

    Artículos relacionados

    Por qué fracasa la legal tech: 6 trampas y qué funciona de verdad

    Por qué fracasa la legal tech: 6 trampas y qué funciona de verdad

    Deja de escribir [CLIENTE]: cómo anonimizar un documento antes de dárselo a una IA

    Deja de escribir [CLIENTE]: cómo anonimizar un documento antes de dárselo a una IA

    La directriz de IA de Qatar: qué exige realmente la QICDRC n.º 1 de 2026

    La directriz de IA de Qatar: qué exige realmente la QICDRC n.º 1 de 2026

    Preguntas frecuentes

    Why do legal AI rollouts fail?

    Because the licence arrives before the process does. In Axiom's 2026 survey of 528 in-house legal leaders, only 7% had scaled AI across their organisation and 83% could not measure whether the spending was working. The tool works; what is missing is a confidentiality policy, a data policy, a verification policy and an AI use policy, each with an owner, plus a pilot on a live matter and a number defined before the purchase.

    What should a law firm AI policy include?

    Four things, ideally as four short documents. Confidentiality: what may be shared with a third party system and who decides. Data: where client and personal data may sit, with which vendors, and what happens on termination. Verification: every citation read in the source and a named sign-off before filing. AI use: which tools are approved, for which tasks, on which accounts, and what is logged. Each needs an owner and a signature from the managing partner.

    Do lawyers need AI training if the tool is easy to use?

    Yes, and the training that matters is not about features. The 8am 2026 Legal Industry Report found that sixty-one percent of legal professionals say AI saves them time each week while fewer than half of firms provide training on responsible use. The skill to teach is redacting a real document, running the prompt, and reading the output against the source. It takes an afternoon.

    Does anonymizing documents make it safe to use AI for client work?

    It answers part of the confidentiality duty owed to the client, because less identifying information leaves the firm. It does not answer the data protection and residency duty owed to the law, which is about where the data sits and which commissioner has jurisdiction, and it does not make the conversation privileged. Treat anonymization as one control inside a policy, not as the policy.

    Who is responsible when AI invents a citation in a court filing?

    The lawyer who filed it. In Arabyads v Gulrez Alam, the ADGM Court of First Instance found on 18 December 2025 that a firm's failure to verify AI-assisted research was a deliberate and reckless choice, and ordered the firm to pay AED 282,508 in costs on the indemnity basis. Courts do not ask the AI to be right; they ask the lawyer to have read what they signed.

    How should a law firm measure the return on legal AI?

    Define the number before buying. Pick two things you can count today, such as hours to a first draft on a recurring document type or citation errors caught at review per filing, measure them for a month without the tool and a month with it. Axiom found 83% cannot measure whether their AI spend is working; a number nobody defined before signing is a number nobody can measure afterwards.

    ¿Qué sigue?

    Prueba HAQQ AI gratis

    Experimenta la redacción e investigación legal con IA

    Calcula tu ROI

    Descubre cuánto tiempo y dinero HAQQ ahorra a tu bufete

    Explora Prompts legales

    Prompts listos para cada tarea legal

    Volver al Blog

    Artículo anterior

    La IA en los tribunales: cómo los jueces latinoamericanos están trazando la línea

    Artículo siguiente

    Debida diligencia de contrapartes en segundos: Lo que muestran los registros públicos de EE. UU. y lo que omiten

    Tabla de contenidos

    10 min de lectura

    Share this

    Ponlo en práctica

    Hazle a HAQQ la pregunta que te dejó este artículo.

    HAQQ across all devices
    HAQQ Legal AI Platform Logo

    Tu Gemelo Legal de IA y Sistema de Gestión de Práctica para redacción, facturación y éxito.

    Download on theApp StoreGet it onGoogle Play

    Documentaciones

    • Docs se abre en una pestaña nueva
    • Primeros pasos se abre en una pestaña nueva
    • Sala de prensa se abre en una pestaña nueva
    • Novedades del producto se abre en una pestaña nueva
    • Estado se abre en una pestaña nueva
    • Seguridad
    • FAQ se abre en una pestaña nueva
    • Comunidad se abre en una pestaña nueva
    • Soporte se abre en una pestaña nueva

    Academy

    • Socio se abre en una pestaña nueva
    • Curso se abre en una pestaña nueva
    • Noticias jurídicas se abre en una pestaña nueva
    • Habilidades se abre en una pestaña nueva
    • Cláusulas se abre en una pestaña nueva
    • Biblioteca de prompts se abre en una pestaña nueva
    • Herramientas se abre en una pestaña nueva
    • Centro de investigación se abre en una pestaña nueva
    • Documentos se abre en una pestaña nueva

    Sitio web

    • eFirm
    • Chat IA Legal
    • Aplicación Móvil
    • Motor Justiniano
    • HAQQ eBar
    • HAQQ eWallet
    • Precios
    • Compáranos
    • Soluciones
    • Blog
    • Conocer equipo
    • Únete a nosotros se abre en una pestaña nueva
    Abrir la app
    • Idiomasenarfresitdeptrohi
    • Contactoinfo@haqq.ai
    • Estadooperativo·fundamentado
    • Términos de Servicio
    • Política de Privacidad
    • Política de Cookies
    • Procesamiento de Datos
    • Humanos se abre en una pestaña nuevaAbogados se abre en una pestaña nuevaSeguridad se abre en una pestaña nueva
    © 2026 HAQQ Inc. Todos los derechos reservados.Producto desarrollado internamente por HAQQ. Sitio web construido con herramientas web modernas.