Governance

The real gap in generative AI governance is not “whether it can be used,” but “which decisions we should entrust to machines.”

Law firms are shifting from banning the use of generative AI to requiring lawyers to incorporate it into their daily work. But what is truly lacking is not a usage policy, but governance over the division of cognitive tasks: which steps can be handed over to AI, and which must remain subject to human professional judgment.

The real gap in generative AI governance is not “whether it can be used,” but “which decisions to hand over to machines”

Law firms’ attitude toward generative AI is undergoing a classic shift in corporate governance: from “cautious prohibition” to “active adoption.” The former focuses on data leakage, fabricated citations, and confidentiality risks; the latter emphasizes efficiency, competitiveness, and client expectations. Superficially, this shift seems to mean the industry has already completed its digital upgrade. But the deeper issue is precisely that many institutions have only updated their rules for “allowing use,” without rebuilding the governance of “how to use” it.

This is also the most important issue to watch in the professional services sector right now. Policy texts often stipulate “do not disclose client information,” “verify hallucinations,” and “embrace AI,” yet rarely answer a truly decisive question about quality and accountability boundaries: in a specific workflow, which kinds of cognitive functions can lawyers delegate to AI, and which must remain with human professional judgment?

This question matters because the impact of generative AI on professional work is not a linear “efficiency gain.” In some tasks, it can indeed expand the scope of retrieval, speed up information organization, and help generate alternative options. But in other tasks, it may also induce overconfidence, compress careful reasoning, and weaken complex judgment. In other words, AI does not simply “make work faster”; it is redistributing cognitive labor, and the way cognitive labor is allocated determines the ceiling of an organization’s capability.

What the professional services sector really needs is not generalized policy, but “cognitive division of labor governance”

From a corporate strategy perspective, the governance dilemma law firms face with generative AI is highly similar to the problems many multinational companies encounter in AI transformation. Initially, companies treat AI as a source of risk that needs to be isolated, so they create bans, whitelists, and approval mechanisms. Then market pressure and client demand push companies to turn AI into a capability they must embrace, requiring teams to use it in daily work. The problem is that both stages remain at the level of “whether to use it,” without moving into the level of “how to allocate cognitive tasks.”

That is exactly where the governance gap lies.

Rather than asking, “Can this document be done with AI?” it is better to ask, “In this work, which functions are retrieval, organization, summarization, generation of candidate solutions, editing, and critical review, and which belong to final judgment?” Once the question is redefined this way, the governance framework no longer revolves around the tool itself, but around the work mechanism. For legal services, consulting, auditing, research, and other knowledge-intensive industries, this shift is especially critical because their core value is not just producing text, but converting complex information into dependable professional judgment.

1. Retrieval and organization: the low-risk stage where AI is best suitedIn phases with low cognitive load, AI’s value is clearest. For example, when a lawyer asks a system to identify clauses in a contract or to piece together a timeline from multiple witness statements, what is essentially being invoked is AI’s ability to retrieve and organize information. These tasks do not create new facts, nor do they require the model to make final judgments, so the risks are relatively controllable.

The strategic significance of these applications is not just “saving time.” For large professional organizations, retrieval and organization capabilities directly affect delivery costs, service speed, and the efficiency of knowledge reuse. They determine whether an institution can free high-value human talent from repetitive labor and shift it toward higher-level analytical and negotiation work. For clients, this means faster responses; for law firms, it means greater operational efficiency and stronger profit elasticity.

But this kind of low-risk scenario also has a frequently overlooked problem: many organizations are overly conservative in governance, which instead limits the scenarios that are truly suitable for AI, causing value to go unrealized. Real maturity in governance is not blanket suppression, but precise differentiation.

2. Summarization and compression: as efficiency improves, selection risk also emerges

When AI starts summarizing, distilling key points, or integrating information from multiple sources, the risk rises significantly. Because once a system decides “what should be retained and what should be omitted,” it is no longer just a tool; it is participating in information selection.

This is especially sensitive in legal and compliance work. Internal investigation materials, board reports, and regulatory communication documents are often not a matter of “the more information, the better,” but rather “which information is emphasized and which is downplayed” directly affects organizational decision-making. AI is good at compressing content, but it does not inherently understand what constitutes a “critical detail.” A human lawyer who is unusually sensitive to procedural nuances may spot a credibility issue in a witness statement at a glance, while the model may classify it as ordinary background information.

Therefore, the most important thing for summarization tasks is not “more automation,” but “who does the review.” If the reviewer does not understand the original materials, they cannot accurately judge whether AI has omitted something truly important. The governance logic here is already close to the control framework for high-risk organizations: the system can accelerate, but it cannot replace informed review.

3. Candidate generation: AI is good at expanding options, but cannot replace professional choice

When drafting memoranda, pleadings, compliance opinions, or board materials, AI is often used to generate initial arguments, alternative phrasings, or reference cases. The value of this kind of use lies in helping professionals enter the “space of discussable options” more quickly.

This is also one of AI’s most productive moments in knowledge work: it expands alternatives, shortens iteration cycles, and allows teams to move from a blank page to structured thinking more quickly. But the boundary of this capability is equally clear — candidate material is only candidate material, not a conclusion ready for direct delivery.The real governance focus lies in the fact that AI-generated content is often fluent, well-structured, and even looks “real.” This creates a dangerous illusion: organizations may mistake fluent output for reliable judgment. For precedents, regulations, or factual background cited in external documents, professionals must still verify independently. Generative AI can help find materials, but it cannot replace reading, understanding, and application.

From a broader corporate governance perspective, this kind of risk points to one fact: in industries with high professional barriers, efficiency gains often come before control capabilities mature, and if control capabilities are not established in time, they will turn efficiency dividends into reputational risk.

4. Editing and rewriting: the most easily underestimated risk of “semantic drift”

Compared with generating new content, rewriting old content seems safer, but in practice it may not be. Because editing tasks are, by nature, about modifying existing wording, and subtle semantic changes can alter the boundaries of responsibility, the scope of rights, or the strength of commitments.

In legal texts, this risk is especially typical. A sentence that seems more concise may quietly narrow the scope of a statement; a smoother paragraph may unknowingly delete a key exception clause. AI’s advantage in the editing stage is the speed of polishing, while its weakness is that it cannot continuously sense, like an experienced lawyer, the legal consequences behind changes in wording.

This also explains why some stronger professionals may actually produce worse results under AI-assisted editing. The more capable a person is, the more likely they are to believe they can quickly spot deviations; as a result, they may relax their review because they over-rely on AI’s fluent expression. This phenomenon offers a lesson for all professional organizations: AI is not only risky for junior staff; it can also induce cognitive slack in senior employees.

5. Challenging and pressure testing: AI’s most underestimated governance function

Many organizations use AI to produce output, but rarely treat it as a “counterargument generator.” In fact, before submitting a pleading, issuing compliance advice, or preparing regulatory communications, having AI actively find flaws, search for loopholes, and simulate opponent attacks is often more valuable than letting it “write faster.”

This is very close to the risk management logic of mature enterprises: not merely pursuing efficiency, but exposing vulnerabilities in advance. For law firms or corporate legal departments, AI at this stage is more like a stress-testing tool than a decision-maker. Its role is to identify problems ahead of time, not to replace final judgment.

The real boundary: when AI begins to “evaluate” and “decide,” professional responsibility cannot be outsourced

No matter how useful AI may be in the foregoing stages, there is a boundary that cannot be crossed: final evaluation and decision-making cannot be handed over to the model.

For example, whether a certain event should be disclosed, whether a settlement should be accepted, whether a client should be advised to take a certain legal action—these are not ordinary text tasks, but a concentration of professional responsibility. The model can provide background information, list comparative options, and flag potential consequences, but it cannot replace a lawyer in making the final decision.This point does not apply only to the legal industry. For any high-responsibility sector—auditing, healthcare, finance, compliance, investment—the governance boundaries for AI should be built on the same principle: it may assist cognition, but it may not assume responsibility; it may expand information-processing capacity, but it may not replace core judgment.

In the long run, this will change the organizational design of professional service firms. The more competitive firms in the future will not necessarily be the ones that “use AI the most,” but the ones that are most clear about “which steps must retain human responsibility.” Because in high-trust industries, the source of capability is not only efficiency, but also explainability, accountability, and verifiability.

For the professional services industry, AI governance is becoming a new dividing line of competitiveness

In the generative AI era, the key to corporate strategy is not just the rate of technology adoption, but whether an organization can establish a new control system. For law firms, this means the governance framework needs to be upgraded from “data security” to “cognitive risk management”; from “permitted use” to “fine-grained authorization by task type”; from “tool policy” to “workflow governance.”

These changes will have three long-term effects.

First, the degree of productization in professional services will increase. AI will accelerate repetitive analysis, standardized retrieval, and junior drafting, pushing the industry to define more clearly which work can be automated and which cannot. The result will not be lawyers being completely replaced, but the service structure being re-tiered.

Second, organizational differences will widen. Those firms that can embed AI into workflows while maintaining strict review and accountability boundaries will gain advantages in cost, speed, and consistency; while those that remain at the level of slogans or prohibitions will be unable to release efficiency and unable to avoid risk.

Third, client expectations of professional firms will change. In the future, clients will not only ask, “Do you use AI?” but will care more about, “How do you ensure AI does not replace critical judgment?” This means AI governance itself will become part of professional credibility, and even part of the brand.

Conclusion: Policy is not governance; governance must answer how responsibility is allocated

At present, many law firms’ AI policies look quite complete: they have data protection requirements, usage reminders, and risk warnings. But what truly determines organizational quality are not these general clauses, but more detailed questions—at each work stage, which cognitive functions can be delegated to AI, and which must be retained by humans.

This is not only a problem for the legal industry, but a common problem facing the entire knowledge economy. AI is reshaping the division of labor within organizations, and once that division changes, governance structures, chains of responsibility, and professional standards must be updated accordingly.

In other words, the most mature governance in the generative AI era is not telling employees whether they “can use it,” but clearly telling them: when AI can make work better, faster, and cheaper; when it will make work shallower, more biased, and more dangerous; and at which critical moments human judgment remains irreplaceable.

---## SEO Description Generative AI is entering the core workflows of legal services and professional organizations, but most enterprises still remain at the shallow governance level of “permitted use.” From the perspectives of corporate strategy, organizational control, and professional responsibility, this article analyzes why law firm AI policies are insufficient and how to establish a more effective AI governance framework through cognitive task division.

Information Source URL https://www.thomsonreuters.com/en-us/posts/technology/genai-governance-gap/

Disclaimer This article is an original business analysis and reinterpretation based on publicly available reference materials, and does not constitute legal advice or investment advice.

Source boundary · corpinsight

corpinsight frames this note through Strategy / Industry / Governance (Strategy / Industry / Governance explains the local editorial angle). Source links should be opened before the summary is reused; dates, names and status changes still need checking.

Source links

  1. https://www.thomsonreuters.com/en-us/posts/technology/genai-governance-gap/Primary

Related articles

Back to channel