---
title: "Legal agents inside the organisation"
description: "A framework for governed legal agents inside an organisation: attention, research, challenge, decision, action and institutional memory."
language: "en-CH"
source: "/agents/"
type: "framework"
author: "Jonas Hertner"
published: "2026-08-27"
modified: "2026-08-27"
---

# Legal agents inside the organisation

For boards, shareholders, general counsel and legal teams assessing where agents belong in an enterprise.

The relevant question is not whether a model can produce a legal answer. It is whether the organisation can notice what requires attention, assemble authoritative context, test possible courses, allocate responsibility and carry an approved decision into the business.

<a id="system"></a>

01 / System

## The primary unit of control is an accountable decision.

Here, a legal agent is software that receives a defined task or event, retrieves permitted context and produces a bounded work product or proposed action. An agentic legal function governs how those outputs lead from a material change or question to evidence, challenge, an authorised decision and verified implementation.

Many legal AI deployments are attached to a task: search, summarise, compare or draft. That can improve an individual task without changing how legal work moves through an organisation.

An organisational system can begin before a request, remain active between human interactions and extend beyond an answer. Within defined coverage and permissions, it receives external and internal events, tests their relevance against current company facts, opens or updates a decision record, initiates research and independent challenge, routes the matter to its accountable owner and keeps it under review until an evidenced disposition is recorded. It brings an issue to judgment; it does not assume authority to decide it. Model output is an intermediate work product.

Model capability is only one constraint. The organisation must also redesign its sources of truth, handoffs, decision rights, incentives, review duties and ownership of exceptions. Technical readiness can therefore precede organisational readiness. If the operating path remains unchanged, automation adds another output to it.

Task assistance

### An output

A person supplies the context, asks the question, checks the answer and carries it into the organisation. The tool stops when the text is produced.

Decision system

### A controlled process

The trigger, sources, decision rights, challenge, approval, resulting actions and evidence of closure are part of one governed record.

01.01 / Decision object

### The durable record

#### 01 / Trigger / Why now

The event, affected entity, product, market or matter; the owner; the deadline; and the decision requested.

#### 02 / Record / What is known

Facts and exact sources; applicable authority and company policy; temporal scope; assumptions; contradictions; and unresolved questions.

#### 03 / Judgment / What follows

Available courses, relevant trade-offs, the proposed position, the strongest contrary case and the uncertainty that remains.

#### 04 / Authority / Who decides

The authority basis, required approvals, dissent, the decision and any conditions attached to it.

#### 05 / Action / What changes

Tasks, controls, contract positions, disclosures or system changes; their owners and due dates; and the evidence required for closure.

#### 06 / Outcome / What was learned

The result, assumptions that proved wrong, conditions that should reopen the decision and any proposed change to policy.

<a id="loop"></a>

02 / Loop

## A workflow is closed only by an evidenced disposition.

The operating loop connects changes in law and business to an owned decision. Implementation, express rejection, deliberate deferral and monitored non-action can each be valid dispositions. Each requires a rationale, owner, durable record and, where applicable, conditions, a review date or a reopen trigger.

### 02.01 / Observe

Receive a material external development or internal business event from the systems in which it occurred.

**Required record:** The original event, source, time, status and affected perimeter.

### 02.02 / Prioritise

Assess materiality, urgency, uncertainty, reversibility and the authority required. Suppress duplicates without concealing severe outliers.

**Required record:** Why the signal matters, who owns it, when action is due and which decision is requested.

### 02.03 / Recall and research

Retrieve authorised internal facts and external law. Separate evidence, inference, company policy and prediction.

**Required record:** A proposition–evidence map, contrary authority, temporal cutoff and material gaps.

### 02.04 / Challenge

Test the principal case independently against facts, authority, alternative interpretation, evidence, operational feasibility and the likely adversary.

**Required record:** A challenge ledger showing the attack made, result, residual uncertainty and stop condition.

### 02.05 / Decide

Present distinct courses, assumptions, consequences and the strongest case against the proposed position to the authorised person.

**Required record:** The decision, authority basis, rationale, dissent, conditions and residual risk.

### 02.06 / Act or monitor

Translate an approved course into changes in the systems where the business works, or record the approved basis and conditions for deferral, rejection or monitoring. Consequential writes remain subject to the relevant approval.

**Required record:** Action owner, due date, target system, approval, execution receipt and reversal route; or review owner, review date and reopen trigger.

### 02.07 / Learn

Compare the outcome with the assumptions and capture corrections. A repeated exception may justify a proposed policy change; it does not become policy by repetition alone.

**Required record:** Outcome, correction cause, reopen trigger and any authorised promotion into institutional knowledge.

<a id="architecture"></a>

03 / Architecture

## Keep authority at the source; join context narrowly.

A business system remains authoritative for its own internal facts; official or otherwise legally recognised sources remain authoritative for external law. Agents assemble the minimum context required for a defined purpose through permissioned interfaces. They do not receive undifferentiated access to the enterprise.

03.01 / Capabilities

### Six functions

#### 01 / Memory / Preserve distinctions

Matter history, approved decisions, policy, external law and observed outcomes remain separate. A draft, conversation or negotiated exception does not become organisational policy merely because it was stored.

#### 02 / Attention / Allocate judgment

Attention begins with a coverage register: jurisdictions, authorities, courts, standards, markets, products, sources, known blind spots and review cadence. Within that perimeter, developments in external sources and events from internal systems are compared with the entities, products, contracts, controls and prior decisions they may affect. The resulting assessment is not a news summary. It states the cited change, applicability hypothesis, affected perimeter, evidence, owner, deadline and decision requested. Anything less adds queue volume without establishing control.

#### 03 / Research / Join law and fact

External authority and internal company facts are researched together. A legally sound proposition applied to the wrong entity, product, data flow or contract remains a wrong answer.

#### 04 / Red team / Seek disconfirmation

The challenger uses an independent path where the consequences justify it. Independence may require different retrieval, assumptions, model, evaluator or human review. Asking the producing model to reconsider its own answer is not independent assurance. The task is to find defects capable of changing the decision, approval level, evidence required or implementation plan.

#### 05 / Interfaces / Bridge silos narrowly

Departmental systems publish defined facts and events through purpose-bound interfaces. Permissions apply to the user, agent, matter, purpose and time; not merely to a broad role.

#### 06 / Actions / Control write-back

Agents propose commands through an action gateway. Consequential changes require validation, appropriate approval, an execution receipt and a way to reverse or remediate failure.

03.02 / Business context

### Purpose-bound data contracts

#### CRM

Counterparty, value, proposed products, markets, commercial thresholds and approval state.

#### Contracts and documents

Exact text, versions, deviations, executed commitments, obligations, source locations and classifications.

#### Product and data

Features, intended uses, user groups, models, vendors, data flows, jurisdictions and release changes.

#### Security and controls

Incidents, affected assets, control status, evidence and notification-clock inputs.

#### People and finance

Employment locations, roles, material transactions, spend and exposure thresholds, limited to the purpose at hand.

#### Governance

Delegations, reserved matters, approved conditions, owners, review dates and evidence of completion.

03.03 / Responsibility

### One record, four accountable views

#### Management / Facts, choice and execution

The business owner is responsible for the accuracy of operational facts, the choice within delegated authority, resources for implementation, accepted residual risk and evidence of completion. Decision ownership does not transfer to Legal or to an agent.

#### Legal team / Analysis and process

Matters assembled from their sources; propositions linked to evidence; legal analysis reviewed; standard work routed under policy; conflicts and deviations escalated; actions tracked to disposition. The legal team owns the quality of its work, not the underlying business decision.

#### General Counsel / Decisions and exposure

Material decisions and their owners; unresolved factual and legal uncertainty; competing courses; unresolved disagreements; concentrations of exposure; conditions awaiting implementation; patterns that may require a policy or risk-appetite decision.

#### Board / Oversight and assurance

Material developments, affected decisions, authority exercised, evidence relied on, dissent and uncertainty, conditions imposed, implementation status and residual risk. The board should not receive a stream of operational alerts. An aggregate score is insufficient; material assumptions, dissent and uncertainty must remain visible.

03.04 / Deliberation

### Sparring without substitution

Agents can prepare a pre-mortem, the strongest contrary case, a list of missing evidence, conflicts with precedent or policy, and second-order operational consequences. For the General Counsel, this tests the legal position and whether it can be implemented. For the board, it tests management’s framing, alternatives, control evidence and residual uncertainty. It does not set risk appetite, exercise a vote or replace independent advice.

03.05 / Example

### A product specification changes

#### 01 / Event

The product system records a material change.

#### 02 / Exposure

Affected entities, markets, data, contracts and controls are identified.

#### 03 / Context

Internal facts and external authority are assembled; gaps are requested.

#### 04 / Challenge

The proposed position is tested independently.

#### 05 / Decision

The authorised person proceeds, pauses or imposes conditions.

#### 06 / Action

Approved conditions enter the release workflow.

#### 07 / Closure

Implementation evidence is checked and the decision record is updated.

<a id="authority"></a>

04 / Authority

## Technical permission is not corporate authority.

An agent has technical permissions, not corporate office, professional responsibility or judgment authority. Each permission must trace to a human owner, a lawful basis and a revocable delegation. Accountability does not move to the system. Reading, analysing, recommending, communicating and acting require separate permissions.

### 04.01 / Deterministic / Checks

An agent may verify parties, dates, approvals, clause presence, numerical consistency or other defined conditions after the checks and exception routes have been tested. People remain responsible for the specification and thresholds.

### 04.02 / Bounded / Rule-bound discretion

An agent may operate within an approved, versioned playbook and explicit delegation. Missing facts, novelty, conflicting sources or a threshold breach require escalation.

### 04.03 / Consequential / Strategic judgment

An agent may frame the decision, develop courses, surface assumptions and argue the contrary case. Materiality, acceptable risk, fairness, reputation, negotiation posture and novel interpretation remain human judgments.

### 04.04 / Reserved / Formal acts

An agent may prepare a formal act, but it may not exercise a director’s vote, choose to waive privilege, settle a matter or make an external legal commitment. Filing, signature or communication may be automated only where law and professional rules permit, the responsible authorised person has approved that specific class of act, and approval and execution are recorded.

04.05 / Controls

### Boundaries are part of the system

#### Identity

Each agent has a workload identity, human sponsor, defined purpose, permitted matter and expiry.

#### Least privilege

No standing enterprise superuser. Access is granted to the minimum fields and actions required.

#### Provenance

Material claims retain source, jurisdiction, effective date, version, access scope and currentness.

#### Memory promotion

Drafts, conversations and exceptions enter institutional policy only after authorised review.

#### Professional boundaries

Privilege, confidentiality, conflicts, supervision, retention and legal hold are designed into retrieval and logging.

#### Independent challenge

The system that produced the preferred answer is not the sole evaluator of its own work.

#### Input integrity

Retrieved documents and user content are untrusted inputs. They cannot alter permissions, routing rules, approval state or governing system instructions.

#### Resilience

Source, connector and model failure modes are defined. Consequential actions fail safely, degraded operation is visible and a manual fallback is tested.

#### Change control

Models, prompts, sources, policies, connectors and routing rules run against a versioned regression set before release.

#### Lifecycle

Agents have owners, logs, health checks, expiry, a kill mechanism and retirement criteria. Dormant access is removed.

<a id="maturity"></a>

05 / Maturity

## Maturity is an operating fact, not a product claim.

A company can procure software designed for Stage 7 while its daily work remains at Stage 1. Buying orchestration does not create authoritative context, a tested harness, process ownership or operational continuity.

Stage 4 is the hinge for a workflow intended to operate continuously. Before it, the workflow depends on a person to start it and keep it running. At Stage 4, it becomes an organisational service: triggered by an event or schedule, operated under its own identity, monitored, logged and supported by defined failure and continuity procedures.

Stage 4 depends on the context and harness established at Stages 2 and 3. The stages describe the dominant mode of operation; they do not permit basic controls to be deferred. Privacy, security, professional duties, ownership and human authority apply from Stage 1. Not every workflow should advance to headless or multi-agent operation.

### Stage 01 / Tools

Individuals use AI for discrete tasks and remain responsible for initiating, supplying and checking each one.

**Evidence before proceeding:** Named owner, permitted use, data boundary and a method for checking output.

### Stage 02 / Context

Authoritative knowledge is available through bounded, permissioned interfaces. Domains remain separated.

**Evidence before proceeding:** Source registry, authority by field, access policy, freshness and provenance.

### Stage 03 / Harness

Evaluation criteria, routing, abstention, escalation and quality gates are defined independently of the chosen model. The durable investment is the system around the model: rules for context, the evaluation set, routing, permissions and the decision record. A replacement model must meet the same release criteria without weakening authority controls or auditability.

**Evidence before proceeding:** Adjudicated test cases, severity-weighted failure classes, regression results and release criteria.

### Stage 04 / Headless operation

Stable, recurring and observable workflows run from business events, conditions or schedules rather than from a person’s laptop. The service no longer depends on one person being present.

**Evidence before proceeding:** Service identity, logs, retries, failure routing, monitoring, continuity testing and an accountable operator.

### Stage 05 / Governance at scale

Access, delegation, retention, agent lifecycle, audit, incident response and retirement are managed systematically across the portfolio. Permissions are suspended on expiry, loss of sponsorship, policy-defined inactivity or regression below an approved evaluation threshold.

**Evidence before proceeding:** Control ownership, review cadence, access recertification, automatic suspension, kill mechanism and retained decision records.

### Stage 06 / Coordination

Specialist agents exchange defined work products within a value chain. Before a handoff is accepted, the work product is checked for required structure, source provenance, completeness, the authority to send and receive it, and known failure modes. That check may be rule-based, performed by an independent model or assigned to a person. Agent coordination is justified only where it improves performance or controls risk better than a simpler pipeline.

**Evidence before proceeding:** Versioned interface contracts, acceptance checks at each handoff, comparative evaluation, named failure ownership and end-to-end traceability.

### Stage 07 / Orchestrated operations

Within the declared coverage perimeter, routine cases proceed through governed workflows. Open obligations, conditions and decisions return to attention when a relevant fact, deadline or threshold changes. People concentrate on exceptions, contested facts, strategy and accountable judgment.

**Continuing evidence:** Decision time, senior attention, critical escapes, escalation quality, action closure, incidents and outcomes.

05.01 / Implementation

### Where the change burden sits

The implementation model determines who carries the work of changing systems and behaviour. It does not remove that work.

#### Internal redesign / Build and operate

The organisation builds and operates the capability itself. This preserves control and institutional learning, but requires sustained executive authority and cross-functional ownership to change roles, incentives, handoffs and systems.

#### Embedded implementation / Deliver the technical integration

A specialist works inside the organisation to connect systems and tune the harness. That can solve the technical integration. It cannot by itself establish decision rights, align incentives or secure adoption. An accountable internal process owner remains necessary.

#### Managed outcome / Delegate a defined process

A provider operates a defined process to an agreed outcome and carries the continuing work of maintaining the workflow and adapting it as models change. This reduces the internal change burden only where the work can properly be outsourced, quality can be specified and audited, and authority boundaries, data arrangements, knowledge transfer and exit are explicit.

No implementation model fits every process; a hybrid arrangement may be appropriate. In every case, adaptation remains an operating function because sources, AI models, law, policy and business processes change on different cadences. Accountability for corporate decisions remains within the organisation.

05.02 / Measurement

### Measure decisions, not usage

Seats activated, token volume and documents generated show adoption. They do not establish value or control. Measures should be defined for each workflow, compared with an appropriate baseline, segmented by risk class and tested through adjudicated samples.

#### Coverage

Defined monitoring perimeter; relevant events detected; known blind spots; source outages; false dismissals and precision by attention tier.

#### Quality

Severity-weighted errors; unsupported propositions; source validity and currentness; and correct abstention, escalation and routing.

#### Deliberation

Material facts, alternatives, contrary authority and second-order effects omitted when the decision was made.

#### Execution

Time from event to decision and from decision to closure; overdue conditions; failed or reversed writes; and reopened decisions.

#### Economics

Senior legal time, net external spend and the full cost of integration, evaluation, supervision, incidents and maintenance.

#### Safety

Unauthorised access or action, cross-matter leakage, privilege events, malicious-input failures and incidents during degraded operation.

#### Operations

Governed-workflow coverage; manual bypasses; regression results after changes; source and connector availability; time to contain a failure; and tested manual fallback.

#### Outcome

Corrections, disputes, losses and control failures against the assumptions recorded at the time. Outcomes are lagging and confounded; alone, they do not prove decision quality.

05.03 / Oversight

### Questions for the board

1. Which defined decisions or workflows are within scope?
2. Which external developments and internal business events can initiate legal work, and where are the known coverage gaps?
3. Which sources are authoritative, and how is currentness established?
4. Where does human judgment remain mandatory?
5. Which failure classes are tested, and how are severe misses reported?
6. What may the system read, recommend, communicate and change?
7. How are privilege, confidentiality, conflicts and matter boundaries preserved?
8. Who owns each agent and the associated process change, and when do its permissions expire?
9. How does management prove that an approved decision was implemented?
10. Which implementation model is being used, and which organisational changes must management still deliver?
11. What is the economic case after the full cost of integration, evaluation, supervision, incidents and maintenance?
12. What remains operational and auditable if a model, provider, source or connector becomes unavailable or must be replaced?

<a id="end-state"></a>

Conclusion

## The intended end state is not an autonomous legal department.

It is a legal function that maintains defined coverage, tests relevant changes against current company facts and keeps open matters under review. Routine execution is systematic, institutional knowledge is available at the point of decision and judgment is independently challenged. Authority remains explicit, and approved decisions are followed into business action and evidenced closure.

Jonas Hertner

Document

Legal agents inside the organisation Published 27 August 2026

Related

- [Legal work inside the organisation](/pivot/)
- [AI in legal work](/notes/ai-in-legal-work/)
- [Main page](/)

Formats

- [Markdown edition](/agents/index.md)
- [LLM index](/llms.txt)
- [Site privacy](/#privacy)

<a id="scope"></a>

## Scope

This is an operating framework, not legal advice or a statement that any particular use is lawful. The applicable law, professional duties, corporate authority and technical controls must be assessed for the organisation and the work concerned.

<a id="privacy"></a>

## Privacy

No visitor analytics or advertising code runs on this page. It sets no cookies. GitHub Pages processes technical request data, including IP addresses, to deliver and protect the site.

<a id="references"></a>

## Reference points

[NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework); [NIST Generative AI Profile](https://doi.org/10.6028/NIST.AI.600-1); [OECD Recommendation on AI](https://legalinstruments.oecd.org/en/instruments/OECD-LEGAL-0449); [EU AI Act](https://eur-lex.europa.eu/eli/reg/2024/1689/oj).

© 2026 Jonas Hertner · Independent lawyer
