← All insights | Adoption and Change Management

Your Firm Has Another AI Problem You Don’t Know About Yet

Scott Samborn July 21, 2026 6 min read

By Scott Samborn, Aspen Management Group
Topics: AI governance, professional services firms, law firm AI policy, AI risk management, shadow AI

Most professional services firms think their AI risk begins and ends with whether the tools work.

It doesn’t.

The real risk is simpler and more immediate: nobody has defined who is responsible when the tools get something wrong.

According to the 8am 2026 Legal Industry Report, 43% of law firms have no formal AI policy and no plans to create one. Only 9% have a written policy that is actually enforced. More than half, 54%, have provided no training on responsible AI use and have no plans to do so.

Those numbers are specific to law firms, but the same pattern holds across CPA practices, financial advisory firms, and independent insurance agencies. The tools arrived. The guardrails did not.

What is the AI governance gap in professional services firms?

The AI governance gap is the space between how staff are actually using AI tools and what the firm has formally approved, documented, and trained for.

Staff are using AI. That much is clear. Nearly 70% of legal professionals now use generative AI tools for work-related tasks, up from 31% just a year ago, according to the 8am 2026 Legal Industry Report as cited by LawNext.

What is less clear is whether anyone knows which tools are being used, what client data is being entered into them, or what happens to that output before it reaches a client.

In most firms, the honest answer is no one knows. Usage is happening at the individual level. Organizational structure has not caught up.

That gap has a name: shadow AI. Staff members using tools that nobody approved, on data that nobody audited, producing output that nobody reviewed. It is not malicious. It is just what happens when curious people have access to powerful tools and no guidance on how to use them.

Why does AI governance matter more now than it did a year ago?

Courts are beginning to answer the liability question that most firms have not asked yet.

A German court held Google liable for inaccurate AI-generated summaries, treating the output as the company’s own statement rather than a neutral tool’s output. An Air Canada case went the same direction, holding the airline responsible for a promise its chatbot made to a customer.

The pattern is consistent: when AI produces something wrong, the accountability lands on whoever deployed it. Not the model vendor. Not the software provider. The organization that put the tool in front of the client.

For a law firm, a CPA practice, or a financial advisor, that exposure is not theoretical. It is a question of when, not if.

What three questions should every professional services firm be able to answer about AI?

A governance framework does not have to be long. It does not have to be a 40-page policy document. It has to answer three things clearly:

What tools are approved, and under what conditions? Not “we use AI sometimes.” A specific list of approved tools, with specific guidance on what client data can and cannot be entered, and what use cases are and are not permitted.

Who reviews AI output before it reaches a client? This is the question that exposes the most firms. Many have no answer. Output goes from the tool to the email to the client with no checkpoint in between. That is the moment where liability lives.

What happens when something is wrong? Who is responsible for catching the error? Who is responsible for correcting it? Who is responsible for communicating with the client if something went out that should not have? Firms that have thought this through in advance are in a different position from the ones who have to try to figure it out after an incident.

Why is AI training part of a governance strategy?

Governance without training is a policy nobody reads.

More than half of law firms have provided no training on responsible AI use. Similar numbers show up in accounting and financial services. The tools are in the hands of staff who learned to use them on their own, from YouTube, from trial and error, or from watching a colleague.

That is not a criticism of staff. It is a structural problem. When firms invest in AI tools and skip the training, they are assuming that responsible use is intuitive. It is not. What to prompt, what not to prompt, how to verify output, when not to trust it, these are skills that have to be taught.

What does a reasonable AI governance starting point look like for a boutique firm?

The firms that are ahead of this are not the ones with the most sophisticated AI programs. They are the ones that did the basic work first.

A short approved-tools list. A clear output review standard that names who is responsible. A one-page staff policy that answers the three questions above. And a conversation with staff about why it matters, not just what the rules are.

None of this requires a large budget or a dedicated operations team. It requires someone to own it, and a few hours to put it in writing.

The firms that do this work now will not be scrambling when a client asks, or worse, when something goes wrong.

Frequently asked questions about AI governance for professional services firms

Do small law firms and CPA practices need an AI policy? Yes. Size does not reduce liability. Courts have held organizations of all sizes responsible for AI output. A one-page policy is sufficient to start.

What is shadow AI? Shadow AI refers to staff using AI tools that the firm has not formally approved, often on client data. It is one of the most common and underrecognized risks in professional services firms today.

What should an AI governance policy include? At minimum: an approved-tools list, guidance on what data can be entered into AI tools, an output review standard, and a clear escalation path when something goes wrong.

How long does it take to put AI governance in place? A working first draft can be produced in a half-day structured session. AMG’s AI Governance Workshop covers policy, output review standards, and staff training in a single engagement.

Scott Samborn is the founder of Aspen Management Group, a workflow strategy and AI implementation firm serving boutique professional services firms in the DC Metro area and beyond. AMG helps law firms, CPA practices, RIAs, independent insurance agencies, and nonprofits build the workflows, governance, and training that make AI adoption actually stick. Visit aspenmg.net or connect on LinkedIn.

Aspen Management Group
Scott Samborn
Founder, Aspen Management Group

Scott spent 20 years running a managed IT services practice with law firm clients across the DC Metro area, and has worked in technology for 30 years. AMG helps boutique law firms get practical value out of AI.

← Previous
All insights
Next →

Ready to see what AI can do for your firm?

Start with a Clarity Assessment. A 90-minute session, a written report, no obligation to continue.

Book your Clarity Assessment