# Governance for AI-enabled legal work.

CyberSquire helps teams use AI in legal workflows with policy, risk tiers, human review, approved playbooks, and auditable records.

## Governance model

01

**Policy**  
Define approved uses, prohibited uses, and required review paths for AI in legal work.

02

**Risk tier**  
Classify each request by risk level before it enters any review workflow.

03

**Review path**  
Route to the appropriate review path based on risk tier and issue type.

04

**Human oversight**  
Require human review and sign-off before any AI-assisted guidance is finalized.

05

**Audit trail**  
Record every step — request, review, decision, and rationale — for future reference.

## Risk tiers

### Low risk  
✓ Permitted  
Internal drafting and summarization.  
- Internal memo drafts  
- Document summaries  
- Clause explanation

### Medium risk  
⚠ Reviewed  
Business guidance and workflow support.  
- FAQ responses  
- Workflow routing  
- Template generation

### High risk  
! Attorney required  
Legal conclusions, sensitive data, external-facing decisions.  
- Binding guidance  
- Sensitive personal data  
- External communications

### Restricted  
✕ Requires approval  
Prohibited uses or leadership-approved uses only.  
- Prohibited categories  
- Leadership exceptions only

## Approved playbooks

- **Contract review playbook**  
Standard positions for MSA, NDA, SOW, and DPA clause-by-clause review.

- **Vendor review playbook**  
Security, privacy, and legal review steps for new and renewing vendors.

- **AI use review playbook**  
Risk tiering, review path, and approval conditions for AI tool requests.

- **Policy response playbook**  
Approved answer structures for common compliance and policy questions.

- **Escalation playbook**  
Conditions, paths, and owners for escalating high-risk or complex matters.

- **Human review checklist**  
Required steps before any AI-assisted output is finalized and sent to business.

## Reporting

**41**  
AI use by team  
**6 teams this month**

**128**  
Review volume  
↑ 14% vs last month

**9**  
Escalations  
**3 high-risk**

**7**  
High-risk decisions  
**All attorney reviewed**

**84%**  
Training status  
**16% outstanding**

**4**  
Open exceptions  
**2 awaiting approval**

## Governance record

| Request                               | Risk tier | Reviewer       | Decision               | Evidence            |
|---------------------------------------|-----------|----------------|-----------------------|---------------------|
| AI summarization — M&A memo           | Low       | Self-certified  | Permitted             | Policy log          |
| Vendor DPA — Northwind Cloud          | Medium    | Privacy lead    | Approved w/ conditions | DPA record          |
| External legal opinion — IPO          | High      | Senior counsel   | Attorney required      | Review notes        |
| AI hiring tool — HR                   | High      | Compliance      | Escalated             | Risk tier log       |
| Auto-draft — NDA                      | Low       | Playbook match  | Permitted             | Playbook v3        |
| Regulatory chatbot — Finance          | Restricted| Leadership      | Pending approval       | Exception form      |

## Let legal support AI adoption without losing control.

CyberSquire gives your team the policy framework, review paths, and audit records needed to govern AI use in legal work.

[Review governance workflows](/content/cys/contact/index.html)
