A structured decision framework for evaluating, procuring, and onboarding AI tools — covering vendor due diligence, EU AI Act compliance, DPA review, SRA alignment, and ongoing monitoring.
Complete for every AI tool before approval. Score each question: Yes = 1, No = 0, Partial = 0.5. Score below 20 = Conditional. Score below 15 = Reject.
Maintain this register as the single source of truth for all AI tools at the firm. Update monthly. All fee earners must check this register before using any AI tool on client work.
| Tool | Version | Use Cases | DPA Status | EU AI Act Class | Decision | Conditions | Review Date |
|---|---|---|---|---|---|---|---|
| Microsoft Copilot (M365) | Enterprise | Drafting, summarisation, research | ✓ M365 DPA | TBC — assessment required | Conditional | Complete DPIA. Verify no training on client data. Review M365 data residency settings. | Quarterly |
| Harvey AI | Enterprise | Legal research, drafting | ⚠ DPA not executed | TBC — legal AI, assess Annex III | Suspended | Execute DPA before reinstatement. Obtain EU AI Act technical documentation. Complete DPIA. | On DPA execution |
| Luminance | Enterprise | Contract review, due diligence | ✓ DPA executed | TBC — likely limited high-risk | Conditional | Complete EU AI Act risk classification. Human review mandatory on all outputs. | Quarterly |
| ChatGPT (Personal) | Any | Any client matter use | ✗ No DPA — consumer terms | General purpose — no legal classification | Rejected | Not approved for any client matter use. Personal accounts must not be used for client work under any circumstances. | Permanent |
| Otter.ai (or similar transcription) | Any | Meeting transcription | ⚠ DPA not executed | Limited risk — but captures privileged content | Suspended | High confidentiality risk. Must not be used for client meetings until DPA executed and privilege protection confirmed. Seek alternative with explicit legal sector DPA. | On DPA execution |
| [New Tool] | Pending assessment | Pending classification | Pending | Complete vendor due diligence questionnaire before deployment. |