TL;DR: A firm of three to fifteen lawyers can put AI into daily practice in ninety days without a disaster, but only if access starts with two named people, the pilot is confined to research and first drafts, and one partner reads every AI-assisted document against its primary sources before it leaves the office. The three failures that actually happen in small Indian firms are lawyers using personal chatbot accounts on client files, an unverified citation reaching a filing, and a subscription nobody opens after week three.
On this page
- Who this plan is for
- Decide what you are buying before you buy it
- Who gets access first, and why
- What to pilot: research and first drafts
- Work you can route to AI, and work you cannot
- The partner sign-off rule
- The approval gate between draft and filing
- The client confidentiality problem
- What the DPDP Act adds on top of confidentiality
- What to put in the engagement letter
- What to measure in the first 90 days
- The 30/60/90 day rollout plan
- Failure mode one: shadow AI on personal accounts
- Failure mode two: an unverified citation reaches a filing
- Failure mode three: a subscription nobody opens
- What this costs and how to decide at day 90
- Frequently asked questions
Who this plan is for
This is written for an Indian firm with three to fifteen lawyers. One or two partners who still appear in court, a handful of associates, a clerk or two, one person who handles filings and accounts, and nobody whose job title contains the word technology.
At that size you have a specific set of constraints. There is no IT department to write a policy. There is no procurement process. There is no budget line for a pilot that fails. Every hour a partner spends evaluating software is an hour not billed. And the person most likely to bring AI into the firm is a second-year associate who has already been using it for four months without telling anyone.
That last point is the reason to run a deliberate rollout rather than let one happen. A firm that has not sanctioned a tool has not prevented AI use. It has only prevented supervised AI use.
The plan below assumes you are starting from zero, that you want to be using AI on live matters within thirty days, and that you want a defensible answer if a client, a court or the Bar Council asks what your firm does with client material. It does not assume you will hire anyone, change your billing model, or buy more than one product.
Decide what you are buying before you buy it
Firms that get this wrong almost always got it wrong at the first step. They bought a general assistant and hoped a use case would appear.
Write down the single task you want to be faster at. Not a category. A task. Examples that work: “finding the authorities on condonation of delay under Section 5 of the Limitation Act for a first appeal in the Bombay High Court”, or “producing a first draft of a Section 138 demand notice from the client’s cheque return memo”, or “reading a 140 page judgment and telling me which paragraphs deal with maintainability”.
Then ask a harder question about that task. How would a person in your office know within ten minutes that the output was wrong? If the answer is “open the judgment and read paragraph 34”, the task is a good pilot candidate, because verification is cheap. If the answer is “we would find out at the hearing”, it is a bad pilot candidate, and you should not start there regardless of how much time it appears to save.
This test does most of the work of choosing a product. A tool that retrieves from an indexed corpus of Indian judgments and shows you the paragraph it relied on makes verification a ten-second step. A tool that predicts fluent text and appends a citation as decoration makes verification a separate research project, which means it will not happen. How to vet legal AI for citation accuracy sets out the specific tests to run during a trial, and a 2026 buyer’s guide to AI tools for lawyers in India covers the comparison across products.
One more decision belongs here rather than later. Decide whether the tool will ever see client-identifying material. If the answer is yes, the confidentiality and data-protection work described further down has to be finished before day one, not bolted on in month three.
Who gets access first, and why
Give the first two seats to a partner and one associate. Not the whole firm, and not the associate alone.
The partner matters because a rollout that the partners have not personally used will fail at the sign-off stage. A partner who has never seen how the tool behaves cannot tell a well-verified AI-assisted draft from a badly verified one, and will either wave everything through or refuse everything. Both outcomes end the pilot.
The associate matters because associates do the work the tool is meant to change. Pick the one who is already curious, already fast, and already careful. Curiosity without care produces a hallucinated citation in week two. Care without curiosity produces a seat that is never opened.
Do not start with the clerk or the person handling filings. Their work is procedural, deadline-driven and unforgiving of experiments, and errors there surface late.
Two seats for thirty days is enough to answer the questions that decide the rollout. Does the tool find Indian authorities the firm’s existing method misses? How often does it produce a citation that does not survive checking? How long does verification actually take? Does the drafting output need more editing than starting from the firm’s own precedent?
At day thirty, widen to everyone who does research or drafting. At day sixty, decide whether the clerk and the filing staff get read-only access for tasks like case status checks and chronology building. Where AI genuinely helps litigators as against corporate teams is worth reading before you decide who in a mixed practice benefits most.
One rule applies from the first seat. Every person with access uses the firm’s account, on the firm’s login, and nobody uses a personal account for firm work. This is the single most important sentence in the whole policy and the reason is set out below.
What to pilot: research and first drafts
Confine the pilot to two functions. Research, and the first draft of documents you would otherwise start from a template.
Research is the right first pilot for an Indian litigation practice because the output is checkable against a primary source in minutes. You get a case name and a proposition. You open the judgment on the Supreme Court’s eSCR portal or the relevant High Court website, find the paragraph, and either the proposition is there or it is not. The feedback loop is immediate and unambiguous, which is exactly what a firm learning a new tool needs.
First drafting is the right second pilot, with a narrower scope than most firms assume. Use it where you already own the structure: a legal notice, a reply to a notice, a routine application, a standard clause set. The tool assembles from your material and known law, and you edit. Do not use it to produce a document type your firm has never drafted, because you will have no baseline against which to judge the output. How to draft a legal notice and AI contract drafting cover what the drafting step should and should not include.
What stays out of the pilot: anything that is filed, anything sent to a client, and anything involving a point of law where you could not name the two competing lines of authority yourself. You cannot supervise what you do not understand, and a pilot is the worst time to discover that.
Set a volume target rather than a quality target for the first month. Something like: twenty research queries and eight first drafts across live matters, every one of them verified and logged. Quality judgements come after you have enough instances to see the pattern. Two impressive answers in week one tell you nothing.
Work you can route to AI, and work you cannot
This table is the operational core of the policy. Print it and put it on the wall.
The dividing line is not difficulty. It is whether a competent person in your office can confirm the output is correct, cheaply, before it matters.
| Work | Route to AI? | Reason |
|---|---|---|
| Finding authorities on a settled point of law | ✓ Yes | Every citation is checkable against the judgment text in minutes |
| Summarising a long judgment you are going to read anyway | ✓ Yes | The summary is verified against the paragraphs it points to |
| Building a chronology or document index from a brief | ✓ Yes | Errors are visible against the source documents |
| First draft of a notice or application from your own precedent | ✓ Yes | You own the structure and edit every line |
| Extracting deviations in a contract against your own clause playbook | ✓ Yes | Deviations are checked one by one before advice goes out |
| Internal translation of a district court order in Hindi or Marathi | ✓ Yes | Internal comprehension only; certified translation still comes from a translator |
| Finding judgments factually similar to your matter | ✓ Yes | You read the judgments before relying on any of them |
| The final text of anything filed in court | ✗ No | The person who signs the filing carries the risk of every word in it |
| Advice that goes to a client without a lawyer reading every line | ✗ No | The duty to the client under the Bar Council of India Rules is personal |
| Any point where you cannot name the competing authorities yourself | ✗ No | Unverifiable output looks identical to verified output |
| Client identity documents or medical records in a consumer chatbot | ✗ No | Confidentiality and DPDP processor obligations both fail at once |
| Quantum, interest or limitation computation you will not redo by hand | ✗ No | Arithmetic errors survive proofreading better than prose errors do |
| Deciding whether to accept a settlement or file an appeal | ✗ No | A judgement call, not a retrieval task |
| Drafting an affidavit of facts from the client’s instructions | ✗ No | Facts must come from the deponent, not from a model completing a pattern |
The last row causes more argument than the others. An affidavit is a statement on oath about what the deponent knows. A model that fills gaps in a narrative because the narrative reads better with them filled is producing exactly the wrong thing. Use the tool to check the affidavit for internal inconsistency after the deponent has given the facts. Do not use it to generate the facts.
The partner sign-off rule
Write this as one sentence in the firm policy and do not qualify it: no AI-assisted document leaves this firm without a partner having read it against its primary sources.
Three words in that sentence are load-bearing.
Read. Not skimmed, not spot-checked. A partner who reads the first citation and assumes the rest are fine has replaced verification with sampling, and sampling is how fabricated citations get through. If the volume makes full reading impossible, the volume is wrong, not the rule.
Against. The partner opens the judgment. A citation that has been checked only against the AI tool’s own summary has not been checked. The check is against the primary source, on the court’s own portal or a database that reproduces the judgment text.
Primary sources. Judgments, the bare Act, the gazette notification, the rules. Not a headnote, not a blog, not another AI summary. Primary versus secondary legal sources sets out the distinction that matters here, and good-law checking covers the step that automated summaries most often get wrong, which is whether the authority is still standing.
The rule is deliberately blunt because the alternative formulations all decay. “Partner review where appropriate” becomes no review by month four. “Spot-check ten percent” becomes a lottery you eventually lose. A single unqualified rule survives contact with a busy practice; a nuanced one does not.
Two practical additions make it workable. First, the associate who used the tool marks which parts of the document were AI-assisted, so the partner knows where to look hardest. Second, the associate records what they verified and where, in two lines in the matter file. That record is what you produce if a court asks, and it takes under a minute. A lawyer’s duty to verify AI legal output sets out why the duty sits with the person signing rather than the vendor.
The approval gate between draft and filing
The rule above only works if it is a gate rather than an intention. Here is the gate as a process, with the loops that matter.
flowchart TD
A[Matter opened, AI use permitted under engagement terms] --> B[Associate runs AI research or first draft]
B --> C[Associate logs tool, date and what was asked in the matter file]
C --> D{Every citation opened<br/>in the source judgment?}
D -->|No| B
D -->|Yes| E{Still good law<br/>after the citator check?}
E -->|No| B
E -->|Yes| F[Associate rewrites in own words, marks AI-assisted parts]
F --> G[Partner reads draft against the primary sources]
G --> H{Facts, law and client data<br/>all clear?}
H -->|No| B
H -->|Yes| I[Disclosure added where the court requires it]
I --> J[Partner signs, document filed or sent]
Two features of this gate are worth defending against the inevitable request to simplify it.
The citation check and the good-law check are separate gates because they fail differently. A citation check catches a case that does not exist. A good-law check catches a case that exists, says what the tool claimed, and was overruled in 2019. The second failure is more dangerous because the document survives casual scrutiny and dies at the hearing.
The rewrite step exists because a draft that reproduces model output verbatim tends to carry the model’s confidence along with its words. Making the associate restate the proposition in their own words is a comprehension test disguised as an editing step. If they cannot restate it, they did not understand it, and it should not be in the document.
The client confidentiality problem
This is the part of the rollout most small firms handle last and should handle first.
An advocate’s duty of confidence to a client is not a contractual nicety that a software licence can adjust. Two separate bodies of law create it. The first is the evidentiary privilege attaching to professional communications. The second is the professional conduct obligation enforced by the Bar Councils under the Advocates Act 1961, breach of which is professional misconduct under Section 35 of that Act, referred to the disciplinary committee of the State Bar Council.
The evidentiary privilege now sits in the Bharatiya Sakshya Adhiniyam 2023, which replaced the Indian Evidence Act 1872 with effect from 1 July 2024. The provision protecting professional communications between an advocate and a client, which was Section 126 of the Evidence Act, carries a new section number in the BSA, and the corresponding provisions on interpreters and clerks and on confidential communication with a legal adviser were renumbered along with it. If you are drafting a firm policy, cite the BSA number and give the old Evidence Act number in brackets, because most of the commentary your associates will find still uses the old numbering. The new criminal laws: BNS, BNSS and BSA covers the renumbering across all three statutes.
The practical question for an AI rollout is narrower than the doctrine. Privilege protects the communication. It does not follow the communication onto whatever infrastructure you send it to. If your associate pastes a client’s matrimonial affidavit into a free consumer chatbot, the privilege in the underlying communication is not automatically destroyed, but you have created a copy of privileged material on a system your firm has no contract with, cannot audit, and cannot compel to delete. You have also lost the ability to answer the only question that matters if the client asks: where is my file, and who has seen it?
So the confidentiality analysis for a legal AI tool comes down to four questions you must be able to answer before the first upload.
- Does the vendor train models on your inputs? If yes, or if the answer is “only if you do not opt out”, assume client material becomes training data and do not upload client-identifying content.
- Who inside the vendor can read your content, and under what process? Support access for debugging is normal. Unlogged, unrestricted access is not.
- Where is the content stored and for how long? You need a retention period you can state to a client and a deletion process you can trigger.
- What contract binds the vendor? A terms-of-service page you clicked through is a contract, but it is usually the vendor’s contract. For client material you want processing terms that name your firm as the controlling party.
Legal AI data residency in India works through the storage and cross-border questions in detail, including the vetting checklist to run before you upload anything. For the narrower question of what a general consumer chatbot does with legal content, ChatGPT for lawyers in India is the relevant comparison.
There is a simpler intermediate step that many small firms miss. Most research work does not need client identity at all. “Is a delay of 412 days in filing a first appeal condonable where the appellant was in judicial custody” is a complete research question containing no client data. Train the firm to ask the legal question without the client attached, and a large share of the confidentiality exposure disappears before the tool is even involved.
What the DPDP Act adds on top of confidentiality
The Digital Personal Data Protection Act 2023 is a separate obligation that runs alongside the confidentiality duty and is owed to a different person: the individual whose personal data you hold, who may be your client, the opposing party, a witness or a third party mentioned in a document.
For a small firm the position is straightforward in outline. When you decide the purpose and means of processing personal data, you are a Data Fiduciary. When you hand that data to an AI vendor to process on your instructions, the vendor is a Data Processor, and the Act requires that engagement to rest on a valid contract. Your obligations to keep data secure and to deal with a breach do not transfer to the vendor along with the data. You remain answerable.
Four duties bear directly on an AI rollout.
Security safeguards. You must take reasonable security safeguards to prevent a personal data breach. An account shared by four lawyers with one password is not that. Individual logins, a record of who has access, and removal of access when someone leaves are the minimum.
Breach notification. A personal data breach has to be notified to the Data Protection Board and to affected individuals. Decide now who in the firm makes that call and where the vendor’s incident contact is written down, because working it out during an incident is how deadlines get missed.
Purpose limitation and erasure. Personal data must be erased when the purpose is no longer served and retention is not required by law. For a law firm, retention is frequently required by law, so the discipline is to know which category a given file falls into rather than to keep everything forever by default.
Cross-border transfer. The DPDP Act does not impose blanket data localisation. It uses a restriction model, under which transfer outside India is permitted except to countries the Central Government restricts by notification. That is a lower bar than localisation, but it is not the same as “anywhere is fine”, and it interacts with any confidentiality undertaking you have already given a client.
The Rules under the Act were notified in November 2025 with a phased commencement, which means the operating obligations arrive on a schedule rather than all at once. The DPDP Rules 2025 covers what was notified and when, and DPDP compliance deadlines for 2026 and 2027 sets out the phases against dates.
One point often missed in firm discussions. Court judgments are public documents, and the DPDP Act carves out personal data that the individual has made publicly available or that is made public under a legal obligation. Research over published judgments is a materially different data-protection question from uploading a client’s Aadhaar copy. Treating those two activities identically produces a policy so restrictive that people route around it, which is worse than a policy that distinguishes them.
What to put in the engagement letter
If your firm will use AI tools on a client’s matter, say so in the engagement letter. Not in a technology annexure nobody reads. In the body, in plain language, in one short paragraph.
There are three reasons, in ascending order of importance. It is a courtesy. It prevents an awkward conversation later. And most importantly, it is the only moment at which you can find out that this particular client will not accept it, before you have already done it.
A workable paragraph covers five things.
- That AI tools may be used, and for what: research, summarisation, first drafts, document review.
- That every output is reviewed by a lawyer and that professional responsibility for the work remains with the firm. This is a statement of what you already owe, not a new promise.
- How client material is handled: whether client-identifying material is uploaded at all, to which category of tool, and on what terms.
- That the client may object, with a named contact and a stated consequence. Usually the consequence is a longer turnaround and a higher fee, and it is better to say that than to discover it.
- Confidentiality is unaffected: the firm’s confidentiality obligations apply to AI-assisted work in the same terms as to any other work.
Two clients will treat this differently. A bank or a listed company will already have a vendor and AI policy of its own, and its outside counsel guidelines may prohibit or restrict AI use entirely. Read those guidelines before you sign the retainer, because they override your firm policy on that client’s work. An individual litigant will mostly not care, but the disclosure protects you if they later do.
Keep it separate from anything you file. The engagement letter governs the client relationship. Whether you must tell the court that AI was used in preparing a document is a different obligation with a different source, covered in the duty to declare AI use in pleadings and what the Supreme Court’s draft AI rules say. Do not let one substitute for the other.
What to measure in the first 90 days
Most firms measure nothing and then argue about whether the tool is worth renewing based on who liked it. Six numbers settle the argument, and all six can be kept in a shared spreadsheet by the associate running the pilot.
Seats opened per week. Weekly active users as a fraction of paid seats. If it drops below half by week six, you have a subscription problem, not a technology problem, and the fix is training or removal of seats rather than a better tool.
Citations rejected at the verification step. Count the citations the tool produced that failed the check, as a fraction of citations produced. This number should never be zero. Zero means nobody is checking, and that is a finding about your firm, not about the tool. A stable low number is the healthiest signal in the whole pilot.
Time from brief received to first draft circulated. Measure it for the matter types in the pilot only. Compare against your own recollection of the same task types before the pilot, and write that recollection down in week one before it is contaminated by optimism.
Research hours per matter. If you record time, this is already in your system. If you do not, have the two pilot users log research time for pilot matters only, for ninety days.
Rework rate. How many AI-assisted drafts came back from the partner needing a second full pass, as against a normal edit. A high rework rate at day thirty is expected. A high rework rate at day ninety means the drafting use case is not working for your document types.
Matters where the tool found something the old method missed. Keep this as a list, not a count, with one line each. It is the only measure that captures quality rather than speed, and at renewal it is the one that persuades a sceptical partner.
Deliberately not on this list: hours billed, revenue, and any firm-wide productivity figure. Ninety days is too short and a three to fifteen lawyer firm is too small for those numbers to mean anything. Global surveys report time savings in the range of a few hours a week; what the 2026 AI adoption surveys actually found sets out those figures with their scope, and none of them were measured in India. Measure your own firm.
The 30/60/90 day rollout plan
Each window has one owner, a small set of actions, and a gate that must be passed before the next window starts. If a gate fails, repeat the window. Do not proceed on schedule with a failed gate, because every later problem in an AI rollout traces back to a gate somebody waved through.
| Window | Owner | What happens | Gate before moving on |
|---|---|---|---|
| Days 1 to 7 | Managing partner | Write the one-page policy: approved tool, who has access, what may and may not be routed to it, the sign-off rule, and the personal-account prohibition. Open the firm account. Two seats only. | Policy signed by all partners and circulated to every person in the office, including clerks |
| Days 8 to 30 | Pilot associate | Run 20 research queries and 8 first drafts on live matters. Verify and log every one. Record every citation that failed the check. Partner uses the tool personally at least twice a week. | Citation rejection rate known and stable; partner has personally run the tool on a live matter |
| Days 31 to 45 | Pilot associate | Widen to everyone doing research or drafting. One 90 minute internal session: how to ask, how to verify, what never to upload. Add the AI paragraph to the engagement letter template. | Every user has verified at least three AI-produced citations against the primary source, watched by the pilot associate |
| Days 46 to 60 | Managing partner | Complete the vendor diligence: training on inputs, storage location, retention, deletion, incident contact, processing terms. Name the person who handles a data breach. Check outside counsel guidelines for your two largest institutional clients. | Written answers to all four confidentiality questions on file; no client-identifying upload until they exist |
| Days 61 to 75 | Pilot associate | Extend to a second use case only if the first is stable. Review the reject log for patterns: which matter types, which courts, which kinds of proposition produce bad citations. | Rework rate at or below the level of a normally supervised junior draft |
| Days 76 to 90 | All partners | Review the six measures. Decide: renew and widen, renew at current size, change tool, or stop. Write the decision and the reason in one paragraph. | A written decision with numbers attached, not a discussion |
The gate at days 46 to 60 is the one firms skip because it is unglamorous and involves emails to a vendor. Skip it and you have a firm-wide AI habit with no answer to a client’s diligence questionnaire, which is a problem you can only fix by stopping.
Failure mode one: shadow AI on personal accounts
This is the most common failure and the least visible. It does not announce itself. You find out when a client asks, or when someone leaves the firm.
The mechanics are ordinary. An associate has a personal chatbot account they have used since law school. A brief arrives at 9 pm with a hearing the next morning. They paste in the relevant pages, ask for the point, get a usable answer, and file. Nobody sees it. It works, so they do it again. Within a quarter it is habit, and the firm’s client material is distributed across a personal account the firm does not control, cannot audit, and cannot delete on request.
The exposure has four parts. Client material sits on infrastructure the firm has no contract with. If the associate leaves, the material leaves with them and the firm has no ability to recall it. The firm cannot answer a data-protection question about where personal data was processed. And the tool has probably been chosen for fluency rather than for grounding in Indian judgments, which makes it the highest-risk source of fabricated citations.
The fix is not enforcement. Enforcement fails because you cannot see the conduct you are trying to prohibit. The fix is supply. Give every lawyer who does research a working, sanctioned tool on the firm account, in the first thirty days, before the habit forms. Shadow AI is overwhelmingly a symptom of a firm that has not provided an alternative, and firms whose lawyers think the firm is moving too slowly report it most.
Three things make the prohibition stick once you have supplied an alternative.
- State it as a client obligation, not an IT rule. “We told the client their file stays inside the firm” is an argument that lands with a lawyer. “It is against policy” is not.
- Make the sanctioned tool at least as good for the daily task. If the approved tool is slower for the thing people actually do at 9 pm, the personal account comes back.
- Ask about it in supervision, without penalty, twice in the first quarter. A junior who admits they used a personal account in week three and is helped rather than punished will use the firm account thereafter. One who is punished will simply stop telling you.
A tool that runs on the firm account and retrieves from Indian judgments rather than predicting them removes both halves of the problem at once, which is the case for Niyam as the sanctioned option rather than a general consumer assistant. Free versus paid legal AI in India works through what the free option actually costs once this exposure is priced in.
Failure mode two: an unverified citation reaches a filing
The second failure is the one that ends up in a judgment.
Language models produce text that is statistically likely, which means a fabricated citation looks exactly like a real one: correct party-name conventions, a plausible court, a plausible year, a plausible reporter cite. There is no stylistic tell. The only reliable check is to open the judgment.
Indian courts have moved from noticing this to acting on it. The Supreme Court’s AI Committee released the Draft Regulations for Use of Artificial Intelligence in Courts, 2026 on 3 June 2026, and their centre of gravity is disclosure and verification: counsel who used AI in preparing a document must say so at filing, and responsibility for fabricated or false AI-generated content sits with the person who filed it, not with the tool. The Kerala High Court had already issued a binding policy for its district judiciary on 19 July 2025, prohibiting the use of AI tools to arrive at any finding, relief, order or judgment. AI hallucinated citations in India covers what has already gone wrong, and what Indian courts have said about AI-generated case law covers the judicial response.
For a small firm the risk is concentrated in a specific place. It is not the partner’s own research. It is the citation that reaches a draft through a junior, at speed, on a matter the partner is not personally across, in a court where the partner does not usually appear. That is the path every reported incident has taken.
Three controls close it, and all three are cheap.
No citation enters a draft without the paragraph. The associate pastes the operative paragraph from the judgment into the working file alongside the citation. If they cannot find the paragraph, the citation does not go in. This single rule catches fabrication and misdescription together.
The neutral citation is the checkable form. Indian judgments increasingly carry neutral citations, and a neutral citation either resolves on the court’s portal or it does not. Neutral citations and the eSCR system covers how they work, and how to cite Indian judgments covers the form a court will accept.
Good law is a separate check with a separate tick. Existence and currency are different questions. Run both, record both. Good-law checking sets out what the automated summaries miss.
The reject log described in the measurement section is what turns this from a rule into a habit. When an associate can see that three of the last forty citations failed, verification stops feeling like bureaucracy and starts feeling like the reason they have not been embarrassed in court.
Failure mode three: a subscription nobody opens
The third failure costs the least and teaches the most. A firm buys eight seats in a burst of enthusiasm in March. By June two people use it, by September nobody does, and the renewal is cancelled with the conclusion that AI does not work for Indian practice.
It is not a technology conclusion. It is what happens when a tool is bought for a category rather than a task.
Four causes account for almost all of it.
Too many seats too early. Eight people who have not been trained will each try it once, get a mediocre answer because they asked badly, and never return. Two people who use it daily for a month will develop a way of asking that works, and can then teach the other six. Seats are cheaper to add than habits are to restart.
No named owner. If the tool belongs to everyone, nobody notices it is unused. One person should own the pilot, hold the spreadsheet, and be asked about it in every partners’ meeting for ninety days.
The task was never specific. “Use AI for research” produces nothing. “Every Section 138 matter starts with a three-minute check for High Court authority on the point in issue” produces a habit, because it attaches the tool to a recurring trigger.
Verification friction was never reduced. If checking a citation takes fifteen minutes because the tool gives you a case name and nothing else, people will stop using the tool rather than stop verifying. A tool that shows the source paragraph makes the check a ten-second step, which is the difference between a habit and an abandoned tab.
Kill the subscription deliberately if the measures say so. A documented decision at day ninety that the tool did not fit your matter types is a good outcome and costs one quarter’s fees. An undocumented drift into non-use costs the same money and teaches the firm nothing.
What this costs and how to decide at day 90
The cost of a rollout at this size is mostly not the licence. It is the partner hours in the first month and the verification time that never goes away.
Budget honestly for three things. Two seats for ninety days. Roughly ten to fifteen partner hours across the pilot, front-loaded into the first two weeks. And a permanent verification overhead on every AI-assisted document, which does not disappear as the firm gets better at the tool, because the duty does not.
That last item is where firms deceive themselves. A time saving on research that is fully spent on verification is still a real saving, because the verification produces a document you can defend and the old method produced one you hoped was right. But it is not the saving in the vendor’s slide, and planning around the slide is how a firm ends up taking on more matters with the freed hours and skipping the check.
At day ninety you have four options and should pick one in writing.
- Renew and widen. Citation rejection rate is stable and low, seats are being opened, and at least three matters produced something the old method missed.
- Renew at current size. It works for one function and one team. Do not widen until that function is boring.
- Change tool. The use case is real but the output is not checkable fast enough, or the tool is not grounded in Indian judgments. Native Indian legal AI as against a generic model covers what usually goes wrong here.
- Stop. Write down what you tried, on which matter types, and what failed. That paragraph is worth more in eighteen months than the subscription was.
Whichever you choose, the one-page policy, the sign-off rule and the engagement letter paragraph stay. They cost nothing to keep, and they are what you will need the day an associate uses something you have not sanctioned.
Frequently asked questions
Is there any Indian rule that stops a law firm from using AI?
No Indian statute prohibits an advocate from using AI. The Bar Council of India has not issued a rule specifically on AI use by advocates. What binds you are the existing duties: confidentiality to the client, competence, and personal responsibility for what you sign and file. Some High Courts have issued policies on AI in judicial work, and the Supreme Court’s draft AI regulations of June 2026 would require disclosure at filing. Check the position in each court where you appear.
How many seats should a five-lawyer firm buy in month one?
Two. One partner and one associate. Widen at day thirty once you know how often the tool produces a citation that fails checking and how long verification takes. Buying five seats on day one produces five people who try the tool once, ask badly, get a mediocre answer, and never return. Seats can be added in a day; a firm-wide first impression cannot be reset.
Can I put a client’s documents into an AI tool?
Only after you can answer four questions in writing: does the vendor train on your inputs, who inside the vendor can read your content, where is it stored and for how long, and what contract governs the processing. Under the DPDP Act 2023 you engage a processor on a valid contract and remain answerable for security and breach notification. Until those answers exist, ask the legal question without client-identifying material attached.
Do I have to tell my client that the firm uses AI?
There is no general statutory duty to disclose AI use to a client, but you should put it in the engagement letter anyway. It is the only point at which you learn that a particular client objects before you have already used the tool on their matter. Institutional clients frequently have outside counsel guidelines restricting AI use, and those guidelines govern that client’s work regardless of your firm policy.
Do I have to tell the court?
That depends on the court. The Supreme Court’s Draft Regulations for Use of Artificial Intelligence in Courts, 2026, released on 3 June 2026, would require a party or counsel who used AI in preparing a document to disclose it at filing, and place responsibility for fabricated content on the filer. They remain draft provisions. Check the practice direction of the specific court, because the position is not uniform across High Courts.
What is the single most important rule to write down?
That nobody uses a personal AI account for firm work. Every other rule can be relaxed under pressure with limited harm. This one cannot, because a breach of it puts client material somewhere the firm cannot see, cannot audit and cannot delete, and the firm will not find out until a client asks or the lawyer leaves.
Should the pilot start with research or with drafting?
Research. The output is checkable against the judgment text in minutes, so the firm learns quickly and cheaply where the tool is reliable. Drafting errors are less visible and surface later, which makes drafting a poor teacher during a pilot. Add drafting at day sixty, restricted to document types where you already own the template and can judge the output against a known baseline.
How do I know the AI is not making up cases?
You do not know from the output, because a fabricated citation is stylistically identical to a real one. You know by opening the judgment on the court’s portal and finding the paragraph. Make the rule that no citation enters a draft without the operative paragraph pasted alongside it. Tools that retrieve from an indexed corpus and show the source paragraph make this a ten-second check rather than a research task.
What is a reasonable citation rejection rate?
Any stable, non-zero number that your people are actually recording. Zero is the warning sign, because it almost always means nobody is checking rather than that the tool is perfect. Track the rate as a fraction of citations produced, note which matter types and courts generate the failures, and use the pattern to decide where the tool is trustworthy in your practice.
Does the DPDP Act require me to keep client data in India?
No. The DPDP Act 2023 does not impose blanket data localisation. It uses a restriction model under which transfer of personal data outside India is permitted except to countries the Central Government restricts by notification. That is a different and lower bar than localisation. Your confidentiality undertakings to a client, and any outside counsel guidelines, may still be stricter than the statute.
Are court judgments covered by the DPDP Act?
The Act excludes personal data that the individual concerned has made publicly available, and personal data made public under a legal obligation. Published judgments sit differently from a client’s identity documents. Research over public judgments is not the same data-protection question as uploading a client file, and a firm policy that treats them identically will be too restrictive to survive.
Who should own the rollout in a firm with no IT person?
One associate owns the day-to-day pilot, holds the measurement spreadsheet, and is asked about it in every partners’ meeting. One partner owns the policy, the vendor diligence and the sign-off rule. Do not split ownership across all partners, because a tool that belongs to everyone gets reviewed by nobody and quietly lapses at renewal.
What if a partner refuses to use it?
Do not force the tool on them. Force the gate. The partner’s role in the rollout is to read AI-assisted drafts against the primary sources before signing, and that role works even if they never open the tool themselves. In practice a partner who reviews ten such drafts develops an accurate sense of where the tool is reliable, which is most of what personal use would have given them.
How long before a small firm sees a real time saving?
Expect nothing in month one, because the pilot is spent learning to ask and building the verification habit. Measurable time savings on research typically appear once the same lawyer has run the same category of query several times and knows how to frame it. Global surveys report savings in the range of a few hours a week, none measured in India, so treat them as direction and measure your own firm.
Should the clerk and filing staff get access?
Not in the first thirty days. Their work is procedural and deadline-driven, and errors there surface late, which is the opposite of what a pilot needs. Consider read-only access at day sixty for tasks like case status checks and chronology building, where the output is checked against the court record the same day.
What happens if an AI-assisted filing turns out to contain a fabricated citation?
You own it. The Supreme Court’s draft AI regulations state expressly that responsibility for fabricated or false AI-generated content sits with the person who filed it, and no Indian court has treated the tool as a defence. Correct the record with the court immediately, in writing, before the other side raises it. Then find which gate in your process was skipped and close it.
Is a purpose-built Indian legal AI actually different from a general chatbot?
For Indian case law, yes, and the difference is architectural rather than a matter of quality. A general model predicts plausible text and may produce a citation that does not exist. A retrieval-grounded system searches an indexed corpus of Indian judgments and returns the passage it relied on, which is what makes verification fast enough to survive a busy practice. Niyam is built on the second pattern, over Supreme Court and High Court judgments.