PreviewYou're previewing CLO AI Chambers. Sign in to use it.Sign in
← Tools

Signature tool · CLO AI Chambers

Legal AI use-case triage

For any proposed AI use in legal or the wider business: how sensitive is the data, could privilege be lost, what does the vendor do with the data, how accurate must the output be, who reviews it and where does it go? A fixed rule table (shown on the page) turns your answers into a verdict and a list of required controls. Hard stops, such as privileged data with a vendor that may train on it, always mean don't. The verdict is calculated in code; AI only explains it.

A structured first view, not legal advice. The verdict comes from the fixed rule table below; a lawyer should confirm it for anything high-stakes.

What is the most sensitive business information the AI will see?

Pick the highest class present in prompts, files or connected sources.

Will it process personal data?

Sensitive includes health, biometric, financial, children's or other special-category data.

Which kind of tool and terms?

The product tier you will actually use, not the vendor's best tier.

May the vendor train or improve its models on our inputs or outputs?

Read the contract, not the marketing page. If you don't know, choose Unclear.

Is any third-party information restricted by an NDA, protective order or client terms?

For example, counterparty documents under an NDA or discovery material under a protective order.

Where will the output go?

Choose the furthest destination.

How accurate must the output be?

High means people will rely on legal authorities, figures or advice in it.

What human review happens before the output is used?

Review by someone qualified to spot errors.

Does it affect decisions about individuals?

For example, hiring, performance, credit, insurance, access to services or legal claims against a person.

How much regulatory exposure does this use have?

High: a regulated high-risk area (for example, EU AI Act high-risk uses), active regulator interest, or a sector regulator's AI rules.

The rule table (23 rules)

Each answer has risk points; the risk score is 100 × points ÷ maximum possible points for the questions answered. Verdict: any hard-stop rule that matches → Don't. Otherwise, if any question is unanswered → incomplete. Otherwise, any control rule that matches, or a risk score at or above 40 → Approve with controls. Otherwise → Approve.

RuleWhenResult
Confidential or privileged data with a vendor that may train on it.What is the most sensitive business information the AI will see?: Confidential (company or client confidential, trade secrets) / Privileged (legal advice or work product)May the vendor train or improve its models on our inputs or outputs?: Yes, or by default unless we opt outDon't
Privileged data where the vendor's training terms are unclear. For privileged material, treat unclear as yes.What is the most sensitive business information the AI will see?: Privileged (legal advice or work product)May the vendor train or improve its models on our inputs or outputs?: Unclear / not yet confirmedDon't
Privileged data in a consumer tool. Consumer terms can defeat confidentiality and privilege.What is the most sensitive business information the AI will see?: Privileged (legal advice or work product)Which kind of tool and terms?: Consumer tool or personal accountDon't
Confidential data in a consumer tool or personal account.What is the most sensitive business information the AI will see?: Confidential (company or client confidential, trade secrets)Which kind of tool and terms?: Consumer tool or personal accountDon't
Sensitive personal data with a vendor that may train on it, or where that is unclear.Will it process personal data?: Sensitive personal dataMay the vendor train or improve its models on our inputs or outputs?: Yes, or by default unless we opt out / Unclear / not yet confirmedDon't
Third-party information restricted by an NDA, protective order or client terms in a consumer tool.Is any third-party information restricted by an NDA, protective order or client terms?: Yes, restricted third-party informationWhich kind of tool and terms?: Consumer tool or personal accountDon't
Restricted third-party information with a vendor that may train on it.Is any third-party information restricted by an NDA, protective order or client terms?: Yes, restricted third-party informationMay the vendor train or improve its models on our inputs or outputs?: Yes, or by default unless we opt outDon't
Output filed with a court or regulator without a qualified person reviewing every output.Where will the output go?: Filed with a court or regulatorWhat human review happens before the output is used?: Sampled or occasional review / No review before useDon't
Decisions about individuals made by AI with no human review.Does it affect decisions about individuals?: It makes or effectively makes the decisionWhat human review happens before the output is used?: No review before useDon't
High-accuracy output used with no human review.How accurate must the output be?: High — legal authorities, figures or advice relied onWhat human review happens before the output is used?: No review before useDon't
Confidential data while the vendor's training terms are still unclear.What is the most sensitive business information the AI will see?: Confidential (company or client confidential, trade secrets)May the vendor train or improve its models on our inputs or outputs?: Unclear / not yet confirmedControls
Privileged material is involved.What is the most sensitive business information the AI will see?: Privileged (legal advice or work product)Controls
Personal data is processed.Will it process personal data?: Ordinary personal data (names, contact details, HR records) / Sensitive personal dataControls
Restricted third-party information is involved.Is any third-party information restricted by an NDA, protective order or client terms?: Yes, restricted third-party informationControls
People will rely on legal authorities, figures or advice in the output.How accurate must the output be?: High — legal authorities, figures or advice relied onControls
Output goes to a court or regulator.Where will the output go?: Filed with a court or regulatorControls
Output goes to a counterparty or customer.Where will the output go?: Documents sent to a counterparty or customer, reviewed before sendingControls
Output reaches customers or the public automatically.Where will the output go?: Shown to customers or the public automatically (no review of each output)Controls
Only sampled review for output that people rely on.What human review happens before the output is used?: Sampled or occasional reviewHow accurate must the output be?: Medium — summaries relied on with checks / High — legal authorities, figures or advice relied onControls
The AI affects decisions about individuals.Does it affect decisions about individuals?: It informs decisions a human makes / It makes or effectively makes the decisionControls
High regulatory exposure.How much regulatory exposure does this use have?: High — high-risk category or active regulator interestControls
Sector or data protection rules apply.How much regulatory exposure does this use have?: Moderate — sector rules or data protection duties applyControls
A consumer tool is used (only for public or internal data).Which kind of tool and terms?: Consumer tool or personal accountControls

Sign in to save your work privately and come back to it. Export works without an account.

The other signature tool →📑 AI contract clause library