Unit 12 / 12

Legal Limits of AI Output and Professional Liability

Gains:

  • Be able to clarify that AI does not provide legal advice and professional responsibility remains with the human
  • Ability to define human inspection and verification gates in high-risk tasks
  • Ability to establish an internal governance and accountability framework that documents the use of AI

Throughout this module, we have seen that artificial intelligence (AI) is a powerful speed multiplier in contract review, drafting, legal research and compliance work. In this last unit we draw the most important line: AI is an assistant, not a lawyer. It does not provide legal advice, it does not replace the professional, and the responsibility always remains with the person. This line is not a restriction, but a prerequisite for using technology safely and sustainably. The same principle applies in other safety-critical professions: in engineering, AI may draft a construction calculation, but in a safety-critical job, AI output is not a substitute for approval from a competent and competent engineer. In law, the final analysis, decision and responsibility lies with the competent professional. In this unit we will establish an internal governance and accountability framework that documents the use of AI.

Let's clarify the terms. Professional responsibility is the legal and ethical responsibility that arises when fulfilling the requirements of a profession; Faulty work may result in compensation and discipline. Human-in-the-loop is the principle that a critical decision is reviewed and approved by an authorized human before it goes into effect. Governance is the framework that determines who will use AI, under what rules and under what conditions. A verification gate is a mandatory checkpoint that the output must pass before it can be used. Traceability (audit trail) is the record of which output was produced, how and by whom it was approved.

Bottom Line: AI Doesn't Give Recommendations

AI-generated text, no matter how professional it may appear, is not legal advice. There are three concrete reasons for this. First, AI cannot fully know the full context of your incident, the parties' true intentions, and the current applicable law; It produces from general patterns. Second, the information he gives may be fabricated due to the risk of hallucination (see Unit 5). Third, it cannot bear legal liability; In case of a mistake, it is always the professional who is held accountable, compensated or disciplined.

AI output should therefore be viewed as an expert's “raw material”: valuable, accelerating, but unusable without processing and validation.

Caution: "The output came from the AI" is not a defence. The responsibility for every text presented to a client, a court or a regulator lies with the professional presenting it. It is not legally possible to transfer responsibility to the vehicle or the person who wrote the prompt.

Audit According to Risk Level

Not every task requires the same level of supervision. For a low-impact, easily retrievable task, light control is sufficient; A high-impact, hard-to-reverse decision requires mandatory human oversight and documentation. Ranking risk based on task impact and reversibility preserves both safety and efficiency.

Risk level

sample task

Required inspection

low

Internal note summary, term explanation

Light review

medium

Contract summary, checklist

Expert control + source verification

high

Petition, contract to be signed, legal opinion

Mandatory human approval + documentation

critical

Presentation to the court, regulatory statement

Multi-eye approval + full traceability

Your role: an AI governance advisor.Propose a risk-control matrix for the following task list:| Quest | Impact (low/medium/high) | Retrievability | Recommended inspection gate | Who approves | Documentation required | Recommend mandatory human approval for high-impact and difficult-to-reverse tasks. Mark your suggestions as "must be approved by the organization"; strict rule imposition.<tasks>[tasks that the legal/compliance team performs with AI]</tasks>

Establishing a Governance Framework

The use of distributed and person-dependent AI will sooner or later lead to a mistake. A corporate governance framework; It determines which tasks AI can be used for, what data can be entered (see Units 9 and 11), which authentication gates are mandatory, and how usage will be recorded.

Draft an “AI use policy” for our legal/compliance team.Sections:1) Purpose and scope2) Permitted and prohibited uses (task-based)3) Data rules (which data to which medium; masking; privileged document)4) Verification gates (hallucination/attribution verification, source confirmation)5) Human oversight and approval levels (based on risk level)6) Documentation and traceability7) Breach and liability[TO BE FILLED] leave gaps; Check "legal approval required" for legal content. Don't make up a legal provision on your own.

It is also useful to have a short "usage tag" attached to each important deliverable; This makes traceability practical.

Generate a short "AI usage tag" template to be added to each AI-powered output: which task, which tool, data class entered, verification steps performed, verifier, person approving, date. Make it a 6-8 line form that is easy to fill out.

Weak Prompt / Strong Prompt

Weak approach:Transmit AI output directly to client/court; Be quick.

Result: Unverified, unaccountable, untenable in case of error. A single hallucination or context error can cause serious harm.

Strong approach: [audit according to risk level + mandatory verification gates + source confirmation + authorized human approval + documentation with user ID]

The result: a verified and traceable output that benefits from its speed but has clear accountability. AI increases efficiency; The process provides assurance.

Who is responsible? Quick Look

  • Accuracy of output: depends on the professional who uses it.
  • The work presented to the client/court: the person who signed/presented it.
  • Data protection and privacy: on the team processing the data (not the tool provider).
  • Governance and rule: in the institution and in management.

In no case is responsibility transferred to the "AI" or the "assistant who writes the prompt".

Three Mini Cases

Case 1 — Location of responsibility. At one agency, an assistant sent a compliance report he prepared with AI directly to the regulator; The report contained unverified data. The "AI wrote it" defense didn't work when the problem arose; The responsibility was deemed to belong to the institution presenting the report and the official who should approve it. The institution then mandated that "no external declaration shall be sent without authorized approval and source confirmation".

Case 2 — Risk-level audit. When a legal team applied the same burdensome approval process to all tasks, AI was not getting any results. They established a risk-audit matrix: internal memorandum summaries went through light scrutiny, contracts and petitions for signature were subject to mandatory double-blind approval. Thus, while speed was maintained in low-risk jobs, security increased in high-risk jobs; The team began to use AI both widely and confidently.

Case 3 — The value of traceability. In an audit, “how did you do this contract review, did you use AI, did you verify?” came the question. The team that applied the usage tag showed with documentation which tool each output was produced with, which verification steps it went through, and who approved it. The auditor saw that the process was controlled and did not write any additional findings. Documentation transformed the use of AI from a risk into a managed process.

Common mistakes

  • Transferring responsibility to the vehicle. “AI wrote it” is not a defense; The responsibility always lies with the person.
  • Applying the same control to every task. Either the efficiency decreases or the high risk remains uncontrolled; Rate by risk level.
  • Bypassing verification gates. In particular, the output should not go out without attribution and source confirmation.
  • Not putting governance in writing. Personal, irregular use will sooner or later lead to an error.
  • Not maintaining traceability. If who produced what and how they verified it is not documented, a gap in control and disputes will arise.
  • Leaving AI unregulated because it is “enough advanced.” Increasing ability does not mean that responsibility disappears from people.

In summary

AI is a powerful speed multiplier in law, but it does not provide legal advice and does not replace the professional; The final analysis, decision and responsibility always lies with the person in authority. The way to make this sustainable is with a governance framework: rate tasks by risk level, impose mandatory human audit and verification gates on high-risk work, enforce data and privacy rules, and make every output traceable with a usage tag. This way you benefit from the speed of AI and maintain accountability and trust. AI generates and accelerates; The competent professional decides and bears the responsibility for what will be presented and its consequences.

Application task

List the tasks your team does with AI. (1) With the risk-audit matrix prompt, rate each task according to impact and reversibility and assign audit gates. (2) Produce a draft AI use policy; Collect "legal approval required" signs. (3) Create a usage tag template and apply it to your final printout. (4) Put in writing the rule that "No external declaration goes without authorized approval and source confirmation."

checklist

  • [ ] Are tasks rated by risk level (impact + reversibility)?
  • [ ] Has mandatory human consent been defined for high-risk missions?
  • [ ] Are attribution/source verification gates included in the process?
  • [ ] Have data and privacy rules (Units 9 and 11) been added to the framework?
  • [ ] Can every important output be tracked by usage tag?
  • [ ] Has it been clarified in writing that the responsibility lies with the human?
  • [ ] Has the AI ​​usage policy been prepared for legal approval?

Module Exam

1. When having AI summarize a long contract, which application most increases the reliability of the output?

  • A) Linking each determination in the summary to the source with the relevant article number and short quote ✔
  • B) Request the summary as short as possible, in a single paragraph
  • C) Instructing the model to 'make no mistakes' and trusting the result
  • D) Signing the contract based only on the summary without reading it at all

Annotation: Linking each finding in the AI summary to the source with the relevant item number and short quote makes the summary verifiable and allows you to quickly catch fabricated information (hallucination). This is the most critical credibility check for legal review.

2. What is the most effective input to AI when evaluating risk clauses in a supply contract?

  • A) Just 'is this contract risky?' to ask
  • B) Giving a playbook containing the standard positions of the institution and classifying the items according to these criteria ✔
  • C) Asking AI to rewrite the contract in favor of the other party.
  • D) Counting only the number of characters of the items

Description: Giving a playbook of the organization's standard positions allows the AI to classify items as 'acceptable / should be negotiated / rejected' according to your criteria. It's much more useful than the general 'is it risky' question.

3. Why is AI 'missing clause' analysis valuable in contract review?

  • A) Because it is only useful for finding spelling errors
  • B) Because it shortens the contract
  • C) Because it introduces protective clauses that should have been present but were never included in the contract ✔
  • D) Because it determines who the other party is

Explanation: Part of the risk is not in the written clause, but in clauses that should be present but are not in the contract (e.g. intellectual property transfer, data processing, liability after termination). I asked AI 'what are the clauses that are expected in this type of contract but are missing here?' Asking: reveals these gaps.

4. Which approach most improves quality and consistency when drafting contracts with AI?

  • A) Asking the AI to write the topic from scratch without giving any context
  • B) Copying any contract found on the internet and using it directly
  • C) Putting the draft into force without reviewing it
  • D) Provide a template and scenario information approved by the institution and have AI adapt it ✔

Description: Instead of producing from a blank page, giving a template and scenario information approved by the institution and having the AI adapt it; It both maintains the institutional standard and reduces the risk of hallucinations. The approved template acts as an 'anchor' and keeps the model from drifting away from the text.

5. When reviewing a non-disclosure agreement (NDA) with AI, which distinction should be made clear at the very beginning?

  • A) Whether the NDA is one-way or two-way and on which side the obligation lies ✔
  • B) Total number of pages of the document
  • C) What font is the contract written in?
  • D) Whether the other party has a logo or not

Disclosure: Whether the NDA is one-way (only one party disclosing information) or two-way (mutual disclosure) determines the entire balance of obligations. Getting the AI ​​to query this first is key to reading clauses like confidentiality period, exclusions, and return obligation correctly.

6. What is the most serious risk when doing legal research with AI and how is it managed?

  • A) AI is too slow; more powerful hardware is used
  • B) AI's ability to fabricate non-existent precedent/citation; Each source is verified from the primary text ✔
  • C) AI writes the text in very formal language; style is corrected by hand
  • D) AI only outputs in English; translation is done

Description: AI can fabricate non-existent precedent, statute, or citation (hallucination). Therefore, every source, decision and reference made by AI must be verified from the primary/official text (official legislation, decision text). AI is for preliminary research, not the final authority.

7. When drafting a petition with AI, which step strengthens the content the most?

  • A) Writing the petition in as long and fancy language as possible
  • B) Just write your own request and ignore counter arguments
  • C) Interrogating possible counter objections in advance and answering them on the basis of fact-law-demand ✔
  • D) Submitting the petition directly to the court without verifying it

Explanation: A good petition anticipates not only its own argument but also the other party's possible objections. Ask the AI ​​'what objections might arise to this request and how to respond to each?' Asking questions like this builds the draft on the fact-law-demand framework and closes the weak points in advance.

8. What is the most useful form of output to request from AI when translating a regulation into an actionable compliance checklist?

  • A) Printing only the title and date of the edit
  • B) Combining all items into one long paragraph
  • C) Being content with arranging the requirements in alphabetical order
  • D) Putting the requirements into a control chart with columns for responsible role, required evidence and satisfaction status ✔

Description: Every requirement; Putting it in a table with responsible role, evidence/documentation, and satisfaction status (yes/no/partial) makes the list auditable and actionable. The abstract list of items cannot be followed alone.

9. What is the most valuable addition to ask from AI to make a corporate policy draft auditable?

  • A) Matching each obligation with the responsible role/RACI ✔
  • B) Keeping the policy as abstract and general as possible
  • C) List only legal citations
  • D) Adding plenty of legal jargon to the policy.

Explanation: Mapping each obligation with the RACI (Responsible/Approving/Consulted/Informed) or at least the 'responsible role' clarifies the policy 'who will do what' and establishes who will be held accountable in the audit. A policy without a role cannot be implemented.

10. What should an expert do who wants to summarize a document containing the client's TR ID number, name and case details with AI?

  • A) Paste the document as it is and get results quickly
  • B) Masking and anonymizing personal data and/or using an approved tool with corporate data assurance ✔
  • C) Just add 'confidential' to the end of the document
  • D) It is enough to send the document once and then delete the chat

Explanation: Personal data and client secrets should not be entered directly. The right approach; masking and anonymizing identity information and/or using an approved tool with institutional data assurance (not using in education, data retention policy). This is a requirement of both KVKK and confidentiality obligations.

11. Which is the correct approach when evaluating the intellectual property and copyright status of a text produced with AI?

  • A) AI output is always automatically proprietary and completely unique
  • B) AI output cannot be used under any circumstances
  • C) AI output is not assumed to be original/free; provenance, similarity risk and ownership are evaluated ✔
  • D) Copyright is only valid for music, so it is unimportant for texts.

Disclosure: Copyright ownership of AI output may be uncertain depending on country and situation; Additionally, the output may resemble third-party protected content. Therefore, AI output should not be assumed to be original/free without verification, source and similarity risk should be evaluated, and corporate ownership should be clarified by contract.

12. What is the rule of thumb for using AI in terms of attorney-client privilege (confidential/privileged document)?

  • A) Privileged documents can be freely entered into every AI tool
  • B) Use of AI is irrelevant as the privilege only applies in court
  • C) If the document is encrypted, it does not matter which tool it is entered into.
  • D) Confidential/privileged documents should only be processed in approved vehicles with appropriate safeguards, otherwise privilege and confidentiality may be compromised ✔

Explanation: Privilege may be compromised and confidentiality may be violated when privileged and confidential documents are accessed through third-party tools that do not have data security and confidentiality commitments. Therefore, such documents should only be processed on approved vehicles with appropriate contractual and technical safeguards.

13. Where does professional liability lie regarding the use of AI in a corporate legal/compliance team?

  • A) The final analysis, decision and responsibility always lies with the competent human professional; AI is a support tool only ✔
  • B) Since the output comes from AI, the responsibility lies with the tool provider
  • C) If AI is advanced enough, human verification will not be needed
  • D) The responsibility lies with the assistant personnel who wrote the prompt.

Description: AI is a speed multiplier and blueprint generator; It does not provide legal advice and is not a substitute for a professional. The final analysis, decision and responsibility always lies with the competent human professional; The outputs must be verified by an expert.

14. What governance control is most appropriate for using AI in a high-stakes legal task (e.g., final approval of a contract)?

  • A) Submit AI output directly for approval to save time
  • B) Require a human inspection door that is reviewed and approved by a qualified professional and document use ✔
  • C) The person who wrote the prompt gives the approval alone.
  • D) Just ask the AI 'are you sure?' asking and trusting the answer

Explanation: For high-impact and hard-to-reverse decisions, AI output should not be applied directly; Human-in-the-loop porting, reviewed and approved by a qualified professional, must be required and this use must be documented.