A prospective client visits your firm’s website at 9 p.m. and starts interacting with an AI intake assistant.
It asks what happened. It collects names, dates, and other details. It summarizes the matter and explains what will happen next.
No lawyer has reviewed the exchange. No conflicts check has been completed. The prospect may not know where the information they entered is being stored, whether a third-party vendor can access it, or how the AI decided what to say next.
Marketing may have selected the platform. IT may have approved the technology. Intake staff may administer the workflow.
But who owns what just happened?
That question is becoming increasingly important as law firms use AI not only to create marketing content, but also to respond to inquiries, qualify prospects, summarize intake information, route matters, and automate follow-up.
The technology may be new. The accountability problem is not.
Accountability does not follow the technology
Law firms routinely delegate work. Marketing agencies create campaigns. Technology teams select platforms. Vendors provide software. Intake specialists interact with prospective clients.
AI adds another participant to that chain.
But using AI does not transfer the lawyer’s professional responsibilities to the technology provider, marketing team, or outside agency.
Law firms still need to consider familiar obligations around supervision, confidentiality, truthful communications, conflicts, and professional judgment.
The practical problem is that AI often enters the firm through one department while creating risks that belong to several others.
The risk is often at the handoffs
Consider four common handoffs in an AI-enabled client journey.
Marketing → AI → Prospect
Marketing may configure a chatbot or automated campaign. But who determines what the system is allowed to say about the firm, its capabilities, likely outcomes, or the prospect’s legal situation?
Prospect → AI → Firm data
A prospective client may disclose highly sensitive facts before ever speaking with a lawyer. Who decides what information the system should collect, where it is stored, how long it is retained, and what the vendor may do with it?
AI intake → Qualification and routing
AI may categorize an inquiry, summarize a potential matter, or recommend where it should be routed. But should it also determine that a matter is unlikely to be valuable, outside the firm’s criteria, or not worth pursuing?
AI output → Lawyer
At some point, human judgment has to enter the workflow. The important question is whether the firm has deliberately decided where that point is.
These are not primarily technology questions.
They are ownership questions.
Four decisions every firm should make
A useful way to govern AI in marketing and intake is to define four boundaries before deployment.
1. What may the AI say?
An intake system can collect information, explain the firm’s process, schedule a consultation, or provide approved general information.
But firms should be much more deliberate when a system begins assessing legal rights, suggesting what someone should do, predicting outcomes, or creating the impression that an attorney-client relationship has already begun.
The precise boundary will depend on the use case and jurisdiction.
What should not be ambiguous is who inside the firm has authority to define that boundary.
2. What should the prospect know?
Firms should also decide how transparent they want to be when prospective clients are interacting with AI.
Does the user know that the response is AI-generated? Is it clear that submitting information does not necessarily establish an attorney-client relationship? Are limitations explained before sensitive information is collected?
These should not be left to whatever default language came with the vendor’s software.
Someone at the firm should approve them.
3. What information may the AI receive?
Client intake can involve names, medical information, financial details, employment disputes, allegations of misconduct, or other highly sensitive information.
Before deploying an AI tool, the firm should understand where that information goes.
Can the vendor use it to improve a model? How long is it retained? Who can access it? Is it transferred to other service providers? Can the firm delete it?
Vendor due diligence therefore becomes part of AI governance, not simply an IT procurement exercise.
The basic question is straightforward:
Who approved what happens to the prospect’s information after they click “send”?
4. What may the AI decide?
This may be the most important boundary.
There is a meaningful difference between asking AI to:
Route this inquiry to the employment-law team.
and asking it to:
Determine whether this matter is worth pursuing.
The second involves considerably more judgment.
As AI becomes embedded in lead scoring and intake qualification, firms should examine whether systems could consistently disadvantage certain types of matters, communities, languages, or prospective clients.
The greater the consequence of the decision, the stronger the case for human review.
Ownership does not mean finding one AI czar
The answer is not necessarily to give one executive responsibility for every AI decision in the firm.
AI-enabled intake crosses several functions.
A practical model is to make four forms of ownership explicit:
| Area | Core responsibility |
| Business | Why the AI is being used and what business outcome it supports |
| Technology & Data | Security, integrations, vendors, retention, and data controls |
| Workflow | How the tool fits into intake and where escalation occurs |
| Professional Responsibility | Ethical boundaries, supervision, communications, and required lawyer review |
The titles will differ by firm.
At a large firm, these responsibilities may sit with a CMO, CIO, COO, General Counsel, and designated partners.
At a smaller firm, one managing partner may perform several of these functions.
The roles are functions, not headcount.
What matters is that they are explicit.
A practical way to make ownership explicit is to separate accountability, approval, execution, and documentation by risk domain.

The five-question front-door test
Firms do not need to begin with a fifty-page AI policy.
Start by walking through every place where AI touches a prospective client: advertising, website chat, intake forms, lead qualification, matter summaries, automated emails, and follow-up.
For each use case, ask five questions:
- What is the AI allowed to say?
- What information is it allowed to collect?
- What is it allowed to decide or recommend?
- Where is human review required?
- Who is accountable for each of those decisions?
If the answers are unclear, the governance gap already exists.
AI can make law-firm marketing and client intake faster, more responsive, and more consistent.
The problem begins when the technology crosses organizational boundaries faster than accountability does.
The firms that manage this well will not necessarily be the ones with the most sophisticated AI tools.
They will be the ones that know exactly who owns what happens at the front door.