Zack Shapiro’s essay on the Claude-native law firm struck a nerve. Seven million views. Thousands of lawyers suddenly wondering if they’re doing it wrong. I read it and thought: he’s right about everything, and he’s only describing one perspective.
Zack is a practitioner. A damn good one. He uses Claude to close deals, draft documents, and outperform teams ten times his size. His essay is the best thing written about AI in legal practice this year.
But here’s what it doesn’t cover: what happens when you’re not just using AI to practice law but also building an AI governance company, investing in AI startups, and advising law firms on how to deploy AI without destroying attorney-client privilege?
I wear four hats. Every single day.
I’m the General Counsel and Chief Trust Officer at Attri, an AI governance and enablement platform for regulated industries. I’m the Chief Legal Officer and General Partner at Twelvefold Ventures, where I evaluate AI companies from the investment side. I serve as counsel and advisor to law firms and legal departments deploying enterprise AI. And I’m building the governance frameworks that companies like Zack’s firm will eventually need to adopt.
These four roles don’t just coexist. They collide. And in the collisions, I’ve learned things about AI in legal that you can’t see from any single vantage point.
This is what that looks like.
Read the essay that got 7 million views
The View from the PeopleSoft Graveyard
Before law school, before Attri, before any of this, I implemented ERP systems. PeopleSoft. Oracle. The heavy machinery of enterprise HR and finance.
Those systems were brutal to deploy. Eighteen-month implementation cycles. Change management nightmares. But when they worked, they worked. HR departments could actually see their workforce data. Finance teams could close their books in days instead of weeks.
Then I went to law school at UT Austin, got my JD on top of my BBA in MIS and my Masters in Technology Commercialization, and walked into the legal industry.
I was stunned.
Not by the complexity of the law. By the absence of technology.
Lawyers were doing in 2015 what finance teams had stopped doing in 2005. Manual review. Email-based workflows. Knowledge management that consisted of knowing which partner to call. Billing systems that hadn’t fundamentally changed since the 1990s.
The gap between what I’d seen in enterprise technology and what I saw in legal wasn’t just a gap. It was a canyon.
I spent years thinking about how to bridge it. And then, on the day OpenAI announced ChatGPT, I stopped thinking and started building.
Attri was born that day. Not because anyone had some grand business plan. Because we’d spent years watching technology-starved industries suffer, and we could see, instantly, viscerally, that this was the moment everything changed.
Why Governance Isn’t a Dirty Word
Zack makes a compelling case that general-purpose AI beats specialized legal AI tools. I agree with him. But he’s writing from the perspective of a practitioner who controls his own environment. He’s the lawyer, the technologist, and the compliance officer, all in one person.
Most law firms don’t work that way.
When a 200-lawyer firm wants to deploy Claude, and they should, they don’t just need to figure out prompting. They need to answer questions that would make Zack’s head spin:
Who has access to what? Not every associate should be feeding privileged client communications into the same AI system. Role-based access isn’t a nice-to-have. It’s a malpractice prevention mechanism.
Where does the data go? Zero data retention APIs exist. Great. But can your managing partner explain that to a client who reads a headline about an AI data breach? Can your general counsel certify it in a client engagement letter? The technical answer and the governance answer are different problems.
What’s the audit trail? When a junior associate uses AI to draft a motion, and that motion contains a hallucinated citation, and this still happens, even with Claude, who’s accountable? The associate who prompted it? The partner who signed it? The firm that deployed the tool without adequate training?
How do you preserve privilege? This is the one that keeps me up at night. Zack addresses it well, the ABA guidance, the agent/instrumentality exception, the engagement letter provisions. But he’s describing how one lawyer manages privilege for himself. Scaling that to an enterprise requires governance infrastructure that most firms haven’t built yet.
This is what Attri does. We don’t compete with Claude. We make it safe to deploy Claude at scale in environments where a single misstep can trigger a malpractice claim, a regulatory investigation, or the loss of attorney-client privilege for an entire matter.
Governance isn’t the opposite of innovation. It’s what makes innovation sustainable.
Piece the set off the discussion
The Investor’s View: What Founders Get Wrong
At Twelvefold Ventures, I’ve reviewed hundreds of pitches from legal AI startups. The pattern I see most often is founders who’ve built impressive technology and have no idea how regulated industries actually buy.
Here’s the uncomfortable truth most legal AI founders don’t want to hear:
The sales cycle isn’t 30 days. It’s 300 days. Law firms don’t buy software the way SaaS companies do. There are partnership votes. Ethics committee reviews. Conflicts checks. Malpractice insurance consultations. I’ve seen deals that were technically closed take another six months to get through a firm’s risk management process.
Your security questionnaire is your product demo. In regulated industries, the first thing a sophisticated buyer looks at isn’t your feature list. It’s your SOC 2 report. Your data processing agreement. Your incident response plan. If those documents aren’t as polished as your UI, you’ve already lost.
“AI-powered” isn’t a differentiator anymore. Every legal tech startup says they use AI. The firms that are actually buying want to know: which model, what version, what’s the data retention policy, where are the servers, who trained it, and what happens when the model gets updated and your outputs change?
The legal AI companies that will win aren’t the ones with the best models. They’re the ones that understand the compliance tax is real, it’s permanent, and it’s actually a moat if you embrace it instead of fighting it.
I know this because I live on both sides. I shape the governance layer at Attri, and I evaluate the companies trying to sell into regulated industries at Twelvefold. The founders who get it, who build compliance into their architecture from day one, are the ones I invest in.
How I Actually Use AI Across Four Roles
Zack described his three modes of using Claude: Chat, Cowork, and Code. I use all three. But the way they layer across my four roles creates something he didn’t describe.
As Attri’s GC & Chief Trust Officer: AI Building AI Governance
There’s a delicious irony in using Claude to build a company that helps other companies govern their use of AI.
Every morning, I use Claude to scan the regulatory landscape. EU AI Act enforcement updates. NIST AI RMF developments. State-level AI legislation, there are now over 40 states with some form of AI regulation pending or enacted. I can’t track this manually. No one can.
Claude doesn’t just summarize the news. I’ve built custom instructions, what Zack calls “skills”, that analyze each regulatory development through three lenses simultaneously: What does this mean for Attri’s product roadmap? What does this mean for our clients? What does this mean for our portfolio companies at Twelvefold?
One prompt. Three strategic outputs. Every morning.
I also use Claude to draft client-facing governance frameworks. When a law firm comes to Attri and says “we want to use AI but we don’t know where to start,” I don’t hand them a generic checklist. I have Claude generate a customized AI governance framework based on their firm size, practice areas, client base, and risk profile. The framework covers acceptable use policies, training requirements, privilege preservation protocols, and incident response procedures.
It takes me an hour to produce what used to take a consulting team two weeks.
As Twelvefold’s CLO & GP: AI-Powered Due Diligence
When a legal AI startup pitches Twelvefold, I use Claude to do something most VCs don’t: real-time technical due diligence during the pitch itself.
The founder says they’ve built a “proprietary legal language model.” I ask Claude to analyze their technical claims against what’s publicly known about their architecture. Within minutes, I know whether they’re actually fine-tuning a model or just wrapping an API. This isn’t about catching liars, most founders are honest. It’s about having informed follow-up questions that show I understand their technology at a level most investors don’t.
For deal documentation, I use Claude the way Zack describes, feeding it the investment documents, the company’s terms, the market comps. But I add a governance layer. I have Claude flag any provisions that would create conflicts with our existing portfolio companies’ AI governance requirements. Because if we invest in a legal AI company that can’t pass our own governance standards, we’ve got a credibility problem.
As Outside Counsel: Privilege-Preserving AI Practice
When I advise law firms and legal departments on AI deployment, I practice what I preach. But I do it with a critical difference from Zack’s approach: I never let AI touch anything that could compromise privilege without first routing it through a governance checkpoint.
Here’s what that looks like in practice.
A client, a mid-size firm deploying AI for the first time, asks me to review their draft AI acceptable use policy. I use Claude to analyze the policy against the ABA’s formal opinions on AI, the state bar guidance for every jurisdiction where the firm practices, and the latest case law on AI and privilege.
But I don’t just dump the policy into Claude raw. I strip client-identifying information first. I use zero-data-retention API endpoints. And I log every interaction in our governance system so there’s a complete audit trail showing exactly what information was shared with AI, when, by whom, and under what data handling conditions.
Is this extra work? Yes. Is it necessary? Ask the first firm that loses privilege because they can’t demonstrate adequate safeguards around their AI usage.
As an AI Governance Advisor: Teaching the Teachers
The most important thing I do with AI isn’t any specific task. It’s demonstrating to skeptical lawyers that governance and innovation aren’t enemies.
When I walk into a law firm for an AI governance workshop, I don’t start with slides about risk. I start by showing them what’s possible. I pull up Claude, I show them how to draft a contract analysis in minutes, how to research a novel legal question with citations they can verify, how to generate a first draft of a client memo that’s 80% there.
Their eyes light up.
Then I show them everything that can go wrong. The hallucinated case citations. The privilege exposure. The ethical violations lurking in unmonitored AI usage. The regulatory hammer that’s coming.
Their eyes get serious.
Then I show them the governance framework that lets them capture the first experience without the second. That’s the moment it clicks. Governance isn’t a cage. It’s a safety net that lets you fly higher.
The Privilege Question, Scaled
Zack handles the privilege question elegantly for a solo practitioner. The ABA’s formal opinions, the agent/instrumentality exception, the engagement letter provisions, he’s got it right.
But here’s the enterprise version of that problem, which is where it gets genuinely hard:
Multi-jurisdictional complexity. A firm with offices in New York, California, Texas, and London is subject to different ethical rules in each jurisdiction. New York’s guidance on AI is different from California’s. The SRA in England has its own framework. A governance system that works in one jurisdiction may violate rules in another. I’ve seen firms deploy AI tools that were compliant in their home jurisdiction but technically violated ethical rules in a state where they had a satellite office.
Client-specific requirements. Increasingly, sophisticated clients are adding AI provisions to their outside counsel guidelines. Some Fortune 500 companies now require that any AI used on their matters be listed, that the specific model and version be disclosed, and that the law firm certify zero data retention. Others go further and prohibit AI usage on their matters entirely. A firm-wide AI deployment that ignores these client-specific requirements is a breach of the engagement, full stop.
The training data problem. When you use Claude (or any AI) to analyze a contract, the insights it generates are informed by patterns in its training data. If those patterns include information from other clients’ confidential matters, even indirectly, you’ve got a privilege problem that no engagement letter can fix. This is why zero-data-retention isn’t just a technical specification. It’s a privilege preservation requirement.
Insurance implications. Most legal malpractice policies were written before AI existed. The coverage for AI-related claims is, at best, ambiguous. Some carriers are already adding AI exclusions. Others are offering AI-specific riders, at significant premium increases. A governance framework that doesn’t account for insurance implications is incomplete.
These aren’t theoretical problems. These are conversations I’m having with firms right now, today, in 2026
What I Tell Every Law Firm
After hundreds of these conversations, I’ve distilled my advice to five principles:
Start with governance, not technology. Don’t ask “which AI tool should we buy?” Ask “what’s our acceptable use policy, and who’s responsible for enforcing it?” The technology decision is easy once the governance framework exists.
Privilege preservation is non-negotiable. Zero data retention. Audit trails. Client-specific protocols. If your AI vendor can’t provide all three, find a different vendor. This isn’t about being cautious. It’s about being competent.
Training is more important than tooling. The best AI tool in the world is useless, or dangerous, in the hands of a lawyer who doesn’t understand how it works, what it can’t do, and when to verify its output. Invest more in training than in technology.
Build for the regulatory future, not the regulatory present. The AI governance landscape is changing faster than any regulatory environment I’ve seen in 25 years. The EU AI Act is just the beginning. NIST frameworks are evolving quarterly. State legislation is proliferating. Build your governance framework to be adaptable, not static.
Measure everything. How many people are using AI? What are they using it for? How often is the output modified before use? What’s the error rate? If you can’t answer these questions, you don’t have governance, you have hope. And hope is not a compliance strategy.
The Real Competition
Zack argues that one lawyer with Claude beats big firms. He’s right. But that’s not the competition that keeps me up at night.
The real competition isn’t between AI-enabled lawyers and traditional lawyers. It’s between regulated industries that embrace AI governance and those that don’t.
The legal industry has a once-in-a-generation opportunity. For the first time, the technology exists to fundamentally reimagine how legal services are delivered, not just faster, but better. More accessible. More affordable. More human.
I’ve seen it at Attri. Firms that deploy AI with proper governance don’t just work faster. They serve more clients. They take on cases they previously couldn’t afford to touch. They give junior associates meaningful work instead of document review. They spend their time on judgment and strategy, the things that actually require a law degree, instead of production and process.
But none of that is possible without the governance layer. And the firms that build that layer first will have an insurmountable advantage.
I came from a world where HR and finance teams had mature technology stacks. I watched those industries transform over decades. The legal industry is about to compress that same transformation into years.
I’m helping build Attri to make sure that transformation happens responsibly. I’m investing through Twelvefold in the companies that will drive it. I’m advising firms on how to navigate it. And I’m practicing law with the same tools I’m helping others deploy.
Four hats. One AI. And the conviction that the legal industry’s best days are ahead of it.
