Last Tuesday, I tried to draft a simple amendment.
I wasn’t stuck on the law.
I was stuck on where thinking was allowed to happen.
My phone was already drafting a response to a client’s text.
Outlook was quietly suggesting next steps in the background.
My browser sat open, ready to generate a full memo the moment I dropped in context.
None of this felt reckless.
All of it felt helpful.
And yet, for the first time, I realized something uncomfortable:
I didn’t know who was actually in control.
Information was moving—sometimes automatically—across devices, platforms, and models. Not maliciously. Not even incorrectly. Just quietly.
Internal → external.
Privileged → processed.
Draft → acted on.
The problem wasn’t that AI was thinking.
The problem was that AI could now act, and there was no clear place where restraint lived.
In 2025, legal teams asked: “Where is it safe to use AI?”
In 2026, the real question is sharper:
Who controls the agent?
The Subscription Fallacy
The prevailing answer today sounds reasonable:
Buy Apple Intelligence for personal work.
Buy Copilot for the enterprise.
Buy ChatGPT or Claude for “deep thinking.”
Three subscriptions. Three lanes. Done.
This looks like a strategy.
It isn’t.
It’s like installing three state-of-the-art security cameras—each with incredible resolution, night vision, motion detection—and then never staffing a security room.
Each camera sees something different.
None of them coordinate.
None of them decide what shouldn’t be recorded.
And none of them stop anything once it starts happening.
Legal work doesn’t fail because tools are weak.
It fails because no one is watching the monitors.
From Context Wars to Agent Wars
The era of “one model to rule them all” is already over.
What we have instead is something more dangerous: autonomous capability layered onto fragmented context.
Apple increasingly owns personal context, messages, proximity, habits, often on-device.
Microsoft owns organizational context, email, documents, permissions, and is racing toward agentic workflows.
Frontier models own the reasoning layer, analysis, synthesis, planning, now capable of multi-step execution without waiting for you.
Each of these systems is powerful.
None of them are designed for legal restraint.
Legal teams that simply “turn things on” are effectively asking lawyers to be part-time security guards, hoping nothing sensitive is copied, escalated, or acted on while they sleep.
That’s not a workflow.
That’s a liability posture.
Regulation Has Entered the Room
This is no longer theoretical.
The Colorado AI Act comes into force in 2026.
The EU AI Act follows shortly after.
AI systems used in legal analysis, dispute resolution, or decision-support with real-world effect fall squarely into high-risk categories. The obligations are concrete: transparency, logging, human oversight, data minimization.
Regulators won’t ask whether you use AI.
They’ll ask whether you control it.
That’s the lens I bring to this, as a lawyer responsible for risk, and as an investor responsible for durability.
And it’s why, inside Twelvefold Ventures, we stopped asking which model was best and started asking something else entirely:
What would a proper legal AI environment actually look like?
The Missing Layer: A Legal Sandbox
Legal doesn’t need a better chatbot.
Legal needs a controlled environment, a place where multiple models, tools, and agents can operate without escaping supervision.
Internally, I think of this as a Legal Sandbox. Sometimes, an exocortex, not because it replaces judgment, but because it extends judgment without leaking it.
This is not another interface.
It’s infrastructure.
A layer that sits between the messy reality of email, document systems, and scanned PDFs, and the increasingly autonomous AI systems lawyers want to use.
The goal is not speed at all costs.
The goal is safe acceleration.
A Builder’s Manifesto: What the Legal Sandbox Is Not
This is not another chatbot.
If it starts with a blank prompt box, it’s already the wrong abstraction.
It is not about replacing lawyers.
Judgment stays human. The system exists to prevent accidental abdication of it.
It is not AI governance theater.
Policies that aren’t enforced in software don’t exist.
It is not a single-model bet.
Models change. Control must not.
It is not maximum automation.
Autonomy without checkpoints is unsupervised delegation.
It is not a surveillance tool.
Audit trails are for regulators and risk teams, not micromanagement.
What it is: A governed place where AI can assist legal thinking without escaping human accountability.
How I Think About the Architecture
The way I now frame this is not three lanes, but four.
The first three already exist.
The fourth is the one legal teams are missing.
Lane 1: The OS Layer
Personal assistants excel at triage, summaries, reminders. They should never be trusted with sensitive drafting once data leaves the device.
Lane 2: The Work Layer
Enterprise copilots are powerful, especially as they become agentic. But broad permissions plus autonomy is a discovery nightmare without strict governance.
Lane 3: The Reasoning Layer
Frontier models are extraordinary thinkers. They should be treated like specialist partners—used deliberately, with explicit checkpoints.
Lane 4: The Legal Sandbox
This is the control room.
It decides:
which model handles which task
when humans must approve the next step
how data is sanitized before leaving the perimeter
where outputs return
how every action is logged
If the first three lanes are security cameras, the Sandbox is the staffed security room, routing feeds, enforcing access, escalating alerts, and making sure someone is always responsible for what the system sees and does.
What This Looks Like in Practice
At a systems level, the Legal Sandbox sits between source systems and AI systems.
Email, DMS, deal rooms, scanned PDFs, these remain unchanged.
AI models never touch them directly.
Instead:
data is normalized (OCR, deduplication, version control)
permissions are enforced for humans and agents
no-go zones are respected automatically
human-in-the-loop checkpoints are mandatory
every interaction is logged
If it’s not logged here, it didn’t happen.
Outputs don’t disappear into chat windows.
They return to Word, Docs, or your DMS, annotated, traceable, and reviewable.
Why We’re Building This
One of Twelvefold’s portfolio companies, Attri, is building toward this architecture, not because the world needs another AI tool, but because legal teams need a safe place to think with machines.
The north star isn’t autonomy.
It’s governed collaboration.
A system where:
agents assist but don’t overreach
lawyers stay accountable without being overwhelmed
compliance is built-in, not bolted on
If you’ve ever watched a deal wobble at 1:30 a.m. because five systems disagreed about which template was “approved,” you already understand why this matters.
The Uncomfortable Truth
Most legal departments don’t have an AI problem.
They have:
a data hygiene problem
a permissions problem
a governance problem
Plugging autonomous agents into that environment doesn’t create intelligence.
It creates accelerated confusion.
The Real 90-Day Playbook
The next 90 days for legal leadership shouldn’t be about buying more seats.
They should be about:
auditing where AI is already in use
identifying no-go zones for sensitive work
defining mandatory human checkpoints
implementing a control layer before regulators do it for you
Some teams will try to build this themselves.
Most won’t have the time.
Either way, the conclusion is the same.
The Takeaway
In 2026, the best legal teams won’t be the ones with the cleverest prompts or the most autonomous agents.
They’ll be the ones who built a governed place to think, where humans and machines collaborate without losing control.
Three subscriptions can make you faster.
A Legal Sandbox makes you scalable, auditable, compliant, and sane.
That’s the system we need for legal departments.
