Legal AI’s Week: Agents, Access Risk and Judicial Guardrails

Legal AI’s Week: Agents, Access Risk and Judicial Guardrails

During the last few weeks in June, there were a few developments that are worth mentioning: Perplexity’s explicit entry into legal workflows alongside Thomson Reuters’ expanded CoCounsel push, a lawsuit by legal tech startup Legion over federal restrictions on access to Anthropic models, and more court signals showing both the promise and limits of AI-assisted legal work.

The first development was the clearest sign that the legal AI competition has moved beyond chatbots and into workflow control. Perplexity is making an explicit move into the legal market with legal-specific features inside Perplexity Computer, positioning the offering as “Computer for Counsel.” The company is not trying to become Westlaw, LexisNexis or Bloomberg Law. Instead, it is presenting itself as a research, drafting and workflow layer that can sit above legal databases, firm documents, contract systems and matter-management tools.

The next phase of legal AI competition is increasingly about who controls the working surface where lawyers begin and finish tasks. Perplexity’s legal push includes scenarios such as cross-jurisdictional research, regulatory tracking, contract review, client research, pitch support and patent prior art searches. It also relies on connectors, including a Midpage connection for U.S. legal research, and lists integrations with document and knowledge systems such as Google Drive, OneDrive, DocuSign, Box, DeepJudge and NetDocuments. Perplexity also pointed to Gunderson Dettmer as an early legal-sector proof point, saying the firm has rolled out Perplexity Enterprise firmwide and that a large share of its lawyers are using it.

Perplexity’s timing was notable because the week also brought Thomson Reuters deeper into the same agentic workflow conversation. Thomson Reuters opened early access to the next generation of CoCounsel Legal, saying existing customers would be able to switch into the new experience while retaining access to the current version. The company describes the new CoCounsel as moving from discrete skills and prompts toward a more agentic system that can take a plain-language request, plan the work, draw on Westlaw, Practical Law and user materials, and produce a single, reviewable work product.

The contrast between Perplexity and Thomson Reuters is the industry’s strategic fork in miniature. Perplexity is betting that a flexible AI layer, connected to many information sources, can become a daily workspace for lawyers. Thomson Reuters is betting that lawyers doing high-stakes work will pay for a system grounded in proprietary legal content, editorial expertise, security controls and what it calls fiduciary-grade AI. For law firms and legal departments, the immediate implication is procurement complexity. The choice is no longer only which AI assistant has the best answer in a demo. It is which platform can connect to firm data without compromising confidentiality, produce work lawyers can verify, and fit into the economics of practice without making the firm dependent on a tool it cannot fully govern.

The second major development showed why that dependency question is becoming urgent. Business Insider reported that Legion, a San Jose-based legal tech startup, sued the U.S. government after a federal directive required Anthropic to restrict access to its Fable 5 and Mythos 5 models for foreign nationals. Legion said its AI-powered litigation software depends on frontier AI models and that it employed Canadian nationals working remotely from Canada. According to the report, the company alleged that losing access to Fable 5 caused immediate and severe harm because that model was central to building and operating its platform.

The dispute is an early warning about the legal industry’s reliance on a small number of frontier model providers whose products may be affected by export-control policy, national-security concerns or other government intervention. Many legal AI vendors market themselves as integrated legal workflow systems, but under the hood they often depend on models from companies such as Anthropic, OpenAI, Google or other labs. If access to those models changes abruptly, the disruption can flow directly to lawyers, legal departments and clients using tools built on top of them.

For law firms, this means AI due diligence has to expand. Security reviews and confidentiality terms remain essential, but they are no longer enough. Firms should be asking vendors which model providers they rely on, what contractual rights they have to those models, whether they can switch models without degrading the product, where their staff and subcontractors are located, and how they would notify clients if a model access restriction affected active matters. In litigation and regulatory work, where deadlines can be unforgiving, a vendor’s model-continuity plan may become as important as its accuracy claims.

The Legion suit also highlights a policy issue that is likely to recur. Governments are increasingly concerned about advanced AI systems, including who can access them and how they can be used. Legal technology companies, by contrast, are building products that assume rapid, stable access to those same models. The legal industry sits in the middle. Lawyers may soon find that their AI stack is not merely a vendor-management question but a regulatory-risk question, especially for multinational firms and legal departments with cross-border teams. The bottom line: access to frontier models can now change quickly, unevenly and for reasons outside a law firm’s or legal vendor’s control.

The third development came from the courts, where judges continue to make clear that AI may assist lawyers but cannot replace lawyer responsibility. Law360 reported on June 25 that a Connecticut federal judge, during a sanctions hearing, urged attorneys to push back when clients demand that lawyers use generative AI tools for legal research. The judge’s point, as Law360 summarized it, was that AI is no substitute for professional judgment.

Early AI sanctions cases often focused on fabricated citations and lawyers who filed briefs without checking whether cited cases existed. The newer issue is more subtle: as clients become more aware of AI tools, some may pressure outside counsel to use them to reduce cost or speed research. That creates a professional-responsibility problem if the lawyer treats the client’s demand as permission to lower the standard of care.

The lesson for law firms is that AI governance cannot be written only as an internal technology policy. It has to be reflected in engagement terms, staffing conversations, billing practices and client education. Lawyers need a clear way to tell clients that they may use AI where it is appropriate, but that the lawyer remains responsible for the legal analysis, the accuracy of citations, the protection of confidential information and the final advice. If a client demands AI use in a way that undermines those obligations, the lawyer has to say no or reshape the assignment. Perhaps it's time to revisit ABA Opinion 512 and revise those engagement letters/outside counsel guidelines?

Taken together, the week’s developments suggest that legal AI is entering a more mature and less forgiving phase. The product market is becoming more ambitious, with tools trying to orchestrate entire matters rather than answer isolated prompts. The infrastructure layer is becoming more fragile, as legal vendors depend on frontier models that may be affected by policy choices outside the legal industry’s control. And the professional-responsibility layer is becoming more concrete, as judges expect lawyers to understand both the benefits and limits of the systems they use.

For legal leaders, the practical takeaway is to govern faster. Firms and legal departments need approved tools that are good enough to keep lawyers away from unsanctioned AI, review processes that make verification routine, vendor contracts that address model access and data use, and client communications that set expectations before AI becomes a dispute.

And, remember, you can't govern what you can't see.

Go To Top