AI Adoption Roadmap for Solicitors: From Agreed Approach to Everyday Practice
Agreed strategy, engaged people, practical playbooks, policies and tools to grow your AI capability with clarity and confidence.
Your people are already using AI. The job now is to put it to work on your own matters, safely and to your standard, and to keep moving as the tools adapt and improve. LexisNexis found that 61 per cent of UK legal professionals now use generative AI, yet only 17 per cent of firms have it embedded in how they work. The gap is created by a lack of clear understanding of how lawyers can actually use these tools.
Most firms start with AI as a tool you type into, to draft, summarise and think something through, and it's ok to do that. But many firms are struggling to take the next step towards AI that works to your standards on your own files and - in time - to take defined steps on your behalf. Each stage brings more benefit and needs more structure behind it for lawyers to be able to use these tools with confidence.
Making that transition deliberately, at your own pace, means deciding where AI is allowed, picking the work it should do, mapping how it is done and where the decisions sit, writing down what a good result looks like and getting lawyers and IT building it together. This page sets out the seven steps a firm can take to make that happen and what we bring to help lawyers and IT work in sync.
Early Steps, in order
1: Bring lawyers and IT together. Lawyers know what the work needs; IT knows what the systems and controls allow but can't be expected to know the law. One Microsoft Teams channel for the whole AI Use Case conversation, with the registers and playbooks as tabs, champions posting what they tried and IT in the thread. Maybe pair lawyer champions and IT people to work together on every playbook, skill and agent.
2: Sort out who can see what. This one is IT's job, and it isn't easy with the platforms moving as fast as they are. AI reads whatever the person using it can already open, and in most firms that is more than anyone intended. Close what should not be open, label client documents and shut the back doors. We run a data assessment in the first two weeks and help IT set the controls up in the Microsoft 365 licences you already hold.
3: Agree the rules once. Three levels of review, Assist, Assist+ and Automate, so oversight matches the risk of each task. A traffic light for tools and uses: Green, Amber, Grey, Red. Anything that acts on a system or a client is Automate and Red until your governance group approves it. We bring the Roadmap document and you adapt it.
4: Pick the legal Use Cases, not the tool. This one is a job for the lawyer as the tech team can't know the answers; it takes lawyers looking at their own workflows and their own legal thinking to see where work repeats and what a good result looks like. Six questions a partner can answer without IT decide whether it is worth doing: 1) how often does this come up, 2) how widely would it be used, 3) what is the benefit (time saved, mistakes caught, a difference the client would notice), 4) will AI have enough to work from at that point in the matter, 5) does the work follow the same pattern every time and 6) have we already defined the process? Four more go to IT. A use case is work a lawyer would recognise: it produces something, at a known point in the matter, with a standard to check it against and someone who owns it.
5: Write the playbooks. Start by mapping out the process, who does what, and where the decisions are made. Add the legal expertise, what to look for and which rules apply. A playbook for each piece of work: what good looks like, your positions, what to escalate, what is checked before anything leaves the firm, who owns it. Built by department on a firm-wide template, written by the fee earners who do the work. This is where firms stall, because two partners want to do things differently. What that looks like by practice area: records chronology and a witness statement first draft in personal injury, a grievance pack and settlement agreement checked against the house standard in employment, a data room first pass in corporate, Form E analysis in family, a disrepair chronology in housing, will instructions against the precedent bank in private client. We facilitate it and do the first one with you.
6: Turn playbooks into legal skills. Once a playbook has run under supervision, turn it into a legal skill: a reusable set of instructions that applies the playbook, or handles a recurring legal situation, in an approved AI tool. First-pass evaluation of a new matter, evaluating the other side's case, a standard response to a routine enquiry, a chronology with a source on every line. Two kinds: a skill inside your own tool, which reaches the matter straight away and stays with that product, or an open-format Agent Skill that works across tools and outlasts any one of them. The fee earner reviews the output and the flags. Each skill has an owner and a version and is tested before use; together they become the firm's skills library.
7: Develop Agents, to run a process end-to-end, acting on a system or a client. It is "Red" until fully tested and approved. The client complaints process is a sensible first partial automation candidate. The procedure is written down, it runs to the eight-week timetable before a client can go to the Legal Ombudsman and every step that reaches the client is one a lawyer can sign off. The agent logs the complaint and acknowledges it, assembles the matter history, correspondence and time records for the complaints partner, drafts the investigation note and the response, tracks the deadlines and records the outcome. Nothing goes to the client without sign-off and the partner can stop it at any point. Other candidates follow the same route: new enquiry handling and quoting, client onboarding and AML document chasing, time recording narratives from the day's activity and precedent maintenance when the law changes.
Why Do Law Firm AI Initiatives Stall?
Without a structured framework, firms struggle with legal AI implementation challenges that include:
- Lawyers and IT talking past each other, so nothing gets built.
- Tools chosen before the work is defined, so nobody can say what a tool is for.
- Nothing in black and white to discuss, so the conversation never starts.
- Hesitation and pushback
driven by accuracy, professional responsibility and confidentiality concerns.
- Inconsistent usage
(some early adopters, many avoiding it entirely).
- Proof-of-value pilots
that don’t translate into day-to-day practice.
- Unclear human oversight
(what must be checked, by whom, and how).
- Risk uncertainty around client expectations, insurers and regulators.
This is where most firms get stuck: not “should we use AI?” but “how do we use it safely and consistently?
According to Thomson Reuters' Future of Professionals 2025 report, 32% of law firm professionals say their firm is moving too slowly on AI adoption, risking competitive disadvantage. As AI agents become more capable, new use cases are feasible and our traffic light approach ensures each one is overseen at the right level before they get used.
The AI Oversight Spectrum
Different tasks require different levels of oversight. We work with firms to map their AI use cases across three levels:
Level 1: Assist. Human-led, AI-assisted. AI drafts or summarises from what you give it. The lawyer does the work, checks every line and takes responsibility. This is where most firms start and where high-judgement tasks should stay.
Level 2: Assist+. AI-led, human-supervised. AI works to your playbook. The lawyer reviews the output and the flags, supervising at checkpoints and sampling for quality. The role shifts from doing to overseeing.
Level 3: Automate. AI-managed, human-governed. AI runs a workflow or an agent acts within agreed boundaries, without a person in between. Humans set the rules, monitor performance, review exceptions and audit samples. Red until approved by the governance group.
Most law firms are at Level 1 today. The firms that build their operating model with the full spectrum in mind will be ready to move up the levels as confidence and capability grow, while maintaining professional standards where they matter most.
What the Roadmap gives you
1. Your AI operating model, the three levels of review
Establishes how lawyers and AI work together in your firm, defining:
- Governance & oversight: approval processes, risk management, regulatory compliance
- Human-in-the-loop protocols: what lawyers must review, when to intervene, quality verification
- Division of labour: which tasks leverage AI vs. require full lawyer control
- Training & capability: AI limitations, verification techniques, building skills not bypassing them
- Quality assurance: standards for AI-assisted work, error detection, continuous improvement
This turns “useful tool” into “repeatable, defensible practice”.
2. Traffic Light Assessment System: evaluates which AI applications are ready for deployment
A simple way to classify AI use cases and tools so your people know what’s allowed. The point is not to ban AI. It's to make usage predictable, auditable and safe, and to move tools and uses from Grey to Amber to Green as controls and tech mature.
3. AI Adoption Policy, Roadmap, User Engagement and Tools
Translates your framework into clear rules people can follow:
- Approved tools and configurations
- What data can/can’t be used
- Required training by role
- Minimum review standards by task type
- Quality controls and escalation routes
- Technical controls for a secure data and technology foundation
So people stop guessing and partners stop carrying unmanaged risk. The Roadmap is a working document that a firm adapts to its own practice, with an implementation checklist alongside it so you can see what needs to be done, what is out of date and what you haven't implemented yet.
What Can Your Firm Achieve with Structured AI Adoption?
Make this an integral part of your law firm technology strategy, enabling you to deliver:
- Confident use: partners use AI with structured oversight and clear protocols
- Faster adoption: proven tools rolled out across the practice
- Risk management: clear protocols satisfy clients, insurers and your SRA supervision duties
- Competitive advantage: harness efficiency gains while others remain stuck in debate
- Scalability: framework applies to new tools as they emerge
Clio's Legal Trends Report indicates 74% of hourly billable tasks could be automated with AI. Firms with structured frameworks can harness these gains safely and confidently, building competitive AI advantage.
How We Work with You
Stage 1: Build Foundations. Governance lead, group and champions in place, the Teams channel open, the data assessment done and core controls on, the first Green tools approved and three to five use cases per practice area on the register, starting with a triage playbook for one team.
Stage 2: Implement with Purpose. Playbooks in each practice area, fee earners owning the content, the skills library built from them, training by role and results measured against the register.
Stage 3: Strategic Integration. The first agents designed and approved, client complaints admin first, the registers of tools and uses growing as they mature and continuous improvement embedded.
The pace and scope of each stage varies based on your firm's resources, current capabilities, strategic priorities and readiness for change.
The link between Law and Tech
We are the link between law and tech. Having practised law and worked in technology selection and adoption in law firms since 1992, we can translate either way. We turn what lawyers need into something IT can build, and what IT can deliver into a decision partners can take.
As ever with technology in law firms, this is as much about people as the tech and AI, and the playbooks, champions and channel are built with that in mind. Wherever your firm is on this, we bring what the next step needs: the Roadmap document, the implementation checklist, the six-question card, process maps, playbook templates and the first playbooks built with your teams. Foundations and the first playbook come first, agents last, at a pace that matches your resources and readiness.
For which tasks, which tools and the specialist legal AI we are testing, see AI Use Cases and Tools for Law Firms.
The Carton & Co Team
Allan Carton: qualified solicitor with an MBA (Alliance Manchester Business School). Advising law firms since 1990 on technology adoption, client relationships, and business development, bridging legal practice and commercial reality.
Frank Manning: technology specialist for professional practices, providing technical implementation expertise. Frank advises on technology selection, integration with existing systems, data security protocols and technical governance requirements.
Dr Lee Williams: expertise in process improvement and change management, helping firms navigate the organisational and cultural shifts required for successful AI adoption.
Together, our legal technology consultants provide the strategic, operational and technical expertise needed for successful AI adoption, from roadmap design through to firm-wide implementation.
Getting Started
If your firm is experimenting with AI but needs a structured approach for firm-wide adoption, Carton & Co can help you build your roadmap quickly, with confidence.
Talk to us about your roadmap here >>
Email: acarton@cartonconsultants.com
Phone: 07779 653105
Carton & Co: helping law firms modernise and grow through smarter technology, stronger client relationships and practical strategy.
____________________
** Frequently Asked Questions About AI Adoption **
Q: What is an AI playbook?
A: our firm's written definition of what good looks like for one piece of work: the steps it goes through and where the decisions are made, your positions, what to escalate, what is checked before anything leaves the firm and who owns it. Written by the people who do the work, one per piece of work, built by department. It comes first because a person can apply it, it survives a change of tool and it is what any AI skill or agent works to.
Q: What is a legal AI skill?
A: A reusable set of instructions that applies your playbook, or handles a recurring legal situation, in an approved AI tool. It can live inside your own tool or as an open-format Agent Skill that works across tools. Each has an owner, a version and a test set and is reworked when the law or a client's requirements change.
Q: When can we let an AI agent act on a matter?
A: When the same work has run as a supervised skill and the supervising partner can say what was verified and by whom. Until your governance group approves it, with a design, a sandbox test and a kill switch, anything that acts on a system or a client is Red. Client complaints admin is the usual first candidate.
Q: What does a Smarter Technology and AI Adoption Roadmap include?
A: The Roadmap covers your data foundations, AI tool classification (using a traffic light system), governance and oversight, the use case and approved tools registers, playbooks, legal AI skills and agents, training requirements by role, quality assurance standards and clear policies for your people. It comes with an implementation checklist, one row for each thing a firm needs in place, with an owner and a date against anything missing.
Q: What is agentic AI and should our firm be preparing for it?
A: Agentic AI refers to systems that can plan and execute multi-step tasks with minimal human direction, researching, drafting, checking and acting within defined boundaries. It's evolving rapidly and agents already outperform humans at some tasks, with coding the clearest example so far and other knowledge work on the same path. Most law firms don't need to deploy agentic AI today, but the firms building their AI operating model now, with the oversight spectrum in mind, will be ready to take advantage as these capabilities mature, rather than starting from scratch.
Q: How long does AI adoption typically take for a law firm?
A: Implementation timelines vary based on firm size and current capabilities. Stage 1 (foundations) typically takes 1-2 months, Stage 2 (systematic deployment) another 2-3 months and Stage 3 (strategic integration) is an ongoing process. We work at a pace that matches your resources and readiness for change.
Q: What are the main risks of AI adoption for law firms?
A: Key risks include professional responsibility concerns, data confidentiality breaches, over-reliance on AI without proper verification and regulatory compliance issues. Our structured approach specifically addresses these through oversight protocols, quality assurance standards and clear governance structures.
Q: Do we need specific professional indemnity insurance for AI use?
A: Many insurers are updating policies to address AI. Our framework helps you satisfy insurer requirements by documenting oversight protocols, quality assurance processes and human review standards. We recommend discussing AI usage with your insurance broker as part of Stage 1.
Q: Can small law firms adopt AI effectively?
A: Yes. While large firms (top 20) are currently leading adoption, structured frameworks are valuable for firms of all sizes. The Traffic Light Assessment System and staged approach allow smaller firms to adopt systematically within their resource constraints. Smaller firms have a good opportunity now to learn from the larger firms too, who have more difficult challenges to overcome in many respects because of their scale.
Q: What if our lawyers are resistant to AI adoption?
A: Resistance often stems from legitimate concerns about professional responsibility, accuracy and client confidentiality. Our approach addresses these directly through clear protocols and training. Dr Lee Williams works specifically on change management and building capability across the firm.
Q: How do you work with our existing technology suppliers?
A: We collaborate with your AI tool suppliers to evaluate their solutions against our Traffic Light Assessment criteria. Frank Manning's technical expertise enables productive dialogue with vendors about integration, security and governance requirements.
Q: How do you stop people relying on AI output without checking it?
A: This is the risk Ethan Mollick calls "cognitive surrender." AI answers look confident and authoritative even when they're wrong and research shows experienced professionals miss those errors too. Our oversight protocols build the checks into the workflow, defining what must be verified, by whom and how, so review happens by design rather than depending on individual discipline. For fee-earners, that's also a supervision and competence safeguard.


