Company Check – New High-Speed Hybrid AI Law Firm

A new AI-powered legal startup backed by Sequoia Capital is rewriting how contracts are reviewed, by building a law firm around the software itself.

Lawyers Using AI To Deliver Services To Clients

Most legal tech startups position themselves as tools for traditional firms to use. It seems, however, that Crosby has taken a radically different approach. Rather than offering AI software to outside lawyers, Crosby has built its own law firm, staffed with lawyers who use its proprietary legal AI systems to deliver services directly to clients.

Launched in early 2025 and already out of stealth with a $5.8 million seed round led by Sequoia Capital, Crosby is a hybrid legal provider combining full legal oversight with rapid AI-powered contract processing. In doing so, it positions itself not just as a legal technology provider, but as a legal services business with a completely different operating model.

“Our goal was never to just automate tasks for law firms,” said Ryan Daniels, Crosby’s co-founder and CEO, in a launch statement. “To really fix how slow legal work is, we had to control the entire process—so we became the law firm ourselves.”

Built for Speed, Designed for Growth

The problem Crosby says it set out to solve is a familiar one in fast-moving industries, i.e. contract delays.

Daniels, who previously served as general counsel for several startups and worked at elite tech law firm Cooley, experienced the issue first-hand. “Most of the time I was spending on legal was for our contracts, sales agreements, MSAs,” he said. “It was the reason we weren’t growing as fast as we wanted to.”

Agentic

Crosby’s solution is what it calls an “agentic” law firm using a “hybrid” model where every contract is reviewed by proprietary AI agents, then verified by experienced lawyers. This human-in-the-loop setup enables clients to get back a reviewed contract within three hours, with many returned in under 60 minutes. Daniels claims the company’s fastest reviews take just minutes.

High-Volume, Sales-Related Agreements

The startup focuses on high-volume, sales-related agreements such as master service agreements (MSAs), data processing agreements (DPAs), and non-disclosure agreements (NDAs). This is because these are the kind of documents that tend to clog deal pipelines for sales teams in growing firms. Crosby’s promise is, therefore, to get contracts reviewed quickly and accurately, so deals close faster.

Who’s Behind Crosby?

Crosby was founded by Daniels and John Sarihan, who serves as CTO. Sarihan previously worked at Ramp, a fintech unicorn, and brought with him engineering talent from companies like Meta, Google, and Vanta. Daniels, a second-generation lawyer whose parents are both law professors, focused on building the legal team, which includes alumni from Harvard, Stanford, and Columbia Law.

The company is headquartered in New York and operates as both a legal technology company and a law firm. Formally, Crosby Legal, Inc. provides the technology, while Crosby Legal PLLC is the law firm offering legal services.

Their Sequoia-led funding round also included participation from Bain Capital Ventures and notable angel investors such as Ramp co-founders Eric Glyman and Karim Atiyeh, Instacart co-founder Max Mullen, Opendoor’s Eric Wu, and Flatiron Health founders Zach Weinberg and Gil Shklarski.

Josephine Chen from Sequoia, who previously backed AI procurement startup Venue (later acquired by Ramp), led the deal. “Legal is a bull’s-eye case for the use of LLMs,” she said. “Contract negotiations can be a real bottleneck for growth.”

AI Meets Legal Expertise

Crosby’s approach blends the rapid processing power of AI with legal precision. For example, clients can send documents or queries via Slack, email, or through a CRM trigger. The system’s legal AI agents, trained on thousands of contracts and guided by firm-developed benchmarks, then analyse the documents, make suggestions, and insert relevant market terms.

Lawyers then step in to review, interpret tricky clauses, and validate any automated changes. The final contract is returned to the client with a fixed price tag (no hourly billing), and no redline confusion (no back-and-forth edits on contracts). For example, “AI never sleeps,” says the firm’s website. “Crosby never gets backlogged.”

Learns About Clients’ Businesses

Crosby’s AI systems are also designed to learn each client’s business over time. This includes storing preferences, preferred clause variations, and common fallback terms. The company claims its software can answer routine contract questions without client input once it’s sufficiently trained.

Targeting Startups That Need to Move Fast

So far, Crosby appears to have aimed its services at venture-backed startups, particularly those with aggressive go-to-market (GTM) strategies. Early clients include Cursor, UnifyGTM, and Clay, all startups known for rapid growth and high sales velocity.

By focusing on sales contracts and offering legal reviews as fast as the sales cycle itself, Crosby is positioning itself as a growth enabler rather than just a legal resource. GTM teams reportedly call it a “secret weapon” for getting contracts over the line.

Crosby’s upfront pricing is also designed to appeal to startups used to controlling costs. For example, clients pay per document, not per hour, which is a sharp contrast with traditional legal billing models.

Why This Matters for the Legal Industry

Crosby’s emergence poses direct questions to the traditional legal services model. For example, most law firms are structured around bespoke work, hourly billing, and long timelines. By contrast, Crosby is productising contract review, treating it as a repeatable, scalable service.

Not The First Legal Firm To Apply AI

It’s worth noting here that Crosby is not the first to apply AI to legal work. For example, companies like Harvey (which recently raised $80m), Ironclad, and Spellbook are building AI tools to support lawyers. However, Crosby is unusual in that it delivers end-to-end legal service directly to clients, with its own regulated legal team and a law firm structure.

This allows Crosby to sidestep law firm conservatism and scale more like a tech startup. “We didn’t want to wait for firms to catch up,” Daniels said. “We wanted to prove it could be done.”

Potential Risks and Criticisms

Crosby’s model is not without its critics. Legal work carries significant liability, and while its lawyers remain in the loop, the firm must prove that its AI systems are reliable, auditable, and ethically sound. The startup says all outputs are lawyer-reviewed, but how clients interpret that balance between machine and human may vary.

There’s also the regulatory question. In most US states, legal services must be delivered by licensed professionals. Crosby’s dual-entity structure is designed to comply with those rules, but regulatory scrutiny may increase as it scales.

UK firms will also need to watch this space closely. For example, while firms like Allen & Overy and Mischon de Reya are experimenting with AI copilots, none have yet adopted a Crosby-style hybrid structure. If Crosby proves successful in the US, it may set a precedent for how AI-led legal services could evolve in other jurisdictions.

Are There Any Competitors Doing the Same?

There are firms inching toward similar models. Atrium (now defunct) once tried to integrate software with legal service delivery, though without the speed or AI emphasis Crosby offers. More recently, firms like Lawtrades and Axiom Legal blend tech-enabled platforms with lawyer marketplaces, but again, they stop short of Crosby’s embedded, AI-first, regulated law firm model.

In the UK, companies like Luminance and Robin AI provide AI tools to assist legal teams but do not operate as regulated firms themselves. Crosby’s core differentiator is that it is both the software company and the law firm, acting as one unified entity with aligned incentives to deliver speed and accuracy at scale.

What Does This Mean For Your Business?

For law firms, Crosby represents a direct challenge to long-established business models built around hourly billing and drawn-out negotiations. Its hybrid setup shows that legal services can be fast, fixed-price, and scalable, without sacrificing human oversight. If the model proves durable, it could force traditional firms to rethink both their pricing structures and the level of tech integration in their workflows.

For UK businesses, the implications could be equally significant. If models like Crosby’s reach the UK market, startups and scaleups would most likely be able to close deals more quickly, reduce legal overheads, and compete more effectively. The demand for faster legal execution is not limited to Silicon Valley. UK firms under pressure to accelerate growth and reduce friction in sales cycles may soon expect legal services to move at the same pace as their CRM or procurement systems. Legal firms serving these clients will need to respond accordingly.

Regulators and legal educators may also come under pressure to modernise. Crosby’s model blurs the line between legal practitioner and product developer. That raises questions not just about compliance, but also about professional training, ethical oversight, and the future identity of the legal profession. As AI models evolve, the challenge will be to strike a balance between innovation and accountability.

The legal industry has long been insulated from the kind of disruption seen in finance or logistics. Crosby’s approach suggests that insulation may be starting to wear thin. Whether it becomes the norm or remains an outlier, it has already expanded the conversation around what legal services can look like, and who is best placed to deliver them.

Company Check – Apple Faces Possible Criminal Contempt Conviction

Apple has been referred for possible criminal contempt by a US judge who found it wilfully defied a court order to open its App Store to greater competition, escalating its long-running legal battle with Epic Games and raising the stakes for one of the world’s most powerful tech firms.

Dramatic

The ruling marks a dramatic twist in the long-running legal saga between Apple and Fortnite developer Epic Games and could actually lead to some serious legal consequences for one of the world’s most valuable companies.

Deliberate Defiance?

The latest judgement, delivered last week by US District Judge Yvonne Gonzalez Rogers, accuses Apple of “insubordination” and “egregious misconduct” in its handling of a 2021 injunction that required it to allow app developers to direct users to external payment systems.

That original injunction followed a partial victory by Epic Games, which sued Apple over its tight control of in-app purchases and up-to-30 per cent commission fees. While the judge rejected broader monopoly claims at the time, she ruled that Apple could no longer prevent developers from linking users to alternative ways to pay, a move that would cut into Apple’s multi-billion dollar revenue stream from the App Store.

However, according to last week’s court filing, it seems that Apple effectively ignored that order. For example, not only did it introduce new barriers, including a controversial 27 per cent commission on off-app purchases, but it also implemented what the judge called “scare screens” designed to discourage users from straying outside Apple’s walled garden.

Internal Pushback and False Testimony Allegation

In perhaps the most damning section of her ruling, Judge Gonzalez Rogers said Apple’s internal documents showed senior leaders knowingly avoided compliance.

She noted that Apple CEO Tim Cook had rejected advice from App Store architect Phil Schiller to follow the injunction, instead siding with CFO Luca Maestri, who advocated keeping revenue protections in place. The judge wrote bluntly: “Cook chose poorly.”

The ruling also accused Apple’s vice-president of finance, Alex Roman, of lying under oath during the proceedings. “He outright lied,” she wrote, further reinforcing the seriousness of the contempt findings.

Decision Time

The matter has now been referred to the US Attorney for the Northern District of California, who will decide whether to pursue criminal contempt proceedings, a rare and serious step that could lead to fines for the company and potentially even jail time for individuals if charges are brought and proven.

Epic Offers a Truce

Epic Games CEO Tim Sweeney welcomed the decision as a major milestone in the fight against what he calls Apple’s “junk fees”. He announced that Fortnite would return to the US iOS App Store this week, three years after being pulled amid the legal fallout.

Sweeney also made a surprising peace offer via social media, suggesting Epic would end all related litigation if Apple agreed to apply the new, frictionless payment rules globally. “Game over for the Apple Tax,” he wrote, referencing similar regulatory moves already under way in Europe under the Digital Markets Act.

Apple Pushes Back and Plans Appeal

In a brief statement, Apple said it “strongly disagrees” with the ruling and will appeal to the 9th US Circuit Court of Appeals. The company is expected to seek a pause on the order while the appeal plays out, although analysts say the appeal may be difficult to win given the weight of evidence already compiled.

Apple also maintains that its updated policies are in line with the injunction. However, the judge ruled that the company’s so-called compliance measures were designed not to enable competition, but to preserve its existing revenue model through subtle deterrents.

What This Could Mean for Apple (and Developers)

The implications of all this could be wide-reaching and, if federal prosecutors do pursue a criminal contempt case, it would mark a highly unusual escalation in a corporate antitrust battle. It could also embolden regulators in other countries, including the UK and EU, where scrutiny of Big Tech practices is intensifying.

For developers, the ruling could finally force Apple to relax some of the strict controls it has long imposed over in-app payments, which is a development that many have lobbied for in recent years. For example, Apple’s 15-30 per cent cut has been criticised as excessive, particularly by smaller app makers who say it squeezes margins and limits innovation.

Meanwhile, investors will be watching closely. While Apple’s stock has remained resilient so far, any criminal findings or further disruption to its lucrative App Store ecosystem could cast a longer-term shadow over one of its most profitable divisions.

What Does This Mean For Your Business?

The decision to refer Apple for possible criminal contempt doesn’t mean charges are guaranteed, but it’s a real escalation that could have serious ripple effects. The US Department of Justice will now decide whether to pursue a prosecution, weighing the judge’s findings against internal documents and court testimony that paint a picture of calculated resistance. Even if no charges follow, the ruling sets the precedent that major tech firms can no longer really expect leniency if they appear to sidestep the spirit of antitrust decisions.

For Apple, the stakes are not only legal. The reputational damage from being publicly rebuked by a federal judge, and having a senior executive accused of lying under oath, may affect how regulators, developers, and consumers perceive the company. In an era of heightened scrutiny, where Europe’s Digital Markets Act and the UK’s Digital Markets, Competition and Consumers Bill aim to rein in tech monopolies, this case may offer lawmakers fresh justification for tougher rules.

Developers worldwide are also, no doubt, watching closely, particularly those who have long criticised Apple’s App Store fees and restrictions. If the outcome leads to genuine, enforceable change, e.g. lower commissions or real freedom to use alternative payment systems, it could shift the balance of power. For UK businesses building or operating apps, any move towards greater flexibility would be welcome, especially in sectors where margins are tight and growth depends on reaching users without excessive overheads.

Broadly speaking, this saga reinforces how global platforms are being forced to justify longstanding business models under legal pressure. The Epic v. Apple dispute may have started in the US, but its consequences are global, and for regulators, developers and digital firms in the UK and beyond, it’s another sign that the era of unchecked platform dominance may finally be nearing its end.

Company Check – New UK Law Could Hit IT Firms With £100K-a-Day Fines

The UK government has unveiled sweeping new cyber legislation that could see organisations hit with fines of up to £100,000 (per day!) if they fail to respond to threats in time – a move that dramatically raises the stakes for IT providers, critical service operators, plus their supply chains.

Tough New Rules Aimed at Critical Infrastructure and the Tech Supply Chain

The draft Cyber Security and Resilience (CSR) Bill, formally outlined this week by technology secretary Peter Kyle, seems to be setting out a more aggressive approach to cyber regulation in response to what ministers describe as “unprecedented threats” to the UK’s digital and physical infrastructure.

Crucially, the bill expands the scope of current regulations and will bring managed service providers (MSPs), IT suppliers, and potentially datacentre operators into the same regulatory framework as public utilities and emergency services. This means that for the first time, commercial tech firms (up to 1,000 of them by current estimates) could be legally obliged to meet strict cybersecurity standards or face financial penalties.

“Economic growth is the cornerstone of our Plan for Change,” said Kyle, “And ensuring the security of the vital services which will deliver that growth is non-negotiable.”

Three Core Pillars – and a Sharp Set of Teeth!

The new bill is built on three pillars. First, widening the scope of the UK’s existing Network and Information Systems (NIS) regulations to include more types of organisations. Second, giving regulators stronger powers to enforce those rules and third, allowing government to rapidly update the rules in response to new and emerging cyber threats.

What’s new (and raising a few eyebrows) is the addition of discretionary government powers to issue binding cyber directives in real-time. For example, if an in-scope organisation receives a formal order to patch a vulnerability or improve cyber defences in response to an active threat and fails to comply, it could face daily fines of up to £100,000, or 10% of turnover, whichever is higher.

The message, therefore, appears to be that falling short isn’t just risky but could be ruinously expensive.

Why Supply Chain Security Is Now Front and Centre

The bill changes how cyber risk is perceived at the national level. For example, instead of focusing solely on headline-grabbing ransomware events or attacks on high-profile utilities, the government now appears to be turning its attention to the digital supply chain, i.e. the vast network of IT support firms, software providers, and cloud service operators that underpin the UK economy.

For example, the Cloud Hopper espionage campaign, which targeted MSPs to indirectly infiltrate governments and corporations, is a cautionary tale of how supply chain vulnerabilities can be weaponised at scale. Likewise, the recent breach of the Ministry of Defence’s payroll system showed how even indirect routes into sensitive data can have real-world consequences.

The UK’s National Cyber Security Centre (NCSC) is backing the approach, and as NCSC CEO Richard Horne says: “The Cyber Security and Resilience Bill is a landmark moment,” adding that “It will improve the cyber defences of the critical services on which we rely every day, such as water, power and healthcare.”

Datacentres and the Next Phase of CNI Regulation

The government is also strongly considering bringing datacentre operators into the bill’s remit, a step it hinted at last year when these facilities were designated as critical national infrastructure (CNI).

If passed, this could affect more than 180 UK-based datacentres and over 60 operators, according to industry figures. While exact compliance requirements haven’t yet been defined, it’s expected that these facilities will be subject to the same incident reporting rules and real-time intervention powers as other in-scope entities.

What’s more, ministers are exploring the use of AI tools to help detect and respond to threats inside these physical and virtual infrastructure hubs.

Mandatory Incident Reporting Tightens Timelines

Another key change is a tightening of mandatory reporting timelines. Organisations in scope of the CSR Bill will need to notify regulators and the NCSC of significant incidents within 24 hours – faster than the 72-hour window required by both the EU’s NIS2 directive and the US’s CIRCIA.

A full report must follow within 72 hours, creating a dual-stage reporting process that places UK organisations under one of the most stringent regulatory regimes in the world.

As technology secretary Peter Kyle says: “This is not just red tape,” but rather “It’s about making sure we know, quickly, when something serious is happening – and being able to act fast.”

Why This Isn’t a ‘One and Done’ Job

Legal experts and cyber risk consultants are warning that the scale of the challenge posed by the new rules is significant, i.e. not just in terms of cost, but also the time and effort required. For example, even well-resourced organisations could find the process of aligning legacy infrastructure with modern cyber resilience standards a long and complex task.

The key point that many are making is that cyber security is not something that can be addressed once and then forgotten. With threats constantly evolving, businesses will need to build ongoing investment and regular system upgrades into their operations. The burden, therefore, isn’t going to be just technical, but will also demand sustained leadership focus and cultural change across entire workforces. In other words, achieving compliance in this case is going to be a continuous journey.

Statutory Powers and Strategic Priorities

As well as giving regulators sharper enforcement tools, the bill proposes that the government publish a unified Statement of Strategic Priorities (updated every three to five years) to guide the approach of different regulators. This aims to bring consistency and clarity to enforcement across sectors, ensuring that energy, healthcare, and IT providers all face comparable expectations.

The government would also be granted the power to issue emergency directions to organisations where needed. This could prove vital in responding to fast-moving attacks, such as zero-day exploits or geopolitical cyber events.

Rising Threats, Rising Costs

The need for faster, tougher intervention isn’t theoretical. In 2023, attacks on UK utility firms surged by 586 per cent, according to reinsurance firm Chaucer. The NCSC dealt with 89 nationally significant incidents (up from 62 the previous year) including 12 so serious they required COBR (Cabinet Office Briefing Rooms) meetings.

Notably, one of the most damaging incidents of last year (i.e. the ransomware attack on NHS blood testing partner Synnovis) cost the NHS an estimated £32 million! Analysts have suggested that a well-coordinated attack on the energy grid in southeast England could cost the UK economy up to £49 billion!

In light of this, the CSR Bill is not just about compliance, but is also about protecting national prosperity.

What Does This Mean For Your Business?

The details of the Cyber Security and Resilience Bill seem to show that the intention is to move things from reactive firefighting to proactive, enforceable standards. For UK businesses, particularly those in the technology supply chain, the message is that cybersecurity isn’t simply optional, nor is it simply an IT issue. It is now a board-level priority with legal and financial consequences attached.

While some organisations, especially larger providers, may already have mature systems in place, many will find that aligning with the new expectations demands more than just a policy refresh. Compliance will mean revisiting internal processes, investing in tools and training, and developing the ability to respond quickly and transparently to incidents. Smaller IT firms, regional MSPs, and niche datacentre operators, who may not have considered themselves part of critical national infrastructure until now, are likely to face the steepest learning curve.

The government’s aim appears to be to ensure the resilience of the UK’s digital backbone, and it is using both carrot and stick to get there. On one hand, businesses are being offered access to NCSC resources and support frameworks like Cyber Essentials. On the other, they face heavy penalties if they fail to take action when directed. Regulators, too, will be expected to step up, with clearer powers and more tools to enforce consistent, effective oversight across all sectors.

For regulators, IT service providers, and businesses that rely on outsourced digital infrastructure, the implications are far-reaching. In the short term, there may be uncertainty over exactly how these rules will be applied and interpreted, especially as the list of in-scope organisations grows. But in the long term, the bill signals a new era in which resilience and responsiveness are the benchmark for doing business in a connected economy.

The stakes are high but, looking on the positive side, so is the opportunity to build a more secure, digitally confident UK. With attacks becoming more frequent, more sophisticated, and more costly, the government is hoping that strong, enforceable rules are the best way to safeguard both national infrastructure and future economic growth. For those now falling under the scope of this legislation, the clock has started ticking.

Tech News : Law Firm Restricts AI Access After Surge in Usage

It’s been reported that international law firm Hill Dickinson has introduced new restrictions on the use of artificial intelligence (AI) tools following a sharp increase in staff engagement with the technology.

What Happened?

The development was first reported by the BBC after it allegedly obtained an internal email from Hill Dickinson’s senior management. The email reportedly revealed that the firm had identified a “significant increase in usage” of AI tools by employees, prompting a review of its policies and subsequent restrictions on access. It seems that the move may have been prompted by growing industry concerns over data security, compliance, and the ethical implications of AI in legal work.

The Email

According to reports about the data cited in the email, in just one week between January and February 2024, Hill Dickinson staff recorded over 32,000 interactions with the AI chatbot ChatGPT, 3,000 with the Chinese AI service DeepSeek, and nearly 50,000 with the writing assistance tool Grammarly. While these figures may illustrate widespread engagement, they don’t clarify how many individuals were actually using the tools or how frequently they returned, as each use could generate multiple interactions.

Limited General Access To The Tools

In response, it’s been reported that the firm has now limited general access to such tools, introducing a request-based approval system to monitor and regulate AI usage more closely. It seems that the internal communication may have highlighted that much of the AI use may not have been in line with the firm’s AI policy, thereby perhaps necessitating stricter oversight.

Why Impose These Restrictions?

It seems that the firm’s AI policy (implemented back in September 2024) actually prohibits employees from uploading client information to AI platforms and requires them to verify the accuracy of AI-generated content. The recent spike in AI engagement may have, therefore, raised concerns that these guidelines were not being strictly followed, potentially exposing the firm to regulatory and security risks.

A spokesperson for Hill Dickinson has been quoted clarifying its stance, stating: “Like many law firms, we are aiming to positively embrace the use of AI tools to enhance our capabilities while always ensuring safe and proper use by our people and for our clients.”

Not An Outright Ban

The firm maintains that it is not banning AI outright but ensuring its application is controlled and compliant. It has already received and approved some individual AI usage requests under the new system.

Broader Industry Implications

The legal profession does appear to be facing a bit of an increasing dilemma over AI adoption. For example, while AI has the potential to streamline tasks such as legal research, contract analysis, and document drafting, it also presents risks related to data security, accuracy, and ethical considerations.

Enter The ICO

Now the UK’s Information Commissioner’s Office (ICO) has weighed in on the debate, warning against excessive restrictions. A spokesperson for the ICO stated: “With AI offering people countless ways to work more efficiently and effectively, the answer cannot be for organisations to outlaw the use of AI and drive staff to use it under the radar. Instead, companies need to offer their staff AI tools that meet their organisational policies and data protection obligations.”

AI Can Help, But Needs Oversight

The Law Society of England and Wales has emphasised its view that AI has potential benefits, with its chief executive, Ian Jeffery, saying: “AI could improve the way we do things a great deal.” However, he also stressed that AI tools require human oversight and that legal professionals must adapt to their responsible use.

Concerns About A Lack of Expertise

Meanwhile, the Solicitors Regulation Authority (SRA) has expressed concerns about an apparent general lack of digital expertise in the legal sector. For example, a spokesperson was recently quoted as warning that “despite this increased interest in new technology, there remains a lack of digital skills across all sectors in the UK. This could present a risk for firms and consumers if legal practitioners do not fully understand the new technology that is implemented.”

This highlights a broader challenge for the legal industry, i.e. embracing AI innovation while ensuring legal professionals are adequately trained and aware of the risks.

Mixed Reactions

Reports of Hill Dickinson’s approach have drawn mixed reactions. Some industry figures argue that overly strict AI regulations could stifle innovation and slow the adoption of technologies that could make legal work more efficient.

Others point out that firms must proceed with caution, particularly regarding data privacy and regulatory compliance. High-profile cases of data breaches linked to AI use have reinforced concerns about inadvertently exposing confidential client information to external platforms.

Not An Isolated Case

It should be noted here that the reported move by Hill Dickinson is certainly not an isolated case. For example, other major corporations (including Samsung, Accenture, and Amazon) have also implemented restrictions on AI tools over concerns about data security and the potential for AI-generated content to be unreliable or misleading.

The Legal Sector Needs To Find A Balance

AI’s increasing presence in the legal world is undeniable, and firms may now be tasked with finding the right balance between harnessing its benefits and mitigating its risks. Hill Dickinson’s decision highlights a broader industry trend of cautious AI integration, ensuring that its use remains secure, ethical, and compliant with professional standards.

What Does This Mean For Your Business?

The reported move by Hill Dickinson to restrict general AI access highlights a growing tension within the legal sector between technological advancement and regulatory caution. AI undoubtedly holds transformative potential, offering efficiencies in legal research, contract analysis, and document drafting. However, its use comes with inherent risks, particularly in an industry where confidentiality, accuracy, and compliance are paramount.

The firm’s reported decision to implement a request-based approval system reflects an industry-wide concern about data security, regulatory obligations, and ethical considerations. While this is not an outright ban, it does indicate that unregulated AI usage in professional settings remains a real concern. It seems that the spike in AI interactions may have signalled that existing policies were not being strictly adhered to, thereby prompting a need for greater oversight. Such caution is understandable, given the possible risks associated with AI-generated inaccuracies or inadvertent data leaks.

At the same time, broader industry voices, including the ICO and the Law Society, have warned against overly restrictive measures that could stifle innovation. Their position suggests that rather than banning AI, firms should focus on implementing clear, structured policies that allow for responsible usage while maintaining compliance with legal and data protection standards. The Solicitors Regulation Authority’s concerns about a lack of digital expertise in the sector further highlight that law firms must not only regulate AI usage but also ensure that legal professionals are adequately trained in its application.

Hill Dickinson’s approach is not just a legal sector issue and, in fact, it has far-reaching implications for businesses of all sizes across the UK. Many large corporations, such as Samsung and Amazon, have already imposed AI restrictions, reflecting wider concerns about security, compliance, and the reliability of AI-generated content. However, for smaller businesses that lack dedicated legal or IT departments, these challenges could be even more pressing. Without clear guidance or internal expertise, SMEs risk either underutilising AI and missing out on its benefits or adopting it without proper safeguards, exposing themselves to potential legal and reputational risks.

This highlights the need for a balanced, industry-wide approach to AI governance. Government agencies and industry bodies may need to step in to provide clearer guidance. Hill Dickinson’s move is far from isolated, as many large corporations have taken similar steps to control AI’s integration into their workflows.