Skip to main content
Why Your AI Policy Won't Hold Up in CourtBoard Committees and Governance
6 min readFor GRC Leaders

Why Your AI Policy Won't Hold Up in Court

You have an AI policy. It probably mentions human oversight, responsible use, and verification of outputs. However, that policy is not evidence. It's an assertion, and when tested, assertions without supporting documentation fail.

The gap between having a policy and proving compliance exposes organizations to sanctions, regulatory action, and reputational damage. The recent Reaves Law Firm case demonstrates this distinction. When a federal court ordered the firm to describe its verification process for AI-generated content, Reaves could not produce meaningful evidence. The firm was sanctioned under Rule 11, not because it lacked a policy, but because it could not demonstrate that any verification occurred.

Why These Mistakes Keep Happening

Organizations often treat AI governance as a documentation exercise rather than an operational discipline. You draft a policy, circulate it for approval, and file it away. The policy states expectations but creates no mechanism to record compliance. When scrutiny arrives from regulators, auditors, opposing counsel, or your board, you're asked to prove what happened, not what you intended.

The pressure to adopt AI quickly compounds this problem. Teams deploy AI tools to gain efficiency without building the infrastructure to track how those tools influence decisions. By the time someone asks for evidence, the decision has been made, the personnel have changed, and the record does not exist.

This is not a new problem created by AI. Rule 11, under which Reaves was sanctioned, has existed for nearly 90 years. AI simply makes it easier to outsource consequential tasks and harder to reconstruct what oversight occurred after the fact.

Mistake 1: Treating Policy Statements as Proof of Compliance

Why it happens: You assume that stating an expectation in a policy document satisfies your governance obligation. The policy says "AI outputs are subject to human review," and you believe that statement alone demonstrates oversight.

The consequence: When asked to prove compliance, you produce the policy document. The court, regulator, or auditor asks for evidence that the review occurred. You have nothing to show. In the Reaves case, the firm referenced an internal email with the subject line "Mandatory Ethical AI Training & Reporting Protocols for All Staff" but could not demonstrate the email was shared firm-wide or that any training took place.

The fix: Separate policy from proof. Your policy states the expectation. Your compliance infrastructure creates the record. For every AI-assisted decision that carries legal, financial, or reputational risk, document what the AI produced, what the human reviewed, and what judgment was exercised. This record must be contemporaneous, not reconstructed from memory after a show-cause order arrives.

Mistake 2: Failing to Define Which Decisions Require Human Review

Why it happens: Your policy contains broad language about "responsible AI use" without specifying which outputs require verification. You assume your team knows which decisions are consequential, but you have not defined the boundaries.

The consequence: When AI influences a decision that later becomes contested, you cannot demonstrate that the decision was flagged for review. In Reaves, the firm never meaningfully answered what role AI played in its court pleadings. Filing pleadings is a consequential decision with legal obligations for the attorney, the firm, and the client. Without a defined process, the firm could not show that this decision triggered oversight.

The fix: Create a decision taxonomy. Identify which decisions carry legal, financial, or reputational risk and require human verification of AI outputs. Document this taxonomy in your governance framework. For example, if AI drafts regulatory filings, customer communications, or financial disclosures, those outputs require documented review before submission. If AI generates internal analysis with no external consequence, the review standard may differ. Make the distinction explicit.

Mistake 3: Not Recording the Results of Human Review

Why it happens: Your team performs the review but creates no record of it. The attorney reads the AI-generated draft, makes edits, and submits the final version. The verification happened in someone's mind, but no documentation exists.

The consequence: You cannot prove the review occurred. When the court ordered Reaves to describe its verification steps, the firm produced no records demonstrating what was reviewed, what judgment was exercised, or what conclusion was reached. Without a record, the firm's claim of verification was unsupported.

The fix: Implement a verification log. For each AI-assisted decision requiring review, record: the date, the reviewer's name, what the AI produced, what was verified (citations, calculations, factual assertions), and what action was taken. This does not require complex technology. A structured log entry in your document management system or a simple attestation form signed by the reviewer creates the contemporaneous record you need.

Mistake 4: Assigning Accountability Only After a Problem Surfaces

Why it happens: Your policy states that "human oversight" is required but does not name who owns that oversight for specific decisions. When something goes wrong, you attempt to assign accountability retroactively, often to departed personnel or restructured teams.

The consequence: Accountability without named ownership is not accountability. In Reaves, the firm attempted to place responsibility on a departed general counsel. The court attributed accountability to the firm jointly with the attorney whose name appeared on the pleadings. Blaming departed personnel does not relieve the organization of responsibility.

The fix: Assign named ownership at the decision point, not after failure. For each category of AI-assisted decision, identify the role responsible for verification. If AI drafts a regulatory filing, the compliance officer owns the review. If AI generates financial analysis, the finance director owns the verification. Document this assignment in your governance framework and in the verification log for each decision.

Mistake 5: Ignoring Warning Signals That Your Process Is Failing

Why it happens: You receive a signal that your AI governance process has failed (an error, a complaint, an allegation), but you do not stop to review or correct your processes. You assume the failure was isolated and continue operating as before.

The consequence: The failure repeats, often with escalating consequences. In Reaves, the defendants alleged that the first motion contained AI hallucinations. The firm then filed two additional pleadings with the same defects. A warning signal arrived, and the firm did not stop, review, or correct its processes before the court issued sanctions.

The fix: Build escalation triggers into your governance framework. Define what constitutes a warning signal: an unverified output reaching a client, a regulator questioning a submission, an internal audit finding a gap in documentation. When a trigger occurs, halt similar decisions, conduct a root-cause review, and document corrective action before resuming. Your governance framework should include a monitoring function that tracks these signals across decisions and over time.

Prevention Checklist

Before the next audit, regulatory inquiry, or legal challenge, confirm you can produce evidence of AI oversight:

  • You have defined which decisions require human verification of AI outputs, documented in a decision taxonomy
  • For each decision requiring verification, you create a contemporaneous record: date, reviewer name, what was verified, and what action was taken
  • Named individuals are assigned ownership of verification for each category of AI-assisted decision
  • Your verification records are stored in a system that preserves them even when personnel change or processes are restructured
  • You have defined warning signals that trigger a halt and review of your AI governance process
  • You can produce, within 24 hours, a log of all AI-assisted decisions requiring verification in the past 90 days, including evidence that verification occurred
  • Your legal, risk, or compliance team has tested your ability to produce this evidence through a mock inquiry

If you cannot check every box, your AI policy is an assertion, not evidence. The question worth asking now is simple: If asked tomorrow to prove it, what would there be to produce?

Rule 11

You Might Also Like