How One Law Firm Got AI Certified in 90 Days
Ninety days before their certification date, the firm's managing partner had a list of twelve AI tools her associates were using — none of them approved, four of them running on US servers — and a major bank client whose procurement team had just added "certified AI governance" to the annual panel review criteria. The bank's deadline was four months away. The partner needed a plan.
That scenario is becoming common. A 2024 Thomson Reuters survey found that 71% of law firms had received questions about AI governance from clients in the past twelve months. Fewer than 20% could produce a documented governance framework in response. The gap between what clients are asking for and what firms have available is the actual business case for AI certification — not the regulatory calendar.
The Real Forcing Function
Most managing partners expect AI certification pressure to come from bar associations and regulators. It's arriving from procurement departments first. Financial services clients, pharmaceutical companies under FDA oversight, and government agencies now include AI certification in procurement requirements. Fieldfisher's Brussels office completed ISO 42001 certification — the AI management system standard that maps directly to EU AI Act requirements — in Q1 2025, citing client procurement requirements as the primary driver. CMS, operating across 17 EU jurisdictions, published its AI governance framework in 2024 and uses sovereign deployment as a core requirement.
Bar association pressure follows its own timeline. Luxembourg's Bar Association's AI guidance, published in February 2024, requires firms to document the infrastructure sovereignty of any AI system processing client communications. France and Germany published comparable guidance in 2024. Bar association guidelines move slowly compared to commercial contracts. The procurement team at a major bank that removes an uncertified firm from their legal panel acts within weeks — not years.
Law firms handling EU clients face AI certification requirements from three simultaneous sources: the EU AI Act (which classifies AI used in legal proceedings as high-risk under Annex III — the EU's category for AI applications that directly affect individual rights, effective August 2026), bar association AI guidance, and client procurement policies. Addressing all three with a single 90-day program is more efficient than three separate compliance projects running on three separate timelines.
Some firms ask whether to "move fast with AI now and figure out certification later." That's a false choice. The EU AI Act is not waiting for law firms to get comfortable with it — high-risk classification takes effect August 2026. The 90-day certification path enables AI deployment and closes regulatory exposure at the same time. Moving fast and moving compliantly are the same project.
What the Associates Are Already Doing
Ask any managing partner whether their associates use AI, and the answer is yes. Ask whether those tools are approved and audited, and the conversation gets complicated.
Six months into an AI governance review, a firm's IT team typically finds the same picture: research queries running through consumer AI accounts, contract drafting support through tools the firm hasn't audited, translation software processing client communications on infrastructure the firm has no visibility into. Nobody authorized these tools. Nobody prohibited them either. Associates adopted what worked, and the firm accumulated exposure month by month.
68% of Am Law 200 firms reported in a 2024 Thomson Reuters survey that they are using AI in client-facing work. Only 12% have completed a formal AI governance process. Every month that gap persists, bar associations in France, Germany, and Luxembourg move closer to enforcement actions that name managing partners directly — not just the firms.
The legal exposure is specific. Luxembourg's legal professional secrecy law does not provide an exception for AI tools running on external servers. A firm that processes client matter data through a US-hosted AI system may be in breach of professional secrecy rules regardless of the AI vendor's security posture. The vendor processed the data on the firm's behalf. The lawyer authorized it — explicitly or by omission. There is no vendor defense for professional secrecy breaches in law.
One way to see the urgency clearly: start from the bar association audit scenario and work backward. An auditor asks for the list of AI systems processing client data, the legal basis for each, the professional secrecy assessment, and the data retention records. How long would it take your firm to produce that documentation today? If the answer is "weeks" or "we'd have to reconstruct it," certification is your fastest route to having that documentation ready before the question arrives.
The Four-Phase Path
Getting certified in 90 days follows a structured sequence. The bottleneck is almost never the technology — it's the governance conversation between partners about which AI use cases are authorized.
Phase one: scoping (weeks 1-2). Map every AI tool currently in use across the firm, whether authorized or not. Classify each by the data it touches and the privilege status of that data. Get partners to a documented decision about which use cases are authorized going forward. This is the hardest phase — not technically, but politically. Three partners who disagree about whether AI should draft client-facing correspondence can stall a 90-day program for six weeks. Resolving that governance conversation before technical implementation begins is the fastest path to certification.
Phase two: deployment (weeks 3-8). Replace the twelve unauthorized tools with a single sovereign system. Leeloo's SL2 deployment — dedicated infrastructure with nothing leaving EU jurisdiction and zero data exiting the firm's perimeter — handles the professional secrecy requirement by architecture, not policy. The system logs every interaction, creates an audit trail for every client matter touch, and enforces the privilege boundaries the firm defined in phase one. Associates get full-capability AI access. Managing partners get governance documentation. The tension that usually divides them resolves structurally.
Phase three: documentation (weeks 9-10). ISO 42001 certification requires documentation covering AI system governance, risk assessment, and management controls. From scratch, that's approximately 60 hours of consulting work. Leeloo's legal sector deployment includes four pre-built components: a data processing register for AI systems under professional privilege (satisfying GDPR Article 30 — the data protection rule requiring organizations to maintain written records of exactly how they process personal data), a risk classification matrix for EU AI Act high-risk system documentation, a sovereignty attestation document required by most bar association guidelines, and an ISO 42001 gap analysis — a structured comparison of what the standard requires versus what the firm currently has in place — pre-populated for a law firm context. The firm contributes the firm-specific risk decisions. Infrastructure documentation comes pre-written.
Phase four: audit preparation and certification (weeks 11-12). Submit the documentation package, prepare for the ISO 42001 audit, and update the firm's client pitch materials with the certification credential. At this point, the client who triggered the certification project gets the documented answer their procurement team required.
Certification as Sales Asset
Managing partners who frame AI certification as "regulatory burden" will underfund it and under-deliver. Those who frame it as "the credential that wins regulated industry clients" will resource it properly and complete it in time to pitch the next panel renewal.
Both manage the same certification work. One treats it as a cost center. The other treats it as a client acquisition investment.
Pharmaceutical companies completed ISO 13485 certification — quality management for medical devices, requiring comparable governance documentation and audit processes — through the 1990s. The firms that certified early gained regulatory approval faster, attracted more research partnerships, and commanded higher acquisition premiums. The firms that waited were acquired by the ones that didn't. The parallel isn't exact. The direction is the same.
When a client's procurement team adds "certified AI governance" to panel criteria, uncertified competitors can't bid. Standalone AI governance consulting fees run €80,000–€250,000 for what the 90-day path covers in a pre-built deployment. One successful panel renewal covers the implementation cost.
The Pitch After the Certificate
Four months after that first conversation with the bank's procurement team, the firm walked into the panel renewal meeting with documentation: sovereign AI certified to ISO 42001, operating on SL2 infrastructure within EU jurisdiction, with a complete audit trail for every client matter that touched the system. Procurement questions took twenty minutes. The retainer discussion took the rest of the meeting.
Certification became a sales conversation, not a compliance exercise. That reframe — from cost to credential — is what separates firms that resource certification properly from firms that treat it as a burden and stall.
Associates still use AI — their firm's AI, governed, audited, and jurisdiction-confirmed. And the managing partner has something her competitors don't yet have: the answer ready before the question arrives.