Current Awareness Strategy Blog

A Governance Policy Isn't a Readiness Plan

Written by Philippa McIntosh | August 17, 2026

If your firm has a formal AI governance framework in place, you're already ahead of most of the legal market. But our State of AI Readiness in Legal 2026 research turned up an inconvenient finding: having a policy and being ready to scale AI safely are two different things, and right now, a lot of firms have the first without the second.

The paradox at the top of the market

Knowledge and innovation leaders report a formal AI governance framework at nearly double the rate of the broader market: 85% versus 44%. On paper, they're well ahead. But ask those same leaders whether their firm is actually ready to scale AI safely, and the lead nearly disappears: 37% say yes, compared to 33% across the broader market.

Put differently: the document exists. The confidence to act on it doesn't.

Where the real exposure sits

That gap tends to live in a handful of specific, structural places that a governance document alone doesn't fix, and it's exactly what came up when we put these findings in front of a live panel of knowledge and research leaders at our August online event, Fragmented, Ungoverned, Unconfident.

Shadow AI. 43% of respondents aren't confident they know which AI tools their own lawyers are using day to day. You can't govern what you can't see, a point our own live poll on the panel echoed almost exactly. Marijah Sroczynski, Research Services Operations Manager at Morrison Foerster, put it plainly: "As much data as I have at my fingertips, tracking everything, I'm never confident they're not doing something I can't see."

Knowledge foundations. AI output is only as reliable as the knowledge infrastructure behind it, and fragmented, ungoverned knowledge bases are the root cause behind most of the AI underperformance we found in the data. James Grandage, Hill Dickinson, made the same point from the practitioner's seat: "AI is just polishing what is there, making it look professional, even though underneath it's data that's not very structured, not very organized. It makes it more obvious how bad the data is."

Client-facing risk. 58.8% of respondents named a client-facing mistake caused by AI as their single biggest fear, ahead of regulatory breach or data security risk. Fear isn't the same as a process that catches the mistake before it reaches a client. Emily Florio, Director of Knowledge Research and Resources at DLA Piper, described how that gap opens up in practice: "It's got citations now, so I must be okay. So I don't bother to fact-check that the citation actually says the exact opposite of what the AI just told me."

None of these show up on a governance framework's cover page. They show up in the workflow, the systems, and the review process underneath it.

Why a number won't tell you what to do next

We built a free AI Readiness Diagnostic so firms could benchmark themselves against the market across exactly these dimensions: adoption, governance, visibility, knowledge foundations, risk management, integration, expertise, and confidence to scale. It's a useful gut check, and worth taking if you haven't.

If any of this sounds like where your firm sits right now, we'd rather talk it through than hand you another report to read. Book 20 minutes with the Vable team and we'll walk through where the real exposure is for your firm specifically, and what closing it would actually take.

Book a meeting with the team →