> ## Content Index
> Fetch the complete content index at: https://www.realaigovernance.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Every Firm Will Need an AI Vendor Policy. The Question Is When.
- URL: https://www.realaigovernance.com/every-firm-will-need-an-ai-vendor-policy-the-question-is-when/
- Published: 2026-08-19T13:00:55.000Z
- Updated: 2026-08-19T13:00:55.000Z
- Description: Malpractice exposure lands on the attorney who signed the document, not on the vendor's terms of service.
- Author: Robert T. Boyer Ph.D.
- Tags: Future - Inevitability, Vendor Policy, AI Policy, AI risk, AI Governance, Governance Debt Monthly, vendor contract, vendor due diligence, Vendor TOS

The tool was Westlaw. The bill was $29,877\. The vendor says it wasn't their fault.

In a Texas bankruptcy case, a lawyer's filing relying on Westlaw Precision — a paid, established legal research product — contained three fabricated cases and two misrepresented ones. The court didn't treat "I used a reputable tool" as a defense. It found civil contempt, ordered CLE training on generative AI, imposed an adverse costs order, and assessed nearly $30,000 in penalties. And in the background: the vendor itself disputes that its tool produced the errors.

Whoever's right about causation, the lawyer is the one who ate the sanction. That's the part firms keep underestimating. When an AI tool — free or paid, in-house or vendor-supplied — gets something wrong in a filing, the malpractice exposure doesn't land on the vendor's terms of service. It lands on the attorney who signed the document, and by extension, the firm that put the tool in front of them without a process for catching the error first.

Right now, most firms treat AI tool selection the way they'd treat picking a document management system: whoever's cheapest or already has a relationship gets the nod, with little formal vetting. That's not sustainable once "the vendor said it was reliable" stops being an answer courts accept.

A real AI vendor policy isn't complicated. It means: knowing which tools your lawyers actually use (not just the ones IT approved), requiring verification workflows regardless of vendor reputation, and understanding what your indemnification looks like — or doesn't — when the tool gets it wrong.

Firms of every size will have one of these within a few years, the same way every firm eventually got a conflicts-check process. The firms writing theirs now are doing it on their own timeline. The firms that wait are going to write theirs after a bill like this one.

*Does your firm know every AI tool currently in use across matters — or just the ones that were formally approved?*