SecurityTechInsider AI security & governance
EN/ NL
Governance

Thomson Reuters CEO: gap widens between firms operationalising AI and those falling behind

Thomson Reuters CEO Steve Hasker warns in the 2026 report about an execution gap around AI in law firms. What does that mean for governance?

1 September 2026 3 min
Illustration for this article: gap widens between firms operationalising AI and those falling behind. Oxidised copper and patinated brass sheet, corrosion blooming across the surface.
Firms must now document AI model use, data handling and human review points to remain competitive and compliant. Image: SecurityTechInsider — original editorial illustration

You must now document which AI models your workflows use, what data they touch, and where human review occurs. This is no longer optional: the execution gap between firms that can demonstrate responsible AI use and those that cannot has become a material risk to your clients, your talent and your revenue.

An analysis of 1 September 2026 of how legal firms operationalise AI and measure its value argues that the technology itself is ready, but that many organisations have not yet built the governance structures to use it responsibly. The case in point is legal practice, where generative AI adoption nearly doubled in a single year, yet almost half of firms still operate without formal AI policy. In our assessment, this gap is not about whether you use AI—it is about whether you can prove to your clients, regulators and your own board that you use it within defined boundaries, with human oversight at the points that matter.

What has changed in how lawyers work with AI?

The shift is structural. Lawyers are moving from generic tools towards domain-specific AI applications built for legal work. That means your role is increasingly one of review, framing and supervision rather than primary execution. Your AI system may draft a research memo, flag case law or surface contract terms, but you decide what stands, what needs correction and what the client receives. This creates new points of friction: you must verify sources, protect client confidentiality and remain accountable for every output that bears your name.

Which failure modes does this create?

  • Unverified source material — AI outputs citing case law or precedent without visible traceability to the actual source.
  • Confidentiality leakage — sensitive client information processed by AI systems without documented safeguards or data handling controls.
  • Accountability gaps — AI-assisted decisions with no audit trail showing which model was used, what inputs it received or which human reviewed the output.
  • Inconsistent workflows — different teams using different AI tools or processes without firm-wide standards or measurement.
  • Uncontrolled model drift — AI systems changing behaviour over time without documented retraining, versioning or performance monitoring.

What must you be able to demonstrate?

  1. Document each workflow's AI model and its lawful basis — record which model each task uses, what data it processes and the legal ground for that processing.
  2. Establish verification and source visibility — build in steps that make AI reasoning and source material visible for your own review before any output reaches a client.
  3. Log human review and decision points — maintain an audit trail showing which outputs a lawyer reviewed, what corrections or disagreements they recorded and what was ultimately delivered.
  4. Define boundaries on what AI may decide alone — specify which tasks AI may complete without human sign-off and which require your explicit approval before use.
  5. Measure performance against stated objectives — track whether your AI investments actually free up time for higher-value work or reduce error rates, as claimed.

How does this differ from earlier AI adoption?

Earlier experiments with AI in legal practice often ran as loose pilots: a team tried a tool, found it useful, and kept using it. The execution gap emerges because that approach no longer satisfies your clients or your regulators. Firms that have closed the gap have moved to formal AI strategy, documented governance and workflows that are auditable. They can tell a client exactly which AI system reviewed their contract, what checks applied and which human lawyer signed off on the result. Firms still running loose experiments cannot.

What can tooling do, and what remains your responsibility?

A verification layer can route tasks through selected AI models, make reasoning and sources visible, and log which human reviewed the output. It can replace sensitive data with synthetic equivalents before processing, or fail closed when privacy checks do not pass. What it cannot do is remove your need to read, think and decide. The final professional judgement—whether an AI output is accurate, complete, appropriate for your client and compliant with your obligations—always remains yours. Tooling makes that judgement visible and defensible. It does not replace it.

Sources: This article draws on reporting and guidance from Thomson Reuters and Thomson Reuters Institute.

Marit Halversen

Written by

Marit Halversen

Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.