White & Case buys into AI contract platform Clauze: what to check now about your contract AI
White & Case has invested in the Saudi AI contract platform Clauze.AI. These are the governance, verification and privacy questions to ask before you adopt it.
You must now document which AI agents act on which contract clauses, under which jurisdiction client data flows, and how you will reconstruct each decision if challenged. Before adopting any contract-AI platform, test these points explicitly rather than treating the tooling as proven by a law firm's investment in it.
An analysis of 10 September 2026 of agentic contract platforms and the governance questions they raise argues that a leading firm's equity stake in a regional AI contract platform shifts the evaluation from capability to controllability. The concrete case is a major international law firm's investment in a Saudi-based platform focused on AI-driven legal workflows and contract management. In our assessment, this development means you cannot treat such an investment as product endorsement; instead, it signals that governance frameworks for agentic AI in sensitive legal work remain unsettled, and you must test them yourself before adoption.
What makes agentic contract platforms different from document automation?
The distinction lies in autonomy. Classic contract tools display text or flag clauses for human review. Agentic platforms embed AI agents that perform steps within the workflow—analysing clauses, proposing edits, managing lifecycle stages—without human intervention at each point. That capability makes them useful for high-volume, lower-risk work, but it also means decisions affecting confidential client contracts are made by systems you do not directly control. The moment an AI agent acts on a clause, you need to know which agent it was, what instruction it followed, and what it changed.
Where do client data and conflicts of interest create governance risk?
A law firm that is both user and shareholder in a contract platform faces three overlapping tensions. First, client data flows through a start-up's infrastructure in an emerging market, raising questions about jurisdiction, data residency and who can access it. Second, the firm's growth incentives as a shareholder do not automatically align with its duty of care to clients; the platform's commercial success may depend on features or data practices the firm would not permit if it were merely a customer. Third, when firm-linked AI tools act on confidential contracts, the firm remains liable for their outputs, but the start-up controls the system. These are not theoretical risks; they are the points at which governance breaks down.
What must you be able to demonstrate about each workflow?
Before you adopt a contract-AI platform, you must be able to show:
- Identify the model and its training data — which AI model each workflow uses, what data it was trained on, and whether that training included client contracts or confidential material.
- Document the lawful basis for data processing — the legal ground under which you process client data through the platform, and how you have obtained client consent if required.
- Log which agent performed which action — a complete audit trail showing which AI agent edited which clause, when, and what the change was.
- Verify outputs before they leave your systems — a human review step that catches errors, hallucinations or unintended changes before any output reaches a client or external party.
- Establish data residency and access controls — confirmation that client data remains within jurisdictions you control, and that only authorised personnel can access it.
- Define the scope of agent autonomy — explicit rules for which tasks the AI agent can perform without human approval, and which require a lawyer's sign-off before execution.
What failure modes should you test for?
When you evaluate a contract platform, look for these specific risks:
- Data leakage through the platform — client confidential information reproduced in model outputs or inferred from patterns the AI has learned.
- Untracked agent decisions — AI actions on clauses that leave no audit trail, making it impossible to explain what changed or why.
- Conflicts of interest in feature design — platform features that benefit the shareholder firm's commercial position but not the client's interests.
- Jurisdiction and data residency gaps — client data stored or processed outside the legal framework you have agreed with the client.
- Hallucination and false edits — the AI agent proposing or making changes to contracts that do not reflect the actual terms the parties agreed.
- Inadequate human oversight — workflows where the AI agent's output becomes binding without a lawyer's review.
What can tooling show you, and what remains your own judgement?
Verification and logging systems can make AI activity visible and inspectable; they can show you which agent acted, when, and what changed. They cannot tell you whether the change was correct, whether it serves the client's interests, or whether it complies with the client's instructions. That remains the lawyer's responsibility. A console that displays agent actions and flags data flows is useful for control; it is not a substitute for professional judgement. The investment by a leading firm in a contract-AI platform is a governance moment, not a governance solution. You must still ask the hard questions yourself.
Sources: This article draws on reporting and guidance from White & Case, Reuters and Stanford Institute for Human-Centered AI.
Written by
Marit Halversen
Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.