New regulations pulled daily, scored for relevance per client, summarised and sent.
Tracking legislation is work nobody bills for, so it happens irregularly. The audit looks at how available the sources are, how precisely relevance can be judged for a specific client, and how to turn the output into something you can charge for.
AI Workflow
An AI workflow with human review gates will automate routine relevance scoring and summarisation while keeping lawyers in control of judgment calls.
The recommended path is an AI workflow with structured human-in-the-loop gates at the exception and sign-off stages. The process is highly repetitive, text-heavy, and rule-driven for the majority of cases, making it a strong candidate for AI-assisted triage and summarisation. The firm has no developer and no appetite for custom code, so a low-code AI workflow platform that integrates with Outlook and the document management system is the right fit. Compliance constraints around legal professional privilege and GDPR mean that only vetted, data-processing-agreement-backed AI tools can be used, and a human must review every output before it reaches a client. The goal stated by the client, letting routine cases handle themselves while people focus on exceptions, maps precisely to what a well-configured AI workflow delivers.
The firm uses a document management system and Outlook with no in-house developer. A low-code AI workflow platform such as Microsoft Power Automate with Copilot, or a vetted legal AI tool, can connect to both systems without custom development and keeps data within a contractually controlled environment.
Process Overview
The Legal and Administration team at this firm monitors the statute book and official gazettes on a daily basis, watching for newly published regulations that may be relevant to their clients. When new material appears, a team member, typically one of the four fee earners or the paralegal, reads through it, assesses whether it applies to each client on their roster, assigns a relevance score, and writes a summary. That summary is then sent directly to any client for whom the regulation is considered material. The whole cycle runs a few times a week and amounts to roughly 250 discrete instances per year, each taking around 45 minutes on average.
The process sits entirely inside two systems: a document management system where regulations and client files are stored, and Outlook for communication. There are no confirmed APIs between these systems and no developer on the team. The relevance criteria used to assess each regulation against each client are not formally documented; they live, for the most part, in the heads of two or three experienced people. This creates both a knowledge risk and a consistency risk, since the same regulation could be scored differently depending on who happens to review it.
The compliance stakes are high. Every client-facing output carries potential negligence liability if the legal assessment turns out to be wrong and a client relies on it. Client documents are subject to legal professional privilege and GDPR, which means any tool that touches client data must have a properly signed data processing agreement in place and must not use that data to train its models. These are non-negotiable constraints that shape every automation decision for this process.
Path Scores
The process is document-heavy, largely rule-driven, and high in volume relative to team size. An AI workflow can handle ingestion, relevance scoring against client profiles, and first-draft summarisation automatically, routing only exceptions to a human. This matches the client's stated goal and requires no developer to configure or maintain.
A hybrid approach is essentially what the recommended AI workflow already embeds, since human review gates are mandatory given the negligence and privilege constraints. Scoring it separately, a more explicitly hybrid design with a dedicated triage dashboard could add value but introduces more build complexity than the firm can sustain without a developer.
An autonomous AI agent could in principle monitor gazettes, score relevance, and draft summaries end-to-end. However, the compliance constraints and negligence liability make fully autonomous output to clients unacceptable, and the firm lacks the technical capacity to build, monitor, and govern an agent safely.
The current manual process is inconsistent, unbillable, and dependent on tacit knowledge held by two or three people. Staying manual preserves the status quo risks of missed regulations, rework, and staff time spent on low-value work, with no path to improvement.
RPA is well suited to structured, repetitive UI interactions but cannot read and interpret unstructured legal text or make relevance judgments. It could assist with ingestion from fixed-format sources but would not address the core problem of understanding and scoring regulatory content.
The firm has no developer and no appetite for one. Even if built externally, a coded solution would require ongoing maintenance and cannot handle the natural language interpretation that is central to this process. This path is impractical given the team's constraints.
Process Dimensions
Eight dimensions drive the recommendation, scored 0–10 with a note on each.
Input data is unstructured legal text from gazettes and statute books, which requires natural language understanding rather than simple field extraction.
Relevance rules exist per client but are partially tacit, held in the heads of two or three people, making them partially codifiable but not fully explicit today.
Approximately a quarter of cases are non-standard and require human judgment, which is a meaningful exception rate but still leaves a clear majority as automatable routine cases.
The document management system and Outlook are the only systems in use, and no APIs are confirmed, but both are common platforms with established low-code connectors available.
At 250 runs per year and 45 minutes each, the process consumes around 188 hours annually, representing a meaningful but not enormous automation target that justifies a low-to-mid investment.
The structure of the process is stable but the content changes constantly as new legislation is published, which is exactly what AI summarisation handles well.
Legal relevance assessment and client-specific advice carry negligence liability, making human sign-off on every client-facing output non-negotiable regardless of the automation approach.
Legal professional privilege, GDPR, and duty of care create strict constraints on which tools can process client data, requiring vetted platforms with data processing agreements in place before any AI tool is used.
ROI Estimate
€1,875
Current annual cost
60%
Estimated time saved
€1,125
Annual savings
32mo
Payback period
Current annual cost calculated as 250 runs x 45 minutes / 60 x EUR 25 per hour = EUR 1,875. The 60% savings estimate reflects automation of routine cases (approximately 75% of volume) with AI handling ingestion, scoring, and first-draft summarisation, while human review time on those cases is reduced but not eliminated; the biggest cost driver is the build and vetting effort required to meet compliance requirements.
Implementation Roadmap
Identify and legally vet one or two low-code AI workflow platforms (for example Microsoft Copilot Studio with Power Automate, or a specialist legal AI tool) against GDPR and privilege requirements. Obtain data processing agreements and confirm that client data will not be used for model training. This is the critical compliance gate and must be completed before any data flows to an AI tool.
Work with the fee earners to extract and document the relevance criteria currently held in people's heads for each client. These criteria become the scoring rules fed to the AI workflow. This step surfaces tacit knowledge and is essential for the AI to produce useful relevance scores rather than generic summaries.
Configure the AI workflow to ingest new gazette publications, run them against documented client profiles, generate a relevance score and a draft summary, and route the output to the responsible fee earner for review via Outlook. Start with the most predictable client types to build confidence. No client-facing output is sent without human approval at this stage.
Add a triage layer that flags low-confidence or high-complexity items for senior review before the summary is finalised. Define clear criteria for what constitutes an exception. This ensures the human-in-the-loop gate is structured rather than ad hoc, and that the paralegal and fee earners know exactly what they are being asked to check.
Train all five team members on the new workflow, focusing on how to review AI-generated summaries critically, how to update client relevance profiles, and how to escalate edge cases. Document the process so that knowledge is no longer held by two or three individuals. Run in parallel with the manual process for a short period to validate output quality.
Decommission the parallel manual process and move to the AI workflow as the primary method. Establish a monthly review of AI output quality and a lightweight mechanism for fee earners to flag incorrect relevance scores so that client profiles can be updated. Monitor for any compliance incidents and maintain an audit log of all client-facing outputs.
Risks & Considerations
The most significant risk is compliance failure. If client documents are processed by an AI tool that has not been properly vetted under GDPR and legal professional privilege rules, the firm faces regulatory exposure and potential breach of client confidentiality. Every platform used must have a signed data processing agreement and a clear commitment that client data is not used for model training. This vetting step cannot be shortcut. A second risk is over-reliance on AI relevance scores. If fee earners begin approving summaries without genuine review, the human gate becomes a rubber stamp, and the negligence liability that exists today is not reduced. The firm must invest in training that reinforces critical review rather than passive approval. Finally, the client relevance profiles that drive scoring will drift over time as client circumstances change. Without a lightweight process for keeping those profiles current, the AI output will degrade and the team may lose confidence in the tool, reverting to manual methods.
Architecture Overview
Hover to zoom · click for fullscreen
Why This Approach
The recommended path is an AI Workflow with structured human review gates, and the reasoning starts with the nature of the work itself. The core tasks, reading unstructured legal text, matching it against a set of client-specific criteria, and producing a concise written summary, are exactly what current AI language models do well. The volume is meaningful, around 188 hours of fee-earner time per year, and the majority of cases are routine enough that a well-configured AI can handle ingestion, relevance scoring, and first-draft summarisation without any human involvement until the review stage. That frees the team to focus their attention on the roughly quarter of cases that genuinely need experienced legal judgment, which is precisely the outcome the client described as their goal.
The firm's technology constraints point clearly toward a low-code AI workflow platform rather than anything that requires custom development. Microsoft Power Automate with Copilot Studio is the most natural fit given the Outlook dependency and the likelihood that the document management system is also part of the Microsoft ecosystem, though a specialist legal AI platform with established connectors to common document management systems is a credible alternative if data governance terms are stronger. Either way, the configuration work stays within a visual, low-code environment, and the team does not need a developer to build or maintain it. This directly addresses the firm's stated preference, and it is worth being direct: recommending a coded solution or a fully autonomous AI agent here would be ignoring a real and reasonable constraint, not just a preference.
The compliance requirements are the single biggest factor in why a fully autonomous AI Agent scores lower despite being technically capable of handling the same tasks. An agent that monitors sources, scores relevance, and sends summaries to clients without a human in the loop is not acceptable under the firm's duty of care and negligence liability position, regardless of how accurate the agent might be. The AI Workflow path is specifically designed to keep a human sign-off step before any output reaches a client, which means the legal professional responsibility stays exactly where it belongs: with the fee earner who approves the summary. This is not a limitation of the recommended approach; it is a feature of it.
Compared to the Hybrid path, which scores similarly, the AI Workflow recommendation already embeds the human-in-the-loop gates that a hybrid design would add separately. Treating them as distinct paths is somewhat academic in this context, since the compliance requirements mean the workflow must be hybrid in character. The difference is that a more explicitly hybrid design, with a dedicated triage dashboard and separate routing logic, adds build and maintenance complexity that the firm cannot sustain without technical support. The AI Workflow path achieves the same control with less infrastructure.
Stay Manual, RPA, and Traditional Code each fail for different but clear reasons. Staying manual preserves the current knowledge concentration risk and the inconsistency problem, with no realistic path to improvement. RPA cannot interpret unstructured legal text, so it might automate the ingestion step but leaves the hard part untouched. Traditional Code requires a developer the firm does not have and is not looking to hire, and a coded rules engine cannot handle the natural language interpretation that sits at the heart of this process. The honest position is that none of these three paths addresses the actual problem, which is that skilled people are spending significant time on work that is largely pattern-matching against documented client criteria, and that pattern-matching is now something AI does reliably and cheaply.
Comparing the Top Approaches
The two most credible paths here are AI Workflow and Hybrid. In practice, the distinction between them is narrower than the labels suggest, because any responsible AI Workflow for this process already embeds human review gates at the exception and sign-off stages. The reason AI Workflow edges ahead is simplicity of ownership. A more formally architected Hybrid design, with a dedicated triage dashboard and explicit human queues built as separate components, would deliver marginally more visibility but would also require ongoing configuration and maintenance that a five-person team with no developer simply cannot sustain. The AI Workflow approach folds the human gate into the existing Outlook environment the team already uses, keeping the operational burden low.
The AI Agent path scores a five and is worth addressing directly, because it sounds appealing on paper. An autonomous agent monitoring gazettes, scoring relevance, and drafting summaries end-to-end would save the most time. The problem is that autonomous output to clients is not acceptable here. The negligence liability attached to wrong advice, combined with GDPR and legal professional privilege constraints, means a human must review every client-facing output before it leaves the firm. An AI Agent designed to operate without that gate would require governance infrastructure, monitoring tooling, and technical oversight that this firm does not have and is not seeking to build. It is the right answer for a different organisation in a different context. It is not the right answer here.
RPA, Traditional Code, and Stay Manual all score at three or below and are not serious contenders. RPA cannot interpret unstructured legal text, which is the entire substance of the problem. Traditional Code requires a developer to build and maintain, which the firm has ruled out. And staying manual preserves a process that is already inconsistent, unbillable, and dependent on tacit knowledge concentrated in two or three people. The direction of travel is clearly toward AI Workflow, and the assessment data supports that conclusion firmly.
How to Build It
The first and most important step is tool vetting, and it has to happen before any client data touches an AI system. The firm should evaluate one or two low-code AI workflow platforms against its GDPR obligations and legal professional privilege requirements. Microsoft Copilot Studio with Power Automate is the most practical candidate given the existing Outlook environment and the likelihood that a Microsoft 365 licence is already in place, but a specialist legal AI platform such as Harvey or Luminance is worth assessing if the firm wants domain-specific relevance scoring out of the box. Whichever platform is selected, a signed data processing agreement must be in place and the firm must confirm in writing that client data will not be used to train or improve the underlying model. This gate takes two to three weeks and cannot be compressed.
In parallel with vetting, the team needs to externalise the relevance criteria that currently live in people's heads. Each client has a profile of regulatory areas they care about, shaped by their sector, their structure, and their prior instructions to the firm. Those criteria need to be documented in a format the AI workflow can use as scoring rules, whether that is a structured prompt template per client, a tagged keyword schema, or a combination of both. This step is genuinely collaborative: the fee earners know the rules, and the automation consultant's job is to help translate them into something a machine can apply consistently. Getting this right is what separates a useful AI output from a generic summary that the team ignores.
Once the profiles are documented and the platform is vetted, the pilot workflow can be built. Power Automate monitors a shared mailbox or a watched folder in the document management system for new gazette publications, passes the document text to the AI model with the relevant client profile as context, and returns a relevance score alongside a draft summary. That output is routed to the responsible fee earner as a structured email in Outlook, flagging the client name, the regulation, the score, and the draft text for review. The fee earner approves, edits, or rejects the summary before anything leaves the firm. Items that score below a defined confidence threshold, or that touch a regulatory area flagged as high-complexity for that client, are automatically routed to a senior fee earner rather than the paralegal queue. Nothing automated goes to a client without a named individual having approved it.
The final phase is handover and quality assurance. All five team members need training that goes beyond clicking buttons: they need to understand what the AI is doing well enough to catch it when it is wrong. That means reviewing summaries critically rather than scanning them, knowing how to update a client relevance profile when circumstances change, and having a clear escalation path for edge cases. A parallel run against the manual process for the first two to three weeks after go-live will surface any systematic errors before they reach clients. After that, a monthly review of a sample of AI outputs, combined with a simple feedback mechanism for fee earners to flag incorrect scores, keeps the system honest over time. The audit log that Power Automate generates as a byproduct of its workflow runs also provides a defensible record of every client-facing output and who approved it.
Risks in Detail
The most serious risk is a compliance failure before the workflow is properly governed. If the team moves quickly and routes client documents through an AI tool that does not have a signed data processing agreement, or that retains data for model training without the client's knowledge, the firm faces a GDPR breach and a potential violation of legal professional privilege. The reputational and regulatory consequences of that are significantly worse than the inefficiency the automation is trying to solve. The vetting step in week one is not a formality: it is the foundation the rest of the implementation rests on, and it should involve the firm's own compliance review rather than being delegated entirely to the automation consultant.
The second category of risk is subtler and more likely to materialise slowly. If fee earners begin approving AI-generated summaries without genuinely reading them, the human review gate stops functioning as a control and becomes a record of passive sign-off. The negligence liability that exists today does not diminish just because an AI drafted the summary. A lawyer who approves and sends an inaccurate summary to a client is still the responsible professional. This means the firm needs to be deliberate about how it frames the review step in training, treating it as a professional judgment rather than an administrative tick. Related to this, the client relevance profiles that drive the AI's scoring will drift if they are not maintained. A client's regulatory footprint changes as their business evolves, and a profile built in year one that is never updated will produce increasingly irrelevant scores by year two. Without a lightweight process for keeping those profiles current, the output quality degrades quietly until the team loses confidence in the tool and reverts to doing everything by hand.
Claude Code Starter
A scaffolded project ready to open in Claude Code. Unzip, open the folder, and Claude starts building immediately.
Claude Code Starter (.zip)
Your own assessment includes a ready-to-use project scaffold: CLAUDE.md, pyproject.toml, src/agent.py and .env.example. Open the folder in Claude Code and it starts building.