You can review a contract in three ways: with a general AI assistant, with legal-specific AI software, or by a human, possibly supported by a junior or legal ops. The question that matters is not which brand scores best, but which approach fits this contract type and risk level. An NDA on your own template asks something different from a negotiated agreement with bespoke clauses and three rounds of redlines. This piece compares the three on time, error risk, data policy, auditability, and what you can explain to the client.
The three approaches, briefly
A general AI assistant is a chat interface without legal specialization. You paste in text and ask a question or give an instruction; the model is trained on a broad corpus, not specifically on contract law or case law.
Legal-specific AI software works with clause libraries, playbooks, and redlining workflows, often citing a clause's source and tracking version history.
Human review is a lawyer reading the contract, possibly with a junior doing a first pass or legal ops streamlining the process with checklists.
What it costs in time
| Approach | Quick scan of a standard contract | In-depth review of a bespoke contract | Effect of repeated use | |---|---|---|---| | General AI assistant | Minutes | Unreliable without your own instructions and checks | No learning effect unless you build your own prompts and checklists | | Legal-specific software | Minutes to a quarter hour | Hours, guided by a playbook | Faster after the first rounds, through an accumulated clause library | | Human, possibly with junior or legal ops | Fifteen to thirty minutes | Hours to days, depending on complexity | Faster through experience with the counterparty and the file, not the tool |
The time saved by AI sits mostly in the fast part: flagging risks, spotting deviations, producing a summary. In a negotiated agreement, the work shifts to interpretation and judgment, and there AI on its own saves no time without a human weighing the outcome.
What goes wrong
Three recurring failures, regardless of brand. First, hallucination: a model citing a clause or ruling that does not exist, or paraphrasing a provision in a way that shifts its meaning. Bigger with a general assistant lacking source documents, smaller but not zero with legal-specific software carrying a citation requirement.
Second, missed exceptions: an AI system judges what is there, not always what is missing. A missing exoneration clause or a silent renewal without a notice period is exactly what an experienced lawyer catches and a language model easily misses, because nothing looks "wrong."
Third, false confidence: output that sounds certain regardless of whether it is correct. That risk applies to any AI system, and European privacy regulators pointed out that risks of AI models can arise in both the development and the deployment phase4. The more convincing the output looks, the more important the independent check.
Where your data goes
This is the distinction that gets overlooked fastest. With a general AI assistant you often paste in a full contract, including names, amounts, and sometimes special-category personal data, into an interface whose processing regime, retention period, and use for model training you do not always know. Legal-specific software is usually built around data processing agreements, EU hosting, and excluding training on customer data, but that is a procurement condition you must verify, not a given.
The EDPB confirmed that personal data can carry risk in both the development and deployment phase, and that controllers must substantiate that4. For lawyers, there is a separate layer on top: legal professional privilege and confidentiality obligations are not part of the AI Act, a separate, older duty that keeps applying independently of the AI rules. A tool being AI Act-compliant does not automatically make it one you may feed confidential client information into. You check that separately, per processor, per vendor clause.
Governance: what the AI Act does and does not regulate here
Most general AI assistants are general-purpose AI models. Obligations for that model sit with the provider, since 2 August 2025 for models placed on the market from that date, with a transition to 2 August 2027 for older ones1. As deployer, whether firm or legal department, the emphasis falls on responsible use: since 27 July 2026, Article 4 requires measures supporting your people's AI literacy, not a guaranteed individual skill level1. Article 50 on transparency has applied since 2 August 2026 and was not delayed by the amending regulation; only the machine-readable marking obligation of paragraph 2 has a transition until 2 December 2026, and only for systems already on the market before 2 August 20261.
Annex III high-risk obligations only become enforceable from 2 December 20271. Contract review software does not automatically fall under that, but it is a per-system qualification question. What matters now: your privacy and procurement terms, and what measures you can show a regulator2.
Two things on certification get mixed up often. A vendor may hold ISO/IEC 42001 as an AI management system; that is an international governance standard, but not a harmonised European standard, so it grants no presumption of conformity with the AI Act5. EN 18286, approved 12 July 2026 as the first European standard under standardisation request M/613, is on that route; a harmonised standard delivers the presumption of conformity once it is cited in the Official Journal, and then only for the part it covers6. So do not just ask a vendor whether they are certified; ask under which standard, and whether it grants a presumption of conformity3.
For a serious incident with a high-risk system, the deployer first informs the provider, plus the importer or distributor and the market surveillance authority; if the provider cannot be reached, the deployer's own reporting duty under Article 73 applies, with its own deadlines1. Fines for prohibited practices run up to EUR 35 million or 7% of global turnover, for most other breaches up to EUR 15 million or 3%, and for SMEs and start-ups the lower amount always applies1.
How auditable is the result
With a general assistant, output is usually not traceable to a source: no link to the clause, no version history. Legal-specific software is often built to cite the playbook rule, making it easier to reconstruct why a suggestion was made. Human review is most auditable in terms of explainability: a lawyer can argue their judgment, even where it is subjective. None of the three is automatically fully auditable; that only happens once you record it, in a review note, an audit trail, or an annotation.
What you can explain to the client
This is where the approaches really diverge. "I quickly checked it with an AI assistant" is not an answer a lawyer gives when a liability or conduct question comes up. "We ran the contract against our playbook first and had a senior reviewer sign off" is. Explainability depends not on how advanced the tool is, but on whether a human carries and can substantiate final responsibility.
Contract type: standard versus bespoke
| Contract type | Best approach | Reason | |---|---|---| | Standard NDA, own template | General AI assistant for a quick scan, human spot check | Low risk, little room for deviation, speed matters most | | Standard procurement terms, no negotiation | Legal-specific software if available, otherwise a general assistant with a fixed checklist | Repeat volume needs consistency, not necessarily depth | | Negotiated agreement with bespoke clauses | Legal-specific software for the first round, senior human for the final call | Interpretation and judgment are not an automatable step | | Core agreements with high financial or reputational stakes | Human leads, AI supports, never replaces | Errors are costly, explainability to the client is critical |
Decision rule per contract type
For standard NDAs and procurement terms on your own, approved template: a general AI assistant may do the first scan, provided you use a fixed instruction or checklist and input no confidential third-party data without consent. A human spot check remains necessary, not on every clause but on the deviations the system flags.
For negotiated agreements with bespoke clauses, the opposite applies: AI is a tool for the first round, never the final look. Legal-specific software with a playbook tends to be stronger here, because deviations trace back to a rule, but the final judgment stays with a senior lawyer.
"Neither AI approach" is the answer for clauses touching legal professional privilege, special-category personal data without verified processing terms, and agreements where an error directly leads to liability or reputational damage. "Both at once" fits high-volume standard contracts: a general assistant filters fast, legal-specific software then structures deviations for human review.
The human-review floor
Whichever AI approach you choose, a floor remains that does not move. Exception clauses, liability limitations, playbook deviations, and anything touching privilege or client confidentiality are always assessed by a qualified human before anything goes out the door. A junior or legal ops may do the first pass, but final responsibility for these categories stays with a senior lawyer.
Frequently asked questions
Is legal-specific AI software always better than a general assistant for contract review?
Not by definition. For a quick scan of a standard NDA, a general assistant can be faster and sufficient. Legal-specific software pulls ahead with repeated use, playbook consistency, and traceable suggestions.
Can I paste client documents into a general AI assistant?
That depends on the assistant's processing regime, whether a data processing agreement is in place, and your own confidentiality obligation as a lawyer. That last duty sits outside the AI Act and needs its own check, per tool and document.
Does contract review software fall under the AI Act's high-risk rules?
That is a qualification question per system, not automatically yes or no. Annex III high-risk obligations only become enforceable from 2 December 2027, so for most firms this is currently a procurement consideration rather than an active obligation.
What does Article 4 concretely mean for a law firm using AI?
Since 27 July 2026, Article 4 is a measures obligation: your organization must take demonstrable steps that support AI literacy, such as internal guidelines and training. It does not guarantee an individual skill level per employee, but you must be able to show the measures themselves.
Does a vendor's ISO 42001 certificate provide assurance of AI Act compliance?
No. ISO/IEC 42001 is an international AI management standard, not a harmonised European one, so it grants no legal presumption of conformity. Ask which harmonised standards apply to the part you are using.
Can a junior handle the full review when working with AI software?
For standard, low-risk contracts on fixed templates, yes, given a fixed checklist and spot checks. For negotiated agreements with bespoke clauses, a senior review remains necessary on the categories the human-review floor covers.

