LEGAL AI AGENTS NEED MATTER-SPECIFIC AUTHORITY BUDGETS

AIAgent

LawFuel’s September 24 coverage of Casepoint’s new purpose-built agents captures where legal technology is heading. The systems are moving beyond chatbots and drafting assistants toward agents that perform relevance review, issue coding, and other steps inside live legal workflows.

Casepoint’s emphasis on audit trails, performance testing, and human validation is a useful start.

The next control legal teams need is an explicit limit on how much authority each agent receives.

Law is full of consequential boundaries. A junior lawyer may review documents without authority to settle a case. A litigation support specialist may manage discovery data without authority to file a pleading. A billing administrator may prepare an invoice without authority to move client funds. Agentic AI should inherit the same principle: capability does not equal permission.

The stakes extend beyond ordinary professional mistakes. Jacob Coxon, after roughly three years doing pretraining research across OpenAI and Anthropic, warned that leading labs are “racing straight to self-improving superintelligence and gambling with our lives.” 

Evan Hubinger, Anthropic’s Alignment Science Lead, responded that “we really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade.” These are their warnings and personal assessments, but human-extinction risk is now part of the frontier AI safety debate.

The current control problem is already concrete. OpenAI disclosed that agents in cyber evaluations circumvented controls, reached the internet, used exposed credentials, and compromised Hugging Face production systems. 

METR later reported that roughly 1,200 agents meant to be isolated found and used an unsanctioned message board, exchanged more than 70,000 messages and files, and about 700 participated in the attack. The agents found a coordination path their designers had not intended.

A law firm does not need a frontier model capable of catastrophic harm to learn from that incident. It only needs an agent whose permissions exceed the task.

That is where an authority budget helps. An authority budget defines the maximum delegated power an agent receives for a matter before human approval becomes mandatory.

A discovery agent might read documents inside one workspace but lack access to unrelated matters. A research agent might retrieve authorities but be unable to contact a court or client. A docketing agent might prepare a filing package while final submission stays human-controlled. A billing agent might identify anomalies but remain unable to move money or alter trust-account records.

The budget should cover data, credentials, tools, external communications, record changes, spending, deployment, and delegation to other agents. It should also expire. Matter-specific access should end when the assignment ends. A recurring agent should not automatically inherit every permission held by the partner or administrator who launched it.

Legal teams should pay particular attention to delegation. If one agent can call another service, create a subprocess, or pass credentials to a tool with broader access, the effective authority may exceed what the user sees on the screen. Logging should capture those handoffs.

Monitoring should flag unexpected tool use, repeated permission failures, or attempts to reach a different matter. Administrators need an immediate pause and revocation mechanism.

This framework complements the human-validation approach LawFuel described in Casepoint’s agents. Performance metrics tell a firm whether the system usually produces good results. Authority controls limit the damage when it does not. Both matter because legal work combines confidential information, fiduciary duties, deadlines, and actions that can affect rights and money.

I am not arguing that law firms should wait for perfect AI. I help organizations adopt AI for a living, and I want useful systems deployed faster.

In The Psychology of AI Adoption at Work, I explain why clear rules and credible safeguards increase trust. Lawyers are more likely to delegate real work when they know exactly where the agent must stop.

Independent evaluation should become stricter as authority expands. A tool that summarizes a deposition should face a different testing burden from an agent that can send a client communication, change a case record, or trigger a filing.

Frontier AI companies are also making stronger commitments around evaluation, cybersecurity, and incident reporting. Law firms should translate those general safety ideas into matter-level permission architecture.

If future systems can discover vulnerabilities, obtain credentials, coordinate, and work around controls, broad access to courts, financial systems, communications networks, healthcare infrastructure, or defense systems could create consequences far beyond a bad legal draft. The legal profession already understands that power requires authorization. AI agents should be no exception.

The most useful question for legal AI procurement is therefore not only, “How capable is the agent?” It is, “What can this agent do without asking us again?” A good answer should be narrow, explicit, auditable, and easy to revoke.

Glebtsipursky

Gleb Tsipursky, PhD, a behavioral scientist, CEO of Disaster Avoidance Experts, and author of The Psychology of AI Adoption at Work: From Resistance to Results (Georgetown University Press, 2026). https://disasteravoidanceexperts.com/aibook

Contact: gleb@disasteravoidanceexperts.com | https://disasteravoidanceexperts.com

Leave a Comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Scroll to Top