Here’s the short version, because you shouldn’t have to scroll to get it: paralegals can use firm-approved AI for paralegals tools to organize redacted case materials, build chronologies, extract fields from documents, draft issue lists, prepare questions for the supervising attorney, structure discovery logs, check citations before anyone relies on them, summarize transcripts, and draft routine correspondence that a lawyer will still review. What AI cannot do is give legal advice, decide strategy, verify legal authority on its own, sign or file anything, communicate a firm’s final position to a client or court, or step around attorney supervision and the court’s own rules. That line matters more than any feature list a vendor hands you, and everything below is really just an explanation of how to work right up to it without crossing it.
What paralegals may delegate to AI–and what they may not
Every paralegal I’ve talked to about this eventually asks the same question in a slightly different way: “Okay, but where’s the actual line?” Fair question. There isn’t one universal answer, because it depends on your jurisdiction, your firm’s policy, and the specific matter – but this is really the core question behind any generative AI for paralegals policy, and a delegation matrix gives you a working starting point that most compliance-minded legal ops teams reach for first.
Think of it in three colors.
Green means routine, low-risk, and typically fine with supervision: organizing already-redacted or fictional materials into a chronology, drafting a research plan outline, generating a first-pass issue list from a public transcript, or building an exhibit index template.
Yellow means proceed only with explicit matter authorization, a controlled environment, and attorney sign-off before anything leaves the draft stage: summarizing real client documents inside an approved, access-controlled platform, drafting client-facing language that a lawyer will edit, or running citation checks that still require independent verification.
Red means don’t, full stop, no matter how good the tool’s marketing looks: unsupervised legal conclusions, filing anything without attorney review, sharing privileged material with a public or unapproved tool, giving a client legal advice framed as AI output, or presenting an AI summary as a verified fact in a pleading.
| Area | Green | Yellow | Red |
|---|---|---|---|
| Confidentiality | Public/fictional data in any approved tool | Client data in an approved, access-controlled environment only | Client or privileged data in a public/unapproved tool |
| Privilege | Drafting privilege log templates | AI-assisted privilege review with attorney spot-check | AI determining privilege status unsupervised |
| Competence | Using AI as a drafting aid you understand | Using a new AI feature after firm training | Relying on AI output without understanding its limits |
| Supervision | Any task under a named supervising attorney | Novel task types pending policy update | Any task with no attorney oversight |
| Candor | Drafting talking points for attorney review | AI-assisted brief sections, attorney-verified | Submitting AI text/citations unverified to a tribunal |
| Filing rules | Formatting checks against public court rules | Court-specific formatting under attorney sign-off | Filing without attorney authorization |
| Client communication | Internal drafts, never sent | Attorney-reviewed client emails | AI sending or finalizing client communication |
| Unauthorized practice | Research organization, no advice given | Attorney reviews all client-facing legal conclusions | AI (or paralegal via AI) giving legal advice |
Nothing here is legal advice, and none of it substitutes for your firm’s own policy or your jurisdiction’s ethics rules – the ABA’s Formal Opinion 512 on generative AI, for instance, is a widely cited framework, but it isn’t binding law everywhere, and several state bars have gone further than the ABA in their own guidance. Check what applies to you before you build a workflow around any of this.
A supervised legal-support workflow
Matrices are useful, but they don’t tell you when to check something – they tell you what to check. So here’s the actual sequence, the one that should run underneath basically every use of AI in paralegal work, no matter what the task looks like on the surface.
| Step | Input | Output | Reviewer | Main risk |
|---|---|---|---|---|
| 1. Matter authorization | Case assignment | Confirmed scope, permitted tools | Supervising attorney | Working outside authorized scope |
| 2. Data classification | Case documents | Public / redacted / confidential / privileged tag | Paralegal + attorney | Misclassifying sensitive material |
| 3. Approved environment | Firm’s AI policy | Confirmed tool + access tier | IT / compliance | Using an unapproved tool |
| 4. Minimum necessary inputs | Classified documents | Redacted or fictional working set | Paralegal | Feeding more data than the task needs |
| 5. AI draft | Prompt + inputs | Draft chronology, list, or summary | Paralegal | Treating draft as fact |
| 6. Source verification | AI citations/claims | Independently opened primary sources | Paralegal | Unverified citation reaches a filing |
| 7. Privilege/confidentiality review | Draft output | Cleared or flagged draft | Attorney | Privileged material slipping into a shared draft |
| 8. Attorney review | Cleared draft | Approved or revised content | Supervising attorney | Skipping substantive review |
| 9. Filing/client approval | Approved content | Final filed or sent document | Attorney of record | AI content reaching a court or client unreviewed |
| 10. Record retention | Full workflow trail | Retained audit record | Firm records/compliance | No record of who approved what |
A few things about this list that are easy to gloss over. Step 4 – minimum necessary inputs – is the one paralegals skip most often, usually just because it’s faster to paste the whole file. It also happens to be where most confidentiality incidents start. And step 6 isn’t optional busywork; an AI tool can produce a citation that reads perfectly and points to a case that doesn’t say what it claims, or doesn’t exist at all. That’s not a hypothetical – it’s shown up in reported court sanctions more than once.
10 safe prompts for paralegal workflows
These are some of the more reliable prompts we’ve seen work across different AI tools for paralegals, written around fictional or redacted materials on purpose. None of them ask the model for a legal conclusion, and each should still go through the review chain above before anything leaves your desk.
- Chronology builder: “Using this redacted timeline of events [insert redacted facts], organize them into a chronological table with date, event, and source document reference. Flag any date that’s ambiguous or missing.”
- Transcript issue list: “Identify the topics discussed, in order, from this fictional deposition transcript excerpt. Do not evaluate the credibility of the witness or draw any legal conclusions.”
- Discovery tracker: “Create a discovery request tracker template with columns for request number, description, response due date, and status – no content populated yet.”
- Exhibit index: “Create an exhibit index template with columns for exhibit number, description, Bates range, and admitted status.”
- Research plan: “Write an outline of a research plan for [general legal topic] listing likely categories of primary source to check – statutes, regulations, and case law – without stating what the law says.”
- Citation audit checklist: “Generate a checklist for verifying a legal citation, covering jurisdiction, current validity, and pin cite accuracy.”
- Handoff memo: “Draft a neutral handoff memo template summarizing task status for the next paralegal on this fictional matter, with a section for open questions to the attorney.”
- Redacted document summary: “Summarize this redacted document’s structure and section headings only, not its substantive content.”
- Attorney question list: “Based on this redacted fact pattern, draft a list of clarifying questions a paralegal might ask the supervising attorney – do not answer them.”
- Vendor comparison table: “Create a blank comparison table template for evaluating legal AI tools, with columns for confidentiality terms, data retention, and audit logging.”
Notice what’s missing from that list: nothing here says “tell me if this argument would win” or “what should we file.” That’s deliberate – the model isn’t your co-counsel, and treating it like one is exactly the unauthorized-practice risk the matrix above flags in red.
Legal research and citation verification
This is the part of the job where AI’s fluency actually works against you. A generated citation can look completely correct – right case name, right-sounding court, plausible year – and still be wrong or fabricated. So the standard has to be mechanical, not a gut check.
Before anyone relies on an AI-suggested citation, require: primary authority (not a summary of a summary), the actual jurisdiction, the date, whether there’s subsequent history that changes its weight, the exact quoted language pulled from the source itself, a pin cite to the specific page, and a signature from the reviewing attorney confirming all of that. An AI citation is a lead, nothing more, until someone independently opens the source and checks it line by line. That’s not paranoia – it’s the same standard you’d apply to a citation handed to you by a first-year who you haven’t worked with yet.
Discovery, privilege, and case-file risks
Discovery work is where confidentiality risk and volume collide, which is exactly why it’s worth slowing down here rather than speeding up.
Protective orders and client engagement terms often restrict where case data can even be processed, sometimes down to which specific tool or server region is permitted – and that restriction doesn’t disappear just because chatgpt for paralegals is the fastest option sitting open in another browser tab. Metadata is its own quiet risk too: a document scrubbed of visible content can still carry author names, edit histories, or comments in the file properties, and an AI tool ingesting the raw file may see all of it. Privilege and work-product protection can be waived by disclosure to the wrong party or the wrong system, ethical screens exist specifically to prevent that kind of cross-contamination on conflicted matters, and none of this is something a paralegal should assess alone – it’s a judgment call that belongs with the supervising attorney and, often, firm compliance. Vendor review matters here too: what does the client’s engagement letter actually permit, and has the specific AI tool been reviewed against it? This isn’t a jurisdiction-specific rulebook – your firm’s actual policy and your client’s actual terms are the source of truth, not this article.
How to evaluate AI tools for a legal team
Once a firm decides to formally adopt AI for legal assistants and paralegals, the evaluation questions look less like a product demo checklist and more like a due-diligence file.
Confidentiality terms need reading in full, not just skimming the summary page: where is data located and how long is it retained, is it used to train the vendor’s models, and can that be contractually turned off. Matter-level access controls matter almost as much – can access be restricted to specific matters and staff, are there ethical-screen features for conflicts, is there an audit log showing who did what and when, does the tool support checking citations against real sources rather than just generating text that resembles one, how does it integrate with existing case management and document systems, can data be exported cleanly if the firm switches tools later, is deletion actually verifiable, and what’s the vendor’s incident-response process if something goes wrong. If a vendor can’t answer these plainly, that’s information too – and it’s exactly the kind of gap that separates genuinely vetted paralegal AI tools from ones that just look polished in a sales call.
If your firm is separately building AI literacy across departments, the fundamentals overlap a lot with general workplace AI training – AI training for employees covers that broader ground, and firm-wide AI governance questions are covered in more depth in this AI governance course overview, both worth a look before a legal team writes its own policy from scratch.
What an AI for paralegals course should teach
A paralegal AI course that’s actually useful for this role – as opposed to a generic AI 101 with “legal” pasted into the title – needs to cover: the real limits of what generative AI can and can’t reliably do, confidentiality and data-handling basics, how to independently verify legal research rather than trust it, discovery and case-file workflows end to end, prompt construction for the kinds of tasks in the list above, what supervision actually requires in practice, how to check work against court-specific formatting and filing rules, how to evaluate a vendor tool before it touches real matters, and – this is the part that separates a course from a slide deck – a capstone built entirely around a fictional matter, so nobody’s practicing new habits on live client data.
If prompt-writing itself is new to you, what is prompt engineering is a reasonable primer before diving into anything legal-specific, since the underlying skill transfers across every one of the ten prompts above.
A 30-day paralegal AI pilot
If your firm hasn’t formally adopted anything yet, don’t start with a live matter. Start smaller than that feels comfortable.
- Scope it narrow. Pick one task – a redacted chronology exercise or a public-authority citation check – and explicitly exclude anything touching client advice or actual filings. Name a supervising attorney for the pilot, define exactly what data is permitted (fictional or fully redacted only), and set a small test set rather than rolling it out firm-wide on day one.
- Track it and know when to stop. Keep a review log of every output and every correction an attorney had to make. Set stop conditions in advance – for example, more than one unverifiable citation, or any instance of the tool being fed data outside the permitted set – pauses the pilot immediately, no exceptions. At day 30, make an actual decision: expand, adjust, or discontinue, based on what the log actually shows, not on how convenient the tool felt.
Thirty days sounds short, but it’s usually enough to surface whether a tool’s real-world behavior matches its marketing – and it’s a lot cheaper to find that out on a fictional matter than on a live one.
Final recommendation
If you’re a paralegal or a legal-support manager trying to figure out where to actually begin, start with the delegation matrix and the workflow table above, run a narrow 30-day pilot on non-client material, and don’t touch anything beyond that until a supervising attorney has signed off on the results. The one decision that never moves to a machine, in any of this, is professional judgment about a client’s matter – that stays with a licensed attorney, every time, no exceptions for convenience or deadline pressure.
Coursiv’s AI for Paralegals course, in that context, is best understood as structured, supervised practice – a way to build habits around research organization, discovery, case-file work, citation checking, and review workflows – not as legal education that authorizes the practice of law, not legal advice, and not a professional credential. It awards a certificate of completion, not a license or a bar-recognized designation, and like any course, what you get out of it depends on how it’s applied afterward under real supervision. If your firm is also weighing broader AI adoption questions – what’s actually worth adopting across the business, not just in legal – best AI tools for business is a reasonable next read, and if you work alongside attorneys who are evaluating their own AI use, chatgpt for lawyers and will AI replace lawyers cover that side of the same question without overlapping what’s written here.