
You already know AI can fabricate a citation and get you sanctioned. Here's the part nobody's warned you about: the instructions you type into an AI review tool may be the next thing opposing counsel demands to see. And a paper published two weeks ago argues you should be structuring your work right now so they can't.

THE LEAD PLAY
Your AI Prompts Are About to Become the Most Fought-Over Text in Your Case
For a year and a half, every AI-in-litigation story in this newsletter has been about output: fabricated cases, hallucinated quotes, the signature that certifies a filing. This one is about input. The instructions your team types into an AI tool to review documents, and whether the other side gets to read them.
On July 1, Tara Emory and Maura Grossman posted a paper to SSRN, forthcoming in the Columbia Science and Technology Law Review, arguing that the prompts attorneys write to run AI-assisted document review are attorney work product and shouldn't be handed across the table like search terms. Grossman isn't a bystander here. She's the court-appointed special master for ESI in the hair relaxer MDL in the Northern District of Illinois, a case that entered a stipulated AI review protocol in April. So this is less an academic position than a preview of the protocol language that's about to start showing up in your matters.
The argument is sharper than it sounds. A keyword is neutral. A well-developed AI review prompt is not. By the time you've tested and refined it against a live document set, it contains your factual investigation, your theory of what proves the claim, and an explicit list of the sensitive material you're trying to filter out. Hand that over and you've handed over a map of your interviews, your theories, and your vulnerabilities. The underlying responsive documents still get produced either way. Disclosing the prompt just tells the other side how you think.
The courts haven't settled this, and it's worth being precise about why. The rulings that protected AI use as work product, Warner (E.D. Mich.), Morgan (D. Colo.), and a July 13 Missouri decision, have something in common: they involved people representing themselves, using consumer tools. Your posture is different, and mostly stronger. Enterprise tool, lawyers directing the work, an active matter. But "stronger argument" and "settled law" aren't the same thing, and the one case closest to how your team actually works, an expert's prompts in Conservation Law Foundation v. Shell, went the other way before it was stayed on objection. That's the whole point. This gets decided matter by matter, and you want your record built before it's yours.
The Play this week: If your firm or department runs any document review through AI, stop treating the prompts as disposable. Three moves, none of which require a lawsuit to be pending. One, develop and refine prompts against the actual review set, not off a template, because refined prompts are the ones that carry protectable work product. Two, preserve the final prompts and your validation scores, so if performance ever gets challenged, a judge can review them in camera instead of your opponent reading them in the open. Three, if you're ever inclined to share prompts voluntarily to settle a dispute, get a Rule 502(d) order first so disclosure doesn't waive protection over everything adjacent. The reader who does this now has a defensible record. The one who doesn't finds out the answer during a motion to compel.
The reflex after every sanctions story has been to check your output. This is the first one that says check what you're feeding in.

SUPPORTING PLAY 1
"One Agent to Rule Them All" Is a Great Pitch. Ask What It Costs You to Leave.
Litera relaunched this week around a single message: one agent, one dataset, spanning both the practice and the business of law. After 30 years and 99% of the Am Law 100, the pitch is that Lito, its AI agent, sits inside Microsoft 365 and Google Workspace across drafting, comparison, contract review, knowledge, and business development, with no separate tool, login, or dataset. Its chief product officer put the real selling point plainly: AI is table stakes, trust is the moat, and you can't pilot your way into the Am Law 100.
To be clear about what this was: a rebrand, not a product launch. Litera's own CEO called it a branding relaunch and a statement of work already done. That's not a knock. The consolidation thesis is genuinely attractive when your attorneys are drowning in eight logins. But "one dataset spanning every corner of the firm" is the exact phrase that should make an operator slow down. A single dataset is a convenience feature and a lock-in mechanism at the same time. The more of your firm's knowledge lives in one vendor's unified layer, the more expensive it is to ever be somewhere else.
The Play this week: The next time a vendor pitches you a unified, single-agent, single-dataset platform, run one test before the demo dazzles anyone: ask what leaving looks like. If you consolidated drafting, knowledge, and client development onto this one agent and wanted to move in three years, what comes with you and in what format? Get the data-portability and export answer in writing before you deepen the integration, not after. Consolidation is a real efficiency. It's also the most effective lock-in a vendor has, and the two arrive in the same sentence.

SUPPORTING PLAY 2
Your Legal AI Vendor Might Be Quietly Deciding You're Not the Priority
On July 16, Harvey acquired Benchmark, a startup that helps investment firms reuse knowledge from past deals. It's Harvey's third acquisition of 2026, and it points the same direction as the other two: away from law firms and toward asset management, where Harvey already works with 50-plus firms including Blue Owl, Bridgewater, and KKR. The company built its name selling AI to lawyers. Its expansion capital is now going somewhere else.
There's nothing wrong with a vendor growing. But watch where the money and the engineers go, because that's where the roadmap goes. When a legal AI company's most-publicized moves are all about an adjacent, higher-margin market, the practice-area features you actually care about aren't the ones getting the next three quarters of attention. That's not a reason to rip anything out. It's a reason to know where you sit in your vendor's priority stack before you renew as if nothing changed.
The Play this week: Pull up your primary legal-AI vendor's last year of announcements, acquisitions, funding, product launches, partnerships, and sort them into two piles: things that made your specific practice area better, and things that expanded the vendor into a new market. If the second pile is winning, ask your account rep a direct question at the next check-in: what's on the roadmap for my workflow in the next two quarters, specifically. A vague answer is the answer. You're not looking to leave. You're looking to not be surprised.
QUICK HITS
A federal appeals court just referred a lawyer for discipline over citations he couldn't explain. The Eleventh Circuit referred an attorney for potential discipline on July 10 in Parnell v. Florida Department of Corrections, after he failed to explain how several defective quotes and citations ended up in his brief. The tell worth noting: the problem wasn't admitting AI use, it was having no account of how the errors got there. "I don't know how that happened" is not a defense that's aging well.
Briefpoint added response governance for the 1,000-plus firms drafting discovery on its platform. Its new Discovery Playbooks (July 14) let firms standardize how discovery responses get drafted. Relevant if you've been meaning to make your discovery-response process consistent instead of associate-by-associate, and doubly so given this issue's Lead.
The EU AI Act's enforcement teeth activate August 2. Roughly two weeks out, the Commission's power to investigate and fine general-purpose AI model providers goes live, with penalties up to 3% of global turnover. This lands on the model makers, not on you, but if a tool in your stack touches EU work, it's a fair question to put to the vendor now: are you covered.
92% of in-house teams expect AI rate cuts from outside counsel. Few are getting them. Axiom's survey (July 9) puts a number on the gap we've flagged before. If you're firm-side and can't say what AI has changed about your delivery, you're the reason that number holds. If you're in-house, that's your leverage at the next rate conversation.
Descrybe put verified legal research inside ChatGPT. Worth a look if your attorneys are already living in a general chatbot and you'd rather point them at something with a citation layer than fight the tide.
The pattern this week: the risk keeps moving one step earlier in the process. First it was the filing, now it's the prompt behind it. Preserve what you feed the machine. See you in the next one.