ooligo
STACK

Law firm AI governance stack — ethical walls, citation checks, and the certificate you sign

Deploying legal AI inside an AmLaw or mid-size firm under conflicts, ethical-wall, and court-certification obligations rather than on the honor system.

Difficulty
advanced
Tools
4
Legal Ops

The stack

When Judge Brantley Starr of the Northern District of Texas issued the first standing order on generative AI in 2023, he listed the tools it covered: ChatGPT, Bard, and Harvey.ai. A federal judge named a legal-specific AI product in a certification requirement three years ago, and most firms deploying that product today still cannot answer two questions about it — who inside the firm can see which matter through it, and who checked the citations before the brief went out.

That is the gap this stack closes. It is four layers, and only three of them are software.

The shape: Intapp Walls for AI is the control plane that decides who may see what, Harvey is the work surface that produces the draft, LexisNexis Shepard’s — reachable inside Harvey through Protégé — is the citation-verification layer, and a written AI-use policy plus a certification runbook is the layer that makes the other three defensible in front of a tribunal.

How the pieces fit

  • Intapp Walls for AI is the control plane, and it enforces rather than duplicates. Intapp announced the Harvey partnership on February 23, 2026; the integration reached general availability by July 23, 2026 after an early-access period. When a wall is created or updated in Intapp Walls for AI, Harvey syncs it automatically across Threads, Vault, Review Tables, Shared Spaces, Workflows, and Playbooks. The design point that matters: Harvey inherits the wall from the source system rather than recreating it in a second console. A wall maintained in two places is a wall that drifts. More than 70 of the Am Law 100 already run Intapp Walls, and the same product governs Microsoft Copilot and Intapp’s own Celeste agent — so the control plane is not Harvey-specific even though this integration is.

  • Harvey is the work surface, and it is where the filing actually gets written. By June 2026 Harvey passed $300M ARR across 1,300-plus organizations, with an $11B valuation set in March 2026. Volume is the reason governance is urgent rather than optional: the more drafting moves into one assistant, the more a single misconfigured permission becomes a firm-wide exposure instead of one lawyer’s mistake.

  • Shepard’s is the citation-verification layer. The LexisNexis alliance announced June 18, 2025 puts LexisNexis primary law inside Harvey — customers can select the Protégé service and get answers grounded in US case law and statutes with citations validated through Shepard’s, which flags whether a case has been overruled, criticized, or followed. This is the only layer in the stack that addresses the failure mode judges are actually sanctioning.

  • The written policy is a component, not paperwork. ABA Formal Opinion 512, issued July 29, 2024, creates no new rules — it maps the existing Model Rules onto generative AI: competence, confidentiality under Rule 1.6, client communication, candor toward the tribunal, supervisory duties over both lawyers and non-lawyers, and reasonable fees. Every one of those maps to a control in the three layers above. A firm that buys the software without writing the policy has bought the ability to demonstrate nothing.

Named handoffs

  1. Matter walled in Intapp → Harvey enforcement. Wall created or updated in Intapp Walls for AI → automatic sync → the walled matter stops appearing in that user’s Threads, Vault, Review Tables, and Shared Spaces. Access is blocked by the system, not by the lawyer remembering they are screened.
  2. Research question in Harvey → Shepard’s-validated answer. The question routes to Ask LexisNexis → answer returns grounded in Lexis primary law with Shepard’s treatment attached → the lawyer sees the citation status before the cite reaches the brief, not after opposing counsel finds it.
  3. Draft leaves Harvey → the human verification pass. A named person checks every citation and quotation against the source, then the signing attorney files the certificate the judge’s standing order requires. This handoff has no automation and no vendor.
  4. Enforcement event → two logs, one record. Intapp Walls for AI records the wall configuration and its policy source; Harvey records every sync cycle, access attempt, and enforcement action. When a wall is challenged, that pair is the evidence — configuration on one side, behavior on the other.

The upload gap nobody diagrams

Harvey and Legora both have direct iManage integrations, and both respect iManage permissions and ethical walls at the point of upload. What almost nobody carries through to the next sentence: once content is inside Harvey or Legora, it sits under that platform’s own governance, and retention and deletion fall to whoever configured them there.

So the honest picture is that the DMS wall was never enforced continuously — it was enforced once, on the way in. Intapp Walls for AI closes the access half of that gap by making the wall live inside Harvey. It does not close the retention half. If a client’s outside counsel guidelines require consent before their data enters a generative AI tool and the ability to delete that data permanently, you still need an answer to “which of this client’s content is currently in Harvey Vault,” and no ethical-wall product produces it.

Guard: write a retention rule for the AI platform on the day you turn the connector on, and treat “what client data is in the AI tool” as a question the firm must be able to answer within a business day. Both belong in the policy document, because neither belongs to a vendor.

The certificate is signed by a person

Starr’s order gave attorneys two options: certify that no part of a filing was drafted by generative AI, or certify that any AI-drafted language was checked for accuracy by a human being. Courts from Oklahoma to Pennsylvania modeled their requirements on it. There is still no uniform federal standard — orders are issued judge by judge, and they vary on whether they demand disclosure of use, identification of the tool, or certification that every citation was human-verified.

The sanctions are no longer theoretical, and they are not small:

  • District of Oregon. Magistrate Judge Mark D. Clarke’s December 12, 2025 opinion imposed $110,000 over 15 references to nonexistent cases and 8 fabricated quotations — $80,000 in fees plus roughly $15,000 in fines against one lawyer, $14,000 in additional fees against the other. The judge called it a notorious outlier in both degree and volume.
  • Sixth Circuit. $30,000 against two attorneys for more than two dozen fake citations, with the case dismissed.
  • Southern District of Ohio. $7,500 against two attorneys, with contempt findings and a disciplinary referral attached.
  • Fifth Circuit. $2,500 against an attorney who used vLex and Thomson Reuters CoCounsel.

Read that last one twice. The lawyer was not pasting from a consumer chatbot — they were using paid, grounded, legal-specific research AI, and the citations were still sanctionable. By May 2026, Damien Charlotin’s tracker of court decisions commenting on AI-generated hallucinations held more than 1,300 entries globally.

Guard: budget the verification pass as billable, staffed time. Every stack that treats citation-checking as a residual activity someone does at the end produces the Fifth Circuit outcome eventually. See legal AI grounding vs hallucination for why grounding reduces the rate without reaching zero.

Cost reality

Intapp. No published rate card; Walls is quoted. The line item buyers miss: the Harvey integration requires an Intapp Walls for AI cloud licence plus a separate Harvey connector licence. Two SKUs, not one, and the second one is easy to leave out of a budget built from the first quote.

Harvey. No published price. Third-party reporting — not vendor-published, and it should be treated as a negotiating band rather than a number — puts mid-market firms near $1,000 to $2,000 per seat per month, with 25-to-50-seat minimums and annual contracts commonly in the $50K to $300K range.

LexisNexis. Entitlement-based. Ask LexisNexis rides a Lexis subscription; neither party publishes an incremental price for the Harvey route.

The policy. No licence cost, and the largest internal time cost in the stack — drafting, partner sign-off, attestation tracking, and the recurring verification hours that no software absorbs.

At 50 Harvey seats on the reported mid-market band, the assistant alone runs roughly $600K to $1.2M a year. The governance licences are a small fraction of that, and they are the fraction that determines whether the rest survives a wall challenge or a sanctions motion. Governance is not where this stack is expensive.

Common variations

  • Swap Harvey for Legora. Take it when Word-native drafting is the real requirement, or when Harvey’s floor will not clear — Legora publishes a $250 entry point and reached a $5.6B valuation in 2026 on the strength of drafting inside the document. What you give up is the spine of this stack: Intapp’s published Walls for AI integration list covers Copilot, Harvey, and Celeste, and Legora’s own security page describes zero-trust access control, SSO, ISO 42001, ISO 27001, SOC 2 Type 2, EU or US residency, and data-governance visibility — with no mention of ethical walls or an Intapp integration. Choose Legora on drafting merit and accept that the wall reverts to upload-time DMS enforcement plus workspace discipline.

  • Govern Copilot instead of a legal assistant. Take it when the firm’s AI use is general knowledge work over Microsoft 365 rather than legal work product. Walls for AI already covers Copilot and controls which sources it reaches through Microsoft Graph. What you give up is the grounded-research route and the Shepard’s validation, which means the citation layer disappears entirely.

  • Add a DMS-side policy layer. iManage Security Policy Manager or NetDocuments ethical walls, when the wall has to hold against humans browsing the DMS and not only against the AI. Take it when the firm’s screening obligations predate the AI deployment, which is most firms.

What this stack does NOT replace

  • Conflicts clearance. Walls enforce a screening decision; they do not make it. See conflicts checking for the analysis that produces the wall in the first place.
  • The verification pass. No component of this stack signs a certificate or reads a case. The lawyer does.
  • Your AI use policy. ABA 512 maps duties; it does not write your document. See AI policy for legal teams.
  • Client consent and outside counsel guidelines. Increasingly clients require consent before their data enters a generative AI tool and deletion on demand. That is a contract obligation, tracked outside the AI platform.
  • Retention inside the AI platform. Access control and retention are different problems, and this stack solves one of them.
  • EU obligations. Firms practising in the EU carry a separate compliance surface. See the EU AI Act for legal teams.

Match rules

Use this stack when:

  • Intapp Walls is already deployed. The Harvey integration is a connector decision on top of an existing control plane, not a reason to buy one.
  • The firm files in federal court. The certification requirement is what converts governance from good practice into exposure management.
  • You run matters where a wall failure is a client-relationship event — competing bidders, adverse parties in the same industry, lateral hires under screening.
  • Someone owns the connector configuration. A sync that stops syncing produces a wall that exists in one system and not the other, and neither console flags the divergence for you.

Do not use this stack when:

  • Walls is not deployed and would be bought only for this. Buy the ethical-wall product for the conflicts and screening obligation it serves firm-wide, then connect it. In the other order you are paying enterprise governance pricing to solve one vendor’s permissions.
  • The firm is small enough that screening is handled by everyone knowing every matter. Below that threshold the audit trail costs more than it protects.
  • The AI work is transactional and never gets filed. Drafting and diligence carry confidentiality duties, but the certification layer is answering a litigation problem.
  • Nobody will own the verification pass. Without a named person and staffed hours, the Shepard’s layer is a feature the firm paid for and did not use.