AT&T announced this week that it is integrating OpenAI's AI chatbots and agents into LegalEdge, its internal legal function, to reduce reliance on external counsel. The story matters to UK mid-market law firms, insurers, and financial services companies because it signals what every large corporate is now thinking: why pay external lawyers when AI can do the work faster and cheaper? The question is entirely reasonable. The answer, for regulated firms in the UK, is more complicated than AT&T's model allows. The SRA Code of Conduct for Solicitors (2019) and FCA Consumer Duty (PS22/9) both impose personal accountability on the individuals who oversee legal advice. When an AI agent generates legal work product, and a lawyer signs off on it without genuine review, that lawyer owns the output. AT&T's scale allows it to absorb reputational risk. UK regulated firms cannot.
This is not the first time we have seen this pattern. Harvey, Luminance, and Legora all built legal AI products around the assumption that automation plus speed equals transformation. What we are seeing instead is a market split into two camps: large enterprises like AT&T that can afford to treat AI as a high-risk, high-reward experiment with their own counsel; and regulated mid-market firms that face regulatory consequences if an AI-generated contract template contains a hidden liability or if a compliance opinion fails under FCA Consumer Duty scrutiny. The EU AI Act (Article 6) classifies legal advice generation as high-risk. The ICO's UK GDPR guidance on AI processing makes clear that regulated firms cannot delegate accountability to a vendor. AT&T's move is intellectually honest about what it is doing: it is accepting risk in exchange for operational efficiency. Most UK firms copying this approach will not have made that choice consciously. They will have simply bought the tool and hoped.
Here is Trovix's view: in-house legal transformation using AI does not fail because the technology is weak. It fails because firms implement it without first mapping what actually needs to remain human-controlled. At Trovix, we have spent three years watching firms integrate AI into legal operations, and the winning approach is not faster automation—it is disciplined governance. That means documenting which decisions require human judgment (regulatory sign-off, matters involving novel legal questions, high-value transactions), which can be augmented by AI (contract assembly, regulatory change tracking, precedent analysis), and which can be fully automated (intake, triage, basic document production). Harvey treats all legal work as automatable. Microsoft Copilot treats all legal work as assistable. Neither approach separates what must remain inside the practitioner's professional liability circle from what can sit outside it. Trovix Audit was built on this principle—it maps which parts of your AI workflow create regulatory risk and which do not, and it generates the evidence trail that the SRA and FCA actually want to see. AT&T has no such framework. Its lawyers will find that out when the first mistake costs someone money.
If you run a mid-market law firm, accountancy practice, insurer, or financial services company, the move now is not to follow AT&T. It is to ask yourself three questions. One: which parts of my legal or compliance operations are actually bottlenecked by human time rather than by judgment? Two: for those parts, can I automate them without creating regulatory risk under SRA Code, FCA Consumer Duty, PRA SS1/23, or the ICO's AI guidance? Three: do I have governance in place to prove that answer to a regulator? Most firms answer no to all three. That is not a technology problem. It is a strategy problem. Trovix Brief and Trovix Watch exist precisely because the honest answer is that you need to measure before you automate. Start there.
Source: Crypto Briefing