How to Choose Your LegalTech Tools at the Age of AI Washing

When every LegalTech provider describes its product as AI-powered, how can a legal team tell which claims describe a dependable tool and which ones point to AI washing?

AI washing means overstating what an AI system can do. A vendor might claim a level of accuracy that exists only in controlled tests, describe assisted work as fully automated, or attach the AI label to features that rely mainly on rules or keyword matching. As regulators in the United States and Europe pay closer attention to inaccurate AI claims, legal teams and general counsels need a practical way to assess them.

Legal has a dual role here. It buys legal technology in a market where AI claims can run ahead of product performance, and it advises the business on whether its own statements about AI can be supported. The practical question is clear: how can legal teams choose technology they can trust and support that decision with evidence?

What AI washing looks like in practice

AI washing becomes easier to spot when legal teams know the forms it can take. Common claims made about LegalTech tools include:

  • Inflating accuracy: A vendor presents a high accuracy rate without explaining the test conditions, document set, jurisdiction, or margin of error.
  • Overstating automation: A product is described as autonomous even though lawyers must review, correct, or approve its output at key stages.
  • Hiding coverage gaps: A tool claims to monitor a regulatory area or jurisdiction even though its sources are limited, outdated, or incomplete.
  • Using AI as a label: A feature is marketed as AI-powered when it relies mainly on fixed rules, keyword matching, or document retrieval.
  • Relying on irrelevant benchmarks: A vendor cites results from tests that do not resemble the organization’s documents, languages, workflows, or risk profile.

These claims can sound convincing in a demonstration. The harder part is testing whether they hold in the work the legal team actually does.

AI washing creates a delay between the sales claim and the moment when the organization discovers the product’s limits. By then, the tool may already sit inside a high-volume or high-risk process and cause harm to the business. The risks vary according to the use case:

Legal use caseAI washing riskPossible consequence
Contract reviewNear-perfect accuracy is claimed without test conditionsMissed clause, renegotiation, or liability exposure
Regulatory monitoringCoverage and update cycles are unclearMissed development, filing error, fine, or remediation
Legal researchCitations cannot be traced or checkedFabricated authority reaches a memo or filing
Document processingData residency and access controls are vagueConfidentiality concern, privilege issue, or regulatory breach

AI washing has real consequences, and regulators are taking a closer look at claims about AI. The SEC’s action against Delphia and Global Predictions shows how existing rules can apply to misleading AI statements. In 2024, the two investment advisers agreed to pay $400,000 in civil penalties after the SEC found that they had made false and misleading statements about their use of AI.

In the European Union, the European Commission’s guidance on the EU AI Act confirms that Article 50 transparency obligations have applied since 2 August 2026 to certain AI systems, including some systems that interact with people or generate content.

The lesson for legal teams is practical. Claims about an AI product need to be tested against the work, the data, and the obligations attached to that work.

Legal often has to assess the technology it buys while reviewing the claims the business makes about AI more broadly.

As a technology buyer, the legal team evaluates products for contract analysis, due diligence, board management, document generation, matter review, and entity management. A vague promise of automation can conceal a product that requires more review than expected, works only with certain documents, or lacks coverage in the jurisdictions the business needs.

As a business advisor, the GC and legal team review statements about the company’s AI in filings, marketing material, client proposals, and sales conversations. Each statement needs to reflect what the technology does in practice. This is where AI governance matters for both the vendor and the end user. As key business partners, the GC and legal function help ensure that the technology follows the organization’s governance rules.

The questions asked during procurement should give the GC evidence to support, qualify, or challenge an AI-related statement later. Once AI-powered tools or features are involved, vendor evaluation becomes part of AI governance.

How to spot a trustworthy vendor

A product presentation gives you a starting point, but the real assessment begins when the legal team asks how the product behaves in its own environment.

Start by testing the product’s boundaries.

What does the AI actually do, and where does it stop?

Ask the vendor to explain:

  • Which tasks the system automates and which tasks it supports
  • How performance was tested, including the documents, languages, and jurisdictions used
  • What happens when the system is uncertain or produces an incorrect result
  • Which decisions require human review or approval
  • How the product fits into the team’s risk thresholds and approval workflows

A credible provider should explain how its capabilities fit into the legal team’s processes without overstating accuracy or reach. The provider should also be able to explain the tool’s limitations and when human intervention may be required.

Once the organization understands a product’s limits and capabilities, the legal function can turn to data privacy and data management.

Where does the data go, and who controls it?

Data quality is partly an internal issue because the legal team and the business understand how complete, clean, and reliable their data is. The service provider still needs to answer specific questions about data management, including:

  1. Where is the data processed and stored?
  2. Who can access it, including service providers and subprocessors?
  3. Is customer data used to train or improve a shared model?

Sovereign AI matters because it keeps data processing and AI operations within defined organizational and jurisdictional controls. The underlying model may involve third-party technology, but the vendor should explain who controls the data, where processing takes place, how access is managed, and whether customer data is used to train shared models. DiliTrust’s guide to private AI for legal teams provides a useful reference for this assessment.

DiliTrust’s AI Readiness Blueprint for General Counsel also provides a broader framework for connecting AI adoption with legal controls and business priorities.

A provider that cannot document its data flows, model-training practices, access controls, and security measures should not process sensitive legal material until those gaps are resolved.

The final test concerns how the provider responds when the system falls short.

What happens when the tool gets something wrong?

Ask how the product:

  • Traces an answer back to source material
  • Records user actions and corrections
  • Distinguishes source-based answers from generated suggestions
  • Alerts users when information is missing or uncertain
  • Supports the correction or removal of an inaccurate result

Legal AI hallucinations can create serious problems when a fabricated precedent or inaccurate clause summary reaches a decision-maker. Data quality affects the result, but the provider still needs to explain how outputs are produced and checked. A legal team cannot stand behind work it cannot verify.

These questions assess the vendor from the outside. The GC also needs an internal process for tracking what the provider has claimed and whether those claims remain accurate.

What the GC needs to own in this process

The GC’s role is to connect the technology the organization uses with its legal, regulatory, contractual, and disclosure responsibilities.

That usually means owning 3 controls:

  1. A record of AI claims. Keep the vendor’s claims, test conditions, known limitations, and approved uses in one place so legal, procurement, marketing, and security teams work from the same reference.
  2. A review when the product changes. New models, features, subprocessors, or data practices can alter the risk profile. Revisit external descriptions when the product or its use changes, and confirm that the provider communicates material updates.
  3. A link to the AI Code of Conduct. The organization’s AI Code of Conduct should lead to practical questions about the tools people use, the data they process, and the human checks that remain in place.

This process gives the legal team a record of why a tool was selected, how it is used, and where its limits sit. It also makes the vendor relationship easier to manage when the product or the organization’s needs change.

Choosing a partner means reviewing its governance

A LegalTech provider becomes part of the legal team’s working environment. Its product decisions affect the quality of legal work, its data practices affect the organization’s exposure, and its handling of errors affects how quickly the team can respond.

Before selecting a vendor, ask whether it can provide:

  • Clear documentation of the system’s architecture, data flows, and known limits
  • Education for users on how to interpret and check outputs
  • Notice when a model, feature, subprocessor, or data practice changes
  • A defined process for reporting errors and managing incidents
  • Evidence of human review and internal responsibility for its own AI governance

A provider asking customers to rely on its AI should explain how it tests the system, manages change, handles incidents, and keeps its claims current. Those answers show whether the vendor understands the standard it is asking legal teams to meet.

The choice of technology is also a governance decision. It affects the work the legal team can stand behind, the data the organization can keep under control, and the claims it can make about AI in public. In a market where AI washing can create regulatory, contractual, and reputational exposure, a long-term partner earns trust through clear evidence, useful education, and candid answers about where human judgment remains necessary.

What evidence should a legal team request before buying an AI LegalTech tool?

Ask for test methodology, performance results on comparable documents, known limitations, data-flow diagrams, model-training terms, access controls, and human-review requirements. A live pilot using representative, anonymized work can show whether the vendor’s claims hold in your environment before the tool reaches a critical workflow.

How can legal teams check whether a vendor uses customer data to train its AI models?

Request a written answer covering model training, service providers, data retention, deletion, and product improvement. The commitment should appear in the contract or data-processing documentation, rather than only in a sales presentation. Review it again if the vendor changes its model or subprocessors.

Does the EU AI Act make inaccurate AI marketing claims illegal?

The answer depends on the claim, the system, and the organization’s role. Article 50 creates transparency duties for certain AI systems which have applied since 2 August 2026, while inaccurate claims may also create exposure under consumer-protection, securities, or contractual rules. Legal teams should assess the specific use and statement together.

Ana Aguirre
Author

Ana Aguirre

Content Marketing Manager at DiliTrust

Ana Aguirre is Content Marketing Manager at DiliTrust, with over 7 years of experience creating content across tech and SaaS. She's passionate about Legal Tech, following how the regulatory environment, including topics like CSRD, is reshaping legal teams' ways of working and technology choices. Ana is especially focused on how AI is transforming the legal function, from daily workflows to what's coming next for legal teams.