Legal AI Insights & Contract Operations Blog | Execo

Agentic AI in Legal: Draw the Line Before the Default Does

Written by Eunice Tan | Sep 4, 2026, 5:05:47 PM

'Agentic' has been a hot term this year. Yet it seems like almost no two people using it mean the same thing. For one person it is a faster research assistant. For the next it is software that goes off and does the thing on its own. Same word, two very different promises.

So let's set the label aside for a moment. From a GC’s standpoint, the question that matters is not whether a tool counts as agentic, but if the tool still hands the work back for you to act on, or whether it acts on its own.

With everything we have today, that question has a clearer answer than the noise around it suggests, which is precisely why now is the time to get specific about it.

What "agentic" actually means

The idea underneath the word is straightforward, even when the marketing around it sometimes isn’t.

Let’s start with the simplest one. A basic tool responds to a prompt and stops. You ask, it answers, it waits for you. Anything "agentic" goes further than that: it takes a goal and works toward it across multiple steps, deciding things along the way, like which sources to pull and in what order, rather than waiting for you at every turn.

The catch is that "agentic" is an umbrella. It covers a wide span of capability, and two things sitting under the same word can be a long way apart. That's the reason no two people mean the same thing by it.

For deciding what a tool is allowed to do without you, it helps to use a simpler distinction than the market’s terminology: a human-approved agentic workflow and an externally acting autonomous agent. The first may plan, reason and execute multiple internal steps, but it stops before an external action until a person approves it. The second is authorised to take that action within defined limits without case-by-case human approval. One returns the work for you to act on. The other acts on its own.

The line that matters: does it wait for you, or act on its own?

Here's the distinction I observe. Both can handle and decide a lot on their own. What separates them is what happens after they decide: whether the work comes back to a person, or whether the system is authorised to act externally.

An agentic workflow hands the work back for you to review. Depending on how it is configured it may pull from approved sources, set the sequence, judge when it has finished, and then the output returns to you before it touches anything in the outside world. You still see it. You still act on it. The tool handled the middle. You kept the ends.

An autonomous agent acts on its own. Picture a tool that sends the redline, files the response, messages the counterparty, and does so before any human has looked at that particular action. The decision to act on the world has moved from you to the software.

Workflows that hand the work back are common now. Tools marketed as capable of acting on their own are beginning to appear in legal, although it is still hard to verify how widely they are used in ordinary practice or under what controls. That is the category we need to keep an eye on.

Is anything acting on its own right now? An inventory 

The reality is simpler than the hype suggests. Here’s what’s actually happening.

Start with scale. In Thomson Reuters Institute’s cross-sector survey of more than 1,500 professionals in legal, tax, accounting, risk, fraud and government, 15% said their organizations use agentic AI, and a further 53% said their organizations were planning or considering it. These numbers reflect real momentum rather than hype. And they are broad, global figures across professional services, not a measure of in-house legal specifically, so read it as the weather over the whole field rather than a count of legal teams running an autonomous agent in production. Simply put: The trend is real, but these figures do not show widespread use of systems that take external action without human approval.

At the product level, consider how one widely used legal AI tool, Harvey, describes its approach to complex legal work. The tool drafts a plan, the lawyer reviews and edits that plan before the complex task runs, and it pauses on anything outside the playbook or on higher-stakes calls. Set that against the last section. This is an agentic workflow. The work still comes back to a person. By Harvey’s own description, it is built to stay on the near side of the line.

That is not the only direction of travel. Tools marketed as capable of autonomous legal action are beginning to appear. Some vendors say their contract-negotiation systems can review an agreement, apply an approved playbook, exchange revisions with a counterparty and progress the negotiation without a person approving every step. From the outside, though, it is still hard to verify the scope, controls, reliability or prevalence of those deployments. But the governance issue is already clear: once a system is authorised to send a contractual position externally without a human reviewing that particular action first, it has crossed the line from returning work to acting on it.

So the category talk runs well ahead of what has been shown to be running in practice. That gap, between what the word promises and what has really shipped into daily work, is the room you have to work in.

Where this is heading

The capability being marketed is not being aimed only at legal teams. It is increasingly being opened to the wider enterprise.

That’s what we need to think more about. The capability that crosses the line is being pointed at more users, not fewer. And at users who sit further from legal judgment than the lawyers it started with.

Drawing the line is a manageable exercise today, while autonomous agents remain early and isolated. It becomes a harder exercise once that capability ships as a default feature to every category manager and sales lead in the business.

Having an early view is an advantage, and also a temporary one.

None of this argues for holding everything back. Blanket caution has a real cost, in speed, and in the goodwill of a business that wants legal to move faster rather than slower. The point was never to review everything forever. It is to know which acts you are willing to let run without you, and which ones you are not, before that choice gets made by a default setting instead of by you. A line drawn on purpose can say yes to a great deal. A line you never drew says yes to all of it.

What changes when the line is crossed

It’s worth being precise here because saying "the risk goes up" is true but tells you very little. Two specific things change the moment a tool is authorised to act externally rather than hand the work back.

First, the action becomes external. The redline reaches a counterparty. The filing reaches a court. The message lands in a system of record. Many of those actions are difficult or impossible to walk back once taken. A draft you disagree with, you rewrite. A redline that has already gone to the other side is a fact you now have to manage.

Second, the order flips. Today you review, then you act. Once a tool acts on its own, it acts, and you review what it has already done. Same lawyer, same care, reversed sequence: from clearing a step before it happens to accounting for one that already has. That is the quieter change, and it is the one that reshapes the role.

Neither of those is a prediction of harm. They are simply describing mechanics of the delegated authority. And that is what the line comes down to, underneath the category talk: the difference between reviewing a decision and inheriting one.

Where this leaves us

The point where software acts before we look, is going to be drawn in every legal department, one way or another. The only choice is whether you draw yours deliberately, while autonomous capability is still early and the timing still belongs to you, or whether it gets drawn for you later by a legal AI tool’s default setting.

For now, that line is yours to draw, and no one else's. Existing professional duties already apply, and bar associations have begun issuing guidance on AI. What is not yet settled is how those duties operate where a system is authorised to take consequential external action without case-by-case human approval. In that space, the legal department still has to set the operating rules. Not the vendor. You.

And there's a reason lawyers will be careful with that, beyond liability. Handing off control of the work cuts against something deeper: the professionalism the role is built on, and the trust a client places in a named human who stands behind the output. This is why workflows matter so much in legal, and why letting go will, and should, take time. The instinct to keep a hand on the work isn't caution for its own sake. It's the job doing what the job is for.

None of that is a reason to freeze. It's a reason to be deliberate. Deciding what a tool can do without you comes down to a few clear choices: which tools can act before a person has checked the work, which ones always need a human to sign off, and how both of those get written into the contracts you're already negotiating with vendors. Make those choices early, and your team stays in control of what it adopts and how, whatever ships next.

This is quiet, internal work, and far easier done now than under a deadline later. If you're already thinking through where your line sits, you're ahead of most of the field.