Generative AI adoption inside corporate legal departments has nearly doubled in a single year. According to the 2026 General Counsel Report from FTI Consulting and Relativity, 87% of General Counsel now report AI use within their teams, up from 44% in 2025 and just 20% in 2023. By most measures, that’s one of the fastest technology adoption curves the legal profession has ever seen.
Here is the harder number. According to a 2026 industry survey reported by legal AI advisory firm Swiftwater and Company, only 8.7% of General Counsel actually own AI governance within their organizations. Most of it sits with IT or the CIO instead, despite the legal function carrying direct responsibility for the enterprise risk, compliance exposure, and regulatory obligations that AI use creates.
Adoption raced ahead. Ownership didn’t follow. That gap is not an abstract governance problem. It is already showing up in courtrooms, and it is the reason a growing share of the legal industry’s most serious conversations this year are happening in California specifically.
The adoption curve nobody quite priced in
Two years ago, generative AI in legal departments was still an experiment. The Association of Corporate Counsel’s GenAI survey with Everlaw found corporate legal AI adoption more than doubled in one year alone, from 23% to 52%, and the implications go beyond internal efficiency. As in-house teams get faster at AI-assisted work, 64% now expect to rely less on outside counsel because of it, a real shift in leverage between law firms and the corporate legal departments that hire them.
Analysts tracking the space describe 2026 as the year AI stopped being an interesting pilot and became operational infrastructure, whether legal departments were fully ready or not. That framing matters, because infrastructure needs governance the way a pilot program doesn’t. A tool a few people were testing quietly is now embedded in contract review, compliance monitoring, matter intake, and legal research at 87% of legal departments. The risk profile of that is entirely different.
Why the governance gap is a legal problem, not just an IT one
The instinct to hand AI governance to IT or legal operations makes a certain organizational sense, they understand the technology, procurement, and security review. But legal commentary tracking AI malpractice risk has made a pointed observation: when courts sanction lawyers for AI-related failures, they hold counsel responsible regardless of which department selected the tool or how convincing the vendor’s claims were. Delegating the technology decision doesn’t delegate the professional responsibility that comes with it.
This isn’t theoretical. In August 2026, attorneys representing a major national insurer in a Los Angeles fire-damage lawsuit apologized after opposing counsel discovered their court filings contained AI-generated case citations that didn’t exist. A database tracking legal AI hallucinations globally has now logged more than 1,900 documented cases, the large majority of them in the United States, with sanctions escalating sharply since the first widely reported case in 2023. In nearly every one of those cases, the failure traces back to the same root issue: AI use that wasn’t governed by anyone with the authority or the professional obligation to catch it.
The governance gap shows up in privilege law too. Two federal rulings ten days apart in February 2026, United States v. Heppner in the Southern District of New York and Warner v. Gilbarco in the Eastern District of Michigan, reached opposite conclusions on whether AI-assisted materials were protected by attorney-client privilege or work product doctrine. Read closely, the two rulings aren’t really in conflict. Both turn on the same question: was an attorney actually directing the AI use. When governance and legal oversight are present, protection tends to hold. When they’re absent, it tends to fail. A Massachusetts court reinforced the same pattern in July, in a case where a party’s own AI use, without any attorney involvement, lost work product protection entirely.
None of this is a technology failure. It’s a governance failure, and it’s landing on the desks of General Counsel whether or not they’ve claimed formal ownership of it.
California is regulating this from two directions at once
Much of the regulatory response to this gap is happening in California, and it’s worth understanding as a whole rather than as isolated headlines.
SB 53, the Transparency in Frontier Artificial Intelligence Act, signed by Governor Newsom in September 2025 and in effect since January 1, 2026, regulates the developers of the largest AI models, requiring published safety frameworks, transparency reports, and critical incident reporting. Authored by a state senator representing San Francisco, it makes California the first state with a law focused specifically on frontier AI safety, and Newsom’s own signing statement described it explicitly as a blueprint for other states.
SB 574, moving through the California Assembly with a floor vote required by August 31, 2026, works from the opposite direction. Rather than regulating the companies that build AI, it regulates the lawyers who use it, requiring attorneys to personally verify AI-generated citations before filing and prohibiting confidential client information from being entered into public AI tools. New York has already moved on similar ground, adopting a binding court rule in June 2026 that requires attorneys to certify their filings don’t contain AI-fabricated citations, and a New York City Bar committee has since called for the same standard to be built into the national Model Rules of Professional Conduct.
Put together, California is regulating AI governance from both ends simultaneously, the systems being built and the professionals using them, while individual courts fill in the gaps between the two with case-by-case rulings on privilege, sanctions, and professional responsibility. For a General Counsel trying to build a defensible governance program, that’s not background noise. It’s the actual shape of the compliance landscape they’re now operating inside.
What closing the gap actually requires
The fix isn’t a blanket ban on AI tools, that’s increasingly unrealistic given how embedded these tools already are, and it ignores the real productivity gains driving adoption in the first place. Legal AI governance specialists increasingly frame the real starting point as three concrete steps: forming a cross-functional governance body rather than leaving the decision inside one department, adopting a recognized risk framework rather than an ad hoc policy memo, and mapping where AI is actually being used across the organization, including the “shadow AI” use that happens without legal’s knowledge when employees turn to consumer-grade tools on their own.
The distinction that keeps surfacing across the court rulings, the sanctions cases, and the governance research is the same one: was legal actually in the room when the AI decision got made, and can that involvement be demonstrated. Companies that can answer yes are the ones holding up under scrutiny. Companies that can’t are finding out the hard way, often in a courtroom.
Where this conversation is actually happening
This is precisely the terrain LexTalk World San Francisco 2026 is built around. The agenda’s AI Governance, IP & Enterprise Innovation and In-House Leadership in the AI Era tracks, alongside sessions on Board Governance and Executive Accountability, exist because the gap between AI adoption and AI governance is now the defining operational question for legal departments, not a side conversation.
The room reflects that. LexTalk World San Francisco brings together 300+ delegates from 15+ countries and 80+ speakers, with General Counsel and Chief Legal Officers making up 45% of attendees, alongside law firm partners, compliance and risk leaders, and legal technology founders navigating the same governance questions from different sides of the table. Held November 19 and 20 in San Francisco, a city where the frontier AI industry itself is headquartered and where the state legislature is actively writing the rules governing it, the conversations happening in the room are shaped by the same regulatory and technological forces this article has walked through, not adjacent to them.
If the governance gap described here sounds familiar inside your own organization, it’s worth being in a room built specifically to close it.
LexTalk World San Francisco | November 19 and 20, 2026
Frequently Asked Questions:
What is AI governance in a legal department?
AI governance is the set of policies, oversight structures, and accountability mechanisms that determine how an organization evaluates, deploys, monitors, and takes responsibility for its use of AI tools. It’s broader than an AI use policy, which typically just states rules; governance covers who has decision-making authority, how risk is assessed before deployment, and how compliance is monitored on an ongoing basis.
Who should own AI governance, legal or IT?
Legal commentary and court rulings increasingly point toward legal ownership, or at minimum, meaningful legal involvement, because courts have held counsel professionally responsible for AI-related failures regardless of which department selected the tool. IT typically manages the technical infrastructure and security review, but the professional and regulatory accountability tends to land on legal, which makes governance without legal in the room a structural risk.
What percentage of General Counsel use AI in 2026?
According to the 2026 General Counsel Report from FTI Consulting and Relativity, 87% of General Counsel report AI use within their teams, up from 44% in 2025 and 20% in 2023.
What is shadow AI, and why is it a legal risk?
Shadow AI refers to employees or teams using consumer-grade AI tools, often without legal or IT approval, to draft contracts, answer policy questions, or handle other work that touches company or client information. Because these tools often aren’t reviewed for confidentiality or data-handling risk, shadow AI use can create exposure that the legal department isn’t even aware exists until it surfaces in litigation or a regulatory inquiry.
What AI laws should General Counsel in California know about in 2026?
Two are especially relevant. SB 53, the Transparency in Frontier Artificial Intelligence Act, regulates developers of the largest AI models and has been in effect since January 1, 2026. SB 574, still moving through the California Assembly as of this writing, would regulate how attorneys themselves use AI, including verification and confidentiality obligations. Together they represent regulation from both the developer side and the practitioner side.
What happens if a company doesn’t have formal AI governance?
Based on the pattern across 2026’s court rulings and sanctions cases, the risk isn’t hypothetical. Ungoverned AI use has already led to sanctions for fabricated citations in litigation, the loss of attorney-client privilege and work product protection over AI-assisted materials, and reputational damage when failures become public. Courts have shown little patience for the argument that a failure originated outside the legal department.
This article reflects publicly reported data and legal developments as of the publication date below. Legislative and regulatory status can change quickly; readers should confirm current status before relying on this piece for compliance purposes.