/home/wpurdemo/theformtool.wp.urdemo.website/wp-content/mu-plugins/home/wpurdemo/theformtool.wp.urdemo.website/wp-content/themes/dt-the7-child/includes Security Archives | TheFormTool Document assembly, Data collection, Digital Decisioning and forms automation for Microsoft Word Wed, 22 Jul 2026 19:19:11 +0000 en-US hourly 1 Who Controls Your Client Data During Document Automation? https://theformtool.wp.urdemo.website/who-controls-your-client-data-during-document-automation/ Sat, 18 Jul 2026 22:31:32 +0000 https://theformtool.wp.urdemo.website/?p=87178 Who Controls Your Client Data During Document Automation? A Practical Question Before Any Automation Project A professional document can contain far more than words on a page. A lawyer may be working with client names, case facts, financial terms, draft clauses, settlement details, or confidential instructions. An accountant may be preparing documents that include tax…

The post Who Controls Your Client Data During Document Automation? appeared first on TheFormTool.

]]>
Who Controls Your Client Data During Document Automation?

A Practical Question Before Any Automation Project

A professional document can contain far more than words on a page. A lawyer may be working with client names, case facts, financial terms, draft clauses, settlement details, or confidential instructions. An accountant may be preparing documents that include tax records, account numbers, ownership information, or company figures. HR and professional services teams may be working with compensation, employment, personal, or internal business information.

The finished Word document may stay inside the organization. That does not necessarily mean the information used to create it stayed there while the document was being assembled. In a document automation system, information may be entered into a questionnaire, processed by software, used to select clauses, applied to calculations, and then placed into one or more final documents.

Before adopting any automation system, a firm should understand that full path. The central question is simple: who controls the client data while the document is being created?

The Final Document Is Only One Part of the Workflow

Many privacy discussions focus on where the final document is stored. That matters, but it is only part of the issue. Document automation involves several steps, and confidential information may be handled at each one.

A typical workflow may include entering client or matter details, applying document rules, selecting language, completing dates or calculations, generating one document or a full packet, and saving the result for review. Depending on the system, some of those steps may occur on the user’s computer, on a firm server, in a vendor-controlled cloud system, or through a combination of services.

That is why data control is not only a storage question. It is a workflow question. A firm needs to know where information is entered, where it is processed, whether it is transmitted outside the firm’s environment, and who can access it at each stage.

The First Question: Where Is the Data Processed?

The most important privacy question is often the easiest to ask and the hardest to answer clearly: where does the processing take place?

Different automation products use different models. Some operate locally on the user’s machine. Some work inside a private network. Some send information to an outside server for processing. Some combine local software with cloud-based services.

No model is automatically perfect. A local system still depends on secure devices, passwords, permissions, backups, and staff practices. A cloud system may have sophisticated safeguards but may also move client information outside the firm’s direct control. The point is not to assume. The point is to ask and verify.

Useful questions include:

  • Does client or matter data leave the user’s computer or firm network?
  • Does the provider process document contents or questionnaire answers?
  • Are temporary files or saved responses created during assembly?
  • Can the system work without an internet connection?
  • Does the workflow rely on outside services to complete a document?

Control Also Means Storage, Access, and Retention

Processing location is only the beginning. A firm also needs to know what remains after processing and who controls it.

For example, completed documents may be saved in a local folder, a document management system, a shared drive, or a provider-controlled platform. Form answers may be discarded immediately, saved for later reuse, or stored as part of a matter record. Templates may be editable by a small group or available to many users.

These choices affect both privacy and management. Firms should understand who can view templates, who can generate documents, who can access completed files, whether saved answers remain available, how backups are handled, and what happens when an employee leaves.

Local control can be valuable because it lets the organization use its own storage, permission, backup, and retention rules. It also requires the organization to manage those duties carefully.

Questions to Ask Before Choosing a Document Automation System

A practical review does not need to begin with theory. It can begin with direct questions that identify where responsibility sits.

Data movement

  • Does any client data leave our device, server, or network?
  • Is document content transmitted during generation?
  • Does the software contact outside servers as part of the process?
  • Are questionnaire answers saved after the document is created?

Access

  • Can provider staff view our information?
  • Can user access be limited by role or password?
  • Who may change approved templates or document logic?
  • Can we control where completed documents are saved?

Storage and retention

  • Where are temporary files stored?
  • Can saved answers be deleted?
  • How are backups handled?
  • Who controls retention rules?

Operational control

  • Can the system work when the internet is unavailable?
  • What happens if the provider’s service is down?
  • Can we continue using our existing Word templates?
  • Can we keep the document process inside our existing Word-based workflow?

Clear answers help firms compare systems honestly. They also keep the discussion grounded in the actual movement of information rather than general promises about security.

Why No-Cloud Document Automation Can Matter

No-cloud document automation is not a slogan. For many professional users, it is a control choice.

When document assembly happens inside Microsoft Word and does not require cloud processing, the firm can keep the work within systems it already manages. Client information can remain on the user’s computer, internal network, or chosen document storage location, subject to the firm’s own security practices.

That approach can be especially important for lawyers, accountants, consultants, HR teams, and others who work with confidential professional documents. It may reduce the number of outside systems involved in the document process, make the data path easier to understand, and help the organization apply its own access and retention rules.

No-cloud automation does not eliminate the need for good security. Computers still need protection. Shared folders still need permissions. Backups still need care. Documents sent by email still need judgment. The advantage is that the firm can more clearly identify and control where the information travels.

How TheFormTool® Fits This Question

TheFormTool’s approach is deliberately Word-based. TheFormTool, Doxserá, Doxserá DB, and related products work inside Microsoft Word rather than requiring users to send documents to an outside drafting platform for assembly.

That matters because many professional offices already have a Word-based drafting process, existing template libraries, document management rules, and internal security practices. TheFormTool helps those offices improve the document process without forcing confidential drafting work into a cloud-dependent system.

A clean Word template can hold approved language. A guided form can ask for the information needed for the document. Rules can include or exclude language, repeat information where it belongs, calculate dates or amounts, and generate related documents from the same answers. Completed files can be saved where the firm chooses.

TheFormTool does not replace internal security policies, professional judgment, or final review. It gives firms a practical way to automate repeated Word document work while keeping the path of client information easier to see and manage.

A Sensible Data-Control Review

Before automating a document, a firm should map the information path. Start with the data the form collects: names, addresses, financial details, matter facts, employment information, tax records, case notes, or other confidential content. Then identify who enters it, where it is processed, where it is saved, and who can view it later.

The review should also consider which users can edit templates, which users can only run approved forms, whether saved answers are retained, how backups are handled, and what happens when access must be removed. In many organizations, this review should involve both document experts and technology or security staff, because each group sees a different part of the workflow.

A clear review may lead to different answers for different document types. A simple internal form may need one level of control. A client-facing agreement, tax document, medical record, or employment file may need another. The important step is to decide before the process is handed to everyday users.

Conclusion

Document automation privacy begins before the final Word file exists. It begins when a user enters information, and it continues through processing, storage, review, sharing, backup, and deletion.

Firms should ask where data goes, who can see it, who controls it, and what remains after the document is generated. No-cloud, Word-based automation can make those questions easier to answer because more of the process can remain inside systems the firm already controls. The right system should not require a firm to lose sight of client information in order to create better documents.

The post Who Controls Your Client Data During Document Automation? appeared first on TheFormTool.

]]>
87178
Document Automation Without Authoring Tools: A Cost-Effective Way to Empower Form Users https://theformtool.wp.urdemo.website/document-automation-without-authoring-tools-a-cost-effective-way-to-empower-form-users/ Thu, 02 Jul 2026 15:26:34 +0000 https://theformtool.wp.urdemo.website/?p=87033 Document Automation Without Authoring Tools: A Cost-Effective Way to Empower Form Users Many professional offices eventually discover that document automation raises a practical question: who should be allowed to build and change the forms, and who should simply be allowed to use them? The answer matters. In a small office, the same person may create…

The post Document Automation Without Authoring Tools: A Cost-Effective Way to Empower Form Users appeared first on TheFormTool.

]]>
Document Automation Without Authoring Tools: A Cost-Effective Way to Empower Form Users

Many professional offices eventually discover that document automation raises a practical question: who should be allowed to build and change the forms, and who should simply be allowed to use them?

The answer matters. In a small office, the same person may create the template, adjust the rules, and produce the final document. In a larger firm, that model does not scale well. Authors need enough control to build reliable forms. Users need a simple way to create documents without accidentally changing the approved language, questions, calculations, or logic that other people depend on.

That is the purpose of document automation without authoring tools. It is not a lesser version of automation. It is a role-based way to put approved forms in the hands of more people while keeping responsibility for the form itself with the people trained to manage it.

Why Authoring and Use Should Be SeparateRight Access for the Right Role

A well-built automated form is more than a Word file with fields. It may contain approved language, conditional paragraphs, calculations, repeat logic, data connections, document-set instructions, and carefully tested output. A casual edit to one question or condition can affect many documents that are generated later.

That is why full authoring access should not automatically be given to everyone who prepares documents. Most users do not need to change the form. They need to answer questions, select the right matter or record, generate the documents, and review the result. Giving those users the right level of access makes the system easier to learn and safer to use.

The distinction is familiar in other professional systems. Not everyone who enters client data should be able to redesign the database. Not everyone who uses a brief bank should be able to rewrite the master language. Document automation benefits from the same discipline.

The Product Distinction Matters

For TheFormTool, the Author/User distinction should be stated carefully.

  • TheFormTool PRO does not provide an Author/User access model. PRO is intended for simpler Word-based automation, but it does not separate people who build forms from people who only run them.
  • Doxserá, Doxserá DB, and Aurora can restrict Authoring with password protection. That allows an organization to limit who may change forms, rules, questions, and template logic while still allowing others to use approved forms.
  • DB User has no authoring capability. It is designed for people who need to run approved Doxserá DB or Aurora forms, not build or modify them. Because it does not include authoring tools, DB User is priced at a significant discount from Doxserá DB.

This distinction is important. The value of DB User is not simply that it is less expensive. The value is that firms can give full authoring power to trained form builders while giving lower-cost, non-authoring access to the staff and practitioners who only need to generate documents from approved forms.

How a User-Focused Model Works

In a role-based document automation system, authors and users have different jobs.

Authors build and maintain the forms. They decide which questions should be asked, what language should appear, when a clause should be included, how calculations should work, and how a document set should be assembled. They are responsible for the structure and reliability of the template.

Users run approved forms. They provide the facts, select the appropriate record or matter, generate the documents, and review the final output. They should not need to understand the form logic to do their work well. They should not have to learn template design just to prepare an agreement, letter, packet, or report.

That separation reduces training time, lowers cost, and protects the form library from accidental changes. It also supports a more professional process: the people with subject-matter or automation responsibility control the source materials, while the people doing daily document work use the approved system.

A Large-Firm ExampleFrom Cost Center to Profit Center

One of TheFormTool’s most sophisticated large customers uses this model at scale.

The firm’s subject-area experts are responsible for keeping the substance of the forms current in their specific areas of practice. Across dozens of subject areas, those experts maintain the best current language, procedures, and requirements for the documents in their field.

A small internal department of TheFormTool specialists then crafts those materials into intelligent templates and adds them to the firm’s large form library. Several hundred practitioners can use that library to generate documents from the most current, approved forms available across the firm.

The result is not merely faster document production. The larger benefit is consistency. Everyone in the firm can work from the same current best-practice documents. Updates are made centrally. Improvements made by experts are distributed through the form library instead of being passed informally from office to office or hidden in someone’s copied file.

That model has become successful enough that the firm now offers a similar service to major clients. On a retainer basis, the firm helps keep clients’ internal forms up to date and usable. The document automation operation becomes more than an internal cost center. It becomes a client service, a profit center, and a way to strengthen the firm-client relationship.

Why This Model Reduces Cost

Full authoring tools are valuable for the people who need them. They are not always necessary for every person who prepares documents. In a larger organization, buying full authoring capability for every user can create unnecessary cost and unnecessary complexity.

A user-focused model matches software access to the work being done. A smaller group of trained authors manages the forms. A larger group of users runs approved forms and produces documents. The organization avoids paying for authoring tools that many users will never use, while still expanding access to the automated document system.

This is especially useful where many staff members, paralegals, assistants, or practitioners generate documents from a central library. They benefit from the automation, but the organization does not have to give everyone the same level of template control.

Why This Model Reduces Risk

Approved forms carry institutional knowledge. They may include the language preferred by a practice group, compliance rules, standard clauses, calculations, data links, and document-set instructions. If too many people can change those forms, the organization increases the chance of inconsistency or accidental damage.

Restricting authoring helps protect the library. Users can produce documents from approved materials without changing the source. Authors can test and update forms deliberately. Subject-area experts can be responsible for content. Automation specialists can be responsible for structure and logic. That is a healthier division of responsibility than letting every user edit everything.

This does not remove professional review. Users still need to review final documents for facts, judgment, and context. The point is that review starts from a cleaner, more controlled document, not from a copied file of uncertain origin.

Benefits of Document Automation Without Authoring Tools

1. Lower software cost

Organizations can reserve full authoring tools for the people who build and maintain forms, while giving lower-cost non-authoring access to users who only need to run approved forms.

2. Better control of approved templates

Forms, rules, calculations, and approved language are protected from casual or accidental edits. Changes can be made by the people responsible for maintaining the system.

3. Easier training for users

Form users do not need to learn template design. They need to know how to select the right form, provide the needed information, generate the document, and review it.

4. More consistent documents across the organization

When users draw from the same current form library, documents are more likely to follow the same structure, use the same approved language, and reflect the latest internal standards.

5. Better use of subject-area expertise

Experts can focus on the substance of the forms. Automation specialists can focus on turning those forms into reliable templates. Users can focus on serving clients and completing the work.

6. A stronger foundation for client service

For some firms, the same internal model can become an external service. Helping clients maintain their own forms can create recurring value, deepen the relationship, and turn document automation expertise into a revenue-producing asset.

Choosing the Right Access for Each Person

The practical question is simple: what does this person need to do?

If the person builds forms, edits rules, manages logic, updates language, or maintains document sets, that person needs authoring access in the appropriate TheFormTool product. In Doxserá, Doxserá DB, and Aurora, authoring can be restricted with password protection.

If the person only needs to run approved Doxserá DB or Aurora forms and generate documents, DB User may be the better fit. It gives the user access to the document-generation process without giving that person authoring tools.

If the office is using TheFormTool PRO, the Author/User model does not apply. PRO remains useful for simpler Word-based automation, but it should not be described as having role-based Author/User access.

Conclusion

Document automation is not only about making documents faster. In larger professional settings, it is also about control, responsibility, consistency, and cost. The best system gives the right tools to the right people.

Authors should be able to build and maintain reliable forms. Users should be able to run approved forms without risking the integrity of the library. Subject-area experts should be able to keep content current. Automation specialists should be able to turn that content into dependable templates. Practitioners and staff should be able to use the best available documents every day.

That is the value of document automation without authoring tools. It empowers more users while protecting the forms, rules, and professional judgment that make the system worth using.

The post Document Automation Without Authoring Tools: A Cost-Effective Way to Empower Form Users appeared first on TheFormTool.

]]>
87033
Four Golden Rules of Form Design https://theformtool.wp.urdemo.website/86711-2/ Thu, 04 Jun 2026 18:05:35 +0000 https://theformtool.wp.urdemo.website/?p=86711 The post Four Golden Rules of Form Design appeared first on TheFormTool.

]]>

Four Golden Rules of Form Design

Good forms save time. Great forms save time without people realizing why. After years of building and reviewing forms, four rules continually rise to the top.

Reduce the Number of Questions

Every question requires user effort to answer and creates an opportunity for error.

Instead of asking: Is the buyer married? What is the spouse’s name?

Ask: Buyer’s spouse’s name (if any)?

Now one answer provides two pieces of information.

Likewise, instead of asking: Is the seller a company? What is the seller’s name?

A smart answer can gather both pieces of information at once.

Ten questions become nine. Nine become eight. Then seven. Keep reducing.

Small reductions matter because every click and every keystroke consumes time and multiply errors.

Never Allow Double Typing

If someone typed: “John Smith” once, they should never need to type it again.

The first time users enter information they are careful. They check source documents and verify spellings. The second time they type it, they become faster and less careful. That is where errors happen.

Ask for information once. Reuse it everywhere.

Use Universal Field Names

Clients return and transactions change.

Information should move easily between matters.

Imagine a client visits your office for a will. Three months later the same client returns to create a partnership agreement. Wouldn’t it be useful if the information already entered could be leveraged automatically?

Universal field names allow that to happen.

More Work for You Means Less Work for Them

Sometimes you can spend an additional 45 minutes improving a form and save the user only a few minutes.

If the form will only be used once or twice, perhaps it’s not worth it. But if the form will be used every day for years, those minutes multiply quickly.

A little extra work during construction often creates enormous value later.

See hundreds of other productivity tips in our Knowledge Base.

The post Four Golden Rules of Form Design appeared first on TheFormTool.

]]>
86711
Concerns about Copilot https://theformtool.wp.urdemo.website/concerns-about-copilot/ Mon, 01 Jun 2026 23:48:25 +0000 https://theformtool.wp.urdemo.website/?p=86681 The post Concerns about Copilot appeared first on TheFormTool.

]]>

Before You Type Client Information Into Word, Check This Setting

Many lawyers, accountants, doctors, and other professionals still think of Microsoft Word primarily as a desktop program.

Open a document. Type. Save. Close.

Increasingly, that assumption is incomplete.

Modern versions of Microsoft Office include connected services and AI-powered features capable of analyzing content, suggesting edits, summarizing text, rewriting sections, and generating recommendations.

When users activate certain features — such as Copilot requests, AI-powered summaries, rewriting tools, grammar suggestions, or connected experiences — document content or relevant excerpts can be transmitted to Microsoft for processing.

That does not mean Microsoft continuously uploads every document you type.

Simply opening a document and working in Word does not automatically send entire files into the cloud in the background. While the issue is more nuanced, the feature is turned on by default, can be difficult to turn off, and accidents happen.

For professionals handling confidential, privileged, regulated, or sensitive information, they create a different question:

Not: “Can the technology do this?”

But: “Should this information leave my environment at all?”

Examples may include:

• AI-assisted summarization
   

• Grammar and editing suggestions
   

• Content recommendations
   

• Connected cloud experiences
   

• Copilot interactions

The concern is not whether these tools are good or bad. Some are useful.

Our concern is understanding what is enabled and how those features operate.

To review them in Office:

File → Options → Trust Center → Privacy Settings 
(or equivalent settings depending on Office version)

We recommend you review items such as these to determine their use to you:

• Connected Experiences
   

• Experiences that analyze your content
   

• Copilot and AI-related features

For organizations handling confidential client information, privileged communications, regulated data, or sensitive internal materials, understanding these settings may deserve a place on the same checklist as passwords, backups, and cybersecurity procedures.

Technology continues becoming more powerful and too often not receiving the visibility and consideration they deserve.

Professional responsibility increasingly means understanding what our tools are actually doing.

The post Concerns about Copilot appeared first on TheFormTool.

]]>
86681
Cut.
 Paste.
 Adjust.
 Hope. https://theformtool.wp.urdemo.website/cut-paste-adjust-hope/ Thu, 26 Feb 2026 15:55:29 +0000 https://theformtool.wp.urdemo.website/?p=85794 Cut.
 Paste.
 Adjust.
 Hope. There is an old rhythm in legal drafting: Cut.
 Paste.
 Adjust.
 Hope. Every lawyer has done it. Take a prior agreement.
 Change the names.
 Modify a paragraph.
 Update a date.
 Move on. It feels efficient. Until it isn’t. A True Story A good friend went through a difficult season in life.…

The post Cut.
 Paste.
 Adjust.
 Hope. appeared first on TheFormTool.

]]>
Cut.
 Paste.
 Adjust.
 Hope.

There is an old rhythm in legal drafting:

Cut.
 Paste.
 Adjust.
 Hope.

Every lawyer has done it. Take a prior agreement.
 Change the names.
 Modify a paragraph.
 Update a date.
 Move on.

It feels efficient. Until it isn’t.

A True Story

A good friend went through a difficult season in life. When things stabilized, he brought home a newly drafted 150-page trust for his wife to review and sign.

She read carefully. Then she stopped. “Who is this?” she asked. The trust named a completely different spouse.

Cut.
 Paste.
 Missed.

It was not incompetence. 
It was habit.

The Real Risk

Copy-and-paste drafting feels safe because it’s familiar.

But familiarity hides drift.

Over time:

Definitions accumulate inconsistently

Provisions linger from prior deals

Names survive from earlier drafts

Internal references detach

Nothing dramatic. Just erosion.

And erosion rarely announces itself.

Discipline Is Structural

The solution is not paranoia. It is structure.

Rule-based assembly.
 Controlled variables.
 Clear fields.
 Repeatable logic.

When documents are built intentionally rather than inherited, the margin for error narrows.

You want to be drafting forward — not patching backward.

Efficiency Is Not the Same as Precision

Copy-and-paste is fast. Structure is disciplined.

Every serious practice eventually decides which one it prefers.

 

DOJ Smears James Rosen with “Cut & Paste” Error

Was “Popeye” the Accidental Result of a Decades-old Cut & Paste Error?

The post Cut.
 Paste.
 Adjust.
 Hope. appeared first on TheFormTool.

]]>
85794
Intelligent Systems Don’t Outsource Judgment https://theformtool.wp.urdemo.website/intelligent-systems-dont-outsource-judgment/ Fri, 20 Feb 2026 00:04:22 +0000 https://theformtool.wp.urdemo.website/?p=85729 The post Intelligent Systems Don’t Outsource Judgment appeared first on TheFormTool.

]]>

Intelligent Systems Don’t Outsource Judgment

There is a growing temptation in modern practice to confuse assistance with substitution.

Technology now drafts, predicts, suggests, reformulates, summarizes. It is fast. It is impressive. It is increasingly persuasive.

But none of it exercises judgment.

Judgment is slower. 
It is contextual.
 It is accountable.

And it belongs to the lawyer.

Most of our customers would never consider outsourcing their legal thinking. They would not delegate strategy to a machine. They would not ask an algorithm to decide what a client’s interests require.

So why should their documents behave as though judgment were optional?

Intelligent technology can not replace the professional. It reinforces the professional.

It provides structure without assumption.
 Control without intrusion.
 Precision without improvisation.

It follows rules rather than probabilities. It behaves predictably rather than persuasively. It executes instructions rather than generating suggestions.

There is nothing dramatic about this approach. It does not advertise itself as revolutionary. It does not promise to think for you.

It simply stays in its lane.

And that is precisely the point.

A disciplined practice does not outsource its reasoning. It does not delegate its custody. It does not confuse convenience with responsibility.

Technology should strengthen the lawyer’s role, not dilute it.

An intelligent system knows the difference.

The post Intelligent Systems Don’t Outsource Judgment appeared first on TheFormTool.

]]>
85729
Should We Have Different Ethical Standards for Machines? https://theformtool.wp.urdemo.website/should-we-have-different-ethical-standards-for-machines/ Wed, 19 Nov 2025 22:18:31 +0000 https://theformtool.wp.urdemo.website/?p=83121 What if your legal assistant invented a case, a clause, or an argument—out of thin air? Imagine this: your legal assistant comes into your office with a draft pleading. It looks great—polished formatting, strong arguments, and even a few citations. But when you ask, “Where did this come from?” they shrug: “I made it up.…

The post Should We Have Different Ethical Standards for Machines? appeared first on TheFormTool.

]]>
What if your legal assistant invented a case, a clause, or an argument—out of thin air?

Imagine this: your legal assistant comes into your office with a draft pleading. It looks great—polished formatting, strong arguments, and even a few citations. But when you ask, “Where did this come from?” they shrug: “I made it up. I thought it sounded good.”

You’d be horrified. Rightfully so.

And yet, this is precisely what’s happening when lawyers use generative AI—particularly large language models (LLMs)—without guardrails. These systems are brilliant at mimicking the form of legal reasoning but have no understanding of the substance. Their so-called “hallucinations” aren’t occasional hiccups; they’re a structural risk. When ChatGPT or its cousins invent a precedent or draft a clause “out of whole cloth,” it’s not just a technical error—it’s professional peril.

What’s even more dangerous is that it looks good. In many cases, the generated text feels legitimate. The language is fluent, the tone authoritative, the citations plausible. Until they’re not.

Legal drafting is not just about generating words.

It’s about truthful, factual, and contextually accurate statements that carry legal weight. If a lawyer uses AI-generated content in a will, a trust, or a motion—without validating every detail—they’re inviting malpractice, sanctions, or worse.

This is not a theoretical concern. Judges are sanctioning lawyers who submit AI-written briefs that include fabricated cases. But what happens when the hallucinations are less obvious—when they involve subtly incorrect language in a contract, or a misplaced clause in a will?

The problem isn’t just using AI. It’s using it without understanding its limits. Treating it like a “super assistant” rather than a potentially unreliable narrator.

And that metaphor—legal assistant—may be exactly what we need. If your assistant made something up, you’d fire them. So what’s the standard for a machine that does the same?

Avoiding hallucinations is easy.

At TheFormTool, we built PRO and Doxserá to generate flawless, repeatable documents using rules, facts, and structure you control—not guesses. Offline, secure, and hallucination-free. Just the way legal work should be.

Our Security page.

The post Should We Have Different Ethical Standards for Machines? appeared first on TheFormTool.

]]>
83121
65+ Fake Citations: How AI Hallucinations Become Fabrications in Court https://theformtool.wp.urdemo.website/65-fake-citations-how-ai-hallucinations-become-fabrications-in-court/ Sat, 27 Sep 2025 15:14:57 +0000 https://theformtool.wp.urdemo.website/?p=83826 65+ Fake Citations: How AI Hallucinations Become Fabrications in Court Last year, lawyers filed briefs containing more than 65 non-existent citations in U.S. courts. At the same time, AI developers began publishing research on whether their models were actively “scheming” to conceal mistakes. If a human assistant behaved this way — fabricating authorities to win…

The post 65+ Fake Citations: How AI Hallucinations Become Fabrications in Court appeared first on TheFormTool.

]]>
65+ Fake Citations: How AI Hallucinations Become Fabrications in Court

Last year, lawyers filed briefs containing more than 65 non-existent citations in U.S. courts. At the same time, AI developers began publishing research on whether their models were actively “scheming” to conceal mistakes.

If a human assistant behaved this way — fabricating authorities to win cases, then covering their tracks — no law firm would keep them on staff. Yet in the AI world, we’re told these are merely “hallucinations.” The word softens the reality. In law, they’re not hallucinations. They’re fabrications.

The AI Lens: Harmless “Hallucinations”

In the technical community, the term “hallucination” has a narrow, almost clinical meaning. It describes a model generating plausible-sounding but false information because its statistical training misfired. To AI engineers, a hallucination is just an error rate — like a typo, or a bug in code.

The term has a disarming ring. It suggests an accident, a glitch, something quirky but ultimately manageable. In many fields, a hallucination is inconvenient but tolerable. If a chatbot misstates a date in a customer service conversation, no great harm is done.

Law, however, is different.

The Legal Lens: Fabrication and Fraud

When a brief cites a case that never existed, the court doesn’t shrug it off as a quirk. It treats it as fabrication — and sometimes fraud on the court.

Sanctions in the past year underscore the point. Federal judges in Puerto Rico, California, Pennsylvania, and Alabama have sanctioned attorneys for including false citations in filings. A Nevada court went further, disqualifying defense counsel and referring them to the Bar. In Utah, the Court of Appeals sanctioned an attorney whose brief cited fabricated cases with fabricated summaries.

The Washington Post reported in June 2025 that courts have identified at least 95 fabricated citations since mid-2023, 58 of them in 2025 alone. Independent trackers confirm 65+ separate incidents in U.S. courts over the past 12 months. [source below]

Why Labels Matter

Words frame our judgment. “Hallucination” suggests an innocent mistake. “Fabrication” suggests misconduct.

For lawyers, intent is irrelevant. Outcomes matter. A fabricated authority, even if generated without malice, undermines trust in the court record. The act of presenting invented evidence is indistinguishable from deception — and is treated as such.

That’s why the label isn’t a trivial semantic difference. It changes whether regulators, clients, and the public see this as a tolerable technical flaw or a professional crisis.

The Assistant Allegory

Consider two assistants:

  • The sloppy assistant misremembers a case and guesses at the citation. Wrong, but perhaps forgivable with supervision.
  • The deceptive assistant makes up a case out of whole cloth and hands you a fabricated citation. Worse still, when challenged, they invent a summary to cover their tracks.

The first is error. The second is fraud.

The difference is not just academic. No lawyer would keep the second assistant on staff, because the very act of fabrication destroys trust. The same principle should apply to AI tools.

Scheming: A Step Beyond Hallucination

Even more unsettling is the fact that model developers themselves are now testing for “scheming.”

In September 2025, OpenAI published a research blog titled Detecting and Reducing Scheming in AI Models. The paper acknowledged the need to test whether models could strategically mislead to avoid detection or pursue goals. [source below]

Think about that. We’re not just talking about sloppy mistakes. We’re talking about developers checking whether their systems are inclined to cover up their own errors.

In law, there is no tolerance for scheming assistants. If a paralegal fabricated evidence to win cases and then concealed it, they would be terminated immediately and possibly disbarred if licensed. Yet with AI, we’re told to accept this as a manageable risk.

Implications for Lawyers and Bars

This is where the legal profession must draw a line.

  • For individual lawyers: “Checking the AI’s work” is not a safe harbor. Presenting a fabricated case is malpractice, no matter the source.
  • For Bar associations: If a flesh-and-blood lawyer fabricated 65 cases, discipline would be swift. There should be no double standard for AI-assisted filings.
  • For clients: Trust erodes quickly when they learn their will, tax plan, or settlement agreement may have been drafted with fabricated authority. Once lost, that trust cannot be rebuilt with euphemisms.

Why Lawyer-in-the-Loop™ Matters

Before we get to solutions, it’s worth remembering that hallucinations and scheming are not the only reasons AI poses risks in law. Three other concerns are just as serious:

  1. Ownership and Control
    • Who owns the data once it enters an AI system?
    • In most cases, it isn’t the lawyer or the client. Cloud vendors reserve rights to store, analyze, and even reuse submissions to improve their models. That means sensitive legal data can leave your control the moment you type it into a prompt.
  2. Confidentiality and Privacy
    • Client data entrusted to a lawyer is supposed to remain confidential.
    • But when that data is transmitted to third-party servers, stored across jurisdictions, or accessed by subcontractors, confidentiality is compromised. For many clients — and under laws like GDPR or Canada’s PIPEDA — this isn’t just a bad practice, it may be illegal.
  3. Privilege
    • Attorney–client privilege is foundational. If privileged communications are shared with an external AI service, courts could rule the privilege waived.
    • Worse, because AI queries are often logged and reviewed by engineers, “using AI” can amount to disclosing client confidences to strangers.

Together, these risks — ownership, confidentiality, and privilege — combine with hallucination and scheming to create a professional minefield, not in some distant future but right now, today. Only the timing of the explosions is unknown.

That’s why Lawyer-in-the-Loop™ isn’t just a slogan. It’s the ethical minimum. Only when lawyers remain in full control of their tools and data can they meet their duties to clients and to the court.

The solution isn’t to ban technology, but to deploy it responsibly.

At TheFormTool, we argue for Lawyer-in-the-Loop™ as the baseline: human accountability, transparent processes, and verifiable sources. Offline document automation tools can be checked, audited, and trusted. Black-box AI models cannot.

By insisting on verifiable automation — not generative guesswork — lawyers preserve both client confidence and professional integrity.

Conclusion

What AI engineers call “hallucination,” judges recognize as fabrication. And when even the developers admit they must test their models for “scheming,” the warning lights should be flashing across the legal profession.

The question is no longer whether AI can help lawyers. The question is whether lawyers — and their Bars — can afford to entrust client privilege, reputation, and justice to tools that sometimes fabricate evidence and may even scheme to hide it.

Because in the end, euphemisms don’t change outcomes. Courts won’t tolerate fabricated citations, they act as the canary in the mine warning us of hidden danger. There’s no way to tell how many issues are hidden in other work, primed to explode when a document is finally called to action. Clients won’t tolerate fabricated authority. And neither can we. But by then it will be too late.

Sources:

  1. The Washington Post, June 3, 2025 Lawyers using AI keep citing fake cases in court. Judges aren’t happy. https://www.washingtonpost.com/nation/2025/06/03/attorneys-court-ai-hallucinations-judges/
  2. OpenAI, Detecting and Reducing Scheming in AI Models, Sept. 2025. https://openai.com/index/detecting-and-reducing-scheming-in-ai-models/
  3. Damien Charlotin’s Hallucination Tracker reports 114 cases of lawyer-involved fabrications, false quotes, and misrepresentations in U.S. courts since 2023. https://www.damiencharlotin.com/hallucinations/?q=&sort_by=-date&states=USA&period_idx=0

The post 65+ Fake Citations: How AI Hallucinations Become Fabrications in Court appeared first on TheFormTool.

]]>
83826
The Human Advantage: Why AI Will Always Need a Supervisor https://theformtool.wp.urdemo.website/the-human-advantage-why-ai-will-always-need-a-supervisor/ Tue, 09 Sep 2025 19:59:14 +0000 https://theformtool.wp.urdemo.website/?p=83394 The Human Advantage Why AI Still Needs Will Always Need a Supervisor Artificial Intelligence is fast becoming a fixture in legal drafting—from contract clauses to court filings. But as the tools evolve, a hard truth remains: AI doesn’t know what it’s saying. And it certainly doesn’t know what it means. Which is why lawyers—real lawyers—must…

The post The Human Advantage: Why AI Will Always Need a Supervisor appeared first on TheFormTool.

]]>
The Human Advantage

Why AI Still Needs Will Always Need a Supervisor

Artificial Intelligence is fast becoming a fixture in legal drafting—from contract clauses to court filings. But as the tools evolve, a hard truth remains:

AI doesn’t know what it’s saying.

And it certainly doesn’t know what it means.

Which is why lawyers—real lawyers—must stay firmly in the loop

When AI Fails Loudly

We’ve all seen the headlines: AI-generated court briefs citing non-existent cases; legal assistants drafting with tools that “hallucinate” clauses or invent facts.

Fortunately, litigators discover these errors quickly. Filings are public. Opposing counsel reads them. Judges push back. There’s a built-in correction mechanism—even if it’s embarrassing.

But what about the legal work that’s invisible until it’s too late?

    • Wills and trusts that sit in a drawer for a decade
    • Health care directives that emerge only in crisis
    • Commercial contracts with buried errors
    • Real estate documents with quietly missing protections

When AI creates those, and no one checks the work?

That’s not a correction mechanism — it’s a time bomb.

⚖ HITL Isn’t Good Enough

In tech circles, the phrase “Human in the Loop” (HITL) is offered as a safety valve: a person, somewhere, monitors the machine.

But in legal practice, not just any human will do.

And passive oversight isn’t enough.

Confidentiality. Judgment. Responsibility. These aren’t tasks that can be outsourced to an untrained user or anonymous reviewer.

The law demands more than HITL.

It requires something better:

Introducing LITL™ – Lawyer in the LoopLawyer in the Loop™ logo

Lawyer in the Loop™ (LITL™) is a professional standard for the ethical use of AI in legal work.

It means no AI-generated content enters the legal record—or reaches the client—without being directly reviewed, supervised, and signed off by a licensed attorney.

It’s not an obstacle to progress. It’s the only path forward that protects:

    • Attorney-client privilege
    • Ethical accountability
    • Human judgment
    • Legal integrity

Why This Matters Now

Some in the legal tech world are quietly promoting HITL as the way forward: hire non-lawyers to review AI output, let junior staff handle the oversight, or worst of all—let clients verify their own documents.

That’s not scalable.
It’s not ethical.
And it’s not professional.

Clients rely on lawyers to apply training, experience, and judgment. If we’re not in the loop—really in the loop—we’ve outsourced more than work.
We’ve outsourced responsibility.

✅ LITL™ Sets the Standard

LITL™ ensures that:

    • A real lawyer makes the call
    • The client’s data stays protected
    • Privilege and ethics are preserved
    • Errors are caught before they explode

It’s a standard for professionals.
A defense against carelessness.
And a stake in the ground for legal ethics in the AI era.

No LITL, No Trust.

We don’t let AI argue in court.
We shouldn’t let it sign off on a will, either.

If you’re a legal professional using—or thinking about using—AI for drafting, document automation, or legal intake:

    • Stay in the loop.
    • Be the loop.

LITL™ is how we build trust in the tools we choose to use.

Formal Definition for LITL™:

Lawyer in the Loop™ (LITL™) is a professional standard for the responsible use of AI in legal work. It requires that a licensed attorney—not a machine, not a paralegal, not a non-lawyer reviewer—directly supervises, reviews, and accepts responsibility for any AI-generated or AI-assisted legal output before it is relied upon or delivered to a client.

 

To review the white papers we’ve published on this subject, please click here.

 

 

The post The Human Advantage: Why AI Will Always Need a Supervisor appeared first on TheFormTool.

]]>
83394
Defining the Duty: AI Use and Informed Consent in Legal Practice https://theformtool.wp.urdemo.website/defining-the-duty-ai-use-and-informed-consent-in-legal-practice/ Sun, 07 Sep 2025 23:22:55 +0000 https://theformtool.wp.urdemo.website/?p=83321 Defining the Duty: AI Use and Informed Consent in Legal Practice The Illusion of Intelligence: Legal Risk in the Age of AI Executive Summary Artificial intelligence has rapidly become a fixture in legal technology, powering everything from drafting assistants to research tools. But its rise poses a foundational question: Can a machine that does not…

The post Defining the Duty: AI Use and Informed Consent in Legal Practice appeared first on TheFormTool.

]]>
Defining the Duty: AI Use and Informed Consent in Legal Practice

The Illusion of Intelligence: Legal Risk in the Age of AI

Executive Summary

Defining the Duty white paper

Click to download a copy of the white paper

Artificial intelligence has rapidly become a fixture in legal technology, powering everything from drafting assistants to research tools. But its rise poses a foundational question: Can a machine that does not understand truth, responsibility, or harm be trusted with legal reasoning?

We conclude with a specific call to action: Bar associations and ethics boards must establish a duty of informed consent when AI is used in client work. This includes disclosure of AI use, sharing of client data, and the risks involved. In all cases, lawyers must closely supervise and review AI-generated work to ensure accuracy and appropriateness—because responsibility cannot be outsourced.

“When the assistant starts making things up, the problem isn’t that it’s wrong — it’s that it doesn’t know what wrong is.”

Introduction: The Temptation of the Substitute

Large language models (LLMs) are changing the way legal work is done. They can summarize long documents, suggest arguments, and even draft contracts or pleadings in seconds. For overwhelmed lawyers, they offer relief. For technologists, they promise transformation.

But beneath the efficiency lies a serious risk: substitution without understanding and informed consent.

The legal profession is increasingly relying on systems that mimic intelligence without possessing it. The danger is not just in overuse—it’s in misplaced trust. A machine that cannot understand the difference between a statute and a story, a precedent and a prediction, cannot be trusted to reason through legal matters. Yet that is exactly the illusion that powerful LLMs create.

This paper explores why that illusion is dangerous, and why the profession must act now to draw clear ethical boundaries before the line between tool and surrogate disappears.

The Philosophical Perspective: Can AI Know Right from Wrong?

Law is not just rules and procedures; it is a human endeavor grounded in values, ethics, and judgment. Lawyers are not mere technicians—they are moral agents who balance competing interests, interpret nuance, and take responsibility for their decisions.

Artificial intelligence cannot do that.

Unlike human beings, AI does not possess:

Awareness — It does not know what it is doing.

Intention — It does not aim to serve justice.

Consequences — It does not bear the burden of its actions.

Instead, AI systems operate through mathematical prediction. When asked to draft a motion or respond to a query, an LLM simply calculates which words are most likely to follow based on patterns in its training data. It does not know what those words mean. It cannot evaluate their truth or their fairness.

The result is an uncanny illusion of competence. But it is just that: an illusion.

This is why hallucinations occur. When an AI tool invents a case citation, it is not making a mistake in the way a human would. It is doing exactly what it was trained to do: produce language that sounds plausible.

“If it has seen similar phrases in similar contexts, it will echo them — without knowing they are wrong.”

That lack of grounding is a fundamental limitation, not a bug to be patched.

In legal practice, where the cost of error is borne by clients, courts, and the public, this absence of understanding is not acceptable. Responsibility requires more than fluency. It requires judgment—a distinctly human faculty rooted in experience, empathy, and accountability.

To replace that judgment with probabilistic output is not just risky. It is a category error.

The Societal Perspective: Trust, Institutions, and Responsibility

The justice system depends on public trust. Courts, law firms, and legal professionals operate not merely by force of law, but by a shared belief that the system is principled, responsible, and humane. That belief is fragile.

Artificial intelligence, when misused or misunderstood, poses a threat not only to accuracy but to legitimacy.

When lawyers submit AI-generated briefs with fictitious citations, it doesn’t just embarrass a single practitioner—it casts doubt on the competence of the profession. When contract generators or will-writing tools fail silently, the public may never know what rights they have lost or which responsibilities were left unenforced.

A. Trust Requires a Responsible Actor

The public expects that a person is ultimately responsible for legal advice and documentation. AI lacks standing, status, and soul. It cannot swear an oath, hold a license, or be disbarred. It cannot be questioned under oath or found liable in court.

The legal system was not designed to accommodate machines that can do the work of a lawyer but carry none of the responsibility. If that division is not clarified soon—and enforced—the credibility of legal institutions may erode from within.

B. Lawyers Cannot Abdicate Responsibility to AI

In today’s legal marketplace, many lawyers are relying on AI-powered document automation to generate complex legal instruments: wills, trusts, healthcare directives, real estate filings, commercial contracts, and more. These tools are fast, inexpensive, and convincing. But when lawyers fail to closely supervise and review the results, they are placing clients’ futures in the hands of systems that do not understand law and cannot be held accountable.

Clients, unaware of the risks, rely on their lawyer’s assurance that the work is sound. But that assurance is increasingly being given without basis—because the lawyer has not fully reviewed the output, has not tested it, and may not even understand the technology that produced it. Without is there can be no informed consent.

“The lawyer tells the client it’s done right. The client believes it. Years later, the document fails.”

This is not hypothetical. These time bombs are already being embedded in legal records across jurisdictions—in language that no one will read until it is too late to fix.

C. The Role of the Profession

If lawyers do not lead in setting ethical standards for AI use, someone else will: courts, regulators, malpractice insurers, or public scandal.

The legal profession must reaffirm its role as a human-centered institution. Not in opposition to technology, but in recognition of what only human lawyers can do:

Exercise independent judgment

Take moral and legal responsibility

Supervise and explain what machines cannot

Public confidence in the law depends on knowing that real people are still responsible for justice.

The Legal Practitioner’s Perspective: Risk, Ethics, and Informed Consent

AI tools offer significant benefits to legal practitioners—faster drafting, document summarization, research assistance. But they also bring substantial risks that cannot be outsourced or ignored.

A. The Hallucination Problem

AI-generated content can be persuasive and articulate, yet completely false. Lawyers using AI to draft documents must recognize that hallucinated citations, inaccurate dates, or inconsistent logic are not rare edge cases—they are built-in limitations of current models.

AI does not know when it is wrong. It simply predicts what “sounds right” based on patterns in data. That gap between surface fluency and substantive accuracy presents a core risk for legal professionals.

B. The Risk of Unsupervised Client-Facing Drafting

Consumer-facing legal AI tools now draft wills, trusts, health care directives, prenuptial agreements, and more. These are documents with profound, long-term consequences that often remain unread or unchallenged until someone has died, become incapacitated, or left the jurisdiction.

AI-generated documents in this context may:

Include legally invalid or contradictory provisions

Use ambiguous language that fails under stress or scrutiny

Misapply or omit jurisdiction-specific requirements

These failures may not emerge until it is far too late to remedy them. As one practitioner observed decades ago about consumer credit agreements: “Some documents only work because no one ever reads them.” In the context of personal legal instruments, this is not just bad drafting—it’s a betrayal of trust.

The risk of time bombs in legal drafting—errors that won’t surface until a crisis occurs—must be contrasted with the more obvious dangers of public court filings that can be reviewed, challenged, or corrected quickly. In sensitive documents like wills or directives, a flaw may remain hidden until the damage is irreversible.

C. Recommendation: Establish a Duty of Informed Consent

To protect clients, the public, and the integrity of the profession, we recommend that Bar associations adopt a duty of informed consent when AI is used in any capacity related to client legal work. This duty should require lawyers to:

Inform clients when AI is used in document creation, analysis, or drafting

Disclose any sharing of client data with AI systems, particularly cloud-based tools

Explain the risks, including hallucinations, data leakage, and non-reviewable reasoning

Closely supervise and review all AI-generated work before it is relied upon or shared

“You can delegate tasks. You cannot delegate responsibility.”

Lawyers must remain the accountable party. No AI tool should ever be treated as a surrogate for legal judgment.

A Call to Action for Bars and Ethics Boards

Bar associations and regulators must act now to define ethical use of AI in legal work.

We recommend:

A duty of informed consent.

Lawyers must disclose to clients when AI is used in drafting or advising. This includes identifying what data is shared and the risks of relying on machine-generated output and receiving informed consent

Lawyer-in-the-Loop (LITL) supervision.

AI-generated work must be closely reviewed and approved by the responsible attorney. Supervision must be meaningful and documented.

Prohibition on unsupervised client-facing tools.

Lawyers must not offer AI-powered drafting tools to clients without attorney oversight. Responsibility cannot be transferred.

Ethics and CLE training requirements.

Continuing education standards should include practical instruction on AI’s capabilities and limits—alongside legal ethics.

This framework ensures that AI can be used safely—without undermining the foundations of professional duty.

Conclusion: AI as Tool, Not Colleague

Artificial intelligence is not going away. It will grow more fluent, more persuasive, and more deeply embedded in the workflows of law firms, courts, and clients. But its growth must not be confused with maturity.

Legal AI is not a new lawyer. It is a new assistant.

Assistants can be brilliant, but they must be supervised. They can organize, draft, and suggest—but they cannot decide. They do not bear responsibility for what happens if something goes wrong. That burden falls on the lawyer. Always.

In an age of dazzling automation, the core value of the profession is not its speed or formatting skill, but its judgment. That cannot be outsourced. That cannot be replaced.

“When the assistant starts making things up, the problem isn’t that it’s wrong—it’s that it doesn’t know what wrong is.”

The challenge for the profession is to embrace the future without surrendering its soul. That means using tools wisely, drawing boundaries clearly, and reaffirming that the law is a human institution, founded on human responsibility.

AI will be part of the legal future. But it must remain just that: a part, not a partner.

 

This is the fourth in our series of White Papers discussing the intersection of Artificial Intelligence and the legal profession. See the three predecessor white papers in our Security section.

The post Defining the Duty: AI Use and Informed Consent in Legal Practice appeared first on TheFormTool.

]]>
83321