L
Luminos.AI

Luminos.AI is a Washington, DC company, founded in 2023 by Andrew Burt and Mike Schiller, that sells an AI governance and evaluation platform to legal, privacy and AI governance teams and the engineers they work with. Its evaluations, built by the company's lawyers and data scientists, test a customer's classical models, generative AI and agents against specific legal standards such as EEOC and state hiring rules, GDPR, CCPA, the EU AI Act, HIPAA and the FTC Act.

They run inside the platform or through an API in a customer's build pipeline, run again when a model changes, and generate documentation that can be kept under legal privilege. Approval workflows clear systems of low risk automatically and send riskier ones to in house legal or outside counsel. A partnership with the law firm ZwillGen adds a governance package of policies and a library of impact assessment forms written by ZwillGen attorneys. The company grew out of Luminos.Law, a law firm focused on AI risk.

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

BB on AI CentralityThe models are the engine of a core capability, layered on a product that would still function without them as a document or workflow system.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The evaluation engine is the headline product, beside workflows that would run without it. Luminos Evals send test probes to a customer's model and score the results against encoded legal standards, for classical models, generative AI and agents, and run again when a model changes. Around them sit approval workflows, a library of assessment forms written by outside counsel, and documentation generation, which work as software whether or not an eval runs.

Source: Vendor Published
CC on Citation Accuracy and Hallucination DisclosureAccuracy is asserted without measurement, or grounding is claimed while output cites sources the reader cannot open and verify.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Each test is tied to a named legal standard, and how often the tests are right is not published. The vendor says every eval maps a regulatory standard such as EEOC rules, GDPR, the EU AI Act, HIPAA or the CCPA to concrete system behaviors, uses statistical tests approved by regulators for classical models, and produces a structured result with a traceable chain of evidence. No false positive or false negative rate, validation study or sample of results is published, for a product whose findings clear most AI systems for release without human review.

Source: Vendor Published
AA on Autonomy and Oversight ModelWhat the system runs alone, what constrains it, and how a lawyer checks it are all published: modes, thresholds, review surfaces, and the route a matter takes back to human judgment. A categorical limit on a named mode or tier, stating what its output may not be used for, meets the threshold limb without a number.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

The levels of automation and the points where people decide are published. Evals run automatically and run again when a model is updated, drifts or appears in a new context. Workflows route by risk: systems of low risk are documented with no review, those of medium risk go to in house legal, and those of high risk escalate to outside counsel, with a review queue showing which provisions were flagged and which cleared.

The vendor states that only work of genuinely high risk routes to people and says about 90 percent of approvals are automated, so a buyer should confirm where its own thresholds sit.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

One named customer, without measured results. Red Ventures is named, with quotes from its chief privacy and AI governance officer and its head of product, neither identified by name. An unnamed customer's data scientist says a 3 to 6 month approval process became 3 to 6 days, and the use case pages describe outcomes such as zero regulatory investigations without naming the customers or giving a method. The vendor is also the first certified under the Ethical Tech Project's Applied AI Governance Certification.

Source: Vendor Published
BB on Privilege and Confidentiality PostureSubstantive published commitments on confidentiality and training use, short of the full picture: commonly silence on segregation between users or matters, or on what the underlying model provider may retain.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

Privilege is addressed directly, and the handling of customer data is not. Customers can assert attorney client privilege and work product protection over any test, evaluation or workflow, turned on per test, so documenting a risk need not create new exposure, and workflows can assign tasks to roles while keeping information confidential. Evals need no access to the model itself. What is not published is any term on how the data a customer points the platform at is used, kept or deleted, and the published site terms are silent on training.

Source: Vendor Published
CC on UPL and Professional Responsibility PostureA boilerplate disclaimer sits in the terms while the marketing describes the product in advice terms, or the intended audience is left ambiguous.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.

Legal conclusions reach people who are not lawyers, and nothing says what the platform is or is not. Eval results mark a system as passing or flagged under laws such as the FTC Act, and they go to data science, product and security teams as well as to legal. Legal advice in the product is attributed to the law firm ZwillGen, and risky findings can be escalated to outside counsel, but no statement on the site or in the site terms says whether Luminos gives legal advice or who may rely on a result.

Source: Vendor Published
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

AI Governance and Bias Disclosure

Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

The vendor governs other companies' AI and says little about governing its own. Evals are written by a legal engineering team of lawyers and data scientists, are versioned, and are aligned with the NIST AI Risk Management Framework, and the platform is certified by the Ethical Tech Project for delivering AI governance. Nothing describes how Luminos tests its own evals for accuracy or bias, who is accountable when an eval clears a system that later causes harm, or what results that testing produced.

Source: Vendor Published
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

A general security page and privacy notice cover the platform without addressing what happens to the data evals run on. The security page describes encryption in transit and at rest, access restricted to authorized personnel, dependency scanning and continuous monitoring, and the privacy notice says Luminos acts as a processor for customer data. No retention period, deletion commitment, subprocessor list or incident notification term is published.

Source: Vendor Published
CC on AI Liability and RecourseLiability is addressed only through a standard limitation clause that disclaims the exposure the product creates.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

Only standard limits are published. The site terms, last updated April 16, 2024, exclude indirect and consequential damages, cap total liability at what the user paid for access to the website, and require the user to indemnify Luminos for use of the services. They note that a signed agreement governs where one exists, and no customer agreement is published, so nothing addresses an eval that clears a system that later breaks the law.

Source: Vendor Published
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

An API is documented by example and named systems are not. Evals run in the platform or through an API inside a customer's CI/CD, MLOps or testing infrastructure, and the platform page shows a Python client configuring evals against a model endpoint with a version and jurisdiction. The vendor says it integrates with workflow, ticketing and document tools but names none, and publishes no API reference.

Source: Vendor Published
CC on Deployment Model and Data ResidencyCloud delivery is implied and neither the tenancy model nor the region is stated.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Cloud delivery is described and location is not. The security page says the infrastructure is hosted on secure platforms using serverless systems and network segmentation, and the privacy notice covers transfers under the Data Privacy Framework. No hosting provider, region or tenancy option is named.

Source: Vendor Published
DD on Security Certifications and Trust CenterNo independent security attestation located.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

No independent security attestation is claimed. The security page says the company's practices align with frameworks such as GDPR, HIPAA and SOC 2, which describes alignment rather than a completed audit, and there is no trust center or report on offer.

Source: Vendor Published
CC on Model Supply Chain DisclosureThe vendor refers to advanced or proprietary models without identifying what sits underneath.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The platform tests other companies' models and says nothing about its own. Evals are described as automated tests and statistical methods, but the vendor does not say whether language models score the results, which ones, or where they run, and nothing commits to notice of change.

Source: Vendor Published
DD on Commercial TransparencyNo pricing information published at any level, including the unit of charge.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

No pricing is published. The site says there is no big setup fee and that the ZwillGen form library can be bought whole or form by form, but gives no price, tier or unit of charge, and every route leads to a demo or a request to run a first eval.

Source: Vendor Published
BB on Firm and Practice CoverageSegment and practice coverage is described with substance, short of the boundaries: what is supported is clear, what is not is left open.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is described with substance, short of stated limits. The platform evaluates classical models, generative AI and agents, with a library covering more than 20 regulatory frameworks including EEOC rules, New York City, Illinois and California hiring laws, GDPR, CCPA, the EU AI Act, the Colorado AI Act and HIPAA, and use cases such as hiring tools and chatbots that face customers. It does not say which jurisdictions or laws are outside the library.

Source: Vendor Published
Sources on file

7 public documents

The public pages on file for Luminos.AI, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Terms silent

A published agreement or policy exists and none of it addresses the question either way, or the document that would answer it could not be read and the summary names the retrieval limit. The summary states which shape the silence takes: an improvement right granted that never names training, or no improvement right granted at all.

The published terms never mention training. The site terms, last updated April 16, 2024, grant Luminos a broad, perpetual and sublicensable license over content users post in the service's interactive areas, without naming model training, and it is unclear whether that reaches material submitted for evaluation. The customer agreement is signed separately and not published, and neither the privacy notice nor the security page states a position on training. Checked 27 September 2026.

Source: Vendor Publishedfully sublicensable right to use, reproduce, modifyAs of Sep 27, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

No public material states how long evaluation data, model outputs or results are kept. Checked 27 September 2026.

Source: Vendor PublishedAs of Sep 27, 2026Evidence

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Claimed, not documented

Segregation is asserted in public materials with no published detail on how it is enforced.

Separation is asserted and not documented. Workflows assign tasks to roles or users while keeping information confidential, and the platform describes role based visibility, but nothing explains how access is enforced across teams or systems. Checked 27 September 2026.

Source: Vendor Publishedkeeping that information confidentialAs of Sep 27, 2026Evidence

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Disclosure addressed, notice absent

Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.

Disclosure is allowed with no promise of notice. The privacy notice says Luminos may be required to disclose personal data in response to lawful requests by public authorities, including for national security or law enforcement, and does not commit to telling the customer. The site terms say nothing on the subject. Checked 27 September 2026.

Source: Vendor Publishedwe may be required to disclose personal data that we receive under the DPF in response to lawful requests by public authoritiesAs of Sep 27, 2026Evidence
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Sources named, basis unstated

Sources are identified without stating the license or rights basis.

The law behind the tests is named, without a rights basis or an update schedule. Each eval maps a named standard such as EEOC rules, GDPR, the EU AI Act, HIPAA or the CCPA to system behaviors, and the ZwillGen forms cover laws such as the EU AI Act and the Colorado AI Act. The vendor says the tests are continuously updated as laws and enforcement change, but gives no cadence. Checked 27 September 2026.

Source: Vendor PublishedEach Eval maps a regulatory standardAs of Sep 27, 2026Evidence

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

The product cites no case law. The nearest practice is the vendor's statement that it updates what it tests for as laws and enforcement evolve, which is not a check on subsequent history. Checked 27 September 2026.

Source: Vendor PublishedAs of Sep 27, 2026Evidence

Refusal and Uncertainty Behavior

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Results are routed by risk level, not by the evaluation's own confidence. Nothing public describes what an eval does when it cannot reach a result or is unsure whether a behavior breaks a standard. Checked 27 September 2026.

Source: Vendor PublishedAs of Sep 27, 2026Evidence

Fabricated Citation Record

Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?

None located

No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.

No court order, opinion or regulatory action involving results produced by Luminos.AI was located as of 27 September 2026.

Source: Vendor PublishedAs of Sep 27, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

No bar or ethics guidance is engaged. The vendor aligns its evals with the NIST AI Risk Management Framework and tests customers' chatbots for unauthorized professional advice, but no rule of professional conduct or ethics opinion on lawyers' own use of the platform is named. Checked 27 September 2026.

Source: Vendor PublishedAs of Sep 27, 2026Evidence

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Outside the fee relationship

The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.

The product is bought by in house legal, privacy and governance teams that bill no client for the work. Its savings claims concern the buyer's own approval time and when to spend on outside counsel. Checked 27 September 2026.

Source: Vendor PublishedAs of Sep 27, 2026Evidence

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Not addressed

No located public material supports a client side disclosure obligation.

No subprocessor or model provider list, security report or disclosure material for clients is published. Checked 27 September 2026.

Source: Vendor PublishedAs of Sep 27, 2026Evidence

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Each evaluation produces a document, which records the customer's AI rather than the platform's. Every run is versioned, tied to the model checkpoint it tested, and exported as documentation meant to support regulatory inquiries and litigation defense, and it can be kept under privilege. It does not identify which models, if any, Luminos used to score the results. Checked 27 September 2026.

Source: Vendor PublishedEvery run is versioned and tied to the model checkpoint it evaluated.As of Sep 27, 2026Evidence
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 303 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
October 7, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746