L
Luminos.AI
Luminos.AI is a Washington, DC company, founded in 2023 by Andrew Burt and Mike Schiller, that sells an AI governance and evaluation platform to legal, privacy and AI governance teams and the engineers they work with. Its evaluations, built by the company's lawyers and data scientists, test a customer's classical models, generative AI and agents against specific legal standards such as EEOC and state hiring rules, GDPR, CCPA, the EU AI Act, HIPAA and the FTC Act.
They run inside the platform or through an API in a customer's build pipeline, run again when a model changes, and generate documentation that can be kept under legal privilege. Approval workflows clear systems of low risk automatically and send riskier ones to in house legal or outside counsel. A partnership with the law firm ZwillGen adds a governance package of policies and a library of impact assessment forms written by ZwillGen attorneys. The company grew out of Luminos.Law, a law firm focused on AI risk.
Capability grades
All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The evaluation engine is the headline product, beside workflows that would run without it. Luminos Evals send test probes to a customer's model and score the results against encoded legal standards, for classical models, generative AI and agents, and run again when a model changes. Around them sit approval workflows, a library of assessment forms written by outside counsel, and documentation generation, which work as software whether or not an eval runs.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Each test is tied to a named legal standard, and how often the tests are right is not published. The vendor says every eval maps a regulatory standard such as EEOC rules, GDPR, the EU AI Act, HIPAA or the CCPA to concrete system behaviors, uses statistical tests approved by regulators for classical models, and produces a structured result with a traceable chain of evidence. No false positive or false negative rate, validation study or sample of results is published, for a product whose findings clear most AI systems for release without human review.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The levels of automation and the points where people decide are published. Evals run automatically and run again when a model is updated, drifts or appears in a new context. Workflows route by risk: systems of low risk are documented with no review, those of medium risk go to in house legal, and those of high risk escalate to outside counsel, with a review queue showing which provisions were flagged and which cleared.
The vendor states that only work of genuinely high risk routes to people and says about 90 percent of approvals are automated, so a buyer should confirm where its own thresholds sit.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
One named customer, without measured results. Red Ventures is named, with quotes from its chief privacy and AI governance officer and its head of product, neither identified by name. An unnamed customer's data scientist says a 3 to 6 month approval process became 3 to 6 days, and the use case pages describe outcomes such as zero regulatory investigations without naming the customers or giving a method. The vendor is also the first certified under the Ethical Tech Project's Applied AI Governance Certification.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Privilege is addressed directly, and the handling of customer data is not. Customers can assert attorney client privilege and work product protection over any test, evaluation or workflow, turned on per test, so documenting a risk need not create new exposure, and workflows can assign tasks to roles while keeping information confidential. Evals need no access to the model itself. What is not published is any term on how the data a customer points the platform at is used, kept or deleted, and the published site terms are silent on training.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
Legal conclusions reach people who are not lawyers, and nothing says what the platform is or is not. Eval results mark a system as passing or flagged under laws such as the FTC Act, and they go to data science, product and security teams as well as to legal. Legal advice in the product is attributed to the law firm ZwillGen, and risky findings can be escalated to outside counsel, but no statement on the site or in the site terms says whether Luminos gives legal advice or who may rely on a result.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
The vendor governs other companies' AI and says little about governing its own. Evals are written by a legal engineering team of lawyers and data scientists, are versioned, and are aligned with the NIST AI Risk Management Framework, and the platform is certified by the Ethical Tech Project for delivering AI governance. Nothing describes how Luminos tests its own evals for accuracy or bias, who is accountable when an eval clears a system that later causes harm, or what results that testing produced.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
A general security page and privacy notice cover the platform without addressing what happens to the data evals run on. The security page describes encryption in transit and at rest, access restricted to authorized personnel, dependency scanning and continuous monitoring, and the privacy notice says Luminos acts as a processor for customer data. No retention period, deletion commitment, subprocessor list or incident notification term is published.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Only standard limits are published. The site terms, last updated April 16, 2024, exclude indirect and consequential damages, cap total liability at what the user paid for access to the website, and require the user to indemnify Luminos for use of the services. They note that a signed agreement governs where one exists, and no customer agreement is published, so nothing addresses an eval that clears a system that later breaks the law.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
An API is documented by example and named systems are not. Evals run in the platform or through an API inside a customer's CI/CD, MLOps or testing infrastructure, and the platform page shows a Python client configuring evals against a model endpoint with a version and jurisdiction. The vendor says it integrates with workflow, ticketing and document tools but names none, and publishes no API reference.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is described and location is not. The security page says the infrastructure is hosted on secure platforms using serverless systems and network segmentation, and the privacy notice covers transfers under the Data Privacy Framework. No hosting provider, region or tenancy option is named.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
No independent security attestation is claimed. The security page says the company's practices align with frameworks such as GDPR, HIPAA and SOC 2, which describes alignment rather than a completed audit, and there is no trust center or report on offer.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The platform tests other companies' models and says nothing about its own. Evals are described as automated tests and statistical methods, but the vendor does not say whether language models score the results, which ones, or where they run, and nothing commits to notice of change.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing is published. The site says there is no big setup fee and that the ZwillGen form library can be bought whole or form by form, but gives no price, tier or unit of charge, and every route leads to a demo or a request to run a first eval.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Coverage is described with substance, short of stated limits. The platform evaluates classical models, generative AI and agents, with a library covering more than 20 regulatory frameworks including EEOC rules, New York City, Illinois and California hiring laws, GDPR, CCPA, the EU AI Act, the Colorado AI Act and HIPAA, and use cases such as hiring tools and chatbots that face customers. It does not say which jurisdictions or laws are outside the library.
7 public documents
The public pages on file for Luminos.AI, with the recorded signals each one supports and the date it was last read. Open any of them and check the reading against the record.
-
luminos.ai/platform3 signals
Primary Law Corpus Provenance, Refusal and Uncertainty Behavior, Court Disclosure Support
Read Sep 27, 2026
-
luminos.ai/faq2 signals
Good Law Verification, Bar Guidance Alignment
Read Sep 27, 2026
-
luminos.ai/privacy2 signals
Prompt and Output Retention, Third Party Request and Subpoena Notice
Read Sep 27, 2026
-
Ethical Walls and Matter Segregation
Read Sep 27, 2026
-
Billing and Fee Posture
Read Sep 27, 2026
-
luminos.ai/security1 signal
Outside Counsel Guideline Readiness
Read Sep 27, 2026
-
luminos.ai/terms1 signal
Client Data in Training
Read Sep 27, 2026
Legal Signals
What each signal meansA signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
A published agreement or policy exists and none of it addresses the question either way, or the document that would answer it could not be read and the summary names the retrieval limit. The summary states which shape the silence takes: an improvement right granted that never names training, or no improvement right granted at all.
The published terms never mention training. The site terms, last updated April 16, 2024, grant Luminos a broad, perpetual and sublicensable license over content users post in the service's interactive areas, without naming model training, and it is unclear whether that reaches material submitted for evaluation. The customer agreement is signed separately and not published, and neither the privacy notice nor the security page states a position on training. Checked 27 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained.
No public material states how long evaluation data, model outputs or results are kept. Checked 27 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Segregation is asserted in public materials with no published detail on how it is enforced.
Separation is asserted and not documented. Workflows assign tasks to roles or users while keeping information confidential, and the platform describes role based visibility, but nothing explains how access is enforced across teams or systems. Checked 27 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
Published terms or policy address disclosure to authorities or in response to legal process, and no commitment or reservation regarding customer notice is located anywhere. The vendor has told the customer that data can leave and has said nothing about whether the customer hears of it.
Disclosure is allowed with no promise of notice. The privacy notice says Luminos may be required to disclose personal data in response to lawful requests by public authorities, including for national security or law enforcement, and does not commit to telling the customer. The site terms say nothing on the subject. Checked 27 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
Sources are identified without stating the license or rights basis.
The law behind the tests is named, without a rights basis or an update schedule. Each eval maps a named standard such as EEOC rules, GDPR, the EU AI Act, HIPAA or the CCPA to system behaviors, and the ZwillGen forms cover laws such as the EU AI Act and the Colorado AI Act. The vendor says the tests are continuously updated as laws and enforcement change, but gives no cadence. Checked 27 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history.
The product cites no case law. The nearest practice is the vendor's statement that it updates what it tests for as laws and enforcement evolve, which is not a check on subsequent history. Checked 27 September 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located public material addresses what the product does when it cannot ground an answer.
Results are routed by risk level, not by the evaluation's own confidence. Nothing public describes what an eval does when it cannot reach a result or is unsure whether a behavior breaks a standard. Checked 27 September 2026.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record addressing fabricated or hallucinated legal citations produced by this product has been located as of the date shown. This is a statement about the public record on that one subject, not a finding about the product, and this signal is not a litigation history.
No court order, opinion or regulatory action involving results produced by Luminos.AI was located as of 27 September 2026.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance.
No bar or ethics guidance is engaged. The vendor aligns its evals with the NIST AI Risk Management Framework and tests customers' chatbots for unauthorized professional advice, but no rule of professional conduct or ethics opinion on lawyers' own use of the platform is named. Checked 27 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product does not touch a fee between a lawyer and a client. It operates before an engagement exists, or it is bought by a team that bills no client for the work. Savings claims aimed at the buyer’s own cost are recorded in the summary and do not make the row a savings claim, because no client bill is in the loop.
The product is bought by in house legal, privacy and governance teams that bill no client for the work. Its savings claims concern the buyer's own approval time and when to spend on outside counsel. Checked 27 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
No located public material supports a client side disclosure obligation.
No subprocessor or model provider list, security report or disclosure material for clients is published. Checked 27 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Some elements of the record are available, short of a document level export.
Each evaluation produces a document, which records the customer's AI rather than the platform's. Every run is versioned, tied to the model checkpoint it tested, and exported as documentation meant to support regulatory inquiries and litigation defense, and it can be kept under privilege. It does not identify which models, if any, Luminos used to score the results. Checked 27 September 2026.