Onspring

No code governance, risk and compliance platform used to build and run GRC programs without developer involvement, spanning risk management, regulatory change management, internal audit, policy management and authoring, control and framework mapping, third party and vendor risk, IT risk, ESG assessment, and business continuity and recovery. Business users configure applications, workflows, surveys, dashboards and reports through the interface rather than through code. Governance frameworks including ISO, NIST and CMMC are supported and mapped to controls. Onspring publishes a separate Corporate Counsel solution for in house legal departments covering legal request intake, matter and task tracking, legal opinions and research, a clause library holding liability, confidentiality, agreement and property management clauses that can be reused across contracts, relation of contracts, policies and clauses to business units and regulations, scheduled recurring review of regulations and clauses, and legal cost and budget tracking. The AI layer is Onspring AI, launched October 2025 as an optional add on module and extended in July 2026 into agentic operation. It is powered by Anthropic's Claude family of models and operates under the oversight of an internal AI governance council. Capabilities include generating and revising long form field content, predictive thought completion, record creation from prompts, surfacing relevant links between controls, employee roles and regulatory requirements, duplicate record detection, and reading and summarising documents such as SOC 2 reports to populate fields. The July 2026 release allows administrators to define rules that prompt agent action, with an assistant present on every screen that can answer from any record or application inside the customer's GRC program, bounded by administrator set limits. Named customers include American Family Insurance, Warner Bros. Discovery and Memorial Hermann Health System. Integrations named include DocuSign, Microsoft 365, Google Drive and Slack, alongside the Onspring API. Maintains an annual SOC 2 Type II attestation.

Vendor siteOverland Park, Kansas, United States
Last verifiedAugust 29, 2026

Capability grades

All 15 axes, graded from public sources on the date shown. Hover a grade to see what the letter means on that axis.

CC on AI CentralityArtificial intelligence is present but peripheral: a feature layer on a product whose value stands without it.

AI Centrality

How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.

The clearest case on the index of AI as an addition rather than a foundation, and the vendor says so itself. Onspring is a no code GRC platform that existed and sold for years before any AI shipped. Onspring AI launched October 2025 as an optional add on module that customers enable and configure, extended July 2026 into agentic operation. The vendor's own framing is that customers have total control over when and how it is used, which is a sound commercial position and also an admission that the product works without it. Removing the model layer removes an efficiency layer over data entry, documentation drafting, duplicate detection and record linking, and leaves the entire platform standing. Graded below Everlaw and Relativity at B, where the model layer is bundled into the core product rather than licensed separately. The AI is real, shipped, documented and dated, which is why this is C and not lower. The brief flagged this vendor to check the AI bar and it clears it comfortably; centrality is a different question from existence.

Source: Vendor Published
DD on Citation Accuracy and Hallucination DisclosureNothing published on accuracy or grounding for a product that produces legal assertions, or a bare claim that the system does not hallucinate.

Citation Accuracy and Hallucination Disclosure

Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.

Nothing published. Onspring AI generates and revises long form content, creates records from prompts, completes text predictively, and reads and summarises uploaded documents such as SOC 2 reports to populate fields. Every one of those is a generation task where a wrong output lands in a compliance record, and none carries a published grounding claim, source citation behaviour, accuracy figure, precision or recall measure for duplicate detection or field extraction, hallucination rate, evaluation, or statement of what the assistant does when it has no answer. Searched the Onspring AI announcements of October 2025 and July 2026, the regulatory change management product page, the security page, the platform pages and the corporate counsel solution page on 29 Aug 2026. The gap is sharper here than the grade alone conveys: the assistant is documented as able to answer from every record and application in a customer's GRC program, and nothing states how those answers are grounded in the underlying records.

Source: Operator Verified
BB on Autonomy and Oversight ModelA written commitment that the models work alongside a supervising lawyer, with real review surfaces, short of the full control structure: commonly the threshold at which the system stops or what happens after it is wrong.

Autonomy and Oversight Model

What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.

The strongest autonomy disclosure located in this category, and the only one on the index where the boundary is a configurable customer artifact rather than a vendor assurance. The July 2026 release is explicit that administrators define the rules that prompt agent action, that automation operates within the boundaries set by the system administrator, and that the design intent is a governed assistant that keeps users in control. The module is opt in and configurable to organisational standards, and an internal AI governance council is named as the oversight body. That gives a buyer three separate levers a compliance function can actually evidence to an examiner: whether the module is on, what rules trigger action, and who governs it. Held at B because none of the mechanics are published. No rule syntax, no scope limits, no statement of what an agent may never do, no escalation or human confirmation behaviour, and no description of what the audit trail captures when an agent rather than a person acts. Better positioned than Regology and Norm Ai, both of which describe oversight without a customer set boundary.

Source: Vendor Published
BB on Operational and Outcome EvidenceReal deployment evidence with substance, short of full attribution or measurement: a named customer without figures, or figures without the named customer.

Operational and Outcome Evidence

Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.

Customers are named, which most of this category does not do. American Family Insurance for IT risk and GRC program management, Warner Bros. Discovery for GRC management, Memorial Hermann Health System for audit, and Northgate Resorts with a stated saving of 200 compliance hours from a single integration. The vendor also publishes an annual GRC Benchmarking Report carrying survey findings, including that 70 percent of GRC practitioners see simplifying repeatable administrative work as the largest AI opportunity, which is industry research rather than product evidence but is dated and attributable. Held at B rather than A because the named customers are described at use case level without published outcome methodology, the 200 hours figure carries no baseline or period, and none of the named accounts is a legal department, so the evidence supports the GRC product rather than the corporate counsel solution this index is grading it for.

Source: Vendor Published
CC on Privilege and Confidentiality PostureConfidentiality is asserted in general terms, or the commitment lives only in a sales conversation and cannot be read in advance.

Privilege and Confidentiality Posture

How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.

General confidentiality is claimed and evidenced; legal specific confidentiality is not addressed at all. The vendor publishes a SOC 2 Type II attestation covering security, availability and confidentiality, and states that information privacy, security and risk management policies are documented with defined roles, responsibilities, policies and procedures protecting stored data. That is a real confidentiality position for a platform generally. What does not exist: any treatment of legal privilege or attorney work product, any statement about the confidentiality of matter records held in the Corporate Counsel solution, and any acknowledgement that a legal department's records on the platform differ in kind from an IT risk register. Checked the security page, the corporate counsel solution page, the platform pages and the AI announcements on 29 Aug 2026. This matters more than usual here because the same platform holds both the legal department's matters and the business units those matters concern.

Source: Vendor Published
DD on UPL and Professional Responsibility PostureNothing published on the advice line for a product that produces legal work, including where it is sold to people who are not lawyers.

UPL and Professional Responsibility Posture

Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.

Not addressed. The Corporate Counsel solution holds legal opinions, legal research and a clause library whose clauses are automatically selected by contract type, and Onspring AI can generate and revise long form field content across the platform. Generated or auto selected contract language reaching a business user without a lawyer in the path is the shape this axis exists to examine, and nothing addresses it. No statement that output is not legal advice, no positioning on the role of the reviewing lawyer, no professional responsibility material of any kind. Checked the corporate counsel solution page, the AI announcements, the platform pages and the resource material on 29 Aug 2026.

Source: Operator Verified
CC on AI Governance and Bias DisclosureResponsible AI principles are published without a mechanism, a testing regime, or anything a buyer could audit.

AI Governance and Bias Disclosure

Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.

A governance body is named and nothing it produces is published. Onspring AI is stated to operate under the oversight of the company's AI governance council, and the module is configurable by customers against their own organisational standards and compliance requirements. Naming an internal governance body at all puts this ahead of most of the roster, where governance disclosure covers security rather than model behaviour. What is missing is everything the council would produce: no AI policy, no model evaluation, no bias testing or fairness assessment, no accuracy monitoring, no drift or regression statement, no model card, no ISO 42001, and no description of what the council reviews or when. A named committee with no published output is a claim rather than evidence, which is the definition of this band. Checked the October 2025 and July 2026 announcements, the security page and the platform pages on 29 Aug 2026.

Source: Vendor Published
CC on AI Safety and Data StewardshipA generic privacy policy covers the product without addressing what happens to documents and prompts after processing.

AI Safety and Data Stewardship

Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.

Platform stewardship is evidenced and AI specific stewardship is not. The SOC 2 Type II attestation covers security, availability and confidentiality, documented privacy, security and risk management policies are stated, and SecurityScorecard is cited as awarding a 100 out of 100 score. Nothing addresses what happens to customer content once it passes into the AI layer: no statement on whether customer records, policies or uploaded documents are used to train or improve any model, no retention position for prompts or generated output, and no description of how data flows to the model provider and back. That last gap is notable because the provider is named, so the vendor has already disclosed the harder fact and stopped short of the easier one. Checked the security page, both AI announcements and the platform pages on 29 Aug 2026. Security certification is graded separately and is not double counted here.

Source: Vendor Published
DD on AI Liability and RecourseNothing published on who bears the loss when the system is wrong.

AI Liability and Recourse

What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.

No published position. Nothing was located on liability for AI output, indemnity, warranty, service levels, or remedy where a generated field value, an auto populated record or an agent action is wrong. The agentic release makes this a live question rather than a theoretical one, since an agent acting on administrator defined rules can write to compliance records that an examiner later reads. The vendor's answer to that risk is architectural, in the form of administrator boundaries and opt in configuration, rather than contractual, and no contractual position is public. Checked the July 2026 agentic announcement, the October 2025 launch announcement, the security page, the platform pages and the site footer on 29 Aug 2026.

Source: Operator Verified
BB on Practice Systems Integration DepthReal integrations exist and are documented, short of depth: named connections without a description of what they actually move.

Practice Systems Integration Depth

How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.

Integrations are named rather than gestured at, and an open API is documented as the extension path. Named: DocuSign, Microsoft 365, Google Drive and Slack, with the vendor stating that further systems connect through the Onspring API. A published customer account credits a single integration with saving 200 compliance hours, which is integration evidence rather than an integration list. Held at B, and the reason matters for a legal index: not one named integration is a legal practice system. No iManage, no NetDocuments, no SharePoint matter workspace, no e-billing or matter management connector, and nothing that would let the Corporate Counsel solution sit inside a legal department's existing document estate. The integrations are the business software a GRC platform needs. Compare Regology at B for naming ServiceNow, Archer and Hyperproof, which is the same shape: real named integrations aimed at the adjacent stack rather than the legal one.

Source: Vendor Published
DD on Deployment Model and Data ResidencyNothing published on where the software runs or where client data sits.

Deployment Model and Data Residency

Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.

Nothing located from the vendor. Third party software directories describe the platform as cloud deployment supporting Windows and macOS with no mobile application, and that is directory material rather than vendor disclosure, so it is recorded here as context and not credited. From Onspring's own pages, located nothing on hosting provider, region, data residency commitment, single tenant or dedicated instance options, or where customer data is processed and stored. Checked the security page, the platform pages, the corporate counsel solution page and the site footer on 29 Aug 2026. Research limitation stated rather than hidden: the security page was reached through search result content rather than a full page render, so a residency statement lower on that page would not have been seen. Flagged as a correction candidate on that basis.

Source: Operator Verified
BB on Security Certifications and Trust CenterCertification is real and stated, short of accessible evidence: a named standard without scope, date, or a way to obtain the report.

Security Certifications and Trust Center

Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.

A named attestation with its scope stated and its currency addressed, published on the vendor's own security page. Onspring states an annual SOC 2 Type II attestation prepared in accordance with AICPA standards, and names the trust services criteria covered as security, availability and confidentiality. Naming which criteria are in scope is the detail most vendors omit and it is the difference between a claim and a checkable one, since a SOC 2 covering security alone is a materially narrower report. Annual renewal addresses currency. Also cited: a SecurityScorecard rating of 100 out of 100, which is an external scanner score rather than an audit and is treated as supporting rather than load bearing. Held at B on three gaps: the auditing firm is not named, the examination period is not stated, and no trust centre or self serve request route for the report was located, so under the three tier test the artifact itself is sales gated. Consistent with Regology at B, which names its auditor but not its currency; Onspring names its currency and scope but not its auditor.

Source: Vendor Published
BB on Model Supply Chain DisclosureThe supply chain is partly disclosed: providers named without change notification, or architecture described without the providers.

Model Supply Chain Disclosure

Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.

The best model supply chain disclosure located in this pull, and the first record to name its provider outright. Onspring states in dated public announcements that Onspring AI is powered by Anthropic's Claude family of generative AI models, repeated across the October 2025 launch and the July 2026 agentic release and carried in independent trade coverage of both. Naming the provider is the single fact a regulated buyer's own supervisor is most likely to ask for, and it is the fact almost every vendor on this index withholds. Held at B rather than A because the disclosure stops at the family name. No specific model or version is identified, no subprocessor list exists, nothing states whether the provider is engaged through an enterprise agreement or what contractual terms govern data sent to it, no data flow description is published, and no statement addresses what happens if the provider is changed. A buyer knows who, and nothing else.

Source: Vendor Published
CC on Commercial TransparencyPricing is gated behind a demo request while tier names and feature splits are published, so the shape is visible and the number is not.

Commercial Transparency

Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.

The pricing structure is discoverable and no figure is. Subscription pricing is structured by number of users and by modules selected, with annual and multi year licensing options, additional modules incurring incremental cost, and implementation services included with the GRC Suite under some licensing models. Onspring AI is separately licensed as an add on. Knowing that price scales on seats and modules, and that the AI costs extra, tells a buyer how the bill will grow, which is more than most of this roster discloses. Held at C because no price, range or entry point is published at any level, every route is a quote request, and the vendor's own licensing model is described by third parties as complex, which is a signal in itself. Source basis recorded as Third Party Estimated rather than Vendor Published: the structural detail comes from an independent review platform's product summary, not from an Onspring pricing page, and no vendor pricing page was located on 29 Aug 2026.

Source: Third Party Estimated
CC on Firm and Practice CoverageCoverage is claimed broadly, for all firms or all practice areas, without evidence that the breadth is real.

Firm and Practice Coverage

Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.

Coverage is broad across compliance domains and thin across legal ones. Governance frameworks are named at ISO, NIST and CMMC, and the platform spans risk, audit, vendor and third party risk, IT risk, policy, ESG, and business continuity, with named deployments across insurance, media and healthcare. Legal coverage is a single Corporate Counsel solution positioned within business operations, describing matter tracking, requests, opinions, research, a clause library and cost tracking. That is one in house legal use case, not practice coverage: nothing addresses practice areas, jurisdictions, matter types beyond the generic, or any distinction between a legal department's work and the adjacent compliance work the platform was built for. Held at C because the legal offering is real and documented but shallow relative to the platform around it, and because the corporate counsel material carries no visible recent update while the GRC and AI material is refreshed continuously.

Source: Vendor Published

Legal Signals

What each signal means

A signal records what public sources say on the date shown. It is not a grade and it is not a recommendation. Where a signal reads Not addressed, it means the index did not locate the material in public sources on that date, which is a statement about disclosure rather than about the product.

Confidentiality and Privilege

Client Data in Training

Can material a lawyer puts into this product be used to train a model?

Terms silent

No located term or policy addresses the question either way.

Terms are silent. The security page describes what the SOC 2 attestation validates, quoted here, and that scope is about safeguarding data rather than about model training. No statement was located anywhere addressing whether customer records, uploaded documents or prompts are used to train or improve any model, in either direction. The gap is pointed because the vendor already names Anthropic's Claude as the model provider, so it has disclosed the harder fact and left the simpler one unanswered. Checked the security page, the October 2025 and July 2026 AI announcements, the platform pages and the site footer on 29 Aug 2026. Recorded as silent, not as a negative commitment.

Source: Operator Verifiedcustomer data security, availability & confidentialityAs of Aug 29, 2026Evidence

Prompt and Output Retention

How long does the product keep what a lawyer typed, and can that be set to zero?

Not addressed

No located public material states how long prompts and outputs are retained.

Not addressed. No retention period is published for prompts, assistant conversations, generated field content or agent actions, and nothing indicates whether retention is configurable or can be set to zero. The platform is explicitly a system of record that retains GRC data by design, but that is record retention rather than AI interaction retention, and the two are not the same question. Nothing states whether an administrator can see or purge what users asked the assistant. Checked the security page, both AI announcements and the platform pages on 29 Aug 2026.

Source: Operator VerifiedAs of Aug 29, 2026

Ethical Walls and Matter Segregation

Does retrieval respect the firm’s ethical walls, or can the model read across them?

Claimed, not documented

Segregation is asserted in public materials with no published detail on how it is enforced.

Claimed and not documented, and the AI release raises the stakes on it. The vendor states clearly defined roles, responsibilities, policies and procedures protecting stored data, so an access model exists and is asserted. Nothing documents its granularity or whether it constrains the AI layer: the July 2026 assistant is described as living on every screen and answering from every record and application in the GRC program, and no published statement says those answers respect the asking user's record permissions. For a platform holding both a legal department's matters and the business units those matters concern, that is the segregation question, and it is unanswered. No document management system exists to inherit permissions from, so the second model shape is the only applicable one. Checked the security page and both AI announcements on 29 Aug 2026.

Source: Vendor PublishedAs of Aug 29, 2026

Third Party Request and Subpoena Notice

If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?

Not addressed

No located term or policy addresses third party requests for customer data.

Not addressed. No government or law enforcement request clause, no commitment to notify a customer before producing their data, and no transparency report were located. Checked the security page, the platform pages and the site footer on 29 Aug 2026.

Source: Operator VerifiedAs of Aug 29, 2026
Accuracy and Authority

Primary Law Corpus Provenance

Where does the law in this product come from, and does the vendor have the right to use it?

Not addressed

No located public material identifies the corpus behind the product’s answers.

Not addressed, and largely not applicable in the usual sense. This product has no primary law corpus: the AI operates over the customer's own GRC records, policies, controls and uploaded documents rather than over published legislation or case law. The one adjacent disclosure is that governance frameworks including ISO, NIST and CMMC are supported and mapped to controls, which names standards bodies rather than a regulatory corpus with sources, jurisdictions and update lag. Regulatory change management is sold as a module, and nothing published names which regulatory sources feed it, which jurisdictions are covered, how current the feed is, or on what licence basis any of it is obtained. That last part is a real gap rather than an inapplicable one. Checked the regulatory change management product page and the platform pages on 29 Aug 2026.

Source: Operator VerifiedAs of Aug 29, 2026

Good Law Verification

Does the product tell you when the authority it just cited has been overruled?

Not addressed

No located public material addresses whether authority is checked for subsequent history.

Not addressed. The regulatory change management module monitors regulatory changes and aligns controls with evolving requirements, and Onspring AI can surface related regulatory controls and suggest which analyst to assign a new control to. That is change routing rather than a currency signal: nothing indicates whether the product flags that a regulation a control relies on has been superseded, withdrawn or amended, and no citator or treatment source is named. Checked the regulatory change management page, both AI announcements and the platform pages on 29 Aug 2026.

Source: Operator VerifiedAs of Aug 29, 2026

Refusal and Uncertainty Behaviour

What does the product do when the answer is not in the corpus?

Not addressed

No located public material addresses what the product does when it cannot ground an answer.

Not addressed. No explicit no answer path, abstention behaviour, confidence score or uncertainty signal is documented for either the assistant or the agentic features. The July 2026 release describes an assistant making contextualised decisions across workflows and answering from every record in the program, and says nothing about what it does when the records do not support an answer. The published control is the administrator defined boundary on what an agent may act on, which limits scope rather than describing behaviour under uncertainty. Checked both AI announcements, the platform pages and the security page on 29 Aug 2026.

Source: Operator VerifiedAs of Aug 29, 2026

Fabricated Citation Record

Does a public court record exist involving output from this product?

None located

No court order, opinion or disciplinary record naming this product has been located as of the date shown. This is a statement about the public record, not a finding about the product.

None located, with the instrument stated so the finding is worth what the search is worth. General web searches combining the vendor and product names with court, opinion, sanction, enforcement and disciplinary terms returned nothing on 29 Aug 2026. No named docket database or court record tracker was searched for this record. Exposure shape is low relative to a research or drafting product: the AI generates internal compliance documentation and populates records rather than producing citations to authority for filing. Recorded as a statement about what was found, not as a clearance.

Source: Operator VerifiedAs of Aug 29, 2026
Professional Responsibility

Bar Guidance Alignment

Has the vendor engaged in public with the ethics opinions its buyers are bound by?

Not addressed

No located public material engages with bar or ethics guidance.

Not addressed. No named ethics opinion, no ABA Formal Opinion 512, no state bar guidance and no engagement with professional responsibility material of any kind was located, including on the Corporate Counsel solution page where it would be most expected. The vendor publishes extensively on compliance obligations owed by its customers' organisations and nothing on the professional duties of lawyers using the legal solution. Checked the corporate counsel solution page, the resource and report material, both AI announcements and the platform pages on 29 Aug 2026.

Source: Operator VerifiedAs of Aug 29, 2026

Billing and Fee Posture

Does the vendor address what happens to the bill when the work takes an hour instead of six?

Savings claims only

Public materials claim time savings without addressing billing or disclosure.

Savings claims only. Published customer material states 200 compliance hours saved from a single integration, and the AI positioning rests on reducing repetitive administrative work, supported by a benchmarking finding that 70 percent of GRC practitioners see simplifying repeatable administrative work as the biggest AI opportunity. All of that describes the customer's internal time. Nothing appears on the client's side of the equation: the Corporate Counsel solution tracks legal costs and budgets as a feature, and no position is published on billing for AI assisted time or on producing a record a department could disclose. Checked the corporate counsel solution page, the customer stories and both AI announcements on 29 Aug 2026.

Source: Vendor PublishedAs of Aug 29, 2026

Outside Counsel Guideline Readiness

Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?

Not addressed

No located public material supports a client side disclosure obligation.

Not addressed, with one genuine component present that the value set cannot express. The model provider is named outright, Anthropic's Claude family, in dated announcements, which is the single hardest element of such a pack and one almost no vendor on this index publishes. Everything around it is missing: no subprocessor list, no data processing agreement, no trust centre, and no self serve route to the SOC 2 report, which is stated to exist but is not reachable without a sales conversation. A department could forward the model provider name and nothing else. Recorded as not addressed because no forwardable disclosure pack or request route exists, with the model provider disclosure noted here so it is not lost. Checked the security page, both AI announcements, the platform pages and the site footer on 29 Aug 2026.

Source: Operator VerifiedAs of Aug 29, 2026

Court Disclosure Support

If a judge’s standing order requires an AI disclosure, can the product produce one?

Partial record

Some elements of the record are available, short of a document level export.

Partial record. The platform is built to evidence compliance to auditors and examiners: control authoring, attestations and documentation, evidence capture, task tracking with automated notifications, real time reporting, and framework to control mapping across ISO, NIST and CMMC. A customer can produce what was required, who was assigned, what was done and when. The AI dimension is where it stops short. Nothing indicates that a record carries which fields were AI generated, which model produced them, what sources the assistant drew on, or whether a human confirmed the output before it was saved. With agentic action now writing into records under administrator rules, the distinction between a human entry and an agent entry is exactly what an examiner would probe, and no published export or audit view addresses it. Checked both AI announcements, the regulatory change management page and the platform pages on 29 Aug 2026.

Source: Vendor PublishedAs of Aug 29, 2026
Contact

Correct a record, or ask how something was graded

Every grade and every signal on this index is drawn from public sources and dated. If a record is wrong, out of date, or missing an artifact the index did not locate, send the source and it will be reviewed and the record redated. Vendors are welcome to submit documentation. Nothing on this index is for sale, including a listing, a placement, or a grade.

AI Legal Index

The AI Legal Index is an independent index that tracks changes to AI vendors in legal. It holds 31 vendors across 9 categories, each graded on the same 15 capability axes and recorded against 12 legal signals, from public sources. No vendor pays for inclusion, placement, or rating.

Index Status
Last index update
August 29, 2026
The AI Legal Index is an editorial reference. It is not a regulatory body, not a law firm, and nothing published here is legal advice or a recommendation to retain or avoid a vendor. Records are verified against published sources, bar guidance and public court records. Where a record reads not addressed, the material was not located in public sources on the date shown. See the Methodology page for evaluation standards and limitations.
© 2026 AI Legal Index
3801 N Capital of Texas Hwy, Ste E240 · Austin, TX 78746