Legal AI

The Checks I Run Before an AI Agent Touches My Inbox

Moses Dor, Adv. · September 6, 2026 · 9 min read


The Checks I Run Before an AI Agent Touches My Inbox

By Moses Dor, Adv. — practising commercial and real-estate attorney; founder, BizLegal AI. Last updated: 2026-09-06.

Every few weeks a new "AI teammate" product launches that promises to read your inbox, draft your replies, and run your calendar while you sleep. The latest wave calls them agents, bots or teammates; the pitch is the same. I run agents in my own practice, so this is not an article about whether to use them. It is the checklist I go through, in order, before any agent is allowed near a client's name. It is procedural, not doctrinal: it tells you what I do, not what your bar requires. That part is yours to verify.

The question

A lawyer who lets an AI agent into the inbox is doing something no engagement letter anticipated: handing a third party's software a live feed of privileged communication. The question is not "is AI allowed?" It is narrower and more useful: what has to be true before this specific agent reads this specific mailbox, and what stays off-limits no matter how good the agent gets?

I answer it in four steps. They map to how any agent product is built, so they work whichever vendor you pick.

Step 1 — Context: decide what the agent is allowed to know

Every agent runs on a description of who you are and what you want. Before writing that description I decide, in writing, three things:

  1. Which matters are in scope. In my practice the answer is "none by name". The agent knows I am a commercial and real-estate lawyer, how I like drafts formatted, and which recurring administrative tasks exist. It does not carry a client list, matter numbers, or deal terms in its standing memory.
  2. What the agent is for. One job per agent. An intake-triage agent triages intake. It does not also draft client updates, because the moment one agent does everything, you can no longer say what it has seen.
  3. What "done" looks like. If I cannot write the finished output in one sentence ("a table of unread emails ranked by deadline, with nothing sent"), the task is not ready to be delegated.

The practical test: if the agent's description were read aloud to a client, would anything in it surprise them? If yes, rewrite it.

Step 2 — Connections: decide what it can touch, and prove consent

This is the step where the liability lives. An agent is only as private as the accounts it is connected to. My rules:

None of this needs a lawyer to implement. It needs someone willing to say no to a shiny product for a month.

Step 3 — Capabilities: write the task as a recipe, with a verification step

Agents work from recipes: a written sequence of steps for a recurring task. The mistake is to write the recipe as if the agent were a trusted associate. Write it as if it were a bright temp on day one.

Every recipe in my practice ends with the same two lines:

Before delivering, re-check every date, name and number against the source document. List anything you could not verify.

and

Do not send, file or delete anything. Leave the draft for review.

The first line is the difference between an agent that helps and one that quietly invents a deadline. The second line is what keeps the agent's mistakes recoverable. An agent that drafts is a productivity tool. An agent that sends is a signatory.

Three recipes that have earned their place in my practice:

  1. Intake triage. Read new enquiries, extract who / what / when / conflict-check names, rank by urgency, draft a holding reply. Nothing sent.
  2. Deadline digest. Once a day, list every date mentioned in the past day's correspondence, with the sentence it came from. Nothing calendared without my click.
  3. Client-update draft. For a matter I name, draft the weekly status note from documents I hand it, in my format, flagged wherever it inferred rather than read.

Step 4 — Cadence: schedule it, log it, and be able to stop it

A scheduled agent is a colleague you cannot see working. So:

The five things I never automate

  1. Advice. Anything that tells a client what to do goes through me, unassisted, every time.
  2. Sending. No agent in my practice has send rights on client correspondence.
  3. Conflict decisions. An agent can surface a name match. It does not decide whether a conflict exists.
  4. Filing deadlines. An agent can list them. It does not calendar them without my confirmation, and it is never the only place a deadline lives.
  5. Anything involving a vulnerable party or a court. The stakes are asymmetric and the agent does not know it.

What this means for a small practice

You do not need a compliance department to do this. You need one afternoon to write four things down: what the agent knows, what it can touch, how each task ends, and where its log lives. Most of the risk I see in colleagues' setups is not the AI; it is the absence of those four pieces of paper.

The second thing it means is that vendor choice matters less than people think. Products come and go — some launch in beta at prices a small firm cannot justify and change their terms a month later. The checklist above survives all of them, because it lives in your engagement letter and your log, not in anyone's app.

The action plan

  1. Write a one-paragraph description for one agent doing one task. Read it aloud as if to a client.
  2. Add a plain-language processing clause to your engagement letter before connecting anything client-facing.
  3. Connect one account, read-only. Run the agent in draft-only mode for a week and read every output.
  4. Add the two verification lines to every recipe. Confirm the off switch works.
  5. Only then decide whether it earned write access, and to what.

FAQ

Does using an AI agent breach client confidentiality? It can, and whether it does depends on what the agent is connected to, what the vendor does with the data, and what your client agreed to. The checklist above is how I keep those three answerable. Your bar's rules on cloud tools and confidentiality govern; check them before you connect anything.

Which AI agent product should a law firm use? This article does not recommend one. The four steps apply to any of them. In my experience the setup decisions matter more than the vendor, and a vendor that will not answer the two data questions in Step 2 is disqualified whatever its features.

Can an agent draft client emails? Draft, yes — if the recipe ends with the verification lines and the draft waits for review. Send, no. In my practice the send button is never delegated.

What is the minimum viable log? One line per run: timestamp, agent, task, what it read, what it produced, where the draft is. A spreadsheet is enough. The point is that it exists before the first client question, not after.

Is this legal advice for my firm? No. It is what I do in mine. Your obligations depend on your jurisdiction and your clients.

Next step (no call required)

If you are setting this up in your own practice and want a second pair of eyes on the four decisions above, I offer a written review: you reply to one email with five short answers about the agents you intend to run, and I return a written memo checking your intended setup against this checklist. It is a review of your setup, not advice on your matters, and it is delivered in writing — no meeting. Write to [email protected] with the subject "AI practice review" and I will send the five questions.

If what you actually need is a contract read, not an AI setup, the $97 contract risk scan is the self-serve route.


This article is written by Moses Dor in his personal capacity as a practising attorney and is for general information only. It is not legal advice, does not create an attorney-client relationship, and does not recommend any vendor or product. Consult a licensed attorney in your jurisdiction before acting on it. BizLegal AI (DOR INNOVATIONS) is a software company, not a law firm. Current as of 2026-09-06.

Need compliance support beyond what a post can provide?

DocAI scans your SaaS agreements, DPAs, and vendor contracts for the clauses that destroy startups — clause location, severity, and suggested negotiation position — in under 10 minutes.

Scan a Contract — $97