Legal teams are past the question of whether AI belongs in their workflow. The question that actually decides adoption is narrower and harder: which specific tasks can be delegated to an AI agent without creating risk you can't explain to a client, a court, or your malpractice carrier?
This guide covers how to answer that question systematically — what an agent skill actually is, the three vetting gates any skill should pass before it touches privileged material, how the ABA's guidance maps to day-to-day use, and a rollout sequence that has worked for teams adopting this technology.
What is an AI agent skill?
An agent skill is a packaged, reviewable unit of workflow expertise: instructions, guardrails, and output requirements that make an AI agent perform one legal task the way an experienced practitioner would — and refuse to do what it wasn't built for.
The distinction from "using a chatbot" matters. A general-purpose AI assistant will attempt anything and improvise everything. A skill is scoped: a contract clause auditor audits clauses against a defined playbook; it does not draft testimony strategy, answer employment law questions, or guess. Scope is what makes review possible, and review is what makes professional use defensible.
The three vetting gates
Before any skill runs on client material, it should pass three gates. If a vendor can't show you all three, the evaluation is over.
1. Data boundary
Where does the material go? The only acceptable answer for privileged documents is: nowhere. The skill runs inside your environment or your cloud tenant; the vendor never holds client documents; and "no training on your data" is contractual, not a settings toggle.
2. Source-cited output
Every assertion in the output must cite its source — the clause, the Bates number, the statute section. This is not a nice-to-have. It's the difference between work product an attorney can verify in minutes and work product that has to be re-done from scratch to be trusted. A useful test during evaluation: ask the vendor to show you an output where the skill declined to answer because it couldn't source the claim.
3. Attorney supervision by design
The skill's output must be structured for attorney review, not for direct delivery. Tiered classifications rather than final calls. Rationale logs rather than bare conclusions. Escalation flags on anything that requires judgment. If the tool's workflow assumes its output goes straight to the client or into a filing, it was not built for legal practice.
What the ABA guidance actually requires
ABA Formal Opinion 512 (2024) is the reference point most risk committees start from. Its practical requirements condense to four duties:
- Competence — you must understand, at a practitioner's level, what the tool does and where it fails. Vendor documentation you haven't read doesn't count.
- Confidentiality — informed client consent may be required where client data is input into a tool, which is why the data-boundary gate above is first.
- Supervision — AI output is treated like the work of a non-lawyer assistant: reviewed before it's relied upon.
- Candor and fees — no fabricated citations reach a court, and billing reflects actual time when AI compresses the work.
None of these prohibit agent skills. All of them shape which skills are usable: scoped, cited, supervised ones.
A rollout sequence that works
- Pick one workflow with painful volume and low judgment-density. First-pass privilege screening and clause auditing are common starting points; final-say decisions are not.
- Run the skill in parallel with your existing process for one matter. Same documents, both pipelines. Measure agreement rate and — more importantly — read every disagreement.
- Write the supervision protocol before expanding. Who reviews, what they sign off on, what triggers escalation. One page is enough; zero pages is how incidents happen.
- Expand by practice area, not by headcount. A skill that works for the commercial contracts group is a template for the employment group's evaluation — not an automatic approval.
Questions to ask any vendor
- Can this run entirely inside our environment? What leaves, if anything, and when?
- Show me an output where the skill refused to answer. What triggered the refusal?
- What does the audit trail look like six months later, when we need to reconstruct a decision?
- What happens to our configuration and data if we terminate?
- Which of your claims are in the contract, and which are only on the website?
A vendor comfortable with that list is a vendor who has been through a legal procurement before. That, too, is signal.
Where LibSkills fits
LibSkills builds hosted agent skills for exactly this evaluation: every skill in the Legal Pack is scoped, produces source-cited output, and is designed for licensed-professional review before anything reaches a client. If you're earlier in the journey — still deciding where to specialize before deciding what to automate — start with the free Sub-Niche Opportunity Report: 25 scored niches, including nine in legal practice.