Discover a Better Way to Run RFPs & Resource Matters. Learn about AVM.

Menu
In This Whitepaper

Insights into how to build a legal tech architecture that unlocks the full power of AI

Overview of the 5 technology archetypes and 7 components of an effective system of record

Breakdown of how to use APIs and MCP Servers to connect your tech stack

Advice on how to approach the “build vs. buy” debate in the AI era

Welcome to the AI Age; Are You Ready For It?

Corporate legal departments are under extraordinary pressure to transform how they work. The 2026 CLOC State of the Industry Report found that demand is surging, with 63% of departments reporting rising workload. Yet resources are not keeping pace, with only 32% of departments anticipating attorney headcount growth. The message is clear: legal departments are being asked to absorb significantly more work without proportional increases in budget or headcount.

The response from most legal leaders is to invest in technology, particularly AI. The 2026 Wolters Kluwer Future Ready Lawyer Survey found that over 90% of legal professionals now use at least one AI tool in their daily work, and 60% expect their organization’s investment in AI technology to increase over the next three years.

But the fact that a legal department is using AI doesn’t mean it’s using AI well, or that it has put the foundations in place to use AI at scale. Gartner has found that teams with higher levels of digital readiness are nearly twice as likely to see significant benefits from their technology systems, but less than a quarter of legal departments are digitally ready.

This white paper is written for Chief Legal Officers, General Counsel, and legal operations leaders who are evaluating their technology strategy in a rapidly changing environment. Its aim is to provide an architectural framework that makes sense of the complexity, and makes the decisions that follow more clear.

In particular, it argues that the question is no longer whether to adopt AI—that’s a certainty—but rather whether the architecture underpinning that adoption is sound. Getting the architecture right is the difference between transformation that compounds over time and a patchwork of tools that creates more problems than it solves. The framework that follows—five archetypes, a reference technology architecture, and an explanation of the interaction models—is designed to help you think clearly about technology strategy in an AI-native world.

Five Archetypes for Technology

The corporate legal technology landscape is crowded and getting more so. Legal tech funding reached nearly $6 billion in 2025, with fourteen rounds exceeding $100 million, according to an analysis by LegalComplex. And the 2026 CLOC State of the Industry Report found that 80% of legal departments now cite technology strategy as their top priority.

With this much money and attention flowing into the space, it’s dangerously easy to make decisions based on product features and demos rather than on a sound understanding of what role each piece of technology plays in the broader architecture.

To cut through this complexity, I’ve found it useful to think in terms of five archetypes. Every piece of technology in a corporate legal department’s legal tech stack falls into one (or more) of these categories.

Systems of Record

Systems of record are the backbone of a corporate legal department’s data and workflows. They define the data model, serve as the source of truth, enforce business logic, manage state and lifecycle, provide auditability, govern permissions, and act as the integration hub.

Everything is centered around and depends on them.

Every corporate legal department will have multiple systems of record, because each one is for a particular domain. Enterprise legal management (ELM), for example, is a system of record for matters, vendors, and spend. Contract lifecycle management (CLM) is a system of record for contracting policies, clause libraries, and the execution and management of contracts throughout their lifecycle. And so on. Importantly, some systems of record are not legal-specific. For example, a company’s AP/ERP is the system of record for paying invoices and managing financial accounts; the ELM system must integrate with it to ensure timely and correct payment of outside counsel invoices. Similarly, an identity management platform like Azure AD or Okta is the system of record for user authentication and access control across the enterprise.

Systems of record are where governance lives. They are what make AI governed—a point I’ll return to in detail in the next section. And governance is not an abstract concept for legal: the 2026 Future Ready Lawyer Survey found that 46% of legal professionals cite data privacy compliance and protecting sensitive information from cyber threats as top information security concerns, while 85% of legal departments in the 2026 CLOC report now have dedicated AI resources overseeing deployment, governance, and risk. Systems of record are the technology foundation on which governance rests.

Data Warehouses

Data warehouses (sometimes called data lakes or lakehouses, depending on their underlying architecture) aggregate governed data from multiple systems of record and make it available for cross-domain analysis. Platforms like Snowflake and Databricks serve this role. Unlike systems of record, which are optimized for transactional writes within a single domain, data warehouses are optimized for high-volume analytical reads across domains.

Every corporate legal department benefits from a data warehouse. A legal department’s data warehouse might combine spend data from the ELM system, contract data from the CLM system, and legal team compensation data from the ERP system, enabling analyses that no single system of record could provide on its own. For example: “What’s our total cost of supporting commercial contracts by business unit?”

The data warehouse inherits the determinism of the systems of record that feed it, but it isn’t a system of record itself. It doesn’t enforce business logic, manage state and lifecycle, or govern permissions. It’s a read-oriented aggregation layer, not a write-oriented governance layer. Its architectural role is durable: as AI workspaces make it easier for more people to ask more complex cross-domain questions more frequently, the demand on the data warehouse layer increases rather than decreases.

AI Workspaces

AI workspaces are single panes of glass within which users can access, use, and take action on data governed by connected systems of record. Think of them as the place where people interact with AI to get work done.

There are both general-purpose AI workspaces—Anthropic’s Claude and OpenAI’s ChatGPT are the most prominent—and legal-specific AI workspaces, such as Libra by Wolters Kluwer. AI workspaces connect with systems of record through the Model Context Protocol (MCP), which I’ll discuss later in this paper.

The distinction between general-purpose and legal-specific AI workspaces matters. General purpose AI tools like Claude are infrastructure, similar to Amazon Web Services (AWS) and other infrastructure-as-a-service platforms. Their objective is to serve customers across a wide range of industries and use cases. But success in any particular domain, such as legal, comes from pairing market-leading infrastructure with deep domain expertise and tailoring. The quality of large language model output—its authoritativeness and contextual relevancy—is heavily dependent on the data on which it’s trained.

General-purpose AI workspaces are trained primarily on publicly available data. But law is a deep domain, and the highest-quality content is not in the public domain; you have to pay for it. Legal-specific AI workspaces have access to this content either because they own it outright (as is the case with Libra, which draws on Wolters Kluwer’s vast legal content library) or because they license it from authoritative publishers. This makes a material difference if you’re looking to draft a contract that complies with the law in a particular jurisdiction, or research a novel legal question. You need all the relevant and authoritative content, not just what happens to be freely available on the internet.

It’s worth noting that even as corporate legal departments migrate toward legal-specific AI workspaces, nearly all AI products—workspaces, agents, and enrichment tools alike—are built on frontier models from companies like Anthropic and OpenAI. This is analogous to how nearly all software companies run on infrastructure from AWS, Google Cloud, or Microsoft Azure. The frontier model is the foundation; the legal-specific product is the domain layer that sits on top of it.

The direction of travel is for every corporate legal department to have an AI workspace. Today, for many, that’s a general-purpose AI workspace. Increasingly—and eventually, universally— it will be a legal-specific one. Both decisions matter: which AI workspace you choose, and whether your systems of record are ready to connect to it. The two are complementary, not competing, priorities.

AI Agents

AI agents operate autonomously or semi-autonomously to complete work on behalf of corporate legal departments. They can be invoked and managed through systems of record, AI workspaces, or their own interfaces—or a combination of these. McKinsey’s 2025 survey found that 23% of organizations are already scaling agentic AI systems in at least one business function, with an additional 39% experimenting, and Gartner predicts that by 2028, 33% of enterprise software applications will integrate agentic AI, up from less than 1% in 2024.

The distinguishing feature of AI agents is that they take actions: they make decisions, trigger workflows, and communicate with stakeholders. For example, a corporate legal department may deploy an AI agent to conduct a first-pass review of outside counsel invoices. In this case, the agent is invoked by the ELM system and governed by the rules it sets out: billing guidelines, rate cards, and so on. The agent reviews each invoice, proposes adjustments based on the corporate legal department’s guidelines and the managing attorney’s preferences, and communicates with outside counsel to effectuate any changes. Throughout it all, the ELM system, as the system of record, governs the agent.

AI Enrichment Tools

AI enrichment tools augment existing data by extracting and recording metadata. Unlike agents, they don’t take actions; instead, they create new data from existing data, which systems of record and other archetypes can then use. AI enrichment tools are effective at combating the “garbage in, garbage out” data quality concern that plagues enterprises. Because they work based on defined, governed rules, they eliminate gaps and inconsistencies that would otherwise exist if humans were creating the data.

For example, an AI enrichment tool might take an outside counsel invoice and augment it with information about the tasks and activities performed, mapped to a standard taxonomy like the Uniform Task-Based Management System (UTBMS). The invoice may arrive from outside counsel as a set of unstructured line items, and the enrichment tool adds a structured layer of meaning on top of it.

Another example is reading a contract and extracting key data points—notice dates, limitations of liability, and so on—that can be stored in the CLM system and made available for automation, reporting, and analysis. The enrichment tool doesn’t decide anything about the contract; it makes the contract’s contents machine-readable so that systems of record, AI workspaces, and AI agents can do their jobs more effectively.

What About Analytics and Business Intelligence Too?

A natural question is where analytics and business intelligence tools fit. Historically, tools like Power BI and Tableau have been the primary way legal departments consume information from data warehouses in the form of dashboards, scheduled reports, and visualizations.

These tools have served legal leaders well, but AI workspaces are rapidly encroaching on their territory. When a legal operations leader can ask an AI workspace a question that previously required someone to build a report, the value proposition of a standalone analytics tool narrows. The data warehouse persists as the cross-domain aggregation engine; what changes is the interface above it.

It’s too early to say whether analytics tools will be fully absorbed by AI workspaces or whether they’ll continue to serve a distinct purpose. For this reason, I haven’t included them as their own archetype. They may become a durable one or they may be subsumed by AI workspaces entirely. What matters for the purpose of this paper is that the data feeding those tools— wherever they sit—is governed by systems of record and aggregated by the data warehouse. Get those layers right, and the interface question resolves itself.

Disambiguating Products and Archetypes

Here’s a critical point that’s easy to miss: products and archetypes are not the same thing. A single product may incorporate capabilities from multiple archetypes. Many systems of record, for instance, also include AI workspace, AI agent, and AI enrichment capabilities.

When thinking about your legal tech stack architecture, it’s essential to design through the lens of archetypes rather than the specifics of any given product.

Ask yourself: are the right responsibilities assigned to the right archetypes? Is my AI governed by systems of record, or is it floating free? These are architecture questions, and they transcend any individual vendor.

The Seven Properties of a System of Record

I’ve asserted that systems of record are the backbone of the corporate legal department tech stack. Let me now explain what that means and why it matters—not just for operational efficiency, but for data quality, security, and AI readiness.

Many corporate legal teams are still running critical processes on email and spreadsheets rather than proper systems of record. This is the single biggest obstacle to successful AI adoption, because if you layer AI on top of bad data, you’re going to get bad results. Systems of record are how you get authoritative, clean, and reliable data. They’re the prerequisite for everything else.

A system of record does seven things. I’ll describe each one and give concrete examples in the context of enterprise legal management—the domain I know best—but they apply equally to CLM, DMS, and any other system of record.

1. Defines the data model

The system of record establishes the structure and relationships of all data within its domain. In ELM, this means defining what a matter is, how vendors relate to matters, how invoices relate to matters and vendors, and so on. The data model is the blueprint. Without it, data is unstructured noise. With it, data becomes information that can be queried, analyzed, and acted upon.

2. Serves as the source of truth

When two systems disagree about a fact—say, the total amount invoiced on a matter— the system of record is authoritative. This isn’t a nice-to-have; it’s essential for making sound decisions and for downstream systems (including AI) to operate reliably. If an AI agent is reviewing invoices, it needs to know with certainty what the approved budget is for a given matter. That figure comes from the system of record, and the system of record alone.

3. Enforces business logic

Business logic is the set of rules that govern how data is created, modified, and used. In ELM, examples of business logic include that invoices must be submitted within 90 days of work being performed; that rates for associates cannot exceed a specified cap; and that invoices above a certain threshold require General Counsel review and approval. The system of record enforces these rules consistently and automatically. This is deterministic behavior: the rules produce the same outcome every time, regardless of who’s interacting with the system.

4. Manages state and lifecycle

Data has a lifecycle: it’s created, reviewed, approved, modified, and eventually archived or disposed of. The system of record manages transitions between these states and ensures that only valid transitions occur. An invoice, for instance, moves from submitted to under review to approved to paid; it cannot skip directly from submitted to paid without passing through the review and approval stages. This is governance in action, and it’s particularly important in legal, where regulatory and compliance requirements dictate how information must be handled.

5. Provides auditability

Every action taken within a system of record is logged: what changes were made, by whom, and when. This audit trail is essential for compliance (for example, with Sarbanes-Oxley, or SOX, which requires demonstrable controls over financial processes), for resolving disputes, and for the kind of accountability that legal and finance leadership demand. When an AI agent approves an invoice, the system of record logs that the agent took the action, which rules it applied, and what the outcome was. This is how you answer the question, “Why was this invoice approved?”, the type of question that regulators, auditors, and business leaders will increasingly ask as AI becomes more prevalent.

6. Governs permissions

Not everyone should be able to see or do everything. The system of record controls who can access which data and perform which actions based on their role, department, geography, and other attributes. A paralegal may be able to view invoices but not approve them. A regional counsel may have access to matters in their jurisdiction but not in others. An AI agent may be authorized to approve invoices below a certain dollar threshold but must escalate those above it. These permissions are defined and enforced by the system of record, not by an AI workspace or AI agent. This is critical for security, and it extends beyond the corporate legal department’s own team.

7. Acts as the integration hub

The system of record is the point at which data flows in and out of the domain. It’s where APIs and MCP servers connect, and it’s what ensures that data shared with other systems—whether another system of record, an AI workspace, or an AI agent—is accurate, current, and appropriately scoped. The ELM system, for example, sends approved invoice data to AP/ERP for payment, receives matter related documents from the DMS, and exposes data to AI workspaces through its MCP server—all while maintaining the integrity and security of the data.

Contrasting Systems of Record and AI Workspaces

Understanding these seven properties makes clear why AI workspaces—no matter how capable—are not substitutes for systems of record. The reason is fundamental: AI is inherently nondeterministic, and a system of record’s essential purpose is to ensure deterministic behavior.

When you ask an AI workspace the same question twice, you’ll get different answers. That’s a feature, not a bug; it’s what makes AI creative, flexible, and useful for research, analysis, and drafting. But it’s precisely the wrong characteristic for enforcing business rules, managing state transitions, governing permissions, and maintaining audit trails. You don’t want “creative” invoice approval logic; you want rules that are applied consistently, every time, without exception.

The right architecture lets each archetype do what it does best. Systems of record provide governance, structure, and determinism. AI workspaces provide intelligence, flexibility, and natural-language interaction. When connected through MCP servers, they’re extraordinarily powerful, far more than either would be alone.

The Reference Technology Architecture

With the five archetypes established and the role of systems of record clear, here’s what I believe a well-architected legal tech stack looks like.

The foundation is a set of domain-specific systems of record, each governing a critical area of legal department operations. Layered on top is one or more AI workspaces— environments where attorneys and legal operations professionals can interact with AI to research, draft, analyze, and take action, all connected to the governed data in the systems of record beneath them.

The most common domain-specific systems of record are:

Enterprise Legal Management (ELM)

The system of record for matters, vendors, and spend. This is the operational backbone of the legal department’s relationship with outside counsel, the largest area of legal expenditure. The 2026 CLOC report found that 85% of legal departments use electronic billing systems and 78% use matter management technology—both core ELM capabilities—making this arguably the most mature system-of-record domain.

Contract Lifecycle Management (CLM)

The system of record for contracting policies, clause libraries, and the execution and management of contracts throughout their lifecycle. Lawyers may use an AI workspace to author and negotiate contracts, but the CLM provides the governing framework—the approved starting positions, the fallback language, the escalation rules.

Document Management System (DMS)

The system of record for storing, organizing, and controlling access to legal documents and attorney work product. This is also where pre-approved templates live—a critical point, because when you start new work product in your AI workspace, you want it to be governed by the approved starting point, which is provided by the DMS.

Legal Hold

The system of record for issuing, tracking, and managing litigation holds to ensure preservation of relevant documents and data. The 2026 CLOC report found that 78% of departments use legal hold technology, tying it with matter management as the second most widely adopted technology category.

Complementing these are AI agents and AI enrichment tools, which may be built into the systems of record, provided by third parties, or both. Surrounding the legal tech stack, in particular, are enterprise systems of record that the legal department depends on but doesn’t own:

  • Identity Management (IAM) and SSO (e.g., Azure AD, Okta): For authentication, access control, and user provisioning across all systems.
  • AP/ERP (e.g., Coupa, SAP): For processing payments to outside counsel and managing financial accounts.

Spanning both the legal and enterprise layers is the data warehouse: the cross-domain aggregation layer. It draws governed data from multiple systems of record (both legal and enterprise) and makes it available for analytical queries that no single system of record could answer on its own. AI workspaces connect to the data warehouse via MCP, giving legal professionals a natural-language interface to cross-domain insights without requiring a dedicated analytics tool or analyst.

This is the reference architecture. It is not intended to be a comprehensive listing of every legal or enterprise system of record; many departments will have additional systems for areas like entity management and intellectual property management. Rather, it represents the most common domains. Every corporate legal team’s specific legal tech stack will differ based on size, industry, maturity, and priorities. But the architectural principles—domain-specific systems of record as the governed foundation, AI workspaces connected on top, supported by agents and enrichment tools, and integrated with enterprise systems—are universal.

The Connective Tissue: APIs and MCP Servers

Having the right pieces is necessary but not sufficient. How those pieces connect to one another is equally important, and this is where many technology strategies fall short. There are two primary interaction models in the corporate legal department technology stack, described below.

System-to-system via API

Systems of record communicate with one another through APIs. An API is a structured, developer-built connection that allows one system to send data to and receive data from another according to predefined rules. For example, when an invoice is approved in the ELM system, an API call transmits the payment instructions to the AP/ERP system. APIs are precise, predictable, and deterministic. They do exactly what they’re programmed to do, every time.

AI-to-system via MCP server

AI workspaces and AI agents connect with systems of record (and with one another) through MCP servers. The Model Context Protocol—introduced by Anthropic in November 2024 as an open standard and since adopted by OpenAI and others—provides a standardized way for AI systems to discover, understand, and interact with data sources and tools. In December 2025, Anthropic donated MCP to the Agentic AI Foundation, cementing its role as an industry-wide standard rather than a proprietary protocol.

The difference between an API and an MCP server is best understood through an analogy. Think of a system of record as a large, well-organized warehouse. An API is like a loading dock with a specific set of instructions: “Put box A on shelf B.” It’s efficient and reliable, but it requires someone (a developer) to write those instructions in advance for every possible operation. An MCP server, by contrast, is like a knowledgeable guide who can walk through the warehouse, understand what’s inside, and respond to requests in natural language: “Find me everything that arrived last week and sort it by size.” The guide translates that request into the specific operations the warehouse supports, retrieves the data, and brings it back.

MCP servers and APIs sit on top of systems of record. This layered architecture is important: the system of record remains the authoritative source of data and business logic; the API provides the programmatic interface; and the MCP server provides the AI-accessible interface. There are also user interfaces for humans, of course—the dashboards, forms, and reports through which people interact with the system directly. Each layer serves a different consumer—developers work with APIs, AI systems work with MCP servers, and users work with UIs—but the system of record is the foundation for all three.

This architecture has profound implications for security and compliance. Because MCP servers communicate with systems of record through the same governed APIs, every action taken by an AI workspace or AI agent is subject to the system of record’s permission model, audit logging, and business rules. The AI doesn’t bypass governance; it operates within it. This is what makes the difference between AI that legal leaders can trust and AI that keeps them up at night.

Architecture in Action: An End-to-End Example

The preceding sections describe the archetypes, the reference architecture, and the interaction models. To make all of this tangible, consider how the architecture works end-to end for one of the most common corporate legal workflows: spend management.

Step 1: Submission.

An outside counsel invoice is submitted to the ELM system— the system of record for matters, vendors, and spend.

Step 2: Enrichment

An AI enrichment tool, operating within the ELM system, classifies each invoice line item against a standard taxonomy. Unstructured text becomes structured metadata.

Step 3: Agent review

An AI agent conducts first-pass review. It compares the enriched invoice against the department’s billing guidelines and the managing attorney’s preferences, proposes adjustments where warranted, and communicates with outside counsel to resolve discrepancies.

Step 4: Approval

The invoice is approved—either by the agent within its authority or by a human reviewer for amounts above the agent’s threshold. The system of record logs who approved it, when, and under which rules.

Step 5: Payment

The invoice is transmitted to the AP/ERP system for payment via API.

Step 6: Insight

Throughout the process, the managing attorney can query the ELM system’s data through its AI workspace, asking questions like, “How does this firm’s spend compare to budget,” or, “Show me the trend in associate rates across my matters,” and get answers grounded in the governed data.

Every step is auditable. Every action is governed by the system of record’s business logic and permissions. And every interaction between AI and data flows through the architecture described in this paper.

This is what Brightflag does. As an ELM system of record, Brightflag governs matters, vendors, and spend. Its AI enrichment capabilities—such as legal spend classification—add structure to unstructured data. Its AI workspace, Ask Brightflag, gives legal professionals a natural-language interface to the governed data. Forthcoming AI agents will handle tasks like first-pass invoice review, operating within the governance framework rather than outside of it. And authoritative data is passed to the data warehouse for cross-domain aggregation. It’s an example of how the five archetypes come together in a single domain—and of the kind of architecture this paper advocates.

Not all ELM systems are this complete. Most were developed before the age of AI and lack AI enrichment tools, an AI workspace, and AI agents. Many govern matters and spend, but not vendors. Still others aren’t ready for the AI-native future.

The Build vs. Buy Debate, Revisited

If systems of record are this important, why not build your own? After all, with AI-assisted coding tools, it’s never been easier to build software. Can’t a legal operations team use Claude Code or OpenAI Codex to create a custom enterprise legal management system tailored to meet their exact needs?

This question is the latest chapter in the “build vs. buy” debate that has existed within enterprise software for decades. The arc of that debate is worth revisiting, because it has important lessons for where we are today.

In the early days, companies built software because buying it wasn’t viable.

Enterprise software was nascent, and what did exist was prohibitively expensive and required technical resources to operate that rendered it inaccessible to most companies. If you needed a system to manage your legal matters, you built one, usually a combination of spreadsheets, Access databases, and SharePoint sites held together by institutional knowledge and good intentions. It was painful, but there was no alternative.

Then SaaS took off and most companies switched to buying.

Purpose-built SaaS products offered better functionality, faster implementation, lower total cost of ownership, and—critically—ongoing innovation. The vendor invested in R&D, regulatory compliance, security certifications, and integrations so that each customer didn’t have to. Gartner has predicted that the global legal technology market will reach $50 billion by 2027, driven in large part by this shift from building to buying.

AI has caused the build vs. buy debate to re-emerge, but in a new form.

The question isn’t, “Should we hire developers to build custom software?” Most legal departments know better than that. Rather, the question is, “Can we use our AI workspace to replicate what a system of record does?” An attorney sees Claude or ChatGPT generate a surprisingly good result and wonders: could this replace our system of record?

The answer is no, for the same reasons that building has always lost to buying over the long term. Building a system of record—a system that defines a data model, serves as the source of truth, enforces business logic, manages state and lifecycle, provides auditability, governs permissions, and acts as the integration hub—is exceptionally difficult. It’s not a spreadsheet problem; it’s an engineering problem that requires deep domain expertise, rigorous security practices, ongoing maintenance, and continuous investment. The initial build may seem easy enough (even though it isn’t), but what’s unquestionably hard is everything that comes after: handling edge cases, maintaining integrations as connected systems evolve, keeping up with regulatory changes, scaling as data volumes grow, and supporting users when things break. Every company that has tried to build and maintain a custom legal technology solution understands this pain.

But here’s what’s different now: “buy” no longer means “settle.”

The historical knock on buying software was that no off-the-shelf product perfectly matched every organization’s unique workflows. You got almost all of what you needed and compromised on the rest. AI changes this equation fundamentally. You can buy a system of record for the core capabilities—the data model, business logic, auditability, permissions, integrations—and use AI to close whatever small gap remains. This isn’t about papering over product deficiency; it’s about eliminating the inherent limitation of any standardized product to perfectly match every organization’s unique workflows. Need a custom report that the system of record doesn’t offer out of the box? Ask your AI workspace to query the system of record’s data through its MCP server and generate it. Need a workflow that’s unique to your organization? Deploy an AI agent that operates within the system of record’s governance framework but handles the specifics your way.

This is a materially better outcome than building from scratch, and a better outcome than the old buy-and-compromise model. It’s the best of both worlds, and it’s only possible when you have a well-architected stack with systems of record at the foundation and AI workspaces and agents connected through MCP servers.

A Practical Guide to Getting Started

Most legal departments are earlier in the journey than they’d like to be: the 2026 CLOC report found that while technology strategy is the top priority, budgets are flattening, and despite the surge in AI adoption, much of that usage is ad hoc. For legal leaders who are persuaded by this framework, the natural question is: what do I do next? Here are the steps I recommend.

First, audit your system of record coverage.

Map each domain in the reference architecture and identify whether you have a proper system of record in place. Be honest with yourself about what you find. Many legal teams that believe they have a system of record actually have a system of reference. Use the seven properties from the earlier section as your evaluation criteria: does your current tool define the data model, serve as the source of truth, enforce business logic, manage state and lifecycle, provide auditability, govern permissions, and act as the integration hub?

Second, prioritize based on opportunity and risk.

Not every domain needs to be addressed at once. Outside counsel typically represents the largest area of legal expense, making ELM a natural starting point for many departments. CLM is another high-impact domain, particularly for departments managing large contract portfolios. Start where the opportunity or pain is greatest, as this represents the greatest ROI.

Third, evaluate systems of record for AI readiness.

Assess whether products offer MCP connectivity. This is what will allow your systems of record to connect with your AI workspaces. A system of record without an MCP server is one that will be isolated from the AI tools that your team uses. Brightflag is investing heavily in this connectivity because it’s fundamental to how legal departments will work in the future. AI readiness also extends to your cross-domain data layer: ensure that your data warehouse is accessible via MCP so that AI workspaces can answer cross-domain questions, not just domain-specific ones.

Fourth, establish a sanctioned AI workspace and govern its use.

Your department needs a sanctioned AI workspace. The alternative—using consumer AI tools with no governance or data protection—is a security and compliance risk that no leader should tolerate. As the 2026 Future Ready Lawyer Survey said, legal departments that don’t provide secure, approved AI tools will end up with “shadow AI” that is dangerous in terms of ethics, reputation, and risk. Start with a sanctioned workspace, connect it to your systems of record through MCP, and expand the use cases from there.

So, You’re in the AI Age; Are You Ready for It?

The legal technology market is projected to reach $50 billion by 2027. Over 90% of legal professionals now use at least one AI tool. Legal operations professionals rank technology strategy as their top priority. The transformation is happening; the question is whether it’s happening with the right architecture.

The framework in this paper—five archetypes (systems of record, data warehouses, AI workspaces, AI agents, and AI enrichment tools), domain-specific systems of record as the governed foundation, and MCP-based connectivity between AI and data—is a blueprint for getting the architecture right.

It isn’t theoretical; it reflects how the most forward-thinking corporate legal departments are already building their technology stacks, and it’s consistent with how the broader enterprise software market is evolving.

The corporate legal teams that thrive in the years ahead will be those that resist the temptation to view AI as a replacement for governance, and instead build a technology stack in which AI and governance reinforce one another. Systems of record provide the structure, the rules, the security, and the accountability. AI workspaces provide the intelligence, the flexibility, and the natural-language interface. Agents and enrichment tools do the work that used to require dozens or hundreds of hours of manual work. Connected through MCP servers and governed by systems of record, the entire stack becomes greater than the sum of its parts.

The architecture is the strategy. Get it right, and you’ll be ready for the AI-native future.

About Brightflag

Brightflag is the intuitive, AI-powered Enterprise Legal Management platform that empowers corporate legal teams and outside counsel to unlock business growth. As the system of record for matters, vendors, and spend, Brightflag combines AI-native e-billing, matter management, and vendor management to give teams real-time control over legal costs, drive more effective collaboration with outside counsel, and enable data driven vendor decisions. Built for seamless integration with AI workspaces, AI agents, and other systems via its API and forthcoming MCP server, the platform delivers rapid implementation, high adoption, and measurable outcomes—backed by unparalleled customer support focused on long-term success.

Sources

© 2026 Shine Analytics Limited (“Brightflag”). All rights reserved.

This 2026 White Paper, including all content, text, images, graphics, and other materials, is the property of Brightflag and is protected under copyright law. The White Paper is provided on an ‘as is’ basis. Unauthorized reproduction, distribution, or use of this White Paper, in whole or in part, without the prior written consent of Brightflag is strictly prohibited. For permissions or inquiries regarding this White Paper, please contact: [email protected]

See Brightflag in action

Put this playbook to work. See how legal teams use Brightflag to manage outside counsel, control spend, and prove their value — in a 30-minute walkthrough.