This website uses cookies

Read our Privacy policy and Terms of use for more information.

Somewhere in your firm there is a memo that approved an AI tool.

It was done properly. A pilot, a bake-off, someone senior asked hard questions, IT checked the security posture, and the tool went on the approved list. The memo has a date on it. Say January.

It is August. What, exactly, is still approved?

The product name is the same. Almost nothing else is guaranteed to be. Models get updated, swapped, and retired under unchanged product names - I have written here before about a model that disappeared overnight, and about how hard it is to know which model you are actually using on any given day. The vendor's retrieval setup changes. The system prompt changes. The terms change. The tool your firm approved in January and the tool your associates used this morning share a logo and a login page. The January memo does not know that.

Assurance ages

This is the quiet problem with assurance: it ages even when nobody makes a mistake. The SOC 2 report in the diligence folder was true when it was issued. The benchmark in the vendor deck was true when it was run. The pilot results were true for the model that took the pilot. A certificate is a statement about a day. Reliance is a thing you do every day after. Each is a photograph. We file them as if they were live feeds.

Call it what it is: the expiring audit. An assessment decays at the rate the thing it assessed changes. And AI systems can change faster than the approval processes built around them.

This is the third form of evidence theater I have written about here: confidence that extends past what the evidence can actually support. Human review can be asked to prove too much. A benchmark can travel beyond the conditions that produced it. Here the problem is time - yesterday's assessment is still being asked to carry today's reliance. An assessment can become stale without ever having been wrong. Nothing has to fail. Time does it alone.

The opinion letter already does this

Lawyers already know how to handle this. We do it with opinion letters.

Every opinion letter you have ever signed is an "as of" document. It speaks as of its date, on stated facts, and everyone sophisticated understands the bargain: the world moves forward, but the opinion stands still. A freedom-to-operate opinion does not cover art published after it; nobody expects it to; the date is doing disciplined work. Patent lawyers live inside this discipline. We simply forgot to bring it with us when we started approving tools.

There is already a professional register for this. Model Rule 1.1, Comment 8 says a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology; patent practitioners owe a parallel competence duty under 37 C.F.R. 11.101. That does not prescribe a review cycle for AI tools. It does make one position hard to defend: that a one-time assessment governs indefinitely while the thing it assessed keeps changing.

Three changes

So bring the discipline. Three changes turn an expiring audit into honest assurance, and none of them costs money.

  1. Date the confidence. Every approval, every attestation, every "we tested this" carries its date in the operative sentence, not the footer. "Approved" is theater. "Approved as of January 14, on version X, for tasks Y" is evidence.

  2. Name the invalidators. The approval memo should say what would void it: a model version change, a vendor terms change, a change in how the tool is wired into your documents. If nothing could invalidate the approval, the approval was not an assessment - it was a blessing.

  3. Trigger re-verification on change. Make it event-driven, not only calendar-driven. An annual review may be useful, but it cannot catch a material change that happened eleven months earlier. Re-verify on version change, terms change, workflow change, or on the calendar - whichever comes first. If you cannot detect the version change, that inability is a finding about the vendor, and it belongs in the file.

The question battery from a few weeks back had five questions. This piece is the fourth one grown to full size: when was it run, and what has changed since?

Ask it of the next assurance someone hands you - a SOC 2 report, a benchmark, a pilot result, your own approved-tools list. If the answer to "what has changed since" is "we do not know," then what you are holding is not current assurance. It is a photograph of assurance, aging in a frame.

Your approved-tools list has dates on it somewhere. Go look at the oldest one. Then reply and tell me the date - just the date. I want to know how old the profession's current AI assurance actually is.

I write about using AI in legal practice without surrendering judgment, privilege, or the duty of competence at The Agentic Lawyer.

Educational only, not legal advice, and no attorney-client relationship is created. Views are my own. Attorney advertising in some jurisdictions.

Stop typing what you could say in 10 seconds.

Wispr Flow turns your voice into clean, professional text inside any app. Emails, Slack, client updates — speak once, send without editing. 4x faster than typing.

The best voice models, now with full orchestration. Build real-time voice and chat agents on one low-latency stack: any LLM, your tools and knowledge, testing, Guardrails, and omnichannel deployment.