How Law Firms Govern and Scale AI: Inside Gilbert+Tobin's Approach

Gilbert+Tobin scales AI firm-wide with CEO commitment, rigorous governance, and human accountability as its three core pillars.
Australian law firm Gilbert + Tobin partnered with OpenAI to develop an enterprise AI deployment model suited to highly regulated industries. Their approach rests on three pillars: CEO-led strategy to secure resources and overcome internal resistance; a robust governance framework defining use-case approval, data confidentiality, and output review; and an unwavering commitment to human accountability, ensuring professional judgment and final responsibility remain with lawyers. Beyond ChatGPT Enterprise for text tasks, G+T also deployed Codex for technical infrastructure, reflecting the depth and breadth of their AI adoption. This case offers valuable lessons for finance, healthcare, and other high-risk sectors.
AI Adoption Is More Than a Technology Problem: The Unique Challenges Facing the Legal Industry
As artificial intelligence moves from concept to enterprise deployment, the real challenges rarely lie in the technology itself — they lie in governance and scale. The collaboration between Australian top-tier law firm Gilbert + Tobin (G+T) and OpenAI offers a case study worth examining closely, particularly for professional services industries that operate under heavy regulation and demand uncompromising accuracy.
The legal industry is defined by rigor, confidentiality, and high stakes. Any misstep in AI application can carry serious compliance and reputational consequences. How G+T managed to roll out tools like ChatGPT Enterprise and Codex across the entire firm — while maintaining human accountability — has become a focal point for the broader industry.

CEO-Led Strategy: Top-Down Commitment to AI
Why Leadership Commitment Is Non-Negotiable
One of the most distinctive aspects of G+T's approach is that its AI strategy is driven directly by the CEO. This stands in sharp contrast to organizations that treat AI as an isolated initiative owned by the IT department or an innovation lab.
In professional services firms, partners and senior lawyers tend to approach new technology with caution, concerned about impacts on service quality and professional liability. Only when senior leadership takes a clear stance, commits resources, and assumes strategic ownership can AI adoption break through internal organizational resistance and become genuinely embedded in day-to-day workflows.
This top-down commitment sends a clear directional signal while laying the organizational foundation needed for governance frameworks and accountability mechanisms to take hold.
Rigorous Governance: Drawing the Boundaries of AI Use in a Regulated Environment
Building a Controlled Framework for AI Use
The distinctive nature of the legal industry means AI adoption must rest on strict governance. Rather than simply opening up AI tools to employees, G+T built a comprehensive governance system covering several dimensions:
- Use-case approval: Defining which business scenarios can incorporate AI assistance
- Data confidentiality: Establishing protocols for handling privileged client information
- Output review: Creating human review processes for AI-generated content
For a law firm, the confidentiality of client data is an absolute boundary. The choice to deploy ChatGPT Enterprise already reflects a heightened commitment to data security — enterprise versions typically offer stronger data isolation, commitments not to use data for model training, and additional compliance safeguards.
Finding the Balance Between Governance and Efficiency
The real challenge is striking the right balance between strict governance and improved efficiency. Overly rigid restrictions render AI tools effectively useless; overly relaxed controls risk triggering compliance failures. G+T's approach demonstrates that a governance framework should not be a constraint on innovation, but rather a set of "safety guardrails" that give employees the confidence to use AI responsibly.
This mindset applies equally to other highly regulated industries: effective AI governance isn't about saying "no" — it's about clearly articulating "yes, under these conditions."
Human Accountability: AI Augments Rather Than Replaces Professional Judgment
Professional Judgment Remains Central
A consistent principle throughout G+T's implementation is human accountability. No matter how capable the AI tools are, final professional judgment and responsibility always rests with the individual lawyer.
In legal services, AI can efficiently handle supporting tasks such as document drafting, case research, and contract analysis — significantly improving team productivity. But it cannot replace a lawyer's professional judgment, ethical considerations, or duty of care to clients. This positioning unlocks AI's productivity value while preserving professional standards.
Codex's Unique Role in Legal Tech
Notably, G+T also deployed Codex, the code generation tool. This reflects the fact that modern law firms' technology needs extend well beyond text processing — from building internal efficiency tools to developing legal tech applications, programming capability is becoming an increasingly important component of digital transformation in professional services.
Including Codex in the toolkit signals that G+T's AI adoption has moved beyond pure content generation into the realm of technical infrastructure.
Core Lessons for Scaling AI Adoption
The "Iron Triangle" Model: From Pilot to Firm-Wide Deployment
G+T's case reveals a clear path to scaling AI, which can be distilled into three critical pillars:
- CEO commitment: Strategic direction and resource allocation from the top
- Rigorous governance: Institutional safeguards covering data security, use-case approval, and output review
- Human accountability: Ensuring professional judgment and ultimate responsibility always rests with people
All three elements are essential — together, they form the core framework for enterprise-level AI deployment.
Lessons for Other Highly Regulated Industries
For industries such as finance, healthcare, and accounting — which share similarly high-regulation, high-risk environments — G+T's model offers broad reference value. Scaling AI deployment is never simply a matter of purchasing tools; it is a systemic undertaking involving organizational change, governance restructuring, and cultural transformation.
As enterprise AI products like ChatGPT Enterprise continue to mature, more and more professional services firms will face similar decisions. G+T's experience demonstrates that with proper governance and clear accountability, AI can be deployed safely even in the most demanding industries — and can become a powerful engine for competitive advantage.
Conclusion: Governance and Accountability Determine AI's True Value
Gilbert + Tobin's practice offers a mature template for enterprise AI adoption: technology is only the starting point — governance and accountability are what make scale possible. In an era of rapid AI proliferation, organizations that can meaningfully integrate leadership commitment, institutional constraints, and human judgment are the ones who will truly harness AI's power, rather than being constrained by its risks.
For every organization hoping to deploy AI responsibly, G+T's story is worth careful reflection: the value of AI ultimately depends on how well we govern it.
Related articles

Catalyst: A Vision for an Enzyme-Like Testing Framework for AI Agents
A developer shared Catalyst on Reddit, an Enzyme-inspired framework for AI Agents, exploring why agents need observable, testable dev tools and the design philosophy behind them.

The Real Capability of AI Coding Agents: Best Models Complete Only 35% of Feature Development Tasks
The 'Agents on Rails' benchmark finds top AI models complete only 35% of feature development tasks. What this means for coding agents and developer teams.

How to Prevent Duplicate Refunds After an AI Agent Crashes: CellaFlow's Durable Execution Approach
How can AI agents avoid duplicate refunds after a crash without deadlocking workflows? CellaFlow uses durable execution, shared work identity, leases, and fencing to solve safety and liveness in multi-agent systems.