Perspective

The Silent Risk Propagation Problem

What happens when companies ‘press play’ on contracts drafted, reviewed, and negotiated using GenAI?

A view from the GC perspective

The three of us have collectively spent almost a century in general counsel roles, across industries ranging from global consumer goods to education, financial services to energy. We have lived through the fax machine, the internet, e-signatures, and the first wave of contract management software. We have seen legal technology overpromise and underdeliver more times than we care to count.

We are not reflexive skeptics of AI. We are on the advisory board of Vichaara precisely because we believe that deterministic, auditable AI reasoning is not only possible but necessary. What concerns us is what is happening in the meantime: a broad and accelerating adoption of AI-native contracting tools that are generating outputs legal teams do not fully trust, while those same teams face productivity pressures that may leave less time to interrogate those outputs as deeply as they otherwise would.

The pressure is real and it is not going away

In 2025, 64% of in-house legal professionals reported pressure from corporate leadership to increase AI adoption, and 43% of law firm respondents reported the same.1 We do not find these numbers surprising. Every one of us received variants of that pressure throughout our careers, in different forms, from different directions. The mandate to do more with less is not new to legal.

What is new is the specific shape the pressure has taken. Legal teams are being asked to compress contracting cycle times, increase throughput per FTE, and manage more agreements per unit of time, without commensurate increases in headcount or budget. AI and especially AI-native tools are being offered as the answer.2 And in important respects, the tools are genuinely capable: AI models are getting better at generating convincing, professionally structured contract language.

That last point is precisely the problem. These tools are based on probabilistic Large Language Models (LLMs). As a practical matter, because LLMs are probabilistic systems, identical or substantially identical inputs can produce different outputs, and consistency cannot simply be assumed. The language is getting more convincing, but the certainty is not: evidence continues to show meaningful reliability and verification challenges in legal AI systems.34

And in a high-pressure contracting workflow, convincing language, even if grounded in probabilism, is enough to get a contract executed.

The can being kicked down the road

We want to be direct about what we are observing, because we think the legal industry has not yet fully reckoned with it.

When an in-house lawyer is managing a pipeline of fifty contracts per quarter, operating with a team that has not grown in two years, and under instruction from the business to turn documents faster, the risk is that an AI-generated contract analysis may not receive the level of scrutiny it deserves. A predictable response under those conditions is to do a quick human-in-the-loop review, catch what looks obviously wrong, and get the contract executed. The business is waiting. The counterparty has a deadline. The CFO wants the deal closed.

This is a predictable response to a structural mismatch between the volume of work being demanded and the capacity of the team delivering it. But it has a consequence that is not visible at the time of execution.

The risk is not being eliminated. It is being deferred. The contract gets signed. The risk gets embedded. And the business moves on, not knowing what obligations and exposures it has just committed to with less scrutiny than the agreement deserved.

We have each seen what happens years later, when a dispute arises over a provision that nobody properly understood at the time of execution. AI-assisted workflows increase that risk where outputs are accepted without sufficient examination.

The difference between now and earlier eras of contract risk is one of scale and speed. AI enables legal teams to process agreements faster than ever before. When the reasoning layer is unreliable, that speed multiplies the exposure.

What the contract says vs. what the contract does

Here is the distinction that we think the market has not yet internalized and that those of us who have spent decades managing contracts operationally understand in a way that technology vendors sometimes do not.

Much of the legal industry, and the AI tools being built for it, remains almost entirely focused on what a contract says. Clause extraction, obligation identification, risk flagging, playbook-driven redline review: all of these are document text-level activities. They are about reading the text and reporting on its content.

But contracts are not static documents. They are operational instruments. They govern what happens when an SLA is missed. They determine whether a penalty can be levied, and whether the notice and measurement procedures required to levy it were properly followed. They specify what constitutes a triggering event for a credit, and what the counterparty must do to preserve the right to claim it. They define the conditions under which a termination right can be exercised, and what procedural steps make that exercise valid.

Much of this can be missed by a document-level analysis that identifies clauses without formally reasoning over their relationships. The contract says what the SLA threshold is. What it does not surface, from a read of the text alone, is how that threshold interacts with the measurement methodology two provisions later, whether the notice obligation in the information governance clause is a condition precedent to the remedy, what the cure period does to the consequence regime before it activates, and whether a force majeure carve-out in a separate section suspends the SLA commitment entirely during certain events. It also does not clearly indicate the power and control a party must permit or prohibit an action, or if this connective tissue between party, permission, consequence, and remedy is torn. These are not questions about systems or operations. They are questions about the normative structure of the agreement itself: how the obligations, conditions, powers, and consequences relate to each other as a live system. Answering them with certainty requires deterministic reasoning over what the contract does, not just cataloguing what it says.

Everyone is focused on the contract at the point of signature. The operational reality begins the moment the ink dries. And in our experience, the contracts that create the most problems are not the ones with bad drafting. They are the ones where the decision makers did not fully understand what they agreed to do.

What happens when companies press play

The question we find ourselves asking, with increasing urgency, is this: what happens across the enterprise portfolio when contracts that were drafted, reviewed, and negotiated using outputs generated by AI-native tools begin to be operationally managed?

Penalties will be harder to levy. The procedural prerequisites for invoking a penalty clause are often more demanding than the clause language suggests. They require notice to be given in a specific form, delivered through a specific channel, within a specific window. They require measurement against defined benchmarks using agreed methodologies. They require cure periods to have run. A legal team that understood the contract at review and execution mainly through an AI-generated summary may not have flagged these procedural dependencies as thoroughly as a team that had the time to undertake a thorough manual review.

The stopgap is to provide AI tools to lawyers to enable them to participate in the review but do it more efficiently. The glib language output by these LLM-based AI tools for subsequent human review may not be fully trusted; but it is expedient, and expediency is a requirement to ensure higher throughput. This creates obvious exposure. The business will discover these gaps when it tries to enforce and finds the counterparty disputing the invocation on procedural grounds. In leadership meetings, our CFO colleagues have referred to this phenomenon as a driver of contract value leakage, and it is expensive, both in economics and credibility.

Credits may be harder to collect. Many commercial agreements include service credit mechanisms that are self-executing in theory but discretionary in practice. The right to a credit can expire if not claimed within a defined period. The measurement of the underlying performance may be contested if the agreement is ambiguous about methodology. An AI-assisted review that caught the existence of the credit regime may not have modelled, or modelled well, the conditions and procedures that make the right to claim it durable.

SLAs may be harder to enforce. Current AI tools can read a service level agreement and tell you that a 99.9% uptime commitment exists, that credits attach at 99.5%, and that the credit table escalates at each tier below that. That is genuine capability, and we do not dismiss it. What those tools cannot do with certainty is reason over the normative chain that determines whether the credit right is actually available in a given situation: whether the measurement period specified in the agreement has been correctly applied, whether the exclusion window for scheduled maintenance was triggered and properly notified, whether the aggregation methodology compounds monthly or resets, whether the credit claim procedure in the information governance provisions was followed in the form and within the timeframe the agreement requires, and whether a force majeure provision in a separate section suspended the commitment during the period being measured. Each of those is a condition. Each one is a gate. Miss any one of them and the credit right that the AI correctly identified does not materialize.

The question the contract itself can answer, and that any serious AI reasoning layer must be able to answer deterministically, is this: given facts supplied and the normative structure of this agreement, is the credit right available? In many cases, that question turns on identifiable conditions, procedures, sequencing, and the interaction of provisions across the document. Where those contractual rules produce a determinate outcome, a serious AI reasoning layer should reach that outcome consistently and provide a full audit trail showing how it got there. Where the contract is genuinely ambiguous, or where the outcome depends on contested facts, interpretation, judgment, or applicable law, the system should identify that uncertainty rather than conceal it behind a confident probabilistic answer.

To be precise about what this requires: the factual predicate, whether an SLA was breached, is supplied by the parties. What the reasoning layer determines, deterministically and with a full audit trail, is what the contract's normative structure requires to follow from that predicate: which conditions must be satisfied, which procedures must have been followed, and whether the remedy is actually available given the contractual rules that govern it. Where those rules do not yield a determinate answer, the system should surface the ambiguity for human judgment rather than manufacture certainty.

It is the difference between supplying the facts and reasoning over what the law of the contract says those facts produce.

In a high-stakes outsourcing agreement, or in a regulated industry where contractual commitments carry compliance consequences, that distinction is not a nuance. It is the entire question. And it requires consistent reasoning over the normative structure of the agreement, with an auditable trace showing exactly which conditions were evaluated, which were satisfied, and which were not. A probabilistic output that gets the answer right most of the time is not a substitute.

In these contexts, “most of the time means some of the time you are wrong,” and you will not know which time that is.

Agentic AI and the amplification of ungrounded risk

The conversation about AI in legal is moving faster than most practitioners realize. The current debate is about AI-assisted drafting and review: a lawyer uses an AI tool, receives an output, applies judgment, and moves on. That is already the scenario we have been describing in this paper. But the next phase, which is arriving now in enterprise legal technology, is agentic AI: systems that do not just assist a lawyer but act on behalf of one. They draft, negotiate, route for approval, flag obligations, trigger notices, and close loops in contracting workflows with minimal human intervention at each step.

We are not opposed to this direction. Agentic workflows, properly grounded, could represent a genuine step forward in how legal work gets done at scale. The operative phrase is properly grounded.

The concern is this: if the AI reasoning layer is probabilistic and not auditable at the point of a single human-reviewed conclusion, what happens when that same reasoning layer is operating autonomously across thousands of contracting events, without a lawyer reviewing each output before it drives an action? The risk does not merely persist. It compounds. Each agentic step taken based on ungrounded reasoning is a downstream commitment, a triggered notice, a waived right, or a missed obligation that the organization may not discover until it surfaces in a dispute.

Bjarne put it precisely in a recent exchange on LinkedIn: “agentic governance, both in the form of policy-led governance and in the form of technology-enabled rulesets, will be critical to securing sustainable and structured velocity at scale.” And we would add the dimension that our combined experience in general counsel roles makes clear: the ruleset in contracting must be the normative content of the contract itself, not a general-purpose policy layer built on top of probabilistic language generation.

Law is a mix of normative rules and judgment applied to those rules in context. When agentic systems are grounded in codified normative rulesets drawn directly from the contracts they govern, human lawyers can interact with those workflows with genuine confidence. They know what the agent knows. They know what rules it is applying. They can trace any action it takes back to the provision that authorizes it. That is governance with teeth.

Without that grounding, agentic legal workflows are operating on the same probabilistic foundation as the AI-assisted review we described earlier, except that the human review step has been compressed or removed. The velocity is higher. The exposure per unit of time is higher. And the silent propagation of risk, the problem we opened this paper with, becomes not a portfolio-level concern but a real-time one.

This is why we believe Vichaara's normative model addresses an important architectural problem in contract AI. It seeks to provide the grounding layer that makes agentic legal workflow trustworthy. The agent needs to know what the contract does: not in a probabilistic sense, but deterministically, with every conclusion traceable to a source provision. The quality of that grounding will increasingly determine whether an agentic system accelerates legal work responsibly or merely accelerates risk.

The scale of the exposure

We want to be precise about why we describe this as a propagation problem rather than an execution problem. It is not that individual contracts are failing. It is that the same gap, between what the AI said the contract means and what the contract does operationally, is being replicated at scale across every agreement that passes through an AI-assisted workflow without a formal reasoning layer.5

In a 2026 survey of more than 200 in-house and law firm leaders, 69.7% of AI outputs still required targeted edits or extensive rework.5 This finding is important, but it understates the problem, because it measures the rework that lawyers caught. It does not measure the risk that passed through review and was embedded in executed agreements.

Legal professionals spend an average of 3.1 hours reviewing a single contract.67 Under volume pressure, that time compresses. And as the language generation capability of AI models improves, their outputs can appear increasingly credible on a quick review. Yet available evidence continues to show meaningful reliability and verification challenges in legal AI systems.34 The resulting asymmetry is troubling: the tools are getting better at generating language that passes a quick review. The structural reasoning behind that language is not improving at the same rate.

Why we are backing Vichaara

We are not backing Vichaara because we are pessimistic about AI in legal. We are backing Vichaara because we believe that the legal industry needs an infrastructure layer that does what current LLM-first systems without a formal normative reasoning layer cannot: reason deterministically over the normative content of a contract, model what the contract does rather than just what it says and produce conclusions that are traceable to source provisions with a full audit trail.

The precision of the approach matters to us. Vichaara's focus on the core normative structure governing contracts, the obligations, conditions, powers, consequences, economic provisions, risk allocation, time-dependencies, and information flows that together determine what a contract does operationally, is the right level of abstraction for the problem we are describing. It is not enough to identify that a penalty clause exists. The infrastructure layer needs to model, with certainty, whether that penalty can be validly invoked, under what conditions, through what procedure, and with what consequence if the procedure is not followed.

In our view, legal AI systems that support high-stakes contracting, particularly those capable of autonomous or agentic action, will increasingly require a trusted reasoning layer capable of representing contractual rules with consistency, transparency and auditability. It is not that the language generation layer is not valuable. But language generation not grounded in deterministic normative reasoning produces confident-sounding output that the business will act on, and that the legal team will not be able to fully account for, at the moment it matters most.

We have each spent decades in positions where we were accountable for exactly that moment. That experience is why we find the silent risk propagation problem both familiar and urgent. The tools that create it are new. The consequences when it surfaces are not.


About the authors

  • Bjarne Tellmann. Former General Counsel, Haleon, Pearson, and GSK Consumer Healthcare; SVP/Deputy GC, Aramco; AGC, Coca-Cola; Author, Law in the Era of AI (Wiley, 2026)
  • Eva Kripalani. Co-Founder, OGC Network; Former EVP and General Counsel, KinderCare Learning Centers (10 years); Former Partner, Stoel Rives LLP; Co-Author, The Generalist Counsel (Oxford University Press)
  • Liz Large. Co-Founder, OGC Network; Former EVP & General Counsel, KinderCare Education; Former Contracted General Counsel, Portland Public Schools

Bjarne Tellmann, Eva Kripalani, and Liz Large are Strategic Advisors to Vichaara. The views expressed in this paper reflect their independent professional judgment based on their combined experience in general counsel roles.

Notes

  1. 1DISCO, "Poll Results: Generative AI and the Legal Profession in 2025" (26 November 2025). Follow-up survey of legal practitioners across law firms and in-house departments, conducted with Ari Kaplan Advisors. 43% of law firm participants reported feeling pressure from their leadership to adopt generative AI, and 64% of in-house legal participants reported pressure from their corporate leadership. Available at: csdisco.com/blog/poll-results-generative-ai-and-the-legal-profession-in-2025. 
  2. 2American Bar Association, 2024 Legal Technology Survey Report, Vol. I: Online Research (March 2025). AI adoption among private practice attorneys rose from 11% in 2023 to 30% in 2024, with 46% adoption at firms of 100 or more attorneys. Available at: americanbar.org. 
  3. 3Magesh, V., Surani, F., Dahl, M., Suzgun, M., Manning, C.D., and Ho, D.E., "Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools," 22 Journal of Empirical Legal Studies 216 (2025). DOI: 10.1111/jels.12413. Testing covered Lexis+ AI, Ask Practical Law AI, and Westlaw AI-Assisted Research across 202 legal queries hand-scored by legal experts; the tools hallucinated between 17% and 33% of the time. 
  4. 4Dahl, M., Magesh, V., Suzgun, M., and Ho, D.E., "Large Legal Fictions: Profiling Legal Hallucinations in Large Language Models," 16(1) Journal of Legal Analysis 64 (2024). The study ran more than 800,000 verifiable legal queries against four general-purpose models (GPT-4, GPT-3.5, PaLM 2, and Llama 2). 
  5. 5Factor, 2026 legal AI benchmarking survey (March 2026), as reported in Artificial Lawyer, "Legal AI Access at 83%, But Trust Issues Remain" (23 March 2026). Survey of more than 200 in-house and law firm leaders. Survey findings: "69.7% [of outputs] still require targeted edits or extensive rework. AI is accelerating drafting and research, but review and defensibility remain the main constraints on workflow-level scale." Available at: artificiallawyer.com. 
  6. 6LegalOn Technologies, "AI Adoption in Contract Review Doubles Year-Over-Year" (12 January 2026). Survey of 452 in-house legal professionals conducted with In-House Connect in December 2025. The survey found legal teams spend an average of 3.1 hours reviewing a single contract, and 87% of respondents say AI would benefit pre-signature contract review and redlining. Available at: legalontech.com. 
  7. 7LegalOn Technologies, "The State of Contracting in the Age of AI" (2024), as reported in Legal Dive, "AI's First Serious Foray into Legal May Be Contract Review" (8 August 2024). Survey of 150 legal professionals; nearly half reported spending three hours or more reviewing a single contract. Available at: legaldive.com. 
The path ahead

Bring deterministic reasoning to your contracts

Vichaara is the deterministic layer for high-stakes contract decisions: identical answers for identical inputs, every determination traced to the clause it came from. We are working with a small number of legal AI and CLM teams.

Get in touch →