In-House Counsel

The Next Legal AI Problem Is Not Hallucination. It Is Authorization.

As AI moves from answering questions to conducting transactions, accuracy is no longer enough.

Imagine an AI agent reviewing a supplier agreement. It reads the limitation of liability correctly, compares it with the company’s standard, concludes that the deviation is relatively minor, and accepts the agreement.

The analysis may be flawless. The decision may still be unauthorized.

For the past several years, much of the legal conversation about AI has focused on accuracy. Does the system understand the question? Did it identify the governing law? Did it invent a case? Did it summarize the contract correctly?

Those questions remain important. But as AI moves from answering questions to conducting transactions, accuracy is no longer enough. The next major legal AI problem is authorization.

B2B agents will not merely summarize information. They will make purchases, negotiate terms, approve changes, initiate payments, renew subscriptions, and communicate commitments to counterparties. At some point, an agent will move from telling someone what an agreement says to doing something because of what the agreement says.

That is a fundamentally different kind of risk.

A system might correctly determine that a proposed indemnity provision is common in the market. But does it have authority to accept it? It might accurately identify a price increase permitted by an existing contract. But can it renew at that price? It might negotiate a limitation of liability that falls within the company’s usual range. But what if the transaction involves regulated data, a critical supplier, or a business unit with different approval requirements?

Correct interpretation does not establish permission to act.

Human organizations manage this distinction every day, although often imperfectly. A commercial lawyer may understand what a clause means but still need approval from the general counsel. A procurement professional may negotiate price but lack authority to approve a data-use provision. A business leader may have spending authority but no authority to depart from the company’s security requirements.

Experienced employees navigate these boundaries using policies, approval matrices, negotiation playbooks, institutional knowledge, and judgment. Sometimes they ask. Sometimes they escalate. Sometimes they know that an apparently ordinary issue becomes extraordinary in a particular context.

AI agents will need the same boundaries, made far more explicit.

That means legal teams should begin thinking beyond whether an agent can read a contract. They should ask what the agent is allowed to do with what it reads.

What decisions can it make independently? Which positions may it accept? How far may it deviate from the company standard? Does its authority change based on transaction value, data sensitivity, geography, counterparty, or business criticality? What requires approval, and from whom? When must the agent stop entirely?

These are not primarily prompting questions. They are governance questions.

Many companies will discover that their answers are scattered across policy documents, contracting playbooks, delegation-of-authority schedules, emails, and the memories of experienced employees. Some answers will conflict. Others will amount to “ask Legal” or “use judgment,” instructions that work poorly when translated into autonomous action.

This is where in-house lawyers have an immediate role. Legal teams understand that authority is contextual, that a familiar clause can create an unfamiliar risk, and that being within market range does not necessarily make a decision acceptable for this company or this transaction.

Lawyers should help design the authority layer before transactional agents are widely deployed. That layer should include clear decision rights, approved positions, prohibited commitments, permitted deviations, escalation triggers, and reliable records of who or what authorized each action. It should also account for the possibility that an agent may be highly confident and still lack permission.

Hallucinations are visible failures. An invented case or nonexistent clause can often be identified and corrected. Unauthorized action may look entirely competent until the company discovers that its agent made a commitment no one intended to approve.

The legal question of the next phase will not be only, “Did the AI get it right?”

It will be, “Who gave it the right to decide?”


Olga V. Mack is the CEO of TermScout, where she builds legal systems that make contracts faster to understand, easier to operate, and more trustworthy in real business conditions. Her work focuses on how legal rules allocate power, manage risk, and shape decisions under uncertainty. A serial CEO and former General Counsel, Olga previously led a legal technology company through acquisition by LexisNexis. She teaches at Berkeley Law and is a Fellow at CodeX, the Stanford Center for Legal Informatics. She has authored several books on legal innovation and technology, delivered six TEDx talks, and her insights regularly appear in Forbes, Bloomberg Law, VentureBeat, TechCrunch, and Above the Law. Her work treats law as essential infrastructure, designed for how organizations actually operate.