Operating guides / Practical guide

Can ChatGPT review a contract? What it can and cannot do for a small firm

Operational guidance, not legal advice or regulatory advice. Your regulator's current publications are the authority; this is how one operator reads the position.

by Hamza Suleman. Published .

Someone in your firm has already tried this. A supplier agreement, an NDA, maybe a lease: pasted into a chatbot with "check this for anything nasty" and a hopeful pause. The answer came back fluent, structured and confident. The question for a firm of 2-20 fee earners is not whether the answer looked good. It is whether the firm can defend what happened next.

Direct answer

ChatGPT can read a contract and produce a plausible summary of what it says. It cannot review a contract in the sense a regulator, an insurer or a client would recognise: against the firm's own positions, under a duty of confidentiality, with a supervised human accountable for the result. Used as a private learning aid on documents that contain no client information, it is roughly harmless. Used on client documents, or relied on as the review, it creates three separate problems at once: confidentiality, competence and supervision. Proper AI contract review exists to close exactly that gap. A working definition worth keeping: AI contract review is a trained system reading a contract against a defined playbook and flagging where it deviates, while a named lawyer keeps the decision.

What ChatGPT genuinely does well

Credit where it is due. A general chatbot is a reasonable reading companion. It can explain what a limitation-of-liability clause is trying to do in plain English. It can summarise a thirty-page agreement into a page. It can list the clause types a document appears to contain. For a trainee getting oriented, or a practice manager trying to understand a supplier's terms before a meeting, that has real value and costs nothing.

Notice what those uses have in common: the document contains no client confidential information, and nobody is relying on the output for a decision that matters. That boundary is the whole game.

Where it breaks for firm use

Confidentiality leaves the building first. On consumer plans, what you paste can be used to improve the service unless the account settings say otherwise, and it travels to a third party's infrastructure under that party's terms. A client's settlement position, a counterparty's pricing, an employee's name in a dispute: all personal or confidential information the moment it is pasted. Under UK GDPR the firm is making a processing decision it has not documented, and under the SRA's confidentiality obligations the breach does not need the data to leak - the unauthorised disclosure is the paste itself. The ICO's guidance on data sharing and processors was not written for chatbots, but it fits them exactly.

It reviews against nothing. A chatbot has no playbook. It does not know your firm's positions on liability caps, indemnities, IP assignment or termination notice. Ask it the same contract twice and you can get two different answers, because nothing anchors the review to a standard. A review that cannot say "this deviates from our position" is a summary wearing a review's clothes.

Confidence is not accuracy. Generative systems produce fluent text whether or not the underlying claim is true. Invented clause references and misread cross-references are documented behaviour, not edge cases. The SRA's public warnings about AI have made the same point: the duty of competence and the duty to supervise apply to machine-drafted work exactly as they do to a junior's work. A skim-read of a confident answer is not supervision.

What supervised contract review looks like instead

The tools built for this job, including the one we are building, differ in kind rather than degree. The contract is read against a written playbook the firm controls, so every flag is a deviation from a stated position, not a vibe. Client data stays inside defined boundaries with contractual and technical safeguards a firm can show its insurer. And the output is drafted for review: a named fee earner sees what was flagged, why, and what was left alone, so supervision is a real act rather than a hope. That is the standard Margo is being built to, and it is why Margo is in controlled development rather than general availability: the review has to earn the supervision it asks for.

The small-firm verdict

Ban nothing and bless nothing. Write down one rule this week: no client document goes into a consumer AI tool, full stop, and any AI-assisted review a client relies on goes through a named fee earner against a written position. Two sentences in a policy document moves the firm from "someone is doing this quietly" to "the firm has a position", which is what your insurer and your regulator will each ask for in their own way.

If you want the fuller version, our half-day workshop exists for exactly this: map the workflows, set the data boundaries, agree the review rules, leave with the documents. It is £2,500 fixed, for firms of 2-20 fee earners in England and Wales. To test one workflow first, the free readiness score runs it through the checks in about ten minutes.

Frequently asked questions

Is it ever OK to paste a contract into ChatGPT? Only when the document contains no client or personal information and nobody will rely on the output: your own supplier terms you are reading for general understanding, for example. The moment client information is involved, the firm's confidentiality and UK GDPR obligations are engaged, and "I removed the names" is not a safeguard - context re-identifies parties constantly.

Does removing names make a contract safe to paste? No. Deals are identifiable from dates, values, sectors and counterparties. Anonymisation is a technical standard, not a find-and-replace, and a chatbot prompt is the wrong place to attempt it.

What should we tell fee earners who already use it? Do not make it a discipline issue; make it a routing issue. They adopted it because it saves time, which is a signal the firm needs a sanctioned route. Give them the one rule above, name the approved alternative, and ask what they were using it for - that list is your workflow map.

Will ChatGPT get good enough to replace contract review? It will keep getting better at reading. The parts that make a review a review - your playbook, your confidentiality duties, a supervised human answerable for the result - are not features that arrive in a model update. They are decisions a firm makes and documents.

How is Margo different from pasting into a chatbot? Three ways: the review runs against a written playbook the firm controls, client data is handled inside defined boundaries rather than a consumer service's terms, and every output is structured for a named lawyer's review. Margo is in controlled development; join the waitlist if you want to see it as it hardens.

Sources