AI × Legal × Compliance × Governance

The AI Transformation of Legal and Compliance Functions

We are witnessing a fundamental shift: from external standard solutions to company-specific, AI-powered applications. At the intersection of innovation speed and regulatory responsibility, a new paradigm for Corporate Legal and Compliance is emerging.

Dr. Nicolai Kruck
Dr. Nicolai Kruck, MLE — Compliance by AI
The Starting Point
Why Standing Still Is the Greatest Risk

The pace of AI development exceeds the adaptability of traditional corporate structures. 88% of all organizations already use AI in at least one function (McKinsey, 2025) — yet only 6% have fundamentally redesigned their workflows. The remaining 94% risk being overtaken by the next wave of disruption.

A paradigm shift is particularly evident in Compliance, Governance, Risk and Legal: companies are moving away from rigid, externally sourced standard solutions toward flexible, internally developed AI applications tailored to their specific regulatory requirements.

The Central Tension

⚡
Innovation Side
Speed
Automation
Competitive Advantage
Efficiency Gains
⟷
🛡️
Regulatory Side
GDPR / EU AI Act
IT Security
Auditability
Accountability

Massive Automation of Knowledge Work

McKinsey estimates that 22% of lawyer activities and 35% of legal assistant work are automatable with current AI. Goldman Sachs puts automatable legal tasks at 44%.

▸ Read deep dive
+
The Data: Where Does Automation Really Stand?

McKinsey's report "Agents, Robots, and Us" (November 2025) sharpened the debate: 57% of all U.S. work hours are potentially automatable with today's technology — nearly double the 30% estimate from 2023. For the legal sector, the numbers are particularly striking. Legal and Administrative Services rank among the occupations with the highest automation potential — together representing 40% of all U.S. wages in highly automatable roles.

Goldman Sachs' study "The Potentially Large Effects of AI on Economic Growth" (2023) remains a key reference: 44% of all legal tasks are automatable by generative AI — the highest rate among all knowledge professions, ahead of financial services (35%) and management (32%). The OECD confirms this trend: Legal professions rank globally among the top 5 most AI-exposed occupational groups.

What Gets Automated — and What Doesn't

Automation doesn't blanket "legal work" — it targets specific task types: document review and classification, regulatory research, standard contract drafting, compliance monitoring, and reporting. What remains non-automatable: strategic legal counsel, negotiation, judgment calls under uncertainty, novel legal questions, and ethical balancing of conflicts of interest. McKinsey emphasizes: Over 70% of skills demanded by employers today will remain relevant in an AI-dominated workplace — though applied differently.

"Everyone is experimenting, but almost nobody is transforming. Only 6% redesign workflows and win — the other 94% become footnotes."

— LawFuel, Analysis of McKinsey AI Report 2025
The Scaling Problem: Adoption Without Transformation

McKinsey's Global AI Survey 2025 (~2,000 executives): 88% of companies use AI, but only 39% report measurable EBIT impact. For most, the effect is below 5%. Only 6% of companies — McKinsey's "high performers" — fundamentally redesign their workflows. The rest apply AI to decades-old processes.

🔮 Outlook & Recommendations

Companies must act now: Conduct a systematic task analysis — which legal tasks are automatable, which require human judgment? Launch pilot projects with measurable KPIs, not enterprise-wide visions. Prioritize upskilling — McKinsey shows demand for "AI fluency" in job postings has grown sevenfold in two years. Organizations without AI-competent legal teams in 12 months won't be able to recruit them.

From Buy to Build: Companies Becoming Software Developers

Low-code platforms, foundation models, and agentic AI enable legal and compliance teams to build custom applications — without traditional IT projects, faster and more precisely than any off-the-shelf solution.

▸ Read deep dive
+
Why the Barrier to Entry Has Fallen

Foundation Models (OpenAI's GPT-4o, Anthropic's Claude, Meta's Llama, Mistral's Mixtral) provide expert-level language understanding via APIs — for pennies per query. Frameworks like LangChain and LlamaIndex orchestrate complex RAG workflows incorporating proprietary documents. Platforms like n8n, Make, and Microsoft Power Platform enable non-programmers to configure AI agents visually.

BCG's "Build for the Future" report (2025): Only 5% of companies are "Future-Built" generating scaled AI value. 60% report minimal results — often because they rely on generic solutions that don't address their specific governance requirements.

Practical Examples of Successful Internal Development

McKinsey "Lilli": Used by 75% of 43,000 employees monthly, converting 50,000+ consulting hours into higher-value analysis. PwC "ChatPwC": Generates compliance reports for 75,000+ trained employees. Klarna: The Swedish fintech replaced capabilities previously handled by Salesforce, Workday, and external firms — CEO Sebastian Siemiatkowski reported AI agents handling work equivalent to 700 customer service employees.

"Organizations with defined AI strategies are 2x more likely to experience revenue growth and 3.5x more likely to realize critical AI benefits."

— Steve Hasker, CEO Thomson Reuters, 2026
Data Sovereignty as Strategic Driver

For European companies, data sovereignty is the central build argument. GDPR, the EU AI Act, and sector-specific regulations require control over data flows. Gartner projects: By 2027, 35% of countries will be locked into region-specific AI platforms. European companies building internal competence now gain strategic independence.

🔮 Outlook & Recommendations

Pursue a hybrid build-buy strategy: Cover standardized tasks with established tools, but build internal competence for company-specific compliance applications. First step: A concrete pilot project in 4–6 weeks — e.g., a RAG-based policy chatbot. Deloitte's State of AI Report (2026): Only 1 in 5 companies has a mature AI governance model. Building capability now creates sustainable competitive advantage.

Agentic AI: From Assistants to Autonomous Agents

Gartner predicts that by 2026, 40% of all enterprise applications will integrate AI agents (today: under 5%). In legal, agents will independently research, review, and prepare compliance decisions.

▸ Read deep dive
+
What Distinguishes Agentic AI from Current Tools

Current AI tools work reactively: humans ask, AI responds. Agentic AI marks a paradigm shift — systems that autonomously plan, decide, act, and learn from results. Gartner's Anushree Verma describes five stages: From AI assistants (2025) through task-specific agents (2026) and collaborative multi-agent systems (2027–2028) to the "new normal" (2029), where 50%+ of knowledge workers create and govern agents.

McKinsey's 2025 Global AI Survey confirms: 62% of companies are already testing AI agents, with adoption fastest in IT, knowledge management, and customer service.

Agentic AI in Legal: Concrete Developments

Thomson Reuters CoCounsel launches agent-based legal workflows in early 2026 with autonomous document review and "Deep Research." LexisNexis Protégé deploys four specialized agents collaborating on complex workflows. Harvey AI, used by Allen & Overy and PwC Legal, develops specialized legal agents for contract drafting, regulatory analysis, and litigation support. Gartner predicts zero-touch contracting for low-risk agreements and 95% accuracy in surgical redlining for 2026.

"AI agents will evolve rapidly, progressing from task-specific agents to agentic ecosystems — transforming enterprise applications into platforms enabling seamless autonomous collaboration."

— Anushree Verma, Sr Director Analyst, Gartner (August 2025)
The Governance Challenge: Who Controls the Agents?

Gartner warns: Over 40% of agentic AI projects will be canceled by end of 2027 due to escalating costs or unclear business value. Additionally, over 2,000 "death by AI" legal claims are expected by end of 2026. The EU AI Act requires human oversight (Art. 14) for high-risk systems — including agent-based ones.

🔮 Outlook & Recommendations

Prepare now: Build an Agent Governance Framework — which decisions can agents make autonomously, where is human-in-the-loop mandatory? Implement audit trails for every agent action. Build agent management competence internally: Gartner expects 50%+ of knowledge workers to create agents "on demand" by 2029. Legal departments that don't build this capability become the bottleneck of the enterprise AI strategy.

EU AI Act: Compliance Becomes Mandatory

The EU AI Act is in force — but the 2026 “Digital Omnibus” deferred the high-risk obligations: Annex III now applies from Dec 2027, embedded systems from Aug 2028. Transparency duties (Art. 50) and a new nudifier/CSAM ban stay on the 2026 track. Penalties up to €35M or 7% of global revenue.

▸ Read deep dive
+
The Regulatory Timeline

The EU AI Act (Regulation 2024/1689) is enforced in three stages: Since February 2025, prohibitions on unacceptable AI practices apply. From August 2025, transparency obligations for general-purpose AI (GPAI) take effect. High-risk obligations were originally set for August 2026; the 2026 “Digital Omnibus” pushed them to Dec 2027 (Annex III) and Aug 2028 (embedded systems). Transparency duties (Art. 50) stay on 2 August 2026.

AI systems in administration of justice and democratic processes (Annex III, Point 8) are classified as high-risk. Obligations include: risk management (Art. 9), data governance (Art. 10), technical documentation (Art. 11), logging (Art. 12), transparency (Art. 13), human oversight (Art. 14), and accuracy/robustness/cybersecurity requirements (Art. 15).

International Regulatory Pressure

The Colorado AI Act takes effect June 2026. The Illinois AI in Employment Act has been in effect since January 2026. ABA Formal Opinion 512 (July 2024) requires lawyers to have "reasonable understanding" of AI tools. Gartner projects: By 2026, 80% of organizations will formalize AI policies addressing ethical, brand, and PII risks.

"2026 marks the emergence of a new divide among organisations: those that adopt an AI strategy and those that do not."

— Steve Hasker, CEO Thomson Reuters
Conformity Assessment: Practical Steps

Compliance with the EU AI Act requires: AI inventory, risk analysis per system, technical documentation, human oversight mechanisms, and audit trails. ISO/IEC 42001:2023 (AI Management Systems) provides a compatible international framework. Organizations implementing this standard simultaneously build the foundation for EU AI Act compliance.

🔮 Outlook & Recommendations

Even with high-risk deadlines now moved to 2027/2028, transparency and GPAI duties already apply — organizations serving the EU market should act now: create AI inventories, assign risk categories, build governance structures. Penalties — up to €35M or 7% of global revenue — make inaction an existential risk. Yet compliance is a strategic enabler: Organizations with mature AI governance can scale faster. Thomson Reuters shows: Organizations with defined AI strategies are 2x more likely to achieve revenue growth and 3.5x more likely to realize critical AI benefits.

The In-House Power Shift

52% of in-house counsel actively use GenAI (ACC/Everlaw, 2025) — doubling from the previous year. 64% use AI specifically to reduce dependence on outside counsel.

▸ Read deep dive
+
The Numbers Behind the Power Shift

The ACC/Everlaw GenAI Survey 2025 documents one of the fastest adoption waves in legal market history: GenAI usage in legal departments more than doubled in one year — from 23% to 52%. Notably, 64% of in-house teams expect to depend less on outside counsel through internally built AI capabilities. Routine work traditionally outsourced to law firms is increasingly handled internally.

What Drives the In-House Power Shift

Three factors converge: Availability of powerful tools (CoCounsel, Harvey AI, Luminance), cost pressure (internal AI review costs a fraction of external hourly rates), and data control (internal solutions avoid sensitive data transfers to third parties).

Forrester tempers the hype: Their 2026 predictions declare the "AI hype period over," projecting enterprises will defer 25% of planned AI spending into 2027 due to ROI concerns. Only 15% of AI decision-makers reported EBITDA improvements in the past 12 months.

"The gap between inflated vendor promises and value delivered is widening, forcing market correction."

— Sharyn Leaver, Chief Research Officer, Forrester (2026 Predictions)
New Competencies: The GC as Technology Strategist

The power shift fundamentally changes the General Counsel's profile. McKinsey confirms: Companies with active C-suite participation in AI initiatives achieve measurable value 2.6x more often. Gartner's "Predicts 2026: AI and Agentic AI Will Enable Legal Self-Service" forecasts that agentic AI will transform legal departments through higher lawyer productivity, internal self-service, and automated routine contracts.

🔮 Outlook & Recommendations

The in-house power shift is no longer a prediction — it's happening. Legal departments must position themselves as strategic technology functions: Double legal-tech budgets, build interdisciplinary teams (lawyers, data scientists, process experts), and offer AI governance as internal advisory. Law firms without demonstrable AI capabilities and transparency will lose market share — the question is not whether, but how fast.

Strategic Action Areas
Three Levers of AI Transformation
The key factors that will determine the success and relevance of legal and compliance functions in the years ahead.
🏗️

Build Instead of Buy

Rigid standard solutions with long implementation cycles are being replaced by in-house AI applications. Foundation models like GPT-4, Claude or Llama make it possible to develop domain-specific legal and compliance tools in weeks rather than years — adapted to your own governance, data and risk landscape.

Build vs. Buy • Sovereignty • Time-to-Value
🤖

Agentic AI & Low-Code

The next generation of AI no longer just reacts to prompts but plans, decides and acts autonomously. Combined with low-code/no-code platforms, AI agents emerge that independently conduct compliance reviews, contract analyses and due diligence processes — under human oversight, but with speed and consistency far superior to manual processes.

AI Agents • No-Code • Automation
🛡️

Governance by Design

Innovation without a control framework is negligent. The EU AI Act, GDPR and industry-specific regulation require that AI governance be built into the architecture from the start — not retrofitted. Only 1 in 5 companies has a mature governance model for autonomous AI systems (Deloitte, 2026). Those who invest early gain room to maneuver.

EU AI Act • GDPR • Risk Management

92%
of legal professionals now use AI in their work (Ironclad 2026; 2024: 74%)
10–20%
of legal tasks AI can complete autonomously today (Harvey benchmark, via Point Nine)
$16.5B
combined valuation of Harvey & Legora in the 2026 legal-AI arms race
Dec 2027
new EU AI Act deadline for high-risk systems (Annex III) after the “Digital Omnibus” deferral

Sources: Ironclad State of AI in Legal 2026 · Point Nine / Louis Coppey 2026 · TechCrunch & PlatinumIDS (funding 2026) · Thomson Reuters 2026 · EU AI Act “Digital Omnibus” (Gibson Dunn 2026)


In-Depth Analyses
Six Perspectives on AI Transformation
Six current analyses (as of 2026) on AI transformation in legal and compliance — with concrete data, market figures and verified further sources.
01 — MARKET MATURITY

Legal AI is far from done

Why the market is still early despite billion-dollar valuations — the Point Nine thesis
▸ Read article
+

Despite record funding, legal AI is only getting started. Louis Coppey (Point Nine) lays out the math: the legal services market exceeds $1 trillion, legal software is only tens of billions — and legal AI merely hundreds of millions so far. If AI takes over most legal work, that implies room to grow well over 1000x.

What AI can actually do today

A benchmark of more than 1,250 tasks (built with Harvey) shows the sober reality behind the hype: AI currently completes only 10–20% of legal tasks autonomously. The far larger share still needs human direction, context and judgment.

No one has locked up the market

A survey of roughly 100 law-firm decision-makers shows that Harvey and Legora are still being compared against generic LLMs and custom builds. Switching costs are low — nobody has closed the market.

The next stage: from “model + RAG” to real research

Today’s tools mostly deploy frontier models with RAG. The next edge, Coppey argues, comes from deep technical innovation: per-case specialized models, “test-time adaptation” and long-running agents for complex matters — e.g. the research start-up grubel around Moritz Hardt and Reinhard Heckel, with angels such as Jeff Dean and Chris Ré.

Core thesis: Legal AI is far from done. For decision-makers that means: don’t bet prematurely on a supposed “winner” — preserve optionality, evaluate on your workflows, and build the ability to integrate new models fast.

02 — MARKET & CAPITAL

The billion-dollar legal-AI arms race

Harvey, Legora & co.: record funding in 2026 — and what it means for buyers
▸ Read article
+

In 2026 legal AI is also a capital-markets story. Harvey reached a valuation of about $11 billion in March 2026 (round led with GIC and Sequoia), with more than 100,000 lawyers across 1,300+ organizations — with reports pointing toward $15B by August 2026.

Legora is catching up

Swedish challenger Legora hit roughly $5.55 billion (a $550M Series D led by Accel), tripled its valuation in five months, and reported about $100M ARR in only ~18 months.

The overall market

The legal-AI market is estimated at around $5.6B for 2026 and projected to reach about $10.8B by 2030 (CAGR ≈28%). Capital is flowing mainly into distribution and frontier models.

What it means for buyers

  • High valuations do not equal market maturity — switching costs remain low.
  • Test multiple vendors on real workflows, not demos.
  • Prioritize data sovereignty, traceability and exit options to avoid vendor lock-in.

Perspective: The real test isn’t valuation but whether vendors deliver genuine reliability on complex matters — beyond “model + RAG.”

03 — ADOPTION & ROI

From adoption to measurable value

92% use AI — but only 18% measure ROI. The 2026 reality check
▸ Read article
+

Usage is mainstream: per Ironclad’s “State of AI in Legal 2026,” 92% of legal professionals use AI (2024: 74%), 97% report measurable business outcomes, and 42% reduce outside-counsel spend.

The ROI gap

Thomson Reuters shows the flip side: only 18% of legal departments measure ROI at all (82% don’t or are unsure). 87% expect AI to be central within five years — yet only about 40% use it organization-wide today.

The workload paradox

AI saves time per task — yet 88% of teams report increased workloads as expectations and volume grow. Efficiency alone isn’t enough.

What leading teams do differently

Organizations with a formal AI strategy are more than 3x more likely to realize positive ROI. In-house adoption already sits near 87% — the leaders define clear KPIs, error/accountability policies and governance.

Lesson learned: The question isn’t “Are we using AI?” but “How do we measure success?” Tightly scoped pilots with KPIs beat enterprise-wide visions without measurement.

04 — AGENTIC AI

From assistants to autonomous agents

Agentic AI in legal: 15% in use, 53% planning — potential and limits
▸ Read article
+

The next step is systems that don’t just answer but plan, act and learn from results. Per Thomson Reuters, 15% of legal departments already use agentic AI and 53% are planning or evaluating it.

Long-running agents

Point Nine sees the next edge exactly here: long-running agents that work complex cases across many steps — rather than a single prompt. That requires case-specific data, robust evaluation and real research, not just a frontier model with RAG.

The limits are real

Because AI completes only 10–20% of legal tasks autonomously today, the human stays accountable. Agents accelerate — they don’t replace legal judgment.

Governance first

Deploying agents demands an agent-governance framework: which decisions can an agent make autonomously, and where is human-in-the-loop mandatory? Audit trails for every agent action are essential.

Outlook: Agentic AI is the most exciting but least mature frontier. Value appears where reliability and control meet autonomy.

05 — REGULATION

EU AI Act 2026: the timeline has shifted

The “Digital Omnibus” defers the high-risk obligations — what actually applies now
▸ Read article
+

An important correction to the previous roadmap: the 2026 “Digital Omnibus” package significantly defers the EU AI Act’s high-risk obligations.

The new deadlines

  • Stand-alone high-risk systems (Annex III): compliance now from 2 December 2027 (instead of 2 August 2026).
  • Systems embedded in regulated products (Annex I): from 2 August 2028.

What already applies

The transparency duties (Art. 50) — e.g. labeling AI interactions and content — remain on 2 August 2026. GPAI obligations have applied since August 2025 and the bans on unacceptable practices since February 2025. A new prohibition on “nudifiers”/CSAM (Art. 5) has a transition to December 2026.

What it means for legal & compliance

More time for high-risk conformity — but transparency and GPAI apply now. The sensible answer remains “governance by design”: establish an AI inventory, risk classification, documentation and human oversight early. Penalties (up to €35M or 7% of global revenue) remain.

Perspective: The deferral is runway, not a free pass. Building governance now means you’re ready when obligations bite — and can scale AI faster because the questions are answered.

06 — BUILD VS. BUY

Build vs. buy & the in-house power shift

In-house adoption at 87%, outside-counsel spend −42% — the 2026 make-or-buy question
▸ Read article
+

Legal departments are bringing capability in-house. In-house adoption of legal AI sits at roughly 87% in 2026, and 42% of users cut outside-counsel spend with it.

Why build is realistic today

Foundation models via APIs, RAG and low-code lower the barrier. Company-specific compliance apps can be prototyped in weeks — with your own governance, data sovereignty and response speed.

Why buy still matters

Established platforms bring maturity, certifications (SOC2, ISO 27001) and maintenance. For highly standardized tasks (eDiscovery, CLM, research), buying is often faster.

Optionality is the real strategy

Because switching costs are low (Point Nine) and the market is still moving, the smartest stance is a hybrid model: buy the standard, build core competence and sensitive, governance-critical apps yourself — and re-evaluate vendors regularly.

Recommendation: Start with a tightly scoped internal pilot (e.g. a policy chatbot), measure results rigorously, and build an interdisciplinary team of legal, IT and process in parallel.

✍️ Real Voice
My Own Thoughts
In this section you will find texts written exclusively by me — Dr. Nicolai Kruck — personally. No AI, no automation, no generated content. Just my own reflections, experiences and perspectives.

Why this section? This website is deliberately an experiment. Design, structure and all other content on this site were created entirely by Artificial Intelligence – from the layout to the texts to the source research. I wanted to test what is possible today when you let AI create an entire web presence.

This "Real Voice" section is the deliberate exception: here I write myself. Authentic, unpolished, human. Because in the age of AI, the real, personal voice becomes more valuable than ever.

🤖 All other content on this website was generated by AI

THE FUTURE IS NOW – AND TOMORROW IT WILL BE DIFFERENT

Dr. Nicolai Kruck · February 2026
✦ Click to read
+

Hello dear visitors,
in this section of my website theailawyer.org you will find exclusively content created by me personally – AI-generated content has no place here.

This creates a space on this site where I can share my personal views and commentary. I also use this section to explain the background and purpose of this project.

Why did I create theailawyer.org?

As a lawyer, my involvement with IT issues was for a long time primarily that of a requirements provider – defining what I needed in terms of legal and compliance applications and presenting those requirements to an IT department or an external vendor. I would then wait (often for weeks) for results. I was generally glad when my computer worked and I could simplify my professional and personal life with a bit of IT support. I had never shown any particular interest in the technical side of things. That world seemed too cumbersome and abstract to me, and I assumed it would stay that way forever.

When I took on my current role in data protection in 2018, I inevitably engaged more deeply with the topic of data and IT systems. But a genuine interest in IT subjects still did not develop.

When OpenAI released ChatGPT based on GPT-3.5 in November 2022, news of the AI revolution reached me too, and I began looking more closely at the topic in early 2023.

As was probably the case for most of us, I was deeply impressed and fascinated by the results these language models were producing. The spark was lit. I found it particularly exciting to think about and discuss how this new technology could be meaningfully integrated into my day-to-day work and into large corporate organisations, and I ran several projects on this with my team.

Then came January 2026: I heard about Claude Code through my information channels and did not hesitate to sign up for the somewhat more expensive account. This experience has fundamentally changed my perspective on the subject. Since mid-January, I have been spending a great deal of time running all kinds of projects with Claude.

The website theailawyer.org is one of the outcomes of my efforts to become productive with Claude Code.

If someone had told me a few weeks ago that I could build and run my own website, I would simply have laughed at them. Today I know that ANYONE (reasonably tech-open and curious) with a computer and internet access can build and run a website.

With this website I therefore pursue two goals: on the one hand, it serves as an experimental playground to discover and demonstrate what is possible with AI in February 2026. On the other hand, I want this website to be a platform for examining the use of AI in a legal context. That aspect has two dimensions for me: 1. How can lawyers use AI directly to work more effectively? 2. How can lawyers use AI to independently develop and operate the tools they need?

My Experimental Playground

This website and its content (with the explicit exception of this section) are 100% AI-generated. I did not write a single word of the content myself, and I did not write a single line of code for it. The website currently visible is the result of many prompts and several conversations with Claude to overcome technical hurdles. I will continuously evolve the website as I develop new ideas and find ways to implement them.

How can others do the same? Simply ask Claude (or any other AI of your choice)!

An Information and Exchange Platform

This website is not intended for AI experts. Rather, I want to publish information and perspectives here on the meaningful and effective use of AI in the legal field and in particular within large corporations.

I am of course aware of the irony of having an AI shed light on the question of what impact the AI revolution will have on the work of lawyers. It will be fascinating to see whether and how the AI assesses its own role, and what future scenarios and visions it presents to us. I want to make clear that the content is generated by an AI. My intervention will initially consist of influencing the strategic direction of the content when I feel that is necessary. I would also intervene if objectively incorrect information were to be presented. When I want to add or change substantive topics, I always craft my prompts so that the AI is guided by verified information and sources and applies academic standards. There should always be evidence and references wherever possible.

My First Experiences

After just the first few hours of my tentative experiments with Claude Code, it was clear to me that the AI revolution has now genuinely arrived and it is not an exaggeration to speak of a revolution. I would even go so far as to call it a genuine liberation. With these new tools it is possible to independently design and deploy applications. There seem to be almost no limits to creativity.

As lawyers, we were always (only) the requirements providers for IT systems. We had to explain to IT colleagues or external service providers which tools, workflows, upload fields and buttons we needed in order to, for example, digitalise a data protection management system or a business partner due diligence process. Weeks later we would see results, and the next release would then be many months away again.

Those days are probably over. I am firmly convinced of that. Compliance and legal applications can be brought to at least an MVP stage with good prompting (Vibe Coding) in a manageable amount of time – and it is actually great fun. In just a few hours I created a family app (shared shopping list, shared calendar, shared expense tracking, chat function) and got it running synchronously on our smartphones. In just a few hours I prompted the basic framework for a data protection management platform. Creating and launching this website was also accomplished in just a few working hours. I have not hit any limits so far, and the AI has made no promises about feasibility that ultimately could not be kept.

That is why I am so full of enthusiasm and drive. With this technology I am reaching an entirely new dimension of effectiveness, productivity and creativity. There seem to be no limits, and opportunities are opening up that I would never have dared to dream of. It feels as though an insurmountable barrier has suddenly fallen.

Perhaps the assessments of Matt Schumer ("Something big is happening") are infused with a generous dose of Bay Area hype. But I do see a substantial core to them.

Also very fascinating are the developments around OpenClaw (https://openclaw.ai); here you can set up an agent that independently handles digital tasks (from managing your inbox to maintaining your social media presence). At present, this approach raises significant security concerns, as the agent must take on extensive permissions of the user in order to carry out these tasks. I will report promptly once I have explored the topic further.

What Does This Mean for Legal and Compliance Departments in Companies?

AI-driven support for lawyers in transactional legal work, in capturing and summarising facts, in researching case law and commentary, or in drafting submissions and opinions should by now have reached in-house counsel too. Numerous providers have positioned themselves and are offering these services, some with slightly different features and capabilities. We will see which providers survive the competition that is now emerging.

Even more interesting from my perspective is the question of the future of developers and vendors of legal and compliance software such as EQS, Proxora or OneTrust. If the trends that are clearly taking shape continue to confirm themselves, compliance and legal departments will soon be able to independently design and operationalise this kind of software. This would bring not only cost advantages for companies. Companies would also be able to build a tool precisely tailored to their needs and could respond very flexibly to requirements for adjustment, without being dependent on slow-moving external forces. They would also have complete sovereignty over their data.

Companies that master this approach will have an enormous competitive advantage.

Naturally, creating a first "theoretical" tool or an MVP is only the beginning, and there are several hurdles to clear before end users within a company can operationally use a newly self-developed tool. The focus will likely be on IT security questions, documentation and IT compliance. But questions such as quality assurance, comprehensive and documented testing, and ongoing maintenance also need to be resolved.

The demands placed on IT departments in supporting such processes are likely to change significantly, and the success or failure of such projects will depend largely on a functioning symbiotic collaboration between requirements providers, internal IT/AI experts and other stakeholders.

What I perceive above all as a major challenge is the breathtaking pace of technological development and the possibilities that come with it. Tasks the AI could not perform – or performed only poorly – six months ago work very well today. Approaches that were state of the art a year ago are already ruthlessly outdated. This rapid pace will accelerate further, and the great skill will be in identifying the truly relevant changes and implementing them accordingly.

What does this mean for large corporations? If the future changes (too) quickly, there is ultimately little choice but to set yourself up as flexibly as possible in order to respond swiftly to new technologies. Large companies are not good at setting themselves up flexibly. Large organisations require operating in fixed processes and structures so that many small transactions always follow the same path and lead to comparable outcomes. Furthermore, in established companies that have grown over decades, we encounter very diversified IT landscapes. This leads to less flexibility and makes connecting the necessary data very resource-intensive.

I do not have a definitive answer to these challenges either. What seems important to me is that companies gather practical experience as quickly as possible and understand the AI revolution as an ongoing process rather than a one-off disruption to be worked through. Another interesting question will be whether it is sufficient to support existing processes with AI, or whether the processes themselves must be adapted to the capabilities of AI in order to harness its full potential.

I am very curious to see how large corporations will face up to this challenge, and I will report back once I have had further experience to share.

Nicolai Kruck, February 2026


Security & Regulation
Enabling Innovation Safely
Three dimensions that every AI project in legal and compliance must address from day one.
🔒

Data Protection (GDPR)

AI systems processing personal data are subject to the full requirements of GDPR — including Art. 22 (automated individual decisions), Art. 35 (DPIA) and the principles of data minimization.

  • Privacy by Design & by Default
  • Data protection impact assessment for AI
  • Transparency on algorithmic decisions
  • Right to human review
🏛️

EU AI Act & Regulation

The EU AI Act classifies AI systems by risk. Legal AI often falls under "High Risk" with extensive obligations for providers and deployers alike.

  • Risk classification & conformity assessment
  • Technical documentation & audit trails
  • Human oversight & escalation paths
  • Quality management system for AI
🛡️

IT Security & Sovereignty

AI systems expand the attack surface. Especially with autonomous agents, the need for cybersecurity governance grows exponentially — from prompt injection to data exfiltration.

  • On-premise or controlled cloud environment
  • Encryption, access control, logging
  • ISO/IEC 42001 for AI risk management
  • Sovereign AI: Data sovereignty in your own jurisdiction

Knowledge & Studies
Curated Source Collection
Current studies, reports and publications (2026) on AI transformation in legal, compliance and governance — every link checked and reachable.
Market, Adoption & Maturity (2026)
Market & Capital
Regulation & Legal Framework
Profile
Dr. Nicolai Kruck — The AI Lawyer

With over 17 years of experience in compliance, data protection, antitrust and corporate law in the automotive industry, I combine deep legal expertise with a clear vision for technological transformation. My path — from international law firms like Clifford Chance and Noerr, through in-house positions at Infineon Technologies and MAN SE, to leading compliance and privacy teams at Porsche and Volkswagen AG — has given me a unique perspective on the future of legal work.

As Head of Group Privacy International at Volkswagen AG, I lead a team of nine data protection specialists and actively drive the use of AI to optimize legal processes: privacy chatbots, automated documentation, AI-assisted contract review. I am convinced that the future of in-house legal work lies at the intersection of legal excellence, technological competence and strategic leadership.

"Compliance and legal departments will reach a new level of efficiency, quality and speed through the targeted use of Artificial Intelligence — if they have the courage to actively shape the change."

— Dr. Nicolai Kruck
  • AI in Legal OperationsChatbots, automated documentation, contract tools, process automation
  • Data Protection & PrivacyInternational GDPR compliance, AI governance, technical data protection
  • Compliance LeadershipAnti-corruption, business partner due diligence, antitrust law
  • Digital TransformationSoftware selection, implementation & optimization of compliance processes
  • Team Building & LeadershipHigh-performance teams, trust-based management, innovation culture
  • Automotive IndustryVW, Porsche, MAN, Infineon — deep industry knowledge

Career
Milestones of a Leadership Career
2023 — Present

Head of Group Privacy International, Divisional Support

Volkswagen AG

9 specialists. AI tools for privacy: chatbot, automated documentation, contract review. International data protection, AI governance, M&A privacy.

2020 — 2022

Head of Technical & International Data Protection

Volkswagen AG

5 specialists. Strategic alignment with international requirements. Chair of Group Steering Committee.

2018 — 2020

Senior Member, Agile Task Force — US Diesel Monitorship

Volkswagen AG

Central interface between US monitor and compliance organization.

2016 — 2018

Head of Legal and Compliance

Porsche Middle East & Africa FZE

Establishment of local compliance program. Legal services for 15+ markets.

2012 — 2016

Consultant Compliance (Team Lead)

MAN SE

Third-party due diligence, antitrust law, EU truck cartel proceedings.

2008 — 2012

In-House Counsel & Associate

Infineon Technologies · Noerr · Clifford Chance

Antitrust law, compliance, contract drafting. International law firm foundations.


Outlook
Next Development Stages
01

Whitepaper Series

In-depth analyses on build vs. buy, AI governance frameworks and industry-specific implementation strategies — available for download.

02

Thought-Leadership-Blog

Regular commentary on regulatory developments, new AI tools and strategic implications for legal & compliance.

03

Speaking & Advisory

Keynotes, panel discussions and strategic consulting for companies looking to make their legal and compliance function AI-ready.

Contact
Shaping the Future Together

Interested in AI transformation in legal & compliance, keynotes or strategic exchange?

Or write directly

Mit dem Absenden erklären Sie sich mit der Verarbeitung Ihrer Angaben zum Zweck der Contactaufnahme gemäß unserer Privacy Policy einverstanden. Ihre Daten werden ausschließlich zur Bearbeitung Ihrer Anfrage verwendet und nicht an Dritte weitergegeben. Es werden keine Cookies gesetzt.

✓ Thank you! Your message has been sent successfully.