Legal AI Tools for Law Firms: A Complete Category Map
Document review, research, drafting, record intelligence and intake triage: a plain-English map of the legal AI tools law firms actually use.

Ask five lawyers what "legal AI tools" means and you'll get five different answers. One is picturing a chatbot that drafts a first-pass motion. Another means the software that scans thirty thousand documents for privilege in an afternoon. A third is thinking of the tool that turns a shoebox of medical records into a dated timeline. All of them are right, because legal AI software isn't one product, it's a stack of very different tools solving very different problems, with very different consequences if one of them gets something wrong.
That's a real problem for a firm trying to work out what to buy, or what an AI paralegal can safely touch versus what still needs a person doing it the slow way. This piece maps the landscape: the main categories of legal AI tools a firm is likely to encounter, what each one actually does, where record-intelligence tools like Chartely sit inside that wider map rather than replace it, what "HIPAA compliant AI" has to mean in practice, and the questions worth asking before any of it touches a live case.
TL;DR: Legal AI tools split into five practical categories: document review/e-discovery, legal research, drafting/contracts, record intelligence (chronologies), and intake/triage. None of them replace a lawyer's judgment or a paralegal's review, and none should touch protected health information without a signed Business Associate Agreement and a real human check step.
The shape of the legal AI stack
Most firms don't buy "legal AI" as a single decision. They buy a research tool for one problem, a review tool for another, and something else entirely for the paperwork that piles up on every personal injury or workers'-compensation file. The table below is a rough map of the categories in general use across the wider legal tech industry, not an endorsement of any specific product, since naming and comparing individual vendors accurately is its own research project.
| Category | What it does | Example use case |
|---|---|---|
| Document review / e-discovery AI | Sorts, tags and prioritises large document sets for relevance, privilege and responsiveness | Triaging hundreds of thousands of emails ahead of a discovery deadline, so reviewers see the most relevant documents first |
| Legal research AI | Searches case law, statutes and secondary sources and drafts a summary, usually with citations to check | Finding cases on a narrow point of state negligence law without reading every headnote by hand |
| Drafting & contract AI | Generates first-draft language for pleadings, letters or contracts, or flags clauses against a playbook | Producing a first draft of a routine settlement letter, or flagging a non-standard indemnity clause in a contract |
| Record intelligence / chronology tools | Extracts events from medical or case records into a dated, page-cited timeline | Turning a multi-provider medical file into a chronology for a demand letter or deposition prep |
| Client intake & triage AI | Screens new matters, answers routine questions, or routes urgent items to the right person | Gathering the basic facts from a new personal injury caller before a paralegal ever picks up the phone |
Legal AI tool categories at a glance
Document review and e-discovery AI
This is the oldest and most mature corner of legal AI software, and the one most litigators have already touched even if they don't call it AI. Predictive coding and technology-assisted review have been used to rank documents by relevance since well before the current wave of generative tools, and the newer generation adds natural-language search on top: ask a plain question about a document set instead of building a Boolean string. The realistic use case is a big-discovery matter where a human reading every document simply isn't feasible on the timeline, so the tool ranks and clusters documents and a reviewer works through the ranked list rather than the raw pile.
Legal research AI
Legal research AI reads a question in plain English and returns cases, statutes, or secondary sources that seem relevant, often with a drafted summary of the argument they support. It's a genuine time-saver for the first pass of research on an unfamiliar area of law. It's also the category with the most visible failure mode: a tool can return a citation that looks completely correct and isn't, either because the underlying case doesn't say what the summary claims, or, in the worst documented instances, because the case doesn't exist at all. That risk is exactly why every major legal research product, and every firm using one, still treats citation-checking as a mandatory step rather than an optional one.
Drafting and contract AI
This category covers tools that produce or review first-draft text: a demand letter, a routine pleading, a settlement agreement, or a contract clause checked against a firm's standard playbook. Used well, it removes the blank-page problem and standardises language across a firm. Used badly, it produces confident-sounding prose that nobody actually checked against the facts of the case, which is a much harder mistake to catch after the fact than a research citation, because there's no separate source document to check the draft against.
Record intelligence and chronology tools
This is Chartely's own category, and it's worth being precise about what it is and isn't. Record-intelligence tools take a stack of medical, employment, or case records and turn them into a structured, dated, page-cited event list, so a paralegal or attorney can see the whole course of treatment or the whole fact pattern without reading every page of every document first. It's a narrower job than the drafting or research categories above: the output is a verifiable timeline, not a finished legal argument. We've written separately about how that extraction gets called programmatically by an AI legal agent working a case, which is a useful read if you're building rather than just buying.
Because this category touches medical records directly, it carries the sharpest HIPAA and accuracy obligations of any of the five, which is why we've covered evaluation criteria for it specifically in a separate buyer's review of AI medical record review elsewhere on this blog, rather than trying to cover every category's evaluation criteria at that same depth here.
Client intake and triage AI
Intake and triage tools sit at the front door of a practice: a chatbot or voice tool that gathers the basic facts from a new caller, checks for an obvious conflict, and routes the matter to the right person, or flags it as urgent. For AI for personal injury lawyers specifically, this often means a tool that can tell the difference between a routine fender-bender inquiry and a catastrophic-injury case that needs a partner's attention within the hour, based on the details the caller volunteers before anyone on staff has spoken to them.
People sometimes describe these tools, and drafting tools, loosely as an "AI paralegal". That's a fair shorthand for what they automate, first-pass triage or first-draft text, but it overstates what any of them do unsupervised. None of the categories above are built to make a judgment call and stand behind it the way a paralegal or attorney does; they're built to produce a draft or a shortlist that a person then checks.
What HIPAA compliant AI actually requires
Any tool in the record-intelligence category, and some intake tools, will handle protected health information at some point, which means "HIPAA compliant" needs to mean something specific rather than being a marketing phrase on a sales page. HIPAA compliance isn't a certificate a vendor buys once; it's a set of administrative, physical and technical safeguards set out in HHS's guidance for professionals, and in practice it comes down to a short list of concrete things a firm can actually check.
- A signed Business Associate Agreement. If a vendor processes PHI on a covered entity's behalf and won't sign a BAA, that's a hard stop, not a detail to work around.
- Clear data handling. Where is the data stored and processed, does it leave that environment to reach a third-party model provider, and is it encrypted at rest and in transit?
- Access controls and audit logs. Who inside the vendor's organisation, and inside the firm, can see a given file, and is there a record of who accessed what and when?
- A defined retention and deletion policy. What happens to the record once the work product is delivered, and how long is it kept after that?
A vendor that can answer all four with specifics is a very different proposition from one that offers a single reassuring sentence about compliance and nothing underneath it.
The real risks: hallucination, oversight, and what bar associations say
Generative AI systems can state something confidently that isn't supported by the underlying source at all, a well-documented behaviour usually called hallucination. In legal research this has already produced real, publicly reported consequences: in Mata v. Avianca, attorneys submitted a brief citing entirely fictitious cases generated by an AI tool, and the court sanctioned them for it. That case is now widely cited across the profession precisely because it shows what happens when AI output is filed without anyone checking it against a real source.
This is why every serious framework for using AI in a professional context treats human review as a control, not an optional extra. The NIST AI Risk Management Framework builds oversight into how AI risk should be managed generally, and the legal profession has its own version of the same message: the American Bar Association's first formal ethics guidance on generative AI, issued in 2024, is explicit that there's no "AI exception" to a lawyer's existing duties of competence, confidentiality and candour to the court. A tool that drafted the sentence doesn't change who's accountable for filing it.
The malpractice risk was never really the AI. It was skipping the review step the AI was supposed to make faster, not optional.
How to evaluate any legal AI tool
The specifics differ by category, but a short list of questions travels across all five, and it's worth running any tool a firm is considering, including a chronology tool like ours, against it before signing anything.
- What does the output actually rely on? A citation, a page reference, a source document, or just the model's own confidence.
- How does a human check it, and how long does that take? If checking the output takes as long as doing the work manually, the tool isn't saving time, it's moving where the time goes.
- What happens when the tool is wrong or unsure? A flagged low-confidence result is a very different product from a silent, confident guess.
- What data does it touch, and where does that data go? Especially for anything handling medical records, client communications, or other sensitive material.
- Can it be tested before a firm commits? A tool worth trusting with real case files is usually one a firm can try against a real (or realistic) file first, not just a demo.
For firms with their own developers, or evaluating an AI legal document review or agent platform that needs to call these tools programmatically rather than through a browser, it's also worth checking whether a vendor exposes its functionality as an actual API, since Chartely's own developer documentation is a reasonable example of what that should look like: a documented endpoint, a schema, and a way to test it before committing to an account.
None of this is really about AI specifically. It's the same due diligence a firm would run on any vendor touching client work, applied to a category of tool that's newer, moving faster, and easier to over-trust than the software it's replacing.
See how Chartely's record-intelligence tools turn medical records into a page-cited chronology.
See a sample chronologyFrequently asked questions
What are legal AI tools?
Legal AI tools are software that use machine learning or generative AI to help with legal work: reviewing documents, researching case law, drafting text, extracting events from records, or triaging new matters. They span several distinct categories rather than one single product type.
Is AI legal software HIPAA compliant?
It can be, but only if the vendor signs a Business Associate Agreement and can show specifics on data storage, encryption, access controls and retention. A tool that only claims to be "HIPAA compliant" without offering those details shouldn't be trusted with protected health information.
Can AI replace a paralegal?
No. AI tools can automate first-pass drafting, research, triage or record extraction, but none of the current categories are built to exercise the professional judgment a paralegal applies, or to take responsibility for the result. The tools are commonly described as an "AI paralegal" as shorthand, which overstates what they do unsupervised.
How do law firms evaluate legal AI tools?
By checking what the output relies on (citations, page references, or just model confidence), how long human review actually takes, what happens when the tool is wrong or unsure, what data it touches, and whether it can be tested against a real file before the firm commits.
Is AI legal document review reliable enough for litigation?
Document review and e-discovery AI is one of the more mature legal AI categories and is widely used in litigation, but it's used as a triage and ranking layer, not a replacement for human review. Reviewers still check flagged documents, particularly around privilege and responsiveness calls.
This guide is general reference, not legal or medical advice. To try it on a real record set, use the medical chronology builder, or see how the same engine works from your own code or an AI agent.
More guides
Build a chronology, then build on it
Build a chronology free, then get an API key for your software or your AI agent, no card to start.