Most law firms talk about AI adoption. Gilbert + Tobin is actually doing it — and the way they’re doing it is worth paying close attention to. The Australian firm has built what looks like one of the more serious enterprise AI programs in the legal sector, combining ChatGPT Enterprise and OpenAI Codex with a governance structure that starts at the CEO level and runs all the way down to individual accountability for every AI-assisted output. This isn’t a pilot program or a skunkworks experiment. It’s a firm-wide deployment, and the architecture behind it tells you a lot about where serious enterprise AI adoption is actually heading.
Why Law Firms Are Such a Hard Case for AI Deployment
Before getting into what G+T specifically built, it’s worth understanding why law firms are one of the trickier environments to deploy AI at scale. The obvious reason is confidentiality — client privilege is sacrosanct, and any AI tool that might expose privileged communications to third parties is a non-starter. But there’s a second, less-discussed problem: lawyers are professionally liable for their work product. A consultant can caveat a slide deck. A lawyer can’t caveat a court filing.
That liability structure changes everything about how you deploy AI in a legal context. You can’t just roll out ChatGPT to 500 lawyers and tell them to be careful. You need a system that maintains human accountability at every step, that creates audit trails, and that makes clear — both internally and externally — that AI is augmenting lawyer judgment, not replacing it.
Add to that the billable-hour model, where efficiency gains can paradoxically threaten revenue, and you start to see why so many firms have moved slowly. G+T’s approach is a direct response to all of these pressures, and it’s a more sophisticated answer than most.
What Gilbert + Tobin Actually Built
According to OpenAI’s case study on the deployment, the G+T approach rests on three pillars: CEO-led commitment, a formal governance framework, and a principle of human accountability that applies to every AI output the firm produces.
The CEO-led piece matters more than it sounds. In most enterprise AI rollouts, the initiative lives in IT or maybe a dedicated innovation team. It rarely has genuine executive sponsorship. When the CEO is visibly and actively behind a technology program, it changes the internal politics dramatically — partners who might otherwise ignore or resist the tool can’t easily dismiss it as someone else’s project.
The governance framework G+T built covers a few specific areas:
- Data handling and confidentiality: ChatGPT Enterprise, unlike the consumer product, doesn’t train on customer data by default. G+T’s governance protocols layer additional controls on top of that, specifying what types of matters can use AI assistance and under what conditions.
- Output accountability: Every AI-assisted work product has a named human accountable for its accuracy and appropriateness. There’s no ambiguity about who reviews, who approves, and who signs off.
- Training and competency standards: Lawyers and staff aren’t just given access and left to figure it out. There are structured training programs that establish baseline competency before someone is cleared to use the tools on live matters.
- Ongoing review and iteration: The governance structure isn’t static. G+T has built in regular review cycles to update policies as the tools evolve and as they learn more about how the technology is actually being used in practice.
Codex is the other interesting layer here. While ChatGPT Enterprise handles the broad language work — drafting, summarizing, researching — Codex is being used for automation of more structured, repetitive tasks. Think document processing workflows, data extraction from contracts, and internal tooling that legal ops teams can build without needing a full engineering team. The combination of a general-purpose language model with a code-generation tool gives the firm a much wider surface area for automation than either tool alone would provide.
The Governance Model as a Competitive Asset
Here’s something that doesn’t get discussed enough in enterprise AI coverage: the governance framework itself is a product. G+T isn’t just deploying AI — they’re building institutional knowledge about how to deploy AI responsibly in a regulated, high-liability environment. That knowledge compounds. In two years, they’ll be significantly ahead of firms that are only now starting to think about policy frameworks.
This has direct commercial implications. Sophisticated clients — the large corporates and multinationals that generate the most valuable legal work — are increasingly asking their law firms about AI governance. Having a credible, CEO-backed answer to that question is a differentiator. It’s not the same as winning on price or practice area strength, but it’s becoming part of the pitch in a way it wasn’t three years ago.
How This Compares to Other Enterprise AI Deployments
G+T’s approach is notably more structured than what you see at most enterprises deploying AI tools. The typical pattern is: get access, do some internal evangelism, let adoption grow organically, worry about governance later. That works fine for low-stakes internal tools. It’s a problem when you’re producing legal advice that people are relying on to make major decisions.
The closest comparable I’ve seen in terms of governance seriousness is financial services — banks and asset managers deploying AI for compliance and research functions have been forced to build similar accountability structures because the regulatory environment demands it. Legal is getting there, and G+T looks like one of the firms pushing that standard forward rather than waiting for it to be imposed externally.
It’s also worth noting how this sits relative to OpenAI’s broader push into high-stakes enterprise environments. The company has been working to establish that its tools can meet the security and accountability standards that regulated industries require. A law firm case study of this depth is useful evidence for that claim — more useful than a generic enterprise testimonial, because law firms are specifically hard.
What This Means for Legal Tech and Enterprise AI Broadly
The legal technology market has been waiting for a signal about what serious AI adoption in law actually looks like. G+T’s deployment gives the sector something concrete to orient around.
For other law firms, the immediate question is whether to build similar frameworks or wait. My read: waiting is increasingly costly. The firms that develop institutional expertise with these tools now — including the governance muscle, not just the technical deployment — will have a meaningful advantage in a market where AI fluency is becoming a baseline expectation.
For legal tech vendors, the G+T model clarifies what enterprise law firms actually need from AI tools. It’s not just capability — it’s auditability, data boundaries, and the ability to integrate with governance workflows. Products that don’t address those requirements will struggle to get past procurement at serious firms, regardless of how impressive their demos are.
For OpenAI, this case study is important in a different way. It demonstrates that ChatGPT Enterprise can operate in a context where the stakes for errors are genuinely high and where clients are paying close attention to how the technology is managed. That’s a more valuable proof point than most of the generic enterprise deployments that get written up. And given that OpenAI has been increasingly focused on governance and accountability narratives across its product lines, a law firm case study fits neatly into that story.
The Billing Model Question Nobody’s Answering
One thing the case study doesn’t address directly, and which I think is the most interesting unresolved tension in legal AI broadly: what happens to the billable hour? If AI genuinely makes lawyers 30-40% more efficient on drafting and research tasks, does the firm pass that savings to clients, absorb it as margin improvement, or find new ways to scope engagements? G+T hasn’t publicly answered that, and neither has any other firm doing serious AI deployment. It’s the elephant in the room for the entire sector, and the firms that figure it out first — in a way that’s both commercially sustainable and client-credible — will have solved something that matters a lot more than which AI tool they’re running.
Key Takeaways
- Gilbert + Tobin’s deployment of ChatGPT Enterprise and Codex is built on a three-pillar framework: executive leadership, formal governance, and named human accountability for every AI output.
- The combination of a general language model (ChatGPT Enterprise) with a code-generation tool (Codex) gives the firm a much broader automation surface than most competitors are working with.
- Governance isn’t just risk management here — it’s becoming a client-facing differentiator as sophisticated corporates ask harder questions about how their law firms use AI.
- The model points toward where enterprise AI adoption in regulated industries is heading: not less governance, but more structured governance built in from the start.
- The billing model question — what AI efficiency gains mean for the billable hour — remains unresolved and is arguably the most consequential issue the legal sector hasn’t publicly addressed.
What is ChatGPT Enterprise, and how is it different from regular ChatGPT?
ChatGPT Enterprise is OpenAI’s business-tier product, which by default doesn’t use customer data for model training and includes enhanced security controls, admin tools, and higher usage limits. For law firms specifically, the data handling commitments are what make deployment legally defensible — using the standard consumer product for client matters would raise serious confidentiality concerns.
What is Codex being used for in a law firm context?
In G+T’s case, OpenAI Codex is being applied to structured, repeatable automation tasks — things like building internal tools for document processing, data extraction from contracts, and legal operations workflows. It extends the firm’s AI capability beyond language tasks into process automation without requiring a dedicated engineering team for every project.
How does G+T’s AI governance model address lawyer liability?
The core mechanism is named human accountability: every AI-assisted output has a specific lawyer responsible for reviewing and approving it. That preserves the professional liability structure that legal practice requires — AI is a tool in the production of legal advice, but a qualified human is always accountable for the final work product.
Is this model applicable to other industries beyond law?
The governance architecture — executive sponsorship, clear data handling policies, named human accountability, structured training, and regular review cycles — maps well onto any regulated industry where errors have serious consequences. The broader question of how humans stay accountable when AI handles more of the cognitive work is something every sector deploying these tools will have to answer eventually. Law just happens to be working it out in a particularly high-stakes environment.
G+T’s deployment won’t stay the exception for long. As more firms see what a structured AI program actually looks like in practice, the pressure to build comparable frameworks will intensify — driven partly by client expectations, partly by competitive pressure, and partly by regulators who are only beginning to turn their attention to how AI is used in professional services. The firms building that muscle now are doing something more durable than just deploying a chat tool.