Skip to content
AI Board

For in-house counsel and compliance managers

AI for in-house counsel: know what is true in your own registers

The contract that rolls over does not do it on the end date, it does it on the notice period you did not check in time. The DPA hunt starts a week before the audit, and the tool nobody told you about never reached the article 30 register at all. You are one lawyer, or two, for a company of 250 people, and the answer to all three questions is sitting in spreadsheets on your own drive.

Almost everything written about AI for in-house legal teams assumes a legal-ops function with a budget, evaluating clause-level review of contracts drafted on someone else's paper. That is a real job. It is not your job. Your exposure is register-level and cross-source: an end date in one file, a notice period in a column beside it, a sub-processor that appears in no file at all. Nobody gets sued because a limitation-of-liability clause was reviewed slightly slower. They get an uncomfortable meeting because a contract renewed for another year and nobody flagged it.

Your peers have already moved, and faster than the committee culture suggests. In the ACC and Everlaw survey of 657 in-house legal professionals across 30 countries, active generative-AI use reached 52% in 2025, up from 23% in 2024, while outright policy prohibitions fell from 29% to 9% and 71% said they intend to bring contract management in-house. Those are self-reported figures, and Europe reports the highest active adoption in the set. The point is not the percentage. The point is that a one-person legal function no longer needs anyone's permission to work differently.

AI Board reads the files you already maintain: the contract register with end dates and notice periods, the DPA tracker, the article 30 processing register, the company-card ledger. It answers the question you would type, and it names the file, the row and the date the answer came from, so you can check it in seconds instead of trusting it. It gives you the argument and the article in play, never the verdict. This page is not legal advice and the product does not produce a compliance opinion. The assessment stays yours, which is the only version of this a lawyer can actually use.

The week you recognize

The deadline is the notice period, not the end date

A supplier contract ends 1 November, so it feels like an autumn problem. The three-month notice period makes it a problem for this week, and the register shows the end date in a column your eye goes to and the notice period in a column it skips. Miss it and the contract rolls for another year at a price you did not renegotiate. In business-to-business contracts the statutory consumer protections against silent renewal largely do not apply, which is precisely why the diary is yours to keep. It is the cleanest kind of failure to be blamed for: nothing legal went wrong, a date went by.

The DPA gap, and the sub-processor nobody mapped

Before an audit you count signatures, and the count is never clean. Some processors signed, some sit in draft, and at least one has nothing on file while touching customer data. Worse is the layer under it: under GDPR article 28(1) you may only use processors offering sufficient guarantees, and the European Data Protection Board returned to controller reliance on processors and sub-processors in its Opinion 22/2024. Knowing who is actually in your chain is your obligation, not your vendor's, and the unmapped sub-processor is the first document an auditor asks for.

The register only sees what somebody registered

A marketing tool goes live in April on a company card. No intake, no article 30 entry, no assessment. Your processing register is complete and still wrong, because it can only be complete about what reached it. This is the expensive gap: IBM's Cost of a Data Breach Report 2025 found that breaches involving a high level of shadow AI cost on average USD 670,000 above the USD 4.44M global average, that 20% of breached organisations were compromised via shadow AI, and that 97% of organisations with an AI-related breach lacked proper AI access controls. You cannot review what was never declared to you.

Live demo

Your personal AI assistant, thinking

Did a tool go live this quarter that should've had a DPIA first?

Cross the register against the card-expense ledger and two tools paid since April were never logged. The marketing-automation one touches customer data and needs a DPIA before the audit. Assess that first.

Company card expenses Q2 2026.xlsxcrossed w/ processing register art.30
Ask AI Board…

What changes

The renewal found while you can still act

Ask which supplier contracts auto-renew in the next 90 days and you get the vendor, the end date, the notice period, the days remaining and which ones are still inside the window, read from the contract register on your drive with the version named. The count reconciles, so you can forward it without re-checking it by hand. You still decide whether to cancel, renegotiate or let it run. What changes is that you decide with eleven days left instead of finding out in the renewal invoice.

Signed, draft, or nothing, and the chain underneath

Ask what is missing before the audit and you get the split that determines your week: the ones sitting in draft are a signature, the ones with nothing on file are an escalation, and the ones whose sub-processor chain is unmapped are the ones to open first. If the file records special-category data or a transfer outside the EEA, it says so. If the file is silent, it says that too, rather than filling the gap with an assumption. You get a work list you can defend line by line.

The cross-source join you never have time for

Crossing the article 30 register against the company-card ledger finds the tools that were paid for but never registered, which is the one check that surfaces what you did not know to look for. And it holds the line your role requires: it will flag that a tool touching customer data belongs at the top of your assessment queue, but it will not conclude that the processing is unlawful, and it will not sign off a DPIA on your behalf. It names the criteria in GDPR article 35(3) and leaves the assessment where it belongs, with you.

Answered on demand

Transfers outside the EEA

Which processors in our register send personal data outside the EEA, and which of those contracts actually names a transfer mechanism?

Liability and indemnity drift

Which signed supplier contracts deviate from our standard liability cap or indemnity position, and by how much?

Retention promised versus recorded

Where do the retention periods in our privacy statement not match what the processing register says we actually keep?

AI Act inventory

Which tools we already pay for would count as AI systems the board will ask me to inventory, and which register entry covers each one?

Questions, answered

What can AI do for an in-house lawyer, specifically?
It answers register-level questions from your own files instead of from the open internet: which supplier contracts auto-renew inside their notice period, which processors are still missing a signed DPA before an audit, which paid tools never reached the article 30 processing register. You point it at the spreadsheets you already maintain and it reads across them, naming the file, the row and the date behind every figure so the answer is re-checkable. That is a different job from the clause-level contract review most legal AI is sold for. It does not review the law for you and it does not produce a compliance opinion. It removes the archaeology between you and the question you already knew to ask.
Can AI track contract renewal dates and notice periods?
Yes, and the notice period is the part that matters. A register that only surfaces end dates will show you a contract ending in November while the real deadline, three months of notice earlier, has already passed. Asked which contracts auto-renew in the next 90 days, AI Board reads the end date and the notice period together, reports the days remaining and separates the ones still inside their window from the ones that are gone, citing the register and its version. In business-to-business contracts the consumer rules against silent renewal largely do not help you, so the diary is the control. It flags the deadline; whether to cancel or renegotiate stays a commercial decision.
Is it safe to let an AI read confidential contracts and personal data?
The honest answer is architectural rather than a promise. AI Board is private by design: it runs on your own laptop, grounded in the files already on it, so contracts and personal data are not shipped somewhere to be processed and are not turned into a product claim. We make no EU-hosting claim and hold no compliance certification, and you should be suspicious of any legal AI that leads with a badge instead of an architecture. The comparison that matters is the real alternative, which is a colleague pasting a supplier contract into a personal chatbot account nobody registered. See [security](/en/security) for what the setup does and does not do, and [the shadow AI economy](/en/blog/shadow-ai-economy) for what it is replacing.
Does the AI tool itself need a DPIA, and will AI replace in-house counsel?
On the DPIA: that is a controller assessment under [GDPR article 35](https://eur-lex.europa.eu/eli/reg/2016/679/oj), which requires one where processing is likely to result in a high risk to rights and freedoms, and article 35(3) lists the cases where it is mandatory. It will tell you what to look at, which criteria are in play and what belongs first in the queue; the conclusion stays yours. On replacement: no. The reading, the risk call and the conversation with the business are the job, and none of them transfer. What goes is the register archaeology on a Thursday afternoon. The AI Act timeline is worth watching too: it entered into force on 1 August 2024 and applies fully from 2 August 2026, with prohibited practices since 2 February 2025 and, [after the omnibus revision, high-risk obligations deferred to 2 December 2027 and 2 August 2028](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai). That calendar has already moved once, so re-check it against the Commission's own page (dates as published July 2026).

The lonely legal function does not fail on doctrine. It fails on a date in a column nobody read, a signature that stayed in draft, a tool that was paid for and never declared. AI Board is your personal AI assistant that makes you AI-native: it runs on your own laptop, grounded in your company's data, and gets sharper as your knowledge grows. It gives you the register, the article and the argument, with the source named every time. The judgement, and the meeting where you defend it, stay yours.

Put your own registers to work

See what happens when your contract register, DPA tracker and processing register can be asked a question directly: the file, the row and the date behind every answer, private by design.

Runs on your own laptop. Your data never leaves it.