# AI Technology for Lawyers: Agentic AI

> Agentic AI moves from generating outputs to taking actions, changing the authorization, liability, and security questions organizations must answer.

Canonical URL: http://modelmonster.ai/blog/ai-technology-for-lawyers-agentic-ai/

## Article Metadata

- Author: Van Lindberg
- Published: 2026-01-22
- Category: AI Governance
- Reading time: 5 min
- Tags: AI governance

*Note: This article is part of* ***AI Technology for Lawyers***, *a series explaining the technical foundations of AI for legal professionals. *[*Start with the series introduction*](/blog/ai-technology-for-lawyers-a-technical-foundation/)*.*

### From Outputs to Actions

The shift that defines 2025 and 2026 is the movement from AI that generates outputs to AI that takes actions.

**Traditional AI** answers a question: Is this email spam? What movies are you likely to want to watch? What categories does this expenditure belong in? The outputs are generally simple, stable, and as a rule do not expose substantial information about the source.

**Generative AI **produces content: you ask a question, you get an answer. The human decides what to do with it. The AI is an author; you are the editor and actor.

**Tool-calling AI** can trigger external functions. You ask the model to schedule a meeting, and it actually calls your calendar API. You ask it to send an email, and it composes and sends the message. The model produces structured instructions that execute in the real world.

**Agentic AI** goes further. The model does not just call tools - it decides which tools to call, in what sequence, based on the results it observes. You give it a goal: "Research the top five competitors and prepare a summary memo." The agent breaks that into subtasks, searches the web, reads documents, drafts content, reviews its own work, and iterates until it determines the task is complete.

This is a fundamental change in liability posture. When AI only generated text, the human decided whether to use it. When AI takes actions autonomously, the questions become: Who authorized this? What permissions did the system have? What happens when it makes a mistake?

### Definitions

The industry uses "agent" loosely, which creates confusion. Here are working definitions:

**Agent** is simply a software component that interacts with users or systems. It may or may not have autonomous decision-making capability. The term does not necessarily imply anything about intelligence or autonomy.

**Agentic AI** is more specific. An AI system is agentic if it does one or both of the following: (a) takes a larger request and breaks it down into smaller tasks for execution, or (b) calls a tool and, based on the output, decides whether to provide a response or continue (including changing the plan or calling another tool).

The key characteristics of agentic AI are: autonomous decision-making about next steps, tool access that enables real-world actions, and iterative operation where the system continues until it determines the task is complete.

### The Lethal Trifecta

An AI researcher and commentator named Simon Willison identified a vulnerability pattern he calls the "Lethal Trifecta." An agent becomes dangerous when it simultaneously has all three of the following:

1. Access to private or sensitive data
2. Exposure to untrusted content
3. Ability to communicate externally

Here is the attack: Malicious instructions are embedded in content the agent processes - a webpage it visits, an email it reads, a document it retrieves. The model follows those instructions (because it cannot reliably distinguish instructions from data), accesses confidential information, and exfiltrates it to an attacker.

Let’s make this more concrete. Here is how it could affect a hypothetical near-future you: You have an agent that runs on your computer to help you with your tasks. It can generally do what you do. This agent reads inbound email (an untrusted input), and because you have access to SharePoint (a sensitive resource), so does the agent. The agent can also send outbound messages or search the web (both of which will exfiltrate data). A malicious instruction in the small-text disclaimer in the email footer of every lawyer’s email can redirect the agent to summarize confidential documents and send them externally.

This is not theoretical. Security researchers have publicly demonstrated variants of this attack against major enterprise AI products, including popular copilot and RAG systems. The combination of data access, untrusted input, and external communication creates an exfiltration path that attackers can exploit.

### The Agents Rule of Two

Meta extended Willison's framework into the "Agents Rule of Two": an agent should satisfy no more than two of three properties:

- (A) Processing untrustworthy inputs
- (B) Accessing sensitive systems or private data
- (C) Changing state or communicating externally

If a task requires all three, the agent should not operate autonomously. It needs human-in-the-loop approval.

Why this rule? Because prompt injection - adversarial input causing the model to ignore its instructions - remains an unsolved problem. Security researchers have tried filtering, detection, and sandboxing. No general-purpose defense reliably prevents prompt injection across contexts; most mitigations are partial and threat-model specific. The model cannot consistently distinguish between legitimate instructions and malicious ones embedded in data.

The defense, therefore, must be architectural. Design systems so that even successful prompt injection cannot cause catastrophic harm. If the agent cannot access sensitive data, there is nothing to steal. If the agent cannot communicate externally, it cannot exfiltrate. If the agent requires human approval before taking external action, the human can catch the manipulation.

### Excessive Agency and Least Privilege

The OWASP Top 10 for LLMs identifies "excessive agency" as a key vulnerability: granting AI systems more autonomy, permissions, or capabilities than necessary for their intended function.

Imagine an AI assistant that needs to send calendar invites. Does it need access to all employee calendars? Does it need write access to modify existing appointments, or could read-only access plus targeted invite capability suffice? Does it need 24/7 access, or only during business hours?

The principle of least privilege, meaning “granting only the minimum permissions necessary”, applies to AI systems just as it applies to human users and traditional software. But it is more important for AI because of the prompt injection risk. If an attacker compromises an AI system through prompt injection, they can only do what the system was authorized to do. Narrow permissions limit the blast radius.

Practical controls include:

- Scoping tool permissions to specific operations
- Requiring human approval for sensitive actions
- Implementing rate limits and budget caps
- Logging all tool calls for audit
- Designing approval workflows for high-risk operations

When reviewing AI vendor contracts or internal deployment policies, ask: What are the tool permissions? Who authorized them? How are they monitored? Can they be revoked? This is where organizational controls meet technical controls. The policies need to translate into actual system configurations.

*A note for practitioners:* Once AI systems can call tools that change state - e.g. sending emails, modifying records, executing transactions - you are no longer just managing software performance. You are allocating authority and agency. The governance question shifts from "does this tool work correctly?" to "who authorized this action, and through what chain of delegation?" This is a place where almost all AI governance processes (and especially AI governance tools) fall down. You should be looking for tools that actively help you identify these risks. In the mean time, use the CORE framework to help you analyze systems to find these issues.

***Continue here to the next article in the series:***[***Alignment, Evaluation, and Drift***](/blog/ai-technology-for-lawyers-alignment-evaluation-and-drift/)
