Legal 法务
1. 介绍
1.1 背景
法务工作是 AI 应用中"收益最直观、风险最致命"的领域。一方面,合同审查、尽调资料梳理、法条检索、诉讼材料准备高度依赖文本处理,正是大模型最擅长的任务类型;另一方面,法务输出具有举证属性——一份提交给法院的代理意见、一份对外签署的合同,其内容的真实性直接关联执业责任与司法秩序。
2023 年以来,全球司法系统集中遭遇了一类新型问题:AI 生成的虚假法条与判例进入法庭。这不是理论担忧,而是已经产生罚款、禁业、训诫等实际后果的现实问题。与此同时,AI 生成内容本身的权利归属、AI 换脸的人格权边界等问题,也通过一系列"首案"逐步确立了裁判规则。
对法务方向的 AI Harness 而言,这意味着一个根本性的设计前提:法务场景中,模型的语言流畅度是负资产而非正资产。一个表述粗糙但每条引用都真实的检索结果,价值远高于一份文辞优美但含三处虚构判例的代理意见。因为后者不会被识别为错误,而会被当作欺诈。
1.2 定义
Legal 法务方向的 AI Harness,是指承载合同审查、法律尽职调查、诉讼支持、法规检索等法务任务的工程化运行层。其核心职责是保证每一条法律引用都真实、每一处条款抽取都完整、每一份对外文书都经过人工核验,而不是提升文书的文采或产量。
本方向覆盖四类任务:
| 任务类别 | 典型任务 | 输出形态 |
|---|---|---|
| 合同审查 | 条款抽取、差异比对、风险条款标注、范本套用 | 审查意见草稿,非定稿意见 |
| 法律尽调 | 目标公司资料梳理、诉讼与处罚检索、股权链路核查 | 尽调材料与疑点清单 |
| 诉讼支持 | 案例检索、争议焦点整理、证据目录编排、文书初稿 | 检索结果与初稿,非提交文书 |
| 法规检索 | 法条检索、效力核验、适用性初判、法规变动跟踪 | 检索结果与初判,非法律意见 |
关键界定:法务方向的所有输出都是待核验草稿。法律意见的出具、合同的签署、诉讼文书的提交,均须由具备执业资格的自然人完成并承担责任。
1.3 在 AI Harness 体系中的定位
图 1-1|法务方向 AI Harness 六层定位:瓶颈在 L1/L5
数据来源:基于本文分析绘制的示意图。
| 层 | 法务方向的承载内容 | 关键工程要求 |
|---|---|---|
| L1 上下文工程 | 法条、判例、合同范本、内部条款库的检索 | 权威源绝对优先;模型记忆不得作为条文内容来源 |
| L2 工具与执行 | CLM 合同管理系统、法源核验接口、尽调资料库 | 电子签章与对外发文工具为 R3 不可逆,默认关闭 |
| L3 编排与控制 | 合同审查流水线、尽调清单编排、条款比对与差异标注 | 核验环节不可跳过,失败的核验必须阻断下游 |
| L4 记忆与状态 | 合同版本历史、条款库、既往谈判要点与让步边界 | 版本比对是法务场景的核心能力 |
| L5 评估与观测 | 条款抽取准确率、法条引用核验通过率、遗漏率 | 引用核验通过率是一票否决指标 |
| L6 治理与安全 | 禁止编造法条判例、对外发文与用印需人审、生成标识 | 本方向的主约束层 |
瓶颈在 L1 与 L5。
- L1 是风险源头:法务任务的失败绝大多数不是"推理错了",而是"检索到的东西是编的"。模型的参数记忆中存储了大量法条与案号的片段,它会以极高的置信度输出这些内容,且格式规范、措辞专业,与真实条文几乎无法凭肉眼区分。因此 L1 层的第一设计要求是:截断模型记忆作为法源的能力,强制所有条文与判例从权威库检索取得。
- L5 是能力瓶颈:法务任务的评估集构建难度高。一份合同审查意见"对不对"没有标准答案,但"引用的法条是否存在"有客观答案。这使得法务方向的评估必须分层设计:把可客观判定的部分(引用真实性、条款覆盖完整性)作为硬指标,把主观判断部分(风险是否可接受)留给人工。
与其他方向的关键差异:法务方向是五个方向中唯一把"引用真实性"作为首要质量指标的方向。金融方向重视数字溯源,审计方向重视证据链,但只有法务方向会因为一条虚构的案号直接触发执业责任。
1.4 价值与局限
价值:
- 全量覆盖替代抽样阅读。尽调中面对成百上千份合同与文书,AI 可做全量扫描,人工只需复核高风险项。
- 版本差异精确比对。合同谈判中的版本迭代,人工比对极易遗漏细微修改,机器比对可精确到字符级。
- 检索效率提升。法规与判例检索从关键词匹配升级为语义检索,召回率显著改善。
- 释放重复性文书工作。证据目录编排、材料要点整理、初稿生成等任务可大幅提效。
局限(必须正视):
- 幻觉在法务场景的代价是执业责任与司法秩序。2023 年美国纽约南区联邦法院审理的马塔诉阿维安卡航空案中,原告律师使用 AI 生成的辩护材料凭空虚构六份完整航空事故判例,包含标准案号、法官署名、裁判说理和案件细节;律师未开展任何人工核验便直接提交法庭,面对对方律师质疑仍坚持判例真实,最终被法院认定违反勤勉执业义务、滥用司法程序,两名代理律师及其律所被共同处以 5000 美元连带罚款,违规记录永久记入执业档案(据《法治日报》报道)。
- 模型不具备法律判断能力。法律适用涉及规则冲突、价值衡量与政策考量,模型只能提供材料与线索,不能替代判断。
- "看似完美"是最危险的失效形态。北京市通州区人民法院法官郑吉喆在描述一起 AI 生成虚假案例时说:"跟我们这个案子好像描述的观点,包括描述的内容、情形都特别像,完美地还原这个案例目前的事实情况,裁判观点是完美支持了他的诉请。"正是这种"完美契合"使虚假内容更难被察觉。
- 核验成本并未消失,只是转移。AI 把"从零检索"的成本转为"逐条核验"的成本。若机构不为核验环节配置资源,AI 只是把错误产出得更快。
2. 名词解释
| 术语 | 英文/缩写 | 释义 |
|---|---|---|
| 合同管理系统 | Contract Lifecycle Management / CLM | 覆盖合同起草、审批、签署、履约、归档全生命周期的管理系统;法务方向的核心业务系统 |
| 条款抽取 | Clause Extraction | 从合同文本中识别并结构化提取特定类型条款(如管辖、违约、保密、责任限制)的过程 |
| 差异比对 | Redline / Diff Comparison | 对两个或多个合同版本做逐处修改识别,输出差异清单 |
| 法律尽职调查 | Legal Due Diligence / LDD | 对目标主体法律状况的系统性核查,含主体资格、股权、资产、诉讼、合规等维度 |
| 诉讼支持 | Litigation Support | 为诉讼或仲裁提供的案例检索、证据整理、文书准备等辅助工作 |
| 法源 | Source of Law | 法律规则的来源,含法律、行政法规、部门规章、地方性法规、司法解释等 |
| 判例 | Case / Precedent | 法院已作出的裁判;中国语境下指导性案例、公报案例与入库案例具有参照价值 |
| 案号 | Case Number | 法院案件的唯一标识,如 (2022) 沪 01 民终 12345 号;核验判例真伪的第一抓手 |
| 裁判要旨 | Holding / Gist | 裁判文书核心裁判规则的概括表述 |
| 效力层级 | Legal Hierarchy | 法律、行政法规、部门规章、规范性文件的层级关系;引用时必须标注 |
| 法律幻觉 | Legal Hallucination | 模型生成不存在的法条、案号、裁判要旨或对真实判例作错误描述的现象 |
| 可识别性 | Identifiability | 肖像权侵权判定标准:只要一般公众能够将形象识别为特定自然人,即构成对该自然人肖像的使用 |
| 举证不能 | Failure of Proof | 负有举证责任的一方无法提供证据或证据不足时,承担不利后果的法律状态 |
| 训诫 | Reprimand | 法院对妨害诉讼秩序但情节轻微的行为人当庭予以批评告诫的强制措施 |
| 电子签章 | Electronic Signature | 以电子形式表现并可用于识别签名人身份、表明认可内容的数据;用印为不可逆动作 |
| 诚信原则 | Principle of Good Faith | 民事诉讼活动应当遵循的基本原则;是法院处理 AI 生成虚假材料问题的主要规范依据 |
| 人民法院案例库 | People's Court Case Database | 最高人民法院建设的案例库,入库案例具有参照与指引价值 |
3. 案例
以下案例均取自公开可查的司法判例与权威媒体报道。涉及具体案件的,已标注案件进展状态。
3.1 AI 生成内容的著作权边界:全国首例认定案
3.1.1 背景
AI 生成的内容能否受到著作权法保护,是生成式 AI 普及后最先遭遇的法律问题之一。若答案是否定的,则任何 AI 生成的文本、图像都可被任意复制使用;若答案是肯定的,则需要界定权利归属于谁。
腾讯公司自主开发了基于数据和算法的智能写作辅助系统 Dreamwriter。2018 年 8 月 20 日,Dreamwriter 创作完成一篇财经报道文章,文末注明"本文由腾讯机器人 Dreamwriter 自动撰写"。该文在腾讯证券网站首次发表后,上海盈讯科技有限公司于同日复制该文章,通过其经营的"网贷之家"网站向公众传播。腾讯公司遂以侵犯著作权为由诉至深圳市南山区人民法院。
3.1.2 方案(法院的裁判路径)
法院的裁判路径,本质上是在回答"AI 生成过程中,人的智力投入在哪里":
- 外在表现形式审查:认定涉案文章"外在表现符合文字作品的形式要求,其表现的内容体现出对当日上午相关股市信息、数据的选择、分析、判断,文章结构合理、表达逻辑清晰,具有一定的独创性"。
- 生成过程审查:认定原告主创团队在数据输出、触发条件设定、模板和语料风格的取舍上的安排与选择,属于与涉案文章的特定表现之间具有直接联系的智力活动;Dreamwriter 软件的自动运行体现了原告的个性化选择与安排。
- 权利归属认定:认定涉案文章由原告多团队、多人分工形成的整体智力创作完成,整体体现原告对于发布股评综述类文章的需求和意图,属于法人作品。
3.1.3 效果
据法治网报道,法院最终认定被告未经许可在其网站向公众提供被诉侵权文章,侵害了原告享有的信息网络传播权,判令被告赔偿经济损失及合理维权费用共计 1500 元。该案案号为 (2019) 粤 0305 民初 14010 号,判决日期为 2019 年 12 月 27 日,是全国首例确认 AI 生成内容可享有著作权的案例。
对法务 Harness 设计的启示:本案确立了"智力投入"标准——判断 AI 生成内容的权利归属,看的是人在数据选择、条件设定、模板与语料取舍上的安排与选择。这一标准对 Harness 的工程含义是:提示词设计、语料选择、参数配置的过程应当被记录。这些记录在未来可能的权利争议中,正是"智力投入"的证据。
需要指出的是,该案之后北京互联网法院在另一起计算机软件生成物案件中作出了不同认定,认为自然人创作仍应是著作权法上作品的必要条件。这说明 AI 生成物的可版权性问题在司法实践中尚未完全统一,引用时须注明案件与时间(据天达共和律师事务所公开文章、法治网报道)。
3.2 AI 换脸的肖像权边界:可识别性标准与举证责任
3.2.1 背景
AI 换脸技术的普及,使"使用他人肖像"的门槛降至近乎为零。由此产生的核心争议是:AI 生成或 AI 换脸后的形象,与原肖像并非完全一致时,是否仍构成对该自然人肖像的使用?
在一起由 AI 换脸引发的侵权案件中,原告为国内某知名演员。其发现被告 A 公司制作并发布的短剧中,通过 AI 换脸技术将原告肖像拼接至剧中角色面部,致使公众误认为原告参演了该剧,相关话题在社交平台引发热议。另一被告 B 公司则在其运营的视频账号中上线了该短剧。
A 公司辩称,涉案形象系 AI 生成,并非主观使用原告肖像,且争议片段时长极短、已及时下架。B 公司则称,其已获得短剧的信息网络传播权授权,并非制作者,不存在侵权故意。
3.2.2 方案(法院的裁判路径)
- 以"可识别性"为核心标准:法院查明涉案短剧共 44 集、时长 90 分钟,其中两个片段使用了 AI 换脸技术,换脸后的面部与原告高度相似;社交平台上出现大量"#短剧疑似 AI 换脸演员某某#"等话题,众多网友参与讨论并质疑。法院认为,虽然 AI 换脸后的形象与原肖像并非完全一致,但依据《中华人民共和国民法典》,肖像是"可以被识别的外部形象",只要一般公众能够识别,即构成肖像权侵权。
- 举证责任分配:A 公司未能复现其声称的 AI 生成过程,需承担举证不能的责任,法院据此认定其存在侵权故意。
- 平台义务独立:B 公司虽获得著作权授权,但法院指出著作权不能吸收或覆盖肖像权,B 公司未尽到合理审查义务,亦构成侵权。
3.2.3 效果
据经济参考网报道,法院最终判令 A、B 两公司分别在其视频账号发布书面致歉声明,并赔偿原告经济损失。该案的核心价值在于:首次以"公众可识别性"为标准,确立了"高度相似即构成肖像侵权"的裁判规则,并明确了内容发布平台的独立审查义务——取得著作权合法授权仅为内容上线的基础义务,不能以此免责。
另一起同类案件中,某科技公司未经许可在其运营的一键制作 AI 换脸特效视频 APP 中将网络视频创作者吴某的肖像视频上传为模板并营利,法院判决该公司在 APP 首页显著位置连续 15 日发布致歉声明,并赔偿经济损失、合理维权费用及精神损害赔偿金(据澎湃新闻报道的福州中院相关案例)。
对法务 Harness 设计的启示:本案最重要的一条工程含义是——"AI 生成"不是免责事由,但"能否复现生成过程"直接影响责任认定。这要求 Harness 必须完整保留生成过程的记录(提示词、输入素材、模型版本、参数),否则在争议中将因举证不能而处于不利地位。
《中华人民共和国民法典》相关条文:第 1018 条规定自然人享有肖像权,肖像是"通过影像、雕塑、绘画等方式在一定载体上所反映的特定自然人可以被识别的外部形象";第 1019 条规定"任何组织或者个人不得以丑化、污损,或者利用信息技术手段伪造等方式侵害他人的肖像权",未经肖像权人同意不得制作、使用、公开其肖像。
3.3 失败与风险:AI 幻觉入侵司法与全球律师惩戒潮
3.3.1 背景
这是法务方向最重要、也是最不能回避的一类案例。自 2023 年起,AI 生成的虚假法条与判例持续进入各国司法程序,引发了一轮全球性的律师惩戒潮。中国法院自 2025 年起也集中出现同类问题。
3.3.2 方案(各国司法系统的应对)
中国的应对路径:
- 北京市通州区人民法院在审理一起由代持股引发的民事纠纷时,原告代理律师在庭后提交的书面代理意见中附带了两个"参考案例",其中一个标注为 (2022) 沪 01 民终 12345 号。法官核查后发现,该案号对应的案件实际是一起民间借贷纠纷,与股权代持"风马牛不相及"。在法官质询下,律师承认参考案例系其提炼本案事实情节后反复向某 AI 大模型软件提问、由软件生成,未经核实直接复制粘贴提交。
- 法院考虑到该行为在法律上没有明确规定、律师无明显恶意、情节轻微、未造成严重后果,将这一情节写进判决书予以批评:"希望原告代理人引以为戒,在向法院提交参考案例、法条时,应当进行检查和核验,确保内容的真实性和准确性,不得放任人工智能模型生成或者编造虚假信息扰乱司法秩序。"
- 2025 年 12 月,该案入选人民法院案例库,裁判要旨明确:诉讼参与人在民事诉讼活动中应当遵循诚信原则;诉讼参与人提交通 AI 技术获取且未经甄别核实的虚假案例的,应当承担相应的法律后果;情节轻微的,人民法院可以对其进行批评教育;情节较重的,可以参照《中华人民共和国民事诉讼法》第一百一十四条第一款的规定处理。
其他法域的应对路径:据《法治日报》报道,美国、英国、澳大利亚司法系统均已出现 AI 判例造假案件并形成处置链条。
3.3.3 效果(已发生的实际后果)
| 时间 | 法域/法院 | 事实 | 后果 |
|---|---|---|---|
| 2023 | 美国纽约南区联邦法院(马塔诉阿维安卡航空案) | 原告律师使用 AI 生成辩护材料,虚构六份完整航空事故判例,含标准案号、法官署名、裁判说理;未做任何人工核验即提交,面对质疑仍坚持判例真实 | 两名代理律师及律所共同被处以 5000 美元连带罚款;违规记录永久记入执业档案 |
| 2025 | 美国加州上诉法院 | 两名律师提交的上诉文书中 23 条法律引文有 21 条由 AI 凭空捏造 | 1 万美元罚单;明确要求所有法律引用必须由律师逐条核验原件 |
| 2025 | 美国加州(两家律所) | 批量提交含虚假判例的诉讼材料 | 合计 3.1 万美元罚款 |
| 2025 | 英国高等法院 | 出庭实习大律师提交的文书中包含 5 份完全不存在的判例 | 未启动藐视法庭程序,但案卷线索移交大律师标准委员会开展行业调查 |
| 2026 | 美国密西西比州北区联邦地区法院 | 原被告双方四名执业律师提交的多份代理文书中,十余份核心援引判例全部为 AI 虚构;导致庭审反复延期、司法资源严重浪费 | 四名律师分别被罚款;原告、被告两名跨州出庭核心律师被判处两年内禁止在该辖区所有联邦法院出庭 |
| 2026 | 美国第五巡回上诉法院 | 律师整份答辩状依靠 AI 生成且刻意隐瞒 AI 使用情况,数十处判例、法条存在编造、歪曲 | 2500 美元罚金并下达惩戒令;违规线索移交州律师协会启动吊销执业证审查程序 |
| 2025 | 中国北京市通州区人民法院 | 律师提交 AI 生成的虚假参考案例 | 判决书批评;该案 2025 年 12 月入选人民法院案例库 |
| — | 中国湖北孝感大悟县人民法院 | 原告作为证据提交的水电表照片带有"AI 生成"水印 | 经法官质询后承认利用 AI 技术伪造证据,受到训诫 |
| 2026-07 | 中国宜昌市西陵区人民法院 | 律师提交的案例材料中,案号与对应案件信息无法匹配、法条引用与原法条对不上号、部分引用无法找到真实来源;律师称材料由助理借助 AI 收集汇总、未全面核实 | 法院认定其未尽审查义务,予以训诫 |
(以上据《法治日报》、央广网、人民网、宜昌长安网报道)
本案例的启示(法务 Harness 工程含义):
- 引用核验不是可选项,是执业底线。美国多州法院已明确要求"所有法律引用必须由律师逐条核验原件",中国法院通过入库案例确立了"提交未经甄别核实的虚假案例应承担责任"的规则。任何法务方向的 Harness 若没有强制引用核验环节,等于在制度上预留了执业事故。
- "助理用 AI 整理的"不是免责事由。宜昌西陵区法院明确指出,无论来源是助理整理还是 AI 生成,律师对提交法庭的材料负有审查核实义务。
- 隐瞒 AI 使用情况会加重后果。美国第五巡回上诉法院的案件中,"刻意隐瞒 AI 使用情况"是被惩戒的加重情节之一。这提示 Harness 应当主动记录并披露 AI 参与程度,而不是隐瞒。
- 生成过程的可复现性具有举证价值。AI 换脸案中"未能复现 AI 生成过程"直接导致举证不能。保留生成记录既是合规要求,也是自我保护。
4. 实践标准
4.1 AGENTS.md 规范
以下为 Legal 法务方向建议的 AGENTS.md 全文。本文为建议稿,业界无官方标准,可直接复制后按机构实际情况裁剪。
# AGENTS.md —— Legal 法务
> 本文为建议稿,业界无官方标准。引用法规与判例为真实规范文本与公开案例,落地方式为工程建议。
## 角色与边界
- 角色:检索者、条款抽取者、差异比对者、材料整理者、初稿起草者。
- 不是:法律意见出具人、合同签署人、诉讼文书提交人、定性判断者。
- 不得:出具法律意见;自主用印或签署;自主向法院或仲裁机构提交文书。
- 边界判定:凡传统工作流中需律师签字、用印、负责人签发的动作,智能化后仍需同等人工程序。
## 环境假设
- 存在权威法源库(法律法规、司法解释)与判例库,可返回效力层级、生效日期与案号。
- 存在合同管理系统(CLM)与条款库;电子签章接口默认不开放给 Agent。
- 存在合同版本历史与差异比对能力。
- 存在不可变日志存储;生成过程记录(提示词、输入素材、模型版本、参数)可完整保留。
## 上下文加载顺序(Context Budget)
1. 任务契约(任务类型、适用法域、允许工具、确认点、输出用途)。
2. 适用法条(**必须来自权威法源库**,携带效力层级与生效日期)。
3. 相关判例(**必须来自权威判例库**,携带案号与裁判要旨原文)。
4. 内部条款库与范本(含让步边界与谈判要点)。
5. 合同或证据材料(按数据分级脱敏后加载)。
6. 补充资料(预算不足时最先裁剪)。
硬约束:**法条与判例一律不得取自模型记忆**;未携带生效日期或案号的内容禁止加载。
## 工具契约
| 工具 | 风险等级 | 说明 |
|---|---|---|
| 法源检索 | R0 | 只读,必须返回效力层级与生效日期 |
| 判例检索 | R0 | 只读,必须返回案号与原文片段 |
| 法条/案号回源核验 | R0 | 只读,逐条核验,返回核验结论 |
| 合同文本读取 | R0/R2 | 按数据分级,敏感合同按 R2 受控 |
| 条款抽取与比对 | R1 | 输出审查意见草稿,不写入 CLM 正式字段 |
| 尽调资料库写入 | R1 | 写入草稿区,可回滚 |
| 电子签章 / 对外发文接口 | R3 | **默认关闭**,需人工在用印系统完成 |
## 任务执行流程(SOP)
1. 定级:识别任务类型、适用法域、数据分级、是否涉及不可逆动作。
2. 定源:锁定权威法源库与判例库;明确本次任务禁用模型记忆作为法源。
3. 检索:取得法条与判例原文,携带效力层级、生效日期与案号。
4. 生成:产出条款抽取结果、比对差异、审查意见初稿。
5. **引用回源核验(强制环节)**:对每一条法条与案号逐条回源;核验不通过的一律删除,不得标注"待核实"保留。
6. 完整性检查:对照条款清单核对是否遗漏;遗漏项必须显式声明。
7. 人工核验:由具名律师核验并签字,核验记录绑定主体与时间。
8. 用印与提交:由授权人员完成,Agent 不参与。
9. 归档:输入快照、法源版本、模型与提示词版本、核验记录、产物哈希一并留痕。
## 验证与证据要求
- **法条与判例引用核验通过率必须 100%**,未核验条目不得进入输出。
- 判例核验须同时核对:案号是否存在、案由是否匹配、裁判要旨是否与原文一致。
- 条款抽取须输出"已抽取/未发现/不适用"三类结论,不得以静默方式跳过。
- 输出必须显式声明 AI 参与程度(如"本材料由 AI 辅助生成,已由 [姓名] 于 [时间] 核验")。
- 生成过程记录须完整保留,以支持未来可能的"复现生成过程"要求。
## 失败与升级策略
- 检索不到权威法源 → 输出"未取得结论",不得用模型记忆或网络搜索结果替代。
- 引用核验不通过 → **删除该引用及依赖它的全部结论**;累计触发阈值上报法务负责人。
- 法条效力状态存疑 → 停止该部分分析,交人工确认效力。
- 触发电子签章或对外发文调用尝试 → 拦截并告警至法务与 IT 安全负责人。
- 发现材料中存在 AI 伪造痕迹(如带"AI 生成"水印的证据图片)→ 立即标记并升级人工核查,不得作为证据采纳。
## 安全与合规红线
- 严格遵守《人工智能生成合成内容标识办法》(2025-09-01 施行):生成内容须保留显式标识与元数据隐式标识;依法留存相关日志不少于六个月(第 9 条);不得恶意删除、篡改、伪造、隐匿标识(第 10 条)。
- **禁止编造法条、司法解释、判例案号、裁判要旨、标准编号。**
- **禁止以模型记忆提供法条或判例内容**,必须回源核验。
- 禁止自主用印、签署、对外发函、提交诉讼或仲裁文书。
- 禁止在引用核验未通过时保留结论。
- 合同与证据材料中的个人信息按最小必要原则处理,保存期限不短于法定要求。
## 禁止事项
1. 禁止生成或引用任何未经回源核验的法条、案号、裁判要旨。
2. 禁止以"待核实""仅供参考"等措辞保留未核验的引用。
3. 禁止出具最终法律意见或定性结论。
4. 禁止自主用印、签署、对外发函、提交文书。
5. 禁止隐瞒 AI 参与生成的事实。
6. 禁止把 AI 生成内容伪装为人工撰写的专业意见。
7. 禁止删除或弱化生成合成内容标识与审计日志。
8. 禁止删除生成过程记录(提示词、输入素材、模型版本、参数)。
9. 禁止使用可能侵犯他人肖像权、著作权、名誉权的素材作为输入或输出。
10. 禁止把本文件的建议表述为法律规定或执业规范。
## 输出格式
- 结论:明确、可判定;无法得出结论时写明"未取得结论"及原因。
- 依据:表格化,含来源类型、来源标识、**效力层级**、**生效日期**、**案号**、条款或片段位置、**核验状态**。
- 不确定性:列出影响可靠性的事项与建议处置。
- AI 参与声明:显式声明 AI 辅助生成及人工核验情况。
- 留痕:任务标识、法源版本、模型与提示词版本、核验人及时间、产物哈希。
## 评估与自检
- [ ] 所有法条与判例引用已逐条回源核验,核验通过率 100%
- [ ] 未使用模型记忆提供条文或判例内容
- [ ] 条款抽取已输出"已抽取/未发现/不适用"三类结论,无静默跳过
- [ ] 已显式声明 AI 参与程度与人工核验情况
- [ ] 未执行任何 R3 动作;用印与提交由人工完成
- [ ] 生成过程记录已完整保留
- [ ] 生成合成内容标识已保留,日志已写入只追加存储
- [ ] 未编造任何法条、案号、裁判要旨或标准编号 4.2 SKILL.md 规范
以下为 Legal 法务方向建议的 SKILL.md 全文。本文为建议稿,业界无官方标准。
---
name: legal-contract-review-draft
description: 合同审查草稿生成。对合同文本做条款抽取、范本差异比对与风险标注,输出待律师核验的审查意见草稿。所有法条与判例引用强制回源核验。适用于采购合同、服务合同、保密协议等常规合同的初审场景。
version: 1.0
created: 2026-09-12
---
# 合同审查草稿生成
## 适用场景
- 适用:常规合同的初审、条款完整性核查、与内部范本的差异比对、风险条款标注、修改建议起草。
- 不适用:重大合同的最终意见出具、谈判决策、自主用印或签署、涉外合同的法律适用终判。
## 前置条件
- 已获取待审合同文本(最终版或指定版本)与适用范本。
- 权威法源库可用,可返回效力层级与生效日期。
- 内部条款库与让步边界清单可用。
- 审查意见草稿区可写入(R1),且核验律师已指定。
## 输入
| 输入项 | 必填 | 说明 |
|---|---|---|
| 合同文本与版本号 | 是 | 明确是哪个版本,避免审查错版本 |
| 合同类型 | 是 | 采购/服务/保密/其他,决定条款清单 |
| 适用法域 | 是 | 涉及时须明确,影响法条检索范围 |
| 我方立场 | 是 | 甲方/乙方,决定风险倾向判断 |
| 内部范本与让步边界 | 是 | 差异比对的基准 |
| 数据分级 | 是 | 涉密合同按 R2 受控处理 |
## 输出
| 输出项 | 说明 |
|---|---|
| 条款抽取表 | 条款类型、所在位置、核心内容摘要、状态(已抽取/未发现/不适用) |
| 差异比对表 | 与范本的差异项、差异性质(有利/不利/中性)、建议处置 |
| 风险标注清单 | 风险点、风险等级、法条或制度依据(已核验)、修改建议 |
| 遗漏声明 | 明确列出未能审查的部分及原因 |
| 留痕信息 | 合同版本、法源版本、模型与提示词版本、核验人及时间 |
## 执行步骤
1. 核对合同版本与类型,确认审查基准(范本 + 让步边界 + 我方立场)。
2. 按条款清单逐项抽取:主体、标的、价款与支付、履行期限、验收、违约、责任限制、保密、知识产权、争议解决、管辖、不可抗力、变更与解除。
3. 与范本逐项比对,标注差异性质与建议处置。
4. 对不利差异检索法条与制度依据,**逐条回源核验**;核验不通过的引用直接删除。
5. 生成风险标注清单与修改建议草稿。
6. 自校验:条款状态三类结论齐全;引用核验通过率 100%;差异项无遗漏静默。
7. 输出草稿并转具名律师核验。
8. 归档留痕,核验结论回流为评估样本。
## 质量标准(DoD)
- 一票否决:存在未回源核验的法条引用;使用了模型记忆提供条文;自主写入 CLM 正式字段或用印;审查了错误版本却未发现。
- 条款抽取完整性:条款清单覆盖率 100%,每项均有明确状态(不得为空白)。
- 引用核验通过率 100%,核验状态不得出现"未核验"。
- 差异项 100% 标注性质与建议处置。
- 未能审查的部分必须显式声明,不得静默跳过。
## 常见失败与处理
| 失败模式 | 表现 | 处置 |
|---|---|---|
| 法条幻觉 | 生成不存在的法条编号或条文内容 | 强制回源核验;核验不通过即删除该条及依赖结论 |
| 案号错配 | 案号真实但案情描述与裁判文书不符 | 逐条比对裁判要旨原文;不符即删除 |
| 版本错审 | 审查了过期版本 | 版本号前置校验;与 CLM 中最新版本比对 |
| 静默遗漏 | 条款清单中某项未抽取也未声明 | 强制输出三态结论;空白项阻断交付 |
| 立场错判 | 未考虑我方立场,给出中性但无用的意见 | 立场为必填输入;差异性质按立场重新标注 |
| 效力过时 | 引用已废止条款 | 强制携带生效日期;废止条款禁止加载 |
## 示例
输入:
- 合同文本:《XX 服务合同》v3.2
- 合同类型:服务合同;适用法域:中国内地;我方立场:甲方(采购方)
- 内部范本:服务合同范本 v2.0;让步边界清单:责任限制上限不超过合同总额
输出(节选):
| 条款类型 | 位置 | 核心内容 | 状态 |
|---|---|---|---|
| 责任限制 | 第 9.2 条 | 乙方责任上限为合同总额的 50% | 已抽取 |
| 知识产权 | — | — | 未发现(建议补充) |
| 不可抗力 | 第 12 条 | 约定不可抗力范围与通知期限 | 已抽取 |
| 差异项 | 与范本差异 | 性质 | 建议处置 |
|---|---|---|---|
| 责任限制 | 范本为 100%,本合同为 50% | 不利 | 建议谈判恢复至不低于 100%,或在价款中作对价调整 |
| 风险点 | 风险等级 | 依据(已核验) | 修改建议 |
|---|---|---|---|
| 责任上限过低 | 中 | [法条以法源库检索结果为准,核验状态:已核验] | 建议调整上限并明确除外情形 |
> 说明:上表中条款位置与比例为示例格式,实际必须以合同原文与法源库返回结果填充,不得沿用示例值。 4.3 落地检查清单
| 序号 | 检查项 | 检查方法 | 通过标准 |
|---|---|---|---|
| 1 | 模型记忆截断 | 系统配置核查 | 法条与判例 100% 来自权威库检索 |
| 2 | 引用核验通过率 | 输出全量检查 | 100%,无"未核验"条目 |
| 3 | 案号与案情一致性 | 判例抽检 50 条 | 100% 案号、案由、裁判要旨三项一致 |
| 4 | 效力层级与生效日期 | 引用抽检 | 100% 携带 |
| 5 | 条款三态结论 | 审查意见抽检 | 已抽取/未发现/不适用 100% 齐全 |
| 6 | 用印权限 | 权限核查 | 电子签章接口对 Agent 全部关闭 |
| 7 | 法律意见出具权限 | 流程核查 | 100% 由具名律师出具并签字 |
| 8 | AI 参与声明 | 输出抽检 | 100% 显式声明 AI 参与与人工核验情况 |
| 9 | 生成过程记录保留 | 日志核查 | 提示词、输入素材、模型版本、参数 100% 保留 |
| 10 | 生成内容标识 | 产物抽检 | 显式标识与元数据隐式标识 100% 保留 |
| 11 | 肖像与著作权合规 | 素材来源核查 | 输入与输出素材 100% 有合法授权或属合法使用 |
| 12 | 数据分级执行 | 数据流核查 | 涉密合同未出域 |
| 13 | 日志不可篡改 | 权限与存储核查 | 业务账号仅有追加权限 |
| 14 | 伪造痕迹识别 | 证据材料检查流程 | AI 伪造痕迹 100% 被标记并升级人工 |
| 15 | 责任到人 | 核验记录核查 | 每份对外文书可定位到具名核验人 |
5. 总结
法务方向的 AI Harness,本质是一套把"引用真实性"工程化为可强制执行的机制的系统。
三点结论:
第一,法务方向唯一不可妥协的指标是引用核验通过率,且必须是 100%。 其他方向可以有 99% 的容忍度,法务方向不行。原因很简单:在合同审查中漏掉一个非核心条款,损失有限;在代理意见中放一条虚构案号,代价是执业责任与司法秩序损害。美国加州上诉法院已明确要求"所有法律引用必须由律师逐条核验原件",中国法院通过入库案例确立了"提交未经甄别核实的虚假案例应承担责任"的规则——这两条来自不同法域的规则指向同一个工程要求。
第二,"AI 参与"要主动披露,而不是隐瞒。 美国第五巡回上诉法院的案件中,"刻意隐瞒 AI 使用情况"是被加重惩戒的情节。中国法院虽未就隐瞒行为单独加重,但通州法院在判决书中明确写入"不得放任人工智能模型生成或者编造虚假信息扰乱司法秩序"。Harness 应当在输出中固定挂载 AI 参与声明与人工核验信息。
第三,保留生成过程记录既是合规要求,也是自我保护。 AI 换脸案中,被告因"未能复现其声称的 AI 生成过程"而承担举证不能的不利后果。这一裁判逻辑完全可以迁移到法务场景:当一份 AI 辅助生成的材料引发争议时,能否复现生成过程(用了什么素材、什么提示词、什么模型版本)将直接影响责任认定。因此提示词、输入素材、模型版本与参数的留存,不是可选项。
必须正视的局限:本方向引用的多起境外案件为媒体转述,具体罚则与程序以各法域法院的正式文书为准;部分中国案件的进展状态(如是否上诉、是否进入再审)未能逐一核实,引用时应注明"以有权机关最终认定为准"。此外,AI 生成物的可版权性在司法实践中尚未完全统一,本案之后的裁判发展仍在演进中。
信息缺口声明
以下数据在本方向撰写过程中未能取得可靠二次信源,已按规范标注处理,待补充:
- 腾讯 Dreamwriter 案判决书的完整裁判文书原文:本文引用内容来自法治网、36 氪等媒体转述,未取得判决书全文,标注为 。
- 北京互联网法院 AI 换脸案的具体案号与判决日期:报道未披露完整案号,仅知由北京互联网法院审结、判决已生效,标注为 [待填写]。
- 吴某诉某科技公司 AI 换脸 APP 案的审理法院与案号:澎湃新闻报道未完整披露,仅知为福州中院相关案例,标注为 。
- 腾讯 Dreamwriter 案与北京互联网法院计算机软件生成物案的裁判差异:有观点认为两案认定存在分歧,但未取得两案的完整比对分析,本案结论标注为"实践中尚未完全统一"。
- 境外各案(Mata 案、加州案、密西西比案等)的正式裁判文书编号:均为媒体转述,未取得原始文书编号,标注为 。
- 湖北孝感大悟县法院案的案号与进展:仅见于央视《法治在线》报道,未披露案号,标注为 [待填写]。
6. 参考资料
- AI 判例造假有恃无恐,全球携手严打 — 法治日报,2026。http://www.lawnewscn.cn/wap/content/2026-08/26/content_9446481.html
- 法治在线 | 律师用 AI 生成虚假案例被法院发现 将承担何种责任 — 央广网,2026。https://news.cnr.cn/native/gd/20260115/t20260115_527494281.shtml
- 警惕 AI 生成虚假案例干扰司法审理 — 人民网,2026。https://yn.people.com.cn/BIG5/n2/2026/0121/c361322-41478254.html
- 媒体关注 | 律师提交 AI 生成虚假案例被当庭训诫 — 宜昌长安网,2026。http://zfw.yichang.gov.cn/content-64133-965206-1.html
- AI 作品著作权归谁?法院审判多起"首案"厘清侵权边界 — 法治网,2026。https://www.legaldaily.com.cn/index/content/2026-06/03/content_9400177.html
- 你用 AI 写的文章,著作权到底归谁?— 天达共和律师事务所,2026。http://www.east-concord.com/zygd/Article/20266/ArticleContent_4652.html
- 技术不是侵权"挡箭牌" 法院这样认定 AI"盗脸" — 经济参考网,2026。https://www.jjckb.cn/20260418/957b6bc4d3a34c27b9954fe4d240ae97/c.html
- 《家事法庭》联动普法:你的声音肖像,AI 说了不算!— 澎湃新闻。https://m.thepaper.cn/newsDetail_forward_32953019
- 人工智能写作领域第一案在深圳法院落槌首次确认 — 法制日报 / 36 氪。https://36kr.com/coop/uc/5283237.html
- 关于印发《人工智能生成合成内容标识办法》的通知(国信办通字〔2025〕2 号)— 国家互联网信息办公室等四部门,2025。https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm
- 中央网信办部署开展"清朗·整治 AI 技术滥用"专项行动 — 中央网络安全和信息化委员会办公室,2025。https://www.cac.gov.cn/2025-04/30/c_1747719097461951.htm
- Secure Software Development Practices for Generative AI and Dual-Use Foundation Models(NIST SP 800-218A)— NIST CSRC,2024。https://csrc.nist.gov/pubs/sp/800/218/a/final
Legal
1. Introduction
1.1 Background
Legal work is the domain in AI applications where the returns are "most tangible" and the risks "most fatal." On the one hand, contract review, due-diligence document organization, statute retrieval, and litigation material preparation all rely heavily on text processing — precisely the type of task at which large models excel. On the other hand, legal output carries an evidentiary attribute: for a representation opinion submitted to a court, or a contract to be signed externally, the authenticity of its content is directly tied to professional liability and to the order of the judicial system.
Since 2023, judicial systems around the world have collectively encountered a new class of problem: AI-generated fabricated statutes and precedents entering the courtroom. This is not a theoretical concern but a real problem that has already produced actual consequences such as fines, practice bans, and court reprimands. At the same time, issues such as the ownership of rights in AI-generated content and the boundaries of personality rights around AI face-swapping have progressively established adjudicative rules through a series of "first cases."
For an AI Harness for the Legal direction, this implies a fundamental design premise: in legal scenarios, the model's linguistic fluency is a liability rather than an asset. A crudely worded search result in which every citation is authentic is worth far more than an elegantly written representation opinion containing three fabricated precedents. The latter will not be recognized as an error; it will be treated as fraud.
1.2 Definition
The AI Harness for the Legal direction refers to an engineering-oriented operation layer that carries legal tasks such as contract review, legal due diligence, litigation support, and regulatory retrieval. Its core responsibility is to ensure that every legal citation is authentic, every clause extraction is complete, and every outward-facing document has undergone human verification — not to improve the elegance or volume of documents.
This direction covers four types of tasks:
| Task Category | Typical Tasks | Output Form |
|---|---|---|
| Contract review | Clause extraction, difference comparison, risk-clause annotation, template application | Review-opinion draft, not a final opinion |
| Legal due diligence | Target-company document organization, litigation and penalty search, equity-chain verification | Due-diligence materials and a list of concerns |
| Litigation support | Case search, dispute-issue organization, evidence-list compilation, document first drafts | Search results and first drafts, not documents to be filed |
| Regulatory retrieval | Statute retrieval, effectiveness verification, preliminary applicability assessment, regulatory-change tracking | Search results and preliminary assessment, not legal advice |
Key boundary: All output of the Legal direction consists of drafts pending verification. The issuance of legal opinions, the signing of contracts, and the filing of litigation documents must all be completed and borne by natural persons who hold the relevant professional qualifications.
1.3 Positioning within the AI Harness system
图 1-1|法务方向 AI Harness 六层定位:瓶颈在 L1/L5
数据来源:基于本文分析绘制的示意图。
| Layer | Content Carried by the Legal Direction | Key Engineering Requirement |
|---|---|---|
| L1 Context engineering | Retrieval of statutes, precedents, contract templates, and the internal clause library | Authoritative sources have absolute priority; model memory must not serve as a source of statutory text |
| L2 Tools and execution | CLM contract management system, legal-source verification interfaces, due-diligence database | Electronic sealing and outward-facing document tools are R3 irreversible and disabled by default |
| L3 Orchestration and control | Contract-review pipeline, due-diligence checklist orchestration, clause comparison and difference annotation | The verification step cannot be skipped; a failed verification must block downstream stages |
| L4 Memory and state | Contract version history, clause library, prior negotiation points and concession boundaries | Version comparison is the core capability of the legal scenario |
| L5 Evaluation and observation | Clause-extraction accuracy, citation-verification pass rate, omission rate | The citation-verification pass rate is a veto indicator |
| L6 Governance and safety | Prohibiting fabrication of statutes and precedents; human review required for outward filings and sealing; generation labeling | The primary constraint layer for this direction |
The bottleneck lies in L1 and L5.
- L1 is the source of risk: the vast majority of legal-task failures are not "reasoning errors" but "fabricated retrieval results." The model's parametric memory stores fragments of many statutes and case numbers, and it outputs them with extremely high confidence, in a well-formatted, professional tone that is nearly indistinguishable from genuine text to the naked eye. The first design requirement of the L1 layer is therefore to cut off the model's ability to draw on its memory as a legal source, forcing all statutory text and precedents to be obtained through retrieval from authoritative databases.
- L5 is the capability bottleneck: building an evaluation set for legal tasks is difficult. A contract-review opinion has no standard answer to "is it correct," but "does the cited statute actually exist" has an objective answer. This requires the evaluation for the legal direction to be designed in layers: the objectively determinable parts (citation authenticity, clause-coverage completeness) serve as hard indicators, while the subjective-judgment parts (whether a risk is acceptable) are left to humans.
A key difference from other directions: the Legal direction is the only one among the five directions that takes "citation authenticity" as its primary quality indicator. The Finance direction values digital traceability, and the Audit direction values the chain of evidence, but only the Legal direction will trigger professional liability directly because of a single fabricated case number.
1.4 Value and Limitations
Value:
- Full-coverage scanning replaces sampling reads. Faced with hundreds or thousands of contracts and documents during due diligence, AI can scan everything, and humans only need to re-check high-risk items.
- Precise comparison of version differences. In version iterations during contract negotiation, manual comparison easily misses subtle changes, whereas machine comparison can be precise down to the character level.
- Improved retrieval efficiency. Regulatory and precedent retrieval upgrades from keyword matching to semantic retrieval, markedly improving recall.
- Freeing up repetitive document work. Tasks such as evidence-list compilation, material-point organization, and first-draft generation can be substantially accelerated.
Limitations (which must be faced squarely):
- In legal scenarios, the cost of hallucination is professional liability and the order of the judicial system. In the Mata v. Avianca case heard by the U.S. District Court for the Southern District of New York in 2023, the plaintiff's attorneys used AI-generated defense materials that fabricated six complete aviation-accident precedents out of thin air, including standard case numbers, justices' signatures, legal reasoning, and case details. The attorneys filed them with the court without any human verification, insisted on the precedents' authenticity when challenged by opposing counsel, and were ultimately found by the court to have violated their duty of diligent practice and to have abused judicial process. The two attorneys and their firm were jointly fined a total of $5,000, with the misconduct permanently recorded in their practice files (as reported by Rule of Law Daily).
- The model lacks legal judgment capability. The application of law involves rule conflicts, value balancing, and policy considerations; the model can only supply materials and leads, not substitute for judgment.
- "Seeming perfection" is the most dangerous failure mode. Judge Zheng Jizhe of the Beijing Tongzhou District People's Court, describing an AI-generated fabricated case, said: "It seemed to describe exactly the same viewpoint as our case — the described content and circumstances were remarkably similar, perfectly recreating the current factual situation of this case, and the adjudicative viewpoint perfectly supported our client's claims." It is precisely this "perfect fit" that makes fake content harder to detect.
- The cost of verification has not disappeared; it has merely shifted. AI converts the cost of "searching from scratch" into the cost of "verifying item by item." If an organization does not allocate resources to the verification stage, AI merely produces errors faster.
2. Glossary of Terms
| Term | English / Abbreviation | Definition |
|---|---|---|
| Contract management system | Contract Lifecycle Management / CLM | A management system covering the full lifecycle of a contract — drafting, approval, signing, performance, and archiving; the core business system of the Legal direction |
| Clause extraction | Clause Extraction | The process of identifying and structurally extracting specific types of clauses from contract text (e.g., jurisdiction, breach, confidentiality, limitation of liability) |
| Difference comparison | Redline / Diff Comparison | Identifying each modification between two or more contract versions and outputting a list of differences |
| Legal due diligence | Legal Due Diligence / LDD | Systematic examination of a target entity's legal status, covering dimensions such as entity qualification, equity, assets, litigation, and compliance |
| Litigation support | Litigation Support | Auxiliary work for litigation or arbitration, including case search, evidence organization, and document preparation |
| Source of law | Source of Law | The source of legal rules, including laws, administrative regulations, departmental rules, local regulations, and judicial interpretations |
| Precedent | Case / Precedent | A ruling already rendered by a court; in the Chinese context, guiding cases, gazette cases, and cases in the case database carry reference value |
| Case number | Case Number | The unique identifier of a court case, e.g., (2022) Hu 01 Min Zhong No. 12345; the first handle for verifying whether a precedent is genuine |
| Holding | Holding / Gist | A condensed statement of the core adjudicative rule of a judgment document |
| Legal hierarchy | Legal Hierarchy | The hierarchy among laws, administrative regulations, departmental rules, and regulatory documents; must be noted when citing |
| Legal hallucination | Legal Hallucination | The phenomenon in which a model generates statutes, case numbers, or holdings that do not exist, or misdescribes real precedents |
| Identifiability | Identifiability | A standard for determining portrait-right infringement: as long as the general public can identify an image as a particular natural person, it constitutes use of that person's portrait |
| Failure of proof | Failure of Proof | The legal status in which the party bearing the burden of proof cannot provide evidence or provides insufficient evidence, thereby bearing adverse consequences |
| Reprimand | Reprimand | A coercive measure in which a court criticizes and admonishes, in court, a person who obstructs litigation order but whose conduct is minor |
| Electronic signature | Electronic Signature | Data in electronic form that can be used to identify the signer's identity and indicate assent to the content; sealing is an irreversible action |
| Principle of good faith | Principle of Good Faith | A fundamental principle to be followed in civil litigation; the primary normative basis on which courts handle AI-generated fabricated materials |
| People's Court Case Database | People's Court Case Database | A case database built by the Supreme People's Court; cases included in it carry reference and guidance value |
3. Case Studies
The case studies below are drawn from publicly verifiable judicial precedents and authoritative media reports. For those involving specific cases, the status of the case proceedings has been noted.
3.1 Copyright Boundaries of AI-Generated Content: The Nation's First Recognition Case
3.1.1 Background
Whether AI-generated content can be protected under copyright law is one of the first legal questions encountered after the spread of generative AI. If the answer is no, then any AI-generated text or image can be freely copied and used; if the answer is yes, then it becomes necessary to determine to whom the rights belong.
Tencent independently developed Dreamwriter, an intelligent writing-assistance system based on data and algorithms. On August 20, 2018, Dreamwriter produced a financial news article, which stated at its end that "this article was automatically written by Tencent's robot Dreamwriter." After the article was first published on Tencent's securities website, Shanghai Yingxun Technology Co., Ltd. copied the article the same day and disseminated it to the public through its "Wangdai Zhijia" (P2P-lending home) website. Tencent accordingly sued Shanghai Yingxun for copyright infringement before the Shenzhen Nanshan District People's Court.
3.1.2 Approach (The Court's Adjudicative Path)
The court's adjudicative path essentially answers the question "where does the human intellectual input lie in the AI generation process":
- Review of the external form of expression: the court found that the article at issue "externally met the formal requirements of a written work; its expressed content reflected selection, analysis, and judgment concerning the relevant stock-market information and data of that morning, the article had a reasonable structure and clear logic of expression, and it possessed a certain degree of originality."
- Review of the generation process: the court found that the arrangements and choices made by the plaintiff's core creative team in data output, trigger-condition settings, and the adoption or rejection of templates and corpus styles constituted intellectual activity directly connected to the specific expression of the article at issue; the automatic operation of the Dreamwriter software embodied the plaintiff's individualized choices and arrangements.
- Determination of rights ownership: the court found that the article at issue was completed as an overall intellectual creation through the division of labor among multiple teams and individuals of the plaintiff, and on the whole reflected the plaintiff's needs and intent in publishing stock-review summary articles, thus constituting a work made for hire by a legal person.
3.1.3 Outcome
According to reports from Legal Daily's website (fazhiwang), the court ultimately found that the defendant, without permission, provided the allegedly infringing article to the public on its website, infringing the plaintiff's right to disseminate over information networks, and ordered the defendant to pay a total of 1,500 yuan in economic losses and reasonable rights-protection costs. The case number is (2019) Yue 0305 Min Chu No. 14010, the judgment date was December 27, 2019, and it is the country's first case confirming that AI-generated content can enjoy copyright.
Implication for the design of a Legal Harness: this case established the "intellectual input" standard — determining the ownership of rights in AI-generated content looks at a person's arrangements and choices in data selection, condition setting, and the adoption or rejection of templates and corpus. The engineering implication of this standard for Harness is that the process of prompt design, corpus selection, and parameter configuration should be recorded. In any future rights dispute, these records are precisely the evidence of "intellectual input."
It should be noted that, after this case, the Beijing Internet Court reached a different determination in another case involving a computer-software-generated output, holding that creation by a natural person should still be a necessary condition for a work under copyright law. This shows that the copyrightability of AI-generated output has not yet been fully unified in judicial practice, so citations must indicate the case and the time (according to public articles by Tenda Chinese Law Firm and reports by Legal Daily's website).
3.2 Portrait-Right Boundaries of AI Face-Swapping: The Identifiability Standard and Burden of Proof
3.2.1 Background
The spread of AI face-swapping technology has lowered the barrier to "using another person's portrait" to nearly zero. The central dispute it gives rise to is: when a face that is AI-generated or AI-swapped is not completely identical to the original portrait, does it still constitute use of that natural person's portrait?
In a tort case triggered by AI face-swapping, the plaintiff was a well-known domestic actor. The plaintiff discovered that in a short drama produced and released by defendant Company A, AI face-swapping technology had been used to splice the plaintiff's portrait onto the faces of characters in the drama, leading the public to mistakenly believe the plaintiff had starred in it, and the relevant topic sparked heated discussion on social platforms. The other defendant, Company B, put the short drama online on a video account it operated.
Company A argued that the image at issue was AI-generated, that it had not subjectively used the plaintiff's portrait, and that the disputed clips were extremely short in duration and had been promptly taken down. Company B argued that it had obtained the authorization for the right to disseminate the short drama over information networks, that it was not the producer, and that it had no intent to infringe.
3.2.2 Approach (The Court's Adjudicative Path)
- "Identifiability" as the core standard: the court found that the short drama at issue comprised 44 episodes totaling 90 minutes, of which two clips used AI face-swapping technology, and the faces after swapping were highly similar to the plaintiff; numerous hashtags such as "#short drama suspected of using AI-swapped face of actor so-and-so" appeared on social platforms, with many netizens participating in discussion and raising doubts. The court held that, although the image after AI swapping was not completely identical to the original portrait, under the Civil Code of the People's Republic of China a portrait is an "external image that can be recognized," and as long as the general public can recognize it, the conduct constitutes portrait-right infringement.
- Allocation of the burden of proof: Company A failed to reproduce the AI generation process it claimed, so it had to bear the responsibility for failure of proof, and the court accordingly found that it had intent to infringe.
- Independent duty of the platform: although Company B had obtained copyright authorization, the court pointed out that copyright cannot absorb or override portrait rights, and since Company B failed to fulfill its duty of reasonable review, it also constituted infringement.
3.2.3 Outcome
According to reports from the Economic Information Daily website (jingjicankao), the court ultimately ordered Companies A and B to each publish a written apology on their respective video accounts and to compensate the plaintiff for economic losses. The core value of this case lies in the fact that it established, for the first time using the "public identifiability" standard, the adjudicative rule that "high similarity constitutes portrait infringement", and clarified the independent review duty of content-publishing platforms — obtaining valid copyright authorization is only the basic duty for putting content online and cannot be used to escape liability.
In another similar case, a technology company, without permission, uploaded the portrait video of an online video creator, Wu, into its one-click AI face-swap effects video app as a template and profited from it. The court ruled that the company must publish an apology at a prominent position on the app's homepage for 15 consecutive days and compensate for economic losses, reasonable rights-protection costs, and mental-distress damages (according to a related Fuzhou Intermediate People's Court case reported by The Paper).
Implication for the design of a Legal Harness: the most important engineering implication of this case is that "AI-generated" is not a ground for exemption from liability, but "whether the generation process can be reproduced" directly affects the determination of liability. This requires Harness to fully preserve records of the generation process (prompts, input materials, model version, parameters); otherwise, in a dispute, it would be at a disadvantage due to failure of proof.
Related provisions of the Civil Code of the People's Republic of China: Article 1018 provides that a natural person enjoys portrait rights, and a portrait is "an external image of a specific natural person that can be recognized, reflected on a certain carrier through images, sculptures, paintings, and other means"; Article 1019 provides that "no organization or individual may infringe another person's portrait rights by defacing, soiling, or forging through information-technology means or otherwise," and may not produce, use, or publicly disclose a person's portrait without the consent of the portrait-right holder.
3.3 Failure and Risk: AI Hallucination Invading the Judiciary and the Global Wave of Lawyer Discipline
3.3.1 Background
This is the most important category of cases for the Legal direction, and the one that cannot be avoided. Since 2023, AI-generated fabricated statutes and precedents have continued to enter judicial proceedings in various countries, triggering a global wave of lawyer discipline. Chinese courts have also seen a concentration of similar problems since 2025.
3.3.2 Approach (Responses of National Judicial Systems)
China's response path:
- While hearing a civil dispute arising from shareholding-on-behalf (dai chi gu), the Beijing Tongzhou District People's Court found that, in a written representation opinion submitted after the hearing, the plaintiff's attorney had attached two "reference cases," one of which was marked (2022) Hu 01 Min Zhong No. 12345. Upon verification, the judge found that the case corresponding to that number was actually a private-lending dispute, "completely unrelated" to shareholding-on-behalf. Under the judge's questioning, the attorney admitted that the reference cases had been generated by repeatedly querying a certain large AI-model software based on the facts of this case, and had been copied and pasted into the filing without verification.
- Considering that there was no explicit legal provision covering the conduct, that the attorney showed no obvious malice, that the circumstances were minor, and that no serious consequences resulted, the court wrote this circumstance into the judgment as a criticism: "It is hoped that the plaintiff's representative will take this as a warning and, when submitting reference cases and statutes to the court, will examine and verify them to ensure the truthfulness and accuracy of the content, and will not allow artificial-intelligence models to generate or fabricate false information that disrupts judicial order."
- In December 2025, this case was included in the People's Court Case Database, with the holding clarifying: litigation participants should follow the principle of good faith in civil-litigation activities; litigation participants who submit false cases obtained through AI technology and not screened or verified should bear the corresponding legal consequences; where the circumstances are minor, the people's court may criticize and educate them; where the circumstances are more serious, they may be handled by reference to Article 114, Paragraph 1 of the Civil Procedure Law of the People's Republic of China.
Response paths in other jurisdictions: According to Rule of Law Daily, the judicial systems of the United States, the United Kingdom, and Australia have all seen cases of AI-fabricated precedents and have formed a chain of handling.
3.3.3 Outcome (Actual Consequences That Have Occurred)
| Time | Jurisdiction / Court | Facts | Consequences |
|---|---|---|---|
| 2023 | U.S. District Court for the Southern District of New York (Mata v. Avianca) | The plaintiff's attorneys used AI-generated defense materials, fabricating six complete aviation-accident precedents including standard case numbers, justices' signatures, and legal reasoning; they filed them without any human verification and insisted on the precedents' authenticity when challenged | The two attorneys and their firm were jointly fined a total of $5,000; the misconduct permanently recorded in their practice files |
| 2025 | California Court of Appeal, U.S. | Of the 23 legal citations in an appellate brief filed by two attorneys, 21 were fabricated out of thin air by AI | A $10,000 fine; explicitly required that all legal citations be verified line by line by attorneys against the originals |
| 2025 | California, U.S. (two law firms) | Batch submission of litigation materials containing fabricated precedents | A total of $31,000 in fines |
| 2025 | High Court of England and Wales | Documents filed by a trainee barrister appearing in court contained five precedents that did not exist at all | No contempt-of-court proceedings were initiated, but the case-file leads were referred to the Bar Standards Board for an industry investigation |
| 2026 | U.S. District Court for the Northern District of Mississippi | In multiple representation documents filed by four practicing attorneys on both sides, over a dozen core supporting precedents were all fabricated by AI; this caused repeated postponements of hearings and a serious waste of judicial resources | The four attorneys were each fined; the two core out-of-state attorneys appearing for the plaintiff and defendant were barred from appearing in all federal courts in that district for two years |
| 2026 | U.S. Court of Appeals for the Fifth Circuit | An attorney relied on AI for an entire brief and deliberately concealed the use of AI, with dozens of precedents and statutes fabricated or distorted | A $2,500 fine and a disciplinary order; the violation leads were referred to the state bar association to initiate a review procedure for revocation of the practice license |
| 2025 | Tongzhou District People's Court, Beijing, China | An attorney submitted an AI-generated fabricated reference case | Criticized in the judgment; the case was included in the People's Court Case Database in December 2025 |
| — | Dawu County People's Court, Xiaogan, Hubei, China | A photo of water and electricity meters submitted as evidence by the plaintiff bore an "AI-generated" watermark | After questioning by the judge, admitted to forging evidence using AI technology and received a reprimand |
| 2026-07 | Xiling District People's Court, Yichang, China | In case materials submitted by an attorney, the case numbers could not be matched to the corresponding case information, the statute citations did not match the original statutes, and some citations had no verifiable source; the attorney said the materials had been compiled by an assistant using AI and had not been fully verified | The court found that the attorney failed to fulfill the duty of review and issued a reprimand |
(The above is based on reports from Rule of Law Daily, CNR (cnr.cn), People's Daily Online, and Yichang Changan Net.)
Implications of this case (engineering meaning for a Legal Harness):
- Citation verification is not optional; it is the baseline of practice. Courts in many U.S. states have already explicitly required that "all legal citations be verified line by line by attorneys against the originals," and Chinese courts have, through database-included cases, established the rule that "submitting false cases that are not screened or verified carries responsibility." Any Legal-direction Harness without a mandatory citation-verification stage is, in effect, institutionalizing a foreseeable practice incident.
- "Compiled by an assistant with AI" is not a ground for exemption from liability. The Yichang Xiling District Court made clear that regardless of whether the source is assistant compilation or AI generation, attorneys bear the duty to review and verify materials submitted to the court.
- Concealing AI use aggravates the consequences. In the U.S. Fifth Circuit case, "deliberately concealing AI use" was one of the aggravating circumstances for discipline. This suggests that Harness should proactively record and disclose the degree of AI involvement, rather than conceal it.
- The reproducibility of the generation process carries evidentiary value. In the AI face-swapping case, "failure to reproduce the AI generation process" directly led to failure of proof. Retaining generation records is both a compliance requirement and a form of self-protection.
4. Practice Standards
4.1 AGENTS.md Specification
Below is the full recommended AGENTS.md for the Legal direction. This is a draft recommendation, and there is no official industry standard; it may be copied directly and trimmed to suit the organization's actual circumstances.
# AGENTS.md —— Legal 法务
> 本文为建议稿,业界无官方标准。引用法规与判例为真实规范文本与公开案例,落地方式为工程建议。
## 角色与边界
- 角色:检索者、条款抽取者、差异比对者、材料整理者、初稿起草者。
- 不是:法律意见出具人、合同签署人、诉讼文书提交人、定性判断者。
- 不得:出具法律意见;自主用印或签署;自主向法院或仲裁机构提交文书。
- 边界判定:凡传统工作流中需律师签字、用印、负责人签发的动作,智能化后仍需同等人工程序。
## 环境假设
- 存在权威法源库(法律法规、司法解释)与判例库,可返回效力层级、生效日期与案号。
- 存在合同管理系统(CLM)与条款库;电子签章接口默认不开放给 Agent。
- 存在合同版本历史与差异比对能力。
- 存在不可变日志存储;生成过程记录(提示词、输入素材、模型版本、参数)可完整保留。
## 上下文加载顺序(Context Budget)
1. 任务契约(任务类型、适用法域、允许工具、确认点、输出用途)。
2. 适用法条(**必须来自权威法源库**,携带效力层级与生效日期)。
3. 相关判例(**必须来自权威判例库**,携带案号与裁判要旨原文)。
4. 内部条款库与范本(含让步边界与谈判要点)。
5. 合同或证据材料(按数据分级脱敏后加载)。
6. 补充资料(预算不足时最先裁剪)。
硬约束:**法条与判例一律不得取自模型记忆**;未携带生效日期或案号的内容禁止加载。
## 工具契约
| 工具 | 风险等级 | 说明 |
|---|---|---|
| 法源检索 | R0 | 只读,必须返回效力层级与生效日期 |
| 判例检索 | R0 | 只读,必须返回案号与原文片段 |
| 法条/案号回源核验 | R0 | 只读,逐条核验,返回核验结论 |
| 合同文本读取 | R0/R2 | 按数据分级,敏感合同按 R2 受控 |
| 条款抽取与比对 | R1 | 输出审查意见草稿,不写入 CLM 正式字段 |
| 尽调资料库写入 | R1 | 写入草稿区,可回滚 |
| 电子签章 / 对外发文接口 | R3 | **默认关闭**,需人工在用印系统完成 |
## 任务执行流程(SOP)
1. 定级:识别任务类型、适用法域、数据分级、是否涉及不可逆动作。
2. 定源:锁定权威法源库与判例库;明确本次任务禁用模型记忆作为法源。
3. 检索:取得法条与判例原文,携带效力层级、生效日期与案号。
4. 生成:产出条款抽取结果、比对差异、审查意见初稿。
5. **引用回源核验(强制环节)**:对每一条法条与案号逐条回源;核验不通过的一律删除,不得标注"待核实"保留。
6. 完整性检查:对照条款清单核对是否遗漏;遗漏项必须显式声明。
7. 人工核验:由具名律师核验并签字,核验记录绑定主体与时间。
8. 用印与提交:由授权人员完成,Agent 不参与。
9. 归档:输入快照、法源版本、模型与提示词版本、核验记录、产物哈希一并留痕。
## 验证与证据要求
- **法条与判例引用核验通过率必须 100%**,未核验条目不得进入输出。
- 判例核验须同时核对:案号是否存在、案由是否匹配、裁判要旨是否与原文一致。
- 条款抽取须输出"已抽取/未发现/不适用"三类结论,不得以静默方式跳过。
- 输出必须显式声明 AI 参与程度(如"本材料由 AI 辅助生成,已由 [姓名] 于 [时间] 核验")。
- 生成过程记录须完整保留,以支持未来可能的"复现生成过程"要求。
## 失败与升级策略
- 检索不到权威法源 → 输出"未取得结论",不得用模型记忆或网络搜索结果替代。
- 引用核验不通过 → **删除该引用及依赖它的全部结论**;累计触发阈值上报法务负责人。
- 法条效力状态存疑 → 停止该部分分析,交人工确认效力。
- 触发电子签章或对外发文调用尝试 → 拦截并告警至法务与 IT 安全负责人。
- 发现材料中存在 AI 伪造痕迹(如带"AI 生成"水印的证据图片)→ 立即标记并升级人工核查,不得作为证据采纳。
## 安全与合规红线
- 严格遵守《人工智能生成合成内容标识办法》(2025-09-01 施行):生成内容须保留显式标识与元数据隐式标识;依法留存相关日志不少于六个月(第 9 条);不得恶意删除、篡改、伪造、隐匿标识(第 10 条)。
- **禁止编造法条、司法解释、判例案号、裁判要旨、标准编号。**
- **禁止以模型记忆提供法条或判例内容**,必须回源核验。
- 禁止自主用印、签署、对外发函、提交诉讼或仲裁文书。
- 禁止在引用核验未通过时保留结论。
- 合同与证据材料中的个人信息按最小必要原则处理,保存期限不短于法定要求。
## 禁止事项
1. 禁止生成或引用任何未经回源核验的法条、案号、裁判要旨。
2. 禁止以"待核实""仅供参考"等措辞保留未核验的引用。
3. 禁止出具最终法律意见或定性结论。
4. 禁止自主用印、签署、对外发函、提交文书。
5. 禁止隐瞒 AI 参与生成的事实。
6. 禁止把 AI 生成内容伪装为人工撰写的专业意见。
7. 禁止删除或弱化生成合成内容标识与审计日志。
8. 禁止删除生成过程记录(提示词、输入素材、模型版本、参数)。
9. 禁止使用可能侵犯他人肖像权、著作权、名誉权的素材作为输入或输出。
10. 禁止把本文件的建议表述为法律规定或执业规范。
## 输出格式
- 结论:明确、可判定;无法得出结论时写明"未取得结论"及原因。
- 依据:表格化,含来源类型、来源标识、**效力层级**、**生效日期**、**案号**、条款或片段位置、**核验状态**。
- 不确定性:列出影响可靠性的事项与建议处置。
- AI 参与声明:显式声明 AI 辅助生成及人工核验情况。
- 留痕:任务标识、法源版本、模型与提示词版本、核验人及时间、产物哈希。
## 评估与自检
- [ ] 所有法条与判例引用已逐条回源核验,核验通过率 100%
- [ ] 未使用模型记忆提供条文或判例内容
- [ ] 条款抽取已输出"已抽取/未发现/不适用"三类结论,无静默跳过
- [ ] 已显式声明 AI 参与程度与人工核验情况
- [ ] 未执行任何 R3 动作;用印与提交由人工完成
- [ ] 生成过程记录已完整保留
- [ ] 生成合成内容标识已保留,日志已写入只追加存储
- [ ] 未编造任何法条、案号、裁判要旨或标准编号 4.2 SKILL.md Specification
Below is the full recommended SKILL.md for the Legal direction. This is a draft recommendation; there is no official industry standard.
---
name: legal-contract-review-draft
description: 合同审查草稿生成。对合同文本做条款抽取、范本差异比对与风险标注,输出待律师核验的审查意见草稿。所有法条与判例引用强制回源核验。适用于采购合同、服务合同、保密协议等常规合同的初审场景。
version: 1.0
created: 2026-09-12
---
# 合同审查草稿生成
## 适用场景
- 适用:常规合同的初审、条款完整性核查、与内部范本的差异比对、风险条款标注、修改建议起草。
- 不适用:重大合同的最终意见出具、谈判决策、自主用印或签署、涉外合同的法律适用终判。
## 前置条件
- 已获取待审合同文本(最终版或指定版本)与适用范本。
- 权威法源库可用,可返回效力层级与生效日期。
- 内部条款库与让步边界清单可用。
- 审查意见草稿区可写入(R1),且核验律师已指定。
## 输入
| 输入项 | 必填 | 说明 |
|---|---|---|
| 合同文本与版本号 | 是 | 明确是哪个版本,避免审查错版本 |
| 合同类型 | 是 | 采购/服务/保密/其他,决定条款清单 |
| 适用法域 | 是 | 涉及时须明确,影响法条检索范围 |
| 我方立场 | 是 | 甲方/乙方,决定风险倾向判断 |
| 内部范本与让步边界 | 是 | 差异比对的基准 |
| 数据分级 | 是 | 涉密合同按 R2 受控处理 |
## 输出
| 输出项 | 说明 |
|---|---|
| 条款抽取表 | 条款类型、所在位置、核心内容摘要、状态(已抽取/未发现/不适用) |
| 差异比对表 | 与范本的差异项、差异性质(有利/不利/中性)、建议处置 |
| 风险标注清单 | 风险点、风险等级、法条或制度依据(已核验)、修改建议 |
| 遗漏声明 | 明确列出未能审查的部分及原因 |
| 留痕信息 | 合同版本、法源版本、模型与提示词版本、核验人及时间 |
## 执行步骤
1. 核对合同版本与类型,确认审查基准(范本 + 让步边界 + 我方立场)。
2. 按条款清单逐项抽取:主体、标的、价款与支付、履行期限、验收、违约、责任限制、保密、知识产权、争议解决、管辖、不可抗力、变更与解除。
3. 与范本逐项比对,标注差异性质与建议处置。
4. 对不利差异检索法条与制度依据,**逐条回源核验**;核验不通过的引用直接删除。
5. 生成风险标注清单与修改建议草稿。
6. 自校验:条款状态三类结论齐全;引用核验通过率 100%;差异项无遗漏静默。
7. 输出草稿并转具名律师核验。
8. 归档留痕,核验结论回流为评估样本。
## 质量标准(DoD)
- 一票否决:存在未回源核验的法条引用;使用了模型记忆提供条文;自主写入 CLM 正式字段或用印;审查了错误版本却未发现。
- 条款抽取完整性:条款清单覆盖率 100%,每项均有明确状态(不得为空白)。
- 引用核验通过率 100%,核验状态不得出现"未核验"。
- 差异项 100% 标注性质与建议处置。
- 未能审查的部分必须显式声明,不得静默跳过。
## 常见失败与处理
| 失败模式 | 表现 | 处置 |
|---|---|---|
| 法条幻觉 | 生成不存在的法条编号或条文内容 | 强制回源核验;核验不通过即删除该条及依赖结论 |
| 案号错配 | 案号真实但案情描述与裁判文书不符 | 逐条比对裁判要旨原文;不符即删除 |
| 版本错审 | 审查了过期版本 | 版本号前置校验;与 CLM 中最新版本比对 |
| 静默遗漏 | 条款清单中某项未抽取也未声明 | 强制输出三态结论;空白项阻断交付 |
| 立场错判 | 未考虑我方立场,给出中性但无用的意见 | 立场为必填输入;差异性质按立场重新标注 |
| 效力过时 | 引用已废止条款 | 强制携带生效日期;废止条款禁止加载 |
## 示例
输入:
- 合同文本:《XX 服务合同》v3.2
- 合同类型:服务合同;适用法域:中国内地;我方立场:甲方(采购方)
- 内部范本:服务合同范本 v2.0;让步边界清单:责任限制上限不超过合同总额
输出(节选):
| 条款类型 | 位置 | 核心内容 | 状态 |
|---|---|---|---|
| 责任限制 | 第 9.2 条 | 乙方责任上限为合同总额的 50% | 已抽取 |
| 知识产权 | — | — | 未发现(建议补充) |
| 不可抗力 | 第 12 条 | 约定不可抗力范围与通知期限 | 已抽取 |
| 差异项 | 与范本差异 | 性质 | 建议处置 |
|---|---|---|---|
| 责任限制 | 范本为 100%,本合同为 50% | 不利 | 建议谈判恢复至不低于 100%,或在价款中作对价调整 |
| 风险点 | 风险等级 | 依据(已核验) | 修改建议 |
|---|---|---|---|
| 责任上限过低 | 中 | [法条以法源库检索结果为准,核验状态:已核验] | 建议调整上限并明确除外情形 |
> 说明:上表中条款位置与比例为示例格式,实际必须以合同原文与法源库返回结果填充,不得沿用示例值。 4.3 Rollout Checklist
| No. | Check Item | Check Method | Pass Criteria |
|---|---|---|---|
| 1 | Cutoff of model memory | System-configuration check | 100% of statutes and precedents come from authoritative-database retrieval |
| 2 | Citation-verification pass rate | Full inspection of output | 100%, with no "unverified" items |
| 3 | Case number and case-facts consistency | Sample check of 50 precedents | 100% agreement on case number, cause of action, and holding |
| 4 | Effectiveness level and effective date | Sample check of citations | 100% carried |
| 5 | Three-state clause conclusions | Sample check of review opinions | Extracted / not found / not applicable 100% complete |
| 6 | Sealing authority | Permission check | All electronic-sealing interfaces closed to Agents |
| 7 | Authority to issue legal opinions | Process check | 100% issued and signed by a named attorney |
| 8 | AI-participation disclosure | Sample check of output | 100% explicitly discloses AI involvement and human verification |
| 9 | Retention of generation-process records | Log check | Prompts, input materials, model version, and parameters 100% retained |
| 10 | Generated-content labeling | Sample check of outputs | Explicit labels and metadata implicit labels 100% retained |
| 11 | Portrait and copyright compliance | Material-source check | Input and output materials 100% legally authorized or lawfully used |
| 12 | Data-classification execution | Data-flow check | Confidential contracts do not leave the domain |
| 13 | Tamper-proof logs | Permission and storage check | Business accounts have append-only permission |
| 14 | Forgery-trace detection | Evidence-material inspection process | 100% of AI-forgery traces are flagged and escalated to humans |
| 15 | Accountability to a person | Verification-record check | Every outward-facing document can be traced to a named verifier |
5. Summary
The AI Harness for the Legal direction is essentially a system that engineers "citation authenticity" into a mandatory, enforceable mechanism.
Three conclusions:
First, the one non-negotiable indicator for the Legal direction is the citation-verification pass rate, and it must be 100%. Other directions may tolerate 99%, but the Legal direction cannot. The reason is simple: missing a non-core clause in contract review causes limited loss, but placing a single fabricated case number in a representation opinion costs professional liability and harms the order of the judicial system. The California Court of Appeal has already explicitly required that "all legal citations be verified line by line by attorneys against the originals," and Chinese courts have, through database-included cases, established the rule that "submitting false cases that are not screened or verified carries responsibility" — these two rules from different jurisdictions point to the same engineering requirement.
Second, "AI involvement" should be proactively disclosed, not concealed. In the U.S. Fifth Circuit case, "deliberately concealing AI use" was an aggravating circumstance for discipline. Although Chinese courts have not separately aggravated concealment, the Tongzhou court explicitly wrote into its judgment that "artificial-intelligence models must not be allowed to generate or fabricate false information that disrupts judicial order." Harness should firmly attach an AI-participation disclosure and human-verification information to its output.
Third, retaining generation-process records is both a compliance requirement and a form of self-protection. In the AI face-swapping case, the defendant bore the adverse consequence of failure of proof because it "could not reproduce the AI generation process it claimed." This adjudicative logic can be fully transferred to the legal scenario: when an AI-assisted material sparks a dispute, whether the generation process can be reproduced (what materials, what prompts, what model version were used) will directly affect the determination of liability. Therefore retaining prompts, input materials, model versions, and parameters is not optional.
A limitation that must be faced squarely: many of the foreign cases cited in this direction come from media retellings, and the specific penalties and procedures are subject to the formal documents of the courts in each jurisdiction; the progress status of some Chinese cases (e.g., whether an appeal was filed or retrial entered) could not be verified one by one, and citations should note "subject to the final determination by the competent authority." In addition, the copyrightability of AI-generated output has not yet been fully unified in judicial practice, and the adjudicative development after these cases is still evolving.
Information-Gap Disclosure
The following data could not be corroborated by a reliable secondary source during the writing of this direction and has been marked for processing per the specification, to be supplemented:
- The full original text of the judgment in the Tencent Dreamwriter case: the content cited here comes from media retellings by Legal Daily's website (fazhiwang), 36 Kr, and others; the full text of the judgment was not obtained, and it is marked
[To be verified]. - The specific case number and judgment date of the Beijing Internet Court AI face-swapping case: the report did not disclose the full case number; it is only known that the case was concluded by the Beijing Internet Court and the judgment has taken effect, and it is marked
[To be filled]. - The trial court and case number of the Wu v. a technology company AI face-swap APP case: The Paper's report did not fully disclose them; it is only known that it is a related Fuzhou Intermediate People's Court case, and it is marked
[To be verified]. - The adjudicative difference between the Tencent Dreamwriter case and the Beijing Internet Court computer-software-generated-output case: some views hold that the two cases differ in their findings, but a complete comparative analysis of the two cases was not obtained, and this direction's conclusion is marked "not yet fully unified in practice."
- The official judgment-document numbers of the various foreign cases (Mata case, California cases, Mississippi case, etc.): all are media retellings, and the original document numbers were not obtained; they are marked
[To be verified]. - The case number and progress of the Xiaogan Dawu County Court, Hubei case: it is only found in reports by CCTV's "Rule of Law Online" (Fazhi Zaixian), which did not disclose the case number; it is marked
[To be filled].
6. References
- AI 判例造假有恃无恐,全球携手严打 — 法治日报,2026。http://www.lawnewscn.cn/wap/content/2026-08/26/content_9446481.html
- 法治在线 | 律师用 AI 生成虚假案例被法院发现 将承担何种责任 — 央广网,2026。https://news.cnr.cn/native/gd/20260115/t20260115_527494281.shtml
- 警惕 AI 生成虚假案例干扰司法审理 — 人民网,2026。https://yn.people.com.cn/BIG5/n2/2026/0121/c361322-41478254.html
- 媒体关注 | 律师提交 AI 生成虚假案例被当庭训诫 — 宜昌长安网,2026。http://zfw.yichang.gov.cn/content-64133-965206-1.html
- AI 作品著作权归谁?法院审判多起"首案"厘清侵权边界 — 法治网,2026。https://www.legaldaily.com.cn/index/content/2026-06/03/content_9400177.html
- 你用 AI 写的文章,著作权到底归谁?— 天达共和律师事务所,2026。http://www.east-concord.com/zygd/Article/20266/ArticleContent_4652.html
- 技术不是侵权"挡箭牌" 法院这样认定 AI"盗脸" — 经济参考网,2026。https://www.jjckb.cn/20260418/957b6bc4d3a34c27b9954fe4d240ae97/c.html
- 《家事法庭》联动普法:你的声音肖像,AI 说了不算!— 澎湃新闻。https://m.thepaper.cn/newsDetail_forward_32953019
- 人工智能写作领域第一案在深圳法院落槌首次确认 — 法制日报 / 36 氪。https://36kr.com/coop/uc/5283237.html
- 关于印发《人工智能生成合成内容标识办法》的通知(国信办通字〔2025〕2 号)— 国家互联网信息办公室等四部门,2025。https://www.cac.gov.cn/2025-03/14/c_1743654684782215.htm
- 中央网信办部署开展"清朗·整治 AI 技术滥用"专项行动 — 中央网络安全和信息化委员会办公室,2025。https://www.cac.gov.cn/2025-04/30/c_1747719097461951.htm
- Secure Software Development Practices for Generative AI and Dual-Use Foundation Models(NIST SP 800-218A)— NIST CSRC,2024。https://csrc.nist.gov/pubs/sp/800/218/a/final