What the source can and cannot show
OpenAI reports the customer’s process and results. That makes the page primary evidence for what OpenAI published and secondary evidence for the firm’s outcomes. No independent error rate, legal-outcome measure or return calculation appears in the reviewed record.
The control-before-expansion sequence
| Stage | Reported control | Transfer question |
|---|---|---|
| 1. Scope | Approved tasks and input guidance | Which tasks and data classes are permitted? |
| 2. Contract | Contractual and data-processing review | Which product and agreement govern? |
| 3. Access | Role-based access and residency controls | Who can reach which surface and region? |
| 4. Review | Human review and professional judgment | Who owns corrections and final approval? |
| 5. Expansion | Role-specific enablement and selected workflows | Which evidence allows the next cohort? |
Treat workflow examples as reported, not certified
The story describes operational work and selected conflict, AML, PEP and KYC processing with human review and sign-off. It does not establish completeness, legal sufficiency or error rates for those processes. Another firm should keep existing systems of record and acceptance criteria during any evaluation.
What a second firm must adapt
- its jurisdiction, professional duties and client terms;
- its identity, conflict, AML and records systems;
- the exact ChatGPT, Codex or API surface and data path;
- its risk classification and incident process;
- the named person responsible for every final decision.
Measure the rollout in cohorts
Start with one role and one task family. Preserve baseline time, correction count and escalation rate. Expand only after the guardrails pass. A broader seat count is an adoption measure, not proof of quality or business value.
FAQ
Does the Gilbert + Tobin story prove OpenAI is compliant for law firms?
No. It is a vendor-authored customer story. Compliance and professional duties depend on the firm’s jurisdiction, workflow, configuration and agreements.
What is the most reusable lesson?
The sequence is reusable: scope tasks and data, review contracts, restrict access, preserve human sign-off, and expand by evidence.
Does the case prove KYC or conflict-check accuracy?
No independent error rate or completeness measure was identified in the reviewed source.
Sources checked
- How Gilbert + Tobin governs and scales AI, checked 2026-09-03.
- Data controls in the OpenAI platform, checked 2026-09-03.
- OpenAI Services Agreement, checked 2026-09-03.
Operational information, not legal advice. Verify current terms, account configuration and applicable professional duties before use.