AI in Legal Work: What to Record and What a Hash Can Prove

When AI Assisted Legal Work Is Challenged What a Verifiable Record Can and Cannot Show

If AI-assisted legal work is challenged, the useful question is not simply whether AI was used. It is what the tool did, what information it received, what a lawyer checked, and which exact file was approved.

A hash and timestamp can help identify that file and show when its cryptographic fingerprint was recorded. They cannot prove that the work was correct. That limit is what makes proof stamping useful rather than promotional.

Lawyers now use generative AI to summarize documents, organize issues, test arguments, and draft early versions. Courts are not treating every use as misconduct. They are applying a familiar rule: counsel remains responsible for the final work.

The Ontario Superior Court of Justice requires careful, informed, and ongoing oversight when AI is used in court proceedings. AI-assisted legal information must be checked against trusted, authoritative sources. The American Bar Association’s Formal Opinion 512 takes the same practical approach under the ABA Model Rules. Lawyers must understand the tool, protect client information, review the output, and remain responsible for the result.

We already know what failure looks like. In Mata v. Avianca, lawyers filed fake cases and quotations generated by ChatGPT and were sanctioned. In Ontario, Ko v. Li involved false or misleading authorities in a factum and a show-cause process concerning possible contempt.

The lesson is simple. Fluent output is not verified work.

Neither court guidance nor professional rules create a universal duty to disclose every use of AI or build an AI audit trail. Duties vary by court, client, matter, and use. An internal review record does not replace those rules. It helps a firm preserve the facts about its own process.

Four things worth recording

1. The task

“Used AI” says almost nothing. Record the approved purpose instead. For example: “Used an approved tool to create a first-pass chronology from a redacted document set.” Add the tool, model, and date when they matter.

2. The information provided

Note whether the input was public, anonymized, redacted, or confidential. Record any consent, contract, or security control that applied. Do not place client names, prompts, facts, or privileged analysis in a public timestamp record.

Private data. Public proof.

Even a hash can leak information when the original content is short or predictable. Someone can guess likely inputs and compare the resulting hashes. Sensitive workflows may need a private manifest, a random value kept off the public record, batching, or another commitment design reviewed by a security specialist.

3. The human review

Record what the lawyer actually checked. Authorities should be opened in CanLII, a court website, or another accepted source. Quotations and pinpoint references should match. Holdings need context. Factual claims must connect to the record. A responsible lawyer must approve the final work.

A completed checklist is still only an assertion. A named reviewer and a reliable digital signature can support attribution. They do not prove that the review was competent.

4. The exact approved file

Legal documents change fast. A reviewed passage can be altered or reintroduced during a late edit. The record should identify the exact file submitted or relied upon, not just the matter name or document title.

A SHA-256 hash is a fingerprint of a file’s bytes. Change the bytes and the hash changes. This proves byte-for-byte identity, not visual or semantic equivalence. Simply opening and saving a DOCX may alter internal metadata and produce a new hash even when the visible text looks the same. Hash the exact submitted file. If the firm also keeps a reference PDF, identify and hash it separately.

What a hash and timestamp can prove

A credible record has five layers. Each answers a different question.

LayerQuestionTypical support
IntegrityDoes this file match the recorded bytes?Cryptographic hash
Time and orderWhen was a matching fingerprint recorded?Trusted timestamp or public ledger
AttributionWho made or approved the record?Authenticated identity and digital signature
ReviewWhat did the lawyer check?Internal review record and sign-off
Legal useCan the evidence be admitted, and what weight will it receive?Applicable law, procedure, and supporting testimony

A proof stamp mainly supports the first two layers. It can show that a hash was recorded in a particular timestamp system and that a file presented later matches that hash. It cannot show that the file is true, complete, lawful, or professionally adequate. It does not identify the author or reviewer without separate identity evidence. It does not create privilege, a complete chain of custody, or automatic admissibility.

Time claims also need care. A public ledger records when a hash entered that ledger’s history. A trusted timestamp service signs its own time assertion. Neither method proves when the document was first created, who controlled it before stamping, or whether the person submitting the hash had reviewed the file. A matching timestamp is one fact in a larger timeline.

The defensible claim: A cryptographic fingerprint matching this file was recorded in this independently checkable time record. The file presented now matches that fingerprint.

Identity, signing, custody, and workflow records can strengthen the wider argument. The stamp alone cannot finish it.

A practical five-step workflow

  1. Check the rules. Review court directions, professional duties, client instructions, protective orders, security requirements, and firm policy before using the tool.
  2. Keep a deliberate internal record. Record the task, data classification, reviewer, sources checked, material corrections, and exact approved file. Do not log everything. The record may become discoverable or subject to a litigation hold, so define access, privilege treatment, retention, and deletion in advance.
  3. Verify the substance. Open the sources. Check citations, quotations, facts, and legal propositions. No cryptographic tool can repair weak legal review.
  4. Approve and stamp the right file. Have the responsible lawyer approve the final version. Hash locally when possible. Stamp meaningful milestones, such as the approved filing and any material correction.
  5. Keep a portable proof package. Retain the file, review record, signature, timestamp receipt, verification instructions, and relevant logs under the firm’s policy. A vendor webpage is convenient, but it should not be the only way to verify the proof.

Fewer records can be better. A consistent, limited process is easier to explain than a flood of screenshots, prompts, and timestamps with no clear purpose.

The milestones should match the firm’s reason for keeping the record. A pre-filing stamp can identify the approved submission. A later stamp can identify a corrected version. Stamping every draft adds cost and metadata but may not answer any useful question. If a matter is highly sensitive, even the timing and frequency of public records can reveal activity. Batching may reduce that exposure.

How this fits into evidence law

For Ontario proceedings, section 34.1 of the Ontario Evidence Act addresses electronic records and the integrity of the system in which data was recorded or stored. A hash, timestamp, and documented process may help. They do not make every stamped file admissible.

Federal proceedings have their own framework under the Canada Evidence Act. In U.S. federal practice, Federal Rule of Evidence 902(14) recognizes digital identification processes, including hash matching, as a route to authenticate copied data through certification.

None of these rules says that a blockchain timestamp automatically authenticates a document. The useful evidence is the whole package: the file, the proof record, the verification method, the people responsible, and the process around it.

Authentication is only one issue. A court may still consider relevance, hearsay, privilege, chain of custody, notice, and the reliability of the surrounding process. Even admitted evidence can receive little weight if nobody can explain how the hash was created, which file it represented, or how the original was preserved. Technology helps most when the business process is clear enough for another person to reproduce.

ProofStamp’s narrow role

ProofStamp focuses on a limited but useful problem. It helps connect an exact file to a time record that others can check without receiving the private file in advance.

For legal work, a practical proof package should include the file hash, the timestamp receipt, the algorithm and policy details, and open verification instructions. It should remain usable even if ProofStamp.org is unavailable. Identity, review policy, retention, and legal strategy stay with the firm and its advisers.

This is not proof that AI output was correct. It is evidence that a matching fingerprint was recorded at a certain point and that the file has not changed since that version was stamped.

That is a narrow claim. It is also one a third party can test.

Disclaimer. This article is for general educational purposes only. It is not legal, evidentiary, cybersecurity, records-management, or professional-conduct advice. Requirements differ by jurisdiction, court, client, matter, and tool.

Sources and further reading

  1. Ontario Superior Court of Justice, Consolidated Civil Provincial Practice Direction
  2. American Bar Association, Formal Opinion 512
  3. Mata v. Avianca, Inc.
  4. Ko v. Li, 2025 ONSC 2766
  5. Ontario Evidence Act, section 34.1
  6. Canada Evidence Act, electronic documents
  7. Federal Rule of Evidence 902
  8. NIST Secure Hash Standard