All insights Method · AI governance

Standards as Code: The Gate Behind the Signature

A sign-off practice accumulates liability with every signature. Here is the runtime governance kernel that makes the firm’s standards non-bypassable — three gates, deny-by-default, and an audit trail that writes its own defence.

Răzvan Alexandru Olaru25 June 20266 min read

A signature outlives the matter it closes. In a practice built on sign-off, every attestation is a promise that lives for years — so the real question is not whether we hold standards, but whether the system could ever issue a signature that breaks one. Our answer is to write the standards as code and let a single gate enforce them.

Most accounts of legal AI stop at a comforting sentence: “a human reviews it.” True, and not enough. A human can be tired, rushed, or quietly talked round; a checklist taped to the wall can be skipped on a busy Friday. A control you merely hope is followed is not a control. The honest version is one the system itself enforces — a small, dull piece of software that sits between the work and any consequential act, and refuses to let that act through until the standards behind it are met.

Borrowing a term from software engineering, this is a runtime governance kernel: governance applied at the moment of action, not as advice the model is trusted to remember. The kernel does no legal thinking of its own. Its only job is to check that what should have happened, did — before a door opens.

Three gates, one that cannot be forced

Work passes through three checkpoints. At intake, the matter cannot be accepted until the conflict check is clear and, where Law 129/2019 bites, customer due diligence is done. At the AI first-pass, the model may touch only the material this matter permits, personal data is stripped before any third-party call, and the no-retention term is asserted — the machine never reaches the act of signing. And at issue, the decisive gate, the e-signature is simply unreachable unless every standard is green: a human sign-off on the file, a stated scope and reliance limit, a liability cap valid for this kind of client, the comparative-analysis disclaimer on any English-law content, professional-indemnity cover confirmed, the rubric version pinned, and the exact document fixed by its fingerprint.

RUNTIME GOVERNANCE KERNEL01Intakeconflicts · KYC / AML02AI first-passscope · PII redacted · no-retention03Issue · the signaturesign-off · scope · cap · disclaimerrubric · document hashEACH GATE OPENS ONLY ON ALLOW · ABSENCE OF EVIDENCE DENIES
Three gates, one that cannot be forced: the signature stays shut until every standard behind it is green.

Silence is a “no”

The kernel runs on one stubborn rule: deny by default. It is not looking for a reason to refuse; it is looking for proof that it may proceed, and the absence of that proof is itself a refusal. Feed it the matter’s yes/no facts and it returns one of three verdicts. Allow means every standard is met. Escalate means a judgment a machine should not make alone — a liability cap asserted against a consumer, say, which the law may not let us rely on — and routes it to a person. Deny means a standard is breached, or, just as importantly, that the action is one no rule yet covers. The worst verdict always wins.

Matter contextthe yes / no factskernelevaluate()ALLOWevery standard metESCALATEa human confirmsDENYany breach · or no rule yetWORST VERDICT WINS · NO MATCHING RULE IS ITSELF A DENIAL
Silence is a 'no': any breach — or any act no rule yet covers — denies; only a clean pass allows.

Standards as code, not as a poster

The elegant part is what each rule is made of. Every policy in the kernel names the instrument it enforces — a clause of the engagement letter, a duty under the Statut, an AML trigger. Change what the firm promises in the letter, and you change the matching rule and stamp a new version on it. The code and the legal instrument stop being shadows of one another and become the same standard, written twice. That is less exotic than it sounds: a professional-conduct code is already a system of must, may and must-not — a deontic logic. The kernel only makes that logic executable.

Why a sign-off practice especially needs it

Liability here accumulates in one direction: it only ever grows, one signature at a time. Years later, a claim will not turn on whether the lawyer was clever on the day; it will turn on whether a sound, repeatable process was followed. A kernel that refuses to issue without a pinned rubric, and that logs every decision as it goes — what was checked, which version of the rules applied, never the client’s document itself — converts “did he miss something?” into “did the process run, and pass?”. The audit trail is not bureaucracy. It is the defence, written automatically.

None of this displaces judgment; it protects the place where judgment lives. The kernel enforces only what we have thought to encode, so its one real weakness is a gap in coverage — which is why a new kind of document is never offered before its gate is written. The machine reads at scale, the gate holds the line, and the signature at the end remains exactly what it always was: a human being, accountable and insured, putting their name to a judgment.

The move

Before a new document type is offered to clients, its gate is written first — the standard becomes code before it becomes a product. And the one button that can issue a signature is wired so it cannot fire on a red: enforcement you can prove, not merely promise.

General information about our method, not legal advice, and no lawyer–client relationship is created by reading it. Romanian and EU law is handled by a practising avocat; any English-law reference is comparative analysis by a solicitor (non-practising).

Building an AI workflow that ends in a signature? Write the gate before you ship the product.

Free brochure

Standards as code: the governance gate

A one-page brief on this topic, sent straight to your inbox.

Facing this on a live document?

Book a 30-minute clinic

A quick read on your exact seam — by a lawyer qualified on both sides of it. No charge for the first look.

Your details go to Răzvan Alexandru Olaru (raz@olawru.com) and are held under a lawyer’s professional secrecy (Legea nr. 51/1995 & the Statutul profesiei de avocat) and the corresponding SRA confidentiality rules, processed in line with the GDPR. See our Privacy Policy and GDPR Statement.