Generative AI is rapidly moving beyond individual productivity tools. For corporate legal departments, the more consequential question is how far legal knowledge and workflows can be embedded directly in business processes – without compromising confidentiality, accountability, or control.
GoingDigital spoke with Ruben Miessen, Founder and CEO of LEGALFLY, about the experience that led him from consumer technology to legal AI, the shift from copilots to increasingly automated workflows, and why successful AI adoption is ultimately as much a question of governance as it is of technology.
GoingDigital: Before founding LEGALFLY, you worked on AI initiatives at Tinder and Match Group. What did you observe there about the way in-house legal teams worked that ultimately convinced you there was a problem worth solving – and what lessons from consumer technology have proved particularly relevant to legal AI?
Ruben Miessen: Our whole founding team worked together at Tinder and Match Group. I hired most of them myself, almost five years ago now. Tinder moves incredibly fast. New features, new markets, constant experimentation, and if something works, you scale it immediately. The product and engineering teams operate at real software speed. But whenever we needed legal input, things could suddenly take days or weeks. That wasn’t because Legal was doing anything wrong, but simply how legal work gets done. It didn’t scale the way the rest of the organization did, and we’ve since seen the same thing at plenty of other companies.
One moment really stuck with me. I’d put forward eight product proposals in a row, and all eight were rejected, not because the ideas were bad, but because each one was judged too big a legal bet, with too much legal uncertainty attached. The safe answer from the legal committee was always to do something easier instead. Legal uncertainty was effectively setting product strategy, even though we had the technology and the teams to build what we’d proposed. That’s the moment I started asking: Why is Legal the one part of the company that doesn’t scale with technology? That question became the starting point for LEGALFLY.
The lesson from consumer tech is really about treating a workflow as a product, not a department: Build for the specific, high-volume, repeatable case, put fast, structured human review around anything the system produces, and let good underlying data – case law and contracts, in Legal’s case, rather than a generic model – do the work.
GoingDigital: The legal-tech debate has moved rapidly from individual AI tools and copilots toward agents and increasingly automated workflows. How far do you expect this development to go? Could the role of an in-house legal team increasingly shift from performing legal work itself to designing, supervising, and governing the systems that perform it?
Ruben Miessen: It goes a long way, and I don’t think this is unique to any one industry; it’s structural. Legal expertise sits in a small team, but legal questions come up in every part of the business, every day: A sales rep needs a clause approved before a deal closes, HR needs a compliance answer before making an offer. If Legal can’t respond fast enough, people find another way. And increasingly, they do so by asking a general-purpose tool like ChatGPT and treating the answer as fact, which is its own risk.
Making individual lawyers faster with AI is valuable, but it doesn’t fix that on its own: Even if review time drops by a third or half, everything still funnels through the same small team. The bigger shift is capturing the legal team’s own knowledge and policies and making these available directly to the business for the repeatable, lower-risk work, while lawyers stay involved for the complex, high-risk decisions.
We think about it in three buckets: Routine, repeatable tasks that can be fully self-served, known exceptions, run as a workflow with a specific human approval step built in, and genuinely novel, high-risk matters, which we don’t automate at all. We just make sure the lawyer has the right tools to run them manually.
Crucially, it’s never the AI that decides where those lines sit. Every organization has a different risk appetite, and that’s a decision the legal team makes once, for itself, then applies consistently through the technology.
So, yes. The in-house team’s role shifts from answering every question itself to deciding where those lines are, building the guardrails around them, and supervising what happens inside them. That’s a governance job, not a drafting job.
GoingDigital: For legal departments in regulated industries, efficiency is only one part of the equation. Confidentiality, data protection, reliability, and auditability are equally important. What, in your view, are the prerequisites for using generative AI responsibly in legal work – and where should human review remain non-negotiable?
Ruben Miessen: Efficiency is the easy sell. The harder, and more important, conversation is what has to be true before you let generative AI near a contract, a regulatory filing, or client data. We surveyed 154 general counsel across the UK, France, and Germany earlier last year for our AI Governance Gap report, and found that 90% of these companies are already using AI in some form, but only 18% have a fully implemented governance framework, and close to a quarter of leaders admit they don’t really know which AI tools their own people are using day to day. That gap is the real risk, not the technology itself.
For me, the prerequisites are that sensitive data gets anonymized before it ever reaches a language model, and customer data is never used to train anyone’s model. Every output has to be traceable back to a source, such as a piece of legislation or a clause in the original contract, not just a plausible-sounding answer. And for the most sensitive work, the deployment model itself has to be a genuine choice, not one given by default. Single-tenant or on-premises, not only SaaS.
Data sovereignty is a good example of why that matters. For a lot of our German clients specifically, hosting outside a US hyperscaler’s default region has become a real requirement, not a nice-to-have, so we deploy single-tenant instances in the client’s preferred region, including the EU, to meet that. Just as important is who decides what gets automated in the first place – never the AI itself, always the legal team, based on its own organization’s preference.
Where human review stays non-negotiable. With one insurance client, straightforward claims get a full AI assessment end to end, and the team simply checks and approves the output; anything more complex is escalated to a person to review or run manually. That’s the model – AI can prepare a decision and show its reasoning, but for anything that creates a binding obligation or represents the company externally, a person makes the final call.
GoingDigital: Many companies have experimented with generative AI, but moving from an impressive pilot to widespread adoption is a different challenge. What distinguishes a successful legal AI implementation from a project that remains stuck in the pilot phase? And which metrics should general counsel (GC) use to determine whether AI is actually creating value?
Ruben Miessen: The projects that stall are usually the ones that never had a clear use case to begin with. Teams adopt AI for its own sake rather than picking a specific problem to solve. My advice is always the same. Scope one or two use cases where the value is real – time saved, external counsel spend reduced, risk lowered – and where the work happens often enough that you feel the benefit every time. Appoint one person accountable for making that use case succeed across the organization. And be skeptical when choosing a vendor: Don’t trust the sales deck or the marketing site. Push for a trial, bring your own documents and your own use case, and genuinely try to break the product before you commit to it.
The metrics I’d tell a GC to use: Turnaround time per matter type against a documented baseline, throughput per person – one insurance claims team we work with went from roughly 150 claims handled per person per month to around 700 – how much work no longer needs to go to outside counsel, and, just as importantly, whether the team is actually using it every day rather than only in a pilot cohort. Adoption is itself a metric.
We’ve just passed 200 active customers across 33 countries, and the pattern holds across almost all of them. The ones getting real value picked a narrow, high-volume starting point and made someone own it.
GoingDigital: Looking three to five years ahead, how do you expect AI to change the division of labor between in-house legal teams, business functions, and external law firms? And are there any particular characteristics of the German legal market that will shape this transformation?
Ruben Miessen: Three to five years out, I’d expect the routine, high-volume work, such as contract review, first-line compliance monitoring, claims handling, and standard advice, to have moved almost entirely in-house, and in many cases out of the legal department itself and into the business functions that generate it, with Legal setting the rules rather than doing the work.
That’s already the shape of our own customer base. Around 95% are corporates rather than law firms, and 60% are enterprises, because that’s where this structural need is strongest. Legal decides what knowledge and workflows the rest of the business can use safely, and teams like Sales, HR, and Claims self-serve the majority of their own legal work under those rules, through products like our Collaborator Access.
External counsel doesn’t disappear, but the relationship narrows to what’s genuinely novel: Litigation, cross-border and regulatory matters that need an outside opinion, the things a playbook can’t yet cover. Law firms that don’t produce around that shift and continue to sell hours will struggle, and I’d expect real consolidation on both the law-firm and the legal-tech vendor side.
Germany will shape this in a specific way. It’s a market with a genuinely rigorous data-protection culture, stricter in practice than much of the rest of Europe, and large, engineering-minded corporates, including some we work with here, that won’t adopt anything that can’t be anonymized, audited, and, where needed, run on-premises. That makes for a slower buying cycle than somewhere like the UK, but a more durable one. German legal departments tend to demand exactly the governance maturity our own research found most companies still lack.
GoingDigital: Ruben, thank you very much for the interview and for sharing your insights with us.
