Editorial standards

What gets rejected.

Every submission is read by a person before it publishes. These are the grounds for turning one down, published so you can hold the index to them. The last one is new, and every seeded spec was rewritten to meet it.

01

Acts without approval

Any spec where an agent sends, files, publishes, or contacts a client on its own. Drafting is a tool. Acting on your behalf is unsupervised nonlawyer assistance, and no directory entry gets to hand you that.

02

Writes reviews

Anything that generates, edits, or suggests review text, or that offers something of value for a review. Asking a satisfied client at the right moment is fine. Writing their words for them is not.

03

Contacts represented parties

Outreach specs must check for existing representation, prior declines, and do-not-contact status before drafting anything. A spec that skips the check for speed gets rejected.

04

Makes the legal call

No spec may determine privilege, responsiveness, causation, valuation, or whether a claim is time-barred. Specs locate, assemble, cite, and flag. An attorney decides.

05

Hides its exposure

If a spec touches privileged material, protected health information, trust funds, or bar advertising rules, it says so on its face. Specs that quietly route confidential material to a third party get rejected.

06

Invents evidence

Anything that fills a gap with a plausible-sounding fact rather than reporting the gap. Unsourceable figures go to an open-items list, never into a total, a chronology, or a demand.

07

Cannot be tested

Every spec has to describe a supervised first run against something you already know the answer to. A spec you cannot check before trusting is not a spec, it is a hope.

08

Is really a sales page

Specs naming a single vendor as the only way to run them, or written to funnel firms into a product. Naming a system as an example is fine. Requiring one is an ad.

09

Trusts what it reads

Any spec that takes in documents, pages, messages, or record fields without saying how it separates that material from instruction. A model cannot tell the difference on its own — to it, both are just text. The three requirements are set out below.

Untrusted input

Requirement 09

A bot that reads documents does not only read yours. It reads what opposing counsel produced, what a vendor sent over, what a claimant typed into a form, and what somebody wrote into a case note two years ago.

To a model, none of that is distinguishable from an instruction you gave it. There is no technical marker separating content from command — both arrive as text, in the same stream, and the only thing telling them apart is a judgment the bot has to be built to make. Every spec in this index is written against that, and every submission is judged on three questions.

Q1

Is the hidden layer stripped before the model reads it?

Text hidden by styling, text colored to match its background, zero-width characters, and PDF text layers with no visible glyph are all invisible in a print-out and perfectly legible to a model. This part is deterministic — ordinary code catches it exactly, every time, at no cost. Using a model to find hidden instructions means feeding the instructions to a model in order to ask about them, which is the wrong shape for the job.

Q2

Is what was stripped logged, or quietly discarded?

The log is the evidence. A spec that cleans its input and says nothing has protected this one run and taught you nothing — you cannot raise what you never saw, and you certainly cannot show a pattern. Stripped content goes somewhere a person will read it.

Q3

Does the ethics gate screen the output, or the request?

This is the one most tools have backwards. A gate on the way in asks whether a person is allowed to ask, and a determined claimant gets around it by rephrasing three times. A gate on the way out asks whether the bot is allowed to say — which catches both the persistent claimant and the poisoned document, because it does not care where the pressure came from.

What this standard is not

There is no published case of an instruction planted in a discovery production to steer opposing counsel's AI, and nothing here should be read as a claim that it is happening. The requirement exists because the attack costs nothing, leaves no visible trace, and every component of it already exists in ordinary document formats — and because “we had not considered it” is a poor position to take in front of a bar committee.

On the specs published here

These rules apply to the seeded entries too. If you find one that breaks them, that is a defect, not an exception — say so and it gets fixed or pulled.

Think yours clears the bar?

Publish it with your name and your firm's link on it.

Add a bot