The O'Mono input bar reading 'Type the idea the way it comes,' with a Write button, Text and Image attachment controls, a prompt count on the ledger, and Restore, History and Settings controls

An associate types a sentence about a training session she must run on Thursday, and seconds later reads why the system decided her prompt needed a Role, why it drafted an example but refused to include it, and what rule she could carry into the next prompt she writes.

Sixty-nine percent of legal professionals now use generative AI at work, and fifty-four percent of their firms provide no training and have no plans to provide any. Asked what they expect from new lawyers, seventy-six percent of practicing attorneys named cite-checking AI output and fourteen percent named prompt engineering, which leaves the skill that decides what the model produces near the bottom of what the profession has agreed to require. Tools like O'Mono live in that gap.

1. The Final Product

The generated prompt screen showing eight field chips for Role, Task, Context, Input, Constraints, Examples, Format and Tone, with Input and Examples dimmed, above the assembled prompt text and a Copy prompt control

Eight fields come back from a single sentence of input, two of them deliberately left out of the prompt itself, each one carrying a verdict on whether it belongs, a reason written for this input, and a rule of thumb built to travel.

The reason expires with the input that produced it, and the rule of thumb is registered locally, since it is written for somebody who no longer has the application in front of them.

The Role field marked advisable, showing the drafted role text, a Why explanation written for this input, and a rule of thumb about naming a role by who it teaches

With her own prompt in front of her, the associate reads that once and learns what a training module could have told her in the abstract and never made stick.

The Examples field marked inadvisable, showing the drafted example text that was cut, the reason for omitting it, and the rule of thumb that an example inventing facts is worse than no example

The application drafts an example, decides against including it, and shows her the draft anyway, with the reason for leaving it out and the rule of thumb that follows from it.

The Reasoning view labelled overall strategy, explaining how the deliverable shape was fixed, why failure modes were supplied, and why the drafted examples were cut

Above the field level sits the construction strategy for the whole prompt, and a toggle appends all of it, strategy and verdicts and rules of thumb together, to whatever gets copied. The teaching travels wherever the prompt travels, to the colleague who receives it and into the matter file where it lands.

2. Data

The average conversation with a general AI tool runs two prompts, while the heaviest five percent of users average eighteen. Two prompts is a question, a disappointing answer, and a person deciding the tool is not for them. Nobody files a ticket to report that, so the department never learns it happened.

I designed and redesigned O'Mono repeatedly to find out whether the enablement layer could carry more weight, and what follows is what the building taught me. The record here exists because I kept meeting the same corrections and had no way to tell which ones they were. A recurrence a person can feel but cannot name is not yet a curriculum.

Every prompt it generates stores its rules of thumb, and months of those entries, read together, describe what one person keeps getting wrong.

The Learning view header showing 26 prompts and 20 rated across 78 days, with the first ranked rule of thumb about naming the reader rather than the document type Lower in the Learning view, the fourth ranked rule about constraining by what the reader can do, followed by the rest of the record including an entry marked gone

Each entry carries a direction, and the entry at the foot of that view shows a rule marked gone, meaning it stopped appearing partway through the record and has not come back, which is the closest thing to evidence that somebody learned it.

Two phrasings of one rule fold into a single entry, since a view that counted them separately would measure vocabulary where it means to measure habit. The horizon runs to the last prompt in the log, not to today, so that one week away from the application cannot present itself as progress.

That record is mine, and what it changed is the part I can vouch for directly. My prompts now carry the parts I used to leave out. I number the tasks so the model does not skip one, I name a role when the work is specific enough that the answer depends on who gives it, and I supply the fields the model treats loosely before it asks for them. None of that arrived in a course. It came from reading, on my own work, why a field was judged weak, one prompt at a time.

A department that has run this for a year holds something no vendor can sell: a dated account of what its own people found hard, what they stopped finding hard, and roughly when the change happened.

2.1 The Enterprise's Curriculum

In its enterprise version, the administrators only access the centralized folder of reports, one file for each installation, and the page that merges them states its limits before it states a number, so the page cannot be opened onto a person by any setting:

The merged enterprise report page headed 'What this view can and cannot show,' listing three things the view reports and three things it cannot, including who wrote any prompt and what anybody was working on

From the prose delivered per prompt, only the rules of thumb across Role, Task, Context, Input, Constraints, Examples, Format, Tone leave the user's machine. The wording of the rule itself is named in the export as a single literal path that every other field is refused against. What leaves the machine is what somebody needed to learn, and never what they were working on.

Across an enterprise with hundreds of users and months of usage, the data becomes curriculum.

3. Privilege

An on-device stop message reading that the prompt was stopped on your Mac before anything was sent, that it looks like it carries client or privileged material, and offering Redact, an override with a reason, or editing the text

A prompt carrying sensitive terms or data, as well as attaching protected documents and images, stops on the machine before any request leaves it, and the message names what it found in ordinary language rather than in a class code the reader would have to look up. The attorney can also explain to a client what happens to a document inside the application, showing it live.

The Redact screen showing two of two findings changed, a note that nothing has been sent and that tokens keep their meaning and come back through Restore, and per-finding choices of Placeholder, Delete, Generalize, My own text and Not that
A 'What will be sent' panel showing the redacted prompt text, a 'Why this is the right call' panel noting that the replaced values are never recorded, and a line confirming the text was re-checked after redaction and is clear to send

The check runs with no network involved, because the machine is the only place a transmission can be prevented. Every block arrives with a way forward, since hard stops without an alternative are what push people into unapproved tools.

LayerX's State of AI Usage Report 2026 finds that nearly half of all enterprise AI conversations happen through personal identities rather than managed corporate accounts, and that over 14 percent of conversations on corporate identities are tied to personal AI licenses. Enterprise-shaped products like Copilot M365 and Gemini Enterprise are used mostly through managed accounts, while ChatGPT and Claude stay dominated by personal use even inside companies that bought the enterprise version. More than 6 percent of those conversations carry sensitive data. The constraint layer is not redundant in a firm with enterprise licenses: it is aimed at exactly the traffic the enterprise license does not cover.

A firm that bought an enterprise licence has not thereby covered the traffic that matters. Nearly half of enterprise AI conversations run through personal identities rather than managed accounts, and more than six percent of them carry sensitive data.

4. Embedded AI Governance Frameworks

Every control in the application traces to a published requirement, and the table below sets each one beside the requirement it answers.

Control in the code Requirement it answers

Control in the codeField-level verdicts, reasons, and rules of thumb, written in non-specialist language for teaching and enablement

Requirement it answersEU AI Act Article 4, AI literacy for staff operating AI systems, and ABA Model Rule 1.1 comment 8, technology competence

Control in the codeHuman confirmation before generation, a contestable recommendation, and an override that records its reason

Requirement it answersNIST AI RMF MAP 3.5, human oversight, and EU AI Act Article 26(2), deployer oversight by competent natural persons

Control in the codeHash-chained append-only record of every generation, override, redaction, and outcome, with the engine version on each entry

Requirement it answersEU AI Act Article 12(1), automatic event recording, Article 26(6), deployer log retention, GDPR Article 5(2), accountability, and Article 32(1)(b), integrity of processing systems, alongside ISO/IEC 42001 A.6.2.8, AI system event logs

Control in the codeLocal screening, the matter list, redaction and restoration, all running before any network call

Requirement it answersISO/IEC 42001 A.7, data for AI systems, GDPR Article 5(1)(c), data minimization, and Article 25, data protection by design and by default, alongside the confidentiality duty under ABA Model Rule 1.6

Control in the codeRedaction of the terms the screen identifies, with restoration handled on the machine

Requirement it answersGDPR Article 4(5), pseudonymisation, and Article 32(1)(a), pseudonymisation as a measure appropriate to the risk

Control in the codeThe pre-filing verification checklist and its elapsed-time record

Requirement it answersABA Formal Opinion 512 on verification of AI-assisted work, and NIST AI RMF MEASURE 2.5

Control in the codeThe outcome loop and the repeated-lesson ranking

Requirement it answersNIST AI RMF MANAGE 4.1 and ISO/IEC 42001 A.6.2.6, operation and monitoring

Control in the codeOne engine file holding every rule, version-stamped into each record entry

Requirement it answersISO/IEC 42001 A.6.2.7, technical documentation

Control in the codeThe register of assessed AI destinations, recording what each one permits, what it bars, and when the assessment expires

Requirement it answersGDPR Article 30(1)(d), categories of recipients, and Article 28(1), the duty to use only processors offering sufficient guarantees

Most of the AI Act obligations cited bind providers and deployers of high-risk systems specifically, while Article 4 binds providers and deployers of AI systems generally and has stood since 2 February 2025, untouched when the Digital Omnibus deferred the high-risk obligations to late 2027. The table shows that a control exists in the code and corresponds to a cited requirement, which is not the same as full compliance.

A general counsel who buys a monitoring product in November 2027 will have bought inspection, and inspection answers a different question from the one Article 4 asks. What Article 4 asks for is evidence that the people operating these systems understood what they were operating, and that evidence is a history of what a team was taught, week by week, out of the work it was doing. A history of that kind cannot be bought in the quarter a regulator asks for it, which is the argument for building the teaching layer first.

The professional rules did not move either. The ABA Model Rules bind lawyers rather than software, and no state bar's competence obligation changed when the European timetable did.

5. The Lesson

The teaching layer changed behavior, and the governance layer settled how much of the real work that teaching could reach. A tool trusted with a real matter gets opened on that matter, gets read while somebody is deciding something, and leaves a rule of thumb behind that outlives the session, while a tool nobody trusts with anything sensitive teaches people on the easy half of their job.

Numbering the tasks is decomposition, naming a role decides who the answer is for, saying what not to do is a constraint, and naming the jurisdiction is scope. None of that is a trick about wording, and none of it arrives with a better model, because it encodes what the person wanted and intent is the part a lawyer is paid for. Stronger models make a vague instruction cheaper to survive. They do not remove the need to say what you want, and a system that runs forty steps before anybody looks raises the cost of not saying it.

Somewhere around the end of next year a regulator or a client or a bar will ask a department what its people understood about these systems and when they understood it, and the answer will be a history that already exists or an assurance nobody can check.

Discuss this analysis