An associate opens the desktop application, types one sentence about a training session she must run on Thursday, and names the AI application that will receive the finished prompt. O'Mono does not answer the training question or send the request to that destination. It returns the reasoning that will shape the prompt, including who should speak, what the audience and timing require, which assumptions need confirmation, and which drafted material should be cut before the model receives it.
Legal professionals are already doing this work inside firms that often have not trained them. The 2026 Legal Industry Report finds that sixty-nine percent use general-purpose generative AI for work while fifty-four percent of firms provide no training and have no plans to provide it.1 Bloomberg Law reports that seventy-six percent of practicing attorneys expect new lawyers to cite-check AI output and fourteen percent expect prompt-engineering skill,2 leaving the instruction that shapes the first answer far less expected than the work required to verify it.
1. The Prompt
O'Mono assembles the request through eight fields: Role, Task, Context, Input, Constraints, Examples, Format, and Tone. Each field receives a verdict and a reason written for this input, dimmed chips preserve fields that were considered and cut, and the prompt below carries only the material that changes the result. When the task itself needs checks before reliance, a verification block follows the eight fields. The user then clicks the Copy button and pastes the finished prompt into the destination's own application.
When the associate opens a field decision, the panel states what that field is doing for the prompt and follows it with a short rule of thumb she can carry to the next request. Because the controlling fact remains visible, she knows which part of the request to revise when she disagrees.
A field that loses its place does not disappear without explanation. O'Mono keeps the cut verdict beside the reason, so the associate can see why the example would have repeated the Format instruction and decide whether that judgment should stand.
Opening Why expands the same decision record across the whole prompt, including fields kept, fields cut, and the task or destination fact that controlled each one. A person who disagrees can return to the specific decision instead of rebuilding the request from the beginning.
2. One Screen Between Idea and Prompt
Before O'Mono writes, it returns one sentence showing how it read the request, lets the person overwrite that reading, lists the assumptions while they can still be corrected, and asks only questions whose answers would change the result. For this task, who is in the room decides which failure modes will read as credible, who delivers the session decides whether the deliverable is a curriculum outline or speaker notes, and what already worries the person about current use decides whether the session opens with concrete examples and red flags or with frameworks and accountability. Each question carries the reason it is being asked and a suggested answer the person can overrule.
Local screening runs before any network call, while the machine can still prevent a transmission. LayerX reports that nearly half of enterprise AI conversations use personal rather than managed corporate identities, more than fourteen percent of conversations on corporate identities are tied to personal AI licenses, and more than six percent carry sensitive data.4 An enterprise license cannot govern traffic it never sees.
While the person makes those decisions, one lesson chosen for the task and destination sits in the same flow without demanding an answer. The card names the phenomenon, explains the mechanism, states what should follow from it, and cites its source; scrolling past it does not change the prompt or block generation.
When the request would carry sensitive material, the same flow adds one advisory line and its reason. The line does not stop generation, and the interface exposes no redaction control; work continues after the person decides what to change before copying anything into another system.
3. The Teaching Layer
Article 4 has applied generally to providers and deployers since 2 February 2025, and the 2026 Digital Omnibus now requires them to take measures that support the development of AI literacy while considering the knowledge and experience of the people involved and the context in which the systems are used.5 O'Mono works at that level of specificity by shaping the questions and lesson around the task being written, with any safeguard tied to the same task and destination rather than to a session delivered months earlier.
While O'Mono assembles the prompt, the writing state rotates lesson hooks. The line comes from the current lesson set; every generated lesson must name the phenomenon, explain the mechanism plainly, state the consequence, and cite a source before it can enter that set.
After the person copies a prompt into its destination, O'Mono asks whether the last prompt worked and keeps the unresolved outcome with the prompt until the person answers. Opening Verification lists the prompts still waiting on an answer, each carrying its own one-tap outcome, with older ones kept in History. The response joins the ledger without importing the destination's answer; choosing Failed can reopen the prompt for repair, while the failure reaches the curriculum only as a category.
4. The Record, and the Curriculum It Becomes
Each generation adds an immutable ledger entry for the shape of the work: task type, included fields, safeguards, and engine version, with no prompt content. A later outcome adds its own record against that generation, so Worked, Partly, or Failed can inform learning without rewriting the original entry.
On one machine, those entries become the Learning view, where covered areas appear in sentences, the largest gap is named, and the record states what it cannot establish. In the illustrative enterprise view below, the combined record wrote one hundred and fifty lessons that day and shows four of them: an area no lesson covered while prompts moved to agent surfaces, the failure repaired most often across the deployment, the same task carried unchanged between nine different tools, and attachments whose advisory line was dismissed without redaction. Each card states in one line what in the record produced it. A candidate enters only if it names the phenomenon, explains the mechanism in plain language, states the consequence, and cites a source, and three candidates were rejected that day for failing those checks. Personal lessons go live immediately. Enterprise lessons draw from aggregate deployment data, go live for everyone by default, and remain subject to retirement or review by an administrator.
The illustrative export opens by naming what the file is and how it was built, then reports the period's work records, complete lesson displays, and recorded outcomes. Beneath them the quarter divides into worked, partly worked, failed, and unreported results, alongside repeated failures, repairs completed, work returned for correction, and failures that occurred despite protections. Recorded outcomes count only the prompts on which somebody answered, so that figure sits well below the count of prompts.
Enterprise administrators receive aggregate results without individual drill-down or free text, and the export withholds any cell that counts fewer than five people. The limits sit on the same page as the figures they qualify, where a reader sees them before deciding what the numbers can support.
The second page names the curriculum itself, reporting how many areas it covers, which areas it taught most and least in the period, and the sections it maintains for different kinds of work. Beneath them sit the curriculum decisions, each carrying a finding, the evidence supporting it, and the action it recommends. A pattern appears only when at least thirty work records from at least five people support it, and it changes the curriculum automatically only after the same pattern repeats in the next reporting period. The counts measure recorded exposure rather than mastery.
When an enterprise aggregate moves a signal off a person's machine, it carries what the system needed to teach and never the prompt or answer that produced the signal. Over time, a department gains a dated account of where work created difficulty, which areas later improved, and roughly when the change occurred.
5. Embedded AI Governance
Each row in the table maps a product control to a legal duty, professional rule, framework function, or standard clause that the control may support. The mapping shows correspondence at the level of design; it does not establish that O'Mono, a deployment, or a user has satisfied every condition attached to the cited authority.
Control in the codeThe lesson layer: one reviewed card per prompt, field verdicts and reasons in non-specialist language, a canon across eighteen literacy domains
CorrespondenceEU AI Act Article 4, AI literacy for staff operating AI systems, and ABA Model Rule 1.1 comment 8, technology competence
Control in the codeHuman confirmation before generation: a contestable reading of the task, editable assumptions, and a real Cancel that aborts the work
CorrespondenceNIST AI RMF MAP 3.5, human oversight, and EU AI Act Article 26(2), deployer oversight by competent natural persons
Control in the codeA hash-chained, append-only record of every generation, cancellation, redaction, outcome, and policy trail, with the engine version on each entry
CorrespondenceEU AI Act Article 12(1), automatic event recording, Article 26(6), deployer log retention, GDPR Article 5(2), accountability, and Article 32(1)(b), integrity of processing systems, alongside ISO/IEC 42001 A.6.2.8, AI system event logs
Control in the codeLocal screening of the prompt on the machine, before any network call
CorrespondenceISO/IEC 42001 A.7, data for AI systems, GDPR Article 5(1)(c), data minimization, and Article 25, data protection by design and by default, alongside the confidentiality duty under ABA Model Rule 1.6
Control in the codeThe verification loop, the pre-filing checklist, and their elapsed-time record
CorrespondenceABA Formal Opinion 512 on verification of AI-assisted work, and NIST AI RMF MEASURE 2.5
Control in the codeThe outcome loop, the curriculum's evidence floors, and the failure-and-repair modules
CorrespondenceNIST AI RMF MANAGE 4.1 and ISO/IEC 42001 A.6.2.6, operation and monitoring
Control in the codeOne engine file holding every rule, version-stamped into each record entry
CorrespondenceISO/IEC 42001 A.6.2.7, technical documentation
Control in the codeThe tool-dossier register: what each destination is trusted with, every claim sourced and dated, every assessment carrying an expiry
CorrespondenceGDPR Article 30(1)(d), categories of recipients, and Article 28(1), the duty to use only processors offering sufficient guarantees
Article 4 reaches providers and deployers generally, while several other AI Act provisions in the table apply only to high-risk systems. Regulation (EU) 2026/1744 amended Article 4 in July 2026 and split the delayed high-risk dates: Annex III systems move to 2 December 2027, while systems embedded in products covered by Annex I move to 2 August 2028.5 NIST and ISO provide frameworks and standards, and the ABA authorities address lawyers and professional responsibility rather than certify software.
When an organization keeps a dated learning record, it can show which literacy measures it took, for whom, in what context, and when. Article 4 does not prescribe O'Mono's workflow or require a week-by-week curriculum history,6 so the record can support an account of the measures without proving compliance by itself.
Professional-responsibility duties attach to lawyers under the rules adopted in their jurisdictions. The European implementation calendar does not suspend duties of competence, confidentiality, or verification.
6. The Lesson
LayerX places the median conversation at two prompts and the ninety-fifth percentile at eighteen.3 A shallow exchange can end with a disappointing answer and no report to the department, leaving the failure outside any training record.
When a professional names the task, assigns the right role, states the jurisdiction, and tells the model what to do, the prompt carries intent the model cannot supply. A stronger model may recover from vagueness more often, but an agent that acts through many steps raises the cost of every ambiguity left in the instruction.
When a regulator, client, or bar later asks what a department did to develop AI literacy and how it knows, the answer will depend on the record the department kept while the work was happening.
Notes
- Sixty-nine percent using generative AI, and fifty-four percent of firms providing no training and having no plans to provide any: 8am, 2026 Legal Industry Report, 1,300+ legal professionals, fielded 19 September to 18 October 2025. The sample skews small, 45 percent solo and 38 percent two-to-five lawyers, so it evidences the profession broadly rather than large firms. ↑
- Seventy-six percent expecting cite-checking of AI output and fourteen percent expecting prompt engineering: Bloomberg Law, 2026 Path to Practice Survey, 1,800+ law students, faculty and practicing attorneys. ↑
- Median conversation length of two prompts and a ninety-fifth percentile of eighteen: LayerX Security, State of AI Usage Report 2026. ↑
- Nearly half of enterprise AI conversations on personal identities, over fourteen percent of conversations on corporate identities tied to personal licenses, and more than six percent of conversations carrying sensitive data: LayerX Security, State of AI Usage Report 2026. LayerX sells browser security and the figures are telemetry from its own deployments, so they evidence its customer base rather than the market. ↑
- Article 4 binding providers and deployers of AI systems generally since 2 February 2025: Regulation (EU) 2024/1689, Article 4. Amendment of Article 4 and the split high-risk dates, 2 December 2027 for Annex III systems and 2 August 2028 for systems embedded in Annex I products: Regulation (EU) 2026/1744, the Digital Omnibus on AI. ↑
- What Article 4 requires of providers and deployers: Regulation (EU) 2024/1689, Article 4. ↑
Table citations, by row. No markers in the table; its right column carries the citation. Listed here for the record.
- Row 1: EU AI Act Article 4; ABA Model Rule 1.1 comment 8.
- Row 2: NIST AI RMF 1.0, MAP 3.5; EU AI Act Article 26(2).
- Row 3: EU AI Act Articles 12(1) and 26(6); GDPR Articles 5(2) and 32(1)(b); ISO/IEC 42001:2023 A.6.2.8.
- Row 4: ISO/IEC 42001:2023 A.7; GDPR Articles 5(1)(c) and 25; ABA Model Rule 1.6.
- Row 5: ABA Formal Opinion 512; NIST AI RMF 1.0, MEASURE 2.5.
- Row 6: NIST AI RMF 1.0, MANAGE 4.1; ISO/IEC 42001:2023 A.6.2.6.
- Row 7: ISO/IEC 42001:2023 A.6.2.7.
- Row 8: GDPR Articles 30(1)(d) and 28(1).
Sources
- Regulation (EU) 2024/1689, the EU AI Act, Articles 4, 12 and 26.
- Regulation (EU) 2026/1744, the Digital Omnibus on AI.
- Regulation (EU) 2016/679, the General Data Protection Regulation.
- ABA Model Rules of Professional Conduct, Rules 1.1 and 1.6; ABA Formal Opinion 512.
- NIST AI Risk Management Framework 1.0.
- ISO/IEC 42001:2023, Annex A.
- Bloomberg Law, 2026 Path to Practice Survey; 8am, 2026 Legal Industry Report; LayerX Security, State of AI Usage Report 2026.