The safest first use of AI in a South African legal team is drafting and checking contracts against your own approved documents, in accounts that don't train on your files, with a lawyer reading every draft before it's used. That's the setup I built for one team. They aren't a law firm. They're financial advisers with one lawyer among them, and they work on their contracts from a shared library in Claude Cowork.
What I set up for the team
Most guides to AI for lawyers start with which tool to buy. This setup came down to three things, and none of them was choosing a model.
- I helped the team install Claude Cowork.
- I set up a cloud file structure for the library.
- I built a prompting tool that helps them write better prompts for Cowork. It asks them what type of legal work they want Cowork to help with, lets them add the specific documents that matter, and asks what output they expect, all built on Anthropic's latest prompting guide so the model knows exactly what they want.
The library itself came down to two pieces: a precise system prompt, and a cloud-based folder structure that makes it easy for the agent to find the relevant documents.
The library only holds templates that are specific to the kind of work this client does. Its design is still ongoing, too. As they use it more, they keep finding out what their specific needs are.
The client picked out several types of requests they wanted help with, ones that matter in their industry, and the templates are built around those. Until the needs settle, the system keeps evolving as they get more comfortable with the tool.
The file structure matters more since Anthropic changed how Cowork works on 6 October 2026. Its help page now says "Claude Cowork is now just Claude", and from that date new Cowork tasks on the Pro and Max plans run in the cloud, on Anthropic's servers. The option to keep work only on your computer is gone. Sessions and files are saved to the Claude account, and when a task needs a file from a folder you've connected on your computer, Claude fetches a copy of that file (checked on 9 October 2026). So the folder structure is also the access list. Whatever sits in a connected folder can end up in a cloud session.
What goes into those folders is an editorial decision before it's a technical one. A folder holding every past agreement isn't a useful library, because some files are outdated, some contain exceptions and some belong to a different client. Someone has to decide which template is current, who owns the standard terms, and how the team will recognise a superseded version. My public Claude Legal Library guide shows one way to lay it out, with approved templates and playbooks kept apart from each matter's source documents, drafts and review notes. That layout is from the public guide, not this client's library. If you'd like help with that part, it's the document library setup I do for teams.
Who checks the draft, and what has Claude got wrong?
The legal lead goes over everything and reads every draft in full before it's used.
I can't tell you yet what Claude has got wrong. As of 7 October 2026 the team hadn't sent me any corrections. That doesn't mean there were no mistakes. It means nothing has been reported. From now on the legal lead writes a short review note on each draft. Over time I'll use those notes to improve Claude's system prompt so it makes fewer mistakes.
The cost of skipping that read is now on record in South African courts. In both Mavundla and Northbound Processing, the courts referred lawyers' reliance on AI-invented case authorities to the Legal Practice Council for investigation. In July 2026 ENS reported on a Labour Court matter where a disciplinary chairperson's ruling cited four authorities, two of them fabricated and one materially misrepresented. A convincing citation, or a confident answer from a model, isn't verification. Open the original source and check that the passage says what the draft claims it says.
Which Claude plan, and is training switched off?
The team uses individual Claude plans, not the Team plan. I went that way because the Team plan needed at least five seats. Anthropic's help page now says "Team plans require a minimum of two members" (checked on 9 October 2026). They signed up several months ago, when five seats was still the minimum. Now that it's changed, I'll advise them to move to the Team plan.
On individual plans, whether your chats train Anthropic's models is a setting each person controls. I switched model training off on each of their accounts right after signing them up.
| Individual plans (Free, Pro, Max) | Commercial plans (Team, Enterprise, API) | |
|---|---|---|
| Used to train models? | Only if "Help improve our AI models" is on. Each person sets it | Not by default |
| Where to check | Settings, then Privacy | The exception is feedback: the thumbs-up and thumbs-down buttons, or choosing to allow it |
| Anthropic page last updated | 3 August 2026 | 18 August 2026 |
Two details are easy to miss. Switching the setting off covers new chats and sessions, but data already used in training stays there. And on the commercial plans, a thumbs-up or thumbs-down on a response is feedback Anthropic may train on, so tell the team before they start rating answers on client documents.
Training is only one part of handling personal information. The Protection of Personal Information Act is the primary source, and this guide doesn't decide whether a particular setup complies with it. Write down which accounts and folders Claude can reach, who can see what it produces, and how access gets switched off. A prompt that says "read only" is an instruction, not an access setting. Anthropic's own Cowork safety page says to "be cautious about granting access to sensitive information like financial documents, credentials, or personal records", and that "you remain responsible for all actions taken by Claude performed on your behalf."
A worked example: checking a draft against your own terms
Fictional training example. The documents and output below are invented to show the review step. They aren't recommended contract terms, a client result or a benchmark.
- Approved playbook, item P-03: "For this exercise, the standard payment period is 30 calendar days after invoice."
- Incoming draft, clause 4.2: "Invoices are payable within 60 calendar days after invoice."
- Incoming draft, schedule A: "[Supplier name to be confirmed]."
The instruction is to compare the texts, list differences and missing information, and not fill any gaps. A useful answer looks like this:
| Finding | Evidence | Decision for the reviewer |
|---|---|---|
| Payment period differs | Clause 4.2 says 60 days. Playbook P-03 says 30 | Negotiate, or accept the departure |
| Supplier name is missing | Schedule A is a placeholder | Get the approved name. Don't take it from another matter |
A tidy rewrite that quietly changes 60 to 30 would hide a decision the lawyer has to make. A neat document can still leave out the detail that matters. The practice pack in my Cowork guide works the same way: it plants a time conflict and an unconfirmed price, and the instruction tells Claude not to resolve either. If the output misses the planted problem, keep that correction in the instructions and retry with a different example.
How do you know it's worth keeping?
Run a small trial before anyone relies on it.
- Put the same type of task through your current process and the new one. Record preparation time, review time, corrections and missing information.
- Include a conflicting term and a missing fact, so the trial tests more than the easy case.
- Have the person who signs off check each output against the original.
- Where errors repeat, change the sources or the instructions, then try an example the setup hasn't seen.
- Carry on only if the reviewed result is useful enough to justify the setup, software and support costs.
I don't promise an exact return from a first call, because the trial is how you find out.
Is this legal advice?
No. This is guidance on setting up and checking AI tools. A qualified practitioner decides whether any legal content is right and whether it gets used.
I'm Henno Fourie. I find where admin is costing an owner-run business time and money, fix it with AI around the tools the business already uses, one job at a time, and stay on as the person responsible for AI in that business. If one type of contract takes up more of your team's week than it should, book a free 30-minute call. Bring that one job. I'll tell you whether it's worth fixing and what the next step costs.
How I wrote this: I drafted it with AI from my own notes and client work, then checked the facts and edited it myself.