What You'll Learn
This guide shows how to use adversarial prompting—asking AI to attack its own outputs—to look for weak legal reasoning before it reaches clients.
Difficulty: Beginner—no technical skills required
The Problem This Solves
AI tools can be sycophantic: they can favour an answer that matches what you appear to think over one that is correct. The behaviour has been studied in AI assistants: see Sharma and others, Towards Understanding Sycophancy in Language Models (first submitted 20 October 2023, read 29 September 2026). Ask "Is this analysis good?" and you invite a yes.
Adversarial prompting changes the question: instead of asking for validation, you ask the AI to find problems.
Before You Use Client Material
This guide is about how to word a prompt. It does not make a client's document or information safe to put into an AI tool. What you may enter depends on the plan your firm has, its agreement with the vendor and your firm's policy: Claude Projects for Client Matters sets out the checks for one tool. To practise, use a precedent or a published document that contains no client information, and refer to parties by role.
The Basic Technique
Step 1: Generate Your Initial Output
Use AI to draft something—a contract clause, legal memo, argument, whatever.
Example:
Draft an indemnity clause for a software services agreement governed
by English law, where the supplier indemnifies the customer for IP
infringement.
Step 2: Save the Output
Copy the AI's response into a separate document. You'll need it for comparison.
Step 3: Run the Adversarial Prompt
In a new conversation (important!), paste this template:
You are a senior partner in a firm in England and Wales reviewing
this contract clause drafted by a trainee solicitor. Your job is to
find problems, not validate their work.
[PASTE THE CLAUSE HERE]
Identify:
- Ambiguous language that could be interpreted against our client
- Missing protective provisions
- Overly broad commitments
- Standard market terms that are absent
- Potential enforcement issues
Be specific. Cite exact language. Don't hold back.
Step 4: Review Both Outputs
Now you have:
- The original generation (what the AI thinks is good)
- The adversarial review (what the AI thinks could be wrong)
Your job: Synthesise both, using the adversarial feedback to improve the original.
Worked Example
This example is illustrative. It shows how the technique runs, not the result of a published test.
Original Output (Generation Prompt):
Prompt: "Draft an indemnity clause for a software services agreement governed by English law, where the supplier indemnifies the customer for IP infringement."
AI Output:
INDEMNITY
The Supplier shall indemnify the Customer against all claims, losses and
liabilities arising out of any allegation that the Software infringes the
intellectual property rights of any third party.
Looks good, right? Let's test it.
Adversarial Prompt:
You are a senior partner reviewing this indemnity clause drafted by a
trainee solicitor. Your job is to find problems, not validate their work.
[CLAUSE TEXT]
Identify problems, ambiguities, and missing protections. Be specific.
AI Adversarial Output:
Issues identified:
1. NO SURVIVAL PROVISION: Clause doesn't say whether the indemnity
survives termination. IP claims often arise after termination.
2. NO NOTICE REQUIREMENTS: Nothing requires the Customer to notify the
Supplier of a claim, or says what happens if it does not.
3. NO CONDUCT OF CLAIMS: Doesn't say who has conduct of the claim or
whether the Customer must cooperate.
4. AMBIGUOUS "ARISING OUT OF": Is the indemnity limited to infringement
by the Software as supplied, or does it extend further?
5. NO EXCLUSIONS: Nothing excludes claims arising from the Customer's own
modifications or misuse.
6. NO REMEDY PROVISIONS: Doesn't address what happens if the Supplier
can't or won't indemnify. Should include alternative remedies (termination rights,
replacement software, etc.)
7. NO CAP: Unlimited liability for the Supplier, likely to be resisted in
negotiation. Consider whether this is intentional.
The original looked fine. The adversarial review lists seven points to consider.
Synthesised Final Output
Now revise using both:
INDEMNITY
9.1 Supplier's indemnity. The Supplier shall indemnify the Customer against
all claims, losses and liabilities arising out of any allegation that the
Software, as supplied by the Supplier and used in accordance with this
Agreement, infringes the patent, copyright or trade mark rights of any
third party.
9.2 Exclusions. Clause 9.1 shall not apply to a claim arising from: (a) the
Customer's modification of the Software; (b) use of the Software in
combination with products not supplied by the Supplier; or (c) the
Customer's continued use after the Supplier has notified it of the alleged
infringement.
9.3 Conduct of claims. The Customer shall: (a) notify the Supplier promptly
of any claim; (b) give the Supplier sole conduct of the claim and of any
settlement; and (c) give the Supplier reasonable assistance, at the
Supplier's expense.
9.4 Remedies. If the Software becomes subject to an infringement claim, the
Supplier may: (a) obtain the right for the Customer to continue using it;
(b) replace or modify the Software so that it no longer infringes; or (c) if
neither is commercially reasonable, terminate this Agreement and refund a
pro rata share of the fees.
9.5 Survival. This clause 9 shall survive termination of this Agreement.
Much better. Six of the seven points are addressed, and the seventh (the cap) is a commercial decision for you and the client. The redraft is an illustration of the technique, not a precedent: a solicitor still has to check it against the law and the deal.
When to Use This Technique
Use adversarial prompting for:
- Contract clauses before sending to counterparty
- Legal memos before client delivery
- Skeleton arguments and statements of case before they are filed
- Any AI output where quality matters
Don't use it for:
- Quick brainstorming or ideation
- Internal notes to yourself
- Background research (validate substance differently)
Advanced Variation: Specify the Attack Vector
Make the adversarial prompt even more targeted:
For Litigation:
You act for the other side. Attack this argument as hard as you can:
[ARGUMENT]
Identify:
- Distinguishable case authority
- Factual weaknesses
- Alternative legal arguments that defeat this position
- Procedural issues
For Contracts:
You represent the counterparty. Your client wants to pay as little as
possible and minimise commitments. Find every way this contract language
could be interpreted against the drafting party:
[CLAUSE]
For Regulatory:
You are a regulator investigating this company. Read this policy with
maximum scepticism. Where are the gaps, loopholes, and non-compliance risks?
[POLICY]
Each variation targets the specific failure mode you're most worried about.
Common Mistakes
Mistake 1: Using the Same Conversation
If you run the adversarial prompt in the same conversation as generation, the AI has your original request in front of it, and that may soften its review.
Fix: New conversation, fresh start, no context.
Mistake 2: Asking "Is this good?"
A general request for validation invites agreement.
Fix: Specific attack mandate: "Your job is to find problems, not validate."
Mistake 3: Ignoring the Adversarial Feedback
"The adversarial output found issues, but the original seems fine..."
Fix: Take adversarial feedback seriously. If the AI can find the issue, the other side's lawyers can too.
Measuring Success
Record these after your first 10 uses:
- How many issues did adversarial prompting find that you hadn't noticed?
- How many of those issues were legitimate (vs. false positives)?
- How much revision time did this save by catching issues early?
No results have been published for this technique, so your own record is the evidence that counts. If the adversarial review rarely finds a real issue in your work, change the prompt or stop using it.
Next Steps
- Try it today: Take your next AI-generated output and run it through adversarial review
- Create templates: Save your best adversarial prompts for reuse
- Expand to peer review: Use adversarial prompting before sending to senior lawyers
- Build it into workflow: Make adversarial review mandatory for client-facing work
This one technique—asking AI to attack its own outputs—gives you a second, critical reading before a draft reaches a supervisor, a client or the other side. It does not replace your own check.
Measure what it finds, and the time it saves you.
Related:
- Five Validation Layers - Build comprehensive quality assurance systems
- Testing Checklist - Systematic validation before deployment