Skip to content
Back to Guides
prompt engineeringbeginnerFeatured

Run Your First Adversarial Prompt Test

Use devil's advocate prompting to look for weak legal reasoning in an AI draft before anyone else reads it.

What You'll Learn

This guide shows how to use adversarial prompting—asking AI to attack its own outputs—to look for weak legal reasoning before it reaches clients.

Difficulty: Beginner—no technical skills required

The Problem This Solves

AI tools can be sycophantic: they can favour an answer that matches what you appear to think over one that is correct. The behaviour has been studied in AI assistants: see Sharma and others, Towards Understanding Sycophancy in Language Models (first submitted 20 October 2023, read 29 September 2026). Ask "Is this analysis good?" and you invite a yes.

Adversarial prompting changes the question: instead of asking for validation, you ask the AI to find problems.

Before You Use Client Material

This guide is about how to word a prompt. It does not make a client's document or information safe to put into an AI tool. What you may enter depends on the plan your firm has, its agreement with the vendor and your firm's policy: Claude Projects for Client Matters sets out the checks for one tool. To practise, use a precedent or a published document that contains no client information, and refer to parties by role.

The Basic Technique

Step 1: Generate Your Initial Output

Use AI to draft something—a contract clause, legal memo, argument, whatever.

Example:

Draft an indemnity clause for a software services agreement governed
by English law, where the supplier indemnifies the customer for IP
infringement.

Step 2: Save the Output

Copy the AI's response into a separate document. You'll need it for comparison.

Step 3: Run the Adversarial Prompt

In a new conversation (important!), paste this template:

You are a senior partner in a firm in England and Wales reviewing
this contract clause drafted by a trainee solicitor. Your job is to
find problems, not validate their work.

[PASTE THE CLAUSE HERE]

Identify:
- Ambiguous language that could be interpreted against our client
- Missing protective provisions
- Overly broad commitments
- Standard market terms that are absent
- Potential enforcement issues

Be specific. Cite exact language. Don't hold back.

Step 4: Review Both Outputs

Now you have:

  1. The original generation (what the AI thinks is good)
  2. The adversarial review (what the AI thinks could be wrong)

Your job: Synthesise both, using the adversarial feedback to improve the original.

Worked Example

This example is illustrative. It shows how the technique runs, not the result of a published test.

Original Output (Generation Prompt):

Prompt: "Draft an indemnity clause for a software services agreement governed by English law, where the supplier indemnifies the customer for IP infringement."

AI Output:

INDEMNITY

The Supplier shall indemnify the Customer against all claims, losses and
liabilities arising out of any allegation that the Software infringes the
intellectual property rights of any third party.

Looks good, right? Let's test it.

Adversarial Prompt:

You are a senior partner reviewing this indemnity clause drafted by a
trainee solicitor. Your job is to find problems, not validate their work.

[CLAUSE TEXT]

Identify problems, ambiguities, and missing protections. Be specific.

AI Adversarial Output:

Issues identified:

1. NO SURVIVAL PROVISION: Clause doesn't say whether the indemnity
   survives termination. IP claims often arise after termination.

2. NO NOTICE REQUIREMENTS: Nothing requires the Customer to notify the
   Supplier of a claim, or says what happens if it does not.

3. NO CONDUCT OF CLAIMS: Doesn't say who has conduct of the claim or
   whether the Customer must cooperate.

4. AMBIGUOUS "ARISING OUT OF": Is the indemnity limited to infringement
   by the Software as supplied, or does it extend further?

5. NO EXCLUSIONS: Nothing excludes claims arising from the Customer's own
   modifications or misuse.

6. NO REMEDY PROVISIONS: Doesn't address what happens if the Supplier
   can't or won't indemnify. Should include alternative remedies (termination rights,
   replacement software, etc.)

7. NO CAP: Unlimited liability for the Supplier, likely to be resisted in
   negotiation. Consider whether this is intentional.

The original looked fine. The adversarial review lists seven points to consider.

Synthesised Final Output

Now revise using both:

INDEMNITY

9.1 Supplier's indemnity. The Supplier shall indemnify the Customer against
all claims, losses and liabilities arising out of any allegation that the
Software, as supplied by the Supplier and used in accordance with this
Agreement, infringes the patent, copyright or trade mark rights of any
third party.

9.2 Exclusions. Clause 9.1 shall not apply to a claim arising from: (a) the
Customer's modification of the Software; (b) use of the Software in
combination with products not supplied by the Supplier; or (c) the
Customer's continued use after the Supplier has notified it of the alleged
infringement.

9.3 Conduct of claims. The Customer shall: (a) notify the Supplier promptly
of any claim; (b) give the Supplier sole conduct of the claim and of any
settlement; and (c) give the Supplier reasonable assistance, at the
Supplier's expense.

9.4 Remedies. If the Software becomes subject to an infringement claim, the
Supplier may: (a) obtain the right for the Customer to continue using it;
(b) replace or modify the Software so that it no longer infringes; or (c) if
neither is commercially reasonable, terminate this Agreement and refund a
pro rata share of the fees.

9.5 Survival. This clause 9 shall survive termination of this Agreement.

Much better. Six of the seven points are addressed, and the seventh (the cap) is a commercial decision for you and the client. The redraft is an illustration of the technique, not a precedent: a solicitor still has to check it against the law and the deal.

When to Use This Technique

Use adversarial prompting for:

  • Contract clauses before sending to counterparty
  • Legal memos before client delivery
  • Skeleton arguments and statements of case before they are filed
  • Any AI output where quality matters

Don't use it for:

  • Quick brainstorming or ideation
  • Internal notes to yourself
  • Background research (validate substance differently)

Advanced Variation: Specify the Attack Vector

Make the adversarial prompt even more targeted:

For Litigation:

You act for the other side. Attack this argument as hard as you can:

[ARGUMENT]

Identify:
- Distinguishable case authority
- Factual weaknesses
- Alternative legal arguments that defeat this position
- Procedural issues

For Contracts:

You represent the counterparty. Your client wants to pay as little as
possible and minimise commitments. Find every way this contract language
could be interpreted against the drafting party:

[CLAUSE]

For Regulatory:

You are a regulator investigating this company. Read this policy with
maximum scepticism. Where are the gaps, loopholes, and non-compliance risks?

[POLICY]

Each variation targets the specific failure mode you're most worried about.

Common Mistakes

Mistake 1: Using the Same Conversation

If you run the adversarial prompt in the same conversation as generation, the AI has your original request in front of it, and that may soften its review.

Fix: New conversation, fresh start, no context.

Mistake 2: Asking "Is this good?"

A general request for validation invites agreement.

Fix: Specific attack mandate: "Your job is to find problems, not validate."

Mistake 3: Ignoring the Adversarial Feedback

"The adversarial output found issues, but the original seems fine..."

Fix: Take adversarial feedback seriously. If the AI can find the issue, the other side's lawyers can too.

Measuring Success

Record these after your first 10 uses:

  1. How many issues did adversarial prompting find that you hadn't noticed?
  2. How many of those issues were legitimate (vs. false positives)?
  3. How much revision time did this save by catching issues early?

No results have been published for this technique, so your own record is the evidence that counts. If the adversarial review rarely finds a real issue in your work, change the prompt or stop using it.

Next Steps

  1. Try it today: Take your next AI-generated output and run it through adversarial review
  2. Create templates: Save your best adversarial prompts for reuse
  3. Expand to peer review: Use adversarial prompting before sending to senior lawyers
  4. Build it into workflow: Make adversarial review mandatory for client-facing work

This one technique—asking AI to attack its own outputs—gives you a second, critical reading before a draft reaches a supervisor, a client or the other side. It does not replace your own check.

Measure what it finds, and the time it saves you.


Related:

Related Topics

validationquality-assurancetesting

Tools Referenced

ChatGPTClaudeany-llm