Event recap
Vibe Coding in Law Firms:How to InnovateWithout Losing Control
Fliplet, Lawfront, and Willkie shared how legal teams can create useful software with AI while IT keeps control of access, security, testing, and publishing.

NASHVILLE, Tennessee - At ILTACON 2026, Fliplet CEO Ian Broom joined James Grice, Head of Innovation & AI at Lawfront, and Stephanie Lopez, Senior Manager of UI/UX Development at Willkie Farr & Gallagher, for Vibe Coding in Law Firms: How to Innovate Without Losing Control.
The session explored how law firms can empower lawyers and business-services professionals to build useful software with AI without sacrificing the governance, security, and oversight required in a legal environment.
Its central argument was straightforward: vibe coding is most valuable when it sits inside a controlled enterprise platform. Employees are already experimenting with general-purpose AI coding tools, often on personal devices. The resulting software can be difficult for IT teams to assess, secure, deploy, and maintain. A managed environment offers an alternative: people can turn ideas into working solutions while IT retains control over permissions, authentication, integrations, auditing, publishing, and the ability to disable a solution centrally.

From document to tool
Ian opened with the story of an associate at a large UK law firm who needed a better way to handle complex anti-dilution calculations. Existing AI tools could discuss the problem or generate a spreadsheet, but the lawyers could not confidently understand or validate the spreadsheet's calculations.
The associate uploaded an 80-page legal document to Fliplet and asked the platform to use a specific section to create an anti-dilution calculator. The result gave the associate and partner something they could inspect, understand, and improve. It also prompted them to think of other tools they could build from the same source material.
The example captured the wider change discussed throughout the session: domain experts can translate their knowledge directly into practical tools instead of waiting for a conventional development project.
A seven-minute prototype
A live demonstration reinforced the point. From a short spoken description, Fliplet planned and produced the first phase of an ISO 27001 and SOC 2 compliance-tracking solution in approximately seven minutes. The prototype included readiness metrics, controls, tasks, a Kanban-style workflow, an evidence library, and reporting.

Click or tap to expand the full screenshot. Compliance Readiness Hub demo: controls, evidence, tasks, and reporting in one place. Explore the demo.
Ian then told the builder that the organization was a law firm. It refined the prototype to account for client confidentiality, privileged information, matter-level access, and conflict references. The point was not that seven minutes produced finished, production-ready software. It was that a working first version could improve the conversation with stakeholders and expose wrong assumptions much faster than a written specification.
Ian's advice for that first prompt was simple:
“Don't be too specific. Just give Fliplet some high-level information and leave it to be creative.”
Build inside guardrails
The central concern was not whether attorneys and staff can create useful prototypes. It was what happens when those prototypes need to enter the firm.
Fliplet combines AI code generation with governance, integrations, existing SSO and authentication controls, databases and file storage, managed hosting, centralized logging and analytics, and publishing for web, iOS, and Android. IT can manage access, review what teams build, and stop a solution centrally when needed.
That governance is not an obstacle to experimentation. It is what makes broader experimentation possible without surrendering organizational oversight.
Lawfront: safe experimentation
James described a fast-moving environment where his team supports several regional law firm brands, each with its own systems and technology history. When he first tried the new Fliplet, he saw two immediate opportunities: a practical way to create a shared prompt library and a governed route for lawyers who were already experimenting with AI-built tools on personal devices.
“It will give me a safe space for my lawyers to build probably what I might refer to as micro apps - small, containerized tools to solve small task-based problems for our lawyers.”
For Lawfront, the appeal was not to turn every lawyer into a developer. It was to give legal engineers and technologists a way to create and test useful tools without adding significantly to an already stretched IT workload. As James put it, "I could control and deploy this without any need for additional IT input, because it's all there within the product."
His innovation team has no conventional software-development background. Its strengths lie in understanding legal processes, engaging lawyers, and translating business problems into requirements. AI allows the team to apply those existing skills directly to software creation.
“For me, it was that simplicity and being able to just enable a team that was already well embedded, understood the business's problems and let them get creative.”
James also saw value beyond individual tools. Lawfront runs design-thinking workshops, hackathons, and ideation sessions. Rapid prototyping gives lawyers something tangible to respond to, making it easier to move from an idea to a deployable solution in a short space of time.
Willkie: more ways to say yes
Stephanie focused on choice. Some larger projects still need developers and a more traditional delivery path. Other requests can be produced conversationally in minutes, without forcing a developer to work against an urgent deadline.
“And literally, I think the first thing we built, we built it in half an hour and it went live. And I was like, 'Ooh, I get to have dinner with my family tonight.' It was great.”
For Stephanie, the operational benefit is having more than one delivery route. "I think that is what is the best part of the new platform for me - I now have choices," she said. Her team can reserve specialist development resources for projects that genuinely require them while enabling non-technical teams to handle smaller, focused needs.
She gave event surveys as a practical example. Willkie's marketing team runs frequent events and regularly needs attendee feedback tools. Instead of placing every survey on the development team's list, Stephanie showed a marketing colleague how to create one directly.
“I showed the marketing team how to build a survey they can build it by themselves all the time. And now they love it. And that's one less thing on my to-do list.”
At Willkie, that flexibility still sits inside a clear permission model. Stephanie's team owns Fliplet Studio and decides who can build and who can publish. A marketing colleague can create a survey, but, as Stephanie explained, "they're not allowed to publish them. They still have to go through me so we can just make sure it's okay."
That balance can help an IT or development team say yes to more requests without giving up its role in review, security, and rollout.
What teams are building
The examples shared at ILTACON showed that vibe coding is moving beyond generic prototypes. Suitable starting points are focused, task-based tools with a clear user, workflow, and owner.

Examples from the session, grouped by team
Attorneys
- Document processors: anti-dilution calculator and LP term analysis.
- Document generators: due diligence reports and investment round documents.
- Calculators: redundancy calculator and capital gains calculator.
- Tools: fee estimator, pitch builder, client portal, and travel approval.
IT and innovation
- Staff onboarding, compliance monitoring, policy acceptance, surveys and dashboards, desk and meeting booking, documentation sites, and a prompt library.
Marketing and events
- Marketing websites, jurisdiction comparison tools, horizon scanning tools, and event websites, registration, and attendee experiences.
The discussion also covered internal dashboards and reporting, data-capture and compliance workflows, integrations with existing firm systems and cloud services, and rapid prototypes for hackathons or stakeholder discussions. These are often point solutions that a central software team may not have time to prioritize, but that still need a professional route into production.
Know where the line is
The speakers were clear that vibe coding is not the right fit for every project. Ian highlighted three areas that may still need a different approach:
- Software with very high complexity.
- Software expected to handle very high load.
- Projects without access to experienced developers when deeper review or support is needed.
Those boundaries will move as AI models, security analysis, audit tooling, and infrastructure improve. For now, human review remains essential. As Ian told the audience:
“I wouldn't suggest anybody in this room blindly trust AI yet.”
The practical question is not only whether AI can generate a working version. Teams also need to know who will test it, approve it, publish it, monitor it, and maintain it.
Eight practical lessons
The session produced eight practical recommendations for firms starting with vibe coding:
- Start with focused problems. Small, task-based solutions are easier to validate, govern, and maintain.
- Begin with high-level requirements. Give the AI room to propose a plan before constraining every detail.
- Prototype early and iterate. A working version improves stakeholder conversations and reveals incorrect assumptions quickly.
- Be willing to restart. When an initial version is inexpensive to create, abandoning the wrong direction is less costly than forcing it to work.
- Ask AI to explain and repair its work. Users can request explanations, fixes, and structural improvements in plain language.
- Match access to the user and the risk. Creation, publishing, integrations, and administration do not need to be granted equally.
- Keep human accountability. Lawyers must validate legal logic and outputs, while IT, information-security, and development specialists review higher-risk solutions.
- Use audit features before publishing. Check vulnerabilities, security concerns, and relevant privacy requirements.
From prototype to production
Vibe coding changes who can participate in software creation. It does not remove the need for governance, technical judgment, or operational ownership.
For law firms, the useful model is a shared environment where lawyers and business-services teams can explore ideas, specialists can support them, and IT retains control over security and release. Firms do not have to choose between innovation and control. With the right guardrails, they can distribute software creation to the people who understand the problems best while allowing scarce technology teams to concentrate on the work where their expertise adds the greatest value.
Explore the wider principles in our guides to vibe coding for business, enterprise vibe coding, and AI software for law firms.
Session speakers

Stephanie Lopez
Senior Manager, UI/UX Development, Willkie Farr & Gallagher

James Grice
Head of Innovation & AI, Lawfront

Ian Broom
CEO, Fliplet
About Fliplet
Fliplet is an enterprise AI software builder that helps teams move from prompt to production. Business users and technical teams can create, review, publish, and maintain secure business software in one governed platform, with support for integrations, SSO, data, audit controls, and web and mobile distribution.


