Competence includes tool choice
Professional responsibility rules do not name every product. They do require competence, confidentiality, and reasonable safeguards. Putting client facts into an AI service is a custody decision.
As bar associations, malpractice carriers, and clients ask sharper questions about AI use, firms that cannot show where data went will look reckless next to peers who can.
- Confidentiality: data leaving the firm boundary expands the risk set.
- Competence: associates using unapproved tools create an unmanaged data flow.
- Supervision: partners remain responsible for how junior lawyers work.
Why enterprise agreements are not enough for many matters
Contractual promises not to train on your data are better than nothing. They still leave data on someone else's infrastructure, subject to their breach surface, subprocessors, and legal process.
For high-stakes litigation, M&A, and regulated industries, many clients will expect a private or dedicated path with a documented custody boundary.
Make the deployment explainable to clients
Private retrieval systems running on controlled hardware can keep privilege-sensitive material inside a documented custody boundary, with access logs and source citations. A firm can explain that model to a client or court.
- Source-grounded answers with document citations
- Role-based access by matter and seniority
- Query audit trails for compliance review
Review an explainable legal AI plan
We can map the custody, access, source, and supervision requirements for one workflow.
Discuss Legal AI Governance