Sector

AI consultancy for legal & professional services

Privilege and client confidentiality make hosted AI a difficult conversation with your risk partner. Private retrieval over your own matter files keeps the material inside the firm.

The constraint

Why law firms stall on AI

The material that would make AI genuinely valuable in a law firm (matter files, advice, correspondence, precedents) is exactly the material that is privileged, confidential, and in many cases subject to client-imposed restrictions on where it may be processed.

Sending that to a third-party API is a conversation most risk partners will end quickly, and reasonably so. The question is not whether the vendor is trustworthy; it is whether the firm can characterise and control the processing well enough to satisfy its duties to clients who did not consent to it.

Meanwhile the pressure is real: clients are asking what the firm is doing with AI, and increasingly asking in tenders. Doing nothing has become a competitive position rather than a neutral one.

Where it works

What actually earns its place here

Ordered roughly by how quickly they get approved. The first item on this list is usually the right first project, precisely because it is the least contentious.

01

Precedent and know-how retrieval

Finding the firm’s own prior work (clauses, advice, arguments) with citation to the source document. Frequently the highest-value first build, because the knowledge already exists and is simply unfindable.

02

Document review support

First-pass classification and issue spotting across disclosure or due diligence sets, prioritising human attention rather than replacing it.

03

Drafting against house style

First drafts from structured inputs and firm precedents, for fee earner review. The value is in the blank page, not the final document.

04

Matter intake and conflicts support

Extraction and structuring of intake information, surfacing potential issues for the conflicts team to assess.

The gate

What your assurance function will ask for

We build so that this evidence is a by-product of delivery rather than a document assembled under pressure afterwards. It is markedly cheaper that way, and considerably more likely to be accurate.

  • Processing entirely within the firm’s boundary, documented and demonstrable
  • Matter-level access control enforced at query time, not after retrieval
  • A written position on privilege and confidentiality for client and insurer questions
  • Retention and logging policy covering prompts and outputs as well as documents
  • Supervision arrangements consistent with SRA expectations
  • Answers ready for the AI section of client tenders and outside counsel guidelines

Illustrative scenario: a composite example of how an engagement typically runs, not a specific client.

Illustrative: a commercial firm’s know-how project

A firm wants fee earners to find the firm’s own prior advice and precedent clauses without asking three partners who might remember. The corpus is entirely privileged, and several clients have contractual restrictions on offshore processing.

That constraint decides the architecture immediately: self-hosted, inside the firm’s network, with no component that reaches an external API, including the embedding step, which is the one teams routinely overlook when they carefully self-host inference and then send the whole corpus to a hosted embedding service.

The critical design decision is matter-level access control resolved per user at query time. Without it the system will eventually surface one client’s material to a fee earner on the other side, which is not a bug to be fixed later but a professional obligation breached once.

The firm gets a written processing position it can hand to clients and to its insurer, which turns out to have commercial value in tenders beyond its compliance function.

Questions from this sector

Does using AI on client files waive privilege?

That is a question for the firm’s own risk and compliance advice, and it turns on the specifics of the processing. What we can say is that firms who are comfortable proceeding are generally those who can demonstrate the material never left their control, which is an architectural property, established by design rather than asserted afterwards.

Our clients ask about AI in tenders. What do they want to see?

Increasingly specific things: where processing occurs, whether their material is used for training, who can access it, what is retained and for how long, and what supervision applies to AI-assisted work. A firm with written answers has a real advantage over one that has to draft them under deadline for each tender.

Can this work if we cannot use any external service at all?

Yes. Fully self-hosted deployment, including the embedding model, with nothing crossing the firm’s perimeter is entirely achievable, and for firms with strict client restrictions it is the correct answer rather than an expensive over-reaction.

Start with a straight answer

A 30-minute call, no pitch deck. Tell us what you are trying to do and we will tell you whether AI is the right tool, what it would take, and what it would cost, or that you should not bother.