Services AI Audit Guides Marketplace Blog Contact
Regulated sectors

AI in a law firm without sending files anywhere.

The value of AI in legal work is obvious — summarising, searching, drafting, reviewing. The obstacle is equally obvious: the material is privileged, and sending it to a third party raises questions that a good privacy policy does not fully answer. Running the model in the firm removes the question rather than managing it.

This page is about technology, not professional obligations. Confidentiality duties, privilege and the rules of your law society or bar govern what you may do, and they differ by jurisdiction. Resolve those first; the technical options below only matter afterwards.

Where AI genuinely helps in practice

Why local matters more here than elsewhere

Privilege is not a privacy preference; it is a legal status that can be affected by disclosure to third parties. Whether and how transmitting material to a service provider affects privilege is a question for your jurisdiction and your regulator — but a system where nothing is transmitted does not raise it at all.

There is also a client-relations dimension. "Our AI runs on our own servers and your file never leaves this firm" is a sentence clients understand immediately, and increasingly one that sophisticated clients ask for before it is offered.

What a firm setup looks like

1
A machine in the firm with enough memory to run a capable model — see hardware requirements.
2
A private index over your own documents, so the model answers from your material rather than from general knowledge.
3
Access control tied to matter permissions. The system must not let anyone query files they could not otherwise open — this is the requirement most commonly overlooked, and the one most likely to cause an incident.
4
An audit log. Who asked what, and when. Both for supervision and for the conversation with your regulator.
5
A written policy on what may be used with external AI tools, so the sanctioned system is the easy path rather than the obstacle.

The honest limitation

Local models are good at summarising, searching and drafting. They are not as strong as frontier cloud models at the hardest analytical reasoning, and none of them — local or cloud — should be trusted to state the law without verification. They produce fluent, confident text whether or not it is correct.

The realistic value is in the hours returned on reading, searching and first drafts, with a lawyer reviewing everything. Any vendor promising more than that is selling something you should not buy.

Common questions

Can law firms use AI on privileged material?

That depends on your jurisdiction, your regulator and your engagement terms, and it is a question for professional advice rather than a technology vendor. What is clear is that a system where material never leaves the firm avoids the disclosure question entirely, which is why local deployment is the common answer where the analysis is uncertain.

Is a local model good enough for legal work?

For summarising, searching precedents, extracting structured information and producing first drafts — yes, with review. For complex analytical reasoning, frontier cloud models are stronger. No model of either kind should be relied on for legal conclusions without a lawyer verifying them; fluency is not accuracy.

What does it cost to set up?

Hardware capable of running a good model sits in the mid four figures, plus the work of indexing your documents and configuring access control properly. The access control and audit layer is usually the larger part of the project, and the part it is unwise to economise on.

How do we stop staff using consumer AI tools instead?

By making the sanctioned system genuinely easier to use than the alternative. Prohibition alone fails — the tools are useful and deadlines are real. A local system that is fast and integrated into how people already work removes the temptation far more reliably than a policy document.

Keep reading
AI and your business data Running AI locally Private AI for accountants

AI that runs
on your terms.

Private AI systems in environments you control — your data never trains public models, and engagements are available under NDA.

Private AI systems Book a free audit