The value of AI in legal work is obvious — summarising, searching, drafting, reviewing. The obstacle is equally obvious: the material is privileged, and sending it to a third party raises questions that a good privacy policy does not fully answer. Running the model in the firm removes the question rather than managing it.
Privilege is not a privacy preference; it is a legal status that can be affected by disclosure to third parties. Whether and how transmitting material to a service provider affects privilege is a question for your jurisdiction and your regulator — but a system where nothing is transmitted does not raise it at all.
There is also a client-relations dimension. "Our AI runs on our own servers and your file never leaves this firm" is a sentence clients understand immediately, and increasingly one that sophisticated clients ask for before it is offered.
Local models are good at summarising, searching and drafting. They are not as strong as frontier cloud models at the hardest analytical reasoning, and none of them — local or cloud — should be trusted to state the law without verification. They produce fluent, confident text whether or not it is correct.
The realistic value is in the hours returned on reading, searching and first drafts, with a lawyer reviewing everything. Any vendor promising more than that is selling something you should not buy.
That depends on your jurisdiction, your regulator and your engagement terms, and it is a question for professional advice rather than a technology vendor. What is clear is that a system where material never leaves the firm avoids the disclosure question entirely, which is why local deployment is the common answer where the analysis is uncertain.
For summarising, searching precedents, extracting structured information and producing first drafts — yes, with review. For complex analytical reasoning, frontier cloud models are stronger. No model of either kind should be relied on for legal conclusions without a lawyer verifying them; fluency is not accuracy.
Hardware capable of running a good model sits in the mid four figures, plus the work of indexing your documents and configuring access control properly. The access control and audit layer is usually the larger part of the project, and the part it is unwise to economise on.
By making the sanctioned system genuinely easier to use than the alternative. Prohibition alone fails — the tools are useful and deadlines are real. A local system that is fast and integrated into how people already work removes the temptation far more reliably than a policy document.
Private AI systems in environments you control — your data never trains public models, and engagements are available under NDA.