Skip to content
Kapitel 30/30

After You Buy: Rolling AI Into a Firm Without Breaking Privilege

Every chapter before this one teaches a lawyer to use AI. This one teaches a firm to deploy it: two duties most firms conflate, four policies signed before seat one, redaction before prompting, a verification gate before filing, and a pilot you can measure. Buying the tool was the easy part.

CHAPTER 30of 30After You Buy: Rolling AIInto a Firm WithoutBreaking Privilege
  • Lesezeit: 12 min

Was dieses Kapitel behandelt

  1. Two Duties, Not One
  2. Four Policies Before Seat One
  3. Redact Before You Prompt
  4. The Verification Gate
  5. The Rollout
  6. What Good Looks Like at 90 Days

Die Kurskapitel sind auf Englisch verfasst. Der Rest der Academy ist übersetzt.

TL;DR

Every chapter before this one teaches a lawyer to use AI. This one teaches a firm to deploy it. The licence was the easy part. The work is two duties most firms conflate, four short policies signed before the first lawyer logs in, redaction before every prompt, a verification gate before anything leaves the firm, and a pilot you can measure. Skip those and usage decays within a quarter, or worse, privilege goes with it.

1) Two duties, and why most firms only know about one

Ask a partner why the firm cannot paste a client's contract into a chat tool and you will usually get one answer: confidentiality. That is half of it. Two duties are in play, they are owed to different people, and they fail in different ways.

Confidentiality is owed to the client. It is the professional duty covered in Privilege & Confidentiality with AI: what you may disclose, to whom, and what happens to privilege the moment a third party sees the material.

Data protection and residency are owed to the law. They constrain where the data may physically sit and under which regime it is processed, whatever the client would be happy with. In the DIFC, Regulation 10 on personal data processed through autonomous and semi-autonomous systems was enacted in September 2023 and has been in full enforcement since 1 January 2026. The ADGM has its own regime with the same shape.

Conflating the two produces both failure modes at once. The lawyer who uploads nothing gets no value and reports that the tool does not work. The lawyer who uploads everything has no idea which duty was just breached, because the two were never separated in the first place. A vendor's anonymization feature answers part of the first duty. It cannot answer the second: a document with the names removed still sits on a server somewhere, and the law cares where.

2) Four policies before seat one

A licence is not a deployment. Before the first lawyer logs in, the firm needs four short written policies. Each has an owner, a signatory, and a price for skipping it.

  1. 1. Confidentiality policy

    Owned by the partner responsible for professional conduct.

    What may be shared with a third-party system, at which tier of sensitivity, and who decides. The anchor is US v. Heppner (SDNY, Judge Rakoff, written opinion 17 February 2026): documents generated with a free-tier consumer AI product were held not privileged and not work product. The court left an opening for AI use directed by counsel, which is exactly what a written policy establishes. The case is covered in AI conversations are not privileged. Cost of skipping it: a client's material produced in discovery by the other side.

  2. 2. Data policy

    Owned by whoever is accountable for data protection: the DPO where one exists, otherwise the managing partner.

    Where client data may sit, in which jurisdictions, with which approved vendors, for how long, and what happens on termination. In the DIFC, Regulation 10 has been in full enforcement since 1 January 2026, so this is no longer a policy a firm can defer. Run each vendor's answers through the GDPR Compliance Checklist and the red flags in How to Evaluate a Legal AI Vendor. Cost of skipping it: a regulatory finding that no amount of client consent can cure.

  3. 3. Verification policy

    Owned by the supervising lawyer on each matter.

    Every authority is opened and read by a named person before it is cited. Every quotation is checked against the source document, not against the tool's summary of it. A named lawyer signs before anything is filed or sent, and the signature means they did the reading. This is the load-bearing policy; section 4 says why.

  4. 4. AI use policy

    Owned by firm management.

    Which tools are approved, for which categories of work, what is logged, and how a lawyer records that AI was used on a matter. Cost of skipping it: the opening Heppner left for use directed by counsel closes, because use that nobody directed is use the firm cannot defend.

3) Redact before you prompt

The confidentiality policy will say that some material may only go into a tool once identifying details are removed. How you remove them changes the answer you get back.

The default is to swap every name for one generic label, [CLIENT] or [COMPANY], or to black it out. A September 2026 study (Deußer et al., arXiv 2609.11335) tested five anonymization techniques on reasoning and retrieval benchmarks and found that generalization, turning a specific name into a category label, and redaction consistently produced the largest drops in model performance. Placeholders that keep each entity distinct, [LENDER-1], [LENDER-2], [BORROWER-1], did best. The study tested no legal task, so applying it to contracts is our inference, and we say so. The mechanism is plain enough: a facility agreement with a borrower, two lenders and an agent bank collapses into one party the moment all four become [COMPANY], and the model can no longer tell who owes what to whom.

Three rules for the policy. Placeholders are typed and consistent across the whole document. Metadata is stripped as a separate, explicit step. The mapping between placeholder and real name is kept somewhere the document is not. The full argument, with the public redaction failures that make the case, is in Stop writing [CLIENT]. The free Redact before you prompt tool applies typed, consistent placeholders in the browser and nothing leaves it. It suggests; the lawyer confirms. It runs on rules, not a model, so it will miss things, and the confirm step is part of the design rather than a fallback.

4) The verification gate

Courts have not asked AI to be right. They have asked the lawyer to have personally read and verified what was filed. That is the whole standard, and it is older than the technology.

In December 2025 the ADGM Court of First Instance ordered indemnity costs of AED 282,508 against a law firm whose pleadings contained AI hallucinations (Arabyads Holding v Gulrez Alam Marghoob Alam, Justice Paul Heath KC). The ABA's Formal Opinion 512 (July 2024) says the same thing in the language of professional conduct: competence, confidentiality, supervision and candour to the tribunal all apply to AI-assisted work. The running count of sanctions cases worldwide is on our hallucination tracker; it moves every week, which is the point.

The gate itself is short. Every authority is opened and read by a named person before it is cited. Every quotation is checked against the source, not against the tool's summary of it. A named lawyer signs before anything leaves the firm, and the signature means they did the reading. The habit is Correctness Over Confidence; the policy is what makes the habit survive a busy week.

5) The rollout

The numbers say most firms skip this part. Three surveys, dated, side by side:

  • 8am's 2026 Legal Industry Report (1,300+ respondents, fielded September to October 2025): fewer than half of firms provide training on responsible use, while 61% of respondents say AI saves them time every week. Usage is running ahead of training.
  • Thomson Reuters, April 2025, close to 1,800 professionals across legal, tax, accounting, corporate risk and government: among the corporate professionals, 64% had not been trained to use generative AI for their work. That population is wider than law firms.
  • Axiom's 2026 Legal AI Survey (528 in-house leaders, published 29 June 2026): 7% had scaled AI organisation-wide, and 83% could not say whether last year's AI spend had paid for itself.

Three populations, three dates, one shape: the tool arrives and the operating manual does not. A rollout that avoids it has three parts.

A pilot group, not a firm-wide licence. A small group across two practice areas, with one partner who wants it to work and one who does not. The sceptic's objections are the training material.

A live matter, not a demo NDA. Every tool passes a generic NDA, so a generic NDA tells you nothing. Put the pilot on a real, current matter, redacted per section 3, with the verification gate from section 4 switched on from day one.

Define the number before you buy. Axiom found 83% cannot answer the ROI question. A number nobody defined before signing is a number nobody can measure afterwards. Pick two: hours to first draft on a defined document type, review turnaround, citation errors caught at the gate, or the share of matters where the tool was used at all. Measure them the week before the pilot and the week after. Practitioner-Led Benchmarks covers how to score a tool on your own work rather than on the vendor's demo.

6) What good looks like at 90 days

  • The four policies are signed, dated and in the onboarding pack. A new joiner reads them before the first login.
  • The pilot has run on real matters, redacted, with the two numbers you chose measured before and after.
  • Every lawyer using the tool can say which tier of material goes in, which does not, and what the redaction step is.
  • The verification gate has caught at least one thing, and the catch was logged rather than hidden. A gate that has caught nothing is a gate nobody is using.
  • The renewal decision is made on the measured numbers, not on the vendor's usage dashboard.
  • Nothing depends on a single enthusiast. If the partner who championed the rollout leaves, the policies and the pilot record stay.

Practitioner rule

Buying the tool is the easy part. Before seat one: four policies, signed. Before every prompt: redact, with typed placeholders. Before anything leaves the firm: a named person has read every authority. Before renewal: the two numbers you chose in advance. The long-form version, with the survey data and the case law, is Buying the tool is the easy part.