home  /  automation & building  /  connecting systems
automation · ai for legal practice

Connecting what you already own.

The highest-leverage AI development of 2026 for most firms was not a model. It was a connection standard.

begin here

Where is your firm?

Start a conversation with the AI Adoption Concierge, already scoped to connecting systems. Pick a starting point, or describe your situation directly.

AI Adoption Conciergeconnecting systems · orientation, not legal or ethics advice
Tell me what document and practice management systems you run. I'll help you work out what can connect today and what to check first. Permissions and ethical walls come before capability.

For most of the generative AI era, getting a model to work with a firm's own systems meant a bespoke integration for every pairing — a project with a budget, a vendor and a maintenance burden. That changed materially through 2025 and 2026. A connection standard open-sourced in late 2024 was donated to a neutral foundation in December 2025 with backing from the major cloud and model providers, and during 2026 both dominant law-firm document management systems shipped support for it, alongside legal research providers and a free body of court data. The practical result is that a firm can point an AI tool at its own governed repository without commissioning anything, and that the connection inherits the permissions already in place. The caution is the mirror image: a connected agent can be given the ability to act, and that changes the risk profile entirely.

mechanisms

What changed, and what to check.

The capability is real. The due diligence underneath it is where firms come unstuck.

A standard rather than a project

One connection per system rather than one per system-and-tool pair — which is what makes the investment survive a change of AI vendor.

Document systems opened up

Both dominant law-firm DMS platforms shipped support during 2026, with the vendors stressing that permissions and ethical walls are preserved and content stays in place.

Research and court data

Major research providers and a free court-opinion corpus became reachable the same way, which lowers the cost of a research workflow considerably.

Connector depth varies enormously

"Integrates with" spans a full API and a single trigger. Verified counts across legal practice management systems differ by more than an order of magnitude.

Tool access is a security decision

A connected agent that can read, send and write is a different risk object from a chatbot. Read-only defaults exist for a reason.

The audit trail question

Whether a connected client receives raw documents or AI-shaped representations of them, and whether the firm can produce an end-to-end record, is genuinely unresolved.

methodology

What the evidence shows — and what we examine.

How to approach a connection project.

Verify the specific triggers you needBefore designing anything. Vendor marketing claims of integration have not survived checking in several cases.
Read-only firstRetrieval before action. Write access is a separate decision with a separate approval.
Confirm permissions are enforced at retrievalAsk the vendor to demonstrate it against a genuinely walled matter, not to assert it on a web page.
Pin and allow-list connectorsTreat a connector update as a change requiring review. A previously clean component can be updated maliciously.
what's at stake

What connection changes.

It converts AI from something that reads what you paste into something that reads what you have.

access to the firm's own knowledge the cost of a research or drafting workflow whether ethical walls hold at the AI layer portability between AI vendors the blast radius if an agent is misdirected what the audit trail can show

A community connector holds real keys.

Where no official connector exists for a system, community-built ones frequently do — and connecting one means handing it credentials to that system. A malicious package published to a public registry in 2025 silently copied every email it sent. Treat an unofficial connector to your practice management system as you would any third party with full data access: read the code, or do not run it.

common questions

Connecting systems — practical questions.

How do I know if my practice management system really integrates?

Check the specific operations you need, not the marketing page. Verified comparisons across legal practice management platforms found enormous variation behind identical "integrates with" language — some systems expose a rich set of triggers, actions and lookups; at least one exposes a single trigger; another offers no lookup operations at all, which means a workflow cannot check whether a record already exists before creating one. Several vendors marketed as integrated turned out to have no first-party connector. Fifteen minutes on the actual integration listing before designing a workflow saves a project.

Does connecting AI to our document system break ethical walls?

It should not, and the vendors have designed against exactly this — the DMS connectors shipped in 2026 emphasise that an AI tool can only retrieve what the authorising person could access, with existing screens and audit logging preserved. Two cautions remain. First, ask for a demonstration against a real walled matter rather than accepting the assertion; independent audit of these claims does not exist. Second, the more common failure is not the connector at all but pre-existing over-permissioning in the document estate — material nobody would ever have browsed, which an assistant will now surface in a summary.

What is the risk of giving an agent tool access?

It converts a bad output into a bad action. A model that can only produce text is limited to being wrong; a model that can send, file, write or pay is capable of doing something irreversible on the strength of being wrong — including on the strength of instructions hidden in a document it was asked to read. The controls are proportionate rather than exotic: read-only by default, write scopes granted narrowly and per-purpose, and a human confirmation gate in front of anything that files, sends, signs, pays or deletes.

Does this lock us in or free us up?

On balance it frees you up, which is the strategic argument for preferring standardised connections to bespoke ones. A bespoke integration between one AI vendor and your DMS is an asset that dies when you change either. A standardised connection is closer to plumbing — the same server serves whatever tool you point at it, so switching AI vendors becomes a procurement decision rather than a rebuild. That is also why the standard being governed by a neutral foundation rather than a single vendor matters more than it sounds.

related

Related specialization areas & resources.

Want your AI to see what you already have?

Tell the Institute what systems you run. We will help you work out what can connect and what it takes.

AI adoption conciergeorientation · not legal or ethics advice
Tell me what document and practice management systems you run. I'll help you work out what can connect today and what to check first. Permissions and ethical walls come before capability.