Read the terms before the demo. A remarkable number of evaluations end there, and the ones that do not usually should have.
Start a conversation with the AI Adoption Concierge, already scoped to client data & training. Pick a starting point, or describe your situation directly.
The question is narrow and consequential: what does this vendor's agreement permit them to do with what the firm puts in. Retention, training, human review, subprocessing and jurisdiction are the dimensions that matter, and they vary enormously — between vendors, between tiers of the same vendor, and between the marketing page and the contract. The reason this belongs at the very start of an evaluation is that it is dispositive in a way capability is not: a tool that may train on inputs is unusable for client-confidential work regardless of how good it is, so evaluating capability first wastes the time of everyone involved.
Six questions. The answers should come from the agreement, not from a salesperson.
May inputs be used to improve models. The threshold question, and the one most likely to disqualify.
How long inputs and outputs are kept, and whether deletion is available and verifiable.
Whether vendor staff may read submissions, for abuse monitoring or quality, and under what controls.
Who else touches the data — model providers, infrastructure, moderation — and under what terms.
Where data is processed and stored, which may matter contractually and for some clients absolutely.
What happens on exit: deletion, export, and how long anything survives the relationship.
How firms handle it in practice.
This is the duty most easily engaged, by an action that feels routine.
The same vendor frequently offers consumer terms that permit training and enterprise terms that do not. "We already use this" is not an answer to the question — which agreement governs the firm's use is.
It helps and it is weaker protection than it feels. Removing names and identifiers reduces exposure, but legal documents are frequently identifiable from their facts alone — a dispute between two parties over a distinctive transaction does not become anonymous because the names are removed. Redaction also has to be done reliably every time by busy people, which is a control that degrades under deadline. It is a reasonable supplementary measure and a poor primary one.
The question is the same and firms frequently miss it, because an AI feature arriving inside an existing product does not feel like adopting an AI tool. Document management systems, practice management platforms, email and research services have all added AI capabilities, sometimes enabled by default, sometimes under terms that differ from the base product. The practical step is an inventory of what has AI features and what governs them — most firms doing this for the first time find at least one they did not know about.
For most firms handling personal data the answer is generally yes as a matter of data protection law, quite separately from professional confidentiality obligations — and the two are distinct analyses that firms sometimes conflate. What the DPA should address is the same list that matters for confidentiality: purpose limitation, retention, subprocessors, security, international transfers, and deletion on termination. This is a question for the firm's own counsel, and it applies regardless of what the confidentiality analysis concludes.
Carefully, and it is the case most often overlooked. Litigation files contain documents produced by opponents under protective orders, personal data about people who are not clients, and material subject to confidentiality undertakings the firm has given. Client consent does not reach any of that. Protective orders in particular may restrict disclosure to third parties in terms that a vendor's system plainly engages, and firms have generally treated material under a protective order as requiring separate analysis rather than falling under a general AI policy.
Describe the tools in use. The Institute will help you work through the questions.