A large share of legal AI products are interfaces over models somebody else operates. That is not disqualifying — but you should know, and know who.
Start a conversation with the AI Adoption Concierge, already scoped to vendor diligence & contracts. Pick a starting point, or describe your situation directly.
Diligencing an AI vendor is largely conventional supplier diligence with two additions: the model supply chain, and the unusual pace of change in the market. The supply chain matters because a great many products are built on foundation models operated by a third party, which means the firm's material may reach a company it has never evaluated, under terms it has never seen. The pace matters because vendors in this market are acquired, repriced and repositioned quickly, and the terms a firm agreed to can change hands. Neither is a reason to avoid smaller vendors — it is a reason to ask specific questions and to get the answers into the contract rather than the proposal.
Standard supplier diligence, plus the two questions specific to this market.
Whose models, operated by whom, under what terms — and whether the firm's data reaches them.
Independent assessment, encryption, access controls, breach history and notification commitments.
Whether matter-level restrictions and ethical walls are honoured inside the product, tested rather than asserted.
What the vendor carries and what it will stand behind, which is often much less than assumed.
What happens on acquisition, shutdown or a material change of terms, in a market that moves fast.
Data export in a usable format, deletion, and confirmation — agreed before signing, not at termination.
How the diligence is run.
Mostly against discovering the answer to one of these questions after an incident.
Many legal AI products are interfaces over foundation models operated by another company. The firm's material may therefore reach a party it never evaluated, on terms it never read. Ask directly, and ask what governs that leg.
Four, in order. Whose models do you use and where do they run. May our inputs be used for training, by you or by them. Who else touches the data, and will you notify us before that list changes. And what happens to our data if you are acquired or cease trading. Those four separate serious providers from thin ones faster than any security questionnaire, partly because a vendor that answers them crisply has plainly been asked before by customers who knew what they were doing.
Most firms handling client-confidential material do insist on it for that material, and many vendors offer it as standard on business tiers precisely because the demand is universal. Where it becomes a negotiation is with smaller vendors whose economics assume improvement from usage. The firm's realistic options are to obtain the commitment contractually, to restrict the tool to non-confidential work, or not to proceed — and being clear internally about which of those has been chosen matters more than the choice itself.
The same questions, with proportionate depth, and one extra consideration. Smaller vendors are frequently more responsive, more willing to contract on the firm's terms, and better at the specific task. What they carry is continuity risk: less insurance, more acquisition exposure, and a shorter runway. That argues for exit terms that actually work — usable data export, tested rather than assumed — rather than for avoiding smaller vendors, who are often the better product.
Increasingly, and often in more detail than firms expect. Institutional clients have begun including AI questions in panel processes, outside counsel guidelines and security questionnaires — covering which tools are used, what happens to their data, whether training is permitted, and what the firm's verification process is. Firms that have done the diligence answer in an afternoon. Firms that have not spend a fortnight assembling it under a deadline, and the quality of the answer shows.
Describe the vendor and what you are considering. The Institute will help you build the question set.