That combination is why firms are targeted disproportionately — and why AI changed the economics of attacking one.
Start a conversation with the AI Adoption Concierge, already scoped to security & threats. Choose the question closest to yours, or describe your situation directly.
Most security material written for law firms is generic material with the word "law firm" inserted. The specific exposure is narrower and worse than that. A firm holds client funds in trust and holds pre-announcement commercial secrets for dozens of better-defended organisations, which makes it a concentrated target rather than an incidental one — a point federal advisories aimed at the legal sector have made explicitly. AI has changed three things about that: it made convincing impersonation cheap enough to use against every firm rather than the largest ones; it introduced a genuinely new attack that arrives inside documents lawyers are professionally obliged to read; and it created a category of confidentiality exposure that produces no alert, no ransom note and no moment of discovery. The controls that address the worst of it are unglamorous and mostly free.
What is being used against firms, what defends them, and how to deploy AI without creating the exposure you were trying to avoid.
Deepfake wire fraud, impersonation of the firm's own IT, and instructions hidden inside documents you are obliged to read.
investigateWhere defensive AI genuinely earns its cost, and where the independent measurement is far below the marketing.
investigateThe tier you buy is a confidentiality decision, and it is usually made by whoever expensed the subscription.
investigateHow the Institute approaches security here — evidence over vendor claims.
Write down a wire-verification protocol and enforce it. Callback to a number from the firm's own records — never a number supplied in the request — a mandatory hold on any change to payment instructions, and explicit written authority for any member of staff to delay a transfer to verify without being second-guessed. It costs nothing, and it defeats the attack that has the largest single-event consequence for a firm. Federal reporting on wire fraud in real-estate closings includes matters where the fraudulent instruction impersonated the buyers' own attorneys.
No such case could be found in the public record as of September 2026. That is worth saying plainly, and worth not over-reading. Three explanations fit equally well: enterprise-tier deployments have held; it has happened and firms have strong incentives not to disclose a confidentiality failure; or it is happening through unsanctioned consumer-tool use, which produces no alert and no moment of discovery. The absence of a named cautionary case is the main reason firm leadership underweights this, and it is not evidence of safety.
Attackers, at the margin, because the gains are asymmetric. Controlled research found AI-generated spear-phishing matched a skilled human operator's success rate at a fraction of the cost — which does not make it better than expert phishing, it makes expert-quality phishing affordable against every employee of every firm. On the defensive side, independent measurement of AI security tooling has consistently come in far below vendor claims. The honest position is that AI has raised attack volume and quality more than it has raised defensive capability, and that most of the useful defensive AI is in email security rather than anywhere more exciting.
Partly, and the parts that do not are the ones that get missed. Deciding which AI tier the firm buys is a confidentiality decision with a procurement mechanism. Deciding whether an agent may act on a matter is a supervision question. Deciding what happens in the first hour after an incident is a professional-responsibility question. Firms that delegate the whole area to IT tend to end up with good endpoint protection and an unanswered question about what their lawyers are pasting into a chatbot on a personal phone.
Describe the firm and how AI is being used today. The Institute will help you find the gaps that matter.