One category in this list is worth buying almost regardless of firm size. Several are not yet worth buying at all.
Start a conversation with the AI Adoption Concierge, already scoped to defending the firm. Pick a starting point, or describe your situation directly.
Defensive security AI is the part of this field where vendor claims and independent measurement diverge most sharply, and a firm making a purchase decision from marketing material will spend badly. The category that consistently justifies itself is behavioural email security, because it detects something a traditional filter structurally cannot: a plain-text message, from a genuinely compromised counterparty mailbox, inside a real reply thread, asking to change payment instructions. There is no attachment, no link and no known-bad indicator to catch. Beyond that the picture is mixed. Independent surveys of autonomous security operations tooling measure improvements roughly a third the size of what vendors advertise, and the largest randomised trial ever run on phishing simulation training found an effect of about two percentage points.
Ordered by how well the evidence supports the spend.
Baselines who normally emails whom, about what, and flags the deviation. The one category that catches the attack that drains trust accounts.
Bulk access, personal cloud sync and mass printing in the weeks before a resignation — a pattern behavioural tooling models well, and one the legal sector has more of than most.
Blocking sensitive content being pasted into third-party AI sites. Effective on managed devices, blind to personal phones.
Unglamorous and free. Prioritising by likelihood of exploitation rather than severity score is the highest-leverage change most small IT teams can make.
For most firms the managed service with 24/7 humans matters more than the model behind it.
Real products, genuinely early. Independent measurement sits far below vendor claims and adoption in legal is not yet reported.
How to buy in this category without being sold to.
And what it does not — no defensive tool covers the confidentiality decision you make at procurement.
Cyber applications increasingly ask which AI tools the firm uses, whether there is a written policy, and who reviews AI-assisted work. The application is a representation. Insurers have denied claims where an insured attested to controls — multi-factor authentication being the canonical example — that were not in fact in place. Treat the AI questions with the same care.
The evidence is weaker than the industry assumes. The largest randomised trial run on the question — ten campaigns over eight months across roughly 19,500 employees, published at a major security conference in 2025 — found embedded training reduced click-through by about two percentage points, found most recipients engaged with the training for under a minute, and found no significant relationship between completing mandated annual training and phishing resistance. The researchers recommended redirecting spend toward phishing-resistant authentication. The defensible reasons to still buy it are that it generates reporting behaviour, which gives the security team early signal, and that insurers credit it. Buy it cheaply, and never treat a low simulated-failure rate as evidence of anything.
For firms below several hundred seats, generally not yet. Vendors in this category advertise improvements in the range of 85 to 98 percent; the best independent survey found an average investigation-time reduction of roughly a third, with a minority exceeding fifty percent, and reported that a large share of organisations attempting internal builds abandoned or replaced them. Analyst positioning through 2026 placed the category at early maturity with low single-digit market penetration. The practical read is that a managed detection service with real humans is a better purchase than an autonomous tool nobody has time to supervise.
More than firms expect. Writing and enforcing the wire-verification protocol costs nothing and addresses the highest-consequence attack. Prioritising patching by likelihood of exploitation rather than by severity score uses a freely published scoring system. Enabling multi-factor authentication everywhere is usually already licensed. Auditing which AI tier each lawyer is actually on costs an afternoon. And firms on a bundled enterprise licence commonly already own insider-risk, data-loss prevention and AI-usage monitoring capability that has never been switched on.
From a register rather than from memory, because the honest answer includes AI features silently enabled inside tools the firm already licenses. The questions that recur are which AI systems touch the client's data, what the retention and training posture is on each, who reviews output, and what the firm's policy says. A firm that maintains a current inventory can answer in an afternoon; a firm answering from recollection will answer incompletely and, if the client checks, wrongly. There is no legal-industry standard questionnaire — firms are borrowing general frameworks.
Describe the firm and what you already own. The Institute will help you work out what is missing.