The most consequential security decision most firms make about AI is a procurement decision nobody treated as one.
Start a conversation with the AI Adoption Concierge, already scoped to secure deployment. Pick a starting point, or describe your situation directly.
The distinction between a consumer AI subscription and an enterprise one is contractual rather than technical, and it is the control that matters most. On consumer tiers, training on submitted content is commonly opt-out rather than off by default, and the administrative apparatus a firm needs — single sign-on, audit logging, retention control, a compliance interface — does not exist at all. This produces a result that surprises people: a partner personally expensing a premium consumer subscription may have materially fewer protections than the same firm's cheaper business workspace. A well-publicised US preservation order made the point concretely, capturing several consumer and mid tiers while exempting enterprise and zero-retention arrangements. Deployment security is mostly about getting three things right before anyone logs in: the tier, the retention setting, and the permissions the tool will inherit.
Ordered by how much difference each makes, which is not the order firms address them.
Contractual, not technical. Training posture, retention control and the entire administrative layer turn on it. The single highest-leverage decision.
Defaults differ by vendor and at least one major provider's commercial default is indefinite until a window is set. Set it explicitly rather than inheriting it.
AI does not grant new access — it removes obscurity as a de facto control. Over-permissioned documents nobody browsed will now be surfaced in answers.
A screen enforced in the document system but not in the AI layer is not a screen. Ask vendors to demonstrate it against a real walled matter.
AI conversations are retained business records subject to retention policy and legal hold, and are searchable by discovery tooling.
Read-only by default. Anything that files, sends, signs, pays or deletes needs a human gate in front of it.
The deployment sequence that avoids the common failures.
Chiefly whether the firm can answer, in writing, what happens to client material.
AI conversations in a major enterprise suite are stored in the user's mailbox, governed by retention policy, suspended from deletion by any legal hold, and searchable by eDiscovery tooling — and what a user sees in the interface does not reflect what is retained. An exploratory prompt asking whether a client is exposed on an indemnity clause is a preserved artefact whose privilege status is untested.
Generally not for client-confidential work, and the reason is the administrative layer rather than the model. Consumer tiers commonly lack single sign-on, provisioning, audit logging, retention control and any compliance interface, and training on submitted content is frequently opt-out rather than off by default. The counter-intuitive consequence is that an expensive personal subscription can carry weaker protections than a cheaper business workspace. Firms should audit which tier every lawyer is actually on — the answer is usually more varied than anyone expects, because individual subscriptions get expensed.
Less than the phrase implies, and the details have moved. Retention commitments are commonly scoped to specific interfaces rather than to an account as a whole, so a firm can hold a zero-retention arrangement and still have material persisted through a different endpoint used to store documents or build a searchable index. Separately, at least one provider introduced a policy in 2026 retaining prompts and outputs for a defined safety window for certain named models even for zero-retention customers. The diligence question is no longer whether a vendor offers zero retention — it is which specific models are being called, on which platform, and what the retention mode is on each.
Because AI does not grant access — it removes obscurity as a de facto control. A document estate accumulates over-permissioned material that nobody has ever browsed, and a firm-wide assistant will surface it in a summary. In a law firm the consequence is not untidiness; it is a screened matter becoming visible to someone who should be walled from it, which is a conflicts problem rather than an IT one. The audit is unglamorous, takes weeks rather than days, and is the step most commonly skipped and most commonly regretted.
Rarely, and not for cost reasons. Open-weight models a firm can realistically self-host sit meaningfully behind frontier models on the long-context, multi-document reasoning that constitutes real legal work, and the hardware plus operational burden is substantial. The narrow cases where it genuinely makes sense are air-gapped or classified work, matters where a client contractually forbids third-party processing, and high-volume mechanical tasks such as redaction or classification where a smaller model suffices. For everyone else the confidentiality objection is better addressed contractually and architecturally than physically. Run it as a second lane if at all, not as a replacement.
Describe what you are rolling out and to whom. The Institute will help you sequence it safely.