home  /  security & threats  /  secure deployment
security · ai for legal practice

Secure deployment.

The most consequential security decision most firms make about AI is a procurement decision nobody treated as one.

begin here

Where is your firm?

Start a conversation with the AI Adoption Concierge, already scoped to secure deployment. Pick a starting point, or describe your situation directly.

AI Adoption Conciergesecure deployment · orientation, not legal or ethics advice
Tell me what you're deploying, to how many people, and what tier you're on today. I'll help you sequence it. What your conduct rules require is a question for your own counsel.

The distinction between a consumer AI subscription and an enterprise one is contractual rather than technical, and it is the control that matters most. On consumer tiers, training on submitted content is commonly opt-out rather than off by default, and the administrative apparatus a firm needs — single sign-on, audit logging, retention control, a compliance interface — does not exist at all. This produces a result that surprises people: a partner personally expensing a premium consumer subscription may have materially fewer protections than the same firm's cheaper business workspace. A well-publicised US preservation order made the point concretely, capturing several consumer and mid tiers while exempting enterprise and zero-retention arrangements. Deployment security is mostly about getting three things right before anyone logs in: the tier, the retention setting, and the permissions the tool will inherit.

mechanisms

What determines your actual exposure.

Ordered by how much difference each makes, which is not the order firms address them.

The subscription tier

Contractual, not technical. Training posture, retention control and the entire administrative layer turn on it. The single highest-leverage decision.

The retention setting

Defaults differ by vendor and at least one major provider's commercial default is indefinite until a window is set. Set it explicitly rather than inheriting it.

Permissions the tool inherits

AI does not grant new access — it removes obscurity as a de facto control. Over-permissioned documents nobody browsed will now be surfaced in answers.

Ethical walls that reach the AI layer

A screen enforced in the document system but not in the AI layer is not a screen. Ask vendors to demonstrate it against a real walled matter.

Discoverability of prompts

AI conversations are retained business records subject to retention policy and legal hold, and are searchable by discovery tooling.

What agents are allowed to do

Read-only by default. Anything that files, sends, signs, pays or deletes needs a human gate in front of it.

methodology

What the evidence shows — and what we examine.

The deployment sequence that avoids the common failures.

Tier and terms before rolloutTraining posture, retention window and administrative controls settled in writing before anyone is given access.
Permissions audit before AI searchRun it before enabling anything that reads across the document estate. This takes weeks and firms consistently underestimate it.
Add AI transcripts to retention and holdAs a named record type. Most firms' hold templates do not mention them.
Give every agent a named ownerWith defined authority and an expiry date, inside the same access reviews as human accounts.
what's at stake

What the deployment decision determines.

Chiefly whether the firm can answer, in writing, what happens to client material.

whether inputs train a model how long material is retained whether screens actually hold what becomes discoverable compliance with outside counsel guidelines the confidentiality analysis under conduct rules

Your prompts are records.

AI conversations in a major enterprise suite are stored in the user's mailbox, governed by retention policy, suspended from deletion by any legal hold, and searchable by eDiscovery tooling — and what a user sees in the interface does not reflect what is retained. An exploratory prompt asking whether a client is exposed on an indemnity clause is a preserved artefact whose privilege status is untested.

common questions

Secure deployment — practical questions.

Is a paid consumer subscription good enough?

Generally not for client-confidential work, and the reason is the administrative layer rather than the model. Consumer tiers commonly lack single sign-on, provisioning, audit logging, retention control and any compliance interface, and training on submitted content is frequently opt-out rather than off by default. The counter-intuitive consequence is that an expensive personal subscription can carry weaker protections than a cheaper business workspace. Firms should audit which tier every lawyer is actually on — the answer is usually more varied than anyone expects, because individual subscriptions get expensed.

What does zero data retention actually cover?

Less than the phrase implies, and the details have moved. Retention commitments are commonly scoped to specific interfaces rather than to an account as a whole, so a firm can hold a zero-retention arrangement and still have material persisted through a different endpoint used to store documents or build a searchable index. Separately, at least one provider introduced a policy in 2026 retaining prompts and outputs for a defined safety window for certain named models even for zero-retention customers. The diligence question is no longer whether a vendor offers zero retention — it is which specific models are being called, on which platform, and what the retention mode is on each.

Why is a permissions audit necessary before deploying AI search?

Because AI does not grant access — it removes obscurity as a de facto control. A document estate accumulates over-permissioned material that nobody has ever browsed, and a firm-wide assistant will surface it in a summary. In a law firm the consequence is not untidiness; it is a screened matter becoming visible to someone who should be walled from it, which is a conflicts problem rather than an IT one. The audit is unglamorous, takes weeks rather than days, and is the step most commonly skipped and most commonly regretted.

Should we run models on our own hardware?

Rarely, and not for cost reasons. Open-weight models a firm can realistically self-host sit meaningfully behind frontier models on the long-context, multi-document reasoning that constitutes real legal work, and the hardware plus operational burden is substantial. The narrow cases where it genuinely makes sense are air-gapped or classified work, matters where a client contractually forbids third-party processing, and high-volume mechanical tasks such as redaction or classification where a smaller model suffices. For everyone else the confidentiality objection is better addressed contractually and architecturally than physically. Run it as a second lane if at all, not as a replacement.

related

Related specialization areas & resources.

Deploying something across the firm?

Describe what you are rolling out and to whom. The Institute will help you sequence it safely.

AI adoption conciergeorientation · not legal or ethics advice
Tell me what you're deploying, to how many people, and what tier you're on today. I'll help you sequence it. What your conduct rules require is a question for your own counsel.