Key Takeaways:
• 74.7% of lawyers cite accuracy concerns and 47.2% worry about data privacy when implementing AI tools, making security evaluation critical before adoption • Zero Trust architecture and SOC 2 Type II certification should be minimum requirements for any legal AI vendor handling client data • ABA Formal Opinion 512 requires lawyers to fully understand AI vendors’ data practices including encryption, retention policies, and training data usage before implementation
Your clients trust you with their most sensitive information. Trade secrets, litigation strategies, merger plans, personal data—it all flows through your firm’s systems every day. Now you’re considering adding AI tools to boost efficiency and stay competitive. But here’s the uncomfortable question: How do you know these AI vendors won’t become your firm’s biggest liability?
The legal industry is experiencing an AI gold rush. According to the ABA’s 2024 Technology Survey, 30.2% of law firms are already using AI-based tools, with adoption rates hitting 47.8% at firms with 500+ lawyers. Yet this same survey reveals a sobering reality: 74.7% of attorneys cite accuracy as their primary concern, while 47.2% worry about data privacy and security risks.
These concerns aren’t theoretical. In 2024 alone, law firms experienced a 68% increase in data breach attempts, with AI systems becoming increasingly attractive targets for cybercriminals. One compromised AI tool could expose thousands of privileged communications, trigger malpractice claims, and destroy decades of carefully built client trust.
But here’s the thing—evaluating AI security doesn’t have to be overwhelming. You don’t need a computer science degree or a team of cybersecurity experts. What you need is a systematic approach to vendor evaluation, clear security benchmarks, and the right questions to ask. This guide will give you exactly that.
The Stakes: Why AI Security Is Different for Law Firms
Traditional software security is complex enough. But AI introduces entirely new risk vectors that most law firms aren’t prepared to evaluate. Consider what makes legal AI uniquely dangerous:
The Training Data Problem: Unlike traditional software that simply processes your data, AI systems learn from it. Every document you upload, every query you submit, potentially becomes part of the AI’s knowledge base. Without proper safeguards, your client’s confidential merger strategy could inadvertently train the AI to suggest similar approaches to your competitors.
The Hallucination Risk: According to Verizon’s 2024 Data Breach Investigations Report, as many as 68% of data breaches involve human error while using AI. When AI generates false information that looks credible—a phenomenon called “hallucination”—and your team relies on it, you’re not just facing accuracy issues. You’re facing potential sanctions, malpractice claims, and ethics violations.
The Compliance Complexity: Your firm already juggles multiple compliance requirements—state bar rules, client security audits, industry regulations. AI adds layers of complexity with GDPR requirements for EU data, CCPA for California residents, and emerging AI-specific regulations that vary by jurisdiction.
The Third-Party Ecosystem: Modern AI tools rarely operate in isolation. They connect to cloud storage, integrate with practice management systems, and share data with sub-processors. Each connection point represents a potential vulnerability. According to Gartner, through 2025, 99 percent of cloud security incidents will be the fault of the customer, caused by human error or misconfiguration of cloud services.
Understanding the Regulatory Landscape
Before diving into technical security features, let’s establish the regulatory framework you’re operating within. The good news? The legal profession has clear guidance. The challenge? It’s evolving rapidly.
ABA Formal Opinion 512: Your Ethical North Star
In July 2024, the ABA issued Formal Opinion 512, providing the first comprehensive ethics guidance on generative AI use in legal practice. This isn’t optional reading—it’s your roadmap to ethical AI adoption.
The opinion makes several points crystal clear:
Competence Requirements (Model Rule 1.1): Lawyers must understand the capacity and limitations of GAI and periodically update that understanding. You can’t plead ignorance about how your AI tools work. If you’re using them, you must understand them.
Confidentiality Obligations (Model Rule 1.6): Lawyers are responsible for knowing how GAI uses data and putting in place adequate safeguards to ensure that data processed by GAI is secure and not susceptible to unwitting or unauthorized disclosure to third parties. The opinion specifically recommends securing informed consent before using client confidences in AI tools—and warns that boilerplate consent in engagement letters won’t cut it.
Communication Duties (Model Rule 1.4): You must communicate your AI use to clients when it materially affects their representation. This isn’t a one-time disclosure—it’s an ongoing obligation as your AI usage evolves.
Supervisory Responsibilities (Model Rules 5.1 and 5.3): Partners and managers must establish clear policies for AI use and ensure all staff—lawyers and non-lawyers—are properly trained. You’re responsible for your team’s AI usage, whether they’re associates, paralegals, or contractors.
Beyond Ethics: Legal and Regulatory Requirements
While ethical rules provide the foundation, various legal requirements add additional layers:
GDPR Compliance: If you handle any EU resident data (including US citizens living in Europe), GDPR applies. Non-compliance with GDPR can result in severe financial penalties—up to €20 million or 4% of annual global revenue, whichever is higher, for serious violations.
State Privacy Laws: California’s CCPA, Colorado’s CPA, and similar state laws create a patchwork of requirements. Each has different thresholds, definitions, and penalties.
Sector-Specific Requirements: Healthcare clients? HIPAA applies. Financial services? Think SOX and GLBA. Government contracts? FedRAMP and FISMA enter the picture.
Core Security Standards: Your Evaluation Framework
Not all security certifications are created equal. Here’s what each major standard tells you about a vendor’s security posture:
SOC 2: The Gold Standard for Service Organizations
SOC 2 isn’t just another checkbox—it’s comprehensive proof that a vendor takes security seriously. But understand the distinction between Type I and Type II:
SOC 2 Type I: This checks how well a company’s controls are set up at a specific moment in time. It focuses on the design of the controls but doesn’t check if they work over time. Think of it as a snapshot—useful, but limited.
SOC 2 Type II: This checks how well the controls work over a period, usually 6 months or more. It looks at both how the controls are designed and how effectively they work in practice. This is what you want to see. It proves the vendor doesn’t just have good policies—they follow them consistently.
SOC 2 evaluates five trust principles:
- Security: Protection against unauthorized access
- Availability: System uptime and performance
- Processing Integrity: Complete, accurate, and authorized processing
- Confidentiality: Protection of confidential information
- Privacy: Personal information handling per privacy policy
For legal AI vendors, all five matter, but confidentiality and security are non-negotiable.
ISO 27001: The International Information Security Standard
ISO 27001 provides a systematic approach to managing sensitive company information, ensuring its confidentiality, integrity, and availability. While SOC 2 is primarily US-focused, ISO 27001 has global recognition.
Key advantages of ISO 27001 certification:
- Risk-based approach: Vendors must identify and manage specific risks
- Continuous improvement: Regular audits ensure ongoing compliance
- Comprehensive scope: Covers 114 security controls across 14 domains
- Third-party validation: Requires certification by accredited bodies
GDPR Compliance: Privacy by Design
GDPR isn’t just about EU data—it’s become the de facto global privacy standard. Vendors claiming GDPR compliance should demonstrate:
Data Minimization: They collect only necessary data and delete it when no longer needed.
Purpose Limitation: Data is used only for stated purposes, not for training their AI on your confidential information.
Privacy by Design: Security isn’t bolted on—it’s built into the system architecture.
Data Subject Rights: Mechanisms for access, correction, deletion, and portability requests.
Breach Notification: Procedures to notify you within 72 hours of any breach.
Technical Security Features: What to Look For
Certifications provide assurance, but you need to understand the actual security architecture. Here’s what modern legal AI platforms should offer:
Encryption: The First Line of Defense
Encryption isn’t optional—it’s foundational. But not all encryption is equal:
Data at Rest: Look for AES-256 encryption minimum. Ask where encryption keys are stored and who has access. Best practice: customer-managed keys with hardware security modules (HSMs).
Data in Transit: TLS 1.3 should be standard. Older protocols have known vulnerabilities. Verify that all API calls, web interfaces, and data transfers use current encryption standards.
Data in Use: This is the holy grail—encryption during processing. Technologies like homomorphic encryption and secure enclaves allow AI processing without exposing plaintext data. Few vendors offer this today, but it’s worth asking about their roadmap.
Zero Trust Architecture: Never Trust, Always Verify
Zero Trust security means that no one is trusted by default from inside or outside the network, and verification is required from everyone trying to gain access to resources on the network.
For legal AI platforms, Zero Trust should include:
Continuous Authentication: Not just at login, but throughout the session. Behavioral analytics detect unusual patterns—like accessing files outside normal hours or downloading unusual volumes of data.
Least Privilege Access: Users and systems get minimum necessary permissions. Your contract attorney reviewing documents shouldn’t have admin access to system settings.
Microsegmentation: Different clients’ data remains isolated. A breach in one area doesn’t compromise everything.
Device Trust: The system verifies not just who is accessing data, but from what device and location. Stolen credentials alone aren’t enough for access.
Data Isolation and Multi-Tenancy
How does the vendor separate your data from other customers’? This is critical for maintaining privilege and confidentiality:
Logical Separation: Minimum acceptable standard. Your data is tagged and separated via software controls.
Virtual Private Clouds: Better. Your data runs in isolated compute environments.
Physical Separation: Best for high-security needs. Dedicated infrastructure for your firm.
Air-Gapped Options: For the most sensitive matters, can the system run completely disconnected from the internet?
Evaluating Specific AI Risks
Beyond general security, AI systems present unique challenges requiring specialized evaluation:
Training Data Contamination
The biggest fear: your confidential data training someone else’s AI. Key questions to ask:
-
Does the vendor train on customer data? The only acceptable answer for production systems is “no.” Some vendors offer separate research partnerships where you can opt-in to training, but this should never be default.
-
How is training data sourced? Understand what data the AI was originally trained on. Public court records? That’s probably fine. Scraped law firm websites? Red flag.
-
Can the model be “unlearned”? If data is accidentally included in training, can it be removed? Most current AI architectures make this impossible, which is why prevention is critical.
-
Is fine-tuning isolated? If the vendor offers custom models fine-tuned on your data, ensure these remain completely separate from their base models and other customers’ instances.
Prompt Injection and Data Leakage
AI systems can be tricked into revealing information through carefully crafted prompts. Protection mechanisms should include:
Input Sanitization: Filtering prompts for potential injection attacks before processing.
Output Filtering: Scanning responses for potential data leakage before returning results.
Context Isolation: Each session should maintain separate context. Previous users’ queries shouldn’t influence your results.
Audit Logging: Complete logs of all prompts and responses for forensic analysis if issues arise.
Hallucination Detection and Prevention
Accuracy was deemed to be the most pressing concern, with 74.7% of those surveyed specifically identifying that risk. Vendors should demonstrate:
Citation Requirements: AI outputs should include sources for verification.
Confidence Scoring: The system should indicate certainty levels for different assertions.
Human-in-the-Loop Options: Critical outputs should route through human review before use.
Fact-Checking Integration: Automated verification against authoritative legal databases.
The Vendor Evaluation Process: A Practical Framework
Now let’s put this knowledge into practice with a systematic evaluation process:
Phase 1: Initial Screening (1-2 Days)
Before investing significant time, quickly eliminate vendors that don’t meet minimum requirements:
Check Public Certifications:
- SOC 2 Type II report available? If not, move on.
- ISO 27001 certified? Preferred but not always mandatory.
- GDPR compliant with documentation? Essential for many firms.
Review Public Security Documentation:
- Security whitepaper available? Should detail architecture and controls.
- Transparency about sub-processors? You need to know who else touches your data.
- Clear data retention and deletion policies? Must align with your obligations.
Assess Basic Architecture:
- Cloud-native or on-premise options? Match to your requirements.
- Multi-tenant or single-tenant? Understand isolation levels.
- Geographic data residency? Some clients require data stay in specific jurisdictions.
Phase 2: Detailed Technical Review (3-5 Days)
For vendors passing initial screening, dig deeper:
Request Documentation:
- Full SOC 2 Type II report (not just the summary)
- Penetration testing results from the last 12 months
- Incident response procedures and breach history
- Business continuity and disaster recovery plans
- Insurance coverage details (cyber liability and E&O)
Technical Architecture Review:
- Data flow diagrams showing how information moves through the system
- API documentation and security controls
- Integration security for your existing practice management systems
- Backup and recovery procedures
- Performance and scalability documentation
Security Controls Assessment:
- Access control mechanisms and authentication methods
- Encryption key management procedures
- Vulnerability management and patching schedules
- Security monitoring and alerting capabilities
- Third-party risk management processes
Phase 3: Legal and Compliance Review (2-3 Days)
Ensure contractual terms protect your firm:
Data Processing Agreement (DPA):
- Clear roles (you’re controller, they’re processor)
- Purpose limitation clauses preventing use of your data for their benefit
- Sub-processor restrictions and notification requirements
- Cross-border transfer mechanisms (Standard Contractual Clauses, adequacy decisions)
- Audit rights and cooperation obligations
Service Level Agreement (SLA):
- Uptime guarantees (99.9% minimum for critical systems)
- Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO)
- Support response times by severity level
- Scheduled maintenance windows and notification procedures
- Service credit structure for failures
Liability and Indemnification:
- Unlimited liability for confidentiality breaches and data protection violations
- Cyber insurance requirements and proof of coverage
- Indemnification for third-party claims arising from vendor negligence
- Clear allocation of regulatory fine responsibility
Phase 4: Practical Testing (5-7 Days)
Don’t just trust documentation—test the system:
Security Testing:
- Attempt common prompt injection attacks (with vendor permission)
- Verify encryption in transit using network analysis tools
- Test access controls with different user roles
- Validate audit logging completeness and immutability
- Check data export and deletion capabilities
Integration Testing:
- Connect with your billing and time tracking systems
- Verify Single Sign-On (SSO) functionality
- Test API rate limits and error handling
- Validate backup and recovery procedures
- Stress test with realistic data volumes
User Acceptance Testing:
- Have real users test typical workflows
- Evaluate the security/usability balance
- Document any workarounds required
- Assess training and documentation quality
- Gather feedback on practical security concerns
Phase 5: Reference Checks and Due Diligence (2-3 Days)
Trust but verify through independent validation:
Customer References:
- Speak with firms of similar size and practice areas
- Ask about actual security incidents and vendor response
- Understand implementation challenges and hidden costs
- Verify claimed features work as advertised
- Learn about ongoing support quality
Industry Research:
- Check for security breaches or incidents in news/legal databases
- Review Better Business Bureau and similar complaints
- Search for lawsuits or regulatory actions
- Verify claimed certifications with issuing bodies
- Check financial stability through credit reports or funding news
Building Your Internal AI Governance Framework
Selecting secure vendors is only half the battle. You need internal controls to maintain security:
Establish Clear Policies
Your AI usage policy should address:
Acceptable Use:
- Which AI tools are approved for which purposes
- What types of data can be processed
- Required approvals for new use cases
- Prohibited activities (e.g., uploading privileged documents to consumer AI)
Data Classification:
- Public information (marketing materials, published articles)
- Internal confidential (firm finances, strategic plans)
- Client confidential (all client-related information)
- Privileged/Highly sensitive (litigation strategy, merger plans)
Different classification levels require different AI tools and security controls.
Access Management:
- Role-based access control matrices
- Onboarding and offboarding procedures
- Regular access reviews and certification
- Privileged access management for administrators
Implement Training Programs
Implementation of training in several areas, including on the use of the tools, on the ethical issues involved, on best practices for protecting confidential client information, as well as on secure data handling and privacy concerns, are important.
Your training should cover:
Basic AI Literacy:
- How AI works (and doesn’t work)
- Understanding hallucinations and limitations
- Recognizing and reporting suspicious outputs
- Prompt engineering for accuracy and security
Security Best Practices:
- Data classification and handling procedures
- Recognizing phishing and social engineering
- Incident reporting procedures
- Password and authentication requirements
Ethical Obligations:
- ABA Formal Opinion 512 requirements
- State bar specific guidance
- Client communication requirements
- Billing considerations for AI-assisted work
Tool-Specific Training:
- Detailed procedures for each approved tool
- Security features and how to use them
- Common mistakes and how to avoid them
- Update training for new features or changes
Monitor and Audit
Continuous monitoring ensures ongoing compliance:
Usage Analytics:
- Track who uses which AI tools and how often
- Monitor data volume and types processed
- Identify unusual patterns or potential abuse
- Measure efficiency gains to justify investments
Security Monitoring:
- Regular security assessment of AI tools
- Penetration testing for critical integrations
- Vulnerability scanning of connected systems
- Incident response plan testing
Compliance Auditing:
- Regular audits against policy requirements
- Client file reviews for appropriate AI use
- Billing audit for AI-assisted work
- Documentation completeness checks
Red Flags: When to Walk Away
Sometimes the best decision is not to proceed. Walk away if you encounter:
Contractual Red Flags
- Unlimited unilateral amendment rights: Vendor can change terms without notice
- Data ownership claims: Any suggestion they own or can use your data
- Liability caps below annual fees: Insufficient coverage for potential damages
- No audit rights: Inability to verify security claims
- Forced arbitration with vendor choice of venue: Especially problematic for international vendors
Technical Red Flags
- No encryption at rest: Inexcusable in 2024
- Shared databases for multi-tenancy: Insufficient isolation
- No SOC 2 or equivalent: Lack of third-party validation
- Closed-source with no security audits: Blind trust required
- No data portability: Vendor lock-in with no exit strategy
Operational Red Flags
- No dedicated security team: Security as an afterthought
- No incident response plan: Unprepared for breaches
- History of breaches without disclosure: Pattern of poor security
- Rapid pivots or unclear business model: Instability risks
- No cyber insurance: Unable to cover potential damages
Implementation Best Practices
Once you’ve selected a vendor, successful implementation requires careful planning:
Start with a Pilot Program
Don’t roll out firm-wide immediately:
- Select a controlled group: One practice area or matter team
- Choose low-risk use cases: Internal research, not client-facing work
- Set clear success metrics: Efficiency gains, error rates, user satisfaction
- Document everything: Issues, workarounds, and victories
- Iterate before expanding: Fix problems while impact is limited
Phase Your Rollout
Gradual implementation reduces risk:
Phase 1: Internal Use Only
- Marketing content generation
- Internal memo drafting
- Knowledge management tasks
- Administrative functions
Phase 2: Client Work with Restrictions
- Public information research
- Initial draft generation for heavy editing
- Citation checking and verification
- Document summarization
Phase 3: Broader Client Applications
- Contract analysis and review
- Discovery document processing
- Legal research and analysis
- Brief writing assistance
Phase 4: Full Integration
- Client-facing applications
- Mission-critical workflows
- Sensitive matter handling
- Strategic decision support
Maintain Ongoing Vigilance
Security isn’t a one-time checkbox:
Regular Reviews:
- Quarterly security posture assessments
- Annual vendor audits
- Continuous monitoring of vendor changes
- Regular policy updates based on lessons learned
Stay Informed:
- Monitor regulatory developments
- Track vendor security updates
- Follow industry best practices
- Participate in legal tech security forums
The Cost-Benefit Calculus
Security comes at a price—both financial and operational. Here’s how to balance protection with practicality:
Direct Costs
Premium for Secure Vendors: Expect to pay 20-50% more for vendors with robust security. A consumer-grade AI at $20/month might cost $100/month for legal-grade security. For a 50-attorney firm, that’s $60,000/year difference. Worth it? Consider that the average law firm data breach costs $4.88 million.
Implementation Resources: Budget for:
- Initial security assessment (40-80 hours)
- Policy development (20-40 hours)
- Training development and delivery (60-100 hours)
- Ongoing monitoring and compliance (10-20 hours/month)
Integration Complexity: Secure systems often require more complex integrations with your existing legal software. Budget additional IT resources or consultant fees.
Hidden Benefits
Competitive Advantage: Security-conscious clients increasingly require proof of AI governance. Your robust framework becomes a selling point.
Efficiency Gains: Clients are keenly aware of the value and risks associated with firms sharing their data with AI tools and are insisting on security measures to maintain confidentiality. Clients are not necessarily expecting reduced costs of outside counsel, but rather quicker responses and a higher quality of service.
Risk Mitigation: One avoided breach, malpractice claim, or bar complaint pays for years of security investment.
Innovation Platform: Secure AI infrastructure enables confident adoption of new capabilities as they emerge.
Future-Proofing Your AI Security Strategy
The AI landscape evolves daily. Your security strategy must be equally dynamic:
Emerging Technologies to Watch
Federated Learning: AI training without data leaving your servers. Perfect for collaborative intelligence without compromising confidentiality.
Confidential Computing: Hardware-based security that protects data during processing. Intel SGX, AMD SEV, and similar technologies are maturing rapidly.
Blockchain Audit Trails: Immutable logs of all AI interactions. Some vendors are beginning to implement this for high-security applications.
Quantum-Resistant Encryption: Current encryption will be vulnerable to quantum computers within 5-10 years. Forward-thinking vendors are already implementing quantum-resistant algorithms.
Regulatory Trends
AI-Specific Legislation: The EU AI Act is just the beginning. Expect US federal and state AI regulations within 24 months.
Professional Liability Evolution: Malpractice insurance and professional liability standards are adapting to AI use. Stay ahead of requirements.
Client-Driven Standards: Major clients are developing their own AI security requirements for outside counsel. Microsoft, Google, and financial institutions are leading this charge.
Making the Decision: Your Action Plan
Here’s your roadmap for the next 30 days:
Week 1: Foundation
- Assemble your evaluation team (IT, compliance, practice leads)
- Document current AI usage (authorized and shadow IT)
- Define security requirements based on your practice areas
- Create evaluation scorecard based on this guide
Week 2: Vendor Identification
- Research 5-10 potential vendors
- Conduct initial screening
- Narrow to 3-5 for detailed evaluation
- Schedule vendor demonstrations
Week 3: Deep Dive Evaluation
- Review security documentation
- Conduct technical assessments
- Check references
- Negotiate contractual terms
Week 4: Decision and Planning
- Make vendor selection
- Develop implementation plan
- Create policies and training materials
- Communicate with stakeholders
The Bottom Line
AI is transforming legal practice. Firms that successfully adopt AI while maintaining security will thrive. Those that rush into AI without proper security evaluation risk everything—client trust, professional reputation, and potentially their very existence.
The good news? You don’t have to choose between innovation and security. By following this guide, asking the right questions, and maintaining vigilant oversight, you can harness AI’s power while protecting your clients’ interests.
Remember, perfect security doesn’t exist. Your goal isn’t to eliminate all risk—it’s to understand, manage, and mitigate risk to acceptable levels. Start with the basics: SOC 2 Type II certification, clear data handling policies, and robust encryption. Build from there as your AI usage matures.
The firms that get this right won’t just avoid disasters—they’ll build competitive advantages that compound over time. Secure AI adoption enables confident innovation, attracts security-conscious clients, and positions your firm as a trusted advisor in an increasingly complex digital world.
The question isn’t whether to adopt AI—it’s how to do it securely. This guide gives you the framework. Now it’s time to act. Your clients are counting on you to get this right. And with the right approach, you will.
FAQ
Q: What’s the absolute minimum security standard we should accept from an AI vendor? A: At minimum, require SOC 2 Type II certification, AES-256 encryption for data at rest and TLS 1.3 for data in transit, a clear statement that they don’t train on your data, and a comprehensive data processing agreement. If a vendor can’t provide these basics, they’re not ready for legal industry use.
Q: How much should we budget for AI security evaluation and implementation? A: For a mid-sized firm (50-150 attorneys), budget $25,000-$50,000 for initial evaluation and implementation, including consultant fees, staff time, and training. Ongoing costs run $5,000-$10,000 monthly for monitoring, updates, and compliance. This seems significant, but it’s less than 1% of what a data breach would cost.
Q: Can we use consumer AI tools like ChatGPT or Claude for legal work? A: Not for client data. Consumer AI tools typically train on user inputs and lack the security controls required for privileged information. They’re fine for marketing content or general research, but never input client information, case details, or strategy discussions. Consider enterprise versions with appropriate security controls instead.
Q: How do we handle client consent for AI use? A: ABA Formal Opinion 512 recommends obtaining informed consent, not just boilerplate language. Update engagement letters to specifically describe your AI use, what data may be processed, and security measures in place. For existing clients, send a detailed notice about your AI adoption and security measures. Consider obtaining explicit consent for sensitive matters.
Q: What if our malpractice insurance doesn’t cover AI-related claims? A: This is increasingly common. First, review your current policy’s exclusions carefully. Then, work with your broker to find coverage that explicitly includes AI use. Some insurers offer riders for AI/cyber risks. Document your security measures thoroughly—insurers offer better rates to firms with robust AI governance.
Q: How often should we re-evaluate our AI vendors’ security? A: Conduct formal reviews annually at minimum, but monitor continuously. Require vendors to notify you of any security incidents, certification changes, or architectural modifications. Set calendar reminders for when SOC 2 reports expire. Major changes in your practice or client base should trigger immediate re-evaluation.
Q: Should we require our AI vendors to have cyber insurance? A: Absolutely. Require at least $5 million in cyber liability coverage, though $10-25 million is better for vendors handling significant data volumes. Verify coverage annually and ensure you’re named as an additional insured where possible. Their insurance should be primary to yours for any breach originating from their systems.
Q: What’s the biggest security mistake law firms make with AI? A: Treating AI security as an IT issue rather than a firm-wide governance challenge. Security isn’t just about technology—it’s about policies, training, and culture. The second biggest mistake is assuming vendor security claims without verification. Always verify through documentation, testing, and references.
Sources
-
American Bar Association. (2024). Formal Opinion 512: Generative Artificial Intelligence Tools. Retrieved from https://www.americanbar.org/content/dam/aba/administrative/professional\_responsibility/ethics-opinions/aba-formal-opinion-512.pdf
-
American Bar Association. (2024). 2024 Legal Technology Survey Report: Artificial Intelligence. Retrieved from https://www.americanbar.org/groups/law\_practice/resources/tech-report/2024/2024-artificial-intelligence-techreport/
-
American Bar Association. (2024). How to Protect Your Law Firm’s Data in the Era of GenAI. Business Law Today. Retrieved from https://www.americanbar.org/groups/business\_law/resources/business-law-today/2024-december/how-protect-law-firm-data-era-gen-ai/
-
Harvard Law School Center on the Legal Profession. (2025). The Impact of Artificial Intelligence on Law Firms’ Business Models. Retrieved from https://clp.law.harvard.edu/knowledge-hub/insights/the-impact-of-artificial-intelligence-on-law-law-firms-business-models/
-
CloudEagle.ai. (2025). ISO 27001 vs. SOC 2 vs. GDPR: Key Differences Explained. Retrieved from https://www.cloudeagle.ai/blogs/iso-27001-vs-soc-2-vs-gdpr-key-differences-explained
-
National Institute of Standards and Technology. (2020). NIST Special Publication 800-207: Zero Trust Architecture. Retrieved from https://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.SP.800-207.pdf
-
Cloud Security Alliance. (2025). How is AI Strengthening Zero Trust? Retrieved from https://cloudsecurityalliance.org/blog/2025/02/27/how-is-ai-strengthening-zero-trust
-
Verizon. (2024). 2024 Data Breach Investigations Report. Referenced in ABA Business Law Today.
-
Gartner. (2024). Cloud Security Predictions Through 2025. Referenced in ABA Business Law Today.
10. Bloomberg Law. (2025). Analysis: AI in Law Firms: 2024 Predictions; 2025 Perceptions. Retrieved from https://news.bloomberglaw.com/bloomberg-law-analysis/analysis-ai-in-law-firms-2024-predictions-2025-perceptions
Published by
The LeanLaw Team
The LeanLaw Team is the legal-finance content team behind LeanLaw — the billing, trust accounting, and revenue-reporting platform built natively on QuickBooks Online. Drawing on years of work alongside law firms and the accountants who serve them, the team writes about trust accounting, IOLTA compliance, legal billing, and law-firm financial operations. LeanLaw is a QuickBooks Online Premium App Partner.
Related articles
-
Accounting
Accounts Receivable Aging for Law Firms: What the Numbers Are Telling You
-
Accounting
How Law Firms Lose Revenue Between the Work and the Invoice — and How to Stop It
-
Accounting
Premium Billing for Niche Tech: Why You Can Charge More for CRISPR/Biotech Expertise Than Mechanical Engineering