Tov Law Grow Your Autonomous Law Firm Free AI Resources for Lawyers
§ 50 · Getting started

The AI Vendor Security Checklist for Law Firms

“Is AI confidential?” is the wrong question, and it produces confident answers in both directions that are equally useless. The right question is narrower: for the specific plan your firm pays for, what do the terms say about training, retention, and access?

Two lawyers can use the same branded product and be in completely different positions because one is on a consumer subscription and the other is on a business agreement. Here is the checklist to run before client material goes anywhere.

The nine questions

Does the vendor train models on our content? For legal work the answer needs to be no, and it needs to be in the terms rather than in a marketing page.

How long is data retained, and can we set it to zero? Zero-retention options exist on enterprise tiers at the major providers. Understand that zero retention often disables features like conversation history, which is a real tradeoff to make deliberately.

Who at the vendor can access our content, and under what circumstances? Most providers retain limited access for abuse investigation and legal process. That is normal. You want to know the specifics rather than assume either extreme.

Will they sign a business associate agreement? If you touch medical records, this is not optional. It is also not automatic, and usually has to be asked for.

Where is data processed and stored? Relevant for some client industries and for anything with cross-border sensitivity.

Do they have a SOC 2 Type II report, and will they show it? A vendor that cannot produce one is not necessarily disqualified, but it tells you how mature their security program is.

What happens to our data if we cancel? Deletion timeline, in writing.

Do they notify us of a breach, and how fast? Your own notification obligations may run from when you knew.

Are subprocessors listed? Your vendor’s vendors also touch your data.

The consumer tier trap

This is the single most common mistake, and it is invisible from inside the product because the interface looks identical.

A lawyer signs up for a personal subscription with a credit card, uses it for months, and assumes the terms match what they read about the enterprise offering. Consumer and business tiers of the same product frequently differ on exactly the two dimensions that matter, training and retention.

Check what your firm actually pays for. If people expensed individual subscriptions, you have a mix of tiers across the firm and no consistent posture, which is worse than a bad policy consistently applied because you cannot even describe your exposure.

Where the real leak usually is

Not the vendor. The shadow account.

Someone at your firm is using a personal account on a personal device for work, because it is faster than asking. That material is outside every agreement you negotiated and outside any log you could produce if asked.

The fix is not a stern policy memo. It is providing an approved tool that is good enough and easy enough that nobody has a reason to route around it. Firms that ban AI outright get the most shadow usage, and get it invisibly.

What to keep out regardless

Some material should not go to an outside service even under good terms.

Anything under a narrow protective order until you have read the order and concluded it permits vendor disclosure.

Material subject to specific client instructions or an outside counsel guideline restricting third-party technology. Corporate clients increasingly address AI expressly, and those guidelines control.

Sealed filings and grand jury material.

Another client’s confidential information sitting in a document you happen to be analyzing, which is easy to miss when you upload an entire file.

Writing it down

A short policy beats a long one nobody reads. One page covering the approved tools and tiers, what may and may not be entered, the requirement that a human reviews output before it goes to a client or a court, and who to ask when unsure.

Then look at your engagement letter. Many already contain technology and vendor language broad enough to cover this. If yours does not, that is a conversation with whoever handles your risk management, and it is easier to update the template once than to have the discussion per matter.

The competence and supervision obligations behind all of this are covered in AI ethics for lawyers, and the analysis is worth reading before you write your own policy.

Do this today

Find out which AI subscriptions your firm actually pays for and at which tier, including anything expensed by individuals.

Most firm owners are surprised by that list. You cannot evaluate exposure you have not inventoried, and the inventory takes one email to your bookkeeper.

Questions lawyers ask

Is it confidential to put client information into ChatGPT or Claude?
It depends on the tier. Business and enterprise plans from the major providers generally do not train on your content and offer controlled retention, while consumer plans have historically differed. The product name tells you nothing on its own. Find the terms for the exact plan you pay for and keep a copy.
Do I need client consent to use AI on their matter?
Bar guidance varies and continues to develop. Several authorities treat routine use of a confidential tool like any other technology not requiring specific consent, while advising disclosure where client data is exposed to a third party in a meaningful way. Check your own jurisdiction, and consider whether your engagement letter's technology language already covers it.
What is a business associate agreement and do I need one?
A BAA is a HIPAA contract governing protected health information. If you handle medical records, which most plaintiff firms do, you want your AI vendor covered by one before those records go in. The major providers offer BAAs on appropriate enterprise tiers, but they are not automatic and usually must be requested.
Can I use AI if my client's data is subject to a protective order?
Read the order. Many protective orders restrict disclosure to defined categories of people and permitted vendors, and sending material to an outside AI service can be a disclosure. Where the order is narrow, either get agreement from opposing counsel or keep that material out of outside tools entirely.

Go deeper