← Blog

AI Vendor Risk for Law Firms Follows the Matter Data

Parminder Singh
Parminder Singh··6 min read
Summarize with AI

California ethics guidance tells lawyers to understand how an AI product collects and uses information, plus how it stores or discloses client information, with diligence that extends beyond marketing claims. Law firms need vendor records tied to each deployment and matter, plus request evidence showing who sent which data to which model under which policy.

Industry Verticalsai-securityai-governanceai-complianceauditcompliancepolicy-enforcement
AI Vendor Risk for Law Firms Follows the Matter Data

A litigation associate copies a draft witness outline into an approved research platform. The platform sends the text to a model operated by another company, in a region selected by a configuration the associate never sees. Procurement had already approved the research platform. The live request still decides which client's information leaves the firm and which model receives it. AI vendor risk law firms work has to connect supplier diligence to that transfer.

The 2026 State Bar of California guidance gives the practical test: understand how the product collects and uses information, plus how it stores or discloses it, rather than relying on generalized marketing assurances. The vendor record and individual model call each need to pass that test.

TL;DR

  • California guidance says reasonable efforts include understanding an AI product's collection and use of client information, plus its storage and disclosure.
  • A law firm vendor record should identify the deployed capability and model route. It should also record the retention setting and data location, along with approved matter classes and reassessment triggers.
  • Each managed request needs caller identity and matter context. It also needs data classification and destination, plus the policy version and outcome. The record needs a timestamp.
  • Contracts establish the supplier's operating obligations. Runtime policy tests the transfer that a lawyer or agent is attempting now.

Confidentiality is tied to the information in the model

The State Bar of California's 2026 Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law says lawyers must make reasonable efforts to protect client confidences when using generative AI. The guidance directs lawyers to understand how a product collects and uses information, plus how it stores or discloses user information. It names terms of use and privacy policies as relevant review material. Vendor documentation is also relevant, while generalized marketing assurances fall short.

California Rule of Professional Conduct 1.6 sets the underlying confidentiality rule. A lawyer may reveal protected client information with informed consent or where a defined exception permits disclosure. The 2026 guidance then applies that duty to prompt content and uploaded material. It also applies to integrated applications and agentic systems.

A supplier review should therefore begin with the information path. Identify the legal entity receiving content and the processing locations. Record retention behavior and training use. Check authorized subprocessors and deletion mechanics, along with incident notice and the security controls around stored prompts. The firm's legal team decides how those facts affect confidentiality and privilege for each jurisdiction and matter.

The approved product can contain several AI routes

A legal research platform may use one model for search summaries and another for document drafting. A discovery product can add an assistant after the original contract review. Practice-management software can introduce meeting summaries that send transcripts to a separate subprocessor. The parent vendor name conceals those changes.

NIST's Generative AI Profile, AI 600-1 identifies value-chain and component-integration risk where upstream components are untraceable or suppliers receive inadequate vetting. The profile also recommends evaluating risk-relevant capabilities before deployment and on an ongoing basis. For a law firm, that means registering the specific function and route instead of treating the surrounding application as one permanent approval.

The vendor record should include the product and deployed capability, along with the business owner and receiving entity. Record the endpoint and model family. Add the approved data classes and processing region, plus the retention setting and subprocessor terms. The record also needs the assessment date and named change triggers. A model substitution or new integration can reopen review even when the invoice still carries the same logo. AI vendor risk management covers the broader diligence cycle. The law-firm record adds matter restrictions and professional-responsibility review.

Matter context is part of the authorization decision

Law firms already separate access by client and matter. They also separate it by role and ethical wall. An AI gateway that sees only a shared API credential discards that structure at the point where it matters. The request needs the authenticated lawyer or agent plus the matter context supplied by the calling application.

Picture two windows on a laptop at 22:14. A deposition outline with a red "Privileged and Confidential" header sits on the left. A model chat sits on the right, ready for a paste. The TLS connection and enterprise subscription establish a secure route to an approved service. They leave unanswered whether this associate may send this matter's content to this deployment.

A matter-aware policy can distinguish public court filings from internal work product. It can also distinguish client-confidential records from privileged communications and material subject to a protective order. The firm defines those categories and the legal consequences. The enforcement point applies the approved rule to the live call. Protecting attorney-client privilege when lawyers use AI addresses the disclosure analysis; runtime authorization preserves the facts needed to support it.

Agentic access is a higher vendor review tier

The California guidance says agentic systems may access email and messaging platforms. They may also access document repositories and knowledge bases, plus client files and calendars. It directs lawyers to evaluate and limit that access. Lawyers should implement monitoring and access controls. They should also prevent autonomous external transmission of client information without safeguards and human review.

Agentic access requires a narrower approval record. A drafting tool with one document uploaded by a lawyer presents a bounded information path. An agent connected to the document-management system may retrieve files across several matters before it sends a model request. Vendor review must cover the agent's available data sources and delegated permissions. It must also cover external tools and stopping conditions, plus review points and model destinations.

My view is that a firm has not approved an agentic AI vendor when its inventory says only "legal assistant." That label tells the risk committee almost nothing. The approval needs the exact system access and permitted action, followed by records showing what the agent actually retrieved and transmitted.

AI governance for law firms covers matter-level decision rights and human review. Vendor governance feeds those decisions with verified facts about each provider and deployment.

Request evidence is part of supervision

A questionnaire captures the supplier's representations on an assessment date. Request evidence shows use under the firm's policy after that date. Both records need a stable join, such as a vendor deployment identifier and an approved use-case identifier.

For each authenticated HTTP model call, the decision record should capture the person or agent and role. It should record the matter identifier and calling application, along with the data classification and provider endpoint. It should also capture the resolved model version and policy version, plus the outcome and reason. The record needs a timestamp. Content retention should follow the firm's evidentiary and confidentiality rules. A protected hash or other correlation value can support investigation without creating a second unrestricted store of client material.

A risk team can isolate every call for one matter and check requests routed to a model version under reassessment. It can also examine denied attempts involving a protected data class. The AI vendor risk assessment template supplies procurement questions. The request log supplies operational evidence.

The California guidance calls for reassessment as AI systems evolve through updates or model changes. A new subprocessor or altered retention term can trigger review. The same applies to a different region or expanded connector, as well as a newly autonomous task. That review can happen before the next annual cycle.

DeepInspect

DeepInspect is a stateless proxy between authenticated law-firm users or agents and HTTP-based LLM endpoints. The calling application supplies identity and matter context for evaluation. Policy classifies the request and checks the approved vendor and model route. The resulting decision can permit or redact the call, or reroute or block it before transmission.

Each decision creates a signed record containing the caller and application. It includes the supplied matter context and classification, along with the vendor deployment and model version. It also includes the policy version and outcome, plus the reason and timestamp. DeepInspect covers managed HTTP AI traffic. Vendor selection and privilege analysis are the responsibility of the firm and its lawyers. The same is true for client consent and professional judgment, along with retention decisions and court obligations.

Book a demo today.

Frequently asked questions

Does an enterprise AI agreement make client information safe to submit?

An enterprise agreement can establish confidentiality and retention terms. It can also establish security and deletion terms, plus incident terms. The law firm still needs to match those terms to the client and matter. It must also match them to the data class and deployment, plus the intended task. California's 2026 guidance asks lawyers to understand the product's actual information practices and to follow client instructions that restrict AI use. The firm's lawyers decide when consent or another legal basis is required.

Should a firm retain every prompt and response?

Retention should follow the firm's legal and client requirements, along with matter and evidentiary requirements. Full-content logging can create another repository of confidential or privileged material. A narrower record can preserve identity and matter, plus classification and destination. It can also preserve policy and outcome, along with time and a protected correlation value. The firm can authorize content capture for defined investigations or workflows where counsel has approved the need and access controls.

How should a firm assess AI embedded in an existing legal product?

Treat the embedded capability as a distinct deployment. Record the model provider and endpoint. Add the processing location and retention, plus training terms and the subprocessor path. Record the data sources and owner of the capability, along with authorized matter classes. Ask which events trigger notice and reassessment. The surrounding product's earlier approval is context, while the new model route needs its own technical and legal analysis.

Can DeepInspect govern personal AI accounts or local models?

DeepInspect covers authenticated HTTP traffic that users or agents route through its enforcement point. A personal account reached outside that path and a model running locally require endpoint and browser controls. They also require network and identity controls, plus policy controls elsewhere. The firm should make approved AI access use a managed route and address bypass paths through its wider security program.