Many law firms already live in Microsoft 365, so AI assistants built into that environment, such as Microsoft Copilot, are an obvious candidate for a pilot. The appeal is simple: draft, summarize and search across email, documents and meetings. The catch is that these assistants generally work with whatever the signed-in user is already permitted to see. If permissions are messy, the assistant can make that mess visible very quickly.
Before launching any pilot, spend time on access hygiene. Check current vendor documentation for specifics, since products and features change frequently.
Why Permissions Matter More With AI
In a typical firm, years of shared folders, old Teams sites, and generous default sharing have left documents accessible to more people than anyone intended. In the past, those files stayed hidden because nobody went looking. A conversational assistant that searches across everything a user can access can surface a sensitive memo in response to an innocent question.
For a law firm, the stakes include ethical walls, privileged materials, personnel records, partner compensation and client files that must be restricted. ABA Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized access to client information, and Formal Opinion 512 discusses confidentiality when using generative AI tools. Ethical screens under conflict rules may also be affected if files are overshared.
Pre-Pilot Checklist
1. Map where sensitive data lives
Identify the locations holding client matter files, HR and finance data, partner materials and conflicted or screened matters. Include SharePoint sites, Teams, OneDrive, shared mailboxes and any file shares synced to the cloud.
2. Review sharing and permissions
- Look for sites or folders shared with "everyone" or large groups
- Review links that give access to anyone with the link
- Check guest and external access
- Remove stale permissions for departed staff and old project teams
- Confirm that ethical walls are enforced technically, not just by policy
3. Apply sensitivity labels
Use classification and labeling features to mark confidential content, and configure protections so that labeled content is handled appropriately. Test how labels behave with the assistant.
4. Use least privilege
Review who has access to each practice group's content. Attorneys should reach matters they work on, and staff should reach what their roles need.
5. Enable logging and monitoring
Make sure audit logs are on and that someone knows how to review AI-related activity. You will want to answer the question, "what did the assistant access?"
6. Confirm data handling terms
Read the vendor's documentation on how prompts, responses and organizational data are handled, where they are stored, whether they are used to train foundation models, and what controls administrators have. Get the answers in writing for your records and client questionnaires.
Designing the Pilot
- Start small. Choose a handful of volunteers across roles, not the whole firm.
- Define use cases. Examples: summarizing meeting notes, drafting routine correspondence, summarizing long documents the user already has permission to see.
- Set rules. Require review of output, prohibit reliance on citations without checking, and ensure everyone knows the firm's AI policy.
- Collect feedback. Track time saved, errors, surprises and any permission issues found.
- Decide with data. Expand, adjust or stop based on results and risk.
Common Mistakes
- Turning on the assistant for everyone before cleaning up permissions
- Assuming the vendor's security covers firm misconfiguration
- Skipping training
- Forgetting about meeting recordings and transcripts, which become searchable
- Not telling clients if required by agreement or ethics guidance
- Measuring only enthusiasm and not risk
Questions for Your Leadership Team
- Which content must the assistant never reach?
- Who approves use for client matters?
- How will we handle clients who prohibit AI?
- How will time savings be reflected in billing?
- Who monitors the pilot and has authority to stop it?
Getting Support
Counsel Cyber helps law firms assess Microsoft 365 permissions, apply sensitivity labels and prepare for AI pilots, so that new tools show attorneys what they should see and nothing more. If you are considering a pilot, we can start with a permissions review.