A vendor's demo shows a tool summarizing a contract in seconds, and it looks impressive. What the demo does not show is where the contract text goes, who can see it afterwards and what the vendor's terms say about reuse. Before any AI tool touches client information, the firm should have asked those questions and recorded the answers.
ABA Formal Opinion 512, from July 2024, discusses generative AI and lawyers' professional duties, including confidentiality, competence, communication and supervision. It notes that lawyers should understand how a tool handles inputs and consider whether client informed consent is needed in certain circumstances. This post offers a practical question list you can use to turn those concepts into a vendor review. It is not legal advice, and you should consult your state bar's guidance.
Group 1: What happens to our data
- Is our input used to train or improve models for you or anyone else? Can that be disabled by contract, and is it off by default on the plan we are buying?
- How long are prompts, files and outputs retained? Can we set or reduce retention?
- Can we delete data on request and receive confirmation?
- Do human reviewers at the vendor ever see our content, for example for abuse monitoring or support?
- Is our data logically separated from other customers?
Group 2: Where it goes
- Where is data stored and processed, geographically?
- Which subprocessors and underlying model providers receive our data?
- Will we be notified of new subprocessors, and can we object?
- Does the product call third-party AI services behind the scenes, and are those services bound by the same terms?
Group 3: Security controls
- Is the vendor independently audited, for example with a SOC 2 report, and will it share the report under confidentiality?
- Is data encrypted in transit and at rest?
- Does the product support single sign-on and multi-factor authentication?
- Are there role-based permissions, so that only people on a matter can reach its content?
- What audit logs are available to administrators?
- How are vulnerabilities handled, and how quickly are customers notified of incidents?
Group 4: Contract terms
- What are the breach notification terms, and do they meet the deadlines in our client guidelines?
- Does the contract address confidentiality in a way compatible with legal ethics duties? Does it explicitly state that the vendor claims no ownership of inputs or outputs?
- What happens to our data if the vendor is acquired, changes terms or shuts down?
- Are there indemnities or limits of liability that make sense for the risk?
- Can we export our data in a usable format at termination?
Group 5: Reliability and accuracy
- What does the vendor say about error rates and known limitations?
- Are sources or citations shown so reviewers can verify them?
- Can we test the tool on non-confidential samples before purchase?
- How are model updates announced, given that behavior may change?
Group 6: Fit with firm obligations
- Can we configure the tool to prevent use outside the approved matters?
- Can we meet client requirements that prohibit AI use or require notice?
- Does the tool create records that may need to be preserved or produced?
- Does it help the attorney review output, or does it hide the reasoning?
How to run the review
Do not ask partners to evaluate all of this alone. Assemble a small group: an attorney who will use the tool, the firm administrator, someone responsible for security and, if possible, ethics counsel. Score responses as acceptable, needs negotiation or unacceptable. Keep a one-page summary for each tool with the date, reviewers and decision.
Be wary of vague answers
"We take security seriously" is not an answer. Ask for specifics in writing. Vendors with solid practices usually answer these questions easily.
Start with a pilot
Choose one practice group and one use case with low-risk data, set rules for review and measure whether the tool actually saves time. Expand only after you are satisfied with the controls and the results.
Revisit periodically
AI products change frequently. Terms, features and subprocessors can shift, so review each approved tool at least annually, and whenever the vendor announces a significant change.
How Counsel Cyber can help
Counsel Cyber helps law firms evaluate AI tools, review vendor terms and configure approved tools with appropriate access controls. If you would like help scoring a vendor you are considering, we are happy to assist.