Law firm AI vendor due diligence
Treat an AI vendor as a third party that may receive client information, not as a writing tool with a clever demo.
DATIK editorial team · Reviewed by Ilya Kostin · Sources checked 7 October 2026
Before any live matter reaches the system, the firm should know what data crosses the boundary, who else receives it, how long each copy remains, and how the firm can retrieve or delete it.
ABA Formal Opinion 512 says lawyers using generative AI must consider competence, confidentiality, communication, supervision, candor, and reasonable fees. The Florida Bar's Opinion 24-1 tells lawyers to research a program's data-retention, data-sharing, and self-learning policies. A sales assurance is not that research.
Start with one approved use case
Review the exact job the product will perform. A public marketing draft, an internal knowledge search, a contract summary, and a client-facing intake tool expose different information and create different failure paths.
Write down approved users, allowed data classes, prohibited data, the output reviewer, and the decision the output may support. Keep sensitive matter data out until the firm's counsel and security owner approve that specific use. Test first with synthetic or public material. A good demo proves that the workflow functions. It does not prove that the product is safe for confidential data.
Map every recipient of the data
Ask the vendor to diagram the route from the user's device to storage, model processing, logs, support systems, analytics, backups, and deletion. Get the names and locations of subprocessors. If the product calls another model provider, that provider belongs on the map too.
The contract should say whether prompts, uploaded files, outputs, metadata, and feedback may train or improve a shared model. “We do not train on your data” needs a definition of data, the covered product tier, exceptions, and the controlling terms.
Ask whether support personnel can read content, whether access is logged, and whether the firm can restrict administration by role and matter. Ethical walls fail if a search index makes one client's files available to the wrong team.
Put retention and deletion in writing
Retention exists in application logs, abuse-monitoring copies, retrieval indexes, file storage, backups, exports, and support tickets. Set a period for each copy. The agreement should explain what happens when a user deletes a conversation, when the firm closes an account, or when a client directs removal.
Some systems cannot remove information incorporated into model weights. If a vendor trains on firm data, deletion may not restore the position before training. Settle training use before upload.
Test security claims against the product you will buy
Request current evidence for the service and tier in the proposal. A certification held by a parent company or a different product does not answer the question.
Review encryption, identity controls, audit logs, tenant separation, vulnerability handling, secure development, and independent testing. Define which event triggers incident notice, the notice deadline, evidence preservation, and who coordinates client or regulator communications. The firm should be able to suspend the integration without losing its records.
Keep lawyers responsible for the work
ABA Formal Opinion 512 does not transfer professional responsibility to the model or vendor. The firm needs a named lawyer responsible for the use case, a verification rule for outputs, and supervision for staff who use the product.
Test citations, quotations, calculations, deadlines, names, and statements of law against authoritative sources. Define human approval before client-facing or court-facing release. Track the system and prompt version so a later complaint can be tied to the configuration that produced the output.
Decide when client communication or consent is required
Formal Opinion 512 says disclosure to a client depends on the facts and the lawyer's duties. It also warns that informed consent may be required before information relating to a representation enters some self-learning systems. Generic boilerplate may not be enough for a particular risk.
Counsel should decide when to explain the tool, information shared, purpose, risks, alternatives, and the client's options. Record that decision by use case.
Write the exit before the pilot
The firm should be able to export prompts, approved knowledge, matter files, outputs, audit history, users, and configuration in a usable format. Set the export window, assistance, fees, and deletion certificate in the contract.
NIST's Generative AI Profile recommends supplier assessments, approved-provider inventories, contract rights to evaluate third-party processes, ongoing monitoring, and contingency plans. A pilot can pass on output quality and fail on ownership.
Keep a decision record
Keep one file containing the use case, data map, contract version, security-evidence date, reviewers, restrictions, test results, client-communication decision, incident owner, renewal date, and exit test. Review it after a material product change and before renewal.
DATIK's Lead Chatbot uses approved knowledge, scoped intake, logging, and human takeover. The ownership terms describe the accounts, configuration, and export that remain with the client. A free diagnostic can map one law-firm workflow before vendor terms or client data are accepted.
Sources and review limits
Sources were checked on October 7, 2026. This is an operational vendor-review guide, not legal advice. The responsible lawyers must apply the rules, law, client terms, insurance conditions, and security requirements for the firm and matter.
Frequently asked questions
May a law firm put client information into a generative AI product?
Only after the responsible lawyers determine that the use complies with confidentiality and other duties. The decision depends on the information, safeguards, terms, use case, applicable law, and whether client disclosure or informed consent is required.
Is a promise not to train on customer data enough?
No. Confirm what customer data covers, which tier and subprocessors are included, how logs and feedback are treated, what exceptions apply, and which contract controls if public documentation changes.
What vendor records should the firm keep?
Keep the data map, contract and terms, subprocessor list, security evidence, test results, approvals, incident contacts, change notices, renewal review, exports, and deletion evidence.
Does an independent security report prove the AI product is safe?
No. It is evidence about stated controls for a defined scope and period. Confirm that it covers the exact service, infrastructure, region, and product tier the firm will use.
What should happen when the vendor changes its model or terms?
The firm should receive notice, reassess the affected controls, test the use case again, and have a documented option to pause or exit before the change exposes client information.
Review one AI vendor before client data moves
Bring the proposed use case, data types, vendor terms, and current security questions. We will map the boundary, owners, tests, and exit path for counsel to review.
4300 Biscayne Blvd, Miami, FL 33137 · [email protected]