The real risk in legal AI is not the lawyer who studies these tools. It is the associate who quietly pastes a client’s contract into a free chatbot at 11 p.m. because a brief is due and nobody gave them anything better.
That lawyer exists at your firm right now. Survey after survey confirms it, and common sense confirms it faster. The tools are free, fast and remarkably good at exactly the drudgery that fills a litigator’s week. Telling people not to use them is like telling people not to use search engines. The use does not stop. It just goes underground, where there is no policy, no supervision and no control over where the client’s information lands.
That is the problem worth writing about. Not whether AI will replace lawyers. Whether lawyers will manage it or pretend it away.
Most firms have picked one of two postures, and both are less careful than they feel.
The first is prohibition. Ban the tools, circulate a stern memo, move on. This feels responsible. It is not. Prohibition does nothing to the demand side. The work is still crushing, the tools are still one browser tab away and the memo guarantees that when someone uses them anyway, and someone will, they will not tell you. You have not eliminated the risk. You have blinded yourself to it.
The second is procurement. Buy an enterprise legal AI platform, sign the vendor’s security addendum and trust the marketing. This feels responsible too. But most lawyers who buy these platforms cannot tell you where the data goes, what the vendor retains, whether client documents train someone else’s model or what happens inside the black box between the upload and the answer. You have not exercised judgment. You have outsourced it, along with your client’s data flow, to a sales team.
Neither posture asks the lawyer to actually understand the technology. That is the tell. We would never let an associate cite a case they have not read. Yet firms routinely adopt, or ban, tools that nobody in the building has taken apart.
There is a third posture, and a small but growing movement of lawyers has already taken it. Some call them “legal quants,” a borrowed term from finance, where quantitative analysts stopped waiting for vendors and built their own instruments. The legal version is a lawyer who learns enough about how these systems work to build careful, narrow, controlled tools for their own practice, rather than banning the technology or buying whatever is on offer.
This is not hypothetical, and it is not confined to coastal tech firms. One of my law partners went through an intensive legal-tech residency and came back with a working tool he built himself, one that handles a defined slice of our document work, runs under conditions he set and keeps client material inside boundaries he can actually describe. I am deliberately light on the details, because the program matters less than the posture. He did not buy a promise. He built an instrument, and he knows exactly what it does and does not do.
That knowledge is the whole point.
My practice is commercial litigation in Georgia. Contract disputes, business torts, healthcare litigation. It is document-heavy in the way that grinds people down: thousand-page productions, deposition transcripts, discovery responses that have to be checked against each other line by line.
The judgment in that work lives in the seams. Which limitation-of-liability clause actually controls. Which answer to Interrogatory 14 contradicts what the witness said on page 212. Whether a document is privileged or merely embarrassing. AI is genuinely useful at surfacing those seams faster, organizing, comparing, flagging. It is genuinely dangerous when it is trusted to resolve them.
A controlled tool respects that line by design. It surfaces, and the lawyer decides. An off-the-shelf chatbot respects no line at all, because nobody drew one.
Here is what the hand-wringing pieces get backwards. Confidentiality is not the reason to avoid understanding these tools. It’s the reason you must.
A lawyer who understands how a language model handles information is far better positioned to protect client confidences than one who does not. They know what gets transmitted, what gets retained, what gets logged and where inference actually runs. They can read a vendor’s data-handling terms and know which questions to ask. They can configure a tool so that client documents never leave a controlled environment. They can spot the difference between real security architecture and a badge on a website.
The lawyer who “protects confidentiality” by refusing to learn cannot do any of that. Their protection is a memo. The other’s is control. Under Rule 1.6 and our duty of technological competence, control is what the obligation actually demands.
None of this replaces judgment, and nothing I have described runs unsupervised. Every output gets reviewed by a lawyer who answers for it, to the client, to the court, to the bar. These systems draft, sort, compare and flag. They do not sign. The hallucinated-citation sanctions cases all share one fact pattern: a lawyer who skipped the review. The tool did not fail. The posture did.
Clients are already asking how their lawyers use AI, and the answers they deserve are specific ones. What we use, what we built, where their information goes and who checks the work. Firms that can answer will earn trust. Firms whose real answer is “we banned it, and we hope everyone complied” will not.
The profession does not need more hype, and it does not need more fear. It needs lawyers willing to take these systems apart, keep a human in charge and build tools worthy of the confidences we hold. Some of us have started. The rest should catch up.
**This article is published as part of the Foundry Expert Contributor Network.**Want to join?