Thousands of knowledge workers, shadow AI on personal accounts, and client-confidential matter data flowing to who-knows-where. Ethical walls have to be enforced, not trusted.
Every firm has two AI programs: the one in the policy memo and the one on associates' phones. The second one is bigger. Client-confidential matter data is being pasted into personal accounts today, not out of malice, but because the unsanctioned tool is better than the sanctioned nothing.
Client audits are catching up. Sophisticated clients now send AI-usage questionnaires with their engagement letters, and "we prohibit it" is an answer nobody believes. The credible answer is architectural: matter-scoped models, per-matter access controls, and retention rules that can be demonstrated rather than asserted.
Privilege raises the stakes beyond ordinary confidentiality: a public model's terms of service were not drafted with work-product doctrine in mind. Private inference, meaning models that run inside the firm's boundary and train on nothing, removes the question instead of litigating it.
Matter-scoped private models for review, drafting, and research. Nothing crosses a client boundary or trains a public model.
Ethical walls encoded as least-privilege gates, per-matter access, and retention controls that satisfy client audits.
A shadow-AI amnesty to surface real usage, then a private stack and 90-day governance rollout that make the sanctioned path the easy one.
Models and retrieval scoped per matter, so a query on one client's documents cannot surface another's.
Screens implemented as access controls in the AI layer, not just the document system.
Prompts and outputs governed by the same retention schedule as the matter file.
A no-penalty discovery pass that surfaces the AI tools actually in use before governance lands.
Drafting and review tools good enough that the compliant path wins on speed, not just policy.
That question is exactly why architecture matters. Keeping inference inside the firm's boundary, with no third-party retention and no training on your data, removes the disclosure argument rather than arguing it. Your general counsel still sets policy; we make the safe answer the technical default.
Start with amnesty, not discipline: a structured discovery pass that surfaces real usage patterns. That inventory tells you which sanctioned capabilities to stand up first, and adoption follows speed.
The rollout pattern is 90 days: amnesty and inventory, then policy tiers and access gates, then the private stack for the highest-value workflows. The readiness assessment on this site scores where you are today.