Subnet Blog

From AI Police to AI Enabler: Securing AI in Your Law Firm

Written by Ben Luks | 2 September 2026, 04:25:24 Z

AI adoption in law firms presents IT teams with an awkward challenge. Lawyers can see the productivity opportunity. They want to summarise documents, draft correspondence, research ideas, analyse information and reduce time spent on repetitive work.

But IT can see another side of the equation. Which AI tools are being used? What information is being entered into them? Where does that information go? And who has access to it?

Faced with those questions, the safest answer can appear to be: “Don't use AI until we've figured this out.” There's just one problem. Your lawyers may already be using it. And if IT becomes known primarily as the department that says no to AI, adoption doesn't necessarily stop. It can simply become harder to see.

The Rise of Shadow AI in Law Firms

Most IT teams are familiar with Shadow IT. An employee needs to solve a problem, so they sign up for an application without going through the normal procurement or IT approval process.

Generative AI has made that behaviour considerably easier. A lawyer doesn't necessarily need to install software or submit a technology request. They can open a browser, create an account and start experimenting within minutes.

That creates Shadow AI: the use of AI applications without the organisation necessarily having visibility or governance around them. For a law firm, the concern isn't simply that an unapproved application exists. It's what might be entered into it.

A lawyer could potentially use an AI tool to:

  • summarise a document;
  • improve a piece of correspondence;
  • analyse meeting notes;
  • generate questions from a brief;
  • extract information from a contract;
  • restructure written advice; or
  • help prepare material relating to a client matter.

These can all sound like perfectly reasonable productivity use cases. But they also raise an important question: What information did the lawyer provide to the AI in order to get the result?

The Problem Isn't AI. It's Visibility.

It's tempting to frame AI security as a choice between two positions: allow AI and accept the risk, or block AI and stay secure. In practice, neither extreme is particularly helpful. AI is becoming part of everyday knowledge work, and lawyers are naturally interested in tools that can help them work more efficiently.

A blanket prohibition can also create an unintended consequence. People may continue experimenting — except now they have an incentive not to tell IT about it. That makes the environment harder to govern, not easier.

A better question is: How can IT give lawyers safe ways to use AI while maintaining appropriate visibility and control? That changes IT's role. Instead of becoming the AI Police, IT can become the AI Enabler.

Start With the Data, Not the Tool

When a new AI application appears, the immediate question is often: “Can we use this?” A better starting point may be: “What information would we allow someone to put into it?”

Not all information carries the same risk. There is a significant difference between asking an AI assistant to help brainstorm an agenda and uploading confidential material relating to an active client matter.

Law firms therefore need clear boundaries around the types of information that can — and cannot — be used with different AI platforms. That might include considering:

  • confidential client information;
  • personally identifiable information;
  • commercially sensitive material;
  • privileged communications;
  • matter documents;
  • internal firm information; and
  • information subject to particular contractual or regulatory requirements.

The objective isn't to create a policy so complicated that nobody remembers it. A lawyer should be able to answer a relatively simple question: “Can I use this information with this AI tool?” If the answer requires reading a 30-page policy document, the guardrails probably aren't practical enough.

Give People an Approved Path

Telling people which AI applications they can't use is only half the job. They also need to know what they can use. If a firm has assessed and approved particular AI platforms, those tools should be clearly communicated. That assessment can consider questions such as:

  • How does the provider handle submitted data?
  • Is information used to train models?
  • What contractual protections apply?
  • What security and privacy controls are available?
  • Can access be managed centrally?
  • What audit or monitoring capabilities exist?
  • How does the tool interact with existing firm information?
  • Can different levels of access be applied to different users?

The answers may vary significantly between a free consumer AI service and an enterprise platform configured within the firm's existing technology environment.

That's why “AI” shouldn't be treated as a single category of technology. The security characteristics of the tool matter. So does how it has been configured. And so does the information being used with it.

Identity and Permissions Become Even More Important

The next stage of enterprise AI introduces another challenge. AI isn't limited to a blank chatbot where someone manually copies and pastes information. Increasingly, AI tools can connect with organisational data and applications. That can make them considerably more useful, but it can also make existing permissions considerably more important.

Imagine an AI assistant capable of finding information across documents, email or collaboration platforms. What should it be able to retrieve? Ideally, the answer is straightforward: Only information the person using it is already authorised to access.

But that assumes the firm's underlying permissions are appropriate in the first place. If users have accumulated excessive access over many years, AI can potentially make that information much easier to discover.

A document that was technically accessible but effectively buried somewhere within the environment may suddenly become easy to surface through a natural-language query. This is why AI readiness is not only an AI project. It can also become an identity, permissions and information-governance project.

Before connecting AI deeply into the firm's data, IT teams should understand what users can already access — and whether they should still have that access.

AI Agents Raise the Stakes Again

AI agents take this concept another step. Instead of only providing information, an agent may be capable of taking actions

Depending on the platform and configuration, that could eventually mean interacting with applications, initiating workflows or completing tasks on behalf of a user. That creates enormous potential for productivity, but it also introduces a new set of questions:

  • What systems can the agent access?
  • What actions is it allowed to perform?
  • Whose permissions does it inherit?
  • Which actions require human approval?
  • What happens if the agent misunderstands an instruction?
  • How are its activities logged?

The underlying principle should be familiar to IT teams: Give the agent only the access it actually needs. The same least-privilege thinking used for users and applications becomes increasingly relevant to AI. The difference is that AI may be capable of operating much faster than a human user, making good governance particularly important before highly autonomous capabilities are introduced.

Don't Make Lawyers Become AI Security Experts

Lawyers don't need to understand every technical detail behind large language models. They do need to understand the boundaries around how AI should be used within their firm.

That education should be practical. Rather than simply saying “Never put confidential information into AI,” explain what that means in the context of actual legal work. For example:

  • Can I summarise this client document?
  • Can I ask AI to rewrite this email?
  • Can I upload meeting notes?
  • Can I use AI to analyse a contract?
  • Can I use a free AI account for work?
  • What should I do if I find a useful new AI tool?

The closer the guidance is to real workflows, the more useful it becomes. Education should also make it easy for people to ask questions. If lawyers believe that mentioning an AI tool to IT will automatically result in it being blocked, they have little incentive to start the conversation.

A better culture encourages people to say: “I've found something that could save us time. Can we work out whether there's a safe way to use it?” That's a much healthier starting point.

Visibility Before Enforcement

Before trying to control AI use, firms need to understand what is already happening. That might mean asking:

  • Which AI services are currently being accessed?
  • Which teams are experimenting most heavily?
  • Are users relying on personal or consumer accounts?
  • What business problems are they trying to solve?
  • Are client or firm data potentially being entered?
  • Which use cases are worth formally enabling?

This is important because not all Shadow AI is evidence of reckless behaviour. Sometimes it is evidence of an unmet business need. If multiple lawyers independently adopt a tool to solve the same problem, that tells IT something useful. The objective should be to identify that demand, assess the risk and determine whether there is a secure, supported way to meet it.

In that sense, visibility isn't only a security capability. It's also a way of discovering where AI might genuinely improve the firm.

Build Guardrails Around the Use Case

A practical AI governance model doesn't have to begin with a huge transformation program. Firms can start with individual use cases. For each one, consider:

  • What are we trying to achieve?
  • Which information does the AI require?
  • Which platform will be used?
  • Who should have access?
  • What human oversight is required?
  • What would happen if the output was wrong?
  • How will we know whether the use case is actually delivering value?

That makes AI governance much more tangible. Instead of debating whether AI is safe, the firm can evaluate a specific use case with a specific tool, dataset and risk profile.

Some use cases may be inappropriate. Some may require additional controls. Others may be relatively low-risk and easy to enable. The important thing is that the decision becomes deliberate rather than accidental.

From Gatekeeper to Strategic Partner

There is a bigger opportunity here for law firm IT teams. AI gives IT an opportunity to become more deeply involved in how legal work evolves. The conversation doesn't have to begin with: “Here's what you aren't allowed to do.” It can begin with: “What are you trying to achieve?”

 

From there, IT can help determine which tools are appropriate, how information should be protected, what access is required and where automation genuinely makes sense. That shifts the relationship from enforcement to enablement. It doesn't mean lowering security standards. In many ways, it means the opposite.

Good governance is what makes broader AI adoption possible. When people have approved tools, clear data boundaries, sensible permissions and somewhere to take new ideas, there is less reason to work around IT.

The Goal Isn't Less AI. It's Better AI Adoption.

AI adoption inside law firms is unlikely to disappear. The more useful question is whether that adoption happens with IT or around IT. Firms that simply attempt to block every new tool may find themselves fighting an increasingly difficult battle against Shadow AI. Firms that adopt AI without appropriate governance create a different set of risks.

There is a more useful middle ground: understand what people are already doing, give them secure and approved options, set clear boundaries around client information, review identity and permissions, introduce new capabilities gradually, and educate people using examples that reflect real legal work.

Most importantly, make IT the place people go when they have an AI idea — rather than the department they try to avoid. Because the best outcome isn't an IT team that successfully prevents lawyers from using AI. It's a firm where lawyers can use AI productively, while IT remains confident that client information and the firm's systems are appropriately protected.