What should a law firm ask a legal AI vendor about client data?
Practical questions on encryption, model training, access and data location to ask before putting client information into legal AI software.
- By
- Vanguard AI®
- Last updated
- Facts checked
Law firms hold some of the most sensitive information their clients have. Before any of it goes into software, and especially software that uses AI, a firm should understand where the data goes, who can see it and what the vendor does with it.
These are the questions worth asking.
Is client data encrypted?
Ask whether data is encrypted in transit (between your browser and the vendor) and at rest (where it is stored). Both should be standard. If the answer is vague, ask for specifics in writing.
Is client data used to train AI models?
This is the most important AI-specific question. Some services use customer data to improve their models. For legal work, a firm will usually want a clear commitment that its data is not used for training, by the vendor or by any AI provider the vendor relies on.
Who can access the data?
Ask who at the vendor can see customer data, in what circumstances, and how that access is controlled and recorded. Inside the firm, check that access can be limited to the people working on each matter.
Where is the data stored?
Data location can matter for regulatory and client reasons. Ask which regions data is stored and processed in, and whether that includes any third-party AI providers.
Which privacy laws was the product built around?
Firms operating across borders may need to consider several regimes, such as the GDPR in Europe, the PDPA in Singapore and the CCPA in California. Ask which ones the vendor has designed for, and read the privacy policy and data processing terms.
What happens to data when you leave?
Ask how you can export your data, and how and when it is deleted after the contract ends.
A checklist to take into the conversation
| Question | What to look for |
|---|---|
| Encryption | In transit and at rest |
| Model training | A clear no-training commitment, covering AI providers too |
| Access | Controlled, limited and recorded |
| Location | Known regions, including any AI providers |
| Privacy laws | Named regimes and published terms |
| Exit | Export and deletion on request |
How does Vanguard AI® handle client data?
Data in Donna AI® is encrypted in transit and at rest, and our products are built with GDPR, PDPA and CCPA in mind. We have a zero-training policy: customer data is not used to train AI models. Details are in our Privacy Policy.
Frequently asked questions
Is it safe to use AI with client information?
It depends on the service and how it handles data. Asking the questions above, and reading the vendor's terms, is the way to decide whether a particular service suits your firm.
Should a firm tell clients it uses AI tools?
That depends on the firm's professional rules, its engagement terms and its clients' expectations. Many firms choose to address it in their engagement letters.
What is a zero-training policy?
It is a commitment that customer data is not used to train AI models. Ask any vendor whether the commitment also covers the AI providers it uses.