What should a law firm ask a legal AI vendor about client data?

Practical questions on encryption, model training, access and data location to ask before putting client information into legal AI software.

By
Vanguard AI®
Last updated
Facts checked

Law firms hold some of the most sensitive information their clients have. Before any of it goes into software, and especially software that uses AI, a firm should understand where the data goes, who can see it and what the vendor does with it.

These are the questions worth asking.

Is client data encrypted?

Ask whether data is encrypted in transit (between your browser and the vendor) and at rest (where it is stored). Both should be standard. If the answer is vague, ask for specifics in writing.

Is client data used to train AI models?

This is the most important AI-specific question. Some services use customer data to improve their models. For legal work, a firm will usually want a clear commitment that its data is not used for training, by the vendor or by any AI provider the vendor relies on.

Who can access the data?

Ask who at the vendor can see customer data, in what circumstances, and how that access is controlled and recorded. Inside the firm, check that access can be limited to the people working on each matter.

Where is the data stored?

Data location can matter for regulatory and client reasons. Ask which regions data is stored and processed in, and whether that includes any third-party AI providers.

Which privacy laws was the product built around?

Firms operating across borders may need to consider several regimes, such as the GDPR in Europe, the PDPA in Singapore and the CCPA in California. Ask which ones the vendor has designed for, and read the privacy policy and data processing terms.

What happens to data when you leave?

Ask how you can export your data, and how and when it is deleted after the contract ends.

A checklist to take into the conversation

Question What to look for
Encryption In transit and at rest
Model training A clear no-training commitment, covering AI providers too
Access Controlled, limited and recorded
Location Known regions, including any AI providers
Privacy laws Named regimes and published terms
Exit Export and deletion on request

How does Vanguard AI® handle client data?

Data in Donna AI® is encrypted in transit and at rest, and our products are built with GDPR, PDPA and CCPA in mind. We have a zero-training policy: customer data is not used to train AI models. Details are in our Privacy Policy.

Frequently asked questions

Is it safe to use AI with client information?

It depends on the service and how it handles data. Asking the questions above, and reading the vendor's terms, is the way to decide whether a particular service suits your firm.

Should a firm tell clients it uses AI tools?

That depends on the firm's professional rules, its engagement terms and its clients' expectations. Many firms choose to address it in their engagement letters.

What is a zero-training policy?

It is a commitment that customer data is not used to train AI models. Ask any vendor whether the commitment also covers the AI providers it uses.

All articles