Legal AI cost comparisons are built the way software comparisons are always built: licence fees, implementation effort, support, and a line for internal time. The term that could exceed all of them combined is the one nobody writes down, because it is a probability rather than an invoice.

What actually leaves

Sending a document to a hosted model is not one event. The material leaves the firm's control; it crosses networks the firm does not operate; it is processed on infrastructure the firm cannot inspect; it may be retained for a period the vendor defines and can change; and it may be duplicated into logs, evaluation sets and support tooling that no one mentioned during the sale.

In most cases the client whose confidential matter this is has not been told any of it is happening. That is the part that converts a technical arrangement into a professional-conduct problem.

What the processing agreement does and does not do

A serious vendor will offer a data processing addendum, and it is worth having. Read it for three things and you will usually learn what you need. The retention window: how long, measured from what event, and who can extend it. The audit right: whether it is an actual right of inspection or a right to receive a report the vendor commissioned. And the liability cap: almost always a multiple of fees paid, which is a number chosen to be survivable by the vendor rather than sufficient for you.

Under GDPR the picture is more structured — Article 28 governs the processor relationship and Article 32 the security measures — but the structure allocates duties; it does not undo an incident. A firm that has done everything Article 28 requires and still has a breach has an Article 33 notification to make, on a clock.

The contract you sign with your AI vendor does not restore privilege once it has been impaired.

The obligations that survive the contract

The professional duties are personal to the lawyer and do not transfer with the data. Rule 1.6(c) requires reasonable efforts to prevent unauthorised disclosure. Rule 1.4 requires the client to be kept reasonably informed. ABA Formal Opinion 483 addresses the duty to notify a current client when a breach involves their information. Formal Opinion 512 adds that where confidential information will be disclosed to a generative tool, informed consent is required first.

A vendor indemnity is a claim against a company. It is not a defence to any of those.

Building the number

The honest model is the ordinary one: probability of an incident multiplied by expected cost. What makes it uncomfortable is the second term, because it has to include items that are not usually costed — the hours spent notifying and explaining, the client relationships that do not survive the notification, the matters where an opponent argues waiver rather than merits, the security questionnaires that get harder for years afterwards, and the insurance conversation that follows.

For a firm running M&A, regulatory or high-stakes disputes work, the second term is large enough that the first does not have to be. That is the whole finding: this is not a risk you manage down to an acceptable number by negotiating a better addendum.

Removing the term rather than pricing it

The alternative is an architecture where the term is zero because the event cannot occur in the ordinary course of use. Inference on infrastructure the firm controls produces no egress to price. Where an external model is genuinely needed for one task, an orchestration layer can send that task with identifying material removed — a disclosure narrow enough to describe to a client in a sentence.

None of this is an argument against using AI. It is an argument for choosing the deployment shape before choosing the features, because the shape is the part that cannot be changed later.