Cloud AI vendors have spent three years building genuinely compelling convenience arguments. Instant deployment. No infrastructure to own. Model improvements that arrive without anyone in IT being asked. For most enterprise software categories those arguments are decisive, and they should be.
Law firms are not most enterprises. The material a firm would most like to put through a model is exactly the material whose protection depends on it not having been shown to anyone else.
Privilege is a property of the communication, not of the contract
Attorney-client privilege protects confidential communications made for the purpose of obtaining legal advice. Its scope has been litigated for centuries; its fragility has not changed. Disclosure to a third party outside the privileged relationship generally waives it, and the waiver is not cured by the third party promising to be careful. A data processing agreement allocates liability between you and a vendor. It does not bind the party on the other side of a discovery dispute, and it does not tell a court that a disclosure did not occur.
Work product is a separate doctrine with a separate test — material prepared in anticipation of litigation, protected since Hickman v. Taylor — but it fails in a similar way. Protection is lost where disclosure substantially increases the likelihood that an adversary obtains the material. Both doctrines turn on who has seen the thing. Neither turns on what your vendor undertook to do afterwards.
None of this means cloud AI is unusable in a law firm. It means the analysis a firm has to run is not the analysis its software vendors are equipped to run for it.
What "reasonable efforts" has come to mean
Model Rule 1.6(c) requires a lawyer to make reasonable efforts to prevent inadvertent or unauthorised disclosure of information relating to a representation. Comment 18 sets out the factors: the sensitivity of the information, the likelihood of disclosure if additional safeguards are not employed, the cost of employing them, the difficulty of implementing them, and the extent to which they would adversely affect the lawyer's ability to represent clients.
Those factors are a balancing test, and the balance moves as technology moves. In 2019 the cost-and-difficulty factors carried real weight against local inference: the safeguard was expensive, hard to run, and materially worse at the job. Every one of those objections has weakened. When a safeguard becomes cheap, easy and capable, the argument that it was unreasonable to adopt it gets harder to make — to a client, to a regulator, and to an insurer.
ABA Formal Opinion 512 (2024) reached the same place from the other direction. It does not prohibit cloud AI. It places the duty on the lawyer to understand the tool, to protect confidentiality, and — where confidential information will be disclosed to a tool — to obtain informed client consent. Informed consent is a conversation a firm has to have with a client. It is significantly easier to have when the honest answer is that nothing left the building.
The 2023 objection has expired
The objection to local deployment used to be capability. Running a competitive model on your own hardware meant accepting output that was visibly worse, or building a data centre. That was a fair objection and it is no longer the position.
Open-weight models have closed most of the gap on the work that actually fills a legal workflow — extraction, classification, structured comparison, first-draft generation that a lawyer will review anyway. Purpose-built appliances put that capability in a rack unit rather than a building. Where a frontier model is genuinely required, an orchestration layer can route that one task outward with identifying material stripped first, which is a far narrower disclosure than sending the matter.
What local deployment actually buys
- A factual answer to "where did our client's documents go" — rather than a contractual one
- Matter isolation enforced beneath the application, before any model call
- An audit trail held on your hardware, produceable without the vendor's cooperation
- No exposure to a vendor's pricing, retention policy or corporate future
- A shorter conversation with a client's information-security team, and with your insurer
The number procurement leaves out
Legal AI cost comparisons tend to compare licence fees, implementation effort and support. They rarely include the expected cost of an incident: the notification obligations that follow one — ABA Formal Opinion 483 addresses the duty to notify current clients of a breach involving their information — the client relationships that do not survive the notification, and the matters where an opponent gets to argue about waiver rather than the merits.
The firms that win will be the ones that treated data sovereignty as an architectural constraint from day one, not a compliance checkbox added later.
Multiply a small probability by a large enough number and the comparison stops being close. That is not an argument against adopting AI. It is an argument for adopting it in a shape that does not create the exposure in the first place.
