The legal AI risk conversation in 2025 and 2026 is focused almost entirely on vendor selection — which platforms meet confidentiality standards, which certifications matter, which contract terms to negotiate. This is a reasonable focus. It is also addressing the wrong threat.

The more immediate compliance risk is not the AI vendor your firm chose. It is the AI tools your lawyers are using without authorisation, on personal devices, with client data, right now.

The Scale of the Problem

Use has spread through firms considerably faster than governance has. In most practices the tools arrived before any policy did, which means a substantial share of the AI work happening inside a firm today is happening under no governance framework at all — not because anyone decided that, but because nobody was asked

IBM's Cost of a Data Breach Report put the 2024 global average at USD 4.88 million, a ten per cent rise on the previous year.[3] In legal contexts, the cost of a privilege waiver — the loss of a client's ability to withhold communications from opposing counsel in litigation — cannot be quantified in the same terms but can be existential to a matter and to the client relationship.

How Shadow AI Actually Works in Law Firms

Shadow AI in legal practice is not a rogue behaviour. It is a rational response to an efficiency gap. Associates working on a research memo at 11pm have access to ChatGPT and need three hours of research compressed into thirty minutes. Partners reviewing a contract redline use an AI writing tool to check their response before sending. Paralegals use an AI summarisation tool to process a large document set before the senior associate has time to review it.

None of these users think of themselves as creating compliance risk. They think of themselves as working efficiently. The compliance risk is invisible to them because the harm — if it occurs — is invisible at the moment of action. A document submitted to a consumer AI platform for processing does not produce an immediate adverse event. The risk materialises later: in discovery, in a malpractice claim, in a bar complaint, or in a court ruling that the information transmitted was not privileged.

What a Policy Framework Actually Requires

Formal Opinion 512 reads the supervisory rules onto generative tools directly, which makes an ungoverned tool a management problem rather than an individual one.[1] The Texas bar's Opinion No. 705 requires lawyers to understand where their data goes when it is submitted to an AI tool.[2] These requirements are consistent: the obligation is not merely to select a compliant vendor for the firm's official AI platform. It is to govern what AI tools are used across the practice, by whom, and under what conditions.

A functional policy framework for AI in legal practice requires five elements.

First, an approved tools list. Lawyers should know which AI tools are authorised for which categories of work. A tool authorised for general research assistance is not necessarily authorised for review of privileged client communications. The distinction should be explicit, not implied.

Second, data classification aligned with tool authorisation. The confidentiality sensitivity of different matter types must map to the AI tools that are permitted to process them. High-sensitivity matters — litigation, regulatory investigations, M&A transactions — require tools with architectural data containment. Lower-sensitivity administrative work can be handled by cloud tools with appropriate vendor controls.

Third, training that addresses the actual risk. Lawyers who understand that submitting a client document to a consumer AI platform may destroy privilege will make different choices than lawyers who understand only that "the firm has a data protection policy." The training needs to connect the specific action to the specific risk.

Fourth, technical controls where possible. Network-level blocking of known consumer AI platforms on firm devices reduces the shadow AI problem without requiring every lawyer to remember a policy in every moment. This is not a complete solution — personal devices are outside the firm's network control — but it reduces the exposure surface for work done on firm infrastructure.

Fifth, an audit function. Firms cannot govern what they cannot see. Usage logging for AI tools — what tools are being used, for what categories of work, by whom — provides the visibility that makes policy enforcement possible and gives the firm the audit trail that supervisory obligations require.

The Governance Gap Is Closing — But Slowly

The percentage of firms with AI governance policies doubled between 2024 and 2025. It is still single digits. The trajectory is in the right direction. The starting point is low enough that the risk accumulation from the governance gap is significant and ongoing.

Firms that wait for the regulatory environment to compel governance — state bar enforcement actions, malpractice litigation, client contract requirements — will address this problem under worse conditions than firms that address it now. The confidentiality risk from shadow AI is not theoretical. It is present in most firms today, visible to anyone who asks associates what tools they are actually using on their work.

The first step is asking the question.