DROZlegal / Blog / Is AI Safe for Law Firms?

Is AI Safe for Law Firms? 2026 Vendor Checklist

AI is safe for a law firm only to the extent the vendor's contract makes it safe — ask exactly four questions before you sign anything: is client data used to train the model, how long is it retained, where is it physically processed, and precisely what the AI can do without your approval. Those questions matter now: 69% of legal professionals already use general-purpose AI at work, but fewer than half of firms provide training on the risk (8am, 2026 Legal Industry Report).

Disclosure: DROZlegal publishes this guide and builds a practice-automation product for Canadian law firms. The vendor-evaluation framework below is Module 3 of DROZlegal's own Lawyer AI Academy curriculum; the adoption and governance statistics cited are sourced directly from 8am's and Thomson Reuters' own 2026 published research, not ours.

Why "is AI safe" is the wrong first question

Ask a vendor "is your AI safe" and almost every vendor says yes — it's not a useful question, because safety isn't a property of the model. It's a property of the contract you sign and the workflow limits built around the model.

The Canadian Bar Association's practice toolkit on AI ethics makes this point directly: choosing an AI tool requires "due diligence when making decisions about acquiring or using such tools," with contractual provisions on data privacy and security "pivotal to the use of these tools in legal practice." That's a due-diligence exercise, not a vibe check.

Four questions do the actual work. Ask them of any vendor — DROZlegal included — before a single client file touches the tool:

  1. Is client data used to train the model?
  2. How long is data retained before deletion?
  3. Where is data physically processed?
  4. What can the AI do without a lawyer's approval?

The governance gap behind the question

The reason these four questions matter right now, not eventually: adoption has outrun oversight. 8am's 2026 Legal Industry Report, surveying more than 1,300 legal professionals, found 69% now use general-purpose AI tools at work — more than double the prior year — while fewer than half of firms provide any training on responsible AI use.

Only 17% of legal professionals feel ethically comfortable allowing AI to give legal advice on its own. Source: Thomson Reuters, "2026 AI in Professional Services Report" (2026).

Read those together and the gap is the risk: most lawyers are already using AI daily, most firms haven't trained anyone on what it should and shouldn't touch, and even the people using it don't trust it to act alone. A vendor contract that answers the four questions above is what closes that gap — not a better model.

Question 1: Is client data used to train the model?

Get this in writing, not implied. Many consumer-facing AI tools use whatever you type to improve their models by default, unless you find and enable an opt-out buried in account settings. A commercial API contract is a different instrument entirely — it's a business agreement, not a consumer terms-of-service page you scrolled past.

DROZlegal's own posture, stated on our security page: "AI requests are processed under Anthropic's commercial terms: nothing trains a model, and inputs and outputs are deleted automatically within approximately 30 days." Elsewhere on that page, plainly: "No files used to train any model — ours, vendors', anyone's."

Question 2: How long is data retained before deletion?

"No training" and "zero retention" are two different claims. A vendor can honestly say client data never trains its model while still holding a copy of every input and output indefinitely for logging, debugging, or dispute purposes. Retention is a separate question, and it needs a separate, specific answer.

DROZlegal's answer is specific: inputs and outputs under Anthropic's commercial terms are auto-deleted within approximately 30 days. That is not zero retention, and it is not a negotiated zero-data-retention (ZDR) arrangement — those are a distinct, separately negotiated deal type Anthropic offers only for certain enterprise configurations. Any vendor that tells you their cloud AI has "zero retention" without qualifying that claim should be asked to put the exact terms in writing before you believe it.

Question 3: Where is data physically processed?

Data residency is a jurisdiction question, not a marketing checkbox. Where a server physically sits determines which country's courts, subpoenas, and disclosure laws can reach your client's file. For a Canadian firm, that usually means the answer needs to be Canada, specifically and verifiably — not "our cloud provider has a Canadian region we could use."

DROZlegal's security page states client files live in AWS ca-central-1 (Montréal) and stored client data never leaves Canada, backed by SOC 2 Type II attestation, PIPEDA and Quebec Law 25 alignment, and LSO By-Law 9-scoped trust-accounting controls. Ask any vendor for the region name, not the country name — "we're Canadian" and "your data is stored in a named Canadian AWS/Azure/GCP region" are different guarantees.

Question 4: What can the AI do without a lawyer's approval?

This is the question that separates a safe workflow from an unsafe one, model quality aside. Even a perfectly accurate AI is unsafe in a workflow that lets it complete an action a human should have reviewed first. The design principle that matters here is a "hard ceiling" — a step that always stops and waits for a human, no matter how capable the surrounding automation is.

DROZlegal's agents are built as "named, observable, retry-bounded jobs" that "finish their work with an audit trail you can read" — but six categories of action are permanent hard ceilings, never completed without a human:

  • Trust money movement — a person authorizes every transfer; the AI never executes one on its own.
  • Court filing — a document reaches the court only after a lawyer submits it.
  • Settlement — no AI accepts or proposes terms on a firm's behalf.
  • Commencing litigation — starting a claim is a human decision, every time.
  • Engagement approval — a drafted engagement letter waits for sign-off before it becomes a retainer.
  • Agent-initiated email send — outbound messages to clients or opposing parties are never sent by the software on its own.

Ask any vendor for their equivalent list. If they can't name specific actions their AI will never complete unsupervised, that's the answer to the question, and it isn't a reassuring one.

Turning four questions into a vendor-demo checklist

Here's the same four questions as a one-page reference — save it for your next vendor call, DROZlegal's included:

QuestionWhat "safe" looks like in writing
TrainingContract states inputs/outputs are never used to train the model — not "we take privacy seriously."
RetentionA named retention window (e.g., ~30 days) — not an unsupported "we don't keep your data."
LocationA named data-residency region (e.g., AWS ca-central-1) with an attached compliance framework — not "we're a Canadian company."
Unsupervised authorityA specific, named list of actions the AI will never complete without a human — not a general "humans are always in the loop."

None of this replaces your own professional-judgment obligations. The Law Society of Ontario's generative AI guidance keeps competence, confidentiality, and supervision duties in place no matter which vendor you choose — Module 2 of this Academy walks through what those duties require in daily practice.

If you want Module 4 — where AI genuinely belongs in the daily workflow, and where a human has to stay in the loop regardless of how capable the tool looks — the Lawyer AI Academy hub links each lesson as it publishes, and the DROZlegal waitlist conversation is usually where firms comparing more than one vendor's answers to these four questions end up next.

Frequently asked questions

Is AI safe for law firms to use with client data? Yes, if the vendor puts four things in writing before you sign: whether client data trains the model, how long it's retained, where it's physically processed, and precisely what the AI can do without a lawyer's approval. Without those four answers in writing, "safe" is a marketing word, not a fact you can rely on — and only 17% of legal professionals say they're ethically comfortable letting AI act without that kind of oversight (Thomson Reuters, 2026).

What's the difference between "no training" and "zero data retention"? They are not the same claim, and a vendor that conflates them should raise a flag. "No training" means your inputs and outputs are never used to improve the underlying model; retention is a separate question about how long the vendor keeps a copy of that data before deleting it — DROZlegal's AI processing, for example, runs under Anthropic's commercial terms, which means no training and automatic deletion within approximately 30 days, not zero retention and not a negotiated zero-retention arrangement.

What should an AI vendor never be allowed to do without a lawyer's sign-off? Anything that moves money, commits the firm legally, or sends something a client or court will see. DROZlegal treats six actions — trust money movement, court filing, settlement, commencing litigation, engagement approval, and agent-initiated email send — as permanent hard ceilings that stay with a human no matter how much of the surrounding workflow is automated.

Not ready to subscribe? Join the DROZlegal waitlist instead.

Newsletter

Get the next issue. No spam, no fluff.

Practice-automation guides, trust-accounting compliance notes, and product news — sent when there's something worth reading.

Get started

Ask us these four questions on your walkthrough

See DROZlegal's data-handling terms, hard ceilings, and audit trail on a real matter — not a slide deck.