AI can help a law firm respond faster, organize information, and reduce repetitive work. It can also touch names, contact details, case facts, documents, recordings, and other sensitive information. That makes vendor selection more than a feature comparison. It is a decision about who may handle your data, what they may do with it, and how clearly they can prove their safeguards.
This free guide gives lawyers a practical starting point for reviewing an AI vendor. It is not legal advice and it is not a replacement for your firm's own legal, ethics, privacy, or security review. The questions should be adjusted for your practice area, jurisdiction, clients, and the kind of information the tool will receive.
Why AI Vendor Vetting Matters
A polished demo does not tell you how a system stores data, whether customer information is used to improve a shared model, which outside companies can access it, or what happens after a security incident. Those details often live in contracts, security documents, and product settings, not on a sales page.
For lawyers, the stakes are especially high. The American Bar Association's Formal Opinion 512 explains that lawyers using generative AI must consider duties such as competence, confidentiality, communication, and supervision. A vendor cannot take those duties away from the firm. The firm still needs to understand what the tool does, where its limits are, and when a person must review its work.
A useful review does not need to begin with a hundred-question spreadsheet. Start with four topics. If a vendor cannot give clear answers on these areas, slow the buying process down.
Data Use And Model Training
Ask what information the product collects and why. Find out whether your prompts, call recordings, messages, uploaded files, or generated outputs are used to train or improve a model shared with other customers. Do not accept a vague statement that data is used to improve services. Ask what that means, whether you can opt out, and whether the answer is written into the agreement.
Also ask where information is stored, how long it is kept, how you can export it, and what happens when your firm requests deletion or ends the contract. The Federal Trade Commission's vendor security guidance recommends addressing how a vendor may use, share, retain, and delete data in writing. A clear vendor should be able to explain the full data lifecycle without hiding behind technical language.
Security And Independent Assurance
Security claims should come with evidence. Ask whether data is encrypted while moving and while stored, whether access is limited by role, whether multi-factor authentication is available, and how one customer's information is separated from another's. Then ask how those controls have been tested.
An independent report such as a current SOC 2 Type II report can provide useful evidence that relevant controls were reviewed over a period of time. It does not prove that every risk is gone. Review the scope, dates, exceptions, and the systems covered. If the full report is confidential, ask whether qualified customers can review it under a nondisclosure agreement.
The National Institute of Standards and Technology notes that third-party generative AI systems can create added privacy, security, and intellectual property risks. Its guidance points organizations toward procurement due diligence, documented risk controls, testing, and independent assurance materials. In plain terms, do not rely only on a vendor's promises. Ask for proof that matches the way your firm will use the product.
Access, Retention, And Incident Response
Ask who can see your information inside the vendor, when that access is allowed, and whether access is logged. Ask for a list of subprocessors, what each one does, and how the vendor evaluates them. Your contract should explain retention, deletion, incident notification, and what happens to data when the relationship ends.
If your planned use may involve protected health information and HIPAA applies, determine whether a business associate agreement is required. The U.S. Department of Health and Human Services explains that applicable agreements should cover permitted uses, safeguards, incident reporting, subcontractors, and return or destruction of protected health information. HIPAA questions depend on the parties and the workflow, so involve qualified counsel instead of treating a badge as the whole review.
Product Reliability And Human Oversight
A secure product can still be a poor fit if it gives unreliable answers or makes important decisions without review. Ask the vendor to show how the system handles uncertainty, escalates to a person, records what happened, and lets your team correct mistakes. Test the tool with realistic but fictional examples before giving it real client information.
Decide in advance which tasks AI may perform and which tasks always need a person. Intake questions, summaries, routing, and scheduling may have different risk levels from legal research, advice, or filing content with a court. Human oversight should be a real workflow with named owners, not a sentence in a policy no one follows.
What To Ask Your Vendor
How To Read The Answers
Strong answers are specific, written, and connected to evidence. They name the data, purpose, retention period, control, report, or contract term involved. Weak answers rely on words like secure, compliant, private, or enterprise-grade without explaining the scope. A badge can start a conversation, but it should not end one.
Watch for four warning signs: the vendor will not say whether customer data trains shared models; deletion and retention answers change depending on who you ask; security documents are unavailable or clearly out of date; or the product has no practical way for a person to review, correct, or take over important work.
A Free Guide For Lawyers
Use this article as a first-pass checklist. Write the vendor's answer beside each question, note the evidence provided, and mark any answer that still depends on a verbal promise. Then give the open items to the person responsible for your firm's legal, ethics, privacy, or security review. The goal is not to create paperwork. The goal is to make the decision visible and informed.
The Bottom Line
In the age of AI, protecting client information means understanding more than where a file is stored. Firms need to know how data moves through models and subprocessors, how long it remains, who can reach it, how incidents are handled, and where human judgment stays in control. The best vendor is not the one with the longest feature list. It is the one that can explain its system clearly, support its claims with evidence, and fit the responsibilities your firm already carries.
Lawgical publishes its security, privacy, AI governance, resilience, and assurance approach in its Trust Center. Use it as one example of the level of clarity you should ask any AI vendor to provide.
Sources and further reading
These primary sources informed the practical checklist above. Rules can vary by jurisdiction and use case.