Shadow AI in Law Firms: Replace It, Don't Ban It

By Jude Lee · · Workflow

Attorneys and a paralegal reviewing AI-assisted document work together in a small law firm conference room

The real exposure is unsanctioned, not agentic

A Bloomberg Law commentary, “Hasty Adoption of Internal AI Tools Can Expose Sensitive Data”, makes a point that lands harder at a 12-lawyer firm than at an AmLaw 50: the risk isn’t only what a vendor does with your data, it’s what happens when tools get rolled out — or adopted informally — faster than anyone defines who can see what.

That informal adoption has a name: shadow AI. In a law firm it looks mundane. A litigation associate drops three pages of a deposition transcript into a free chatbot to get a summary. An intake coordinator pastes a prospective client’s email — name, employer, injury details — into a consumer tool to draft a reply. Nobody is being reckless; they’re being fast.

The ethical frame already exists. The ABA’s Formal Opinion 512, issued in July 2024, addresses lawyers’ duties around competence, confidentiality, informed client consent, supervision of others, and fees when using generative AI. Comment 8 to Model Rule 1.1 has long framed technology competence as part of competence itself. State bars have issued their own guidance, and it varies — confirm your jurisdiction’s opinions with your state bar before you write firm policy.

Why a ban usually fails

Our opinion, stated plainly as opinion: shadow AI gets displaced by better options, not stricter rules. People in professional services route around friction. If the approved tool requires a VPN, three logins, and produces a worse first draft than the free one, the free one wins quietly — and it wins in a way nobody records.

A policy that only prohibits is a policy that only generates non-compliance you can’t see. A policy paired with a sanctioned tool that is genuinely faster than the shadow one gets followed, because following it is the path of least resistance.

A ban you can’t detect isn’t governance. It’s a hope with a signature line.

What a governed alternative looks like

The technical piece that has changed since 2024 is connection. Instead of copy-pasting matter content into a chat window, you can connect an AI assistant to the systems the firm already runs.

MCP — the Model Context Protocol — is an open standard for exposing tools and data to an AI assistant through a defined, permissioned interface. In plain terms: rather than a lawyer moving information into the AI, the AI is given a narrow, logged doorway into a specific system, and it can only do what that doorway allows. It is not the only way to do this. Vendor-native connectors inside your practice management platform, a direct integration built on an existing API (Clio and NetDocuments both publish developer APIs), or even robotic process automation can move the same data with the same access controls. MCP’s advantage is that it’s an open, assistant-agnostic interface rather than one vendor’s integration; its disadvantage is that someone has to build and maintain the server. We walk through a concrete version in connecting Claude to Clio with MCP, and the deeper firm-data version in building a custom MCP server over your matter files.

Be clear-eyed about what governed access does not fix. Scoping and logging solve the confidentiality problem — what left the firm, and where it went. They do nothing about accuracy. An assistant with read-only access to the correct transcript can still summarize ambiguous testimony confidently and wrongly, invent a date, or cite a case that doesn’t exist. Your audit log proves what the model read; it does not prove the model was right. That gap closes only with attorney review.

The second building block is skills — reusable, packaged instructions that teach an assistant to perform one job the same way each time (your deposition summary format, your privilege-log fields, your intake memo structure). Skills are what turn “the AI wrote something” into “the AI produced our firm’s standard work product,” which is also what makes supervision under Rules 5.1 and 5.3 practical. See repeatable document review skills for how that gets defined.

Shadow path (today)
Paralegal copies transcript excerpts into a personal consumer account. No record of what left the firm. Output format varies by person. Supervision happens only if the lawyer notices. Client confidentiality exposure is unknown and unmeasurable.
Governed path (target)
Assistant reads the transcript from the document system via a scoped connection — read-only on that matter, no access to other clients. A firm skill enforces the summary format and citation-to-page discipline. Every call is logged. The reviewing attorney signs off before anything goes in the file.

A 30-day path for a small firm

  1. Run an amnesty inventory

    Ask, without consequences, what people are already using and for what. You cannot govern what you haven’t named. Expect answers involving free chatbots, browser extensions, and transcription tools.
  2. Pick two workflows, not ten

    Choose the highest-volume, lowest-judgment tasks driving the shadow usage — often deposition or record summarization and first-draft correspondence. Narrow scope is how pilots survive.
  3. Choose your tier honestly

    Business/enterprise tiers of a general assistant, an AI feature inside your practice management platform, a legal-specific product, or a custom connection. Most firms should start with the least custom option that plausibly works.
  4. Write the skill before you buy the seat

    Document the exact output format, required source citations, and what the assistant must never do (e.g., never assert a legal conclusion, never touch a matter outside the one named).
  5. Turn on logging and define retention

    Decide where prompts and outputs live, how long, and who can review them. If you can’t answer “who accessed which matter through the assistant last Tuesday,” you aren’t governed yet.
  6. Train supervision, not just usage

    The reviewing attorney needs a checklist for what to verify — hallucinated citations, invented dates, over-confident summaries of ambiguous testimony, and quotations that don’t appear in the source.

Sizing the upside without making up numbers

We have no benchmark for what this saves your firm, and you should distrust anyone who quotes one. Model it yourself, with your own inputs:

The honest full picture has three parts: (1) hours recovered and where they go — reallocated to billable work, to intake response speed, or simply to leaving at six; (2) revenue captured that was previously leaking, which is a different calculation and usually a bigger one; and (3) risk avoided, which you cannot price but can describe.

Where custom actually earns its keep

Be skeptical of the assumption that a custom agent is the answer. If your need is “summarize documents in a standard format,” a legal-specific product like CoCounsel or Harvey, or an AI feature already inside your practice management system, may cover it with no build at all — and for a solo or small firm, that’s frequently the better economics. Sometimes the right answer is a rule-based automation with no AI in it, or no automation at all.

Custom work starts making sense when: your data lives somewhere no vendor connects to; you need an assistant to answer questions across systems that don’t talk to each other; or the permission model you require (matter-level scoping, ethical walls) doesn’t exist in an off-the-shelf tool. Even then, check whether your existing vendors’ native connectors get you 80% of the way first. For a fuller build-versus-buy view, see what actually works vs. hype in law firm AI.

As of 2026, this landscape moves fast — connectors, retention terms, and bar guidance all shift. Re-check your jurisdiction’s ethics opinions and your vendors’ documentation at least annually, and confirm anything with real client-confidentiality stakes with qualified ethics counsel before it becomes firm practice.

Where is your firm losing billable hours?

Get a free automation audit: we map your intake-to-invoice workflow and show you exactly what's worth automating — before you spend a dollar.

Get a free automation audit