Is Your Law Firm’s Client Data Ready for AI?

Artificial intelligence is entering law firms faster than many firms can establish rules for using it.

Attorneys and staff may already be experimenting with ChatGPT, Microsoft Copilot, legal research platforms, drafting assistants, transcription services, and AI features built into software the firm already owns. The immediate question is no longer whether a law firm will use AI, it is whether the firm can use it without exposing confidential information, relying on inaccurate work, or making existing access problems harder to control.

For managing partners and law firm owners, this is a business-management issue - not simply a technology decision.

 

Why AI governance matters now

The legal industry’s AI conversation is shifting from awareness to implementation.

The American Bar Association’s Formal Opinion 512 connects generative AI use to attorneys’ existing responsibilities involving competence, confidentiality, client communication, supervision, candor, and reasonable fees.

Nebraska attorneys are also being introduced to the practical side of AI. The 2026 Nebraska State Bar Association Annual Meeting includes AI ethics education along with demonstrations of commonly used AI platforms for research, drafting, and legal workflows. National events such as ClioCon and ILTACON are similarly focusing on AI adoption, automation, cybersecurity, information governance, and the business impact of legal technology.

Law firms are being encouraged to use AI more effectively while remaining responsible for what happens to client information and the quality of the resulting work.

That creates a difficult balancing act: move too slowly, and the firm may lose productivity or allow unapproved AI use to spread quietly. Move too quickly, and it may connect powerful tools to poorly organized data and overly broad permissions.

 

Copilot does not clean up old access decisions

Microsoft explains that Microsoft 365 Copilot generally operates within a user’s existing access permissions.

That sounds reassuring - and it is an important safeguard - but it does not mean the firm’s current permissions are appropriate.

If an employee can already access an old SharePoint site, broadly shared Teams channel, former client folder, or document exposed through an old sharing link, Copilot may make that information easier to discover and summarize.

Copilot did not create the excessive access. It made an existing problem more visible and more consequential.

For a law firm, that can involve:

  • Former employees or outside guests who still have access.
  • Staff members who can see matters outside their responsibilities.
  • Old client folders with inconsistent permissions.
  • Documents stored in personal OneDrive accounts instead of controlled matter locations.
  • Shared links that remain active long after their original purpose.
  • Unclear retention practices for closed matters.
  • Administrative accounts used by multiple people or outside vendors.

These issues matter even if the firm never purchases Copilot. They affect confidentiality, employee transitions, discovery, incident response, and the firm’s ability to explain who can access client information.

 

Seven Questions To Answer Before Expanding AI Use

  1.  Which AI tools are people already using?

Do not begin by assuming the firm has no AI use because it has not purchased an official platform.

Attorneys and staff may be using free public tools, personal accounts, browser extensions, meeting assistants, transcription services, or AI features embedded in software they already use. A simple, nonpunitive inventory is a better starting point than issuing a policy based on guesses.

Ask:

  • Which tools are currently being used?
  • Which roles and departments are using them?
  • What tasks are they using them for?
  • Has client, employee, financial, or case information been entered?
  • Are users accessing the tools through firm-controlled or personal accounts?

The purpose is to understand actual behavior before creating rules.

 

  1.  What information is permitted to enter an AI tool?

“Do not put confidential information into AI” sounds straightforward, but it may be too vague to guide daily decisions.

Does the restriction include names, facts, medical information, financial records, legal strategies, correspondence, contracts, discovery documents, meeting transcripts, or draft pleadings? What about information that has been partially anonymized?

The firm should define practical categories:

  • Information that must never enter an unapproved AI system.
  • Information that may be used only in a firm-approved platform.
  • Information that may be used after anonymization.
  • Public or administrative information that presents relatively low risk.

The answers should be reviewed by the firm’s leadership and legal or ethics counsel where appropriate. Technology providers can help implement controls, but the firm remains responsible for deciding its professional and legal obligations.

 

  1.  Who can currently access active and closed matters?

Before connecting AI to Microsoft 365, examine the access structure underneath it.

Can the firm produce a current list of everyone who can access each matter workspace? Are closed matters still visible to broad employee groups? Are former employees, temporary workers, vendors, or external guests still listed?

Pay particular attention to:

  • Microsoft Teams memberships
  • SharePoint permissions
  • OneDrive sharing links
  • Guest accounts
  • Shared mailboxes
  • Security groups
  • Third-party integrations
  • Administrative privileges

If the firm cannot clearly explain who can see a closed matter today, it should resolve that before making the information easier to search with AI.

 

  1.  Where is client information actually stored?

A written policy may say that documents belong in the practice-management or document-management system. Actual behavior may be different.

Client information can accumulate in email, desktops, downloads folders, personal OneDrive folders, Teams chats, scanned-document folders, mobile devices, and third-party portals.

Map where information enters the firm, where employees work with it, where it is shared, and where the final record is retained. This often reveals duplicate files, inconsistent retention, and manual workarounds that create both security risk and lost productivity.

The goal is not merely to “lock down” data. It is to make the approved process easier for employees to follow than the workaround.

 

  1.  Which AI-generated work requires human verification?

AI can save time, but it can also produce incomplete, inaccurate, or fabricated material.

The firm should identify where human review is mandatory and who is responsible for performing it. Research results, citations, summaries of evidence, client correspondence, legal conclusions, deadlines, and court submissions should not move forward simply because the output appears polished.

A useful AI policy should answer:

  • Who verifies citations and factual statements?
  • Which work may be used only as an internal starting point?
  • When must AI involvement be disclosed?
  • Who approves final work product?
  • How will the firm supervise nonlawyer use of AI?

The productivity benefit comes from shortening appropriate tasks—not removing professional judgment from work that requires it.

 

  1.  Who has authority to approve AI tools?

Without a clear approval process, every new browser extension or software feature can become an independent technology decision.

The firm should identify who evaluates:

  • The vendor’s contract and privacy terms
  • How submitted data is stored and used
  • Whether data is used to train models
  • Available security and administrative controls
  • Integration with Microsoft 365 or legal software
  • User licensing and offboarding
  • The proposed business use and expected benefit

For a 10–30 employee law firm, this does not need to become a complicated committee. It does need a named owner and a repeatable decision process.

 

  1.  Can the firm demonstrate what it decided and why?

A policy sitting in a shared folder is not the same as an operating program.

The firm should be able to show:

  • Which AI tools are approved
  • Which uses are permitted
  • Who received training
  • When permissions were last reviewed
  • How employee and vendor access is removed
  • How AI-generated work is verified
  • Who reviews exceptions or proposed new tools
  • When the policy will be reviewed again

Documentation makes the program easier to manage, explain to clients, and adjust as tools and professional guidance change.

 

What happens if the firm gets this wrong?

The consequences are not limited to a theoretical data breach.

Poorly governed AI can produce:

  • Exposure of confidential client information
  • Inaccurate legal work and unreliable citations
  • Unnecessary access to sensitive or closed matters
  • Client concerns about how their information is being handled
  • Time lost correcting low-quality output
  • Conflicting practices across attorneys and staff
  • Software spending without measurable productivity gains
  • Difficulty answering client, insurer, or incident-response questions

There is also a less obvious risk: banning AI without providing practical guidance may push its use underground. Employees who see legitimate productivity benefits may continue using personal or unapproved tools rather than asking permission.

A better approach is to create a controlled path for useful adoption.

 

What should a law firm do next?

Start with the environment the firm has today - not with the AI licenses it might buy tomorrow.

  1. Inventory the AI tools attorneys and staff are already using.
  2. Identify where client information is stored and shared.
  3. Review Microsoft 365 users, guests, links, matter permissions, and administrative access.
  4. Create a short approved-tool and approved-use matrix.
  5. Define human-verification requirements for AI-assisted work.
  6. Pilot one controlled workflow with a small group.
  7. Review the results before expanding access.

The pilot should have a specific business purpose, such as summarizing internal administrative information, preparing a first draft of nonconfidential content, or reducing a repetitive internal task. Measure whether it saves time, improves consistency, or simply creates another step employees must manage.

 

A practical path for Lincoln law firms

Independent law firms in Lincoln do not need an enterprise-scale AI governance program. They do need clear rules, appropriate Microsoft 365 permissions, controlled access, employee training, and a way to evaluate new tools without starting from scratch each time.

aZen Technology Solutions can help a firm conduct a Secure AI and Client Data Readiness Review covering current AI use, Microsoft 365 permissions and sharing, privileged access, approved tools, and technical safeguards.

The objective is not to sell an AI product or provide a legal ethics opinion. It is to give firm leadership a clear picture of the current environment, the most important exposures, and the practical steps to address before expanding AI use.

 

Get Started!

Contact us to discuss how we can help your firm conduct a Secure AI and Client Data Readiness Review.