Shadow AI in Law Firms: How to Detect It and What to Do Next
You find shadow AI in a law firm by reading the three data sources the firm already has: network logs, expense reports, and anonymous staff surveys. The survey evidence says most firms will find something, because generative AI use at firms is widespread while formal strategies and vetted tool lists are not. Detection is the easy half. The half that decides the outcome is the sanctioned path you publish next, because lawyers under deadline pressure do not stop using tools that help them work. They move to where the firm cannot see them.
TL;DR
Shadow AI in law firms is staff use of AI tools outside firm approval: consumer chatbots on personal accounts, and AI features switched on inside existing software. The Thomson Reuters Institute Future of Professionals Report 2025 names shadow AI as a material data-exposure and governance risk at firms without a clear AI strategy, and eDiscovery Today's coverage of the ILTA 2025 Technology Survey found 80% of firms using or exploring generative AI. The playbook is known: measure with network, expense, and survey signals, publish a sanctioned path fast enough to be chosen, apply matter-level rules, and keep a record of what leaves the firm in a prompt.
Table of Contents
The Numbers: Unsanctioned AI Use Is the Norm
This page is the legal-sector deep dive. For the general-audience background on the phenomenon and how to find it, start with our guides on what shadow AI is and how to detect shadow AI. What follows assumes you know the phenomenon and need the legal-specific evidence, plus a response plan.
The largest law-firm-specific dataset comes from the ILTA 2025 Technology Survey, released 16 September 2025, which drew on 580 law firms representing more than 152,000 attorneys and roughly 302,820 total technology users. eDiscovery Today's coverage reports that 80% of respondent firms are using or exploring generative AI in 2025, including 100% of firms with 700 or more attorneys and 63% of firms with 50 or fewer. Usage at scale is the base condition. Sanctioned usage is the variable.
The governance side lags. The Thomson Reuters Institute Future of Professionals Report 2025, based on a survey of 2,275 professionals across legal, tax, and compliance, names shadow AI, meaning unsanctioned, unmanaged use of AI tools by staff, as a material data-exposure and governance risk at firms without a clear AI strategy. Attorney at Work's analysis of the report found that only 22% of surveyed professionals say their firm has a visible AI strategy in place, and 32% say their firm is moving too slowly on AI adoption. Individual use runs ahead of firm governance. That gap is where shadow AI lives.
The same analysis captures the motivation gap: 80% of law firm professionals believe AI will transform or have high impact on their work, while only 29% expect high levels of change at their own firm this year. Staff who believe in the technology and do not see the firm providing it will supply their own. That is not malice. It is arithmetic.
Why Law Firms Are a Worst Case
Three conditions stack in legal practices. First, the work product itself is confidential. A prompt that summarizes a draft brief, a settlement posture, or a witness statement carries client names, matter numbers, and strategy. Second, deadline pressure is constant. A filing due tomorrow makes a tool that drafts in two minutes hard to refuse, and the same pressure discourages raising a hand to ask permission. Third, much of the work happens on personal devices and home networks that firm controls never see.
The consumer-account problem compounds this. OpenAI's Data Controls FAQ states that on consumer Free and Plus accounts, content is usable for model training unless the user manually opts out through account data controls, and that retention of up to 30 days for safety review applies regardless of the training setting. The associate who pastes a clause into a personal account is therefore not merely breaking an internal rule. The data leaves with vendor-controlled retention and a training default the firm never agreed to. Whether any given input would reveal information protected by confidentiality duties, and what consent would be required, is a question for your ethics counsel. Our companion piece on whether lawyers can use ChatGPT with client data works through that analysis in detail.
Three Detection Signals That Work in a Firm
No single instrument sees everything, because a meaningful share of use never touches firm infrastructure. Layer three signals instead.
Network logs
DNS, proxy, and secure web gateway logs show connections to AI service domains from firm networks and VPN sessions. This is the fastest signal to stand up and the easiest to quantify by department and practice group. Its blind spot is structural: phones on cellular, personal laptops on home networks, and anything routed through a hotspot produce nothing.
Expense reports and procurement
Personal AI subscriptions expensed as software, new SaaS line items, and existing tools that quietly added AI features all surface here. Expense data catches what network data misses when staff use paid personal accounts, and it hands you vendor names you can take into contract review.
Anonymous staff surveys
The most honest signal is also the cheapest. A short anonymous survey asking which tools people use and for what, with an explicit no-blame framing, reliably finds more use than any log. The Thomson Reuters gap data explains why self-report works: staff know what they use, and firms largely do not.
Run all three for a month before you act on any of them. The baseline turns the conversation from anecdote to inventory.
Detection Without an Alternative Just Moves the Behavior
A block on firm networks does not remove the need. It removes your visibility. The filing deadline still exists, the tool still works on a phone, and the behavior relocates to where no log records it. Firms that treat detection as the finish line usually end up with better-hidden shadow AI.
The block is not the control. The sanctioned path is the control; the block is only the boundary drawn around it.
The governance numbers show how much room there is to get this wrong. eDiscovery Today's analysis of the ILTA 2025 Technology Survey found that only 45% of law firms report having an official policy governing generative AI tool use or a list of vetted applications, even though 80% of firms are already using or exploring the technology. A policy without a sanctioned path is a warning, not a control.
A Response Playbook That Holds
The sequence matters more than any single control.
- Establish the baseline. Run the three signals for a month. Count users, tools, and the matters involved. You cannot scope a response to a number you have not measured.
- Publish a sanctioned path, fast. Pre-approve tools for common tasks such as drafting, summarization, and translation, with an exception process measured in days. The sanctioned path has to be nearly as fast as the shadow one, or it will not be chosen.
- Set matter-level rules. Not every matter carries the same sensitivity. Controls that apply different rules per matter and restrict access by role match how firms actually work. Our overview of AI controls for legal practices covers this model in detail.
- Give every prompt a record. A usage record of what left the firm and what was masked turns any future client question from speculation into an answer.
- Revisit quarterly. The tool landscape changes faster than policy cycles. Put the three signals on a calendar.
If you are evaluating options in this space, we maintain a comparison of shadow AI controls for law firms that lays the approaches side by side.
Where Prompt-Level Protection Fits
Secured AI sits between staff and the model. Before a prompt leaves the device, it detects and masks identifiers, including names, dates of birth, account and record numbers, contact details, and custom patterns you define, and it restores the real values locally when the answer comes back. Masked values live in a zero-knowledge vault, and the master key is never stored server-side.
For legal work, the detection layer covers the categories that matter in practice: client names, matter numbers, case names, opposing parties, witness names, contract terms, and settlement details. It works with OpenAI and DeepSeek, and there is no behavior change for staff, who keep typing prompts the same way. Policies can be set at the matter level, access is role-based, and usage logging produces a record of what left and what was masked. The product is built with compliance-focused architecture. Whether masking satisfies a specific confidentiality duty in a specific engagement is a determination for your ethics counsel, not a vendor.
Frequently Asked Questions
What percentage of law firm staff use AI tools without approval?
Can we just block AI sites on the firm network?
What is the first detection signal a firm should deploy?
How do we detect AI use on personal devices?
Does masking client identifiers before a prompt leaves satisfy our confidentiality duties?
Detect it, then give staff a path they will use
Secured AI masks identifiers on the device before a prompt leaves, restores real values locally, and keeps a record of what left and what was masked. See how it fits legal work on our legal solutions page, or try it directly.
