Compare
Shadow AI in Law Firms: Compare Your Options
Firms handle staff AI use in five ways: blocking, policy, DLP redaction, enterprise legal AI suites, and protecting the prompt itself. This page compares what each one delivers, especially for the question that keeps coming up: how do we let lawyers use AI without losing the record of what left.
The Situation
An associate is drafting a brief late at night. The deadline is tomorrow. They paste matter details into a public AI assistant, because it helps.
The firm's policy already says not to do this. It happens anyway. The prompt leaves the firm with client names, matter numbers, and settlement details inside it, and nothing records what went.
"88 percent report regular AI use in at least one business function, compared with 78 percent a year ago."
McKinsey, The State of AI in 2025 (n=1,993)
"already 29% of employees have turned to unsanctioned AI agents for work tasks"
Microsoft Security Insider, Cyber Pulse, 10 Feb 2026, citing a Hypothesis Group survey of 1,725 data security professionals (July 2025), a survey of security professionals about employees
What Clients Now Ask
Outside-counsel guidelines
Clients increasingly ask firms to declare their generative-AI use in outside-counsel guidelines and security questionnaires.
ABA Formal Opinion 512
Issued 29 July 2024, the opinion addresses confidentiality and competence duties for lawyers using generative AI, restating Model Rules 1.6 and 1.1 for that context.
The question behind the questionnaire
When a client or the firm's own ethics committee asks what staff pasted into which model and when, the answer has to come from somewhere.
The Gap
The missing piece is a record of what was disclosed, to which model, and when. No current approach produces that record without breaking lawyer workflow.
Blocking does not see what it stops. Policy does not see what it forbids. Redaction sees fragments and returns answers lawyers cannot use. Sanctioned suites log their own tool, not the browser tab beside it.
Five Approaches Compared
The five ways firms handle staff AI use, measured against what the firm actually needs when lawyers use AI under deadline pressure.
| What the firm needs | Ban / block AI sites | Policy only | DLP redaction tools (e.g. Nightfall) | Enterprise legal AI suites (e.g. Harvey, CoCounsel) | Secured AI |
|---|---|---|---|---|---|
| Covers unsanctioned ChatGPT or DeepSeek use on any laptop | No. Blocking typically relies on network or device rules that determined staff commonly route around | No. Relies on voluntary compliance, which tends to weaken under deadline pressure | Typically not on its own. Coverage commonly depends on where and how the tool is deployed | No. Enterprise legal AI secures the sanctioned path the firm purchased | Yes. Detection and masking happen on the device, before the prompt leaves |
| AI answers stay usable | There is no AI use to answer | Yes, but the full prompt leaves the firm unprotected | Commonly no. Redaction tends to return answers full of [REDACTED] placeholders that need manual reconstruction | Yes, within the sanctioned tool | Yes. Real values are restored locally in the answer, so answers stay usable |
| Record of what left the firm and what was masked | No record of use that routes around the block | No record at all | Commonly partial. DLP logs typically focus on policy violations, not a per-prompt record | Typically usage logs for the sanctioned tool only | Yes. Usage logging produces a record of what left and what was masked, usable for ethics reviews and client billing of AI-assisted work |
| Requires lawyers to change behavior | Yes. Staff must give up the assistant they already use | Yes. Staff must remember the rule every time | Commonly yes, when answers come back redacted and need manual work to use | Yes. Lawyers move work into the sanctioned tool | No. Staff keep using the assistant they already use |
| Covers the public-assistant path your sanctioned tools do not | Attempts to, by blocking | Attempts to, by policy | Commonly partial | No. That path sits outside the sanctioned rollout | Yes. Secured AI sits between the user and the AI model directly, with no integrations |
| Time to first protected prompt | Depends entirely on enforcement | Immediate, but unprotected | Typically a deployment project | Typically a procurement and rollout cycle | Start in the web app or install the PWA on iOS and Android. No rollout project required |
Statements about the first four approaches are general observations about each category, not claims about any specific product. Contact vendors directly for current capabilities.
Already Bought an Enterprise Legal AI Suite?
Keep it. It is the right tool for the work it was bought for.
Enterprise legal AI secures the sanctioned path. The unsanctioned path, a public assistant on every laptop, stays open no matter how good the sanctioned tool is. That is the gap.
Secured AI complements your rollout. The firm keeps its sanctioned tools and closes the separate unsanctioned path, with masking on the device and a record of what left and what was masked.
How Secured AI Works
Three steps, on the device and back. Matter-level policies, usage logging, and role-based access sit on top.
Detect and mask on the device
Identifiers, including names, dates of birth, account and record numbers, contact details, and custom patterns, are masked before the prompt leaves the device. Detection is tuned for legal documents, covering client names, matter numbers, case names, opposing parties, witness names, contract terms, and settlement details.
Send the masked prompt to the model
The masked prompt goes to the model. Secured AI works with OpenAI and DeepSeek. The zero-knowledge vault never stores the master key server-side. Data is protected with AES-256 at rest and TLS 1.3 in transit.
Restore real values locally
The answer comes back with placeholders. Real values are restored on the device, so the answer stays usable. No manual reconstruction, no [REDACTED] fragments.
Frequently Asked Questions
Does Secured AI replace our enterprise legal AI suite?
Do lawyers have to change how they work?
What record does the firm get?
Does Secured AI integrate with our other tools?
Is Secured AI compliant with ABA Formal Opinion 512?
Close the Unsanctioned Path
Let lawyers keep the assistant they already use, with identifiers masked before the prompt leaves the device and a record of what left and what was masked.
Learn more about Secured AI for law firms
