Skip to main content
Secured AI - Protecting You in the AI Age

Compare

Shadow AI in Law Firms: Compare Your Options

Firms handle staff AI use in five ways: blocking, policy, DLP redaction, enterprise legal AI suites, and protecting the prompt itself. This page compares what each one delivers, especially for the question that keeps coming up: how do we let lawyers use AI without losing the record of what left.

The Situation

An associate is drafting a brief late at night. The deadline is tomorrow. They paste matter details into a public AI assistant, because it helps.

The firm's policy already says not to do this. It happens anyway. The prompt leaves the firm with client names, matter numbers, and settlement details inside it, and nothing records what went.

"88 percent report regular AI use in at least one business function, compared with 78 percent a year ago."

McKinsey, The State of AI in 2025 (n=1,993)

"already 29% of employees have turned to unsanctioned AI agents for work tasks"

Microsoft Security Insider, Cyber Pulse, 10 Feb 2026, citing a Hypothesis Group survey of 1,725 data security professionals (July 2025), a survey of security professionals about employees

What Clients Now Ask

Outside-counsel guidelines

Clients increasingly ask firms to declare their generative-AI use in outside-counsel guidelines and security questionnaires.

ABA Formal Opinion 512

Issued 29 July 2024, the opinion addresses confidentiality and competence duties for lawyers using generative AI, restating Model Rules 1.6 and 1.1 for that context.

The question behind the questionnaire

When a client or the firm's own ethics committee asks what staff pasted into which model and when, the answer has to come from somewhere.

The Gap

The missing piece is a record of what was disclosed, to which model, and when. No current approach produces that record without breaking lawyer workflow.

Blocking does not see what it stops. Policy does not see what it forbids. Redaction sees fragments and returns answers lawyers cannot use. Sanctioned suites log their own tool, not the browser tab beside it.

Five Approaches Compared

The five ways firms handle staff AI use, measured against what the firm actually needs when lawyers use AI under deadline pressure.

Comparison of five approaches to staff AI use in law firms
What the firm needsBan / block AI sitesPolicy onlyDLP redaction tools (e.g. Nightfall)Enterprise legal AI suites (e.g. Harvey, CoCounsel)Secured AI
Covers unsanctioned ChatGPT or DeepSeek use on any laptopNo. Blocking typically relies on network or device rules that determined staff commonly route aroundNo. Relies on voluntary compliance, which tends to weaken under deadline pressureTypically not on its own. Coverage commonly depends on where and how the tool is deployedNo. Enterprise legal AI secures the sanctioned path the firm purchasedYes. Detection and masking happen on the device, before the prompt leaves
AI answers stay usableThere is no AI use to answerYes, but the full prompt leaves the firm unprotectedCommonly no. Redaction tends to return answers full of [REDACTED] placeholders that need manual reconstructionYes, within the sanctioned toolYes. Real values are restored locally in the answer, so answers stay usable
Record of what left the firm and what was maskedNo record of use that routes around the blockNo record at allCommonly partial. DLP logs typically focus on policy violations, not a per-prompt recordTypically usage logs for the sanctioned tool onlyYes. Usage logging produces a record of what left and what was masked, usable for ethics reviews and client billing of AI-assisted work
Requires lawyers to change behaviorYes. Staff must give up the assistant they already useYes. Staff must remember the rule every timeCommonly yes, when answers come back redacted and need manual work to useYes. Lawyers move work into the sanctioned toolNo. Staff keep using the assistant they already use
Covers the public-assistant path your sanctioned tools do notAttempts to, by blockingAttempts to, by policyCommonly partialNo. That path sits outside the sanctioned rolloutYes. Secured AI sits between the user and the AI model directly, with no integrations
Time to first protected promptDepends entirely on enforcementImmediate, but unprotectedTypically a deployment projectTypically a procurement and rollout cycleStart in the web app or install the PWA on iOS and Android. No rollout project required

Statements about the first four approaches are general observations about each category, not claims about any specific product. Contact vendors directly for current capabilities.

Already Bought an Enterprise Legal AI Suite?

Keep it. It is the right tool for the work it was bought for.

Enterprise legal AI secures the sanctioned path. The unsanctioned path, a public assistant on every laptop, stays open no matter how good the sanctioned tool is. That is the gap.

Secured AI complements your rollout. The firm keeps its sanctioned tools and closes the separate unsanctioned path, with masking on the device and a record of what left and what was masked.

How Secured AI Works

Three steps, on the device and back. Matter-level policies, usage logging, and role-based access sit on top.

Step 1

Detect and mask on the device

Identifiers, including names, dates of birth, account and record numbers, contact details, and custom patterns, are masked before the prompt leaves the device. Detection is tuned for legal documents, covering client names, matter numbers, case names, opposing parties, witness names, contract terms, and settlement details.

Step 2

Send the masked prompt to the model

The masked prompt goes to the model. Secured AI works with OpenAI and DeepSeek. The zero-knowledge vault never stores the master key server-side. Data is protected with AES-256 at rest and TLS 1.3 in transit.

Step 3

Restore real values locally

The answer comes back with placeholders. Real values are restored on the device, so the answer stays usable. No manual reconstruction, no [REDACTED] fragments.

Zero-knowledge vault, master key never stored server-side, AES-256 at rest, TLS 1.3 in transit
Web app and installable PWA on iOS and Android
Built with compliance-focused architecture, designed to support compliance use cases

Frequently Asked Questions

Does Secured AI replace our enterprise legal AI suite?
No. Enterprise legal AI suites secure the sanctioned path, the tools the firm rolled out and licensed. The unsanctioned path, a public assistant open in a browser on any laptop, stays open. Secured AI closes that separate path. The firm keeps its sanctioned tools and adds protection where there was none.
Do lawyers have to change how they work?
No. Secured AI requires no behavior change. Staff keep using the assistant they already use, in the web app or the installable PWA on iOS and Android.
What record does the firm get?
Usage logging produces a record of what left and what was masked, to which model, and when. That record is usable for ethics reviews and for client billing of AI-assisted work.
Does Secured AI integrate with our other tools?
No. Secured AI has no integrations. It sits between the user and the AI model directly. It works with OpenAI and DeepSeek.
Is Secured AI compliant with ABA Formal Opinion 512?
Secured AI does not provide legal advice and does not claim any compliance outcome. ABA Formal Opinion 512, issued 29 July 2024, addresses confidentiality and competence duties for lawyers using generative AI, restating Model Rules 1.6 and 1.1 for that context. Secured AI is built with compliance-focused architecture and designed to support compliance use cases. How your firm responds to the opinion is a question for your ethics counsel.

Close the Unsanctioned Path

Let lawyers keep the assistant they already use, with identifiers masked before the prompt leaves the device and a record of what left and what was masked.

Learn more about Secured AI for law firms